Minkowski distance-based federal learning backdoor defense method

Through the federated learning defense framework of sparse training and Minkovsky distance score, the backdoor attack detection problem in high-dimensional space is solved, achieving more efficient model security and accuracy.

CN120296727APending Publication Date: 2025-07-11KUNMING UNIV OF SCI & TECH

Patent Information

Application Number
CN202510385701.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-29
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The existing federated learning backdoor attack detection method is difficult to distinguish between normal updates and malicious updates in high-dimensional space, resulting in a decrease in detection accuracy, and attackers evade detection by making the backdoor model very similar to the normal model.

Method used

A federated learning adaptive backdoor defense framework based on sparse training and Minkovsky distance is adopted. By sparse global models, using Minkovsky distance score and gradient change cumulative value pruning technology, malicious model updates are eliminated, and the model is optimized to resist backdoor attacks.

Benefits of technology

It effectively improves the security and reliability of the federated learning model, reduces the training burden of client models and the transmission pressure of model parameters, and improves the defense ability of backdoor attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296727A_ABST
    Figure CN120296727A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of information security, and discloses a Minkowski distance-based federated learning backdoor defense method, which comprises the following steps of S1, constructing a federated learning adaptive backdoor defense framework based on sparse training and Minkowski distance detection, and acquiring image data from an image public data set; adding a backdoor trigger to the image data to obtain poisoning image data injected into a backdoor, and dividing an image data set and a normal image data set into a training set, a verification set and a test set; according to the Minkowski distance-based federated learning backdoor defense method, the training burden of a client model is reduced by using a sparse training mode, the transmission pressure of excessive model parameters between the server and the client is relieved, the score is updated by using the Minkowski distance-based model, and the defensive performance of the model is improved. And possible malicious model updating is eliminated, so that backdoor attacks are effectively relieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security, and particularly to a federated learning backdoor defense method based on the Minkowski distance. Background Art

[0002] As an emerging distributed machine learning paradigm, federated learning enables different clients to collaboratively train to obtain a globally shared model without sharing local private data. Specifically, the server distributes the global model to the clients, and the clients use local data to train the model and upload the updated local model to the server for aggregation. The mechanism that the client only shares the model update without involving local data enables federated learning to protect the privacy of client data and has received wide attention. Due to its distributed characteristics, federated learning is vulnerable to backdoor attacks. An attacker injects a backdoor into the model to achieve normal behavior for benign inputs, while showing specific malicious behavior for inputs with triggers. Initially, backdoor attacks were mainly studied for deep neural networks (DNNs), and later researchers introduced them into federated learning. Since the training process of federated learning is invisible, compared with DNNs, backdoor attacks are more destructive in federated learning. An attacker can control local clients to train on data with triggers or manipulate model weights to implant a backdoor into the local model and then embed it into the global model through aggregation. Common backdoor attacks are mainly divided into data-level backdoor attacks and model-level backdoor attacks. In the former, the attacker injects a carefully designed trigger into the user's dataset, including Badnets and distributed backdoor attacks (DBA), etc. In the latter, the attacker can directly tamper with the algorithm or weights of the local model to implant a backdoor into the model, including model replacement, etc. The above attack behaviors pose a huge threat to the deployment of federated learning, such as:

[0003] Currently, for backdoor attacks on federated learning, most detection methods use anomaly detection techniques to determine whether the global model is under a backdoor attack and use specific metrics to distinguish malicious updates from normal updates, so as to identify potential malicious clients. To avoid being easily detected, attackers often make the model implanted with a backdoor very similar to the normal model in terms of gradients and weights. Since anomaly detection techniques are very sensitive to data distribution, especially in high-dimensional spaces, as the dimension increases, the calculation of distance may lead to the "curse of dimensionality" phenomenon, making the distance difference between normal updates and malicious updates in high-dimensional model updates may become unclear, thus affecting the detection accuracy.

[0004] In view of the above problems, there is an urgent need to innovate and design on the basis of the original backdoor attack detection method. Summary of the Invention

[0005] The purpose of the present invention is to provide a federated learning backdoor defense method based on the Minkowski distance to solve the problem in the above-mentioned background technology that existing detection methods are difficult to identify the disguises of malicious models. Among them, in order to evade detection, the attacker makes the model implanted with the backdoor extremely similar to the normal model in terms of gradients and weights, increasing the detection difficulty. Moreover, most detection methods rely on anomaly detection techniques and are sensitive to data distributions. In a high-dimensional space, the data distribution is complex, and the distance calculation is easily affected by the "curse of dimensionality", resulting in difficulty in distinguishing the distance difference between normal updates and malicious updates and reducing the detection accuracy.

