Longitudinal federated learning-oriented back door detection and repair method and system
By building auxiliary data sets and alternative models, detecting and fixing backdoor attacks in vertical federated learning systems, the problem of malicious embedding vector attacks is solved, ensuring model accuracy and user privacy security.
Patent Information
- Application Number
- CN202510913732.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-03
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2045-07-03
AI Technical Summary
The existing vertical federated learning system faces the threat of backdoor attacks, and malicious parties may upload tampered embedding vectors to attack the model, resulting in classification errors.
By building auxiliary data sets, the alternative model is trained to simulate the feature extraction model of other participants, and combined with the updated feature extraction model and task output model of local participants, detect and repair the backdoor embedding vector, and use entropy value to judge the credibility and repair it.
It realizes effective detection and repair of backdoor attacks in vertical federated learning systems, protecting model accuracy and user data privacy.
Smart Images

Figure CN120408164A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and in particular, to a backdoor detection and repair method and system for vertical federated learning. Background Art
[0002] In the traditional machine learning training process, it is required that service providers collect user information for centralized training. However, user data is closely related to user sensitive information. If this information is leaked or exploited by service providers during the collection process, it will directly threaten the personal information security of users. Contradictorily, the training process of machine learning relies on a large amount of data collection and fusion. If rich information cannot be obtained to train the model, the performance of the model will be greatly limited. Against the background of the prominent contradiction between data islands and data fusion requirements, vertical federated learning technology has emerged. Vertical federated learning allows multiple participants who hold the same samples but different features to collaborate and learn by exchanging model embeddings. This solution does not require participants to transfer raw data, and improves the performance of machine learning models on the premise of avoiding the leakage of local private data.
[0003] Although existing vertical federated learning systems have achieved quite good performance, they still face the threat of backdoor attacks. In the backdoor attacks in the vertical federated learning scenario, malicious participants may upload tampered embeddings to misclassify the model into the target categories specified by the attacker. Summary of the Invention
[0004] The present invention provides a backdoor detection and repair method and system for vertical federated learning to solve the defect that the existing vertical federated learning system has the threat of backdoor attacks, and to detect and repair backdoor attacks in the vertical federated learning system.
[0005] The present invention provides a backdoor detection and repair method for vertical federated learning, including: Obtaining an auxiliary data set, where the auxiliary data set includes a plurality of complete samples, and the complete samples include complete sample features and corresponding labels; Constructing K-1 surrogate models, where the surrogate models are used to simulate the feature extraction models held by the remaining participants in vertical federated learning, and updating the surrogate models, the feature extraction model held by the local participant, and the task output model based on the auxiliary data set, where K is the number of participants in vertical federated learning; Based on the complete sample features in the auxiliary data set and the updated feature extraction model held by the local participant, obtaining a local embedding vector, and obtaining the to-be-detected embedding vectors generated by each of the remaining participants based on the to-be-predicted object; Input the combined detection vectors into the updated task output model to obtain the respective prediction results output by the task output model, and determine the backdoor embedding vector based on the prediction results. The combined detection vectors include the local embedding vector and one of the embedding vectors to be detected. Repair the backdoor embedding vector based on the updated feature extraction model held by the local party and the surrogate model corresponding to the backdoor embedding vector.
[0006] According to a method for backdoor detection and repair for vertical federated learning provided by the present invention, the updating of the surrogate model, the feature extraction model held by the local party, and the task output model based on the auxiliary dataset includes: Update the surrogate model, the feature extraction model held by the local party, and the task output model based on the following optimization objective: ; where represents the parameters of the feature extraction model held by the local party, represents the parameters of the surrogate model, represents the task output model, represents the labels in the auxiliary dataset. When k = 1, represents the sample features extracted from the complete sample features according to the feature dimensions held by the local party. When k = 2,..., K, represents the sample features extracted from the complete sample features according to the feature dimensions held by the party corresponding to the k-th surrogate model, is used to measure the difference between A and B.
