An Adaptive Differential Privacy Federated Learning Training Method, Medium, and Device

Through the personalized local momentum mechanism and adaptive differential privacy federated learning training method with adaptive crop threshold adjustment, data heterogeneity and privacy-utility balance problems are solved, the convergence speed and accuracy of the model are improved, and the good balance between privacy protection and performance is achieved.

CN120124780BActive Publication Date: 2025-07-08NANJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510601003.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-12
Publication Date
2025-07-08
Estimated Expiration
2045-05-12

AI Technical Summary

Technical Problem

Differential privacy federated learning faces the dual challenges of data heterogeneity and privacy-utility balance, with serious client drift, noise affects model accuracy and insufficient privacy protection.

Method used

Adaptive differential privacy federated learning training method using personalized local momentum mechanism and adaptive crop threshold adjustment is optimized through client random scheduling, personalized momentum update and crop threshold adaptive adjustment, combined with differential privacy Gaussian noise, the model training process is optimized.

Benefits of technology

Effectively reduce the impact of data heterogeneity, improve model convergence speed and accuracy, balance privacy protection and model performance, and improve federated learning efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120124780B_ABST
    Figure CN120124780B_ABST
Patent Text Reader

Abstract

The present invention discloses an adaptive differential privacy federated learning training method, medium and device. The method includes: S1. The cloud server selects clients and broadcasts the global model parameters and clipping thresholds to the selected clients; S2. The selected clients correct the global model using the personalized local momentum mechanism and perform client model training locally; S3. The cloud server aggregates the client model parameters to generate a new global model; S4. Calculate the loss value of the new global model. If the loss value decreases for three consecutive rounds, adjust the clipping threshold; S5. When the aggregation times of the client models reach the preset communication rounds, stop the training. Otherwise, return to S1 and continue the next round of training. The present invention can not only improve the training efficiency, but also effectively cope with the change of data distribution, and improve the training effect on the premise of ensuring differential privacy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of federated learning models, and in particular to an adaptive differential privacy federated learning training method, medium and device. Background Art

[0002] With the continuous development of the information society, the protection of privacy data has become increasingly important. In this context, federated learning, as an emerging machine learning method, has attracted much attention. Federated learning is an emerging distributed machine learning algorithm framework that can collaboratively train models without sharing data among participants. While protecting user privacy, federated learning combines multi-party data for joint modeling to solve the "data silo" problem. From the perspective of technological development, at present, federated learning mainly focuses on in-depth research on challenges such as communication bottlenecks, data heterogeneity, and privacy issues.

[0003] Research work related to the security and privacy of data has received much attention even before the proposal of federated learning. In the prior art, one of the most advanced technologies for mitigating privacy risks in federated learning is differential privacy. Differential privacy prevents privacy leakage by introducing random noise into the data, so the use of differential privacy technology can effectively address privacy issues in federated learning. However, in practical applications, differential privacy federated learning faces the dual challenges of data heterogeneity and privacy-utility balance. Specifically, the data of clients is often non-independent and identically distributed (non-IID), which leads to the client drift phenomenon, that is, there are significant differences in the model update directions of different clients. At the same time, the differential privacy technology will introduce noise in the process of protecting user privacy. Too much noise will affect the accuracy of the model, and too little noise cannot fully protect privacy. Summary of the Invention

[0004] An adaptive differential privacy federated learning training method, medium and device provided by the present invention can at least solve one of the above technical problems.

[0005] To solve the above technical problems, the present invention adopts the following technical solutions:

[0006] An adaptive differential privacy federated learning training method includes the following steps:

[0007] S1. The cloud server selects clients according to the client random scheduling strategy, and broadcasts the global model parameters and the clipping threshold to the selected clients;

[0008] S2. The selected clients use the personalized local momentum mechanism to correct the global model to form a client model, and perform client model training locally;

[0009] S3. After the cloud server receives all the client models participating in the training in this round, it aggregates the client model parameters to generate a new global model;

[0010] S4. Calculate the loss value of the new global model. If the loss value decreases for three consecutive rounds, adjust the pruning threshold until the aggregation times of the client models reach the preset communication rounds;

[0011] S5. When the aggregation times of the client models reach the preset communication rounds, stop the adaptive differential privacy federated learning training based on personalized local momentum. Otherwise, return to S1 and continue the next round of training.

