Plaintext matrix processing method and device, electronic equipment and storage medium
By placing the message element or ciphertext matrix on the real and imaginary parts of the complex matrix, and using the plaintext matrix processing method for calculation, the problem of low computational performance of the CKKS algorithm is solved, and more efficient computing performance is achieved.
Patent Information
- Application Number
- CN202311656460.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-04
- Publication Date
- 2025-06-06
AI Technical Summary
In homomorphic encryption technology, the CKKS algorithm is used for homomorphic correlation calculations, resulting in low computational performance, especially in plaintext multiplication operations and homomorphic operations.
By placing the message element or the ciphertext matrix on the real and imaginary parts of the complex matrix, the plaintext matrix processing method is used for operations, which reduces the number of plaintext multiplication and homomorphic operations.
Improves computing performance, reduces the number of operations and the required resource slot capacity, and improves the computing rate.
Smart Images

Figure CN120110633A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to the technical field of model training, and in particular, to a plaintext matrix processing method, device, electronic device and storage medium. Background Art
[0002] Fully homomorphic encryption technology is to perform calculations on plaintext through ciphertext, so as to ensure that ciphertext calculations can be completed in an untrusted environment. Its main application scenario is federated learning training, that is, joint modeling training is carried out without leaving the domain, thereby solving the problem of data islands.
[0003] In homomorphic encryption technology, the CKKS algorithm can be specifically used to perform homomorphic related calculations. Assuming that the message matrix has two columns, in the related technology, the message matrix data is placed on the real part to obtain two plaintext polynomials, and then two plaintext multiplication operations and two homomorphic operations are required to generate two ciphertexts. Its computing performance needs to be improved. Summary of the invention
[0004] An embodiment of the present invention provides a plaintext matrix processing method to improve computing performance.
[0005] In a first aspect, the present invention provides a plaintext matrix processing method, which is applied to a first electronic device, wherein a first sample is stored in the first electronic device, and specifically comprises the following steps:
[0006] At least one second ciphertext is generated based on multiplication of the first plaintext and the first ciphertext, data of the first plaintext or the first ciphertext is encoded into a real part and an imaginary part, and in the at least one second ciphertext, each second ciphertext includes at least one vector consisting of a real part and an imaginary part, the first plaintext is generated based on a first sample, the first ciphertext is generated based on a second sample, and among the first sample and the second sample, the second sample has gradient data;
[0007] Performing homomorphic operations on each second ciphertext in at least one second ciphertext, and obtaining homomorphic operation results of each second ciphertext;
[0008] The homomorphic operation result of a second ciphertext in at least one second ciphertext is determined in the following manner:
[0009] The real part and the imaginary part of a vector consisting of at least one real part and imaginary part in a ciphertext are summed respectively.
[0010] In the plaintext matrix processing method provided in the present application, the message elements or the ciphertext matrix are placed on the real part and the imaginary part respectively, thereby improving the computing performance.
[0011] One possible way is to encode the data of the first plaintext into the real part and the imaginary part, and generate the first plaintext in the following way:
[0012] generating a first message matrix based on the first sample;
[0013] Combining all row vectors in the first message matrix in pairs to generate at least one second message matrix, wherein each matrix in the second message matrix corresponds to a result of combining row vectors in pairs in the first message matrix;
[0014] Encode the data of each matrix in the second message matrix into the real part and the imaginary part to generate a first plaintext;
[0015] Among them, in the first message matrix, each row vector represents a message vector of a feature of the first sample under a segmentation strategy.
[0016] One possible way is to generate the first ciphertext as follows:
[0017] A first ciphertext is determined based on a first-order gradient of the second sample.
[0018] One possible way is to encode the data of the first ciphertext into the real part and the imaginary part, and generate the first ciphertext in the following way:
[0019] Determine the first-order gradient and the second-order gradient of the second sample to generate a ciphertext vector;
[0020] Encode the ciphertext vector into its real and imaginary parts.
[0021] One possible way is to generate the first plaintext as follows:
[0022] generating a first message matrix based on the first sample;
[0023] For the first message matrix, all row vectors are combined in pairs to generate the first plaintext;
[0024] Among them, in the first message matrix, each row vector represents the message vector of a feature of the first sample under a segmentation strategy
[0025] In the first plaintext, each first plaintext corresponds to a result of pairwise combination of row vectors of the first message matrix.
[0026] In one possible manner, after performing a homomorphic operation on each second ciphertext in at least one second ciphertext and obtaining a homomorphic operation result of each second ciphertext, the method further includes:
[0027] The homomorphic operation result of each second ciphertext is sent to a second electronic device, and the second electronic device stores the second sample.