[0007] According to a method for backdoor detection and repair for vertical federated learning provided by the present invention, the obtaining of the local embedding vector based on the complete sample features in the auxiliary dataset and the updated feature extraction model held by the local party includes: Sample the complete sample features corresponding to multiple categories in the auxiliary dataset, determine partial sample features based on the feature dimensions corresponding to the local party from the sampled complete sample features, and after inputting the respective partial sample features into the updated feature extraction model held by the local party, obtain the local embedding vectors corresponding to the respective categories.
[0008] According to a method for backdoor detection and repair for vertical federated learning provided by the present invention, the determining of the backdoor embedding vector based on the prediction results includes: Calculate the entropy value based on the prediction result, where the entropy value reflects the credibility of the to-be-detected embedded vector in the detection vector combination; When the entropy value is less than a preset threshold, determine that the to-be-detected embedded vector included in the detection vector combination is the backdoor embedded vector.
[0009] According to a backdoor detection and repair method for vertical federated learning provided by the present invention, the calculating the entropy value based on the prediction result includes: Calculate the entropy value based on the following formula: ; where C represents the number of categories, represents the prediction result corresponding to the probability of category j, , represents the updated task output model, represents the local embedded vector corresponding to the i-th category, represents the to-be-detected embedded vector of the k-th party.
[0010] According to a backdoor detection and repair method for vertical federated learning provided by the present invention, the repairing the backdoor embedded vector based on the updated feature extraction model held by the local party and the alternative model corresponding to the backdoor embedded vector includes: Repair the backdoor embedded vector based on the following formula: ; where, represents the repaired backdoor embedded vector, represents the embedded vector extracted by the local party from the to-be-predicted object based on the held updated feature extraction model, , when k = 1, represents the sample feature extracted from the complete sample feature according to the feature dimension held by the local party, represents the updated feature extraction model held by the local party, when k = 2, …, K - 1, represents the sample feature extracted from the complete sample feature according to the feature dimension held by the party corresponding to the k-th alternative model, represents the updated k-th alternative model held by the local party, and d represents the embedding dimension of the local party.
[0011] The present invention also provides a backdoor detection and repair system for vertical federated learning, including: An auxiliary dataset construction module for obtaining an auxiliary dataset, where the auxiliary dataset includes a plurality of complete samples, and each complete sample includes complete sample features and corresponding labels; A local model update module for constructing K - 1 surrogate models, where the surrogate models are used to simulate the feature extraction models held by the remaining parties in vertical federated learning, and updating the surrogate models, the feature extraction model held by the local party, and the task output model based on the auxiliary dataset, where K is the number of parties participating in vertical federated learning; An embedded vector acquisition module for obtaining local embedded vectors based on the complete sample features in the auxiliary dataset and the updated feature extraction model held by the local party, and acquiring the to - be - detected embedded vectors generated by each of the remaining parties based on the object to be predicted; A backdoor detection module for inputting a combination of detection vectors into the updated task output model to obtain respective prediction results output by the task output model, and determining backdoor embedded vectors based on the prediction results, where the combination of detection vectors includes the local embedded vector and one of the to - be - detected embedded vectors; A backdoor repair module for repairing the backdoor embedded vectors based on the updated feature extraction model held by the local party and the surrogate model corresponding to the backdoor embedded vectors.
[0012] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, where when the processor executes the program, it implements any one of the above - mentioned backdoor detection and repair methods for vertical federated learning.
[0013] The present invention also provides a non - transitory computer - readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements any one of the above - mentioned backdoor detection and repair methods for vertical federated learning.
[0014] The present invention also provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements any one of the above - mentioned backdoor detection and repair methods for vertical federated learning.
[0015] The backdoor detection and repair method and system for vertical federated learning provided by the present invention construct an auxiliary data set including complete sample features locally at the active participant, train the local feature extraction model and task output model based on the auxiliary data set, and train an alternative model for simulating the feature extraction models held by other participants. According to the updated feature extraction model held by the local participant, local embedding vectors are obtained, and the to-be-detected embedding vectors generated by the remaining participants based on the to-be-predicted object are acquired. After combining the local embedding vectors and the to-be-detected embedding vectors, they are input into the updated task output model. Based on the prediction result output by the task output model, it is determined whether the to-be-detected embedding vector is a backdoor embedding vector, and based on the updated feature extraction model held by the local participant and the alternative model corresponding to the backdoor embedding vector, the backdoor embedding vector is repaired, realizing backdoor detection and repair in the vertical federated learning system. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0017] Figure 1 is a schematic flowchart of the backdoor detection and repair method for vertical federated learning provided by the present invention.
