Decentralized federated learning-based poisoning attack dynamic defense method
By grouping multiple obfuscators and a dynamic evaluation mechanism, combined with differential privacy and anomaly detection, malicious users can be dynamically identified and eliminated, solving the problem of poisoning attacks in decentralized federated learning and achieving security and robustness in model training.
Patent Information
- Application Number
- CN202510648250.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-20
- Publication Date
- 2025-09-05
AI Technical Summary
Existing technologies make it difficult to effectively detect and dynamically defend against poisoning attacks in decentralized federated learning while ensuring data privacy, and traditional defense methods are difficult to cope with the changing attack methods.
It adopts a decentralized training mechanism based on group multi-obfuscator, combined with differential privacy, model regrouping, anomaly detection and similarity measurement algorithms, and dynamically evaluates user behavior, allocates learning rate and sets malicious user removal threshold to identify and remove malicious users in real time.
On the premise of protecting data privacy, it can effectively resist malicious poisoning attacks, ensure the security and robustness of model training, and prevent privacy leakage and system crashes during model training.
Smart Images

Figure CN120602123A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of data security technology and further relates to a data anomaly detection method, specifically a dynamic defense method for poisoning attacks based on decentralized federated learning, which can be used for dynamic anomaly detection of models in distributed model training. Background Art
[0002] With the widespread adoption of the internet and the digital transformation, new devices such as mobile phones, wearables, and IoT devices are increasingly emerging, significantly expanding the types of data they can collect, including sensitive information such as personal identities, movements, and biometrics. Data privacy protection is receiving unprecedented attention, and numerous laws and regulations have been implemented to protect personal information, posing significant challenges to data collection and training. Therefore, amidst the surge in information protection and data volumes, collecting distributed data and training machine learning models using centralized datasets is becoming increasingly difficult.
[0003] Federated learning, as a decentralized machine learning method, allows model training to be completed through local training, parameter updates, and model aggregation without sharing raw data. However, the characteristics of federated learning also provide opportunities for attackers. First, federated learning requires that trained models be received and processed by a centralized control node. If an attacker launches a denial-of-service attack against this node, the central node may be overwhelmed by traffic and unable to effectively process legitimate user requests, causing a system crash. Second, the centralized control node cannot access or inspect raw data, making it difficult to effectively detect when participating users inject malicious data. This impacts model convergence and may even introduce vulnerabilities such as backdoors, reducing model accuracy and robustness. Finally, each user uploads a different model update direction in each round, and malicious users carrying out poisoning attacks deviate from the normal update direction. This allows attackers to evade detection by continuously adjusting their update direction, further concealing themselves from legitimate users and causing continuous damage to the model.
[0004] Traditional federated learning, which relies on a central server to coordinate model training across multiple devices or clients, presents privacy concerns. However, if the central server is compromised or compromised, traditional federated learning can be manipulated or crashed by the attacker, creating a single point of failure. Furthermore, traditional poisoning mitigation methods typically only mitigate the attacker's impact on the model, but cannot detect and eliminate attackers. Most poisoning detection and defense methods rely on relatively fixed rules, making it difficult to develop a dynamic and effective response to changing attack methods.
