Federal learning abnormal node detection method, system and device and medium

By constructing a multi-dimensional fuzzy evaluation model and dynamic threshold optimization, combined with encrypted transmission and secure authentication, the problem of abnormal node detection in federated learning is solved, efficient and secure abnormal node identification and processing are achieved, and the robustness and training efficiency of the system are improved.

CN120639341APending Publication Date: 2025-09-12SHANDONG ZHICHUANG DIGITAL TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510654195.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-21
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

In existing federated learning systems, it is difficult to effectively detect and respond to complex and changeable abnormal nodes, resulting in deviations in model training and a decrease in credibility.

Method used

A multi-dimensional fuzzy evaluation model is constructed by combining fuzzy theory. Abnormal nodes are detected through membership function, hierarchical analysis method and dynamic threshold adjustment algorithm. HTTPS/ECC/SSL protocol is used for node identity authentication. Paillier homomorphic encryption is used to transmit model parameters. Decision tree classification algorithm is used to identify and process abnormal nodes.

Benefits of technology

It achieves accurate detection and low misjudgment of abnormal nodes, improves the robustness, security and training efficiency of the federated learning system, ensures communication privacy and maintains system stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639341A_ABST
    Figure CN120639341A_ABST
Patent Text Reader

Abstract

The invention provides a federal learning abnormal node detection method, system and device and a medium, and belongs to the technical field of privacy computing. The method comprises the following steps: constructing a multi-dimensional fuzzy evaluation model, and adopting a dynamic threshold adjustment algorithm to realize real-time detection of abnormal nodes; node identity authentication and key distribution are completed through a security protocol combination, and model parameter transmission security is guaranteed in combination with a homomorphic encryption technology; an optimization algorithm and a multi-thread mechanism are introduced in the local training stage to improve the training efficiency; the aggregation server identifies abnormal nodes based on fuzzy evaluation and decision tree classification and executes weight attenuation or removal operation; and finally, a federated average algorithm is adopted to aggregate normal node models, and after secure transmission and distribution, each node completes model iteration through transfer learning and back propagation. According to the method, a fuzzy theory is combined, a plurality of fuzzy features of abnormal nodes are used for detecting node behaviors and states, and the problem that model training deviates due to the fact that federated nodes are abnormal in the past is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of privacy computing technology, and more specifically relates to a method, system, device and medium for detecting abnormal nodes in federated learning. Background Art

[0002] Federated learning is an emerging distributed machine learning approach that allows multiple users to collaboratively train models without sharing local data. However, in federated learning systems, malicious users (i.e., anomalous nodes) may upload false or low-quality local models, thereby compromising the accuracy and credibility of the global model. Existing anomalous node detection methods often rely on simple threshold judgments or statistical methods, which are difficult to effectively address complex and changing anomalous behavior.

[0003] Fuzzy theory is a mathematical tool for dealing with uncertainty and ambiguity. It effectively describes and handles ambiguity and uncertainty in the real world. Traditional binary logic can only express absolute true or false (i.e., 0 and 1). However, many real-world phenomena are less clear-cut. For example, terms like "high temperature" and "young" are difficult to define with precise numerical values. Fuzzy theory was developed to address this need.

[0004] Federated learning is a distributed learning paradigm in which data is stored locally on each participating node. Each node independently trains its model and then uploads its parameters to an aggregation node for integration. Because the quality of each node's model impacts the overall performance, anomalies in any node can lead to biased aggregated results or even model failure. Furthermore, abnormal information about participating nodes is often subtle, making it difficult to accurately detect them through traditional detection methods. Therefore, designing a method that can leverage fuzzy information to detect abnormal nodes has become a pressing issue. Summary of the Invention

[0005] In response to the above problems, the purpose of the present invention is to provide a method, system, device and medium for detecting abnormal nodes in federated learning. By combining fuzzy theory and utilizing several fuzzy features of abnormal nodes to detect node behavior and status, the present invention solves the problem of deviations in model training caused by abnormalities in federated nodes.

[0006] To achieve the above-mentioned purpose, the present invention is implemented through the following technical solutions: In a first aspect, an embodiment of the present application provides a method for detecting abnormal nodes in federated learning, comprising: Construct a fuzzy evaluation model that includes historical participation, model quality, and data contribution. Initialize the model and optimize the detection threshold in real time using membership functions, analytic hierarchy process, and dynamic threshold adjustment algorithms. Each node registers with the aggregation server via HTTPS. After identity verification through digital signature and certificate, the aggregation server generates a public key based on the ECC algorithm and distributes the public key via the SSL protocol. On each node, a local model is trained using a machine learning algorithm combined with a variant of stochastic gradient descent and early stopping. The encrypted local model is then uploaded to the aggregation server via the DHT network after being homomorphically encrypted using Paillier encryption. The aggregation server then receives and verifies the data through multiple threads. The aggregation server decrypts the encrypted local model, performs single-factor fuzzy evaluation based on the fuzzy evaluation model, constructs the fuzzy evaluation matrix, and obtains the node comprehensive membership through weighted average synthesis; By comparing the comprehensive membership degree with the detection threshold through the decision tree classification algorithm, abnormal nodes are removed or their aggregation weight is reduced. The local models of non-abnormal nodes are aggregated and the federated averaging algorithm is used to generate a global model. After the global model is distributed through SFTP, the nodes use transfer learning and back propagation to update the local models of non-abnormal nodes and iterate the model according to the convergence conditions.

[0007] In an optional embodiment, the fuzzy evaluation model including historical participation, model quality, and data contribution is constructed, the model is initialized and the detection threshold is optimized in real time through a membership function, a hierarchical analysis method, and a dynamic threshold adjustment algorithm, including: A fuzzy evaluation model is constructed based on fuzzy mathematics theory, and a fuzzy set is defined, including three core dimensions: historical participation, model quality, and data contribution. In the dimension of historical participation, a fuzzy subset of this dimension is set. By establishing a participation frequency statistical model based on a time window and combining it with a sliding average algorithm to calculate the historical participation frequency of the node, the membership formula is determined. In the model quality dimension, a fuzzy subset of this dimension is defined. Cross-validation technology is used to obtain key indicators such as the accuracy and loss value of the local model during training. The mapping relationship between model quality and membership is established through the trapezoidal membership function. In the dimension of data contribution, a fuzzy subset of this dimension is constructed, and the data diversity is calculated using information entropy. The data volume is taken as the input variable, and the membership of the data contribution is determined by the Sigmoid membership function. The judgment matrix is ​​constructed using the hierarchical analysis method, and the weight vector of each evaluation factor is set. According to historical data and the expected false positive rate of the system, the adaptive threshold adjustment algorithm is used to set the initial value of the abnormal node detection threshold. During the system operation, the threshold is adjusted in real time through the dynamic programming algorithm.

