Continuous back perception federated learning defense method based on zero trust
By adopting zero trust strategy and Dirichlet distribution model in the federated learning system, dynamically managing client trust is solved, and the problem that traditional security policies cannot cope with dynamic changes in participants' behavior is significantly improved.
Patent Information
- Application Number
- CN202510037498.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-09
- Publication Date
- 2025-06-27
AI Technical Summary
In federated learning systems, traditional security strategies rely on the assessment of trust in participants’ past behavior, cannot effectively respond to security threats when participants’ behavior changes dynamically, and the system is vulnerable to internal malicious attacks.
The zero-trust-based continuous betrayal perceived federated learning defense approach is adopted to dynamically adjust the trust level of clients through continuous risk assessment and trust management, and use the Dirichrey distribution model to evaluate the trust of clients, combined with multi-valued satisfaction analysis, identify and exclude malicious clients.
It effectively improves the security and robustness of the federated learning system, and can dynamically adjust trust scores when facing complex network security threats to ensure data integrity and model training security.
Smart Images

Figure CN120218276A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of distributed machine learning, and particularly to a continuous betrayal perception federated learning defense method based on zero trust. Background Art
[0002] This analysis involves the combined application of federated learning (FL) and zero-trust security models. In particular, it studies how to implement zero-trust security policies in federated learning systems to enhance the system's defense capabilities against malicious attacks and protect data privacy and system integrity.
[0003] Federated learning is a distributed machine learning technique that allows multiple participants to collaboratively train a model without sharing their data. This approach has significant advantages in terms of privacy protection, but as the number of participants increases, the system becomes more vulnerable to internal malicious attackers. Traditional security policies rely on trust assessments of participants' past behaviors, but this method may not be effective when participants' behaviors change dynamically. The zero-trust security model proposes a solution by continuously verifying and minimizing trust to address security threats. Summary of the Invention
[0004] In view of the above problems in the prior art, the present invention proposes a method for implementing zero-trust policies in federated learning. This policy does not default trust to any client, but dynamically manages trust through continuous risk assessment. The federated learning system includes clients C = {1, 2,..., C} and a central server. Only a selected subset K ∈ C of clients can participate in the FL task, where the number of participating clients is denoted as K, and K < C; each client k ∈ K collects its private dataset D k , where D k has a data volume of |D k |, and the size of all training data is denoted as D = ∑k∈K D k ;
[0005] The main objective of the federated learning task is to minimize the global loss function by identifying the optimal model parameters w, whose dimension is E:
[0006]
[0007] where represents the global model parameters, p k = D k / D represents the weight of client k; the global loss function is expressed as the weighted aggregation of individual local loss functions; the local loss function generated by client k is the total deviation between the prediction result and the actual result;
[0008] Let \(M = \{1, 2, \ldots, M\}\) denote the set of global communication rounds, and \(I = \{1, 2, \ldots, I\}\) denote the set of local training rounds; the global model in global round \(m\) can be represented as while the local model of client \(k\) in local round \(i\) of global round \(m\) can be represented as Then, in global round \(m\), use the local stochastic gradient descent method with learning rate \(\eta_m\); by aggregating all local models \(w\) after \(I\) local rounds k,m , the global model is obtained
[0009]
[0010] Quantify decision uncertainty by combining prior knowledge with observations, adopt the Dirichlet distribution to actively update the trust estimation of clients, improve the reliability of local updates based on trust estimation, and then identify and exclude malicious clients.
[0011] In one embodiment, conduct strict behavior analysis on all participating clients based on the zero-trust policy, evaluate the behavior patterns and potential risks of each client, and ensure the integrity of data and the security of model training during the federated learning process.
[0012] In one embodiment, apply the Dirichlet distribution model to evaluate the trust level of clients, and by combining multi-valued satisfaction analysis and considering the time-varying behavior of clients, improve the accuracy of client selection.
