A federated learning model property right protection method based on quantum encoding and lattice cryptography

By using a quantum coding and lattice cryptography approach to protect the intellectual property rights of federated learning models, a quantum watermark is generated and recorded in a DAG ledger. This solves the problem of intellectual property protection for federated learning models in both classical and quantum computing environments, and enables highly secure verification and traceability of model ownership.

CN120658394BActive Publication Date: 2025-10-21SOUTHWEST JIAOTONG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511154087.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-18
Publication Date
2025-10-21
Estimated Expiration
2045-08-18

AI Technical Summary

Technical Problem

Existing intellectual property protection schemes for federated learning models are vulnerable to classical attack methods and future quantum computing threats, and are difficult to trace, making them unable to effectively defend against the cracking of model watermarks and the protection of intellectual property rights.

Method used

By employing a quantum coding and lattice cryptography approach, quantum watermark generation and embedding are combined with multi-key homomorphic encryption and zero-knowledge proof protocols to generate quantum fingerprints and record them in a DAG ledger, thereby enabling the verification and protection of model ownership.

Benefits of technology

It provides resistance to attacks from both classical and quantum computers, ensuring the integrity of the model watermark and the traceability of ownership, meeting the security requirements of future quantum computing environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658394B_ABST
    Figure CN120658394B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of artificial intelligence, and relates to a federated learning model property protection method based on quantum coding and lattice cryptography. The method comprises the following steps: firstly, distributing an initial global model, generating and embedding a quantum watermark based on the initial global model, lattice cryptography quantum state coding and information theory; then, generating corresponding quantum fingerprints based on the initial global model embedded with the watermark, aggregating the quantum fingerprints by using a multi-key homomorphic encryption method to obtain a global aggregated fingerprint, and recording corresponding identity information in a DAG account book; finally, receiving verification information, and verifying the ownership of the model based on the verification information and the identity information in combination with a zero-knowledge proof protocol based on a lattice difficulty problem. The watermark itself is encrypted by an LWE instance, and any computing behavior attempting to remove the watermark is equivalent to solving a difficult LWE problem, which is not feasible in calculation. By using an advanced lattice cryptography algorithm, excellent performance is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of artificial intelligence technology, and in particular to a method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography. Background Art

[0002] Federated learning, a key distributed machine learning paradigm, enables collaborative model training without directly sharing raw data. This feature has led to its widespread application in highly data-sensitive fields such as healthcare and financial services. However, within a federated learning framework, participants must share model updates, such as gradients or weight parameters. This makes trained models, considered crucial intellectual property, highly vulnerable to theft, unauthorized distribution, and plagiarism, significantly hindering organizations with valuable data and models from participating in collaborative ecosystems.

[0003] To address intellectual property protection issues related to machine learning models, deep neural network watermarking technology based on backdoors or trigger sets has become a mainstream approach. This technology embeds a unique "signature" into the model through training. When the model receives a specific input pattern (i.e., a trigger set), it produces a pre-defined non-standard output. Ownership verification is then performed by inputting the trigger set and checking whether the output matches the pre-defined label.

[0004] However, classic watermarking technology has many key flaws when applied to federated learning scenarios. On the one hand, it is significantly fragile. Common operations such as model fine-tuning, pruning, and parameter perturbations may destroy or remove the watermark. In federated learning, each round of model aggregation is a weighted average of the local models of multiple participants. This operation will have the effect of diluting or even completely erasing the watermark. On the other hand, it is powerless to cope with adaptive attacks. Even if the attacker does not know the specific key of the watermark, as long as he knows its embedding methodology, he can design a targeted strategy to remove the watermark. He can even efficiently crack the watermark by creating a differentiable "proxy key", which exposes its fundamental design flaws. In addition, there is a lack of effective traceability and proof of ownership. When the model is infringed, it is difficult to clearly trace the source, training contribution, and prove ownership.

[0005] Currently, security systems used to protect watermark keys or ownership records are mostly based on classical public-key cryptography, such as RSA and ECC. However, with the development of large-scale quantum computers, these cryptographic systems face the critical threat of being cracked by Shor's algorithm in polynomial time. This threat is made even more imminent by the "collect first, crack later" attack model, where attackers intercept and store data encrypted with classical cryptography now, waiting for the advent of quantum computers to crack it. Therefore, it is necessary to develop protection schemes based on post-quantum cryptography to defend against attacks from both classical and quantum computers.

[0006] In summary, the current technology field urgently needs a federated learning model intellectual property protection solution that can simultaneously deal with increasingly complex classical attack methods and future quantum computing threats. A solution that only solves one of the problems is incomplete. Summary of the Invention

[0007] Based on this, it is necessary to address the above technical issues and provide a federated learning model intellectual property protection solution that can simultaneously deal with increasingly complex classical attack methods and future quantum computing threats. It is a federated learning model intellectual property protection method based on quantum coding and lattice cryptography.

[0008] In a first aspect, this application provides a method for protecting intellectual property rights in a federated learning model based on quantum coding and lattice cryptography. The method comprises:

[0009] Distributing an initial global model, generating and embedding a quantum watermark based on the initial global model in combination with lattice cryptographic quantum state coding and information theory, and obtaining an initial global model embedded with a watermark;

[0010] Generate the corresponding quantum fingerprint based on the initial global model embedded with the watermark, aggregate the quantum fingerprint using a multi-key homomorphic encryption method to obtain a global aggregate fingerprint, and record the corresponding identity information in the DAG ledger;

[0011] Verification information is received, and model ownership verification is performed based on the verification information and identity information in combination with a zero-knowledge proof protocol based on a lattice-hard problem.

[0012] Optionally, in one embodiment of the present application, the generating and embedding of quantum watermarks based on the initial global model in combination with lattice cryptographic quantum state coding and information theory includes:

[0013] Preprocess the owner's identity information;

[0014] generating a fault-tolerant learning ciphertext vector based on the preprocessed owner identity information;

[0015] A quantum state watermark is constructed based on the fault-tolerant learning ciphertext vector combined with a distributed entanglement watermark mechanism.

[0016] Optionally, in one embodiment of the present application, the generating and embedding of quantum watermarks based on the initial global model in combination with lattice cryptographic quantum state coding and information theory further includes:

[0017] An adaptive selection strategy based on information theory is used to determine the optimal parameter subset of the watermark embedding model;

[0018] Converting the parameters in the optimal parameter subset of the watermark embedding model into quantum states;

[0019] Quantum state watermarks are embedded using quantum superposition or lattice cryptographic perturbation theory.