[0006] To achieve the above object, the present invention provides the following technical solution: A federated learning backdoor defense method based on the Minkowski distance, comprising the following steps:

[0007] S1: Construct a federated learning adaptive backdoor defense framework based on sparse training and Minkowski distance detection, obtain image data from an image public dataset; add a backdoor trigger to the image data to obtain poisoned image data injected with the backdoor, and divide the image dataset and the normal image dataset into training sets, validation sets, and test sets;

[0008] S2: Model initialization: Initialize a global model on the server side of the federated learning framework;

[0009] S3: Sparsify the global model based on the ERK sparsification strategy: Based on the ERK-based random sparsification method, an optimized update rule is proposed. After the server side sparsifies the global model using the sparsification strategy, it is sent to the selected client for subsequent training;

[0010] S4: The client receives the model sent by the server side, trains the model using local private data, and uploads the model update to the server after training according to the local training rounds;

[0011] S5: Repeat S4 until all the selected clients have completed local training and uploaded the model updates to the server side;

[0012] S6: The server side receives the model updates from all the selected clients, then uses the Minkowski distance to evaluate the scores of all the model updates, and eliminates the model updates with abnormal scores proportionally. The server side uses the average aggregation algorithm to aggregate the remaining model updates to obtain a new aggregated global model;

[0013] S7: Pruning: The server calculates the gradient change values of the model parameters based on the model updates of each client, and then calculates the cumulative values of the gradient changes of each parameter. Based on this, the model parameters are pruned by trimming the parameters with smaller cumulative gradient changes and only retaining the parameters with larger cumulative gradient changes. Then, the pruned parameters are restored to obtain a globally pruned model.

[0014] S8: Repeat S3 to S6 until the total number of rounds required by the federated learning framework is completed, and finally obtain a globally shared federated learning backdoor defense model.

[0015] S9: Input the image data of the test set in S1 into the trained federated learning backdoor defense model for defense effect testing.

[0016] By adopting the above technical solution, through multiple iterative trainings, the model is continuously updated and optimized, so that the finally obtained globally shared federated learning backdoor defense model can better resist backdoor attacks and ensure the security and reliability of the model in the federated learning environment.

[0017] Preferably, the specific steps of S1 include:

[0018] S1.1: Build a complete federated learning framework and add a globally sparse model module based on the ERK sparsification strategy, a malicious model update detection module based on the Minkowski distance, and an adaptive pruning module based on the cumulative gradient change value.

[0019] S1.2: Obtain the MNIST, FMNIST, and CIFAR-100 datasets from the publicly available image datasets.

[0020] S1.3: Add different backdoor triggers, including pixel blocks, watermarks, and noises, to each dataset for data contamination to obtain poisoned datasets. Then, combine the poisoned datasets and normal datasets in different proportions to obtain datasets with different poisoning ratios. Next, divide the obtained datasets into training sets, validation sets, and test sets.

[0021] By adopting the above technical solution, different degrees of backdoor attack scenarios are simulated by adding different backdoor triggers and combining poisoned datasets and normal datasets in different proportions, which helps the model learn the characteristics of various backdoor attacks and improves the defense ability of the model.

[0022] Preferably, the specific steps of S2 are: Initialize the model. For the MNIST dataset, a multi-layer perceptron model composed of two linear layers is used; for the FMNIST dataset, the LeNet model is used; for the CIFAR-100 dataset, the ResNet9 model is used.

[0023] Adopting the above technical solution, selecting a suitable model for different data sets can give full play to the advantages of each model, improve the performance of the model on different data sets, and thus better resist backdoor attacks.

