Verifiable federated learning method and device based on double decomposition and aggregation

Through the verifiable federated learning method of double decomposition and dual aggregation, the problems of data leakage and model failure in federated learning are solved, and the security of the model and the correctness of the aggregation results are achieved without affecting the learning accuracy.

CN120217430AActive Publication Date: 2025-06-27BEIJING UNIV OF POSTS & TELECOMM
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510278099.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-10
Publication Date
2025-06-27
Estimated Expiration
2045-03-10

AI Technical Summary

Technical Problem

There are problems with data breaches and model failures in federated learning, and malicious attackers may use model reversal attacks, aggregation reconstruction attacks, and backdoor attacks to undermine security and credibility.

Method used

Using a verifiable federated learning method of double decomposition and dual aggregation, the model parameters are decomposed into public and private parts by introducing trusted third-party and secret sharing technologies, ensuring that the server only receives shared models that have been specially randomized and performs data verification on the client.

Benefits of technology

It effectively eliminates the risk of local model reconstruction, ensures the correctness of the aggregation results and the security of the model, and does not affect the learning accuracy of the model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217430A_ABST
    Figure CN120217430A_ABST
Patent Text Reader

Abstract

The invention provides a dual decomposition and aggregation verifiable federated learning method and device, and belongs to the field of federated learning privacy security protection. The method specifically comprises the following steps: a trusted third party (TTP) performs key negotiation with each client to generate a corresponding key # imgabs0 # TTP, the key generates a random number # imgabs1 # through a random number generator, the random number # imgabs1 # is summed to obtain # imgabs2 # TTP, and the # imgabs3 # is sent to each client through a symmetric encryption method; each client decomposes trained model parameters into n parts, sends the n parts to other clients and receives parameters sent by other clients; each client performs a second round of decomposition on the parameters, the parameters are decomposed into a public part # imgabs4 # (sent to the server) and a private part # imgabs5 # (reserved locally), the private part is set as # imgabs6 #, and each client constructs a verification function vi based on the uploaded local model parameters and sends the verification function vi to the server together; the server aggregates the model parameter omega i and the verification function v i sent by the client, and sends an aggregation result to the client; and the client verifies whether the data are equal or not through a verification formula # imgabs7 #, if the data are equal, the subsequent updating operation is executed, and the received global model parameters with the bias and the privacy part reserved locally are aggregated to recover a real parameter model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of federated learning, relates to the privacy and security of data, and specifically relates to a verifiable federated learning method and device for dual decomposition and aggregation. Background Art

[0002] Federated learning (FL) has always been one of the most promising methods in privacy-preserving machine learning (ML), which helps to efficiently process and analyze large datasets widely distributed at different locations. However, federated learning still faces a series of major challenges. For example, malicious attackers may use various strategies, such as model inversion attack (MIA), aggregation reconstruction attack (RIA) and backdoor attack, to undermine the security and credibility of federated learning, resulting in data leakage and model failure problems. To address the problem of federated learning data leakage, researchers use secure multi-party computation (MPC). Through complex encryption protocols, participants can ensure that their data remains encrypted during transmission and processing, and the final calculation results - whether it is the global model or any intermediate value - can be accurately decrypted, enabling local participants to fully recover the true, non-precise global model. In addition, in addition to protecting the privacy of gradient vectors, ensuring the integrity of the aggregation results is equally important. A malicious server may return a simplified but inaccurate global model, or even forge the aggregation results to obtain improper benefits. This will cause customers to receive an incorrect global model, thus having a negative impact on the training process.

[0003] Literature 1: E. Sotthiwat, L. Zhen, Z. Li and C. Zhang, "Partially Encrypted Multi-Party Computation for Federated Learning," 2021 IEEE / ACM 21st International Symposium on Cluster, Cloud and Internet Computing (CCGrid), Melbourne, Australia, 2021, pp. 828-835, doi: 10.1109 / CCGrid51090.2021.00101. proposes to encrypt the key parts of the model (gradient) parameters to reduce communication costs while maintaining the advantages of MPC in protecting privacy in the joint model without sacrificing learning accuracy. Theoretical analysis and experimental results prove that the proposed method can prevent the attack of gradient deep leakage on the reconstruction of original parameters to obtain the final data of individual participants.