[0020] Optionally, in one embodiment of the present application, generating a corresponding quantum fingerprint based on the initial global model embedded with the watermark includes:

[0021] Input the trigger data set into the initial global model embedded with the watermark, encode the output data, and obtain high-dimensional quantum state data;

[0022] Extracting quantum state salient features based on the high-dimensional quantum state data using dimensionality reduction technology;

[0023] A quantum fingerprint is generated using a quantum hash function based on the significant characteristics of the quantum state.

[0024] Optionally, in one embodiment of the present application, generating a quantum fingerprint using a quantum hash function based on the quantum state salient features further comprises:

[0025] Classicize the quantum fingerprint to obtain the classical bit string;

[0026] A lattice cryptographic hash value is calculated based on the classical bit string.

[0027] Optionally, in one embodiment of the present application, aggregating the quantum fingerprints using a multi-key homomorphic encryption method to obtain a global aggregated fingerprint includes:

[0028] generating an encrypted fingerprint and a mask based on the quantum fingerprint;

[0029] Performing central homomorphic aggregation based on the encryption fingerprint and mask to obtain aggregated ciphertext;

[0030] Distributed decryption is performed based on the aggregated ciphertext and the private keys of the participants to obtain a global aggregated fingerprint.

[0031] Optionally, in one embodiment of the present application, recording the corresponding identity information in the DAG ledger includes:

[0032] Generate ML-DSA signature based on model hash, watermark hash and owner private key;

[0033] Based on the ML-DSA signature and watermark record, smart contract deployment and registration are performed to generate signed ownership data, which is then stored in a node of the DAG ledger.

[0034] Optionally, in one embodiment of the present application, storing the signed ownership data in a node of the DAG ledger includes:

[0035] Build a new node based on the parent node and broadcast it;

[0036] Verify the parent node validity and content validity of the new node, and sign and vote on valid nodes;

[0037] The ownership data of the signature is stored in the new node based on the signature voting results.

[0038] Optionally, in one embodiment of the present application, receiving verification information, and performing model ownership verification based on the verification information and identity information in combination with a zero-knowledge proof protocol based on a lattice-hard problem includes:

[0039] Generate cryptographic commitment based on fault-tolerant learning private key and send it to the verifier;

[0040] Receive a random challenge from the verifier, generate a response based on the random challenge and the fault-tolerant learning private key, and send it to the verifier.

[0041] Optionally, in one embodiment of the present application, the receiving verification information and performing model ownership verification based on the verification information and identity information in combination with a zero-knowledge proof protocol based on a lattice-hard problem further includes:

[0042] Obtaining a model watermark feature, and calculating fidelity based on the model watermark feature;

[0043] The fidelity threshold is determined by using a dynamic threshold decision mechanism based on statistical hypothesis testing theory;

[0044] An ownership verification result is determined based on the fidelity and the fidelity threshold.

[0045] The aforementioned method for protecting the intellectual property rights of a federated learning model based on quantum coding and lattice cryptography first distributes an initial global model. Based on this initial global model, quantum watermark generation and embedding are performed using lattice cryptographic quantum state encoding and information theory, resulting in a watermarked initial global model. Next, a corresponding quantum fingerprint is generated based on the watermarked initial global model. This quantum fingerprint is aggregated using multi-key homomorphic encryption to obtain a global aggregated fingerprint, and the corresponding identity information is recorded in a distributed aggregation ledger. Finally, verification information is received and model ownership is verified based on this verification information and the identity information using a zero-knowledge proof protocol based on a lattice-hard problem. In other words, the watermark itself is encrypted by a LWE instance. Any computational attempt to remove the watermark is equivalent to solving a difficult LWE problem, which is computationally infeasible. Without knowing the complete watermark information, an attacker cannot perfectly replicate this quantum state for offline analysis. This physically blocks the core path of current mainstream adaptive attacks, which optimize attack parameters by creating differentiable agents. This is a fundamental advantage that classical watermarking technology cannot match. While providing unprecedented security, it achieves superior performance by employing advanced lattice cryptography algorithms. At the same time, it is fully aligned with the international standards for post-quantum cryptography finalized by NIST (FIPS203 (ML-KEM) for key encapsulation (the basis for watermark encoding) and FIPS204 (ML-DSA) for digital signatures (the basis for blockchain evidence storage)), providing the highest level of security assurance reviewed by global cryptographers to resist future quantum computer attacks, ensuring that it can meet future mandatory security requirements of governments and industries and can interoperate with other systems that follow the same standards. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] Figure 1 This is a diagram of an application environment for a method for protecting intellectual property rights in a federated learning model based on quantum coding and lattice cryptography in one embodiment;

[0047] Figure 2 1. A flowchart of a method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography in one embodiment;

[0048] Figure 3 1. A schematic diagram of a process for implementing a grid cryptographic quantum state encoding method according to an embodiment of the present invention;

[0049] Figure 4 A schematic diagram of a quantum circuit for encoding a watermark in a grid cryptographic quantum state according to an embodiment;

[0050] Figure 5 Schematic diagram of a watermark embedding process in one embodiment;

[0051] Figure 6 Schematic diagram of the process of distributed fingerprint generation and aggregation in one embodiment;

[0052] Figure 7 1. A schematic diagram of a process for zero-knowledge ownership verification in one embodiment;

[0053] Figure 8 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0054] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0055] The embodiment of the present application provides a method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography, which can be applied to Figure 1 In the application environment shown, the terminal communicates with the server through the network. The data storage system can store data that the server needs to process. The data storage system can be integrated on the server or placed on the cloud or other network servers. The terminal can be, but is not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can be smart speakers, smart TVs, smart air conditioners, smart car devices, etc. Portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The server can be implemented as a standalone server or a server cluster consisting of multiple servers.

[0056] In one embodiment, Figure 2 As shown in the figure, a method for protecting property rights of a federated learning model based on quantum coding and lattice cryptography is provided. Figure 1 The following steps are used as an example to illustrate the server in the example:

[0057] S201: distributing an initial global model, generating and embedding a quantum watermark based on the initial global model in combination with lattice cryptographic quantum state coding and information theory, and obtaining an initial global model embedded with a watermark.