[0013] In one embodiment, adopt a satisfaction function \(S(x)\) with a range from 0 to 1 to quantify the satisfaction with the provided performance;
[0014] Let \(X\) be a discrete random variable representing the client satisfaction level, drawn from a set of \(N\) finite mutually exclusive events \(X=\{x_1, x_2, \ldots, x\) n \(\}\), where \(N\geq2\); each \(x\) n \(\in[0, 1]\) defines a different satisfaction level and satisfies \(x\) n \(_{n + 1}>x\) n \(_n\); as \(x\) n increases, the weight \(\tau_n\) assigned to each satisfaction level \(x\) n increases, and the sum of the total weights of all levels is 1; define a vector \(\pi=\{\pi_1, \pi_2, \ldots, \pi_n\}\), where \(\sum_{n = 1}^N\pi_n = 1\), which represents the probability distribution of \(X\), and define the probability that \(X\) takes each possible satisfaction level \(x\) n as follows:
[0015] \(P\{X = x\) n \(\}= \pi\) n \(_n\),
[0016] where \(P\) is the probability function;
[0017] Let α = {α1, α2,..., αN} represent the cumulative observations and initial beliefs of the client, serving as the basis for understanding the probability distribution of X; incorporate the forgetting factor γ ∈ [0, 1] into the observation vector α:
[0018]
[0019] where t represents the number of observations; γ t is the satisfaction level of the t-th observation, which can be represented as an N-dimensional tuple (0, 0,..., 0, 1, 0,..., 0), where the n-th element being 1 indicates that the satisfaction level is equal to x n ; the parameter b0 > 0 reflects the prior belief, and Y 0 serves as the initial setting of the probability distribution.
[0020] In one embodiment, assume that the probability of obtaining the satisfaction level x n from N numbers is π n , and the observation of x n is α n ; the posterior Dirichlet distribution of P can be expressed as:
[0021]
[0022] Let and B(α) can be expressed using the gamma function as follows:
[0023]
[0024] Then, considering the historical observations, the probability expectation of π n can be expressed as:
[0025]
[0026] Use the mean of the posterior expectation value {π1, π2,..., π N} to represent the trust level of client k:
[0027]
[0028] In one embodiment, continuously suspect each participant and optimize the weight allocation to minimize the betrayal loss in the worst case, thereby ensuring the robustness of the betrayal awareness.
[0029] The present invention proposes a zero - trust policy in federated learning to ensure the reliability and robustness of federated learning in the face of the increasing risks of client attacks and betrayal behaviors. Through this policy, the system no longer gives inherent trust to any client, but adopts a continuous risk assessment mechanism to dynamically adjust the trust level of clients. The core of this strategy is that even clients with reliable past performance must maintain their trust through continuous behavior verification, thus effectively preventing potential internal threats. In addition, this policy also includes strict behavior analysis of all participating clients, using advanced algorithm models to evaluate the behavior patterns and potential risks of each client, ensuring the integrity of data and the security of model training during the federated learning process. This new security measure aims to provide an additional layer of protection for the federated learning environment, enabling it to resist complex and changing cybersecurity threats.
[0030] Specifically, the present invention applies the Dirichlet distribution model to evaluate the trust of clients. By combining multi - valued satisfaction analysis and considering the time - varying behavior of clients, it promotes an accurate client selection technique. This method can comprehensively understand the behavior patterns and potential risks of each client. Through detailed analysis of past behaviors, it allows the system to dynamically adjust the trust score and make more reasonable participation decisions. By using the Dirichlet distribution, not only can the trust level of clients be quantified, but also their future possible performance can be predicted based on the diversity and complexity of client behaviors, thus enhancing the overall security and efficiency of the federated learning system.
