Federal learning participant trust evaluation method for privacy protection
By adopting the CKKS encryption algorithm and the recommended trust fusion method in decentralized federated learning, the accuracy and privacy protection issues of trust evaluation are solved, and efficient and accurate trust evaluation and privacy protection are achieved, which is suitable for decentralized federated learning scenarios.
Patent Information
- Application Number
- CN202510776649.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-11
- Publication Date
- 2025-09-19
AI Technical Summary
In decentralized federated learning scenarios, existing trust assessment methods cannot effectively evaluate the reliability of participants' behavior, resulting in decreased model training accuracy and system reliability, and existing methods are insufficient in privacy protection.
The CKKS encryption algorithm is used to protect trust evidence, and the comprehensive trust of participants is calculated by integrating direct trust and recommended trust. A privacy-preserving trust evaluation method is designed, combined with the recommendation server and homomorphic encryption technology to ensure privacy security in the trust evaluation process.
It achieves accurate assessment of participants' trust in decentralized federated learning scenarios, improves privacy protection, ensures simplicity, efficiency and accuracy of trust assessment, and is suitable for real-world environments.
Smart Images

Figure CN120675753A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cyberspace security technology, and in particular to a privacy-preserving trust assessment method for federated learning participants. Background Art
[0002] Federated learning, a distributed machine learning framework, stands out from traditional centralized data processing models. It effectively protects data privacy by enabling collaborative training of machine learning models within a distributed storage environment where data remains locally stored. This approach not only efficiently executes machine learning training but also provides a strong privacy protection mechanism for decentralized raw data, making it widely favored across various fields. However, most current federated learning algorithms assume the honesty and trustworthiness of participants, who upload authentic model data for training. However, in real-world scenarios, participants exhibit diverse behavior patterns and data distributions. Consequently, in practical applications, malicious attackers often provide false data for training, or data inaccuracies due to external factors can severely compromise the accuracy of the global federated learning model. If the reliability of participant behavior cannot be guaranteed, it will negatively impact the convergence and integrity of federated learning model training, reduce the reliability of the entire system, and even render federated learning meaningless. Therefore, measuring and guaranteeing the reliability of federated learning participants has become a critical issue that needs to be addressed.
[0003] Trust management, as an effective technology for measuring system reliability, has been widely studied and applied in various network environments. Therefore, the present invention introduces a trust mechanism into the federated learning system, using trust ranking or trustworthiness as a metric for measuring the reliability of participant behavior. The trust of participants in the federated learning system is evaluated, and participants with high reliability will have higher trust rankings or trustworthiness.
[0004] In decentralized scenarios, due to differences in evaluation subjects and standards, evaluation methods and strategies vary. This results in the trust evaluation method proposed for federated learning in centralized scenarios not being applicable to decentralized federated learning. Secondly, in decentralized scenarios, the recommended trust of the evaluated party is given by other participants. Since the trust evaluation functions of different participants are different, the recommended trust given is not suitable for direct integration with direct trust.
[0005] Zhang et al. proposed an incentive mechanism for federated learning based on reputation and reverse auction theory (Jingwen Zhang, Yuezhou Wu, and Rong Pan. Incentive Mechanism for Horizontal Federated Learning Based on Reputation and Reverse Auction[C]. In Proceedings of the WebConference 2021 (WWW'21), 2021, pp. 947–956.). Reputation indirectly reflects a participant's reliability and data quality. In this scheme, the task publisher uses its entire historical reputation for the candidate as direct reputation and the historical reputation evaluations of other task publishers for the candidate as recommendation reputation, or indirect reputation. Finally, direct and indirect reputations are combined to obtain the candidate's comprehensive reputation. However, this scheme only performs a simple processing of indirect reputation, assigning different weights to it based on the recommender's direct reputation and the similarity between the task publisher and the candidate's reputation evaluations of other participants. This does not consider the issue of inaccurate recommendation trust that may arise due to different federated learning scenarios. Summary of the Invention
[0006] In order to overcome the shortcomings of the above-mentioned existing technologies, the purpose of the present invention is to provide a privacy-preserving trust assessment method for federated learning participants in decentralized federated learning scenarios. The method proposes a new recommendation trust assessment method based on the direct trust calculation method of the trust evaluator, and combines the trust evidence collected by the recommender to calculate the recommendation trust of the evaluated person, and then evaluates the comprehensive trust of the participant by fusing the direct trust and the recommendation trust. At the same time, in order to ensure the privacy of the recommendation trust evidence provided by the recommender and the privacy of the recommendation trust value of the trust evaluator, a privacy protection method based on CKKS is designed to provide privacy protection for sensitive data in the trust assessment process.
[0007] In order to achieve the above object, the technical solution adopted by the present invention is:
[0008] A privacy-preserving federated learning participant trust assessment method includes the following steps:
[0009] Step 1: The task publisher issues the initial model;
[0010] Step 2: Each participant obtains the initial model and performs model training locally based on the initial model;
[0011] In step 3, each participant encrypts the local model update trained in step 2 using the CKKS encryption algorithm and then broadcasts it to the rest of the participants.
[0012] Step 4: Each participant obtains the model broadcasted by other participants in step 3;
[0013] Step 5: Each participant obtains the recommendation trust of other participants through the recommendation server, and uses the CKKS encryption algorithm to protect the trust evidence and the calculation result with a mask;
[0014] Step 6: Each participant conducts a trust evaluation on the corresponding participant based on the trust value obtained in step 5 and the model obtained in step 4;
[0015] In step 7, each participant selects the model of the participant whose trust degree is higher than the threshold to participate in the aggregation based on the trust evaluation result of step 6, and repeats steps 3 to 7 until the model converges or reaches the termination condition.
[0016] The step 1 specifically includes:
[0017] The task publisher first initializes a machine learning model. After determining the model architecture, the task publisher sets the initial parameters of the model, including weights and biases. Then, the task publisher distributes this initialized model.
[0018] The model training described in step 2 specifically includes:
[0019] Participant k After obtaining the initial model, the local data is cleaned first to keep the data in the same scale range to improve the model training effect and efficiency; then the participants u k Combine local data and the initial model to train the local model. The local model performs forward propagation operations based on the input data and calculates the prediction results. k The loss function is used to calculate the gap between the predicted value and the true value. This gap assessment result is fed back into the model training process to adjust the model parameters.
[0020] The step 3 specifically includes:
[0021] Each participant u k First, the CKKS encryption algorithm is applied to perform initialization operations, including generating encryption and decryption keys, where participant u k The generated encryption and decryption keys are E k and D k ;
[0022] Afterwards, each participant u k The homomorphic encryption key generated in the initialization phase will be used to encrypt the constant sequence {r1,r2,...,r m} is encrypted, each participant u kAfter encryption is completed, the encrypted information is broadcast to other participants in the system k ;
[0023] The receiver collects this information and integrates it into a global set ER, which is formally represented as formula (1); the encrypted information Er k Indicates that this information comes from participant u k , encrypted information Er k The form is shown in formula (2), where r i Represents the original number in the sequence, E k (r i ) represents participant u k The encryption result of the corresponding number;
[0024] ER={Er1,Er2,…,Er n} (1)
[0025] Er k ={(r1,E k (r1)),(r2,E k (r2)),…,(r m ,E k (r m ))} (2).
