Privacy protection federated learning method and system based on double-target data transformation

By constructing dual-target data transformation losses, and generating transformed data that are visually non-similar and similar in characteristics to local user data, the problem of limited global model accuracy and privacy protection capabilities in the prior art is solved, and high accuracy and strong privacy protection of the global model are achieved.

CN120597325AActive Publication Date: 2025-09-05HEFEI UNIV OF TECH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510719782.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-09-05
Estimated Expiration
2045-05-30

AI Technical Summary

Technical Problem

The existing data transformation-based federal learning method for privacy protection fails to perform dual-objective optimization at the visual level and feature level, resulting in limited global model accuracy and privacy protection capabilities.

Method used

By constructing a dual-target data transformation loss that integrates visual non-similarity loss and feature similarity loss, the local user's generative model is used to generate transform data, so that it has non-similarity with the local user's data features at the visual level and similarity at the feature level. The parameters of the feature extraction and classification model are optimized through the classification model to isolate the interaction between the original data extraction features and the global model server.

Benefits of technology

It achieves the balance between global model accuracy and privacy protection capabilities, effectively resists data reconstruction attacks based on gradient inverse, and ensures the security of data privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120597325A_ABST
    Figure CN120597325A_ABST
Patent Text Reader

Abstract

The invention discloses a privacy protection federated learning method and system based on dual-target data transformation. According to the scheme, the method comprises the following steps: constructing double-target data transformation loss fusing visual dissimilarity loss and feature similarity loss, and obtaining transformation data through a generation model of a local user; therefore, the transformation data has non-similarity with local user data features in the visual level and has similarity with the local user data features in the feature level, so that the global model accuracy and privacy protection capability are balanced. Moreover, the feature extraction model of the local user does not participate in the updating of the global model server, so that the interaction between the original data extraction features and the global model server can be effectively isolated, and the privacy protection capability is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of privacy protection technology, and in particular to a privacy-preserving federated learning method and system based on dual-objective data transformation. Background Art

[0002] Gradient reversal-based data reconstruction attacks analyze the local model gradients as shared parameters to reconstruct the original data in the local dataset with high quality, posing a significant challenge to the privacy protection of local user data. Gradient reversal-based data reconstruction attacks can reveal the fine-grained properties of local user data in federated learning, posing a significant privacy threat.

[0003] Data transformation computes parameter-controlled transformations on the original training data while maintaining the training data labels, allowing the transformed data, aligned with the data labels, to be used for local model training. However, existing privacy-preserving federated learning methods based on data transformation lack dual-objective optimization of the transformed data at both the visual and feature levels, limiting global model accuracy and privacy protection capabilities.

[0004] In view of this, the present invention is proposed. Summary of the Invention

[0005] The purpose of the present invention is to provide a privacy-preserving federated learning method and system based on dual-objective data transformation, which can balance the global model accuracy and privacy protection capabilities.

[0006] The purpose of the present invention is achieved through the following technical solutions:

[0007] A privacy-preserving federated learning method based on dual-objective data transformation, including:

[0008] Step 11: The local user shares the network structure of the classification model and the generation model with the global model server, and initializes the parameters of the feature extraction model, classification model, generation model, and discriminant model;

[0009] In step 12, the local user freezes the parameters of the generative model and the discriminative model, inputs the local data set into the feature extraction model, obtains the data features of each local data, and classifies it through the classification model. The generative model generates the corresponding transformed data for each local data, combines the data features with the corresponding transformed data to construct a dual-target data transformation loss that integrates the visual dissimilarity loss and the feature similarity loss, and constructs a classification loss based on the classification results. The dual-target data transformation loss and the classification loss are combined to optimize the parameters of the feature extraction model and the classification model, and the parameters of the classification model are uploaded as shared parameters to the global model server.

[0010] In step 13, the local user freezes the parameters of the feature extraction model and the classification model, uses the local dataset to train the generative model and the discriminant model, and uploads the parameters of the generative model as shared parameters to the global model server;

[0011] Step 14: The global model server aggregates the parameters of the classification model and the generation model uploaded by the local user and performs a global model server update;

[0012] In step 15, the local user downloads the updated classification model and generation model from the global model server and repeats steps 12, 13, and 14 until the number of global model server update rounds is reached, completing the training process of privacy-preserving federated learning based on dual-objective data transformation.

