Federal learning method by combining algorithm acceleration with homomorphic encryption, program, equipment and storage medium
By introducing fast power modulation and Karatsuba algorithm to optimize the encryption and decryption process of Paillier homomorphic encryption in federated learning, the problem of large computing overhead is solved, and efficient computing and communication costs are achieved, and it is suitable for heterogeneous device collaboration scenarios with resource-constrained.
Patent Information
- Application Number
- CN202510613320.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-13
- Publication Date
- 2025-07-04
AI Technical Summary
The encryption and decryption process of Paillier homomorphic encryption in existing federated learning is expensive, resulting in low iteration efficiency, especially in resource-constrained scenarios, which is difficult to meet the needs of heterogeneous device collaboration.
The fast power-module calculation is optimized, and combined with the Karatsuba algorithm to optimize the modulo multiplication operation, a series collaboration mechanism of "first power-module calculation, and then Karatsuba multiplication" is formed in the encryption and decryption stages, respectively, to reduce the calculation amount and time complexity.
The encryption and decryption process is accelerated, the computing efficiency is improved by 3 times, and the communication cost is reduced by 70%, providing an efficient solution for privacy-enhanced federated learning in resource-constrained scenarios.
Smart Images

Figure CN120263385A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data privacy protection, and particularly relates to a federated learning method, program, device, and storage medium that utilize algorithm acceleration combined with homomorphic encryption. Background Art
[0002] In the era of big data, the combination of federated learning and homomorphic encryption is an important research direction in the field of privacy computing. The core challenge lies in how to reduce the additional computational overhead brought by encryption and decryption while ensuring data security. Existing research shows that the time for a single encryption and decryption operation grows non-linearly with the expansion of the model parameter scale, directly affecting the iteration efficiency of federated learning. To optimize the computational efficiency, existing research mainly explores from two directions: hardware acceleration and algorithm improvement.
[0003] At the hardware acceleration level, researchers have significantly improved the execution speed of high-complexity operations in homomorphic encryption by designing dedicated encryption chips, FPGA-based modular arithmetic accelerators, or GPU parallel computing architectures. However, these methods highly depend on specific hardware environments and have problems such as poor compatibility and high costs in cross-platform deployment and edge computing scenarios, making it difficult to meet the needs of federated learning for heterogeneous device collaboration.
[0004] The optimization at the algorithm level focuses on reducing the complexity of basic operations. Typical solutions include decomposing large integer modular multiplication into small-bitwidth multiplication units that can be processed in parallel, optimizing the convolution operation on polynomial rings through number theory transformation, or using the Chinese Remainder Theorem to perform divide-and-conquer processing on encryption parameters. Taking the Paillier algorithm as an example, although existing improvement methods have improved the efficiency of modular multiplication operations through bitwidth splitting strategies, there are still optimization blind spots in its exponent modulus operation, and the modular exponentiation operations required for high-order exponent operations have not been effectively simplified. This local optimization strategy results in limited overall acceleration effect, and there are still computational bottlenecks especially in the federated learning parameter aggregation stage where encryption operations need to be frequently executed.
[0005] The current technological development shows a trend of algorithm-hardware co-optimization, but there is still a need to break through in terms of generality and computational completeness. How to construct a lightweight encryption architecture independent of hardware and systematically optimize the operations in each stage of the encryption algorithm remains a key research direction for improving the practicality of federated learning. Summary of the Invention
[0006] The purpose of the present invention is to provide a method that can accelerate the encryption and decryption processes after combining Paillier homomorphic encryption in federated learning without relying on specific hardware.
