Federal learning data privacy protection method and device and medium
By employing fully homomorphic encryption and dynamic weight adjustment within a multi-server architecture, the problems of untrusted servers and data imbalance in federated learning are resolved, achieving efficient and secure model aggregation and data protection.
Patent Information
- Application Number
- CN202510940729.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-08
- Publication Date
- 2025-10-28
AI Technical Summary
Federated learning suffers from issues such as untrusted servers leading to data privacy leaks, data imbalance, and client heterogeneity causing differences in model aggregation contributions. Existing solutions struggle to balance privacy protection and model performance.
A multi-server architecture is adopted, and the model parameters are blinded and deblinded using fully homomorphic encryption technology. Combined with a dynamic weight adjustment strategy, multi-key fully homomorphic encryption is used to protect parameter transmission, eliminate the influence of weights on the blinding factor, and ensure that the server cannot obtain the real parameters.
It improves the accuracy and security of model aggregation without sharing the original data, is suitable for large-scale distributed scenarios, protects data privacy, and optimizes model performance in scenarios with imbalanced data.
Smart Images

Figure CN120850339A_ABST
Abstract
Description
Technical Field
[0001] This application relates at least to the field of data security technology, and in particular to a method, apparatus and medium for protecting data privacy in federated learning. Background Technology
[0002] The current problems with federated learning include: 1) server untrustworthiness: when building a federated learning architecture with a single server and multiple clients, the single server is easy to become an attack point, causing data privacy leakage; 2) data imbalance and client heterogeneity challenges: due to the uneven distribution of data on different clients and the differences in computing power among different clients, different clients contribute differently to model aggregation. Summary of the Invention
[0003] To address the aforementioned shortcomings, this application provides a federated learning data privacy protection method, apparatus, and medium to solve the following technical problem: how to design a data privacy protection method based on a multi-server architecture, and how to eliminate the impact of differences in the contributions of different clients to model aggregation under a multi-server architecture.
[0004] In a first aspect, this application provides a method for protecting the privacy of federated learning data, the method being applied to a first server and comprising:
[0005] The system receives first encryption model parameters encrypted with each public key from multiple clients participating in federated learning. It assigns each blinding factor to each first encryption model parameter based on the fully homomorphic operation of each public key and blinds it to obtain first blinded encryption model parameters. It sends the first blinded encryption model parameters to a second server, which decrypts each first blinded encryption model parameter to obtain the first blinded model parameters. It assigns each aggregation weight to each first blinded model parameter and aggregates them to obtain second blinded model parameters. It encrypts the second blinded model parameters and each aggregation weight based on each public key to obtain second blinded encryption model parameters and encrypted aggregation weights.
[0006] The system receives the second blinded encryption model parameters and encryption aggregation weights from the second server. Based on the encryption aggregation weights and each blinding factor, it performs a fully homomorphic operation on the second blinded encryption model parameters using each public key to obtain the second encryption model parameters. The system then sends the second encryption model parameters to each client, enabling each client to decrypt the second encryption model parameters to obtain the aggregation model parameters.
[0007] Further, the system receives the second blinded encryption model parameters and encryption aggregation weights from the second server. Based on the encryption aggregation weights and the fully homomorphic operation of each blinding factor using each public key, the system deblinds the second blinded encryption model parameters to obtain the second encryption model parameters. These parameters are then sent to each client, enabling each client to decrypt the second encryption model parameters to obtain the aggregation model parameters. Specifically, this includes:
[0008] Receive public key-based PK data from the second server j Second blind encryption model parameters and encrypted aggregate weight and the corresponding PK j Where Enc represents an encryption algorithm that satisfies multi-key fully homomorphic operations, β is the second blinding model parameter, and Y... i These are the aggregation weights, i = (1…n) corresponding to the n clients C participating in federated learning. i , pk j It is each client C i The public key, i = j;
[0009] Use each PK j Encrypt each blinding factor τ i get Calculation based on each pk j Encryption-weighted average blinding factor For each γ j Remove the corresponding values using fully homomorphic operations respectively To obtain the parameters of each second encryption model
[0010] Will Based on i = j, send the corresponding client C. i This enables each client C i Each uses its own PK i =pk j corresponding private key decryption Obtain the aggregation model parameters ω fed .
