Zero-trust federated learning security training method and device for edge computing

Through the SM9 key exchange and Shamir secret sharing method, combined with the scaling dot-generating attention mechanism, data privacy and security issues in federated learning are solved, and federated learning security and efficiency in edge computing environments are improved.

CN120354910APending Publication Date: 2025-07-22SOUTHWEST JIAOTONG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510212254.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

With a non-zero trust architecture, existing federated learning is difficult to guarantee data privacy and security, models are susceptible to data contamination and sensitive information leakage, and limited computing and communication resources lead to inefficiency.

Method used

The SM9 key exchange algorithm is used to generate shared keys, and the Shamir secret sharing method is combined for gradient encryption and decryption, and a scalable dot-generated attention mechanism is introduced to prevent malicious client poisoning attacks and ensure communication security and privacy protection.

Benefits of technology

In the edge computing environment, the security and efficiency of federated learning are improved, the man-in-the-middle attacks and tampering by malicious clients are prevented, data privacy is protected, and computing and communication overhead is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120354910A_ABST
    Figure CN120354910A_ABST
Patent Text Reader

Abstract

The invention provides a safety training method and device for zero-trust federated learning for edge computing, and relates to the technical field of federated learning training, and the method comprises the steps: initializing training parameters; generating a shared key through an SM9 key exchange algorithm and the training parameters; performing local training, obtaining a local gradient share based on a secret share generation algorithm, and encrypting the local gradient share through a shared key to obtain an encrypted local gradient share; sending the encrypted local gradient share to an edge node; the encrypted local gradient share is decrypted through the shared key, and then the global gradient is calculated; and performing local training of the next round of the client through the global gradient until the number of training times is reached, and ending the safety training of the zero-trust federal learning. According to the method, the problems that a non-zero trust framework used by existing federal learning is easy to cause that data privacy and security are difficult to fully guarantee, model leakage is difficult to effectively prevent, and data are easy to tamper or counterfeit are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of federated learning training, and more particularly, to a secure training method and device for zero-trust federated learning for edge computing. Background Art

[0002] Since edge computing systems usually rely on wireless networks or public networks for communication, the data in transmission is vulnerable to threats such as man-in-the-middle attacks, eavesdropping, and data tampering. In addition to the above threats, federated learning also needs to defend against poisoning attacks from malicious clients. Malicious clients may carry out poisoning attacks by tampering with local datasets or uploading malicious gradients, thus damaging the global model. Studies have shown that even with a single malicious client, it may have a serious negative impact on the performance of the federated learning model.

[0003] Existing federated learning is usually formed under a non-zero-trust architecture, which leads to some problems. First, due to the lack of a strong trust mechanism, it is difficult to fully guarantee the data privacy and security between participating parties. Especially in the case of malicious participants or attacks, the model may be at risk of data contamination or reverse engineering. Second, it is difficult to effectively prevent model leakage in a non-zero-trust environment. Especially when data from multiple different sources are aggregated, it may lead to the leakage of sensitive information. Third, although federated learning itself has the advantage of keeping data local, in a non-zero-trust architecture, how to ensure that the data transmitted by clients will not be tampered with or forged is still an urgent problem to be solved. Finally, existing technologies usually rely on traditional encryption mechanisms, but in the case of limited computing and communication resources, these mechanisms often bring high computational overhead and latency, affecting the efficiency and scalability of federated learning. Summary of the Invention

[0004] The purpose of the present invention is to provide a secure training method and device for zero-trust federated learning for edge computing to improve the above problems. To achieve the above purpose, the technical solutions adopted by the present invention are as follows:

[0005] In a first aspect, the present application provides a secure training method for zero-trust federated learning for edge computing, including:

[0006] Initializing training parameters, where the training parameters include a precision parameter scalar, an encryption public master key, and the identity identifiers of clients and edge nodes;

[0007] Generating shared keys for multiple clients and corresponding edge nodes through the SM9 key exchange algorithm and the training parameters;

[0008] Perform local training on the dataset of all clients, obtain local gradient shares based on the secret sharing generation algorithm, and encrypt the local gradient shares through the shared key to obtain the encrypted local gradient shares of each client;

[0009] Based on all the clients, send the encrypted local gradient shares to the edge node;

[0010] In the edge node, decrypt the encrypted local gradient shares through the shared key, and calculate the global gradient of each client through the decrypted local gradient shares;

[0011] The client downloads the corresponding global gradient, and performs the next round of local training of the client through the global gradient until the number of training times is reached, and the secure training of zero-trust federated learning ends.