[0005] In the application number "202311575911.2" and the name "A federated machine learning method and system with both robustness and privacy protection", matrix cryptography and secret sharing algorithms are used. Although it is possible to achieve effective aggregation of benign models while ensuring the privacy security of model parameters through model secret transmission, analysis, aggregation and other technologies, and solve the problem of privacy leakage and poisoning attacks in the existing technology that reduce the robustness of federated learning, the introduction of complex encryption and decryption operations affects the efficiency of model training; in the application number 202410825770.3 and the name "A federated learning method, device and computer-readable storage medium that are resistant to poisoning attacks under differential privacy protection constraints", a density-based abnormal model detection method is used. This method combines differential privacy technology with dynamic weight allocation and density screening mechanism to achieve the first effective detection of malicious poisoning attack clients in the federated learning framework that applies differential privacy, solving the problem that the existing technology is difficult to balance data privacy protection and resistance to poisoning attacks, but it is difficult to effectively defend against constantly changing attacks in real time. Summary of the Invention
[0006] The present invention aims to address the deficiencies of the above-mentioned existing technologies and propose a dynamic defense method for poisoning attacks based on decentralized federated learning. It is used to solve the problem that in decentralized federated learning, the existing technology is difficult to effectively detect and dynamically resist poisoning attacks while ensuring data privacy. This method designs a decentralized training mechanism based on a group multi-obfuscator. Through differential privacy, model regrouping and other algorithms, a decentralized structure is achieved under the premise of ensuring data privacy, avoiding the occurrence of single point failure problems; secondly, by combining anomaly detection, similarity measurement and other algorithms, a continuous hierarchical real-time evaluation of user behavior is performed. At the same time, different learning rates are assigned to users according to their maliciousness level to achieve the dilution of the toxicity generated by poisoning attacks and ensure the normality of model training during the period when malicious users participate in training; in addition, according to the statistical characteristics of the user's malicious score, the malicious user removal threshold is set in real time to achieve effective detection and dynamic removal of attackers. The present invention can effectively resist malicious poisoning attacks under the premise of decentralization and protection of user data privacy, and ensure the security and robustness of model training in decentralized federated learning.
[0007] The idea of implementing the method of the present invention is: using the aggregation platform to configure parameters such as the usage model, learning rate and termination conditions, participants deploy the training platform according to the above parameters, and perform local training until the distributed learning conditions are met; the system groups participants according to user model characteristics, and collects and rearranges model information within each group; then, by analyzing the model characteristics within the participant's group and its deviation from the global model, the model deviation and anomaly are calculated to generate the participant's malicious behavior score; then the aggregator of the current round is selected, the update information is collected and aggregated, and the new model is distributed to all participants. At the same time, user defense information is shared between groups, and the attack recognition threshold is dynamically determined based on the malicious score characteristics, thereby achieving effective identification of attackers.
[0008] To achieve the above object, the technical solution of the present invention includes the following steps:
[0009] (1) Presetting training-related parameters and defense-related parameters for multiple homogeneous servers deployed in parallel; the training-related parameters include at least learning rate, model type, and user entry conditions, and the learning rate of each server is the same; the defense-related parameters include at least behavior evaluation preference and model classifier;
[0010] (2) The user connects to the server and completes model pre-training:
[0011] (2.1) The user sends a model training joining request to the server. The server that receives the request randomly assigns the current user to any server and initializes the user's malicious index. At the same time, the user obtains and configures the training parameters;
[0012] (2.2) The user pre-trains the model locally until the model accuracy reaches a preset threshold, completing the local pre-training phase and obtaining a pre-trained model;
[0013] (3) The user adds Laplace noise to the parameters of the pre-trained model to meet the ε-differential privacy requirements and uploads the noisy model parameters to the connected server. After collecting the model parameters of multiple users, the server rearranges the co-located parameters of each user model received by position, that is, performs a permutation operation on the same position parameters of different users.
