Model poisoning defense method, electronic equipment and readable storage medium

By obtaining the model and similarity information of neighboring participants for credibility assessment, and dynamically adjusting the model aggregation weight, the problem of model poisoning attack in fully decentralized distributed learning is solved, and the model performance and system robustness are improved.

CN120561599APending Publication Date: 2025-08-29BEIJING UNIV OF POSTS & TELECOMM

Patent Information

Application Number
CN202510404258.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-01
Publication Date
2025-08-29

AI Technical Summary

Technical Problem

In a fully decentralized distributed learning environment, it is difficult for existing technologies to effectively identify and defend against model poisoning attacks, resulting in degradation of model performance and lack of confidence evaluation from a global perspective and model aggregation optimization.

Method used

By obtaining model and similarity information of neighboring participants, using the target model to perform credibility evaluation, dynamically adjusting the model aggregation weight, optimizing the model aggregation process, and enhancing robustness.

Benefits of technology

In a fully decentralized environment, improve model performance and system robustness, effectively defend against model poisoning attacks, and improve the security and adaptability of the model aggregation process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120561599A_ABST
    Figure CN120561599A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a model poisoning defense method, electronic equipment and a readable storage medium. The method relates to the field of distributed training, and comprises the following steps: acquiring a first model trained by adjacent participants and first similarity information maintained by the adjacent participants; determining a second similarity between a target model trained by the target participant and the first model; according to the first similarity and the second similarity, performing credibility evaluation on whether the first model is subjected to the poisoning attack to obtain a credibility evaluation result of the first model; determining a model aggregation mode of the first model and the target model based on the credibility evaluation result; and according to the model aggregation mode, performing model aggregation processing on the target model and the first model to obtain an aggregated target model. According to the method and the device, the technical problem that the performance of the aggregated global model is reduced due to the fact that the attacked model is difficult to distinguish by related technologies for completely decentralized distributed training and then through a model aggregation process is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of distributed training technology, and in particular to a model poisoning defense method, electronic device, and readable storage medium. Background Art

[0002] The performance of machine learning models is highly dependent on the quality and integrity of their training data. However, this very characteristic also exposes them to the threat of poisoning attacks. A poisoning attack occurs when an attacker injects malicious samples into training data or tampers with existing data, disrupting the model's training process and thereby manipulating the model's output during inference. Such attacks pose a serious security risk to data-driven intelligent systems such as spam detection, facial recognition, and autonomous driving. In distributed learning systems, the attacker aims to disrupt the learning of the global model by tampering with the local data of each participant. Malicious attackers use data poisoning attacks to disrupt the model's training process, thereby reducing its accuracy or causing erroneous predictions.

[0003] The solutions provided by related technologies rely on at least one central node to identify data poisoning across multiple participants, making them unsuitable for fully decentralized distributed learning. Furthermore, because data poisoning targets training data rather than directly tampering with model parameters, the parameters of models trained with poisoned data are minimally different from those of normal models. Furthermore, related technologies fail to address how to correctly identify poisoned models when only local information is available and a global perspective is lacking, and thus fail to mitigate the negative impact of attacked models on training results. Therefore, related technologies lack the ability to defend against model poisoning in fully decentralized distributed learning.

[0004] There is currently no solution to the above problems. Summary of the Invention

[0005] The embodiments of the present application provide a model poisoning defense method, an electronic device, and a readable storage medium to alleviate or solve the technical problem that for completely decentralized distributed training, related technologies have difficulty in distinguishing attacked models, and then through the model aggregation process, the performance of the aggregated global model is reduced.

[0006] In a first aspect, embodiments of the present application provide a model poisoning defense method, which is applied to a target participant, and includes: Obtaining a first model trained by a neighboring participant and first similarity information maintained by the neighboring participant, wherein the first similarity information includes a first similarity between the first model and a neighbor model of the neighboring participant, the neighboring participant and the target participant are respectively adjacent to the neighboring participant, and the target participant is different from the neighboring participant; determining a second similarity between a target model trained by the target participant and the first model; Based on the first similarity and the second similarity, a credibility assessment is performed on whether the first model is subjected to a poisoning attack, thereby obtaining a credibility assessment result of the first model; the poisoning attack includes data poisoning of training data used by the first model, or model poisoning of model parameters of the first model; Determining a model aggregation method for the first model and the target model based on the credibility evaluation result, where the model aggregation method is used to control the influence of the first model on the target model during the model aggregation process; According to the model aggregation method, the target model and the first model are subjected to model aggregation processing to obtain an aggregated target model.

[0007] In a second aspect, an embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored in the memory, wherein the processor implements any method of the embodiment of the present application when executing the computer program.

[0008] In a third aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the method of any one of the embodiments of the present application is implemented.

[0009] Based on the model poisoning defense method of the first aspect mentioned above, the present application has at least the following beneficial effects or advantages: the target participant improves the model performance and enhances the robustness of the system by optimizing the model aggregation process in the distributed learning environment. Its purpose is to solve the problem that the related technology cannot effectively identify and filter the poisoned model in a completely decentralized environment, and lacks a global perspective to accurately distinguish between normal participants and data poisoned participants. By obtaining the first model of the adjacent participants and the first similarity information with the neighbor model, a global perspective is provided, and the credibility is evaluated in combination with the second similarity between the target model and the first model, so as to accurately screen and integrate model information. The model aggregation method is determined based on the credibility evaluation results to avoid the negative impact of the poisoned model on the target model, which significantly improves the defense capability against model poisoning in the distributed learning process.

[0010] The above description is only an overview of the technical solution of this application. In order to more clearly understand the technical means of this application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of this application more obvious and easy to understand, the specific implementation methods of this application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] In the accompanying drawings, unless otherwise specified, the same reference numerals throughout the multiple drawings represent the same or similar components or elements. These drawings are not necessarily drawn to scale. It should be understood that these drawings only depict some embodiments according to the present application and should not be regarded as limiting the scope of the present application.

[0012] Figure 1 A flow chart of the model poisoning defense method according to an embodiment of the present application is shown; Figure 2 A schematic diagram of cosine similarity according to an embodiment of the present application is shown; Figure 3 A schematic diagram of the model aggregation cycle provided by an embodiment of the present application is shown; Figure 4 A schematic diagram of the operation process provided by an embodiment of the present application is shown; Figure 5 A schematic diagram of attack detection provided by an embodiment of the present application is shown; Figure 6 A schematic diagram of the defense effect provided by an embodiment of the present application is shown; Figure 7 A schematic diagram of credibility evaluation provided by an embodiment of the present application is shown; Figure 8 A schematic diagram of the contribution weights of participants provided in an embodiment of the present application is shown; Figure 9 A schematic diagram of the structure of a model poisoning defense device according to an embodiment of the present application is shown; Figure 10 A block diagram of an electronic device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0013] Hereinafter, only certain exemplary embodiments are briefly described. As will be appreciated by those skilled in the art, the described embodiments may be modified in various ways without departing from the spirit or scope of the present application. Therefore, the drawings and description are to be regarded as illustrative in nature and not restrictive.

[0014] To facilitate understanding of the technical solutions of the embodiments of the present application, the following describes the related technologies of the embodiments of the present application. The following related technologies can be combined with the technical solutions of the embodiments of the present application as optional solutions, and all of them fall within the scope of protection of the embodiments of the present application.

[0015] The following terms will be used in the following text: Federated learning is a centralized machine learning framework that allows multiple clients (such as mobile devices or organizations) to collaboratively train models under the coordination of a central server (also known as a hub). This setup ensures that training data does not need to be uploaded to the cloud, thus protecting data privacy and security.

[0016] Distributed machine learning is a technology that breaks down machine learning tasks into multiple computing nodes for collaborative processing. By leveraging the computing resources of these participants to process learning tasks in parallel, it significantly improves training efficiency and scalability. In distributed learning systems, malicious attackers can disrupt model training through data poisoning attacks. The attacker's goal is to disrupt the global model's learning by tampering with the local data of each participant, thereby reducing its accuracy or causing incorrect predictions.