[0011] Further, the first blinded encryption model parameters are sent to the second server, which decrypts each first blinded encryption model parameter to obtain the first blinded model parameters. The second server then assigns each first blinded model parameter an aggregation weight and aggregates them to obtain the second blinded model parameters. Finally, the second blinded model parameters and each aggregation weight are encrypted using the public key to obtain the second blinded encryption model parameters and encrypted aggregation weights. Specifically, this includes:
[0012] n parameters of the first blind encryption model PK with the corresponding n public keys i Send it to the second server so that the second server can decrypt each item using the master key mk and the master key decryption algorithm mDec. Obtain the parameters of the first blinding model According to each α i The input data in the validation set is used to obtain the output results. The stability of each α is evaluated based on the error between the output results and the actual results in the validation set. iThe model accuracy is determined, and each α is assigned according to the accuracy of each model. i Aggregate weight Y i and aggregate α i Obtain the parameters of the second blinding model For the second blinded model parameters β and each aggregate weight Y i Based on each public key PK j =pk i Encryption to obtain parameters of the second blind encryption model and encrypted aggregate weight Among them, pk i It is client C i It is generated based on the public parameter PP sent by the second server, and the master key mk of the second server has a pair with pk. i The ability to decrypt encrypted data.
[0013] Furthermore, the system receives first encryption model parameters encrypted with each public key from multiple clients participating in federated learning. It then assigns blinding factors to each first encryption model parameter based on a fully homomorphic operation with each public key and blinds the parameters to obtain first blinded encryption model parameters. Specifically, this includes:
[0014] Receive data from n clients C participating in federated learning. i PK based on their respective public keys i The n first encryption model parameters are encrypted. PK with n public keys i , where ω i Indicates client C i Using local data D i Local model parameters generated during training;
[0015] Generate n random numbers τ i Random number τ i obey A uniform distribution is given for each random number τ. i Use the corresponding PK i Encrypt to obtain n encrypted random numbers
[0016] Will With the corresponding Perform fully homomorphic operations on the first addition and multiplication to obtain n parameters for the first blind encryption model.
[0017] Furthermore, for each γ j Remove the corresponding values using fully homomorphic operations respectively To obtain the parameters of each second encryption model Specifically include:
[0018] Each γj Each with the corresponding Perform a fully homomorphic operation on the second addition and multiplication, which are the inverses of the first addition and multiplication, to obtain n second encryption model parameters.
[0019] Secondly, this application provides a method for protecting the privacy of federated learning data, the method being applied to a second server and comprising:
[0020] The first blinded encryption model parameter is received from the first server. The first blinded encryption model parameter is obtained by the first server receiving the first encryption model parameter based on each public key from multiple clients participating in federated learning, assigning each blinding factor to each first encryption model parameter based on each public key and blinding it.
[0021] Decrypt each first blinded encryption model parameter to obtain the first blinded model parameters, assign each first blinded model parameter to an aggregation weight and aggregate them to obtain the second blinded model parameters, and encrypt the second blinded model parameters and each aggregation weight based on each public key to obtain the second blinded encryption model parameters and encrypted aggregation weights;
[0022] The second blinding encryption model parameters and encryption aggregation weights are sent to the first server, which then performs a fully homomorphic operation on the second blinding encryption model parameters based on the encryption aggregation weights and each blinding factor using each public key to obtain the second encryption model parameters. The second encryption model parameters are then sent to each client, which decrypts the second encryption model parameters to obtain the aggregation model parameters.
[0023] Furthermore, the second blinded encryption model parameters and the encryption aggregation weights are sent to the first server, enabling the first server to deblind the second blinded encryption model parameters based on the encryption aggregation weights and the fully homomorphic operation of each blinding factor on each public key to obtain the second encryption model parameters. The second encryption model parameters are then sent to each client, enabling each client to decrypt the second encryption model parameters to obtain the aggregation model parameters. Specifically, this includes:
[0024] PK based on each public key j Second blind encryption model parameters and encrypted aggregate weight and the corresponding PK j Send to the first server, where Enc represents the encryption algorithm that satisfies multi-key fully homomorphic operations, β is the second blinding model parameter, and Y... i These are the aggregation weights, i = (1…n) corresponding to the n clients C participating in federated learning. i , pk j It is each client C i The public key, i = j, is used to enable the first server to use each pk. jEncrypt each blinding factor τ i get Calculation based on each pk j Encryption-weighted average blinding factor For each γ j Remove the corresponding values using fully homomorphic operations respectively To obtain the parameters of each second encryption model Will Based on i = j, send the corresponding client C. i This enables each client C i Each uses its own PK i =pk j corresponding private key decryption Obtain the aggregation model parameters ω fed .