[0014] (4) Each server synchronizes the rearranged model parameters, completes model aggregation, obtains the global model M, and evaluates the maliciousness of user behavior based on its characteristics. The implementation steps are as follows:
[0015] (4.1) Randomly select any server as the aggregation server, and obtain the model parameters of the remaining users through the remaining servers to perform model aggregation;
[0016] (4.2) Each server uses the existing normal model data to train the classifier C, which is used in the global training phase to identify whether there are obvious inconsistencies in the various models of the group and calculate the abnormal index f of the user. A ;
[0017] (4.3) Calculate the deviation index f between the user model and the global model M D ;
[0018] (4.4) According to f A With f D Calculate the malicious index TI of each user's behavior, that is, the malicious behavior score:
[0019]
[0020] Among them, V is a pre-set weight parameter, t represents the number of times the user participates in model aggregation, m p is the model of user p;
[0021] (5) The maliciousness evaluation results of user behavior are shared among servers, and malicious users are eliminated based on the data characteristics of the results:
[0022] (5.1) The aggregation server sends the global model M to the remaining servers;
[0023] (5.2) Each server shares the malicious behavior scores of users in its group;
[0024] (5.3) The system's designated aggregation server performs statistical analysis on the malicious behavior score distribution of all users and dynamically adjusts the malicious user identification threshold based on the analysis results;
[0025] (5.4) Sharing the malicious user identification threshold parameters with other servers;
[0026] (5.5) Each server identifies and removes malicious users in the group in the current round based on the shared identification threshold parameters;
[0027] (6) All users identified as normal are randomly grouped into new groups, and their training parameters are dynamically adjusted according to their malicious index. That is, when the user's malicious index increases, its learning rate is lowered;
[0028] (7) Repeat steps (2)-(6) until the accuracy of the global model M on the test set reaches the preset target level.
[0029] Compared with the prior art, the present invention has the following significant advantages:
[0030] First, the present invention adopts a collaborative computing architecture based on group multi-obfuscators. Compared with the traditional single-obfuscator solution, the present invention innovatively establishes an obfuscation traceability blocking mechanism on the cloud server side, and uses a distributed obfuscation architecture to perform topological obfuscation and path camouflage on the source information of the uploaded model. Combined with the dynamic slicing storage solution of the obfuscation group key, it makes it impossible for attackers to reversely infer the identity of the model contributor through the server-side storage information. While ensuring the aggregation accuracy of the cloud model, it effectively solves the traceability leakage problem in multi-party collaboration.
[0031] Second, the present invention utilizes a dynamic security assessment system and innovatively designs a multi-dimensional dynamic assessment model, integrating multi-source indicators such as participant historical behavior analysis, gradient contribution verification, and local update deviation detection, breaking through the limitations of traditional single-dimensional assessment; at the same time, it proposes a threshold adaptive mechanism based on dynamic game, constructs a reputation score attenuation model with temporal memory according to the global model convergence state and attack intensity feedback, and uses a fuzzy control algorithm to dynamically optimize the malicious judgment threshold curve, which not only realizes the flexible adjustment of the assessment strategy in a highly confrontational environment, but also can effectively distinguish between occasional anomalies and continuous attacks.
[0032] Third, the present invention proposes a robust training method for federated learning against malicious attacks. To address the problem of the attacker's continued impact on the global model during his / her residence, a dynamic learning rate control mechanism is designed. Based on the evaluation results, an adaptive weighted algorithm is used to implement gradient amplification processing on high-credibility updates, and at the same time, dynamic learning rate decay is performed on updates whose deviation exceeds a threshold, thereby achieving the goal of suppressing the impact of malicious updates while ensuring model convergence efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] Figure 1 Flowchart for realizing the method of the present invention;
[0034] Figure 2 This is a schematic diagram of the overall structure of the decentralized federated learning defense in the present invention;
[0035] Figure 3 Schematic diagram of the model obfuscation implementation process in the present invention. DETAILED DESCRIPTION
[0036] The present invention will be described in further detail below with reference to the accompanying drawings.
[0037] Example 1: Refer to the attached Figure 1 The present invention proposes a dynamic defense method for poisoning attacks based on decentralized federated learning, which specifically includes the following steps:
[0038] Step 1) Preset training-related and defense-related parameters for multiple, parallel-deployed homogeneous servers; the training-related parameters include at least the learning rate, model type, and user entry requirements, with each server maintaining the same learning rate; and the defense-related parameters include at least the behavior assessment preference and model classifier. In this step, this embodiment first initializes the preconfigured distributed learning framework, determining the model type and parameter settings. It also configures the specific parameters of the distributed training architecture, including user participation requirements, training completion criteria, and inter-node communication protocols. Finally, the determined model type and parameter settings are synchronized to each participating server. When a new user requests to join, the server provides the current model type and parameters.