[0018] Figure 2 is a block diagram of the algorithm logic of the backdoor detection and repair method for vertical federated learning provided by the present invention.
[0019] Figure 3 is a schematic structural diagram of the backdoor detection and repair system for vertical federated learning provided by the present invention.
[0020] Figure 4 is a schematic structural diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0021] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention with reference to the drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments in the present invention fall within the scope of protection of the present invention.
[0022] The following will be combined with Figure 1 - Figure 2 Describe the backdoor detection and repair method for vertical federated learning provided by the present invention, asFigure 1 As shown, the method includes the steps of: S110. Obtain an auxiliary data set, where the auxiliary data set includes multiple complete samples, and each complete sample includes complete sample features and corresponding labels; S120. Construct K - 1 surrogate models, where the surrogate models are used to simulate the feature extraction models held by the remaining parties in vertical federated learning, and update the surrogate models, the feature extraction model held by the local party, and the task output model based on the auxiliary data set, where K is the number of parties participating in vertical federated learning; S130. Based on the complete sample features in the auxiliary data set and the updated feature extraction model held by the local party, obtain a local embedding vector, and obtain the embedding vectors to be detected generated by each of the remaining parties based on the object to be predicted; S140. Input the combination of detection vectors into the updated task output model to obtain the respective prediction results output by the task output model, and determine the backdoor embedding vector based on the prediction results. The combination of detection vectors includes the local embedding vector and one embedding vector to be detected; S150. Repair the backdoor embedding vector based on the updated feature extraction model held by the local party and the surrogate model corresponding to the backdoor embedding vector.
[0023] The method provided by the present invention realizes backdoor detection and repair in a vertical federated learning system by constructing an auxiliary data set including complete sample features locally at the active party, training the local feature extraction model and task output model based on the auxiliary data set, training surrogate models for simulating the feature extraction models held by other parties, obtaining a local embedding vector according to the updated feature extraction model held by the local party, obtaining the embedding vectors to be detected generated by the remaining parties based on the object to be predicted, inputting the combination of the local embedding vector and the embedding vector to be detected into the updated task output model, determining whether the embedding vector to be detected is a backdoor embedding vector based on the prediction results output by the task output model, and repairing the backdoor embedding vector based on the updated feature extraction model held by the local party and the surrogate model corresponding to the backdoor embedding vector.
[0024] The method provided by the present invention is executed by the terminal corresponding to the active participant in vertical federated learning. For the convenience of understanding, a brief introduction to the vertical federated learning system is given first. There are K participants in the vertical federated learning system, one of which is the active participant, and the rest of the participants can be called passive participants. The active participant wants to train a model to perform a classification task. However, the active participant may not hold a large amount of complete sample features to support the training of the complete model. For example, assume that the active participant is a social platform that wants to classify users. In addition to the social data features of the users, it also needs the data features of the users on other platforms (such as e-commerce platforms). However, due to the consideration of user sensitive data security, the e-commerce platform may not provide this data to the social platform. Vertical federated learning can solve this problem. In vertical federated learning, each participant collaborates in training but does not involve the exchange of raw data between participants. Specifically, in the vertical federated learning system, each participant holds a feature extraction model locally. In addition to the feature extraction model, the active participant also holds a task output model. For the same object, the participants other than the active participant perform feature extraction on the partial feature data of the object held locally based on the locally held feature extraction model to obtain an embedding vector, and send the embedding vector to the active participant. The active participant performs feature extraction on the partial feature data of the object held locally based on the locally held feature extraction model to obtain an embedding vector, combines the embedding vector with the embedding vectors sent by the other participants to obtain a complete embedding vector, and inputs the complete embedding vector into the task output model to obtain the prediction result output by the task output model. This prediction result reflects the category of the object.
[0025] In the method provided by the present invention, in order to prevent malicious participants from existing among the participants other than the active participant, when sending the embedding vector to the active participant, it does not send the correct embedding vector, but a tampered backdoor embedding vector. The active participant can detect the embedding vectors sent by the other participants through the method provided by the present invention, identify the backdoor embedding vectors and repair them.
