Model security aggregation system and method supporting client offline

Through the identity-based aggregation signature and single mask mechanism, the security and model aggregation verifiability problems when clients are disconnected in federated learning are solved, lightweight encryption and efficient aggregation are achieved, model integrity and privacy protection are ensured, and the risk of attacks on malicious servers is reduced.

CN120390211APending Publication Date: 2025-07-29ANHUI NORMAL UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510584934.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

There are problems with security when clients are disconnected and verifiability of model aggregation when they are disconnected, especially the risk of malicious aggregation server tampering with the aggregation results, resulting in reduced model accuracy and privacy leakage.

Method used

Using identity-based aggregation signature technology and a single mask mechanism, a verification mechanism is designed. The client encrypts the gradient during training and verifies the correctness of the aggregation result of the aggregation server through tokens to prevent malicious tampering.

Benefits of technology

It realizes lightweight encryption and efficient aggregation in client disconnection scenarios, ensures the integrity and privacy protection of model aggregation, reduces the risk of malicious server forgery results, and improves the robustness and efficiency of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120390211A_ABST
    Figure CN120390211A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a model security aggregation system and method supporting offline of a client, and belongs to the technical field of security and privacy protection of model aggregation. Comprising a client used for encrypting a gradient when local model training is executed; in the training process, the encrypted gradient and related auxiliary information are sent to an aggregation server; sending a token to an aggregation server to assist in recovering the aggregated gradient from the encryption gradients of the plurality of clients; verifying the correctness and integrity of the aggregation gradient returned by the aggregation server; the aggregation server side is used for aggregating the received encryption gradient, the auxiliary information and the token; and in each round of training, performing model updating by using the encryption gradient and the auxiliary information, and sending an aggregation result to the client. According to the method, a single mask mechanism and an identity-based aggregation signature verification mechanism are combined, so that safe aggregation of the model is realized, and a malicious aggregation server is prevented from tampering proof.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of security and privacy protection for model aggregation, and particularly to a model security aggregation system and method supporting client disconnection. Background Art

[0002] With the rapid development of intelligent sensing and wireless communication, the Internet of Medical Things (IoMT) realizes the collection and analysis of real-time health data through distributed intelligent devices, significantly improving the efficiency of intelligent healthcare and reducing the burden on hospitals. With the help of machine learning, IoMT can deeply explore the potential value of medical data and promote precise diagnosis and personalized diagnosis. However, the rapid growth and sensitivity of medical data pose severe challenges to centralized storage and sharing, including storage pressure, privacy leakage, and potential security risks.

[0003] To solve the above problems, Federated Learning (FL), as an emerging distributed learning paradigm, has been gradually applied to multiple fields such as healthcare, finance, and intelligent devices. According to the market estimate in 2023, the global FL market size is 136.89 million US dollars, and it is expected to grow at an annual compound growth rate of 13.7% by 2032. The FL framework allows multiple clients (including mobile phones or other mobile devices) to participate in model training collaboratively, thus realizing distributed learning. In the FL framework, millions of mobile devices cooperate through a central server in a cross-device scenario, ensuring the privacy and integrity of local data without sharing the original data. By allowing clients to train local data, FL significantly reduces the risk of privacy leakage compared to traditional centralized machine learning.

[0004] Although FL has significant advantages in protecting data privacy, existing research shows that it is still vulnerable to various attacks. For example, research shows that the gradient vectors sent by clients may leak sensitive information about private datasets, thus posing a potential threat to the security of the model. To solve this problem, some privacy protection aggregation technologies such as Secure Multi-party Computation (SMPC), Homomorphic Encryption (HE), and Differential Privacy (DP) have been proposed to enhance privacy protection in FL systems.

[0005] However, SMPC and HE will significantly increase communication and computational overheads, thus limiting their applications in FL systems with resource-constrained clients. In contrast, DP faces a trade-off between privacy protection and model performance. Therefore, it is particularly important to design a privacy-preserving aggregation protocol based on lightweight cryptographic methods to improve system efficiency while ensuring security. VerifyNet proposes a practical privacy-preserving aggregation protocol that combines pairwise addition masking and Shamir secret sharing techniques. This protocol uses a double masking algorithm to encrypt the local gradients of clients, ensuring resistance to the impact of client dropouts during the aggregation process. However, this scheme requires additional communication and computational overheads to reconstruct the masks of dropped clients. In addition, since the private key shares of clients are distributed to other clients, if some clients accidentally drop out during the aggregation process, their private keys may be leaked. This design makes it impossible for dropped clients to participate in future training securely unless they regenerate their keys, thus increasing the complexity of key management and potentially affecting the overall efficiency and security of the system.