[0028] In a second aspect, the present application provides a plaintext matrix processing method, which is applied to a second electronic device and is characterized in that:
[0029] Receiving a homomorphic operation result of each second ciphertext, wherein the homomorphic operation result of each second ciphertext is generated based on the homomorphic operation of each second ciphertext in at least one second ciphertext;
[0030] The homomorphic operation result of a second ciphertext in at least one second ciphertext is determined in the following manner:
[0031] respectively summing the real part and the imaginary part of a vector consisting of at least one real part and imaginary part in a ciphertext;
[0032] Based on the homomorphic operation results of each second ciphertext, the optimal segmentation strategy is obtained.
[0033] One possible approach is to obtain the optimal segmentation strategy based on the homomorphic operation result of each second ciphertext, including:
[0034] Decrypt the homomorphic operation result of each second ciphertext.
[0035] In a third aspect, the present application provides a plaintext matrix processing device, which is applied to a first electronic device, wherein a first sample is stored in the first electronic device, including:
[0036] A generating module: used for generating at least one second ciphertext based on multiplying a first plaintext and a first ciphertext, wherein data of the first plaintext or the first ciphertext is encoded into a real part and an imaginary part, and each of the at least one second ciphertext includes a vector consisting of at least one real part and an imaginary part, the first plaintext is generated based on a first sample, the first ciphertext is generated based on a second sample, and among the first sample and the second sample, the second sample has gradient data;
[0037] Operation module: used for performing homomorphic operation on each second ciphertext in at least one second ciphertext, and obtaining a homomorphic operation result of each second ciphertext;
[0038] The homomorphic operation result of a second ciphertext in at least one second ciphertext is determined in the following manner:
[0039] The real part and the imaginary part of a vector consisting of at least one real part and imaginary part in a ciphertext are summed respectively.
[0040] In a fourth aspect, the present application provides a plaintext matrix processing device, which is applied to a second electronic device, characterized in that the second electronic device stores a second sample, and the second sample has gradient data, including:
[0041] Receiving module: used for receiving the homomorphic operation result of each second ciphertext, wherein the homomorphic operation result of each second ciphertext is generated based on the homomorphic operation of each second ciphertext in at least one second ciphertext;
[0042] Determination module: used to obtain the optimal segmentation strategy based on the homomorphic operation results of each second ciphertext;
[0043] Wherein, in at least one second ciphertext, each second ciphertext includes at least one vector consisting of a real part and an imaginary part, and the homomorphic operation result of a second ciphertext in at least one second ciphertext is determined in the following manner:
[0044] The real part and the imaginary part of a vector consisting of at least one real part and imaginary part in a ciphertext are summed respectively.
[0045] In a fifth aspect, the present application provides an electronic device, characterized in that it includes:
[0046] at least one processor; and
[0047] at least one memory in communication with the processor, wherein:
[0048] The memory stores program instructions that can be executed by the processor, and the processor calls the program instructions to execute any method of the first aspect or the second aspect.
[0049] In a sixth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer instructions, and the computer instructions enable a computer to execute the method of the first aspect or the second aspect.
[0050] It should be understood that the second to sixth aspects of the embodiments of the present invention are consistent with the technical solutions of the first aspect of the embodiments of the present invention, and the beneficial effects achieved by each aspect and the corresponding feasible implementation methods are similar and will not be described in detail. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the embodiments are briefly introduced below. Obviously, the drawings described below are only some embodiments of the embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0052] Figure 1 It is a schematic diagram of the process of fully homomorphic encryption technology in related technologies;
[0053] Figure 2 A schematic diagram of a federated learning training scenario in related technologies;
[0054] FIG. 3( a ) and FIG. 3( b ) are example diagrams of the CKKS algorithm in the related art;
[0055] FIG4(a) and FIG4(b) are schematic diagrams of the training process of federated learning in the related art;
[0056] Figure 5 It is an example diagram of the CKKS algorithm in the related art;
[0057] Figure 6 The electronic device structure diagram provided for this application;
[0058] Figure 7 A flow chart of a plaintext matrix processing method provided in an embodiment of the present application;
[0059] Figure 8 A schematic diagram of an exemplary method for processing a plaintext matrix provided in an embodiment of the present application;
[0060] Fig. 9 A flow chart of a method for processing a plaintext matrix is provided as an exemplary embodiment of the present application;
[0061] Fig.10 A schematic diagram of another exemplary method for processing a plaintext matrix provided in an embodiment of the present application;
[0062] Fig.11 A flowchart of a method for processing a plaintext matrix is shown in another exemplary embodiment provided in the present application;
[0063] Fig.12 A schematic diagram of a specific example of plaintext matrix processing provided in an embodiment of the present application;
[0064] Fig.13 A structural diagram of a plaintext matrix processing device provided in an embodiment of the present application;
[0065] Fig.14 A structural diagram of another plaintext matrix processing device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0066] In order to better understand the technical solution of the embodiment of the present invention, the embodiment of the present invention is described in detail below with reference to the accompanying drawings.
[0067] It should be clear that the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments in the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the embodiments of the present invention.