[0026] Specifically, the active participant constructs an auxiliary data set locally. The auxiliary data set includes multiple complete samples, and each complete sample includes complete sample features and corresponding labels. In practical applications, although the active participant cannot obtain a large number of complete sample features that can be used to support the model from initialization to training completion, it may be able to obtain some of the complete sample features. Based on these complete sample features, an auxiliary data set can be constructed. As previously exemplified, when the active participant is a social platform, it cannot obtain a large amount of e-commerce data features from other platforms to form the complete features of users. However, it can obtain some e-commerce data features through other legal channels, thereby obtaining some complete features of users. For example, it can obtain some complete sample features of users by conducting questionnaires among its employees or some authorized users, and thus an auxiliary data set can be constructed.
[0027] The local participant, i.e., the active participant, who executes the method provided by the present invention, utilizes the locally held auxiliary data set and the locally held trained feature extraction model and the task output model , to construct a surrogate model , where each surrogate model corresponds to one of the remaining participants. The input dimension of the surrogate model is the same as the dimension of the data features held locally by its corresponding participant. The model parameters are fine-tuned through the following optimization objective to update the surrogate model and the feature extraction model and the task output model held by the local participant: ; where, represents the parameters of the feature extraction model held by the local participant, represents the parameters of the surrogate model, represents the task output model, represents the labels in the auxiliary data set. When k = 1, represents the sample features extracted from the complete sample features according to the feature dimension held by the local participant. When k = 2, …, K - 1, represents the sample features extracted from the complete sample features according to the feature dimension held by the participant corresponding to the k-th surrogate model, is used to measure the difference between A and B.
[0028] The active participant fine-tunes the model parameters according to the above training objective to obtain . When k = 1, represents the updated parameters of the feature extraction model held locally by the active participant. When k = 2, …, K, denotes the updated parameters of the surrogate model corresponding to the k-th participant. denotes the updated parameters of the task output model locally held by the active participant. The active participant can simultaneously extract the correlation embedding vectors based on the updated surrogate model. , where denotes input into the updated surrogate model and outputs the embedding vector after processing.
[0029] After updating the model held by the local participant, based on the complete sample features in the auxiliary dataset and the updated feature extraction model held by the local participant, the local embedding vector is obtained, and the to-be-detected embedding vectors generated by each of the other participants based on the object to be predicted are acquired. Then, based on the local embedding vector and the to-be-detected embedding vectors, it is determined whether the to-be-detected embedding vectors are backdoor embedding vectors.
[0030] Specifically, obtaining the local embedding vector based on the complete sample features in the auxiliary dataset and the updated feature extraction model held by the local participant includes: Sampling the complete sample features corresponding to multiple categories in the auxiliary dataset, determining partial sample features based on the feature dimensions corresponding to the local participant from the sampled complete sample features, and after inputting the partial sample features into the updated feature extraction model held by the local participant respectively, obtaining the local embedding vectors corresponding to each category respectively.
[0031] As Figure 2 shown, the local participant samples from the auxiliary dataset inputs of different categories, extracts the corresponding embedding vectors as the local embedding vectors. That is to say, is to sample the complete sample features of the i-th category in the auxiliary dataset, extract the corresponding features from the complete sample features based on the input dimension of the local feature extraction model, and after inputting them into the locally held feature extraction model, the embedding vector output by the locally held feature extraction model.
[0032] For the local embedding vector corresponding to the i-th category, combine it with the embedding vector received from the passive participant to obtain the detection vector combination , where denotes the 0 vector. That is to say, fill the detection vector combination to the input dimension of the task output model. Input the detection vector combination into the task output model, and obtain the prediction result output by the task output model. Determine the backdoor embedding vector based on the prediction result, specifically including: Calculate the entropy value based on the prediction result, and the entropy value reflects the credibility of the embedding vector to be detected in the detection vector combination; When the entropy value is less than the preset threshold, determine that the embedding vector to be detected included in the detection vector combination is a backdoor embedding vector.
