Privacy computing protocol compounding method based on parameter security conversion
By performing dense state conversion of parameters after model training on the client and performing dense state aggregation on the MPC server, the problem of poor integration of MPC module and federated learning framework is solved, efficient and secure model parameter conversion and aggregation is achieved, and the flexibility and robustness of the system are improved.
Patent Information
- Application Number
- CN202510446240.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-07-04
AI Technical Summary
In the existing privacy computing technology, the MPC module has poor integration with the federated learning framework, strong coupling of protocol interfaces, and it is difficult to adapt to the parameter structure or format requirements under different tasks. There are fewer types of secure aggregation methods, making it difficult to dynamically select appropriate aggregation strategies, resulting in system performance degradation and complex engineering implementation.
A comprehensive method of privacy computing protocol based on parameter security conversion is designed. By performing dense state conversion of parameters after model training on the client, multi-party aggregation operations are performed in a dense state space using the MPC encryption module and communication interface, and dynamic switching of multiple aggregation strategies is supported. Combined with an efficient communication bridge between the PyTorch module and the MPC computing framework, safe conversion and aggregation of model parameters are realized.
It realizes seamless integration of MPC modules and federated learning, improves the flexibility and security of the system, reduces development costs and deployment complexity, enhances defense capabilities against attacks, and improves the robustness and controllability of the system.
Smart Images

Figure CN120263490A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of privacy computing, and in particular to a privacy computing protocol composite method based on parameter security conversion. Background Art
[0002] With the rapid development of technologies such as artificial intelligence and big data, the value of data has become increasingly prominent in all walks of life. Due to concerns about user privacy, business-sensitive information, or regulatory restrictions, it is difficult to directly share data. To address the practical problem of data being unable to leave the domain, privacy computing technology has emerged. As a typical representative of privacy computing, federated learning avoids the privacy risks associated with centralized storage of raw data. However, there are still significant security risks in the processing of its model parameters during training. To solve the above problems, existing research has begun to attempt to introduce multi-party secure computing into the federated learning process. MPC is a cryptographic method that enables multiple computing parties to perform joint computations without revealing their respective inputs.
[0003] Although existing technologies have attempted to use MPC for privacy protection in federated learning, there are still the following main deficiencies: Most existing solutions only stay at using MPC as an external tool and do not construct a parameter conversion module that is tightly integrated with the federated learning framework. This results in strong coupling and poor flexibility at the protocol interface, making it difficult to adapt to the parameter structure or format requirements under different tasks. Moreover, the current types of secure aggregation methods are few, and it is difficult to dynamically select the most suitable aggregation strategy according to attack types (such as label flipping, model poisoning, etc.). The MPC calculation itself has a certain communication cost, and directly introducing it into an unoptimized structure will lead to a decline in the overall system performance, complex docking of the training framework, and difficulties in engineering implementation. There is still room for further improvement in existing technologies. Summary of the Invention
[0004] In view of the deficiencies of the prior art, the present invention provides a privacy computing protocol composite method based on parameter security conversion, which has the advantages of realizing deep integration of protocols, enhancing security and robustness, etc.
[0005] To achieve the above object, the present invention provides the following technical solution: A privacy computing protocol composite method based on parameter security conversion, including a client for data conversion, several MPC servers, and a communication interface. S100, each client respectively performs model training on the local private dataset to generate local model update parameters, and the parameters are retained locally. S200, parameter encryption and conversion stage: The client calls the MPC encryption module to securely encrypt the local model parameters, and performs encrypted state conversion on the parameters using the secret sharing and homomorphic encryption mechanisms to generate ciphertext parameter representations. S300, Encryption Parameter Transmission Phase: The client transmits the encrypted state parameters to the MPC server through the communication interface, and the data transmission is protected by an encrypted channel; S400, Secure Aggregation Phase: The MPC server receives the encrypted state parameters from each client and performs a multi-party aggregation operation in the encrypted state space. The aggregation method can be flexibly configured; S500, Aggregation Result Decryption and Synchronization Phase: Multiple MPC server participating nodes perform a joint decryption operation according to the protocol, generate the plaintext aggregation result of the global model, and synchronously return it to each client for the next round of training iteration.