[0068] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the embodiments of the present invention. The singular forms "a", "an", "the" and "the" used in the embodiments of the present invention and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings.
[0069] Reference Figure 1 Fully homomorphic encryption technology is to calculate the plaintext through the ciphertext, so as to ensure that the ciphertext calculation can be completed in an untrusted environment. At present, homomorphic encryption has developed to the third generation. Specifically, its second-generation algorithm supports batch processing, and the third-generation algorithm is good at processing nonlinear functions, but does not yet support special batch processing.
[0070] In related technologies, fully homomorphic encryption technology is widely used in secure federated learning training. The so-called federated learning training aims to solve the problem of data isolation, that is, to use federated learning training to enable multiple parties to conduct joint training without leaving the original data domain. Figure 2 Assuming that financial institution A only uses its own data for training, the accuracy of the trained model will be relatively low. In order to improve the accuracy of the model, it is necessary to introduce data privacy. That is, during training, it is necessary to use the data of both financial institution A and financial institution B. In order to ensure that the data of financial institution B is introduced without leaking privacy, federated learning is needed.
[0071] For fully homomorphic encryption algorithms, the CKKS algorithm can be mainly used, that is, to calculate complex / real number messages to perform homomorphic related operations.
[0072] Specifically, for the CKKS algorithm, it mainly uses the batch encoding function to encode the message vector into a plaintext polynomial through FFT (Fast Fourier Transform).
[0073] A specific example of the CKKS algorithm is provided below.
[0074] Assume R _ q=Z_q[x] / X^N+1 to represent the polynomial ring, where N is the length of the ring. The batch encoding function encodes the complex / real vector of length N / 2 into R _ q. Specifically, referring to FIG. 3(a) and FIG. 3(b), its properties include: two message vectors m and message vector m′ are respectively obtained through the batch encoding function as plaintext polynomials poly and poly′, where the message vector is a message element supporting complex / real numbers. The two plaintext polynomials are convolved to obtain poly*poly′, thereby obtaining the point product of the elements at the corresponding positions of the message vectors m and m′.
[0075] The following is a brief introduction to the sum_to_one of the homomorphic algorithm:
[0076] The sum_to_one function specifically refers to adding the elements in a vector through operations such as homomorphic rotation and addition to generate ciphertext.
[0077] In the above, the fully homomorphic encryption algorithm has been explained. The following introduces a specific usage scenario of the fully homomorphic encryption algorithm.
[0078] Here, the training data includes unlabeled data A and labeled data B. The main difference between unlabeled data A and labeled data B is whether they contain gradient data. The process of joint training of labeled data A and unlabeled data B is as follows:
[0079] 4, the unlabeled party A and the labeled party B generate segmentation strategies according to their own local features. At this time, the labeled party B generates a homomorphically encrypted public-private pair, homomorphically encrypts the local first-order gradient data and second-order gradient data, and sends it to the unlabeled party A.
[0080] Exemplarily, at this time, the data sent by tag party B is shown in Table 1:
[0081]
[0082]
[0083] Table 1
[0084] Then the homomorphic encryption process begins, that is, the unlabeled party A receives the ciphertext sent by the labeled party B, that is, receives the encrypted gradient, and performs homomorphic operations. Referring to Figure 4, the homomorphic operation is to multiply the plaintext matrix and the ciphertext vector. Specifically, the ciphertext of each feature segmentation strategy is summed, and the summation result is sent to the labeled party B.
[0085] Exemplarily, assume that the ciphertext sent by the labeled party B is as shown in Table 1. At this time, after receiving the encrypted gradient, the data obtained by the unlabeled party A is as shown in Table 2. Based on Tables 1 and 2, the specific calculation process is shown in Figure 4(b).
[0086] v Feature A1 First-order gradient gi The second-order gradient hi 1 XX g1 h1 2 XX g2 h2 …… …… …… …… n XX gn hn
[0087] Table 2
[0088] At this time, the labeled party B receives the summation result sent by the unlabeled party A and calculates the optimal segmentation strategy. Specifically, the information gain function can be used to determine the optimal segmentation strategy.
[0089] After the optimal segmentation strategy is determined, if the optimal segmentation strategy is on the labeled party B, the samples are cut locally on the labeled party B. If the optimal strategy is on the A party, the optimal strategy is sent to the A party, and the above training process is repeated until the training is completed.
[0090] Reference Figure 5 In the related technology, for the CKKS algorithm, it is assumed that the original length of the message data is N. Specifically, batch encoding is used to place each line of message data on the real part to obtain message data with a length of N / 2, and a plaintext polynomial is generated, and the ciphertext is obtained by homomorphic operation.
[0091] From this, we can see that, taking the message data with the original length of N as an example, placing the data only in the real part for batchencode will result in two plaintext polynomials, requiring two plaintext and ciphertext multiplication operations and two homomorphic operations to obtain two result ciphertexts. Its computing performance needs to be improved.
