Education data privacy security protection method based on block chain and federal learning

Through a combination of blockchain and federated learning, dynamically allocate roles, use Diffie-Hellman key negotiation and Shamir secret sharing, identify and offset Byzantine attacks, solve the privacy protection and data utility problems in heterogeneous scenarios of educational data, and achieve safe and efficient training of educational data.

CN120277708APending Publication Date: 2025-07-08GUANGXI NORMAL UNIV
View PDF 0 Cites 4 Cited by

Patent Information

Application Number
CN202510299120.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-13
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

The existing educational data privacy security protection methods fail to effectively take into account data utility and privacy protection in heterogeneous data scenarios, and the Byzantine robust aggregation effect is not good.

Method used

Using a blockchain-based and federated learning method, through dynamic role allocation, Diffie-Hellman key negotiation, Shamir secret sharing and Byzantine detection algorithms, decentralized management and privacy protection of educational data are realized, combined with smart contract incentive mechanisms, to ensure the verifiability and noise cancelability of gradient exchanges.

Benefits of technology

In the non-independent and homogeneous educational data scenario, the balance between privacy protection and model utility is achieved, preventing witch attacks and centralized monopoly, and ensuring utility and privacy security in data training.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120277708A_ABST
    Figure CN120277708A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data privacy and security protection, in particular to an educational data privacy security protection method based on a block chain and federated learning, and the method comprises the steps: dividing participating nodes into workers, verification committee and aggregation committee based on a dynamic role distribution mechanism of stock right weight, decentralized election is realized through Hash ring mapping; in combination with a double-layer privacy protection strategy of Diffie-Hellman key agreement and Shamir threshold secret sharing, counteractable differential disturbance is added to a local model, and verifiability of gradient exchange and noise elimination are ensured; a Byzantine detection algorithm is used, and poisoning attacks under non-IID data are effectively identified through gradient-based symbol clustering and similarity threshold filtering; based on a contribution degree incentive model of a block chain smart contract, the weight of the committee is dynamically adjusted through proven of interest (PoS), and Sybil attacks and centralized monopoly are prevented. By adopting the method, the effectiveness and privacy security of the education data in the distributed training process can be guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data privacy and security protection, and particularly relates to an education data privacy and security protection method based on blockchain and federated learning. Background Art

[0002] Educational data analysis, especially learning analytics, is a promising scenario for applying federated learning technology to address legal and ethical issues related to sensitive data. Using federated learning technology on data distributed across different educational institutions, we assume that each educational center has management rights over all data of its teachers and students. Therefore, each institution in the education system can be regarded as an island. In fact, considering the nature of the data to be studied (personal data, educational outcomes, and data related to minors), it is necessary to ensure that the conduct of these studies and the publication of their results provide necessary safeguards for protecting the privacy of the individuals involved and data protection. Currently, centralized storage is still the mainstream form of educational data. Each educational institution stores educational data centrally through public clouds or private clouds with itself as the center. In this mainstream method, not only does it cause data isolation between educational institutions, but also centralized storage is prone to problems such as single-point failures.

[0003] Currently, researchers are also actively exploring effective solutions. Arachchige PCM et al. proposed the PriModChain framework, which combines differential privacy and cryptographic technologies to address privacy and trust issues in ML in the system. Among them, differential privacy technology introduces Laplace noise in local model updates to mask real values. However, the introduction of noise may lead to a decrease in data availability and a reduction in model utility. Most existing work uses the Multi-Krum algorithm to verify all transactions in the pool. By comparing the distances of model updates between different workers, potential Byzantine attackers are identified and eliminated, and legitimate updates are accepted. Due to the diversity of gradients, mitigating Byzantine attacks in non-independent and identically distributed data has always been a well-known challenge. And distance-based detection methods such as Multi-Krum are more suitable for independent and identically distributed data, and usually have poor identification effects in data heterogeneous scenarios. Summary of the Invention

[0004] The purpose of the present invention is to provide an education data privacy and security protection method based on blockchain and federated learning, which solves the technical problem that existing education data privacy and security protection methods do not simultaneously need to consider data utility, privacy protection, and Byzantine-robust aggregation in heterogeneous data scenarios, resulting in failure to meet actual application requirements.