[0058] In the embodiment of the present application, first, the central server is responsible for distributing the current initial global model to all participating clients. Each client trains the model on local data and calls the central server's homomorphic watermark embedding module. Combining lattice cryptographic quantum state encoding and information theory, it integrates its own encrypted watermark into the encrypted model update and uploads the encrypted, watermarked model update to the central server. Specifically, the encrypted watermark refers to securely encoding the identity information of the client owner into a unique, cryptographically secure quantum state. Combining information theory, quantum computing, and lattice cryptography theory, it is embedded in the target federated learning model in a secure, robust manner with minimal impact on model performance, thereby implementing an adaptive watermark embedding strategy.

[0059] In one embodiment of the present application, the generation and embedding of quantum watermarks based on the initial global model in combination with lattice cryptographic quantum state coding and information theory includes:

[0060] S301: Preprocess the owner identity information.

[0061] S303: Generate a fault-tolerant learning ciphertext vector based on the pre-processed owner identity information.

[0062] S305: Constructing a quantum state watermark based on the fault-tolerant learning ciphertext vector in combination with a distributed entanglement watermark mechanism.

[0063] In one embodiment of the present application, the owner's identity information (ID) is directly associated with a mathematically recognized difficult problem - Learning With Errors (LWE) problem - and is encoded into the physical properties of the quantum state. Specifically, Figure 3 As shown, first, the owner ID (a bit string of length L_ID bits, such as the public key or unique identifier of an organization) is processed through the national secret SM3 cryptographic hash algorithm to obtain a fixed-length bit string, which will be used as the secret vector s in the LWE problem instance. The national secret SM3 cryptographic hash algorithm is H=SM3(ID), and the hash output H is truncated or expanded to a length of Convert the bit string into an n-dimensional vector as the LWE secret vector.

[0064] Then, a public random matrix is ​​randomly generated and a discrete Gaussian distribution D σ The noise vector sampled in ,in, , σ = α_rate · q, α_rate is the noise rate parameter. And calculate the LWE ciphertext , The modulus is usually a prime number or a power of 2, which is used to control the computational complexity and balance security and efficiency. The key to this LWE example is that it is extremely difficult to calculate the secret s from the public (A, b), even for a quantum computer. This LWE ciphertext b is used to construct a quantum watermark. An N-dimensional quantum state Built as , where N=2 k , k is the number of quantum bits, each calculation basis vector The complex amplitude of A component of the LWE ciphertext The only certainty:

[0065]

[0066] It should be noted that this application explicitly adopts parameters that match the security levels defined in the ML-KEM official standards (such as ML-KEM-512, ML-KEM-768, and ML-KEM-1024), including the lattice dimension n, the modulus , noise distribution, etc. In addition, to improve efficiency, key optimization techniques in ML-KEM will be adopted, such as variants based on ring LWE (Ring-LWE) and module LWE (Module-LWE). These techniques use algebraic structures to reduce the complexity of data such as public keys from O(n 2 ) is reduced to Even O(n), while ensuring security, it greatly reduces storage and computing overhead.

[0067] In federated learning, a distributed machine learning paradigm involving multi-party collaboration, the intellectual property rights of a model often involve the joint contributions of multiple participants. Traditional single-owner watermarking schemes are no longer able to meet the complex needs of multi-party rights protection. To this end, the innovative Distributed Entanglement Watermarking (DEW) mechanism was proposed, specifically for multi-party ownership authentication scenarios in federated learning alliances. The core innovation of this mechanism lies in the fact that when a federated learning system involves multiple participants (such as a learning alliance composed of multiple institutions), the system can dynamically generate distributed entanglement watermarks that match the number and contribution of the participants. For example, a lattice basis GHZ state (Greenberger-Horne-Zeilinger state) can be constructed: , where each and Each of these is an LWE ciphertext encoding associated with a specific participant. According to the theorem (lattice entanglement monotonicity), the entanglement degree of this entangled state constructed using lattice cryptography is monotonically non-increasing under local operations and classical communication among each participant in a federated learning environment. This means that distributed participants cannot increase or forge this global entangled correlation through local operations. This entanglement property provides physical security for the joint authentication of multi-party ownership, ensuring the integrity and anti-collusion forgery of the watermark.

[0068] In specific applications, such as Figure 4 As shown, the circuit diagram describes in detail the generation of lattice cryptographic quantum watermark states The four main steps are: First, the owner's unique ID is converted into the key s of the LWE problem through a cryptographic hash function. Then, the LWE encryption scheme is used, combined with a public random matrix A and a small noise vector e, to calculate the ciphertext vector b = As + e. This classical vector b is the core control parameter of subsequent quantum operations. After that, initialization (Initialization): using two groups of quantum bits: n index quantum bits (|i_{n-1} ) is used to represent 0 to N-1 (N=2 n ) and m auxiliary qubits (|anc_{m-1} ) is used for calculation. Applying Hadamard Gate (H) to all index qubits puts them into a uniform superposition state This allows for parallel processing of all base states. After that, the Arithmetic Oracle (U_b) is a core computing module, which can usually be implemented by a quantum read-only memory (QROM). Its function is to: for each basis state of the indexed quantum bit , it will add the corresponding classical ciphertext value b_i to the auxiliary quantum bit. The whole operation can be expressed as The figure shows a schematic diagram of a multi-bit controlled operation to represent this complex logic. Afterwards, Phase Kickback: a series of phase gates P are applied to the auxiliary qubits. k Each gate P k Acting on the kth auxiliary quantum bit, applying a Phase, P k = P(2π·2 k / q). Due to quantum entanglement, these phases imposed on the auxiliary quantum bits will change according to their states. , "kicks back" to the entangled index qubit. Ultimately, each ground state You will get one The phase of , which is exactly the information we want to encode. Finally, the uncomputation (U_b†): run the inverse operation of the arithmetic oracle again, and move the auxiliary qubit from Restore to the original This step is crucial because it removes the entanglement between the index qubit and the auxiliary qubit, ensuring that the final index qubit is in the pure watermark state we expect. , and the auxiliary qubits can be reused for subsequent calculations. Ultimately, the state in the index qubit register is the cryptographically secure quantum watermark we constructed based on lattice cryptography. .

[0069] In this embodiment, different owner IDs will generate different secret vectors s, and thus different LWE ciphertexts b, ultimately forming quantum states that are almost mutually orthogonal. This orthogonality enables different watermarks to be clearly distinguished during verification, and their inner product satisfies , δ represents the Kronecker function: if the subscripts are the same, the function value is 1; if the subscripts are different, the function value is 0. Attacks that extract the owner information ID from the LWE ciphertext are equivalent to solving the secret s from the LWE ciphertext b, which directly reduces to the difficulty of the LWE problem.

