Federal learning privacy protection method, electronic equipment and storage medium
By adopting local differential privacy mechanisms and layer sensitivity algorithms on the federated learning client, differential privacy noise is solved, and security and privacy risks such as member reasoning attacks in federated learning are achieved, achieving a more efficient balance of privacy protection and model accuracy.
Patent Information
- Application Number
- CN202510118317.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-24
- Publication Date
- 2025-05-30
AI Technical Summary
There are security and privacy risks such as member reasoning attacks in federated learning, and traditional differential privacy methods and other defense strategies are insufficient in model accuracy and computational overhead.
Using local differential privacy mechanisms and layer sensitivity algorithms, differential privacy noise is added on the local model update of the client to protect the privacy of the local data set on the client. By calculating the layer sensitivity of each layer of the local model, noise is added on important layers in a targeted manner, reducing the amount of noise addition and reducing the loss of global model performance.
Enhanced security and privacy protection capabilities of federated learning, balanced the relationship between privacy protection and model accuracy, reduces communication costs, and provides more flexible privacy control capabilities for each client.
Smart Images

Figure CN120074882A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of machine learning privacy protection, and particularly to a privacy protection method, an electronic device and a storage medium for federated learning. Background Art
[0002] Deep learning is a machine learning method that extracts features and patterns from a large amount of data through a multi-layer neural network, and has achieved remarkable success in many fields such as image recognition and natural language processing. However, the training of deep learning models usually requires a large amount of centralized data, which brings challenges in terms of data privacy and security. To address the data privacy issue, federated learning has been proposed as an emerging distributed machine learning framework. Federated learning allows multiple participants to train models on local devices and only share the parameter updates of the models, rather than the original data, thus protecting data privacy to a certain extent. In this way, federated learning realizes the collaborative training of models while protecting the privacy of user data, and has broad application potential.
[0003] Although federated learning has advantages in protecting data privacy, it still faces various security and privacy risks. Among them, the membership inference attack (MIA) is an important attack method in federated learning. The attacker monitors the output of the model to infer whether a specific sample belongs to the training data set, which may lead to the leakage of user privacy.
[0004] To resist the membership inference attack, researchers have proposed a variety of defense strategies, which mainly include:
[0005] 1. Differential privacy: Differential privacy protects data privacy by introducing noise during the model training process. The core idea is to make the impact of a single data sample on the model output negligible, thereby preventing information leakage. Although differential privacy provides theoretical privacy guarantees, in practice, it usually requires a trade-off between privacy protection and model accuracy.
[0006] 2. Regularization techniques: Using techniques such as L2 regularization and Dropout, by restricting the model complexity to reduce overfitting to the training data, thereby reducing the risk of information leakage. Although these techniques can improve the generalization ability of the model to a certain extent, their effects often depend on the specific model and data set.
[0007] 3. Adversarial training: By introducing adversarial samples during the training process to improve the robustness of the model against attacks. This method needs to be designed for specific attacks and usually has a large computational overhead.
[0008] 4. Model Compression and Pruning: By reducing the model parameters, the model is made less prone to overfitting, thereby reducing the risk of information leakage. However, excessive compression may lead to a decline in model performance.
[0009] In summary, traditional differential privacy methods and other defense strategies have problems such as a decline in model accuracy and large computational and communication overheads in the application models of federated learning. Summary of the Invention
[0010] In view of the deficiencies in the prior art, the present invention provides a privacy protection method, an electronic device, and a storage medium for federated learning. When an attack model implements a membership inference attack during the training process of federated learning, a local differential privacy mechanism and a layer sensitivity algorithm are used to add differential privacy noise to the local model updates of the client to protect the privacy of the client's local dataset.
