Federal learning collaborative framework based on dynamic noise injection and hierarchical encryption
By adopting a federated learning collaboration framework of dynamic noise injection and hierarchical encryption in edge computing scenarios, the computing overhead, adaptability and scalability of traditional encryption solutions under resource constrained and dynamic topological characteristics is solved, and efficient privacy protection and balance of computing efficiency is achieved.
Patent Information
- Application Number
- CN202510240525.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2025-06-24
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The prior art is difficult to balance computing overhead, adaptability and dynamic scalability in edge computing scenarios, especially under resource-constrained edge nodes and dynamic topology characteristics, and traditional encryption solutions are difficult to effectively protect privacy and reduce computing pressure.
Using a federated learning collaboration framework based on dynamic noise injection and hierarchical encryption, dynamic noise adaptation and key rotation are achieved through AES-128 encryption and dynamic noise injection at the terminal device layer, improved Paillier aggregation and homomorphic hash verification at the edge node layer, and ECDH protocol negotiation dynamic key management at the cloud server layer, combined with dynamic key management of the T-DKG protocol, dynamic noise adaptation and key rotation are achieved.
It reduces the computing overhead of edge nodes, ensures that the model accuracy loss is less than 5%, and effectively controls encryption delay and key update delay at the scale of 1,000 nodes, solving the problem of balance between privacy protection and computing efficiency.
Smart Images

Figure CN120197671A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of edge computing and privacy protection, and specifically relates to a federated learning collaborative framework based on dynamic noise injection and hierarchical encryption. Background Art
[0002] In the edge computing scenario, terminal devices (such as sensors, intelligent cameras) generate a large amount of data, which is preliminarily processed and aggregated by edge nodes (such as industrial gateways, local servers), and then uploaded to the cloud for federated learning model training. Due to the resource limitations of edge nodes (CPU computing power < 1 TFlops, memory < 8 GB) and dynamic topology characteristics (device online rate fluctuation > 20%), traditional encryption schemes are difficult to balance security, computational overhead, and dynamic adaptability.
[0003] There are also related solutions in the prior art:
[0004] Federated learning solutions based on encryption
[0005] Case 1: CN117294460A encrypts local model parameters through AES-128, but the static allocation of keys leads to the need for full network re-encryption when nodes dynamically exit, resulting in a communication delay of up to 150 ms.
[0006] Case 2: CN119254450A uses pre-set codebook transposition encryption, but the key update period is fixed (default 24 hours), and the security fails in scenarios where the network attack frequency > 5 times / hour.
[0007] Differential privacy technology
[0008] Case 3: CN110632554A adds fixed Laplace noise (Δf = 0.1, ε = 1), resulting in a 10.3% decrease in the accuracy of the indoor positioning model (RMSE increases from 1.2 m to 1.32 m), and it cannot dynamically adapt to changes in data sensitivity.
[0009] Therefore, the main current technical problems are:
[0010] 1. Computational overhead: The Paillier algorithm requires > 100 modular exponentiation operations for a single aggregation, occupying 80% of the CPU resources of edge nodes.
[0011] 2. Lack of adaptability: Static noise or fixed encryption rules cannot cope with changes in data distribution (such as privacy protection fails when the variance fluctuation > 30%).
[0012] 3. Dynamic scalability: When the network scale expands from 100 nodes to 1000 nodes, the key update delay non-linearly increases to more than 8 seconds. Summary of the Invention
[0013] The present invention provides a federated learning collaboration framework based on dynamic noise injection and hierarchical encryption to solve the defects in the prior art.
[0014] The present invention is achieved through the following technical solutions:
[0015] The federated learning collaboration framework based on dynamic noise injection and hierarchical encryption includes a terminal device layer, an edge node layer, and a cloud server layer;
[0016] The terminal device layer described above includes built-in sensors and an encryption module;
[0017] The edge node layer is used to connect the terminal device layer and the cloud server layer;
[0018] The cloud server layer is used to run the federated learning model.
