Model training method, device and system based on distributed system
By augmenting the original image set in federated learning, an enhanced image set against reconstruction attack is generated, and this image set is used for iterative training in model joint training, the risk of training data privacy leakage in federated learning is solved, and efficient and secure model training is achieved.
Patent Information
- Application Number
- CN202510270534.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-07
- Publication Date
- 2025-06-06
AI Technical Summary
In federated learning, although the parameter gradient sent by local devices to the service device may be attacked by an adversary, thereby inversely deriving the training data, resulting in the risk of privacy leakage of the training data.
By augmenting the original image set before model training, an enhanced image set with anti-reconstruction attack ability is generated, and during the joint training of the model, the target model is iteratively trained by using the enhanced image set, and the sent parameter gradient is calculated based on the enhanced image set.
It improves the privacy and security of training data, reduces the difficulty of the opponent in reconstructing the original image through gradient information, avoids the risk of data leakage, and maintains the efficiency of model training.
Smart Images

Figure CN120107723A_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of artificial intelligence technology, and in particular to a model training method, device and system based on a distributed system. Background Art
[0002] Federated learning allows multiple participants to jointly train the target model without sharing local training data. Specifically, the system architecture of federated learning usually includes a service device and multiple local devices. The service device initializes the target model to be jointly trained and distributes it to each local device. Each local device uses local data to train the target model, obtains the parameter gradient corresponding to the target model, and sends the parameter gradient to the service device. The service device updates the parameters of the target model based on the parameter gradient collected from each local device. In this way, during the entire training process, the training data of each participant is always kept locally, thereby avoiding privacy risks caused by data sharing.
[0003] However, in practical applications, the parameter gradients sent by the local device to the service device may still be attacked by the adversary. The adversary obtains the training data by reverse deduction of the intercepted parameter gradients. This makes the training data still at risk of privacy leakage. Therefore, how to further improve the privacy of training data in the joint training process is an urgent problem to be solved.
[0004] The content of the background technology section is only the information known to the inventor personally, and does not mean that the above information has entered the public domain before the application date of this disclosure, nor does it mean that it can become the prior art of the present disclosure. Summary of the invention
[0005] This specification provides a model training method, device and system based on a distributed system, which can improve the privacy of training data and prevent the leakage of training data during the joint training of models.
[0006] In a first aspect, the present specification provides a model training method based on a distributed system, comprising: the distributed system comprises a service device and multiple local devices, the method is executed by any local device in the distributed system, the method comprises: obtaining an enhanced image set, the enhanced image set is obtained by enhancing an original image set based on at least one target enhancement scheme; performing multiple rounds of iterative training on a target model using the enhanced image set, the target model is a model to be jointly trained by the multiple local devices, and each round of iteration process comprises: obtaining the target model from the service device, inputting an image in the enhanced image set into the target model, and obtaining a parameter gradient of the target model according to an output of the target model, and sending the parameter gradient to the service device so that the service device updates the parameters of the target model based on the parameter gradient; wherein the target enhancement scheme is configured to enhance the original image to obtain an enhanced image, and to make the enhanced image have a capability to resist reconstruction attacks, and the capability to resist reconstruction attacks is characterized by: the difficulty of reconstructing the original image from a first parameter gradient is greater than the difficulty of reconstructing the original image from a second parameter gradient, the first parameter gradient is obtained based on the enhanced image, and the second parameter gradient is obtained based on the original image.
[0007] In a second aspect, the present specification also provides a computing device located in a distributed system, wherein the distributed system includes a service device and multiple local devices, and the computing device is any one of the multiple local devices. The computing device includes: at least one storage medium storing at least one instruction set for performing model training based on a distributed system; and at least one processor communicatively connected to the at least one storage medium, wherein the at least one processor reads the at least one instruction set when running, and executes the model training method based on a distributed system as described in any one of the first aspect above according to the instructions of the at least one instruction set.
[0008] In a third aspect, the present specification also provides a distributed system, including a service device; and multiple local devices, wherein at least some of the multiple local devices are computing devices as described in the second aspect.
[0009] It can be seen from the above technical solutions that the model training method, device and system based on the distributed system provided in this specification, the local device uses the enhanced image set to perform local training on the target model, and sends the parameter gradient corresponding to the target model to the service device, wherein the above-mentioned enhanced image set is obtained by enhancing the original image set based on at least one target enhancement scheme. The target enhancement scheme is configured to enhance the original image to obtain an enhanced image, and make the enhanced image have the ability to resist reconstruction attacks. In this way, the difficulty for the adversary to reconstruct the original image from the first parameter gradient obtained based on the enhanced image is greater than the difficulty for the adversary to reconstruct the original image from the second parameter gradient obtained based on the original image. It can be seen that the method provided in this specification can improve the privacy and security of training data during the joint training of multiple local devices. In addition, since the enhancement processing process of the original image set is pre-performed before model training, the enhancement processing process does not increase the computational overhead of the model training process, thereby maintaining the efficiency of the training process.
[0010] Other functions of the model training method, device and system based on distributed system provided in this specification will be partially listed in the following description. The creative aspects of the model training method, device and system based on distributed system provided in this specification can be fully explained by practicing or using the methods, devices and combinations described in the following detailed examples. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] In order to more clearly illustrate the technical solutions in the embodiments of this specification, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0012] Figure 1 A schematic diagram of an application scenario based on a distributed system provided according to an embodiment of this specification is shown;
[0013] Figure 2 A schematic diagram of the hardware structure of a computing device provided according to some embodiments of this specification is shown;
[0014] Figure 3 A flow chart of a model training method based on a distributed system provided according to an embodiment of this specification is shown; and
[0015] Figure 4 A flow chart of a model training method based on a distributed system provided according to another embodiment of the present specification is shown. DETAILED DESCRIPTION
[0016] The following description provides specific application scenarios and requirements of this specification, with the purpose of enabling those skilled in the art to make and use the contents of this specification. Various local modifications to the disclosed embodiments will be apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments and applications without departing from the spirit and scope of this specification. Therefore, this specification is not limited to the embodiments shown, but to the widest scope consistent with the claims.
[0017] The terms used herein are only used for the purpose of describing specific example embodiments and are not restrictive. For example, unless the context clearly indicates otherwise, as used herein, the singular forms "a", "an" and "the" may also include plural forms. When used in this specification, the terms "include", "comprise" and / or "contain" mean that the associated integers, steps, operations, elements and / or components exist, but do not exclude the existence of one or more other features, integers, steps, operations, elements, components and / or groups or that other features, integers, steps, operations, elements, components and / or groups may be added in the system / method.