[0006] In addition, ensuring the verifiability of model aggregation is a crucial security requirement in FL. In fact, the aggregation server may generate incorrect aggregation results. For example, a malicious aggregation server may directly tamper with the aggregation results or forge the aggregation results to deceive clients. In other words, it only aggregates the gradients of some clients, resulting in inaccurate aggregation results. Incorrect aggregation results will not only reduce model accuracy but may also cause the model to fail to converge. Therefore, it is crucial to verify the correctness of the aggregation results provided by the aggregation server. To address this issue, researchers have proposed various verifiable FL schemes. For example, researchers designed a verifiable secure aggregation method that uses bilinear aggregation signatures to verify the global gradients of the aggregation server. However, since clients use the same key for signing, this allows attackers to forge the proof of the aggregation results by bribing multiple clients and the aggregation server. Although some schemes design lightweight verification methods, these methods are still vulnerable to the threat of attackers tampering with the proof. In these schemes, clients cannot effectively resist the deception behavior of the aggregation server tampering with the aggregation results, especially in the absence of a strong anti-tampering mechanism. The aggregation server may mislead clients by tampering with the aggregation results or forging the proof, making clients mistakenly believe that the aggregation results are trustworthy. Therefore, existing schemes have not fully addressed the security issue of clients verifying the aggregation results. Summary of the Invention

[0007] The objective of the embodiments of the present invention is to provide a model secure aggregation system and method that support client disconnection. The model secure aggregation system and method that support client disconnection support lightweight encryption operations and efficient aggregation processes, while tolerating client disconnection. An identity-based aggregation signature is adopted to design a verification mechanism. This mechanism can effectively prevent malicious aggregation servers from tampering with the aggregation results, thereby detecting the deception of the aggregation results by the aggregation server.

[0008] To achieve the above objective, the embodiments of the present invention provide a model secure aggregation system that supports client disconnection. The model secure aggregation system that supports client disconnection includes:

[0009] Clients, used for:

[0010] When performing local model training, encrypt the gradients;

[0011] During the training process, send the encrypted gradients and relevant auxiliary information to the aggregation server;

[0012] Send a token to the aggregation server to assist in recovering the aggregated gradients from the encrypted gradients of multiple clients;

[0013] Verify the correctness and integrity of the aggregated gradients returned by the aggregation server;

[0014] The aggregation server side, used for:

[0015] Aggregate the received encrypted gradients, auxiliary information, and tokens;

[0016] In each round of training, use the encrypted gradients and auxiliary information to update the model, and send the aggregation result to the client.

[0017] In addition, the present invention also provides a model secure aggregation method that supports client disconnection. Using the above model secure aggregation system, the model secure aggregation method that supports client disconnection includes:

[0018] Step 1, initialize the model secure aggregation system;

[0019] Step 2, generate the ciphertext of the gradients and auxiliary information of the clients;

[0020] Step 3, generate the aggregated gradients and proofs of the aggregation server side;

[0021] Step 4, the client verifies the correctness of the aggregation result.

[0022] Preferably, initializing the model secure aggregation system in Step 1 includes:

[0023] Step 11. Assume there are n clients in the system, denoted as U = {u i , i ∈ [1, n]}; First, the KGC selects two cyclic groups G T and G with the same order p, and defines a bilinear pairing e: G × G → G T ; Then, the KGC selects a hash function H1: {0, 1} * → G and two generators g1 ∈ G and g2 ∈ G; Let PRG(·) be a pseudorandom number generator; The KGC selects a master key β ∈ Z p and calculates

[0024] Step 12. For each client u i , the KGC calculates a public-private key pair (pk i , sk i ); The KGC selects a random number x i ∈ Z p and calculates h i = H1(ID i ) and where ID i is the identity of the client; The public key and private key of the client are denoted as pk i = (h i , k i ) and In addition, the KGC is also responsible for selecting two seed sequences and for each client and sending them to each client; Then, the KGC publishes the public parameters Pub = (e, G, G T , g1, g2, h, H1, PRG(·)) and sends the public key pk i to the aggregation server; The aggregation server collects the public keys of all clients from the KGC and defines these clients as U0, where |U0| is the number of clients, and |U0| = n.