[0013] A privacy-preserving federated learning system based on dual-objective data transformation includes: a local user and a global model server, which collaborate to execute the aforementioned method.

[0014] As can be seen from the technical solution provided by the present invention, the present invention constructs a dual-objective data transformation loss that integrates visual dissimilarity loss and feature similarity loss. Transformed data is generated through a generative model for the local user, resulting in visual dissimilarity with the local user's data features and similarity with the local user's data features at the feature level, thereby balancing global model accuracy and privacy protection. Furthermore, the local user's feature extraction model does not participate in global model server updates, effectively isolating the interaction between the original data extraction features and the global model server, ensuring privacy protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0016] Figure 1 A flowchart of a privacy-preserving federated learning method based on dual-objective data transformation provided by an embodiment of the present invention;

[0017] Figure 2 A network diagram of a feature extraction model and a classification model provided by an embodiment of the present invention;

[0018] Figure 3 A network diagram of a generative model and a discriminative model provided by an embodiment of the present invention;

[0019] Figure 4A graph showing the visual dissimilarity loss between features extracted from the transformed data and the original data provided by an embodiment of the present invention;

[0020] Figure 5 A schematic diagram of a privacy-preserving federated learning system based on dual-objective data transformation provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0021] The following is a clear and complete description of the technical solutions in the embodiments of the present invention, in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0022] First, the following terms may be used in this article:

[0023] The terms "include," "comprises," "contains," "has," or other similar expressions should be interpreted as non-exclusive. For example, "including certain technical features (such as raw materials, components, ingredients, carriers, dosage forms, materials, dimensions, parts, components, mechanisms, devices, steps, procedures, methods, reaction conditions, processing conditions, parameters, algorithms, signals, data, products, or manufactured articles, etc.) should be interpreted as including not only the technical features explicitly listed, but also other technical features known in the art that are not explicitly listed.

[0024] The term "consisting of" excludes any technical features not explicitly listed. If used in a claim, this term renders the claim closed, excluding any technical features other than those explicitly listed, except for conventional impurities associated with them. If this term appears only in a clause of a claim, it limits only the elements explicitly listed in that clause; elements listed in other clauses are not excluded from the claim as a whole.

[0025] The following describes in detail a privacy-preserving federated learning method based on dual-objective data transformation, provided by the present invention. Any information not described in detail in the examples of the present invention is prior art known to those skilled in the art. Where specific conditions are not specified in the examples of the present invention, the experiments were conducted according to conventional conditions in the art or the conditions recommended by the manufacturer. Reagents or instruments used in the examples of the present invention, where the manufacturer is not specified, are commercially available conventional products.

[0026] Example 1

[0027] The privacy-preserving federated learning method based on dual-objective data transformation proposed in this paper is dedicated to solving the problem of local user data privacy leakage in federated learning. This method obtains transformed data through the generative model of the local user, making the transformed data dissimilar to the local user data features at the visual level and similar to the local user data features at the feature level, thereby balancing the accuracy of the global model and the privacy protection capability. Figure 1 As shown, the method mainly includes the following steps:

[0028] In step 11, the local user shares the network structure of the classification model and the generation model with the global model server, and initializes the parameters of the feature extraction model, classification model, generation model, and discrimination model.

[0029] In the embodiment of the present invention, K local users are set Participating in federated learning, each local user Owned by n k Original data x k,i and the corresponding category label y k,i Local dataset And the total amount of data Here K and n k The specific value of can be set by the user according to actual conditions or experience.

[0030] In the embodiment of the present invention, the structures of the feature extraction model, classification model, generation model and discrimination model can be set according to actual conditions, such as Figure 2 and Figure 3 As shown, an example of the structure of the above model is provided.