[0017] In distributed learning systems, attackers can tamper with local training datasets without the knowledge of participants, triggering data poisoning attacks. This requires each participant to instantly determine whether their neighbors are poisoned nodes during system training and mitigate the potential impact of suspicious participants on their models. However, existing technologies have significant limitations in addressing these issues.

[0018] A fully decentralized environment increases the difficulty of identifying data poisoning actors, necessitating a credibility assessment scheme that can accurately distinguish malicious actors from legitimate ones from a global perspective, without relying on centralized authority. However, related technologies often struggle to achieve this goal. One approach proposed by related technologies coordinates learning among participants through a voting mechanism and a two-tier scoring mechanism, while introducing gradient compression to reduce communication costs. This requires a coordination center for parameter transfer, making it unsuitable for fully decentralized systems. Furthermore, even in partially decentralized scenarios, the voting mechanism can fail due to collusion among malicious nodes, making it difficult to accurately identify poisoned nodes from a global perspective.

[0019] After completing the credibility assessment, it is necessary to screen out suspicious participants based on the assessment results, and reduce their negative impact on the global model through weight distribution, thereby improving the robustness of distributed training. According to another solution provided in the relevant technology, local similarity in decentralization is used to defend against model attacks in distributed learning, and the local model is used as a similarity reference to determine whether the received model is normal. The above solution is only applicable to situations where the model is directly attacked and the difference between the contaminated model and the normal model is large, and it cannot effectively defend against data poisoning attacks. Data poisoning attacks usually indirectly affect the model by tampering with the training data, so that the difference between the poisoned model and the normal model is not obvious, making it difficult to be identified by existing detection methods based on local similarity. There are problems such as insufficient ability to identify suspicious models and large limitations in identifying attack types.

[0020] Existing distributed learning poisoning defense technologies struggle to effectively address two key issues: credibility assessment and optimization of model aggregation weights in a fully decentralized environment. They are unable to accurately identify data poisoning (i.e., attacked) participants without relying on centralized authority, nor can they effectively optimize model aggregation based on credibility assessment results. Consequently, they are unable to effectively mitigate the negative impact of suspicious participants on the global model, limiting the robustness and security of distributed learning systems against data poisoning attacks.

[0021] The following describes in detail the technical solution of this application and how it solves the aforementioned technical problems using specific embodiments. The several specific embodiments listed can be combined with each other, and the same or similar concepts or processes may not be described in detail in some embodiments. The following describes the embodiments of this application in detail with reference to the accompanying drawings.

[0022] Figure 1 A flow chart of the model poisoning defense method according to an embodiment of the present application is shown. Figure 1 As shown, the method may include steps S101 to S105, and is applied to the target participant.

[0023] Step S101: obtaining a first model trained by a neighboring participant and first similarity information maintained by the neighboring participant, wherein the first similarity information includes a first similarity between the first model and a neighbor model of the neighboring participant, the neighboring participant and the target participant are respectively adjacent to the neighboring participant, and the target participant is different from the neighboring participant; Step S102: determining a second similarity between the target model trained by the target participant and the first model; Step S103: Based on the first similarity and the second similarity, a credibility evaluation is performed on the first model to determine whether it has been subjected to a poisoning attack, thereby obtaining a credibility evaluation result of the first model; the poisoning attack includes data poisoning of the training data used by the first model, or model poisoning of the model parameters of the first model; Step S104: determining a model aggregation mode of the first model and the target model based on the credibility evaluation result, where the model aggregation mode is used to control the influence of the first model on the target model during the model aggregation process; Step S105: performing model aggregation processing on the target model and the first model according to the model aggregation method to obtain an aggregated target model.

[0024] In a distributed learning or decentralized machine learning framework, a participant can refer to any entity capable of independently performing local model training, storing data, and participating in model synchronization and collaboration. These entities can include hardware-based end-user devices, Internet of Things (IoT) devices, edge computing devices, enterprise local servers, cloud virtual machine instances, and so on. These end-user devices can include smartphones or tablets. For example, in distributed learning, each user's phone can train an image classification model using local photos and then learn from models trained by other users. These IoT devices can include sensors, cameras, and smart home devices, for example, which can use local data to detect anomalies in objects. These edge computing devices can include industrial computers processing real-time production data, power monitoring equipment in power systems, and so on. Enterprise local servers can be private servers in institutions such as hospitals and banks. Cloud virtual machine instances can be distributed nodes simulated in a cloud environment.

[0025] In the examples provided herein, poisoning attacks can be categorized into two types: 1) data poisoning, which directly contaminates the training dataset, such as inserting mislabeled samples in a classification task or adding outliers to perturb the cluster center in a clustering task; and 2) model poisoning, in which an attacker manipulates the training process (e.g., malicious participants in federated learning) or modifies model parameters to implant backdoors or specific failure logic. For example, an attacker might use carefully crafted adversarial examples to cause the model to output incorrect predictions when presented with specific triggers (e.g., specific image patterns), while still performing normally with normal inputs, thereby covertly achieving the attack objective.

[0026] In an embodiment of the present application, in a distributed learning environment, in order to optimize the model aggregation process and improve model performance, the target participant obtains two types of information from its neighboring participants, including a first model trained by the neighboring participant and first similarity information. The first similarity information records the similarity between the first model and the neighbor model trained by the neighboring participant of the neighboring participant. The above-mentioned first similarity provides the perspective of other neighboring participants other than the target participant. By combining the first similarity between the neighbor model and the first model, combined with the second similarity between the target model and the first model, more comprehensive information can be provided for the first model, and a credibility assessment result of the first model can be obtained. The credibility assessment result determines the degree of influence of the first model on the target model in the subsequent model aggregation process. Based on the model aggregation method determined by the credibility assessment result, the target participant performs model aggregation processing on the target model and the first model to obtain the aggregated target model. Through the above-mentioned processing, the target participant can effectively filter and integrate model information from neighboring participants, avoid the negative impact of the attacked model on its own model, enhance the robustness and adaptability of the model in a complex distributed environment, and have stronger defense capabilities against potential model attacks.

[0027] Specifically, the above model aggregation method can be performed using a synchronization matrix, which can be denoted as A and is determined based on the communication topology. Each element of the synchronization matrix A Indicates the participants During the model aggregation process, The weight of the model. By properly designing the synchronization matrix A, the contribution of each participant model in the aggregation process can be dynamically adjusted to optimize the performance of the global model. In a distributed learning environment, the communication topology describes the connection relationship between the participants, and the synchronization matrix defines the weight distribution in the model aggregation process based on this connection relationship. and participants In the communication topology, if they are directly connected, May be nonzero; otherwise, is zero.

[0028] According to an optional embodiment provided by the present application, in step 101: obtain a first model trained by an adjacent participant, and first similarity information maintained by the adjacent participant, wherein the first similarity information includes a first similarity between the first model and a neighbor model of the neighbor participant, the neighbor participant and the target participant are adjacent to the adjacent participant, respectively, and the target participant is different from the neighbor participant. The above-mentioned first similarity information can be represented in a variety of forms, for example, it can be represented as a similarity matrix, wherein the rows and columns of the matrix correspond to different participants, respectively, and each element in the matrix represents the similarity between the corresponding models of different participants. The first similarity information can also be represented by other data structures such as vectors and graphs, without specific limitation.

[0029] For example, in a fully decentralized distributed learning environment, the training process must occur without a centralized authority, while ensuring efficient and secure model aggregation and updates. In this communication topology, the relationships and information exchange between the target, adjacent, and neighboring participants are as follows: Each participant (including the target, adjacent, and neighboring participants) starts with the same model and independently trains their own model on a local dataset. Initial learning is performed using their own local data, resulting in model differences based on their respective data distributions. During model aggregation, participants need to share their trained model parameters with their neighboring participants. This distributed learning approach enables model training to leverage diverse data distributed across different devices or institutions, which helps improve model generalization.

