Distributed heterogeneous graph privacy protection-oriented decentralized federated learning method, device and equipment

By adopting a decentralized federated learning method of client networking, relationship differential privacy and adaptive gradient cropping thresholds in distributed heterogeneous graph learning, the balance of privacy protection and model effects is solved, and the model robustness and availability in the face of member reasoning attacks and topological changes is achieved.

CN120338047APending Publication Date: 2025-07-18BEIHANG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510220420.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The existing distributed heterogeneous graph learning model is difficult to balance between privacy protection and model effects, and faces the risk of member inference attacks, fixed gradient cropping thresholds affecting model performance, and a single point of failure caused by communication topology interference.

Method used

The client networking module, the relationship differential privacy definition module and the privacy relationship characterization noise perturbation module are adopted, combined with the attention module based on heterogeneous graph relationship perception and the local gradient crop threshold adaptive adjustment module, decentralized federated learning is performed through the asynchronous communication mechanism, and privacy is protected and the model is optimized using the adaptive gradient crop threshold and two-stage perturbation strategy.

Benefits of technology

While protecting privacy, it ensures the availability and robustness of the model, effectively prevents single point failure risk, and improves the training effect of the model and the stability under flexible topological changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120338047A_ABST
    Figure CN120338047A_ABST
Patent Text Reader

Abstract

The invention relates to a decentralized federated learning method for distributed heterogeneous graph privacy protection. The method comprises the steps of networking clients, defining relation differential privacy and introducing Gaussian noise into a privacy relation, calculating a heterogeneous graph relation weight, aggregating and weighting along a path, projecting to a specific node type, calculating node embedding, and judging whether the size of a sliding window is met or not. And determining whether to use an adaptive adjustment gradient clipping threshold according to a judgment result, realizing an aggregation gradient, updating a training model, and judging whether the number of model training times is reached. According to the method and the device, the model availability can be ensured while privacy is protected. And a single-point fault risk can be effectively prevented, and the robustness of the model is kept in flexible topological change. A two-stage perturbation strategy is proposed to resist member reasoning attacks based on metadata. And a self-adaptive gradient clipping threshold method is introduced, so that model deviation caused by noise is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and particularly to a decentralized federated learning method, device, and equipment for distributed heterogeneous graph privacy protection. Background Art

[0002] Since heterogeneous graphs contain richer semantic information and are helpful for more closely simulating networks in the real world, currently, learning models based on heterogeneous graphs have been widely used in fields such as commercial recommendation, economic decision-making, and scientific research. Currently, due to privacy concerns and privacy protection compliance requirements, heterogeneous graph data is mainly stored in a decentralized form and no longer in a centralized form, which may cause the heterogeneous graph learning model to overfit due to insufficient local training data, resulting in a significant reduction in the performance (i.e., accuracy) of the learning model. Therefore, our main problem is how to protect privacy while minimizing the impact on the model's performance for heterogeneous graph data stored in a distributed manner. To this end, a typical approach is to adopt a traditional federated learning architecture, which collaboratively trains a heterogeneous graph learning model through a central server and multiple clients without sharing local data. At the same time, differential privacy (DP) technology is used to add noise during the global model aggregation process to protect privacy. For example, FedGNN uses federated learning to collaboratively train a graph neural network model on distributed user data and uses differential privacy technology to protect user privacy.

[0003] However, the traditional federated learning architecture still faces the following challenges in protecting heterogeneous graph privacy and maintaining model performance: First, the metadata of heterogeneous graphs makes membership inference attacks easier and the risk of privacy leakage greater. Different from homogeneous graphs, heterogeneous graphs have special metadata (e.g., meta-paths), which contain high-order semantic information, making them more vulnerable to membership inference attacks and increasing the risk of privacy leakage. An attacker with relevant metadata background knowledge (such as a malicious server or client) can more easily perform membership inference attacks using this information. Second, a fixed gradient clipping threshold reduces model performance. When using differential privacy technology to add noise to gradients during the global model aggregation process, a fixed threshold is usually used to clip the gradients and then Gaussian noise is introduced. Research shows that this method has an adverse effect on model parameter updates, that is, too low a clipping threshold causes the noise to mask useful gradient information, while too high a clipping threshold introduces more noise, reducing model performance. Third, communication topology interference (such as single-point or single-link failures) significantly affects model performance. It has been proven that the centralized coordination architecture of clients and servers relies on the strong assumption of a stable communication topology. When the communication topology is interfered with or constantly changing, it is extremely vulnerable to the risk of single-point failures. For example, when the central server crashes or the communication link with a certain client fails, it may cause the federated learning training to abort, significantly reducing model performance. Summary of the Invention