[0018] In view of the following description, these and other features of the present specification, as well as the operation and function of the related elements of the structure, and the economy of the combination and manufacture of the parts can be significantly improved. Reference is made to the accompanying drawings, all of which form a part of this specification. However, it should be clearly understood that the drawings are for illustration and description purposes only and are not intended to limit the scope of this specification. It should also be understood that the drawings are not drawn to scale.
[0019] The flowcharts used in this specification illustrate the operations implemented by the system according to some embodiments in this specification. It should be clearly understood that the operations of the flowcharts may not be implemented in sequence. On the contrary, the operations may be implemented in reverse order or simultaneously. In addition, one or more other operations may be added to the flowchart. One or more operations may be removed from the flowchart.
[0020] In this specification, "X includes at least one of A, B or C" means that X includes at least A, or X includes at least B, or X includes at least C. That is, X may include only any one of A, B, and C, or may include any combination of A, B, and C and other possible contents / elements at the same time. The any combination of A, B, and C may be A, B, C, AB, AC, BC, or ABC.
[0021] In this specification, unless explicitly stated otherwise, the association relationship between structures can be a direct association relationship or an indirect association relationship. For example, when describing "A is connected to B", unless it is explicitly stated that A is directly connected to B, it should be understood that A can be directly connected to B or indirectly connected to B; for another example, when describing "A is above B", unless it is explicitly stated that A is directly above B (AB is adjacent and A is above B), it should be understood that A can be directly above B or indirectly above B (AB is separated by other elements and A is above B). And so on.
[0022] It should be noted that the user data obtained in this manual is authorized by the user and does not involve user privacy.
[0023] For the convenience of description, the terms that will appear in the following text of this specification are first explained.
[0024] Federated learning: is a machine learning technology that aims to solve the problem of joint model training among multiple participants (such as different institutions, organizations or devices) without sharing original data. The core idea is to jointly train a global model by exchanging information such as model parameters or gradients between participants instead of directly sharing data. This training method can fully utilize the data of each participant for model training, improve the accuracy and generalization ability of the model, and ensure the privacy and security of the data of each participant.
[0025] Adversary: In federated learning or other related security fields, an adversary refers to an individual, organization, or program that attempts to obtain sensitive information, undermine system security, or interfere with the normal learning process through various means. Adversaries may exploit system vulnerabilities, information leakage during communication, or other attack methods to steal the original data and model parameters of the participants, or attempt to tamper with model update information to destroy the model training effect, obtain commercial secrets, or other malicious purposes.
[0026] In image recognition scenarios, such as in medical systems, financial systems, or face recognition systems, traditional image recognition methods require centralized storage of large amounts of data, and training of image recognition models based on the stored data. However, such training methods limit data sharing and integration due to issues such as data privacy and security. Local devices can only train image recognition models based on their own existing data, so the model performance of image recognition models trained in this way cannot be guaranteed. In order to solve the problems of data privacy and dispersion, the method provided in this specification adopts a federated learning approach, through a distributed training framework, so that the original image sets corresponding to each local device are retained in the local device, and multiple local devices only share the parameters of the target model with the service device, thereby protecting the privacy of the original image set. Under the premise of realizing collaborative modeling between multiple local devices, this distributed training method is implemented. In this way, each local device does not need to upload the original image set, avoiding the risk of information leakage, and the training of the target model is obtained through training with multi-source data (data from multiple local devices), which enhances the generalization ability of the target model.
[0027] In some embodiments, in order to further improve the privacy and security of data, each local device can use two methods, gradient encryption or gradient perturbation, to ensure the privacy and security of data before transmitting the parameter gradient to the service device. Among them, the gradient encryption method is to ensure the privacy and security of the local device by encrypting the parameter gradient to be transmitted by the local device, but such encryption operation consumes a lot of computing and communication, and the training efficiency of the model will be significantly reduced. The gradient perturbation method is to achieve the purpose of protecting data privacy by introducing random noise, but if the introduced noise is weak, it may lead to insufficient privacy protection, and if the introduced noise is strong, it will significantly reduce the accuracy of the model. In other words, whether it is a gradient encryption algorithm or a noise perturbation algorithm, it will have a certain impact on the training of the model and increase the computational overhead during the training process.
[0028] Therefore, in order to further improve the privacy and security of data without affecting model training, the model training method based on a distributed system provided in this specification performs multiple rounds of iterative training on the target model using the enhanced image set for any local device in the distributed system after the local device obtains the enhanced image set, wherein each round of iterative process includes: the local device obtains the target model from the service device, inputs the image in the enhanced image set into the target model, and obtains the parameter gradient of the target model according to the output of the target model. Then the local device sends the parameter gradient to the service device, so that the service device updates the parameters of the target model based on the parameter gradient sent by each local device.
[0029] Among them, the enhanced image set is obtained by enhancing the original image set based on at least one target enhancement scheme, and the enhanced image after the enhancement processing has the ability to resist reconstruction attacks. The ability to resist reconstruction attacks indicates that the difficulty of reconstructing the original image from the first parameter gradient is greater than the difficulty of reconstructing the original image from the second parameter gradient, the first parameter gradient is obtained based on the enhanced image, and the second parameter gradient is obtained based on the original image. For some adversaries who want to attack the original image of the local device, the adversary faces the parameter gradient of the target model obtained by training based on the enhanced image set, and the possibility of reconstructing the original image based on such a parameter gradient is greatly reduced. And in the above-mentioned process of jointly training the target model through multiple local devices, the target model finally obtained is obtained after performing multiple rounds of iterative training on the target model based on the enhanced image set, each round of iteration is based on The enhanced image set calculates the parameter gradient of the target model, and the parameter gradient of each round is affected by the enhanced image set. As the iteration proceeds, the parameters of the target model will be gradually updated, and these updates are all realized based on the parameter gradient of the enhanced image with anti-reconstruction characteristics. In other words, the gradient information obtained by the adversary is the result of multiple rounds of calculation and updating based on the enhanced image. These gradient information no longer have clear features that directly correspond to the original image. The difficulty for the adversary to reconstruct the original image from these complex gradients that have undergone multiple rounds of transformation will be further increased.