[0025] Preferably, generating the gradient ciphertext and auxiliary information of the client in step 2 includes:

[0026] Step 21. Assume the client u i has a local training set D i = {x j , y j}, where x j represents the input and y j represents the label, and T is the size of the client training set D i ; The loss function of the neural network can be expressed in the following form:

[0027]

[0028] Among them, L f (x j , y j ; w) represents the loss function; by training the neural network, the client can obtain the optimal gradient w, thereby minimizing L f ; at this stage, the client u i executes the backpropagation algorithm to calculate the local gradient w i :

[0029]

[0030] Among them, represents the derivative of L f ; is a subset randomly selected from D i ; during the subsequent encryption process, it is required that u i converts w i from a real number to a finite field;

[0031] Step 22, u i calculates and In addition, u i encrypts the gradient w i as:

[0032]

[0033] Step 23, the client negotiates a perturbation V ∈ {0, 1} * and a random value r i ∈ Z p ; then, u i generates auxiliary information:

[0034] σ i = (V, τ i , φ i )

[0035]

[0036] Step 24, u i sends the ciphertext c i and the auxiliary information σ i to the aggregation server; the aggregation server receives the messages from all clients and defines this group of clients as U1.

[0037] Preferably, generating the aggregation gradient and proof of the aggregation server in step 3 includes:

[0038] Step , upon receiving (c i , σ i) After that, the aggregation server performs decryption and aggregation operations; first, the aggregation server broadcasts the list of offline clients U0\U1 to the online clients U1; then, each online client in U1 calculates the token

[0039]

[0040] and sends ψ i to the aggregation server, where |U0|\|U1| represents the number of offline clients.

[0041] Step 32, the aggregation server calculates the aggregated gradient

[0042]

[0043]

[0044] Step 33, although some clients delay uploading their gradients, since the gradients are encrypted using random values, the aggregation server can maintain the confidentiality of the clients' sensitive information; however, these delayed clients will be removed and do not participate in this round of calculation; then, the aggregation server aggregates the auxiliary information from all clients in U1:

[0045]

[0046] The aggregated token is σ = (V, τ, φ); then, the aggregation server sends (W, σ) to all clients in U1.

[0047] Preferably, in step 4, the client verifying the correctness of the aggregation result includes:

[0048] Step 41, after obtaining the aggregated gradient and its corresponding proof, each client u i uses the proof to verify the following equation:

[0049]

[0050] Step 42, if the equation holds, the aggregated gradient is correct. u i accepts the aggregated gradient and updates its local model; otherwise, the client discards the aggregated gradient and enters the next round of training;

[0051] u i can detect the aggregation gradient deception of the aggregation server because the local gradient exists in both the aggregated gradient ciphertext and the proof σ = (V, τ, φ), where contains which can effectively protect the privacy of the local gradient w i The random values in the aggregated gradient ciphertext W * in can be completely offset by and in the aggregation token ψ; thus, and effectively prevent the aggregation server from tampering with the aggregated gradient W; is calculated by u i using its private key x i which makes it difficult for the aggregation server to tamper with the value of w in i ;

[0052] The verification process of the correctness of the equation is as follows:

[0053]

[0054] Step 43, at the end of this stage, u i updates the corresponding model parameters in each round using the aggregation result: w i = w i - ηW / |U1|.

[0055] In addition, the present invention also provides a machine-readable storage medium, on which instructions are stored, and the instructions are used to cause the machine to execute the above-mentioned model secure aggregation method supporting client disconnection.

[0056] In addition, the present invention also provides a processor for running a program, wherein the program, when run, is used to execute: the above-mentioned model secure aggregation method supporting client disconnection.

[0057] Through the above technical solutions, the present invention uses a single masking mechanism to achieve verifiable secure aggregation of the federated learning model, supports lightweight encryption and efficient aggregation in the scenario of client disconnection. Secondly, by adopting the identity-based aggregation signature technology, a dynamic verification mechanism is designed, which can detect the tampering of the result by a malicious server in real time during the aggregation process, thereby resisting the aggregation spoofing attack. In addition, while tolerating the abnormal exit of some clients, the present invention ensures the integrity and verifiability of the global model aggregation. The present invention not only solves the problems of large encryption overhead and poor fault tolerance in traditional federated learning, but also significantly reduces the risk of a malicious server forging the aggregation result, achieving a balance between privacy protection and computing efficiency, meeting the urgent needs and development trends of data security, system robustness and efficient aggregation in the distributed collaborative learning scenario.