[0012] In a second aspect, the present application also provides a secure training device for zero-trust federated learning for edge computing, including:

[0013] An initial module for initializing training parameters, where the training parameters include a precision parameter scalar, an encrypted public master key, and the identity identifiers of clients and edge nodes;

[0014] A shared key generation module for generating shared keys for multiple clients and corresponding edge nodes through the SM9 key exchange algorithm and the training parameters;

[0015] A first calculation module for performing local training on the dataset of all clients, obtaining local gradient shares based on the secret sharing generation algorithm, and encrypting the local gradient shares through the shared key to obtain the encrypted local gradient shares of each client;

[0016] A transmission module for sending the encrypted local gradient shares to the edge node based on all the clients;

[0017] A second calculation module for decrypting the encrypted local gradient shares through the shared key in the edge node, and calculating the global gradient of each client through the decrypted local gradient shares;

[0018] A training module for the client to download the corresponding global gradient, and perform the next round of local training of the client through the global gradient until the number of training times is reached, and the secure training of zero-trust federated learning ends.

[0019] The beneficial effects of the present invention are as follows: Through the SM9 key exchange algorithm, the present invention ensures the communication security of federated learning in the edge environment and prevents man-in-the-middle eavesdropping and data tampering. At the same time, the Shamir secret sharing method is used to ensure the privacy of federated learning, and it can also prevent collusion attacks and downtime risks among fewer than the preset number of edge nodes. And a scaled dot product attention mechanism is introduced and combined with the Shamir secret sharing method to design an algorithm for defending against poisoning and secure aggregation, preventing malicious clients from poisoning the global gradient, and realizing a zero-trust based federated learning architecture in the edge computing environment, improving the security of federated learning.

[0020] Other features and advantages of the present invention will be described in the subsequent specification, and part of them will become obvious from the specification, or be understood by implementing the embodiments of the present invention. The objectives and other advantages of the present invention can be realized and obtained through the structures specifically pointed out in the written specification, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required in the embodiments. It should be understood that the following drawings only show some embodiments of the present invention, so they should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0022] Figure 1 It is a schematic flowchart of the secure training method for zero-trust federated learning for edge computing described in the embodiments of the present invention;

[0023] Figure 2 It is a schematic diagram of the architecture of federated learning described in the embodiments of the present invention;

[0024] Figure 3 It is a curve graph of the test accuracy of the model at different iteration times under the label flipping attack of the present invention;

[0025] Figure 4 It is a curve graph of the test accuracy of the model at different iteration times under the backdoor attack of the present invention;

[0026] Figure 5 It is a curve graph of the test accuracy of the model at different poisoning client ratios under the label flipping attack of the present invention;

[0027] Figure 6 It is a curve graph of the test accuracy of the model at different poisoning client ratios under the backdoor attack of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0028] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Components of the embodiments of the present invention described and illustrated herein generally may be arranged and designed in a variety of different configurations. Therefore, the detailed description of the embodiments of the present invention provided herein is not intended to limit the scope of the claimed invention, but is merely representative of selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0029] It should be noted that like reference numerals and letters denote like items in the following figures, and thus, once an item is defined in one figure, further definition and explanation thereof are not required in subsequent figures. At the same time, in the description of the present invention, the terms "first", "second", etc. are only used for descriptive distinction and cannot be construed as indicating or implying relative importance.

[0030] Embodiment 1:

[0031] This embodiment provides a secure training method for zero-trust federated learning for edge computing.

[0032] See Figure 1 , which shows that this method includes steps S100, S200, S300, S400, S500, and S600.

[0033] In this embodiment, as Figure 2 shown, it is the architecture of federated learning, including a key generation center, multiple clients, and edge nodes. Among them, the edge nodes are responsible for allocating weights to each client and securely completing the aggregation task through the designed algorithm. The clients are mainly responsible for performing local training and uploading the processed gradient data. The key generation center mainly serves for SM9 key exchange and is responsible for generating and managing shared keys.

[0034] Specifically, the edge nodes are considered as semi - honest servers, which means that they will honestly follow the protocol, but they are curious about the privacy information of other parties. They may collude with each other or with the clients to infer the privacy information. The key generation center is a trusted third party, which can go offline after the key exchange is completed and does not participate in the subsequent federated learning training process. The clients are divided into benign clients and malicious clients. The benign clients train honestly and send the gradient information to the server, while the malicious clients carry out poisoning attacks by modifying the local dataset or local partial gradients, damaging the global model or reducing the model accuracy. To ensure the practicality and usability of the model, this embodiment assumes that the number of malicious clients does not exceed 50% of the total number of clients. In addition, there is also a risk of failure or dropout for the edge nodes.

[0035] Step S100: Initialize the training parameters, where the training parameters include the precision parameter scalar, the encrypted public master key, and the identity identifiers of the clients and edge nodes;

[0036] In this embodiment, the public information parameters of the edge nodes are initialized, the encrypted public master key required by the SM9 key exchange algorithm and the identity identifiers of the clients and edge nodes are initialized, and the secret recovery threshold is initialized. Among them, the secret recovery threshold will set the minimum number of secret recovery participants. Even if some edge nodes go down, as long as the number of active edge nodes meets this secret recovery threshold, the secret can still be normally recovered.