[0070] In one embodiment of the present application, the generation and embedding of quantum watermarks based on the initial global model in combination with lattice cryptographic quantum state coding and information theory further includes:

[0071] S401: Determine the optimal parameter subset of the watermark embedding model based on an adaptive selection strategy based on information theory.

[0072] S403: Convert the parameters in the optimal parameter subset of the watermark embedding model into quantum states.

[0073] S405: Embed the quantum state watermark using quantum superposition or lattice cryptographic perturbation theory.

[0074] In one embodiment of the present application, Figure 5 As shown in the figure, first, in order to maximize the robustness and concealment of the watermark, the watermark is not randomly embedded into the model parameters. Instead, an adaptive selection strategy based on information theory is adopted. The goal of this strategy is to find a subset of model weights S that maximizes the mutual information I(S;Y) between this subset and the final output Y of the model, while also maximizing the mutual information I(S;Y) with the unselected parameter set. Mutual information minimize.

[0075]

[0076] Here, γ is a balancing factor. This principle ensures that the watermark is embedded in the "key neurons" that have the greatest influence on model decisions and have the lowest correlation with other parameters. As a result, any attempt to remove the watermark by modifying parameters will greatly damage the normal function of the model and increase the cost of the attack.

[0077] Specifically, input model parameters , training data set D, balance factor γ, calculate the sensitivity of each parameter: , calculate the information contribution: , calculate the comprehensive score: , greedily select the optimal parameter subset: Initialization , repeatedly select the highest scoring parameter to join , until |S| = k max Or information gain <τ, output the optimal parameter subset S*.

[0078] Afterwards, the selected classical model parameter W is converted into a quantum state via a quantum-classical interface This process usually involves normalization and amplitude encoding. Specifically, the input selection parameter W S , perform parameter normalization , amplitude coding , verify the validity of the quantum state, check the normalization conditions, and output the parameter quantum state | .

[0079] After that, quantum superposition or lattice cryptographic perturbation theory is used to embed the quantum state watermark. Specifically, the process of quantum superposition embedding is: input parameter quantum state , watermark quantum state , embedding strength, calculate the embedding angle: , generate random phases: , perform quantum superposition: , verify fidelity: , parameter reconstruction: ,in, It is the inverse process of "amplitude coding", which recovers the classical numerical array by measuring the quantum state. Finally, the watermark parameters are output. . Superposition coefficient is a key adjustable parameter that precisely controls the embedding strength of the watermark. According to the theorem (lattice quantum superposition fidelity), the fidelity (similarity) between the original model and the watermarked model is approximately This provides users with a quantitative means to balance the robustness of the watermark (requiring a relatively large and the performance fidelity of the model (requiring a relatively large ). In addition, according to the theorem (Holevo bound, a qubit can carry at most one classical bit of information reliably), the maximum amount of information that can be embedded can be determined under a given quantum channel capacity, thus optimizing the watermark design.

[0080] In a more advanced implementation, the embedding process itself also utilizes the homomorphic property of lattice cryptography. Instead of directly superimposing the watermark, it is perturbed in its LWE-encrypted form. The theorem (lattice basis perturbation theory) provides a theoretical basis for this process, which quantifies the impact of a small, lattice-cryptography-encrypted perturbation on the final output of the model . This enables the system to adaptively calculate the optimal embedding strength based on the sensitivity of the model to the perturbation (measured by the condition number and the maximum allowable performance loss, ensuring the best balance between the effectiveness of the watermark and the usability of the model. The specific process is as follows: Input: parameters W S , watermark m, LWE parameters, perturbation coefficient ε, perform parameter encryption: , watermark encryption: , homomorphic perturbation: , where the ⊙ operation represents multiplying each component of the ciphertext by the plaintext scalar ϵ, homomorphic addition: , where the ⊕ operation represents adding the corresponding components of two ciphertexts. Condition number check: , adjust , decrypt and reconstruct: , performance verification: ensure that the accuracy loss < threshold, and finally output the homomorphic embedding parameters .

[0081] S20३: Generate corresponding quantum fingerprints based on the initial global model embedded with watermarks, aggregate the quantum fingerprints using the multi-key homomorphic encryption method to obtain the global aggregated fingerprint, and record the corresponding identity information in the DAG ledger.

[0082] In the embodiments of this application, the central server performs secure aggregation to generate a new version of the global model. This model naturally integrates the contributions and watermark information of all participating clients. After the model training is completed, the central server calls the immutable evidence storage module through the interface to create an immutable and traceable public record for the ownership and fingerprint of the model, and permanently records the "identity information" of the model on the DAG ledger.

[0083] In one embodiment of the present application, generating a corresponding quantum fingerprint based on the initial global model embedded with the watermark includes:

[0084] S501: Input a trigger data set into the initial global model embedded with the watermark, encode the output data, and obtain high-dimensional quantum state data.

[0085] S503: Extracting quantum state salient features based on the high-dimensional quantum state data using dimensionality reduction technology.

[0086] S505: Generate a quantum fingerprint using a quantum hash function based on the significant characteristics of the quantum state.

[0087] In one embodiment of the present application, unlike watermarks that directly embed static information, fingerprints are a reflection of the dynamic behavior of the model. By inputting a specially designed trigger data set into the watermarked model and collecting its outputs, these outputs (for example, the logit vector of the classification task) are encoded into a high-dimensional quantum state. Subsequently, the system uses dimensionality reduction techniques such as quantum principal component analysis (Quantum PCA) to extract the most significant features of the quantum state, and finally generates the final quantum fingerprint through a quantum hash function. According to the theorem (quantum fingerprint collision probability), for an n-qubit quantum fingerprint, the probability that two different models produce the same fingerprint is bounded by , ensuring the uniqueness of the fingerprint. Specifically, first, the model input dimension d, the number of trigger data m = 500, generates mixed trigger data: Gaussian noise data 60% (to stimulate the basic response of the model), uniformly distributed data: 30% (to test boundary behavior), sparse data: 10% (to test special patterns). Data normalization: normalize to the range [-1, 1], and output the trigger data set. After that, extract the model behavior features and input the watermarked model f θ , trigger the dataset T, run the model inference: for each calculate: =f θ ( ), extract the output vector (logits or features); build the behavior vector: , Standardization: B norm = (B - mean) / std, output standardized behavior vector B norm Finally, generate the quantum fingerprint and input the behavior vector B norm , target number of quantum bits n=12, amplitude coding: = B norm [i] / ||B norm ||2. Constructing quantum state: , Dimensionality reduction and compression: Use PCA to reduce the dimension to n-qubit, generate the final fingerprint: get a fixed length fingerprint through quantum hashing, and output the quantum fingerprint .

