Excitation type robust clustering federated learning system based on block chain
Through the incentive-based robust clustering federated learning system based on blockchain, the privacy leakage, heterogeneous data adaptability and incentive mechanism unfairness in cross-institutional collaborative analysis of mental health data is solved, and the model robustness and fairness improvement in highly heterogeneous data scenarios is achieved.
Patent Information
- Application Number
- CN202510359656.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-07-08
AI Technical Summary
In the cross-institutional collaborative analysis of mental health data, there are problems such as privacy leakage risks, poor adaptability of heterogeneous data and unfair incentive mechanisms. Existing federated learning technologies are difficult to achieve model robustness and fair participation in highly heterogeneous data scenarios.
The incentive-based robust clustering federated learning system is adopted based on blockchain, and through multi-client function encryption, hierarchical clustering and dynamic reputation evaluation mechanisms, privacy protection and malicious model detection are realized, model performance of non-independent and homogeneous data scenarios is improved, and a strong learning-driven intelligent incentive mechanism is promoted to promote fair participation of institutions.
On the premise of ensuring data privacy, effectively resist Byzantine attacks, improve model performance, ensure the robustness and fairness of models in heterogeneous data scenarios, and promote the continuous participation of high-quality institutions.
Smart Images

Figure CN120278231A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular, to an incentive-based robust clustering federated learning system based on blockchain. Background Art
[0002] In the context of the rapid development of digital healthcare, the cross-institutional collaborative analysis of mental health data provides new opportunities for precise diagnosis and treatment. The psychological assessment records, treatment feedback data, and behavioral monitoring data accumulated by different medical institutions contain important value for revealing the evolution law of mental diseases. However, the strong privacy attribute of medical data leads to the formation of data silos among hospitals, and it is difficult for traditional centralized machine learning to achieve cross-institutional knowledge integration. Federated learning technology provides a theoretical possibility for breaking this dilemma through a distributed training mechanism of "data does not move while the model moves", but it still faces some challenges in the practical application in the field of mental health.
[0003] First, the high sensitivity unique to psychological data (such as depression tendency scale, EEG brain electrical characteristics, micro-expression behavior records) poses strict requirements for privacy protection. Although existing solutions generally adopt protection technologies such as differential privacy, the reduction of data transparency will significantly amplify the risk of Byzantine attacks, and the traditional defense mechanism relying on a central server has a single point of failure hidden danger; second, psychological data shows significant institutional heterogeneity. Due to differences in diagnosis and treatment standards (such as the DSM-5 and ICD-11 scale systems), patient group characteristics (a higher proportion of severe cases in specialized hospitals), and acquisition environment variables (differences in wearable device models), the data distributions of each institution show highly non-independent and identically distributed (Non-IID) characteristics. When the existing FedAvg algorithm aggregates the global model, it is easily affected by local data biases, resulting in suboptimal convergence. Especially when dealing with outlier institutions (such as psychiatric specialty hospitals and community psychological clinics), the model robustness significantly deteriorates; finally, there is a new participant dilemma in the traditional federated incentive mechanism. The incentive model based on historical contribution evaluation such as the Shapley value makes it difficult for newly joined institutions to obtain fair model usage rights due to the lack of accumulation of training rounds. This Matthew effect seriously restricts the sustainable development of the system.
[0004] Therefore, in order to solve the above problems, the present invention proposes an incentive-based robust clustering federated learning system based on blockchain, which can detect malicious models under the state of privacy protection, is also applicable to highly heterogeneous data scenarios, and can encourage high-quality and honest psychological research institutions to actively participate in learning, improving long-term benefits. Summary of the Invention
[0005] Aiming at the problems of privacy leakage risk, poor adaptability to heterogeneous data and unfair incentive mechanism in cross-institutional mental health data collaborative modeling, the present invention proposes an incentive-based robust clustering federated learning system based on blockchain. By integrating multi-client function encryption, hierarchical clustering and dynamic reputation evaluation mechanisms, it can effectively resist Byzantine attacks, improve the model performance in the scenario of non-independent and identically distributed data while ensuring data privacy, and achieve fair participation of new and old institutions through intelligent incentives driven by reinforcement learning.
[0006] The present invention is implemented through the following technical solutions:
[0007] The present invention provides an incentive-based robust clustering mental data federated learning system based on blockchain, including the following modules:
[0008] Blockchain initialization module: Establish a blockchain and initialize an IPFS node. The task issuer registers an account and publishes a federated learning task, sets algorithm parameters and initializes the global model. The client registers an account and selects to participate in the task, and uploads the set of participating clients to the blockchain;
[0009] Multi-client function encryption module: Encryption algorithm initialization: Use a multi-client function encryption algorithm that supports inner product for privacy protection. Determine the number of clients participating in federated learning according to the security parameters of the task issuer. The KGC (Key Generation Center) sets the public parameters pp;
[0010] Key distribution module: The KGC generates the master private key msk and the client encryption key based on the public parameters pp and distributes them to the clients through a secure channel;
[0011] Client partitioning module based on agglomerative hierarchical clustering: In the first round, the client calculates the cosine similarity between its local gradient and those of other clients. The smart contract performs hierarchical clustering to partition the client clusters according to the similarity and determines the clustering centers. More specifically:
[0012] In the first round, the client downloads the ciphertexts of other clients through the blockchain, and by sending a decryption key query to the KGC, calculates the cosine similarity between its local gradient and the local gradients of the other n - 1 clients. The smart contract performs hierarchical clustering based on the calculated cosine similarity as the distance metric to partition the clients and calculates the clustering center of each cluster;
[0013] Clustering malicious client detection module based on differential privacy: In subsequent rounds, the client adds differential privacy noise and encrypts and uploads the gradient. The clustering center decrypts it and calculates the geometric median gradient, and filters malicious clients through the cosine similarity threshold. More specifically:
[0014] In the next round, the client downloads the global model in sequence to complete the local model update. The clients in the cluster add the local gradients to differential privacy noise, encrypt them, and send them to the clustering center. The clustering center decrypts them to obtain the perturbed gradients and calculates the geometric median. Each client calculates the cosine similarity between the median gradient of its cluster and the local gradient, and filters out clients with abnormal similarity according to the threshold;
[0015] Robust Secure Aggregation Module Based on Weight Allocation: Select high-reputation clients as leader nodes to decrypt the clustering aggregation ciphertext, allocate weights according to the cosine similarity with the global model in the previous round, and weighted-aggregate the global model. More specifically:
[0016] The system calls the smart contract to calculate the aggregation ciphertext of each cluster by means of federated averaging. Select m clients with the highest reputation values as leader nodes. The leader nodes decrypt the aggregation ciphertext of each cluster to obtain the aggregation plaintext, then calculate the cosine similarity between the aggregation plaintext and the global model in the previous round as the weight, and perform global model aggregation according to the weight;
[0017] Intelligent Incentive Mechanism Module Based on Multiple Reputation Assessments:
[0018] Combine the client contribution score and the number of malicious times to calculate the reputation value, dynamically adjust the reward weight, train the DQN model to optimize the incentive strategy, update the reputation value and upload it to the chain until the model converges. More specifically:
[0019] The client calculates the cosine similarity between the newly aggregated global model and the local model as the contribution score of the client, and the number of times p it is detected as "malicious" t as the reputation score of the client, and the two are combined as the reputation score of the client Use the accuracy of the aggregated global model as the reward value, the α value as the action vector, and the state space as the contribution score and the reputation score to train the DQN model. The smart contract rewards the client according to the updated reputation value R i (t) = β·R t-1 +(1 - β)·R i (t), rewards the client, and saves the reputation value on the chain until the convergence condition is reached.