[0037] Step S200: Generate shared keys for multiple clients and corresponding edge nodes through the SM9 key exchange algorithm and the training parameters;

[0038] When the clients and edge nodes interact with gradient data, in order not to disclose the secret and be tampered with by the adversary, the clients and edge node servers will generate shared keys through the SM9 key exchange algorithm, encrypt the gradient information and send it to the other party. Since the other party has the corresponding shared key, it can quickly and securely obtain the desired information.

[0039] In this step, the steps for the clients and edge nodes to generate shared keys are as follows:

[0040] Step D100: Calculate the first key exchange element of the first additive cyclic group through the client, and calculate the temporary key exchange value of the client through the first random number and the first key exchange element;

[0041] In this step, the calculation formulas for the first key exchange element and the temporary key exchange value of the client are:

[0042] Q B =[H1(ID B ||hid,N G )]P1 + Ppub-e

[0043] R A = r A Q B

[0044] r A ∈ [1, N G -1]

[0045] Wherein, Q B represents the first key exchange element, that is, the key exchange element of client A with respect to edge node B, H1 represents a cryptographic function derived from a cryptographic hash function, ID B represents the identity identifier of edge node B, || represents a data merging operation, N G represents the order of the cyclic group, P1 represents the generator of the first additive cyclic group G1, P pub-e represents the encryption public master key, R A represents the temporary key exchange value of client A, r A represents the first random number, wherein, N G is a prime number.

[0046] Step D200: Send the temporary key exchange value of the client to the edge node;

[0047] Step D300: Calculate the second key exchange element of the first additive cyclic group through the edge node, and calculate the temporary key exchange value of the edge node through the second random number and the second key exchange element;

[0048] In this step, the calculation formulas for the second key exchange element and the temporary key exchange value of the edge node are:

[0049] Q A = [H1(ID A || hid, N G )]P1 + P pub-e

[0050] R B = r B Q A

[0051] r B ∈ [1, N G -1]

[0052] Wherein, Q A represents the second key exchange element, that is, the key exchange element of edge node B with respect to client A, H1 represents a cryptographic function derived from a cryptographic hash function, ID A represents the identity identifier of client A, || represents a data merging operation, N Gdenotes the order of the cyclic group, P1 denotes the generator of the first additive cyclic group G1, P pub-e denotes the encrypted public master key, R B denotes the temporary key exchange value of the edge node B, r B denotes the second random number.

[0053] Step D400: Determine by the edge node whether the temporary key exchange value of the client belongs to the first additive cyclic group. If so, calculate the first element information of the second multiplicative cyclic group through the temporary key exchange value of the client; otherwise, return to Step D100 to perform key exchange again;

[0054] In this step, the first element information of the second multiplicative cyclic group G T includes the first element, the second element, and the third element. Among them, the calculation formula for the first element information is:

[0055]

[0056] In the formula, g1 denotes the first element, g2 denotes the second element, g3 denotes the third element, e(·) denotes the bilinear pair from G1×G2 to G T the bilinear pair, G1 denotes the first additive cyclic group, G2 denotes the third additive cyclic group, R A denotes the temporary key exchange value of the client A, r B denotes the second random number, P pub-e denotes the encrypted public master key, P2 denotes the generator of the third additive cyclic group G2, de B denotes the encrypted private key of the edge node B.

[0057] Step D500: Calculate the first shared secret key of the edge node through the temporary key exchange value of the client, the temporary key exchange value of the edge node, and the element information;

[0058] In this step, the calculation formula for the first shared secret key is:

[0059] SK B = KDF(ID A ||ID B ||R A ||R B ||g1||g2||g3, klen)

[0060] In the formula, SK B denotes the first shared secret key, KDF(·) denotes the key derivation function, || denotes the data merging operation, ID A denotes the identity identifier of the client A, ID B denotes the identity identifier of the edge node B, R A denotes the temporary key exchange value of the client A, RB Denote the temporary key exchange value of edge node B, g1 denote the first element, g2 denote the second element, g3 denote the third element, and klen denote the key bit length.

[0061] Step D600: Send the temporary key exchange value of the edge node to the client;

[0062] Step D700: Determine by the client whether the temporary key exchange value of the edge node belongs to the first additive cyclic group. If so, calculate the second element information of the second multiplicative cyclic group through the temporary key exchange value of the client. Otherwise, return to Step D100 to perform key exchange again;

[0063] In this step, the second element information of the second multiplicative cyclic group G T includes the fourth element, the fifth element, and the sixth element. Among them, the calculation formula of the second element information is:

[0064]

[0065] In the formula, g1′ denote the fourth element, g2′ denote the fifth element, g3′ denote the sixth element, e(·) denote the bilinear pair from G1×G2 to G T of, G1 denote the first additive cyclic group, G2 denote the third additive cyclic group, R B denote the temporary key exchange value of edge node B, r A denote the first random number, P pub-e denote the encrypted public master key, P2 denote the generator of the third additive cyclic group G2, de A denote the encrypted private key of edge node A.