[0030] The communication topology includes the target participant, adjacent participants, and neighbor participants. The target participant is directly connected to the adjacent participants, and the target participant is indirectly connected to the neighbor participants through the adjacent participants. Both the target participant and the neighbor participants need to evaluate the first model of the neighbor participant. The target participant cannot directly exchange models or similarity information with the neighbor participants. The target participant can obtain information about the neighbor participants indirectly through the adjacent participants. Each participant in the communication topology maintains similarity information on its own node. This similarity information is the first similarity information for the neighbor participants.

[0031] For ease of understanding, let's take an example. Suppose neighboring participant A is connected to multiple neighboring participants B, C, and D. Neighboring participant A can calculate the similarity between its trained first model and the neighboring models of neighboring participants B, C, and D. Similarly, neighboring participants B, C, and D can also calculate the similarity of their first models (i.e., the first similarity mentioned above). The target participant obtains the first similarity information through neighboring participant A, thereby indirectly understanding the different perspectives of multiple neighboring participants. This multi-perspective information fusion not only enhances the accuracy of credibility assessments but also enables the target participant to construct a global perspective based on local information in a fully decentralized environment, without relying on centralized verification mechanisms. Therefore, the first similarity information provides richer contextual information for the model aggregation process in a distributed learning environment, helping to improve the robustness and security of the model aggregation process.

[0032] According to an optional embodiment provided by the present application, in step 102: a second similarity between the target model trained by the target participant and the first model is determined. There are multiple methods for determining the second similarity, such as cosine similarity or cluster analysis, which are described below.

[0033] Cosine similarity is a metric used to evaluate the similarity of two non-zero vectors in the inner product space by calculating the cosine of the angle between the two non-zero vectors. and , their cosine similarity is calculated by the following formula:

[0034] Dot Product Represents a vector and The sum of the products of the corresponding components. Vector and The Euclidean norm (or modulus) of and , which can be calculated as Figure 2The cosine similarity value range is [−1, 1]: when the value is 1, it indicates that the two vectors are in exactly the same direction, that is, the angle between them is 0°; when the value is 0, it indicates that the two vectors are orthogonal (perpendicular) and have no linear correlation; when the value is -1, the two vectors are in completely opposite directions, and the angle between them is 180°.

[0035] To evaluate the similarity between two models, we can expand them into one-dimensional vectors and calculate their cosine similarity. Similarly, we can also use this method to evaluate the similarity of the update directions of two models. When the update directions of two models are similar, for example Figure 2 in and , the cosine similarity should be close to 1; and It represents an incorrect update direction, so the calculated result It will be close to 0 or even -1. Through the above processing method, the participants of data poisoning can be detected.

[0036] In an optional embodiment of the present application, the method further includes: the target participant maintains second similarity information, and uses the first similarity information and the second similarity to update the second similarity information respectively to obtain updated second similarity information.

[0037] Each participant maintains a dynamically updated similarity matrix locally (i.e. the similarity information mentioned above), where the matrix elements are defined as binary forms, for example In order to facilitate the expression, the target participants are mainly Describes the perspective. The value of For participants The cosine similarity calculation results are: It represents the calculation round of this data. If no result has been obtained yet, it is considered invalid data and recorded as Through the data synchronization mechanism, after the target participant completes the similarity calculation, it immediately updates its own similarity matrix (i.e., the second similarity information mentioned above) and synchronously transmits the currently maintained similarity matrix when exchanging model parameters. At the same time, each participant promptly updates its local similarity matrix after receiving the similarity matrix (i.e., the first similarity information) sent by the adjacent node.

[0038] According to an optional embodiment provided by the present application, in step S103: based on the first similarity and the second similarity, a credibility evaluation is performed on whether the first model is subjected to a poisoning attack to obtain a credibility evaluation result of the first model, specifically including the following steps: Obtaining a global similarity based on the first similarity and the second similarity; The credibility evaluation result is determined according to the global similarity and the historical evaluation results of the target participant on the first model in historical training rounds.

[0039] In an embodiment of the present application, the target participant obtains the first similarity information provided by the adjacent participant, and the first similarity information reflects the similarity between the first model and the neighboring participant's model. At the same time, the target participant calculates the second similarity between its own model (target model) and the first model. Based on the first similarity and the second similarity, the target participant further calculates the global similarity. The global similarity integrates information from multiple angles and can more comprehensively reflect the characteristics and credibility of the first model. The target participant will also refer to its own historical evaluation results of the first model in historical training rounds. The above historical evaluation results provide reference information about the past performance of the first model, which helps to judge its long-term stability and reliability. By combining the global similarity and historical evaluation results, the target participant finally determines the credibility evaluation result of the first model.

[0040] This process not only considers the direct similarity between the target participant and its neighbors, but also indirectly references information about neighboring participants, providing a more comprehensive evaluation perspective. The inclusion of historical evaluation results further enhances the accuracy of credibility assessments. Historical data can reflect the performance of the first model across different training rounds, helping the target participant identify models with potential data poisoning.

[0041] For example, both global similarity and the trustworthiness assessment structure combine two parameters, using methods such as exponential weighting, recursive weighted averaging, the Analytic Hierarchy Process (AHP), and machine learning-based fusion. The exponentially weighted moving average (EWMA) is a dynamic weighting method that assigns higher weights to recent data while retaining the influence of historical data. The recursive weighted average (RWA) is a step-by-step updating method that gradually adjusts the weights based on the previous results. The AHP constructs a hierarchical model, uses the first and second similarities as evaluation indicators, and uses expert scores or historical data to determine the weights to ultimately calculate the global similarity. Machine learning-based fusion methods use the first and second similarities as features and input them into a machine learning model (such as linear regression, support vector machine, or neural network). The model then learns the optimal fusion method.

[0042] The following uses the exponential weighting method to illustrate. For example, the target participant uses the exponential weighted moving average scheme to calculate the similarity value of itself. , and the similarity matrix (i.e. the similarity information above) All valid values ​​in the column are averaged, where The matrix elements in the columns represent the communication topology of all participants (whether directly or indirectly adjacent) to the participant The calculated similarity. (target participant), the global similarity of the first model This can be expressed in the following ways:

[0043] in, Represent different participants, is a smoothing parameter, is the similarity matrix The number of valid data in the column.

[0044] Considering the randomness of a single similarity evaluation result, it is necessary to comprehensively consider the historical evaluation results and the latest evaluation results. For participants No. The secondary credibility assessment result is , and then we can get Calculation method:

[0045] in, is another smoothing parameter, Indicates the previous credibility assessment result (i.e. historical assessment result).

[0046] It should be noted that the participants in the distributed learning system may train an incorrect model due to data poisoning, which in turn affects the performance of the global model. In order to reduce the impact of the poisoned model on the global model, this application proposes to improve it from the perspective of the loss function. Previously, it was assumed that the local loss function of each participant For the global loss function The contribution of is the same, here we can adjust the weight of calculating the global loss function, Represents the model of a single participant. Specifically, the weight contributed by each participant during model synchronization, that is, the sum of each column of the synchronization matrix A (i.e. ), as the weight when calculating the global loss function, to reduce the interference of the poisoned model:

[0047] in, Represents the elements in the synchronization matrix A, N represents the total number of participants in the communication topology, and the set of poisoned participants is , then the global loss function can be expressed as:

[0048] Since the loss function value of the poisoned participant will increase significantly, and the goal is to minimize the global loss function, it is necessary to reduce the loss function contribution of the poisoned participant as much as possible, and then transform the problem of minimizing the loss function into minimizing the contribution of the poisoned participant:

[0049] In order to ensure the convergence of distributed learning, it is necessary to make the sum of the weights of the adjacent models aggregated by each participant equal to 1 when the model is aggregated, that is, the synchronization matrix The sum of each row of is 1. Therefore, an additional constraint is required, and the target problem becomes:

[0050]

[0051] To address the above issues, we first need to identify which participants are poisoning and then reduce their contribution weights. However, due to factors such as data heterogeneity and a fully decentralized environment, it is often impossible to directly confirm which participants are poisoning. Therefore, in the embodiments of this application, a credibility assessment scheme is proposed. By designing an algorithm to assess the credibility of all participants, the assessment results can be used as a basis for determining the probability of a participant being poisoned.

