Byzantine fault-tolerant decentralized federated learning method based on committee
By adopting the Byzantine fault tolerance method based on the committee in the federated learning system and using the committee mechanism and consensus algorithm for model verification and aggregation, the single point of failure and Byzantine attack problems caused by centralized design in the traditional federated learning system are solved, and the system's robustness and security improvement is achieved.
Patent Information
- Application Number
- CN202510250755.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-04
- Publication Date
- 2025-06-20
AI Technical Summary
Traditional federated learning systems are prone to single point failure and Byzantine attacks due to centralized design, which makes it difficult to ensure the robustness and security of the system.
Using the Byzantine fault-tolerant decentralized federal learning method based on the committee, model verification and aggregation is performed through the committee mechanism, a committee consensus algorithm is designed, as well as contribution measurement and reputation renewal mechanisms, and a well-performing client is dynamically selected to enter the committee.
Effectively eliminates dependence on central servers, enhances the security and efficiency of the system, simplifies the aggregation process, reduces communication overhead, and provides a safe, reliable and efficient federated learning solution.
Smart Images

Figure CN120180432A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of federated learning, and particularly to a byzantine fault tolerant decentralized federated learning method based on a committee. Background Art
[0002] Machine learning techniques have been widely applied in fields such as image recognition, autonomous driving, smart cities, and disease diagnosis. However, the training and optimization of these algorithms rely on a large amount of high-quality data. With the increasing attention to data security and privacy protection issues, relevant regulations have been introduced in various countries. In addition, industry competition and complex administrative processes have led to the fragmentation of data, making it difficult to obtain sufficient high-quality data, which has limited the practical application and development of machine learning techniques to a certain extent.
[0003] Federated Learning (FL), as a decentralized machine learning method, allows multiple data holders to jointly train a model, effectively avoiding the problem of privacy leakage. However, current FL solutions are vulnerable to malicious attacks. In the traditional federated learning architecture, the central server is responsible for tasks such as model distribution, aggregation, and update. This centralized design is prone to trust issues and single points of failure. If the server is attacked, the entire training process may be interrupted. Therefore, many studies have focused on designing decentralized federated learning methods, such as using the Gossip protocol to achieve decentralization. However, the Gossip protocol lacks key features such as decentralized storage and cross-validation of blockchain, cannot verify the synchronization of model parameters between nodes, and there is still a single point of failure problem in storage.
[0004] To address these issues, blockchain technology has been introduced into federated learning, forming the blockchain federated learning paradigm. As a decentralized and auditable distributed ledger, blockchain can provide new solutions for federated learning, such as privacy protection, anti-attack, and incentive mechanisms. However, the introduction of blockchain also brings some challenges. On the one hand, blockchain increases communication and computational overhead. Especially when using the proof-of-work consensus algorithm, miners need to consume a large amount of computing resources to compete for the right to record transactions, and the broadcast communication in the consensus process consumes a large amount of bandwidth resources. As the number of miners increases, the communication cost grows exponentially. On the other hand, blockchain federated learning systems also face attack risks that traditional FL cannot solve. Due to the lack of authentication of the local gradients uploaded by clients, the system is vulnerable to Byzantine attacks, and malicious clients can interfere with the global model training by uploading tampered local models. To this end, some existing solutions have designed aggregation rules such as Krum and Median to eliminate malicious gradients by evaluating the distribution and magnitude of gradients, but these methods still have limitations in defending against malicious servers. Summary of the Invention
[0005] The object of the present invention is to provide a committee-based Byzantine fault-tolerant decentralized federated learning method. This method realizes decentralization by adopting a committee mechanism for model verification and aggregation, thus effectively eliminating the need for a central server. In addition, we designed a committee consensus algorithm, as well as a contribution measurement and reputation update mechanism. The object of the present invention is achieved by the following technical solutions:
[0006] Step 1: Randomly select a primary client node from a predefined committee, and this node is responsible for supervising the consensus achievement of this federated learning process;
[0007] Step 2: Each client node in the committee shares its acceptable client set with other member nodes, where the acceptable client set is the client nodes that are screened by model quality detection and whose training results meet the preset marginal utility threshold;
[0008] Step 3: Each committee client node counts the occurrence frequency of each training client node in all acceptable client sets. When the occurrence frequency of a certain client node exceeds the preset threshold [K / 2], this client node is included in the aggregated client set;
[0009] Step 4: The primary client node generates and broadcasts a request message <Request, ID cp , A (t) , TS> to initiate committee aggregation consensus, where ID cp represents the primary client node identifier, A (t) represents the aggregated client set of the current round, and TS represents the timestamp;
[0010] Step 5: After receiving the request message, each committee client node verifies the consistency between its local acceptable client set and the aggregated client set A (t) provided by the primary client node. If they are consistent, it sends a reply message <Reply, ID i , A (t) , vote> to the primary client node, where ID i represents the current client node identifier, and vote represents a vote confirmation;
[0011] Step 6: After receiving the same reply messages from more than half of the committee member nodes, the primary client node confirms that the consensus on the aggregated client set is reached; if the consensus is not reached, reselect the primary client node and repeat Steps 2 to 5.