[0025] Further, the parameters of each first blinding encryption model are decrypted to obtain the first blinding model parameters. Each first blinding model parameter is assigned an aggregation weight and aggregated to obtain the second blinding model parameters. The second blinding model parameters and each aggregation weight are then encrypted using each public key to obtain the second blinding encryption model parameters and the encrypted aggregation weights. Specifically, this includes:
[0026] The parameters of each first blind encryption model are decrypted using the master key mk and the master key decryption algorithm mDec. Obtain the parameters of the first blinding model
[0027] According to each α i The output results are obtained by calculating the input data in the validation set. The stability of each α is evaluated based on the error between the output results and the actual results in the validation set. i Model accuracy;
[0028] Each α is assigned according to the accuracy of each model. i Aggregate weight Y i and aggregate α i Obtain the parameters of the second blinding model
[0029] For the second blinded model parameters β and each aggregate weight Y i Based on each public key PK j =pk i Encryption to obtain parameters of the second blind encryption model and encrypted aggregate weight
[0030] Among them, pk i It is client C i It is generated based on the public parameter PP sent by the second server, and the master key mk of the second server has a pair with pk. i The ability to decrypt encrypted data.
[0031] Further, the system receives first blinded encryption model parameters from the first server. These first blinded encryption model parameters are obtained by the first server receiving first encryption model parameters encrypted with each public key from multiple clients participating in federated learning, assigning each blinding factor to each first encryption model parameter based on a fully homomorphic operation of each public key, and then blinding them. Specifically, this includes:
[0032] Receive n first blind encryption model parameters from the first server PK with the corresponding n public keys i n The first server receives data from n clients C participating in federated learning. i PK based on their respective public keys i The n first encryption model parameters are encrypted. PK with n public keys i Generate n random numbers τ i Random number τ i obey A uniform distribution is given for each random number τ. i Use the corresponding PK i Encrypt to obtain n encrypted random numbers Will With the corresponding Obtained by performing the first addition and multiplication operations with completely homomorphic properties, where ω i Indicates client C i Using local data D i The parameters of the local model generated during training.
[0033] Furthermore, the first server for each γ j Remove the corresponding values using fully homomorphic operations respectively To obtain the parameters of each second encryption model Specifically include:
[0034] The first server will distribute each γ j Each with the corresponding Perform a fully homomorphic operation on the second addition and multiplication, which are the inverses of the first addition and multiplication, to obtain n second encryption model parameters.
[0035] Thirdly, this application provides a federalized learning data privacy protection device, the device being a first server, and comprising:
[0036] The blinding module is used to receive first encryption model parameters encrypted with each public key from multiple clients participating in federated learning, assign blinding factors to each first encryption model parameter based on the fully homomorphic operation of each public key and blind it to obtain first blinded encryption model parameters, send the first blinded encryption model parameters to the second server, and enable the second server to decrypt each first blinded encryption model parameter to obtain the first blinded model parameters, assign each first blinded model parameter with each aggregation weight and aggregate to obtain second blinded model parameters, and encrypt the second blinded model parameters and each aggregation weight based on each public key to obtain second blinded encryption model parameters and encrypted aggregation weights;
[0037] The deblinding module, connected to the blinding module, receives the second blinding encryption model parameters and encryption aggregation weights from the second server. Based on the encryption aggregation weights and each blinding factor, it performs a fully homomorphic operation on the second blinding encryption model parameters using each public key to obtain the second encryption model parameters. The second encryption model parameters are then sent to each client, enabling each client to decrypt the second encryption model parameters to obtain the aggregation model parameters.
[0038] Fourthly, this application provides a federalized learning data privacy protection device, which is a second server and includes:
[0039] The receiving module is used to receive the first blinded encryption model parameters from the first server. The first blinded encryption model parameters are obtained by the first server receiving the first encryption model parameters encrypted based on each public key from multiple clients participating in federated learning, assigning each blinding factor to each first encryption model parameter based on the fully homomorphic operation of each public key, and then blinding them.