[0092] Based on this, the present application provides a plaintext matrix processing method, which places the message data on the real part and the imaginary part respectively for any plaintext, thereby improving the computing performance.
[0093] The following is a brief introduction to the electronic equipment designed in this application:
[0094] Figure 6 A schematic structural diagram of an electronic device 100 is shown.
[0095] The electronic device 100 may include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, an earphone interface 170D, a sensor module 180, a button 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, an air pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.
[0096] It is to be understood that the structure illustrated in the embodiment of the present invention does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may include more or fewer components than shown in the figure, or combine some components, or separate some components, or arrange the components differently. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.
[0097] The processor 110 may include one or more processing units, for example, the processor 110 may include an application processor (AP), a modem processor, a graphics processor (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Different processing units may be independent devices or integrated into one or more processors.
[0098] The controller can generate operation control signals according to the instruction operation code and timing signal to complete the control of instruction fetching and execution.
[0099] The processor 110 may also be provided with a memory for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. The memory may store instructions or data that the processor 110 has just used or cyclically used. If the processor 110 needs to use the instruction or data again, it may be directly called from the memory. This avoids repeated access, reduces the waiting time of the processor 110, and thus improves the efficiency of the system.
[0100] In some embodiments, the processor 110 may include one or more interfaces. The interface may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, etc.
[0101] Please refer to Figure 7 , Figure 7 A flowchart of a plaintext matrix processing method provided in an embodiment of the present application specifically includes the following steps
[0102] S101: Generate at least one second ciphertext based on multiplication of a first plaintext and a first ciphertext.
[0103] Specifically, in the embodiments provided in the present application, each first plaintext or first ciphertext data is encoded into a real part and an imaginary part, and in at least one second ciphertext, each second ciphertext includes at least one vector consisting of a real part and an imaginary part. The first plaintext is generated based on a first sample, and the first ciphertext is generated based on a second sample. Among the first sample and the second sample, the second sample has gradient data.
[0104] Combining relevant technologies, it can be known that, assuming there are unlabeled samples A and labeled samples B, using unlabeled sample A, the message matrix can be used to generate the first plaintext. For labeled sample B, the first-order gradient and second-order gradient can be used to generate the first ciphertext.
[0105] In the embodiment provided in the present application, it is assumed that the first plaintext data is encoded into the real part and the imaginary part using a batch encoding function. In this step, an unlabeled sample (i.e., the aforementioned first sample) is used to generate a first message matrix. It is assumed that an m*n message matrix is constructed, i.e., the first message matrix is an m*n-order matrix. Here, the row vectors in the first message matrix are combined in pairs to generate a second message matrix.
[0106] At the same time, for the first message matrix, here, in the first message matrix, each row vector represents a message vector of a feature of the first sample under a segmentation strategy.
[0107] It can be further understood that, assuming there are 10 features and 10 segmentation strategies, the first message matrix includes 100 elements, where each element corresponds to the result of data segmentation of a feature under a segmentation strategy.
[0108] At the same time, in the second message matrix, each matrix corresponds to a first message matrix, and the row vectors are combined in pairs.
[0109] Exemplarily, assuming that the order of the first message matrix is 100*200, 50 matrices can be formed by grouping two adjacent rows, thereby forming 50 second message matrices, and each second message matrix is encoded into the real part and the imaginary part using the batch encoding function.
[0110] At this time, for the ciphertext, the first ciphertext can be generated directly using the first-order gradient of the labeled data (that is, the first-order gradient of the second sample).
[0111] In another embodiment, assuming that the ciphertext data is encoded into the real part and the imaginary part using a batch encoding function, specifically for the labeled party B, the ciphertext matrix generated by the first-order gradient and the second-order gradient of the labeled data can be encoded into the real part and the imaginary part using a batch encoding function.
[0112] In this embodiment, the sample without label A (ie, the first sample) is preprocessed with the help of the prior art.
[0113] That is, in this embodiment, the first sample is preprocessed, and the message matrix obtained after the preprocessing is the first plaintext.
[0114] S102: Perform a homomorphic operation on each second ciphertext in at least one second ciphertext, and obtain a homomorphic operation result of each second ciphertext.
[0115] Specifically, the second ciphertext may be subjected to homomorphic operation with the help of a sum-to-one function in the related technology.
[0116] Combining the above, it can be known that for the second ciphertext, each second ciphertext includes at least one vector consisting of a real part and an imaginary part. The so-called homomorphic operation is to obtain the sum of the real part and the imaginary part in each second ciphertext respectively.
[0117] For homomorphic operations, two homomorphic rotations and homomorphic additions are required. Taking a 4*1 message matrix as an example, the specific operation process is shown in Table 3.
[0118]
[0119]
[0120] Table 3
[0121] Combining relevant technologies, it can be known that homomorphic rotation, addition and other operations can be used to implement the sum of elements in the vector, and the final ciphertext is the sum ciphertext of all elements of the corresponding message vector.