[0020] In the above steps, step A includes:
[0021] Al: Initialize the blockchain to set up the blockchain and initialize its IPFS node;
[0022] A2: Register an account for the task publisher and publish the federated learning training task to the blockchain. The task publisher also needs to set the security parameters of the cryptographic algorithm, the hyperparameters of model training, and initialize a global model W0.
[0023] A3: Register an account for the client, select whether to participate in the task, and upload the set of participating clients to the blockchain.
[0024] Step B specifically includes the following steps:
[0025] B1: The KGC initializes the cryptographic algorithm according to the security parameters set by the task issuer and the number n of clients that initiate the encrypted key query.
[0026] B2: Select two large prime numbers p rsa and q rsa , calculate N rsa = p rsa × q rsa and Z rsa = (p rsa - 1) × (q rsa - 1);
[0027] B3: Also select two secure prime numbers p mcfe and q mcfe , and satisfy p = 2p mcfe + 1 and q = 2q mcfe + 1 which are also two secure large prime numbers. Then calculate N mcfe = p mcfe × q mcfe , and select a secure collision-resistant hash function In addition, set Select a public function and set the public parameters as pp = (N mcfe , H, X, L).
[0028] Step C specifically includes the following steps:
[0029] C1: For client u i select a number that is relatively prime to Z rsa , let it be d i , and find an e i ≡ 1 (mod Z rsa ). Then the public key pk i,rsa = (e i , N rsa ), and the private key sk i,rsa = (d i , N rsa ). Upload the public keys corresponding to all clients to the blockchain, and send the private keys to the corresponding clients through a secure channel;
[0030] C2: The KGC, based on the public parameters pp, from a Gaussian distribution of integers with variance and mean 0 Select an \(n\times d\) - dimensional matrix \(S\) as the master secret key \(msk\). Take each row of the master secret key \(S\) matrix as the encryption key \(sk\) of the client \(u\) i (\(i\in[1,n]\)) and distribute it to the client through a secure channel. At the same time, record the set \(U\) of clients to whom the encryption key is distributed. i,mcfe And record the set \(U\) of clients to whom the encryption key is distributed.
[0031] Step D specifically includes the following steps:
[0032] D1: After the client \(u\) i completes local training to obtain the local model of the current round and normalizes it, use the functional encryption key \(sk\) i,mcfe to encrypt the local model. According to the formula obtain the local model ciphertext \(ct\) i,l , and upload it to the blockchain, where \(l\) is the local timestamp of the client;
[0033] D2: Each client \(u\) i invokes the IPFS smart contract to obtain the local model ciphertexts \(\{ct\) j,l \(v\) i∈[1,n]\{i} ;\)
[0034] D3: The client \(u\) i uses its own RSA public key \(pk\) i,rsa to encrypt the local model according to the formula to obtain the ciphertext \(c\) i . Subsequently, send the ciphertext \(c\) i as a function decryption key query to the KGC;
[0035] D4: After the KGC receives the decryption key query from the client, first judge whether it is a legitimate client according to the set \(U\) when distributing the functional encryption key. If it is a legitimate client, the KGC uses the respective RSA private keys of the clients according to the formula (\(\bmod N\) rsa ) to decrypt the ciphertext \(c\) i , to obtain the plaintext queries of each client Subsequently, calculate the \(n - 1\) functional decryption keys \(dk\) i of each client \(u\) i =\(\{dk\) i,j |j\in[1,n]\setminus\{i\}\}, and return them to the corresponding client through a secure channel, where \(dk\) i,j =[<s j ,y i >], \(s\) j is the row vector of the matrix \(S\);
[0036] D5: After the client \(u\) i receives the functional decryption key sent by the KGC, according to the formula Calculate the cosine similarity between the local model and the other n - 1 clients, and upload the result to the blockchain. Among them, is client u i The cosine similarity between the local model calculated by client u j and the local model (in ciphertext state) of client u, where k ∈ [1, d];
[0037] D6: The n*(n - 1) cosine similarity calculation results sent by n clients accepted by the blockchain should form a symmetric matrix (with 1s on the diagonal). The smart contract checks if there are unequal calculation results on the symmetric matrix. If cos i,j (t) ≠ cos j,i (t), then client u i and client u j are required to resend the recalculation until it is correct. Multiple errors will be regarded as malicious clients;
[0038] D7: The greater the cosine similarity between clients, the higher the similarity, and the smaller the distance between clients in hierarchical clustering. Therefore, the distance between clients is defined as d i,j = 2 - cos i,j (t). The smart contract deployed on the blockchain divides the clients according to the hierarchical clustering algorithm;
[0039] D8: The smart contract obtains the cluster to which each client belongs. If the number of clients in the cluster is greater than 2, find the geometric median point in each cluster, that is, the point with the smallest sum of distances to other clients, as the cluster center of this cluster;
[0040] D9: The blockchain calls the model aggregation smart contract to calculate the global model gradient ciphertext for the t-th round of iteration according to the formula and upload it to the blockchain.
