Federal learning-oriented privacy state switching method and system

By dynamically adjusting the privacy protection mechanism in federated learning, the balance between privacy protection and computing performance is solved, training efficiency and model convergence speed are improved, and federated learning systems adapted to different environments and devices.

CN120296783APending Publication Date: 2025-07-11LINGSHU TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510370366.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The existing privacy protection scheme in federated learning adopts fixed mechanisms and parameters, and lacks targeted adjustments, which makes it difficult to balance the intensity of privacy protection and computing performance, affecting training efficiency, convergence effect and data security.

Method used

The initial privacy protection mechanism is extracted for federated learning objects and servers through the privacy protection policy engine, and by dynamically adjusting the mechanism, the privacy protection parameters are optimized according to the training stage, learning objects and network status to achieve privacy-performance balance.

Benefits of technology

While ensuring data privacy and security, it optimizes training performance, improves model convergence speed, and adapts to the needs of different training stages and learning objects.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296783A_ABST
    Figure CN120296783A_ABST
Patent Text Reader

Abstract

The invention provides a federated learning-oriented privacy state switching method and system, and relates to the technical field of privacy computing, and the method comprises the steps: extracting an initial privacy protection mechanism for a federated learning object and a federated server based on a privacy protection strategy engine; dynamically adjusting the initial privacy protection mechanism by privacy-efficiency balance optimization to obtain a privacy protection mechanism; and protecting data interaction between the federated learning object and the federated server through a privacy protection mechanism. Through the method, the technical problem that the training efficiency, convergence effect and data security of federated learning are further affected due to the fact that privacy protection strength and calculation performance are difficult to balance in the prior art can be solved, the technical goal of dynamically adjusting a privacy protection mechanism and parameters to adapt to different training stages and different learning objects is achieved, and the user experience is improved. The technical effects of optimizing the training performance and improving the model convergence speed while ensuring the data privacy security are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of privacy computing technology, and particularly to a privacy state switching method and system for federated learning. Background Art

[0002] With the rapid development of artificial intelligence technology, federated learning, as an emerging distributed training paradigm, can achieve joint modeling among multiple data sources while avoiding direct data sharing, thus alleviating the risk of privacy leakage to a certain extent. However, existing federated learning privacy protection methods still face many challenges, including the trade-off between privacy protection and training efficiency, the problem of heterogeneous adaptation for different learning objects, and the problem of privacy policy adjustment in a dynamic network environment. Therefore, how to improve the efficiency of model training while ensuring data privacy has become an important research direction in the field of federated learning.

[0003] Currently, existing privacy protection schemes often adopt fixed mechanisms and parameters, lacking targeted adjustment during the model training process, resulting in an insurmountable contradiction between privacy protection intensity and computing performance. On the one hand, a higher-intensity privacy protection mechanism can effectively reduce the risk of information leakage, but it is usually accompanied by a significant increase in computational overhead, affecting training efficiency and even possibly causing difficulties in model convergence. On the other hand, if the privacy protection intensity is reduced to improve computational efficiency, it may lead to an increased risk of sensitive information leakage and fail to meet the requirements of data security in actual application scenarios. In addition, there are a wide variety of participating devices in federated learning, including terminal devices with huge differences in computing power, storage resources, and network environments. The unified privacy protection mechanism in these heterogeneous environments is difficult to take into account the needs of all devices, which may cause some devices to be unable to participate in training normally, or devices with limited resources to become the bottleneck of system performance, affecting the overall training process.

[0004] In summary, there is a technical problem in the prior art that due to the fixed mechanisms and parameters of the privacy protection scheme and the lack of targeted adjustment, it is difficult to balance the privacy protection intensity and computing performance, further affecting the training efficiency, convergence effect, and data security of federated learning. Summary of the Invention

[0005] The purpose of this application is to provide a privacy state switching method and system for federated learning to solve the technical problem in the prior art that due to the fixed mechanisms and parameters of the privacy protection scheme and the lack of targeted adjustment, it is difficult to balance the privacy protection intensity and computing performance, further affecting the training efficiency, convergence effect, and data security of federated learning.

[0006] In view of the above problems, this application provides a privacy state switching method and system for federated learning.

[0007] In a first aspect, the present application provides a privacy status switching method for federated learning, which is implemented through a privacy status switching system for federated learning, including: extracting an initial privacy protection mechanism for a federated learning object and a federated server based on a privacy protection policy engine; dynamically adjusting the initial privacy protection mechanism with privacy-efficiency balance optimization to obtain a privacy protection mechanism; and protecting the data interaction between the federated learning object and the federated server through the privacy protection mechanism.