[0026] The step 5 specifically includes:
[0027] According to the participants i and evaluator u j The interaction behavior of each evaluator u j After each round of interaction, collect i Interaction information, current interaction information The formal expression of is shown in formula (3):
[0028]
[0029] Where, Indicated by participant u i Behavioral information generated at the rth iteration, including model quality Abnormality stability Recommended trust credibility and model accuracy m represents the maximum number of iterations, where the model accuracy is a set that includes the accuracy of the model on each label. Its formal expression is shown in formula (4), where is the accuracy of the model on label l;
[0030] Participanti and evaluator u j The trust information generated by participating in the historically released federated learning tasks is stored in the historical trust information queue HI i Medium, HI i The form is shown in formula (5), hI k HI i The kth historical interaction information stored in is identified by user u i , the comprehensive trust calculated at the interaction time t and the kth interaction of this historical behavior cht k It consists of three parts, and the historical interaction information can store up to Q pieces;
[0031] HI i ={hI k = i ,r,cht k >,k∈[1,Q]} (5)
[0032] Evaluator u j Send the recommended service period to the participant u i The recommended trust information is stored in the recommended trust information queue RI i Central, RI i The form is shown in formula (6), which consists of user identification and encrypted recommendation trust attribute information It consists of two parts. The form is shown in formula (7);
[0033]
[0034] The above about participant u i The current interaction information, historical interaction information and recommendation trust information of participant u form i Evidence of trust Trust Evidence The formal expression of is shown in formula (8), where h ij Represents participant u i and evaluator u j The number of historical interactions, h ij ≤Q;
[0035]
[0036] The trust evaluation in step 6 includes direct trust calculation, recommended trust calculation and comprehensive trust calculation.
[0037] The direct trust includes current trust and historical trust:
[0038] After the tth round of training, the evaluator u j Calculate its effect on participant ui Direct trust The calculation method is shown in formula (9), where ω h is the historical trust hisT j→i The weight, ω c is the current trust The weight of is calculated as shown in formula (10) and (11), where h ij is the evaluator u j With participants i The number of interactions, Q is the maximum amount of historical trust information that each evaluator can store, τ k is the distance between the time when the kth historical trust information was generated and the current time, τ t is the set time distance threshold, θ is the adjustment factor used to set the maximum value of the historical trust weight; the historical trust of the participant hisT j→i The weight ω h and current trust The weight ω c With the assessor u j and participants i The number of interactions and the distance between the time of each historical interaction and the current time change dynamically. When the number of historical interactions is greater and the time of interaction is closer to the present, the historical trust hisT j→i The weight ω h If the number of interactions is less than or equal to 1, the historical trust information is considered to have no reference value, and the weight ω h is 0; when τ k >τ t When τ is too far away from the present, the historical trust information is considered to have no reference value and is removed from the trust evidence database. That is, the time of all historical interactions should satisfy τ k ≤τ t ;
[0039]
[0040] ω c =1-ω h (11)
[0041] Participant i HisT j→i The calculation method of is shown in formula (12), where τ k is the distance between the kth interaction time and the current time, that is, the closer the interaction time is to the current time, τ k The closer to 0; cht kis the comprehensive trust calculated at the time of the kth interaction. The closer the interaction time of the kth interaction is to the current time, the greater its proportion in the calculation of historical trust. The farther the interaction time is from the present time, the smaller its proportion in the calculation of historical trust. At the same time, τ k Should be less than or equal to the set threshold, that is, τ k ≤τ t , when τ k >τ t When , this interactive information is deleted from the trust evidence database;
[0042]
[0043] Evaluator u j For participants i Current trust level The calculation method of is shown in formula (13), where For participants i Model quality of the broadcast model, is the abnormality, For stability, To recommend trust credibility, To synthesize the model accuracy, ω1, ω2, ω3, and ω4 are all pre-defined weights;
[0044]
[0045] For participants i Model quality at round t The specific calculation method is shown in formula (14), where Acc(·) is the model accuracy calculation function, is the model obtained by aggregating the models broadcast by all other participants collected in this round through federated averaging. In the same way, we aggregate all participants except u i The model obtained after all other participants broadcast their models except the broadcast model;
[0046]
[0047] For participants i Abnormality in round t The model is tested using the ABS (Artificial Brain Stimulation) backdoor detection scheme. The test result is expressed as a value between 0 and 1 to indicate the model abnormality. The closer the value is to 1, the greater the possibility that the model has a backdoor.
[0048] For participants i Stability in round t The anomaly degree in the previous t-1 round is calculated as shown in formula (15), where avg is the weighted average of the anomaly degree in the previous t-1 round, and the calculation method is shown in formula (16). λ is the attenuation parameter. Considering the time delay, the closer the anomaly degree is generated to the current training round t, the higher its weight is, and the greater its impact on stability is.
[0049]
[0050]
[0051] For participants i The credibility of the recommendation in round t When the evaluators in the first t-1 rounds conduct trust evaluation on other participants, participant u i The accuracy of the recommendation trust provided is calculated, and the specific calculation method is shown in formula (17), where is participant u in round r i To the evaluator u j Provided to participants k Recommended trust, is the evaluator u in round r j For participants k Overall trustworthiness;
[0052]
[0053] For participants i Comprehensive model accuracy at round t The specific calculation method is shown in formula (18), p j is the evaluator’s preference on label j;
[0054]
[0055] The recommendation confidence calculation specifically includes:
[0056] Recommender u k In round t, the information about the evaluated person u is given i Recommended trust Recommended by u k Upload the trust evidence collected by the evaluator u j Use these trust evidences to calculate the trust through your own current trust calculation method; when the evaluator u j In the participants i When conducting trust assessment, participants k Request to obtain recommendation trust evidence to calculate the trust of participant u i Recommended trust, participant u kAfter the trust evidence is encrypted using homomorphic encryption, it is sent to the evaluator u j , evaluator u j The received trust evidence is formally expressed as shown in formula (19):
[0057] ri k ={r,u k ,(E k (attr1),E k (attr2),…,E k (attr m ))} (19)
[0058] Evaluator u j Use formula (13) to calculate it and get the encrypted recommendation trust E k (cur_re k ); Then, the evaluator u j Select recommender u from the global set ER generated in the initialization phase (see Formula 1-Formula 2) k Encrypted information Er k , used for mask operation, evaluator u j Randomly select several Er k The encrypted constant in E k (cur_re k ) to perform any four arithmetic operations; this process is repeated twice, and we get and Label these two operations as f1 and f2. and Send to participant u k Decrypt and get and Then participant u k Send the decrypted result back to the evaluator u j , evaluator u j Use the inverse operation of f1 and f2 to recover cur_re k , verify cur_re by comparing the results of the two operations k accuracy, preventing participants from k Modify the decryption result;
[0059] In the verification cur_re k After the accuracy is determined, it is stored in the trust evidence database; after calculating the recommendation trust corresponding to each recommender, the participant u i Recommended trust In round t, participant u i Recommended trust To exclude the evaluator u jand the person being assessed u i The weighted sum of the recommendation trust of all other participants is calculated as shown in formula (20), where Recommended trust The weight reflects the credibility of the recommendation; The calculation method is shown in formula (21), where a1 = 1, is the evaluator u in round l j For the person being evaluated i The comprehensive trust of the recommendation trust is determined by the distance between the recommendation trust and the comprehensive trust in the first t-1 rounds. The closer the distance between the two, the more credible the recommendation trust is and the greater its weight is. The recommendation trust weight a l+1 The calculation method is shown in formula (22);
[0060]
[0061] The comprehensive trust calculation specifically includes:
[0062] In round t, evaluator u j For participants i Comprehensive trust It is calculated by direct trust and recommended trust, and the calculation method is shown in formula (23), where α is the weight of recommended trust; the calculation method of α is shown in formula (24), the smaller the average distance between recommended trust and comprehensive trust, the greater the weight of recommended trust;
[0063]
[0064] The step 7 specifically includes:
[0065] Each participant u k A threshold is set in advance, if the remaining participants u j The comprehensive trust of these participants u is greater than the set threshold. j The model will be used by participant u k Select and participate in aggregation, and repeat steps 3 to 7 until the model converges or the termination condition is reached.