[0008] In an optional embodiment, the registration with the aggregation server via HTTPS, after identity verification by digital signature and certificate, the aggregation server generates a public key based on the ECC algorithm and distributes the public key via the SSL protocol, includes: Each node initiates a federated learning task registration request to the aggregation server based on the Hypertext Transfer Protocol Security. The task registration request includes the node's identity and hardware resource information. When the aggregation server receives the registration information, it verifies the node identity through the built-in identity authentication module and uses digital signature and certificate verification mechanisms to ensure the authenticity and legitimacy of the node identity; After verification, the elliptic curve cryptography algorithm is used to generate a pair of public and private keys for each participating node, and the public key is sent to the corresponding node through the secure socket layer protocol.

[0009] In an optional embodiment, on each node, a machine learning algorithm is used in combination with a stochastic gradient descent variant and an early stopping method to train a local model, and the encrypted local model is uploaded to the aggregation server via the DHT network after Paillier homomorphic encryption. The aggregation server receives and verifies the model through multi-threading, including: On each participating node, based on the objectives of the federated learning task, an adapted machine learning algorithm is selected and model training is performed using the locally stored dataset. During the training process, stochastic gradient descent and its variants are used for parameter optimization; After training is completed, the public key distributed by the aggregation server is used to encrypt the parameters of the local model based on the Paillier homomorphic encryption algorithm; After encryption is completed, the local node uploads the encrypted local model to the aggregation server through the distributed hash table network; The aggregation server adopts a multi-threaded concurrent receiving mechanism, combined with data verification and technology to ensure the collection of encrypted local models uploaded by all nodes and record the upload time.

[0010] In an optional embodiment, the aggregation server decrypts the encrypted local model, performs single-factor fuzzy evaluation based on the fuzzy evaluation model, constructs a fuzzy evaluation matrix, and obtains the node comprehensive membership by weighted average synthesis, including: After the aggregation server receives the encrypted local models uploaded by all nodes, it uses the corresponding private key to decrypt them and obtain the original local model information; Based on the fuzzy evaluation model, single-factor fuzzy evaluation is performed on the three dimensions of historical participation, model quality, and data contribution; For the fuzzy evaluation of the historical participation dimension, the actual participation frequency of the node is calculated by combining the registration information and upload time, and the membership degree of the node in each fuzzy subset of the historical participation dimension is determined by the membership formula; For the fuzzy evaluation of the model quality dimension, the accuracy and loss values ​​recorded during the training process are used to calculate the membership of the node in the fuzzy subset of the dimension through the membership function; For the fuzzy evaluation of the data contribution dimension, the corresponding membership is obtained through the membership function based on the calculation results of the data volume and data diversity provided by the node; The single-factor fuzzy evaluation results of the three dimensions of historical participation, model quality, and data contribution are combined to form a 3×6 fuzzy evaluation matrix, where the matrix elements are the membership degrees of the corresponding evaluation factors to that level; The comprehensive node membership is calculated by using the weight vector of the evaluation factors through weighted average fuzzy synthesis operation.

[0011] In an optional embodiment, the comparing the comprehensive membership degree with the detection threshold by the decision tree classification algorithm and performing the operation of removing or reducing the aggregation weight of abnormal nodes includes: According to the comprehensive membership of the step node, it is compared with the detection threshold; The decision tree classification algorithm is used to classify and judge the nodes. When the sum of the comprehensive membership of the node to the preset level is greater than the detection threshold, the node is identified as an abnormal node. For identified abnormal nodes, the difference between their comprehensive membership and the detection threshold is calculated. If the difference is greater than the preset severity threshold, the node is removed from the federated learning system through the preset node management module; if the difference is less than the preset severity threshold, the weight adjustment algorithm is used to reduce the weight of the node in the model aggregation.

[0012] In an optional embodiment, the local models of non-abnormal nodes are aggregated and a federated averaging algorithm is used to generate a global model. After the global model is distributed via SFTP, the nodes use transfer learning and back propagation to update the local models of the non-abnormal nodes, and the model is iterated according to the convergence condition, including: The aggregation server filters out local models uploaded by nodes that are not identified as abnormal, and uses the federated averaging algorithm to aggregate the models; According to the amount of training data or computing resources of each non-abnormal node, the aggregation weight is allocated, and the local model parameters of each non-abnormal node are weighted and summed according to the weight to obtain the global model of the current iteration round; The global model is distributed to all user nodes via a secure file transfer protocol. After receiving the global model, each node uses transfer learning technology to integrate and update the global model parameters with the local model based on local data and the optimized training strategy, and iterates the local model through the back-propagation algorithm. After completing a model iteration, check whether the preset convergence conditions are met. If the convergence conditions are not met, use a machine learning algorithm combined with a stochastic gradient descent variant and early stopping method to train the local model until the preset convergence conditions are met.

[0013] In a second aspect, an embodiment of the present application further provides a federated learning abnormal node detection system, including: The fuzzy model construction and threshold initialization module is used to build a fuzzy evaluation model that includes historical participation, model quality, and data contribution. It initializes the model and optimizes the detection threshold in real time through membership function, hierarchical analysis method, and dynamic threshold adjustment algorithm. The node security registration and public key distribution module is used to register with the aggregation server via HTTPS on each node. After the identity is verified by digital signature and certificate, the aggregation server generates a public key based on the ECC algorithm and distributes the public key via the SSL protocol. The local model training and encrypted upload module is used to train the local model on each node using a machine learning algorithm combined with a variant of stochastic gradient descent and early stopping. The encrypted local model is then uploaded to the aggregation server via the DHT network after Paillier homomorphic encryption. The aggregation server then receives and verifies the model through multiple threads. The encryption model decryption and fuzzy evaluation module is used by the aggregation server to decrypt the encrypted local model, perform single-factor fuzzy evaluation based on the fuzzy evaluation model, construct the fuzzy evaluation matrix, and obtain the node comprehensive membership through weighted average synthesis; The abnormal node determination and classification processing module is used to compare the comprehensive membership degree with the detection threshold through the decision tree classification algorithm, and remove or reduce the aggregation weight of abnormal nodes; The non-abnormal model aggregation and global update module is used to aggregate the local models of non-abnormal nodes and generate a global model using the federated averaging algorithm. After distribution through SFTP, the nodes use transfer learning and back propagation to update the local models of non-abnormal nodes and iterate the model according to the convergence conditions.