[0008] In a second aspect, the present application further provides a privacy status switching system for federated learning, which is used to execute the privacy status switching method for federated learning described in the first aspect, including: an initial privacy protection mechanism extraction module, which is used to extract an initial privacy protection mechanism for a federated learning object and a federated server based on a privacy protection policy engine; a mechanism dynamic adjustment module, which is used to dynamically adjust the initial privacy protection mechanism with privacy-efficiency balance optimization to obtain a privacy protection mechanism; and a data interaction protection module, which is used to protect the data interaction between the federated learning object and the federated server through the privacy protection mechanism.

[0009] The technical solutions provided in the present application have at least the following technical effects or advantages: by implementing dynamic adjustment of the privacy protection mechanism and parameters to adapt to the technical goals of different training stages and different learning objects, the technical effect of optimizing the training performance while ensuring data privacy security and improving the model convergence speed is achieved.

[0010] The above description is only an overview of the technical solutions of the present application. In order to be able to understand the technical means of the present application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present application more obvious and understandable, the specific embodiments of the present application are specifically given below. It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] In order to more clearly illustrate the technical solutions in the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings described below are only exemplary, and for those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0012] Figure 1 It is a schematic flowchart of the privacy status switching method for federated learning of the present application;

[0013] Figure 2 It is a schematic structural diagram of the privacy status switching system for federated learning of the present application.

[0014] Description of reference numerals: Initial privacy protection mechanism extraction module 11, mechanism dynamic adjustment module 12, data interaction protection module 13. Specific implementation mode

[0015] This application provides a privacy state switching method and system for federated learning, solving the technical problem in the prior art that due to the fixed mechanism and parameters adopted by the privacy protection scheme and the lack of targeted adjustment, it is difficult to balance the privacy protection intensity and computing performance, further affecting the training efficiency, convergence effect and data security of federated learning. The technical goal of dynamically adjusting the privacy protection mechanism and parameters to adapt to different training stages and different learning objects is realized, and the technical effect of optimizing the training performance while ensuring data privacy security and improving the model convergence speed is achieved.

[0016] Next, the technical solutions in this application will be described clearly and completely with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments of this application. It should be understood that this application is not limited by the example embodiments described here. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of this application. Additionally, it should be noted that for the sake of description, only the parts related to this application are shown in the accompanying drawings rather than all of them.

[0017] Embodiment 1. Please refer to the attached Figure 1 , this application provides a privacy state switching method for federated learning, which is applied to a privacy state switching system for federated learning, and specifically includes the following steps:

[0018] S1: Extract an initial privacy protection mechanism for the federated learning object and the federated server based on the privacy protection policy engine.

[0019] Specifically, the privacy protection policy engine is an intelligent decision-making system that can select a suitable privacy protection method according to different environments and requirements. During the federated learning process, the federated learning object refers to the client that provides data and computing resources, such as personal devices, enterprise servers or medical institutions, and the federated server is responsible for coordinating the entire learning process and aggregating model updates from different clients. Extracting the initial privacy protection mechanism means selecting a suitable privacy protection method, such as differential privacy, homomorphic encryption or secure multi-party computation, according to the privacy requirements, computing power and data characteristics of the federated learning object before the training starts. For example, if the federated learning object is a smartphone with low computing power and the server has strong computing power, the initial privacy protection mechanism may choose a lighter differential privacy method instead of a homomorphic encryption with higher computational complexity to ensure the feasibility and efficiency of the training.

[0020] S2: Dynamically adjust the initial privacy protection mechanism by optimizing the privacy-performance balance to obtain a privacy protection mechanism.

[0021] Specifically, the privacy-performance balance means that while ensuring data privacy, the training effect of the model should not be affected as much as possible. Optimization refers to adjusting the parameters of the privacy protection mechanism to achieve the best balance between privacy protection and model performance. Dynamic adjustment means that this adjustment process is real-time rather than fixed. For example, in the early stage of federated learning, in order to speed up model convergence, the intensity of privacy protection can be reduced, such as increasing the noise intensity parameter of differential privacy, so that privacy protection is relatively weak but the model training speed is faster. In the later stage of training, in order to enhance privacy protection, the amplitude of noise can be increased or a stronger encryption method can be used, that is, the intensity of privacy protection can be increased, thereby reducing the risk of data leakage. For example, the privacy protection mechanism initially selected may be gradient clipping plus a small amount of noise, and after dynamic adjustment, the final privacy protection mechanism may enhance the noise intensity or increase encryption calculations to ensure data security.

[0022] S3: Protecting the data interaction between the federated learning object and the federated server through the privacy protection mechanism.