[0052] It should be noted that since the distributed learning system cannot predict how many participants will be attacked in the system, the contribution weight of the suspicious participants cannot be directly reduced to 0 at one time. Instead, the contribution weight (i.e. the synchronization matrix) can be adjusted based on the credibility evaluation results. ) to adjust and optimize, minimizing the impact of suspicious participants on the global model. Therefore, the original problem can be viewed as a topology optimization problem based on credibility assessment (i.e., optimizing the synchronization matrix A).

[0053] According to some embodiments provided herein, the contribution weights of various participants in model aggregation need to be adjusted based on the results of credibility assessment. The output of credibility assessment is a quantitative value. According to the evaluation formula, the larger the value, the higher the participant's credibility. Therefore, during model aggregation, participants with higher credibility assessment results should be prioritized and given higher weights. Credibility assessment is inherently a nonlinear function, and the distribution of credibility can be uneven, which can lead to a series of problems. Experimental data shows that in the later stages of training, the differences in the update directions of the models of various participants gradually increase, resulting in a general decline in the credibility of the mutual assessments and a phenomenon of "value compression." At this point, the credibility difference between malicious and legitimate nodes may shrink to within 0.05, but directly converting the values ​​will still retain a relatively high weight for the malicious node. This residual influence is sufficient to allow the poisoned node to continue to pollute the global model. Even if its weight is reduced compared to other nodes, it can still have a significant negative impact on the final aggregation results.

[0054] In an optional embodiment provided in the present application, in order to further reduce the impact of the data poisoning model on the global training results, in step 104: based on the credibility evaluation result, determining the model aggregation method of the first model and the target model may include the following steps: Sorting the credibility evaluation results corresponding to multiple adjacent participants to obtain a ranking result; Determine weight values ​​of the first models corresponding to the plurality of adjacent participants respectively according to the sorting results using a predetermined distribution, wherein the predetermined distribution is used to control the relationship between the sorting results and the weight values; A model aggregation method is determined based on weight values ​​of the first models corresponding to multiple adjacent participants.

[0055] In the embodiments provided in the present application, in a distributed learning environment, in order to reduce the impact of the data poisoning model on the global training results, more attention is paid to the ranking of the credibility assessment rather than the quantitative value. The credibility assessment results corresponding to multiple adjacent participants are sorted. The output result of the credibility assessment is a quantitative value. The larger the value, the higher the credibility of the participant. According to the sorting result, a predetermined distribution is used to determine the weight value of the first model corresponding to each adjacent participant. The predetermined distribution is used to control the size relationship between the sorting result and the weight value, ensuring that the participant model with high credibility has greater influence in the aggregation process. Using ranking to optimize the topological matrix can avoid the above problems to a certain extent, because no matter how large the difference in the values ​​is, the ranking is relatively stable.

[0056] For example, each participant ranks all neighboring nodes after credibility evaluation. The neighboring participants are represented as participants , participants The ranking is . Zipf distribution can be used to calculate the The contribution weights of all adjacent participants of the target participant. The Zipf distribution is a distribution for discrete data, primarily used to describe the relationship between the frequency or size of an element and its ranking in discrete data. In this application scenario, the Zipf distribution is used to assign weights based on the ranking of adjacent participants, ensuring that participants with higher rankings have greater influence in the model aggregation process. The specific distribution expression is:

[0057]

[0058] in, Used to describe the ranking of a participant under the Zipf distribution The corresponding weighted probability, X represents the ranking of the participants, and It is a specific ranking value. For participants The number of adjacent participants, is the shape parameter of the Zipf distribution, also known as the tail exponent. Determines the shape and tilt of the distribution, represents the ranking of the participants, It is a normalizing constant that ensures that the sum of all probabilities is 1. Specifically, The larger the value of , the more the distribution tends to be concentrated on the top few elements, that is, the frequency of these elements will be higher, while the frequency of other elements will be lower. When the value of is small, the distribution will be more uniform, that is, the frequency of occurrence of each element will not differ too much.

[0059] According to some embodiments provided by the present application, the method further comprises: Determine historical evaluation results of the first model corresponding to the target participant for multiple adjacent participants in historical training rounds; Determining a shape parameter based on historical evaluation results of the first model corresponding to each of the plurality of adjacent participants, where the shape parameter is used to represent a ratio of fluctuations of the plurality of historical evaluation results relative to an average historical evaluation result; According to the shape parameters, the predetermined distribution is determined.

[0060] In an embodiment of the present application, the target participant's historical evaluation results for the first model corresponding to multiple adjacent participants during historical training rounds are determined. These historical evaluation results reflect the past performance of each adjacent participant's model and serve as important reference information for credibility assessment. Based on the historical evaluation results of the first model corresponding to each of the adjacent participants, a shape parameter is calculated to represent the ratio of fluctuation in the multiple historical evaluation results relative to the average historical evaluation result. A predetermined distribution is determined based on the calculated weight tilt coefficient. This predetermined distribution controls the distribution of weight values, ensuring that the weight distribution reflects the stability and reliability of the historical evaluation results. If the historical evaluation results of a neighboring participant fluctuate significantly (i.e., a high shape parameter), it is assigned a lower weight in the current round. Conversely, if the historical evaluation results are relatively stable (i.e., a low shape parameter), it is assigned a higher weight. By calculating the shape parameter, the degree of fluctuation in the historical evaluation results can be quantified. For participants with significant fluctuations, their weights in the current round are reduced, thereby reducing their potential negative impact on the global model. By dynamically adjusting the weight distribution strategy, decentralized credibility assessment and model aggregation are achieved without relying on centralized authority, enhancing the system's adaptability and security in complex environments.

[0061] For example, in order to find a suitable The value can be calculated using the following formula:

[0062] in, It is expressed as the range value of the credibility assessment result. Represents the average value of the credibility evaluation results. For each evaluation, all credibility evaluation results ( ) is divided by the mean value and then multiplied by a coefficient Used for dynamic adjustment The purpose here is to make the contribution of the participants more step-by-step when there is a large gap between the results of the credibility assessment in order to reduce the contribution of the suspicious participants to a greater extent. The probability of each ranking in the Zipf distribution can be calculated by using the value of . In the embodiment of the present application, the probability of the ranking in the Zipf distribution is regarded as the weight of the ranking contribution.

[0063] In some embodiments provided herein, in order to prevent poisoned participants from unknowingly increasing the weight of their own models during model aggregation, all participants are required to maintain the weight of their own model contributions when modifying the aggregation weights. The calculation method for modifying the aggregation weights can be expressed as follows:

[0064] in, represents the weight value of participant i to itself, Indicates the participants For participants The weight value of Indicates the participants Sort all adjacent parties and The ranking in this sorted result.

[0065] According to an optional embodiment provided by the present application, in step S105: performing model aggregation processing on the target model and the first model according to the model aggregation method to obtain the aggregated target model may include the following steps: When the model aggregation processing type is to perform multiple synchronizations, for each synchronization in the multiple synchronizations, the target model and the first model are synchronized once using the model aggregation method to obtain the target model after the single synchronization; Sending a single-synchronized target model to an adjacent participant, and receiving a single-synchronized first model sent by the adjacent participant; Using the model aggregation method, the target model after single synchronization and the first model after single synchronization are synchronized again to obtain the re-synchronized target model; Repeat the predetermined number of synchronizations until a target model after the predetermined number of synchronizations is obtained as the aggregated target model; the aggregated target model is matched with the model states corresponding to the first aggregated model, and the first aggregated model is obtained by adjacent participants performing model aggregation processing.