[0033] The entropy value corresponding to the k-th participant The calculation formula is: ; where C represents the number of categories, represents the prediction result is the probability corresponding to category j, , represents the updated task output model, represents the local embedding vector corresponding to the i-th category, represents the embedding vector to be detected of the k-th participant.
[0034] The active participant sets the backdoor embedding detection threshold , and this threshold can be obtained through experimental testing or calculated based on the data in the vertical federated learning process.
[0035] The active participant initializes the mask vector , with a length of , and the initial value is all 0; the active participant determines that if the entropy value is less than the preset threshold, that is , then set the mask to 1, and at the same time mark as the detected backdoor embedding vector. [[ID=:]]
[0036] For the detected backdoor embedding vector, the local-held alternative model can be used for recovery. Specifically, based on the updated feature extraction model held by the local participant and the alternative model corresponding to the backdoor embedding vector, repair the backdoor embedding vector, including: Repair the backdoor embedding vector based on the following formula: ; where, represents the repaired backdoor embedding vector, represents the embedding vector extracted by the local participant based on the held updated feature extraction model for the object to be predicted, , when k = 1, represents the sample feature extracted from the complete sample feature according to the feature dimension held by the local participant, represents the updated feature extraction model held by the local participant. When k = 2,..., K - 1, denotes the sample features extracted from the complete sample features according to the feature dimensions held by the parties corresponding to the k-th surrogate model, denotes the updated k-th surrogate model held by the local party, and d denotes the embedding dimension of the local party.
[0037] According to the repaired embedding vector, it is combined with the remaining non-backdoor embedding vectors and input into the task output model for model inference to obtain the output result.
[0038] The backdoor detection and repair system for vertical federated learning provided by the present invention will be described below. The backdoor detection and repair system for vertical federated learning described below can be correspondingly referred to the backdoor detection and repair method for vertical federated learning described above. As Figure 3 shown, the backdoor detection and repair system for vertical federated learning provided by the present invention includes: An auxiliary dataset construction module 310, configured to obtain an auxiliary dataset, where the auxiliary dataset includes a plurality of complete samples, and the complete samples include complete sample features and corresponding labels; A local model update module 320, configured to construct K-1 surrogate models, where the surrogate models are used to simulate the feature extraction models held by the remaining parties in vertical federated learning, and update the surrogate models, the feature extraction model held by the local party, and the task output model based on the auxiliary dataset, where K is the number of parties participating in vertical federated learning; An embedding vector acquisition module 330, configured to obtain a local embedding vector based on the complete sample features in the auxiliary dataset and the updated feature extraction model held by the local party, and obtain the to-be-detected embedding vectors generated by each of the remaining parties based on the object to be predicted; A backdoor detection module 340, configured to input the detection vector combination into the updated task output model to obtain each prediction result output by the task output model, and determine the backdoor embedding vector based on the prediction result, where the detection vector combination includes the local embedding vector and one to-be-detected embedding vector; A backdoor repair module 350, configured to repair the backdoor embedding vector based on the updated feature extraction model held by the local party and the surrogate model corresponding to the backdoor embedding vector.
[0039] Figure 4 Illustrates a schematic physical structure diagram of an electronic device, as Figure 4As shown, the electronic device may include: a processor 410, a communications interface 420, a memory 430, and a communication bus 440. Among them, the processor 410, the communications interface 420, and the memory 430 complete communication with each other through the communication bus 440. The processor 410 may call the logical instructions in the memory 430 to execute a backdoor detection and repair method for vertical federated learning. The backdoor detection and repair method for vertical federated learning includes: obtaining an auxiliary data set, where the auxiliary data set includes multiple complete samples, and the complete sample includes a complete sample feature and a corresponding label; constructing K - 1 surrogate models, where the surrogate models are used to simulate the feature extraction models held by the remaining participants in the vertical federated learning, and updating the surrogate models, the feature extraction model held by the local participant, and the task output model based on the auxiliary data set, where K is the number of participants in the vertical federated learning; obtaining a local embedding vector based on the complete sample features in the auxiliary data set and the updated feature extraction model held by the local participant, and obtaining the to - be - detected embedding vectors generated by each of the remaining participants based on the object to be predicted; inputting the combination of detection vectors into the updated task output model to obtain various prediction results output by the task output model, and determining the backdoor embedding vector based on the prediction results, where the combination of detection vectors includes the local embedding vector and one to - be - detected embedding vector; and repairing the backdoor embedding vector based on the updated feature extraction model held by the local participant and the surrogate model corresponding to the backdoor embedding vector.