[0023] Specifically, the role of the privacy protection mechanism is to prevent information leakage when transmitting data between federated learning objects and federated servers. Data interaction includes model parameters uploaded by each device during training, downloaded global models, and communication information with the server. Protecting data interaction means using privacy protection mechanisms to encrypt, perturb, or take other protective measures on the transmitted data. For example, when uploading gradients, differential privacy can be used to add noise to the gradients so that the server cannot accurately restore the original data, thereby preventing privacy leakage. In addition, secure multi-party computing can also be used so that the server can only see the encrypted model updates and cannot directly access the original data, thereby effectively protecting privacy.

[0024] Furthermore, the present application also includes: extracting the real-time link status and training stage corresponding to the federated learning model of the federated learning object and the federated server, and obtaining the privacy protection requirements of the federated learning object; introducing a privacy protection policy engine, and inputting the real-time link status, the training stage and the privacy protection requirements into the privacy protection policy engine to select the initial privacy protection mechanism.

[0025] Specifically, the federated learning model is the core part of the collaborative training between the client and the server, and is continuously updated in multiple training rounds to improve the prediction ability and generalization performance. The real-time link state refers to the network connection status between the client and the server, including factors such as bandwidth, latency, and packet loss rate. These parameters will affect the transmission speed and accuracy of the model parameters. The training phase describes the time process in which the model is trained, such as the initial phase, the convergence phase, or the final optimization phase. The requirements for data security and computing efficiency may vary in each phase. The privacy protection requirement refers to the tolerance level of the federated learning object to data security and privacy leakage risks, which is related to the sensitivity of the data, the computing power of the device, and the legal and regulatory requirements.

[0026] After obtaining these key information, it is necessary to decide which specific privacy protection scheme to adopt to balance data security and model effectiveness. For this purpose, a privacy protection strategy engine is introduced, which can comprehensively consider the network state, the training phase, and the privacy protection requirements, and output the optimal privacy protection strategy. The inputs of the privacy protection strategy engine include the real-time link state, the training phase, and the privacy protection requirements. These factors jointly determine the choice of the privacy protection mechanism. For example, if the link state is good, the computing resources are sufficient, and the privacy requirements are low, a differential privacy method with higher computing efficiency may be selected. In the case of unstable link state and high privacy requirements, more secure but computationally expensive homomorphic encryption or multi-party secure computing may be adopted. The initial privacy protection mechanism refers to the basic protection strategy determined at the beginning of the training, which may be dynamically adjusted during the training process to adapt to the changing environment and requirements.

[0027] Furthermore, this application also includes: extracting the health monitoring data, location records, and application usage of the federated learning object, and matching the data sensitivity library to obtain the data sensitivity; obtaining the computing power and storage capacity of the federated learning object, and combining the data sensitivity to obtain the privacy protection requirements of the federated learning object.

[0028] Specifically, in the process of federated learning, the federated learning objects refer to the devices participating in data training, such as smartphones, smartwatches, enterprise servers, or information systems in medical institutions. These devices have different types of data. Among them, health monitoring data usually includes information such as heart rate, blood oxygen level, number of steps, and sleep patterns. This data is mainly collected by wearable devices or health applications and can reflect the physiological state of users. Location records refer to the geographical location information of the device, such as latitude and longitude coordinates obtained through the Global Positioning System, the travel trajectory of the user, or frequently visited locations, which can provide a basis for analyzing user behavior patterns. Application usage refers to the usage data of different application programs on the device, including application startup time, usage duration, interaction frequency, etc. This information can reflect user preferences and usage habits. Due to the different sensitivity levels of data, for example, medical and health data is usually more sensitive than application usage data, a standardized classification method is required, namely a data sensitivity library, which contains the classification of sensitive levels for different categories of data. For example, heart rate data may be defined as moderately sensitive, while medical record information may be defined as highly sensitive. By matching the collected data with the data sensitivity library, the specific data sensitivity level can be determined, providing a basis for formulating subsequent privacy protection strategies.

[0029] After clarifying the sensitivity level of the data, it is also necessary to consider the computing resources of the federated learning objects to ensure that the privacy protection mechanism can meet the security requirements without consuming excessive computing resources. Computing power refers to the ability of the device to process data and execute complex computing tasks, which is usually determined by the performance of the central processing unit, the size of the memory, and the computing accelerator (such as a graphics processing unit). For example, the computing power of a high-performance server is much higher than that of an ordinary smartphone, so it can perform more complex encryption calculations, while a smartphone may need to use methods with lower computational overhead. Storage capacity refers to the amount of space available on the device to store data, which determines whether the device can cache larger model parameters or intermediate calculation results. The privacy protection requirements are jointly determined by data sensitivity, computing power, and storage capacity. Sensitive data requires stronger privacy protection measures, while devices with limited computing resources may not be able to execute privacy protection technologies with high computational requirements. Table 1 shows the privacy protection requirement matching table for the federated learning objects of a certain enterprise in its most recent instance.