[0004] Reference 2: G. Xu, H. Li, S. Liu, K. Yang and X. Lin, "VerifyNet: Secure and Verifiable Federated Learning," in IEEE Transactions on Information Forensics and Security, vol. 15, pp. 911-926, 2020, doi: 10.1109 / TIFS.2019.2929409. It is proposed that when the server sends the aggregation result, it attaches the verification proof of each client, and uses homomorphic hashing and pseudorandom generation techniques to ensure that users can verify the authenticity of the data, enhancing trust and transparency.

[0005] Reference 3: F. Luo, S. Al-Kuwari, and Y. Ding, “SVFL: Efficient secure aggregation and verification for cross-silo federated learning,” IEEE Trans. Mobile Comput., early access, Nov. 4, 2022, doi: 10.1109 / TMC.2022.3219485. It adopts a basic signature scheme to address the verification challenge, enabling each client to independently verify an aggregation signature that is independent of the total number of clients. Subsequently, each client decrypts the aggregated gradient, updates the local model parameters, and enters the next iteration. This method simplifies the verification process while maintaining the efficiency and security of the system. Summary of the Invention

[0006] To address the above problems, the present invention proposes a double-decomposition and double-aggregation federated learning mechanism to ensure that the server cannot directly access the real global model information, thus completely eliminating the risk of local model reconstruction. At the same time, each client can verify the data from the server to ensure the correctness of the aggregation result. The core of this mechanism lies in the detailed division of local sharing: on the one hand, it generates a public sharing part for secure transmission to the server; on the other hand, it retains the secret sharing part locally so that the server only receives the local model containing the bias.

[0007] The verifiable federated learning method and device for double decomposition and aggregation are as follows:

[0008] Step 1: Introduce a trusted third party (TTP). The TTP and each user respectively generate two key pairs locally;

[0009] The first pair: {(pk 1 , sk1 )(pk 2 , sk 2 )} ← KenGen()

[0010] The second pair:

[0011] The TTP sends the public keys {pk 1 , pk 2} of its two pairs of key pairs to each client through the server, and each client sends the public keys of its two pairs of key pairs to the TTP through the server.

[0012] The TTP uses the public keys received from the server and its retained private key sk 1 to perform key negotiation to obtain

[0013]

[0014] Each client also uses key negotiation to obtain

[0015] Step 2: The TTP and each client use the generated negotiated key as a random number seed to generate arbitrary random numbers through a pseudorandom number generator (PRG)

[0016]

[0017] Through the above operations, the TTP will obtain the random numbers of all clients The TTP sums up all the random numbers to obtain

[0018]

[0019] Step 3: The TTP transmits to each client through the server, and here the data transmitted by the TTP is encrypted using symmetric encryption;

[0020] X ← AE.enc(SK, x)

[0021] AE.dec(SK, X) → x

[0022] The TTP uses the public keys received from the server and its retained private key sk 2 to perform key negotiation to obtain

[0023]

[0024] Use the second negotiated secret key as the secret key for symmetric encryption to perform encryption to obtain the ciphertext ct i ;

[0025]

[0026] TTP sends the corresponding ct to each client through the server. The client decrypts it after obtaining ct i ; i ;

[0027]

[0028] Step Four: Two decompositions will be performed in this step.

[0029] The first round of decomposition:

[0030] First, divide the model parameters w trained by each client i into n independent secret shares;

[0031]

[0032] After decomposing w i according to the above formula, client i (where i is any value between 1 and n) enters the local communication stage. In the case of a fully connected network, client i sends its model block to all adjacent clients and receives model parameters from all other clients j (j ranges from 1 to n) at the same time

[0033] The second round of decomposition:

[0034] Each client further decomposes the received model parameters ;

[0035]

[0036] The second round of decomposition further refines the client data after the first round of decomposition and divides the parameters into two parts: one part is securely stored locally, and the other part is securely sent to the server for global aggregation processing.