[0030] That is to say, in the method provided in this specification, a distributed joint training method is adopted to ensure the data privacy of each local device, and for each local device, before the local device trains the target model based on the data set, it is also necessary to enhance the original image set based on at least one target enhancement scheme to obtain an enhanced image set with anti-reconstruction attack capability, and then train the target model based on the enhanced image set, and synchronize the parameter gradients of the target model of each local device to the service device, so that the service device updates the parameters of the target model based on the parameter gradient. In such a distributed training method, since each local device generates a first parameter gradient based on the enhanced image set, the parameter gradient of the enhanced image has lost the clear characteristics of the original image, so it is difficult for the adversary to reconstruct the original image based on the first parameter gradient. Even if the adversary obtains the parameter gradient generated based on the enhanced image, it is difficult to restore the original image from it. That is, by adopting the method provided in this specification, the original image set of each local device is enhanced based on at least one target enhancement scheme, and the combined effect of multiple factors such as multiple rounds of iterative training and the characteristics of the distributed system is adopted, which effectively prevents the adversary from reconstructing the original image through the gradient, thereby improving the privacy and security of the data.
[0031] It should be noted that the above description of the application scenario is only one of the multiple usage scenarios provided in this specification. Those skilled in the art should understand that when the model training method, device and system based on the distributed system provided in this specification are applied to other usage scenarios, their implementation methods and technical effects are similar.
[0032] Figure 1 A schematic diagram of an application scenario 100 of a distributed system provided according to an embodiment of this specification is shown.
[0033] like Figure 1 As shown, the application scenario may include multiple local devices 110 and a service device 130. In the application scenario 100, each local device 110 has its own corresponding image set. Among them, the image set on each local device 110 includes the original image set and the enhanced image set corresponding to the local device 110. For each local device 110, the original image set can be obtained by the local device in the local data by randomly extracting a preset number of images. The enhanced image set can be obtained by the local device after enhancing the original image set using at least one target enhancement scheme, so that the enhanced image in the enhanced image set has the ability to resist reconstruction attacks, and then, each local device 110 performs multiple rounds of iterative training on the target model using the enhanced image set.
[0034] Among them, the process of each local device 110 in each round of iterative training includes: the local device 110 obtains the target model from the service device 130, inputs the image in the enhanced image set into the target model, and obtains the parameter gradient of the target model according to the output of the target model, and sends the parameter gradient to the service device 130, so that the service device 130 updates the parameters of the target model based on the parameter gradient.
[0035] In some embodiments, the local device 110 may be an electronic device with certain computing capabilities. The model training method based on a distributed system may be executed on the local device 110, and may be specifically executed by a processor in the local device 110. At this time, the local device 110 stores data or instructions for executing the model training method based on a distributed system described in this specification, and may execute or be used to execute the data or instructions. The local device 110 may include a hardware device with a question-and-answer function based on tabular data and a program required to drive the hardware device to work.
[0036] The local device 110 may be a single computing device or a cluster system composed of multiple computing devices, which is not limited in this specification.
[0037] It should be noted that the user data obtained in this manual has been authorized by the user and does not involve user privacy.
[0038] Figure 2 A hardware structure diagram of a computing device 200 provided according to some embodiments of this specification is shown. The computing device 200 can be used as Figure 1 In some embodiments, when the local device 110 adopts a device cluster (including multiple local devices 110), the computing device 200 can act as any one of the local devices 110.
[0039] like Figure 2 As shown, computing device 200 includes at least one storage medium 230 and at least one processor 220. In some embodiments, computing device 200 may further include an internal communication bus 210. In some embodiments, computing device 200 may further include a communication port 250. In some embodiments, computing device 200 may further include an I / O component 260.
[0040] Internal communication bus 210 may connect various system components, including storage media 230 and processor 220. I / O components 260 support input / output between computing device 200 and other components.
[0041] The communication port 250 is used for data communication between the computing device 200 and the outside world. For example, the computing device 200 can be connected to a network through the communication port 250.
[0042] The storage medium 230 may include a data storage device. The data storage device may be a non-temporary storage medium or a temporary storage medium. For example, the data storage device may include one or more of a disk 232, a read-only storage medium (ROM) 234, or a random access storage medium (RAM) 236. The storage medium 230 also includes at least one instruction set stored in the data storage device. The instruction set is a computer program code, and the computer program code may include programs, routines, objects, components, data structures, processes, modules, etc. that execute the model training method based on a distributed system provided in this specification.
[0043] At least one processor 220 is connected to at least one storage medium 230 via an internal communication bus 210. At least one processor 220 is used to execute the at least one instruction set. When the system 130 is running, at least one processor 220 reads at least one instruction set and executes the model training method based on the distributed system provided in this specification according to the instructions of at least one instruction set.
[0044] Processor 220 can execute all steps included in the model training method based on a distributed system. Processor 220 can be in the form of one or more processors. Processor 220 can issue execution instructions. Processor 220 may include one or more hardware processors, such as a microcontroller, a microprocessor, a reduced instruction set computer (RISC), an application-specific integrated circuit (ASIC), an application-specific instruction set processor (ASIP), a central processing unit (CPU), a graphics processing unit (GPU), a physical processing unit (PPU), a microcontroller unit, a digital signal processor (DSP), a field programmable gate array (FPGA), an advanced RISC machine (ARM), a programmable logic device (PLD), any circuit or processor capable of performing one or more functions, etc., or any combination thereof.
[0045] For illustrative purposes only, only one processor 220 is shown in the computing device 200 in the attached drawings in this specification. However, it should be noted that the computing device 200 in this specification may also include multiple processors, and therefore, the operations and / or method steps disclosed in this specification may be performed by one processor as in this specification, or may be performed jointly by multiple processors. For example, if the processor 220 of the computing device 200 in this specification performs step A and step B, it should be understood that step A and step B may also be performed jointly or separately by two different processors 220 (e.g., the first processor performs step A, the second processor performs step B, or the first and second processors perform steps A and B together).
[0046] Figure 3 A flow chart of a model training method based on a distributed system according to an embodiment of the present specification is shown; the model training method based on a distributed system P300 can be executed by any local device 110 in the distributed system. Figure 3 As shown, the method P300 provided in this specification may include S310-S330, wherein:
[0047] S310: Obtain an enhanced image set, where the enhanced image set is obtained by performing enhancement processing on the original image set based on at least one target enhancement scheme.
[0048] In some embodiments, the local device may obtain multiple preset enhancement schemes, and determine at least one target enhancement scheme from the multiple preset enhancement schemes based on the original image set D. Then, the local device performs enhancement processing on each original image in the original image set based on the at least one target enhancement scheme to obtain an enhanced image set D. Among them, the anti-reconstruction attack capability of the enhanced image generated based on the target enhancement scheme is greater than the anti-reconstruction attack capability of the enhanced image generated based on other enhancement schemes.
[0049] Among them, the local device can traverse the original images in the original image set, randomly select a target enhancement scheme from at least one target enhancement scheme as the current enhancement scheme for the current original image, and enhance the current original image based on the current enhancement scheme to obtain an enhanced image, and then, the local device adds the enhanced image to the enhanced image set.