[0006] Preferably, S100, Local Model Training Phase: Each client separately performs model training on its local private dataset to generate local model update parameters. The parameters are usually retained locally as weight vectors or gradient tensors in plaintext form. The client internally sets up a PyTorch module and is responsible for performing local model training on behalf of the client based on the PyTorch module. Using the publicly available FLTrust code as a starting point, the MPC server itself collects a small clean training dataset on its local private dataset. This small clean training data is called the root dataset, and it maintains a model for it. This model is called the global model, just as the client maintains a local model. In each iteration, the model training module follows the general three steps in federated learning: The first step: Synchronize the global model with the client. The MPC server sends the current global model W to the client or a subset in the root dataset; The second step: Train the local model. Each client trains the local model by fine-tuning the global model W using the root dataset; The third step: Update the global model by aggregating local model updates. The server calculates the global model update G by aggregating local model updates according to a certain aggregation method. Then, the server uses the global model update to update the global model, that is, W = W + α·G, where α is the global learning rate, thus completing the training of the local model.
[0007] Preferably, in S200, the parameter encryption and conversion stage: The client invokes the MPC encryption module to securely encrypt the local model parameters. The MPC encryption module is deployed inside the client of federated learning. Its core function is to convert the model parameters into a ciphertext representation after local training. This module encrypts or secretly shares the parameters based on the multi-party secure computation protocol, so that the original parameters are encrypted and encapsulated before leaving the local device, thus preventing interception or leakage during transmission. By invoking the interface function in the MPC computing framework, this module converts the tensor-type model parameters into ciphertext shares and outputs them to the communication interface module for further processing. The parameter security conversion supports floating-point or fixed-point number types and can adapt to the parameter structures of various deep learning tasks.
[0008] Preferably, in S300, the encrypted parameter transmission stage: The client transmits the ciphertext parameters to the MPC server through the communication interface. The data transmission is protected by an encrypted channel. The communication interface is responsible for implementing the data interaction between the PyTorch module and the computing framework of the MPC server. The communication interface provides a unified API interface externally to achieve the sending, receiving, and conversion control of model parameters. Its underlying layer uses an encrypted communication protocol to ensure the integrity and confidentiality of data during transmission. The communication interface supports the structured transmission of batch data, automatic alignment of parameter dimensions, and an automatic recovery mechanism for abnormal transmission, and can adapt to the parameter differences in different batches and rounds of federated training. The communication interface is tightly coupled with the parameter security conversion module, reducing the invasiveness to the existing system structure while ensuring the transmission efficiency, and facilitating subsequent engineering integration and platform deployment.
[0009] Preferably, in S400, the secure aggregation stage: The MPC server receives the ciphertext parameters from each client and performs a multi-party aggregation operation in the ciphertext space. The aggregation method can be flexibly configured. The secure aggregation module is the core module deployed inside the MPC server, and its task is to perform encrypted aggregation on the ciphertext model parameters from the client. This module supports multiple aggregation strategies, including FedAvg and FLTrust, and can be dynamically switched according to the security situation in the current client training environment. All aggregation processes are completed in the ciphertext state, effectively preventing the intermediate nodes inside the client from snooping on the original parameters. The secure aggregation module internally integrates an anomaly detection and screening mechanism. This module outputs the aggregated ciphertext parameter results and hands them over to the decryption module for the next step of processing.
[0010] Preferably, in S500, the aggregation result decryption and synchronization phase: multiple MPC server participating nodes perform joint decryption operations according to the protocol, generate the plaintext aggregation result of the global model, and synchronously return it to each client for the next round of training iteration. An internal decryption and synchronization module is set up in the MPC server, whose function is to jointly decrypt the encrypted aggregated parameter result and synchronize the decrypted global model parameters back to each participant. The decryption and synchronization module adopts a threshold decryption scheme to ensure that the decryption process can be completed only when the nodes of a certain number of MPC servers perform joint operations, thereby enhancing the fault tolerance and security level of the system. The synchronization part is responsible for version control, structure alignment, and compression processing of the aggregated global model to adapt to the computing resource conditions of different clients. The decryption and synchronization module also integrates a secure synchronization mechanism to prevent tampering or forgery during the backhaul of the global model and ensure the legality and consistency of parameter updates.
[0011] Preferably, the client uses a standard Linux server, and the recommended configuration is a multi-core CPU + 128G of memory, supporting containerized operation.