[0031] The network structure of the feature extraction model and the classification model is as follows Figure 2As shown in the figure. In the feature extraction model and classification model, the input data is a color image of size 3×32×32; the size of the data feature is 16×5×5; Conv2d(in_channels, out_channels, kernel_size, stride, padding) is a two-dimensional convolution operation with input channels of in_channels, output channels of out_channels, kernel size of kernel_size, stride of stride, and padding of padding; AvgPool2d(kernel_size, stride) is an average pooling operation with kernel size of kernel_size and stride of stride; Sigmoid is an activation function in deep learning; Flatten is a data feature flattening function; Linear(in_features, out_features) is a linear layer operation with input dimension of in_features and output dimension of out_features; the dimension of the logical output is 10.

[0032] The network structures of the generative model and the discriminative model are as follows Figure 3As shown. In the generative model and the discriminative model, the value range of the category label is [0,9]; the size of the random noise is 100×1×1; the size of the data feature / transformed data is 16×5×5; Embedding(num_embeddings, embedding_dim) is a category label embedding operation with num_embeddings embeddings and embedding dimension embedding_dim; Concatenating is a data concatenation operation; Expanding(num_classes, feature_size, feature_size) is a feature dimension expansion operation with num_classes category labels and feature size feature_size×feature_size; ConvTranspose2d(in_channels, out_channels,kernel_size,stride,padding) is a two-dimensional transposed convolution operation with in_channels as input channels, out_channels as output channels, kernel size as kernel_size, stride as stride, and padding as padding; BN is a batch normalization operation; Conv2d(in_channels,out_channels,kernel_size,stride,padding) is a two-dimensional convolution operation with in_channels as input channels, out_channels as output channels, kernel size as kernel_size, stride as stride, and padding as padding; LeakyReLU and Sigmoid are activation functions in deep learning.

[0033] In step 12, the local user freezes the parameters of the generative model and the discriminative model, constructs a dual-objective data transformation loss that integrates the visual dissimilarity loss and the feature similarity loss, uses the local dataset to train the feature extraction model and the classification model, and uploads the parameters of the classification model as shared parameters to the global model server.

[0034] The main process of this step can be described as follows: the local user freezes the parameters of the generative model and the discriminative model, inputs the local data set into the feature extraction model, obtains the data features of each local data, and classifies it through the classification model, and generates the corresponding transformation data of each local data based on the generative model. Combining the data features with the corresponding transformation data constructs a dual-target data transformation loss that integrates the visual non-similarity loss and the feature similarity loss, and constructs the classification loss through the classification results. Combining the dual-target data transformation loss and the classification loss optimizes the parameters of the feature extraction model and the classification model, and the parameters of the classification model are used as shared parameters uploaded to the global model server.

[0035] The preferred implementation of this step is as follows:

[0036] (1) The kth local user freezes the generated model G k Parameters and the discriminant model D k Parameters For the category label y k,i The original data The parameters used are Feature extraction model E k For the original data x k,i Extracting data features And use the parameters as Classification model C k Calculate the logical output of the data feature (Probability distribution is generated by Softmax function), classification loss It can be expressed as:

[0037]

[0038] in, is the cross entropy loss, is the mathematical expectation.

[0039] (2) The kth local user uses the generated model G k Gaussian noise and class label y k,i Generate transformation data

[0040] Among them,

[0041] (3) The k-th local user constructs a dual-objective data transformation loss that integrates visual dissimilarity loss and feature similarity loss. The dual-objective data transformation optimization objective can be expressed as:

[0042]

[0043] Among them, the visual non-similarity loss is expressed as Parameter μ>0, parameter ε>0, feature similarity loss is expressed as Represents transformed data and data characteristics The cosine similarity of .

[0044] (4) The kth local user uploads the parameters of the classification model as shared parameters to the global model server, which can be expressed as:

[0045]

[0046] Among them, ← is the assignment symbol, is the feature extraction model E after the qth round of training is completed k and classification model C k Parameters, To calculate the feature extraction model E k Gradient and classification model C k The gradient operator, is the feature extraction model E after the q-1th round of training is completed k and classification model C k Parameters, when q = 1, is the initialization parameter in step 11, η1 is the learning rate, and α and β are weights that control the importance of visual non-similarity loss and feature similarity loss.

