Data protection method and system based on federated learning and homomorphic encryption

Through a data protection system based on federated learning and homomorphic encryption, the privacy leakage and model inversion problems of medical data in a centralized aggregation mode are solved, multi-party collaborative modeling and secure reasoning are realized, and regulatory requirements are met. It is suitable for hospital alliances, remote diagnosis and treatment, medical research and other fields.

CN120768634APending Publication Date: 2025-10-10INSPUR ZHUOSHU BIG DATA IND DEV CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510999668.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-21
Publication Date
2025-10-10

AI Technical Summary

Technical Problem

In existing technologies, medical data faces the risk of privacy leakage under centralized aggregation. Traditional encrypted transmission cannot support multi-party collaborative modeling. User information may be inferred during the aggregation of federated learning parameters. There is a lack of privacy protection mechanism in the model inference stage, making it difficult to meet regulatory audit and access control requirements.

Method used

A data protection system based on federated learning and homomorphic encryption is adopted, including a federated coordination server, medical data nodes, homomorphic encryption/decryption modules, authentication management modules, audit log modules and privacy reasoning interface modules. Homomorphic encryption is used to protect model gradients and reasoning results, and combined with alliance chain management keys, identity authentication and permission control are achieved, and monitoring, tracking and compliance auditing are carried out.

Benefits of technology

Significantly reduce the risk of medical data leakage, enable multi-party collaborative modeling without sharing original data, improve model performance and generalization capabilities, support secure reasoning services, meet the high security and compliance requirements of the medical industry, and are suitable for hospital alliances, remote diagnosis and treatment, medical research and other fields.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120768634A_ABST
    Figure CN120768634A_ABST
Patent Text Reader

Abstract

The invention discloses a data protection method and system based on federated learning and homomorphic encryption, belongs to the technical field of data security, and aims to solve the technical problem of how to effectively protect user privacy while ensuring data availability. Comprising the following steps: a medical data node performs model training on a local AI model deployed locally based on a local data set, and uploads an encryption model gradient to a federal coordination server; the global parameters issued by the federal coordination server are decrypted, and gradient updating is performed on the local AI model based on the decryption result of the global parameters; calling the trained local AI model to perform model reasoning on the basis of the reasoning request for the third-party user who passes the identity authentication and has the access permission, and returning a reasoning result to the third-party user; and based on the auditing log, analyzing the running state and resource consumption of the medical data node according to a predefined auditing rule, and generating alarm information based on the abnormal operation.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data security, in particular to a data protection method and system based on federated learning and homomorphic encryption. BACKGROUND

[0002] With the development of artificial intelligence and big data technology, the medical industry is gradually evolving towards intelligentization. However, due to the high sensitivity of medical data and strict regulatory constraints, it is difficult for different medical institutions to directly share patient data for model training or research analysis.

[0003] The existing solutions have the following problems:

[0004] 1. Centralized data aggregation method has the risk of privacy leakage;

[0005] 2. Traditional encrypted transmission cannot support multi-party collaborative modeling;

[0006] 3. Although federated learning has certain privacy protection capabilities, user information may still be inferred during parameter aggregation;

[0007] 4. Lack of privacy protection mechanism for model inference stage;

[0008] 5. It is difficult to meet the needs of regulatory audit and access control.

[0009] While ensuring data availability, how to effectively protect user privacy is a technical problem to be solved. SUMMARY

[0010] The technical task of the present application is to solve the technical problem of how to effectively protect user privacy while ensuring data availability by providing a data protection method and system based on federated learning and homomorphic encryption.

[0011] In a first aspect, the present application provides a data protection system based on federated learning and homomorphic encryption, comprising a federated coordination server, a medical data node, and a homomorphic encryption / decryption module, an authentication management module, an audit log module, and a privacy inference interface module deployed on the medical data node.

[0012] There are multiple medical data nodes, each of which is registered to the alliance chain as a federated learning node, and each medical data node is used to perform the following operations:

[0013] Initialization: each medical node is registered to the alliance chain as a federated learning node, and receives the key pair returned by the alliance chain, which is used for homomorphic encryption and decryption;

[0014] Local model training: Train the local AI model deployed locally based on the local dataset, generate model gradients, call the homomorphic encryption / decryption module to homomorphically encrypt the model gradients, and upload the encrypted model gradients to the federated coordination server.

[0015] Local model update: The homomorphic encryption / decryption module is called to decrypt the global parameters sent by the federated coordination server, and the local AI model gradient is updated based on the decrypted results of the global parameters. The updated local AI model is then used for the next round of local model training. The federated learning server operates on the encrypted model gradients uploaded by each medical data node to generate global parameters.