[0005] To achieve the above object, the present invention provides an educational data privacy and security protection method based on blockchain and federated learning, comprising the following steps:

[0006] Registration and intelligent contract deployment. Educational institutions register with a trusted authority, and the trusted authority deploys an intelligent contract;

[0007] Dynamic role assignment. Based on node equity weights, a verification committee and an aggregation committee are elected through a hash ring space mapping algorithm, and the committee members and worker roles are mutually exclusive;

[0008] Shared key generation. Let the trusted authority honestly execute the Diffie-Hellman key negotiation algorithm to generate a public-private key pair;

[0009] Local training. The blockchain randomly initializes a global model. Each participant downloads the global model from the blockchain and then trains it on the local dataset D i to obtain local gradients;

[0010] Adding a mask to the local model. Educational institutions participating in the training add local model parameters to the mask to generate a random seed. Workers send the random seed to the aggregation committee members using Shamir secret sharing for easy recovery of the random seed during the aggregation phase and send a transaction to the verification committee;

[0011] The verification committee identifies Byzantine attackers. The verification committee identifies malicious gradients through a symbol clustering filter and a similarity threshold filter, outputs a set of benign nodes, then signs the transaction, and sends the transaction containing the determination result to the associated aggregation committee members;

[0012] Model parameter aggregation. The aggregation committee uses Shamir threshold secret sharing to reconstruct the perturbation terms of the filtered nodes, obtains a noise-free global model, and packages and uploads the noise-free global model to the blockchain;

[0013] Local model update. Educational institutions obtain the updated noise-free global model parameters from the blockchain and update the local model parameters for training;

[0014] Repeat the above steps of dynamic role assignment to local model update until the model meets the requirements.

[0015] Among them, in the dynamic role assignment step, the space occupancy ratio of the hash ring is allocated according to the proportion of shares held by each node. The latest block obtained in the previous round is repeatedly hashed, and the hash value will be mapped on the hash ring. The nodes mapped to this space will be selected as verifiers or aggregators. This process is repeated until the required number of verifiers or aggregators is selected to form the verification committee and the aggregation committee.

[0016] Among them, in the shared key generation step, workers conduct Diffie-Hellman (DH) key negotiation pairwise to obtain a shared key as the random seed between them. Some public parameters p are generated, and the participating party u generates a public-private key pair according to p. The user uses their own private key and the public keys of all other users v to generate the private shared key s between u and v u,v . A key negotiation scheme using a hash function is used in the DH key negotiation.

[0017] Among them, in the local training step, during the training process, if it is the first round of training, the initial global model parameters are used for training. Otherwise, the aggregated global model parameters decrypted in the previous round are used to train the local local model.

[0018] Among them, in the step of adding a mask to the local model, a PRG pseudo-random number generator is used to generate random numbers. The same random seed will obtain the same random numbers PRG(s u,v ) = PRG(s v,u ). The obtained random numbers are added as perturbation terms to the local model parameters. If the id of worker u is greater than the id value of worker v, they are added when adding the perturbation terms, otherwise they are subtracted.

[0019] Among them, in the step of the verification committee identifying Byzantine attackers, once the verifiers collect enough updates, they will execute the SignGuard algorithm. The collected model parameters will be sent to multiple filters, including a specification-based threshold filter and a sign-based clustering filter, to eliminate potentially poisonous updates.

[0020] Among them, in the model parameter aggregation step, the aggregation committee aggregates the local model parameters of the verified benign workers.

[0021] A method for protecting the privacy and security of educational data based on blockchain and federated learning, the method comprising: a dynamic role allocation mechanism based on equity weights, dividing participating nodes into workers, verification committees and aggregation committees, and realizing decentralized election through hash ring mapping; a two-layer privacy protection strategy combining Diffie-Hellman key negotiation and Shamir threshold secret sharing, adding cancelable differential perturbations to the local model to ensure the verifiability and noise eliminability of gradient exchange; using a Byzantine detection algorithm, effectively identifying poisoning attacks under non-IID data through gradient-based sign clustering and similarity threshold filtering; a contribution incentive model based on blockchain smart contracts, dynamically adjusting the committee weights through Proof of Stake (PoS) to prevent Sybil attacks and centralized monopolies. This method is oriented to the non-independent and identically distributed (Non-IID) educational data scenario, and realizes the balance between privacy protection and model utility by integrating dynamic role allocation, verifiable secret sharing and anti-Byzantine aggregation mechanisms, so as to ensure the utility and privacy security of educational data in the distributed training process. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art.