[0066] Step D800: Calculate the second shared secret key of the client through the temporary key exchange value of the client, the temporary key exchange value of the edge node, and the element information;

[0067] In this step, the calculation formula of the second shared secret key is:

[0068] SK A = KDF(ID A ||ID B ||R A ||R B ||g1′||g2′||g3′, klen)

[0069] In the formula, SK A denote the second shared secret key, KDF(·) denote the key derivation function, || denote the data merging operation, ID A denote the identity identifier of client A, ID B denote the identity identifier of edge node B, RA Represents the temporary key exchange value of client A, R B Represents the temporary key exchange value of edge node B, g1' represents the fourth element, g2' represents the fifth element, g3' represents the sixth element, and klen represents the key bit length.

[0070] Step D900: Determine whether the first shared secret key and the second shared secret key are equal. If so, use the first shared secret key as the shared key between the edge node and the client. Otherwise, return to step D100 to perform key exchange again.

[0071] Steps D100 to D900 are steps to generate a shared key for any client and any edge node. This step performs multiple authentications to prevent malicious middlemen from tampering with the calculation results and ensure that both the client and the edge node are indeed involved in a legitimate key exchange.

[0072] Step S300: Perform local training on the datasets of all clients, obtain local gradient shares based on the secret sharing algorithm, and encrypt the local gradient shares through the shared key to obtain the encrypted local gradient shares of each client;

[0073] In this embodiment, if it is the first round of training, each client downloads the initialized global model from the edge node as the local model. Otherwise, the client downloads the global gradient from the edge node and updates the local model.

[0074] The step S300 includes:

[0075] Step S301: Obtain the corresponding global gradient through each client;

[0076] Step S302: Update the local model of each client through the global gradient;

[0077] In this embodiment, the update formula of the local model is:

[0078]

[0079] In the formula, and respectively represent the local models of client A at the (t + 1)-th and t-th training, η represents the learning rate, represents the global gradient obtained at the t-th training.

[0080] Step S303: Perform local training on the dataset of the client through the local model to obtain the local gradient of each client;

[0081] Step S304: Normalize the local gradient to obtain the normalized local gradient of each client;

[0082] In this embodiment, a malicious client may intend not to normalize, thus introducing a large malicious gradient.

[0083] Step S305: Multiply the normalized local gradient by the precision parameter scalar to obtain an integer local gradient;

[0084] In this embodiment, the precision parameter scalar integerizes the floating-point gradient to obtain an integer local gradient.

[0085] Step S306: Generate secret shares of the integer local gradient through a secret sharing generation algorithm to obtain local gradient shares of each client;

[0086] In this embodiment, the Shamir secret sharing algorithm is used. The Shamir secret sharing algorithm includes a secret sharing generation algorithm and a secret recovery algorithm. Calculate the local gradient shares of each integer local gradient through the secret sharing generation algorithm, that is, the local gradient shares of each client.

[0087] Step S307: Encrypt the local gradient shares through the shared key to obtain encrypted local gradient shares of each client.

[0088] Step S400: Based on all the clients, send the encrypted local gradient shares to the edge node;

[0089] Step S500: Decrypt the encrypted local gradient shares through the shared key in the edge node, and calculate the global gradient of each client through the decrypted local gradient shares;

[0090] The step S500 includes:

[0091] Step S501: Decrypt the encrypted local gradient shares through the shared key in the edge node to obtain decrypted local gradient shares;

[0092] Step S502: Perform a normalization judgment on each local gradient share through a secret share dot product calculation method to obtain a normalization judgment result, and the normalization judgment result includes normalized and unnormalized;

[0093] The step S502 includes:

[0094] Step A100: Calculate the dot product of each local gradient share with itself through a secret share dot product calculation method in the edge node to obtain a first dot product result share of each local gradient share;

[0095] In this embodiment, the steps of calculating the dot product by the secret share dot product calculation method are as follows:

[0096] Obtain two input secret share vectors, namely [G] and [G'], where [G] = {[g1], …, [g n}, [G'] = {[g1'], …, [g n ']}, [g a and [g a '] respectively represent the a-th elements of the two input secret share vectors;

[0097] Calculate the dot product result of the two input secret share vectors through the secret share multiplication calculation method. The specific formula is:

[0098]

[0099] In the formula, SecDotProduct(·) represents the secret share dot product calculation formula, n represents the number of elements of the input secret share vector, SecMul(·) represents the secret share multiplication calculation formula, [g a and [g a '] respectively represent the a-th elements of the two input secret share vectors.

[0100] In this step, calculate the shares of the product of each pair of elements in the two secret shares through the secret share multiplication calculation formula. At the same time, in addition to the input, the secret share dot product calculation method also protects the privacy of the output, which means that during the execution of this algorithm, the edge node can only see the share corresponding to the dot product result.