[0039] Step 2) The user connects to the server and completes model pre-training:
[0040] (2.1) The user sends a model training joining request to the server. The server that receives the request randomly assigns the current user to any server and initializes the user's malicious index. At the same time, the user obtains and configures the training parameters;
[0041] (2.2) The user pre-trains the model locally until the model accuracy reaches a preset threshold, completing the local pre-training phase and obtaining a pre-trained model;
[0042] Step 3) The user adds Laplace noise to the parameters of the pre-trained model to meet the ε-differential privacy requirements and uploads the noisy model parameters to the connected server; after collecting the model parameters of multiple users, the server rearranges the received co-located parameters of each user model according to position, that is, performs a permutation operation on the same position parameters of different users. In this embodiment, the user adds Laplace noise w' to the model parameters p_i , specifically implemented according to the following formula:
[0043]
[0044] Among them, w p_i represents the parameters of the user pre-trained model; λ is the noise parameter, Δf is the query sensitivity, and ε is the differential privacy parameter that measures the level of privacy protection.
[0045] Step 4) Each server synchronizes the rearranged model parameters, completes model aggregation, obtains the global model M, and evaluates the maliciousness of user behavior based on its characteristics. The implementation steps are as follows:
[0046] (4.1) Randomly select any server as the aggregation server, and obtain the model parameters of the remaining users through the remaining servers to perform model aggregation;
[0047] (4.2) Each server uses the existing normal model data to train the classifier C, which is used in the global training phase to identify whether there are obvious inconsistencies in the various models of the group and calculate the abnormal index f of the user. A , specifically as follows: Note that classifier C groups each server into G k Medium Model m p The judgment result is Flag(m p |m p ∈G k ), when the model is not identified as an abnormal model, the result is recorded as 1, otherwise it is recorded as 0; then the user's abnormal index f is calculated according to the following formula A :
[0048]
[0049] Where η is a pre-set scaling parameter, t represents the number of times a user participates in model aggregation, and r represents the summation index, representing different server groups or evaluation rounds;
[0050] (4.3) Calculate the deviation index f between the user model and the global model M D , the implementation steps are as follows:
[0051] (4.3.1) Calculate the global model M and user model m according to the following formula p The difference Err(m p ,M):
[0052]
[0053] Among them, m p,j With M j Indicates m p and the jth parameter in M,
[0054] (4.3.2) Calculate the model m of user p p Deviation index f from the global model M D :
[0055]
[0056] Among them, ζ is a pre-set scaling parameter.
[0057] (4.4) According to f A With f D Calculate the malicious index TI of each user's behavior, that is, the malicious behavior score:
[0058]
[0059] Among them, V is a pre-set weight parameter, t represents the number of times the user participates in model aggregation, mp is the model of user p;
[0060] Step 5) The maliciousness assessment results of user behavior are shared among the servers, and malicious users are eliminated based on the data characteristics of the results:
[0061] (5.1) The aggregation server sends the global model M to the remaining servers;
[0062] (5.2) Each server shares the malicious behavior scores of users in its group;
[0063] (5.3) The system-designated aggregation server performs statistical analysis on the malicious behavior score distribution of all users and dynamically adjusts the identification threshold of malicious users based on the analysis results. The identification threshold in this embodiment is expressed as follows:
[0064] Thr=μ+ασ+bias,
[0065] Where μ and σ are the mean and standard deviation of all scores in the current group, respectively. α and bias are the pre-set standard deviation scaling factor and threshold offset parameters, which are used to adjust the threshold setting according to the actual model.
[0066] (5.4) Sharing the malicious user identification threshold parameters with other servers;
[0067] (5.5) Each server identifies and removes malicious users in the group in the current round based on the shared identification threshold parameters;
[0068] Step 6) All users identified as normal are randomly grouped into new groups, and their training parameters are dynamically adjusted according to their malicious index. That is, when the user's malicious index increases, its learning rate is reduced;
[0069] Step 7) Repeat steps 2)-6) until the accuracy of the global model M on the test set reaches the preset target level.