[0066] In embodiments of the present application, in a distributed learning environment, model aggregation can be used to exchange model parameters between different participants. A single model aggregation process can include single synchronization or multiple synchronizations. Multiple synchronizations continuously consume communication resources, as the target participant and adjacent participants exchange model parameters during each communication. Using a model aggregation approach (such as a synchronization matrix), a single synchronization is performed on the target model and the first model to obtain a single-synchronized target model. This process can be considered as fusing the information of the two models to achieve better model performance. The single-synchronized target model is sent to the adjacent participants, and the single-synchronized first model sent by the adjacent participants is simultaneously received. This allows the participants to share the latest model information and prepare for the next synchronization. The single-synchronized target model and the first model are synchronized again to obtain a second-synchronized target model. In this way, the model can continuously absorb information from different participants and gradually optimize its performance. This process is repeated until a predetermined number of synchronizations are completed, completing the model aggregation process. After multiple synchronizations, the model states of different participants tend to be consistent, which helps to compare the model training directions of different participants in the future.

[0067] According to an embodiment provided by the present application, the target participant, the adjacent participant, and the neighbor participant belong to a predetermined communication topology. The method may further include the following steps: determining a predetermined threshold based on a communication resource cost of each participant included in the communication topology; The number of synchronizations required to make the difference between the model aggregation mode after multiple synchronizations and the complete matrix less than a predetermined threshold is determined as the predetermined number; the complete matrix is ​​used to represent any participant included in the communication topology during the model aggregation process, and has the same impact on all participants included in the communication topology.

[0068] In an embodiment of the present application, the target participant, adjacent participants, and neighbor participants belong to a predetermined communication topology. A predetermined threshold is determined based on the communication resource overhead of each participant in the communication topology. The communication resource overhead may include factors such as bandwidth, latency, and energy consumption. The predetermined threshold is used to measure the difference between the model aggregation method and the complete matrix. The number of synchronizations that makes the difference between the model aggregation method and the complete matrix after multiple synchronizations less than the predetermined threshold is determined as the predetermined number. The complete matrix is ​​an ideal state, which means that any participant in the communication topology has the same impact on all other participants during the model aggregation process. By dynamically adjusting the number of synchronizations, it is ensured that the effect of model aggregation reaches the predetermined threshold while reducing unnecessary communication overhead.

[0069] Specifically, in distributed learning, each participant only communicates with adjacent participants (i.e., there is no central server). After a single synchronization, the consistency of the model may be poor, so multiple consecutive synchronizations are required to achieve the desired consistency. Approaching a complete matrix. Algebraic connectivity is used to measure the connectivity of a graph. The algebraic connectivity defined here is:

[0070] Among them, the single synchronization matrix is ​​quantized The gap from a fully synchronized matrix. The smaller, the The closer to complete synchronization, the more consecutive synchronizations are required. The less (in a single model aggregation process). The embodiment of the present application increases the number of synchronizations to make distributed learning similar to the effect of federated learning. The synchronization process of federated learning can be regarded as using a system where all elements are A synchronization performed by a double random synchronization matrix is ​​called a complete matrix. The property of the double random matrix is ​​that the sum of each row and each column is 1. In order to make the synchronized model as consistent as possible, the synchronization matrix needs to be As close to the complete matrix as possible. The number of consecutive synchronizations between models. During the consecutive synchronization, the synchronization matrix becomes According to the theorem, as The increase, It will approach a complete matrix infinitely.

[0071] In the embodiment of the present application, the predetermined threshold can be recorded as , calculate so that of The minimum value of After synchronization The matrix is ​​very close to being complete. Continuous synchronization consumes communication resources, and the detection of poisoned models does not need to be performed in real time. Therefore, it is not necessary to use a continuous synchronization strategy every time the model is synchronized; it can be performed periodically.

[0072] According to the embodiment provided in this application, the method further includes the following manner: When the number of training rounds of the target participant reaches a first predetermined number of rounds, performing a model aggregation process of a single synchronization type; When the number of rounds of the model aggregation process of the single synchronization type executed by the target participant reaches a second predetermined number of rounds, the model aggregation process of the multiple synchronization type is executed.

[0073] In an embodiment of the present application, in order to achieve a balance between the need to maintain a consistent model state and the communication overhead, different processing is set according to a predetermined number of rounds. When the first predetermined number of rounds is not reached, each participant uses local data for training. When the number of rounds reaches the first predetermined number of rounds, the type of model aggregation processing performed is a single synchronization. Each time a single synchronization and a local synchronization are performed, different participants in the communication topology will still accumulate model differences. Therefore, when the number of rounds of executing a model aggregation processing of a single synchronization type reaches the second predetermined number of rounds, it is necessary to execute a model aggregation processing of a multiple synchronization type. By regularly performing a model aggregation processing of a multiple synchronization type, the models of different participants can be restored to a consistent state.

[0074] For example, Figure 3 A schematic diagram of the model aggregation cycle provided by the embodiment of the present application is shown in FIG. Figure 3 As shown, local training will be performed between single synchronization and single synchronization, and between single synchronization and multiple synchronizations. After the local training reaches the first predetermined number of rounds, a single synchronization is performed. After performing 3 rounds of single synchronization, the model aggregation processing type performed is recorded as multiple synchronizations.

[0075] According to some embodiments provided by the present application, if model aggregation processing of the type of multiple synchronizations is performed within a predetermined number of times after model aggregation processing of the type of multiple synchronizations is performed, the similarity between the first model and the target model is calculated, the model aggregation method is updated (i.e., the synchronization matrix is ​​updated), and a credibility evaluation is performed.

[0076] If a model aggregation process of the multiple synchronization type is executed within an unpredicted number of times after a model aggregation process of the multiple synchronization type is executed, local training continues.

[0077] In the embodiment provided in the present application, the above-mentioned predetermined number of times can be set as needed, for example, set to the first time, the second time, etc., and the model aggregation process can be optimized by distinguishing between the "first synchronization after multiple synchronizations" and the "non-first synchronization" situations. The reason for distinguishing whether it is the first time is that local training will accumulate model differences, and the comparison of model update directions requires a similar update starting point. As the "first synchronization after multiple synchronizations", its error is acceptable, and it is meaningful to compare the differences in the model update direction, and the similarity matrix can also be evaluated. However, continuing to accumulate local training differences between models may lead to misjudgment. Distinguishing between "predetermined times" and "non-predetermined times" types of model aggregation processing for single synchronization is to ensure the consistency and accuracy of the model while reducing communication overhead and computing resource consumption. According to some embodiments provided herein, determining a second similarity between a target model trained by a target participant and a first model may specifically include the following steps: Determining a first update direction of the adjacent participant based on a target model after a previous aggregation and a first model after local training performed by the adjacent participant, where the previous aggregation is a model aggregation round before a current training round and the type of model aggregation processing performed is a multiple synchronization model aggregation round, and the model states of the target model after the previous aggregation and the first model after the previous aggregation match; Determining a second update direction of the target participant based on the target model after the previous aggregation and the target model after local training performed by the target participant; A second similarity is obtained according to a difference between the first update direction and the second update direction.

[0078] It should be noted that the first model after local training performed by the adjacent participant indicates that there has been local training, which may include model aggregation processing with a single synchronization execution type, all of which are within the scope of protection of the embodiments of this application. The target model after local training performed by the target participant also refers to the same meaning.

[0079] In the embodiments provided herein, the model aggregation strategy can be dynamically adjusted by calculating the similarity of update directions. If a neighboring participant is a malicious node, its update direction may differ from the target participant's target model's update direction. By calculating the similarity of update directions, this discrepancy can be identified, thereby reducing the negative impact of malicious nodes on the global model. If the similarity between the first and second update directions is high, it indicates that the neighboring participant and the target participant have the same update direction, and the neighboring participant can be given a higher weight. Conversely, if the similarity is low, it indicates that the update directions are inconsistent, and the neighboring participant's weight may need to be reduced. The previous aggregation mentioned above refers to the previous execution type of multiple synchronizations. After multiple synchronizations, the model states of all participants are basically consistent. The target model after the previous aggregation can replace the first model after the previous aggregation, facilitating calculations for the target participant. Using the same update starting point, by comparing the model states of the first and target models in the current round, the second update direction of the target participant in this update and the first update direction of the neighboring participant in this update can be obtained. According to the difference between the first update direction and the second update direction, a second similarity is obtained, and the second similarity reflects the similarity of the update directions of the target participant and the adjacent participant after local training.