[0037]

[0038] Here, we use the value generated by TTP in Step One and transmitted to the client as the unified deviation amount for the above decomposition.

[0039] Step 5: The client aggregates the data after secondary decomposition.

[0040]

[0041] ω i represents the reorganized local model parameters after secondary decomposition. Each client uploads this parameter to the server for aggregation. In addition to uploading ω i , each client also uploads a verification function v i .

[0042]

[0043] The verification function v i is constructed based on ω i . Each client combines the random value generated by the secret key negotiated with the TTP sum of random values and the uploaded public local model parameter ω i . After the verification function is generated, v i and ω i are uploaded to the server together.

[0044] Step 6: The server uses the Federated Averaging method to aggregate the two types of parameters after receiving v i and ω i .

[0045]

[0046] ω represents the aggregated global model parameters.

[0047]

[0048] represents the aggregation result of the verification function. This function is passed back to each client together with ω and the number of all online clients for verification.

[0049] Step 7: After receiving the return result, the client verifies the received parameters. The verification formula is as follows:

[0050]

[0051] is the result of the second aggregation. The client calculates the secondary aggregation result ω, and n returned by the server. If then the aggregation result is verified to be correct. The client will update the global model to restore the true global model parameters for the next training;

[0052]

[0053] ω t+1 represents the global model parameters for the next round of training; ω t the global model parameters of the previous round; represents the sum of the random numbers corresponding to the negotiation secret keys generated by the TTP in the previous round, and restores the global model parameters after successful verification by the client.

[0054] The advantages of the present invention are as follows:

[0055] 1) A more secure solution: The algorithm effectively solves the problem of information leakage, greatly limits the ability of the server to view the details of the local model, and only allows the server to access the specially randomized shared model.

[0056] 2) Precise aggregation: Local participants have the ability to fully restore the underlying true global model, and the introduction of encryption and decryption steps does not result in any reduction in model accuracy.

[0057] 3) An efficient verifiable protocol: The introduced double-aggregation method enables each participant to verify the aggregation parameters on the client side, ensuring the correctness of the aggregation result. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] Figure 1 is a framework diagram of a verifiable federated learning method and device for double decomposition and aggregation of the present invention;

[0059] Figure 2 is a schematic diagram of the accuracy comparison between the present invention and different aggregation algorithms on the MINIST dataset;

[0060] Figure 3 is a schematic diagram of the accuracy comparison between the present invention and different aggregation algorithms on the CIFAR-10 dataset;

[0061] Figure 4 is an image after gradient inversion of the present invention and different aggregation algorithms;

[0062] Figure 5 is a structural similarity graph after gradient inversion of the present invention and different aggregation algorithms. DETAILED DESCRIPTION OF THE INVENTION

[0063] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments.

[0064] This application adopts the same threat model as previous research. That is, the clients are honest but curious: they follow the protocol procedures but may try to infer the private data of other clients. However, a potentially malicious server may access the real global model information and reconstruct it to obtain the real client data. In addition, a malicious server may send inaccurate aggregation results to reduce costs or pursue illegal goals. This invention introduces a trusted third party (TTP), which is considered a non-colluding and absolutely trustworthy entity responsible for initializing system parameters and transmitting data such as keys and random numbers. To solve the above problems, this invention proposes an enhanced mechanism that uses double decomposition and double aggregation to keep the global model hidden from the server and enable the clients to self-verify the data transmission. Specifically, based on the traditional MPC decomposition, each decomposed share is further divided into a public part and a private part. This double decomposition retains the lossless encryption and decryption advantages of standard MPC and ensures that the central server obtains a non-real global model. In addition, in terms of aggregation, in addition to aggregating the global model, further aggregation of verification parameters is added, enabling the clients to locally verify the correctness of the aggregated parameters. Theoretical analysis and experimental results show that this improved scheme significantly improves the security and privacy protection of training data with minimal communication, computing, and storage overheads.

