Verifiable safe and efficient federated learning method

Through the hop-by-hop communication model and two-way authentication, mask and homomorphic hash encryption technology are used to solve the problems of client data leakage and dishonest aggregation of cloud servers in federated learning, improving the efficiency and security of federated learning, and especially suitable for IoT environments.

CN120358015APending Publication Date: 2025-07-22HEBEI UNIVERSITY
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202410081818.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-19
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

Existing federated learning methods are inadequate in protecting local models and data privacy of clients, preventing dishonest aggregation gradients of cloud servers, and preventing malicious clients from toxicizing federated learning processes, especially in inefficient and insecurity in IoT devices with limited computing power.

Method used

The hop-by-hop communication model is adopted, and local model parameters and shared session keys are protected using mask encryption and homomorphic hash encryption technology, and the identity of the client and cloud server is verified through two-way authentication, and a tree-like topological communication method is constructed to improve efficiency and security.

Benefits of technology

It realizes effective protection of client data, prevents dishonest aggregation of cloud servers, improves the efficiency and security of federated learning, reduces the computing burden of cloud servers, and ensures communication flexibility and credibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358015A_ABST
    Figure CN120358015A_ABST
Patent Text Reader

Abstract

The invention discloses a verifiable safe and efficient federal learning method. The method comprises the following steps: S1, constructing a hop-by-hop communication model; s2, the client and the cloud server both obtain a shared session key and a name identifier through information interaction; s3, each client performs mask encryption on the local model parameter and performs homomorphic hash encryption on the local model parameter and the shared session key, and transmits the mask encrypted local model parameter, the homomorphic hash encrypted shared session key and the name identifier of the leaf client to the cloud server; each client uploads the local model parameters subjected to homomorphic hash encryption to the client of the second layer, and the local model parameters are sent to each client by the client of the second layer; s4, the cloud server verifies the client, and if verification succeeds, model parameters are aggregated; and S5, the client verifies the cloud server, and if the verification succeeds, the client continues to participate in training. The safety of training in federated learning is improved through data encryption and identity authentication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for privacy protection, specifically a verifiable, secure and efficient federated learning method. Background Art

[0002] There is an obvious contradiction between data security issues and data island phenomena and the dependence on large-scale data collection and fusion necessary for the development of artificial intelligence technology. Without obtaining complete and substantial information for training models and promoting technological progress, the development of artificial intelligence applications will face severe constraints. The contradiction between the need for data fusion and data island phenomena is becoming increasingly prominent. Against this background, federated learning emerged. In 2017, Google first proposed a secure solution, federated learning. During the implementation of federated learning, the data of multiple participants does not need to be uploaded to a central server for joint training. Instead, after local training, the updated local parameters are uploaded to the server, and then the server performs centralized aggregation of the parameters. This process will be repeated until the model converges.

[0003] Although federated learning solves the problem of exposing data to third parties and has a natural protection effect on data privacy, there are still a large number of risks of privacy leakage. For example, during the gradient upload process, attackers may steal the gradients and infer sensitive information or training data of the clients. There may be malicious clients sending poisoned models to poison the entire federated learning process and reduce the model efficiency. The cloud server may not be as honest as it claims. On the one hand, the cloud server may only aggregate part of the gradients to save resources instead of honestly aggregating all gradients and using the idle resources to handle more beneficial things, resulting in low accuracy and unavailability of the trained model. On the other hand, an attacking opponent may attack and damage the cloud server, thus operating the global model and sending incorrect or damaged global models. Therefore, during the federated learning process, to solve the above problems, the uploaded gradients should be protected, and the clients and the cloud server should be verified.

[0004] In recent years, many scholars have proposed various solutions. Li et al. proposed a chain-based secure multi-party computation. All users form a chain. The first user generates a mask and adds it to the local gradient and sends it to the next user as the mask for the next user, and so on until the last user sends it to the cloud server. This solution protects the gradient and relieves the pressure on the cloud server. However, if there are many clients participating in the training, it will take a long time to execute one round of training, and there is no verification of users and the cloud server. Yang et al. proposed a secure and efficient federated learning scheme with verifiable weighted average aggregation. By using masking technology to encrypt the weighted gradient and data size, verifiable aggregation tags are designed, and an effective verification method is proposed to verify the weighted average aggregation result. In this solution, a key needs to be generated between each user, which is very unfriendly to devices with low computing power in the Internet of Things, and only the client verifies the correct aggregation of the cloud server, without two-way verification. Wei et al. proposed a lightweight privacy-preserving FedL solution. To protect the privacy of individual local data, a mask is added to the parameters. An effective secret sharing scheme is adopted to ensure that the mask can be accurately eliminated. However, this solution will increase the burden on the cloud server. If there are a large number of clients, the cloud server needs to recover each mask in the recovery stage of secret sharing, and the computing task is heavy. Therefore, for the privacy requirements of federated learning in the Internet of Things environment, the current methods have solved the problem to a certain extent, but there are still some limitations. Summary of the Invention

[0005] The purpose of the present invention is to provide a verifiable secure and efficient federated learning method to solve the problems of leakage of local models and data of clients, dishonest aggregation of all gradients by the cloud server, and poisoning of the federated learning process by malicious clients.