[0030] Table 1: Privacy Protection Requirement Matching Table for the Federated Learning Objects of a Certain Enterprise in Its Most Recent Instance

[0031]

[0032]

[0033] Further, this application also includes: evaluating the training effect of the initial privacy protection mechanism based on training metrics such as training loss, model accuracy, and convergence speed to obtain the initial training effect; comparing the initial training effect with the expected training effect to obtain a comparison result; if the initial training effect is worse than the expected training effect, obtaining that the comparison result is a poor result; and dynamically adjusting the initial privacy protection mechanism based on the poor result.

[0034] Specifically, in the process of federated learning, training metrics are key factors for measuring the training effect of the model. Among them, the training loss represents the degree of fitting of the model to the training data in the current training stage, which is calculated through a loss function, such as mean squared error or cross-entropy loss. The smaller the training loss, the higher the fitting degree of the model to the current data. However, if the loss is too low, it may mean overfitting, that is, the model performs well on the training data but its generalization ability on new data decreases. Model accuracy is an important indicator for measuring the prediction accuracy of the model, usually represented as the classification accuracy or regression error on the test data set. The convergence speed refers to the rate at which the model reaches a stable state during training. If the loss value of the model drops to a stable range in a short time, the convergence speed is fast, which usually means high training efficiency. By synthesizing these metrics, the impact of the initial privacy protection mechanism on model training can be evaluated, thereby obtaining the initial training effect, that is, the actual performance of the model under the current privacy protection mechanism.

[0035] After obtaining the initial training effect, it is necessary to compare it with the expected training effect to determine whether the current privacy protection mechanism needs to be adjusted. The expected training effect refers to the target performance of the model in a specific training environment under ideal conditions, or the loss value converges to a specific range within a certain number of training rounds. The comparison process is to compare the initial training effect with the expected target to determine the gap between them. If they are basically the same, it means that the current privacy protection mechanism will not significantly affect the training quality and no adjustment is required. However, if the initial training effect is significantly lower than the expected training effect, it means that the privacy protection mechanism may have too much impact on the training process and needs to be optimized.

[0036] During the comparison process, if the initial training effect is significantly lower than the expected training effect, the comparison result is defined as a poor result. This means that the current privacy protection mechanism, such as excessive noise added by differential privacy, too high computational overhead of homomorphic encryption, or too low gradient clipping threshold, may cause the model to be unable to learn effectively, thereby affecting the training convergence speed and accuracy. Therefore, the privacy protection mechanism needs to be dynamically adjusted.

[0037] After determining the poor result, the initial privacy protection mechanism is dynamically adjusted based on this result. Dynamic adjustment means adaptively adjusting the parameters of the privacy protection mechanism according to the training effect feedback to find a balance between privacy protection and training efficiency. For example, if the model accuracy decreases due to excessive differential privacy noise, the noise intensity can be appropriately reduced, that is, the privacy budget can be increased to reduce the interference with the training data and improve the model learning ability. If the gradient clipping threshold is too low, resulting in excessive loss of the model gradient information and thus affecting the training effect, the gradient clipping threshold can be appropriately relaxed to make the gradient update more stable. Through these adjustments, while ensuring privacy security, the model training quality can be improved to make it closer to the expected goal.

[0038] Furthermore, this application also includes: The comparison period includes short-term comparison, long-term comparison, and baseline comparison.

[0039] Specifically, the comparison period refers to the time range or data range selected when evaluating the training effect or the privacy protection mechanism, which is used to measure the change of the training effect and the impact of the privacy protection strategy on the model performance. The setting of the comparison period can affect the frequency of model adjustment and the judgment of the training trend. A suitable comparison period can help find a balance point between privacy protection and training efficiency, and avoid the negative impacts brought by over-adjustment or adjustment lag.

[0040] Short-term comparison means evaluating the training effect within a relatively short time window, such as the change of the model performance within one training epoch or several training epochs. Short-term comparison can be used to quickly detect the immediate impact of the privacy protection strategy, such as detecting whether the adjustment of the differential privacy noise intensity in a certain training epoch has caused too much impact on the training loss. If it is found in the short-term comparison that the model accuracy decreases too quickly or the convergence speed significantly slows down, the privacy protection parameters can be adjusted in a timely manner.

