Federated Learning Method and System for Detecting and Defending Poisoning Attacks under Differential Privacy

By defining differential privacy on the client and combining adaptive noise-added decisions and segmented clustering analysis, identifying and eliminating the poisoning behavior of malicious clients, the problem of differential privacy covering abnormal characteristics is solved, and the coordinated optimization of the security and privacy of the federated learning system is achieved.

CN120069009BActive Publication Date: 2025-07-08SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510542723.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-07-08
Estimated Expiration
2045-04-28

AI Technical Summary

Technical Problem

The differential privacy mechanism introduces anomaly features of noise masking model updates in federated learning, making it difficult for the server to accurately identify the poisoning behavior of malicious clients, reducing the security and robustness of the system.

Method used

Differential privacy is defined on the client, through adaptive noise-added decision-making mechanism and segmented clustering analysis, combined with the K-Means clustering algorithm to identify malicious clients, eliminate abnormal updates, and optimize privacy protection and security.

Benefits of technology

On the premise of protecting user data privacy, accurately identify and eliminate malicious clients, maintain the training performance of the global model, and improve the security and robustness of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120069009B_ABST
    Figure CN120069009B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of distributed machine learning, and more specifically, relates to a federated learning method and system for detecting and defending poisoning attacks under differential privacy. The method includes: defining differential privacy at the client side; the client downloads the global model from the server, trains the local model using the local training dataset, calculates differential privacy noise, and combines the adaptive noise addition decision mechanism to update the local model; the server receives the local model updates from the client and performs malicious update detection based on segmented clustering analysis; the server assigns weights to each client and aggregates the updates to obtain the global model; repeat the above steps until the set number of training rounds is reached, and output the final global model. The present invention solves the problem of difficult attack identification caused by model perturbation under differential privacy, can accurately screen out abnormal clients that pose a threat to the global model, and realizes the coordinated optimization of privacy and security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of distributed machine learning, and more specifically, relates to a federated learning method and system for detecting and defending poisoning attacks under differential privacy. Background Art

[0002] Deep learning technology has high flexibility, automatic feature extraction ability and end-to-end training advantages, and has achieved excellent performance in complex tasks such as image recognition and natural language processing. Traditional model training usually requires collecting large-scale data from each client to a central server, and this centralized solution will bring serious privacy risks. To alleviate the privacy problem, federated learning is proposed as a solution.

[0003] However, federated learning still faces many security challenges. One prominent problem is the privacy leakage caused by local model updates, and another key threat is poisoning attacks. In terms of privacy protection, differential privacy can prevent the server from inferring the client's local data to a certain extent by introducing random noise. However, after adding differential privacy noise, the perturbation of model updates will mask abnormal behaviors, thereby reducing the ability to identify malicious clients, and further affecting the defense of poisoning attacks by defense algorithms. In terms of defending against poisoning attacks, malicious clients usually construct the model gradients they upload to make their numerical distances from the model updates of benign clients close, so that distance-based anomaly detection methods are difficult to distinguish normal and malicious behaviors, thus achieving the purpose of interfering with the global model or seeking their own interests.

[0004] Chinese Patent Document CN117634594A discloses an adaptive clustering federated learning method with differential privacy. The server adaptively clusters clients based on the similarity of local model parameters, and obtains multiple clusters. The clients are divided into different clusters. For each client in a cluster, the server performs intra-cluster aggregation calculation based on the local model parameters of all clients in the cluster to obtain an intra-cluster global model, and performs cross-validation on all intra-cluster global models, selects one intra-cluster global model as the optimal intra-cluster global model, and other intra-cluster global models as non-optimal intra-cluster global models; performs inter-cluster aggregation calculation on all non-optimal intra-cluster global models to obtain an inter-cluster global model, and adds the inter-cluster global model to the intra-cluster optimal global model to obtain a global model.