[0011] The first object of the present invention is to provide a privacy protection method for federated learning. The federated learning includes a server and multiple clients. During the training process of federated learning, an attack model is used to perform a membership inference attack on any client of the federated learning. The method includes:
[0012] Obtain a test dataset for testing the performance of the server's global model, and initialize the parameters of the server's global model;
[0013] During each iterative training, the server randomly selects multiple clients to participate in the training, and sends the global model parameters of the previous iterative round to each selected client;
[0014] Each client uses the local dataset and the global model parameters of the previous iterative round sent by the server to train the local model to generate local model updates, adds differential privacy noise to the local model updates according to the local differential privacy mechanism and the layer sensitivity algorithm to protect the privacy of the local dataset, and sends the local model updates with added differential privacy noise to the server;
[0015] The server aggregates the local model updates with added differential privacy noise uploaded by each client to update the global model parameters, and uses the test dataset to evaluate the performance of the updated global model;
[0016] Iterate continuously until all clients under federated learning have participated in at least one training, and the performance of the server's global model meets the preset conditions, then stop the training, and send the final global model parameters to all clients under federated learning to achieve privacy protection for federated learning.
[0017] As a further improvement of the present invention, the step in which each client adds differential privacy noise to the local model updates according to the local differential privacy mechanism and the layer sensitivity algorithm includes:
[0018] After each client completes local model training to obtain a local model update, the layer sensitivity algorithm calculates the layer sensitivity of each updated layer of the local model according to the L1 norm of the update gap between the local model update in the current iteration round and the local model update in the previous iteration round;
[0019] According to the local differential privacy mechanism and the layer sensitivity of each updated layer of the local model, differential privacy noise is added to the updated layer of the local model.
[0020] As a further improvement of the present invention, the adding of differential privacy noise to the updated layer of the local model according to the local differential privacy mechanism and the layer sensitivity of each layer of the local model includes:
[0021] Sort the layer sensitivities of each updated layer of the local model in descending order;
[0022] According to the descending order of the layer sensitivities of the updated layers of the local model, select the updated layers of the local model at the top of the descending order of layer sensitivities in sequence according to a preset ratio;
[0023] Set local differential privacy parameters according to the local differential privacy mechanism to determine the intensity of the added differential privacy noise, and add differential privacy noise to the selected updated layers of the local model.
[0024] As a further improvement of the present invention, before calculating the layer sensitivity of each updated layer of the local model, it is judged whether the gradient of the local model exceeds a preset clipping threshold. If so, the influence of individual samples in the local dataset is restricted by gradient clipping.
[0025] As a further improvement of the present invention, the calculation formula for the layer sensitivity of each updated layer of the local model is:
[0026]
[0027] Among them, are the local model parameters of the j-th updated layer of the local model of the i-th client in the t-th and t + 1-th iteration rounds respectively, and mean() is the average weight value of the local model parameters, is the layer sensitivity of the j-th updated layer of the local model of the i-th client in the t-th iteration round.
[0028] As a further improvement of the present invention, the standard deviation of the differential privacy noise is:
[0029]
[0030] Among them, q is the sampling rate, that is, the proportion of clients randomly selected by the server in the current iteration round among all clients in federated learning; t is the current iteration round; δ i is the privacy budget of the i-th client; ε iis the privacy cost for the i-th client; C is the preset clipping threshold; m is the size of the local dataset; Δs is the sensitivity of the differential privacy noise in each iteration round; σ i is the standard deviation of the differential privacy noise.
[0031] As a further improvement of the present invention, the preset ratio is set according to the task requirements of each client's local model.
[0032] As a further improvement of the present invention, the gradient clipping is to clip the L2 norm of the local model gradient with the clipping threshold.
[0033] The second object of the present invention is to provide an electronic device, including at least one processing unit and at least one storage unit, wherein the storage unit stores a computer program, and when the program is executed by the processing unit, the processing unit executes the above privacy protection method.
[0034] The third object of the present invention is to provide a storage medium, which stores a computer program executable by an electronic device, and when the program runs on the electronic device, the electronic device executes the above privacy protection method.