[0041] Long-term comparison means evaluating the training effect within a relatively long time window, usually involving multiple training cycles and even continuous monitoring of the entire training process. Long-term comparison can be used to analyze the impact of the privacy protection strategy on the overall training trend of the model, such as whether a certain privacy protection mechanism will cause the model performance to gradually decline as the training process progresses. If it is found in the long-term comparison that the model accuracy steadily improves as the number of training epochs increases, it indicates that the privacy protection mechanism will not significantly affect the model convergence; but if the accuracy remains at a low level for a long time or even shows a downward trend, the privacy protection parameters need to be re-evaluated.

[0042] Baseline comparison refers to comparing the current training effect with a pre-set reference standard, which can be the past best training effect, the training effect without a privacy protection mechanism, or the theoretically optimal training effect. The role of baseline comparison is to measure whether the privacy protection mechanism has a too large impact on the training effect and decide whether adjustment is needed.

[0043] Furthermore, this application also includes: using noise intensity, computational complexity, key length, and clipping threshold as privacy protection parameters to dynamically adjust the parameter size of the initial privacy protection mechanism to obtain an adjusted privacy protection mechanism; evaluating the training effect of the adjusted privacy protection mechanism to obtain an adjusted training effect; and using the adjusted privacy protection strength of the adjusted privacy protection mechanism to constrain the adjusted training effect to obtain the privacy protection mechanism.

[0044] Specifically, the noise intensity refers to the magnitude of the random noise added in the privacy protection mechanism. For example, in the differential privacy mechanism, the noise intensity is usually controlled by the privacy budget. The smaller the privacy budget value, the stronger the privacy protection, but the model accuracy may decrease. The computational complexity represents the computational resources required during the execution of the privacy protection mechanism. The higher the computational complexity, the stronger the privacy protection, but it also increases the computational time and device burden. The key length is used to measure the security of the encryption method. For example, the longer the key length in homomorphic encryption and secure multi-party computation, the higher the security, but the computational and storage costs also increase accordingly. The clipping threshold is used to control the magnitude of the gradient to prevent the gradient from leaking private information. The lower the clipping threshold is set, the stronger the privacy protection, but it may also affect the training convergence speed. Taking these privacy protection parameters as adjustable variables, their sizes can be adjusted at different training stages to optimize the privacy protection mechanism and balance privacy protection and training efficiency. For example, in the initial stage of training, to improve the model convergence speed, a lower noise intensity and a larger clipping threshold can be used, while in the later stage of training, to enhance the privacy protection effect, the noise intensity can be gradually increased and the clipping threshold can be decreased.

[0045] The training effect refers to the performance achieved by the model during training, including key indicators such as training loss, model accuracy, and convergence speed. The training loss represents the degree of optimization of the objective function by the model during the learning process, and generally the lower the better. The model accuracy measures the prediction ability of the model for unknown data, and the higher the value, the better the model performance. The convergence speed represents the number of training rounds required for the model to reach a stable state. If the convergence speed is too slow, it indicates that the privacy protection mechanism may have affected the training efficiency. By evaluating the training effect, it can be judged whether the current privacy protection parameter settings are reasonable. For example, if it is found that the training loss increases significantly after increasing the noise intensity, it means that the privacy protection mechanism has too large an impact on the training process and the parameters need to be adjusted to reduce the interference with model training.

[0046] The privacy protection strength represents the degree of guarantee of the privacy protection mechanism for data security. For example, a higher privacy protection strength can reduce the risk of data leakage, but may reduce the training effect. Containment is to control the change of the training effect while adjusting the privacy protection strength, so that the two are maintained within an acceptable range. The ultimate goal of the privacy protection mechanism is to find the optimal balance point between privacy protection and model training. For example, if the decline in training accuracy exceeds the expectation, the noise intensity can be appropriately reduced or the computational complexity can be adjusted to improve the training effect. If the privacy risk is still high, the privacy protection strength needs to be increased, such as increasing the key length or reducing the clipping threshold.

[0047] Furthermore, this application also includes: obtaining the containment points for adjusting the training effect and adjusting the privacy protection strength; introducing a training loss-privacy loss trade-off ratio, and adjusting the containment points according to the optimal training effect adjustment and the highest privacy protection strength adjustment to obtain the relative optimal of the training effect adjustment and the relative highest of the privacy protection strength adjustment, that is, the dynamic containment points; optimizing the initial privacy protection mechanism according to the dynamic containment points to obtain the privacy protection mechanism.

[0048] Specifically, adjusting the training effect refers to the degree of influence on the training model after adjusting the parameters of the privacy protection mechanism. For example, the change in model accuracy, the reduction speed of training loss, and the change in convergence speed. Adjusting the privacy protection strength represents the degree of adjustment of the privacy protection measures. For example, the increase in noise intensity, the improvement of the complexity of the encryption algorithm, or the decrease in the gradient clipping threshold.

