Federated Learning Backdoor Defense Method Based on Singular Value Decomposition and Model Weight Amplification

Through the federated learning method of singular value decomposition and model weight amplification, the singular value decomposition and differential privacy mechanisms are used to solve the detection problem of backdoor attacks in federated learning, and effective defense under non-independent and homogeneous data sets are achieved, and defense effect is improved.

CN120124075BActive Publication Date: 2025-07-29JIANGXI UNIVERSITY OF FINANCE AND ECONOMICS
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510602497.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-12
Publication Date
2025-07-29
Estimated Expiration
2045-05-12

AI Technical Summary

Technical Problem

When defending against backdoor attacks, existing federated learning methods have the assumption that detection is difficult, cropping threshold is difficult, differential privacy budget is difficult, and relying on clean root datasets, resulting in poor defense effects.

Method used

Using singular value decomposition and model weight amplification methods, through normalization, dimensionality reduction, clustering, singular value decomposition and differential privacy mechanisms, trust scores are calculated and Gaussian noise is added to build a global model to resist backdoor attacks.

Benefits of technology

It effectively resists backdoor attacks from multiple malicious clients without assuming that the number of malicious clients is less than that of benign clients. It is suitable for non-independent and same-distributed client datasets, and does not rely on clean root datasets, which improves defense effect.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120124075B_ABST
    Figure CN120124075B_ABST
Patent Text Reader

Abstract

The present invention proposes a federated learning backdoor defense method based on singular value decomposition and model weight amplification. The method includes: normalizing the model update parameters trained locally by the client to obtain the normalized model update parameters; obtaining the dimension-reduced model update parameters based on the normalized model update parameters; performing a clustering algorithm on the dimension-reduced model update parameters to obtain the clustered clusters; obtaining the cluster model parameters based on the clustered clusters; combining the cluster model parameters of each cluster into a cluster model parameter matrix; performing singular value decomposition on the cluster model parameter matrix to obtain singular vectors; obtaining trust scores through the singular vectors; obtaining the global model update parameters based on the trust scores; calculating the global model using the global model update parameters; and adding Gaussian noise to the global model through the differential privacy mechanism to obtain the final global model. The present invention can still effectively resist backdoor attacks even in the scenario where the client datasets are non-independent and identically distributed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence security technology, and particularly to a federated learning backdoor defense method based on singular value decomposition and model weight amplification. Background Art

[0002] Traditional centralized machine learning methods require collecting a large amount of user data into a central database. However, continuous data leakage incidents have raised concerns about data privacy and security. To protect user data privacy, Federated Learning (FL) has emerged and received significant attention. Federated learning is a distributed machine learning paradigm that collaboratively maintains a global model between a central server and multiple participants without the need for participants to upload data to the server, thus effectively protecting client data privacy to a certain extent. However, many existing studies have shown that the distributed nature of federated learning makes it vulnerable to backdoor attacks. How to mitigate backdoor attacks in federated learning is an issue that we urgently need to consider.

[0003] To defend against backdoor attacks in federated learning, recently proposed solutions can be divided into two categories, namely backdoor anomaly detection and backdoor mitigation. The backdoor anomaly detection method in FL mainly separates benign updates and malicious updates through unsupervised machine learning methods, and then further detects malicious participants.

[0004] Existing methods for defending against backdoor attacks in FL have the following limitations: for backdoor anomaly detection methods, since the training data of clients is usually non-IID, it is difficult to identify malicious model updates using general detection methods. At the same time, attackers can make malicious models similar to benign models through constraint and scaling methods to avoid the server's anomaly detection mechanism; although backdoor mitigation methods can achieve the effect of resisting backdoor attacks, these measures also have some deficiencies. It is difficult to determine the threshold for pruning model parameters, and it is difficult to define the privacy budget of differential privacy. Adding too much noise will reduce the benign performance of the global model. Finally, the calculation of trust scores often depends on the assumption that the server has a clean root dataset or that the number of benign clients is more than that of malicious clients. Summary of the Invention

[0005] In view of the above situation, the main purpose of the present invention is to propose a federated learning backdoor defense method and system based on singular value decomposition and model weight amplification to solve the above technical problems.