[0005] The current mainstream privacy protection technologies in federated learning include differential privacy, homomorphic encryption, and secure multi-party computation. Among them, homomorphic encryption can complete the model aggregation operation in the encrypted state, but the computational and communication overheads are large, making it difficult to be applied to resource-constrained device scenarios; although secure multi-party computation can achieve stronger privacy isolation, the protocol is complex, the implementation cost is high, and the system coordination requirements are strong. In contrast, differential privacy injects noise into the local model, effectively preventing the server from inferring the original user data. While protecting privacy, it has good flexibility and efficiency, and is suitable for federated learning tasks in large-scale and heterogeneous environments. Therefore, it has become the privacy protection method finally adopted in this solution. Although differential privacy has significant advantages in protecting user data privacy, the random noise introduced by it will, to a certain extent, mask the abnormal features in the model update, making it difficult for the server to accurately identify the poisoning behavior of malicious clients during the aggregation stage, thereby weakening the detection and defense effects against poisoning attacks and increasing the security risks faced by the system.

[0006] In summary, although the differential privacy mechanism can alleviate privacy risks, it will weaken the server's ability to identify poisoning attacks due to the introduction of noise, thereby reducing the security and robustness of the system. To address the above challenges, a federated learning mechanism that takes into account both privacy protection and poisoning defense needs to be designed, which can effectively suppress the risk of the server's reverse inference of the original data while improving the ability to identify the behavior of malicious clients, and achieve the coordinated optimization of privacy and security. Summary of the Invention

[0007] The present invention aims to overcome at least one defect of the above-mentioned prior art, and provides a federated learning method for detecting and defending against poisoning attacks under differential privacy, so as to solve the problem of difficult attack identification caused by model perturbation under differential privacy, and can accurately screen out abnormal clients that pose a threat to the global model, and achieve the coordinated optimization of privacy and security.

[0008] The present invention also discloses a system loaded with the federated learning method for detecting and defending against poisoning attacks under differential privacy.

[0009] The detailed technical solution of the present invention is as follows:

[0010] A federated learning method for detecting and defending against poisoning attacks under differential privacy, the method includes:

[0011] S1. Define differential privacy at the client;

[0012] S2. The client downloads the global model of the server, trains the local model using the local training data set, calculates the differential privacy noise, and combines the adaptive noise addition decision mechanism to realize the update of the client's local model; the sample data of the data set is image data;

[0013] S3. The server receives the local model updates from the clients and performs malicious update detection based on segmented clustering analysis;

[0014] S4. The server assigns weights to each client and aggregates the updates to obtain a global model;

[0015] S5. Each client obtains the trained global model to complete one iteration, and repeats steps S2 - S4 until the set number of training rounds is reached, and the server outputs the final global model.

[0016] Preferably according to the present invention, the S1 specifically includes:

[0017] Differential privacy is defined as follows: A random mechanism for the data set whose mapping satisfies -differential privacy if for any two adjacent data sets and that differ by only one element, and any output subset O, there is:

[0018] (1)

[0019] In formula (1), represents probability; is the privacy budget parameter, used to measure the privacy protection strength; represents the upper bound of the probability allowed in the case where the privacy guarantee may fail; and are adjacent data sets; is the random mechanism applied to the data set; represents () the set of any possible output events.

[0020] Preferably according to the present invention, the S2 specifically includes:

[0021] Differential privacy - based federated learning model training involves multiple rounds of communication between the clients and the server: In each round of training denoted as , where, ; Suppose there are clients in the system, and each client owns a local training data set , which contains data samples, where, ;

[0022] The federated learning system sequentially performs the following steps:

[0023] S21: At the beginning of the first round of training the server initializes the global model as ; In addition, at the beginning of each round of training each client downloads the latest global model from the server

[0024] S22: Each client uses the local training dataset to perform training, adopting the Stochastic Gradient Descent (SGD) method, and calculates the local update for this round based on the downloaded global model to obtain the local model ;

[0025] (2)

[0026] In formula (2), is the learning rate, represents the loss function calculated on the local dataset , and represents the global model;

[0027] S23: Since the local updates of some clients may be too large, thus affecting the stability of the global model, gradient clipping is performed on the local model parameters:

[0028] (3)

[0029] In formula (3), is the gradient clipping threshold, ensuring that the norm of the local update does not exceed the set maximum range, thereby ensuring the control of the privacy budget;

[0030] S24: Calculate the sensitivity :

[0031] To meet the differential privacy constraint, the global sensitivity needs to be calculated:

[0032] (4)

[0033] The global sensitivity represents the maximum impact range of a single client's update on the global model and is used for subsequent noise calculation;