[0035] Compared with the prior art, the beneficial effects of the present invention are:
[0036] Introduce the local differential privacy mechanism at each client to protect the client's local dataset (private data) while retaining the distributed characteristics of federated learning and enhancing the security and privacy protection capabilities of federated learning.
[0037] Adopt the layer sensitivity algorithm to optimize the application of the local differential privacy mechanism. By calculating the layer sensitivity of each layer of the local model and adding differential privacy noise to important layers specifically, not only the amount of noise added is reduced, but also the loss of the global model performance is reduced, thus balancing the relationship between privacy protection and model accuracy.
[0038] At the same time, each client can independently adjust the privacy budget and noise addition strategy according to the local dataset and the task requirements of the local model to adapt to different application scenarios and data characteristics. By applying differential privacy locally at each client, the communication cost is reduced, and at the same time, more flexible privacy control capabilities are provided for each client. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 is the flowchart of the privacy protection method;
[0040] Figure 2 is the architecture diagram of federated learning;
[0041] Figure 3 is the working flowchart of the attack model;
[0042] Figure 4 is the workflow diagram of the client;
[0043] Figure 5 is the workflow diagram of the server. Specific implementation manners
[0044] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0045] The following further describes the present invention in detail with reference to the accompanying drawings:
[0046] Please refer to the architecture of federated learning Figure 2 , which includes a central server, i.e., the server, and multiple clients. The server is used to coordinate the consistent behaviors of the clients in the federated learning system to ensure the correct operation of the training of the local models by the clients; the clients are responsible for performing local model training and updating on local devices and collaborating with the server without disclosing the original data. When training the local model on the client side, a local differential privacy mechanism is introduced, and a layer sensitivity algorithm is designed. By calculating the L1 norm, certain specific layers for updating the local model are selected to add noise, so as to reduce the amount of noise added and reduce the loss of model utility.
[0047] During the federated learning training, the attacker uses an attack model to perform a membership inference attack on the server or each client of the federated learning. The attacker can be a malicious participant within the federated learning, attacking other clients within the federated learning during the training phase of the federated learning to obtain the private information of other honest participants (clients); the attack model can also be an external malicious user, attacking the server of the federated learning during the training and inference phase of the federated learning.
[0048] Please refer to the process of the attacker training the attack model to attack each client of the federated learning Figure 3 , and the specific steps are as follows:
[0049] Step 31, the attacker needs to detect the structural information of the target model of the target client, such as network structure, number of layers, optimizer state and other information, to ensure that a shadow model similar to the target model can be trained in the next step to generate the training data of the attack model.
[0050] Step 32, the attacker needs to detect the training data information of the target model, such as data distribution, data type, etc., to ensure that a shadow model similar to the target model can be trained in the next step to generate the training data of the attack model.
[0051] Step 33, use the detected data distribution information to generate D_member and D_nonmember. D_member is defined as using this batch of data to train the shadow model, and D_nonmember is defined as not using this batch of data to train the shadow model.
[0052] Step 34, determine whether the attacker knows the structure of the target model. If so, execute Step 37; if not, execute Step 35.
[0053] Step 35, determine whether the attacker is an attacker inside the federated learning system. If so, execute Step 36; if not, end.
[0054] Step 36, the attacker is an attacker inside the federated learning system, and execute the active membership inference attack.
[0055] Step 37, the attacker trains multiple shadow models to imitate the target model. Training multiple shadow models can enhance the generalization ability of the data.
[0056] Step 38, construct the training dataset of the membership inference attack model through the data output by the shadow model.
[0057] Step 39, use the training dataset output by the shadow model to train the binary classification membership inference attack model to perform the membership inference attack on the target model of the target client.
