Federal learning model property right protection method based on quantum coding and lattice password

Through the federated learning model intellectual property protection method of quantum coding and lattice cryptography, the vulnerability and traceability problems in the intellectual property protection of the federated learning model are solved, the ability to resist classical and quantum computing attacks is achieved, and the integrity and traceability of the model watermark are ensured.

CN120658394AActive Publication Date: 2025-09-16SOUTHWEST JIAOTONG UNIV

Patent Information

Application Number
CN202511154087.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-18
Publication Date
2025-09-16
Estimated Expiration
2045-08-18

AI Technical Summary

Technical Problem

Existing intellectual property protection schemes for federated learning models are vulnerable and difficult to trace when facing classical attack methods and future quantum computing threats, and cannot effectively resist the cracking of model watermarks and infringement tracing.

Method used

A method based on quantum coding and lattice cryptography is adopted, through quantum watermark generation and embedding, multi-key homomorphic encryption and zero-knowledge proof protocol, combined with DAG ledger to record model ownership information, to achieve the protection of model intellectual property rights.

Benefits of technology

It provides dual defense capabilities against attacks from classical and quantum computers, ensures the integrity and traceability of model watermarks, and meets the security requirements in future quantum computing environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658394A_ABST
    Figure CN120658394A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of artificial intelligence, in particular to a federated learning model property protection method based on quantum coding and lattice passwords. The method comprises the steps that firstly, an initial global model is distributed, and quantum watermark generation and embedding are carried out on the basis of the initial global model in combination with lattice password quantum state coding and an information theory; then, generating corresponding quantum fingerprints based on the initial global model embedded with the watermark, aggregating the quantum fingerprints by adopting a multi-key homomorphic encryption method to obtain global aggregated fingerprints, and recording corresponding identity information in a DAG account book; and finally, receiving verification information, and performing model ownership affiliation verification based on the verification information and the identity information in combination with a zero-knowledge proof protocol based on a lattice difficulty problem. The watermark is encrypted by an LWE instance, and any calculation behavior trying to remove the watermark is equivalent to solving a difficult LWE problem, which is not feasible in calculation. Excellent performance is achieved by adopting an advanced lattice cryptographic algorithm.
Need to check novelty before this filing date? Find Prior Art

Claims

1. A method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography, characterized in that: The method comprises: Distributing an initial global model, generating and embedding a quantum watermark based on the initial global model in combination with lattice cryptographic quantum state coding and information theory, and obtaining an initial global model embedded with a watermark; Generate the corresponding quantum fingerprint based on the initial global model embedded with the watermark, aggregate the quantum fingerprint using a multi-key homomorphic encryption method to obtain a global aggregate fingerprint, and record the corresponding identity information in the DAG ledger; Verification information is received, and model ownership verification is performed based on the verification information and identity information in combination with a zero-knowledge proof protocol based on a lattice-hard problem.

2. The method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography according to claim 1 is characterized in that: The generation and embedding of quantum watermark based on the initial global model in combination with lattice cryptographic quantum state coding and information theory includes: Preprocess the owner's identity information; generating a fault-tolerant learning ciphertext vector based on the preprocessed owner identity information; A quantum state watermark is constructed based on the fault-tolerant learning ciphertext vector combined with a distributed entanglement watermark mechanism.

3. The method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography according to claim 2 is characterized in that: The generating and embedding of quantum watermark based on the initial global model in combination with lattice cryptographic quantum state coding and information theory further includes: An adaptive selection strategy based on information theory is used to determine the optimal parameter subset of the watermark embedding model; Converting the parameters in the optimal parameter subset of the watermark embedding model into quantum states; Quantum state watermarks are embedded using quantum superposition or lattice cryptographic perturbation theory.

4. The method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography according to claim 1 is characterized in that: The generating of the corresponding quantum fingerprint based on the initial global model embedded with the watermark includes: Input the trigger data set into the initial global model embedded with the watermark, encode the output data, and obtain high-dimensional quantum state data; Extracting quantum state salient features based on the high-dimensional quantum state data using dimensionality reduction technology; A quantum fingerprint is generated using a quantum hash function based on the significant characteristics of the quantum state.

5. The method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography according to claim 4 is characterized in that: The generating of the quantum fingerprint by using a quantum hash function based on the quantum state salient features further comprises: Classicize the quantum fingerprint to obtain the classical bit string; A lattice cryptographic hash value is calculated based on the classical bit string.

6. The method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography according to claim 1 is characterized in that: The adopting of a multi-key homomorphic encryption method to aggregate the quantum fingerprint to obtain a global aggregated fingerprint includes: generating an encrypted fingerprint and a mask based on the quantum fingerprint; Performing central homomorphic aggregation based on the encryption fingerprint and mask to obtain aggregated ciphertext; Distributed decryption is performed based on the aggregated ciphertext and the private keys of the participants to obtain a global aggregated fingerprint.

7. The method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography according to claim 1 is characterized in that: Recording the corresponding identity information in the DAG ledger includes: Generate ML-DSA signature based on model hash, watermark hash and owner private key; Based on the ML-DSA signature and watermark record, smart contract deployment and registration are performed to generate signed ownership data, which is then stored in a node of the DAG ledger.

8. The method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography according to claim 7 is characterized in that: Storing the signed ownership data in the node of the DAG ledger includes: Build a new node based on the parent node and broadcast it; Verify the parent node validity and content validity of the new node, and sign and vote on valid nodes; The ownership data of the signature is stored in the new node based on the signature voting results.

9. The method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography according to claim 1 is characterized in that: The receiving verification information and performing model ownership verification based on the verification information and identity information in combination with a zero-knowledge proof protocol based on a lattice-hard problem includes: Generate cryptographic commitment based on fault-tolerant learning private key and send it to the verifier; Receive a random challenge from the verifier, generate a response based on the random challenge and the fault-tolerant learning private key, and send it to the verifier.

10. The method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography according to claim 1, characterized in that: The receiving verification information and performing model ownership verification based on the verification information and identity information in combination with a zero-knowledge proof protocol based on a lattice-hard problem further includes: Obtaining a model watermark feature, and calculating fidelity based on the model watermark feature; The fidelity threshold is determined by using a dynamic threshold decision mechanism based on statistical hypothesis testing theory; An ownership verification result is determined based on the fidelity and the fidelity threshold.

Citation Information

Patent Citations

  • Federal learning property label calibration method based on model fingerprints

    CN115759247A

  • Federal learning method and device, medium and product

    CN119204254A

  • Trusted sharing method and system for data resources

    CN120257241A

  • Watermarking quantum models by leveraging metadata

    US20230376577A1

  • Digital Watermarking-Based Digital Asset Ownership Verification

    US20240119128A1

Cited By

  • Deep forgery detection method based on quantum control robust feature watermark

    CN120931466A

  • Classic encryption and quantum walking combined mixed state data storage and retrieval method

    CN121261907A

  • Hybrid state data storage and retrieval method combining classical encryption and quantum walk

    CN121261907B