[0041] Step E specifically includes the following steps:
[0042] E1: If t = 2, client u i calls the IPFS smart contract to obtain the global model gradient ciphertext C(g t-1 ) of the (t - 1)-th round of iteration from IPFS, and then executes steps E2 and E3 to decrypt the global model; otherwise, client u i calls the IPFS smart contract to obtain the global model gradient ciphertext C i (g t-1 ) encrypted with their respective public keys of the (t - 1)-th round of iteration from IPFS, and then executes step E4 to obtain the global model;
[0043] E2: Client u i Select a d-dimensional all-ones vector And send a function decryption key query to the KGC. After receiving the query, the KGC will determine whether it is a legitimate client based on the set U when distributing the encryption key. If it is a legitimate client, the KGC will calculate the function decryption key dk y =[<s j , y>] j∈[1,d] , where is a column vector of S. Finally, the KGC will return the function decryption key dk y to client u i , where represents a d-dimensional integer vector;
[0044] E3: Client u i According to Use the function decryption key dk it obtained y To decrypt the global model gradient ciphertext C(g t-1 ), and obtain the corresponding global model gradient plaintext g t-1 . Subsequently, client u i Based on the global model gradient g t-1 And its local dataset to complete the local model update, obtaining the local model gradient of the t-th round And normalize it;
[0045] E4: Client u i Use the local RSA private key sk i,rsa =(d i , N rsa ) According to To decrypt the global model and obtain the corresponding global model gradient plaintext g t-1 . Subsequently, client u i Based on the global model gradient g t-1 And its local dataset to complete the local model update, obtaining the local model gradient of the t-th round And normalize it.
[0046] E5: Client u i After completing the local training to obtain the local model of the current round and normalizing it, use the function encryption key sk i,mcfe To encrypt the local model and obtain the local model ciphertext ct i,l , and upload it to the blockchain;
[0047] E6: The smart contract traverses each cluster. If the number of clients in cluster cl j >2, then in cluster cl j Except for the cluster center u c Of client u iAdd differential privacy noise to its local model and according to the formula using the cluster center u c 's RSA public key pk c,rsa =(e c , N rsa ) for encryption and upload it to the blockchain, where ε is the differential privacy noise;
[0048] E7: The cluster center client uc of each cluster downloads the noisy ciphertext ct of other clients in the cluster from the blockchain nosie,i , and uses the RSA private key sk c,rsa =(d c , N rsa ) to decrypt according to the formula to obtain the plaintext m of the local model with added noise nosie,i ;
[0049] E8: The cluster center u c adopts the Weiszfeld algorithm to calculate the geometric median of the model gradients of all clients in the cluster cl j and sends the calculated geometric median
[0050] as a function decryption query to the KGC; E9: The KGC receives the decryption query and calculates |cl
[0051] |-1 function decryption keys dk j ={dk j,median |j ∈ [1, n]\{i}}, where where sk i,j is the decryption key of the client u j,i . And distributes them to the cluster center through a secure channel; j,i E10: After receiving the decryption key, the cluster center u
[0052] calculates the cosine similarity between other clients in the cluster and the median gradient according to the formula c . Finally, according to the threshold η distributed by the task issuer on the blockchain, if then mark the client u as malicious, otherwise as a benign client. i
[0053] Step F specifically includes the following steps:
[0054] F1: The system calls the in-class model aggregation smart contract and calculates the aggregated model gradient ciphertext of each cluster cl: in the t-th round of iteration according to the formula Among them, ct i,l is the set of honest clients in the clustering cl j ; the ciphertext of the local model of client u in the set; i is the ciphertext of the local model of client u
[0055] F2: In the t-th round, the system first calls the smart contract to select m clients with the highest R i (t) value (denoted as ), and then the client traverses the ciphertext of the aggregated model gradient of the clustering Client u i selects a d-dimensional all-1 vector and sends a function decryption key query and the set index of the honest client indices of this clustering to the KGC honest,j ;
[0056] F3: After receiving the query, the KGC will determine whether u i is a legitimate client according to the set U when it distributes the encryption key. If it is a legitimate client, the KGC will calculate the function decryption key dk y =[<s k , y)] k∈[1,d] , where is the column vector of S, and the matrix S is composed of the function encryption keys sk j of the honest clients of each clustering cl i as its row vectors s i , and then sends it to client u through a secure channel i ;
[0057] F4: Client u i calculates the aggregated plaintext of each clustering according to the formula
[0058] F5: Client u i calculates the cosine similarity between the global model g of the previous round and the within-cluster aggregated model of each clustering cl t-1 according to the formula j Through the cosine similarity, according to the formula calculates the weight assigned to each clustering cl j where sum cl is the number of clusterings:
[0059] F6: Client u i calculates according to the formula Aggregate the global model with weights. The client ui will use the global model g aggregated in this round t , and use the RSA public keys of n clients. According to the formula , encrypt them respectively and upload them to the blockchain.