[0122] In the aforementioned S101, it can be seen that in some embodiments, the first plaintext data is encoded into the real part and the imaginary part. For this, please refer to Figure 8 , assuming that there are two row vectors m in a first plaintext 00 、m 01 、m 02 ……m 07 and m 10 、m 11 、m 12 ……m 17 , whose ciphertext vector is t 0 ,t 1 ,t 2 ……t 7 , where the first plaintext is multiplied by the first text, and a homomorphic operation is performed.
[0123] Therefore, please refer to Fig. 9 , for encoding the first plaintext data into the real part and the imaginary part, and then performing homomorphic operation, specifically includes the following steps:
[0124] S201: Generate a first message matrix based on a first sample.
[0125] S202: All row vectors in the first message matrix are combined in pairs to generate at least one second message matrix.
[0126] S203: Encode the data of each matrix in the second message matrix into the real part and the imaginary part to generate a first plaintext.
[0127] S204: Determine a first ciphertext based on a first-order gradient of the second sample;
[0128] S205: Generate at least one second ciphertext based on the multiplication of the first plaintext and the first ciphertext
[0129] S206: Perform a homomorphic operation on each second ciphertext in at least one second ciphertext, and obtain a homomorphic operation result of each second ciphertext.
[0130] Reference Fig.10In some other embodiments, it is assumed that the data in the first ciphertext is encoded into the real part and the imaginary part, specifically referring to Fig. 9 , assuming that there are two row vectors m in a first plaintext 00 、m 01 、m 02 ……m 07 and m 10 、m 11 、m 12 ……m 17 Here, the data of the sticky note party B is encrypted through the pass-through state, the first-order gradient and the second-order gradient are encoded into the real part and the imaginary part, and the result of the homomorphic operation is obtained.
[0131] From this we can see that referring to Fig.11 In some other embodiments, for plain text processing, the following steps are included:
[0132] S301: Determine the first-order gradient and the second-order gradient of the second sample to generate a ciphertext vector;
[0133] S302: Encode the ciphertext vector into the real part and the imaginary part to generate a first ciphertext;
[0134] S303: Generate a first message matrix based on the first sample;
[0135] S304: Combine all row vectors in the first message matrix in pairs to generate a first plaintext;
[0136] S305: Generate at least one second ciphertext based on the multiplication of the first plaintext and the first ciphertext
[0137] S306: Perform a homomorphic operation on each second ciphertext in at least one second ciphertext, and obtain a homomorphic operation result of each second ciphertext.
[0138] Therefore, in summary, based on the foregoing embodiments, the plaintext message or the ciphertext message is placed on the real part and the imaginary part respectively to form a complex vector. When the length of the message matrix is N, compared with batch encoding, each row of message data is placed on the real part to obtain message data with a length of N / 2, and a plaintext polynomial is generated, and the message data is placed on the real part and the imaginary part, there is no need to perform two plaintext and ciphertext multiplication operations and two homomorphic operations, thereby improving the operation rate.
[0139] On the basis of the aforementioned embodiment, the aforementioned second ciphertext homomorphic operation result may be sent to the labeled party B, that is, the second electronic device.
[0140] It can be understood that in the embodiments provided in the present application, the difference between the electronic device and the second electronic device is that the first electronic device stores unlabeled samples, and the second electronic device stores labeled samples. In other words, in the embodiments provided in the present application, the first electronic device corresponds to the labeled side, and the second electronic device corresponds to the unlabeled side.
[0141] At this time, the second electronic device receives the homomorphic operation result of each second ciphertext, and obtains the optimal segmentation strategy based on the homomorphic operation result of each second ciphertext.
[0142] Specifically, after the second electronic device has received the homomorphic operation result of the aforementioned second ciphertext, it decrypts the second ciphertext based on the unlabeled sample (second sample) stored in the second electronic device, that is, the second electronic device decrypts the homomorphic operation result of each second ciphertext to obtain the optimal segmentation strategy.
[0143] According to the prior art, after the second ciphertext is decrypted, the optimal strategy can be determined with the help of the information gain function.
[0144] If the optimal segmentation strategy is on the labeled party B, the data will be segmented on the labeled party B. If the optimal segmentation strategy is on the five-label party A, the data will be sent to the unlabeled party A and the data will be segmented on the unlabeled party A.
[0145] This completes the federated learning training, that is, joint modeling training is performed when the data is not in place.
[0146] For the aforementioned federated training scenario, two specific examples are provided below:
[0147] Reference Fig.12 , assuming that there is a two-party vertical federation training, the number of samples is 4096, the number of features of the labeled party B is 1, the number of features of the unlabeled party is 20, and the number of feature segmentation strategies is 10. Taking the joint training of 1 tree and 1 node as an example, the process is as follows:
[0148] The homomorphic parameter is selected as the polynomial dimension N=8192. At this time, the resource slot capacity is 4096, and the ciphertext modulus bits are {59, 50, 50, 59}. Then the CKKS algorithm is used to encode and encrypt the note-holder B.