[0016] Inference service call: Receive inference requests initiated by third-party users through the privacy inference interface module, authenticate and control the third-party users based on the authentication management module, and call the trained local AI model for model inference based on the inference request for third-party users who have passed the identity authentication and have access rights, and return the inference results to the third-party users;

[0017] Monitoring and tracking: Call the audit log module to record the process of local model training, local model update, and inference server call to form an audit log. Based on the audit log and predefined audit rules, the operating status and resource consumption of the medical data node are analyzed, and alarm information is generated based on abnormal operations.

[0018] Preferably, the homomorphic encryption algorithms include Paillier and CKKS.

[0019] Preferably, during local model training, the medical data node is used to call the homomorphic encryption / decryption module and homomorphically encrypt the model gradient using the public key in the key pair;

[0020] Correspondingly, when the local model is updated, the medical data node is used to call the homomorphic encryption / decryption module and perform homomorphic decryption on the global parameters using the private key in the key pair.

[0021] Preferably, when the inference service is called, the medical data node is used to encrypt the inference result based on a predetermined encryption method and return the encrypted inference result to a third-party user, and the corresponding third-party user decrypts the encrypted inference result based on the predefined encryption method.

[0022] In a second aspect, the present invention provides a data protection method based on homomorphic encryption using federated learning, which is used to protect data privacy using a data protection system based on homomorphic encryption using federated learning as described in any one of the first aspects, comprising the following steps:

[0023] Initialization: Each medical node registers with the consortium chain as a federated learning node and receives a key pair returned by the consortium chain. The key pair is used to perform homomorphic encryption and decryption.

[0024] Local model training: Each medical data node trains the locally deployed local AI model based on the local dataset, generates model gradients, calls the homomorphic encryption / decryption module to homomorphically encrypt the model gradients, and uploads the encrypted model gradients to the federated coordination server.

[0025] Local model update: Each medical data node calls the homomorphic encryption / decryption module to decrypt the global parameters sent by the federated coordination server, and updates the local AI model gradient based on the decrypted global parameters. The updated local AI model then undergoes the next round of local model training. The federated learning server operates on the encrypted model gradients uploaded by each medical data node to generate global parameters.

[0026] Inference service call: Each medical data node receives inference requests initiated by third-party users through the privacy inference interface module, performs identity authentication and permission control on third-party users based on the authentication management module, and calls the trained local AI model for model inference based on the inference request for third-party users who have passed identity authentication and have access rights, and returns the inference results to the third-party users;

[0027] Monitoring and tracking: Each medical data node calls the audit log module to record the process of local model training, local model update, and inference server call to form an audit log. Based on the audit log and predefined audit rules, the operating status and resource consumption of the medical data node are analyzed, and alarm information is generated based on abnormal operations.

[0028] Preferably, the homomorphic encryption algorithms include Paillier and CKKS.

[0029] Preferably, when training the local model, the medical data node calls the homomorphic encryption / decryption module and homomorphically encrypts the model gradient using the public key in the key pair;

[0030] Correspondingly, when the local model is updated, the medical data node calls the homomorphic encryption / decryption module and homomorphically decrypts the global parameters using the private key in the key pair.

[0031] Preferably, when the inference service is called, the medical data node is used to encrypt the inference result based on a predetermined encryption method and return the encrypted inference result to a third-party user, and the corresponding third-party user decrypts the encrypted inference result based on the predefined encryption method.

[0032] The data protection method and system based on federated learning homomorphic encryption of the present invention have the following advantages:

[0033] 1. Significantly reduce the risk of medical data leakage;

[0034] 2. Enable multi-party collaborative modeling without sharing original data;

[0035] 3. Improve model performance and generalization capabilities;

[0036] 4. Support security reasoning services and expand application scenarios;

[0037] 5. Meet the high security and compliance requirements of the medical industry;

[0038] 6. It can be widely used in hospital alliances, remote diagnosis and treatment, medical research, public health monitoring and other fields. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0040] The present invention will be further described below with reference to the accompanying drawings.

[0041] Figure 1 This is a flowchart of a data protection method based on federated learning and homomorphic encryption in Example 2. DETAILED DESCRIPTION

[0042] The present invention will be further described below with reference to the accompanying drawings and specific embodiments so that those skilled in the art can better understand the present invention and implement it. However, the embodiments given are not intended to limit the present invention. Unless there is a conflict, the embodiments of the present invention and the technical features in the embodiments may be combined with each other.