[0049] The training loss-privacy loss trade-off ratio is an index to measure the balance degree between the training effect and the privacy protection strength. The training loss represents the size of the model prediction error, and the privacy loss refers to the information loss caused by the introduction of the privacy protection mechanism. For example, the gradient information becomes inaccurate due to the addition of noise. Adjusting the training effect optimally means that among all adjustment schemes, the state with the lowest training loss and the highest model accuracy is achieved, while adjusting the privacy protection strength to the highest means that among all acceptable schemes, the strength of the privacy protection mechanism is maximized. The dynamic containment point refers to the balance point of adaptively adjusting the training effect and privacy protection according to the current training loss-privacy loss trade-off ratio at different training stages. For example, at the initial stage of training, the containment point may be biased towards the training effect and the noise intensity is low, while at the later stage of training, the containment point may be biased towards privacy protection and the noise intensity is appropriately increased.

[0050] Optimizing the initial privacy protection mechanism means that after finding a reasonable dynamic constraint point, adjusting the privacy protection parameters so that the privacy protection and training effect maintain an optimal balance throughout the training process. The optimization of the privacy protection mechanism includes adjusting the noise intensity of differential privacy, adjusting the key length of homomorphic encryption, optimizing the gradient clipping threshold, etc., so that it can adapt to dynamic changes in different training stages. For example, in the first ten rounds of training, the privacy protection mechanism may adopt a lower noise intensity and a higher clipping threshold, while in the last ten rounds of training, the noise intensity gradually increases and the clipping threshold decreases to ensure the maximization of the privacy protection effect while maintaining the stability of the training accuracy.

[0051] Furthermore, this application also includes: generating the training weights for adjusting the training effect and the protection weights for adjusting the privacy protection intensity according to the coefficient of variation method; adjusting the dynamic constraint point through the training weights and the protection weights, and optimizing the initial privacy protection mechanism to obtain the privacy protection mechanism.

[0052] Specifically, the coefficient of variation method is a statistical method used to measure the degree of data fluctuation, and it evaluates the relative change degree of variables by calculating the ratio of the standard deviation to the mean. In the privacy protection mechanism, this method is used to calculate the training weights for adjusting the training effect and the protection weights for adjusting the privacy protection intensity. The training weight refers to the importance of different indicators in the overall training effect during the training process. For example, in some cases, the model accuracy may be more important than the convergence speed, so its weight should be relatively high. The protection weight represents the importance of the privacy protection measures. For example, in application scenarios involving highly sensitive data, the priority of privacy protection needs to be improved, so its weight should also be increased accordingly.

[0053] The training weights and protection weights play a decisive role in the optimization process of the privacy protection mechanism and are used to adjust the dynamic constraint point, that is, to find the best balance position between the privacy protection intensity and the training effect. The adjustment method of the dynamic constraint point depends on the ratio of the training weight and the protection weight. For example, if the training weight is high, the privacy protection intensity is reduced to improve the training effect; if the protection weight is high, the privacy protection measures are strengthened even if the training effect decreases. Finally, through this optimization method, the initial privacy protection mechanism is dynamically adjusted so that it can take into account both the training effect and the privacy protection requirements in different training stages, thus forming a stable and efficient privacy protection mechanism.

[0054] Furthermore, this application also includes: selecting federated learning objects according to the computing power and storage capacity until the object quantity threshold is met to obtain the preferred federated learning objects; updating the preferred federated learning objects according to the stability of the real-time link state to obtain the federated learning objects.

[0055] Specifically, computing power refers to the speed at which a device processes data and performs model training, which is determined by processor performance, memory size, and computing efficiency. Storage capacity represents the amount of training data that a device can store and the space for temporary calculation results. In federated learning, different devices may have different computing powers and storage capacities. Therefore, it is necessary to select appropriate federated learning objects based on these factors. The object quantity threshold refers to the minimum or maximum number of devices that meet the training requirements. During the selection process, devices with strong computing power and sufficient storage capacity are preferably selected to ensure their efficient participation in training.

[0056] The real-time link state refers to the communication status between a device and a server, including factors such as network bandwidth, latency, and data transmission rate. Stability is an important indicator for measuring the degree of link state fluctuation. Higher stability means that the device can maintain a good network connection for a long time, while lower stability may lead to data transmission interruption or training delay. To ensure the stability of federated learning, it is necessary to dynamically update the preferred federated learning objects according to the changes in the link state. For example, if a device meets the requirements of computing power and storage capacity during the initial selection stage but has an unstable network during the training process, it may cause the model parameters to fail to be uploaded or downloaded on time. In this case, it is necessary to replace this device and select a more stable device to participate in the training.