[0006] The purpose of the present invention is achieved as follows:

[0007] A verifiable secure and efficient federated learning method includes the following steps:

[0008] S1. Construct a hop-by-hop communication model, the hop-by-hop communication model includes a cloud server and m clients; the cloud server is the root node of the hop-by-hop communication model, the root node is the first layer of the hop-by-hop communication model, and the other layers of the hop-by-hop communication model are clients; the clients include s leaf clients, and the clients are at least 3 layers;

[0009] S2. Each client interacts with the cloud server, and the cloud server obtains the shared session keys and name identifiers of all clients, and each client obtains its corresponding shared session key;

[0010] S3. Each client in the hop-by-hop communication model performs masked encryption on the local model parameters, and performs homomorphic hashing encryption on the local model parameters and the shared session key respectively; each client uploads the masked local model parameters, the homomorphically hashed shared session key, and the name identifier of the leaf client to the parent node client until it is transmitted to the cloud server; each client uploads the homomorphically hashed local model parameters to the parent node client until it is transmitted to the clients in the second layer, and the clients in the second layer send the homomorphically hashed local model parameters to each client;

[0011] S4. The cloud server verifies the client identity based on the homomorphically hashed shared session key. When the client identity is correct, the cloud server decodes and aggregates the masked local model parameters based on the name identifier of the leaf client to obtain new global model parameters, and sends the new global model parameters to each client;

[0012] S5. Each client compares the new global model parameters with the homomorphically hashed local model parameters sent by each client in the second layer to verify the cloud server. When the verification is successful, it continues to participate in the next round of training. When the verification fails, it exits the training.

[0013] Furthermore, the specific method for a client to perform masked encryption on local model parameters is as follows:

[0014] S3a-1 The leaf client of the hop-by-hop communication model encrypts the local model parameters using a mask to obtain the masked local model parameters;

[0015] S3a-2 Each parent node client uses the masked local model parameters received from the child node client for the first time as a mask to encrypt the local model parameters of the parent node client, obtaining the masked local model parameters of the parent node client.

[0016] Furthermore, the specific method for the leaf client of the hop-by-hop communication model to encrypt the local model parameters using a mask is as follows:

[0017] S3a-1-1 Each leaf client uses the shared session key as the seed of a pseudo-random generator to generate a random number using the pseudo-random generator, and uses the random number as the mask:

[0018]

[0019] where, is the mask of leaf client s i and is the shared session key of leaf client s i ;

[0020] For each leaf client, the local model is encrypted based on the mask to obtain the encrypted local model parameters of the leaf client:

[0021]

[0022] Among them, is the leaf client s i The encrypted local model parameters, is the leaf client s i Local model parameters.

[0023] While supporting the aggregation of local model parameters, the present invention encrypts the local model parameters by using a mask (i.e., single hiding technology) to ensure that the local models and data of the participating clients are not leaked.

[0024] Further, the specific manner in which the client uploads the masked and encrypted local model parameters upward is as follows:

[0025] The client uploads the masked and encrypted local model parameters to the parent node client until they are transmitted to the cloud server. When a parent node client, after sending the masked and encrypted local model parameters of the parent node client to the corresponding parent node client, receives again the masked and encrypted local model parameters sent by other child node clients, it directly uploads the masked and encrypted local model parameters of the child node client to the corresponding parent node client until they are transmitted to the cloud server.

[0026] Further, the specific manner in which the client performs homomorphic hashing encryption on the local model parameters and the shared session key is as follows:

[0027] S3b-1 The trusted third party forwards the key σ of the homomorphic hashing function and the random value h to each client and the cloud server;

[0028] S3b-2 Each client performs homomorphic hashing calculation on the local model parameter W i And the shared session key sk i Based on the homomorphic hashing function key σ and the random value h:

[0029]

[0030]

[0031] Among them, Is the local model parameter after homomorphic hashing encryption, Is the shared session key after homomorphic hashing encryption.