[0060] Step G specifically includes the following steps:
[0061] G1: The intelligent contract initializes the DQN state space = [cosine similarity, percentage of malicious times], which is a two-dimensional state vector, where the cosine similarity is The percentage of malicious times is the percentage p of the number of times the client is detected as "malicious". t . And initialize the DQN action space, which is a set of 10 discrete α values;
[0062] G2: For the current state of each client According to the epsilon-greedy decay mechanism, the DQN neural network explores (randomly selects an α value index to obtain more environmental and reward information) and exploits (selects the optimal α value index and uses the information already collected to optimize its strategy), and maps the α value index to the range [0, 1] to obtain the actual α value;
[0063] G3: Calculate the reputation value of the current client u t according to the α i value provided by DQN Update the reputation value R of the client participating in the aggregation according to the historical decay factor β i (t) = β·R t-1 +(1 - β)·R i (t);
[0064] G4: Based on the updated reputation value of the client, the intelligent contract rewards the high-reputation client and saves the reputation value on the chain;
[0065] G5: Use the accuracy of the global model after aggregation as the reward value r t , corresponding to each (state-action) pair (s t , α t ), and then add the state, action, reward value, and next state information (s t , α t , r t , s t+1 ) to the DQN experience replay buffer. DQN continues to train, updates the Q value estimate, and periodically updates the parameters of the target network. Description of the Drawings
[0066] Figure 1 It is a schematic diagram of the system model of the present invention;
[0067] Figure 2 It is the formal definition of the IP-MCFE algorithm of the present invention;
[0068] Figure 3 It is the algorithm step diagram of step D of the present invention;
[0069] Figure 4 It is the algorithm step diagram of step E of the present invention;
[0070] Figure 5 It is the algorithm step diagram of step F of the present invention;
[0071] Figure 6 It is the algorithm step diagram of step G of the present invention;
[0072] Figure 7 It is the training process diagram of DQN in step G of the present invention. Detailed implementation manners
[0073] The following describes the detailed implementation manners of the present invention to facilitate those skilled in the art of the present technology to understand the present invention. However, it should be clear that the present invention is not limited to the scope of the detailed implementation manners. For those of ordinary skill in the art of the present technology, as long as various changes are within the spirit and scope of the present invention defined and determined by the appended claims, these changes are obvious, and all inventions and creations using the concept of the present invention are within the scope of protection.
[0074] For the privacy protection of federated learning, the cryptographic algorithm used in the system is IP-MCFE, which is a multi-client functional encryption algorithm that supports inner product operations. As Figure 2 shown, according to the literature of Abdal1a et al., the formal definition of a multi-client functional encryption algorithm IP-MCFE that supports inner product operations is as follows:
[0075] Definition (multi-client functional encryption supporting inner product): Given a security parameter λ, a multi-client functional encryption algorithm supporting inner product defined on the function family and the tag family consists of five probabilistic polynomial-time algorithms (Setup, KeyGen, Enc, KeyDer, Dec).
[0076] Setup(1 λ , n) → pp. Given the security parameter λ and the number of clients n as inputs, output the public parameter pp.
[0077] Given the security parameter pp as an input, output the master private key mmsk and the client encryption key ).
[0078] Enc(pp, sk i , x i , l) → c i . Given the security parameter pp, the client encryption key sk i , the message x i and the tag output the corresponding ciphertext c i,l .
[0079] KeyDer(pp, msk, f) → sk f. : Given the security parameter pp, the master private key msk and the function as input, output the corresponding function decryption key skf
[0080] Given the security parameter pp, the function decryption key skf and the client ciphertext group as input, output the decryption result y
[0081] As Figure 1 shown, this embodiment consists of five entities, including a key generation center, a client, a consensus node, a blockchain, and an InterPlanetary File System. The specific description is as follows:
[0082] Key Generation Center: The key generation center is a completely trusted third party, and its main responsibility is to distribute the encryption key to the client and the function decryption key
[0083] Client: In the first round of training, the client obtains the initialized global model from the blockchain, and trains the local model based on this model and local data. Subsequently, the client transmits the encrypted local model to the consensus node. In subsequent training rounds, the client first obtains the ciphertext of the global model from the blockchain, decrypts it to complete the model update, and encrypts the new local model and transmits it to the consensus node
[0084] Consensus Node: The consensus node verifies the local model ciphertext uploaded by the client, and completes the consensus on the local model ciphertext through the consensus algorithm, and uploads the result to the chain
[0085] Blockchain: The main function of the blockchain is to store the hash value corresponding to the model in the InterPlanetary File System, and complete the model quality detection, reputation and sharing evaluation, and reward distribution through smart contracts
[0086] InterPlanetary File System IPFS: An end-to-end distributed file system, mainly used to store the local model ciphertext and the global model ciphertext during the federated learning training process
[0087] The process of the incentive-based robust clustering federated learning system based on blockchain proposed by the present invention is as Figure 1As shown below, the detailed workflow is as follows:
[0088] Step A Blockchain system initialization:
[0089] Step A1: Initialize the blockchain to set up the blockchain and initialize its IPFS node;
[0090] Step A2: Register an account for the task issuer and publish the federated learning training task to the blockchain. The task issuer also needs to set the security parameters of the cryptographic algorithm, the hyperparameters of model training, and initialize a global model W0.
[0091] Step A3: Register an account for the client and select whether to participate in the task, and upload the set of participating clients to the blockchain.
[0092] Step B Encryption algorithm initialization:
[0093] Step B1: The KGC initializes the cryptographic algorithm according to the security parameters set by the task issuer and the number n of clients initiating the encryption key query;
[0094] Step B2: Select two large prime numbers p rsa and q rsa , calculate N rsa = p rsa ×q rsa and Z rsa = (p rsa - 1) × (q rsa
[0095] - 1);
[0096] Step B3: Also select two secure prime numbers p mcfe and q mcfe , and satisfy p = 2p mcfe + 1 and q = 2q mcfe + 1 which are also two secure large prime numbers. Then calculate N mcfe = p mcfe ×q mcfe , and select a secure collision-resistant hash function In addition, set Select a public function and set the public parameters as pp = (N mcfe , H, X, L), where represents an element in the multiplicative group modulo N 2 , and n represents XX.
[0097] Step C Key distribution:
[0098] Step C1: For client u i Select one that is coprime to Zrsa Coprime numbers, let it be d i , and find an e i ≡1(modZ rsa ). Then the client's public key pk i,rsa =(e i ,N rsa ), private key sk i,rsa =(d i ,N rsa ). Upload the public keys corresponding to all clients to the blockchain, and send the private keys to the corresponding clients through a secure channel;
[0099] Step C2: KGC is based on the public parameter pp, from the variance Integer Gaussian distribution with mean 0 Select an n×d dimensional matrix S as the master private key msk. Each row of the master private key S matrix is used as the client u i The encryption key sk of (i∈[1,n]) i,mcfe And distribute it to the client through a secure channel. At the same time, record the client set U to which the encryption key is distributed.