[0014] In a third aspect, an embodiment of the present application further provides an electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, the steps of the federated learning abnormal node detection method as described in any one of the above items are implemented.

[0015] In a fourth aspect, an embodiment of the present application further provides a storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps of the federated learning abnormal node detection method as described in any one of the above items are implemented.

[0016] It can be seen from the above technical solutions that the present invention has the following advantages: The federated learning anomaly node detection method proposed in this application incorporates fuzzy theory into federated learning anomaly node detection. By constructing a fuzzy evaluation model, it provides a more accurate assessment of node credibility. This method comprehensively considers multiple dimensions, including a node's historical participation, model quality, and data contribution, to conduct a comprehensive node assessment, improving detection accuracy and reliability. Furthermore, the anomaly node detection threshold is dynamically adjusted based on the actual situation of the federated learning system, adapting to federated learning scenarios of varying scale and complexity.

[0017] This application achieves accurate anomaly detection through multi-dimensional fuzzy evaluation and dynamic threshold optimization, combines encrypted transmission and secure authentication to ensure communication privacy, and uses efficient training strategies and federal aggregation mechanisms to improve model performance. Ultimately, it forms a federated learning anomaly node management solution with adaptive security protection, low misjudgment rate, and high resource utilization, significantly enhancing the robustness, security, and training efficiency of the federated learning system.

[0018] This application achieves multi-factor quantitative evaluation by integrating a fuzzy evaluation model that integrates historical participation, model quality, and data contribution, combined with hierarchical analysis and dynamic threshold adjustment, effectively reducing the misjudgment rate and accurately identifying low-quality or malicious nodes.

[0019] This application uses the HTTPS / ECC / SSL protocol to complete node identity authentication and public key distribution, combined with Paillier homomorphic encryption to transmit model parameters, to build a full-process encrypted link from registration to aggregation to prevent model parameter leakage and man-in-the-middle attacks.

[0020] This application uses a variant of stochastic gradient descent to accelerate local training, early stopping to prevent overfitting, and multi-threaded reception and DHT network transmission to significantly improve training efficiency; the federated averaging algorithm aggregates non-abnormal node models and combines transfer learning to achieve rapid convergence.

[0021] This application uses a dynamic programming algorithm to optimize the detection threshold in real time, and uses decision tree classification to accurately distinguish the level of anomalies. It uses weight decay instead of direct elimination for mild and moderate abnormal nodes, maintaining the stability of the federated learning ecosystem while ensuring security. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the technical solution of the present invention, the following is a brief introduction to the drawings required for the description. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0023] Figure 1 Schematic diagram of the process of detecting abnormal nodes in federated learning provided in this application.

[0024] Figure 2 A flowchart of another federated learning abnormal node detection method provided in this application.

[0025] Figure 3 Schematic diagram of the structure of the federated learning anomaly node detection system provided in this application.

[0026] Figure 4 This is a schematic diagram of the structure of the electronic device provided in this application. DETAILED DESCRIPTION

[0027] The specific steps of the federated learning abnormal node detection method will be described in detail below, and various embodiments of the present disclosure will be described more fully. The present disclosure can have various embodiments, and adjustments and changes can be made therein. However, it should be understood that there is no intention to limit the various embodiments of the present disclosure to the specific embodiments disclosed herein, but rather that the present disclosure should be understood to cover all adjustments, equivalents, and / or alternatives that fall within the spirit and scope of the various embodiments of the present disclosure.

[0028] Hereinafter, the terms "include" or "may include" as used in various embodiments of the present disclosure indicate the presence of disclosed functions, operations, or elements, and do not limit the addition of one or more functions, operations, or elements. In addition, as used in various embodiments of the present disclosure, the terms "include," "have," and their cognates are intended only to indicate specific features, numbers, steps, operations, elements, components, or combinations of the foregoing, and should not be understood as excluding the presence of one or more other features, numbers, steps, operations, elements, components, or combinations of the foregoing, or the possibility of adding one or more features, numbers, steps, operations, elements, components, or combinations of the foregoing.

[0029] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0030] See also Figure 1 FIG. 1 is a flowchart of a method for detecting abnormal nodes in federated learning according to a specific embodiment. The method includes: S1: Construct a fuzzy evaluation model that includes historical participation, model quality, and data contribution. Initialize the model and optimize the detection threshold in real time through membership function, hierarchical analysis method, and dynamic threshold adjustment algorithm.

[0031] In a specific implementation, a fuzzy evaluation model is first constructed based on fuzzy mathematics theory, defining fuzzy sets for three core dimensions: historical participation, model quality, and data contribution. Within the historical participation dimension, three fuzzy subsets are defined: {"frequent historical participation," "average historical participation," and "rare historical participation." A time-window-based participation statistics model is established, combined with a sliding average algorithm to calculate the node's historical participation frequency. A membership formula is then determined, such as a Gaussian membership function, using historical participation and frequency as input parameters. The greater the number of participations and the higher the frequency, the closer the node's membership to the "frequent historical participation" fuzzy set approaches 1. Within the model quality dimension, the fuzzy subsets {"high model quality," "average model quality," and "low model quality"} are defined. Cross-validation techniques are used to obtain key metrics such as the accuracy and loss of the local model during training. A trapezoidal membership function is used to map model quality to membership. Higher accuracy and lower loss indicate a higher membership for "high model quality." For the data contribution dimension, a fuzzy subset of {"high data contribution", "average data contribution", and "low data contribution"} was constructed. Information entropy was used to calculate data diversity. The Sigmoid membership function was used to determine the data contribution degree, taking the data volume as the input variable. The greater the amount of data provided and the higher the data diversity, the higher the membership degree of "high data contribution". Furthermore, a judgment matrix was constructed using the Analytic Hierarchy Process (AHP). Expert scoring was used to determine the weight vectors for each evaluation factor. Based on historical data and the system's expected false positive rate, an adaptive threshold adjustment algorithm was used to set the initial value of the anomaly node detection threshold. During system operation, the threshold was adjusted in real time using a dynamic programming algorithm based on changes in the number of users and the proportion of anomaly nodes, balancing detection accuracy and system efficiency.