[0012] Beneficial effects 1. The privacy computing protocol composite method based on parameter security conversion constructs a unified parameter security conversion mechanism through this application, enabling the MPC encryption module to be seamlessly integrated into the federated learning process as a module, realizing the encryption conversion and secure aggregation of model parameters. This mechanism supports floating-point fixed-point encoding, tensor slicing processing, and format standardization, effectively solving the problem of data incompatibility between the existing MPC encryption module and the training framework. Through a unified parameter input-output interface, the MPC encryption module is no longer called as an external tool but becomes an endogenous module of federated learning, enhancing the integrity of protocol integration and the flexibility of system integration from the bottom layer.
[0013] 2. The privacy computing protocol composite method based on parameter security conversion constructs an efficient communication bridge between the PyTorch module and the MPC computing framework through this application, supporting the automatic mapping and conversion of model parameters between the training end and the secure computing end. This mechanism has good encapsulation and strong adaptability, and can be directly integrated into the existing training process without significant modification of the original model structure, thereby reducing the development cost and deployment complexity, improving the reusability and cross-platform migration ability of the technical solution, and having a good engineering promotion foundation.
[0014] 3. The privacy computing protocol composite method based on parameter security conversion supports the dynamic loading and scheduling of multiple secure aggregation algorithms through the secure aggregation module designed in this application, and allows for flexible switching of strategies according to different attack types, training scenarios, or participant trust levels. This module also incorporates a model distance analysis and abnormal parameter filtering mechanism to enhance the system's detection and defense capabilities against attacks such as model poisoning and label flipping. Compared with a single-strategy system, the present invention achieves stronger security robustness and controllability while ensuring model performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 is a schematic diagram of the operation process of a privacy computing protocol composite method based on parameter security conversion according to the present invention; Figure 2 is a schematic diagram of the system architecture of a privacy computing protocol composite method based on parameter security conversion according to the present invention; Figure 3 is a schematic diagram of the model training module of a privacy computing protocol composite method based on parameter security conversion according to the present invention; Figure 4 is a schematic diagram of the secure aggregation module of a privacy computing protocol composite method based on parameter security conversion according to the present invention; Figure 5 is a schematic diagram of the training process of the model training module of a privacy computing protocol composite method based on parameter security conversion according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0016] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0017] Embodiment 1 Please refer to Figures 1 to 5 , a privacy computing protocol composite method based on parameter security conversion, including a client for data conversion, several MPC servers, and a communication interface. S100, each client respectively performs model training on the local private dataset to generate local model update parameters, and the parameters are retained locally; S200, parameter encryption conversion stage: The client calls the MPC encryption module to securely encrypt the local model parameters, and performs encrypted state conversion on the parameters using the secret sharing and homomorphic encryption mechanisms to generate ciphertext parameter representations; S300, encrypted parameter transmission stage: The client transmits the encrypted state parameters to the MPC server through the communication interface, and the data transmission is protected using an encrypted channel; S400, Secure Aggregation Phase: The MPC server side receives the encrypted state parameters from each client and performs a multi-party aggregation operation in the encrypted state space. The aggregation method can be flexibly configured; S500, Aggregation Result Decryption and Synchronization Phase: Multiple MPC server participating nodes perform a joint decryption operation according to the protocol, generate the plaintext aggregation result of the global model, and synchronously return it to each client for the next round of training iteration.
[0018] Embodiment Two Please refer to Figures 1 to 5 , based on Embodiment One, further, S100, Local Model Training Phase: Each client performs model training on its local private dataset to generate local model update parameters. The parameters are usually retained locally as weight vectors or gradient tensors in plaintext form. The client internally sets up a module of PyTorch and is responsible for performing local model training on behalf of the client based on the PyTorch module. Starting from the publicly available FLTrust code, the MPC server itself collects a small clean training dataset on its local private dataset. This small clean training data is called the root dataset, and it maintains a model for it. This model is called the global model, just like the client maintains a local model. In each iteration, the model training module follows the general three steps in federated learning: The first step: Synchronize the global model with the client. The MPC server sends the current global model W to the client or a subset in the root dataset; The second step: Train the local model. Each client trains the local model by fine-tuning the global model W using the root dataset; The third step: Update the global model by aggregating local model updates. The server calculates the global model update G by aggregating local model updates according to a certain aggregation method. Then, the server uses the global model update to update the global model, that is, W = W + α·G, where α is the global learning rate, thus completing the training of the local model.