[0080] It should be noted that the embodiment uses cosine similarity detection as the basis for credibility assessment. The premise of this method is that the starting point of the model update is consistent, because different initial states of the model may result in different or completely opposite update directions even if the update is in the correct direction. In distributed learning, each participant (such as an edge server) only exchanges and synchronizes models with its adjacent participants. Therefore, the models of each participant are usually different after each synchronization, which makes the cosine similarity detection method unable to be directly applied. In addition, what is transmitted in the distributed learning system is the model rather than the update direction, so large errors may occur when calculating the update direction. Therefore, the credibility assessment method based on cosine similarity detection in the related art is difficult to apply directly, and because it is in a completely decentralized environment, it is also very difficult for each participant to conduct a global perspective assessment.

[0081] For example, suppose that After the sub-model aggregation, the participants The model is , that is, single synchronization, the model after the hth continuous synchronization is , that is, multiple synchronizations. The update starting point of all participating models is basically the same, whether it is the initial state at the beginning of training or the model aggregation processing with the execution type of multiple synchronizations. conduct After the local update, the model is updated to , then the participants Exchange the updated model with the adjacent participants to obtain the participant Model . - Participants The direction of this update is Indicates the participants conduct After the local update, is the model after h consecutive synchronizations. Can be used to replace Calculation is performed because the models after consecutive synchronizations are identical.

[0082] Participants After obtaining the update direction of participant j, the cosine similarity, i.e. the second similarity, can be calculated:

[0083] above Indicates adjacent parties The first update direction of Indicates the target participant The second update direction.

[0084] Through this approach, each participant can obtain the cosine similarity between the update direction of all adjacent participants and the update direction of its own model after continuous synchronization. The closer the cosine similarity is to 1, the more similar the two vectors are; the closer it is to -1, the less similar they are.

[0085] In the embodiment of the present application, the calculation result of the similarity can be set to fall within the interval of [0,1], which is easier to understand and calculate. The linear transformation method is used to convert the cosine similarity into As the calculation result.

[0086] According to the above embodiment, the present application also provides an optional implementation method: Figure 4 The following is a schematic diagram of the operation process provided by the embodiment of the present application. Figure 4 As shown, in the learning module included in the distributed learning system, there are two steps of local update and model synchronization that are performed in a cycle. In order to defend against model attacks, this application adds a poisoning detection module and a poisoning defense module. The poisoning detection and defense modules work together with the learning module.

[0087] The following poisoning detection module is specifically described. Figure 5 FIG. 4 shows a schematic diagram of attack detection provided by an embodiment of the present application, such as Figure 5 As shown, each participant first independently trains the model on the local dataset, and each participant updates the model parameters based on its own data.

[0088] Determine whether model aggregation is required for the current training round. If not, the process returns to local model training and continues local updates. If aggregation is required, the process proceeds to the next step to determine whether the model aggregation type is a single synchronization or continuous multiple synchronizations.

[0089] Determine whether multiple synchronizations are needed. To reduce communication overhead, multiple synchronizations are performed only in specific training rounds. For example, in the above algorithm, If yes, the model aggregation process is performed in the form of multiple consecutive synchronization steps, and the model consistency is ensured through multiple iterations of model exchange and aggregation.

[0090] If not, a single synchronization is performed. In a single synchronization, the target participant exchanges model parameters and similarity matrices with adjacent participants and performs a model aggregation to update the similarity matrix. In rounds that do not require continuous synchronization, the models of different participants are still updated and synchronized.

[0091] The above process also includes determining whether the current synchronization is the first in a series of synchronizations. If so, a credibility assessment is performed to evaluate the credibility of the model after multiple consecutive synchronizations to detect and prevent poisoning attacks. If not, local model training continues.

[0092]

[0093] As shown in the above algorithm, all participants first initialize their own local models The algorithm enters a main loop with loop variable t, and iterates multiple times from 1 to T, where T represents the total number of training rounds. For each participant i (in set N), the algorithm uses a periodic hybrid synchronization strategy to achieve secure distributed model training. All participants perform the following operations in parallel during each training round: During the local update phase, each participant independently updates the local model parameters based on its own data.

[0094] In the periodic communication phase, it is divided into a dual-cycle synchronization mechanism. For rounds of single synchronization (each The target participant exchanges model parameters and similarity matrix with the adjacent participants, updates the local model through weighted aggregation, and records the latest similarity data. × The process is triggered by a round of model exchange and aggregation (q times), so that the local models of different participants are close to global consistency.

[0095] The first single round after the type of multiple synchronizations also includes processes such as calculating similarity, updating the similarity matrix, calculating the credibility evaluation value, and adjusting the synchronization matrix A.

[0096] After T rounds of iterations, the models held by each participant converge to the global model .

[0097] The following demonstrates the effectiveness of the aforementioned optional implementation. Tables 1 and 2 present selected results from simulation experiments. This optional implementation employs three attack methods: label reversal, data noise, and trigger backdoor attacks. Label reversal attacks modify the labels of training data. By tampering with the labels of some or all samples, they force the learning model to make incorrect inferences or predictions during training. Data noise attacks disrupt the model training process by injecting purposeful noise or false information into the training data for distributed learning. The primary goal is to contaminate the data and cause the learning algorithm to produce an inaccurate or maliciously guided model. Trigger backdoor attacks are adversarial attacks against machine learning models. The attacker injects data with specific triggers (typically small regions or patterns in an image) into the training data, forcing the model to function normally but output incorrect labels specified by the attacker when the trigger is present. Each attack method is designed with two scenarios: 10% of participants are poisoned, and 20% of participants are poisoned. The datasets used include MNIST, FMNIST, and CIFAR10, which are three standard datasets widely used in machine learning.

[0098] This optional implementation also considers the case where the data are not independent and identically distributed. Table 1 shows the case where the data distribution satisfies independent and identical distribution, and Table 2 shows the experimental results when the data distribution is not independent and identically distributed.

[0099] Table 1 Experimental results when the datasets are independent and identically distributed

[0100] Table 2 Experimental results when the dataset is not independent and identically distributed

[0101] The effectiveness of poisoning defense schemes is evaluated primarily based on two metrics: ASR (Attack Success Rate), which represents the probability that an attacker successfully induces the global model to mispredict the target. TER (Error Rate), which represents the error rate of the global model's predictions on the test set. The data presented in the table represents the difference between the experimental results with and without the poisoning defense algorithm. The specific values ​​are for illustrative purposes only and are not intended to be limiting. The results show that the proposed scheme reduces the attack success rate for all three attacks by an average of 5.48%, while reducing the test error rate by an average of 4.55%.

[0102] Figure 6 The schematic diagram of the defense effect provided by the embodiment of the present application is shown as follows: Figure 6As shown, (a) is a label reversal attack, (b) is a noise attack scenario, and (c) is a trigger attack. In some scenarios, the test accuracy of the experimental results changes over time in three different situations. The three different situations are no poisoning, no defense, and after defense. The first situation is that there is no attack, the second situation is that the system is attacked and no defense measures are taken, and the third situation is that the system is attacked and the poisoning defense measures proposed in this application are taken. The experimental results show that the poisoning defense scheme proposed in this application has obvious advantages in countering attacks. The test accuracy is significantly improved compared to the case where no defense measures are taken, and the final effect is close to the case where there is no attack.