[0023] Figure 1 It is a system framework diagram of the method for protecting the privacy and security of educational data based on blockchain and federated learning in the first embodiment of the present invention.

[0024] Figure 2 It is a schematic diagram of the system process of the method for protecting the privacy and security of educational data based on blockchain and federated learning in the first embodiment of the present invention.

[0025] Figure 3 It is a flowchart of the steps of the method for protecting the privacy and security of educational data based on blockchain and federated learning in the first embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0026] The following details the embodiments of the present invention. The examples of the embodiments are shown in the drawings. The embodiments described below with reference to the drawings are exemplary and are intended to explain the present invention, and should not be construed as a limitation of the present invention.

[0027] First Embodiment

[0028] To make the purpose, technical solutions and advantages of the present invention clearer, the following combines the attached Figure 1 to Figure 3 further describes the present invention.

[0029] The technical terms involved in the present invention are explained as follows:

[0030] Federated Learning: It is a distributed machine learning algorithm. The main roles include clients and servers. During the learning process, each client does not share its training data. The server coordinates a large number of clients to jointly train to obtain an optimal global model, breaking the barriers between data while protecting data privacy, thus solving the data silo problem.

[0031] Blockchain: A distributed database technology that has attracted attention for its characteristics such as decentralization, immutability, and high security. The basic principle of blockchain technology is to connect a series of blocks composed of transaction records through cryptographic algorithms to form a continuously growing chain-like structure. Each block contains the hash value of the previous block, which makes it impossible to easily tamper with the data once it is written into the blockchain. In addition, blockchain adopts a consensus mechanism, enabling nodes in the entire network to reach an agreement on the correctness of the data.

[0032] Diffie-Hellman Key Agreement: Diffie-Hellman key exchange is a method for securely negotiating keys over an open communication channel. The basic principle of Diffie-Hellman key exchange is to utilize the discrete logarithm problem in number theory to negotiate a symmetric key through public and private keys and algorithms, and then use this symmetric key to encrypt subsequent communications. It allows two communicating parties to negotiate a shared key through an insecure communication channel without the need to pre-share any key material.

[0033] Verifiable Secret Sharing: Secret sharing is a cryptographic technique designed to split secret information into multiple parts, called "shares", and distribute these shares to different participants. Only when a sufficient number of shares are combined can the original secret information be reconstructed. This technique ensures that even if some shares are lost or maliciously obtained, the original secret information cannot be recovered. Shamir's (t,n) secret sharing scheme divides the secret parameter s to be shared into n parts {s1, s2... s n} and sends them to n participants. Only when at least t (1 < t < n) shares are obtained can s be decrypted, that is, at least any t participants need to cooperate to recover the secret. At the same time, a verifiable secret sharing scheme is used to calculate polynomial commitments and prove in a zero-knowledge proof manner that each secret share belongs to a given polynomial.

[0034] Committee: A fixed number of blockchain nodes considered trustworthy in each round of consensus.

[0035] Committee Consensus Mechanism: In blockchain consensus, the form of a committee is adopted, and the committee nodes are given the responsibilities of verifying model updates and block generation. The smart contract aggregates models based on the scores of the previous round of the committee on the models of other training nodes, and elects the committee nodes for the next round from the participants. The same node will not serve as both a committee member and a trainer at the same time.

[0036] SignGurad Algorithm: Research on model poisoning attacks shows that carefully designed attacks can circumvent most median- and distance-based statistical defense methods, making it difficult to distinguish malicious gradients from honest gradients. To address this challenge, Jian Xu et al. demonstrated that the element signs of the gradient vector can provide valuable insights for detecting model poisoning attacks. In 2022, based on the theoretical analysis of the "less is enough" attack in ICDCS, a new method called "SignGuard" was proposed to achieve Byzantine federated learning through collaborative malicious gradient filtering. More precisely, first, the received gradients are processed to generate relevant magnitude, sign, and similarity statistics, and then these statistics are collaboratively utilized by multiple filters to eliminate malicious gradients before the final aggregation.