[0019] Embodiment Three Please refer to Figures 1 to 5, On the basis of Embodiment 2, further, in S200, the parameter encryption and conversion stage: The client invokes the MPC encryption module to securely encrypt the local model parameters. The MPC encryption module is deployed inside the client of federated learning. Its core function is to convert the model parameters into a ciphertext representation after local training. This module encrypts or secretly shares the parameters based on the multi-party secure computing protocol, so that the original parameters are encrypted and encapsulated before leaving the local device, thereby preventing interception or leakage during transmission. By invoking the interface function in the MPC computing framework, this module converts the tensor-type model parameters into ciphertext shares and outputs them to the communication interface module for further processing. Parameter security conversion supports floating-point or fixed-point number types and can adapt to the parameter structures of various deep learning tasks.
[0020] S300, the encrypted parameter transmission stage: The client transmits the ciphertext parameters to the MPC server through the communication interface. The data transmission is protected by an encrypted channel. The communication interface is responsible for implementing the data interaction between the PyTorch module and the computing framework of the MPC server. The communication interface provides a unified API interface externally to implement the sending, receiving, and conversion control of model parameters. Its underlying layer uses an encrypted communication protocol to ensure the integrity and confidentiality of data during transmission. The communication interface supports structured transmission of batch data, automatic alignment of parameter dimensions, and an automatic recovery mechanism for abnormal transmission, and can adapt to the parameter differences in different batches and rounds of federated training. The communication interface is tightly coupled with the parameter security conversion module, reducing the intrusion into the existing system structure while ensuring the transmission efficiency, and facilitating subsequent engineering integration and platform deployment.
[0021] S400, the secure aggregation stage: The MPC server receives the ciphertext parameters from each client and performs a multi-party aggregation operation in the ciphertext space. The aggregation method can be flexibly configured. The secure aggregation module is the core module deployed inside the MPC server, and its task is to perform encrypted aggregation on the ciphertext model parameters from the client. This module supports multiple aggregation strategies, including FedAvg and FLTrust, and can be dynamically switched according to the security situation in the current client training environment. All aggregation processes are completed in the ciphertext state, effectively preventing intermediate nodes inside the client from snooping on the original parameters. The secure aggregation module internally integrates an anomaly detection and screening mechanism. This module outputs the aggregated ciphertext parameter results and hands them over to the decryption module for the next step of processing.
[0022] S500, Aggregation Result Decryption and Synchronization Phase: Multiple MPC server participating nodes perform joint decryption operations according to the protocol to generate the plaintext aggregation result of the global model, and synchronously return it to each client for the next round of training iteration. An internal decryption and synchronization module is set up in the MPC server, whose function is to jointly decrypt the encrypted aggregated parameter result and synchronize the decrypted global model parameters back to each participant. The decryption and synchronization module adopts a threshold decryption scheme to ensure that the decryption process can only be completed when the nodes of a certain number of MPC servers perform joint operations, thereby enhancing the fault tolerance and security level of the system. The synchronization part is responsible for version control, structure alignment, and compression processing of the aggregated global model to adapt to the computing resource conditions of different clients. The decryption and synchronization module also integrates a secure synchronization mechanism to prevent tampering or forgery during the backhaul of the global model and ensure the legality and consistency of parameter updates.
[0023] The client uses a standard Linux server, and the recommended configuration is a multi-core CPU + 128G of memory, supporting containerized operation.