[0004] This application provides a decentralized federated learning method for distributed heterogeneous graph privacy protection, which is characterized by including: Based on the client networking module, relational differential privacy definition module, and privacy relationship representation noise perturbation module, network the clients, define relational differential privacy, and introduce Gaussian noise into the privacy relationship; Based on the heterogeneous graph relationship-aware attention module, calculate various relationship weights associated with the target node in the heterogeneous graph, aggregate the results along the message passing path, weighted aggregate the relationship types, project them onto specific node types, and calculate node embeddings; Based on the local gradient clipping threshold judgment module, gradient clipping threshold adaptive adjustment module, and local gradient noise perturbation module, determine whether the sliding window size is met, and decide whether to use the adaptive adjustment gradient clipping threshold according to the judgment result; Based on the gossip-based client asynchronous communication module and loop end judgment module, aggregate gradients and update the training model, and determine whether the model training times have been reached.

[0005] Optionally, the step of networking the clients, defining relational differential privacy, and introducing Gaussian noise into the privacy relationship based on the client networking module, relational differential privacy definition module, and privacy relationship representation noise perturbation module includes: The networking of the clients is completed by generating a random graph topology using the Erdos-Renyi graph; The definition of relational differential privacy is such that the random mechanism makes any other heterogeneous graph that differs from the heterogeneous graph adjacency list by only one relationship, and the adjacency list all satisfy ; The introduction of Gaussian noise into the privacy relationship is to embed Gaussian noise into the specified privacy relationship so that it satisfies .

[0006] Optionally, the step of calculating various relationship weights associated with the target node in the heterogeneous graph, aggregating the results along the message passing path, weighted aggregating the relationship types, projecting them onto specific node types, and calculating node embeddings based on the heterogeneous graph relationship-aware attention module includes: The formula for calculating various relationship weights associated with the target node in the heterogeneous graph is: , represents a privacy relationship from node to node , is The node features and the attention calculation result of the node features are the information transmitted from node to node ; Projecting the weighted aggregation relationship type onto a specific node type is expressed as = + . Among them, , is a linear mapping function, is a mapping function of the node type, represents a non-linear activation function, represents the residual connection of the th layer of the model.

[0007] Optionally, the module for judging according to the local gradient clipping threshold, the module for adaptively adjusting the gradient clipping threshold, and the module for local gradient noise perturbation judge whether the sliding window size is satisfied, and decide whether to use the adaptively adjusted gradient clipping threshold according to the judgment result, including: Judging whether the sliding window size is satisfied. If satisfied, execute the module for adaptively adjusting the gradient clipping threshold; if not satisfied, directly execute the module for local gradient noise perturbation; The module for adaptively adjusting the gradient clipping threshold is to adaptively adjust the gradient clipping threshold using the sliding window technique to control the impact of noise on the model; The module for local gradient noise perturbation is to add Gaussian noise to the gradient of the local model to protect privacy, and its formula is , is the gradient with noise, represents the gradient clipping function, represents the noise variance that follows the standard normal distribution .

[0008] Optionally, the module for aggregating gradients and updating the training model, and judging whether the model training times are reached according to the gossip-based client asynchronous communication module and the loop end judgment module, including: The implementation of aggregating gradients and updating the training model is to adopt a gossip-based asynchronous communication mechanism. The communication between clients follows an independent Poisson process. At each tick of the global clock, the clients are activated in turn to communicate with one of their neighbors. In round , client is activated and randomly selects a neighbor to communicate and share its local gradient . In round , client After aggregating the gradients from m neighbors, perform gradient descent to obtain the updated parameters: , where and represent at round and round respectively, the local model parameters, is the learning rate of the local model; The judgment of whether the model training times are reached is that if so, output the trained global model , if not, repeatedly execute local training and neighbor gradient aggregation until the global loss function reaches the optimal value, that is . and are the global and local loss functions respectively, represents all the data participating in the training, represents the data participating in the model training on each client.