[0070] Example 2: The overall implementation steps of the dynamic defense method proposed in this example are the same as those in Example 1. Figure 1-3 Specific parameter settings are given to further describe the implementation process of the present invention in detail:
[0071] Step 1. Each server pre-sets the same training-related parameters such as learning rate, usage model, and user entry conditions, as well as defense-related parameters such as behavior evaluation preferences and model classifier settings:
[0072] The server initializes the preconfigured distributed learning framework, determining the model type and parameter settings. It then initializes key parameters, including the learning rate and training batch size. After that, it configures specific parameters of the distributed training architecture, such as user participation requirements, training completion criteria, and inter-node communication protocols. Finally, the determined model and parameter configurations are synchronized to all participating servers, ensuring that all nodes begin training from the same starting point. When a new user requests to join, the server provides the current model and parameters, allowing them to seamlessly integrate into the training process.
[0073] This example uses an image classification task as an example, selecting a convolutional neural network (CNN) as the base model. The initial learning rate is set to 0.001, and the batch size is 64. User participation requires a local data volume of at least 1,000 annotated images, and training completion criteria require a global model accuracy of 95% or more than 100 training rounds. An encrypted communication protocol is used between nodes to ensure data security. These configurations lay the foundation for subsequent efficient and secure distributed learning.
[0074] Step 2. The user connects to the server and completes model pre-training:
[0075] (2a) The user sends a model training joining request to the server. The server that receives the request will randomly assign the user to any server and obtain and configure the training parameters;
[0076] (2b) The user trains the model locally and determines whether the conditions for joining the group are met after each training session.
[0077] (2c) Repeat step (2b) until the group entry conditions are met, the user joins the global training, and uploads the model information to the connected server, as follows:
[0078] When a user meets the group entry requirements and requests to join the training framework, the server initializes the user's maliciousness index and assigns it to a random server. After each round of training, all users assessed as benign are randomly assigned again, and learning parameters such as the learning rate are dynamically configured based on the user's maliciousness score. Afterward, users join the training and submit model updates to their server.
[0079] Step 3. Reference Figure 3 The server splits and obfuscates the model parameters received from each user and hides the model attribution information, as follows:
[0080] After the server has completed the acquisition of all user model update information in the group, the model obfuscation operation is performed. First, Laplace noise is added to the model data to meet the ε-differential privacy requirements. For user p’s model m with n parameters, p , to each parameter w p_i The calculation formula for adding noise is as follows:
[0081]
[0082] Where λ is the noise parameter, and the query sensitivity is Δf. The noise parameter that meets the ε-differential privacy requirement is calculated as:
[0083]
[0084] After that, the model parameters are rearranged, that is, the model parameters w uploaded by each user during the model training process are rearranged. p_i After the core obfuscation mechanism is processed. Specifically, the mechanism performs a permutation operation on the parameters at the same position. For example, w from different user models p_1 The series parameters will be rearranged, and so will the remaining parameters.
[0085] Step 4. Each server synchronizes the received model parameters, completes model aggregation, and evaluates the maliciousness of user behavior based on model characteristics:
[0086] (4a) Randomly select any server as the aggregation server, and obtain the model information of the remaining users from other servers to perform model aggregation;
[0087] (4b) Each server uses the model classifier C to classify the model m of the received user p p Classify and record the classification result as the abnormality index Flag(m p ), and calculate the user's abnormal index f A ;
[0088] Before calculating the abnormal index, we first use the existing normal model data to train a classifier C, which is used to identify whether there are obvious inconsistencies in the various models of the group within this period. The present invention uses the DBSCAN clustering algorithm to identify abnormal models. k Medium Model m p The judgment result is Flag(m p |m p ∈G k ), when the model is not identified as an abnormal model, the result is recorded as 1, otherwise it is recorded as 0. Abnormal index f A The definition is as follows:
[0089]
[0090] Wherein η is a preset parameter.