[0012] As can be seen from the technical solution provided by the present invention above, the above method can solve the problem of single-point failure hidden danger caused by centralization in the traditional federated learning system and is vulnerable to Byzantine attacks, and can effectively enhance the robustness and reliability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] To better illustrate the technical solution of the embodiments of the present invention, the drawings used in the embodiments will be briefly introduced below. Obviously, the following drawings only show some embodiments of the present invention, and those skilled in the art can design other related drawings without creative labor according to these drawings.
[0014] Figure 1 It is a schematic flowchart of a committee-based Byzantine fault-tolerant decentralized federated learning method provided by an embodiment of the present invention;
[0015] Figure 2 It is a schematic flowchart of committee model selection and aggregation in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0016] To more clearly and completely elaborate on the technical solution of the embodiments of the present invention, the following will be described in detail with reference to the drawings. Obviously, the described embodiments are only a part of the present invention and do not constitute all limitations of the present invention. Any other embodiments proposed by those skilled in the art without creative labor based on the embodiments of the present invention should be regarded as within the protection scope of the present invention.
[0017] As Figure 1 shown is a schematic flowchart of a committee-based Byzantine fault-tolerant decentralized federated learning method provided by an embodiment of the present invention. The method includes three main parts: 1) a committee model selection mechanism based on model utility, 2) a model aggregation method based on utility importance, and 3) a committee client election mechanism based on reputation. In the first part, after the training client completes local training, it uploads the local model update to the committee client, and the latter evaluates the model quality through committee consensus and makes a selection. The second part introduces a model aggregation method based on utility impact. The third part measures the contribution of each client according to its role in the system and updates its reputation score accordingly. After each round of training, the training clients and committee clients for the next round are selected according to the updated reputation scores.
[0018] Step 1: The training client performs local model training based on local data and uploads the locally trained model update to the committee client. The committee client performs quality detection on the model update and selects the model update through committee consensus.
[0019] During the training process, Byzantine clients may upload malicious gradients, affecting the accuracy of the global model. To address this issue, this paper adopts a loss-based margin method to detect the quality of local models. Each committee client evaluates the local model using its own dataset, determines the utility of the model by calculating the difference in the global model loss with and without a certain local model, and then selects the final models to participate in aggregation through the committee consensus algorithm.
[0020] In step 1, in each round, the committee obtains the local model updates of all clients and evaluates the quality of each model. In the t-th round, the i-th committee client calculates the marginal utility of the local model of the j-th training client The formula is as follows:
[0021]
[0022] where w (t) is the global model aggregated from all local models, and is the global model obtained by aggregating the remaining local models after excluding the local model of the j-th training client. L(*, v i ) represents the model loss function of the i-th committee client on the validation set v i . This evaluation method is based on the idea that when a well-performing local model participates in aggregation, the loss of the global model should decrease or remain stable.
[0023] Furthermore, the Gompertz function is applied to measure the utility influence degree of training clients, aiming to enhance the discrimination between malicious gradients and honest gradients. For the j-th training client, its final marginal utility value is the median of the marginal utilities calculated by all committee members. The formula for calculating the utility influence degree using the Gompertz function is as follows:
[0024]
[0025] In this step, the committees reach a consensus through the committee consensus algorithm, which draws on the classical practical Byzantine fault tolerance algorithm and runs in a synchronous network environment. It is assumed that the number of committee members in the federated learning system satisfies n > 2f + 1, where n is the total number of committee members and f is the maximum number of faulty clients that the committee can tolerate. The committee consensus algorithm reduces communication overhead and improves efficiency by restricting the consensus process within the committee and avoiding communication among all clients. First, a committee client is randomly selected as the primary client. Then, each committee client shares its acceptable set of clients, where the quality score U of the training client model j(t) Greater than the threshold. Then, the main client counts the occurrence frequency of each training client in all shared acceptable client sets. When most committee members confirm the update, the aggregated client set reaches a consensus on model selection. Otherwise, a view change is triggered and a new main client is elected. To evenly distribute the computing load, the main client role rotates in a round-robin manner.