[0024] Working Principle: S100, Local Model Training Phase: Each client separately performs model training on its local private dataset to generate local model update parameters. The parameters are retained locally, usually as weight vectors or gradient tensors, in plaintext form. An internal PyTorch module is set up in the client, and the module based on PyTorch is responsible for performing local model training on behalf of the client. Using the publicly available FLTrust code as a starting point, the MPC server itself collects a small clean training dataset on the local private dataset. This small clean training data is called the root dataset, and it maintains a model for it, which is called the global model. Just like the client maintains a local model, in each iteration, the model training module follows the general three steps in federated learning: The first step: Synchronize the global model with the client. The MPC server sends the current global model W to the client or a subset in the root dataset. The second step: Train the local model. Each client trains the local model by fine-tuning the global model W using the root dataset. The third step: Update the global model by aggregating local model updates. The server calculates the global model update G by aggregating local model updates according to a certain aggregation method. Then, the server uses the global model update to update the global model, that is, W = W + α·G, where α is the global learning rate, thus completing the training of the local model. In the second step, in existing federated learning methods, each client trains its local model, while the MPC server also trains its global model by fine-tuning the current global model using the root dataset. In the third step, existing federated learning methods only consider the local model updates of the clients to update the global model. In contrast, this module considers both the MPC global model updates and the local model updates of the clients to update the global model; The MPC server itself does not fully rely on the local model updates of the clients, but rather guides the trust in the FLTrust code. Specifically, the service provider manually collects a small clean training dataset for the learning task, also known as the root dataset. The server maintains the model of the root dataset, also known as the global model, just as the clients maintain their local models. In each iteration, the MPC server updates the global model by considering both its MPC global model updates and the local model updates of the clients; Assume that the service provider can collect a representative root dataset for the learning task, that is, the root dataset has the same distribution as the overall training data distribution of the learning task. In this way, the root dataset can be randomly and uniformly sampled from the union of the clean local training data of the clients. For example, for MNIST-0.5, the root dataset can be randomly and uniformly sampled from its 60,000 training samples; Assume that the distribution of the root dataset is different from the overall training data distribution of the learning task. In this case, it can be assumed that the root dataset is biased towards a certain class. Specifically, from the combination of the clean local training data of the clients, a part of the examples in the root dataset are drawn from a specific class, and the remaining examples are randomly and uniformly sampled from the remaining classes. This can be called the fractional bias probability. Note that for all datasets except HAR and CH-MNIST, the distribution of the root dataset is the same as the overall training data, that is, when the bias probability is 0.1, it can be regarded as the situation in the previous paragraph because they have 10 classes. For HAR and CH-MNIST, when the bias probability is 0.17 and 0.125 respectively, it can also be regarded as the situation in the previous paragraph because they have 6 and 8 classes respectively. When the bias probability is large, the deviation between the root data distribution and the overall training data distribution is greater; In this way, the attacker can manipulate the direction of the local model updates on malicious clients, making the direction of the global model updates opposite to the update direction. Therefore, this paper considers both the direction and magnitude of the model updates. Specifically, first, a trust score is assigned to it according to the similarity of the local model updates and the MPC global model updates. Formally, the trust score of the local model updates in this paper is based on its comparison with the MPC global model updates; ReLU clipped cosine similarity. An attacker can manipulate the direction of local model updates on malicious clients so as to drive the global model update in any direction required by the attacker. Without a trust root, it is very difficult for the MPC server to decide which direction is more "promising" for updating the global model. During the training process, the root trust comes from the direction of the MPC global model update. If the direction of the local model update is more similar to the direction of the MPC global model update, then the direction of the local model update may be more "promising". Normalization ensures that a single local model update will not have too much impact on the aggregated global model update, and also amplifies local model updates with a smaller magnitude to make them have the same magnitude as the MPC global model update; S200, Parameter encryption conversion stage: The client calls the MPC encryption module to securely encrypt the local model parameters. The MPC encryption module is deployed inside the client of federated learning. Its core function is to convert the model parameters into a ciphertext representation after local training. This module encrypts or secretly shares the parameters based on the multi-party secure computation protocol, so that the original parameters are encrypted and encapsulated before leaving the local, thus preventing interception or leakage during transmission. This module converts the tensor-type model parameters into ciphertext shares by calling the interface function in the MPC computing framework and outputs them to the communication interface module for further processing. Parameter security conversion supports floating-point or fixed-point types and can adapt to the parameter structures of various deep learning tasks; This application constructs a unified parameter security conversion mechanism, enabling the MPC encryption module to be seamlessly integrated into the federated learning process as a module, realizing the encryption conversion and secure aggregation of model parameters. This mechanism supports floating-point and fixed-point encoding, tensor slicing