[0037] In view of the business requirements in the Internet of Things scenario in the education field, the present invention provides an education data privacy and security protection method based on blockchain and federated learning, including the following steps:

[0038] S1. Registration and Smart Contract Deployment: Educational institutions register with a trusted authority, and the trusted authority deploys a smart contract.

[0039] S2. Dynamic Role Allocation: Based on the node equity weight, a verification committee and an aggregation committee are elected through the hash ring space mapping algorithm, and the roles of committee members and workers are mutually exclusive.

[0040] Specifically, there are three roles in this method, namely: workers, verification committee, and aggregation committee; the workers are educational institutions participating in local training; the verification committee is a group of educational institutions selected according to the role allocation mechanism for Byzantine detection of the encrypted local model parameters collected; the aggregation committee is a group of educational institutions selected according to the role allocation mechanism for aggregating the secret shares of the local model parameters collected. In each round of iteration, the user roles are reallocated, and users are divided into three identities: workers, verifiers, and aggregators. To prevent malicious nodes from launching a Sybil attack to increase their influence, the identities of the nodes are determined by the shares they hold, ensuring that the influence of the nodes is limited by their shares. Specifically, the space occupation ratio of the hash ring is allocated according to the proportion of the shares held by each node. Among them, s i is the equity value. The latest block obtained in the previous round is repeatedly hashed to obtain a hash sequence. For each hash value Map it on the hash ring If the coordinate θ m falls into the arc length space of node i Then this node will be selected as a verifier or aggregator. Repeat this process until the required number of verifiers or aggregators are selected, and they will form a verification committee and an aggregation committee respectively. Since malicious nodes cannot speculate on the future state of the block before creating the block, they cannot speculate on the output of the consistent hash and execute attacks strategically. Verifiers and aggregators will not provide model updates for the current round. The remaining nodes will act as workers for model training and provide model updates for the current round. Workers perform local model training for the current round and send the local model parameters added with perturbation terms to the verifiers. The verification committee composed of verifiers identifies Byzantine workers based on the model parameter information submitted by the workers, signs the transaction records determined to be benign workers and sends them to the aggregators. The aggregation committee composed of aggregators receives the transactions sent by the verification committee, verifies the signatures, securely aggregates the valid model parameters to obtain the global model, mines and uploads it to the blockchain. In each round of iterative training, nodes that contribute to the global model are given equity rewards. On the contrary, nodes screened out by the verification committee are regarded as malicious nodes and a part of their equity will be deducted. The amount of node equity will affect the probability of the node being selected as a committee. The equity distribution ratio of nodes selected to join the committee will increase or decrease according to the performance of each round, reducing the situation of node monopoly control.

[0041] S3. Shared key generation. Let the trusted authority honestly execute the Diffie-Hellman key negotiation algorithm to generate a public-private key pair;

[0042] S4. Local training. The blockchain randomly initializes a global model. Each participating party downloads the global model from the blockchain and then trains it on the local dataset D i to obtain local gradients;

[0043] S5. Add a mask to the local model. The educational institutions participating in the training add a mask to the local model parameters to generate a random seed. The workers send the random seed to the members of the aggregation committee using Shamir secret sharing for the recovery of the random seed in the aggregation stage and send transactions to the verification committee.

[0044] Specifically, each worker is associated with a verifier and an aggregator respectively. After local model training, the worker sends a transaction to the associated verifier. To prevent malicious verifiers from launching information leakage attacks, it is necessary to add a perturbation term to the local model parameters to hide their updates and prevent information leakage. At the same time, the added noise can cancel each other out during the model aggregation stage to ensure the model utility. Specifically, the workers who perform local training conduct Diffie-Hellman (DH) key agreement pairwise to obtain a shared key as the random seed between them, namely s u,v and s v,u and s u,v = s v,u . This random seed is only known to these two workers and cannot be known to other workers. The worker uses Shamir secret sharing to send this random seed to the members of the aggregation committee for the recovery of the random seed during the aggregation stage. A pseudorandom number generator (PRG) is used to generate random numbers. The same random seed will obtain the same random number PRG(s u,v ) = PRG(s v,u ). The obtained random number is used as the perturbation term and added to the local model parameters. If the ID of worker u is greater than the ID value of worker v, then add them when adding the perturbation term, otherwise subtract them. Intuitively, when all workers participate in the aggregation process, these encrypted parameters can naturally cancel each other out, so that the aggregated global model without noise perturbation is obtained, thus ensuring the utility of the model.