[0058] In the above membership inference attack scenario, this embodiment provides a privacy protection method for federated learning, adding differential privacy noise to the local model update of the client using the local differential privacy mechanism and the layer sensitivity algorithm to protect the privacy of the client's local dataset. For the method flow, please refer to Figure 1 The method includes:
[0059] Obtain a test dataset for testing the performance of the server global model, and initialize the parameters of the server global model;
[0060] In each iterative training, the server randomly selects multiple clients to participate in the training and sends the global model parameters of the previous iterative round to each selected client;
[0061] Each client uses the local dataset and the global model parameters of the previous iteration round sent by the server to train the local model to generate local model updates, adds differential privacy noise to the local model updates according to the local differential privacy mechanism and the layer sensitivity algorithm to protect the privacy of the local dataset, and sends the local model updates with differential privacy noise added to the server;
[0062] The server aggregates the local model updates with differential privacy noise uploaded by each client to update the global model parameters, and evaluates the performance of the updated global model using the test dataset;
[0063] Iterate continuously until all clients under federated learning have participated in training at least once, and the performance of the global model on the server meets the preset conditions, then stop training, and send the final global model parameters to all clients under federated learning to achieve privacy protection for federated learning.
[0064] The client is responsible for model training and updating on the local device and collaborating with the server without disclosing the original data. When local differential privacy (LDP) is involved, the client also needs to ensure effective privacy protection before data sharing. For the workflow of each client, please refer to Figure 4 。
[0065] Step 41, define the hyperparameters during training, such as lr, batch_size, global round, etc.
[0066] Step 42, define the variables of the local differential privacy mechanism, such as (ε i , δ i ) to determine the intensity of the differential privacy noise. In this embodiment, the differential privacy noise is Gaussian noise.
[0067] The definition of the local differential privacy mechanism is:
[0068] For two datasets D and D', if there are only individual differences between the two datasets and the performance of a random algorithm A on the two datasets is within a certain range, then it can be considered that the randomized algorithm A satisfies differential privacy.
[0069] The parameter ε i represents the privacy budget of the i-th client; the parameter δ i is the allowable error of differential privacy for the i-th client, usually a small constant, which provides a certain "elasticity" for the random algorithm to slightly exceed the specified privacy protection range in extremely rare cases.
[0070] ε iThe smaller it is, the more similar the probability distributions of the randomized algorithm A acting on a pair of adjacent data sets (such as data sets D and D’) will be, the more difficult it will be for an attacker to distinguish this pair of adjacent data sets, and the higher the degree of privacy protection will be.
[0071] Step 43, define the variables of the layer sensitivity algorithm, such as select rate, to determine how many important layers to select from the local model update to add differential Gaussian noise. The select rate is set according to the task requirements of each client's local model, that is, it is determined by whether each client's local model focuses more on data security or model performance.
[0072] Step 44, each client uses the local private data set to train the local model.
[0073] Step 45, determine whether the updated gradient exceeds the set clipping threshold (usually 1.0 to avoid gradient explosion). If so, execute Step 46; if not, execute Step 47.
[0074] Step 46, clip the gradient, and clip the L2 norm of the local model gradient with the clipping threshold to limit the influence of individual samples in the local data set.
[0075] Step 47, after each client completes the training of the local model to obtain the local model update, the layer sensitivity algorithm calculates the layer sensitivity of each updated layer of the local model according to the L1 norm of the update gap between the local model update in the current iteration round and the local model update in the previous iteration round, and sorts the layer sensitivities of each updated layer of the local model in descending order;
[0076] According to the descending order of the layer sensitivities of the local model update layers, the layers that need to add noise are selected in order from the top of the descending order of layer sensitivities according to a preset ratio.
[0077] The calculation formula for the layer sensitivity of each updated layer of the local model is:
[0078]
[0079] Among them, are the local model parameters of the j-th updated layer of the local model of the i-th client in the t-th and t+1-th iteration rounds respectively, mean() is the average weight value of the local model parameters, is the layer sensitivity of the j-th updated layer of the local model of the i-th client in the t-th iteration round.
[0080] Step 48, add Gaussian noise to specific layers to achieve local differential privacy.