[0012] Further, in S1, before the training starts, the cloud server initializes the pruning threshold C0 = 1. Before each round of communication, it selects s clients. The strategy for selecting clients is the client random scheduling strategy, that is, randomly sample s clients in each round of communication. The sampling formula is:

[0013] s = qU

[0014] where q is the sampling factor, 0 < q < 1, and U is the total number of clients;

[0015] After selecting the clients, the cloud server broadcasts the global model of the t-th round of communication t and the pruning threshold C to the selected clients.

[0016] Further, in S2, each client executes an optimization algorithm according to the task type and model architecture to update its corresponding local model parameters. This process can be iterated multiple times, and the local model parameters are updated in each iteration. When the client completes the preset number of local model iterations, it prunes and adds noise to the local model parameters according to the pruning threshold C t received from the cloud server, and uploads the updated and noise-added local model parameters to the cloud server.

[0017] Further, S2 further includes:

[0018] S21. Each client stores personalized momentum locally. The selected clients use the local personalized momentum to initialize the client model after receiving the global model broadcast by the cloud server:

[0019]

[0020] where:

[0021] i represents the client;

[0022] t represents the communication round;

[0023] Represents the initial model of client i in the t-th round of communication, that is, the model of the 0-th local iteration;

[0024] Represents the personalized momentum of client i in the t-th round of communication;

[0025] S22. Client i uses the local dataset D i for training to as the loss function, where x j represents the input feature of the j-th sample in the local dataset, and y j represents the true label corresponding to the j-th sample in the local dataset. Then, the loss function of client i on the local dataset D i is defined as:

[0026]

[0027] Client i uses the corrected initial model , and uses the local dataset D i to solve for the optimal parameter w. The goal is to find the optimal model parameters that minimize the loss function ;

[0028] S23. Client i performs k rounds of local iterations based on the stochastic gradient descent algorithm, and the update method is:

[0029]

[0030] where η represents the calculation model update step size, represents the model gradient, represents the model of client i in the k-th round of local iteration, represents the model of client i in the (k - 1)-th round of local iteration;

[0031] S24. After client i finishes the local iteration, calculate the local update Δw i as:

[0032]

[0033] where, represents the model of client i after performing k rounds of local iteration in the t-th round of communication;

[0034] And update the personalized local momentum as:

[0035]

[0036] where λ1 and λ2 are momentum coefficients, and 0 < λ1 < 1, 0 < λ2 < 1, Denote the personalized momentum of client i in the (t + 1)-th round of communication;

[0037] S25. According to the clipping threshold C received by the cloud server t clip the local update Δw i as follows:

[0038]

[0039] and add Gaussian noise that satisfies ε-differential privacy:

[0040]

[0041] where:

[0042] ε represents the privacy protection strength. The smaller the value of ε, the more noise is added and the greater the privacy protection strength;

[0043] represents Gaussian noise, and σ is the noise multiplier coefficient;

[0044] represents the model parameters of client i after clipping;

[0045] represents the model parameters of client i after adding Gaussian noise;

[0046] S26. After adding noise, client i uploads the parameter to the cloud server.

[0047] Furthermore, in S3, after receiving the model parameters of all clients participating in training in this round of communication, the cloud server performs weighted average aggregation on the client model parameters:

[0048]

[0049] where:

[0050] represents the new global model;

[0051] represents the total size of the datasets of the s sampled clients.

[0052] Furthermore, in S4, the cloud server calculates the cross-entropy loss value L on the validation set using the aggregated new global model t , and adaptively adjusts the clipping threshold C for the next round of communication using the following formula t+1 . If the loss value L t decreases continuously in three consecutive communication rounds, then adjust the clipping threshold C t as follows:

[0053]

[0054] Among them, β is the clipping threshold decay coefficient, and 0 < β < 1, L t represents the central-side loss of the global model in the t-th round.

[0055] A computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the processor is caused to execute the steps of the above-mentioned adaptive differential privacy federated learning training method.