[0040] The aggregation module, connected to the receiving module, is used to decrypt each first blinded encryption model parameter to obtain the first blinded model parameter, assign each first blinded model parameter to an aggregation weight and aggregate them to obtain the second blinded model parameter, and encrypt the second blinded model parameter and each aggregation weight based on each public key to obtain the second blinded encryption model parameter and encrypted aggregation weight.
[0041] The sending module, connected to the aggregation module, is used to send the second blinded encryption model parameters and the encryption aggregation weight to the first server. The first server then performs a fully homomorphic operation on the second blinded encryption model parameters based on the encryption aggregation weight and each blinding factor using each public key to obtain the second encryption model parameters. The second encryption model parameters are then sent to each client, allowing each client to decrypt the second encryption model parameters to obtain the aggregation model parameters.
[0042] Fifthly, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the federated learning data privacy protection method as described above.
[0043] This application provides a method, apparatus, and medium for protecting data privacy in federated learning. During model aggregation, different weights are selected to address the data imbalance problem among clients. Dual servers are integrated for blinding / deblinding and encryption / decryption processing, ensuring that no single server can obtain completely accurate client data. Furthermore, the deblinding process eliminates the influence of weights on the blinding factor, allowing clients to obtain accurate global model parameters. All transmitted data is encrypted. Server computation is based on fully homomorphic operations, which directly operate on ciphertext without decryption, and the result remains encrypted, identical to the result of the same operation on plaintext, thus guaranteeing the aggregation effect and data security of federated learning. Attached Figure Description
[0044] Figure 1 This is a flowchart of a method for protecting the privacy of federated learning data according to an embodiment of this application;
[0045] Figure 2 This is a flowchart of another method for protecting the privacy of federated learning data in an embodiment of this application;
[0046] Figure 3 This is a schematic diagram of the structure of a federated learning data privacy protection device according to an embodiment of this application;
[0047] Figure 4 This is a schematic diagram of another federal learning data privacy protection device according to an embodiment of this application. Detailed Implementation
[0048] To enable those skilled in the art to better understand the technical solution of this application, the embodiments of this application will be further described in detail below with reference to the accompanying drawings.
[0049] It is understood that the specific embodiments and accompanying drawings described herein are merely for explaining this application and are not intended to limit this application.
[0050] It is understood that, without conflict, the various embodiments and features in the embodiments of this application can be combined with each other.
[0051] It is understood that, for ease of description, only the parts relevant to this application are shown in the accompanying drawings, while parts unrelated to this application are not shown in the drawings.
[0052] It is understood that each module or unit involved in the embodiments of this application may correspond to only one entity structure, or may be composed of multiple entity structures, or multiple modules or units may be integrated into one entity structure.
[0053] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of this application may occur in a different order than that marked in the accompanying drawings.
[0054] It is understood that the flowcharts and block diagrams of this application illustrate the possible architecture, functions, and operations of systems, apparatuses, devices, and methods according to various embodiments of this application. Each block in a flowchart or block diagram may represent a module, unit, program segment, or code, containing executable instructions for implementing the specified function. Furthermore, each block or combination of blocks in the block diagrams and flowcharts may be implemented using a hardware-based device to implement the specified function, or using a combination of hardware and computer instructions.
[0055] It is understood that the modules and units involved in the embodiments of this application can be implemented by software or by hardware. For example, the modules and units can be located in the processor.
[0056] Example 1:
[0057] like Figure 1 As shown, this application provides a method for protecting data privacy in federated learning, the method being applied to a first server and comprising:
[0058] S11. Receive first encryption model parameters encrypted with each public key from multiple clients participating in federated learning; assign each blinding factor to each first encryption model parameter based on the fully homomorphic operation of each public key and blind it to obtain first blinded encryption model parameters; send the first blinded encryption model parameters to the second server; enable the second server to decrypt each first blinded encryption model parameter to obtain the first blinded model parameters; assign each aggregation weight to each first blinded model parameter and aggregate to obtain second blinded model parameters; encrypt the second blinded model parameters and each aggregation weight based on each public key to obtain second blinded encryption model parameters and encrypted aggregation weights.
[0059] S12. Receive the second blinded encryption model parameters and encryption aggregation weights from the second server. Perform a fully homomorphic operation on the second blinded encryption model parameters based on the encryption aggregation weights and each blinding factor using each public key to obtain the second encryption model parameters. Send the second encryption model parameters to each client so that each client can decrypt the second encryption model parameters to obtain the aggregation model parameters.