[0007] The present invention provides a federated learning method that utilizes algorithm acceleration combined with homomorphic encryption, including:
[0008] Step 1: The client initializes the global model;
[0009] Step 2: The client updates the initialized global model parameters through backpropagation using the local training set to obtain the updated local model parameters;
[0010] Step 3: Homomorphically encrypt the local model parameters uploaded by the client using algorithm optimization to update the local model parameters and obtain the encrypted local model parameters; the algorithm optimization is to accelerate the power modulo calculation through the fast power modulo and optimize the modular multiplication operation by combining the Karatsuba algorithm;
[0011] Step 4: After the secure server receives the encrypted local model parameters transmitted by the client, it verifies whether the client's identity is legal and forwards the screened legal encrypted local model parameters to the aggregation server;
[0012] Step 5: After the aggregation server receives the legal encrypted local model parameters transmitted by the secure management server, it uses the addition and scalar multiplication characteristics of the Paillier homomorphic encryption algorithm to aggregate the model parameters, generates the recalculated encrypted global model parameters, and distributes the updated encrypted global model parameters to all clients;
[0013] Step 6: After each client receives the updated encrypted global model parameters, it performs a decryption operation using the algorithm optimization based on the private key;
[0014] Step 7: Use the decrypted global model parameters to re - train with the local training set for the next round, and repeat Steps 2 to 7 until the set number of iterations is reached, and the training process is completed.
[0015] Further, in Step 3, first use the fast power modulo algorithm to quickly calculate the key value g m mod n 2 and r n modn 2 ; the fast power modulo algorithm is to use the binary expansion of the power, split the exponent into the sum of several binary bits, and calculate the power result through square and multiplication operations; then use the fast power modulo algorithm to optimize the calculation in the process of encrypting the plaintext.
[0016] Further, for the calculation of the key value g m mod n 2 , where g is n + 1, m is the plaintext, n is the product of two large prime numbers, and the two large prime numbers need to satisfy gcd(pq, (p - 1)(q - 1)) = 1, and gcd is the greatest common divisor. Specifically:
[0017] Step 3.1.1: Convert the exponent m into binary form, examine the binary bits from right to left in turn, and construct the set [m1,..., mN , m i represents the value of the i-th bit from the right to the left in the binary form of the exponent m; initialize i = 1, a1 = 1;
[0018] Step 3.1.2: If m i = 1, then a i+1 = (a i × (g 2 mod n 2 )) mod n 2 ;
[0019] If m i = 0, then a i+1 = a i ;
[0020] Step 3.1.3: If i < N, then set i = i + 1 and return to Step 3.1.2; otherwise, output a i , that is, g m mod n 2 = a N .
[0021] Furthermore, the calculation steps for calculating the key value r n mod n 2 are the same as those for the key value g m mod n 2 , and the fast exponentiation modulo algorithm is used for calculation.
[0022] Furthermore, the process of encrypting the plaintext is as follows:
[0023] c = ((g m mod n 2 ) × (r n mod n 2 )) mod n 2
[0024] The Karatsuba algorithm is to decompose the multiplication of large integers into the multiplication of smaller integers, specifically:
[0025] Step 3.2.1: Let x = g m mod n 2 , y = r n mod n 2 , and split the two large integers x and y into two parts respectively;
[0026] x = a × 10 e + b
[0027] y = k × 10 e + d
[0028] Among them, a is the high-order coefficient after splitting x; b is the low-order value after splitting x; k is the high-order coefficient after splitting y; d is the low-order value after splitting y; e is the exponential parameter for splitting.
[0029] Step 3.2.2: Introduce an intermediate term z to reduce the number of multiplications. The calculation process is as follows:
[0030] x × y = ak × 10 2e + z × 10 e + bd
[0031] z = (a + b) × (k + d) - ak - bd
[0032] Furthermore, in Step 4, the decryption process is performed using a decryption optimization algorithm module; the decryption optimization algorithm module includes the Karatsuba algorithm and the fast exponentiation modulo algorithm; the specific operation process includes:
[0033] Step 4.1: Calculate the key component μ of the private key;
[0034] μ = L(g λ mod n 2 ) -1 mod n
[0035] Among them, the function g λ mod n 2 has the same calculation steps as the key value g m mod n 2 and is calculated using the fast exponentiation modulo algorithm, where λ = lcm(p - 1, q - 1), and lcm is the least common multiple;
[0036] Step 4.2: Calculate the plaintext m';
[0037] m′ = L(c λ mod n 2 ) × μ mod n
[0038] Among them, c λ mod n 2 has the same calculation steps as the key value g m mod n 2 and is calculated using the fast exponentiation modulo algorithm; the multiplication of L(c λ mod n 2 ) and μ is calculated using the Karatsuba algorithm.