[0065] The verifiable federated learning method and device of the double decomposition and aggregation are as Figure 1 shown, and are divided into the following steps:

[0066] Step 1: Introduce a trusted third party (TTP). The TTP and each user respectively generate two key pairs locally;

[0067] The first pair: {(pk 1 , sk 1 )(pk 2 , sk 2 )} ← KenGen()

[0068] The second pair:

[0069] The TTP sends the public keys {pk 1 , pk 2} of its two key pairs to each client through the server, and the client sends the public keys of its two key pairs to the TTP through the server.

[0070] The TTP uses the public key of the first key pair received from the server and the private key sk 1 of the first key pair it retains to perform key negotiation to obtain

[0071]

[0072] Each client also uses the public key pk of the first pair of secret keys of the TTP received from the server 1 and the private key of the first pair of secret key pairs reserved locally to perform key negotiation to obtain

[0073] Step 2: The TTP and each client will use the generated negotiated secret key as a random number seed to generate arbitrary random numbers through a random number generator (PRG)

[0074]

[0075] Through the above operations, the TTP will obtain the random numbers of all clients while each client only knows its own The TTP sums up all the random numbers to obtain

[0076]

[0077] Step 3: The TTP transmits through the server to each client. At the same time, in order to prevent malicious third parties or malicious servers from stealing information, an encryption method needs to be used. We use the symmetric encryption method to encrypt the data transmitted by the TTP;

[0078] X←AE.enc(SK,x)

[0079] AE.dec(SK,X)→x

[0080] The TTP uses the public key of the second pair of secret key pairs received from the server and the private key sk of the second pair of secret key pairs retained by itself 2 , to perform key negotiation to obtain

[0081]

[0082] Use the second negotiated secret key as the secret key for symmetric encryption to encrypt to obtain the ciphertext ct i ;

[0083]

[0084] The TTP sends the corresponding ct i to each client through the server. The client decrypts after obtaining ct i ;

[0085]

[0086] Step Four: Two decompositions will be performed in this step.

[0087] The first decomposition:

[0088] First, the model parameters w trained by each client i are divided into n independent secret shares;

[0089]

[0090] The subscript i represents the client participating in the decomposition, and the model of client i will be decomposed into n parts. represents the model fragment transmitted from client i to client j. Compared with being managed by a single client, decomposing the model parameters into multiple secret shares and jointly managing them by multiple participants significantly improves security. Since each part exists in isolation, it is almost impossible to discover the overall view of the model or the sensitive information embedded in it. This distributed management method greatly reduces the risk of data leakage.

[0091] After decomposing w i according to the above formula, client i (where i is any value between 1 and n) enters the local communication stage. In the case of a fully connected network, client i sends its model block to all adjacent clients and simultaneously receives the model parameters from all other clients j (j ranges from 1 to n)

[0092] The second decomposition:

[0093] Each client further decomposes the received model parameters for further processing;

[0094]

[0095] The second-round decomposition further refines the client data after the first-round decomposition and divides the parameters into two parts: one part is securely stored locally, and the other part is securely sent to the server for global aggregation processing. To achieve this decomposition, the client can simply randomly select a part from its complete model as the bias term and subtract this part from the original model to obtain a general model block. The key is that all participating clients must reach a consensus on this random bias amount, that is, all clients should have the same bias amount.

[0096]

[0097] This ensures that when the server returns the globally aggregated common model blocks to each client, they can accurately add their respective bias terms to restore the complete local model. This mechanism not only protects the privacy of the data but also promotes the effective aggregation of models in a distributed environment. Here, we will use the value generated by the TTP in Step 1 and transmitted to the clients as the unified bias term for the above decomposition.

[0098] Step 5: The clients will aggregate the data after secondary decomposition;

[0099]

[0100] ω i represents the recombined local model parameters after secondary decomposition. Each client uploads this parameter to the server for aggregation. In addition to uploading ω i , each client also uploads a verification function v i .