[0088] In one embodiment of the present application, generating a quantum fingerprint using a quantum hash function based on the quantum state salient features further includes:

[0089] S601: Classicize the quantum fingerprint to obtain a classical bit string.

[0090] S603: Calculate a lattice cryptographic hash value based on the classical bit string.

[0091] In one embodiment of the present application, in order to ensure the cryptographic security of the fingerprint, the hash function used is constructed based on a lattice-hard problem (such as Ring-LWE or SIS problem). For example, a hash function based on Ring-LWE can be expressed as According to the theorem (lattice quantum one-way property), it is computationally infeasible to infer the input from the hash value, even for a quantum computer. This ensures the anti-collision and one-way property of the fingerprint. Specifically, first, input the quantum fingerprint , measure the quantum state in the computational basis and obtain the classical bit string: , perform bit string verification, ensure length and validity, and output classic bit string bit (length is n bits). After that, the lattice cryptographic hash is calculated, and the input bit string bit With a security level of λ = 192 (i.e., NIST level 3), select the hash scheme: Ring-LWE hash for standard scenarios and SIS hash for high-security scenarios; set the parameters: lattice dimension n = 1024, modulus q = 12289; perform the hash calculation: Ring-LWE: ,SIS: ; Output verification, check the randomness and uniqueness of the hash value, and output the password hash value h (384 bits).

[0092] In one embodiment of the present application, aggregating the quantum fingerprints using a multi-key homomorphic encryption method to obtain a global aggregated fingerprint includes:

[0093] S701: Generate an encrypted fingerprint and a mask based on the quantum fingerprint.

[0094] S703: Perform central homomorphic aggregation based on the encryption fingerprint and mask to obtain aggregated ciphertext.

[0095] S705: Perform distributed decryption based on the aggregated ciphertext and the private keys of the participants to obtain a global aggregated fingerprint.

[0096] In one embodiment of the present application, in a federated learning scenario, each participant generates a fingerprint of its local model. In order to obtain a global fingerprint, these local fingerprints need to be aggregated. Uploading plaintext fingerprints directly to the central server will bring serious privacy risks. Therefore, multi-key homomorphic encryption (MKHE) technology is adopted. MKHE allows each participant to encrypt the local fingerprint using its own independent key. After the central server receives these ciphertexts from different keys, it can directly perform homomorphic addition operations on the ciphertext to obtain an encrypted global aggregate fingerprint. The server cannot decrypt any single fingerprint or aggregation result throughout the process.

[0097] Traditional MKHE schemes (such as CDKS) have security vulnerabilities in the distributed decryption process, potentially allowing malicious parties to recover the original data of others through collusion. To address this critical issue, the aggregation protocol (lattice-secure multi-party computation theorem) employed in this paper explicitly integrates a novel masking mechanism, consistent with the design principles of SMHE (Secure Multi-Key Homomorphic Encryption) schemes. This mechanism introduces an additional random mask during the ciphertext expansion and aggregation process, ensuring that the partial decrypted information contributed by any participant does not reveal any content of the original input. This design provides provable anti-collusion security, a key step towards achieving true privacy protection in multi-party environments, and a significant enhancement to the original technical solution.

[0098] Specifically, such as Figure 6 As shown, first, for the fingerprints of t participants , generate random masks for the first t-1 parties: , the last square mask is , verification: Σr i = 0 (to ensure the mask is unbiased); local encryption by each party: generate a key pair (pk i , sk i ), encrypted fingerprint c i = Enc(pk i , f i ), encryption mask c mask_i = Enc(pk i , r i ), output encrypted fingerprint and mask {c i , c mask_i}. Afterwards, the center homomorphically aggregates, for all encrypted fingerprints { } and mask { , ..., c mask_t}, aggregate fingerprint: csum = ⊕ ⊕ ... ⊕ , aggregation mask: c mask_sum = ⊕ ... ⊕ c mask_t ;Remove mask: c final = c sum c mask_sum , due to Σr i = 0, the mask is completely removed and the aggregate ciphertext c is output final Finally, distributed decryption, input aggregate ciphertext c final and each party's private key { , , ..., sk t}, generate decryption share: each party calculates: share i = PartialDec(sk i , c final ), submit the decrypted shares (without revealing the original fingerprint). Final decryption: Combine all shares: F agg = Combine( , , ...,share t ), verify the validity of the aggregation result and output the final aggregation fingerprint F agg .

[0099] In one embodiment of the present application, recording the corresponding identity information in the DAG ledger includes:

[0100] S801: Generate an ML-DSA signature based on the model hash, watermark hash, and owner private key.

[0101] S803: Deploy and register a smart contract based on the ML-DSA signature and watermark record, generate signed ownership data, and store the signed ownership data in a node of the DAG ledger.

[0102] In one embodiment of the present application, the ownership record of a model, including a hash of the model content, the owner's lattice-based quantum watermark (or its hash), and a generation timestamp, is encapsulated in a smart contract and recorded on the blockchain. To ensure the authenticity and non-repudiation of these records, all write operations to the ledger must be digitally signed by the owner using their private key. The post-quantum digital signature standard FIPS204, finalized by NIST, is used: ML-DSA (Module-Lattice-based Digital Signature Algorithm), formerly known as the CRYSTALS-Dilithium algorithm. The security of ML-DSA is based on difficult problems on module lattices (such as Module-SIS), which can effectively resist quantum attacks. Smart contracts are designed to natively verify these ML-DSA signatures, thereby providing post-quantum security for the entire evidence storage system.

[0103] Specifically, first input the model hash modelHash, watermark hash watermarkHash, and owner private key sk. Select the security level: ML-DSA-44 (128-bit security) for standard scenarios, ML-DSA-65 (192-bit security) for high-security scenarios, and ML-DSA-87 (256-bit security) for the highest security scenario. Construct the message to be signed: message = hash(modelHash + watermarkHash + timestamp). Generate the ML-DSA signature: signature = ML-DSA.Sign(sk, message). Verify the validity of the signature: isValid = ML-DSA.Verify(pk, message, signature). Output the ML-DSA signature signature and public key pk. After that, the smart contract is deployed and registered. The watermark record watermarkRecord and ML-DSA signature signature are input, and the evidence storage contract is deployed: the watermark record structure is defined, the ML-DSA signature verification function is implemented, and it is deployed to the blockchain network; the watermark record is registered: the ML-DSA signature is verified: require(verifySignature(record, signature)), duplicate registration is checked: require(!isRegistered(modelHash)), the record is stored: watermarkRecords[modelHash] = record, the event is triggered: emitWatermarkRegistered(modelHash, owner), and the contract address and registration transaction hash are output.