[0032] S2: Each node registers with the aggregation server via HTTPS. After identity verification via digital signature and certificate, the aggregation server generates a public key based on the ECC algorithm and distributes the public key via the SSL protocol.

[0033] In a specific implementation, each node initiates a federated learning task registration request to the aggregation server based on the Hypertext Transfer Protocol Secure (HTTPS). The request contains metadata such as the node's identity, hardware resource information, etc. After receiving the registration information, the aggregation server verifies the node's identity through the identity authentication module, and uses a digital signature and certificate verification mechanism to ensure the authenticity and legitimacy of the node's identity. After the verification is passed, the elliptic curve cryptography (ECC) algorithm is used to generate a pair of public and private keys for each participating node, and the public key is sent to the corresponding node through the Secure Sockets Layer (SSL) protocol. The public key is used in the subsequent process for the node to homomorphically encrypt the local model, ensuring that even if the model is intercepted during transmission, the attacker cannot obtain the original information of the model parameters, providing security for the node to upload the encrypted model.

[0034] S3: On each node, a machine learning algorithm combined with a variant of stochastic gradient descent and early stopping is used to train the local model. After Paillier homomorphic encryption, the encrypted local model is uploaded to the aggregation server via the DHT network. The aggregation server receives and verifies the data through multiple threads.

[0035] In a specific implementation, each participating node selects an appropriate machine learning algorithm (such as a deep neural network (DNN) or support vector machine (SVM)) based on the objectives of the federated learning task and uses locally stored datasets for model training. During training, stochastic gradient descent (SGD) and its variants (such as Adam and Adagrad) are used for parameter optimization, and early stopping is used to prevent model overfitting. After training is complete, the local model parameters are encrypted using the public key distributed by the aggregation server using the Paillier homomorphic encryption algorithm. This algorithm supports addition and multiplication operations in ciphertext, ensuring that the encrypted model parameters do not need to be decrypted during calculations on the aggregation server, effectively protecting data privacy. After encryption, the node uploads the local encrypted model to the aggregation server via a distributed hash table (DHT) network. The aggregation server uses a multi-threaded concurrent reception mechanism and data checksum technology to ensure accurate collection of encrypted models uploaded by all nodes. It also records metadata such as the upload time for subsequent evaluation.

[0036] S4: The aggregation server decrypts the encrypted local model, performs single-factor fuzzy evaluation based on the fuzzy evaluation model, constructs the fuzzy evaluation matrix, and obtains the node comprehensive membership through weighted average synthesis.

[0037] In a specific implementation, after the aggregation server receives the local encrypted models uploaded by all nodes, it uses the corresponding private key to decrypt them. The decryption process uses a secure key management system to ensure that the storage and use of the private key comply with security specifications. After decrypting and obtaining the original local model information, based on the fuzzy evaluation model constructed in step S1, a single-factor fuzzy evaluation is performed on the three dimensions of historical participation, model quality, and data contribution. In the historical participation evaluation, the actual participation frequency of the node is calculated based on the registration information recorded in step S2 and the upload time of step S3, and the membership of the node in each fuzzy subset of the historical participation dimension is determined by the membership formula; for the model quality dimension, the accuracy rate, loss value and other indicators recorded during the training process are used to calculate the node's membership in the three fuzzy subsets of "high model quality", "average model quality" and "low model quality" through the membership function; in the data contribution dimension, the corresponding membership is obtained through the membership function based on the calculation results of the amount of data and data diversity provided by the node. The single-factor fuzzy evaluation results from the three dimensions are combined to form a 3×6 fuzzy evaluation matrix, where the rows correspond to the three evaluation factors, and the columns correspond to the six levels of the node evaluation set {"trustworthy," "relatively trustworthy," "basically trustworthy," "node questionable," "low trustworthiness," and "untrustworthy"}. The matrix elements represent the membership of the corresponding evaluation factor to that level. Finally, using the evaluation factor weight vectors determined in step S1, a weighted average fuzzy synthesis operation is performed to calculate the node's comprehensive membership to each level in the node evaluation set, thus achieving a comprehensive assessment of the node's trustworthiness.

[0038] S5: Compare the comprehensive membership degree with the detection threshold through the decision tree classification algorithm, and remove or reduce the aggregation weight of abnormal nodes.

[0039] In a specific embodiment, the node comprehensive membership calculated in step S4 is compared with the dynamically adjusted abnormal node detection threshold. A decision tree classification algorithm is used to classify and judge the nodes. When the sum of the comprehensive memberships of the nodes belonging to the "node in doubt," "low trust," and "untrustworthy" levels is greater than the detection threshold, the node is identified as an abnormal node. For the identified abnormal node, the difference between its comprehensive membership and the threshold is calculated. If the difference is greater than the pre-set severity threshold, the node is removed from the federated learning system through the node management module, and the node list and communication topology in the system are updated. If the difference is less than the severity threshold, a weight adjustment algorithm is used to reduce the weight of the node in the model aggregation. For example, its weight is multiplied by an adjustment coefficient less than 1, so that the node's contribution to the update of the global model is reduced, thereby reducing the impact of the abnormal node on the overall performance of the federated learning system.

[0040] S6: Aggregate the local models of non-abnormal nodes and use the federated averaging algorithm to generate a global model. After distributing it through SFTP, the nodes use transfer learning and back propagation to update the local models of non-abnormal nodes and iterate the model according to the convergence conditions.

[0041] In a specific implementation, the aggregation server selects models uploaded by nodes that have not been identified as abnormal and uses the Federated Averaging Algorithm (FedAvg) for model aggregation. Specifically, aggregation weights are assigned based on factors such as the amount of training data or computing resources of each non-abnormal node. The local model parameters of each node are weighted and summed according to the weights to obtain the global model for the current iteration. The global model is distributed to all user nodes via the Secure File Transfer Protocol (SFTP). After receiving the global model, each node uses transfer learning technology to integrate and update the global model parameters with the local model based on local data and an optimized training strategy. The local model is then fine-tuned using the back propagation algorithm (BP). After completing a model iteration, a check is performed to determine whether the preset convergence conditions have been met. For example, if the accuracy of the global model on the validation set has increased by less than a set threshold for multiple consecutive rounds, or if the loss value remains stable within a preset range, if the convergence conditions have not been met, the process returns to step S3 to continue the next round of training, evaluation, and aggregation until the convergence conditions are met, terminating the federated learning process.