[0066] Compared with the prior art, the present invention has the following beneficial effects:
[0067] 1. The present invention adopts homomorphic encryption in the recommendation trust calculation process, which realizes the protection of recommendation trust evidence and recommendation trust calculation results, and effectively improves the privacy protection effect.
[0068] 2. This paper proposes a privacy-preserving trust assessment method in a decentralized federated learning scenario. In this method, the recommender only provides recommendation trust evidence, and the trust evaluator uses its evaluation function to calculate the recommendation trust value. This overcomes the problem that the recommended trust given is not suitable for direct integration with direct trust due to differences in trust evaluation functions among different participants, and is more suitable for real-world environments.
[0069] 3. This invention considers both direct trust and recommended trust when calculating the trust value, and more comprehensively and accurately evaluates the trust level of each participant in the decentralized federated learning system. It has the advantages of simple, efficient, and high-precision evaluation.
[0070] In summary, the present invention has the advantages of privacy protection, simple evaluation, high efficiency and high accuracy. BRIEF DESCRIPTION OF THE DRAWINGS
[0071] Figure 1 This is a diagram of the decentralized federated learning participant trust evaluation model of the present invention.
[0072] Figure 2 This is the CKKS homomorphic encryption flow chart of this paper.
[0073] Figure 3 Flowchart of the privacy-preserving trust evaluation scheme of the present invention.
[0074] Figure 4 This is a graph showing the changing trend of trust among participants with different behavior patterns under the MNIST dataset according to an embodiment of the present invention.
[0075] Figure 5 This is a graph showing the changing trend of trust among participants with different behavior patterns under the MNIST dataset according to an embodiment of the present invention.
[0076] Figure 6 This is a graph showing the changing trend of the model accuracy under different thresholds when there is no malicious user in an embodiment of the present invention.
[0077] Figure 7 This is a graph showing the changing trend of the model accuracy under different thresholds when a malicious user exists in an embodiment of the present invention.
[0078] Figure 8 This is a comparison chart of the experimental results of the embodiment of the present invention on the MNIST dataset.
[0079] Figure 9 This is a comparison chart of experimental results of an embodiment of the present invention using the Fashion-MNIST dataset. DETAILED DESCRIPTION
[0080] The present invention will be described in detail below with reference to the accompanying drawings.
[0081] The privacy-preserving federated learning participant trust assessment method described in the present invention is as follows: Figure 1 As shown, this is done in a decentralized horizontal federated learning scenario, which includes several participants, each of which is directly connected to other participants. When the present invention conducts federated learning training, each participant can perform a trust assessment on the other participants according to its own trust assessment method, and then select a local model to participate in the aggregation based on the assessment results. The specific steps are as follows:
[0082] See also Figure 1 ,A privacy-preserving federated learning participant trust assessment method,including the following steps:
[0083] Step 1: The task publisher issues the initial model;
[0084] Step 2: Each participant obtains the initial model and performs model training locally based on the initial model;
[0085] See also Figure 2 ,Step 3, each participant uses the CKKS encryption algorithm to encrypt the local model update ,after training in step 2, and then broadcasts it to the rest of the ,participants;
[0086] Step 4: Each participant obtains the model broadcasted by other participants in step 3;
[0087] See also Figure 3 ,Step 5, each participant obtains the recommendation trust of other participants through the ,recommendation server, and uses the CKKS encryption algorithm to protect the ,trust evidence, and uses a mask to protect the calculation results;
[0088] Step 6: Each participant conducts a trust evaluation on the corresponding participant based on the trust value obtained in step 5 and the model obtained in step 4;
[0089] In step 7, each participant selects the model of the participant whose trust degree is higher than the threshold to participate in the aggregation based on the trust evaluation result of step 6, and repeats steps 3 to 7 until the model converges or reaches the termination condition.
[0090] The step 1 specifically includes:
[0091] The task publisher first initializes a machine learning model. After determining the model architecture, the task publisher sets the initial parameters of the model, including weights and biases. Then, the task publisher distributes this initialized model.
[0092] The model training described in step 2 specifically includes:
[0093] Participant kAfter obtaining the initial model, the local data is cleaned first to keep the data in the same scale range to improve the model training effect and efficiency; then the participants u k Combine local data and the initial model to train the local model. The local model performs forward propagation operations based on the input data and calculates the prediction results. In order to measure the accuracy of the model prediction, the participant u k The loss function is used to calculate the gap between the predicted value and the true value. The gap assessment result is fed back into the model training process to adjust the model parameters and continuously optimize the model performance so that it can predict and analyze data more accurately.
[0094] The step 3 specifically includes:
[0095] Each participant u k First, the CKKS encryption algorithm is applied to perform initialization operations, including generating encryption and decryption keys, where participant u k The generated encryption and decryption keys are E k and D k ;
[0096] Afterwards, each participant u k The homomorphic encryption key generated in the initialization phase will be used to encrypt the constant sequence {r1,r2,...,r m} is encrypted, each participant u k After encryption is completed, the encrypted information is broadcast to other participants in the system k ;
[0097] The receiver collects this information and integrates it into a global set ER, which is formally represented as formula (1); the encrypted information Er k Indicates that this information comes from participant u k , encrypted information Er k The form is shown in formula (2), where r i Represents the original number in the sequence, E k (r i ) represents participant u k The encryption result of the corresponding number;
[0098] ER={Er1,Er2,…,Er n} (1)
[0099] Er k ={(r1,E k (r1)),(r2,E k (r2)),…,(r m ,E k (r m ))} (2).