[0031] In addition, in order to adhere to the principle of zero - trust for all participants, the present invention implements a suspicion mechanism to guard against potential betrayal behaviors. To enhance the robustness of the model, the present invention formulates a min - max optimization problem to minimize the betrayal loss in the worst - case scenario, thus protecting the federated learning system from unexpected security challenges. Through this suspicion mechanism, even well - behaved participants are not fully trusted, and the system continuously verifies the consistency and reliability of their behaviors. The design of the min - max optimization model is to ensure that even in the face of extremely adverse situations, the overall performance of the system can be guaranteed, effectively reducing the losses that may be caused by the improper behaviors of participants and enhancing the security and continuous operation ability of the entire federated learning network.
[0032] To verify the zero - trust policy proposed by the present invention, extensive simulation experiments were conducted. The simulation results show that, in terms of the effectiveness of trust and the robustness against betrayal, the policy of the present invention is superior to the baseline method. Through these simulations, the present invention can test the performance of the zero - trust strategy in various scenarios, ensuring the feasibility and effectiveness of the strategy in actual operation. These simulations consider different types of client behaviors, including normal behaviors and potential malicious behaviors, thus comprehensively evaluating the effectiveness of the policy in defending against internal threats. The results prove that even in an environment where client behaviors are extremely complex or hostility increases, the zero - trust policy of the present invention can effectively maintain the security and stability of the system, significantly improving the adaptability and overall performance of the federated learning system in the face of security challenges. Brief Description of the Drawings
[0033] In the following, the present invention will be described in more detail based on embodiments and with reference to the drawings. Among them:
[0034] Figure 1 The zero - trust policy for FL includes posterior trust evaluation techniques and betrayal - aware defense mechanisms;
[0035] Figure 2 are the prior and posterior Dirichlet probability density functions of two users;
[0036] Figure 3 are the trust values under different settings;
[0037] Figure 4 are the training losses of different methods;
[0038] Figure 5 are the training losses under different attack intensities. Detailed Description of the Preferred Embodiments
[0039] The present invention will be further described below with reference to the drawings.
[0040] The present invention considers a federated learning system consisting of a set of clients C = {1, 2,..., C} and a central server. Due to limited resources and the presence of potential malicious clients, only a selected subset K ∈ C of clients can participate in the FL task, where the number of participating clients is denoted as K (K < C). Each client k ∈ K collects its private dataset D k , where D k has a data volume of |D k |, and the size of all training data is denoted as D = ∑k∈K D k .
[0041] The main objective of the federated learning task is to minimize the global loss function by identifying the optimal model parameters w, whose dimension is E:
[0042]
[0043] where represents the global model parameters, p k = D k / D represents the weight of client k. Note that the global loss function is expressed as a weighted aggregation of the individual local loss functions. The local loss function generated by client k can be calculated as the total deviation between the predicted result and the actual result.
[0044] Let M = {1, 2,..., M} represent the set of global communication rounds, and I = {1, 2,..., I} represent the set of local training rounds. The global model in the global round m can be represented as while the local model in the local round i of client k in the global round m can be represented as Then, in the global round m, the local stochastic gradient descent method with the learning rate ηm is used. By aggregating all the local models w k,m after I local rounds, the present invention can obtain the global model
[0045]
[0046] The present invention introduces a trust-based technique to improve the reliability of local updates by identifying and excluding malicious clients. The server selects clients for FL training based on the managed trust memories of all clients. The present invention estimates the future satisfaction level of clients by analyzing the satisfaction distribution among client performances. To quantitatively evaluate the contribution of clients, the present invention uses a satisfaction function S(x), ranging from 0 to 1, to quantify the satisfaction with the provided performance.
[0047] Let X be a discrete random variable representing the client satisfaction level, drawn from a set of N (N ≥ 2) finite mutually exclusive events in X = {x1, x2,..., x n}. Each x n ∈ [0, 1] defines a different satisfaction level and satisfies x n +1 > x n . As x n increases, the weight τn assigned to each satisfaction level x n increases, and the sum of the total weights of all levels is 1. The present invention defines a vector π = {π1, π2,..., πn}, where ∑Nn = 1 πn = 1, which represents the probability distribution of X, and defines the probability that X takes each possible satisfaction level x n as follows
[0048] P{X = x n} = π n ,
[0049] where P is the probability function.