[0042] In this embodiment, by constructing a multi-dimensional fuzzy evaluation model and a dynamic threshold optimization mechanism, accurate anomaly detection and low-error control of federated learning nodes are achieved, significantly improving the security and reliability of the system. By combining the full-link encrypted transmission protocol and Paillier homomorphic encryption technology, a complete privacy protection system from node authentication to model aggregation is constructed, effectively preventing data leakage and malicious attacks. By introducing a stochastic gradient descent variant, early stopping method, and multi-threaded DHT transmission mechanism, local training efficiency and model aggregation speed are greatly optimized, shortening the federated learning iteration cycle. Finally, with the help of a dynamic programming algorithm, the detection threshold is adjusted in real time, and a weight decay strategy is adopted instead of directly eliminating abnormal nodes, maintaining the healthy operation of the federated learning ecosystem while ensuring system stability. The overall solution comprehensively enhances the robustness, privacy, and training efficiency of federated learning scenarios through the collaborative design of security protection, performance optimization, and adaptive control.

[0043] Furthermore, as a refinement and expansion of the specific implementation of the above embodiment, in order to fully illustrate the specific implementation process of this embodiment, as shown below: Figure 2 As shown in Figure 2, another method for detecting abnormal nodes in federated learning is provided, which specifically includes the following steps: Step 101: Construct a fuzzy evaluation model and define several fuzzy sets and membership formulas.

[0044] Step 102: Initialize the abnormal node detection threshold.

[0045] Step 103: Each node registers the federated learning task with the aggregation server.

[0046] Step 104: The aggregation server sends the public key to each participating node.

[0047] Step 105: The participating nodes use their own local data to perform model training to obtain a local model.

[0048] Step 106: The participating nodes use the public key to encrypt the local model to form a local encrypted model.

[0049] Step 107: The participating nodes upload the local encrypted model to the aggregation server.

[0050] Step 108: The aggregation server collects the local encrypted models uploaded by all nodes and decrypts them.

[0051] Step 109: The aggregation server uses fuzzy sets to perform single-factor fuzzy evaluation on the nodes.

[0052] Step 110: The aggregation server performs overall fuzzy evaluation using the membership degree of the fuzzy set obtained by single-factor fuzzy evaluation.

[0053] Step 111: Based on the comprehensive membership degree, determine the possibility of the node being a trusted node or an abnormal node.

[0054] Step 112: When the credibility of the node is lower than the threshold, execute step 113; otherwise, execute step 115.

[0055] Step 113: The node is identified as an abnormal node; Step 114: If the difference is too large, remove the node; if the difference is not large, reduce the weight of the node in the model aggregation, and then execute step 116.

[0056] Step 115: The node is identified as a normal node.

[0057] Step 116: The aggregation server performs model aggregation using the models uploaded by the non-abnormal nodes to obtain the global model of the current iteration round.

[0058] Step 117: Distribute the global model to all users, and each node updates its local model based on the received global model.

[0059] Step 118: Go to step 105 until the convergence condition is reached.

[0060] As can be seen from the above process, in this method, several fuzzy sets and membership formulas are first defined, and the abnormal node detection threshold is initialized. Then, each node registers the federated learning task with the aggregation server, which sends the public key to each participating node. Each participating node uses its own local data to train the model, obtains a local model, and encrypts the local model with the public key to form a local encrypted model.

[0061] At this point, participating nodes upload their local encrypted models to the aggregation server. The aggregation server collects and decrypts the locally encrypted models uploaded by all nodes. The aggregation server then uses fuzzy sets to perform single-factor fuzzy evaluations on the nodes. It then uses the membership of the fuzzy sets obtained from the single-factor fuzzy evaluations to perform an overall fuzzy evaluation. The evaluation process first combines the results of all single-factor fuzzy evaluations to form a fuzzy evaluation matrix.

[0062] Then, the fuzzy evaluation matrix and the evaluation factor weight vector are used to obtain the comprehensive membership of the node to each level in the node evaluation set through fuzzy synthesis operation.

[0063] Next, based on the size of the comprehensive membership, the likelihood of the node being a trusted node or an anomaly is determined. The evaluation result is compared with the anomaly detection threshold. If the node's trustworthiness falls below the threshold, the node is considered an anomaly. If a node is identified as an anomaly, appropriate measures are taken based on the difference between the node's trustworthiness and the threshold. If the difference is too large, the node is removed; if the difference is small, the node's weight in model aggregation is reduced. The aggregation server then aggregates the models uploaded by non-anomaly nodes to obtain the global model for the current iteration.

[0064] Finally, the global model is distributed to all users, and each node updates its local model based on the received global model. The above steps are repeated until convergence conditions are reached.

[0065] It should be noted that in the above method, the fuzzy evaluation model uses the membership of the fuzzy set obtained by single-factor fuzzy judgment to perform an overall fuzzy evaluation; the fuzzy set is the historical participation dimension: {"frequent historical participation", "general historical participation", "rare historical participation"}, the model quality dimension: {"high model quality", "general model quality", "low model quality"}, and the data contribution dimension: {"large data contribution", "general data contribution", "small data contribution"}.

[0066] The membership formula for the historical participation dimension determines a node's membership based on its historical participation count and frequency. For example, a node with more historical participation counts and a higher frequency has a higher membership in the "historically frequent participation" fuzzy set.

[0067] For the model quality dimension, the node's membership function for this dimension is determined based on indicators such as the accuracy and loss value of the node's local model during training. For example, nodes with higher accuracy and lower loss values ​​have a higher membership in the "high model quality" fuzzy set.

[0068] For the data contribution dimension, the node's membership function for this dimension is determined based on metrics such as the amount of local data provided by the node and its data diversity. For example, nodes with greater data volume and data diversity have a higher degree of membership in the "high data contribution" fuzzy set. The fuzzy evaluation matrix is ​​structured such that each row represents a factor, and each column represents a level within the evaluation set. Each element in the matrix represents the degree of membership of that factor within that level.

[0069] The weight vector of the evaluation factors is determined by expert scoring, hierarchical analysis method and other methods to determine the weight of each evaluation factor; the fuzzy synthesis operation is such as weighted average method, maximum membership method and the like.