[0149] Specifically, the batch encoding of the CKKS algorithm is used to encode the first-order gradient data {g_i}_(i=1,2,3……,4096) into I=[4096 / 4096] plaintexts, and then homomorphically encrypts them to obtain a ciphertext, which is sent to the unlabeled party A.
[0150] Then, the unlabeled party A is initialized to generate the first message matrix. Based on the above, it can be seen that the number of unlabeled party features is 20 and the number of feature segmentation strategies is 10. There are 200 total segmentation strategies to be calculated. Here, a message vector is obtained for each segmentation strategy to form a message matrix M_(200×4096). At this time, the first message matrix is generated.
[0151] After the first message matrix is generated, plaintext encoding is required, that is, the row vectors of the first message matrix are combined in pairs.
[0152] Specifically, the vector data of the 2i-th and 2i+1-th rows in the first message matrix M_(200×4096) may be placed on the real part and the imaginary part respectively to form a complex vector, and the vector may be encoded into a plaintext through batch encoding.
[0153] It can be seen that the unlabeled party A finally obtains 100 plaintexts, which are then multiplied with the aforementioned ciphertext to obtain the second ciphertext. The second ciphertext is homomorphically operated, and the real part and imaginary part of each second ciphertext are summed up to obtain the homomorphic operation result.
[0154] Therefore, the unlabeled party B decrypts the homomorphic operation result to obtain the optimal segmentation strategy, and then performs sample segmentation according to the optimal segmentation strategy.
[0155] It can be seen from the above examples that in the embodiment provided in the present application, only 100 ciphertext multiplication operations and homomorphic operations are required, and the results of the homomorphic operations are only 100, which improves the computing performance compared to the existing technical solutions.
[0156] Assuming that the ciphertext data is encoded into the real part and the imaginary part, another example is provided here:
[0157] Similarly, for the joint defense vertical joint defense training model, it is assumed that there are 500,000 sample sets, the labeled party B has 1 feature, the number of features of the unlabeled party is 50, the number of feature splitting strategies is 2, and 1 node of 1 tree is jointly trained. Here, the parameter polynomial dimension N = 8192 is also selected. At this time, the resource slot capacity is 4096, and the ciphertext modulus bits are {59, 50, 50, 59}.
[0158] Here, the labeled party B needs to be encoded and encrypted. Specifically, the first-order gradient data {g_i}_(i=1,2,3...,500000) and the second-order gradient data {h_i}_(i=1,2,3...,500000) are encoded to the real part and the imaginary part respectively through batch encoding of the CKKS algorithm, and encoded into 123=[500000 / 4096] plaintexts. After homomorphic encryption, 123 ciphertexts are obtained and sent to the unlabeled party A.
[0159] For A, initialize the segmentation strategy of 50 features. That is to say, there are 100 segmentation strategies to be calculated for the first sample. Get the message vector for each segmentation strategy. At this time, the preprocessing of the first sample is completed and the message matrix M_(100×500000) is generated.
[0160] At this time, the message matrix can be encoded, that is, the message matrix can be split into 123 small matrices and encoded into plain text, and the first plain text is generated at this time.
[0161] Then a homomorphic operation is performed to multiply the first plaintext and the first ciphertext to generate 100×123 ciphertexts, that is, 123 second ciphertexts. For each second ciphertext, its real part and imaginary part are added separately to generate the result of the homomorphic operation. At this time, the result of the homomorphic operation is sent to the labeled party B, which then decrypts it. The information gain function can be used to determine the optimal segmentation strategy.
[0162] When the optimal segmentation strategy is on the labeled party B, the segmentation is performed on the labeled party B. Otherwise, the decrypted sample and the optimal segmentation strategy are sent to the unlabeled party A, and the unlabeled party A performs the segmentation based on the optimal segmentation strategy.
[0163] It can be seen from the above examples that in the embodiment provided in the present application, only 100 ciphertext multiplication operations and homomorphic operations are required, and the homomorphic operation results are only 100. Compared with the existing technical solution, 200 multiplication operations and homomorphic operations are required, which improves the computing performance.
[0164] Please refer to Fig.13 The embodiment of the present application further provides a plaintext matrix processing device, which is applied to a first electronic device, in which a first sample is stored, including:
[0165] A generating module: used for generating at least one second ciphertext based on multiplying a first plaintext and a first ciphertext, wherein data of the first plaintext or the first ciphertext is encoded into a real part and an imaginary part, and each of the at least one second ciphertext includes a vector consisting of at least one real part and an imaginary part, the first plaintext is generated based on a first sample, the first ciphertext is generated based on a second sample, and among the first sample and the second sample, the second sample has gradient data;
[0166] A first operation module: used for performing a homomorphic operation on each second ciphertext in at least one second ciphertext, and obtaining a homomorphic operation result of each second ciphertext;
[0167] The homomorphic operation result of a second ciphertext in at least one second ciphertext is determined in the following manner:
[0168] The real part and the imaginary part of a vector consisting of at least one real part and imaginary part in a ciphertext are summed respectively.