[0043] Embodiments of the present invention provide a data protection system and method based on federated learning and homomorphic encryption, which are used to solve the technical problem of how to effectively protect user privacy while ensuring data availability.

[0044] Example 1:

[0045] The present invention provides a data protection system based on federated learning and homomorphic encryption, including a federated coordination server, a medical data node, and a homomorphic encryption / decryption module, an authentication management module, an audit log module, and a privacy reasoning interface module deployed on the medical data node.

[0046] In this embodiment, there are multiple medical data nodes, each of which is registered to the alliance chain as a federated learning node, and each of which is used to perform five steps of initialization, local model training, local model updating, inference service calling, and monitoring tracking.

[0047] Initialization: Each medical node is registered to the alliance chain as a federated learning node and receives a key pair returned by the alliance chain, which is used to perform homomorphic encryption and decryption.

[0048] In this embodiment, during the initialization process, each medical data node configures a local AI model and initializes the local AI model, and configures a homomorphic encryption / decryption module, an authentication management module, an audit log module, and a privacy inference interface module. In the authentication management module, user access permissions are deployed to facilitate identity authentication and permission management of third-party users, and in the audit log module, audit rules are deployed to facilitate auditing of recorded logs based on the audit rules.

[0049] Local model training: based on the local data set, the local AI model deployed locally is trained to generate model gradients, and the homomorphic encryption / decryption module is called to homomorphically encrypt the model gradients, and the encrypted model gradients are uploaded to the federated coordination server.

[0050] In this embodiment, during local model training, each medical data node loads a local private data set, trains the local AI model based on the local private data set, generates model gradients, and calls the homomorphic encryption / decryption module to homomorphically encrypt the model gradients using the public key in the key pair, and uploads the encrypted model gradients to the federated coordination server.

[0051] Local model updating: the homomorphic encryption / decryption module is called to decrypt the global parameters issued by the federated coordination server, and the local AI model is updated based on the decryption result of the global parameters, and the updated local AI model is used for the next round of local model training. The federated learning server operates the encrypted model gradients uploaded by each medical data node to generate global parameters.

[0052] In this embodiment, during local model updating, the alliance coordination server receives the encrypted model gradients uploaded by each medical data node, aggregates the encrypted model gradients to generate global parameters, and issues the global parameters to each medical data node. After receiving the global parameters, each medical data node calls the homomorphic encryption / decryption module to decrypt the global parameters using the private key in the key pair, and updates the local AI model based on the decrypted global parameters, and enters the next round of local model training.

[0053] In this embodiment, the medical data node supports incremental learning and transfer learning strategies to improve convergence efficiency.

[0054] Inference service call: Receive inference requests initiated by third-party users through the privacy inference interface module, perform identity authentication and permission control on third-party users based on the authentication management module, and for third-party users who have passed identity authentication and have access rights, call the trained local AI model for model inference based on the inference request, and return the inference results to the third-party user.

[0055] In this embodiment, when the inference service is called, the medical data node is used to encrypt the inference result based on a predetermined encryption method and return the encrypted inference result to the third-party user. The corresponding third-party user decrypts the encrypted inference result based on the predefined encryption method.

[0056] Among them, the inference request includes the basic information of the third-party user and the inference requirements. After receiving the inference request, the medical data node calls the authentication management module to perform identity authentication and permission control on the third-party user. For third-party users who have passed the identity authentication and have access rights, model inference is performed without decryption, and the inference results are returned to the third-party user based on the predefined encryption method. The third-party user decrypts the encrypted inference results based on the predefined encryption method.

[0057] Monitoring and tracking: Call the audit log module to record the process of local model training, local model update, and inference server call to form an audit log. Based on the audit log and predefined audit rules, the operating status and resource consumption of the medical data node are analyzed, and alarm information is generated based on abnormal operations.

[0058] This embodiment records the process of local model training, local model updates, and inference service calls, generating an audit log. Based on this audit log, it supports real-time monitoring of the operating status and resource consumption of each medical data node. It also analyzes the operating status and resource consumption of medical data nodes based on audit rules, and triggers alarm information based on abnormal operations in the analysis results. Furthermore, this audit log can be used for subsequent compliance reviews and accountability.

[0059] The system of this embodiment combines horizontal federated learning with partially homomorphic encryption algorithms to complete global model training and secure reasoning while retaining the original data locally by all parties, thereby realizing cross-institutional and cross-regional medical AI collaboration while preventing data leakage and reverse inference attacks.