[0070] The node evaluation set is {"Trustworthy," "Relatively Trustworthy," "Basically Trustworthy," "Questionable," "Low Trustworthy," and "Untrustworthy." The threshold for detecting abnormal nodes is initially set based on experience and dynamically modified during execution. For example, as the number of users in the federated learning system increases, the threshold is appropriately lowered to improve detection sensitivity; as the number of users decreases, the threshold is appropriately raised to reduce the false positive rate. When the proportion of detected abnormal nodes in the system is high, the threshold is appropriately lowered to strengthen detection; when the proportion of abnormal nodes is low, the threshold is appropriately raised to balance detection accuracy and system efficiency.

[0071] It can be seen that the federated learning abnormal node detection method disclosed in the present invention achieves accurate anomaly detection by constructing a multi-dimensional fuzzy evaluation model and a dynamic threshold optimization mechanism, combines the full-link encrypted transmission protocol with Paillier homomorphic encryption technology to ensure communication privacy, adopts a random gradient descent variant, early stopping method and multi-threaded DHT transmission to improve training efficiency, and adjusts the detection threshold and weight decay strategy in real time based on the dynamic programming algorithm to maintain system stability, ultimately comprehensively enhancing the security, privacy, training efficiency and ecological robustness of the federated learning scenario.

[0072] like Figure 3As shown, the following is an embodiment of the federated learning abnormal node detection system provided by the embodiment of the present disclosure. The system and the federated learning abnormal node detection method of the above embodiments belong to the same inventive concept. For details not fully described in the embodiment of the federated learning abnormal node detection system, please refer to the embodiment of the above-mentioned federated learning abnormal node detection method.

[0073] A federated learning abnormal node detection system includes: a fuzzy model construction and threshold initialization module, a node security registration and public key distribution module, a local model training and encrypted upload module, an encrypted model decryption and fuzzy evaluation module, an abnormal node determination and hierarchical processing module, and a non-abnormal model aggregation and global update module.

[0074] The fuzzy model construction and threshold initialization module is used to build a fuzzy evaluation model that includes historical participation, model quality, and data contribution. It initializes the model and optimizes the detection threshold in real time through membership function, hierarchical analysis method, and dynamic threshold adjustment algorithm.

[0075] The node security registration and public key distribution module is used to register with the aggregation server through HTTPS on each node. After the identity is verified by digital signature and certificate, the aggregation server generates a public key based on the ECC algorithm and distributes the public key through the SSL protocol.

[0076] The local model training and encrypted upload module is used to train the local model on each node using a machine learning algorithm combined with a variant of stochastic gradient descent and early stopping. After Paillier homomorphic encryption, the encrypted local model is uploaded to the aggregation server via the DHT network, and the aggregation server receives and verifies it through multi-threaded processing.

[0077] The encryption model decryption and fuzzy evaluation module is used to decrypt the encrypted local model on the aggregation server, perform single-factor fuzzy evaluation based on the fuzzy evaluation model, construct the fuzzy evaluation matrix and obtain the node comprehensive membership through weighted average synthesis.

[0078] The abnormal node determination and classification processing module is used to compare the comprehensive membership degree with the detection threshold through the decision tree classification algorithm, and perform the operation of removing or reducing the aggregation weight of abnormal nodes.

[0079] The non-abnormal model aggregation and global update module is used to aggregate the local models of non-abnormal nodes and generate a global model using the federated averaging algorithm. After distribution through SFTP, the nodes use transfer learning and back propagation to update the local models of non-abnormal nodes and iterate the model according to the convergence conditions.

[0080] The federated learning abnormal node detection system provided in this embodiment achieves accurate identification and low misjudgment of abnormal nodes by constructing a multi-dimensional fuzzy evaluation model and dynamically optimizing the detection threshold. It combines full-link encrypted transmission and security authentication mechanisms to ensure communication privacy and data security in the federated learning process. It adopts efficient training algorithms, parallelized reception, and federated average aggregation strategies to significantly improve model iteration efficiency and resource utilization. Finally, through adaptive weight adjustment and abnormal node management, it comprehensively enhances the security, reliability, and training performance of federated learning scenarios while maintaining system stability.

[0081] Figure 4 A schematic diagram of the hardware structure of an electronic device for implementing various embodiments of the present invention.

[0082] The federated learning abnormal node detection method provided in the embodiments of the present application can be applied to electronic devices. Those skilled in the art will understand that the electronic device structure involved in the embodiments of the present invention does not constitute a limitation of the electronic device. The electronic device may include more or fewer components than shown, or combine certain components, or arrange the components differently. In the embodiments of the present invention, the electronic device includes but is not limited to laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the embodiments of the present application described and / or required herein.

[0083] The electronic device may include a processor, an external memory interface, an internal memory, a universal serial bus (USB) interface, a charging management module, a power management module, a battery, a wireless communication module, an audio module, a speaker, a microphone, a sensor module, a button, a camera, a display, and a SIM card interface, etc.

[0084] A processor may include one or more processing units, such as a central processing unit (CPU), an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU). Different processing units may be independent devices or integrated into one or more processors.

[0085] The processor can be the nerve center and command center of the electronic device. The controller can generate operation control signals based on the instruction opcode and timing signal to complete the control of instruction fetching and execution.

[0086] The processor may also include a memory for storing instructions and data. In some embodiments, the memory in the processor is a cache memory. This memory can store instructions or data that the processor has just used or is reusing. If the processor needs to use the instruction or data again, it can directly call it from the memory. This avoids repeated accesses, reduces processor latency, and thus improves system efficiency.

[0087] The external memory interface can be used to connect an external memory card, such as a MicroSD card, to expand the storage capacity of an electronic device. The external memory card communicates with the processor through the external memory interface, enabling data storage. For example, files such as music and videos can be stored on the external memory card.

[0088] Internal memory can be used to store computer-executable program code, which includes instructions. The processor executes the instructions stored in the internal memory to perform various functional applications and data processing of the electronic device. The internal memory can include a program storage area and a data storage area. The internal memory can include high-speed random access memory and non-volatile memory, such as at least one disk storage device, flash memory device, universal flash storage (UFS), etc.

[0089] The wireless communication function of an electronic device can be implemented through an antenna, a wireless communication module, a modem processor, and a baseband processor.

[0090] Wireless communication modules can provide wireless communication solutions for electronic devices, including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared technology (IR), etc.