[0039] The present invention also provides a computer device / apparatus / system, including a memory, a processor, and a computer program stored on the memory. When the processor executes the computer program, the steps of the federated learning method using algorithm acceleration combined with homomorphic encryption described in any one of the above are implemented.
[0040] The present invention also provides a computer-readable storage medium, on which a computer program / instructions are stored. When the computer program / instructions are executed by a processor, the steps of the federated learning method using algorithm acceleration combined with homomorphic encryption described in any one of the above are implemented.
[0041] The present invention also provides a computer program product, including a computer program / instructions. When the computer program / instructions are executed by a processor, the steps of the federated learning method using algorithm acceleration combined with homomorphic encryption described in any one of the above are implemented.
[0042] The beneficial effects of the present invention are as follows:
[0043] The federated learning method using algorithm acceleration combined with homomorphic encryption provided by the present invention innovatively integrates the Karatsuba algorithm and the fast modular exponentiation algorithm into the process of combining homomorphic encryption and federated learning, and forms a series cooperation mechanism of "first fast modular exponentiation, then Karatsuba multiplication" in the encryption and decryption stages of Paillier homomorphic encryption respectively. Through algorithm-level optimization, the present invention achieves a significant effect of a 3-fold increase in encryption efficiency and a 70% reduction in communication cost on the premise of ensuring model accuracy, providing an efficient solution for the practical application of privacy-enhanced federated learning in resource-constrained scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 is the overall flowchart of a federated learning method using algorithm acceleration combined with homomorphic encryption according to the present invention;
[0045] Figure 2 is the flowchart of the encryption algorithm optimization of a federated learning method using algorithm acceleration combined with homomorphic encryption according to the present invention;
[0046] Figure 3 is the flowchart of the decryption algorithm optimization of a federated learning method using algorithm acceleration combined with homomorphic encryption according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0047] The following further describes the present invention with reference to the drawings.
[0048] The present invention discloses a federated learning method that combines algorithm acceleration with homomorphic encryption. The Karatsuba algorithm and the fast modular exponentiation algorithm are incorporated into the process of combining homomorphic encryption and federated learning, forming a tandem cooperation mechanism of "first fast modular exponentiation, then Karatsuba multiplication" in the encryption and decryption phases of Paillier homomorphic encryption.
[0049] I. Optimization of the Encryption Process
[0050] Fast Calculation of Key Parameters:
[0051] In the Paillier encryption process, two core parameters (power operations involving exponents and moduli) need to be calculated. The fast modular exponentiation algorithm is used to optimize this process: by converting the exponent into binary form, decomposing the power operation steps bit by bit, and taking the modulus of the intermediate result immediately at each step, this step can significantly reduce the computational amount and avoid the overflow problem of large number operations, thus quickly completing the modular exponentiation operation.
[0052] Reorganization of Efficient Multiplication Operations:
[0053] After completing the above parameter calculations, it is also necessary to perform a multiplication operation on the modular exponentiation results of two large integers. However, the traditional method of multiplying bit by bit is inefficient, so the Karatsuba divide-and-conquer algorithm is introduced: the large integer is split into a high-order part and a low-order part, and then the single large number multiplication is converted into three smaller-scale multiplication operations through recursion. Finally, only the intermediate results need to be reorganized to obtain the final product. This strategy significantly reduces the time complexity of the multiplication operation and further accelerates the encryption process.
[0054] II. Optimization of the Decryption Process
[0055] Fast Generation of Private Key Parameters:
[0056] When the client decrypts, it needs to generate the core parameters of the private key, which involves complex power operations on large prime numbers. The fast modular exponentiation algorithm is used to decompose the high-order power operation into binary bit operations, and the private key parameters are quickly generated through loop multiplication and modulo steps.
[0057] The core idea of the fast modular exponentiation algorithm is to use the binary expansion of the power, split the exponent into the sum of several binary bits, calculate the power result through square and multiplication operations, and perform modulo operations at each step to prevent numerical overflow. Its time complexity is O(log2N), where N is the value of the exponent. For calculating a b mod t (where a is the base, b is the exponent, and t is the modulus), the specific algorithm process is as follows:
[0058] (i) First, set the result a i to 1.