[0058] Other features and advantages of the embodiments of the present invention will be described in detail in the subsequent detailed description part. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] The accompanying drawings are used to provide a further understanding of the embodiments of the present invention and form a part of the specification. Together with the following specific embodiments, they are used to explain the embodiments of the present invention, but do not constitute a limitation to the embodiments of the present invention. In the accompanying drawings:

[0060] Figure 1 It is a schematic diagram of the model of a method for secure aggregation of models supporting client disconnection according to the present invention;

[0061] Figure 2 It is a schematic flowchart of a method for secure aggregation of models supporting client disconnection according to the present invention. Specific Embodiments

[0062] The following will detail the specific embodiments of the embodiments of the present invention with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only used to illustrate and explain the embodiments of the present invention, and are not used to limit the embodiments of the present invention.

[0063] Embodiment 1

[0064] Figure 1 It is a schematic diagram of the model of a method for secure aggregation of models supporting client disconnection provided in Embodiment 1 of the present invention. As Figure 1 shown, the method for secure aggregation of models supporting client disconnection includes:

[0065] The client is used to: encrypt the gradient during local model training; during the training process, the client sends the encrypted gradient and related auxiliary information to the aggregation server; the online client sends a token to the aggregation server to assist in recovering the aggregated gradient from the encrypted gradients of multiple clients; and can verify the aggregated gradient returned by the aggregation server to ensure its correctness and integrity;

[0066] The aggregation server side is used to: aggregate the received encrypted gradients, auxiliary information, and tokens from the online client. In each round of training, the aggregation server uses the encrypted gradients and auxiliary information to update the model and sends the aggregation result to the online client.

[0067] Embodiment 2

[0068] As Figure 2 shown, a schematic flowchart of a method for secure aggregation of models supporting client disconnection includes the following steps:

[0069] Step 1, initialize the model secure aggregation system;

[0070] Step 2, generate the ciphertext of the gradient and auxiliary information of the client;

[0071] Step 3, generate the aggregated gradient and proof of the aggregation server side;

[0072] Step 4, the client verifies the correctness of the aggregation result.

[0073] In this implementation method, the system initialization method in Step 1 includes:

[0074] Step 11, assume there are n clients in the system, denoted as U = {u i , i ∈ [1, n]}. First, the KGC selects two cyclic groups G T and G with the same order p, and defines a bilinear pairing e: G × G → G T . Then, the KGC selects a hash function H1: {0, 1} * → G and two generators g1 ∈ G and g2 ∈ G. Let PRG(·) be a pseudorandom number generator. The KGC selects a master key β ∈ Z p and calculates

[0075] Step 12, for each client u i , the KGC calculates a public-private key pair (pk i , sk i ). The KGC selects a random number x i ∈ Z p and calculates h i = H1(ID i ) and where ID i is the identity of the client. The public key and private key of the client are denoted as pk i = (h i , k i ) and In addition, the KGC is also responsible for selecting two seed sequences and for each client and sending them to each client. Then, the KGC publishes the public parameters Pub = (e, G, G T , g1, g2, h, H1, PRG(·)) and sends the public key pk i to the aggregation server. The aggregation server collects the public keys of all clients from the KGC and defines these clients as U0, where |U0| is the number of clients, and |U0| = n.

[0076] In this implementation method, the method for gradient ciphertext and auxiliary information in Step 2 includes:

[0077] Step 21, assume the client u i has a local training set D i = {x j , y j}, where x j represents the input, yj Denote the label as T, and the size of the client training set D i is. The loss function of the neural network can be expressed in the following form:

[0078]

[0079] where L f (x j ,y j ; w) represents the loss function. By training the neural network, the client can obtain the optimal gradient w to minimize L f . At this stage, client u i executes the backpropagation algorithm to calculate the local gradient w i :

[0080]

[0081] where represents the derivative of L f . is a subset randomly selected from D i . In the subsequent encryption process, it is required that u i convert w i from a real number to a finite field.

[0082] Step 22, u i calculates and In addition, u i encrypts the gradient w i as:

[0083]

[0084] Step 23, the client negotiates a perturbation V ∈ {0,1} * and a random value r i ∈ Z p . Then, u i generates auxiliary information:

[0085] σ i =(V,τ i ,φ i )

[0086]

[0087] Step 24, finally, u i sends the ciphertext c i and the auxiliary information σ i to the aggregation server. The aggregation server receives messages from all clients and defines this group of clients as U1.