[0101] In this embodiment, the steps of calculating the multiplication result by the secret share multiplication calculation method are as follows:

[0102] First, obtain two elements and public information parameters in the edge node, and calculate the local calculation result through the two elements and public information parameters.

[0103] Among them, the public information parameter is calculated by the Lagrange interpolation theorem. The calculation formula is:

[0104]

[0105] In the formula, β j represents the public information parameter of edge node j, N represents the number of edge nodes, e i and e j respectively represent the identity identifiers of edge node i and edge node j.

[0106] The calculation formula of the local calculation result is:

[0107] z j = [x]j·[y]j ·β j

[0108] In the formula, z j represents the local calculation result, [x] j represents the j'-th secret share of the element x held by the edge node j, [y] j represents the j'-th secret share of the element y of the edge node j, β j represents the public information parameter of the edge node j. Here, in this embodiment, it is set that the edge node only receives the secret shares corresponding to its own edge node number for all secrets. Therefore, the values of j' and j are equal.

[0109] Then, the secret shares of the local calculation result are generated through the secret share generation algorithm. Among them, the secret shares of the local calculation result are {[z j 1, [z j 2,…, [z j N}, [z j i′ represents the i'-th secret share of the local calculation result of the edge node j, i' ∈ [1, N], and N represents the number of edge nodes.

[0110] Secondly, the secret shares of the local calculation result are sent to the corresponding edge nodes according to the share labels of the secret shares of the local calculation result;

[0111] In this step, except for [z j j″ , the other secret shares of the local calculation result are sent accordingly. For example, [z j 1 is only sent to the edge node 1. Among them, [z j j″ represents the j''-th secret share of the local calculation result of the edge node j, and the values of j'' and j are equal.

[0112] Finally, the secret shares of the local calculation result sent by other edge nodes are obtained, and the multiplication result of the two elements is calculated.

[0113] In this step, the calculation formula of the multiplication result is:

[0114]

[0115] In the formula, h represents the multiplication result [x·y] j , that is, it represents the j * -th share of the multiplication result of the element x and the element y held by the edge node j, [z j j″ ​​​​​​​The j″-th secret share representing the local computation result of edge node j, [z i j″ The j″-th secret share representing the local computation result of edge node i, where j * is equal to the value of j.

[0116] In step A100, calculate the dot product of the local gradient share with itself to obtain the corresponding first dot product result share.

[0117] Step A200: Recover the first dot product result share through the secret recovery algorithm to obtain the dot product recovery result of each local gradient share;

[0118] Step A300: Calculate the ratio of the dot product recovery result to the square of the precision parameter scalar;

[0119] Step A400: Determine whether the ratio is one. If so, the normalization judgment result of this local gradient share is normalized; otherwise, the normalization judgment result of this local gradient share is not normalized.

[0120] In this embodiment, first calculate the first dot product result share, then perform recovery and exclude the precision parameter scalar. If the normalization judgment result is not equal to one, it indicates that this client has not been normalized and will be excluded. Then use the remaining local gradient shares to securely calculate the baseline gradient.

[0121] Step S503: Mark the local gradient shares with the normalization judgment result of being normalized;

[0122] Step S504: Calculate the baseline gradient through the marked local gradient shares;

[0123] In this embodiment, the baseline gradient is the local gradient with the greatest similarity to the global gradient of the previous round.

[0124] The step S504 includes:

[0125] Step B100: Calculate the cosine similarity between the marked local gradient shares and the global gradient obtained from the previous round of training to obtain the cosine similarity share of each marked local gradient share;

[0126] Step B200: Perform secret recovery calculation on the cosine similarity share through the secret recovery algorithm to obtain the restored cosine similarity of each marked local gradient share;

[0127] Step B300: Select the normalized local gradient of the client with the largest restored cosine similarity as the baseline gradient.

[0128] ​Step S505: Calculate the weight of each client by scaling the dot product attention mechanism and the baseline gradient;

[0129] The step S505 includes:

[0130] Step C100: Calculate the dot product of each local gradient share and the baseline gradient through the secret share dot product calculation method to obtain the second dot product result of each local gradient share;

[0131] Step C200: Scale the second dot product result according to the gradient dimension of the client to obtain the weight fraction share of each client;

[0132] In this embodiment, the calculation formula of the weight fraction share is:

[0133]

[0134] In the formula, [α A represents the weight fraction share of client A, represents the share of the baseline gradient at the t-th training, the share of, represents the local gradient share of client A, d represents the gradient dimension of the client, and M represents the index of the labeled client.

[0135] Step C300: Recover the weight fraction share through the secret recovery algorithm to obtain the weight fraction of each client;

[0136] Step C400: Calculate the weight through the normalization exponential function and the weight fraction to obtain the weight of each client.