processing, and format standardization, effectively solving the problem of data incompatibility between the existing MPC encryption module and the training framework. Through a unified parameter input and output interface, the MPC encryption module is no longer called as an external tool but becomes an endogenous module of federated learning, enhancing the integrity of protocol integration and the flexibility of system integration from the bottom layer; S300, Encrypted parameter transmission stage: The client transmits the ciphertext parameters to the MPC server through the communication interface. The data transmission is protected by an encrypted channel. The communication interface is responsible for implementing the data interaction between the PyTorch module and the computing framework of the MPC server. The communication interface provides a unified API interface externally to implement the sending, receiving, and conversion control of model parameters. Its underlying layer uses an encrypted communication protocol to ensure the integrity and confidentiality of data during transmission. The communication interface supports structured transmission of batch data, automatic alignment of parameter dimensions, and an automatic recovery mechanism for abnormal transmission, and can adapt to the parameter differences in different batches and different rounds of federated training. The communication interface is tightly coupled with the parameter security conversion module, reducing the intrusion into the existing system structure while ensuring the transmission efficiency, facilitating subsequent engineering integration and platform deployment; After local training using the model training module, the next step is to perform private and robust aggregation in a distributed aggregator setup using MPC technology. This aggregation can be carried out using an aggregation module running on the MPC computing framework. In this paper, a communication interface is created that enables two-way communication between the modules in PyTorch and the MPC computing framework. Using this communicator, the secret shares of the locally trained model in PyTorch are securely transmitted to the MPC servers in the MPC computing framework. These servers compute the aggregation using the specified MPC protocol and then return the aggregated model to the PyTorch module for the next round of training; This paper is based on the banker's bonus example provided by the MPC computing framework, which solves the Yao's millionaires' problem and can accommodate up to 8 users. In this example, the MPC servers listen for users on the specified ports and accept connections from the user-side interfaces. When all users are connected, the calculation starts and the connection is closed when the calculation is completed. In addition, the connection is encrypted using SSL, and the required keys and certificates are generated at startup; This paper extends the user interface of the MPC computing framework to send any amount of data and integrates the users into the PyTorch module to send the secretly shared local models to the MPC servers and retrieve the aggregated models. For simplicity, this paper makes the PyTorch module behave like a single user and distributes all local models to the MPC servers. However, this can be easily extended to individual connections for each user. This is the first time a communicator is developed to connect the PyTorch module and the MPC computing framework, especially for federated learning; This application constructs an efficient communication bridge between the PyTorch module and the MPC computing framework, supporting the automatic mapping and conversion of model parameters between the training side and the secure computing side. This mechanism is well encapsulated and highly adaptable, and can be directly integrated into the existing training process without significant modification to the original model structure, thus reducing the development cost and deployment complexity, enhancing the reusability and cross-platform migration ability of the technical solution, and having a good foundation for engineering promotion; At the same time, this application significantly reduces the communication and computing load in a multi-party environment by introducing mechanisms such as batch processing compression, breakpoint resumption, and tensor reorganization. The communication interface is encapsulated as a standardized API, supporting parameter structure adaptation and distributed message control, effectively enhancing the stability and availability of the system in weak network environments, asynchronous training, and edge devices. This design takes into account both security and efficiency, improves the overall performance and response ability of the system, and expands the actual deployment scope; S400, Secure Aggregation Phase: The MPC server receives the encrypted state parameters from each client and performs multi-party aggregation operations in the encrypted state space. The aggregation method can be flexibly configured. The secure aggregation module is the core module deployed inside the MPC server. Its task is to encrypt and aggregate the encrypted model parameters from the clients. This module supports multiple aggregation strategies, including FedAvg and FLTrust, and can be dynamically switched according to the security situation in the current client training environment. All aggregation processes are completed in the ciphertext state, effectively preventing the intermediate nodes inside the client from snooping on the original parameters. The secure aggregation module integrates an anomaly detection and screening mechanism internally. This module outputs the aggregated encrypted state parameter results and passes them to the decryption module for the next step of processing; The secure aggregation module performs distributed secure aggregation using the MPC protocol implemented in the MPC computing framework. In this paper, the FLTrust code is selected as the best candidate for the private and robust aggregation method used in the experiment. For the FLTrust code, this paper allows a trusted user (which can be a user or the MPC server) in the PyTorch module to train the global model on the root dataset. The MPC computing framework is used to calculate the trust scores and aggregate the final model. This paper also implements the FLTrust aggregation method as a benchmark to estimate the cost overhead of adding robust aggregation. Weighting according to the user data size is removed from FedAvg to make it more efficient and reduce numerical errors; SMPC Protocol for Malicious Models The SPDZ2k protocol is a secure multi-party computing protocol designed specifically for dealing with the situation of dishonest majority. It is an extension of the original SPDZ protocol, allowing the participating parties to perform calculations in the environment of modulo 2k, where k is a security parameter. This setting is closer to standard computer operations. In this way, the SPDZ2k protocol designs a new type of information-theoretically secure message authentication code MAC scheme, which is homomorphic on Z2k and as efficient as the standard solution on finite fields; MPC Protocol for Semi-Honest Models The Replicated2k protocol is a new three-party computing protocol that is very efficient under the semi-honest adversary model and can resist malicious adversaries in the client or the MPC global model by using related randomness generation techniques. The Replicated2k protocol is applicable to arithmetic circuits on rings of arithmetic circuits over any domain. The addition gates only require local addition, while the multiplication gates require each participating party to send only a single domain / ring element to another party, which is suitable for parallelization on standard computers; MPC Protocol for Malicious Models The PsReplicated2k protocol is an efficient protocol for multi-party secure computing. It aims to process large-scale integer operations while ensuring privacy through the "additive secret sharing" mechanism. This protocol is based on the semi-honest model and is applicable to scenarios where secure collaborative computing is required without revealing the input data. The basic principle of the PsReplicated2k protocol is to perform secret sharing on the input of each participant, that is, to split the input data into multiple parts and distribute these parts to the participating parties. Each participant only holds a part of the information, and the original data cannot be deduced even by observing alone. The secure aggregation module designed in this application supports the dynamic loading and scheduling of multiple secure aggregation algorithms and allows for flexible switching of strategies according to different attack types, training scenarios, or participant trust levels. This module also incorporates a model distance analysis and abnormal parameter filtering mechanism to enhance the system's detection and defense capabilities against attacks such as model poisoning and label flipping. Compared with a single-strategy system, the present invention achieves stronger security robustness and controllability while ensuring model performance. S500, Aggregation result decryption and synchronization phase: Multiple MPC server participating nodes perform joint decryption operations according to the protocol to generate the plaintext aggregation result of the global model and synchronously return it to each client for the next round of training iteration. A decryption and synchronization module is set inside the MPC server, whose function is to jointly decrypt the encrypted aggregated parameter result and synchronize the decrypted global model parameters back to each participant. The decryption and synchronization module adopts a threshold decryption scheme to ensure that the decryption process can only be completed when a certain number of MPC server nodes perform joint operations, thereby enhancing the system's fault tolerance and security level. The synchronization part is responsible for version control, structure alignment, and compression processing of the aggregated global model to adapt to the computing resource conditions of different clients. The decryption and synchronization module also integrates a secure synchronization mechanism to prevent tampering or forgery during the backpropagation of the global model and ensure the legality and consistency of parameter updates.
[0025] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A composite method for privacy computing protocols based on parameter security conversion, including a client for data conversion, several MPC servers, and a communication interface, characterized in that, S100. Each client performs model training on its local private dataset respectively to generate local model update parameters, which are retained locally. S200. Parameter encryption and transformation stage: The client calls the MPC encryption module to securely encrypt the local model parameters, and uses the secret sharing and homomorphic encryption mechanisms to perform encrypted state transformation on the parameters to generate ciphertext parameter representations. S300. Encrypted parameter transmission stage: The client transmits the encrypted state parameters to the MPC server through the communication interface, and the data transmission is protected by an encrypted channel. S400. Secure aggregation stage: The MPC server receives the encrypted state parameters from each client and performs multi-party aggregation operations in the encrypted state space, and the aggregation method can be flexibly configured. S500. Aggregation result decryption and synchronization stage: Multiple MPC server participating nodes perform joint decryption operations according to the protocol to generate the plaintext aggregation result of the global model, and synchronously return it to each client for the next round of training iteration.
2. The composite method of a privacy computing protocol based on parameter security conversion according to claim 1, characterized in that: S100. Local model training stage: Each client performs model training on its local private dataset respectively to generate local model update parameters, which are retained locally. Usually, the parameters are retained locally in plaintext as weight vectors or gradient tensors. The client internally sets up a module of PyTorch and is responsible for performing local model training on behalf of the client based on the PyTorch module. Using the publicly available FLTrust code as a starting point, the MPC server itself collects a small clean training dataset on the local private dataset. This small clean training data is called the root dataset, and maintains a model for it. This model is called the global model, just as the client maintains the local model. In each iteration, the model training module follows the general three steps in federated learning: The first step: Synchronize the global model with the client. The MPC server sends the current global model W to the client or a subset in the root dataset. The second step: Train the local model. Each client trains the local model by fine-tuning the global model W using the root dataset. The third step: Update the global model by aggregating the local model updates. The server calculates the global model update G by aggregating the local model updates according to a certain aggregation method. Then, the server uses the global model update to update the global model, that is, W = W + α·G, where α is the global learning rate, thus completing the training of the local model.