[0059] (ii) Convert the exponent b into binary form. Examine the binary digits from right to left. Use the variable i to represent the index of the currently examined binary digit, starting from 1.
[0060] (iii) When examining a certain bit b i First, calculate the result of taking the modulus of the square of b with respect to t
[0061] b 2 mod t = (b × b) mod t (1)
[0062] b i is the value (0 or 1) of the current binary digit;
[0063] If the current bit b i is 1, then multiply the current result a i by b 2 mod t and update the result by taking the modulus with respect to t, that is
[0064] a i+1 = (a i × b 2 mod t) mod t (2)
[0065] If b i is 0, then the result a i remains unchanged.
[0066] (iiii) After completing the processing of the current bit, prepare to process the next bit. At this time, i is incremented by 1, and repeat the above steps until i reaches the index N of the highest bit in the binary representation of b. The finally obtained result a N is the value of a b mod t.
[0067] Ciphertext decryption acceleration:
[0068] In the final step of converting ciphertext to plaintext, perform large integer exponentiation and multiplication operations. First, use the fast exponentiation modulo algorithm to optimize the exponentiation operation and reduce the time consumption of exponent calculation; then use the Karatsuba algorithm to split the large integer multiplication, and reduce the number of multiplications through the divide-and-conquer strategy. Through these two operations, the decryption operation can be efficiently completed.
[0069] Example 1
[0070] A federated learning method that combines algorithm acceleration with homomorphic encryption, as Figure 1 shown, includes:
[0071] I. Global model initialization: First, initialize the global model for each client to ensure that all clients start training from the same point.
[0072] II. Training Client: Receive the global model parameters transmitted from the initialization parameters or the aggregation server, then use the local dataset for training, update the model parameters through backpropagation, and finally send the updated local model parameters to the secure client module for encryption.
[0073] III. Secure Client Module:
[0074] Encryption Process
[0075] (1) Calculate the key values: Since in the process of encrypting the plaintext m using Paillier encryption, two intermediate process values need to be calculated, namely g m mod n 2 and r n mod n 2 , where n is the product of two large prime numbers p and q, and these two large prime numbers need to satisfy gcd(pq, (p - 1)(q - 1)) = 1, where gcd represents the greatest common divisor. Additionally, for simplicity of calculation, g is usually set to n + 1. r is a random number used to increase randomness during the encryption process to ensure that the same plaintext will generate different ciphertexts when encrypted at different times, and m is the plaintext to be encrypted.
[0076] Since the numbers involved in the calculation may be very large, during the calculation process, the fast exponentiation modulo algorithm is used to quickly calculate these two values.
[0077] Taking the calculation of g m mod n 2 as an example (at this time a = g, b = m, t = n 2 ), assume that a certain bit m i (with a value of 0 or 1) in the binary form of m is being processed. First, determine whether the current bit is 1; if it is 1, square g and multiply it by the accumulated result, and then take the modulo of n 2 . This step is equivalent to including the current power part in the final result. If it is 0, the current result is equal to the accumulated result; then, update the current g m mod n 2 value according to the judgment result. After completing the processing of the current bit, prepare to process the next bit. At this time, i is incremented by 1, and the above steps are repeated until i reaches the index of the highest bit in the binary representation of m. The final result obtained is the value of g m mod n 2 .
[0078] (2) Encrypt the plaintext: After completing the above key value calculation, enter the process of encrypting the plaintext, and it is necessary to calculate
[0079] c = (g m mod n 2 ) × (r nmod n 2 ) mod n 2 (3)
[0080] Among them, c is the ciphertext after calculation, which is the product of two large integers in the fast calculation formula (3). The Karatsuba algorithm is used to decompose the large integer multiplication into multiplications of smaller integers.
[0081] In (3), the two large integers to be calculated are x = g m mod n 2 and y = r n mod n 2 , assuming that the two n-bit large integers x and y are respectively split into two parts: Let x = a × 10 e + b, y = k × 10 e + d, where a is the high-order coefficient after splitting x; b is the low-order value of the other bits except the high-order after splitting x; k is the high-order coefficient after splitting y; d is the low-order value of the other bits except the high-order after splitting y; e is the exponent parameter for splitting, which depends on the number of bits of x and y, generally half of the number of bits.