[0060] Example 2:

[0061] The present invention provides a data protection method based on homomorphic encryption of federated learning, which is used to implement data privacy protection through a system as disclosed in Example 1, including five steps: initialization, local model training, local model update, inference service call, and monitoring and tracking.

[0062] Step S100 initialization: Each medical node registers to the alliance chain as a federated learning node and receives the key pair returned by the alliance chain. The key pair is used to perform homomorphic encryption and decryption.

[0063] During the initialization process of this embodiment, each medical data node configures a local AI model and initializes the local AI model, and deploys user access rights in the authentication management module to facilitate identity authentication and permission management of third-party users, and deploys audit rules in the audit log module to facilitate auditing of recorded logs based on the audit rules.

[0064] Step S200: Local model training: Each medical data node performs model training on the local AI model deployed locally based on the local data set, generates model gradients, calls the homomorphic encryption / decryption module to homomorphically encrypt the model gradients, and uploads the encrypted model gradients to the federal coordination server.

[0065] During local model training in this embodiment, each medical data node loads a local private dataset, performs a round of model training on the local AI model based on the local private dataset, generates a model gradient, calls the homomorphic encryption / decryption module, homomorphically encrypts the model gradient using the public key in the key pair, and uploads the encrypted model gradient to the federated collaborative server.

[0066] Step S300: Local model update: Each medical data node calls the homomorphic encryption / decryption module to decrypt the global parameters issued by the federal coordination server, and performs gradient updates on the local AI model based on the decryption results of the global parameters, and performs the next round of local model training on the updated local AI model. The federated learning server operates on the encrypted model gradients uploaded by each medical data node to generate global parameters.

[0067] In this embodiment, when updating the local model, the alliance collaborative server receives the encrypted model gradients uploaded by each medical data node, aggregates them, generates global parameters, and distributes these global parameters to each medical data node. After receiving the global parameters, each medical data node invokes the homomorphic encryption / decryption module, decrypts the global parameters using the private key in the key pair, and updates the parameters of the local AI model based on the decrypted matrix, thus entering the next round of local model training.

[0068] Among them, medical data nodes support incremental learning and transfer learning strategies to improve convergence efficiency.

[0069] Step S400: Inference service call: Each medical data node receives the inference request initiated by the third-party user through the privacy inference interface module, performs identity authentication and permission control on the third-party user based on the authentication management module, and for the third-party user who has passed the identity authentication and has access rights, calls the trained local AI model for model inference based on the inference request, and returns the inference result to the third-party user.

[0070] In this embodiment, when the inference service is called, the medical data node is used to encrypt the inference result based on a predetermined encryption method and return the encrypted inference result to the third-party user. The corresponding third-party user decrypts the encrypted inference result based on the predefined encryption method.

[0071] Among them, the inference request includes the basic information of the third-party user and the inference requirements. After receiving the inference request, the medical data node calls the authentication management module to perform identity authentication and permission control on the third-party user. For third-party users who have passed the identity authentication and have access rights, model inference is performed without decryption, and the inference results are returned to the third-party user based on the predefined encryption method. The third-party user decrypts the encrypted inference results based on the predefined encryption method.

[0072] Step S500 monitoring and tracking: Each medical data node calls the audit log module to record the process of local model training, local model update, and inference server call to form an audit log, and analyzes the operating status and resource consumption of the medical data node based on the audit log and predefined audit rules, and generates alarm information based on abnormal operations.

[0073] In this embodiment, step S500 records the process of local model training, local model updates, and inference service invocations, generating an audit log. This audit log enables real-time monitoring of the operating status and resource consumption of each medical data node. This audit log also analyzes the operating status and resource consumption of each medical data node based on audit rules, triggering alarms based on abnormal operations in the analysis results. Furthermore, this audit log can be used for subsequent compliance reviews and accountability.

[0074] The method of this embodiment can realize collaborative model training and reasoning services among multiple institutions without sharing original medical data, ensuring patient privacy and data security.

[0075] The above is a detailed introduction to the data protection system method based on homomorphic encryption of federated learning provided by the present invention. Specific examples are used in this article to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea. At the same time, for those skilled in the art, according to the ideas of the present invention, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.