[0100] The step 5 specifically includes:
[0101] According to the participants i and evaluator u j The interaction behavior of each evaluator u j After each round of interaction, collect i Interaction information, current interaction information The formal expression of is shown in formula (3):
[0102]
[0103] Where, Indicated by participant u i Behavioral information generated at the rth iteration, including model quality Abnormality stability Recommended trust credibility and model accuracy m represents the maximum number of iterations, where the model accuracy is a set that includes the accuracy of the model on each label. Its formal expression is shown in formula (4), where is the accuracy of the model on label l;
[0104] Participant i and evaluator u j The trust information generated by participating in the historically released federated learning tasks is stored in the historical trust information queue HI i Medium, HI i The form is shown in formula (5), hI k HI i The kth historical interaction information stored in is identified by user u i , the comprehensive trust calculated at the interaction time t and the kth interaction of this historical behavior cht k It consists of three parts, and the historical interaction information can store up to Q pieces;
[0105] HI i ={hI k = i ,r,cht k >,k∈[1,Q]} (5)
[0106] Evaluator u j Send the recommended service period to the participant u i The recommended trust information is stored in the recommended trust information queue RI i Central, RI i The form is shown in formula (6), which consists of user identification and encrypted recommendation trust attribute information It consists of two parts. The form is shown in formula (7);
[0107]
[0108] The above about participant u i The current interaction information, historical interaction information and recommendation trust information of participant u form i Evidence of trust Trust Evidence The formal expression of is shown in formula (8), where h ij Represents participant u i and evaluator u j The number of historical interactions, more precisely the number of participants u stored in the trust database i and evaluator u j The number of historical interaction information, h ij ≤Q;
[0109]
[0110] The trust evaluation in step 6 includes direct trust calculation, recommended trust calculation and comprehensive trust calculation.
[0111] The direct trust includes current trust and historical trust:
[0112] After the tth round of training, the evaluator u j Calculate its effect on participant u i Direct trust The calculation method is shown in formula (9), where ω h is the historical trust hisT j→i The weight, ω c is the current trust The weight of is calculated as shown in formula (10) and (11), where h ij is the evaluator u j With participants i The number of interactions, Q is the maximum amount of historical trust information that each evaluator can store, τ k is the distance between the time when the kth historical trust information was generated and the current time, τ t is the set time distance threshold, θ is the adjustment factor used to set the maximum value of the historical trust weight; the historical trust of the participant hisT j→i The weight ω h and current trust The weight ω c With the assessor u j and participants iThe number of interactions and the distance between the time of each historical interaction and the current time change dynamically. When the number of historical interactions is greater and the time of interaction is closer to the present, the historical trust hisT j→i The weight ω h If the number of interactions is less than or equal to 1, the historical trust information is considered to have no reference value, and the weight ω h is 0; when τ k >τ t When τ is too far away from the present, the historical trust information is considered to have no reference value and is removed from the trust evidence database. That is, the time of all historical interactions should satisfy τ k ≤τ t ;
[0113]
[0114] Participant i HisT j→i The calculation method of is shown in formula (12), where τ k is the distance between the kth interaction time and the current time, that is, the closer the interaction time is to the current time, τ k The closer to 0; cht k is the comprehensive trust calculated at the time of the kth interaction. The closer the interaction time of the kth interaction is to the current time, the greater its proportion in the calculation of historical trust. The farther the interaction time is from the present time, the smaller its proportion in the calculation of historical trust. At the same time, τ k Should be less than or equal to the set threshold, that is, τ k ≤τ t , when τ k >τ t When , this interactive information is deleted from the trust evidence database;
[0115]
[0116] Evaluator u j For participants i Current trust level The calculation method of is shown in formula (13), where For participants i Model quality of the broadcast model, is the abnormality, For stability, To recommend trust credibility, To synthesize the model accuracy, ω1, ω2, ω3, and ω4 are all pre-defined weights;
[0117]
[0118] For participants i Model quality at round t The specific calculation method is shown in formula (14), where Acc(·) is the model accuracy calculation function, is the model obtained by aggregating the models broadcast by all other participants collected in this round through federated averaging. In the same way, we aggregate all participants except u i The model obtained after all other participants broadcast their models except the broadcast model;
[0119]
[0120] For participants i Abnormality in round t The model is tested using the ABS (Artificial Brain Stimulation) backdoor detection scheme. The test result is expressed as a value between 0 and 1 to indicate the model abnormality. The closer the value is to 1, the greater the possibility that the model has a backdoor.
[0121] For participants i Stability in round t The anomaly degree in the previous t-1 round is calculated as shown in formula (15), where avg is the weighted average of the anomaly degree in the previous t-1 round, and the calculation method is shown in formula (16). λ is the attenuation parameter. Considering the time delay, the closer the anomaly degree is generated to the current training round t, the higher its weight is, and the greater its impact on stability is.
[0122]
[0123] For participants i The credibility of the recommendation in round t When the evaluators in the first t-1 rounds conduct trust evaluation on other participants, participant u i The accuracy of the recommendation trust provided is calculated, and the specific calculation method is shown in formula (17), where is participant u in round r i To the assessor u j Provided to participants k Recommended trust, is the evaluator u in round r j For participants k Overall trustworthiness;
[0124]
[0125] For participantsi Comprehensive model accuracy at round t The specific calculation method is shown in formula (18), p j is the evaluator’s preference on label j;
[0126]
[0127] The recommendation confidence calculation specifically includes:
[0128] Recommender u k In round t, the information about the evaluated person u is given i Recommended trust Recommended by u k Upload the trust evidence collected by the evaluator u j Use these trust evidences to calculate the trust through your own current trust calculation method; when the evaluator u j In the participants i When conducting trust assessment, participants k Request to obtain recommendation trust evidence to calculate the trust of participant u i Recommended trust, participant u k After the trust evidence is encrypted using homomorphic encryption, it is sent to the evaluator u j , evaluator u j The received trust evidence is formally expressed as shown in formula (19):
[0129] ri k ={r,u k ,(E k (attr1),E k (attr2),…,E k (attr m ))} (19)
[0130] Evaluator u j Use formula (13) to calculate it and get the encrypted recommendation trust E k (cur_re k ); Then, the evaluator u j Select recommender u from the global set ER generated in the initialization phase (see Formula 1-Formula 2) k Encrypted information Er k , used for mask operation, evaluator u j Randomly select several Er k The encrypted constant in E k (cur_re k ) to perform any four arithmetic operations; this process is repeated twice, and we get and Label these two operations as f1 and f2. and Sent to participant u k Decrypt and get and Then participant u k Send the decrypted result back to the evaluator u j , evaluator u j Use the inverse operation of f1 and f2 to recover cur_re k , verify cur_re by comparing the results of the two operations k accuracy, preventing participants from k Modify the decryption result;
[0131] In the verification cur_re k After the accuracy is determined, it is stored in the trust evidence database; after calculating the recommendation trust corresponding to each recommender, the participant u i Recommended trust In round t, participant u i Recommended trust To exclude the evaluator u j and the person being assessed u i The weighted sum of the recommendation trust of all other participants is calculated as shown in formula (20), where Recommended trust The weight reflects the credibility of the recommendation; The calculation method is shown in formula (21), where a1 = 1, is the evaluator u in round l j For the person being evaluated i The comprehensive trust of the recommendation trust is determined by the distance between the recommendation trust and the comprehensive trust in the first t-1 rounds. The closer the distance between the two, the more credible the recommendation trust is and the greater its weight is. The recommendation trust weight a l+1 The calculation method is shown in formula (22);
[0132]
[0133] The comprehensive trust calculation specifically includes:
[0134] In round t, evaluator u j For participants i Comprehensive trust It is calculated by direct trust and recommended trust, and the calculation method is shown in formula (23), where α is the weight of recommended trust; the calculation method of α is shown in formula (24), the smaller the average distance between recommended trust and comprehensive trust, the greater the weight of recommended trust;
[0135]
[0136] The step 7 specifically includes:
[0137] Each participant u k A threshold is set in advance, if the remaining participants u j The comprehensive trust of these participants u is greater than the set threshold. j The model will be used by participant u k Select and participate in aggregation, and repeat steps 3 to 7 until the model converges or the termination condition is reached.