[0047] In step 13, the local user freezes the parameters of the feature extraction model and the classification model, uses the local dataset to train the generation model and the discriminant model, and uploads the parameters of the generation model as shared parameters to the global model server.

[0048] The preferred implementation of this step is as follows:

[0049] (1) The kth local user frozen feature extraction model E k Parameters and classification model C k Parameters

[0050] (2) The kth local user uses the local dataset Train the generative model G k and the discriminant model D k , which can be expressed as:

[0051]

[0052] Among them, ← is the assignment symbol, η2 is the learning rate, Generate model G when the qth round of training is completed k Parameters, Generate model G when the q-1th round of training is completed k Parameters, is the discriminant model D after the qth round of training is completed k Parameters, is the discriminant model D after the q-1th round of training is completed k Parameters, when q=1, and is the initialization parameter in step 11; and Represent the computational generation model Gk Gradient and discriminant model D k Gradient operator, generating model G k loss and the discriminative model loss They can be expressed as:

[0053]

[0054] in, represents the mathematical expectation, For the kth local user Owned by n k Original data x k,i and the corresponding category label y k,i The local data set formed; Indicates that the kth local user uses the parameter Generative model G k and Gaussian noise and the class label y k,i The generated transformation data, is a normal distribution with a mean of 0 and a standard deviation of 1; Indicates that the kth local user uses the parameter Feature extraction model E k From the original data x k,i The data features extracted from Indicates that the kth local user uses the parameter The discriminant model D k The judgment result of input X is:

[0055] In step 14, the global model server aggregates the parameters of the classification model and the generation model uploaded by the local user, and performs a global model server update.

[0056] The parameter aggregation process of the classification model uploaded by the local user and the generation model can be expressed as:

[0057]

[0058] in, is the parameter of the classification model when the global model server update is completed in round t, is the classification model parameter uploaded by the tth local user during the tth round of global model server update, To generate the model parameters when the global model server is updated in round t, is the generated model parameters uploaded by the tth local user during the tth round of global model server update, n k is the number of data of the kth local user, K is the number of local users, Represents the total amount of data of K local users.

[0059] In an embodiment of the present invention, after completing several rounds of training, local users upload relevant model parameters, which are aggregated by the global model server.

[0060] In step 15, the local user downloads the updated classification model and generation model from the global model server and repeats steps 12, 13, and 14 until the number of global model server update rounds is reached, completing the training process of privacy-preserving federated learning based on dual-objective data transformation.

[0061] In the embodiment of the present invention, the number of update rounds of the global model server is defined as T, and its specific value can be set by the user according to actual conditions or experience.

[0062] It should be noted that the above steps only use a single local user as an example to introduce its processing flow. The processing flow for other local users is the same and will not be repeated here.

[0063] The solution provided by the embodiments of the present invention constructs a dual-objective data transformation loss that integrates visual dissimilarity loss and feature similarity loss. Transformed data is generated through the local user's generative model, ensuring that the transformed data is visually dissimilar to the local user's data features and similar to the local user's data features at the feature level, thereby balancing global model accuracy and privacy protection. Furthermore, the local user's feature extraction model does not participate in global model server updates, effectively isolating the interaction between the original data extraction features and the global model server, ensuring privacy protection.

[0064] To test the global model accuracy and privacy protection capabilities of the proposed privacy-preserving federated learning method based on dual-objective data transformation, we compared it with three other privacy-preserving federated learning methods. These three privacy-preserving federated learning methods are denoted as A, B, and C. A is a privacy-preserving federated learning method based on block scrambling, B is a privacy-preserving federated learning method based on pixel transformation and channel scrambling, and C is a privacy-preserving federated learning method based on an automatic transformation strategy.

[0065] To test the global model's accuracy and privacy protection capabilities, the CIFAR-10 dataset was used, with Adam as the underlying model optimization algorithm. The number of local users was set to 5, the number of global model server updates was set to 5, the number of local model training rounds was set to 50, the randomly sampled dataset size was set to 64, and the learning rate was set to 0.001. To test the global model's accuracy, local users used the trained generative model to convert the original data in the local dataset into transformed data. The trained classification model was then used to test the classification accuracy of the transformed data. To test privacy protection, the visual dissimilarity loss between features extracted from the transformed and original data was used to measure privacy protection. The experimental results are shown in Tables 1 and 2.