[0024] Preferably, the specific steps of S3 are as follows: after obtaining the global model, different sparsities are assigned to different layers according to the ERK sparsification rule;

[0025] ERK sparsification rule: Given a data set D, where the target label corresponding to a single sample is x i , the goal is to minimize the loss function ∑ i L(f Θ (x i ), y i ), where f Θ (·) is a neural network, and the parameters of the l-th layer are represented by a vector Θ l of length N l . The sparse layer only retains a small part s l ∈ (0, 1) of its connections, and uses a vector θ l of length (1 - s l )N l for parameterization. θ represents the parameters of the sparse network. Define 1 and 0 parameters for each parameter to represent the retention and discard of the neural network parameters. Finally, the overall sparsity of the sparse network is defined as the ratio of the number of 0 parameters to the total number of parameters In the ERK method, the kernel dimension is used to modify the original formula. Specifically, the number of parameters of the sparse convolutional layer is scaled proportionally to the number of 1 parameters, where w and h l are the width and height of the l-th convolutional kernel. ERK assigns a higher sparsity to the layer with more parameters and a lower sparsity to the smaller layer;

[0026] The sparse model will perform subsequent pruning and recovery of parameters and connections according to the gradient at regular intervals. After updating the parameters and connections, continue training with the updated neural network until the next update;

[0027] Update scheduling rule: The update scheduling is defined by the following parameters: (1) T: the number of iterations between sparse connection updates, (2) T end : the number of iterations to stop updating sparse connections, (3) α: the initial score of the updated connections, and (4) f decay : the function called at each iteration before T end that may decay the score of the updated connections over time. For the f decay function, the present invention selects an optimized exponential decay strategy:​

[0028]

[0029] Sparsify the model using a binary mask. The rule is to keep the parameters with a mask of 1 and discard the parameters with a mask of 0:

[0030]

[0031] Finally, obtain the global model sparsified using the ERK strategy.

[0032] Adopt the above technical solution to prune and recover parameters and connections according to the gradient at regular intervals, and update the connection scores using the optimized exponential decay strategy, enabling the model to dynamically adapt to changes during the training process, avoiding overfitting, and improving the generalization ability and defense ability of the model.

[0033] Preferably, the specific steps of S4 are as follows: The client receives the model sent by the server and trains the model using local private data. The expression formula for the process is

[0034]

[0035] In the formula, represents the model parameters of client i at the t-th iteration, η is the learning rate, is the gradient calculated on client i with respect to the current model and m i,t represents the intermediate mask.

[0036] Adopt the above technical solution to determine the specific formula for the client to train the model using local private data, making the training process of the client quantifiable and repeatable, helping to improve the accuracy and consistency of model training. At the same time, through the use of the intermediate mask, the update of model parameters is further controlled, enhancing the security of the model.

[0037] Preferably, the specific steps of S5 are as follows: Conduct local training on all selected clients. After completing the specified number of rounds, upload the model update to the server. The expression formula for the process is Δw t (i) = w t+1 (i) - w t (i).

[0038] Adopt the above technical solution to clarify the process formula for the client to upload the model update to the server after completing local training, ensuring the standardization and accuracy of data transmission and model update between the client and the server, enabling the entire federated learning process to proceed orderly.

[0039] Preferably, the specific steps of S6 are as follows: after the server receives the updated sparse training model from the client, the Minkowski distance with dynamic weighting is used to evaluate the score of each model update, and possible malicious model updates are eliminated. The expression formula of the process is

[0040]

[0041] In the formula, Δw t represents the update of the global model in the t-th round, u is the number of clients, and q is the order of the Minkowski distance;

[0042] According to the Minkowski distance, the anomaly score of all uploaded models is evaluated, and a score threshold is set to determine malicious updates. If the weighted score of a certain client is greater than the threshold, the update is considered malicious. After eliminating possible malicious model updates, the average aggregation algorithm is used to aggregate the remaining model updates to obtain a globally shared model. The expression formula of the process is

[0043]

[0044] In the formula, M is the number of clients, and α i is the weighted coefficient assigned by the server to the i-th user, satisfying

[0045] Adopting the above technical solution, after eliminating malicious model updates, the average aggregation algorithm is used to aggregate the remaining model updates, which can make full use of the model update information of normal clients to obtain a more reliable globally shared model, ensuring the performance and stability of the model.

[0046] Preferably, the specific steps of S7 are as follows: in the globally shared model, the importance of parameters is judged according to the cumulative value of the gradient change of each parameter, and the model parameters are pruned to further eliminate possible malicious parameters;

[0047] The pruning method prunes the parameters with the smallest percentage of the absolute value of the cumulative gradient change in each layer, and updates m i,t+1 :

[0048]

[0049] In the formula, returns the coordinates with the smallest percentage of the absolute value of the cumulative gradient change in each layer and masks them as 1, indicating that they will be pruned. Then, the parameters are restored:

[0050]

[0051] In the formula, Return the coordinates of the maximum percentage of the cumulative gradient change value for each layer, and mask them as 1, indicating that these parameters will be restored. After the pruning process, a new global shared model without backdoor parameters is obtained.