[0026] Step 2: After evaluating the quality of the local models, the selected models are merged to create a new global model. To improve the accuracy of the model, we propose a model aggregation method based on the model utility influence degree. Specifically, we adjust the weights of the local models according to the quality detection results of each training client. During the model aggregation process in the t-th round, the local model parameters of the j-th training client will be weighted according to its utility influence degree and the model aggregation update calculation formula is as follows:
[0027]
[0028] where, is the model weight of the j-th training client, m is the number of aggregated clients obtained after consensus is reached in Step 1, is the model update of the j-th training client.
[0029] The reputation-based committee client election mechanism aims to dynamically select committee members based on the historical performance and contribution degree of clients. The system elects committee members according to the reputation scores, preferentially selecting clients with higher reputations to participate in the model training and aggregation process, thus ensuring the honesty and reliability of committee members.
[0030] In Step 3, due to the different responsibilities of participating nodes, we use different contribution evaluation criteria to measure the contribution of each participating node in each round of model training. For training clients, we propose a method based on gradient projection to measure their contribution to model training. In the t-th round, the local gradient of the j-th training client is projected onto the global gradient g( t ), and the training client contribution calculation formula is as follows:
[0031]
[0032] For committee clients, the contribution value is evaluated based on their verification accuracy, and the verification accuracy is defined as the intersection ratio of the acceptable client set in this round and the aggregated client set A (t) . The higher the intersection ratio, the higher the verification accuracy. The contribution of the i-th committee client in this round is calculated as follows:
[0033]
[0034] For the committee's main client, its contribution is given a higher weight to reflect its core role in guiding the aggregation process. Since the main client is responsible for coordinating decisions and setting selection criteria, its contribution is twice the median of the contributions of the committee clients. The formula for calculating the main client's contribution is as follows:
[0035]
[0036] Furthermore, to elect reliable clients to join the committee, we use reputation as the basis for election. After each round of training, the reputation of the clients is updated in real time by combining the current contribution and historical reputation of the clients. To smooth the reputation changes, we use the weighted average of the current round contribution and historical reputation of the clients to update the reputation. The formula for updating the reputation of the j-th client in the t-th round is as follows:
[0037]
[0038] where, is the updated reputation of the j-th training client in the t-th round, is the updated reputation of the i-th committee client in the t-th round, and λ is the update ratio coefficient. This approach takes into account both the contribution in the current round and its past performance, thus being able to more accurately reflect its long-term reliability in the system.
[0039] Furthermore, after each round of training is completed, the training clients and committee clients are reselected according to the updated reputation values. The honesty of the committee is crucial for maintaining the stability and security of the entire decentralized federated learning system. In the initial round of committee selection, due to the lack of sufficient historical performance data, several clients are randomly selected from all participating clients to form the initial committee. Before each subsequent round of training, the committee is re-elected through a two-stage process: the preliminary election stage and the re-election stage, and the number of committee members is K.
[0040] In the preliminary election stage, the committee members are selected from the aggregated clients obtained in the previous round of training. According to the reputation of each client, at most [K / 2] clients are randomly selected as the initial members of the committee. The probability of being selected is directly related to the reputation of the client. Although clients with higher reputations have a greater chance of being selected, all aggregated clients in the previous round have a chance of being selected.
[0041] In the re-election phase, the aggregated clients not selected in the preliminary election in the previous round of training are included in the candidate pool. In addition, several times the number of idle clients equal to the committee size are added to the candidate pool according to the reputation of the clients. Finally, clients are randomly selected from this candidate pool to fill the remaining committee seats according to their reputation ratio, ensuring that the total number of committee members is K. Similar to the preliminary election phase, the probability of a client being selected is proportional to its reputation.
[0042] It should be noted that the content not described in detail in the embodiments of the present invention belongs to the prior art well-known to those skilled in the art.
[0043] In summary, the method described in the embodiments of the present invention is a committee-based Byzantine fault-tolerant decentralized federated learning method. It conducts model verification and aggregation through the committee mechanism to achieve decentralization, eliminate the dependence on the central server, and enhance the security and efficiency of the system. The method adopts an evaluation method based on contribution and a reputation update mechanism to dynamically select well-performing clients into the committee, improving the stability and fault tolerance of the system. By designing the committee consensus algorithm and combining the contribution and reputation update mechanisms, the robustness of model training is enhanced. The committee-based Byzantine fault-tolerant decentralized federated learning method effectively addresses Byzantine attacks, simplifies the aggregation process, reduces communication overhead, and provides a secure, reliable, and efficient federated learning solution.