[0034] S25: Calculate the variance of the differential privacy noise:

[0035] According to the set privacy budget , calculate the variance of the Gaussian noise that needs to be added in this round:

[0036] (5)

[0037] Among them, The amplitude of the added noise is controlled, and the privacy budget The larger it is, the smaller the required noise; to ensure that the local updates of each client satisfy differential privacy, Gaussian noise needs to be added to the local model parameters;

[0038] S26: Model update adaptive noise addition decision mechanism:

[0039] When the model uploaded in this round is almost the same as the previous round, in fact, no new sensitive information is contributed, so there is no need to re-add noise, thus avoiding the cumulative interference caused by adding noise in each round in conventional differential privacy and effectively reducing the injection of invalid noise;

[0040] If the change amount of the model is less than or equal to the preset ratio threshold :

[0041] (6)

[0042] In formula (6), represents the ratio threshold, represents the change amount of the model, represents the local model of the i-th client in the (t - 1)-th round, represents the local model of the i-th client in the t-th round;

[0043] Then the global model in this round is replaced by the global model in the previous round:

[0044] (7)

[0045] If the change amount of the model is greater than the ratio threshold :

[0046] (8)

[0047] Then normal noise addition:

[0048] (9)

[0049] In formula (9), represents the local model added with differential privacy noise; represents the standard Gaussian distribution; represents the identity matrix.

[0050] According to the preference of the present invention, the said S3 specifically includes:

[0051] S31: The server collects the local model updates processed with differential privacy noise from all clients ;

[0052] S32: The server divides the local model update of each client into n sub-vector segments: divides the complete local model update into n sub-vector segments according to dimensions to extract the update values in different dimension intervals:

[0053] (10)

[0054] (11)

[0055]

[0056] (12)

[0057] Among them, represents the sub-vector of the local update vector of the client on the nth segment;

[0058] S33: For each sub-vector segment, the server performs clustering analysis on the parameter sets of all clients on this segment. Preferably, the K-Means clustering algorithm is used to divide the local updates with similar parameter distributions into several clusters, and the cluster with the largest number of clients is identified, and the cluster with the largest number of clients is defined as the malicious client set.

[0059] According to the preferred embodiment of the present invention, the use of the K-Means clustering algorithm to divide the local updates with similar parameter distributions into several clusters and identify the cluster with the largest number of clients specifically means:

[0060] For each sub-vector segment, first, randomly select data points as the initial cluster centers, denoted as ;

[0061] Then, for each data point, assign it to the nearest cluster center:

[0062] (13)

[0063] Where represents the rth data point; represents the data point to the cluster center the square of the Euclidean distance represents the number of the cluster center that selects the minimum distance , used to assign data points;

[0064] Finally, update each cluster center let it be the mean of all data points in the corresponding cluster:

[0065] (14)

[0066] Among them, represents the clustering center corresponding cluster;

[0067] Repeat the above steps until all clustering centers converge or the maximum number of iterations is reached;

[0068] Then, for each sub-vector segment, use the K-means clustering algorithm to identify the cluster with the largest number of clients:

[0069] (15)

[0070] In formula (15), represents the cluster with the largest number of clients; q represents the label of the sub-vector segment; The model update collection of the q-th sub-vector segment.

[0071] According to a preferred embodiment of the present invention, the S4 specifically includes:

[0072] S41: After clustering, traverse each client whether it belongs to the cluster with the largest number of clients , if it is found that the client belongs to this cluster, then delete it from the training, and then aggregate the models to calculate the global model :

[0073] (16)

[0074] Among them, represents the set of remaining clients, that is, the clients still retained after excluding the largest clustering cluster; J represents the total number of remaining model updates; j represents the label of the remaining model updates; represents the aggregated global model; represents the j-th model update in the t-th round;

[0075] S42: Finally, the algorithm returns the final global model parameters .

[0076] In another aspect of the present invention, there is also provided a federated learning system for detecting and defending poisoning attacks under differential privacy, including clients and servers participating in federated learning. The clients and servers participating in federated learning perform federated learning using the above-mentioned federated learning method.