[0137] In this embodiment, the calculation formula of the weight is:

[0138]

[0139] In the formula, ω A represents the weight of client A, α A represents the weight fraction of client A, and M represents the index of the labeled client.

[0140] Step S506: Perform secure aggregation on the local gradient share with the weight of the client to obtain the global gradient share;

[0141] Step S507: Recover the global gradient share through the secret recovery algorithm to obtain the global gradient of each client.

[0142] Step S600: Download the corresponding global gradient through the client, and perform local training on the next round of the client using the global gradient until the number of training times is reached, and end the secure training of zero-trust federated learning.

[0143] In summary, the present invention designs a zero-trust based federated learning architecture in an edge computing environment. By designing relevant algorithms, the security of federated learning is improved. Since the zero-trust architecture defaults to not trusting any participant, during the process of this federated learning, the authentication of all participants, the reliability of client data, and the security of interactions will be controlled and verified through strict mechanisms.

[0144] Meanwhile, in the edge environment, the SM9 key exchange algorithm is used to ensure the communication security during the federated learning process. The public key infrastructure is used to ensure the authentication of participating parties and secure key exchange. In this way, man-in-the-middle attacks are avoided, and it is ensured that the key will not be stolen or tampered with during transmission, thereby enhancing the confidentiality and integrity of the data transmission process. Especially in a complex edge computing environment, the SM9 key exchange algorithm can provide the necessary security guarantee.

[0145] And in federated learning, each edge node trains its local data. However, to protect privacy, the original gradient data is not directly shared. Therefore, the Shamir secret sharing method is used to split the sensitive gradient data into multiple shared shares, and the data can only be recovered when a sufficient number of participants come together. In this way, even if some nodes are attacked, the attacker cannot obtain valuable data from them. In edge computing, if some edge nodes are down or unstable, as long as the number of remaining nodes reaches the threshold, the integrity and security of privacy can still be ensured. At the same time, according to the linear characteristics of Shamir secret sharing, a secret share multiplication calculation method and a secret share dot product calculation method are designed, expanding the practicality of Shamir secret sharing so that it can be better used to defend against poisoning.

[0146] The present invention also excludes the attempts of some malicious clients to introduce large-amplitude malicious gradients that have a great adverse impact on the global gradient by determining whether the local gradients of the clients are normalized. Secondly, the local gradients of the clients in this round are compared with the global gradients of the previous round through the cosine similarity mechanism, and the most similar client gradients are selected as the baseline gradients. Then, the scaled dot-product attention mechanism is introduced to deeply compare the relationship between the remaining gradients and the baseline gradients. Finally, weights are attached to each client to reduce the adverse effects brought by malicious gradients and gradients with little contribution, but not completely exclude them, to prevent some clients with small contributions from being ignored, ensuring fairness. And it also combines the Shamir secret sharing method to implement a defense poisoning mechanism in the case of only the input of gradient secret shares, greatly reducing the adverse effects brought by malicious attackers while taking into account privacy.

[0147] Embodiment 2:

[0148] In this embodiment, two datasets are selected for simulation experiments, including the Fashion-MNIST dataset and the CIFAR-10 dataset. And the data distributions of the clients are set using independent and identically distributed (IID) and non-independent and identically distributed (non-IID).

[0149] The poisoning attack test is carried out using the method of the present invention and multiple existing federated learning algorithms. Among them, the existing federated learning algorithms used include Krum, Trimmed Mean, Median, GALAXY, CROSSBEAM, and ShieldFL, and the poisoning attacks use label flipping and backdoor attacks.

[0150] From Figures 3 - 6 As can be seen from the figure, the test accuracy of the method of the present invention is basically better than the currently popular federated learning algorithms in terms of different attack means, different iteration times, or different client poisoning ratios. Among them, Our scheme represents the method of the present invention. Therefore, the present invention has made remarkable progress in defending against poisoning, and the privacy protection strategy combined with the Shamir secret sharing method can also well protect the privacy data of the clients.

[0151] Embodiment 3:

[0152] This embodiment provides a secure training device for zero-trust federated learning for edge computing. The device includes:

[0153] An initial module for initializing training parameters, where the training parameters include a precision parameter scalar, an encrypted public key, and the identity identifiers of the clients and edge nodes;

[0154] A shared key generation module for generating shared keys for multiple clients and corresponding edge nodes through the SM9 key exchange algorithm and the training parameters;

[0155] A first calculation module for locally training the datasets of all clients, obtaining local gradient shares based on the secret sharing algorithm, and encrypting the local gradient shares through the shared key to obtain encrypted local gradient shares for each client;

[0156] A transmission module for sending the encrypted local gradient shares to the edge nodes based on all the clients;

[0157] A second calculation module for decrypting the encrypted local gradient shares through the shared key in the edge nodes and calculating the global gradient of each client through the decrypted local gradient shares;

[0158] A training module for downloading the corresponding global gradient by the client and performing local training of the next round of clients through the global gradient until the number of training times is reached, ending the secure training of zero-trust federated learning.

