Federal learning back door defense method based on singular value decomposition and model weight amplification

By adopting singular value decomposition and model weight amplification methods in federated learning, dimensionality reduction and clustering of client model update parameters, calculating trust scores and optimizing the global model, the limitations of the existing federated learning backdoor defense method in identifying malicious model updates are solved, and effective defense against multiple malicious clients is achieved.

CN120124075AActive Publication Date: 2025-06-10JIANGXI UNIVERSITY OF FINANCE AND ECONOMICS

Patent Information

Application Number
CN202510602497.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-12
Publication Date
2025-06-10
Estimated Expiration
2045-05-12

AI Technical Summary

Technical Problem

The existing federated learning backdoor defense methods have limitations in identifying malicious model updates, especially in scenarios where client data is not independent and same distributed, it is difficult to effectively resist backdoor attacks from multiple malicious clients.

Method used

The federated learning backdoor defense method based on singular value decomposition and model weight amplification is adopted. By normalizing the client model update parameters and singular value decomposition and dimensionality reduction, combining DBSCAN clustering algorithm and cosine distance calculation, a cluster model parameter matrix is ​​constructed, and the trust score is calculated through singular value decomposition, and the global model is finally optimized through the differential privacy mechanism.

Benefits of technology

There is no need to assume that the number of malicious clients is less than that of benign clients. It can effectively resist backdoor attacks from multiple malicious clients, and can also effectively defend against backdoor attacks in non-independent and same-distributed data scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120124075A_ABST
    Figure CN120124075A_ABST
Patent Text Reader

Abstract

The invention provides a federated learning backdoor defense method based on singular value decomposition and model weight amplification, and the method comprises the steps: carrying out the normalization processing of a model updating parameter locally trained by a client, and obtaining a normalized model updating parameter; on the basis of the normalized model updating parameters, model updating parameters after dimension reduction are obtained; performing clustering algorithm processing on the model updating parameters after dimension reduction to obtain clustered clusters; obtaining cluster model parameters based on the clustered clusters; combining the cluster model parameters into a cluster model parameter matrix; performing singular value decomposition on the cluster model parameter matrix to obtain a singular vector; obtaining a trust score through the singular vector; obtaining global model update parameters based on the trust score; calculating by utilizing the global model updating parameters to obtain a global model; and adding Gaussian noise to the global model through a differential privacy mechanism to obtain a final global model. According to the method, backdoor attacks can still be effectively resisted under the scene that the client data sets are non-independent and identically distributed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence security technology, and particularly to a federated learning backdoor defense method based on singular value decomposition and model weight amplification. Background Art

[0002] Traditional centralized machine learning methods require collecting a large amount of user data into a central database. However, continuous data leakage incidents have raised concerns about data privacy and security. To protect user data privacy, Federated Learning (FL) has emerged and received significant attention. Federated learning is a distributed machine learning paradigm that collaboratively maintains a global model between a central server and multiple participants without the need for participants to upload data to the server, thus effectively protecting the data privacy of clients to a certain extent. However, many existing studies have shown that the distributed nature of federated learning makes it vulnerable to backdoor attacks. How to mitigate backdoor attacks in federated learning is an issue that we urgently need to consider.

[0003] To defend against backdoor attacks in federated learning, recently proposed solutions can be divided into two categories, namely backdoor anomaly detection and backdoor mitigation. The backdoor anomaly detection method in FL mainly separates benign updates and malicious updates through unsupervised machine learning methods and then further detects malicious participants.

[0004] Existing methods for defending against backdoor attacks in FL have the following limitations: For backdoor anomaly detection methods, since the training data of clients is usually non-IID, it is difficult to identify malicious model updates using general detection methods. At the same time, attackers can make malicious models similar to benign models through constraint and scaling methods to avoid the server's anomaly detection mechanism; Although backdoor mitigation methods can achieve the effect of resisting backdoor attacks, these measures also have some deficiencies. It is difficult to determine the threshold for pruning model parameters, and it is difficult to define the privacy budget of differential privacy. Adding too much noise will reduce the benign performance of the global model. Finally, the calculation of trust scores often depends on the assumption that the server has a clean root dataset or that the number of benign clients is more than that of malicious clients. Summary of the Invention

[0005] In view of the above situation, the main purpose of the present invention is to propose a federated learning backdoor defense method and system based on singular value decomposition and model weight amplification to solve the above technical problems.