[0103] The poisoning defense algorithm is effective because of the credibility evaluation scheme adopted by this optional embodiment. Figure 7 A schematic diagram of the credibility evaluation provided by the embodiment of the present application is shown in FIG. Figure 7 As shown, the results of the credibility evaluation of all 10 parties are displayed. Figure 7 Figure (a) shows 10% of participants under attack, and (b) shows 20% of participants under attack. In each case, the average value of each participant's evaluation by its neighboring participants changes over time. The dashed line represents the poisoned participants. It can be seen that the credibility assessment of poisoned participants is significantly lower than that of other participants, by an average of 34.5%. This confirms the effectiveness of the credibility assessment scheme proposed in this optional implementation. It can also be seen that as training progresses, the gap between the credibility assessment of poisoned participants and that of other participants decreases, which explains why this optional implementation optimizes the topology matrix based on ranking.

[0104] After performing a credibility assessment, each participant adjusts the weight of the model's aggregation. From a global perspective, this is considered an adjustment to the synchronization matrix. The sum of each column of the synchronization matrix A represents the sum of the weights contributed by each participant to the global model. Without adjusting the synchronization matrix, the total contribution weight of each participant is 1. From a global perspective, the change in each participant's contribution weight over the training rounds is observed. Figure 8 The following is a schematic diagram of the contribution weights of the participants provided in the embodiment of the present application. Figure 8 As shown in the figure, (a) represents 10% of the participants being attacked, and (b) represents 20% of the participants being attacked. The dotted line represents the total contribution weight of the poisoned participants. It can be seen that after topology optimization, the total contribution weight of the participants is significantly less than the average contribution weight of the non-poisoned participants, an average of 74.2% lower.

[0105] Through the above processing, this optional embodiment implements poisoning detection in a fully decentralized distributed learning system, eliminating the need for a central server for parameter processing and network management. It can also detect both data and model poisoning. Based on the poisoning detection results, the topology matrix is ​​optimized to achieve poisoning defense in a decentralized distributed learning system.

[0106] This application also provides another optional implementation method. If distributed learning poisoning defense is to be implemented in a fully decentralized environment, the security of the system can be enhanced by having participants use cluster analysis methods. Specifically, if each participant has a sufficient number of adjacent nodes, cluster analysis can be performed on the models of all adjacent participants, thereby effectively identifying and isolating potential malicious nodes.

[0107] The core idea of ​​cluster analysis is to divide participating models into clusters based on the similarity of model parameters. In decentralized federated learning (DFL), participants train models using local data and exchange model updates with other participants. Since malicious nodes may introduce abnormal model parameters through poisoning attacks, cluster analysis can help identify these anomalies. The specific steps are as follows: 1. Model parameter collection: Each participant collects the model parameters of its neighboring participants to form a local model parameter set. In decentralized federated learning, point-to-point communication or distributed communication mechanisms are usually used to achieve the exchange of model parameters.

[0108] 2. Similarity measurement: Use metrics such as Euclidean distance or cosine similarity to calculate the similarity between model parameters of adjacent participants. Euclidean distance can directly measure the distance between model parameters; cosine similarity can be used to measure the directional similarity of model parameters.

[0109] 3. Clustering Algorithm: Clustering algorithms such as K-means and DBSCAN are used to divide model parameters into different clusters. Model parameters of healthy participants are generally clustered in one or more primary clusters, while model parameters of malicious participants may form outlier clusters. The K-means algorithm divides clusters by specifying the number of clusters (K value) and is suitable for cases where data is relatively evenly distributed. The DBSCAN algorithm does not require a pre-specified number of clusters and can identify clusters of any shape, making it suitable for processing noisy data and outliers. Model parameters of healthy participants are generally clustered in one or more primary clusters, while model parameters of malicious participants may form outlier clusters.

[0110] 4. Anomaly Detection: By setting a threshold or analyzing the distribution of clusters, abnormal model parameters in outlier clusters are identified and marked as potential malicious participants. For example, if a distance threshold is set, if the distance between the model parameters of a participant and the main cluster exceeds the threshold, the participant is considered an anomaly.

[0111] 5. Model aggregation: When updating the global model, exclude or reduce the weight of abnormal model parameters, thereby reducing the influence of malicious participants on the global model.

[0112] This approach not only effectively defends against poisoning attacks but also maintains high robustness in a decentralized environment. For example, the Krum defense method calculates the Euclidean distance between model parameters and selects the model with the smallest distance to the majority as the global model, thereby eliminating anomalous models. Similarly, the Median-based aggregation rule filters out anomalous updates by calculating the median of model parameters.

[0113] Furthermore, cluster analysis can be combined with other defense mechanisms. For example, contribution-based evaluation methods can dynamically adjust model weights based on participants' historical performance, further enhancing system security. In this way, decentralized federated learning systems can effectively defend against poisoning attacks while protecting data privacy, ensuring model accuracy and robustness.

[0114] Figure 9 The schematic diagram of the structure of the model poisoning defense device according to the embodiment of the present application is shown as follows: Figure 9 As shown, corresponding to the application scenario and method of the method provided in the embodiment of the present application, the embodiment of the present application also provides a model poisoning defense device, including: Communication module 901 is configured to obtain a first model trained by a neighboring participant and first similarity information maintained by the neighboring participant, wherein the first similarity information includes a first similarity between the first model and a neighbor model of the neighboring participant, the neighboring participant and the target participant are respectively adjacent to the neighboring participant, and the target participant is different from the neighboring participant; A similarity determination module 902 is configured to determine a second similarity between a target model trained by a target participant and the first model; The credibility evaluation module 903 is configured to perform a credibility evaluation on the first model based on the first similarity and the second similarity to determine whether the first model has been subjected to a poisoning attack, thereby obtaining a credibility evaluation result of the first model; the poisoning attack may include data poisoning of the training data used by the first model or model poisoning of the model parameters of the first model; A weight adjustment module 904 is configured to determine a model aggregation mode for the first model and the target model based on the credibility evaluation result. The model aggregation mode is configured to control the influence of the first model on the target model during the model aggregation process. The model aggregation module 905 is configured to perform model aggregation processing on the target model and the first model according to the model aggregation method to obtain an aggregated target model.

[0115] The functions of each module in each device in the embodiments of the present application can be found in the corresponding description in the above method, and have corresponding beneficial effects, which will not be repeated here.

[0116] It should be noted that the communication module 901, similarity determination module 902, credibility assessment module 903, weight adjustment module 904, and model aggregation module 905 correspond to steps 101 to 105 in the embodiment. The examples and application scenarios implemented by these modules and corresponding steps are the same, but are not limited to the contents disclosed in the above embodiment. It should be noted that the above modules, as part of the device, can run on a computer terminal.

[0117] The above-mentioned model poisoning defense device can also include a processor and a memory. The communication module 901, the similarity determination module 902, the credibility assessment module 903, the weight adjustment module 904, the model aggregation module 905, etc. are all stored in the memory as program units, and the processor executes the above-mentioned program units stored in the memory to realize the corresponding functions.

[0118] The processor includes a kernel, which retrieves the corresponding program unit from memory. There can be one or more kernels. Memory may include non-permanent memory in a computer-readable medium, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory includes at least one memory chip.

[0119] Figure 10 FIG. 1 is a block diagram of an electronic device for implementing an embodiment of the present application. Figure 10 As shown, the electronic device includes: a memory 1001 and a processor 1002. The memory 1001 stores a computer program that can be executed on the processor 1002. When the processor 1002 executes the computer program, the method of the above embodiment is implemented. The number of memory 1001 and processor 1002 can be one or more. In a specific implementation, the electronic device may also include a communication interface 1003 for communicating with external devices and exchanging data.

[0120] In a specific implementation, if the memory 1001, processor 1002, and communication interface 1003 are implemented independently, the memory 1001, processor 1002, and communication interface 1003 can be connected to each other via a bus and communicate with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 4 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0121] Optionally, in a specific implementation, if the memory 1001, the processor 1002 and the communication interface 1003 are integrated on a chip, the memory 1001, the processor 1002 and the communication interface 1003 can communicate with each other through an internal interface.

[0122] An embodiment of the present application provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the model poisoning defense method provided in the embodiment of the present application.

[0123] An embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the model poisoning defense method provided in the embodiment of the present application.