[0009] Optionally, the introducing Gaussian noise into the privacy relationship is to embed m_(φ(e)) into the specified privacy relationship e=(s,t) to introduce Gaussian noise so that it satisfies the (ε,δ)-differential relationship, including: The specific formula for satisfying the (ε,δ)-differential relationship is: , is the noisy privacy relationship embedding, represents the weight, represents a noise variance that follows the standard normal distribution ; where is the l2-sensitivity, H and H’ represent two sets of heterogeneous graph data that differ by only one relationship. Due to the backward processing property of differential privacy, all subsequent processing processes satisfy .

[0010] Optionally, the gradient clipping threshold adaptive adjustment module is to adaptively adjust the gradient clipping threshold Θ using the sliding window technique to control the impact of noise on the model, including: At one tick of the global clock, K clients participate in the training. For client , it receives the noisy gradients from m neighbors; Therefore, at the global training round , the adaptive adjustment method of the local gradient clipping threshold of is: is the gradient sequence ; At round , ​Representation Noisy gradient aggregation of m neighbors of .

[0011] This application also provides an apparatus for a decentralized federated learning method for distributed heterogeneous graph privacy protection, characterized in that the apparatus includes: A memory, a processor, and a computer program stored on the memory and running on the processor, the computer program being configured to implement the steps of the decentralized federated learning method for distributed heterogeneous graph privacy protection according to any one of claims 1 to 7.

[0012] Optionally, the apparatus for the decentralized federated learning method for distributed heterogeneous graph privacy protection is characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by the processor, the steps of the decentralized federated learning method for distributed heterogeneous graph privacy protection according to any one of claims 1 to 7 are implemented.

[0013] This application also provides an electronic device, characterized in that it includes: A memory and a processor, and a computer program is stored in the memory. When the processor executes the computer program, the steps of the decentralized federated learning method for distributed heterogeneous graph privacy protection according to any one of claims 1 to 7 are implemented.

[0014] The beneficial effects of this application are as follows: While protecting privacy, the model availability can be guaranteed. It can effectively prevent the risk of single-point failure and maintain the model robustness in flexible topological changes. A two-stage perturbation strategy is proposed to resist the membership inference attack based on metadata. An adaptive gradient clipping threshold method is introduced to reduce the model bias caused by noise. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following briefly introduces the drawings required in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0016] Figure 1 A flowchart showing a decentralized federated learning method for distributed heterogeneous graph privacy protection disclosed in this application; Figure 2 A flowchart showing an embodiment of a decentralized federated learning method for distributed heterogeneous graph privacy protection disclosed in this application. DETAILED DESCRIPTION

[0017] Various exemplary embodiments, features, and aspects of the present application will be described in detail below with reference to the accompanying drawings. Identical reference numerals in the drawings denote elements having the same or similar functions. Although various aspects of the embodiments are shown in the drawings, the drawings do not have to be drawn to scale unless otherwise specified.

[0018] Among them, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the present application, "a plurality" means two or more unless otherwise specifically defined.

[0019] The term "exemplary" used herein means "serving as an example, embodiment, or illustration". Any embodiment described herein as "exemplary" does not have to be construed as superior or better than other embodiments.

[0020] In addition, for a better description of the present application, numerous specific details are given in the following detailed implementation manners. Those skilled in the art should understand that the present application can also be implemented without some specific details. In some instances, methods, means, elements, and circuits well-known to those skilled in the art are not described in detail so as to highlight the gist of the present application.