[0032] Further, the specific way for the client to upload the homomorphically hashed shared session key is as follows:

[0033] S3c-1 Each leaf client transmits the homomorphically hashed shared session key to the parent node client;

[0034] S3c-2 Each parent node client calculates the homomorphically hashed shared session key by computing the homomorphically hashed shared session key of the parent node client and the homomorphically hashed shared session key sent by the child node client received for the first time, obtaining the calculation result of the homomorphically hashed shared session key;

[0035] S3c-3 Each parent node client uploads the calculation result of the homomorphically hashed shared session key and the homomorphically hashed shared session key sent by the child node client received for the second and subsequent times to the parent node client until it is transmitted to the cloud server.

[0036] Further, the specific way for the cloud server to verify the client identity according to the homomorphically hashed shared session key in step S4 is as follows:

[0037] S4-1 The cloud server merges the shared session keys corresponding to all clients to obtain a merged key, and performs a homomorphic hash calculation on the merged key according to the key σ and the random value h of the homomorphic hash function;

[0038] S4-2 The cloud server performs a multiplication calculation on the calculation result of the homomorphically hashed shared session key sent by each child node client and the homomorphically hashed shared session key sent by the child node client received for the second and subsequent times, obtaining the multiplication calculation result;

[0039] S4-3 Compare the merged key after homomorphic hash calculation with the multiplication calculation result. When the merged key after homomorphic hash calculation is the same as the multiplication calculation result, the client identity verification is successful. When the merged key after homomorphic hash calculation is different from the multiplication calculation result, the client identity verification fails.

[0040] The parent node client calculates the homomorphically hashed shared key of the parent node client and the homomorphically hashed shared session key of the child node client, reducing the latency consumed by the cloud server for aggregating the shared key, that is, reducing the latency of the server for authenticating the client; the parent node client calculates the masked encrypted local model parameters of the parent node client and the masked encrypted local model parameters of the child node client, reducing the latency consumed by the cloud server for aggregating the local model parameters and improving the efficiency of federated learning.

[0041] Further, the specific way for the client to upload the homomorphically hashed local model parameters is as follows:

[0042] In S3d-1, each leaf client transmits the homomorphically hashed local model parameters to the parent node client;

[0043] In S3d-2, each parent node client calculates the homomorphically hashed local model parameters of the parent node client and the homomorphically hashed local model parameters sent by the child node client received for the first time, and obtains the calculation result of the homomorphically hashed local model parameters;

[0044] In S3d-3, each parent node client transmits the calculation result of the homomorphically hashed local model parameters and the homomorphically hashed local model parameters sent by the child node client received for the second time and afterwards to the parent node client until it is transmitted to the client on the second layer of the hop-by-hop communication model. Each client on the second layer transmits the calculation result of the homomorphically hashed local model parameters and the homomorphically hashed local model parameters sent by the child node client received for the second time and afterwards to each client.

[0045] Furthermore, the specific method for the client to verify the cloud server is as follows:

[0046] In S5-1, the client performs homomorphic hashing calculation on the new global model parameters to obtain the new global model parameters after homomorphic hashing calculation;

[0047] In S5-2, the client multiplies the calculation results of the homomorphically hashed local model parameters sent by each client on the second layer and the homomorphically hashed local model parameters sent by the child node client received for the second time and afterwards, and obtains the result after multiplication calculation;

[0048] In S5-3, the client compares the new global model parameters after homomorphic hashing calculation with the result after multiplication calculation. When the new global model parameters after homomorphic hashing calculation are the same as the result after multiplication calculation, the verification is successful. When the new global model parameters after homomorphic hashing calculation are different from the result after multiplication calculation, the verification fails.

[0049] The present invention proposes a new communication method in federated learning, namely hop-by-hop communication. The tree-like topology of hop-by-hop communication adds flexibility to the entire system, enhances communication efficiency and security, and ensures communication security through the method of authentication and sharing session keys. This hierarchical data transmission method makes federated learning more efficient.

[0050] The present invention uses a two-way authentication method that involves the server's hash calculation of the shared session key and the client's hash calculation of the global gradient. The application of the two-way authentication method makes the system more secure and reliable. The cloud server authenticates the client to prevent malicious clients from poisoning the federated learning process. The client verifies the newly aggregated global model parameters formed by the cloud server to prevent the cloud server from dishonestly aggregating all gradients. The use of the homomorphic hash algorithm provides additional security for the verification between the client and the cloud server, enabling mutual identity confirmation and enhancing the security of data transmission. The present invention also strengthens the security of federated learning by encrypting local model parameters with masks before uploading them to the parent node client, thus preventing the leakage of local model parameters during data upload. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 It is a system model for hop-by-hop communication transmission.