[0082] Calculating the product of x and y according to the traditional method, the calculation process is:
[0083] x × y = (a × 10 e + b) × (k × 10 e + d) = ak × 10 2e + (ad + bk) × 10 e + bd (4)
[0084] This process requires calculating the four products ak, ad, bk, and bd.
[0085] The Karatsuba algorithm reduces the number of multiplications by introducing an intermediate term:
[0086] z = (a + b) × (k + d) - ak - bd (5)
[0087] The calculation process becomes:
[0088] x × y = ak × 10 2e + z × 10 e + bd (6)
[0089] Only the three products ak, bd, and z need to be calculated, thus significantly reducing the time complexity of large integer multiplication.
[0090] IV. Security Management Server: After receiving the encrypted local model parameters transmitted by the security client, it is necessary to verify the client's identity first to ensure its legitimacy, and then forward the filtered encrypted local model parameters to the aggregation server.
[0091] V. Aggregation Server: After receiving the legitimate encrypted local model parameters transmitted by the security management server, use the addition and scalar multiplication properties of the Paillier homomorphic encryption algorithm to aggregate the model parameters, generate the recalculated encrypted global model parameters, and distribute the updated encrypted global model parameters to all clients.
[0092] VI. Training Client: Receive the encrypted global model parameters, decrypt them using the optimized decryption algorithm, and perform the next round of training on the decrypted global model;
[0093] Decryption Process
[0094] (1) Calculate the key part of the private key: After the client receives the encrypted global model, the first step in the decryption process is to calculate a key component of the private key, namely μ. The calculation formula is:
[0095] μ = L(g λ mod n 2 ) -1 mod n (7)
[0096] Among them, the function λ = lcm(p - 1, q - 1), where p and q are the two large prime numbers mentioned above, and lcm represents the least common multiple.
[0097] When calculating g λ mod n 2 , use the fast exponentiation modulo algorithm to accelerate this process. The calculation method is the same as the fast exponentiation modulo algorithm used when calculating the key value in the encryption process.
[0098] (2) Obtain the plaintext: To obtain the plaintext m′, it is necessary to perform the calculation
[0099] m′ = L(c λ mod n 2 ) × μ mod n (8)
[0100] Similarly, when calculating c λ mod n 2 in the formula (6), use the fast exponentiation modulo algorithm to optimize this step, and the calculation method is the same as that of the above calculation of g λ mod n 2 .
[0101] After obtaining L(g λ mod n 2After the result of ( ) is obtained, it needs to be multiplied by μ. To accelerate this multiplication operation, the Karatsuba algorithm is adopted. According to the Karatsuba algorithm, x and y are split into two parts (let x = a × 10 e + b, y = k × 10 e + d), and by calculating the intermediate term z, the product of x and y is finally calculated, and then the result is taken modulo n to obtain the final plaintext m'.
[0102] Example 2
[0103] Experimental results based on the MNIST dataset with 10 global iterations:
[0104] Model accuracy guarantee: After introducing the optimization algorithm, the accuracy of the model reaches more than 90% after the 5th global aggregation. The accuracy trend is basically the same as that of the non-optimized scheme, and the maximum deviation is less than 1%, proving that the algorithm optimization has no significant impact on the model accuracy.
[0105] Improvement in computing efficiency: The encryption time is reduced from 892 ± 37 seconds in the original scheme without algorithm optimization to 272 ± 46 seconds (a decrease of 69.5%), and the decryption time is reduced from more than 900 seconds in the original scheme to 511.05 ± 18.51 seconds (a decrease of 43.2%).
[0106] Reduction in communication cost: The waiting time before the client uploads the model parameters to the server is reduced from more than 900 seconds in the original scheme to 263.66 ± 38.08 seconds (a decrease of 70.7%), and the network occupancy time is significantly shortened.
[0107] In summary, in the encryption optimization stage, for the core modular exponentiation operation in Paillier encryption, the fast exponentiation modulo algorithm is used to optimize the time complexity from O(n) to O(log n); then the Karatsuba algorithm is used to decompose the large integer multiplication into small bit-width operations, reducing the multiplication complexity from O(n2) to O(n1.585). In the decryption optimization stage, the fast exponentiation modulo is used to accelerate the power modulo calculation, and the Karatsuba algorithm is combined to optimize the modular multiplication operation, significantly reducing the time-consuming of the private key operation.
[0108] In particular, in some preferred embodiments of the present invention, a computer device is further provided, including a memory, a processor, and a computer program stored on the memory. When the processor executes the computer program, the steps of the federated learning method using algorithm acceleration combined with homomorphic encryption in any of the above embodiments are implemented.
[0109] In some other preferred embodiments of the present invention, a computer-readable storage medium is further provided, on which a computer program / instructions are stored. When the computer program is executed by a processor, the steps of the federated learning method using algorithm acceleration combined with homomorphic encryption described in any of the above embodiments are implemented.
[0110] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it may include the processes of the embodiments of the federated learning method using algorithm acceleration combined with homomorphic encryption as described above, which will not be repeated here.
[0111] In the description of this specification, the descriptions referring to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or N embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0112] In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of the features. In the description of the present invention, the meaning of "N" is at least two, such as two, three, etc., unless otherwise clearly and specifically defined.
[0113] Any process or method description shown in the flowchart or described in other ways herein can be understood as representing a module, segment, or part of code including one or more executable instructions for implementing a customized logic function or process. The scope of the preferred embodiments of the present invention includes additional implementations, where the functions can be executed in a substantially simultaneous manner or in the reverse order according to the involved functions, rather than in the order shown or discussed, which should be understood by those skilled in the art to which the embodiments of the present invention belong.
[0114] The logic and / or steps represented in the flowchart or otherwise described herein can, for example, be considered a definitional sequence list of executable instructions for implementing logical functions, and can be embodied specifically in any computer-readable medium for use by or in connection with an instruction execution system, apparatus, or device, such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of the computer-readable medium include the following: an electrical connection (electronic device) having one or N wirings, a portable computer diskette (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, the computer-readable medium can even be paper or other suitable medium on which the program can be printed, as the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpretation, or otherwise processing as appropriate, and then storing it in a computer memory.
[0115] It should be understood that various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above-described embodiments, the N steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.
[0116] Those of ordinary skill in the art of this technology can understand that all or part of the steps carried by the method of the above embodiments can be completed by instructing relevant hardware through a program, and the program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiments.
[0117] In addition, each functional unit in various embodiments of the present invention may be integrated into one processing module, may exist separately as individual physical units, or two or more units may be integrated into one module. The above-mentioned integrated module may be implemented in the form of hardware or in the form of a software functional module. When the integrated module is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium.
[0118] The above-mentioned storage medium may be a read-only memory, a magnetic disk, an optical disc, etc. Although the embodiments of the present invention have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.
Claims
1. A federated learning method that utilizes algorithm acceleration combined with homomorphic encryption, characterized in that: Including: Step 1: The client initializes the global model; Step 2: The client updates the initialized global model parameters through backpropagation using the local training set to obtain the updated local model parameters; Step 3: The local model parameters uploaded by the client are homomorphically encrypted using algorithm optimization to update the local model parameters and obtain the encrypted local model parameters; the algorithm optimization is to accelerate the power modulo calculation through fast exponentiation modulo and optimize the modular multiplication operation in combination with the Karatsuba algorithm; Step 4: After receiving the encrypted local model parameters sent by the client, the security server verifies whether the client's identity is legal and forwards the filtered legal encrypted local model parameters to the aggregation server; Step 5: After receiving the legal encrypted local model parameters sent by the security management server, the aggregation server aggregates the model parameters using the addition and scalar multiplication characteristics of the Paillier homomorphic encryption algorithm to generate the recalculated encrypted global model parameters, and distributes the updated encrypted global model parameters to all clients; Step 6: After each client receives the updated encrypted global model parameters, it performs a decryption operation using algorithm optimization based on the private key; Step 7: The decrypted global model parameters are re-trained using the local training set in the next round, and steps 2 to 7 are repeated until the set number of iterations is reached, and the training process is completed.