[0077] Compared with the prior art, the beneficial effects of the present invention are:

[0078] (1) The present invention slices the model update vector uploaded by the client according to dimensions, divides it into multiple sub-vector segments, and applies a clustering algorithm to each sub-segment respectively, fully mining the feature differences of the model in different local regions, combining gradient slicing with local clustering, so that on the premise of protecting the user's local data from being leaked, the server can still identify the abnormal clients that upload, thereby maintaining the performance of the global model during the system training process in the face of poisoning attacks, making it close to the training effect in a non-attack environment.

[0079] (2) In order to reduce the consumption of privacy budget, the present invention designs a model update adaptive noise-adding decision mechanism to enhance the privacy protection effect. BRIEF DESCRIPTION OF THE DRAWINGS

[0080] Figure 1 is a schematic flow diagram of the federated learning method described in the present invention.

[0081] Figure 2 is a schematic diagram of the federated learning architecture described in Embodiment 1 of the present invention.

[0082] Figure 3 is a test accuracy graph of the global model protected by the defense algorithm of the present invention, the Bulyan defense algorithm, the Median defense algorithm, and the M-Krum defense algorithm respectively under the Lie attack in the FEMNIST dataset.

[0083] Figure 4 is a test accuracy graph of the global model protected by the defense algorithm of the present invention, the Bulyan defense algorithm, the Median defense algorithm, and the M-Krum defense algorithm respectively under the Fang attack in the FEMNIST dataset.

[0084] Figure 5 is a test accuracy graph of the global model protected by the defense algorithm of the present invention, the Bulyan defense algorithm, the Median defense algorithm, and the M-Krum defense algorithm respectively under the MinMax attack in the FEMNIST dataset. DETAILED DESCRIPTION OF THE INVENTION

[0085] The following further describes the present disclosure in conjunction with the drawings and embodiments.

[0086] Embodiment 1

[0087] As Figure 1 , this embodiment provides a federated learning method for detecting and defending against poisoning attacks under differential privacy, and the method includes:

[0088] S1. Define differential privacy at the client;

[0089] The definition of differential privacy is as follows: A random mechanism for the dataset The mapping satisfies - differential privacy, if for any two adjacent data sets that differ by only one element and , and any output subset O, there is:

[0090] (1)

[0091] In formula (1), represents probability; is the privacy budget parameter, used to measure the strength of privacy protection; represents the upper bound of the probability allowed in the case where the privacy guarantee may fail; and are adjacent data sets; is the random mechanism applied to the data set; represents ( ) the set of any possible output events.

[0092] S2. The client downloads the global model of the server, trains the local model using the local training data set, calculates the differential privacy noise, and combines the adaptive noise addition decision mechanism to update the client's local model, specifically including:

[0093] Differential privacy federated learning model training involves multiple rounds of communication between the client and the server: In each round of training denoted as , where ; Suppose there are clients in the system, and each client owns the local training data set , which contains data samples, where ;

[0094] The federated learning system sequentially executes the following steps:

[0095] S21: At the beginning of the first round of training , the server initializes the global model as ; In addition, at the beginning of each round of training each client downloads the latest global model from the server

[0096] S22: Each client uses the local training data set for training, adopts the stochastic gradient descent method SGD, and calculates the local update of this round based on the downloaded global model to obtain the local model ;

[0097] (2)

[0098] In formula (2), is the learning rate, represents the loss function calculated on the local dataset and represents the global model;

[0099] S23: Since the local updates of some clients may be too large, affecting the stability of the global model, gradient clipping is performed on the local model parameters:

[0100] (3)

[0101] In formula (3), is the gradient clipping threshold to ensure that the norm of the local update does not exceed the set maximum range, thus ensuring the control of the privacy budget;

[0102] S24: Calculate the sensitivity :

[0103] To satisfy the differential privacy constraint, the global sensitivity needs to be calculated:

[0104] (4)

[0105] The global sensitivity represents the maximum impact range of a single client update on the global model and is used for subsequent noise calculation;

[0106] S25: Calculate the variance of the differential privacy noise:

[0107] According to the set privacy budget , calculate the variance of the Gaussian noise to be added in this round:

[0108] (5)

[0109] where controls the amplitude of the added noise. The larger the privacy budget , the smaller the required noise. To ensure that the local updates of each client satisfy differential privacy, Gaussian noise needs to be added to the local model parameters;

[0110] S26: Model update adaptive noise addition decision mechanism:

[0111] When the model uploaded in this round is almost the same as the previous round, it actually does not contribute new sensitive information. Therefore, there is no need to add noise again, thus avoiding the cumulative interference caused by adding noise in each round in conventional differential privacy and effectively reducing the injection of invalid noise;

[0112] If the model change amount is less than or equal to the ratio threshold :

[0113] (6)

[0114] represents the ratio threshold, represents the model change amount, represents the local model of the i-th client in the (t - 1)-th round, represents the local model of the i-th client in the t-th round;

[0115] Then the global model of this round uses the global model of the previous round instead:

[0116] (7)

[0117] If the model change amount is greater than the ratio threshold :

[0118] (8)

[0119] Then add noise normally:

[0120] (9)

[0121] In formula (9), represents the local model added with differential privacy noise; represents the standard Gaussian distribution; represents the identity matrix.

[0122] S3. The server receives the local model updates from the clients and performs malicious update detection based on segmented clustering analysis, specifically including:

[0123] S31: The server collects the local model updates processed by differential privacy from all clients ;

[0124] S32: The server divides the local model update vector of each client into multiple sub-vector segments. According to the dimension, the complete model update is sliced into several sub-vector segments to extract the update values in different dimension intervals. For example, the model update can be evenly divided into three segments by dimension, denoted as:

[0125] (10)

[0126] (11)

[0127] (12)

[0128] respectively represent the client sub-vectors of the local update vector on three segments;

[0129] S33: For each sub-vector segment, the server performs clustering analysis on the parameter sets of all clients on this segment. Preferably, the K-Means clustering algorithm is used to divide the local updates with similar parameter distributions into several clusters, and the cluster with the largest number of clients is identified and defined as the malicious client set, as follows:

[0130] For each sub-vector segment, first, randomly select data points as the initial clustering centers, denoted as ;

[0131] Then, for each data point, assign it to the nearest clustering center:

[0132] (13)

[0133] where represents the r-th data point; represents the data point to the squared Euclidean distance of the clustering center ; represents the number of the clustering center that selects the minimum distance, for assigning data points;

[0134] Finally, update each clustering center and make it the mean of all data points in the corresponding cluster:

[0135] (14)

[0136] where, represents the cluster corresponding to the clustering center ;

[0137] Repeat the above steps until all clustering centers converge or reach the maximum number of iterations;

[0138] Then, for each sub-vector segment , use the K-means clustering algorithm to identify the cluster with the largest number of clients:

[0139] (15)

[0140] In formula (15), represents the cluster with the largest number of clients; q represents the label of the sub-vector segment; the model update collection of the q-th sub-vector segment.

[0141] S4. The server assigns weights to each client and aggregates and updates them to obtain a global model, specifically including:

[0142] S41: After clustering, traverse each client whether it belongs to the cluster with the largest number of clients . If it is found that the client belongs to this cluster, delete it from the training, and then aggregate the models to calculate the global model :

[0143] (14)

[0144] Among them, represents the set of remaining clients, that is, the clients that are still retained after excluding the largest clustering cluster; J represents the total number of remaining model updates; j represents the label of the remaining model updates; represents the aggregated global model; represents the j-th model update in the t-th round;

[0145] S42: Finally, the algorithm returns the final global model parameters , preferably, the global model is a convolutional neural network model ResNet-18.

[0146] In another aspect of the present invention, a federated learning system for detecting and defending poisoning attacks under differential privacy is further provided, including clients and servers participating in federated learning. The clients and servers participating in federated learning perform federated learning using the above-mentioned federated learning method.

[0147] S5. Repeat steps S2 - S4 until the set number of training rounds is reached, and output the final global model.

[0148] Figure 2 shows the overall architecture of the federated learning system, where the server is located in the center and is responsible for coordinating the model training and update of each client. Benign clients upload parameters after training the model based on local data, and the server aggregates them and then distributes the global model. There may be malicious clients in the system, and the models uploaded by them may contain attack behaviors. Therefore, the server introduces an attack detection mechanism to conduct security reviews on the uploaded content, thereby improving the overall robustness and security of federated learning.