[0050] Let α = {α1, α2,..., αN} represent the cumulative observations and initial beliefs of the client, serving as the basis for understanding the probability distribution of X. To give greater importance to the most recent observations than the older ones, the present invention incorporates the forgetting factor γ (∈[0, 1]) into the observation vector α in the following manner:
[0051]
[0052] where t represents the number of observations. γ t is the satisfaction level of the t-th observation, which can be represented as an N-dimensional tuple (0, 0,..., 0, 1, 0,..., 0), where the n-th element being 1 indicates that the satisfaction level is equal to x n . The parameter b0 > 0 reflects the prior belief, and Y 0 serves as the initial setting of the probability distribution.
[0053] By combining prior knowledge with observations to quantify decision uncertainty, the present invention uses the Dirichlet distribution to actively update the trust estimate of the client. The Dirichlet distribution represents the initial belief in an uncertain event and evolves into a posterior distribution after being combined with sample data. This helps to dynamically update the trust based on the interaction history, leading to the following definition.
[0054] Definition 1: Suppose the probability of obtaining the satisfaction level x n from N numbers is π n , and the observation of x n is α n . The posterior Dirichlet distribution of P can be expressed as
[0055]
[0056] Let and B(α) can be represented by the gamma function as follows
[0057]
[0058] Then, considering the historical observations, the probability expectation of π n can be expressed as:
[0059]
[0060] Therefore, the present invention uses the mean of the posterior expectation value {π1, π2,..., π N} to represent the trust level of client k, which can be expressed as:
[0061]
[0062] Although trusted clients can participate in FL training, there is a risk that they may betray the system after initially gaining trust. To simplify further analysis, the present invention assumes the existence of a malicious client who adds random noise from a Gaussian distribution to the parameters transmitted upward as an attack method. The traitor uses a subtle noise attack aimed at reducing the accuracy of the model without being detected by the trust evaluation system.
[0063] To further derive the loss caused by the betrayal attack, the present invention first introduces the definition of "(∈, ζ)-potential attack under zero trust" as described below.
[0064] Definition 2: The (∈, ζ)-potential attack under zero trust indicates that when the traitor applies the attack model Y, for all measurable output sets R, and any pair of adjacent data sets X and X', the following inequality holds:
[0065]
[0066] where ∈ > 0 represents the attack impact, and ζ ∈ [0, 1] represents the probability of failure.
[0067] A smaller ∈ results in less discrimination between adjacent data sets because the traitor introduces stronger noise. The standard deviation σ of the Gaussian noise k can be expressed as
[0068]
[0069] where ρ is defined as the upper bound of the model parameter ∥w∥, and p k is the data size of client k. The present invention considers the general assumptions of the loss function as described below:
[0070] Assumption 1. For all k ∈ {1, 2,..., K}, Fk(w) is L-smooth and has a lower bound.
[0071] Assumption 2. For all k ∈ {1, 2,..., K}, Fk(w) is μ-strongly convex.
[0072] Assumption 3. Fk(w) is β-Lipschitz.
[0073] To measure the impact of the noise attack on the FL performance, the present invention provides an upper bound for E[F(wT)] - F(w*), by deriving the following theorem.
[0074] Theorem 1. Assume that Assumptions 1 to 3 hold. Let Δ0 = F(w0) - F(w * ), where F(w0) and F(w * ) represent the initial parameter w0 and the optimal parameter w* The loss function. When only client k betrays the system, the present invention can obtain The upper bound of:
[0075]
[0076] where A2 = LE 2 M.
[0077] Theorem 1 establishes the connection between Gaussian noise attacks (represented by σ k ) and the convergence of federated learning (represented by ). A stronger attack (with a higher standard deviation σ k ) will result in a higher upper bound, thus leading to a decrease in accuracy. In addition, a higher weight p k will further reduce the convergence performance of federated learning because the traitor can deteriorate the system performance by increasing the misleading global aggregation. Therefore, it is crucial to allocate weights appropriately to balance the global trust and potential attack damage, thus maintaining the robustness of the FL system.