[0104] In one embodiment of the present application, storing the signed ownership data in a node of the DAG ledger includes:

[0105] S901: Build a new node based on the parent node and broadcast it.

[0106] S903: Verify the parent node validity and content validity of the new node, and perform signature voting on the valid nodes.

[0107] S905: Determine the ownership data of the signature based on the signature voting result and store it in the new node.

[0108] In one embodiment of the present application, in order to cope with the high frequency of ownership registration and verification requests that may be generated by a large-scale federated learning system, a ledger structure based on a directed acyclic graph (DAG) is adopted instead of a traditional linear chain structure. The DAG structure allows transactions to be processed in parallel, thereby significantly improving the system's transaction throughput (TPS) and scalability, while ensuring data consistency and finality through a Byzantine fault-tolerant consensus protocol. First, the client requests and selects at least two valid "top" nodes (Tips) from the network as parent nodes, constructs an assembly node object containing signed ownership data WatermarkRecord, parentHashes, and timestamp, and submits the newly constructed node to the distributed network. Afterwards, the verifier verifies the parent node validity and content validity, that is, checks whether the node's parentHashes points to a known, valid node in the ledger, and verifies the ML-DSA digital signature contained in the WatermarkRecord. If the node is valid, the verifier signs the node's hash using its own private key and broadcasts this signature (vote) to other verifiers. Finally, each node continues to collect signature votes from different validators. When the number of valid votes collected by a node reaches the network's preset Byzantine fault tolerance threshold (for example, more than 2 / 3 of the total number of validators), the node achieves finality. The node is marked as "confirmed" by the entire network, and the WatermarkRecord it contains officially becomes an immutable public record. The node can now serve as a valid parent node for new nodes, and its data can be queried externally.

[0109] S205: Receive verification information, and perform model ownership verification based on the verification information and identity information in combination with a zero-knowledge proof protocol based on a lattice-hard problem.

[0110] In the embodiment of the present application, when verification is required, the verifier calls the zero-knowledge ownership verification module through the ownership verification interface provided by the central server, starts the verification process, and finally confirms the ownership of the model. The model owner can prove his ownership to any third party (verifier) ​​without revealing any secret information. Figure 7 As shown, the ownership verification process is an interactive zero-knowledge proof (ZKP) protocol. This protocol is based on the difficulty of lattice cryptography (e.g., a lattice generalization of the Stern protocol). The protocol consists of the following steps: Commitment: The owner (prover) generates a cryptographic commitment to their secret (i.e., the LWE private key) and sends it to the verifier. Challenge: The verifier sends a random challenge to the prover. Response: The prover computes a response based on its secret and the challenge and sends it back to the verifier. The entire protocol is designed to satisfy zero-knowledge, soundness, and completeness. Zero-knowledge means that the verifier learns no information about the secret from the interaction except that the prover possesses it. Soundness ensures that an imposter without the secret cannot pass verification. The security of this protocol is based on lattice-hard problems and is therefore post-quantum secure.

[0111] The core part of verification is that the verifier challenges the prover to prove the claimed watermark quantum state. The verifier extracts the embedded watermark state from the suspected model and interacts with the prover through the ZKP protocol to reconstruct the desired quantum state. Finally, the fidelity between the two quantum states is calculated to determine whether they are consistent. Uhlmann's theorem provides a solid mathematical foundation for calculating the fidelity between these mixed states.

[0112] In one embodiment of the present application, receiving verification information, and performing model ownership verification based on the verification information and identity information in combination with a zero-knowledge proof protocol based on a lattice-hard problem includes:

[0113] S1001: Generate a cryptographic commitment based on the fault-tolerant learning private key and send it to the verifier.

[0114] S1003: Receive a random challenge sent by the verifier, generate a response based on the random challenge and the fault-tolerant learning private key, and send it to the verifier.

[0115] In one embodiment of the present application, first, for the LWE public parameters (A, b) and the private key s provided by the prover, a random mask is generated, and the cryptographic commitment vector u is calculated and sent to the verifier. ,in, is a random mask. Afterwards, a random challenge ch∈Zq is received from the verifier, and the response vector z is calculated based on the private key s, mask r and challenge ch and sent to the verifier. It should be noted that in order to avoid multiple rounds of interaction, the protocol can also be converted to non-interactive and generate commitments: ; Generate challenge: Use a cryptographic hash function H to generate the challenge, ; Generate response: Calculate , will prove Package output.

[0116] In one embodiment of the present application, receiving verification information, and performing model ownership verification based on the verification information and identity information in combination with a zero-knowledge proof protocol based on a lattice-hard problem further includes:

[0117] S1101: Obtain model watermark features, and calculate fidelity based on the model watermark features.

[0118] S1103: Determine the fidelity threshold using a dynamic threshold decision mechanism based on statistical hypothesis testing theory.

[0119] S1105: Determine an ownership verification result based on the fidelity and the fidelity threshold.

[0120] In one embodiment of the present application, first, input the certificate and public parameters , recalculate the challenge using the same hash function , check whether the response provided by the prover satisfies the LWE relation. Verification passed. If verification fails, it will be rejected directly. If successful, proceed to the next step.

[0121] For the ownership information of the suspicious model M, the watermark trace is extracted from the parameters of the model M and reconstructed into a quantum state. . , where β i Extracted from the model parameters and normalized. Calculate the similarity between the extracted state and the expected state.

[0122]

[0123] Since the LWE problem itself contains noise and the federated learning process may also introduce noise, using a fixed fidelity threshold (such as 99%) is not robust. A dynamic threshold decision mechanism based on statistical hypothesis testing theory is adopted. This mechanism will be based on the system's security parameters, estimated channel noise and LWE noise boundary. , dynamically calculates an optimal acceptance / rejection threshold. This allows verification decisions to maintain high statistical confidence in the face of various uncertainties in the real world. Specifically, the total system noise σ is estimated total Impact on fidelity F. The total noise is LWE, quantum ,train A combination of various noises.