[0138] Simulation experiment
[0139] Privacy Analysis
[0140] There are two potential privacy leakage issues when using this invention for trust evaluation: (1) the evaluator becomes curious about the original trust evidence of the recommended trust information provider; and (2) the recommended trust information provider becomes curious about the evaluator's calculation results. Next, we will conduct a theoretical analysis of these two privacy leakage issues to demonstrate that the invention can effectively protect the privacy information of participants during trust evaluation.
[0141] (1) The evaluator is curious about the original trust evidence of the trust provider
[0142] After receiving the original trust evidence from the recommendation trust provider, the evaluator attempts to crack the recommender's encryption algorithm to obtain the original trust evidence. The recommender's original trust evidence is encrypted using the CKKS homomorphic encryption algorithm. Since encryption and decryption are performed locally on the recommender, the evaluator is unaware of any details of this encryption algorithm. The CKKS encryption scheme adopted in this invention is a homomorphic encryption scheme whose security relies on the RLWE (Ring Learning with Errors) problem. If the evaluator only has the ciphertext information, the evaluator cannot crack the encryption algorithm, and the security of the trust evidence is guaranteed.
[0143] (2) Recommended trust provider's calculation results of curious evaluators
[0144] After receiving the calculation result sent by the evaluator, the recommender decrypts it and tries to infer the recommendation trust value calculated by the evaluator through the decrypted result. According to the description in step 6, the recommender obtains two results after decryption: and In the extreme case, the four arithmetic operations performed by the evaluator in step 6 using the calculated encrypted recommendation trust value and the encrypted random number are simplified to addition and subtraction operations. At this time, we can obtain the equation group shown in formula (25).
[0145]
[0146] where (r1, r2, …, r m ) is a random number sequence generated when the system is initialized, (a1, a2, ..., a m ) and (b1,b2,…,b m ) is an unknown parameter sequence, where m>>2. According to the knowledge of linear algebra and the solution of non-homogeneous equations, we know that there are countless solutions to the equations, so the recommender cannot infer cur_re k In extreme cases, when the evaluator only performs addition and subtraction operations on the results, the recommender cannot infer cur_re k , then the recommender cannot infer cur_re when the evaluator may perform any four arithmetic operations on the result k .
[0147] Experimental setup
[0148] The experimental platform of the present invention is shown in Table 1. The local training model of the node is a convolutional neural network (CNN). The local training set of the node uses two different data sets: MNIST and Fashion-MNIST. The CNN model structure consists of a convolutional layer and a fully connected layer. The convolutional layer structure of the CNN model for training MNIST and Fashion-MNIST is the same, and the convolutional layer consists of two convolution operations and two pooling operations. The topological structure between the participants in the experiment is a fully connected mesh topology, and each participant is directly connected to the other participants. Only the non-independent and identically distributed case is set in the experiment, and the specific Non-IID settings are as follows:
[0149] The data is classified according to the label. The data with the same label is in the same category. There are m categories of data in total. Each participant has m / 2 categories of data with the same amount of data, and the Non-IID setting is realized from the data distribution level.
[0150] In the experiment, the CKKS scheme is implemented based on the Python open source library tenseal. The parameter settings of all participants are the same, the polynomial modulus degree is set to 8192, the coefficient modulus bit size is set to [60, 40, 40, 60], and the global scaling parameter is set to 2^40.
[0151] Table 1 Experimental environment
[0152]
[0153]
[0154] Table 2 Experimental parameter settings
[0155]
[0156] Table 3 Behavior patterns of participants in the federated learning system
[0157] Behavioral patterns describe Mode 1 Honest participant, always maintain good behavior Mode 2 Malicious actors always behave maliciously Mode 3 Malicious participants provide malicious updates every other round Mode 4 Malicious participants first provide 5 rounds of normal updates, then 2 rounds of malicious updates, alternating Mode 5 Malicious participants first provide 2 rounds of normal updates, then 5 rounds of malicious updates, alternating
[0158] Twenty participants are deployed in the system, and the initial trust level of all participants is an uncertain trust level of 0.5. In addition, this experiment considers behaviors with a trust level of 0.7-1 to be good behaviors, behaviors with a trust level of 0-0.4 to be malicious behaviors, and the rest to be uncertain behaviors, for which no direct conclusion can be given. The relevant simulation parameters and values during the experiment are shown in Table 2. At the same time, Table 3 summarizes the five different behavior patterns that may occur in the federated learning system. In order to track the changing trends in the trust rankings of federated learning participants with different behavior patterns during multiple interactions with the aggregation server, the present invention assumes that all participants participate in each iteration process regardless of whether they are malicious or not.
[0159] To simulate the problem solved by this invention (in a decentralized scenario, inaccurate trust recommendations due to differences in trust preferences and personalized needs affect the trust assessment results, resulting in the global model obtained by selecting the model for aggregation based on the trust assessment results to perform poorly on the personalized needs of the participants), we simulate the personalized needs of the participants by setting priority goals, and set different weights for the trust attributes in each participant's trust assessment method to simulate different trust preferences. To simplify the setup and make the experimental results more intuitive, the priority goals set for each participant in the experiment are the participants' desire to obtain a more accurate model on some labels. Specifically, the goal of federated learning among participants is to make the final model obtained by the participants have higher accuracy on some labels without reducing the overall accuracy of the model.
[0160] experiment
[0161] To verify the feasibility of this invention, we first tracked the changing trends in trust assessment results for participants with different behavior patterns during the federated learning process, when a single benign participant served as the evaluator. The experiment involved 20 participants, including four malicious participants, one each with behavior patterns 2 through 5. The system employs a fully connected mesh topology, with each participant directly connected to every other participant. Participants share model information via broadcast, and trust recommendations are obtained through end-to-end communication. The participant data distribution is non-IID. Figure 4This paper demonstrates the trust evaluation results of a normal participant on other participants with different behavior patterns in the MNIST dataset. The experimental results show that the trust of honest participants in Pattern 1 quickly rises to 0.8 after just a few iterations of federated learning, and then slowly increases with the number of iterations. This is because honest participants consistently perform good behavior. However, the trust of malicious participants with other behaviors (Patterns 2 to 5) drops below 0.5 within a short period of time, significantly different from the trust of honest participants. Therefore, the proposed solution enables the aggregation server to accurately identify malicious participants.