[0078] The present invention integrates the Dirichlet-based trust evaluation technology and the traitor-aware defense mechanism into FL and proposes the corresponding zero-trust policy, aiming to mitigate the security threats brought by the dynamic behavior of clients and potential traitor attacks, such as Figure 1 shown.
[0079] To screen for possible malicious clients, the present invention sets a threshold ψ calculated based on the trust value V for client selection. The present invention arranges reliable users who meet the following conditions:
[0080]
[0081] where ψ is the threshold of the trust score. If a k = 1, client k is arranged to perform FL training; otherwise, the client is not selected.
[0082] Although the above client selection method effectively excludes highly untrusted clients, it ignores the subtle trust differences among the remaining clients. In the context of diverse trust levels, simply equalizing the contribution weights of each client may expose the model to vulnerabilities. Therefore, it is crucial to assign different weights p k to different clients according to their trust scores during model aggregation to enhance robustness. To this end, the present invention introduces a new threshold θ to set the lower bound of the cumulative weighted trust evaluation, which can be written as
[0083]
[0084] In addition, to fully embody the zero-trust policy, the present invention remains skeptical of all clients, even those that are highly trusted. If a highly trusted client betrays, the resulting loss may be more severe than that caused by a less trusted client, posing a significant threat to the robustness of the system. By directly addressing the worst-case betrayal attack, the goal of the present invention is to enhance overall security and the effectiveness of the policy. Therefore, the present invention formulates a minimax optimization problem to recognize and address the severe consequences that the most serious betrayal may bring.
[0085] Here, the goal of the present invention is to minimize the potential worst-case betrayal loss without compromising overall stability. To achieve the zero-trust goal, the objective that the present invention needs to minimize can be simplified to A1a k p k σ k +A2(a k p k σ k ), simplifying the problem by removing the constant term. In addition, the present invention restricts the lower bound of the sum of weighted trust values to ensure FL performance. The present invention formulates the following minimax optimization problem by optimizing the selection metrics a = [a1, a2,... a 2 and the aggregation weights p = [p1, p2,... p k : k
[0086]
[0087] Therefore, the importance of optimizing the selection metrics and the weights of clients lies in balancing the relationship between global trust and potential betrayal attacks. Directly solving the aforementioned problem is challenging due to the uncertainty of the maximum loss and the integer constraint of a k . To provide an effective solution, the present invention first introduces an auxiliary variable ξ. Then, the present invention eliminates the parameter a k by setting p k = 0 when a k = 0, and p k > 0 when a k = 1. Subsequently, the problem can be reformulated in the following form:
[0088]
[0089] Since only the first constraint is convex while the objective and other constraints are linear, this problem is a convex optimization problem. Therefore, the present invention applies the interior-point method to solve it.
[0090] To visually demonstrate the Dirichlet distribution probability density function, the present invention considers three satisfaction levels: dissatisfied, neutral, and satisfied, spanning 10 rounds. Initially, without prior information about the probability distribution, the present invention assumes a uniform prior distribution, Y0 = (2, 2, 2). The weights for the satisfaction levels are τ = {0.01, 0.14, 0.85}, and the forgetting factor γ is set to 0.9.
[0091] Figure 2 Depicts the dynamic Dirichlet probability density function for two clients across two rows. The left column shows the same prior Dirichlet probability density function for both users. In the right column, after accumulating 10 new observations, the posterior Dirichlet probability density function shows a narrowing of the peak relative to the prior probability density function. For client 1, the satisfaction level x3 dominates in all rounds, causing the posterior pdf to deviate from the bottom of the triangle, corresponding to the π3 axis. In contrast, client 2 received more evaluations at the satisfaction level x1, causing the posterior pdf to deviate from the right side of the triangle, representing the π1 axis.