[0088] In this implementation method, the method for aggregating gradients and proofs in step 3 includes:

[0089] Step 31, after receiving (c i ,σ i ), the aggregation server performs decryption and aggregation operations. First, the aggregation server broadcasts the list of offline clients U0\U1 to the online clients U1. Then, each online client in U1 calculates the token

[0090]

[0091] and sends ψ i to the aggregation server, where |U0|\|U1| represents the number of offline clients. In particular, assuming that the online clients are relatively stable, these clients will not go offline during the token sending.

[0092] Step 32, the aggregation server calculates

[0093]

[0094] Then, it calculates

[0095]

[0096] and obtains the aggregated gradient

[0097]

[0098] Step 33, although some clients delay uploading their gradients, since the gradients are encrypted using random values, the aggregation server can maintain the confidentiality of the clients' sensitive information. However, these delayed clients will be removed and will not participate in this round of calculations. Then, the aggregation server aggregates the auxiliary information from all clients in U1:

[0099]

[0100] The aggregated token is σ = (V, τ, φ). Then, the aggregation server sends (W, σ) to all clients in U1.

[0101] In this implementation method, the method for verifying the correctness of the aggregation result in step 4 includes:

[0102] Step 41, after obtaining the aggregated gradient and its corresponding proof, each client u i uses this proof to verify the following equation:

[0103]

[0104] Step 42, if the equation holds, the aggregated gradient is correct. u iAccept the aggregated gradient and update its local model. Otherwise, the client discards the aggregated gradient and proceeds to the next round of training.

[0105] It is worth noting that u i can detect the aggregated gradient deception of the aggregation server because the local gradient exists in both the ciphertext of the aggregated gradient and the proof σ=(V,τ,φ), where contains This can effectively protect the privacy of the local gradient w i The random values in the ciphertext of the aggregated gradient W * can be completely cancelled out by those in the aggregation token ψ and and Therefore, and effectively prevent the aggregation server from tampering with the aggregated gradient W. is calculated by u i using its private key x i This makes it difficult for the aggregation server to tamper with the value of w in i Value.

[0106] Correctness: The process of verifying the correctness of the equation is as follows:

[0107]

[0108] Step 43, at the end of this stage, u i uses the aggregation result to update the corresponding model parameters in each round: w i =w i -ηW / |U1|.

[0109] In addition, the present invention also provides a machine-readable storage medium, on which instructions are stored, and the instructions are used to make a machine execute the above-mentioned model secure aggregation method that supports client disconnection.

[0110] In addition, the present invention also provides a processor for running a program, where the program, when running, is used to execute: the above-mentioned model secure aggregation method that supports client disconnection.

[0111] Those skilled in the art should understand that the embodiments of the present application can be provided in the form of a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0112] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and combinations of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to produce a machine, such that the instructions executed by the processors of the computer or other programmable data processing device generate means for implementing the functions specified in one Figure 1 flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0113] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means that implement the functions specified in one Figure 1 flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0114] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operational steps are performed on the computer or other programmable device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one Figure 1 flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0115] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0116] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.

[0117] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0118] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0119] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0120] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.

Claims

1. A model secure aggregation system that supports client disconnection, characterized in that, The model secure aggregation system supporting client disconnection includes: Clients, for: Encrypt the gradients during local model training; During the training process, send the encrypted gradients and related auxiliary information to the aggregation server; Send a token to the aggregation server to assist in recovering the aggregated gradients from the encrypted gradients of multiple clients; Verify the correctness and integrity of the aggregated gradients returned by the aggregation server; The aggregation server side, for: Aggregate the received encrypted gradients, auxiliary information, and tokens; In each round of training, use the encrypted gradients and auxiliary information to update the model and send the aggregation result to the client.

2. A model secure aggregation method supporting client disconnection, characterized in that, Using the model secure aggregation system described in claim 1, the model secure aggregation method supporting client disconnection includes: Step 1, initialize the model secure aggregation system; Step 2, generate the ciphertext of the gradients and auxiliary information of the clients; Step 3, generate the aggregated gradients and proofs of the aggregation server side; Step 4, the client verifies the correctness of the aggregation result.