[0056] A computer device includes a memory and a processor. The memory stores a computer program. When the computer program is executed by the processor, the processor is caused to execute the steps of the above-mentioned adaptive differential privacy federated learning training method.

[0057] The beneficial effects of the present invention are embodied in:

[0058] 1. The client adopts a personalized local momentum mechanism, effectively coping with the problem of data heterogeneity commonly existing in actual scenarios, reducing the bias caused by the client drift phenomenon, and accelerating the local training process of the client.

[0059] 2. By means of the strategy of adaptively reducing the clipping threshold, an appropriate amount of random noise is dynamically added to the model parameters, reducing the interference introduced by the noise, and improving the convergence speed and final accuracy of the model. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application.

[0061] Figure 1 is a schematic flowchart of the adaptive differential privacy federated learning training method according to an embodiment of the present invention.

[0062] Figure 2 is a graph showing the performance of the model accuracy in the test set in the comparative experiment according to an embodiment of the present invention.

[0063] Figure 3 is a structural block diagram of the computer device according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0064] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0065] It should be noted that the meaning of "and / or" appearing throughout the text includes three parallel solutions. Taking "A and / or B" as an example, it includes solution A, or solution B, or the solution where A and B are satisfied simultaneously. In addition, "a plurality" means two or more. In addition, the technical solutions between the various embodiments can be combined with each other, but it must be based on the ability of those of ordinary skill in the art to implement. When the combination of technical solutions conflicts with each other or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection required by the present invention.

[0066] See Figure 1 , the embodiments of the present invention provide an adaptive differential privacy federated learning training method, including the following steps:

[0067] S1. The cloud server selects clients according to the client random scheduling strategy and broadcasts the global model parameters and the clipping threshold to the selected clients;

[0068] S2. The selected clients use the personalized local momentum mechanism to correct the global model to form a client model and perform client model training locally;

[0069] S3. After the cloud server receives all the client models participating in the training in this round, it aggregates the client model parameters to generate a new global model;

[0070] S4. Calculate the loss value of the new global model. If the loss value decreases for three consecutive rounds, adjust the clipping threshold until the aggregation times of the client models reach the preset communication rounds;

[0071] S5. When the aggregation times of the client models reach the preset communication rounds, stop the adaptive differential privacy federated learning training based on personalized local momentum. Otherwise, return to S1 and continue the next round of training.

[0072] In this embodiment, in S1, the cloud server initializes the clipping threshold C0 = 1 before the training starts, selects s clients before each round of communication, and the strategy for selecting clients is the client random scheduling strategy, that is, randomly sample s clients in each round of communication, and the sampling formula is:

[0073] s = qU

[0074] Among them, q is the sampling factor, 0 < q < 1, and U is the total number of clients;

[0075] After selecting the clients, the cloud server broadcasts the global model and the pruning threshold C t to the selected clients.

[0076] In this embodiment, in S2, each client executes an optimization algorithm according to the task type and model architecture to update its corresponding local model parameters. This process can be iterated multiple times, and the local model parameters are updated in each iteration. When the client completes the preset number of local model iterations, according to the pruning threshold C received by the cloud server t the local model parameters are pruned and noise is added, and the updated and noisy local model parameters are uploaded to the cloud server.

[0077] In this embodiment, S2 further includes:

[0078] S21. Each client stores personalized momentum locally. After the selected client receives the global model broadcast by the cloud server it initializes the client model using the local personalized momentum:

[0079]

[0080] Where:

[0081] i represents the client;

[0082] t represents the communication round;

[0083] represents the initialization model of client i in the t-th communication round, that is, the 0-th local iteration model;

[0084] represents the personalized momentum of client i in the t-th communication round;

[0085] S22. Client i uses the local dataset D i for training, with as the loss function, where x j represents the input feature of the j-th sample in the local dataset, and y j represents the true label corresponding to the j-th sample in the local dataset. Then the loss function of client i on the local dataset D i is defined as:

[0086]

[0087] The client i uses the corrected initialization model , and utilizes the local dataset D i to solve for the optimal parameter w. The goal is to find the optimal model parameters that minimize the loss function ;