[0066] Table 1 Ablation experimental results on dual-target data transformation loss that integrates visual non-similarity loss and feature similarity loss

[0067]

[0068] Table 1 shows the ablation experiment results of the dual-objective data transformation loss that integrates visual non-similarity loss and feature similarity loss. In this experiment, different combinations of loss functions are used to test the global model accuracy. When the loss function is given, each group of global model accuracy is tested three times, and the final global model accuracy is expressed in the form of mean and standard deviation. As shown in Table 1, the use of loss function The highest global model accuracy can be achieved when

[0069] Table 2 Comparative experimental results of global model accuracy of different privacy-preserving federated learning methods

[0070]

[0071] Table 2 shows the experimental results of the global model accuracy comparison of different privacy-preserving federated learning methods. The privacy-preserving federated learning method based on dual-objective data transformation proposed in this paper can achieve the highest global model accuracy.

[0072] Figure 4 A plot of the visual dissimilarity loss between the features extracted from the transformed and original data is shown. Figure 4 It can be seen that as the number of training rounds increases, the visual dissimilarity loss between the features extracted from the transformed data and the original data continues to decrease, proving that the visual dissimilarity between the features extracted from the transformed data and the original data continues to increase, which can effectively resist data reconstruction attacks based on gradient inversion and has privacy protection capabilities.

[0073] Through the description of the above embodiments, those skilled in the art will clearly understand that the above embodiments can be implemented through software or by using software plus a necessary general-purpose hardware platform. Based on this understanding, the technical solutions of the above embodiments can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) and includes a number of instructions for causing a computer device (such as a personal computer, a server, or a network device) to execute the methods described in the various embodiments of the present invention.

[0074] Example 2

[0075] The present invention also provides a privacy-preserving federated learning system based on dual-objective data transformation, such as Figure 5 As shown, the system mainly includes: a local user and a global model server, which collaborate to execute the method provided in the above embodiment, specifically the above steps 11 to 15. Considering that the main technical details involved in the system have been introduced in detail in the previous embodiment, they will not be repeated here.

[0076] Those skilled in the art will clearly understand that for the convenience and brevity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the system can be divided into different functional modules to complete all or part of the functions described above.

[0077] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by any person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims. The information disclosed in the background technology section of this article is only intended to deepen the understanding of the overall background technology of the present invention, and should not be regarded as an admission or any form of implication that the information constitutes prior art already known to those skilled in the art.

Claims

1. A privacy-preserving federated learning method based on dual-objective data transformation, characterized by: include: Step 11: The local user shares the network structure of the classification model and the generation model with the global model server, and initializes the parameters of the feature extraction model, classification model, generation model, and discriminant model; In step 12, the local user freezes the parameters of the generative model and the discriminative model, inputs the local data set into the feature extraction model, obtains the data features of each local data, and classifies it through the classification model. The generative model generates the corresponding transformed data for each local data, combines the data features with the corresponding transformed data to construct a dual-target data transformation loss that integrates the visual dissimilarity loss and the feature similarity loss, and constructs the classification loss based on the classification results. The dual-target data transformation loss and the classification loss are combined to optimize the parameters of the feature extraction model and the classification model, and the parameters of the classification model are uploaded as shared parameters to the global model server. In step 13, the local user freezes the parameters of the feature extraction model and the classification model, uses the local dataset to train the generative model and the discriminant model, and uploads the parameters of the generative model as shared parameters to the global model server; Step 14: The global model server aggregates the parameters of the classification model and the generation model uploaded by the local user and performs a global model server update; In step 15, the local user downloads the updated classification model and generation model from the global model server and repeats steps 12, 13, and 14 until the number of global model server update rounds is reached, completing the training process of privacy-preserving federated learning based on dual-objective data transformation.

2. The privacy-preserving federated learning method based on dual-objective data transformation according to claim 1, characterized in that: Inputting the local data set into the feature extraction model to obtain the data features of each local data, and classifying it through the classification model includes: kth local user Owned by n k Original data x k,i and the corresponding category label y k,i Local dataset The k-th local user freezes the generated model G k Parameters and the discriminant model D k Parameters For the category label y k,i The original data The parameters used are Feature extraction model E k For the original data x k,i Extracting data features And use the parameters as Classification model C k Calculate the logical output of the data feature As the classification result.