Claims

1. A data protection system based on federated learning and homomorphic encryption, characterized in that: It includes a federated coordination server, medical data nodes, and homomorphic encryption / decryption modules, authentication management modules, audit log modules, and privacy reasoning interface modules deployed on the medical data nodes; There are multiple medical data nodes, each of which is registered in the consortium chain as a federated learning node. Each medical data node is used to perform the following operations: Initialization: Each medical node registers with the consortium chain as a federated learning node and receives a key pair returned by the consortium chain. The key pair is used to perform homomorphic encryption and decryption. Local model training: Train the local AI model deployed locally based on the local dataset, generate model gradients, call the homomorphic encryption / decryption module to homomorphically encrypt the model gradients, and upload the encrypted model gradients to the federated coordination server. Local model update: The homomorphic encryption / decryption module is called to decrypt the global parameters sent by the federated coordination server, and the local AI model gradient is updated based on the decrypted results of the global parameters. The updated local AI model is then used for the next round of local model training. The federated learning server operates on the encrypted model gradients uploaded by each medical data node to generate global parameters. Inference service call: Receive inference requests initiated by third-party users through the privacy inference interface module, authenticate and control the third-party users based on the authentication management module, and call the trained local AI model for model inference based on the inference request for third-party users who have passed the identity authentication and have access rights, and return the inference results to the third-party users; Monitoring and tracking: Call the audit log module to record the process of local model training, local model update, and inference server call to form an audit log. Based on the audit log and predefined audit rules, the operating status and resource consumption of the medical data node are analyzed, and alarm information is generated based on abnormal operations.

2. The data protection system based on federated learning and homomorphic encryption according to claim 1, characterized in that: Homomorphic encryption algorithms include Paillier and CKKS.

3. The data protection system based on federated learning and homomorphic encryption according to claim 1, characterized in that: During local model training, the medical data node is used to call the homomorphic encryption / decryption module and homomorphically encrypt the model gradient using the public key in the key pair. Correspondingly, when the local model is updated, the medical data node is used to call the homomorphic encryption / decryption module and perform homomorphic decryption on the global parameters using the private key in the key pair.

4. The data protection system based on federated learning and homomorphic encryption according to claim 1, characterized in that: When the inference service is called, the medical data node is used to encrypt the inference result based on a predetermined encryption method and return the encrypted inference result to the third-party user. The corresponding third-party user decrypts the encrypted inference result based on the predefined encryption method.

5. A data protection method based on homomorphic encryption of federated learning, characterized in that: The method is used to protect data privacy through a data protection system based on homomorphic encryption of federated learning as described in any one of claims 1 to 4, comprising the following steps: Initialization: Each medical node registers with the consortium chain as a federated learning node and receives a key pair returned by the consortium chain. The key pair is used to perform homomorphic encryption and decryption. Local model training: Each medical data node trains the locally deployed local AI model based on the local dataset, generates model gradients, calls the homomorphic encryption / decryption module to homomorphically encrypt the model gradients, and uploads the encrypted model gradients to the federated coordination server. Local model update: Each medical data node calls the homomorphic encryption / decryption module to decrypt the global parameters sent by the federated coordination server, and updates the local AI model gradient based on the decrypted global parameters. The updated local AI model then undergoes the next round of local model training. The federated learning server operates on the encrypted model gradients uploaded by each medical data node to generate global parameters. Inference service call: Each medical data node receives inference requests initiated by third-party users through the privacy inference interface module, performs identity authentication and permission control on third-party users based on the authentication management module, and calls the trained local AI model for model inference based on the inference request for third-party users who have passed identity authentication and have access rights, and returns the inference results to the third-party users; Monitoring and tracking: Each medical data node calls the audit log module to record the process of local model training, local model update, and inference server call to form an audit log. Based on the audit log and predefined audit rules, the operating status and resource consumption of the medical data node are analyzed, and alarm information is generated based on abnormal operations.

6. The data protection method based on homomorphic encryption of federated learning according to claim 1 is characterized in that: Homomorphic encryption algorithms include Paillier and CKKS.

7. The data protection method based on homomorphic encryption of federated learning according to claim 1 is characterized in that: During local model training, the medical data node calls the homomorphic encryption / decryption module and homomorphically encrypts the model gradient using the public key in the key pair. Correspondingly, when the local model is updated, the medical data node calls the homomorphic encryption / decryption module and homomorphically decrypts the global parameters using the private key in the key pair.

8. The data protection method based on homomorphic encryption of federated learning according to claim 1 is characterized in that: When the inference service is called, the medical data node is used to encrypt the inference result based on a predetermined encryption method and return the encrypted inference result to the third-party user. The corresponding third-party user decrypts the encrypted inference result based on the predefined encryption method.

Citation Information

Cited By

  • Federal learning security aggregation method and system based on privacy protection reinforcement learning

    CN121770871A

  • Trusted access system and method for computing power network

    CN122419979A