[0169] Fig.13 The plaintext matrix processing device provided in the embodiment shown can be used to execute the present application Figures 1 to 12 The technical solution of the method embodiment shown, its implementation principle and technical effects can be further referred to the relevant description in the method embodiment.
[0170] Fig.14 A structural diagram of another plaintext matrix processing device provided by the present application is applied to a second electronic device, characterized in that the second electronic device stores a second sample, and the second sample has gradient data, including:
[0171] Receiving module: used for receiving the homomorphic operation result of each second ciphertext, wherein the homomorphic operation result of each second ciphertext is generated based on the homomorphic operation of each second ciphertext in at least one second ciphertext;
[0172] Determination module: used to obtain the optimal segmentation strategy based on the homomorphic operation results of each second ciphertext;
[0173] Wherein, in at least one second ciphertext, each second ciphertext includes at least one vector consisting of a real part and an imaginary part, and the homomorphic operation result of a second ciphertext in at least one second ciphertext is determined in the following manner:
[0174] The real part and the imaginary part of a vector consisting of at least one real part and imaginary part in a ciphertext are summed respectively.
[0175] Fig.14 The plaintext matrix processing device provided in the embodiment can be used to execute the present application Figures 1 to 12 The technical solution of the method embodiment is shown in the figure. Its implementation principle and technical effect can be further referred to the relevant description in the method embodiment.
[0176] The application embodiment provides an electronic device, which can be an electronic device or a circuit device built into the electronic device. The electronic device can be used to execute the functions / steps in the above method embodiment.
[0177] An embodiment of the present application provides a computer-readable storage medium, in which instructions are stored. When the instructions are executed on a terminal device, the terminal device executes the functions / steps in the above method embodiment.
[0178] The embodiment of the present application also provides a computer program product comprising instructions, and when the computer program product is run on a computer or any at least one processor, the computer executes the functions / steps in the above method embodiment.
[0179] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0180] The above describes specific embodiments of the present invention. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0181] In the description of the embodiments of the present invention, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the embodiments of the present invention. In the embodiments of the present invention, the schematic representations of the above terms do not necessarily refer to the same embodiments or examples. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in the embodiments of the present invention and the features of the different embodiments or examples, without contradiction.
[0182] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of the features. In the description of the embodiments of the present invention, the meaning of "plurality" is at least two, such as two, three, etc., unless otherwise clearly and specifically defined.
[0183] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, fragment or portion of code comprising one or more executable instructions for implementing the steps of a custom logical function or process, and the scope of the preferred implementation of the embodiments of the present invention includes alternative implementations in which functions may not be performed in the order shown or discussed, including performing functions in a substantially simultaneous manner or in reverse order depending on the functions involved, which should be understood by technicians in the technical field to which the embodiments of the present invention belong.
[0184] The word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrases "if it is determined" or "if (stated condition or event) is detected" may be interpreted as "when it is determined" or "in response to determining" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)", depending on the context.
[0185] It should be noted that the electronic devices involved in the embodiments of the present invention include but are not limited to personal computers (Personal Computer; hereinafter referred to as: PC), personal digital assistants (Personal Digital Assistant; hereinafter referred to as: PDA), wireless handheld devices, tablet computers (Tablet Computer), mobile phones, MP3 players, MP4 players, etc.
[0186] In the several embodiments provided in the embodiments of the present invention, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0187] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of hardware plus software functional units.
[0188] The above-mentioned integrated unit implemented in the form of a software functional unit can be stored in a computer-readable storage medium. The above-mentioned software functional unit is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, an electronic device, or a network device, etc.) or a processor (Processor) to perform some steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (Read-Only Memory; hereinafter referred to as: ROM), random access memory (Random Access Memory; hereinafter referred to as: RAM), disk or optical disk and other media that can store program codes.
[0189] The above are only preferred embodiments of the embodiments of the present invention and are not intended to limit the embodiments of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present invention should be included in the scope of protection of the embodiments of the present invention.
Claims
1. A plaintext matrix processing method, It is characterized in that The method is applied to a first electronic device, wherein a first sample is stored in the first electronic device, and specifically includes the following steps: At least one second ciphertext is generated based on multiplication of a first plaintext and a first ciphertext, wherein data of the first plaintext or the first ciphertext is encoded into a real part and an imaginary part, and each of the at least one second ciphertext includes a vector consisting of at least one real part and an imaginary part, the first plaintext is generated based on a first sample, the first ciphertext is generated based on the second sample, and among the first sample and the second sample, the second sample has gradient data; Performing a homomorphic operation on each second ciphertext in the at least one second ciphertext, and obtaining a homomorphic operation result of each second ciphertext; The homomorphic operation result of a second ciphertext in at least one second ciphertext is determined in the following manner: The real part and the imaginary part of the vector formed by at least one real part and imaginary part in the one ciphertext are summed respectively.