[0057] In summary, the privacy state switching method for federated learning provided by this application has the following technical effects: by realizing the dynamic adjustment of the privacy protection mechanism and parameters to adapt to the technical goals of different training stages and different learning objects, it achieves the technical effects of optimizing the training performance while ensuring data privacy security and improving the model convergence speed.

[0058] Embodiment 2. Based on the same inventive concept as the privacy state switching method for federated learning in the foregoing embodiment, this application also provides a privacy state switching system for federated learning. Please refer to the appendix Figure 2 , including: an initial privacy protection mechanism extraction module 11, which is used to extract an initial privacy protection mechanism for federated learning objects and a federated server based on a privacy protection policy engine; a mechanism dynamic adjustment module 12, which is used to dynamically adjust the initial privacy protection mechanism with privacy - efficiency balance optimization to obtain a privacy protection mechanism; and a data interaction protection module 13, which is used to protect the data interaction between the federated learning objects and the federated server through the privacy protection mechanism.

[0059] Furthermore, the privacy state switching system for federated learning is also used for: extracting the real-time link state and training phase corresponding to the federated learning model of the federated learning object, and obtaining the privacy protection requirements of the federated learning object; introducing a privacy protection policy engine, and inputting the real-time link state, the training phase, and the privacy protection requirements into the privacy protection policy engine to select the initial privacy protection mechanism.

[0060] Furthermore, the privacy state switching system for federated learning is also used for: extracting the health monitoring data, location record, and application usage of the federated learning object, and matching a data sensitivity library to obtain the data sensitivity; obtaining the computing power and storage capacity of the federated learning object, and combining the data sensitivity to obtain the privacy protection requirements of the federated learning object.

[0061] Furthermore, the privacy state switching system for federated learning is also used for: evaluating the training effect of the initial privacy protection mechanism based on the training loss, model accuracy, and convergence speed in the training metrics to obtain the initial training effect; comparing the initial training effect with the expected training effect to obtain an effect comparison result; if the initial training effect is worse than the expected training effect, obtaining the effect comparison result as a poor effect result; and dynamically adjusting the initial privacy protection mechanism based on the poor effect result.

[0062] Furthermore, the privacy state switching system for federated learning is also used for: the comparison periods include short-term comparison, long-term comparison, and baseline comparison.

[0063] Furthermore, the privacy state switching system for federated learning is also used for: taking the noise intensity, computational complexity, key length, and clipping threshold as privacy protection parameters, dynamically adjusting the parameter sizes of the initial privacy protection mechanism to obtain an adjusted privacy protection mechanism; evaluating the training effect of the adjusted privacy protection mechanism to obtain an adjusted training effect; and using the adjusted privacy protection intensity of the adjusted privacy protection mechanism to constrain the adjusted training effect to obtain the privacy protection mechanism.

[0064] Furthermore, the privacy state switching system for federated learning is also used for: obtaining the constraint points of the adjusted training effect and the adjusted privacy protection intensity; introducing a training loss-privacy loss trade-off ratio, and adjusting the constraint points according to the optimal adjusted training effect and the highest adjusted privacy protection intensity to obtain the relative optimal of the adjusted training effect and the relative highest of the adjusted privacy protection intensity; and optimizing the initial privacy protection mechanism according to the dynamic constraint points to obtain the privacy protection mechanism.

[0065] Further, the privacy state switching system for federated learning is further configured to: generate a training weight for adjusting the training effect and a protection weight for adjusting the privacy protection strength according to the coefficient of variation method; adjust the dynamic restraint point by the training weight and the protection weight, and optimize the initial privacy protection mechanism to obtain the privacy protection mechanism.

[0066] Further, the privacy state switching system for federated learning is further configured to: select federated learning objects according to computing power and storage capacity until the object quantity threshold is met to obtain preferred federated learning objects; update the preferred federated learning objects according to the stability of the real-time link state to obtain the federated learning objects.

[0067] The various embodiments in this specification are described in a progressive manner, and the key point of each embodiment is to illustrate the differences from other embodiments. The privacy state switching method and specific examples in the foregoing Embodiment 1 for federated learning are equally applicable to the privacy state switching system for federated learning in this embodiment. Through the foregoing detailed description of the privacy state switching method for federated learning, those skilled in the art can clearly know the privacy state switching system for federated learning in this embodiment. Therefore, for the sake of brevity of the specification, it will not be described in detail herein.

[0068] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0069] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the present application and its equivalent technologies, the present application is also intended to include these changes and modifications.