[0052] Adopting the above technical solution, parameter restoration is performed after pruning, which can retain the parameters important for model training, avoid the decline of model performance caused by excessive pruning, and ensure the effectiveness and stability of the model.

[0053] Preferably, the specific steps of S8 are as follows: Repeat S3 to S6 until the total number of rounds required for the federated learning framework is completed. After each iterative training, the validation set in the dataset is used to verify the effect of the model to prevent overfitting problems. Finally, a global shared federated learning backdoor defense model is obtained.

[0054] Adopting the above technical solution, by repeatedly performing steps S3 to S6 multiple times and continuously updating and optimizing the model, the model can continuously learn and improve throughout the process of federated learning, and finally a better global shared federated learning backdoor defense model is obtained.

[0055] Preferably, the specific steps of S9 are as follows: Use the test set in the dataset to test the model, test the main task accuracy and ASR of the model, and compare the main task accuracy and ASR results with other tested models.

[0056] Adopting the above technical solution, using the test set to test the main task accuracy and backdoor attack success rate of the model and comparing with other tested models can intuitively quantify the defense effect of the model, evaluate the performance of the model in resisting backdoor attacks, and provide a strong basis for the improvement and optimization of the model.

[0057] Compared with the prior art, the beneficial effects of the present invention are as follows: The federated learning backdoor defense method based on the Minkowski distance:

[0058] By using the method of sparse training to reduce the burden of client model training and alleviate the transmission pressure of excessive model parameters between the server and the client, and by using the model update score based on the Minkowski distance to eliminate possible malicious model updates, the backdoor attack is effectively mitigated. Pruning is performed using the cumulative value of historical gradient changes to effectively remove backdoor parameters. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] Figure 1 It is a flowchart of the present solution of the present invention;

[0060] Figure 2 It is an overall framework diagram of the present solution of the present invention;

[0061] Figure 3This is a comparison of the convergence effect of the proposed solution of the present invention with other test models. Detailed implementation manners

[0062] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0063] Please refer to Figures 1 - 3 , the present invention provides a technical solution: a federated learning backdoor defense method based on Minkowski distance, including the following steps;

[0064] S1: Construct a federated learning backdoor defense framework based on sparse training and Minkowski distance detection, and obtain image data from the image public dataset;

[0065] Add a backdoor trigger to the image data to obtain poisoned image data injected with the backdoor, and divide the image dataset and the normal image dataset into training set, validation set and test set;

[0066] As shown in the accompanying drawings of the specification Figure 2 , the federated learning backdoor defense model includes a sparse training module, a malicious model update detection module based on Minkowski distance, and a pruning module based on the cumulative value of historical gradient changes;

[0067] The present invention selects MNIST, FMNIST and CIFAR-100 image data from the image public dataset, performs backdoor poisoning on the above three types of image data, implants the backdoor by adding a trigger to the picture data, and selects pixel blocks, watermarks and noises as the three triggers to contaminate the data in different types, so as to obtain different backdoor image data of the three datasets, and combines the poisoned image dataset and the normal image dataset in a ratio of 1:1 to obtain a combined dataset, and then divides the dataset into training set, validation set and test set;

[0068] S2: Model initialization: Initialize a global model on the server side of the federated learning framework;

[0069] Since the present invention uses different neural network models for different datasets, for the MNIST dataset, a multi-layer perceptron model composed of two linear layers is used;

[0070] For the FMNIST dataset, the LeNet model is used;

[0071] For the CIFAR-100 dataset, the ResNet9 model was used;

[0072] S3: Sparsify the global model based on the optimized ERK sparsification strategy: Based on the ERK-based random sparsification method, an optimized ERK sparsification strategy was proposed. After the server sparsifies the global model using the optimized strategy, it sends it to the selected clients for subsequent training;

[0073] Combined with the Figure 2 As shown in the sparsification training part of the accompanying drawings of the specification, use the ERK sparsification strategy on the server side and use the mask m i,t to sparsify the model:

[0074]

[0075] Then, use the optimized update rule:

[0076]

[0077] Sparsify the global model according to this strategy and send the obtained model to the selected clients. This can prevent malicious clients from obtaining all the model parameters at once to design more concealed backdoors, and at the same time can reduce the transmission burden;

[0078] S4: The client receives the model sent by the server, sets the loss function of the client model, trains the model using local private data, and uploads the model update to the server after completion according to the local training rounds;

[0079] In step S4, the loss function set for the model is the cross-entropy function, and its expression formula is

[0080]

[0081] In the formula, y is the vector of the true label, y c is the probability of the label class c, usually 1 or 0, indicating whether the sample belongs to class c, Υ is the probability distribution predicted by the model, Υ c is the predicted probability of the model for class c, and C is the number of classes;

[0082] The expression formula for its training process is

[0083]

[0084] In the formula, represents the model parameters of client i at the t-th iteration, η is the learning rate, is the gradient calculated on client i with respect to the current model , Represents the intermediate mask;

[0085] S5: Repeat S4 until all the selected clients have completed local training and uploaded the model updates to the server side;

[0086] The expression formula for the client model update is

[0087] Δw t (i) = w t+1 (i) - w t (i)

[0088] S6: The server side receives the model updates from all the selected clients, then uses the Minkowski distance to evaluate the scores of all the model updates, and eliminates the model updates with abnormal scores proportionally; the server side uses the average aggregation algorithm to aggregate the remaining model updates to obtain a new aggregated global model;

[0089] The expression formula for evaluating the scores of all the model updates using the Minkowski distance is

[0090]

[0091] In the formula, M represents the number of clients, and q represents the order of the Minkowski distance;

[0092] Because many data in real life do not meet the requirements of independent and identically distributed, the present invention proposes to use a dynamic distance score evaluation method, introducing a dynamic coefficient β:

[0093]

[0094] In the formula, D i represents the amount of data owned by the client, D represents the total amount of data, and α represents the score proportion; the final score evaluation expression formula is

[0095]

[0096] Eliminate the possible malicious model updates according to the scores, and only aggregate the remaining benign model updates:

[0097]

[0098] In the formula, p represents the proportion of the number of malicious model updates eliminated to the total number of model updates;

[0099] S7: Pruning: The server calculates the gradient change values of the model parameters based on the model updates of each client, and then calculates the cumulative values of the gradient changes of each parameter, so as to prune the model parameters, pruning the parameters with smaller cumulative gradient change values and only retaining the parameters with larger cumulative gradient change values, and then restoring the pruned parameters to obtain a globally pruned model;

[0100] Specifically, the pruning method prunes the parameters with the smallest percentage of the absolute value of the cumulative gradient change in each layer and updates m accordingly i,t+1 :

[0101]

[0102] In the formula, Returns the coordinates of the smallest percentage of the absolute value of the cumulative gradient change in each layer and masks them as 1, indicating that they will be pruned;

[0103] Then, restore the parameters:

[0104]

[0105] In the formula, Returns the coordinates of the largest percentage of the absolute value of the cumulative gradient change in each layer and masks them as 1, indicating that these parameters will be restored;

[0106] S8: Repeat S3 to S6 until the total number of rounds required by the federated learning framework is completed, and finally obtain a globally shared federated learning backdoor defense model;

[0107] S9: Input the image data of the test set in S1 into the trained federated learning backdoor defense model for defense effect testing;

[0108] Specifically, use the test sets in the three datasets to test the model, test the main task accuracy and ASR of the model, and compare the main task accuracy and ASR results with other test models;

[0109] The experiment was completed on an experimental system of Ubuntu 22.04-bit Linux, an NVIDIA GeForce RTX 4090 GPU with 24GB of memory, and the PyTorch framework. The environment was configured with CUDA 12.2 and torch 2.3.0. The initial learning rate was set to 0.1. The main task accuracy and the success rate of the backdoor attack were used as the evaluation indicators of the experiment;

[0110] In specific implementation, the comparison results of the model performance between the present invention and other test models are shown in Table 1 of the following table, where MA is the accuracy of the main task. The higher the index of MA indicates the higher the classification accuracy of the main task of the model, and the lower the ASR indicates the better the effect of the model in defending against backdoor attacks. In addition, as shown in Figure 3 of the accompanying drawings of the specification, the convergence speeds between different models are also compared.