[0052] Figure 2 It is a flow chart of hop-by-hop communication.

[0053] Figure 3 It is a flow chart for two-way verification between the cloud server and the client.

[0054] Figure 4 It is a comparison of the accuracies of different methods after 100 rounds of training on the independent and identically distributed MNIST dataset.

[0055] Figure 5 It is a comparison of the accuracies of different methods after 100 rounds of training on the non-independent and identically distributed MNIST dataset.

[0056] Figure 6 It is a comparison of the accuracies of different methods after 100 rounds of training on the independent and identically distributed CIFAR-100 dataset.

[0057] Figure 7 It is a comparison of the accuracies of different methods after 100 rounds of training on the non-independent and identically distributed CIFAR-100 dataset.

[0058] Figure 8 It is the running time of the complete federated learning training for different methods with different numbers of clients.

[0059] Figure 9 It is the latency consumed by clients for different methods with different numbers of clients.

[0060] Figure 10 It is the latency consumed by the cloud server for different methods with different numbers of clients.

[0061] Figure 11 It is the total latency corresponding to different methods. Detailed implementation manners

[0062] The present invention will be further described in detail below.

[0063] As Figure 1 shown, the verifiable secure and efficient federated learning method provided by the present invention specifically includes the following steps:

[0064] S1. Construct a hop-by-hop communication model.

[0065] The hop-by-hop communication model includes a cloud server and m clients; the clients include s leaf clients, the first layer is the root node cloud server, and the other layers are clients, and the clients are at least 3 layers.

[0066] S2. Each client interacts with the cloud server, the cloud server obtains the shared session keys and name identifiers of all clients, and each client obtains its corresponding shared session key.

[0067] The cloud server stores the shared session keys sk of all clients. Only both parties retain the session shared keys and will not be stolen by other clients or attackers.

[0068] S3. Each client in the hop-by-hop communication model performs masked encryption on the local model parameters, and performs homomorphic hash encryption on the local model parameters and the shared session keys respectively; each client uploads the masked local model parameters, the homomorphic hash-encrypted shared session keys, and the name identifiers of the leaf clients to the parent node client until it is transmitted to the cloud server; each client uploads the homomorphic hash-encrypted local model parameters to the parent node client until it is transmitted to the clients in the second layer, and the clients in the second layer send the homomorphic hash-encrypted local model parameters to each client

[0069] Each leaf client uses the shared session key with the cloud server as the seed of a Pseudorandom Generator (PRG) to generate a random number and use it as a mask to mask the local model parameters of the leaf client. The process of generating the mask is as follows:

[0070]

[0071] wherein, is the mask of the s i th leaf client, is the shared session key of the s i th leaf client.

[0072] The leaf client uses the mask Added to the local model parameters of the leaf client, the training process of the local model parameters is the same as that of FedProx. The process of the leaf client performing masked encryption on the local model parameters is as follows:

[0073]

[0074] Among them, is the local model parameter of leaf client s i after encrypted local model parameters, is the local model parameter of leaf client s i of.

[0075] In the hop-by-hop communication model, each client performs homomorphic hashing encryption on the local model parameters and the shared session key respectively. The leaf client sends the homomorphically hashed encrypted local model parameters and the shared session key to the parent node client.

[0076] The trusted third party forwards the key σ and the random value h of the homomorphic hashing function to each client and the cloud server, where h ∈ G.

[0077] The key σ of the cloud server and each client is equal, and the random value h of the cloud server and each client is equal.

[0078] Each client performs a homomorphic hashing operation on the local model parameter W i according to σ and h to obtain the homomorphically hashed encrypted local model parameter

[0079] Each client performs a homomorphic hashing operation on the shared session key sk i according to σ and h to obtain the homomorphically hashed encrypted shared session key

[0080] Each leaf client will send the name identifier id, and to the corresponding parent node client.

[0081] Each parent node client uses the masked encrypted local model parameter received from the corresponding child node client for the first time as a mask, and adds this mask to the local model parameter of the parent node client to perform masked encryption on the local model parameter of the parent node client.

[0082] After the parent node client of each layer has completed the calculation, it sends the calculation result and the name identifier of the leaf client to the corresponding parent node client until it is sent to the cloud server. During this process, a parent node client will receive data from multiple child node clients. When the parent node client of each layer receives the data sent by the child node for the second time, it does not need to perform any calculation and directly sends it to the parent node client until it is sent to the cloud server. That is, the local model parameters of the parent node client only participate in one addition during the mask encryption process. After the cloud server sends the aggregated global model parameters to each client, the data received by each parent node client for the first time is the data received by each parent node client for the first time.