[0045] Each worker has a unique local model The difference between the local model and the global model w obtained in the previous round t-1 is called the update Δw of worker u u = w u - w t-1 . To balance privacy loss and model performance, an algorithm for differential privacy protection of clients in federated optimization is adopted, which can achieve client-level differential privacy protection at the cost of a small loss of model performance. A Gaussian mechanism is used in this algorithm to distort all updates The sensitivity upper bound of the scaled update is S, and noise is added to all proportionally adjusted updates. We apply this process to our algorithm to balance privacy loss and model performance.

[0046] Among them, the update is distorted, and the perturbed term y obtained by conducting DH key agreement between workers is added to some scaled local model parameters w u = Δw u + w t-1 u = w u + ζ u .

[0047] Among them, ​

[0048] S6. The verification committee identifies Byzantine attackers. The verification committee identifies malicious gradients through a symbol clustering filter and a similarity threshold filter, outputs a set of benign nodes, then signs the transaction, and sends the transaction containing the judgment result to the associated members of the aggregation committee.

[0049] Specifically, the verification committee verifies the noisy update to prevent model poisoning. The verifier receives the locally added model parameters with perturbation terms and broadcasts the transaction to other verifiers. Once the verifier collects enough updates, the SignGuard algorithm will be executed. The collected model parameters will be sent into multiple filters, including a norm-based threshold filter and a sign-based clustering filter. For the norm-based threshold filter, the median of the parameters will be used as the reference norm because the median is always in the benign set. Secondly, for the sign-based clustering filter, the MeanShift algorithm is used as an unsupervised clustering model to adaptively cluster the number, and the cluster with the largest scale is selected as the trusted set. Here, the ratios of positive signs, zero signs, and negative signs are calculated as basic features, which are sufficient to cope with various attack methods. Among them, random coordinate selection is introduced and cosine similarity features or Euclidean distance features are added as enhanced variants "SignGuard-Sim". After the filtering process, the intersection of multiple filtered outputs will be selected as the trusted set, and the verifier will save the filtering result in the transaction, sign the transaction and send it to the associated aggregator (members of the aggregation committee).

[0050] S7. Model parameter aggregation. The aggregation committee uses Shamir threshold secret sharing to reconstruct the perturbation terms of the filtered nodes, obtains a noise-free global model, and packages and uploads the noise-free global model to the blockchain.

[0051] Specifically, the aggregation committee uses a secure protocol to aggregate the un-noisy updates. The aggregator selects the benign workers who have passed the verification to participate in the aggregation, receives the secret sharing sent by the benign workers, and uses polynomial commitment to verify the authenticity of the shares for secure aggregation; the aggregator will receive the transactions sent by the verifiers at this stage. The aggregator verifies the signatures of the verifiers in the transaction and aggregates the locally added model parameters that have passed the verification. According to the above privacy protection strategy, when all workers U1 participate in the aggregation process, the added perturbation terms can be naturally offset. However, in fact, after the verification and filtering by the verification committee, only the model updates of some benign workers U2 are retained, and the model updates of some workers (U1\U2) are filtered out. Therefore, it is necessary to request the Shamir secret shares of the shared keys of the filtered workers sent by the benign workers U2 to reconstruct the shared key s negotiated by the benign workers and them v,u , and calculate the perturbation term PRG(s v,u ), so as to offset yu The PRG(s u,v ) in Meanwhile, polynomial commitment and verifiable secret sharing are used to verify the correctness of the secret shares.

[0052] S8. Local model update: The educational institution obtains the updated noise-free global model parameters from the blockchain and updates the local model parameters for training.

[0053] S9. Repeat the above steps of dynamic role assignment to local model update until the model meets the requirements.

[0054] Specifically, the aggregation committee members save the global model in a transaction, and the updated aggregation is saved in a newly created block, which is broadcast to all nodes. All workers who contribute to the final update and the nodes that serve as the verification and aggregation committee will obtain corresponding equity values. Using the updated global model and equity, repeat the above steps of dynamic role assignment to local model update until the model meets the requirements.