Claims

1. A privacy state switching method for federated learning, characterized in that Including: Extracting an initial privacy protection mechanism for the federated learning object and the federated server based on the privacy protection policy engine; Dynamically adjusting the initial privacy protection mechanism with privacy - efficiency balance optimization to obtain a privacy protection mechanism; Protecting the data interaction between the federated learning object and the federated server through the privacy protection mechanism.

2. The privacy status switching method for federated learning according to claim 1, wherein Extracting an initial privacy protection mechanism for the federated learning object and the federated server based on the privacy protection policy engine, including: Extracting the real - time link state and training phase corresponding to the federated learning model of the federated learning object and the federated server, and obtaining the privacy protection requirements of the federated learning object; Introducing a privacy protection policy engine, and inputting the real - time link state, the training phase, and the privacy protection requirements into the privacy protection policy engine to select the initial privacy protection mechanism.

3. The privacy status switching method for federated learning according to claim 2, wherein Obtaining the privacy protection requirements of the federated learning object, including: Extracting the health monitoring data, location records, and application usage of the federated learning object, and matching a data sensitivity library to obtain data sensitivity; Obtaining the computing power and storage capacity of the federated learning object, and combining the data sensitivity to obtain the privacy protection requirements of the federated learning object.

4. The privacy state switching method for federated learning according to claim 1, wherein Before dynamically adjusting the initial privacy protection mechanism with privacy - efficiency balance optimization, including: Evaluating the training effect of the initial privacy protection mechanism based on training loss, model accuracy, and convergence speed in training metrics to obtain an initial training effect; Comparing the initial training effect with the expected training effect to obtain a comparison result of the effects; If the initial training effect is worse than the expected training effect, obtaining the comparison result of the effects as a poor result; Dynamically adjusting the initial privacy protection mechanism based on the poor result of the effects.

5. The privacy state switching method for federated learning according to claim 4, wherein, The comparison periods include short - term comparison, long - term comparison, and baseline comparison.

6. The privacy status switching method for federated learning according to claim 1, wherein Dynamically adjusting the initial privacy protection mechanism with privacy - efficiency balance optimization to obtain a privacy protection mechanism, including: Taking noise intensity, computational complexity, key length, and clipping threshold as privacy protection parameters, and dynamically adjusting the parameter sizes of the initial privacy protection mechanism to obtain an adjusted privacy protection mechanism; Evaluating the training effect of the adjusted privacy protection mechanism to obtain an adjusted training effect; Constraining the adjusted training effect through the adjusted privacy protection intensity of the adjusted privacy protection mechanism to obtain the privacy protection mechanism.

7. The privacy status switching method for federated learning according to claim 6, wherein Constraining the adjusted training effect through the adjusted privacy protection intensity of the adjusted privacy protection mechanism to obtain the privacy protection mechanism, including: Obtaining the constraint points of the adjusted training effect and the adjusted privacy protection intensity; Introducing a training loss - privacy loss trade - off ratio, and adjusting the constraint points according to the optimal adjusted training effect and the highest adjusted privacy protection intensity to obtain the relative optimal of the adjusted training effect and the relative highest of the adjusted privacy protection intensity of the dynamic constraint points; Optimizing the initial privacy protection mechanism according to the dynamic constraint points to obtain the privacy protection mechanism.

8. The privacy status switching method for federated learning according to claim 7, wherein, Optimizing the initial privacy protection mechanism according to the dynamic constraint points to obtain the privacy protection mechanism, including: Generating the training weight of the adjusted training effect and the protection weight of the adjusted privacy protection intensity according to the coefficient of variation method; Adjust the dynamic restraint points through the training weights and the protection weights, and optimize the initial privacy protection mechanism to obtain the privacy protection mechanism.

9. The privacy status switching method for federated learning according to claim 1, wherein The steps for obtaining federated learning objects include: Select federated learning objects according to computing power and storage capacity until the object quantity threshold is met to obtain preferred federated learning objects; Update the preferred federated learning objects according to the stability of the real-time link state to obtain the federated learning objects.

10. A privacy state switching system for federated learning, characterized in that, The steps for implementing the privacy state switching method for federated learning according to any one of claims 1 to 9 include: An initial privacy protection mechanism extraction module, configured to extract an initial privacy protection mechanism for federated learning objects and a federated server based on a privacy protection policy engine; A mechanism dynamic adjustment module, configured to dynamically adjust the initial privacy protection mechanism with privacy-efficiency balance optimization to obtain a privacy protection mechanism; A data interaction protection module, configured to protect the data interaction between the federated learning objects and the federated server through the privacy protection mechanism.