[0021] The present application is a decentralized federated learning method for distributed heterogeneous graph privacy protection. In this method, locally at each client, it first learns the node and edge features of the heterogeneous graph based on a relationship-aware attention method. Then, a two-stage perturbation strategy based on differential privacy is adopted to protect both privacy relationships and local model gradients to resist metadata-based membership inference attacks. Further, to prevent gradient noise from overly affecting the optimization of the global model, an adaptive gradient clipping threshold strategy based on a sliding window is adopted to dynamically adjust the gradient noise amplitude according to the training progress, preventing overly large or overly small noise clipping thresholds from significantly affecting the model performance. When aggregating the global model, to prevent the risk of single-point failure, we adopt a gossip-based decentralized federated learning architecture to train the global model in an asynchronous communication manner between clients, which can ensure that even if some topologies fail, it will not significantly affect the model performance.

[0022] As Figure 1 shown, it is a flowchart of a decentralized federated learning method for distributed heterogeneous graph privacy protection according to an embodiment of the present application, which specifically includes the following contents: S100, according to the client networking module, the relational differential privacy definition module, and the privacy relationship characterization noise perturbation module, network the clients, define relational differential privacy, and introduce Gaussian noise into the privacy relationship.

[0023] Specifically, the system performs client networking with a random topology on K clients and the edge independent existence probability p of the Erdos Renyi graph through the client networking module.

[0024] Specifically, the system makes the outputs of the random mechanisms of two input data sets that differ by only one relationship be statistically very close through the relational differential privacy definition module.

[0025] Specifically, the system adds Gaussian noise, which is a random noise that follows a normal distribution, through the privacy relationship characterization noise perturbation module, and controls the noise variance to meet the privacy requirements.

[0026] S200: Calculate the weights of various relationships associated with the target node in the heterogeneous graph according to the attention module based on heterogeneous graph relationship perception, aggregate the results along the message passing path, and weighted aggregate the relationship types, project them onto a specific node type, and calculate the node embedding.

[0027] Specifically, the system calculates the attention weights between it and the target node and adjacent nodes for the local heterogeneous graph in each client through the attention module based on heterogeneous graph relationship perception , obtains the neighbor node information and the intermediate representation along the message passing path, then projects the weighted aggregated result onto the target node type , and finally calculates the final embedding of the target node .

[0028] S300: Determine whether the sliding window size is met according to the local gradient clipping threshold judgment module, the gradient clipping threshold adaptive adjustment module, and the local gradient noise perturbation module, and decide whether to use the adaptive adjustment gradient clipping threshold according to the judgment result.

[0029] Specifically, first execute the local gradient clipping threshold judgment module to determine whether the training from the starting round to the current round meets the sliding window size. If so, then execute the gradient clipping threshold adaptive adjustment module and then execute the local gradient noise perturbation module. If not, directly execute the local gradient noise perturbation module.

[0030] Specifically, the gradient clipping threshold adaptive adjustment module first receives the noisy gradients from m neighbors at the client , and aggregates them into a local gradient , then use a sliding window to record the gradient sequences of W and the rounds , then calculate the gradient clipping threshold for the next round according to the gradient sequences and the adaptive adjustment function , finally, when performing gradient update, use the dynamically adjusted threshold to perform gradient clipping to control the impact of noise on the model.

[0031] Specifically, the local gradient noise perturbation module adds Gaussian noise to the m-th local gradient , where the variance of the noise is related to the gradient clipping threshold .

[0032] S400. According to the client asynchronous communication module based on gossip and the loop end judgment module, aggregate gradients and update the training model, and judge whether the model training times are reached.

[0033] Specifically, the client asynchronous communication module based on gossip simulates the random communication behavior of clients in a Poisson process to avoid communication asynchrony problems in decentralized training, and uses the gradients of aggregated neighbors by the clients to update the local model parameters.

[0034] Specifically, the loop end judgment module first decides whether to terminate the training by judging whether the predefined Epoch is reached. If so, the training is terminated and the trained global model is output , if not, local training and neighbor gradient aggregation are performed until the global loss function converges, where the global loss function refers to measuring the performance of the model on all client data.