[0091] (4c) Each server calculates the received model m p Deviation index f from the global model M D ;
[0092] For the model of user p, record the n parameters in the global model M and the model m p The difference of n parameters in is:
[0093]
[0094] Deviation malicious index f D The definition is as follows:
[0095]
[0096] Where ζ is a pre-set parameter.
[0097] (4d) Each server calculates the anomaly index f of the received model A and the deviation index f D , calculate the malicious index TI of each user behavior;
[0098] Combined with the user's abnormal index f A and the deviation index f D , these two malicious indices can be used to represent the malicious index of user behavior:
[0099]
[0100] Where V is a preset parameter.
[0101] Step 5. Share the user behavior evaluation results between servers and remove malicious users based on the data characteristics of the evaluation results:
[0102] (5.1) The aggregation server sends the global model to the remaining servers;
[0103] (5.2) Each server shares the maliciousness scores of users in its group;
[0104] (5.3) The selected information processing server in this round analyzes the distribution of user malicious scores and dynamically adjusts the identification threshold for malicious users;
[0105] (5.4) After the analysis is completed, the recognition threshold is shared with other servers;
[0106] After completing the user maliciousness assessment, each server sends the maliciousness index of each user to the selected server to calculate the rejection threshold. At this time, the threshold for identifying a user as a malicious user can be calculated as:
[0107] Thr=μ+ασ+bias,
[0108] Where μ and σ are the mean and standard deviation of all scores in the group, respectively; α and bias are pre-set parameters used to adjust the threshold settings according to the actual model.
[0109] (5.5) After receiving the malicious user identification threshold for this round, each server will identify and remove malicious users from the group, randomly group all users identified as normal users in a new round, and dynamically adjust their training parameters based on their malicious score characteristics;
[0110] Step 6. Repeat steps 2-5 until the user training end condition or the global model training end condition is met.
[0111] This paper constructs a dual-platform initialization architecture based on a trusted execution environment, deploys parameter obfuscation and dynamic grouping strategies; designs a multi-layer progressive security assessment model that integrates subgroup parameter similarity detection, gradient manifold analysis, and Bayesian reasoning; implements a dynamic learning rate control system to generate an interference-resistant learning rate matrix through gradient credibility assessment; implements an adaptive aggregation algorithm with temporal memory, combined with a secure multi-party computing protocol to synchronize defense parameters across subgroups; and establishes a dynamic threshold generator that outputs attack judgment boundaries and updates the global defense strategy based on a federated game model. This approach significantly improves the system's ability to resist malicious attacks while ensuring model convergence efficiency, effectively preventing privacy leaks and security threats during model training.
[0112] Parts of the present invention that are not described in detail belong to common knowledge among those skilled in the art.
[0113] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Obviously, for professionals in this field, after understanding the content and principles of the present invention, they may make various modifications and changes in form and details without departing from the principles and structure of the present invention. However, these modifications and changes based on the ideas of the present invention are still within the scope of protection of the claims of the present invention.