[0149] The sample data of the dataset in this embodiment is image data, such as the FEMNIST dataset; preferably, the FEMNIST dataset is used as the processed data to verify the test accuracy of the global model protected by the method of the present invention, the Bulyan defense algorithm, the Median defense algorithm, and the M-Krum defense algorithm under three situations of Lie attack, Fang attack, and MinMax attack. The global model is preferably a convolutional neural network model ResNet-18, and the test results are as followsFigures 3 - 5 As shown in:

[0150] Figure 3 It is the test accuracy graph of the Lie attack on the global model protected by the defense algorithm of the present invention, the Bulyan defense algorithm, the Median defense algorithm, and the M-Krum defense algorithm respectively under the FEMNIST dataset. As the test accuracy gradually stabilizes, it can be clearly concluded that the test accuracy of the present invention is higher than that of the Bulyan defense algorithm, the Median defense algorithm, and the M-Krum defense algorithm.

[0151] Figure 4 It is the test accuracy graph of the Fang attack on the global model protected by the defense algorithm of the present invention, the Bulyan defense algorithm, the Median defense algorithm, and the M-Krum defense algorithm respectively under the FEMNIST dataset. As the test accuracy gradually stabilizes, it can be clearly concluded that the test accuracy of the present invention is higher than that of the Bulyan defense algorithm, the Median defense algorithm, and the M-Krum defense algorithm.

[0152] Figure 5 It is the test accuracy graph of the MinMax attack on the global model protected by the defense algorithm of the present invention, the Bulyan defense algorithm, the Median defense algorithm, and the M-Krum defense algorithm respectively under the FEMNIST dataset. As the test accuracy gradually stabilizes, it can be clearly concluded that the test accuracy of the present invention is higher than that of the Bulyan defense algorithm, the Median defense algorithm, and the M-Krum defense algorithm.

[0153] In summary, from the experimental results, the defense algorithm of the method described in this embodiment achieves higher accuracy compared to other defense algorithms.

[0154] Embodiment 2

[0155] This embodiment provides a federated learning system for detecting and defending poisoning attacks under differential privacy, including clients and servers participating in federated learning. The clients and servers participating in federated learning perform federated learning using the above-mentioned federated learning method.

[0156] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the technical solutions of the present invention, rather than limitations on the specific implementation manners of the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the claims of the present invention shall be included within the protection scope of the claims of the present invention.

Claims

1. A federated learning method for detecting and defending poisoning attacks under differential privacy, characterized in that The method includes: S1. Define differential privacy at the client side; S2. The client downloads the global model from the server, trains a local model using the local training dataset, calculates differential privacy noise, and combines an adaptive noise addition decision mechanism to update the client's local model; the sample data of the dataset is image data; S3. The server receives the local model updates from the clients and performs malicious update detection based on segmented clustering analysis, specifically as follows: S31: The server collects the locally model updates processed with differential privacy noise from all clients ; S32: The server divides the local model update of each client into n sub-vector segments: divides the complete local model update into n sub-vector segments according to dimensions to extract the update values in different dimension intervals; (1) (2) (3) Among them, represents the client sub-vector of the local update vector on the nth segment; S33: For each sub-vector segment, the server performs clustering analysis on the parameter sets of all clients on this segment, uses the K-Means clustering algorithm to divide the local updates with similar parameter distributions into several clusters, and identifies the cluster with the largest number of clients, and defines the cluster with the largest number of clients as the malicious client set; S4. The server assigns weights to each client and aggregates the updates to obtain the global model; S5. Each client obtains the trained global model to complete one iteration, and repeats steps S2 - S4 until the set number of training rounds is reached, and the server outputs the final global model.

2. The federated learning method for detecting and defending poisoning attacks under differential privacy according to claim 1, wherein The specific content of S1 includes: Differential privacy is defined as follows: A random mechanism that maps a dataset satisfies -differential privacy if, for any two neighboring datasets and that differ in only one element, and for any output subset O, the following holds: (4) In formula (4), represents probability; is the privacy budget parameter, which is used to measure the privacy protection strength; represents the upper bound of the probability allowed in the case where the privacy guarantee may fail; and are adjacent data sets; is the random mechanism applied to the data set; represents the set of any possible output events.