[0100] Step D: Hierarchical clustering partitioning client:
[0101] Step D1: Get the initialized global model W0 from the blockchain, then u i Based on its local data, machine learning algorithm, hyperparameters and global model W0=g0, the first round of local model gradient is obtained through training After normalizing the local model gradient, use the function to encrypt the key sk i,mcfe Encrypt the local model, according to the formula Get the local model ciphertext ct i,l , and upload it to the blockchain, where l is the local timestamp of the client;
[0102] Step D2: Each client u i Call the IPFS smart contract to obtain the local model ciphertext of other n-1 clients from IPFS {ct j,l} i∈[1,n]\{i} , where \{i} means excluding the current client u i itself;;
[0103] Step D3: Client u i Use your own RSA encryption algorithm public key pk i,rsa According to the formula Encrypt the local model and get the ciphertext c i . Then the ciphertext c iSent to the KGC as the function decryption key query;
[0104] Step D4: After receiving the decryption key query from the client, the KGC first determines whether it is a legitimate client according to the set U when encrypting the key by the distribution function. If it is a legitimate client, the KGC uses the respective RSA private keys of the clients according to the formula Decrypt the ciphertext c i , to obtain the plaintext queries of each client Subsequently, calculate the n - 1 function decryption keys dk t for each client u i ={dk i,j |j∈[1,n]\{i}}, and return them to the corresponding clients through a secure channel, where dk i,j =[(s j ,y i >], s j is the row vector of the matrix S;
[0105] D5: After receiving the function decryption key sent by the KGC, the client u i calculates the cosine similarity between the local model and the other n - 1 clients according to the formula and uploads the result to the blockchain. Among them, is the cosine similarity between the local model calculated by the client u i and the local model (in ciphertext state) of the client u j , k∈[1,d]. The correctness of the formula is as follows;
[0106]
[0107] represents the product of the component ct j,k,l of the ciphertext gradient of client j in dimension k after being exponentiated by the plaintext gradient component of client i, ct j,k,l represents the encryption result of client j for the k - th dimension gradient , represents using the decryption key dk i,j to eliminate the hash noise term, H(l) is a collision - resistant hash function, input label l, dk i,j represents the decryption key of client i for client j;
[0108] D6: The n*(n - 1) cosine similarity calculation results sent by the n clients received by the blockchain should form a symmetric matrix (with 1s on the diagonal). The smart contract detects whether there are unequal calculation results on the symmetric matrix. If there is cosi,j (t) ≠ cos j,i (t), then it is required that the client u i and the client u j send it back for recalculation until it is correct. Multiple errors are regarded as malicious clients;
[0109] Among them, the symmetric matrix is shown as follows:
[0110]
[0111] D7: The greater the cosine similarity between clients, the higher the similarity, and the smaller the distance between clients in hierarchical clustering. Therefore, the distance between clients is defined as d i,j = 2 - cos i,j (t). The smart contract deployed on the blockchain divides the clients according to the hierarchical clustering algorithm;
[0112] D8: The smart contract obtains the cluster to which each client belongs. If the number of clients in the cluster is greater than 2, find the geometric median point in each cluster, that is, the point with the smallest sum of distances to other clients, as the cluster center of this cluster;
[0113] D9: The blockchain calls the model aggregation smart contract to calculate the ciphertext of the global model gradient at the t-th round of iteration according to the formula and uploads it to the blockchain.
[0114] Step E: Detection of encrypted malicious models:
[0115] E1: If t = 2, the client u i calls the IPFS smart contract to obtain the ciphertext C(g t-1 ) of the global model gradient at the (t - 1)-th round of iteration from IPFS, and then executes steps E2 and E3 to decrypt the global model; otherwise, the client u i calls the IPFS smart contract to obtain the ciphertext C i (g t-1 ) of the global model gradient encrypted with the respective public keys at the (t - 1)-th round of iteration from IPFS, and then executes step E4 to obtain the global model;
[0116] E2: The client u i selects a d-dimensional all-1 vector and sends a function decryption key query to the KGC. After receiving the query, the KGC will judge whether it is a legitimate client according to the set U when it distributes the encryption key. If it is a legitimate client, the KGC will calculate the function decryption key dk y = [<s j , y>] j∈[1,d] , where is the column vector of S, and finally KGC decrypts the function decryption key dk y and returns it to the client u i , where represents a d-dimensional integer vector;
[0117] E3: The client u i According to uses the obtained function decryption key dk y to decrypt the global model gradient ciphertext C(g t-1 ), and obtains the corresponding global model gradient plaintext g t-1 . Subsequently, the client u i completes the local model update based on the global model gradient g t-1 and its local dataset, and obtains the local model gradient of the t-th round and normalizes it;
[0118] E4: The client u i uses the local RSA private key sk i,rsa =(d i , N rsa ) to decrypt the global model according to and obtains the corresponding global model gradient plaintext g t-1 . Subsequently, the client u i completes the local model update based on the global model gradient g t-1 and its local dataset, and obtains the local model gradient of the t-th round and normalizes it.
[0119] E5: After the client u i completes the local training to obtain the local model of the current round and normalizes it, it uses the function encryption key sk i,mcfe to encrypt the local model and obtains the local model ciphertext ct i,l , and uploads it to the blockchain;
[0120] E6: The smart contract traverses each cluster. If the number of clients in the cluster cl j > 2, then for the clients u j in the cluster cl c except for the cluster center u i add differential privacy noise to their local models and encrypt them according to the formula using the RSA public key pk c of the cluster center u c,rsa =(e c , N rsa ), and uploads them to the blockchain, where ε is the differential privacy noise;
[0121] E7: The cluster center client u of each cluster c, download the noisy ciphertext ct of other clients in the cluster from the blockchain nosie,i , use the RSA private key sk c,rsa =(d c , N rsa ) According to the formula decrypt to obtain the plaintext m of the local model with added noise nosie,i ;
[0122] E8: Cluster center u c Adopt the Weiszfeld algorithm to calculate the geometric median of the model gradients of all clients in the cluster cl j and send the calculated geometric median as a decryption query of the function to the KGC;
[0123] E9: The KGC receives the decryption query and calculates |cl j |-1 function decryption keys dk j,median ={dk i,j |j∈[1,n]\{i}}, where where sk j,i is the decryption key of client u j,i . And distribute it to the cluster center through a secure channel;
[0124] E10: After the cluster center uc receives the decryption key, according to the formula calculate the cosine similarity between other clients in the cluster and the median gradient . Finally, according to the threshold η distributed by the task publisher on the blockchain, if then mark the client ui as malicious, otherwise as a benign client.