[0019] For the federated learning collaboration framework based on dynamic noise injection and hierarchical encryption as described above, after the original data received by the terminal device layer is split into data blocks of 256 bits, it is encrypted by AES-128 (the secret key K _ sym is generated by the T-DKG protocol), and then the dynamic noise module is called for dynamic noise injection, and finally the encrypted perturbation data is output.
[0020] For the federated learning collaboration framework based on dynamic noise injection and hierarchical encryption as described above, the calculation formula for the amount of noise of the dynamic noise module is: amount of noise = Laplace(λ), where λ = δ / ε, ε is the privacy budget, and δ is the local data variance calculated by the edge node every 5 minutes, and its calculation formula is: δ = Var(D_i).
[0021] For the federated learning collaboration framework based on dynamic noise injection and hierarchical encryption as described above, after receiving the encrypted data output by the terminal device layer, the edge node layer calculates the homomorphic hash in parallel, verifies the consistency of the homomorphic hash (if inconsistent, a warning is triggered), performs improved Paillier aggregation (the pre-computation acceleration module reduces 70% of the modular exponentiation operation), and outputs the aggregated data result.
[0022] For the federated learning collaboration framework based on dynamic noise injection and hierarchical encryption as described above, the formula for homomorphic hash verification is H(x) = ∏x_i^α_i mod p, where p is a 2048-bit prime number.
[0023] For the federated learning collaboration framework based on dynamic noise injection and hierarchical encryption as described above, the edge node layer generates a threshold polynomial and distributes the key shard SK_i = f(i) to each node.
[0024] The collaborative framework for federated learning based on dynamic noise injection and hierarchical encryption as described above, the formula of the threshold polynomial is: f’(x) = a0 + a1x +... + a_tx^t (t = 3).
[0025] In the collaborative framework for federated learning based on dynamic noise injection and hierarchical encryption as described above, after the edge node layer receives a new node submission request, the existing nodes calculate the new shard SK_{new} through Lagrange interpolation and broadcast the encrypted shard (using the recipient's public key), triggering the network-wide key version number +1.
[0026] In the collaborative framework for federated learning based on dynamic noise injection and hierarchical encryption as described above, when the edge node layer detects that a node is offline, the remaining nodes verify the threshold quantity (≥t + 1), reconstruct the polynomial f’(x) to generate a new shard and destroy the old shard to complete the key rotation, with the whole process taking ≤1 second.
[0027] In the collaborative framework for federated learning based on dynamic noise injection and hierarchical encryption as described above, after the cloud server layer receives the aggregated data, it trains through the federated learning model, then negotiates the dynamic secret key K_dyn (elliptic curve parameter secp256k1) through the ECDH protocol, and finally distributes the encrypted model parameters.
[0028] The advantages of the present invention are as follows:
[0029] 1. Hierarchical encryption optimization: A three-layer collaborative mechanism of the terminal device layer (AES-128 + noise injection), the edge node layer (improved Paillier aggregation), and the cloud server layer (ECDH parameter distribution), combined with dynamic key management based on the T-DKG protocol, reduces the single-node computing pressure (goal: CPU occupancy of edge nodes <50%);
[0030] 2. Dynamic noise adaptability: Adjust the noise amount in real time according to the data variance δ to ensure that the model accuracy loss ≤5%;
[0031] 3. Dynamic key management: It supports achieving technical effects of encryption delay ≤45ms, key update delay ≤0.8 seconds, and a security isolation rate of 100% when nodes exit under the scale of 1000 nodes, and overcomes the balance problem between privacy protection and computing efficiency in the edge computing scenario. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0033] Figure 1 is the structural schematic diagram of the present invention;
[0034] Figure 2 is the dynamic key management flow chart of the present invention;
[0035] Figure 3 is the schematic diagram of the attack scenario of the collusion attack in the verification test of the present invention;
[0036] Figure 4 is the schematic diagram of the defense mechanism process of the present invention. Detailed implementation manners
[0037] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0038] As Figure 1 shown, the federated learning collaboration framework based on dynamic noise injection and hierarchical encryption includes a terminal device layer, an edge node layer, and a cloud server layer;
[0039] The terminal device layer described includes built-in sensors and an encryption module;
[0040] The edge node layer is used to connect the terminal device layer and the cloud server layer;
[0041] The cloud server layer is used to run the federated learning model.