[0162] The trustworthiness of malicious participants also varies depending on their behavior patterns. Participants with Pattern 2 are identified after a single interaction with the evaluator, and their trustworthiness rapidly decreases due to their consistent malicious behavior, ultimately stabilizing at a low level. For participants who alternate between good and malicious behavior (Patterns 3, 4, and 5), trustworthiness increases as the proportion of good behavior increases during the alternating cycles. Continuous good behavior effectively increases trustworthiness. Participants with Pattern 4, due to their greater number of good behaviors, have higher trustworthiness than those with Patterns 3 and 5. However, experimental results show that even when they perform more good behaviors than malicious ones, their trustworthiness remains below 0.5. Therefore, the trustworthiness of participants with different behavior patterns can be accurately assessed, providing effective decision support for the selection of participants in the federated learning system and improving the reliability of the federated learning system. Figure 5 We present experimental results on the FMNIST dataset and observe that the conclusions are consistent with those of the experiments performed on the MNIST dataset.
[0163] In the federated learning trust evaluation scheme of the present invention, after the evaluator conducts a trust evaluation on other participants, the local models of the participants whose comprehensive trust is greater than the threshold value will be selected for aggregation, and then the next round of model training will be carried out. In federated learning, the trust evaluation threshold is a key parameter used to determine which participants' models should be selected for the aggregation of the global model. Setting the threshold too high will result in overly strict trust requirements, which may cause too many participants to be excluded from the model aggregation, thereby limiting the cooperation and scalability of the federated learning system, and may even cause data scarcity problems. On the contrary, setting the threshold too low will result in lax trust requirements, which may allow the models of untrustworthy participants to be included in the aggregation of the global model, thereby reducing the quality and reliability of the global model and increasing the security risks of the system. Therefore, setting the threshold reasonably is crucial to ensuring the security of the federated learning system, the quality of the model and the effectiveness of cooperation. In order to analyze the impact of the trust evaluation threshold on federated learning, we conducted experiments under the conditions that the number of participants is 20, the training dataset is MNIST, the data distribution is Non-IID setting, and the federated learning rounds are set to 10 rounds. Figure 6 and Figure 7 These are the experimental results with and without malicious users under different trust evaluation threshold settings.
[0164] Figure 6 The figure shows the change in average model accuracy of participants at different thresholds when there are no malicious users. As can be seen, since there are no malicious users in the system at this time, the average model accuracy is higher and the convergence is faster when the threshold is lower. This is because the lower the threshold, the more models are aggregated during model aggregation, resulting in higher average model accuracy. As the threshold increases, the number of models available for aggregation decreases, and the average model accuracy gradually decreases. However, due to the presence of malicious users in the system, the threshold must be set neither too high nor too low. Figure 7 The figure shows the change in the average model accuracy of participants under different thresholds when there are malicious users in the system. At this time, the proportion of malicious users is 20% (there is one malicious user in each of the two to five modes). Figure 7 It can be seen that due to the existence of malicious users in the system, when the threshold is set low, participants can easily select the malicious model provided by malicious participants during model aggregation, which leads to the devaluation of the accuracy of the aggregated model. When the threshold is set high, the situation is similar. Figure 7 As shown in the figure, the number of models involved in the aggregation is small, and the accuracy of the aggregated model is difficult to improve.
[0165] This scheme uses CKKS homomorphic encryption to encrypt the recommendation trust evidence. CKKS is a fully homomorphic encryption scheme particularly suitable for processing real and complex data. In the CKKS scheme, encryption and decryption are not lossless but rather subject to errors. These errors primarily come from two sources: approximation noise and rounding error.
[0166] Approximation noise: One of the main sources of noise in the CKKS scheme is approximation noise. During encryption, the original real or complex plaintext is converted into a polynomial form, the coefficients of the polynomial are mapped to a finite ring, and a small amount of noise is added to increase security. This noise is typically a random number following a Gaussian distribution. During decryption, this noise is removed, but because it is random, it introduces a certain amount of error.
[0167] Rounding Error: Another factor that affects the accuracy of the CKKS scheme is rounding error. In the CKKS scheme, during encryption and decryption operations, polynomial coefficients are rounded or decremented to fit within the finite range of the ring. These rounding operations can introduce errors that accumulate over multiple calculations, affecting the accuracy of the final result.
[0168] This method uses the recommender's trust evidence to calculate recommendation trust in order to obtain more accurate trust. To protect the privacy of the trust evidence, homomorphic encryption is employed. Since homomorphic encryption is subject to error, to test its impact on this scheme, we tracked and compared the results obtained by calculating the trust level of a recommendation using unencrypted trust evidence and homomorphically encrypted trust evidence, followed by decryption, during 10 iterations of a federated learning process. Table 4 shows two calculations of trust level for participant u1, acting as the evaluator, during the first 10 iterations of a federated learning process. The total number of participants in this federated learning process was 10, and the threshold was 0.65. Since the primary focus was on the error of the homomorphic encryption algorithm, no malicious participants were included in this experiment, and the trust evaluation functions for all participants were identical. Evaluator u1, evaluated participant u2, and recommender u3 were all legitimate users. From Table 4, we can see that the error between the decrypted result after calculating the encrypted recommendation trust evidence using the recommendation trust calculation method proposed in the present invention (i.e., the encrypted calculation result in the table) and the result calculated for the unencrypted recommendation trust evidence (i.e., the original result in the table) is very low, with an average error of 2.4E-06, which can be completely ignored. The experiment in Table 4 proves that the error generated during encryption and decryption of the homomorphic encryption scheme CKKS has little impact on this scheme and can be ignored.
[0169] Table 4 The impact of encryption of recommendation trust evidence on recommendation trust results
[0170] Round Original results Encrypted calculation results error 1 0.791828 0.791829 1E-06 2 0.791099 0.791092 7E-06 3 0.75692 0.75692 0 4 0.785003 0.784999 4E-06 5 0.726591 0.726601 1E-05 6 0.768935 0.768933 2E-06 7 0.72663 0.72663 0 8 0.808096 0.808091 5E-06 9 0.772308 0.772311 3E-06 10 0.864647 0.864646 1E-06
[0171] To verify that the recommended trust calculation method of this invention provides more accurate trust assessments than the traditional method of directly assigning recommended trust levels, thereby obtaining models with higher accuracy on priority targets, we compared the changes in average model accuracy on each participant's priority targets after evaluating participants using the two recommended trust calculation methods and then selecting the participant models aggregated based on the evaluation results. The experiment involved 20 participants, 20% of whom were malicious, with one participant each exhibiting behavior patterns 2 through 5, and a threshold of 0.65. We simulated the differences in participants' trust assessment preferences by assigning different weights to the trust attributes in each participant's trust evaluation method. Figure 8 The figure shows the average model accuracy of all normal participants in federated learning on the priority target and the change between federated learning rounds when using the MNIST dataset as the participant dataset and two recommended trust acquisition methods. Figure 9 This is the experimental result when using the Fashion-MNIST dataset as the participant dataset. Figure 8 as well as Figure 9 The experimental results show that the average model accuracy of the participants who use the proposed invention to perform recommendation trust calculation on priority targets is significantly higher than the model accuracy of the participants who use the traditional method to perform recommendation trust calculation.