[0159] The first calculation module includes:

[0160] An acquisition unit for obtaining the corresponding global gradient through each client;

[0161] An update unit for updating the local model of each client through the global gradient;

[0162] A training unit for locally training the dataset of the client through the local model to obtain the local gradient of each client;

[0163] A normalization unit for normalizing the local gradient to obtain the normalized local gradient of each client;

[0164] A first calculation unit for multiplying the normalized local gradient by the precision parameter scalar to obtain an integer local gradient;

[0165] A second calculation unit for generating secret shares of the integer local gradient through the secret sharing algorithm to obtain local gradient shares of each client;

[0166] An encryption unit for encrypting the local gradient shares through the shared key to obtain encrypted local gradient shares for each client.

[0167] The second calculation module includes:

[0168] A decryption unit, configured to decrypt the encrypted local gradient share by using the shared key in the edge node to obtain a decrypted local gradient share;

[0169] A judgment unit, configured to perform a normalization judgment on each of the local gradient shares by using a secret share dot product calculation method to obtain a normalization judgment result, where the normalization judgment result includes normalized and unnormalized;

[0170] A marking unit, configured to mark the local gradient shares with a normalization judgment result of normalized;

[0171] A third calculation unit, configured to calculate a baseline gradient by using the marked local gradient shares;

[0172] A fourth calculation unit, configured to calculate the weight of each client by using a scaled dot product attention mechanism and the baseline gradient;

[0173] An aggregation unit, configured to perform secure aggregation on the weights of the clients and the local gradient shares to obtain a global gradient share;

[0174] A recovery unit, configured to recover the global gradient share by using a secret recovery algorithm to obtain the global gradient of each client.

[0175] The third calculation unit includes:

[0176] A fourth calculation unit, configured to calculate a cosine similarity share of each marked local gradient share by performing a cosine similarity calculation on the marked local gradient shares and the global gradient obtained in the previous round of training;

[0177] A fifth calculation unit, configured to perform a secret recovery calculation on the cosine similarity share by using a secret recovery algorithm to obtain a restored cosine similarity of each marked local gradient share;

[0178] A selection unit, configured to select the normalized local gradient of the client with the largest restored cosine similarity as the baseline gradient.

[0179] It should be noted that for the device in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated here.

[0180] The above are only preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

[0181] As described above, it is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.

Claims

1. A secure training method for zero-trust federated learning in edge computing, characterized in that, Including: Initializing training parameters, where the training parameters include a precision parameter scalar, an encrypted public master key, and the identity identifiers of the client and the edge node; Generating shared keys for multiple clients and corresponding edge nodes through the SM9 key exchange algorithm and the training parameters; Locally training the datasets of all clients, obtaining local gradient shares based on the secret sharing generation algorithm, and encrypting the local gradient shares through the shared key to obtain encrypted local gradient shares for each client; Based on all the clients, sending the encrypted local gradient shares to the edge nodes; In the edge node, decrypting the encrypted local gradient shares through the shared key, and calculating the global gradient of each client through the decrypted local gradient shares; Downloading the corresponding global gradient by the client, and performing local training of the next round of the client through the global gradient until the number of training times is reached, ending the secure training of zero-trust federated learning.

2. The secure training method for zero-trust federated learning for edge computing according to claim 1, wherein , The locally training the datasets of all clients, obtaining local gradient shares based on the secret sharing generation algorithm, and encrypting the local gradient shares through the shared key to obtain encrypted local gradient shares for each client includes: Obtaining the corresponding global gradient through each client; Updating the local model of each client through the global gradient; Locally training the datasets of the clients through the local model to obtain local gradients for each client; Normalizing the local gradients to obtain normalized local gradients for each client; Multiplying the normalized local gradients by the precision parameter scalar to obtain integer local gradients; Generating secret shares of the integer local gradients through the secret sharing generation algorithm to obtain local gradient shares for each client; Encrypting the local gradient shares through the shared key to obtain encrypted local gradient shares for each client.

3. The secure training method for zero-trust federated learning for edge computing according to claim 1, characterized in that , The decrypting the encrypted local gradient shares through the shared key in the edge node and calculating the global gradient of each client through the decrypted local gradient shares includes: In the edge node, decrypting the encrypted local gradient shares through the shared key to obtain decrypted local gradient shares; Performing normalization judgment on each local gradient share through the secret sharing dot product calculation method to obtain a normalization judgment result, where the normalization judgment result includes normalized and unnormalized; Marking the local gradient shares with the normalization judgment result of normalized; Calculating the baseline gradient through the marked local gradient shares; Calculating the weights of each client through the scaled dot product attention mechanism and the baseline gradient; Performing secure aggregation on the weights of the client and the local gradient shares to obtain global gradient shares; Recovering the global gradient shares through the secret recovery algorithm to obtain the global gradient of each client.