[0042] Preferably, after the original data received by the terminal device layer is segmented into data blocks of 256 bits, it is encrypted by AES-128 (the secret key K _ sym is generated by the T-DKG protocol), and then the dynamic noise module is called to perform dynamic noise injection and finally output encrypted perturbation data.
[0043] Preferably, the calculation formula for the amount of noise of the dynamic noise module in this embodiment is: amount of noise = Laplace(λ), where λ = δ / ε, ε is the privacy budget, and δ is the local data variance calculated by the edge node every 5 minutes. Its calculation formula is: δ = Var(D_i).
[0044] Preferably, the edge node layer described in this embodiment calculates the homomorphic hash in parallel after receiving the encrypted data output by the terminal device layer, verifies the consistency of the homomorphic hash (triggering a warning if inconsistent), performs improved Paillier aggregation (pre-calculation acceleration module reduces 70% modular exponentiation operations), and outputs the aggregated data results.
[0045] Preferably, the formula for homomorphic hash verification described in this embodiment is H(x)=∏x_i^α_imodp, where p is a 2048-bit prime number.
[0046] Preferably, the edge node layer described in this embodiment generates a threshold polynomial and distributes the key fragment SK_i=f(i) to each node.
[0047] like Figure 2 and Figure 4 As shown, preferably, the formula of the threshold polynomial described in this embodiment is: f'(x)=a0+a1x+...+a_tx^t(t=3).
[0048] Preferably, after the edge node layer described in this embodiment receives the submission request from the new node, the existing node calculates the new shard SK_{new} through the current Lagrangian interpolation and broadcasts the encrypted shard (using the recipient's public key) to trigger the network-wide key version number +1.
[0049] Preferably, the edge node layer detection node described in this embodiment is offline, and the remaining nodes verify the threshold number (≥t+1) to reconstruct the polynomial f'(x) to generate a new shard and destroy the old shard to complete the key rotation, and the whole process takes ≤1 second.
[0050] Preferably, after receiving the aggregated data, the cloud server layer described in this embodiment is trained through a federated learning model, and then a dynamic key K_dyn (elliptic curve parameter secp256k1) is negotiated through the ECDH protocol, and finally the encrypted model parameters are distributed.
[0051] Verification test
[0052] Anti-attack ability
[0053] Eavesdropping Attack:
[0054] The AES-128 encrypted data and dynamic noise work together to make the original data restoration error rate >99.9% (when δ≥0.1).
[0055] Collusion attack (such as Figure 3 shown):
[0056] The T-DKG protocol requires at least t+1 nodes to collude to crack the key. When t=3 and the total number of nodes ≥1000, the success probability is <10^-6.
[0057] Performance benchmark (comparative patent: CN117294460A), and the results are shown in Table 1 below.
[0058] Index The present invention Comparative patent Improvement range Encryption calculation delay 45ms 150ms 70% Model accuracy loss ≤5% 10.3% 51% Key update delay 0.8 seconds 8 seconds 86% Against 50-node collusion attack Success rate < 0.1% Success rate 12% 99.2%
[0059] Table 1
[0060] Tampering attack defense:
[0061] The homomorphic hash module can detect data modification, and the verification success rate for 256-bit data blocks reaches 100% (test sample size = 10^6 times).
[0062] Experiments show that in an industrial Internet of Things test environment with a scale of 1000 nodes:
[0063] 1. Encryption efficiency: The computing overhead of edge nodes is reduced to 45 ms / request (compared with 150 ms in the traditional scheme), meeting the real-time requirement (<100 ms).
[0064] 2. Model accuracy: In the dynamic fluctuation scenario of δ ∈ [0.05, 0.2], the accuracy of the image classification model remains 94.7% (the benchmark without privacy protection is 99.2%, with only a 4.5% loss).
[0065] 3. Scalability: The key update delay is stable at 0.8 seconds (±0.1 second), and secure isolation is completed within 1 second after a node exits.