[0125] Step F Global model robust secure aggregation:
[0126] F1: The system calls the in-class model aggregation smart contract and calculates the aggregated model gradient ciphertext of each cluster clj in the t-th round of iteration according to the formula where, ct is the local model ciphertext of client u i,l in the honest client set j in the cluster cl ; i
[0127] F2: In the t-th round, the system first calls the smart contract to select m clients with the highest R i (t) value (denoted as ), and then client traverses the aggregated model gradient ciphertext of the cluster Client u i Select a d-dimensional all-1 vector And send a function decryption key query and the set of honest client indices index of this cluster to the KGC honest,j ;
[0128] F3: After receiving the query, the KGC will judge whether u is a legitimate client according to the set U when it distributes the encryption key. If it is a legitimate client, the KGC will calculate the function decryption key dk i =[<s y k ,y>] k∈[1,d] , where is the column vector of S, and the matrix S is composed of the honest client function encryption keys sk j of each cluster cl i as its row vector s i , and then send it to the client u through a secure channel i ;
[0129] F4: The client u i Calculate the aggregated plaintext of each cluster according to the formula
[0130] F5: The client u i Calculate the cosine similarity between the global model g in the previous round and the within-cluster aggregated model of each cluster cl t-1 j According to the cosine similarity, calculate the weight assigned to each cluster cl according to the formula j where sum cl is the number of clusters;
[0131] F6: The client u i Aggregate the weighted global model according to the formula The client u i Will encrypt the global model g aggregated in this round t using the RSA public keys of n clients and upload it to the blockchain according to the formula respectively.
[0132] Step G Intelligent Multi-Dimensional Incentive:
[0133] G1: The smart contract initializes the DQN state space = [cosine similarity, percentage of malicious times], which is a two-dimensional state vector, where the cosine similarity is The malicious frequency percentage is the percentage p of the number of times the client is detected as "malicious". t And initialize the DQN action space as a set of 10 discrete α values;
[0134] G2: For the current state of each client Explore (randomly select an α value index) and exploit (select the optimal α value index) according to the epsilon-greedy decay mechanism and the DQN neural network, and map the α value index to the range [0, 1] to obtain the actual α value;
[0135] G3: Calculate the reputation value of the current client u according to the α value provided by DQN t i Update the reputation value R of the clients participating in the aggregation according to the historical decay factor β i (t) = β · R t-1 + (1 - β) · R i (t);
[0136] G4: Based on the updated reputation value of the client, the smart contract rewards the high-reputation clients and saves the reputation value on the chain;
[0137] G5: Use the global model accuracy after aggregation as the reward value r t , corresponding to each (state-action) pair (s t , α t ), and then add the state, action, reward value, and next state information (s t , α t , r t , s t+1 ) to the DQN experience replay buffer. DQN continues to train, update the Q-value estimation, and periodically update the parameters of the target network.
[0138] In summary, the present invention addresses the problem of collaborative modeling of multi-modal psychological data in the cross-institutional psychology research scenario, and proposes an incentive-based robust clustering federated learning system for mental health data. Aiming at the three characteristics of psychological data, namely high sensitivity (such as psychological scales, EEG features, behavioral observation records), strong heterogeneity (different medical institutions adopt different evaluation tools), and dynamic evolution (psychological states fluctuate over time), a three-in-one innovative solution is constructed: First, aiming at the problems that the existing privacy protection technologies induce Byzantine attacks due to reduced data transparency and the traditional defense solutions have single-point failures, a blockchain-based distributed Byzantine tolerance mechanism is constructed. Through the encrypted geometric median calculation and malicious model detection algorithms driven by smart contracts, the detection rate of malicious nodes in the decentralized environment is improved, thereby ensuring the security and reliability of the federated learning participating clients. Aiming at the natural non-independent and identically distributed characteristics of psychological data (such as the fragmentation of the feature space caused by different hospitals adopting different scales such as MMPI and SCL-90), while the federated learning has insufficient adaptability in the non-independent and identically distributed data scenario (Non-IID), a clustering federated learning framework based on multi-client functional encryption is constructed. Through the dynamic weight allocation strategy and the robust security aggregation criterion, secure clustering division and double filtering of malicious clients in the encrypted space are realized, ensuring the synchronous improvement of model efficiency and effect in the heterogeneous data scenario. Finally, aiming at the problem that new participating institutions in mental health research are difficult to obtain fair model usage rights due to lack of historical contributions, an intelligent incentive mechanism based on multi-dimensional reputation evaluation is constructed. Through the contribution-verifiable calculation empowered by blockchain and the strategy optimization driven by reinforcement learning, the dynamic and accurate matching of contribution-return in the privacy protection scenario is realized, ensuring the continuous participation of high-quality honest users and the efficient and healthy development of the system.
Claims
1. An incentive-based robust clustering psychological data federated learning system based on blockchain, characterized in that, It includes the following modules: Blockchain Initialization Module: Establish a blockchain and initialize the IPFS node. The task publisher registers an account and publishes a federated learning task, sets algorithm parameters and initializes the global model. The client registers an account and selects to participate in the task, and uploads the set of participating clients to the blockchain; Multi-Client Function Encryption Module: Adopt a multi-client function encryption algorithm that supports inner product for privacy protection. Determine the number of clients participating in federated learning according to the security parameters of the task publisher. The KGC (Key Generation Center) sets the public parameters pp; Key Distribution Module: The KGC generates a master private key msk and a client encryption key based on the public parameters pp and distributes them to the client through a secure channel; Client Partitioning Module Based on Agglomerative Hierarchical Clustering: In the first round, the client calculates the cosine similarity between its local gradient and those of other clients. The smart contract performs hierarchical clustering to partition the client clusters according to the similarity and determines the cluster centers; Clustering Malicious Client Detection Module Based on Differential Privacy: In subsequent rounds, the client adds differential privacy noise and encrypts and uploads the gradient. The cluster center decrypts it and calculates the geometric median gradient, and filters malicious clients through the cosine similarity threshold; Robust Secure Aggregation Module Based on Weight Allocation: Select high-reputation clients as leader nodes to decrypt the clustered aggregation ciphertext, allocate weights according to the cosine similarity with the global model of the previous round, and weighted-aggregate the global model; Intelligent Incentive Mechanism Module Based on Multiple Reputation Assessments: Calculate the reputation value by combining the client contribution score and the number of malicious times, dynamically adjust the reward weight, train the DQN model to optimize the incentive strategy, update the reputation value and upload it to the chain until the model converges.