[0092] Figure 3 Shows the impact of the observation rounds on the trust value. The three lines correspond to different initial belief weights (b0) of 10, 20, and 30. The first two curves represent users with consistently good behavior, while the third curve shows the transition of the user to malicious behavior. It can be seen that as b0 decreases and good behavior persists, the trust value quickly stabilizes. In contrast, dissatisfied evaluations lead to a rapid decline in trust. Therefore, although subsequent satisfactory performance can mitigate the impact of this malicious transition, rebuilding trust takes longer.
[0093] The performance of the zero-trust policy is tested by using the MNIST dataset and a 3-layer deep neural network in an FL simulation involving 50 clients and 1 central server. Each client performs 2 local epochs, while global training lasts for 100 epochs, using a learning rate of 0.01 and the Adam optimizer. The present invention introduces noise attacks from a Gaussian distribution to simulate the behavior of malicious clients. To highlight the superiority of the zero-trust policy, the present invention considers the following baselines for comparison:
[0094] Benign: All clients are benign, and no defense measures are taken in the system.
[0095] Betrayal: One of the trusted clients becomes malicious and attacks the model by adding subtle noise to the uploaded model, and no defense measures are taken in the system.
[0096] Figure 4Shows the changes in the loss function of three methods during the federated learning iteration process. It can be observed in the present invention that even in cases involving betrayal, all three methods can converge, thanks to continuous trust evaluation, which effectively filters out malicious clients. Then, it can be seen in the present invention that in the "betrayal" case, the loss is the highest, indicating that betrayal has the greatest negative impact on FL performance. This is because potential betrayers are hidden among seemingly trustworthy user groups, and they may try to attack the model while strategically avoiding detection. In addition, it can be found that the zero-trust policy of the present invention results in a lower loss compared to the "betrayal" case, showing its effectiveness in mitigating the losses caused by the betrayal of trusted clients. This is attributed to the continuous suspicion of each participant and the optimized weight allocation in the present invention to minimize the worst-case betrayal loss, thus ensuring the robustness of betrayal awareness. In addition, it can also be seen in the present invention that the loss from the zero-trust policy exceeds that of the "benign" case because of the existence of potential betrayers.
[0097] Figure 5 Shows the loss function values of the three methods under different attack intensities, where the attack intensity is represented by the standard deviation σ of Gaussian noise. It can be seen from the figure that for both the "benign" and "zero-trust" policies, the loss increases when the attack intensity increases, indicating that the model accuracy decreases in the presence of betrayal attacks. This is consistent with Theorem 1 that higher attack intensities increase the interference of attackers on the global model. It can also be found in the present invention that in the "benign" case, the loss remains constant because there is no betrayal behavior.
[0098] The present invention emphasizes the importance of integrating multi-valued trust evaluation techniques and betrayal awareness mechanisms in a zero-trust enabled federated learning system. The present invention proposes a trust evaluation technique based on the Dirichlet distribution, which uses multi-valued evaluation to achieve continuous participant selection over time. Considering the risk of unconditional trust in highly reputable clients due to potential significant betrayal impacts, the present invention adopts the zero-trust principle. The zero-trust policy of the present invention involves continuous suspicion of all clients, actively guarding against possible betrayals even by highly trusted participants. Thereafter, the present invention introduces a min-max formula aimed at mitigating the worst-case betrayal loss. Through extensive simulations, the present invention verifies the effectiveness of the zero-trust policy of the present invention, demonstrating its ability to accurately model trust and significantly enhance the betrayal awareness robustness of the model.
[0099] Although the present invention has been described herein with reference to particular embodiments, it should be understood that these embodiments are merely examples of the principles and applications of the present invention. Accordingly, it should be understood that numerous modifications may be made to the exemplary embodiments, and other arrangements may be devised, without departing from the spirit and scope of the present invention as defined by the appended claims. It should be understood that the different dependent claims and the features described herein may be combined in a manner different from that described in the original claims. It should also be understood that the features described in connection with separate embodiments may be used in other described embodiments.