[0006] The present invention proposes a federated learning backdoor defense method based on singular value decomposition and model weight amplification, and the method includes the following steps:

[0007] Step 1: After obtaining the model update parameters trained locally on the client side, normalize the model update parameters trained locally on the client side to obtain the normalized model update parameters;

[0008] Concatenate the normalized model update parameters into a model update parameter matrix, and through singular value decomposition, reduce the dimension of the normalized model update parameters in the model update parameter matrix to obtain the dimension-reduced model update parameters;

[0009] Step 2: Process the dimension-reduced model update parameters using the DBSCAN clustering algorithm to obtain the clustered clusters;

[0010] Calculate the cosine distance between the elements in each clustered cluster to obtain the cosine distance between the elements;

[0011] Construct a distance square matrix based on the cosine distance between the elements, and make a judgment through the number of elements in the distance square matrix to obtain the cluster model parameters;

[0012] Combine the cluster model parameters of each cluster into a cluster model parameter matrix;

[0013] Step 3: Perform singular value decomposition on the cluster model parameter matrix to obtain singular vectors;

[0014] Calculate the trust score through the singular vectors;

[0015] Step 4: Calculate the global model update parameters based on the trust score;

[0016] Calculate the global model using the global model update parameters;

[0017] After obtaining the global model, through the differential privacy mechanism, add Gaussian noise to the global model to obtain the final global model.

[0018] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0019] 1. The present invention does not need to assume that the number of malicious clients is less than that of benign clients, and can effectively resist the backdoor attacks launched by multiple malicious clients simultaneously;

[0020] 2. The present invention calculates a singular vector as the basis for trust guidance, thus eliminating the need to assume that the server side requires a clean root data set;

[0021] 3. The present invention can still effectively resist backdoor attacks in the scenario where the client datasets are non-independent and identically distributed.

[0022] The additional aspects and advantages of the present invention will be partially given in the following description, partially become apparent from the following description, or be understood through the embodiments of the present invention. Brief Description of the Drawings

[0023] Figure 1 This is the flowchart of the federated learning backdoor defense method based on singular value decomposition and model weight amplification proposed by the present invention;

[0024] Figure 2 It is a schematic diagram of the federated learning backdoor attack process. Specific embodiments

[0025] The embodiments of the present invention will be described in detail below. The examples of the embodiments are shown in the drawings, where the same or similar reference numerals denote the same or similar elements or elements with the same or similar functions throughout. The embodiments described below by referring to the drawings are exemplary and are only used to explain the present invention and should not be construed as a limitation of the present invention.

[0026] Referring to the following description and drawings, these and other aspects of the embodiments of the present invention will be clear. In these descriptions and drawings, some specific embodiments of the embodiments of the present invention are specifically disclosed to represent some ways of implementing the principles of the embodiments of the present invention, but it should be understood that the scope of the embodiments of the present invention is not limited thereto.

[0027] Please refer to Figure 1 , the embodiments of the present invention propose a federated learning backdoor defense method based on singular value decomposition and model weight amplification. The method includes the following steps:

[0028] Step 1: After obtaining the model update parameters locally trained by the client, normalize the model update parameters locally trained by the client to obtain the normalized model update parameters;

[0029] Concatenate the normalized model update parameters into a model update parameter matrix, and through singular value decomposition, reduce the dimension of the normalized model update parameters in the model update parameter matrix to obtain the dimension-reduced model update parameters;

[0030] In Step 1, after obtaining the model update parameters locally trained by the client, normalize the model update parameters locally trained by the client to obtain the normalized model update parameters. The relationship existing in the corresponding process is:

[0031] ;

[0032] Among them, represents the model update parameters of the th round of the th client, represents the normalized model update parameters.

[0033] Further, in this step, after obtaining the model update parameter matrix, the model update parameter matrix is decomposed using singular values to obtain the singular value matrix of the model update parameter matrix, the left singular matrix of the model update parameter matrix, and the right singular matrix of the model update parameter matrix;

[0034] Among them, the elements on the main diagonal of the singular value matrix of the model update parameter matrix are singular values arranged from largest to smallest. The larger the singular value, the more characteristic information it contains. Therefore, the first two singular values are selected to retain the corresponding benign features and backdoor features of the matrix, so as to achieve the effect of distinguishing between benign model parameters and malicious model parameters.

[0035] Specifically, the model parameter matrix after dimensionality reduction is composed of multiple two-dimensional vectors.