3. The privacy-preserving federated learning method based on dual-objective data transformation according to claim 1, characterized in that: The generation of transformation data corresponding to each local data based on the generative model and the construction of a dual-target data transformation loss that integrates visual dissimilarity loss and feature similarity loss by combining data features with the corresponding transformation data include: The kth local user uses the generative model G k Gaussian noise and class label y k,i Generate transformation data And use the classifier C k Calculate the logical output of the transformed data Defining transformation data Among them, z k,i is the category label y k,i The corresponding original data; Combining data features with corresponding transformation data, a dual-target data transformation loss is constructed that integrates visual dissimilarity loss and feature similarity loss: Among them, the visual non-similarity loss is expressed as Parameter μ>0, parameter ε>0, feature similarity loss is expressed as Represents transformed data and data characteristics The cosine similarity of .

4. The privacy-preserving federated learning method based on dual-objective data transformation according to claim 1, 2, or 3, characterized in that: The parameters of the feature extraction model and the classification model optimized by combining the dual-objective data transformation loss and the classification loss are expressed as: Among them, ← is the assignment symbol, is the feature extraction model E after the qth round of training is completed k and classification model C k Parameters, To calculate the feature extraction model E k Gradient and Classification Model C k The gradient operator, is the feature extraction model E after the q-1th round of training is completed k and classification model C k Parameters, when q = 1, is the initialization parameter in step 11, η1 is the learning rate, and α and β are weights that control the importance of visual non-similarity loss and feature similarity loss.

5. The privacy-preserving federated learning method based on dual-objective data transformation according to claim 1, characterized in that: The use of local data sets to train the generative model and the discriminative model includes: For the kth local user, it uses the local dataset Train the generative model G k and the discriminant model D k , expressed as: Among them, ← is the assignment symbol, η2 is the learning rate, Generate model G when the qth round of training is completed k Parameters, Generate model G when the q-1th round of training is completed k Parameters, is the discriminant model D after the qth round of training is completed k Parameters, is the discriminant model D after the q-1th round of training is completed k Parameters, when q = 1, and is the initialization parameter in step 11; and Represent the computational generation model G k Gradient and discriminant model D k Gradient operator.

6. The privacy-preserving federated learning method based on dual-objective data transformation according to claim 5, characterized in that: The generation model loss and the discriminative model loss are expressed as: in, represents the mathematical expectation, For the kth local user Owned by n k Original data x k,i and the corresponding category label y k,i The local data set formed; Indicates that the kth local user uses the parameter Generative model G k and Gaussian noise and the class label y k,i The generated transformation data, is a normal distribution with a mean of 0 and a standard deviation of 1; Indicates that the kth local user uses the parameter Feature extraction model E k From the original data x k,i The data features extracted from Indicates that the kth local user uses the parameter The discriminant model D k The judgment result of input X is:

7. The privacy-preserving federated learning method based on dual-objective data transformation according to claim 1, characterized in that: The parameters of the classification model and generation model aggregated by the global model server and uploaded by local users are expressed as: in, is the parameter of the classification model when the global model server update is completed in round t, is the classification model parameter uploaded by the tth local user during the tth round of global model server update, To generate the model parameters when the global model server is updated in round t, is the generated model parameters uploaded by the tth local user during the tth round of global model server update, n k is the number of data of the kth local user, K is the number of local users, Represents the total amount of data of K local users.

8. A privacy-preserving federated learning system based on dual-objective data transformation, characterized by: include: The local user and the global model server collaborate to execute the method described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Non-equilibrium data-oriented cost-aware privacy protection federated learning method

    CN115511054A

  • Visual loopback detection method based on improved dynamic expansion model adaptive algorithm

    CN118038103A

  • Live broadcasting room marking method and system based on multi-modal characteristics

    CN118070126A

  • Personalized federated learning method and system based on similar features and collaboration

    WO2024169374A1