[0040] In addition, when the logical instructions in the above - mentioned memory 430 are implemented in the form of software functional units and sold or used as an independent product, they can be stored in a computer - readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read - only memories (ROM, Read - Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0041] On the other hand, the present invention also provides a computer program product, which includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the backdoor detection and repair method for vertical federated learning provided by the above-mentioned various methods. The backdoor detection and repair method for vertical federated learning includes: obtaining an auxiliary data set, where the auxiliary data set includes a plurality of complete samples, and the complete samples include complete sample features and corresponding labels; constructing K - 1 surrogate models, where the surrogate models are used to simulate the feature extraction models held by the remaining participants in vertical federated learning, and updating the surrogate models, the feature extraction model held by the local participant, and the task output model based on the auxiliary data set, where K is the number of participants in vertical federated learning; obtaining a local embedding vector based on the complete sample features in the auxiliary data set and the updated feature extraction model held by the local participant, and obtaining the to-be-detected embedding vectors generated by each of the remaining participants based on the object to be predicted; inputting the combination of detection vectors into the updated task output model to obtain the respective prediction results output by the task output model, and determining the backdoor embedding vector based on the prediction results, where the combination of detection vectors includes the local embedding vector and one to-be-detected embedding vector; and repairing the backdoor embedding vector based on the updated feature extraction model held by the local participant and the surrogate model corresponding to the backdoor embedding vector.
[0042] In another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it realizes the backdoor detection and repair method for vertical federated learning provided by the above-mentioned various methods. The backdoor detection and repair method for vertical federated learning includes: obtaining an auxiliary data set, where the auxiliary data set includes a plurality of complete samples, and the complete samples include complete sample features and corresponding labels; constructing K - 1 surrogate models, where the surrogate models are used to simulate the feature extraction models held by the remaining participants in vertical federated learning, and updating the surrogate models, the feature extraction model held by the local participant, and the task output model based on the auxiliary data set, where K is the number of participants in vertical federated learning; obtaining a local embedding vector based on the complete sample features in the auxiliary data set and the updated feature extraction model held by the local participant, and obtaining the to-be-detected embedding vectors generated by each of the remaining participants based on the object to be predicted; inputting the combination of detection vectors into the updated task output model to obtain the respective prediction results output by the task output model, and determining the backdoor embedding vector based on the prediction results, where the combination of detection vectors includes the local embedding vector and one to-be-detected embedding vector; and repairing the backdoor embedding vector based on the updated feature extraction model held by the local participant and the surrogate model corresponding to the backdoor embedding vector.
[0043] The system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0044] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0045] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A backdoor detection and repair method for vertical federated learning, characterized in that Including: Obtain an auxiliary dataset, where the auxiliary dataset includes a plurality of complete samples, and each complete sample includes complete sample features and corresponding labels; Construct K - 1 surrogate models, where the surrogate models are used to simulate the feature extraction models held by the remaining parties in vertical federated learning, and update the surrogate models, the feature extraction model held by the local party, and the task output model based on the auxiliary dataset, where K is the number of parties participating in vertical federated learning; Based on the complete sample features in the auxiliary dataset and the updated feature extraction model held by the local party, obtain a local embedding vector, and acquire the to - be - detected embedding vectors generated by each of the remaining parties based on the object to be predicted; Input the combination of detection vectors into the updated task output model, obtain each prediction result output by the task output model, and determine the backdoor embedding vector based on the prediction results, where the combination of detection vectors includes the local embedding vector and one of the to - be - detected embedding vectors; Repair the backdoor embedding vector based on the updated feature extraction model held by the local party and the surrogate model corresponding to the backdoor embedding vector.