[0091] Electronic devices can implement audio functions through audio modules, speakers, receivers, microphones, headphone jacks, and application processors.

[0092] Electronic devices can achieve shooting functions through ISP, camera, video codec, GPU, display and application processor.

[0093] Electronic devices can achieve display functions through GPU, display screen and application processor.

[0094] A GPU is a microprocessor for image processing that connects the display screen to the application processor. The GPU performs mathematical and geometric calculations for graphics rendering. A processor may include one or more GPUs, which execute program instructions to generate or modify display information.

[0095] The display screen is used to display images, videos, etc. The display screen includes a display panel.

[0096] The above-mentioned electronic device implements the federated learning abnormal node detection method of the present application by constructing a multi-dimensional fuzzy evaluation model and combining it with a dynamic threshold adjustment algorithm to accurately identify abnormal nodes, adopting a full-link encryption protocol and homomorphic encryption technology to ensure communication privacy, optimizing the random gradient descent variant and multi-threaded transmission mechanism to improve training efficiency, and using a dynamic programming algorithm and a weight decay strategy to balance the system stability, thereby achieving the beneficial effect of comprehensively improving the security, privacy, resource utilization and ecological robustness of the federated learning system.

[0097] The storage medium provided in this application stores a program product that can implement a method for detecting abnormal nodes in federated learning.

[0098] Federated learning abnormal node detection methods include: Construct a fuzzy evaluation model that includes historical participation, model quality, and data contribution. Initialize the model and optimize the detection threshold in real time using membership functions, analytic hierarchy process, and dynamic threshold adjustment algorithms. Each node registers with the aggregation server via HTTPS. After identity verification through digital signature and certificate, the aggregation server generates a public key based on the ECC algorithm and distributes the public key via the SSL protocol. On each node, a local model is trained using a machine learning algorithm combined with a variant of stochastic gradient descent and early stopping. The encrypted local model is then uploaded to the aggregation server via the DHT network after being homomorphically encrypted using Paillier encryption. The aggregation server then receives and verifies the data through multiple threads. The aggregation server decrypts the encrypted local model, performs single-factor fuzzy evaluation based on the fuzzy evaluation model, constructs the fuzzy evaluation matrix, and obtains the node comprehensive membership through weighted average synthesis; By comparing the comprehensive membership degree with the detection threshold through the decision tree classification algorithm, abnormal nodes are removed or their aggregation weight is reduced. The local models of non-abnormal nodes are aggregated and the federated averaging algorithm is used to generate a global model. After the global model is distributed through SFTP, the nodes use transfer learning and back propagation to update the local models of non-abnormal nodes and iterate the model according to the convergence conditions.

[0099] In some possible implementations, the federated learning abnormal node detection method disclosed herein can be implemented in the form of a program product, which includes program code. When the program product is run on a terminal device, the program code is used to enable the terminal device to execute the steps described in the above "Exemplary Method" section of this specification according to various exemplary implementations of the present disclosure.

[0100] The storage medium of the present disclosure can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, a system, device or component of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination thereof. More specific examples (non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.

[0101] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not limited to the embodiments shown herein but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for detecting abnormal nodes in federated learning, characterized in that: include: Construct a fuzzy evaluation model that includes historical participation, model quality, and data contribution. Initialize the model and optimize the detection threshold in real time using membership functions, analytic hierarchy process, and dynamic threshold adjustment algorithms. Each node registers with the aggregation server via HTTPS. After identity verification through digital signature and certificate, the aggregation server generates a public key based on the ECC algorithm and distributes the public key via the SSL protocol. On each node, a local model is trained using a machine learning algorithm combined with a variant of stochastic gradient descent and early stopping. The encrypted local model is then uploaded to the aggregation server via the DHT network after being homomorphically encrypted using Paillier encryption. The aggregation server then receives and verifies the data through multiple threads. The aggregation server decrypts the encrypted local model, performs single-factor fuzzy evaluation based on the fuzzy evaluation model, constructs the fuzzy evaluation matrix, and obtains the node comprehensive membership through weighted average synthesis; By comparing the comprehensive membership degree with the detection threshold through the decision tree classification algorithm, abnormal nodes are removed or their aggregation weight is reduced. The local models of non-abnormal nodes are aggregated and the federated averaging algorithm is used to generate a global model. After the global model is distributed through SFTP, the nodes use transfer learning and back propagation to update the local models of non-abnormal nodes and iterate the model according to the convergence conditions.

2. The method for detecting abnormal nodes in federated learning according to claim 1, characterized in that: The fuzzy evaluation model is constructed, which includes historical participation, model quality, and data contribution. The model is initialized and the detection threshold is optimized in real time through the membership function, the hierarchical analysis method, and the dynamic threshold adjustment algorithm, including: A fuzzy evaluation model is constructed based on fuzzy mathematics theory, and a fuzzy set is defined, including three core dimensions: historical participation, model quality, and data contribution. In the dimension of historical participation, a fuzzy subset of this dimension is set. By establishing a participation frequency statistical model based on a time window and combining it with a sliding average algorithm to calculate the historical participation frequency of the node, the membership formula is determined. In the model quality dimension, a fuzzy subset of this dimension is defined. Cross-validation technology is used to obtain key indicators such as the accuracy and loss value of the local model during training. The mapping relationship between model quality and membership is established through the trapezoidal membership function. In the dimension of data contribution, a fuzzy subset of this dimension is constructed, and the data diversity is calculated using information entropy. The data volume is taken as the input variable, and the membership of the data contribution is determined by the Sigmoid membership function. The judgment matrix is ​​constructed using the hierarchical analysis method, and the weight vector of each evaluation factor is set. According to historical data and the expected false positive rate of the system, the adaptive threshold adjustment algorithm is used to set the initial value of the abnormal node detection threshold. During the system operation, the threshold is adjusted in real time through the dynamic programming algorithm.

3. The method for detecting abnormal nodes in federated learning according to claim 2, characterized in that: Registering with the aggregation server via HTTPS, verifying identity through digital signature and certificate, and then generating a public key based on the ECC algorithm by the aggregation server and distributing the public key via the SSL protocol include: Each node initiates a federated learning task registration request to the aggregation server based on the Hypertext Transfer Protocol Security. The task registration request includes the node's identity and hardware resource information. When the aggregation server receives the registration information, it verifies the node identity through the built-in identity authentication module and uses digital signature and certificate verification mechanisms to ensure the authenticity and legitimacy of the node identity; After verification, the elliptic curve cryptography algorithm is used to generate a pair of public and private keys for each participating node, and the public key is sent to the corresponding node through the secure socket layer protocol.