[0111] Table 1

[0112]

[0113] In specific implementation, the present invention is compared with other test models in terms of the defense results. From the comparison results, it can be seen that the method proposed by the present invention can keep the ASR as small as possible while ensuring that the accuracy of the main task is the same as that of other methods, so as to achieve a better defense performance.

[0114] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention.

Claims

1. A backdoor defense method for federated learning based on Minkowski distance, characterized in that It includes the following steps: S1: Construct a federated learning adaptive backdoor defense framework based on sparse training and Minkowski distance detection, obtain image data from the public image dataset; add backdoor triggers to the image data to obtain poisoned image data with injected backdoors, and divide the image dataset and the normal image dataset into training sets, validation sets, and test sets; S2: Model initialization: Initialize a global model on the server side of the federated learning framework; S3: Sparsify the global model based on the ERK sparsification strategy: Based on the ERK-based random sparsification method, an optimized update rule is proposed. After the server side sparsifies the global model using the sparsification strategy, it sends it to the selected client for subsequent training; S4: The client receives the model sent by the server side, trains the model using local private data, and uploads the model update to the server after completing the training according to the local training rounds; S5: Repeat S4 until all the selected clients have completed local training and uploaded the model updates to the server side; S6: The server side receives the model updates from all the selected clients, then uses the Minkowski distance to evaluate the scores of all the model updates, and eliminates the model updates with abnormal scores proportionally. The server side uses the average aggregation algorithm to aggregate the remaining model updates to obtain a new aggregated global model; S7: Pruning: The server calculates the gradient change values of the model parameters based on the model updates of each client, and then calculates the cumulative values of the gradient changes of each parameter, so as to prune the model parameters, pruning off the parameters with smaller cumulative gradient changes and only retaining the parameters with larger cumulative gradient changes, and then restoring the pruned parameters to obtain a pruned global model; S8: Repeat S3 to S6 until the total number of rounds required by the federated learning framework is completed, and finally obtain a globally shared federated learning backdoor defense model; S9: Input the image data in the test set in S1 into the trained federated learning backdoor defense model to test the defense effect.

2. The method for defending against backdoors in federated learning based on the Minkowski distance according to claim 1, wherein: The specific steps of S1 include: S1.1: Build a complete federated learning framework and add a module for sparsifying the global model based on the ERK sparsification strategy, a module for detecting malicious model updates based on the Minkowski distance, and a module for adaptive pruning based on the cumulative gradient change value; S1.2: Obtain the MNIST, FMNIST, and CIFAR-100 datasets from the public image dataset; S1.3: Add different backdoor triggers, including pixel blocks, watermarks, and noises, to each dataset respectively to contaminate the data, obtain poisoned datasets, then combine the poisoned datasets and the normal datasets in different proportions to obtain datasets with different poisoning proportions, and then divide the obtained datasets into training sets, validation sets, and test sets.

3. A backdoor defense method for federated learning based on Minkowski distance according to claim 1, characterized in that: The specific steps of S2 are: Initialize the model. For the MNIST dataset, a multi-layer perceptron model composed of two linear layers is used; For the FMNIST dataset, the LeNet model is used; For the CIFAR-100 dataset, the ResNet9 model is used.

4. A federated learning backdoor defense method based on Minkowski distance according to claim 1, characterized in that: The specific steps of S3 are as follows: After obtaining the global model, different sparsities are assigned to different layers according to the ERK sparsification rule; ERK sparsification rule: Given a dataset D, where the target label corresponding to a single sample is x i , the goal is to minimize the loss function ∑ i L(f Θ (x i ),y i ), where f Θ (·) is a neural network, and the parameters of the lth layer are expressed by length N l The vector Θ l Indicates that the sparse layer only retains a small portion s of its connections l ∈(0,1), and use a length of (1 s l )N l The vector θ l Parameterize, θ represents the parameters of the sparse network, define 1 and 0 parameters for each parameter to indicate the retention and discard of neural network parameters, and finally, define the overall sparsity of the sparse network as the ratio of the number of 0 parameters to the total number of parameters In the ERK method, the kernel dimension is used to modify the original Formula, specifically, the number of parameters of the sparse convolutional layer is proportional to the number of parameters Proportional scaling, where w l and h l is the width and height of the lth convolution kernel. ERK assigns higher sparsity to layers with more parameters and lower sparsity to smaller layers. The sparse model will perform subsequent pruning and recovery of parameters and connections according to the gradient at regular intervals. After updating the parameters and connections, the updated neural network is used to continue training until the next update; Update scheduling rules: The update scheduling is defined by the following parameters: (1) T: the number of iterations between sparse connection updates, (2) T end : the number of iterations to stop updating the sparse connection, (3) α: the initial score of the updated connection, and (4) f decay : the function called at each iteration before T end that may decay the score of the updated connection over time. For the f decay function, the present invention selects an optimized exponential decay strategy: The binary mask is used for model sparsification. The rule is that the parameters with the mask value of 1 are retained, and the parameters with the mask value of 0 are discarded: Finally, the global model sparsified using the ERK strategy is obtained.