[0036] Step 2: Process the model update parameters after dimensionality reduction using the DBSCAN clustering algorithm to obtain the clusters after clustering;

[0037] Calculate the cosine distance between the elements in each cluster after clustering to obtain the cosine distance between the elements;

[0038] Construct a distance square matrix based on the cosine distance between the elements, and judge by the number of elements in the distance square matrix to obtain the cluster model parameters;

[0039] Combine the cluster model parameters into a cluster model parameter matrix;

[0040] In Step 2, calculate the cosine distance between the elements in each cluster after clustering to obtain the cosine distance between the elements. Taking the first element and the second element in the cluster as an example, the relational expression in the corresponding process is:

[0041] ;

[0042] Among them, represents the cosine distance between the first element and the second element, represents the th first element in the th round and the second element in the

[0043] Construct a distance square matrix based on the cosine distance between the elements. The relational expression in the corresponding process is:

[0044] ;

[0045] Among them, represents the th distance square matrix of the

[0046] Judgment is made based on the number of elements in the distance square matrix to obtain the cluster model parameters. The specific steps are as follows:

[0047] When there is only one element in the distance square matrix, the cluster model parameters are determined. The relational expression existing in the corresponding process is:

[0048] ;

[0049] wherein, represents the cluster model parameter of the th cluster in the

[0050] When the number of elements in the distance square matrix is greater than one, the cluster model parameters are obtained through calculation. The relational expression existing in the corresponding process is:

[0051] ;

[0052] wherein, represents the sum of the cosine distances from the th element in the th cluster to other elements.

[0053] Furthermore, in this step, the dimension of the cluster model parameter matrix is , wherein, represents the feature dimension of each cluster.

[0054] Specifically, the size of the distance square matrix is .

[0055] Step 3: Perform singular value decomposition on the cluster model parameter matrix to obtain singular vectors;

[0056] Calculate the trust score through the singular vectors;

[0057] In Step 3, perform singular value decomposition on the cluster model parameter matrix to obtain singular vectors. The relational expression existing in the corresponding process is:

[0058] ;

[0059] wherein, represents the singular vector of the th round, represents the cluster model parameter matrix of the th round, represents the first column vector of the right singular matrix, represents the first element on the main diagonal of the singular value matrix;

[0060] The trust score is calculated through singular vectors, and the relational expressions in the corresponding process are as follows:

[0061] ;

[0062] Among them, represents the trust score of the model update parameters of the th client in the th round, represents the remaining th client's model update parameters in the th round.

[0063] Step 4: Calculate the global model update parameters based on the trust score;

[0064] Calculate the global model using the global model update parameters;

[0065] After obtaining the global model, add Gaussian noise to the global model through the differential privacy mechanism to obtain the final global model;

[0066] In Step 4, the global model update parameters are calculated based on the trust score, and the relational expressions in the corresponding process are as follows:

[0067] ;

[0068] Among them, represents the global model update parameters of the th round, represents the number of remaining local models after removing the largest malicious cluster;

[0069] Calculate the global model using the global model update parameters, and the relational expressions in the corresponding process are as follows:

[0070] ;

[0071] Among them, represents the global model of the th round, represents the global model of the th round, represents the learning rate of the th round;

[0072] After obtaining the global model, add Gaussian noise to the global model through the differential privacy mechanism to obtain the final global model, and the relational expressions in the corresponding process are as follows:

[0073] ;

[0074] Among them, represents the final global model, Denote adding random Gaussian noise, Denote the noise scale, Denote the mean of the L2 norm of the remaining model update parameters, Denote taking the mean, Denote the privacy bound, Denote the probability of breaching the privacy bound, Denote the noise level factor.

[0075] Please refer to Figure 2 , Figure 2 which is a schematic diagram of the backdoor attack process for federated learning, including four steps: First, before the round of training, the server will send the global model to the clients participating in the current round of training; then after receiving the global model, the clients optimize the loss function based on local data to train the local model update parameters; subsequently, the clients upload the trained local model update parameters to the server; finally, after receiving the model update parameters from the clients, the server aggregates the local model update parameters through the extreme algorithm FedAVG to obtain the global model.

[0076] It should be understood that each part of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.

[0077] In the description of this specification, the descriptions referring to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.

[0078] The above-described embodiments merely represent several implementation manners of the present invention. Their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the patent for the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all fall within the protection scope of the present invention. Therefore, the protection scope of the patent for the present invention shall be subject to the appended claims.