[0044] The above content is only the preferred embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any professional familiar with the technical field, within the technical scope disclosed by the present invention, any modifications or equivalent replacements made thereto shall be regarded as falling within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the content of the claims. It should be noted that the information involved in the background art section is only used to help understand the overall technical background of the present invention and cannot be regarded as an admission that this information constitutes the prior art generally known to those skilled in the art.
Claims
1. A committee-based Byzantine fault-tolerant decentralized federated learning method, characterized in that: The method comprises: Step 1: The training client uploads the local model update obtained through training to the committee client. The committee client performs quality inspection on the model update and selects the model update through committee consensus. Step 2: Perform weighted aggregation on the selected model updates according to the model utility influence to form a new global model; Step 3: Update the reputation value based on the client's contribution in this round and historical performance, and use the reputation value as the basis for selecting the training client and committee client in the next round.
2. The committee-based Byzantine fault-tolerant decentralized federated learning method according to claim 1, characterized in that: In step 1, in each round, the committee obtains the local model updates of all clients and performs a quality assessment on each model. In the tth round, the i-th committee client calculates the marginal utility of the local model of the j-th training client The formula is as follows: Among them, w (t) is the global model aggregated from all local models, and It is the global model obtained by excluding the local model of the jth training client and aggregating the remaining local models. L(*,v i ) indicates that the i-th committee client is in the validation set v i The model loss function of Furthermore, the Gompertz function is applied to measure the utility impact of the training client. For the jth training client, its final marginal utility value is The median marginal utility calculated for all committee members, using the Gompertz function to calculate utility influence The formula is as follows: In this step, the committee reaches a consensus through the committee consensus algorithm. First, a committee client is randomly selected as the master client. Second, each committee client shares its acceptable client set, which contains the training client model quality scores. Greater than the threshold; again, the master client counts the frequency of occurrence of each training client in the set of all shared acceptable clients; finally, when most committee members confirm the update, the aggregated client set reaches a consensus on model selection; otherwise, the view change is triggered and a new master client is elected; in order to evenly distribute the computing load, the master client role is rotated in a round-robin manner.
3. The committee-based Byzantine fault-tolerant decentralized federated learning method according to claim 1, characterized in that: In step 2, after evaluating the quality of local models, the selected models are merged to create a new global model. In order to improve the accuracy of the model, we propose a model aggregation method based on model utility influence. Specifically, according to the quality test results of each training client, the weight of the local model is adjusted. In the t-th round of model aggregation, the local model parameters of the j-th training client will be adjusted according to its utility influence. The weighted model aggregation update calculation formula is as follows: in, is the model weight of the jth training client, m is the number of aggregated clients obtained after consensus is reached in step 1, is the model update of the jth training client.
4. The committee-based Byzantine fault-tolerant decentralized federated learning method according to claim 1, characterized in that: In step 3, for training clients, we propose a gradient projection-based method to measure their contribution to model training; in the tth round, the local gradient of the jth training client is projected to the global gradient g (t) The training client contribution calculation formula is as follows: For committee clients, the contribution value is evaluated based on its verification accuracy, which is defined as the set of acceptable clients in this round With the aggregate client set A (t) The intersection ratio of the i-th committee client in this round is calculated as follows: For the committee master client, its contribution value is twice the median contribution value of the committee client. The calculation formula for the master client contribution is as follows: Furthermore, after each round of training, the client's reputation is updated in real time by combining the client's current contribution and historical reputation. In order to smooth the reputation change, we use the weighted average of the client's current round contribution and historical reputation to update the reputation. The reputation update formula for the client in round t is as follows: in, is the updated reputation of the jth training client in round t, is the updated reputation of the i-th committee client in round t, and λ is the update proportional coefficient. This approach takes into account both the contribution of the current round and its past performance, thus more accurately reflecting its long-term reliability in the system. Furthermore, after each round of training, the training clients and committee clients are reselected according to the updated reputation value; in the initial round of committee selection, a number of clients are randomly selected from all participating clients to form the initial committee; before each subsequent round of training, the committee is re-elected through a two-stage process: a preliminary election stage and a re-election stage, and the number of committees is K; In the preliminary election phase, committee members are selected from the aggregated clients obtained in the previous round of training; based on the reputation of each client, up to [K / 2] clients are randomly selected as the initial members of the committee; During the re-election phase, the aggregated clients that were not selected in the preliminary election in the previous round of training are included in the candidate pool; in addition, based on the reputation of the clients, several times the size of the committee idle clients are added to the candidate pool; finally, clients are randomly selected from this candidate pool to fill the remaining committee seats according to their reputation ratio to ensure that the total number of committee members is K.
Citation Information
Cited By
Block chain-based trusted data space federal learning hostile attack verification method
CN121000428A