[0083] Each parent node client performs a multiplication calculation on the homomorphically hashed encrypted local model parameters of the parent node client and the homomorphically hashed encrypted local model parameters sent by the corresponding child node client received for the first time. Each parent node client obtains the multiplication result of the homomorphically hashed encrypted local model parameters; each parent node client performs a multiplication calculation on the homomorphically hashed encrypted shared session key of the parent node client and the homomorphically hashed encrypted shared session key sent by the corresponding child node client received for the first time. Each parent node client obtains the multiplication result of the homomorphically hashed encrypted shared session key.

[0084] After the parent node client of each layer has completed the calculation, it sends the calculation result of the homomorphically hashed encrypted local model parameters and the calculation result of the homomorphically hashed encrypted shared session key to the corresponding parent node client until it is sent to the cloud server. When the parent node client of each layer receives the data sent by the child node for the second time, it does not need to perform any calculation and directly sends it to the parent node client until it is sent to the client of the second layer. That is, the local model parameters of the parent node client only participate in one multiplication during the homomorphic hashing encryption process, and when a parent node client sends the calculation result of the homomorphically hashed encrypted shared session key to the corresponding parent node client, it does not need to perform any calculation and directly sends it to the parent node client until it is sent to the cloud server. That is, the shared session key of the parent node client only participates in one multiplication during the homomorphic hashing encryption process. After the cloud server sends the aggregated global model parameters to each client, the data received by the parent node client for the first time is the data received by the parent node client for the first time.

[0085] As Figure 2 shown, the leaf client is client 1, the parent node of the penultimate layer is client 2, and the node of the nth layer is client n; the data received by the parent node client 2 for the first time is the data sent by the leaf client 1; the mask of client 1 is PRN1, the shared session key of client 1 is sk1, the shared session key of client 2 is sk2, and the shared session key of client n is skn .

[0086] W1′ is the masked encrypted local model parameter of client 1; H W1 H is the local model parameter of client 1 after homomorphic hash encryption; sk1 is the shared hash key after homomorphic hash encryption of client 1. W2′ is the local model parameter after mask encryption of client 2, W2 is the local model parameter of client 2; H W2 The local model parameters of client 2 are encrypted by homomorphic hashing; client 2 homomorphically hashes the local model parameters H of client 2. W2 The local model parameters H after homomorphic hash encryption with client 1 W1 Calculate and get H fw .H sk2 is the shared hash key encrypted by homomorphic hashing of client 2. Client 2 uses the shared hash key H encrypted by homomorphic hashing of client 2 sk2 The local model parameters H after homomorphic hash encryption with client 1 sk1 Calculate and get H fsk .

[0087] W n ′ is the local model parameter after mask encryption on the client side, where W n-1 ′ is the masked encrypted local model parameter of client n’s child node client n-1, W n H is the local model parameter of client n. Wn The local model parameters of client n are encrypted by homomorphic hashing. Client n will be the local model parameters H encrypted by homomorphic hashing of client n Wn Calculate the local model parameters after homomorphic hash encryption sent by other clients to get H sWn The shared hash key after homomorphic hash encryption on client n is H skn , client n homomorphically hashes the shared hash key H encrypted by client n skn Calculate the local model parameters after homomorphic hash encryption sent by other clients to get H ssk .

[0088] like Figure 3 As shown, client n will H sWn Send to each client, H ssk and W n ’ is sent to the cloud server.

[0089] S4. Figure 3As shown, the cloud server verifies the client identity based on the calculation result of the homomorphically hashed encrypted shared session key. When the client identity is correct, the cloud server decodes and aggregates the locally masked encrypted model parameters to obtain new global model parameters, and sends the new global model parameters to each client.

[0090] When there are r clients in the second layer, the cloud server receives the homomorphically hashed encrypted shared session key H nsk1 , …, The cloud server performs a multiplication calculation on the received homomorphically hashed encrypted shared session keys to obtain the calculation result H tsk 。

[0091] The cloud server merges the shared session keys sk i of all clients to obtain the merged shared session key SK: SK = sk1 + sk2 +... + sk m 。

[0092] The cloud server performs homomorphic hashing encryption on the merged shared session key SK according to the key σ and random value h of the homomorphic hash function to obtain H SK 。

[0093] The cloud server compares the calculated H SK with H tsk When each parent node client first receives the data sent by the corresponding all child node clients, the cloud server performs a comparison calculation when it first receives the data sent by the corresponding all child node clients.