2. The federated learning method using algorithm acceleration combined with homomorphic encryption according to claim 1, wherein: In step 3, first use the fast exponentiation modulo algorithm to quickly calculate the key value g m mod n 2 and r n mod n 2 ; The fast exponentiation modulo algorithm is to use the binary expansion of the power, split the exponent into the sum of several binary bits, calculate the power result through square and multiplication operations; then use the fast exponentiation modulo algorithm to optimize the calculation in the process of encrypting the plaintext.
3. The federated learning method using algorithm acceleration combined with homomorphic encryption according to claim 2, wherein: The calculated key value g m mod n 2 , where g is n + 1, m is the plaintext, n is the product of two large prime numbers, and the two large prime numbers need to satisfy gcd(pq, (p - 1)(q - 1)) = 1. gcd is the greatest common divisor, specifically: Step 3.1.1: Convert the exponent m into binary form, examine the binary digits from right to left in turn, and construct the set [m1,..., m N , m i represents the value of the i-th bit from the right to the left in the binary form of the exponent m; initialize i = 1, a1 = 1; Step 3.1.2: If m i = 1, then a i+1 = (a i × (g 2 mod n 2 )) mod n 2 ; If m i = 0, then a i+1 = a i ; Step 3.1.3: If i < N, then set i = i + 1 and return to Step 3.1.2; otherwise, output a i , that is, g m mod n 2 = a N .
4. The federated learning method using algorithm acceleration combined with homomorphic encryption according to claim 2, wherein: The calculation of the key value r n mod n 2 is the same as that of the key value g m mod n 2 and is calculated using the fast exponentiation modulo algorithm.
5. The federated learning method using algorithm acceleration combined with homomorphic encryption according to claim 2, wherein: The encryption plaintext process is as follows: c = ((g m mod n 2 ) × (r n mod n 2 )) mod n 2 The Karatsuba algorithm decomposes the multiplication of large integers into the multiplication of smaller integers, specifically: Step 3.2.1: Let x = g m mod n 2 , y = r n mod n 2 , and split the two large integers x and y into two parts respectively; x = a × 10 e + b y = k×10 e + d Where a is the high-order coefficient after splitting x; b is the low-order value after splitting x; k is the high-order coefficient after splitting y; d is the low-order value after splitting y; e is the exponent parameter for splitting. Step 3.2.2: Introduce an intermediate term z to reduce the number of multiplications, and the calculation process is as follows: x × y = ak × 10 2e + z × 10 e + bd z = (a + b) × (k + d) - ak - bd.
6. The federated learning method using algorithm acceleration combined with homomorphic encryption according to claim 1, characterized in that: In step 4, the decryption process uses the decryption optimization algorithm module to perform the decryption operation; the decryption optimization algorithm module includes the Karatsuba algorithm and the fast exponentiation modulo algorithm; the specific operation process includes: Step 4.1: Calculate the key component μ of the private key; μ = L(g λ mod n 2 ) -1 mod n Among them, the function g λ modn 2 has the same calculation steps as the key value g m mod n 2 and is calculated using the fast exponentiation modulo algorithm, where λ = lcm(p - 1, q - 1), and lcm is the least common multiple; Step 4.2: Calculate the plaintext m'; m′ = L(c λ mod n 2 )×μ mod n Among them, c λ mod n 2 has the same calculation steps as the key value g m mod n 2 , and is calculated using the fast exponentiation modulo algorithm; The multiplication of L(c λ modn 2 ) and μ is calculated using the Karatsuba algorithm.
7. A computer device / apparatus / system, comprising a memory, a processor, and a computer program stored on the memory, characterized in that: The processor executes the computer program to implement the steps of the method according to any one of claims 1 to 6.
8. A computer-readable storage medium having computer programs / instructions stored thereon, characterized in that: When the computer program / instructions are executed by the processor, the steps of the method according to any one of claims 1 to 6 are implemented.
9. A computer program product, comprising a computer program / instructions, characterized in that: When the computer program / instructions are executed by the processor, the steps of the method according to any one of claims 1 to 6 are implemented.