[0088] S23. The client i performs k rounds of local iterations based on the stochastic gradient descent algorithm, and the update method is as follows:

[0089]

[0090] where η represents the calculation model update step size, represents the model gradient, represents the model of the client i in the k-th round of local iteration, represents the model of the client i in the (k - 1)-th round of local iteration;

[0091] S24. After the client i finishes the local iteration, it calculates the local update Δw i as:

[0092]

[0093] where, represents the model of the client i after performing k rounds of local iteration in the t-th round of communication;

[0094] and updates the personalized local momentum as:

[0095]

[0096] where λ1 and λ2 are momentum coefficients, and 0 < λ1 < 1, 0 < λ2 < 1, represents the personalized momentum of the client i in the (t + 1)-th round of communication;

[0097] S25. According to the clipping threshold C received by the cloud server t clip the local update Δw i :

[0098]

[0099] and add Gaussian noise that satisfies ε-differential privacy:

[0100]

[0101] where:

[0102] ε represents the privacy protection strength. The smaller the ε value, the more noise is added, and the greater the privacy protection strength;

[0103] represents the Gaussian noise, and σ is the noise multiplier coefficient;

[0104] Denote the model parameters of client i after clipping;

[0105] Denote the model parameters of client i after adding Gaussian noise;

[0106] S26. After the noise addition is completed, client i uploads the parameter to the cloud server.

[0107] In this embodiment, in S3, after the cloud server receives all the client models participating in the training in this round of communication, it performs weighted average aggregation on the client model parameters:

[0108]

[0109] Where:

[0110] Denote the new global model;

[0111] Denote the total size of the datasets of the s sampled clients.

[0112] In this embodiment, in S4, the cloud server calculates the cross-entropy loss value L on the validation set using the aggregated new global model t , and adaptively adjusts the clipping threshold C for the next round of communication using the following formula t+1 , if the loss value L t continuously decreases in three consecutive communication rounds, then adjust the clipping threshold C t :

[0113]

[0114] Where β is the clipping threshold decay coefficient, and 0 < β < 1, L t denotes the central-side loss of the global model in the t-th round.

[0115] To verify the application of the present invention, a specific experiment will be provided below to further illustrate this adaptive differential privacy federated learning training method:

[0116] Experimental environment:

[0117] The experiment considers training in a distributed framework consisting of one cloud server and 100 clients to participate in the training.

[0118] In local training, a convolutional neural network was considered as the model, and validation was carried out on the CIFAR-10 and CIFAR-100 datasets. The model initialized three convolutional layers and three fully connected layers, and max-pooling operations were used after each convolutional layer. Among them: the input channels of the first convolutional layer were 3, the output channels were 16, the kernel size was 3, and the padding was 1. The input channels of the second convolutional layer were 16, the output channels were 32, the kernel size was 3, and the padding was 1. The input channels of the third convolutional layer were 32, the output channels were 32, the kernel size was 3, and the padding was 1. The input nodes of the first fully connected layer were 32×4×4, and the output nodes were 32×4×4. The input nodes of the second fully connected layer were 32×4×4, and the output nodes were 32×2×2. The input nodes of the third fully connected layer were 32×2×2, and the output nodes were 10. The input data passed through the first convolutional layer, then ReLU activation and max-pooling were performed, then passed through the second convolutional layer, and ReLU activation and max-pooling were also performed. Then, it passed through the third convolutional layer, and ReLU activation and max-pooling were performed again. Finally, the data was flattened to 32×4×4, passed through the first fully connected layer and ReLU activation was applied, then passed through the second fully connected layer and ReLU activation was applied, and finally the output result was returned through the three fully connected layers.

[0119] In this experiment, the CIFAR-10 and CIFAR-100 datasets were used for validation. The CIFAR-10 dataset contains 60,000 images in 10 categories, including 50,000 training images and 10,000 test images. The CIFAR-100 dataset is an extended version of CIFAR-10, containing 60,000 images in 100 categories, including 50,000 training images and 10,000 test images. Compared with CIFAR-10, CIFAR-100 contains more categories and higher challenges, and is suitable for more complex image classification tasks. For the training set data, this experiment adopted the Dirichlet Data Partitioning strategy to simulate the non-independent and identically distributed scenario, and its characteristic is that it can generate an unbalanced and biased data distribution.