[0006] The present invention proposes a federated learning backdoor defense method based on singular value decomposition and model weight amplification, and the method includes the following steps: Step 1: After obtaining the model update parameters locally trained by the client, normalize the model update parameters locally trained by the client to obtain the normalized model update parameters; Concatenate the normalized model update parameters into a model update parameter matrix, and through singular value decomposition, reduce the dimension of the normalized model update parameters in the model update parameter matrix to obtain the dimension-reduced model update parameters; Step 2: Process the dimension-reduced model update parameters using the DBSCAN clustering algorithm to obtain the clustered clusters; Calculate the cosine distance between the elements in each clustered cluster to obtain the cosine distance between the elements; Construct a distance square matrix based on the cosine distance between the elements, and make a judgment through the number of elements in the distance square matrix to obtain the cluster model parameters; Combine the cluster model parameters of each cluster into a cluster model parameter matrix; Step 3: Perform singular value decomposition on the cluster model parameter matrix to obtain singular vectors; Calculate the trust score through the singular vectors; Step 4: Calculate the global model update parameters based on the trust score; Calculate the global model using the global model update parameters; After obtaining the global model, through the differential privacy mechanism, add Gaussian noise to the global model to obtain the final global model.

[0007] Compared with the prior art, the beneficial effects of the present invention are as follows: 1. The present invention does not need to assume that the number of malicious clients is less than that of benign clients, and can effectively resist the backdoor attacks launched by multiple malicious clients at the same time; 2. The present invention calculates a singular vector as the basis for trust guidance, so there is no need to assume that the server side needs a clean root data set; 3. The present invention can still effectively resist backdoor attacks in the scenario where the client data sets are non-independent and identically distributed.

[0008] The additional aspects and advantages of the present invention will be partially given in the following description, partially become obvious from the following description, or be understood through the embodiments of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] Figure 1 is a flowchart of a federated learning backdoor defense method based on singular value decomposition and model weight amplification proposed by the present invention; Figure 2 is a schematic diagram of the federated learning backdoor attack process. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0010] Embodiments of the present invention will be described in detail below. Examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by referring to the accompanying drawings are exemplary and are only used to explain the present invention and should not be construed as a limitation of the present invention.

[0011] Referring to the following description and the accompanying drawings, these and other aspects of the embodiments of the present invention will become clear. In these descriptions and drawings, some specific embodiments of the embodiments of the present invention are specifically disclosed to represent some ways of implementing the principles of the embodiments of the present invention. However, it should be understood that the scope of the embodiments of the present invention is not limited thereto.

[0012] Please refer to Figure 1 , an embodiment of the present invention provides a federated learning backdoor defense method based on singular value decomposition and model weight amplification. The method includes the following steps: Step 1: After obtaining the model update parameters locally trained by the client, normalize the model update parameters locally trained by the client to obtain the normalized model update parameters; Concatenate the normalized model update parameters into a model update parameter matrix, and through singular value decomposition, reduce the dimension of the normalized model update parameters in the model update parameter matrix to obtain the dimension-reduced model update parameters; In Step 1, after obtaining the model update parameters locally trained by the client, normalize the model update parameters locally trained by the client to obtain the normalized model update parameters. The relational expression existing in the corresponding process is: ; Where represents the model update parameters of the rd th client in the th round, and

[0013] represents the normalized model update parameters. Furthermore, in this step, after obtaining the model update parameter matrix, decompose the model update parameter matrix using singular values to obtain the singular value matrix of the model update parameter matrix, the left singular matrix of the model update parameter matrix, and the right singular matrix of the model update parameter matrix;

[0014] Specifically, the dimension-reduced model parameter matrix is composed of multiple two-dimensional vectors.

[0015] Step 2: Process the updated parameters of the dimensionality-reduced model using the DBSCAN clustering algorithm to obtain the clusters after clustering; Calculate the cosine distance between the elements in each cluster after clustering to obtain the cosine distance between the elements; Construct a distance square matrix based on the cosine distance between the elements, and make a judgment based on the number of elements in the distance square matrix to obtain the cluster model parameters; Combine the cluster model parameters of each cluster into a cluster model parameter matrix; In Step 2, calculate the cosine distance between the elements in each cluster after clustering to obtain the cosine distance between the elements. Taking the first element and the second element in the cluster as an example, the relational expression in the corresponding process is: ; Among them, represents the cosine distance between the first element and the second element, represents the round the first element in the represents the round the second element in the Construct a distance square matrix based on the cosine distance between the elements. The relational expression in the corresponding process is: ; Among them, represents the distance square matrix of the represents the element index; Make a judgment based on the number of elements in the distance square matrix to obtain the cluster model parameters. The specific steps are as follows: If there is only one element in the distance square matrix, determine the cluster model parameters. The relational expression in the corresponding process is: ; Among them, represents the round cluster model parameters of the When the number of elements in the distance square matrix is greater than one, calculate to obtain the cluster model parameters. The relational expression in the corresponding process is: ; Among them, represents the round the sum of the cosine distances from the th element in the