[0035] In summary, while protecting privacy, this method can ensure model availability. First, based on the heterogeneous graph relationship-aware attention module, use the relationship-aware attention method to learn the node and edge features of the heterogeneous graph. Then, the relational differential privacy definition module, the privacy relationship representation noise perturbation module, and the local gradient noise perturbation module adopt a two-stage perturbation strategy based on differential privacy to protect privacy relationships and local model gradients at the same time. In addition, the local gradient clipping threshold judgment module and the gradient clipping threshold adaptive adjustment module adopt an adaptive gradient clipping threshold strategy based on a sliding window to dynamically adjust the gradient noise amplitude according to the training progress, preventing the model effect from being greatly affected by too large or too small noise clipping thresholds. Finally, through the client networking module, the client asynchronous communication module based on gossip, and the loop end judgment module, when aggregating the global model, to prevent the risk of single-point failure, a gossip-based decentralized federated learning architecture is adopted. First, the clients are networked in the form of an Erdos-Renyi random graph, and the clients perform global model training in an asynchronous communication manner.

[0036] Such asFigure 2 As shown in Figure 2 , the flowchart of the specific embodiment of the decentralized federated learning method for distributed heterogeneous graph privacy protection includes the following: Specifically, the input part needs to be given a heterogeneous graph composed of an actual social network dataset, with 28,991 nodes, 398,230 edges, and a total of 4 node types, namely users, stores, addresses, and categories; and a total of 4 edge types, namely user-user, user-store, store-category, and store-address. According to the number of clients K = 10, the heterogeneous graph is evenly divided into 10 heterogeneous graphs to form a distributed heterogeneous graph. , the independent edge existence probability p of the Erdos-Renyi graph is 0.7, the number of model training epochs Epoch = 200, and the initial local gradient clipping threshold , the privacy budget allocated to the privacy relationship = 1, the privacy budget allocated to the local gradient , the sliding window size , the percentile for intercepting the gradient sequence . Designate a privacy relationship as e = (user 1, user 2).

[0037] Specifically, the client networking module A uses the Erdos-Renyi graph to generate a random graph topology to network the clients.

[0038] Specifically, the relational differential privacy definition module B is given a heterogeneous graph adjacency list , if there exists a random mechanism , making any heterogeneous graph adjacency list that differs from by only one relationship satisfy: Then it is said that satisfies .

[0039] Specifically, the heterogeneous graph relationship-aware attention module C, at each client, for the local heterogeneous graph , we first calculate the weights of various relationship types associated with the target node , and then aggregate the results along the message passing path. The calculation formula is: . Among them, the privacy relationship = (user 1, user 2). Finally, according to the calculated weights, weighted aggregation of various relationship types associated with the target node (including: user-user, user-store, store-category, store-address) is performed and projected onto a specific node type = user, so as to calculate the node embedding of the target node , which can be expressed as: = + Among them, , is a linear mapping function, is a mapping function of node types, represents a non-linear activation function, represents the residual connection of the

[0040] Specifically, for the specified privacy relationship, the privacy relationship representation noise perturbation module D introduces Gaussian noise to its embedding to make it satisfy , and the specific formula is: , where is initialized = 1.

[0041] Specifically, the local gradient clipping threshold judgment module E judges whether the current training round has satisfied the sliding window size W = 5 from the starting round to the current round. If it is satisfied, the gradient clipping threshold adaptive adjustment module is executed; if not, the local gradient noise perturbation module is directly executed.

[0042] Specifically, the gradient clipping threshold adaptive adjustment module F uses the sliding window technique to adaptively adjust the gradient clipping threshold . Suppose that at one tick of the global clock (i.e., the global training round ), 10 clients participate in the training. For client , it receives the noisy gradients from m neighbors. Then, at the next global training round , the adaptive adjustment method of the local gradient clipping threshold of is: where is the gradient sequence . At round , represents the aggregation of the noisy gradients of the m neighbors of

[0043] Specifically, for the local gradient noise perturbation module G, assuming that all clients are semi-honest, in order to protect privacy, we add Gaussian noise to the gradients of the local model before other clients share the model parameters. The specific formula is as follows: . Among them is the noisy gradient, represents the gradient clipping function, represents the noise variance that follows the standard normal distribution .