[0081] The standard deviation of the differential privacy noise is:
[0082]
[0083] Among them, q is the sampling rate, that is, the proportion of clients randomly selected by the server at the current iteration round among all clients in federated learning; t is the current iteration round; δ i is the privacy budget of the i-th client; ε i is the privacy cost of the i-th client; C is the preset clipping threshold; m is the size of the local dataset; Δs is the sensitivity of the differential privacy noise in each iteration round; σ i is the standard deviation of the differential privacy noise.
[0084] Step 49, each client uploads the locally updated model with added noise (parameters or gradients generated by local training) to the server so that the server can aggregate this information to update the global model.
[0085] Introduce local differential privacy mechanism in each client to protect the local dataset (private data) of the client while retaining the distributed characteristics of federated learning and enhancing the security and privacy protection capabilities of federated learning.
[0086] Adopt the layer sensitivity algorithm to optimize the application of the local differential privacy mechanism. By calculating the layer sensitivity of each layer of the local model and adding differential privacy noise to important layers specifically, not only the amount of added noise is reduced, but also the loss of global model performance is reduced, thus balancing the relationship between privacy protection and model accuracy.
[0087] At the same time, each client can autonomously adjust the privacy budget and noise addition strategy according to the task requirements of the local dataset and local model to adapt to different application scenarios and data characteristics.
[0088] The server plays the role of a coordinator in the federated learning system. Through efficient model aggregation and communication management, it enables the local training results distributed on different clients to work together to form a global model with high performance and high security. For the workflow of the server, please refer to Figure 5 .
[0089] Step 51, the server defines the basic variables of the aggregation algorithm.
[0090] Step 52, the server initializes the initial global model.
[0091] Step 53, the server sets the metrics for testing the performance of the global model and initializes the metrics required for testing the model performance.
[0092] Step 54, in each global communication round (each iteration round), the server randomly selects the locally updated models with added noise uploaded by k clients. When iteratively training, each client participates in at least one training.
[0093] Step 55: Aggregate the locally model updates with added noise uploaded by k clients to obtain new global model parameters.
[0094] Step 56: Test the new global model with the test set to determine whether the performance of the new global model on the test set exceeds best_acc. If so, execute Step 57; otherwise, execute Step 58.
[0095] Step 57: Update the global model parameters.
[0096] Step 58: The server distributes the updated global model parameters to each client participating in the training in this global communication round.
[0097] Step 59: Return the final test_acc and end the training of federated learning.
[0098] Each client adds differential privacy noise to the local model update, protecting the privacy of the client's private data. And each client calculates the layer sensitivity according to the L1 norm of the update gap after each global round update, and determines the proportion of the layers to add noise according to the task requirements of each client, so as to select specific layers to add noise. In this way, without significantly affecting the model performance, the defense ability against membership inference attacks can be enhanced. This method based on local differential privacy not only retains the distributed characteristics of federated learning, but also effectively balances the relationship between privacy protection and model accuracy. By applying differential privacy locally, the communication cost is reduced, and at the same time, more flexible privacy control capabilities are provided for each client, which makes the privacy protection method more practical and effective in practical applications.
[0099] This embodiment provides an electronic device, including at least one processing unit and at least one storage unit. Among them, the storage unit stores a computer program, and when the program is executed by the processing unit, the processing unit is enabled to execute the above privacy protection method.
[0100] This embodiment provides a storage medium, which stores a computer program executable by an electronic device. When the program runs on the electronic device, the electronic device is enabled to execute the above privacy protection method.