[0101]

[0102] The verification function v i is constructed based on ω i . Each client combines the random value sum of random values generated by the secret key negotiated with the TTP and the uploaded public local model parameter ω i . After the verification function is generated, v i is uploaded to the server together with ω i .

[0103] Step 6: The server uses the Federated Averaging method to aggregate the two types of parameters after receiving v i and ω i .

[0104]

[0105] ω represents the aggregated global model parameters. These parameters are not the real global model parameters but are with bias terms.

[0106]

[0107] Here, we keep the sum of the shared keys generated by the TTP secret from the server. The result of the above formula is In the result of the above proof, the obtained value of ω has The deviation amount, which is added after being transmitted back to the client to obtain the complete global model parameters, thus realizing a lossless encryption process.

[0108]

[0109] Represents the aggregation result of the verification function, and its aggregation process is shown as follows.

[0110]

[0111] This function will be transmitted back to each client together with ω and the number of all online clients for verification.

[0112] Step Seven: After the client receives the returned result, it will verify the received parameters, and the verification formula is as follows:

[0113]

[0114] Is the result of the second aggregation. The client calculates the quadratic aggregation result ω returned by the server, And n. If Then it is verified that the aggregation result is correct. The client will update the global model to restore the real global model parameters for the next training;

[0115]

[0116] ω t+1 Represents the global model parameters participating in the training in the next round, and this parameter is a real lossless parameter; ω t The global model parameters of the previous round, and this parameter has a random bias; Represents the sum of the random numbers corresponding to the negotiation secret keys generated by the TTP in the previous round. This parameter is used as a bias and restores the global model parameters after the client successfully verifies.

[0117] The present invention adopts a two-step decomposition mechanism of secret sharing, making the real global model invisible to the central server. At the same time, each client can verify the global model returned by the server locally. And each client can independently verify the data from the server, preventing a malicious server from sending inaccurate aggregation results, causing the client training not to converge, thus ensuring the correctness of the server data transmission and realizing the security protection of federated learning.

[0118] The result indicates:

[0119] The present invention conducted relevant experiments using the MINIST and CIFAR-10 datasets, with 100 training epochs. For the MNIST dataset, we used a deep learning model based on a three-layer fully connected network, with two 256-dimensional hidden layers and the ReLU activation function to extract and classify features from the MNIST handwritten digit dataset, and output 10-class results. For the CIFAR-10 dataset, we used a neural network consisting of three convolutional layers and two fully connected layers to extract features and classify them through convolution, pooling, and the ReLU activation function. We used Adam as the network optimizer with a batch size of 64, the learning rate for both models was 0.001, and the number of clients was 50. Gradient inversion used the vgg-16 model, and the number of clients was set to 4. The experiments were run using Python 3.8.19 on the PyTorch framework.

[0120] Figure 2 and Figure 3 shows the training and test performance of different algorithms on two datasets. The results show that the curves of MPC-based algorithms almost overlap with the curves of unencrypted federated learning, indicating that these additional MPC encryption and decryption steps do not affect the final performance. At the same time, our method (MPC_VAL) also shows a similar effect, which is consistent with the theoretical analysis that MPC_VAL successfully inherits the lossless property of MPC.

[0121] Figure 4 shows the final image obtained after 4000 iterations and compares it with the ground truth. Using unprotected FedAvg and traditional MPC algorithms, when the batch size is 16, the server can accurately recover almost all images. In contrast, the MPC_VAL algorithm allows the server to receive only biased models or gradients by introducing two rounds of decomposition. After 4000 local iterations, the server can only obtain some random noise, thus providing stronger defense against gradient inversion methods.

[0122] Figure 5 shows that the server or a malicious attacker can start from random noise, gradually adjust the gradients to match the true gradients, and finally recover the underlying image. For all algorithms except MPC_VAL, the structural similarity (SSIM) between the inverted image and the true image continues to increase, while MPC_VAL maintains a low SSIM value, demonstrating its advantage in privacy protection.