[0050] In some embodiments, multiple preset enhancement schemes may constitute an initial enhancement scheme set. Where a single preset enhancement scheme T = t 1 ×t 2 ×...×t n , indicating that each preset enhancement scheme is composed of a combination of multiple randomly selected data enhancement algorithms in sequence, where t 1 ,t 2 ,...,t n Represents multiple randomly selected data enhancement algorithms. The multiple preset enhancement schemes may be determined by: obtaining multiple enhancement algorithms and multiple enhancement amplitude information corresponding to each enhancement algorithm. Then, the following steps are repeated until multiple preset enhancement schemes are obtained: the local device randomly selects at least one target enhancement algorithm from the multiple enhancement algorithms, and determines the target enhancement amplitude information from the multiple enhancement amplitude information corresponding to each target enhancement algorithm. Furthermore, the local device generates a preset enhancement scheme based on the at least one target enhancement algorithm and the target enhancement amplitude information corresponding to each target enhancement algorithm.
[0051] In some embodiments, the multiple enhancement algorithms may include: an overall enhancement algorithm and / or a local enhancement algorithm. The overall enhancement algorithm is used to adjust the position, brightness, and color of the entire pixel of the original image without distinguishing the image content of the original image. The local enhancement algorithm first requires the local device to segment the original image so that the original image includes multiple regions. Then, the local device randomly masks some of the multiple regions of the original image based on the number of regions to be masked to obtain an intermediate result image.
[0052] The enhancement range of the overall enhancement algorithm may include: rotation angle, cropping range, translation range, etc. The current enhancement scheme may include an overall enhancement algorithm and its corresponding target enhancement range information, as well as a local enhancement algorithm and its corresponding target enhancement range information. The local device may enhance a part of the current original image based on the local enhancement algorithm and its corresponding target enhancement range information to obtain an intermediate result image. Furthermore, the local device enhances the entire intermediate result image based on the overall enhancement algorithm and its corresponding target enhancement range information.
[0053] It should be understood that different overall enhancement algorithms may have multiple preset enhancement ranges. For example, some overall enhancement algorithms may have multiple preset enhancement ranges. When determining the enhancement range corresponding to the target overall enhancement algorithm, an enhancement range may be randomly determined from the preset multiple enhancement ranges. Some overall enhancement algorithms may have a preset enhancement range. When determining the enhancement range corresponding to the target overall enhancement algorithm, an enhancement range may be randomly determined from the preset enhancement range.
[0054] The enhancement amplitude of the local enhancement algorithm is used to characterize the number of areas to be masked. The method for determining the number of areas to be masked can be: within the preset mask number range, a preset mask number is randomly determined as the number of areas to be masked. The preset mask number is positively correlated with the number of areas included in the original image after segmentation.
[0055] When each original image in the original image set is a face image, the multiple regions are regions obtained by dividing the face in the original image. The face division method can be: directly dividing the face in the original image according to a preset division method, for example, dividing the face in the original image into 9*9 images. Alternatively, dividing the face in the original image according to preset face regions to obtain multiple divided face regions.
[0056] Still taking the division of faces in the original image according to the preset face regions as an example, for a face image x∈R C×H×W , where C represents the number of channels, H represents the height of the face image, and W represents the width of the face image. Assuming that the function F represents the face segmentation process, the segmentation result can be expressed as M x =F(x),M x ∈Z H×W , The segmentation result is a two-dimensional grid of size H×W, where the value of each grid represents a category label of 1 to m, and m represents the total number of category labels. For example, m can be 25, and the area labels included in the preset face area can be as shown in Table 1 below. It should be understood that the face area shown in Table 1 is only an exemplary description, and the preset face area can also include: eyes, eyebrows, chin, ears, mouth, neck, glasses, hair, clothing, headdress, cheeks, forehead and other division methods. The specific division method of the preset face area and the number of area divisions can be flexibly adjusted according to user needs, and are not limited to the above embodiments.
[0057] Table 1
[0058] Serial number Label Serial number Label Serial number Label Serial number Label 1 Headdress 8 Middle forehead 15 Left eyebrow 22 hair 2 Right cheek 9 Left eye area 16 Right eyebrow 23 Clothing 3 Left cheek 10 Right eye area 17 left ear 24 Glasses 4 Left chin 11 mouth 18 Right ear 25 background 5 Right chin 12 nose 19 Upper lip 6 Left forehead 13 Left Eye 20 Lower lip 7 Right forehead 14 Right eye 21 neck
[0059] Table 2 below shows some possible examples of multiple enhancement algorithms, where the local area mask in Table 2 is to mask part of the area to be masked in the original image. It should be understood that the algorithms shown in Table 2 are only exemplary, and the multiple enhancement algorithms may include some of the enhancement algorithms in Table 2, and may also include other enhancement algorithms in addition to Table 2. The algorithm content included in the specific multiple enhancement algorithms can be flexibly adjusted according to user needs, and is not limited to the following embodiments, as shown in Table 2:
[0060] Table 2
[0061] Serial number Enhanced Algorithm Serial number Enhanced Algorithm Serial number Enhanced Algorithm 1 Image Flip 6 Sharpness Adjustment 11 Color Adjustment 2 Contrast adjustment 7 Vertical cropping 12 Brightness Adjustment 3 Rotation 8 Auto Contrast 13 Exposure Reversal 4 Horizontal Pan 9 Histogram Equalization 14 Local area mask 5 Vertical Pan 10 Color separation
[0062] Among them, the target enhancement scheme is an enhancement scheme with the following capabilities among multiple preset enhancement schemes: for the target enhanced image generated by the target enhancement scheme, when the similarity between any reference image and the target enhanced image is greater than the preset similarity, the difference between the parameter gradient obtained based on the target enhanced image and the parameter gradient obtained based on the reference image is greater than the preset difference. Such a setting method makes it difficult for the adversary to infer the feature original data of the original image from the gradient information even if the adversary obtains the parameter gradient of the local device because the target enhancement scheme makes the difference between the gradients even between similar images very large. Even if the adversary obtains the parameter gradient of the local device, it is difficult to infer the feature original data of the original image from the gradient information. Even if the adversary generates reference images (reconstructed images) that approximate the enhanced images, the difference in parameter gradients between these reference images and the real enhanced images is still greater than the preset difference, thereby greatly increasing the difficulty of the adversary's reconstruction, protecting the privacy of the data, and ensuring the security and reliability of the target model.