[0044] Specifically, for the chat-based client asynchronous communication module H, due to the problem of communication asynchrony in decentralized collaborative training, an asynchronous communication mechanism based on chat is adopted. Assume that the communication between clients follows an independent Poisson process, and each client has a local clock that counts time at a Poisson process with a rate of 1. Therefore, the communication behaviors of 10 clients are equivalent to a global clock of a single Poisson process with a rate of 10. At each tick of the global clock, clients are activated in sequence to communicate with one of their neighbors. In a round (corresponding to one tick of the global clock), the client is activated and randomly selects a neighbor to communicate with and share its local gradient . In round , after the client aggregates the gradients from m neighbors, it performs gradient descent to obtain the updated parameters: , where and respectively represent the local model parameters at round and round , is the learning rate of the local model, and here .

[0045] Specifically, for the loop end judgment module I, it determines whether 200 training sessions have been completed. If not, it repeatedly performs local training and neighbor gradient aggregation until the global loss function reaches the optimal value.

[0046] An apparatus for a decentralized federated learning method for distributed heterogeneous graph privacy protection used in the above steps, characterized in that the apparatus includes: a memory, a processor, and a computer program stored on the memory and running on the processor, and the computer program is configured to implement the steps of any one of the decentralized federated learning methods for distributed heterogeneous graph privacy protection.

[0047] An electronic device used in the above steps, characterized in that it includes: a memory and a processor, and a computer program is stored in the memory, and when the processor executes the computer program, it implements the steps of any one of the decentralized federated learning methods for distributed heterogeneous graph privacy protection.

[0048] The embodiments of the present application have been described above. The above description is exemplary and not exhaustive, and is also not limited to the disclosed embodiments. Many modifications and variations are obvious to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The choice of terms used herein is intended to best explain the principles of the embodiments, practical applications, or improvements to the technology in the market, or to enable other ordinary skill in the art to understand the embodiments disclosed herein.

Claims

1. A decentralized federated learning method for privacy protection of distributed heterogeneous graphs, characterized in that, Including: Based on the client networking module, relational differential privacy definition module, and privacy relationship representation noise perturbation module, network the clients, define relational differential privacy, and introduce Gaussian noise into the privacy relationship; Based on the heterogeneous graph relationship-aware attention module, calculate various relationship weights associated with the target node in the heterogeneous graph, aggregate the results along the message passing path, weighted-aggregate the relationship types, project them onto specific node types, and calculate the node embeddings; Based on the local gradient clipping threshold judgment module, gradient clipping threshold adaptive adjustment module, and local gradient noise perturbation module, determine whether the sliding window size is satisfied, and decide whether to use the adaptive adjustment of the gradient clipping threshold according to the judgment result; Based on the gossip-based client asynchronous communication module and loop end judgment module, aggregate the gradients and update the training model, and determine whether the model training times have been reached.

2. The decentralized federated learning method for distributed heterogeneous graph privacy protection according to claim 1, characterized in that, The network the clients, define relational differential privacy, and introduce Gaussian noise into the privacy relationship based on the client networking module, relational differential privacy definition module, and privacy relationship representation noise perturbation module, including: The networking of the clients is completed by generating a random graph topology using the Erdos-Renyi graph; The defined relational differential privacy is such that the random mechanism makes any other heterogeneous graph whose adjacency list differs from the heterogeneous graph adjacency list by only one relationship all satisfy ; The introduction of Gaussian noise into the privacy relationship is to introduce Gaussian noise into the specified privacy relationship so that it satisfies the following conditions .

3. The decentralized federated learning method for distributed heterogeneous graph privacy protection according to claim 1, characterized in that, The calculate various relationship weights associated with the target node in the heterogeneous graph, aggregate the results along the message passing path, weighted-aggregate the relationship types, project them onto specific node types, and calculate the node embeddings based on the heterogeneous graph relationship-aware attention module, including: The weight formulas for various relationships associated with the heterogeneous graph and the target node are as follows: , represents a privacy relationship from node to node ; is the attention calculation result of the node feature and the node feature, is the information transmitted from node to node ; The weighted aggregation relationship type is projected onto a specific node type, expressed as = + . Among them, , is a linear mapping function, is a mapping function of the node type, represents a non-linear activation function, represents the residual connection of the th layer of the model.