[0016] Furthermore, in this step, the dimension of the cluster model parameter matrix is , where represents the characteristic dimension of each cluster.

[0017] Specifically, the size of the distance square matrix is .

[0018] Step 3: Perform singular value decomposition on the cluster model parameter matrix to obtain singular vectors; Calculate the trust score through the singular vectors; In Step 3, when performing singular value decomposition on the cluster model parameter matrix to obtain singular vectors, the existing relationship in the corresponding process is: ; where represents the round of singular vectors, represents the round of cluster model parameter matrix, represents the first column vector of the right singular matrix, represents the first element on the main diagonal of the singular value matrix; Calculate the trust score through the singular vectors, and the existing relationship in the corresponding process is: ; where represents the trust score of the model update parameter of the th client in the round, represents the remaining th client's model update parameter in the round.

[0019] Step 4: Calculate the global model update parameter based on the trust score; Calculate the global model using the global model update parameter; After obtaining the global model, add Gaussian noise to the global model through the differential privacy mechanism to obtain the final global model; In Step 4, when calculating the global model update parameter based on the trust score, the existing relationship in the corresponding process is: ; where represents the global model update parameter of the round, represents the number of remaining local models after removing the largest malicious cluster; Calculate the global model using the global model update parameter, and the existing relationship in the corresponding process is: ; where denotes the global model of the round; denotes the global model of the round; denotes the learning rate of the round; After obtaining the global model, through the differential privacy mechanism, Gaussian noise is added to the global model to obtain the final global model. The relational expression existing in the corresponding process is: ; wherein, denotes the final global model, denotes adding random Gaussian noise, denotes the noise scale, denotes the mean value of the L2 norm of the remaining model update parameters, denotes taking the mean value, denotes the privacy bound, denotes the probability of breaking through the privacy bound, denotes the noise level factor.

[0020] Please refer to Figure 2 , Figure 2 which is a schematic diagram of the backdoor attack process for federated learning, and includes four steps: First, before the round of training, the server will send the global model to the clients participating in the current round of training; then after receiving the global model, the clients optimize the loss function based on the local data to train the local model update parameters; subsequently, the clients upload the trained local model update parameters to the server; finally, after receiving the model update parameters of the clients, the server aggregates the local model update parameters through the extreme algorithm FedAVG to obtain the global model.

[0021] It should be understood that each part of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.

[0022] In the description of this specification, the description referring to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.

[0023] The above-described embodiments merely represent several implementation manners of the present invention. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be subject to the appended claims.

Claims

1. A federated learning backdoor defense method based on singular value decomposition and model weight amplification, characterized in that: The method comprises the following steps: Step 1: After obtaining the model update parameters trained locally on the client, normalize the model update parameters trained locally on the client to obtain the normalized model update parameters; The normalized model update parameters are concatenated into a model update parameter matrix, and the normalized model update parameters in the model update parameter matrix are reduced in dimension by singular value decomposition to obtain the reduced-dimensional model update parameters; Step 2: Use the DBSCAN clustering algorithm to process the updated parameters of the model after dimensionality reduction to obtain clusters; Calculate the cosine distance of the elements in each clustered cluster to obtain the cosine distance between the elements; The distance matrix is ​​constructed according to the cosine distance between elements, and the number of elements in the distance matrix is ​​used to determine the cluster model parameters. Combining the cluster model parameters into a cluster model parameter matrix; Step 3: Perform singular value decomposition on the cluster model parameter matrix to obtain singular vectors; The trust score is obtained by calculating the singular vector; Step 4: Calculate the global model update parameters based on the trust score; The global model is obtained by using the global model to update the parameters and calculate the global model; After obtaining the global model, Gaussian noise is added to the global model through the differential privacy mechanism to obtain the final global model.