[0120] In this experiment, the system model parameters were configured as shown in Table 1 below:

[0121] Table 1 System Model Parameter Configuration Table

[0122]

[0123] Comparison experiment settings:

[0124] The performance of the method proposed in the present invention is compared with several latest methods in differential privacy federated learning, including the differential privacy federated learning algorithm (DP-FedAvg) and the differential privacy federated learning algorithm based on sharpness-aware minimization (DP-FedSAM).

[0125] Conclusion analysis:

[0126] The experimental results are as Figure 2 shown. It can be seen that the method of the present invention significantly outperforms the comparison algorithms DP-FedAvg and DP-FedSAM in differential privacy federated learning. In terms of the improvement of the test set accuracy, the method of the present invention shows a faster convergence speed and a higher final accuracy on both the CIFAR-10 and CIFAR-100 datasets. During the entire training process, the accuracy significantly exceeds the comparison algorithms, finally reaching approximately 56% on the CIFAR-10 dataset and approximately 23% on the CIFAR-100 dataset. This shows that the present invention effectively reduces the bias problem introduced by differential privacy noise in the global model through the personalized momentum mechanism and dynamic pruning threshold adjustment, enabling the client to quickly adjust and optimize the local model, and improving the efficiency and effect of federated learning.

[0127] The embodiment of the present invention also provides a computer-readable storage medium storing a computer program, which when executed by a processor causes the processor to execute the steps of the above-mentioned adaptive differential privacy federated learning training method.

[0128] See Figure 3 , the embodiment of the present invention also provides a computer device including a memory and a processor, the memory storing a computer program, which when executed by the processor causes the processor to execute the steps of the above-mentioned adaptive differential privacy federated learning training method.

[0129] The embodiment of the present invention also provides a computer program product containing instructions, which when running on a computer causes the computer to execute the steps of the above-mentioned adaptive differential privacy federated learning training method.

[0130] It is understandable that the system, device and storage medium provided by the embodiment of the present invention correspond to the method provided by the embodiment of the present invention, and the explanations, examples and beneficial effects of the relevant content can refer to the corresponding parts in the above-mentioned adaptive differential privacy federated learning training method.

[0131] It should be noted that those of ordinary skill in the art can understand that all or part of the steps implemented in the embodiments of the present invention can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using hardware, it can be implemented in whole or in part in the form of purchasing standard parts or modified parts. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid-state drive (SSD)).

[0132] In summary, to address the dual challenges of data heterogeneity and privacy-utility balance faced by differential privacy federated learning, the present invention proposes an adaptive differential privacy federated learning training method, which has two complementary innovation points in differential privacy federated learning: First, the personalized momentum mechanism accelerates the early convergence of the model and improves the communication efficiency; Second, the dynamic pruning threshold adjustment optimizes the later training process of the model, further improving the accuracy and generalization ability. The above experimental results also further fully demonstrate that the present invention achieves a good balance between privacy protection and model performance, providing strong support for the practical application of differential privacy federated learning in privacy-sensitive scenarios.