[0063] In some embodiments, when determining at least one target enhancement scheme, the local device can perform usability evaluation on multiple preset enhancement schemes based on the original image set to obtain a first evaluation result, and the first evaluation result is used to characterize the degree of influence of the preset enhancement scheme on the model performance of the target model. Based on the first evaluation result, the local device determines multiple candidate enhancement schemes from multiple preset enhancement schemes, and the degree of influence of the candidate enhancement scheme on the model performance is less than the degree of influence of other enhancement schemes on the model performance. The local device determines multiple candidate enhancement schemes based on the first evaluation result. By selecting an enhancement scheme with a small degree of influence on the model performance as a candidate enhancement scheme, it can be ensured that when the data is enhanced in the subsequent data, the key indicators such as the accuracy and generalization ability of the model will not be reduced due to the unreasonable selection of the enhancement scheme, and the effect of the model in subsequent training and application is guaranteed. In addition, the selection of candidate enhancement schemes can exclude those enhancement schemes that have a greater impact on the model performance, focus on the enhancement schemes that have a smaller impact on the model performance, and make the model training process more stable and efficient. It avoids the problems of large fluctuations in model training and slow convergence caused by the use of inappropriate enhancement schemes, saving the training time and computing resources of the model.
[0064] In some embodiments, the usability evaluation process may include: the local device performs enhancement processing on multiple original images in the original image set based on a preset enhancement scheme to obtain multiple enhanced images, and inputs the multiple enhanced images into the target model to obtain multiple output information of the target model. The local device determines the target matrix corresponding to the preset enhancement scheme based on the multiple enhanced images and the multiple output information, and the target matrix represents the sensitivity of the output of the target model to the input. Then, the local device determines the first evaluation result corresponding to the preset enhancement scheme based on the target matrix. It should be understood that the above embodiments are only exemplary descriptions, and the usability of each preset enhancement scheme can also be evaluated by cross-validation method, retention method, meta-learning evaluation, information entropy evaluation and other methods. The specific method of evaluating the usability of each preset enhancement scheme can be flexibly adjusted according to user needs, and is not limited to the above embodiments.
[0065] In some embodiments, the target matrix may be a gradient Jacobian matrix. That is, the local device may determine the correlation coefficient matrix corresponding to the preset enhancement scheme based on the gradient Jacobian matrix, and extract the eigenvalue of the correlation coefficient matrix, and then the local device determines the first evaluation result corresponding to the preset enhancement scheme based on the eigenvalue. The above method of determining the first evaluation result corresponding to the preset enhancement scheme based on the gradient Jacobian matrix uses the eigenvalue as an intuitive and effective indicator to measure the degree of influence of the enhancement scheme on the model performance, avoids the bias of subjective judgment, and improves the objectivity and accuracy of the evaluation. At the same time, the above method takes into account the overall characteristics of the model, rather than focusing only on a single performance indicator, so that the evaluation results are more comprehensive and reliable, which helps to screen out candidate enhancement schemes that have better effects on improving model performance.
[0066] Assuming the target model is f, after N original images are enhanced using the target enhancement scheme T, the N enhanced images obtained constitute the enhanced image set The gradient Jacobian matrix J represents the sensitivity of the model output to the input image. The gradient Jacobian matrix J is defined as:
[0067]
[0068] On this basis, the correlation coefficient matrix R of the gradient Jacobian matrix is calculated. For example, for the i-th column and the k-th column in the gradient Jacobian matrix J, the correlation coefficient R i,k The calculation method is:
[0069]
[0070] Where N represents the total number of rows in the gradient Jacobian matrix J, Represents the column vector J i The mean of Represents the column vector Jk The mean value, J ji Represents the vector value of the jth row and the ith column, J jk Represents the vector value of the jth row and kth column.
[0071] Assume σ J,1 ≤…≤σ J,N is the N eigenvalues of the matrix R, then the first evaluation result (availability index) corresponding to the preset enhancement solution S a (T) can be defined as:
[0072] Wherein, ∈ is a preset constant value. In some embodiments, ∈=10 -5 Of course, the above embodiment is only an exemplary description, and the value of ∈ can also be any other value. a The larger the (T) is, the more balanced the distribution of the enhanced images in terms of data features is, and the higher the match between the enhanced image set and the model is, which means that the model can achieve better performance after training.
[0073] Initial Enhanced Solution Set for Local Devices The first evaluation result of each preset enhancement scheme is calculated to obtain a candidate enhancement scheme set consisting of multiple candidate enhancement schemes. in, Represents the initial enhancement scheme set, and ε represents the filtering threshold. Through the above method, the local device can effectively filter out the preset enhancement schemes that have a greater impact on the recognition performance of the target model, and only retain the candidate enhancement schemes that have a higher matching degree with the target model.
[0074] After determining the candidate enhancement schemes, the local device performs privacy assessments on multiple candidate enhancement schemes based on the original image set to obtain a second assessment result, which characterizes the ability of the enhanced image generated by the candidate enhancement scheme to resist reconstruction attacks. Further, based on the second assessment result, the local device determines at least one target enhancement scheme from the multiple candidate enhancement schemes, and the at least one target enhancement scheme constitutes a target enhancement scheme set. The above method can screen out a target enhancement scheme with stronger privacy protection ability from multiple candidate enhancement schemes, making it more difficult for the adversary to obtain the original image through reconstruction attack based on the enhanced image generated based on the target enhancement scheme, greatly enhancing the security and privacy of the data and providing more practical protection for data privacy.
[0075] In some embodiments, the process of the local device performing a privacy assessment may be: the local device performs enhancement processing on multiple original images in the original image set based on the candidate enhancement scheme to obtain multiple enhanced images. The local device generates multiple control images corresponding to the enhanced image for each enhanced image in the multiple enhanced images. The local device determines the gradient similarity based on the enhanced image and the multiple control images, and the gradient similarity represents the degree of similarity between the parameter gradient obtained based on the enhanced image and the parameter gradient obtained based on the multiple control images, and the similarity between the multiple control images and the enhanced image is different. Furthermore, the local device determines the anti-reconstruction index of the candidate enhancement scheme based on the gradient similarity corresponding to each of the multiple enhanced images, and determines the second evaluation result of the candidate enhancement scheme based on the anti-reconstruction index.
[0076] This method of generating the second evaluation result does not require the actual execution of the reconstruction attack on the enhanced image, and the second evaluation result can be determined by simulating the attack. It should be understood that the above embodiment is only an exemplary description, and the method for determining the second evaluation result of the candidate enhancement scheme can also be an evaluation method using an adversarial attack, an evaluation method based on feature extraction and comparison, an evaluation method based on statistical analysis, etc. The specific method for determining the second evaluation result can be flexibly adjusted according to user needs and is not limited to the above embodiment.