[0124]

[0125] Then, set the hypothesis and likelihood: H0 (non-owner): observed fidelity F obs follows a distribution centered around random guessing, ,in . H1 (real owner): F obs Obey the distribution centered on the theoretical value, ,in (Affected by noise). Afterwards, Bayesian risk decision: Based on the observed Fobs, use Bayes’ theorem to calculate the posterior probability P(H0|F obs ) and P(H1|F obs ). Introducing the misjudgment cost C FN (false rejection) and C FP (false acceptance), calculate the risk of both decisions.

[0126]

[0127]

[0128] Finally, the decision with less risk is selected and the decision result and corresponding confidence level are output.

[0129]

[0130] In one embodiment of this application, the watermark embedding process is performed by the model owner, representing the "ownership confirmation" phase of the model's intellectual property. The model owner (e.g., the AI ​​model developer or organization) is the sole executor of this process. They utilize their unique user identity to generate a unique watermark using the system's quantum encoding technology. This watermark is then invisibly embedded into the AI ​​model, and ownership records (such as the model fingerprint, owner information, and a timestamp) are securely recorded on an immutable blockchain. The fingerprint extraction process is performed by the verifier, representing the "forensic" phase of intellectual property verification. When verifying the ownership of a suspected model, the verifier (e.g., a copyright investigator, a model marketplace reviewer, or any user needing to confirm the model's origin) executes this process. They input a specific set of "trigger data" into the suspected model and analyze the model's output behavior to extract the hidden "quantum fingerprint." This fingerprint is then converted into a hash value for subsequent comparison. The verification process is interactively executed between the model owner and the verifier, representing the "verification and adjudication" phase of intellectual property. The verifier first initiates a verification request. The system issues a "quantum challenge" to the purported model owner (acting as the prover). The model owner must use their private key to complete a zero-knowledge proof to verify their identity. Finally, the verifier's system calculates the fidelity between their extracted fingerprint and the original watermark, combining the results of the zero-knowledge proof to make a final determination.

[0131] In one embodiment of the present application, taking the medical institution scenario of the joint development of a multi-center rare disease AI diagnostic model as an example, several top hospitals hope to integrate their limited rare disease (Alzheimer's disease) imaging data (such as CT, MRI) and jointly train a high-precision AI diagnostic model, but the patient data of any hospital cannot leave the local server. The main roles include the model owner / sponsor - Hospital A (a national medical center), participants / co-builders - Hospital B and Hospital C (regional top hospitals), verifiers - the National Medical Products Administration (NMPA), and third-party business partners. The application process is as follows:

[0132] Title confirmation and preparation (Hospitals A, B, and C): Hospitals A, B, and C agree to jointly build the model and agree on the ownership of intellectual property rights (for example, Hospital A owns 40%, and Hospitals B and C each own 30%). In the intellectual property protection ecosystem, each hospital uses the [Quantum Watermark Generation] module to generate a unique, highly concealed quantum watermark based on its own institutional identity information. .

[0133] Federated training and watermark embedding (clients of hospitals A, B, and C): The central server (which can be hosted by hospital A or a trusted third party) distributes the initial global model. Each hospital uses local, strictly confidential patient imaging data to train the model on its own client. Before uploading model updates (gradients or weights), each hospital calls the [homomorphic watermark embedding] module to embed its encrypted quantum watermark. Securely integrated into encrypted model updates middle.

[0134] Secure Aggregation and Storage (Central Server and Ecosystem Protection): After the central server collects the encrypted, watermarked model updates from all parties, it performs [Secure Aggregation]. Due to the properties of homomorphic encryption, the aggregated new global model naturally incorporates the watermark contributions of hospitals A, B, and C. After multiple rounds of iterations, the final global model training is complete. Hospital A, as the representative, registers the final model hash, the public keys of all co-constructors, and other information on the DAG ledger through the [Immutable Storage] module using post-quantum signatures (ML-DSA), forming an immutable "birth certificate."

[0135] A medical technology company releases rare disease diagnostic software, and its core functionality is highly suspected to be related to a model jointly developed by parties A, B, and C. A verifier (such as the National Medical Product Association) intervenes to investigate. They first query the blockchain using the "Ownership Verification Interface" to confirm that parties A, B, and C had registered ownership of the model long before the company's software was released. The verifier then analyzes the company's software and can clearly extract watermark traces belonging to parties A, B, and C. If the company claims to be the legal owner, the verifier can initiate a "Zero-Knowledge Ownership Verification" and require it to prove ownership without disclosing trade secrets. The company will be unable to complete the verification, ultimately establishing a clear chain of evidence of infringement.

[0136] In one embodiment of the present application, taking a financial institution that collaborates on an intelligent anti-money laundering (AML) model across banks as an example, a financial alliance consisting of multiple banks hopes to jointly train an AI model that can identify new, cross-platform money laundering patterns. The transaction data of any bank must never be shared, but the model needs to learn from the data of all banks. The main roles include the model owner / alliance manager - the financial regulator or the lead bank designated by the alliance (large bank A), participants / data contributors - small and medium-sized banks such as Bank B and Bank C, and verifiers - audit institutions and international financial crime investigation organizations. The application process includes:

[0137] Alliance establishment and watermark generation (all banks): Alliance members jointly sign an agreement. Each bank generates an encrypted watermark representing its own institution in the intellectual property protection ecosystem.

[0138] Privacy-preserving federated training (bank clients): Each bank trains the model locally using its own massive transaction data. This data contains extremely sensitive customer information. After local training, each bank uses the [Homomorphic Watermark Embedding] module to embed its own watermark into the encrypted model update. This step ensures that even if the model is leaked, its source can be traced.

[0139] Aggregation and Immutable Audit Log (Central Server and Ecosystem Protection): A central server (operated by the regulatory body) performs secure aggregation, generating a more robust AI model capable of providing global insight into money laundering risks. For every major model update, its digital fingerprint and list of contributors are signed and recorded on the immutable DAG ledger, creating a clear, tamper-proof audit trail. This is crucial for meeting regulatory compliance requirements.

[0140] When an overseas fintech company claimed to have developed a revolutionary unified anti-money laundering (AML) platform and began selling it to smaller banks, the alliance suspected the technology was plagiarizing their collaborative efforts. The verifier (auditor) obtained the company's technical model for analysis. Using the "ownership verification interface," they were able to easily detect watermarks from the model belonging to multiple banks within the alliance. Furthermore, timestamps on the blockchain clearly showed that the alliance's model existed long before the company's founding. Faced with this challenge, the company was unable to prove its legal ownership of the model's core algorithm through "zero-knowledge ownership verification," thus confirming its infringement.