[0055] The above-disclosed are only one or more preferred embodiments of the present application, and the scope of rights of the present application cannot be limited thereby. Those of ordinary skill in the art can understand all or part of the processes of implementing the above embodiments, and the equivalent changes made according to the claims of the present application still fall within the scope covered by the present application.

Claims

1. An educational data privacy and security protection method based on blockchain and federated learning, characterized in that, It includes the following steps: Registration and smart contract deployment. The educational institution registers with a trusted authority, and the trusted authority deploys a smart contract. Dynamic role assignment. Based on the node equity weights, a verification committee and an aggregation committee are elected through the hash ring space mapping algorithm, and the committee members are mutually exclusive with the worker roles. Shared key generation. Let the trusted authority honestly execute the Diffie-Hellman key negotiation algorithm to generate a public-private key pair. Local training, the blockchain randomly initializes a global model, and each participant downloads the global model from the blockchain and then trains it on the local dataset D i to obtain local gradients; Adding a mask to the local model. The educational institutions participating in the training add the local model parameters to the mask to generate a random seed, and the worker sends the random seed to the aggregation committee members using Shamir secret sharing for the recovery of the random seed in the aggregation phase and sends a transaction to the verification committee. The verification committee identifies Byzantine attackers. The verification committee identifies malicious gradients through a symbol clustering filter and a similarity threshold filter, outputs a set of benign nodes, then signs the transaction, and sends the transaction containing the determination result to the associated aggregation committee members. Model parameter aggregation. The aggregation committee uses Shamir threshold secret sharing to reconstruct the perturbation terms of the filtered nodes, obtains a noise-free global model, and packages and uploads the noise-free global model to the blockchain. Local model update. The educational institution obtains the updated noise-free global model parameters from the blockchain and updates the local model parameters for training. Repeat the above dynamic role assignment steps to the local model update steps until the model meets the requirements.

2. The educational data privacy and security protection method based on blockchain and federated learning according to claim 1, wherein: In the dynamic role assignment step, the space ratio of the hash ring is allocated according to the share ratio held by each node, and the latest block obtained in the previous round is repeatedly hashed. The hash value will be mapped on the hash ring, and the nodes mapped to this space will be selected as verifiers or aggregators. Repeat this process until the required number of verifiers or aggregators are selected to form a verification committee and an aggregation committee.

3. The educational data privacy and security protection method based on blockchain and federated learning according to claim 2, wherein: In the step of generating the shared key, the workers perform Diffie-Hellman (DH) key negotiation pairwise to obtain a shared key as the random seed between them. Some public parameters p are generated, and the participant u generates a public-private key pair based on p The user uses its own private key and the public keys of all other users v to generate the private shared key s between u and v u,v , and a key negotiation scheme using a hash function is used in the DH key negotiation.

4. The educational data privacy and security protection method based on blockchain and federated learning according to claim 3, wherein: In the local training step, during the training process, if it is the first round of training, the initial global model parameters are used for training, otherwise, the aggregated global model parameters decrypted in the previous round are used to train the local local model.

5. The educational data privacy and security protection method based on blockchain and federated learning according to claim 4, wherein: In the local model adding the masking step, a random number is generated using a PRG (pseudo-random number generator). The same random seed will result in the same random number, PRG(s u,v ) = PRG(s v,u ). The obtained random number is added as a perturbation term to the local model parameters. If the ID of worker u is greater than the ID value of worker v, then they are added when adding the perturbation term; otherwise, they are subtracted.

6. The educational data privacy and security protection method based on blockchain and federated learning according to claim 5, wherein: In the step where the verification committee identifies Byzantine attackers, once the verifier has collected enough updates, the SignGuard algorithm will be executed. The collected model parameters will be fed into multiple filters, including a specification-based threshold filter and a symbol-based clustering filter, to eliminate potentially toxic updates.

7. The method for protecting the privacy and security of educational data based on blockchain and federated learning according to claim 6, wherein: In the step of aggregating the model parameters, the aggregation committee aggregates the local model parameters of the benign workers that have passed the verification.

Citation Information

Cited By

  • Data trusted processing method and system fusing trusted computing and block chain

    CN121144418A

  • A data trust processing method and system integrating trusted computing and blockchain

    CN121144418B

  • Federal learning method and system based on differential privacy and zero knowledge proof

    CN121150970A

  • A federated learning method and system based on differential privacy and zero-knowledge proof

    CN121150970B