4. The secure training method for zero-trust federated learning for edge computing according to claim 3, wherein , Performing normalization judgment on each local gradient share through the secret sharing dot product calculation method to obtain a normalization judgment result, including: In the edge node, calculate the dot product of each local gradient share with itself through the secret share dot product calculation method to obtain the first dot product result share of each local gradient share; Restore the first dot product result share through the secret recovery algorithm to obtain the dot product recovery result of each local gradient share; Calculate the ratio of the dot product recovery result to the square of the precision parameter scalar; Judge whether the ratio is one. If so, the normalization judgment result of this local gradient share is normalized; otherwise, the normalization judgment result of this local gradient share is not normalized.

5. The secure training method for zero-trust federated learning for edge computing according to claim 3, wherein , calculating the baseline gradient through the marked local gradient share includes: Calculate the cosine similarity of each marked local gradient share by calculating the cosine similarity between the marked local gradient share and the global gradient obtained in the previous round of training to obtain the cosine similarity share of each marked local gradient share; Perform secret recovery calculation on the cosine similarity share through the secret recovery algorithm to obtain the restored cosine similarity of each marked local gradient share; Select the normalized local gradient of the client with the largest restored cosine similarity as the baseline gradient.

6. The secure training method for zero-trust federated learning for edge computing according to claim 3, characterized in that , calculating the weight of each client through the scaled dot product attention mechanism and the baseline gradient includes: Calculate the dot product of each local gradient share and the baseline gradient through the secret share dot product calculation method to obtain the second dot product result of each local gradient share; Scale the second dot product result according to the gradient dimension of the client to obtain the weight score share of each client; Restore the weight score share through the secret recovery algorithm to obtain the weight score of each client; Calculate the weight of each client through the normalization exponential function and the weight score.

7. A secure training device for zero-trust federated learning in edge computing, characterized in that, including: An initial module for initializing training parameters, where the training parameters include a precision parameter scalar, an encryption public key, and the identity identifiers of clients and edge nodes; A shared key generation module for generating shared keys for multiple clients and corresponding edge nodes through the SM9 key exchange algorithm and the training parameters; A first calculation module for locally training the datasets of all clients, obtaining local gradient shares based on the secret share generation algorithm, and encrypting the local gradient shares through the shared key to obtain the encrypted local gradient shares of each client; A transmission module for sending the encrypted local gradient shares to the edge nodes based on all the clients; A second calculation module for decrypting the encrypted local gradient shares through the shared key in the edge node and calculating the global gradient of each client through the decrypted local gradient shares; A training module for downloading the corresponding global gradient by the client and performing local training of the next round of clients through the global gradient until the number of training times is reached, ending the secure training of zero-trust federated learning.

8. The secure training device for zero-trust federated learning for edge computing according to claim 7, wherein, The first calculation module includes: An acquisition unit for acquiring the corresponding global gradient through each client; An update unit for updating the local model of each client through the global gradient; A training unit for locally training the dataset of the client through the local model to obtain the local gradients of each client; A normalization unit for normalizing the local gradients to obtain the normalized local gradients of each client; A first calculation unit for multiplying the normalized local gradients by the precision parameter scalar to obtain integer local gradients; A second calculation unit for generating secret shares of the integer local gradients through a secret share generation algorithm to obtain the local gradient shares of each client; An encryption unit for encrypting the local gradient shares through the shared key to obtain the encrypted local gradient shares of each client.

9. The secure training device for zero-trust federated learning for edge computing according to claim 7, wherein The second calculation module includes: A decryption unit for decrypting the encrypted local gradient shares through the shared key in the edge node to obtain the decrypted local gradient shares; A judgment unit for performing a normalization judgment on each of the local gradient shares through a secret share dot product calculation method to obtain a normalization judgment result, where the normalization judgment result includes normalized and unnormalized; A marking unit for marking the local gradient shares with a normalization judgment result of normalized; A third calculation unit for calculating a baseline gradient through the marked local gradient shares; A fourth calculation unit for calculating the weights of each client through a scaled dot product attention mechanism and the baseline gradient; An aggregation unit for securely aggregating the weights of the clients and the local gradient shares to obtain global gradient shares; A recovery unit for recovering the global gradient shares through a secret recovery algorithm to obtain the global gradients of each client.

10. The secure training device for zero-trust federated learning for edge computing according to claim 9, wherein, The third calculation unit includes: A fourth calculation unit for calculating the cosine similarity shares of each marked local gradient share through the marked local gradient shares and the global gradient obtained in the previous round of training; A fifth calculation unit for performing a secret recovery calculation on the cosine similarity shares through a secret recovery algorithm to obtain the restored cosine similarity of each marked local gradient share; A selection unit for selecting the normalized local gradient of the client with the largest restored cosine similarity as the baseline gradient.