[0066] Example 1 (Predictive maintenance scenario in an intelligent factory)
[0067] 1. Deployment configuration:
[0068] Terminal: 500 vibration sensors (sampling rate 1 kHz, data block 256 bit)
[0069] Edge node: 5 industrial gateways (Intel i7-8550U, 16GB memory)
[0070] Cloud: AWS EC2 instance (vCPU 32 cores)
[0071] 2. Noise parameter configuration:
[0072] Initial parameters: ε = 0.8, δ range = 0.05 - 0.15 (automatically adjusted according to the degree of equipment aging)
[0073] 3. Performance verification:
[0074] The F1-score of the bearing fault detection model reaches 93.4%, and the key update operation requires no manual intervention.
[0075] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A federated learning collaborative framework based on dynamic noise injection and hierarchical encryption, characterized by: Includes terminal device layer, edge node layer and cloud server layer; The terminal device layer includes built-in sensors and encryption modules; The edge node layer is used to connect the terminal device layer and the cloud server layer; The cloud server layer is used to run the federated learning model.
2. The federated learning collaborative framework based on dynamic noise injection and hierarchical encryption according to claim 1 is characterized by: The terminal device layer receives the original data and divides it into 256-bit data blocks, and then encrypts it using AES-128 (secret key K _ sym is generated by the T-DKG protocol) and then the dynamic noise module is called to perform dynamic noise injection and finally output the encrypted disturbance data.
3. The federated learning collaborative framework based on dynamic noise injection and hierarchical encryption according to claim 2 is characterized in that: The calculation formula for the noise amount of the dynamic noise module is: noise amount = Laplace (λ), where λ = δ / ε, ε is the privacy budget, and δ is the local data variance calculated by the edge node every 5 minutes. The calculation formula is: δ = Var (D_i).
4. The federated learning collaborative framework based on dynamic noise injection and hierarchical encryption according to claim 2 is characterized in that: The edge node layer calculates the homomorphic hash in parallel after receiving the encrypted data output by the terminal device layer, verifies the consistency of the homomorphic hash (triggering a warning if inconsistent), performs improved Paillier aggregation (pre-calculation acceleration module reduces 70% modular exponentiation operations), and outputs the aggregated data results.
5. The federated learning collaborative framework based on dynamic noise injection and hierarchical encryption according to claim 4 is characterized in that: The formula for homomorphic hash verification is H(x)=∏x_i^α_imodp, where p is a 2048-bit prime number.
6. The federated learning collaborative framework based on dynamic noise injection and hierarchical encryption according to claim 4 is characterized in that: The edge node layer generates a threshold polynomial and distributes the key fragment SK_i=f(i) to each node.
7. The federated learning collaborative framework based on dynamic noise injection and hierarchical encryption according to claim 4 is characterized by: The formula of the threshold polynomial is: f'(x)=a0+a1x+...+a_tx^t(t=3).
8. The federated learning collaborative framework based on dynamic noise injection and hierarchical encryption according to claim 7 is characterized in that: After the edge node layer receives the submission request from the new node, the existing node calculates the new shard SK_{new} through the current Lagrange interpolation and broadcasts the encrypted shard (using the recipient's public key) to trigger the network-wide key version number +1.
9. The federated learning collaborative framework based on dynamic noise injection and hierarchical encryption according to claim 4, characterized in that: The edge node layer detects that the node is offline, and the remaining nodes verify the threshold number (≥t+1) to reconstruct the polynomial f'(x) to generate a new shard and destroy the old shard to complete the key rotation. The whole process takes ≤1 second.
10. The federated learning collaborative framework based on dynamic noise injection and hierarchical encryption according to claim 4, characterized in that: After receiving the aggregated data, the cloud server layer is trained through the federated learning model, and then the dynamic key K_dyn (elliptic curve parameter secp256k1) is negotiated through the ECDH protocol, and finally the encrypted model parameters are distributed.
Citation Information
Patent Citations
Indoor positioning method and device based on federated learning, terminal device and medium
CN110632554A
Lightweight federated learning privacy protection method under edge computing
CN117294460A
Edge computing encryption communication method and device
CN119254450A