[0094] After the cloud server receives the homomorphically hashed encrypted shared session key sent by the child node, it continuously verifies. When H SK and H tsk are not equal, the cloud server does not aggregate the received encrypted local model parameters; when H SK and H tsk are equal, the cloud server has received the data sent by all clients, and the clients are registered legal clients, then the cloud server aggregates according to the encrypted local model parameters sent by the clients.

[0095] The cloud server receives the name identifiers id1, id2,…, id s sent by each leaf client, as well as the locally masked encrypted model parameters. The cloud server performs an addition calculation on the received locally masked encrypted model parameters to obtain W G ′:

[0096] The cloud service searches for the corresponding shared session keys sk1, sk2,..., sk of each client according to the name identifiers sent by each leaf client s and uses each shared session key as a seed to generate masks PRN1, PRN2,..., PRN using a pseudo-random generator s The cloud server decrypts the masked encrypted local model parameters sent by the client according to the generated masks to obtain W G .

[0097] The cloud server calculates new global model parameters W G based on W t : and sends the new global model parameters W t to each client

[0098] S5. Each client compares the new global model parameters of the cloud server with the calculation results of the homomorphically hashed encrypted local model parameters sent by each client in the second layer to verify the cloud server. When the verification is successful, it continues to participate in the next round of training. When the verification fails, it exits the training

[0099] The client verifies the new global model W sent by the cloud server t Each client calculates the calculation results of the homomorphically hashed encrypted local model parameters sent by the clients in the second layer to obtain H SW :

[0100]

[0101] Each client performs a homomorphic hash calculation on the new global model parameters W sent by the cloud server t to obtain

[0102] Each client compares the calculated H SW and When each parent node client first receives the data sent by all its corresponding child node clients, the calculation for the cloud server to compare is

[0103]

[0104] After each client receives the calculation results of the homomorphically hashed encrypted local model parameters sent by the clients in the second layer and the new global model sent by the cloud server, it performs verification. When H SW and are not equal, the client exits the training; when H SW and When they are equal, the cloud server correctly aggregates all local models, and the client still participates in the next round of training.

[0105] The present invention uses Pytorch as an experimental platform, uses the publicly available datasets MNIST and CIFAR-100, and compares with the schemes of chain-PPFL, FedProx, FedProx DP, FedProx HE, and Wei. The simulation experiment uses a computer with an Intel(R) Core(TM) i5-10400F CPU@2.90GHz. In the comparative test of training accuracy, the two datasets are each divided into independent and identically distributed (IID) and non-independent and identically distributed non-IID. The number of clients participating in the training is 100.

[0106] As Figure 4 , Figure 5 , Figure 6 and Figure 7 shown, the training accuracy of the present invention is relatively close to that of chain-PPFL, FedProx (baseline FL), FedProx HE (HE-based FL), and the scheme of Wei et al. FedProx DP (DP-based FL) maintains privacy by adding noise to the original gradient. In order to improve the level of protecting model parameters, noise with a larger variance needs to be added, which will cause a decrease in training accuracy. The accuracy of FedProx DP is the worst, about 20% lower than other schemes in the IID scenario, and performs even worse in the non-IID scenario, about 20% lower than other schemes. In the scheme proposed in this paper, the mask can be eliminated, and the training accuracy can be the same as that of FedProx, and the number of training rounds does not increase, being close to FedProx. FedProx does not add privacy protection. Compared with FedProx, the present invention has higher security.

[0107] As Figure 8As shown, the time for a client to complete local training in the present invention is 2 s, and the data transmission delay can be ignored. The delay consumed by the client to generate a mask is 0.001 s, the aggregation time for two users is 0.005 s, the hashing encryption operation time is 0.001 s, and the delay to recover a secret in secret sharing is 0.07 s. According to the comparison of the binary tree for the solution of the present invention, FedProx HE has the largest delay because it needs to perform homomorphic encryption operations. The solution of Wei et al. uses secret sharing and needs to recover secrets during gradient aggregation, so the delay is lower than that of FedProx HE but higher than other solutions. Based on FedProx DP, chain-PPFL, and the solution of the present invention have comparable delays when the number of clients is small. However, as the number of clients increases, the delay consumed by chain-PPFL increases rapidly and gradually becomes higher than the solution of the present invention and the one based on FedProx DP. The solution proposed in the present invention consumes slightly more delay than FedProx DP, but the present invention adds a two-way verification stage and, through Figures 4 - 7 it can be seen that the training accuracy of the present invention is higher than that of FedProx DP, demonstrating the superiority of the present invention.