[0123] This invention is compared with two well-known secure aggregation protocols. These two protocols are widely used as benchmarks in the literature. All complexity calculations given below assume a single server and N users, where each user has a model parameter vector of size V.

[0124] [1] H.Fereidooni et al., "SAFELearn: Secure Aggregation for private FEderated Learning," 2021 IEEE Security and Privacy Workshops (SPW), San Francisco, CA, USA, 2021, pp. 56-62, doi:10.1109 / SPW53761.2021.00017.

[0125] [2] G.Xu, H.Li, S.Liu, K.Yang and X.Lin, "VerifyNet: Secure and Verifiable Federated Learning," in IEEE Transactions on Information Forensics and Security, vol. 15, pp. 911-926, 2020, doi:10.1109 / TIFS.2019.2929409.

[0126] The cost calculation of the client mainly includes computing cost, communication cost, and storage cost. In terms of computing, each client needs to perform self-decomposition, send the decomposed parameters to other clients, and perform parameter recombination. The computational complexity of this process is O(V). In addition, the client also needs to generate random numbers with a computational complexity of O(N), as well as for computing v i and verifying the gradients with a computational complexity of O(V), resulting in a computational complexity of O(N+V). In terms of communication, the client needs to send and receive the decomposed parameters to other clients, and send the reconstructed parameters and verification parameters to the server. The overall communication complexity is also O(NV). In terms of storage overhead, in addition to storing its own key generation data, the client also needs to save the keys corresponding to the trusted third party, with a complexity of O(N), and store v i , and the data vectors of the model parameters with a complexity of O(V), so the total storage overhead is O(N+V).

[0127] The cost calculation of the server also includes computing cost, communication cost, and storage cost. In terms of computing, the server needs to aggregate the local gradients of all clients, which involves subtracting the biased local model parameters, with a computational complexity of O(NV), and the complexity of computing the aggregated gradients Is O(N), and the computational complexity reaches O(NV). In terms of communication, the server acts as an interface between the user and the trusted third party, responsible for collecting and broadcasting keys, forwarding encrypted ciphertexts, receiving the parameter vector and v from the client i vector, and aggregating the parameter vector and v i vector and broadcasting it to each client. The communication complexity is O(N). Each client uploads the parameters twice, for a total of 2N uploads, with each upload being O(V). Therefore, the total upload traffic is 2N * O(V) = O(NV). The server needs to distribute the parameters of each client to the other N - 1 clients, that is, each parameter is broadcast N - 1 times. So the total download traffic is N * (N - 1) * O(V) ≈ O(N 2 V). The overall communication complexity is O(N 2 V). In terms of storage cost, the server needs to store the public keys of the users, the list of online clients, the aggregated parameter vector, and the aggregated verification vector, and the storage complexity is O(N + V).

[0128]

[0129] According to the comparison in the above table, since it is an improvement based on the secret sharing method, the client will transmit the decomposed model parameters through the server, resulting in a slightly larger communication overhead between the client and the server of this invention than the above two methods. However, because of two decompositions and the verification function being just a simple random number, this invention is superior to the above two methods in terms of both computational overhead and storage overhead.