[0060] In this embodiment, the method selects different weights to address the data imbalance problem among clients during model aggregation, and integrates two servers for blinding / deblinding and encryption / decryption processing. No single server can obtain completely accurate client data. Simultaneously, the deblinding process eliminates the influence of weights on the blinding factor, allowing clients to obtain accurate global model parameters. All transmitted data is encrypted, and the server's computation is based on fully homomorphic operations. This operation method directly operates on ciphertext without decryption, and the result remains encrypted, identical to the result of the same operation on plaintext, ensuring the aggregation effect and data security of federated learning. Figure 1 The method shown corresponds to the execution in the second server, as follows: Figure 2 As shown, Figure 1 The method shown is applicable to, for example, Figure 3 The device shown, such as Figure 2 The method shown is applicable to, for example, Figure 4 The apparatus shown.
[0061] Specifically, this embodiment provides a method for protecting data privacy in federated learning. In the era of big data, the data silo problem has become a bottleneck restricting the development of machine learning. Federated learning, as a distributed machine learning framework, effectively solves the data silo problem by collaboratively training a global model without sharing the original data. However, existing federated learning solutions have at least two problems: 1) When dealing with data imbalance, they often rely on client-side filtering or weight adjustment strategies, without fully integrating encryption technology, making it difficult to balance privacy protection and model performance; 2) They are mostly single-server architectures, making the server a performance bottleneck and vulnerable to attacks, failing to meet the needs of large-scale distributed scenarios. To address the aforementioned issues, this embodiment proposes a privacy protection scheme for federated learning based on multi-key fully homomorphic encryption. Through a dual-server architecture (S′ and S), server S′ receives and blinds the encrypted parameters uploaded by the client, while server S decrypts the aggregated parameters and returns the results. This ensures that neither server (S′ nor S) can obtain the actual parameters, achieving "double insurance" for privacy protection. Simultaneously, it incorporates the dynamic weight adjustment strategy in federated learning to optimize model aggregation in imbalanced data scenarios. Parameter transmission is protected through multi-key fully homomorphic encryption, including encrypting transmitted weights to protect the privacy of the weight calculation process. Fully homomorphic operations are performed based on the encrypted weights and blinding factors to eliminate the influence of weights on the blinding factors, thereby eliminating the impact of the blinding factors on the global model parameters and improving global model performance.
[0062] More specifically, this embodiment provides a single-model-dominated federated learning data privacy protection method. Single-model-dominated federated learning, due to its simplicity and efficiency, has become a hot research topic. Single-model federated learning trains a global model jointly by multiple clients, with the server selecting the dominant model. This reduces the complexity of multi-model management and fully utilizes the differentiated data from each client to improve the model's generalization ability. However, single-model federated learning still faces significant challenges in privacy protection, handling data imbalance, and communication efficiency. Traditional encryption techniques, such as single-key homomorphic encryption or secure multi-party computation, require participants to share keys in advance, which is difficult to achieve in dynamic distributed scenarios and carries a high risk of key leakage. While differential privacy can protect data by adding noise, attackers can still recover sensitive information through model inversion attacks. Regarding communication efficiency, traditional encryption schemes suffer from high computational complexity, leading to increased communication rounds or decreased model accuracy. For example, single-key fully homomorphic encryption requires all computations to be completed in ciphertext state, resulting in low efficiency; while differential privacy-based schemes reduce computational overhead, their privacy protection strength is insufficient. In light of this, this embodiment provides an efficient, secure, and flexible solution for distributed machine learning through the deep integration of multi-key fully homomorphic encryption and single-model federated learning. The introduction of multi-key fully homomorphic encryption technology allows each model participant to independently generate key pairs without pre-sharing keys, and supports dynamic client joining and leaving. The multi-key fully homomorphic encryption scheme employs addition and multiplication homomorphic encryption, significantly improving system flexibility and making it suitable for fields with high privacy protection requirements, such as healthcare and finance. The fully homomorphic encryption is implemented using IBM's (International Business Machines Corporation) HElib open-source fully homomorphic encryption library, a C++ software library that implements fully homomorphic encryption functionality.