[0077] For a data enhancement scheme with strong privacy protection, when the control image (reconstructed image) approaches the enhanced image, a large gradient difference can still be maintained. Therefore, the anti-reconstruction index S p (T) is defined as:
[0078]
[0079] x′(i)=(1-i)*x 0 +i*T(x).
[0080] Where D represents the original image set, x 0 represents the initial noise reconstructed image. When i→1, the control image x′(i) gradually approaches the enhanced image T(x). G is the gradient similarity calculation algorithm. For example, for the sample m with the true label y and the control sample m′, the gradient similarity calculation can be expressed as The above G(m′,m) reflects the gradient matching degree between sample m and reference sample m′. p The smaller (T) is, the greater the gradient difference is when the control image approaches the enhanced image, and the more difficult the reconstruction attack is. The local device calculates the candidate enhancement solution set based on the original image set D The candidate enhancement scheme set includes multiple candidate enhancement schemes, and the anti-reconstruction index of each candidate enhancement scheme is sorted in ascending order, and the one with the smallest index value is selected. The target enhancement scheme set Indicates the sorting result in ascending order based on the anti-reconstruction index.
[0081] It can be seen that the method provided in this specification first combines the data enhancement algorithms to obtain multiple initial enhancement schemes, and then screens the candidate enhancement schemes from the multiple initial enhancement schemes based on the model performance, and then determines the target enhancement scheme based on privacy. In the above method, on the one hand, the recognition ability of the target model is guaranteed by filtering out the enhancement schemes that have a greater impact on the training performance. On the other hand, by selecting a data enhancement strategy with strong resistance to data reconstruction attacks, the privacy of the local device is effectively protected, thereby achieving a balance between model performance and privacy protection. In other words, the method provided in this specification not only takes into account the effect and efficiency of model training, but also pays full attention to the privacy security of the data, avoids the problem of only focusing on one side and ignoring the other side, and makes the final target enhancement scheme more practical and reliable in practical applications. At least one target enhancement scheme determined by the above two rounds of evaluation can make at least one target enhancement scheme better adapt to the specific original image set and target model. Since the determination of the target enhancement scheme is a targeted evaluation and selection based on the characteristics of the actual data and the target model, the target enhancement scheme can be closely combined with the task requirements of the local device, and can play a better role in different application scenarios and data environments.
[0082] It should be understood that, when determining at least one target enhancement scheme, in order to ensure the accuracy of the at least one target enhancement scheme determined, so as to improve the ability of the subsequent enhanced image set to resist reconstruction attacks, each local device can determine at least one target enhancement scheme corresponding to each local device based on multiple preset enhancement schemes. Alternatively, in order to improve the efficiency of determining at least one target enhancement scheme, one local device among multiple local devices can also determine at least one target enhancement scheme based on multiple preset enhancement schemes, and synchronize the at least one target enhancement scheme to other local devices. The above embodiments are only exemplary, and the specific method of determining at least one target enhancement scheme can be flexibly adjusted according to user needs, and is not limited to the above embodiments.
[0083] In some embodiments, the segmentation of the original image and the generation of the target enhancement scheme can be completed before the distributed training begins, avoiding overlap with the actual training process of the target model, thereby ensuring that the target model does not introduce additional computational overhead during the distributed training process, reducing the computational overhead while maintaining the efficiency of the training process.
[0084] S330: Perform multiple rounds of iterative training on a target model using the enhanced image set, where the target model is a model to be jointly trained by multiple local devices.
[0085] Among them, in each iteration process of multiple rounds of iterative training, each local device 110 among the multiple local devices 110 performs similar steps based on the enhanced image set. The following takes the i-th iteration as an example to introduce the specific situation of the local device 110 executing S330. It should be understood that the steps performed by the local device in other iteration processes are similar and will not be repeated.
[0086] S331: Obtain a target model from a service device, input an image in the enhanced image set into the target model, and obtain a parameter gradient of the target model according to an output of the target model.
[0087] Since the local device obtains the target model from the service device during each iteration and calculates the gradient parameters of the target model based on the enhanced image set, multiple local devices in the distributed system can calculate the parameter gradients of their corresponding target models in parallel, which improves the overall training efficiency and accelerates the training process of the target model.
[0088] In a distributed training scenario, since the original image data may include sensitive information, the method provided in this specification performs multiple rounds of iterative training on the target model through an enhanced image set, avoiding direct exposure of the original image, thereby protecting the privacy of the data. In addition, since the enhanced images are obtained after enhancement processing based on the target enhancement scheme, and each round of iteration calculates the parameter gradient of the target model based on the enhanced image, the parameter gradient of each round is affected by the enhanced image. As the iteration proceeds, the parameters of the target model are continuously updated, and these updates are based on the parameter gradient of the enhanced image with anti-reconstruction characteristics. Therefore, the direct correlation between the parameter gradient of the target model obtained by each local device based on the enhanced image and the original image is weakened, thereby effectively preventing the adversary from using the gradient information to reversely deduce the original data.
[0089] S333: Sending parameter gradients to the service device so that the service device updates the parameters of the target model based on the parameter gradients; wherein the target enhancement scheme is configured to enhance the original image to obtain an enhanced image, and to make the enhanced image resistant to reconstruction attacks, and the resistant to reconstruction attacks is characterized by: the difficulty of reconstructing the original image from the first parameter gradient is greater than the difficulty of reconstructing the original image from the second parameter gradient, the first parameter gradient is obtained based on the enhanced image, and the second parameter gradient is obtained based on the original image.
[0090] In the above training method, each local device only sends parameter gradients to the service device, reducing the overhead and privacy risks during data transmission. The gradient information obtained by the adversary is the result of multiple rounds of calculations and updates based on enhanced images. These gradient information no longer have clear features that directly correspond to the original image. The difficulty for the adversary to reconstruct the original image from these complex gradients that have undergone multiple rounds of transformations will be greatly increased. In other words, the method of performing multiple rounds of iterative training on the target model based on the enhanced image set can enable the target model to better resist the attack of the adversary and ensure the security and reliability of the target model.
[0091] In some embodiments, the service device may update the parameters of the target model in an average manner based on the parameter gradients sent by each local device. Alternatively, due to the different levels of trust the service device has in different local devices, different local devices may have different preset weights. In the process of the service device updating the parameters of the target model, the parameters of the target model may be updated based on the preset weights of each local device and the parameter gradients sent by each local device. It should be understood that the above embodiments are only exemplary, and the specific service device can update the parameters of the target model in a flexible manner according to user needs, and is not limited to the above embodiments.
[0092] Figure 4 A flow chart of a model training method based on a distributed system according to another embodiment of this specification is shown. Taking the method provided in this specification as an example of applying the method provided in this specification to the training scenario of a face recognition model, the method provided in this specification constructs a target enhancement scheme set. Used in the face recognition model training process of the local device to protect the privacy of the local data of the local device.