[0172] To better demonstrate the effectiveness of trust assessment, we compared the performance of models using different trust assessment methods under backdoor attacks. Table 5 shows the average success rate of backdoor attacks (the success rate refers to the proportion of backdoors successfully triggered when the model encounters all backdoor samples) after obtaining recommended trust using traditional methods and using the recommended trust acquisition method in the proposed scheme. A malicious actor selects 30% of the images in the dataset and adds a specific pixel pattern to these images (selecting a 3x3 block of 9 pixels in the lower right corner of the image and setting its RGB color to a near-black block of [20, 20, 20]. The RGB color of [20, 20, 20] is very subtle from pure black to the human visual system and is almost invisible in the image, but sufficient for machines to distinguish the two). The malicious actor also modifies the labels of these images to a specific incorrect category to generate poisoned data. To make the attack more effective, all malicious actors adopt the second behavior pattern. In each round of federated learning, the malicious actor trains the model using this poisoned data along with normal data. Table 5 shows that, under different settings for data sets, number of participants, and proportion of malicious users, the backdoor attack success rate of the final model obtained at the end of federated learning using the recommended trust calculation scheme proposed in this invention for trust evaluation is lower than that of the model obtained by federated learning using traditional recommended trust calculation methods. This demonstrates that the proposed scheme is more effective in resisting backdoor attacks. It also confirms that the trust evaluation scheme using the recommended trust calculation scheme proposed in this invention can perform trust evaluation more accurately.
[0173] Table 5 Backdoor attack success rate
[0174]
[0175] Table 6 Comparison results between the proposed scheme and existing schemes on the MNIST dataset
[0176]
[0177] To demonstrate the superiority of our proposed scheme, we conducted a comparative experiment with existing trust assessment schemes. The experiment involved 20 participants, a threshold of 0.65, a malicious user ratio of 20%, and one malicious user behavior pattern from pattern 2 to pattern 5. Table 6 shows the experimental results for the overall accuracy and priority target accuracy of the final models obtained after model training on the MNIST dataset using the proposed scheme and a federated learning incentive mechanism proposed by Zhang et al., based on reputation and reverse auction theory. The five selected participants were all normal participants, and their priority targets were different labels. The experimental results in the table show that the overall accuracy of the final models of the five participants in the federated learning trust assessment using the comparison scheme and the proposed scheme is not significantly different, but the priority target accuracy of the proposed scheme is significantly better than that of the comparison scheme. This is clearly because our scheme obtains more accurate recommendation trust during the participant trust assessment phase, making the overall trust assessment result more accurate for the evaluator. Therefore, the final model, obtained after model aggregation based on the trust assessment results to select participant models, performs better in meeting the participants' personalized needs. Table 7 shows the experimental results conducted on the FMNIST dataset. Similar to the experimental results shown in Table 6, the final model of the federated learning participants using this scheme is significantly better than the comparison scheme in terms of priority target accuracy.
[0178] Table 7 Comparison results between the proposed scheme and existing schemes on the FMNIST dataset
[0179]
Claims
1. A privacy-preserving method for trust assessment among federated learning participants, characterized in that: The following steps are involved: Step 1: The task publisher issues the initial model; Step 2: Each participant obtains the initial model and performs model training locally based on the initial model; In step 3, each participant encrypts the local model update trained in step 2 using the CKKS encryption algorithm and then broadcasts it to the rest of the participants. Step 4: Each participant obtains the model broadcasted by other participants in step 3; Step 5: Each participant obtains the recommendation trust of other participants through the recommendation server, and uses the CKKS encryption algorithm to protect the trust evidence and the calculation result with a mask; Step 6: Each participant conducts a trust evaluation on the corresponding participant based on the trust value obtained in step 5 and the model obtained in step 4; In step 7, each participant selects the model of the participant whose trust degree is higher than the threshold to participate in the aggregation based on the trust evaluation result of step 6, and repeats steps 3 to 7 until the model converges or reaches the termination condition.
2. A privacy-preserving federated learning participant trust assessment method according to claim 1, characterized in that: The step 1 specifically includes: The task publisher first initializes a machine learning model. After determining the model architecture, the task publisher sets the initial parameters of the model, including weights and biases. Then, the task publisher distributes this initialized model.
3. A privacy-preserving federated learning participant trust assessment method according to claim 1, characterized in that: The model training described in step 2 specifically includes: Participant k After obtaining the initial model, the local data is cleaned first to keep the data in the same scale range to improve the model training effect and efficiency; then the participants u k Combine local data and the initial model to train the local model. The local model performs forward propagation operations based on the input data and calculates the prediction results. k The loss function is used to calculate the gap between the predicted value and the true value. This gap assessment result is fed back into the model training process to adjust the model parameters.
4. A privacy-preserving federated learning participant trust assessment method according to claim 1, characterized in that: The step 3 specifically includes: Each participant u k First, the CKKS encryption algorithm is applied to perform initialization operations, including generating encryption and decryption keys, where participant u k The generated encryption and decryption keys are E k and D k ; Afterwards, each participant u k The homomorphic encryption key generated in the initialization phase will be used to encrypt the constant sequence {r1,r2,...,r m } is encrypted, each participant u k After encryption is completed, the encrypted information is broadcast to other participants in the system k ; The receiver collects this information and integrates it into a global set ER, which is formally represented as formula (1); the encrypted information Er k Indicates that this information comes from participant u k , encrypted information Er k The form is shown in formula (2), where r i Represents the original number in the sequence, E k (r i ) represents participant u k The encryption result of the corresponding number; IS={Is1,Is2,…,Is n } (1) Is k ={(r1,E k (r1)),(r2,E k (r2)),…,(r m ,E k (r m ))} (2).
5. A privacy-preserving federated learning participant trust assessment method according to claim 1, characterized in that: The step 5 specifically includes: According to the participants i and evaluator u j The interaction behavior of each evaluator u j After each round of interaction, collect i Interaction information, current interaction information The formal expression of is shown in formula (3): Where, Indicated by participant u i Behavioral information generated at the rth iteration, including model quality Abnormality stability Recommended trust credibility and model accuracy m represents the maximum number of iterations, where the model accuracy is a set that includes the accuracy of the model on each label. Its formal expression is shown in formula (4), where is the accuracy of the model on label l; Participant i and evaluator u j The trust information generated by participating in the historically released federated learning tasks is stored in the historical trust information queue HI i Medium, HI i The form is shown in formula (5), hI k HI i The kth historical interaction information stored in is identified by user u i , the comprehensive trust calculated at the interaction time t and the kth interaction of this historical behavior cht k It consists of three parts, and the historical interaction information can store up to Q pieces; HI i ={hI k = i ,r,cht k >,k∈[1,Q]} (5) Evaluator u j Send the recommended service period to the participant u i The recommended trust information is stored in the recommended trust information queue RI i Central, RI i The form is shown in formula (6), the recommendation information consists of the user identifier and the encrypted recommendation trust attribute information It consists of two parts. The form is shown in formula (7): The above about participant u i The current interaction information, historical interaction information and recommendation trust information of participant u form i Evidence of trust Trust Evidence The formal expression of is shown in formula (8), where h ij Represents participant u i and evaluator u j The number of historical interactions, h ij ≤Q; 6. A privacy-preserving federated learning participant trust assessment method according to claim 1, characterized in that: The trust evaluation in step 6 includes direct trust calculation, recommended trust calculation and comprehensive trust calculation.