4. The decentralized federated learning method for distributed heterogeneous graph privacy protection according to claim 1, characterized in that, The determine whether the sliding window size is satisfied, and decide whether to use the adaptive adjustment of the gradient clipping threshold according to the judgment result based on the local gradient clipping threshold judgment module, gradient clipping threshold adaptive adjustment module, and local gradient noise perturbation module, including: The determining whether the sliding window size is satisfied is as follows: if satisfied, execute the gradient clipping threshold adaptive adjustment module; if not satisfied, directly execute the local gradient noise perturbation module; The gradient clipping threshold adaptive adjustment module is to adaptively adjust the gradient clipping threshold using the sliding window technique to control the impact of noise on the model; The local gradient noise perturbation module adds Gaussian noise to the gradient of the local model to protect privacy, and its formula is , is the gradient with noise, represents the gradient clipping function, represents a noise variance that follows the standard normal distribution .

5. The decentralized federated learning method for distributed heterogeneous graph privacy protection according to claim 1, characterized in that, The aggregate the gradients and update the training model, and determine whether the model training times have been reached based on the gossip-based client asynchronous communication module and loop end judgment module, including: The implementation of the aggregated gradient variable update training model is as follows. An asynchronous communication mechanism based on gossip is adopted. The communication between clients follows an independent Poisson process. At each tick of the global clock, clients are activated in turn to communicate with one of their neighbors. In round , the client is activated and randomly selects a neighbor to communicate with and share its local gradient . In round , after the client aggregates the gradients from m neighbors, it performs gradient descent to obtain the updated parameters: , where and respectively represent the local model parameters at round and round , and is the learning rate of the local model; The determination of whether the model training times have been reached is as follows. If so, the trained global model is output , otherwise, local training and neighbor gradient aggregation are repeatedly executed until the global loss function reaches the optimal value, that is . and are the global and local loss functions respectively, represents all the data participating in training, represents the data participating in model training on each client.

6. The decentralized federated learning method for distributed heterogeneous graph privacy protection according to claim 2, characterized in that, The introducing Gaussian noise into the privacy relationship is to embed m_(φ(e)) into the specified privacy relationship e=(s,t) and introduce Gaussian noise to make it satisfy the (ε,δ) relational differential, including: The specific formula for the difference that satisfies the (ε,δ) relationship is as follows: , is the privacy relationship embedding with noise, represents the weight, represents the noise variance that follows the standard normal distribution . where is the l2-sensitivity, H and H’ represent two sets of heterogeneous graph data that differ by only one relationship. Due to the backward processing property of differential privacy, all subsequent processing processes satisfy .

7. The decentralized federated learning method for distributed heterogeneous graph privacy protection according to claim 4, characterized in that, The gradient clipping threshold adaptive adjustment module is to adaptively adjust the gradient clipping threshold Θ using the sliding window technique to control the impact of noise on the model, including: At one tick of the global clock, K clients participate in training. For a client , it receives noisy gradients from m neighbors; Therefore, in the global training round when the adaptive adjustment method of the local gradient clipping threshold is as follows: , where is the gradient sequence At round , represents noisy gradient aggregation of the m neighbors.

8. An apparatus for a decentralized federated learning method for privacy protection of distributed heterogeneous graphs, characterized in that The device includes: A memory, a processor, and a computer program stored on the memory and running on the processor, the computer program being configured to implement the steps of the decentralized federated learning method for distributed heterogeneous graph privacy protection according to any one of claims 1 to 7.

9. The device for the decentralized federated learning method for distributed heterogeneous graph privacy protection according to claim 8, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the decentralized federated learning method for distributed heterogeneous graph privacy protection according to any one of claims 1 to 7 are implemented.

10. An electronic device, characterized in that, It includes: a memory and a processor, where a computer program is stored in the memory. When the processor executes the computer program, the steps of the decentralized federated learning method for distributed heterogeneous graph privacy protection according to any one of claims 1 to 7 are implemented.