[0108] As Figure 9 , Figure 10 and Figure 11 shown, in the verification stage, the present invention proposes two-way verification, and the two-way verification stage uses homomorphic hashing operations. The present invention is compared with the solution of Yang et al. From Figure 9 it can be seen that the delay consumed by the client in the present invention is higher than that of the solution of Yang et al.; from Figure 10 it can be seen that the solution of Yang et al. consumes a relatively high delay and shows an upward trend; from Figure 11 it can be seen that when the number of clients is small, the gap between the two solutions is small. However, as the number of clients increases, the delay consumed by the solution of Yang et al. gradually increases, while the delay consumed by the present invention is less. The reason is that the tree structure proposed in the present invention can greatly reduce the delay consumed by the cloud server for aggregation, spreading the aggregation process to each client for synchronous execution, while other solutions are all aggregated by the cloud server uniformly and then proceed to the next step. When the number of clients increases, the superiority of the present solution is gradually reflected.

[0109] The solution proposed by Wei et al. is: Z. Wei, Q. Pei, N. Zhang, X. Lin, C. Wu and A. Taherkordi, "Lightweight Federated Learning for Large-Scale IoT Devices With Privacy Guarantee," in IEEE Internet of Things Journal, vol. 10, no. 4, pp. 3179-3191, 15 Feb. 15, 2023, doi: 10.1109 / JIOT.2021.3127886.

[0110] The solution of chain-PPFL is: Y. Li, Y. Zhou, A. Jolfaei, D. Yu, G. Xu and X. Zheng, "Privacy-Preserving Federated Learning Framework Based on Chained Secure Multiparty Computing," in IEEE Internet of Things Journal, vol. 8, no. 8, pp. 6178-6186, 15 April 15, 2021, doi: 10.1109 / JIOT.2020.3022911.

[0111] The solution proposed by Yang et al. is: Z. Yang, M. Zhou, H. Yu, R. O. Sinnott and H. Liu, "Efficient and Secure Federated Learning With Verifiable Weighted Average Aggregation," in IEEE Transactions on Network Science and Engineering, vol. 10, no. 1, pp. 205-222, 1 Jan.-Feb. 2023, doi: 10.1109 / TNSE.2022.3206243.

Claims

1. A verifiable, secure and efficient federated learning method, characterized in that, It includes the following steps: S1. Construct a hop-by-hop communication model, which includes a cloud server and m clients; the cloud server is the root node of the hop-by-hop communication model, the root node is the first layer of the hop-by-hop communication model, and the other layers of the hop-by-hop communication model are clients; the client includes s leaf clients, and the client is at least 3 layers; S2. Each client interacts with the cloud server. The cloud server obtains the shared session keys and name identifiers of all clients, and each client obtains its corresponding shared session key; S3. Each client in the hop-by-hop communication model performs masked encryption on the local model parameters and performs homomorphic hash encryption on the local model parameters and the shared session key respectively; each client uploads the masked local model parameters, the homomorphically hashed shared session key, and the name identifier of the leaf client to the parent node client until it is transmitted to the cloud server; Each client uploads the homomorphically hashed local model parameters to the parent node client until it is transmitted to the client in the second layer. The client in the second layer sends the homomorphically hashed local model parameters to each client; S4. The cloud server verifies the client identity according to the homomorphically hashed shared session key. If the client identity is correct, the cloud server decodes and aggregates the masked local model parameters according to the name identifiers of the leaf clients to obtain new global model parameters, and sends the new global model parameters to each client; S5. Each client compares the new global model parameters with the homomorphically hashed local model parameters sent by each client in the second layer to verify the cloud server. If the verification is successful, it continues to participate in the next round of training. If the verification fails, it exits the training.

2. The method according to claim 1, wherein The specific method for the client to perform masked encryption on the local model parameters is: S3a-1 The leaf client of the hop-by-hop communication model encrypts the local model parameters using a mask to obtain the masked local model parameters; S3a-2 Each parent node client uses the masked local model parameters received from the child node client for the first time as a mask to encrypt the local model parameters of the parent node client to obtain the masked local model parameters of the parent node client.

3. The verifiable secure and efficient federated learning method according to claim 2, wherein The specific method for the leaf client of the hop-by-hop communication model to encrypt the local model parameters using a mask is: S3a-1-1 Each leaf client uses the shared session key as the seed of the pseudo-random generator, generates a random number using the pseudo-random generator, and uses the random number as the mask: Among them, is the mask of leaf client s i , is the shared session key of leaf client s i . S3a-1-2 Each leaf client encrypts the local model based on the mask to obtain the encrypted local model parameters of the leaf client: Among them, is the leaf client s i encrypted local model parameters, is the leaf client s i local model parameters.