7. A privacy-preserving federated learning participant trust assessment method according to claim 6, characterized in that: The direct trust level includes current trust level and historical trust level: After the tth round of training, the evaluator u j Calculate its effect on participant u i Direct trust The calculation method is shown in formula (9), where ω h is the historical trust hisT j→i The weight, ω c is the current trust The weight of is calculated as shown in formula (10) and (11), where h ij is the evaluator u j With participants i The number of interactions, Q is the maximum amount of historical trust information that each evaluator can store, τ k is the distance between the time when the kth historical trust information was generated and the current time, τ t is the set time distance threshold, θ is the adjustment factor used to set the maximum value of the historical trust weight; the historical trust of the participant hisT j→i The weight ω h and current trust The weight ω c With the assessor u j and participants i The number of interactions and the distance between the time of each historical interaction and the current time change dynamically. When the number of historical interactions is greater and the time of interaction is closer to the present, the historical trust hisT j→i The weight ω h If the number of interactions is less than or equal to 1, the historical trust information is considered to have no reference value, and the weight ω h is 0; when τ k >τ t When τ is too far away from the present, the historical trust information is considered to have no reference value and is removed from the trust evidence database. That is, the time of all historical interactions should satisfy τ k ≤τ t ; oh c =1-h h (11) Participant i HisT j→i The calculation method of is shown in formula (12), where τ k is the distance between the kth interaction time and the current time, that is, the closer the interaction time is to the current time, τ k The closer to 0; cht k is the comprehensive trust calculated at the time of the kth interaction. The closer the interaction time of the kth interaction is to the current time, the greater its proportion in the calculation of historical trust. The farther the interaction time is from the present time, the smaller its proportion in the calculation of historical trust. At the same time, τ k Should be less than or equal to the set threshold, that is, τ k ≤τ t , when τ k >τ t When , this interactive information is deleted from the trust evidence database; Evaluator u j For participants i Current trust level The calculation method of is shown in formula (13), where For participants i Model quality of the broadcast model, is the abnormality, For stability, To recommend trust credibility, To synthesize the model accuracy, ω1, ω2, ω3, and ω4 are all pre-defined weights; For participants i Model quality at round t The specific calculation method is shown in formula (14), where Acc(·) is the model accuracy calculation function, is the model obtained by aggregating the models broadcast by all other participants collected in this round through federated averaging. In the same way, we aggregate all participants except u i The model obtained after all other participants broadcast their models except the broadcast model; For participants i Abnormality in round t The model is tested using the ABS (Artificial Brain Stimulation) backdoor detection scheme. The test result is expressed as a value between 0 and 1 to indicate the model abnormality. The closer the value is to 1, the greater the possibility that the model has a backdoor. For participants i Stability in round t The anomaly degree in the previous t-1 round is calculated as shown in formula (15), where avg is the weighted average of the anomaly degree in the previous t-1 round, and the calculation method is shown in formula (16). λ is the attenuation parameter. Considering the time delay, the closer the anomaly degree is generated to the current training round t, the higher its weight is, and the greater its impact on stability is. For participants i The credibility of the recommendation in round t When the evaluators in the first t-1 rounds conduct trust evaluation on other participants, participant u i The accuracy of the recommendation trust provided is calculated, and the specific calculation method is shown in formula (17), where is participant u in round r i To the evaluator u j Provided to participants k Recommended trust, is the evaluator u in round r j For participants k Overall trustworthiness; For participants i Comprehensive model accuracy at round t The specific calculation method is shown in formula (18), p j is the evaluator’s preference on label j; 8. A privacy-preserving federated learning participant trust assessment method according to claim 7, characterized in that: The recommendation confidence calculation specifically includes: Recommender u k In round t, the information about the evaluated person u is given i Recommended trust Recommended by u k Upload the trust evidence collected by the evaluator u j Use these trust evidences to calculate the trust through your own current trust calculation method; when the evaluator u j In the participants i When conducting trust assessment, participants k Request to obtain recommendation trust evidence to calculate the trust of participant u i Recommended trust, participant u k After the trust evidence is encrypted using homomorphic encryption, it is sent to the evaluator u j , evaluator u j The received trust evidence is formally expressed as shown in formula (19): ri k ={r,u k ,(E k (attr1),E k (attr2),…,E k (attr m ))} (19) Evaluator u j Use formula (13) to calculate it and get the encrypted recommendation trust E k (cur_re k ); Then, the evaluator u j Select recommender u from the global set ER generated in the initialization phase (see Formula 1-Formula 2) k Encrypted information Er k , used for mask operation, evaluator u j Randomly select several Er k The encrypted constant in E k (cur_re k ) to perform any four arithmetic operations; this process is repeated twice, and we get and Label these two operations as f1 and f2 respectively. and Sent to participant u k Decrypt and get and Then participant u k Send the decrypted result back to the evaluator u j , evaluator u j Use the inverse operation of f1 and f2 to recover cur_re k , verify cur_re by comparing the results of the two operations k accuracy, preventing participants from k Modify the decryption result; In the verification cur_re k After the accuracy is determined, it is stored in the trust evidence database; after calculating the recommendation trust corresponding to each recommender, the participant u i Recommended trust In round t, participant u i Recommended trust To exclude the evaluator u j and the person being assessed u i The weighted sum of the recommendation trust of all other participants is calculated as shown in formula (20), where Recommended trust The weight reflects the credibility of the recommendation; The calculation method is shown in formula (21), where a1 = 1, is the evaluator u in round l j For the person being evaluated i The comprehensive trust of the recommendation trust is determined by the distance between the recommendation trust and the comprehensive trust in the first t-1 rounds. The closer the distance between the two, the more credible the recommendation trust is and the greater its weight is. The recommendation trust weight a l+1 The calculation method is shown in formula (22); 9. A privacy-preserving federated learning participant trust assessment method according to claim 8, characterized in that: The comprehensive trust calculation specifically includes: In round t, evaluator u j For participants i Comprehensive trust It is calculated by direct trust and recommended trust, and the calculation method is shown in formula (23), where α is the weight of recommended trust; the calculation method of α is shown in formula (24), the smaller the average distance between recommended trust and comprehensive trust, the greater the weight of recommended trust; 10. A privacy-preserving federated learning participant trust assessment method according to claim 9, characterized in that: The step 7 specifically includes: Each participant u k A threshold is set in advance, if the remaining participants u j The comprehensive trust of these participants u is greater than the set threshold. j The model will be used by participant u k Select and participate in aggregation, and repeat steps 3 to 7 until the model converges or the termination condition is reached.