[0093] The specific process is as follows Figure 4 As shown in the figure. Before starting the joint training of the target model, the local device first performs random batch sampling based on the local image set to obtain the original image set D. The local device performs face region segmentation (image segmentation) on the original image set to obtain the segmentation result of each original face image. When the local device performs data enhancement on each original image in the original image set, it first starts from the target enhancement scheme. Randomly select a target enhancement scheme T * , and then use T * The original image is data enhanced to obtain the enhanced image corresponding to the original image. After data enhancement is performed on each original image in the original image set, the enhanced image set can be obtained. Then, the local device uses the enhanced data set to replace the original image set to train the target model. After the local device obtains the target model from the service device, it performs multiple rounds of target model training based on the enhanced image set. In each round of training, the local device determines the parameter gradient of the target model based on the enhanced image set, and submits the parameter gradient update of the local device to the service device, so that the service device updates the parameters of the target model based on the parameter gradient sent by each local device.
[0094] In summary, the model training method, device and system based on a distributed system provided in this specification, in the process of joint training of the target model, will use the acquired enhanced image set to perform multiple rounds of iterative training on the target model, and the target model is a model to be jointly trained by multiple local devices. In each round of iteration, each local device obtains the target model from the service device, inputs the image in the enhanced image set into the target model, and obtains the gradient parameters of the target model according to the output of the target model. Each local device sends a parameter gradient to the service device so that the service device updates the parameters of the target model based on the parameter gradient. In the above method, the target enhancement scheme is configured to enhance the original image to obtain an enhanced image, and the enhanced image has the ability to resist reconstruction attacks. The difficulty of reconstructing the original image from the first parameter gradient obtained based on the enhanced image is greater than the difficulty of reconstructing the original image from the second parameter gradient obtained based on the original image. The method provided in this specification achieves the goal of not having to perform complex encryption or perturbation operations on parameter gradients. It only requires enhancing the original image based on the target enhancement scheme before jointly training the target model to obtain an enhanced image set, and then performing multiple rounds of iterative training on the target model based on the enhanced image set. This greatly reduces the computational overhead while maintaining the efficiency of the training process.
[0095] On the other hand, the present specification provides a computer-readable non-transitory storage medium storing at least one instruction set for performing executable instructions of a model training method based on a distributed system. When at least one instruction set is executed by a processor, at least one instruction set instructs the processor to implement the steps of the model training method P300 based on a distributed system of the present specification. In some possible implementations, various aspects of the present specification may also be implemented in the form of a program product, which includes a program code. When the program product is run on a local device 110, the program code is used to cause the local device 110 to perform the steps of the method P300 described in the present specification. The program product for implementing the above method may include a portable compact disk read-only memory (CD-ROM) including program code and may be run on a local device 110. However, the program product of the present specification is not limited thereto. In the present specification, a readable storage medium may be any tangible medium containing or storing a program, which may be used by an instruction execution system or used in combination therewith. The program product may use any combination of one or more readable media. The readable medium may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination thereof. More specific examples of readable storage media include: an electrical connection with one or more conductors, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. A computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, wherein a readable program code is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable storage medium may also be any readable medium other than a readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, device, or device. The program code contained on the readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the above. The program code for performing the operations of this specification can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and conventional procedural programming languages such as "C" language or similar programming languages.
[0096] The above is a description of a specific embodiment of the present specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require a specific order or a continuous order to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0097] In summary, after reading this detailed disclosure, those skilled in the art will appreciate that the foregoing detailed disclosure may be presented only by way of example and may not be limiting. Although not explicitly stated herein, those skilled in the art will appreciate that this specification requires various reasonable changes, improvements, and modifications to the embodiments. These changes, improvements, and modifications are intended to be proposed by this specification and are within the spirit and scope of the exemplary embodiments of this specification.
[0098] In addition, certain terms in this specification have been used to describe embodiments of this specification. For example, "one embodiment", "an embodiment" and / or "some embodiments" mean that a particular feature, structure or characteristic described in conjunction with the embodiment may be included in at least one embodiment of this specification. Therefore, it can be emphasized and should be understood that two or more references to "an embodiment" or "one embodiment" or "an alternative embodiment" in various parts of this specification do not necessarily refer to the same embodiment. In addition, specific features, structures or characteristics may be appropriately combined in one or more embodiments of this specification.
[0099] It should be understood that in the foregoing description of the embodiments of this specification, in order to help understand a feature and for the purpose of simplifying this specification, this specification combines various features in a single embodiment, figure or its description. However, this does not mean that the combination of these features is necessary. When reading this specification, it is entirely possible for a person skilled in the art to mark out some of the devices as separate embodiments. In other words, the embodiments in this specification can also be understood as the integration of multiple secondary embodiments. And the content of each secondary embodiment is also valid when it is less than all the features of a single aforementioned disclosed embodiment.
[0100] Each patent, patent application, publication of patent application, and other materials, such as articles, books, specifications, publications, documents, documents, etc., cited in this disclosure (excluding any historical review documents related thereto) are hereby incorporated by reference for all purposes related to this disclosure, such as in the specification and claims of this disclosure. However, if there is any inconsistency or conflict between the descriptions, definitions, and / or terminology of the above materials and the descriptions, definitions, and / or terminology used in this disclosure, the descriptions, definitions, and / or terminology used in this disclosure shall prevail.
[0101] Finally, it should be understood that the embodiments of the application disclosed herein are explanations of the principles of the embodiments of this specification. Other modified embodiments are also within the scope of this specification. Therefore, the embodiments disclosed in this specification are only used as examples and not as limitations. Those skilled in the art can adopt alternative configurations according to the embodiments in this specification to implement the applications in this specification. Therefore, the embodiments of this specification are not limited to the embodiments accurately described in the application.
Claims
1. A model training method based on a distributed system, wherein the distributed system includes a service device and multiple local devices, and the method is executed by any local device in the distributed system, and the method includes: Obtaining an enhanced image set, wherein the enhanced image set is obtained by performing enhancement processing on the original image set based on at least one target enhancement scheme; Perform multiple rounds of iterative training on a target model using the enhanced image set, where the target model is a model to be jointly trained by the multiple local devices, and each round of iterative training includes: obtaining the target model from the service device, inputting the image in the enhanced image set into the target model, and obtaining the parameter gradient of the target model according to the output of the target model, Sending the parameter gradient to the service device so that the service device updates the parameters of the target model based on the parameter gradient; Among them, the target enhancement scheme is configured to enhance the original image to obtain an enhanced image, and make the enhanced image have the ability to resist reconstruction attacks, and the anti-reconstruction attack capability is characterized by: the difficulty of reconstructing the original image from a first parameter gradient is greater than the difficulty of reconstructing the original image from a second parameter gradient, the first parameter gradient is obtained based on the enhanced image, and the second parameter gradient is obtained based on the original image.