4. The verifiable, secure and efficient federated learning method according to claim 2, characterized in that The specific method for the client to upload the masked local model parameters is: The client uploads the masked and encrypted local model parameters to the parent node client until they are transmitted to the cloud server. If a parent node client, after sending the masked and encrypted local model parameters of the parent node client to the corresponding parent node client, receives again the masked and encrypted local model parameters sent by other child node clients, it directly uploads the masked and encrypted local model parameters of the child node client to the corresponding parent node client until they are transmitted to the cloud server.

5. The verifiable secure and efficient federated learning method according to claim 1, characterized in that, The specific method for the client to perform homomorphic hashing encryption on the local model parameters and the shared session key is as follows: S3b-1 The trusted third party forwards the key σ and the random value h of the homomorphic hashing function to each client and the cloud server; For each client in S3b-2, perform homomorphic hashing calculation on the local model parameters W according to the homomorphic hash function key σ and the random value h i and the shared session key sk i as follows: Among them, is the local model parameter after homomorphic hash encryption, is the shared session secret key after homomorphic hash encryption.

6. The verifiable, secure and efficient federated learning method according to claim 1, wherein The specific method for the client to upload the homomorphically hashed and encrypted shared session key is as follows: S3c-1 Each leaf client transmits the homomorphically hashed and encrypted shared session key to the parent node client; S3c-2 Each parent node client calculates the homomorphically hashed and encrypted shared session key by computing the homomorphically hashed and encrypted shared session key of the parent node client and the homomorphically hashed and encrypted shared session key sent by the child node client received for the first time, obtaining the calculation result of the homomorphically hashed and encrypted shared session key; S3c-3 Each parent node client uploads the calculation result of the homomorphically hashed and encrypted shared session key and the homomorphically hashed and encrypted shared session keys sent by the child node clients received the second time and afterwards to the parent node client until they are transmitted to the cloud server.

7. The verifiable secure and efficient federated learning method according to claim 6, wherein In step S4, the specific method for the cloud server to verify the client identity based on the homomorphically hashed and encrypted shared session key is as follows: S4-1 The cloud server combines all the shared session keys corresponding to the clients to obtain a combined key, and performs homomorphic hashing calculation on the combined key based on the key σ and the random value h of the homomorphic hashing function; S4-2 The cloud server performs a multiplication calculation on the calculation results of the homomorphically hashed and encrypted shared session keys sent by each child node client and the homomorphically hashed and encrypted shared session keys sent by the child node clients received the second time and afterwards, obtaining the multiplication calculation result; S4-3 Compare the combined key after homomorphic hashing calculation with the multiplication calculation result. If the combined key after homomorphic hashing calculation is the same as the multiplication calculation result, the client identity verification is successful; if the combined key after homomorphic hashing calculation is different from the multiplication calculation result, the client identity verification fails.

8. The verifiable, secure and efficient federated learning method according to claim 1, wherein The specific method for the client to upload the homomorphically hashed and encrypted local model parameters is as follows: S3d-1 Each leaf client transmits the homomorphically hashed and encrypted local model parameters to the parent node client; S3d-2 Each parent node client calculates the homomorphically hashed and encrypted local model parameters by computing the homomorphically hashed and encrypted local model parameters of the parent node client and the homomorphically hashed and encrypted local model parameters sent by the child node client received for the first time, obtaining the calculation result of the homomorphically hashed and encrypted local model parameters; For each parent node client in S3d-3, the calculation result of the homomorphically hashed local model parameters and the homomorphically hashed local model parameters sent by the child node clients received for the second time and later are transmitted upward to the parent node client until they are transmitted to the clients in the second layer of the hop-by-hop communication model. Each client in the second layer transmits the calculation result of the homomorphically hashed local model parameters and the homomorphically hashed local model parameters sent by the child node clients received for the second time and later to each client.

9. The verifiable, secure and efficient federated learning method according to claim 8, wherein The specific method for the client to verify the cloud server is as follows: S5-1 The client performs homomorphic hashing calculation on the new global model parameters to obtain the new global model parameters after homomorphic hashing calculation. S5-2 The client performs a multiplication calculation on the calculation results of the homomorphically hashed local model parameters sent by each client in the second layer and the homomorphically hashed local model parameters sent by the child node clients received for the second time and later to obtain the result after multiplication calculation. S5-3 The client compares the new global model parameters after homomorphic hashing calculation with the result after multiplication calculation. If the new global model parameters after homomorphic hashing calculation are the same as the result after multiplication calculation, the verification is successful; if the new global model parameters after homomorphic hashing calculation are different from the result after multiplication calculation, the verification fails.

Citation Information

Cited By

  • Network communication information encryption transmission method and system

    CN121125352A