3. A privacy computing protocol composite method based on parameter security conversion according to claim 1, characterized in that: S200, Parameter Encryption and Transformation Phase: The client invokes the MPC encryption module to securely encrypt the local model parameters. The MPC encryption module is deployed inside the client of federated learning. Its core function is to convert the model parameters into a ciphertext representation after local training. This module encrypts or secretly shares the parameters based on the multi-party secure computation protocol, so that the original parameters are encrypted and encapsulated before leaving the local device, thus preventing interception or leakage during transmission. By calling the interface function in the MPC computing framework, this module converts the tensor-type model parameters into ciphertext shares and outputs them to the communication interface module for further processing. Parameter security transformation supports floating-point or fixed-point number types and can adapt to the parameter structures of various deep learning tasks.
4. A privacy computing protocol composite method based on parameter security conversion according to claim 1, characterized in that: S300, Encrypted Parameter Transmission Phase: The client transmits the ciphertext parameters to the MPC server through the communication interface. The data transmission is protected by an encrypted channel. The communication interface is responsible for implementing the data interaction between the PyTorch module and the computing framework of the MPC server. The communication interface provides a unified API interface externally to achieve the sending, receiving, and conversion control of model parameters. Its underlying layer uses an encrypted communication protocol to ensure the integrity and confidentiality of data during transmission. The communication interface supports structured transmission of batch data, automatic alignment of parameter dimensions, and an automatic recovery mechanism for abnormal transmission, and can adapt to the parameter differences in different batches and rounds of federated training. The communication interface is tightly coupled with the parameter security transformation module, reducing the intrusion into the existing system structure while ensuring transmission efficiency, which is convenient for subsequent engineering integration and platform deployment.
5. A composite method for a privacy computing protocol based on parameter security conversion according to claim 1, characterized in that: S400, Secure Aggregation Phase: The MPC server receives the ciphertext parameters from each client and performs a multi-party aggregation operation in the ciphertext space. The aggregation method can be flexibly configured. The secure aggregation module is the core module deployed inside the MPC server, and its task is to perform encrypted aggregation on the ciphertext model parameters from the clients. This module supports multiple aggregation strategies, including FedAvg and FLTrust, and can be dynamically switched according to the security situation in the current client training environment. All aggregation processes are completed in the ciphertext state, effectively preventing intermediate nodes inside the client from snooping on the original parameters. The secure aggregation module integrates an anomaly detection and screening mechanism internally. This module outputs the aggregated ciphertext parameter results and hands them over to the decryption module for the next step of processing.
6. A privacy computing protocol composition method based on parameter security conversion according to claim 1, characterized in that: S500, Aggregation Result Decryption and Synchronization Phase: Multiple MPC server participating nodes perform joint decryption operations according to the protocol to generate the plaintext aggregation result of the global model, and synchronously return it to each client for the next round of training iteration. The decryption and synchronization module is set inside the MPC server, whose function is to jointly decrypt the encrypted aggregated parameter results and synchronize the decrypted global model parameters back to each participant. The decryption and synchronization module adopts a threshold decryption scheme to ensure that the decryption process can only be completed when the nodes of a certain number of MPC servers perform joint operations, thereby enhancing the fault tolerance and security level of the system. The synchronization part is responsible for version control, structure alignment, and compression processing of the aggregated global model to adapt to the computing resource conditions of different clients. The decryption and synchronization module also integrates a secure synchronization mechanism to prevent tampering or forgery during the backhaul process of the global model and ensure the legality and consistency of parameter updates.
7. A composite method for a privacy computing protocol based on parameter security conversion according to claim 1, characterized in that: The client uses a standard Linux server, and the recommended configuration is a multi-core CPU + 128G memory, supporting containerized operation.
Citation Information
Cited By
Federal learning-oriented privacy enhancement data security aggregation method and system
CN122475866A
A privacy-enhanced data security aggregation method and system for federated learning
CN122475866B