3. The model security aggregation method supporting client disconnection according to claim 2, wherein Initializing the model secure aggregation system in step 1 includes: Step 11, assume there are n clients in the system, denoted as U = {u i , i ∈ [1, n]}; First, the KGC selects two cyclic groups G T and G with the same order p, and defines a bilinear pairing e: G × G → G T ; Then, the KGC selects a hash function H1: {0, 1} * → G and two generators g1 ∈ G and g2 ∈ G; Let PRG(·) be a pseudorandom number generator; The KGC selects a master key β ∈ Z p and calculates Step 12, for each client u i , the KGC calculates the public-private key pair (pk i , sk i ); the KGC selects a random number x i ∈ Z p and calculates h i = H1(ID i ) and where ID i is the identity of the client; the public key and private key of the client are represented as pk i = (h i , k i ) and In addition, the KGC is also responsible for selecting two seed sequences and for each client and sending them to each client; then, the KGC publishes the public parameters Pub = (e, G, G T , g1, g2, h, H1, PRG(·)) and sends the public key pk i to the aggregation server; the aggregation server collects all the clients' public keys from the KGC and defines these clients as U0, where |U0| is the number of clients, and |U0| = n.

4. The model security aggregation method for supporting client disconnection according to claim 3, wherein Generating the ciphertext of the gradients and auxiliary information of the clients in step 2 includes: Step 21, assume that client u i has a local training set D i ={x j ,y j}, where x j represents the input, y j represents the label, T is the size of the client training set D i ; the loss function of the neural network can be expressed in the following form: Among them, L f (x j , y j ; w) represents the loss function; by training the neural network, the client can obtain the optimal gradient w, thereby minimizing L f ; at this stage, the client u i executes the backpropagation algorithm to calculate the local gradient w i : Among them, represents the derivative of L f ; is a randomly selected subset from D i ; in the subsequent encryption process, it is required that u i convert w i from a real number to a finite field. Step 22, u i Calculate and In addition, u i Encrypt the gradient w i as: Step 23, the client negotiates a perturbation V ∈ {0, 1} * and a random value r i ∈ Z p ; then, u i generates auxiliary information: σ i =(V,τ i ,φ i ) Step 24, u i Send the ciphertext c i and the auxiliary information σ i to the aggregation server; the aggregation server receives messages from all clients and defines this set of clients as U1.

5. The method for securely aggregating models supporting client disconnection according to claim 4, wherein Generating the aggregated gradients and proofs of the aggregation server in step 3 includes: Step 31, after receiving (c i , σ i ), the aggregation server performs decryption and aggregation operations; first, the aggregation server broadcasts the list of dropped clients U0\U1 to the online clients U1; then, each online client in U1 calculates the token And send ψ i to the aggregation server, where |U0|\|U1| represents the number of dropped clients. Step 32, the aggregation server calculates the aggregated gradients Step 33, although some clients delay uploading their gradients, since the gradients are encrypted using random values, the aggregation server can maintain the confidentiality of client-sensitive information; however, these delayed clients will be removed and do not participate in this round of calculation; then, the aggregation server aggregates the auxiliary information from all clients in U1: The aggregated token is σ = (V, τ, φ); then, the aggregation server sends (W, σ) to all clients in U1.

6. The method for secure aggregation of models supporting client disconnection according to claim 5, wherein, In step 4, the client verifies the correctness of the aggregation result includes: Step 41, after obtaining the aggregated gradient and its corresponding proof, each client u i uses this proof to verify the following equation: Step 42, if the equation holds, the aggregated gradient is correct. u i Accept the aggregated gradient and update its local model; otherwise, the client will discard the aggregated gradient and proceed to the next round of training; u i It can detect the aggregation gradient deception of the aggregation server because the local gradient exists in the aggregation gradient ciphertext at the same time and in the proof of σ=(V,τ,φ), where contains This can effectively protect the privacy of the local gradient w i The random value in the aggregation gradient ciphertext W * can be completely offset by the in the aggregation token ψ; therefore and effectively prevent the aggregation server from tampering with the aggregation gradient W; and is calculated by u using its private key x i which makes it difficult for the aggregation server to tamper with the value of w in i ; w i ; The correctness verification process of the equation is as follows: Step 43, at the end of this stage, u i Update the corresponding model parameters in each round using the aggregation result: w i = w i - ηW / |U1|.

7. A machine-readable storage medium having instructions stored thereon, characterized in that, This instruction is used to cause a machine to execute the model secure aggregation method supporting client disconnection described in any one of claims 2-6.

8. A processor, characterized in that, For running a program, wherein when the program is run, it is used to execute: the model secure aggregation method supporting client disconnection described in any one of claims 2-6.