Claims

1. A verifiable federated learning method and device with dual decomposition and aggregation, characterized in that: The following steps are taken: Step 1: Introduce a trusted third party (TTP). The TTP and each user generate two key pairs locally. The first pair: {(pk 1 ,sk 1 )(pk 2 ,sk 2 )}←KenGen() Second pair: TTP uses the server to send the public keys of its two key pairs {pk 1 ,pk 2 } is sent to each client, and the client sends the public key of its two pairs of secret keys Sent to TTP through the server. TTP uses the public key received from the server With the private key sk retained by yourself 1 , and perform key negotiation to obtain Each client also uses the secret key to negotiate Step 2: TTP and each client will generate a negotiated key Generates any random number through a random number generator (PRG) as a random number seed Through the above operations, TTP will get the random numbers of all clients. TTP sums up all random numbers to get for i∈[1,2,…,n] Step 3: TTP sends Transmitted to each client, here the symmetric encryption method is used to encrypt the data transmitted by TTP; X←AE.enc(SK,x) AE.dec(SK,X)→x TTP uses the public key received from the server The private key sk 2 , and perform key negotiation to obtain The second negotiated key As a key pair for symmetric encryption Encrypt to get the ciphertext ct i ; TTP sends the corresponding ct i Sent to each client. The client gets ct i Then perform decryption operation; Step 4: Two decompositions will be performed in this step. First round breakdown: First, the model parameters w trained by each client are i Divide into n independent secret shares; for i∈[1,2,…,n] w i After decomposition according to the above formula, client i (where i is any value between 1 and n) enters the local communication phase. In the case of a fully connected network, client i blocks its model Send to all neighboring clients and receive model parameters from all other clients j (j from 1 to n) Second round of breakdown: Each client will receive the model parameters Further decomposition processing; The second round of decomposition further refines the client data after the first round of decomposition and converts the parameters Divided into two parts: one Stored securely locally, the other part Securely sent to the server for global aggregation processing. Here, we will generate and transmit to the client based on the TTP in step 1 The values ​​are decomposed as above as uniform deviations. Step 5: The client aggregates the data after the secondary decomposition; for j∈[1,2,…,n] ω i Represents the reorganized local model parameters after secondary decomposition, and each client uploads this parameter to the server for aggregation. i , each client will also upload a verification function ν i . for i∈[1,2,…,n] Verification function ν i is based on ω i Each client generates a random value based on the secret key negotiated with the TTP. Random value sum And the uploaded public local model parameters ω i After the verification function is generated, ν i With ω i Upload to the server together. Step 6: The server receives ν i With ω i Then the two parameters are aggregated using the Federated Averaging method. for i∈[1,2,…,n] ω represents the global model parameters after aggregation. for i∈[1,2,…,n] Represents the aggregate result of the verification function, which will be passed back to each client for verification along with ω and the number of all online clients. Step 7: After receiving the returned result, the client will verify the received parameters. The verification formula is as follows: The client calculates the secondary aggregation result ω returned by the server. and n. If Then verify that the aggregation result is correct. The client will update the global model and restore the real global model parameters for the next training; ω t+1 Represents the global model parameters participating in the next round of training; ω t The global model parameters of the previous round; It represents the sum of random numbers corresponding to the negotiation key generated by TTP in the previous round, and restores the global model parameters after successful client verification.

2. A method and apparatus for verifiable federated learning with dual decomposition and aggregation as claimed in claim 1, characterized in that: In step 4, the second round of decomposition is based on the sum of random numbers generated by TTP, and a part of it is retained locally so that the server cannot obtain the real model parameters. At the same time, this function can also be used to construct the verification function ν in the following steps. i .

3. A method and apparatus for verifiable federated learning with dual decomposition and aggregation as claimed in claim 1, characterized in that: In the step 5, based on ω i Based on the random value generated by the secret key negotiated between each client and TTP Random value sum Combine and construct a verification function.

4. A method and apparatus for verifiable federated learning with dual decomposition and aggregation as claimed in claim 1, characterized in that: In step 6, the global model parameter aggregation proof formula is as follows: Here, we make The sum of the shared keys generated by the TTP is kept secret from the server. The result of the above formula is In the results of the above proof, the obtained value of ω exists The bias value is added after being passed back to the client to obtain the complete global model parameters, thus achieving a lossless encryption process. The verification function aggregation proof formula is as follows: Each client can verify by itself, by judging Δ and Whether the model parameters are equal is used to determine whether they have been tampered with and to perform subsequent parameter update operations.

Citation Information

Patent Citations

  • Secure verifiable federal learning scheme

    CN116506154A

  • Bidirectional verifiable federal learning method for privacy protection

    CN117648716A

  • Method for protecting privacy and preventing backdoor attack in federated learning

    CN119312381A

  • Verifiable active security aggregation method and system for federated learning

    CN119416266A