[0141] In the aforementioned method for protecting the intellectual property rights of a federated learning model based on quantum coding and lattice cryptography, an initial global model is first distributed. A quantum watermark is generated and embedded based on this initial global model, combining lattice cryptographic quantum state encoding and information theory to obtain the watermarked initial global model. Next, a corresponding quantum fingerprint is generated based on the watermarked initial global model. This quantum fingerprint is aggregated using multi-key homomorphic encryption to obtain a global aggregated fingerprint, and the corresponding identity information is recorded in a distributed aggregation ledger. Finally, verification information is received, and model ownership is verified based on this verification information and the identity information using a zero-knowledge proof protocol based on a lattice-hard problem. In other words, the watermark itself is encrypted by a LWE instance. Any computational attempt to remove the watermark is equivalent to solving a difficult LWE problem, which is computationally infeasible. Without knowing the complete watermark information, an attacker cannot perfectly replicate this quantum state for offline analysis. This physically blocks the core path of current mainstream adaptive attacks, which are strategies that optimize attack parameters by creating differentiable agents. This is a fundamental advantage that classical watermarking technology cannot match. While providing unprecedented security, it achieves superior performance by employing advanced lattice cryptography algorithms. At the same time, it is fully aligned with the international standards for post-quantum cryptography finalized by NIST (FIPS203 (ML-KEM) for key encapsulation (the basis for watermark encoding) and FIPS204 (ML-DSA) for digital signatures (the basis for blockchain evidence storage)), providing the highest level of security assurance reviewed by global cryptographers to resist future quantum computer attacks, ensuring that it can meet future mandatory security requirements of governments and industries and can interoperate with other systems that follow the same standards.

[0142] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0143] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 8As shown. The computer device includes a processor, memory, a communication interface, a display, and an input device connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal via wired or wireless communication. Wireless communication can be achieved via Wi-Fi, a mobile cellular network, NFC (near-field communication), or other technologies. When executed by the processor, the computer program implements a method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography. The display of the computer device can be a liquid crystal display or an electronic ink display. The input device of the computer device can be a touch layer covering the display, keys, a trackball, or a touchpad provided on the computer device housing, or an external keyboard, touchpad, or mouse.

[0144] Those skilled in the art will understand that Figure 8 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0145] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above method embodiments when executing the computer program.

[0146] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0147] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.

[0148] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0149] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned embodiments. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), data processing logic devices based on quantum computing, and the like.

[0150] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0151] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography, characterized in that: The method comprises: Distributing an initial global model, generating and embedding a quantum watermark based on the initial global model in combination with lattice cryptographic quantum state coding and information theory, and obtaining an initial global model embedded with a watermark; Generate the corresponding quantum fingerprint based on the initial global model embedded with the watermark, aggregate the quantum fingerprint using a multi-key homomorphic encryption method to obtain a global aggregate fingerprint, and record the corresponding identity information in the DAG ledger; Receiving verification information, and performing model ownership verification based on the verification information and identity information in conjunction with a zero-knowledge proof protocol based on a lattice-hard problem; The generation and embedding of quantum watermark based on the initial global model in combination with lattice cryptographic quantum state coding and information theory includes: Preprocessing owner identity information; generating a fault-tolerant learning ciphertext vector based on the preprocessed owner identity information; Constructing a quantum state watermark based on the fault-tolerant learning ciphertext vector combined with a distributed entanglement watermark mechanism; The generating and embedding of quantum watermark based on the initial global model in combination with lattice cryptographic quantum state coding and information theory further includes: An adaptive selection strategy based on information theory is used to determine the optimal parameter subset of the watermark embedding model; Converting the parameters in the optimal parameter subset of the watermark embedding model into quantum states; Embed quantum state watermarks using quantum superposition or lattice cryptographic perturbation theory; Recording the corresponding identity information in the DAG ledger includes: Generate ML-DSA signature based on model hash, watermark hash and owner private key; Based on the ML-DSA signature and watermark record, smart contract deployment and registration are performed to generate signed ownership data, which is then stored in a node of the DAG ledger.

2. The method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography according to claim 1 is characterized in that: The generating of the corresponding quantum fingerprint based on the initial global model embedded with the watermark includes: Input the trigger data set into the initial global model embedded with the watermark, encode the output data, and obtain high-dimensional quantum state data; Extracting quantum state salient features based on the high-dimensional quantum state data using dimensionality reduction technology; A quantum fingerprint is generated using a quantum hash function based on the significant characteristics of the quantum state.

3. The method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography according to claim 2 is characterized in that: The generating of the quantum fingerprint by using a quantum hash function based on the quantum state salient features further comprises: Classicize the quantum fingerprint to obtain the classical bit string; A lattice cryptographic hash value is calculated based on the classical bit string.

4. The method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography according to claim 1 is characterized in that: The adopting of a multi-key homomorphic encryption method to aggregate the quantum fingerprint to obtain a global aggregated fingerprint includes: generating an encrypted fingerprint and a mask based on the quantum fingerprint; Performing central homomorphic aggregation based on the encryption fingerprint and mask to obtain aggregated ciphertext; Distributed decryption is performed based on the aggregated ciphertext and the private keys of the participants to obtain a global aggregated fingerprint.

5. The method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography according to claim 1 is characterized in that: Storing the signed ownership data in the node of the DAG ledger includes: Build a new node based on the parent node and broadcast it; Verify the parent node validity and content validity of the new node, and sign and vote on valid nodes; The ownership data of the signature is stored in the new node based on the signature voting results.

6. The method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography according to claim 1 is characterized in that: The receiving verification information and performing model ownership verification based on the verification information and identity information in combination with a zero-knowledge proof protocol based on a lattice-hard problem includes: Generate cryptographic commitment based on fault-tolerant learning private key and send it to the verifier; Receive a random challenge from the verifier, generate a response based on the random challenge and the fault-tolerant learning private key, and send it to the verifier.

7. The method for protecting intellectual property rights of a federated learning model based on quantum coding and lattice cryptography according to claim 1 is characterized in that: The receiving verification information and performing model ownership verification based on the verification information and identity information in combination with a zero-knowledge proof protocol based on a lattice-hard problem further includes: Obtaining a model watermark feature, and calculating fidelity based on the model watermark feature; The fidelity threshold is determined by using a dynamic threshold decision mechanism based on statistical hypothesis testing theory; An ownership verification result is determined based on the fidelity and the fidelity threshold.

Citation Information

Patent Citations

  • Federal learning property label calibration method based on model fingerprints

    CN115759247A

  • Federal learning method and device, medium and product

    CN119204254A