[0063] Furthermore, the shortcomings of existing technologies include: 1) Privacy vulnerabilities and server untrustworthiness issues in single-model federated learning: Traditional single-model federated learning relies on a central server to aggregate model parameters, but the server is often assumed to be "semi-honest" or untrustworthy. Once an attacker steals the model parameters stored on the server, they can reconstruct the client's original data through gradient inversion attacks (such as GAN-based attacks). For example, research has shown that even with differential privacy to add noise, attackers can still reconstruct training data through model parameters. For single-model federated learning, the global model parameters contain the aggregated features of all clients, and their leakage will lead to the simultaneous loss of privacy for all participants, posing a much higher risk than in multi-model scenarios. Existing single-key homomorphic encryption schemes require pre-shared keys, cannot support dynamic participation, and the single-server architecture is prone to becoming a single point of attack. 2) Inconsistent model versions and outdated updates: Single-model federated learning requires clients and servers to keep their model versions synchronized, but asynchronous update mechanisms often lead to "outdated updates." For example, when a client uploads an old version of parameters, the server may have already updated the global model based on the new parameters, resulting in deviations in subsequent aggregation results. Traditional solutions use heartbeat mechanisms or fixed-round synchronization, but do not fundamentally solve the version conflicts caused by asynchronous communication. In scenarios with high real-time requirements, such as medical settings, inconsistent model versions may delay diagnostic decisions. 3) Waste of communication resources and efficiency bottlenecks: Single-model federated learning requires frequent transmission of model parameters, especially in encrypted scenarios. The high computational complexity of Fully Homomorphic Encryption (FHE) increases the number of communication rounds. For example, existing solutions require an average of dozens of iterations to perform federated processing in encrypted states, while only a few rounds are needed in plaintext scenarios. In addition, traditional single-key encryption requires the client and server to share the key, increasing initial communication overhead. For resource-constrained edge devices (such as IoT sensors), high-frequency, high-bandwidth communication will significantly shorten device lifespan. 4) Data imbalance and client heterogeneity challenges: In single-model federated learning, uneven distribution of client data (such as the small amount of rare case data in medical imaging) and differences in device computing power (such as mobile phones and cloud servers) cause the model to favor clients with large amounts of data or strong computing power. Existing solutions (such as FedProx, an optimization algorithm for heterogeneous federated learning networks) adjust proximal terms but lack cryptographic techniques, making it difficult to balance privacy protection and model fairness. For example, client models with insufficient data may be marginalized, causing the global model to fail in certain scenarios. This embodiment deeply integrates multi-key fully homomorphic encryption (MK-FHE) with single-model federated learning (Single ModelFL), proposing a federated learning framework that supports dynamic participation, privacy protection, and efficient aggregation.By introducing a single-round communication mechanism and a dominant model strategy from single-model federated learning, combined with the privacy protection capabilities of multi-key fully homomorphic encryption, this approach addresses issues such as inconsistent model versions, data imbalance, low communication efficiency, and high risk of privacy leakage in existing technologies.
[0064] In one embodiment, S12 involves receiving second blinded encryption model parameters and encryption aggregation weights from a second server, performing deblinding on the second blinded encryption model parameters based on the encryption aggregation weights and the fully homomorphic operation of each blinding factor using each public key to obtain second encryption model parameters, and sending the second encryption model parameters to each client so that each client can decrypt the second encryption model parameters to obtain aggregation model parameters. Specifically, this includes:
[0065] Receive public key-based PK data from the second server j Second blind encryption model parameters and encrypted aggregate weight and the corresponding PK j Where Enc represents an encryption algorithm that satisfies multi-key fully homomorphic operations, β is the second blinding model parameter, and Y... i These are the aggregation weights, i = (1…n) corresponding to the n clients C participating in federated learning. i , pk j It is each client C i The public key, i = j;
[0066] Use each PK j Encrypt each blinding factor τ i get Calculation based on each pk yj Encryption-weighted average blinding factor For each γ j Remove the corresponding values using fully homomorphic operations respectively To obtain the parameters of each second encryption model
[0067] Will Based on i = j, send the corresponding client C. i This enables each client C i Each uses its own PK i =pk j corresponding private key decryption Obtain the aggregation model parameters ω fed .