[0101] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A privacy protection method for federated learning, wherein the federated learning includes a server and multiple clients. During the training process of the federated learning, an attack model is used to perform a member reasoning attack on any client of the federated learning, characterized in that: The method comprises: Obtain a test data set for testing the performance of the server-side global model and initialize the server-side global model parameters; During each iteration of training, the server randomly selects multiple clients to participate in the training and sends the global model parameters of the previous iteration to each selected client; Each client uses the local data set and the global model parameters of the previous iteration round sent by the server to train the local model to generate a local model update. According to the local differential privacy mechanism and layer sensitivity algorithm, differential privacy noise is added to the local model update to protect the privacy of the local data set, and the local model update with differential privacy noise is sent to the server. The server aggregates the local model updates with differential privacy noise uploaded by each client to update the global model parameters, and uses the test dataset to evaluate the performance of the updated global model. Iterate continuously until all clients under federated learning have participated in training at least once and the performance of the global model on the server meets the preset conditions. Then, the training is stopped and the final global model parameters are sent to all clients under federated learning to achieve privacy protection for federated learning.
2. According to claim 1, a privacy protection method for a federated learning model is characterized in that: Each client adds differential privacy noise to the local model update according to the local differential privacy mechanism and the layer sensitivity algorithm, including: After each client completes local model training, it obtains a local model update. The layer sensitivity algorithm calculates the layer sensitivity of each updated layer of the local model based on the L1 norm of the update gap between the local model update of the current iteration round and the local model update of the previous iteration round. According to the local differential privacy mechanism and the layer sensitivity of each update layer of the local model, differential privacy noise is added to the local model update layer.
3. The privacy protection method of a federated learning model according to claim 2, characterized in that: The adding of differential privacy noise to the local model update layer according to the local differential privacy mechanism and the layer sensitivity of each layer of the local model includes: Sort the layer sensitivity of each updated layer of the local model in descending order; According to the descending order of layer sensitivity of the local model update layer, the local model update layer at the top of the descending order of layer sensitivity is selected in sequence according to a preset ratio; The local differential privacy parameters are set according to the local differential privacy mechanism to determine the intensity of the added differential privacy noise, and the differential privacy noise is added to the selected local model update layer.
4. A privacy protection method for a federated learning model according to claim 2 or 3, characterized in that: Before calculating the layer sensitivity of each updated layer of the local model, it is determined whether the gradient of the local model exceeds the preset clipping threshold. If so, the influence of individual samples in the local dataset is limited by gradient clipping.
5. The privacy protection method of a federated learning model according to claim 4, characterized in that: The calculation formula of the layer sensitivity of each update layer of the local model is: in, are the local model parameters of the jth update layer of the local model of the ith client at the tth and t+1th iteration rounds respectively, and mean() is the average weight value of the local model parameters. Layer sensitivity of the jth updated layer of the i-th client local model at the t-th iteration round.
6. The privacy protection method of a federated learning model according to claim 4, characterized in that: The standard deviation of the differential privacy noise is: Among them, q is the sampling rate, that is, the proportion of clients randomly selected by the server in the current iteration round to all clients of federated learning; t is the current iteration round; δ i is the privacy budget of the i-th client; ε i is the privacy cost of the i-th client; C is the preset pruning threshold; m is the size of the local dataset; Δs is the sensitivity of differential privacy noise in each iteration round; σ i is the standard deviation of the differential privacy noise.
7. The privacy protection method of a federated learning model according to claim 3, characterized in that: The preset ratio is set according to the task requirements of the local model of each client.
8. The privacy protection method of a federated learning model according to claim 3, characterized in that: The gradient clipping is to clip the L2 norm of the local model gradient using a clipping threshold.
9. An electronic device, characterized in that: The method comprises at least one processing unit and at least one storage unit, wherein the storage unit stores a computer program, and when the program is executed by the processing unit, the processing unit executes the privacy protection method according to any one of claims 1 to 8.
10. A storage medium, characterized in that: It stores a computer program executable by an electronic device. When the program runs on the electronic device, the electronic device executes the privacy protection method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Layered federal learning method and system applying differential privacy protection
CN113361694A
Federal learning acceleration method based on model segmentation
CN114492746A
Internet of vehicles data privacy protection method based on block chain and ternary federated learning
CN119046973A