2. The federated learning backdoor defense method based on singular value decomposition and model weight amplification according to claim 1 is characterized in that: In step 1, after obtaining the model update parameters of the local training of the client, the model update parameters of the local training of the client are normalized to obtain the normalized model update parameters. The relationship between the corresponding process is: ; in, Indicates Round The model update parameters of each client, Represents the normalized model update parameters.

3. The federated learning backdoor defense method based on singular value decomposition and model weight amplification according to claim 2 is characterized in that: In step 2, the cosine distance is calculated for the elements in each cluster after clustering to obtain the cosine distance between the elements. Taking the first element and the second element in the cluster as an example, the relationship between the corresponding process is: ; in, Represents the cosine distance between the first element and the second element, Indicates Round The first element in the cluster, Indicates Round The second element in the cluster.

4. The federated learning backdoor defense method based on singular value decomposition and model weight amplification according to claim 3 is characterized in that: In step 2, a distance matrix is ​​constructed according to the cosine distance between elements, and the relationship between the corresponding process is: ; in, Indicates The distance matrix of clusters, Represents the element index.

5. The federated learning backdoor defense method based on singular value decomposition and model weight amplification according to claim 4 is characterized in that: In step 2, the number of elements in the distance matrix is ​​used for judgment to obtain cluster model parameters. The specific steps are as follows: If there is only one element in the distance matrix, the cluster model parameters are determined, and the corresponding process has the following relationship: ; in, Indicates Round Cluster model parameters of the cluster; When the element in the distance matrix is ​​greater than one, the cluster model parameters are obtained by calculation, and the relationship between the corresponding process is: ; in, Indicates Round No. 1 in the cluster The sum of the cosine distances from an element to every other element.

6. The federated learning backdoor defense method based on singular value decomposition and model weight amplification according to claim 5 is characterized in that: In step 3, singular value decomposition is performed on the cluster model parameter matrix to obtain singular vectors. The relationship between the corresponding process is: ; in, Indicates round singular vectors, Indicates Wheel cluster model parameter matrix, represents the first column vector of the right singular matrix, Represents the first element on the main diagonal of the singular value matrix.

7. The federated learning backdoor defense method based on singular value decomposition and model weight amplification according to claim 6 is characterized in that: In step 3, the trust score is obtained by calculating the singular vector, and the relationship between the corresponding process is: ; in, Indicates Round The trust score of the model update parameters of each client, Indicates The remaining rounds The model update parameters of each client.

8. The federated learning backdoor defense method based on singular value decomposition and model weight amplification according to claim 7 is characterized in that: In step 4, the global model update parameter is calculated based on the trust score, and the relationship between the corresponding process is: ; in, Indicates The global model update parameters of the round, Represents the number of local models remaining after removing the largest malicious cluster.

9. The federated learning backdoor defense method based on singular value decomposition and model weight amplification according to claim 8 is characterized in that: In step 4, the global model is updated by using the global model to calculate the parameters, and the corresponding process has the following relationship: ; in, Indicates The global model of the wheel, Indicates The global model of the wheel, Indicates The learning rate of the round.

10. The federated learning backdoor defense method based on singular value decomposition and model weight amplification according to claim 9 is characterized in that: In step 4, after obtaining the global model, Gaussian noise is added to the global model through the differential privacy mechanism to obtain the final global model. The relationship between the corresponding process is: ; in, represents the final global model, represents adding random Gaussian noise, represents the noise scale, represents the mean of the L2 norm of the remaining model update parameters, It means taking the mean value, Indicates privacy boundaries. represents the probability of breaking the privacy boundary, Represents the noise level factor.

Citation Information

Patent Citations

  • Defense method for horizontal federated learning system

    CN116523078A

  • Trusted model training method based on federal learning

    CN116628504A

  • Defense method for cluster federated learning attack, terminal and storage medium

    CN117424754A

  • Hardware-assisted malware detection using explainable machine learning

    US20220121744A1

Cited By

  • Graph data backdoor defense method and device based on spectral domain transformation and edge weight learning, equipment, medium and program product

    CN121256426A

  • Graph data backdoor defense method and device based on spectral domain transformation and edge weight learning, equipment, medium and program product

    CN121256426B

  • Non-IID federated learning backdoor attack defense method and system and medium

    CN121262004A

  • A non-iid federated learning backdoor attack defense method, system and medium

    CN121262004B