2. The incentive-based robust clustering federated learning system based on blockchain according to claim 1, characterized in that: The blockchain initialization module is specifically implemented as follows: Step A1: Initialize the blockchain to build the blockchain and initialize its IPFS node; Step A2: Register an account for the task publisher and publish the federated learning training task to the blockchain. The task publisher sets the security parameters of the cryptographic algorithm, the hyperparameters of model training, and initializes a global model W0; Step A3: Register an account for the client, select whether to participate in the task, and upload the set of participating clients to the blockchain.
3. A blockchain-based incentive robust clustering federated learning system according to claim 1, characterized in that: The specific implementation of the multi-client function encryption module includes the following steps: Step B1: The KGC initializes the cryptographic algorithm according to the security parameters set by the task publisher and the number n of clients that initiate the encryption key query; Step B2: Select two large prime numbers p rsa and q rsa , calculate N rsa = p rsa × q rsa and Z rsa = (p rsa - 1) × (q rsa - 1); Step B3: Select two secure large prime numbers p mcfe and q mcfe , and satisfy p = 2p mcfe +1 and q = 2q mcf e+1. Subsequently, calculate N mcfe = p mcfe ×q mcfe , and select a secure collision-resistant hash function . In addition, set Select a public function and set the public parameters as pp = (N mcfe , H, X, L), where represents an element in the multiplicative group modulo N 2 , and n represents the number of clients participating in federated learning.
4. The incentive-based robust clustering federated learning system based on blockchain according to claim 3, wherein: The specific implementation of the multi-client function encryption module also includes the following steps: Step C1: For client u i Select a number that is relatively prime to Z rsa , and let it be d i , and find an e i ≡1 (mod Z rsa ). Then the public key pk i,rsa of this client is = (e i , N rsa ), and the private key sk i,rsa is = (d i , N rsa ). Upload the public keys corresponding to all clients to the blockchain, and send the private keys to the corresponding clients through a secure channel; Step C2: Based on the public parameters pp, KGC selects an n×d-dimensional matrix S from an integer Gaussian distribution with variance and mean 0 as the master secret key msk, and takes each row of the master secret key S matrix as the encryption key sk of the client u i (i ∈ [1, n]), and distributes it to the client through a secure channel. At the same time, the set U of clients to which the encryption key is distributed is recorded. i,mcfe 5. The incentive-based robust clustering federated learning system based on blockchain according to claim 4, characterized in that: The implementation of the key distribution module includes the following steps: Step D1: Obtain the initial global model W0 from the blockchain, and then u i Based on its local data, machine learning algorithm, hyperparameters, and the global model W0 = g0, train to obtain the local model gradient of the first round Client u i After completing local training to obtain the local model of the current round and normalizing it, use the function encryption key sk i,mcfe Encrypt the local model, according to the formula Obtain the ciphertext ct of the local model i,l , and upload it to the blockchain, where l is the local timestamp of the client, where Represents the local model gradient obtained by client u i In the initial round of training; Step D2: Each client u i invokes the IPFS smart contract to obtain the ciphertexts of the local models of the other n - 1 clients from IPFS, {ct j,l} i∈[1,n]\{i} , where \{i} means excluding the current client u i itself; Step D3: Client u i Uses its own public key pk of the RSA encryption algorithm i,rsa According to the formula Encrypts the local model to obtain the ciphertext c i , and then sends the ciphertext c i As a function decryption key query to the KGC; Step D4: After KGC receives the decryption key query from the client, it first determines whether it is a legitimate client according to the set U when encrypting the key by the distribution function. If it is a legitimate client, KGC uses the respective RSA private keys of the clients to decrypt the ciphertext c according to the formula i , and obtains the plaintext queries of each client Subsequently, it calculates the n - 1 function decryption keys dk i for each client u i ={dk i,j |j ∈ [1, n]\{i}}, and returns them to the corresponding clients through a secure channel, where dk i,j =[<s j , y i >], and s j is the row vector of the master private key matrix S; Step D5: Client u i After receiving the function decryption key sent by the KGC, according to the formula calculate the cosine similarity between the local model and the other n - 1 clients, and upload the result to the blockchain, where is the cosine similarity between the local model calculated by client u i and the local model of client u j in the ciphertext state, k ∈ [1, d], represents the component ct of the ciphertext gradient of client j in dimension k j,k,l is the product of the plaintext gradient component of client i after exponentiation, ct j,k,l represents the encryption result of client j for the k - th dimensional gradient ; represents using the decryption key dk i,j to eliminate the hash noise term, H(l) is a collision - resistant hash function, with input label l, dk i,j represents the decryption key of client i for client j; Step D6: The n*(n - 1) cosine similarity calculation results sent by n clients accepted by the blockchain should form a symmetric matrix. The smart contract checks if there are unequal calculation results on the symmetric matrix. If cos i,j (t) ≠ cos j,i (t), then it requests client u i and client u j to resend the recalculation until it is correct. Multiple errors are regarded as malicious clients; Step D7: The greater the cosine similarity between clients, the higher the similarity, and the smaller the distance between clients in hierarchical clustering. Therefore, the distance between clients is defined as d i,j = 2 - cos i,j (t), and the smart contract deployed on the blockchain divides the clients according to the hierarchical clustering algorithm; Step D8: The smart contract obtains the cluster to which each client belongs. If the number of clients in the cluster is greater than 2, find the geometric median point in each cluster, that is, the point with the smallest sum of distances to other clients, as the cluster center of the cluster; Step D9: The blockchain invokes the model aggregation smart contract to calculate the ciphertext of the global model gradient for the t-th round of iteration according to the formula and uploads it to the blockchain.