Claims
1. A dynamic defense method for poisoning attacks based on decentralized federated learning, characterized in that: The steps include: (1) Presetting training-related parameters and defense-related parameters for multiple homogeneous servers deployed in parallel; the training-related parameters include at least learning rate, model type, and user entry conditions, and the learning rate of each server is the same; the defense-related parameters include at least behavior evaluation preference and model classifier; (2) The user connects to the server and completes model pre-training: (2.1) The user sends a model training joining request to the server. The server that receives the request randomly assigns the current user to any server and initializes the user's malicious index. At the same time, the user obtains and configures the training parameters; (2.2) The user pre-trains the model locally until the model accuracy reaches a preset threshold, completing the local pre-training phase and obtaining a pre-trained model; (3) The user adds Laplace noise to the parameters of the pre-trained model to meet the ε-differential privacy requirements and uploads the noisy model parameters to the connected server. After collecting the model parameters of multiple users, the server rearranges the co-located parameters of each user model received by position, that is, performs a permutation operation on the same position parameters of different users. (4) Each server synchronizes the rearranged model parameters, completes model aggregation, obtains the global model M, and evaluates the maliciousness of user behavior based on its characteristics. The implementation steps are as follows: (4.1) Randomly select any server as the aggregation server, and obtain the model parameters of the remaining users through the remaining servers to perform model aggregation; (4.2) Each server uses the existing normal model data to train the classifier C, which is used in the global training phase to identify whether there are obvious inconsistencies in the various models of the group and calculate the abnormal index f of the user. A ; (4.3) Calculate the deviation index f between the user model and the global model M D ; (4.4) According to f A With f D Calculate the malicious index TI of each user's behavior, that is, the malicious behavior score: Among them, V is a pre-set weight parameter, t represents the number of times the user participates in the model aggregation, m p is the model of user p; (5) The maliciousness evaluation results of user behavior are shared among servers, and malicious users are eliminated based on the data characteristics of the results: (5.1) The aggregation server sends the global model M to the remaining servers; (5.2) Each server shares the malicious behavior scores of users in its group; (5.3) The system's designated aggregation server performs statistical analysis on the malicious behavior score distribution of all users and dynamically adjusts the malicious user identification threshold based on the analysis results; (5.4) Sharing the malicious user identification threshold parameters with other servers; (5.5) Each server identifies and removes malicious users in the group in the current round based on the shared identification threshold parameters; (6) All users identified as normal are randomly grouped into new groups, and their training parameters are dynamically adjusted according to their malicious index. That is, when the user's malicious index increases, its learning rate is lowered; (7) Repeat steps (2)-(6) until the accuracy of the global model M on the test set reaches the preset target level.
2. The method according to claim 1, wherein: The server described in step (1) first initializes the pre-configured distributed learning framework and determines the model type and parameter settings; at the same time, it configures the specific parameters of the distributed training architecture, including user participation conditions, training completion standards, and inter-node communication protocols; finally, it synchronizes the determined model type and parameter settings to each participating server. When a new user requests to join, the server provides the current model type and parameters.
3. The method according to claim 1, wherein: In step (3), the user adds Laplace noise w' to the model parameters p_i , according to the following formula: Among them, w p_i represents the parameters of the user pre-trained model; λ is the noise parameter, Δf is the query sensitivity, and ε is the differential privacy parameter that measures the level of privacy protection.
4. The method according to claim 1, wherein: The calculation described in step (4.2) obtains the user's abnormal index f A , specifically as follows: Note that classifier C groups each server into G k Medium Model m p The judgment result is Flag(m p |m p ∈G k ), when the model is not identified as an abnormal model, the result is recorded as 1, otherwise it is recorded as 0; then the user's abnormal index f is calculated according to the following formula A : Where η is a pre-set scaling parameter, t represents the number of times a user participates in model aggregation, and r represents the index of the summation, representing different server groups or evaluation rounds.
5. The method according to claim 1, wherein: In step (4.3), the deviation index f between the user model and the global model M is calculated D , the implementation steps are as follows: (4.3.1) Calculate the global model M and user model m according to the following formula p The difference Err(m p ,M): Among them, m p,j With M j Indicates m p and the jth parameter in M, (4.3.2) Calculate the model m of user p p Deviation index f from the global model M D : Among them, ζ is a pre-set scaling parameter.
6. The method according to claim 1, wherein: The recognition threshold in step (5.3) is expressed as follows: Thr=μ+ασ+bias, Where μ and σ are the mean and standard deviation of all scores in the current group, respectively. α and bias are the pre-set standard deviation scaling factor and threshold offset parameters, which are used to adjust the threshold setting according to the actual model.
Citation Information
Patent Citations
A federated machine learning method and system that takes into account both robustness and privacy protection
CN117828627B
A federated learning method, device and computer-readable storage medium for resisting poisoning attacks under differential privacy protection constraints
CN118378255B
Cited By
Anti-physical attack edge AI model dynamic protection method, device and program product
CN122179140A