Claims

1. A federated learning backdoor defense method based on singular value decomposition and model weight amplification, characterized in that The method includes the following steps: Step 1: After obtaining the model update parameters trained locally on the client side, normalize the model update parameters trained locally on the client side to obtain the normalized model update parameters; Concatenate the normalized model update parameters into a model update parameter matrix, and through singular value decomposition, reduce the dimension of the normalized model update parameters in the model update parameter matrix to obtain the dimension-reduced model update parameters; Step 2: Process the dimension-reduced model update parameters using the DBSCAN clustering algorithm to obtain the clusters after clustering; Calculate the cosine distance between the elements in each cluster after clustering to obtain the cosine distance between the elements; Construct a distance square matrix based on the cosine distance between the elements, and make a judgment based on the number of elements in the distance square matrix to obtain the cluster model parameters; Combine the cluster model parameters of each cluster into a cluster model parameter matrix; Step 3: Perform singular value decomposition on the cluster model parameter matrix to obtain singular vectors; Calculate the trust score through the singular vectors; Step 4: Calculate the global model update parameters based on the trust score; Calculate the global model using the global model update parameters; After obtaining the global model, through the differential privacy mechanism, add Gaussian noise to the global model to obtain the final global model; In the said Step 3, when performing singular value decomposition on the cluster model parameter matrix to obtain singular vectors, the existing relational expression for the corresponding process is: ; Among them, represents the round singular vector, represents the round cluster model parameter matrix, represents the first column vector of the right singular matrix, represents the first element on the main diagonal of the singular value matrix; In the said Step 3, when calculating the trust score through the singular vectors, the existing relational expression for the corresponding process is: ; Among them, represents the trust score of the model update parameters of the th client in the round, represents the remaining th client's model update parameters in the In the said Step 4, when calculating the global model update parameters based on the trust score, the existing relational expression for the corresponding process is: ; Among them, represents the global model update parameters for the round, represents the number of remaining local models after removing the largest malicious cluster.

2. The federated learning backdoor defense method based on singular value decomposition and model weight amplification according to claim 1, wherein In the said Step 1, after obtaining the model update parameters trained locally on the client side, when normalizing the model update parameters trained locally on the client side to obtain the normalized model update parameters, the existing relational expression for the corresponding process is: ; Among them, represents the model update parameter of the nth client in the round, and represents the normalized model update parameter.

3. The federated learning backdoor defense method based on singular value decomposition and model weight amplification according to claim 2, characterized in that, In the said Step 2, when calculating the cosine distance between the elements in each cluster after clustering to obtain the cosine distance between the elements, taking the first element and the second element in the cluster as an example, the existing relational expression for the corresponding process is: ; Among them, represents the cosine distance between the first element and the second element, represents the first element in the cluster in the round and represents the second element in the cluster in the round.

4. The federated learning backdoor defense method based on singular value decomposition and model weight amplification according to claim 3, characterized in that In the said Step 2, when constructing a distance square matrix based on the cosine distance between the elements, the existing relational expression for the corresponding process is: ; Among them, represents the distance square matrix of the th cluster, represents the element index.

5. The federated learning backdoor defense method based on singular value decomposition and model weight amplification according to claim 4, characterized in that In the said Step 2, when making a judgment based on the number of elements in the distance square matrix to obtain the cluster model parameters, the specific steps are as follows: If there is only one element in the distance square matrix, determine the cluster model parameters, and the existing relational expression for the corresponding process is: ; Among them, represents the cluster model parameter of the round cluster; When the number of elements in the distance square matrix is greater than one, calculate to obtain the cluster model parameters, and the existing relational expression for the corresponding process is: ; Among them, represents the sum of the cosine distances from the th element to other elements in the th cluster in the th round.

6. The federated learning backdoor defense method based on singular value decomposition and model weight amplification according to claim 5, characterized in that, In the said Step 4, when calculating the global model using the global model update parameters, the existing relational expression for the corresponding process is: ; Among them, represents the global model of the round, represents the global model of the round, and represents the learning rate of the round.

7. The federated learning backdoor defense method based on singular value decomposition and model weight amplification according to claim 6, characterized in that In the said Step 4, after obtaining the global model, when adding Gaussian noise to the global model through the differential privacy mechanism to obtain the final global model, the existing relational expression for the corresponding process is: ; Among them, represents the final global model, represents adding random Gaussian noise, represents the noise scale, represents the mean of the L2 norm of the remaining model update parameters, represents taking the mean, represents the privacy bound, represents the probability of breaking the privacy bound, represents the noise level factor.

Citation Information

Patent Citations

  • Trusted model training method based on federal learning

    CN116628504A

  • Defense method for cluster federated learning attack, terminal and storage medium

    CN117424754A