[0133] It should be understood that the examples and embodiments described herein are for illustrative purposes only and are not intended to limit the present invention. Those skilled in the art can make various modifications or changes based on it. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. An adaptive differential privacy federated learning training method, characterized in that, It includes the following steps: S1. The cloud server selects clients according to the client random scheduling policy, and broadcasts the global model parameters and the clipping threshold to the selected clients; S2. The selected clients use the personalized local momentum mechanism to correct the global model, form the client model, and perform client model training locally; S3. After the cloud server receives all the client models participating in the training in this round, it aggregates the client model parameters to generate a new global model; S4. Calculate the loss value of the new global model. If the loss value drops for three consecutive rounds, adjust the clipping threshold until the aggregation times of the client models reach the preset communication rounds; S5. When the aggregation times of the client models reach the preset communication rounds, stop the adaptive differential privacy federated learning training based on personalized local momentum. Otherwise, return to S1 and continue the next round of training; The S2 further includes: S21. Each client stores personalized momentum locally. The selected client initializes the client model with the local personalized momentum after receiving the global model broadcast by the cloud server. After that, the client model is initialized with the local personalized momentum: Where: i represents the client; t represents the communication round; Denote the initial model of client i in the t-th round of communication, that is, the model of the 0-th local iteration; Denote the personalized momentum of client i in the t-th round of communication; S22. The client i uses the local dataset D i for training, with as the loss function, where x j represents the input feature of the j-th sample in the local dataset, and y j represents the true label corresponding to the j-th sample in the local dataset. Then, the loss function of the client i on the local dataset D i is defined as: The client i uses the corrected initialization model , and uses the local dataset D i to solve for the optimal parameter w, with the goal of finding the optimal model parameters that minimize the loss function ; S23. The client i performs k rounds of local iterations based on the stochastic gradient descent algorithm, and the update method is: where η represents the update step size of the computing model, represents the model gradient, represents the model of the i-th client in the k-th local iteration, represents the model of the i-th client in the (k - 1)-th local iteration; After the client i finishes the local iteration, calculate the local update Δw i It is: Among them, represents the model after client i performs k rounds of local iterations in the t-th round of communication; And update the personalized local momentum as: where λ1 and λ2 are momentum coefficients, and 0 < λ1 < 1, 0 < λ2 < 1, represents the personalized momentum of client i in the (t + 1)-th round of communication; S25. According to the clipping threshold C received by the cloud server t clip the local update Δw i as follows: And add Gaussian noise that satisfies ε-differential privacy: Where: ε represents the privacy protection strength. The smaller the ε value, the more noise is added, and the greater the privacy protection strength; represents Gaussian noise, and σ is the noise multiplication factor; Indicates the model parameters after the client i is pruned; Indicates the model parameters after adding Gaussian noise to client i; S26. After the noise addition ends, client i uploads the parameter to the cloud server.

2. The adaptive differential privacy federated learning training method according to claim 1, wherein In the S1, the cloud server initializes the clipping threshold C0 = 1 before the start of training, and selects s clients before each round of communication. The policy for selecting clients is the client random scheduling policy, that is, randomly sample s clients in each round of communication, and the sampling formula is: s = qU Where q is the sampling factor, 0 < q < 1, and U is the total number of clients; After selecting the clients, the cloud server broadcasts the global model of the t-th round of communication and the pruning threshold C t to the selected clients.

3. The adaptive differential privacy federated learning training method according to claim 1, wherein In S2, each client executes an optimization algorithm according to the task type and model architecture to update its corresponding local model parameters. This process can be iterated multiple times, and the local model parameters are updated in each iteration. When the client completes the local model iteration of the preset number of rounds, according to the pruning threshold C received by the cloud server t prune the local model parameters and add noise, and upload the updated and noisy local model parameters to the cloud server.

4. The adaptive differential privacy federated learning training method according to claim 1, wherein In the S3, after the cloud server receives all the client models participating in the training in this round of communication, it performs weighted average aggregation on the client model parameters: Where: Represents the new global model; Denote the total size of the datasets of the s sampled clients.

5. The adaptive differential privacy federated learning training method according to claim 1, characterized in that In S4, the cloud server calculates the cross-entropy loss value L on the validation set using the new aggregated global model t , and adaptively adjusts the pruning threshold C for the next round of communication using the following formula t+1 . If the loss value L t decreases continuously for three communication rounds, then the pruning threshold C is adjusted t : where β is the clipping threshold decay coefficient, and 0 < β < 1, and L t represents the central-side loss of the global model in the t-th round.

6. A computer-readable storage medium, characterized in that, There is a computer program. When the computer program is executed by a processor, the processor executes the steps of the adaptive differential privacy federated learning training method described in any one of claims 1-5.

7. A computer device, characterized in that, It includes a memory and a processor. The memory stores a computer program. When the computer program is executed by the processor, the processor executes the steps of the adaptive differential privacy federated learning training method described in any one of claims 1-5.

Citation Information

Patent Citations

  • Asynchronous hierarchical joint learning training method based on bandwidth pre-allocation

    CN117221122A

  • Federal learning-based privacy improvement method, system and device and medium

    CN118350051A