2. The backdoor detection and repair method for vertical federated learning according to claim 1, characterized in that The updating the surrogate models, the feature extraction model held by the local party, and the task output model based on the auxiliary dataset includes: Update the surrogate models, the feature extraction model held by the local party, and the task output model based on the following optimization objective: ; Among them, represents the parameters of the feature extraction model held by the local participant, represents the parameters of the alternative model, represents the task output model, represents the labels in the auxiliary dataset. When k = 1, represents the sample features extracted from the complete sample features according to the feature dimensions held by the local participant. When k = 2, …, K, represents the sample features extracted from the complete sample features according to the feature dimensions held by the participant corresponding to the k-th alternative model, is used to measure the difference between A and B.
3. The backdoor detection and repair method for vertical federated learning according to claim 1, wherein, The obtaining the local embedding vector based on the complete sample features in the auxiliary dataset and the updated feature extraction model held by the local party includes: Sample the complete sample features corresponding to multiple categories in the auxiliary dataset, determine partial sample features based on the feature dimensions corresponding to the local party from the sampled complete sample features, and after inputting each of the partial sample features into the updated feature extraction model held by the local party, obtain the local embedding vectors corresponding to each category.
4. The backdoor detection and repair method for vertical federated learning according to claim 3, characterized in that, The determining the backdoor embedding vector based on the prediction results includes: Calculate the entropy value based on the prediction results, where the entropy value reflects the credibility of the to - be - detected embedding vector in the combination of detection vectors; When the entropy value is less than a preset threshold, determine the to - be - detected embedding vector included in the combination of detection vectors as the backdoor embedding vector.
5. The backdoor detection and repair method for vertical federated learning according to claim 4, characterized in that The calculating the entropy value based on the prediction results includes: Calculate the entropy value based on the following formula: ; where C represents the number of said categories, represents the said prediction result corresponding to the probability of category j, , represents the updated said task output model, represents the said local embedding vector corresponding to the i-th category, represents the said embedding vector to be detected of the k-th said party.
6. The backdoor detection and repair method for vertical federated learning according to claim 1, wherein, The repairing the backdoor embedding vector based on the updated feature extraction model held by the local party and the surrogate model corresponding to the backdoor embedding vector includes: Repair the backdoor embedding vector based on the following formula: ; Among them, represents the repaired backdoor embedding vector. represents the embedding vector extracted by the local participant from the object to be predicted based on the updated feature extraction model held. When k = 1, represents the sample features extracted from the complete sample features according to the feature dimensions held by the local participant. represents the updated feature extraction model held by the local participant. When k = 2, …, K - 1, represents the sample features extracted from the complete sample features according to the feature dimensions held by the participant corresponding to the k-th alternative model. represents the updated k-th alternative model held by the local participant, and d represents the embedding dimension of the local participant.
7. A backdoor detection and repair system for vertical federated learning, characterized in that, The system includes: An auxiliary dataset construction module, configured to obtain an auxiliary dataset, where the auxiliary dataset includes a plurality of complete samples, and each complete sample includes complete sample features and corresponding labels; A local model update module, configured to build K-1 surrogate models, where the surrogate models are used to simulate the feature extraction models held by the remaining parties in vertical federated learning, and update the surrogate models, the feature extraction model held by the local party, and the task output model based on the auxiliary dataset, where K is the number of parties participating in vertical federated learning; An embedding vector acquisition module, configured to obtain a local embedding vector based on the complete sample features in the auxiliary dataset and the updated feature extraction model held by the local party, and obtain the to-be-detected embedding vectors generated by each of the remaining parties based on the object to be predicted; A backdoor detection module, configured to input a detection vector combination into the updated task output model to obtain respective prediction results output by the task output model, and determine a backdoor embedding vector based on the prediction results, where the detection vector combination includes the local embedding vector and one of the to-be-detected embedding vectors; A backdoor repair module, configured to repair the backdoor embedding vector based on the updated feature extraction model held by the local party and the surrogate model corresponding to the backdoor embedding vector; 8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the backdoor detection and repair method for vertical federated learning according to any one of claims 1 to 6; 9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the backdoor detection and repair method for vertical federated learning according to any one of claims 1 to 6; 10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the backdoor detection and repair method for vertical federated learning according to any one of claims 1 to 6;
Citation Information
Patent Citations
Federal learning-based backdoor attack defense method and system, and storable medium
CN113962322A
Federal learning backdoor attack-oriented defense method
CN118036770A