2. The method according to claim 1, It is characterized in that The data of the first plaintext is encoded into the real part and the imaginary part, and the first plaintext is generated in the following manner: generating a first message matrix based on the first sample; Combining all row vectors in the first message matrix in pairs to generate at least one second message matrix, wherein each matrix in the second message matrix corresponds to a result of combining row vectors in pairs in the first message matrix; Encoding the data of each matrix in the second message matrix into the real part and the imaginary part to generate a first plaintext; Among them, in the first message matrix, each row vector represents a message vector of a feature of the first sample under a segmentation strategy.
3. The method according to claim 2, It is characterized in that The first ciphertext is generated as follows: The first ciphertext is determined based on a first-order gradient of the second sample.
4. The method according to claim 1, It is characterized in that The data of the first ciphertext is encoded into the real part and the imaginary part, and the first ciphertext is generated in the following manner: Determine a first-order gradient and a second-order gradient of the second sample to generate a ciphertext vector; The ciphertext vector is encoded into the real part and the imaginary part.
5. The method according to claim 4, It is characterized in that The first plaintext is generated in the following manner: generating a first message matrix based on the first sample; Combining all row vectors in the first message matrix in pairs to generate the first plaintext; Among them, in the first message matrix, each row vector represents the message vector of a feature of the first sample under a segmentation strategy Among the first plaintexts, each of the first plaintexts corresponds to a result of pairwise combination of row vectors of a first message matrix.
6. The method according to any one of claims 1 to 5, It is characterized in that After the step of performing a homomorphic operation on each second ciphertext in the at least one second ciphertext and obtaining a homomorphic operation result for each second ciphertext, the method further includes: The homomorphic operation result of each second ciphertext is sent to a second electronic device, and the second electronic device stores the second sample.
7. A method for processing plaintext matrix, It is characterized in that The method is applied to a second electronic device and is characterized by comprising the following steps: Receiving the homomorphic operation result of each second ciphertext; The homomorphic operation result of each second ciphertext is generated based on the homomorphic operation of each second ciphertext in the at least one second ciphertext; The homomorphic operation result of a second ciphertext in at least one second ciphertext is determined in the following manner: respectively summing the real part and the imaginary part of a vector consisting of at least one real part and imaginary part of the one ciphertext; Based on the homomorphic operation result of each second ciphertext, an optimal segmentation strategy is obtained.
8. The method according to claim 7, wherein the process of obtaining the optimal segmentation strategy based on the homomorphic operation result of each second ciphertext include: Decrypt each homomorphic operation result of the second ciphertext.
9. A plaintext matrix processing device, It is characterized in that Applied to a first electronic device, wherein a first sample is stored in the first electronic device, including: A generating module: configured to generate at least one second ciphertext based on multiplication of a first plaintext and a first ciphertext, wherein data of the first plaintext or the first ciphertext is encoded into a real part and an imaginary part, and each of the at least one second ciphertext includes a vector consisting of at least one real part and an imaginary part, and the first plaintext is generated based on a first sample, and the first ciphertext is generated based on the second sample, and among the first sample and the second sample, the second sample has gradient data; Operation module: used for performing homomorphic operation on each second ciphertext in the at least one second ciphertext, and obtaining a homomorphic operation result of each second ciphertext; The homomorphic operation result of a second ciphertext in at least one second ciphertext is determined in the following manner: The real part and the imaginary part of the vector formed by at least one real part and imaginary part in the one ciphertext are summed respectively.
10. A plaintext matrix processing device, It is characterized in that The method is applied to a second electronic device, wherein the second electronic device stores a second sample, and the second sample has gradient data, including: A receiving module: used for receiving a homomorphic operation result of each second ciphertext, wherein the homomorphic operation result of each second ciphertext is generated based on the homomorphic operation of each second ciphertext in the at least one second ciphertext; Determination module: used for obtaining an optimal segmentation strategy based on the homomorphic operation result of each second ciphertext; Among them, in the at least one second ciphertext, each second ciphertext includes at least one vector consisting of a real part and an imaginary part, and the homomorphic operation result of a second ciphertext in the at least one second ciphertext is determined in the following manner: The real part and the imaginary part of the vector formed by at least one real part and imaginary part in the one ciphertext are summed respectively.
11. An electronic device, It is characterized in that include: at least one processor; as well as at least one memory in communication with the processor, wherein: The memory stores program instructions executable by the processor, and the processor can execute the method according to any one of claims 1 to 6 or 7 to 8 by calling the program instructions.
12. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions enable the computer to execute the method according to any one of claims 1 to 6 or 7 to 8.