3. The federated learning method for detecting and defending poisoning attacks under differential privacy according to claim 1, wherein The specific content of S2 includes: Differential privacy federated learning model training involves multiple rounds of communication between the client and the server: In each round of training, denoted as , where ; There are a total of clients in the system, and each client has a local training dataset , which contains data samples, where ; The federated learning system sequentially performs the following steps: S21: At the beginning of the first round of training the server initializes the global model as ; In addition, at the beginning of each round of training each client downloads the latest global model from the server S22: Each client uses the local training dataset to perform training, adopting the Stochastic Gradient Descent (SGD) method, and calculates the local update of this round based on the downloaded global model to obtain the local model ; (5) In formula (5), is the learning rate, represents the loss function calculated on the local dataset , and represents the global model; S23: Since the local updates of some clients may be too large, affecting the stability of the global model, gradient clipping is performed on the local model parameters; (6) In formula (6), is the gradient clipping threshold to ensure that the norm of the local update does not exceed the set maximum range, thus ensuring the control of the privacy budget; S24: Calculate the sensitivity : To satisfy the differential privacy constraint, the global sensitivity needs to be calculated : (7) Global sensitivity It represents the maximum influence range of a single client update on the global model and is used for subsequent noise calculation; S25: Calculate the variance of differential privacy noise; According to the set privacy budget , calculate the variance of the Gaussian noise to be added in this round : (8) Among them, The amplitude of the added noise is controlled, and the privacy budget The larger it is, the less noise is required; to ensure that the local updates of each client satisfy differential privacy, Gaussian noise needs to be added to the local model parameters; S26: Model update adaptive noise addition decision mechanism: When the model uploaded in this round is almost the same as the previous round, in fact, no new sensitive information is contributed, so there is no need to add noise again, thus avoiding the cumulative interference caused by adding noise in each round in conventional differential privacy and effectively reducing the injection of invalid noise; If the model change amount is less than or equal to a preset proportional threshold : (9) In formula (6), represents the proportional threshold,[[]]END]] represents the model change amount,[[]]END]] represents the local model of the ith client in the (t - 1)-th round,[[]]END]] represents the local model of the ith client in the t-th round;[[]]END]] Then the global model of this round is replaced by the global model of the previous round; (10) If the model change amount is greater than the ratio threshold : (11) Then add noise normally; (12) In formula (9), represents the local model with differential privacy noise added; represents the standard Gaussian distribution; represents the identity matrix.

4. The federated learning method for detecting and defending poisoning attacks under differential privacy according to claim 1, wherein The use of the K-Means clustering algorithm to divide the local updates with similar parameter distributions into several clusters and identify the cluster with the largest number of clients specifically refers to: For each sub-vector segment, first, randomly select data points as the initial clustering centers, denoted as ; Then, for each data point, assign it to the nearest cluster center; (13) Among them represents the r-th data point; represents the data point to the cluster center the square of the Euclidean distance represents the number of the cluster center that gives the minimum distance , which is used to assign data points; Finally, update each cluster center Let it be the mean of all data points in the corresponding cluster: (14) Among them, represents the clustering center corresponding cluster; Repeat the above steps until all cluster centers converge or reach the maximum number of iterations; Then, for each sub-vector segment, use the K-means clustering algorithm to identify the cluster with the largest number of clients; (15) In formula (15), represents the cluster with the largest number of clients; q represents the label of the sub-vector segment; the model update collection of the q-th sub-vector segment.

5. The federated learning method for detecting and defending against poisoning attacks under differential privacy according to claim 1, wherein The specific content of S4 includes: S41: After clustering, traverse each client Whether it belongs to the cluster with the largest number of clients , if it is found that the client belongs to this cluster, then remove it from the training, and then the model aggregates to calculate the global model : (16) Among them, represents the set of remaining clients, that is, the clients that are still retained after excluding the largest cluster; J represents the total number of remaining model updates; j represents the label of the remaining model updates; represents the aggregated global model; represents the j-th model update in the t-th round; S42: The final algorithm returns the final global model parameters .

6. A federated learning system for detecting and defending against poisoning attacks under differential privacy, characterized in that, It includes clients and servers participating in federated learning. The clients and servers participating in federated learning perform federated learning using the federated learning method described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Self-adaptive privacy protection federal learning method

    CN116739079A

  • Self-adaptive clustering federal learning method with differential privacy

    CN117634594A