2. The method of claim 1, wherein: The step of obtaining an enhanced image set comprises: Get multiple preset enhancement schemes; Based on the original image set, determining at least one target enhancement scheme from the plurality of preset enhancement schemes, wherein the anti-reconstruction attack capability of the enhanced image generated based on the target enhancement scheme is greater than the anti-reconstruction attack capability of the enhanced image generated based on other enhancement schemes; and Based on the at least one target enhancement scheme, each original image in the original image set is enhanced to obtain the enhanced image set.
3. The method of claim 2, wherein: The target enhancement scheme is an enhancement scheme among the multiple preset enhancement schemes that has the following capabilities: for a target enhanced image generated by the target enhancement scheme, when the similarity between any control image and the target enhanced image is greater than a preset similarity, the difference between a parameter gradient obtained based on the target enhanced image and a parameter gradient obtained based on the control image is greater than a preset difference.
4. The method of claim 2, wherein: The obtaining of multiple preset enhancement schemes includes: Obtain multiple enhancement algorithms and multiple enhancement amplitude information corresponding to each enhancement algorithm; Repeat the following steps to obtain the plurality of preset enhancement schemes: randomly selecting at least one target enhancement algorithm from the plurality of enhancement algorithms, Determine the target enhancement amplitude information from the plurality of enhancement amplitude information corresponding to each target enhancement algorithm, and A preset enhancement scheme is generated based on the at least one target enhancement algorithm and the target enhancement amplitude information corresponding to each target enhancement algorithm.
5. The method of claim 2, wherein: The step of determining at least one target enhancement scheme from among the plurality of preset enhancement schemes based on the original image set comprises: Based on the original image set, respectively perform usability evaluation on the plurality of preset enhancement schemes to obtain a first evaluation result, wherein the first evaluation result represents the degree of influence of the preset enhancement scheme on the model performance of the target model; Based on the first evaluation result, determining a plurality of candidate enhancement schemes from the plurality of preset enhancement schemes, wherein the degree of influence of the candidate enhancement schemes on the model performance is less than the degree of influence of other enhancement schemes on the model performance; Based on the original image set, performing privacy evaluation on the multiple candidate enhancement schemes respectively to obtain second evaluation results, wherein the second evaluation results represent the anti-reconstruction attack capability of the enhanced images generated by the candidate enhancement schemes; and Based on the second evaluation result, the at least one target enhancement scheme is determined from the multiple candidate enhancement schemes.
6. The method of claim 5, wherein: For each preset enhancement solution, the usability evaluation process includes: Performing enhancement processing on a plurality of original images in the original image set based on the preset enhancement scheme to obtain a plurality of enhanced images; Inputting the plurality of enhanced images into the target model to obtain a plurality of output information of the target model; Based on the multiple enhanced images and the multiple output information, determining a target matrix corresponding to the preset enhancement scheme, the target matrix representing the sensitivity of the output of the target model to the input; and Based on the target matrix, a first evaluation result corresponding to the preset enhancement scheme is determined.
7. The method of claim 6, wherein: The target matrix is a gradient Jacobian matrix. Based on the target matrix, determining a first evaluation result corresponding to the preset enhancement scheme includes: Based on the gradient Jacobian matrix, determining a correlation coefficient matrix corresponding to the preset enhancement scheme, and extracting eigenvalues of the correlation coefficient matrix; and Based on the characteristic value, a first evaluation result corresponding to the preset enhancement scheme is determined.
8. The method of claim 5, wherein: For each candidate enhancement solution, the privacy assessment process includes: Performing enhancement processing on a plurality of original images in the original image set based on the candidate enhancement scheme to obtain a plurality of enhanced images; For each enhanced image of the plurality of enhanced images, a plurality of control images corresponding to the enhanced image are generated, and a gradient similarity is determined based on the enhanced image and the plurality of control images, wherein the gradient similarity represents a degree of similarity between a parameter gradient obtained based on the enhanced image and a parameter gradient obtained based on the plurality of control images, and the plurality of control images have different similarities with the enhanced image; Determining an anti-reconstruction index of the candidate enhancement scheme based on the gradient similarities corresponding to each of the plurality of enhanced images; and Based on the anti-reconstruction index, a second evaluation result of the candidate enhancement solution is determined.
9. The method of claim 2, wherein: The step of performing enhancement processing on each original image in the original image set based on at least one target enhancement scheme to obtain the enhanced image set includes: Traverse the original images in the original image set, and for the current original image: One of the at least one target enhancement schemes is randomly selected as a current enhancement scheme, and based on the current enhancement scheme, the current original image is enhanced to obtain an enhanced image, and the enhanced image is added to the enhanced image set.
10. The method of claim 9, wherein: The current enhancement scheme includes: an overall enhancement algorithm and its corresponding target enhancement amplitude information, and a local enhancement algorithm and its corresponding target enhancement amplitude information. The current original image is enhanced based on the current enhancement scheme to obtain an enhanced image, including: Based on the local enhancement algorithm and its corresponding target enhancement amplitude information, enhancing the local part of the current original image to obtain an intermediate result image; and Based on the overall enhancement algorithm and its corresponding target enhancement amplitude information, the overall enhancement processing is performed on the intermediate result image.
11. The method of claim 10, wherein: The current original image includes multiple regions, and the target enhancement amplitude information corresponding to the local enhancement algorithm represents the number of regions to be masked; based on the local enhancement algorithm and the corresponding target enhancement amplitude information, the local part of the current original image is enhanced to obtain an intermediate result image, including: Based on the number of the areas to be masked, some areas of the multiple areas are randomly masked to obtain the intermediate result image.
12. The method of claim 11, wherein: Each of the original images in the original image set is a face image, and the multiple regions are regions obtained by dividing the faces in the original images.
13. A computing device, located in a distributed system, the distributed system comprising a service device and a plurality of local devices, the computing device being any one of the plurality of local devices, the computing device comprising: At least one storage medium storing at least one instruction set for performing model training based on a distributed system; as well as At least one processor is communicatively connected to the at least one storage medium, wherein the at least one processor reads the at least one instruction set when running, and executes the model training method based on a distributed system as described in any one of claims 1-12 according to the instructions of the at least one instruction set.
14. A distributed system comprising: Service equipment; as well as A plurality of local devices, wherein at least some of the plurality of local devices are the computing devices according to claim 13.