6. The incentive-based robust clustering federated learning system based on blockchain according to claim 1, wherein: The specific implementation of the clustering malicious client detection module based on differential privacy includes the following steps: Step E1: If t = 2, client u i invokes the IPFS smart contract to obtain the ciphertext C(g t-1 ) of the global model gradient in the (t - 1)-th iteration from IPFS, and then executes Steps E2 and E3 to decrypt the global model; otherwise, client u i invokes the IPFS smart contract to obtain the ciphertext C i (g t-1 ) of the global model gradient encrypted with the respective public keys in the (t - 1)-th iteration from IPFS, and then executes Step E4 to obtain the global model; Step E2: Client u i Select a d-dimensional all-ones vector and send a function decryption key query to the KGC. After receiving the query, the KGC will determine whether it is a legitimate client based on the set U when distributing the encryption key. If it is a legitimate client, the KGC will calculate the function decryption key dk y =[<s j , y>] j∈[1,d] , where is a column vector of S. Finally, the KGC will return the function decryption key dk y to client u i , where represents a d-dimensional integer vector; Step E3: Client u i According to Use the function decryption key dk obtained by it y Decrypt the global model gradient ciphertext C(g t-1 ), and obtain the corresponding global model gradient plaintext g t-1 , then client u i Based on the global model gradient g t-1 And its local dataset to complete the local model update, obtaining the local model gradient of the t-th round And normalize it; Step E4: Client u i uses the local RSA private key sk i,rsa =(d i , N rsa ) to decrypt the global model and obtain the corresponding plaintext of the global model gradient g Then, client u t-1 updates the local model based on the global model gradient g i and its local dataset to obtain the local model gradient at the t-th round t-1 and normalizes it: Step E5: Client u i After completing local training to obtain the local model of the current round and normalizing it, use the function encryption key sk i,mcfe to encrypt the local model and obtain the ciphertext ct of the local model i,l , and upload it to the blockchain; Step E6: The smart contract traverses each cluster. If the number of clients in cluster cl j > 2, then for the clients in cluster cl j except the cluster center u c client u i adds its local model with differential privacy noise and, according to the formula uses the RSA public key pk c of the cluster center u c,rsa =(e c , N rsa ) to encrypt and upload it to the blockchain, where ε is the differential privacy noise; Step E7: The cluster center client u of each cluster c , downloads the noise ciphertext ct of other clients in the cluster from the blockchain nosie,i , and uses the RSA private key sk c,rsa =(d c , N rsa ) to decrypt according to the formula , and obtains the plaintext m of the local model with added noise nosie,i ; Step E8: Clustering center u c Use the Weiszfeld algorithm to calculate the geometric median of all client model gradients in cluster cl j And send the calculated geometric median as a function decryption query to the KGC; Step E9: KGC receives a decryption query and calculates |cl j |-1 function decryption keys dk j,median ={dk i,j |j ∈ [1, n]\{i}}, where where sk j,i is the decryption key of client u j,i and is distributed to the clustering center through a secure channel; Step E10: Clustering center u c After receiving the decryption key, according to the formula Calculate the cosine similarity between other clients within the cluster and the median gradient , and finally, according to the threshold η distributed by the task issuer on the blockchain, if then mark the client u i as malicious, otherwise as a benign client.
7. The incentive-based robust clustering federated learning system based on blockchain according to claim 1, characterized in that: The robust secure aggregation module based on weight allocation specifically includes the following steps: Step F1: The system calls the in-class model aggregation smart contract and calculates the aggregated model gradient ciphertext of each cluster cl in the t-th round of iteration according to the formula where Ct j is the ciphertext of the local model of client u in the set of honest clients in cluster cl where Ct i,l is the set of honest clients in cluster cl j and is the ciphertext of the local model of client u i in it; Step F2: In the t-th round, the system first calls the smart contract to select m clients with the highest R i (t) values, denoted as Subsequently, the client traverses the ciphertext of the aggregated model gradient of the cluster Client u i selects a d-dimensional all-1 vector and sends a function decryption key query and the set index of honest clients in this cluster to the KGC honest,j ; Step F3: After receiving the query, KGC will determine u based on the set U when it distributes the encryption key i Is it a legitimate client? If it is a legitimate client, KGC will calculate the function decryption key dk y =[ k ,y>] k∈[1,d] ,in is a column vector of S, the matrix S consists of each cluster cl i The honest client function encryption key sk i As its row vector s i Then it is sent to the client u through a secure channel i ; Step F4: Client u i According to the formula Calculate the aggregated plaintext of each cluster Step F5: Client u i According to the formula Calculate the global model g of the previous round t-1 And each cluster cl j Cosine similarity of the intra-cluster aggregation model Through cosine similarity, according to the formula Calculate each cluster cl j Allocated weight Where sum cl Is the number of clusters; Step F6: Client u i According to the formula Aggregate the global model with weights. Client u i Regarding the global model g aggregated in this round t , using the RSA public keys of n clients, according to the formula Encrypt them separately and upload them to the blockchain.
8. A blockchain-based incentive robust clustering federated learning system according to claim 1, characterized in that: The intelligent incentive mechanism module based on multiple reputation assessments specifically includes the following steps: Step G1: Initialize the DQN state space = [cosine similarity, percentage of malicious times], which is a two-dimensional state vector, where the cosine similarity is The percentage of malicious times is the percentage p of the number of times the client is detected as "malicious". t , and initialize the DQN action space, which is a set of 10 discrete α values; Step G2: For the current state of each client According to the epsilon-greedy decay mechanism, the DQN neural network explores and exploits, and maps the α value index to the range of [0, 1] to obtain the actual α value; Step G3: Calculate the reputation value of the current client u according to the α value provided by DQN t Value i Of Update the reputation value R of the clients participating in the aggregation according to the historical decay factor β i (t) = β · R t-1 +(1 - β) · R i (t); Step G4: Based on the updated reputation value of the client, the smart contract rewards high-reputation clients and saves the reputation value on the chain; Step G5: Use the global model accuracy after aggregation as the reward value r t , corresponding to each (state-action) pair (s t , α t ), and then add the state, action, reward value, and next state information (s t , α t , r t , s t+1 ) to the DQN experience replay buffer, and the DQN continues to train, update the Q-value estimate, and periodically update the parameters of the target network.
Citation Information
Cited By
Dynamic incentive federal learning method based on trusted execution environment and block chain
CN120875092A
Semantic communication large model knowledge base security synchronization method and system based on password
CN121309601A