[0124] An embodiment of the present application also provides a chip, which includes a processor for calling and executing instructions stored in the memory from the memory, so that a communication device equipped with the chip executes the model poisoning defense method provided in the embodiment of the present application.

[0125] An embodiment of the present application also provides a chip, including: an input interface, an output interface, a processor and a memory. The input interface, the output interface, the processor and the memory are connected through an internal connection path. The processor is used to execute the code in the memory. When the code is executed, the processor is used to execute the model poisoning defense method provided in the embodiment of the application.

[0126] It should be understood that the processor described above may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor. It is worth noting that the processor may be a processor that supports the Advanced RISC Machines (ARM) architecture.

[0127] Furthermore, optionally, the aforementioned memory may include read-only memory and random access memory. The memory may be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. Non-volatile memory may include read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory may include random access memory (RAM), which serves as an external cache memory. By way of example and not limitation, many forms of RAM are available. For example, static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM) and direct memory bus random access memory (DR RAM).

[0128] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the present application are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another.

[0129] In the description of this specification, the reference terms "one embodiment," "some embodiments," "example," "specific example," or "some examples" mean that the specific features, structures, materials, or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. Moreover, the specific features, structures, materials, or characteristics described may be combined in any appropriate manner in any one or more embodiments or examples. In addition, those skilled in the art may combine and combine different embodiments or examples described in this specification, as well as features of different embodiments or examples, unless they are mutually inconsistent.

[0130] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features being referred to. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one such feature. Throughout the description of this application, "plurality" means two or more, unless otherwise specifically defined.

[0131] Any process or method described in the flowchart or otherwise described herein can be understood to represent a module, segment or portion of code comprising one or more executable instructions for implementing the steps of a specific logical function or process. The scope of the preferred embodiments of the present application includes other implementations in which the functions may be performed in a different order than shown or discussed, including performing the functions substantially simultaneously or in reverse order depending on the functions involved.

[0132] The logic and / or steps described in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, apparatus or device (such as a computer-based system, a system including a processor, or other system that can fetch instructions from and execute instructions on an instruction execution system, apparatus or device), or used in conjunction with such instruction execution systems, apparatuses or devices.

[0133] It should be understood that various parts of the present application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. All or part of the steps of the above embodiment method can be completed by instructing the relevant hardware through a program, which can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiment.

[0134] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing module, or each unit may exist physically separately, or two or more units may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or in the form of software functional modules. If the aforementioned integrated modules are implemented in the form of software functional modules and sold or used as independent products, they may also be stored in a computer-readable storage medium. The storage medium may be a read-only memory, a magnetic disk, or an optical disk, etc.

[0135] The above are merely exemplary embodiments of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily conceive of various modifications or substitutions within the technical scope described in this application, and such modifications or substitutions should be included within the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A model poisoning defense method, characterized in that: Applied to a target participant, the method includes: Obtaining a first model trained by a neighboring participant and first similarity information maintained by the neighboring participant, wherein the first similarity information includes a first similarity between the first model and a neighbor model of a neighboring participant, the neighboring participant and the target participant are respectively adjacent to the neighboring participant, and the target participant is different from the neighboring participant; determining a second similarity between a target model trained by the target participant and the first model; Based on the first similarity and the second similarity, a credibility assessment is performed on whether the first model is subjected to a poisoning attack, thereby obtaining a credibility assessment result of the first model; the poisoning attack includes data poisoning of training data used by the first model, or model poisoning of model parameters of the first model; Determining, based on the credibility evaluation result, a model aggregation mode of the first model and the target model, wherein the model aggregation mode is used to control the influence of the first model on the target model during the model aggregation process; According to the model aggregation method, the target model and the first model are subjected to model aggregation processing to obtain the aggregated target model.

2. The method according to claim 1, characterized in that The step of performing a credibility evaluation on whether the first model is subjected to a poisoning attack based on the first similarity and the second similarity to obtain a credibility evaluation result of the first model includes: Obtaining a global similarity based on the first similarity and the second similarity; The credibility evaluation result is determined according to the global similarity and the historical evaluation results of the target participant on the first model in historical training rounds.

3. The method according to claim 1, characterized in that There are multiple adjacent participants, and determining a model aggregation method of the first model and the target model based on the credibility evaluation result includes: Sorting the credibility evaluation results corresponding to multiple adjacent participants to obtain a ranking result; Determining weight values ​​of the first models corresponding to the plurality of adjacent participants respectively according to the ranking result using a predetermined distribution, wherein the predetermined distribution is used to control the magnitude relationship between the ranking result and the weight value; The model aggregation mode is determined based on the weight values ​​of the first models respectively corresponding to the multiple adjacent participants.

4. The method according to claim 3, characterized in that The method further comprises: Determining historical evaluation results of the target participant on the first model corresponding to each of the plurality of adjacent participants in historical training rounds; Determining a shape parameter based on historical evaluation results of the first model corresponding to each of the plurality of adjacent participants, the shape parameter being used to represent a ratio of fluctuations of the plurality of historical evaluation results to an average historical evaluation result; The predetermined distribution is determined according to the shape parameter.

5. The method according to any one of claims 1 to 4, characterized in that The step of performing model aggregation processing on the target model and the first model according to the model aggregation method to obtain the aggregated target model includes: In a case where the type of the model aggregation processing is to perform multiple synchronizations, for each synchronization of the multiple synchronizations, the target model and the first model are synchronized once using the model aggregation method to obtain the target model after the single synchronization; Sending the target model after a single synchronization to the adjacent participant, and receiving the first model after a single synchronization sent by the adjacent participant; Using the model aggregation method, performing a single synchronization on the target model after the single synchronization and the first model after the single synchronization again to obtain the re-synchronized target model; Repeat the synchronization for a predetermined number of times until the target model after the predetermined number of synchronizations is obtained as the aggregated target model; the aggregated target model is matched with the model states corresponding to the first aggregated model respectively, and the first aggregated model is obtained by the adjacent participants performing model aggregation processing.

6. The method according to claim 5, characterized in that The target participant, the adjacent participant, and the neighbor participant belong to a predetermined communication topology, and the method further includes: determining a predetermined threshold based on a communication resource overhead of each participant included in the communication topology; Determine the number of synchronizations that makes the difference between the model aggregation mode after multiple synchronizations and the complete matrix less than the predetermined threshold value as the predetermined number; the complete matrix is ​​used to represent any participant included in the communication topology during the model aggregation process, and has the same impact on all participants included in the communication topology.

7. The method according to claim 5, characterized in that Determining a second similarity between the target model trained by the target participant and the first model includes: Determining a first update direction of the adjacent participant based on the target model after a previous aggregation and a first model after local training performed by the adjacent participant, wherein the previous aggregation is a model aggregation round before a current training round and the type of the model aggregation processing performed is a multiple synchronization model aggregation round, and the model states of the target model after the previous aggregation and the first model after the previous aggregation match; Determining a second update direction of the target participant based on the target model after the previous aggregation and the target model after local training performed by the target participant; The second similarity is obtained according to a difference between the first update direction and the second update direction.

8. The method according to claim 5, characterized in that The method further comprises: When the number of training rounds of the target participant reaches a first predetermined number of rounds, performing the model aggregation process of a single synchronization type; When the target participant executes the model aggregation process of the single synchronization type for a number of rounds reaching a second predetermined number of rounds, the model aggregation process of the multiple synchronization type is executed.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory, wherein the processor implements the method according to any one of claims 1 to 8 when executing the computer program. 10 . A computer-readable storage medium, wherein a computer program is stored in the computer-readable storage medium, and when the computer program is executed by a processor, the method according to claim 1 is implemented.

Citation Information

Patent Citations

  • Federal learning data poisoning attack-oriented defense method and device

    CN113965359A

  • Two-dimensional poisoning attack defense method in federal learning

    CN117494123A

  • Federal learning operation method, system and device with robustness

    CN118504012A

  • Federated learning defense method, apparatus, electronic device, and storage medium

    WO2021208721A1

Cited By

  • Defense method for power system poisoning attack

    CN121509115A