5. A backdoor defense method for federated learning based on the Minkowski distance according to claim 1, characterized in that: The specific steps of S4 are as follows: The client receives the model sent by the server and trains the model using local private data. The expression formula of the process is: In the formula, represents the model parameters of client i at the t-th iteration, η is the learning rate, is the gradient calculated on client i with respect to the current model , and m i,t represents the intermediate mask.

6. A backdoor defense method for federated learning based on the Minkowski distance according to claim 1, characterized in that: The specific steps of S5 are as follows: perform local training on all selected clients, and after completing the specified number of rounds, upload the model update to the server. The expression formula for this process is Δw t (i) = w t+1 (i) - w t (i).

7. A backdoor defense method for federated learning based on Minkowski distance according to claim 1, characterized in that: The specific steps of S6 are as follows: After the server receives the updated sparsified training model from the client, the dynamic weighted Minkowski distance is used to evaluate the score of each model update, and possible malicious model updates are removed. The expression formula of the process is: where, Δw t represents the update of the global model at the t-th round, u is the number of clients, and q is the order of the Minkowski distance; The anomaly score of all uploaded models is evaluated according to the Minkowski distance. A score threshold is set for the determination of malicious updates. If the weighted score of a certain client is greater than the threshold, it is considered that the update is malicious. After removing possible malicious model updates, the average aggregation algorithm is used to aggregate the remaining model updates to obtain the global shared model. The expression formula of the process is where M is the number of clients, and α i is the weighting factor assigned by the server to the i-th user, satisfying 8. A backdoor defense method for federated learning based on Minkowski distance according to claim 1, characterized in that: The specific steps of S7 are as follows: In the global shared model, the importance of parameters is judged according to the cumulative value of the gradient change of each parameter, and the model parameters are pruned to further eliminate possible malicious parameters; The pruning method prunes the parameters with the smallest percentage of the absolute value of the cumulative gradient change in each layer and updates m accordingly i,t+1 : Wherein, Return the coordinates of the smallest percentage of the absolute value of the cumulative gradient change for each layer, mask it as 1, indicating that it will be pruned, and then restore the parameters: In the formula, Returns the coordinates of the maximum percentage of the cumulative gradient change value for each layer, and masks them as 1, indicating that these parameters will be restored. After the pruning process, a new global shared model without backdoor parameters is obtained.

9. A backdoor defense method for federated learning based on the Minkowski distance according to claim 1, characterized in that: The specific steps of S8 are as follows: Repeat S3 to S6 until the total number of rounds required by the federated learning framework is completed. After each iterative training, the validation set in the dataset is used to verify the effect of the model to prevent overfitting problems. Finally, a global shared federated learning backdoor defense model is obtained.

10. A federated learning backdoor defense method based on the Minkowski distance according to claim 1, characterized in that: The specific steps of S9 are as follows: The test set in the dataset is used to test the model, and the main task accuracy and ASR of the model are tested, and the main task accuracy and ASR results are compared with other test models.

Citation Information

Patent Citations

  • Federal learning model compression defense method and device based on block chain

    CN113468130A

  • Efficient federated learning sparse training method based on parallel over-parameterization

    CN114925847A

  • Federal learning sparse training method and system based on comparative learning

    CN115829027A

  • Backdoor attack defense method in federated learning based on multi-dimensional index dynamic identification

    CN116150745A

  • Federal learning backdoor attack-oriented defense method

    CN118036770A

Cited By

  • Federal learning backdoor defense method based on gradient screening and weight adjustment

    CN120979739A