4. The method for detecting abnormal nodes in federated learning according to claim 3, characterized in that: On each node, a machine learning algorithm combined with a stochastic gradient descent variant and early stopping method is used to train a local model. After Paillier homomorphic encryption, the encrypted local model is uploaded to the aggregation server via the DHT network. The aggregation server receives and verifies the model through multiple threads, including: On each participating node, based on the objectives of the federated learning task, an adapted machine learning algorithm is selected and model training is performed using the locally stored dataset. During the training process, stochastic gradient descent and its variants are used for parameter optimization; After training is completed, the public key distributed by the aggregation server is used to encrypt the parameters of the local model based on the Paillier homomorphic encryption algorithm; After encryption is completed, the local node uploads the encrypted local model to the aggregation server through the distributed hash table network; The aggregation server adopts a multi-threaded concurrent receiving mechanism, combined with data verification and technology to ensure the collection of encrypted local models uploaded by all nodes and record the upload time.

5. The method for detecting abnormal nodes in federated learning according to claim 4, characterized in that: The aggregation server decrypts the encrypted local model, performs single-factor fuzzy evaluation based on the fuzzy evaluation model, constructs a fuzzy evaluation matrix, and obtains the node comprehensive membership through weighted average synthesis, including: After the aggregation server receives the encrypted local models uploaded by all nodes, it uses the corresponding private key to decrypt them and obtain the original local model information; Based on the fuzzy evaluation model, single-factor fuzzy evaluation is performed on the three dimensions of historical participation, model quality, and data contribution; For the fuzzy evaluation of the historical participation dimension, the actual participation frequency of the node is calculated by combining the registration information and upload time, and the membership degree of the node in each fuzzy subset of the historical participation dimension is determined by the membership formula; For the fuzzy evaluation of the model quality dimension, the accuracy and loss values ​​recorded during the training process are used to calculate the membership of the node in the fuzzy subset of the dimension through the membership function; For the fuzzy evaluation of the data contribution dimension, the corresponding membership is obtained through the membership function based on the calculation results of the data volume and data diversity provided by the node; The single-factor fuzzy evaluation results of the three dimensions of historical participation, model quality, and data contribution are combined to form a 3×6 fuzzy evaluation matrix, where the matrix elements are the membership degrees of the corresponding evaluation factors to that level; The comprehensive node membership is calculated by using the weight vector of the evaluation factors through weighted average fuzzy synthesis operation.

6. The method for detecting abnormal nodes in federated learning according to claim 5, characterized in that: The decision tree classification algorithm is used to compare the comprehensive membership degree with the detection threshold, and remove or reduce the aggregation weight of abnormal nodes, including: According to the comprehensive membership of the step node, it is compared with the detection threshold; The decision tree classification algorithm is used to classify and judge the nodes. When the sum of the comprehensive membership of the node to the preset level is greater than the detection threshold, the node is identified as an abnormal node. For identified abnormal nodes, the difference between their comprehensive membership and the detection threshold is calculated. If the difference is greater than the preset severity threshold, the node is removed from the federated learning system through the preset node management module; if the difference is less than the preset severity threshold, the weight adjustment algorithm is used to reduce the weight of the node in the model aggregation.

7. The method for detecting abnormal nodes in federated learning according to claim 6, characterized in that: The local models of non-abnormal nodes are aggregated and a federated averaging algorithm is used to generate a global model. After the global model is distributed via SFTP, the nodes use transfer learning and back propagation to update the local models of the non-abnormal nodes, and iterate the model according to the convergence conditions, including: The aggregation server filters out local models uploaded by nodes that are not identified as abnormal, and uses the federated averaging algorithm to aggregate the models; According to the amount of training data or computing resources of each non-abnormal node, the aggregation weight is allocated, and the local model parameters of each non-abnormal node are weighted and summed according to the weight to obtain the global model of the current iteration round; The global model is distributed to all user nodes via a secure file transfer protocol. After receiving the global model, each node uses transfer learning technology to integrate and update the global model parameters with the local model based on local data and the optimized training strategy, and iterates the local model through the back-propagation algorithm. After completing a model iteration, check whether the preset convergence conditions are met. If the convergence conditions are not met, use a machine learning algorithm combined with a stochastic gradient descent variant and early stopping method to train the local model until the preset convergence conditions are met.

8. A federated learning abnormal node detection system, characterized in that: The system adopts the federated learning abnormal node detection method according to any one of claims 1 to 7; The system comprises: The fuzzy model construction and threshold initialization module is used to build a fuzzy evaluation model that includes historical participation, model quality, and data contribution. It initializes the model and optimizes the detection threshold in real time through membership function, hierarchical analysis method, and dynamic threshold adjustment algorithm. The node security registration and public key distribution module is used to register with the aggregation server via HTTPS on each node. After the identity is verified by digital signature and certificate, the aggregation server generates a public key based on the ECC algorithm and distributes the public key via the SSL protocol. The local model training and encrypted upload module is used to train the local model on each node using a machine learning algorithm combined with a variant of stochastic gradient descent and early stopping. The encrypted local model is then uploaded to the aggregation server via the DHT network after Paillier homomorphic encryption. The aggregation server then receives and verifies the model through multiple threads. The encryption model decryption and fuzzy evaluation module is used by the aggregation server to decrypt the encrypted local model, perform single-factor fuzzy evaluation based on the fuzzy evaluation model, construct the fuzzy evaluation matrix, and obtain the node comprehensive membership through weighted average synthesis; The abnormal node determination and classification processing module is used to compare the comprehensive membership degree with the detection threshold through the decision tree classification algorithm, and remove or reduce the aggregation weight of abnormal nodes; The non-abnormal model aggregation and global update module is used to aggregate the local models of non-abnormal nodes and generate a global model using the federated averaging algorithm. After distribution through SFTP, the nodes use transfer learning and back propagation to update the local models of non-abnormal nodes and iterate the model according to the convergence conditions.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the steps of the federated learning abnormal node detection method according to any one of claims 1 to 7 are implemented.

10. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the federated learning abnormal node detection method according to any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Simulation method and system for visual conduction path damage

    CN121565040A