Claims
1. A zero-trust based continuous betrayal-aware federated learning defense method, characterized in that: The federated learning system includes clients C = {1, 2,..., C} and a central server. A selected subset K ∈ C of clients participates in the FL task, where the number of participating clients is denoted as K, and K < C; for each client k ∈ K, a private dataset D of client k is collected k , where D k has a data volume of |D k |, and the size of all training data is denoted as D = ∑k∈K D k ; The main goal of the federated learning task is to minimize the global loss function by identifying the optimal model parameters w, whose dimension is E: in represents the global model parameters, p k =D k / D represents the weight of client k; the global loss function is expressed as the weighted aggregation of each local loss function; the local loss function generated by client k is the total deviation between the predicted results and the actual results; Let M = {1, 2, ..., M} represent the set of global communication rounds, and I = {1, 2, ..., I} represent the set of local training rounds; the global model in global round m can be expressed as The local model of local round i of client k in global round m can be expressed as Then, in the global round m, a local stochastic gradient descent method with a learning rate ηm is used; by aggregating all local models w after I local rounds k,m , and obtain the global model By combining prior knowledge with observations to quantify decision uncertainty, Dirichlet distribution is used to actively update the client's trust estimate. The reliability of local updates is improved based on the trust estimate, thereby identifying and excluding malicious clients.
2. The zero-trust based continuous betrayal-aware federated learning defense method according to claim 1, characterized in that: Based on the zero-trust policy, strict behavioral analysis is performed on all participating clients to evaluate the behavior patterns and potential risks of each client, ensuring the integrity of data and the security of model training during federated learning.
3. The zero-trust based continuous betrayal-aware federated learning defense method according to claim 2, characterized in that: The Dirichlet distribution model is applied to evaluate customer trust, and by combining multi-valued satisfaction analysis, the customer's behavior over time is considered to improve the accuracy of customer selection.
4. The zero-trust based continuous betrayal-aware federated learning defense method according to claim 3, characterized in that: The satisfaction function S(x), ranging from 0 to 1, is used to quantify the satisfaction with the provided performance; Let X be a discrete random variable representing the level of customer satisfaction, from a set X = {x1, x2, ..., x n } is extracted from N finite opposing events, N ≥ 2; each x n ∈[0,1] defines different satisfaction levels and satisfies x n +1>x n ; With x n The increase is assigned to each satisfaction level x n The weight τn increases, and the total weight of all levels is 1; define a vector π={π1,π2,...,πn}, where ∑Nn=1,πn=1, which represents the probability distribution of X, and define X to take each possible satisfaction level x n The possibilities are as follows: P{x=x n }=π n , Where P is the probability function; Let α = {α1, α2, ..., αN} represent the client's cumulative observations and initial beliefs as the basis for understanding the probability distribution of X; integrate the forgetting factor γ∈[0,1] into the observation vector α: Where t represents the number of observations; γ t is the satisfaction level of the t-th observation, which can be represented as an N-dimensional tuple (0,0,...,0,1,0,...,0), where the n-th element is 1, indicating that the satisfaction level is equal to x n ; The parameter b0>0 reflects the prior belief, while Y 0 It is used as the initial setting of the probability distribution.
5. The zero-trust based continuous betrayal-aware federated learning defense method according to claim 4, characterized in that: Assume that we get satisfaction level x from N numbers n The probability is π n , and for x n The observation is α n ; The posterior Dirichlet distribution of P is set up And B(α) is expressed as the gamma function as follows: Then, considering historical observations, π n The expected probability of is: The mean of the posterior expected value {π1,π2,...,π N } is used to represent the trust level of customer k:
6. The zero-trust based continuous betrayal-aware federated learning defense method according to claim 5, characterized in that: We maintain suspicion of each participant and optimize the weight distribution to minimize the worst-case betrayal loss, thus ensuring the robustness of betrayal awareness.