[0068] In this embodiment, the first server S′ is responsible for removing blinding and distributing the model. Server S′ determines the model based on the aggregated weights Y. i and weighted average blinding factor τ fed By removing blinding information through fully homomorphic operations, encrypted global model parameters are generated. Specifically, based on the aggregated weight Y i Weighted average τ using the FedAvg algorithm i Obtain the average blinding factor τ fed To improve data security and protect the privacy of the weight calculation process, Y i It also uses encrypted transmission, and v i After encryption, a fully homomorphic weighted average operation is performed to obtain... Remove get Will After encryption, the data is distributed to each client. The client decrypts the data to obtain the final global model parameter ω. fed Update the local model.
[0069] In one embodiment, in S11, the first blinded encryption model parameters are sent to the second server, which then decrypts each of the first blinded encryption model parameters to obtain the first blinded model parameters. The second server assigns each of the first blinded model parameters an aggregation weight and aggregates them to obtain the second blinded model parameters. The second blinded model parameters and each aggregation weight are then encrypted using each public key to obtain the second blinded encryption model parameters and encrypted aggregation weights. Specifically, this includes:
[0070] n parameters of the first blind encryption model PK with the corresponding n public keys i Send it to the second server so that the second server can decrypt each item using the master key mk and the master key decryption algorithm mDec. Obtain the parameters of the first blinding model According to each α i The input data in the validation set is used to obtain the output results. The stability of each α is evaluated based on the error between the output results and the actual results in the validation set. i The model accuracy is determined, and each α is assigned according to the accuracy of each model. i Aggregate weight Y i and aggregate α i Obtain the parameters of the second blinding model For the second blinded model parameters β and each aggregate weight Y i Based on each public key PK j =pk i Encryption to obtain parameters of the second blind encryption model and encrypted aggregate weight Among them, pk i It is client C i It is generated based on the public parameter PP sent by the second server, and the master key mk of the second server has a pair with pk. i The ability to decrypt encrypted data.
[0071] In this embodiment, there are multiple ways to determine the current round weight of each client. A key aspect is determining the contribution of each client's current round model parameters to the global model. This is achieved by evaluating the model accuracy obtained from different model parameters. Since the model parameters at this stage include a blinding factor, the model accuracy is evaluated based on the stability / volatility of the output error, rather than directly using the error between the output result and the actual result in the validation set. This ignores the impact of the blinding factor on the output result. The validation set and validation algorithm are pre-set in the second server S. A specific weight adjustment method can be implemented through a dominant model strategy. The steps of dominant model selection and weight adjustment include: 1) Initializing weight allocation: During the first aggregation, server S sequentially assigns each client model as the dominant model, allocating weight M, and the remaining models equally share the remaining weights (1-M) / (N-1); 2) Validation set evaluation: Server S calculates the global model accuracy under each dominant model using the validation set and selects the client model with the highest accuracy as the final dominant model k. max 3) Dynamic weight decay: Gradually reduce the weight of the dominant model M = M - Step according to the preset dominant weight step size Step, and reallocate the weights of other models; 4) Iterative optimization: Repeat the weight allocation, aggregation, and verification process until the verification accuracy θ reaches the preset threshold or the maximum number of iterations (epochs). Additionally, each public key pk... i The generation of the public key pk is based on the server S generating public parameters PP=(N,k,g) and master key mk=(p′,q′) through the Setup algorithm, and sending PP to each client. Each client then generates its own public key pk based on PP. i Thus, server S has the corresponding decryption capability.
[0072] In one embodiment, S11 involves receiving first encryption model parameters encrypted with each public key from multiple clients participating in federated learning, assigning blinding factors to each first encryption model parameter based on a fully homomorphic operation of each public key, and blinding the parameters to obtain the first blinded encryption model parameters. Specifically, this includes:
[0073] Receive data from n clients C participating in federated learning. i PK based on their respective public keys i The n first encryption model parameters are encrypted. PK with n public keys i , where ω i Indicates client C i Using local data D i Local model parameters generated during training;
[0074] Generate n random numbers τ i Random number τ i obey A uniform distribution is given for each random number τ. i Use the corresponding PK i Encrypt to obtain n encrypted random numbers
[0075] Will With the corresponding Perform fully homomorphic operations on the first addition and multiplication to obtain n parameters for the first blind encryption model.
[0076] In this embodiment, server S′ receives the encrypted model parameter Enc sent by the client. pki (ω i ) and public key pk i Data updates are performed by server S′ on the model parameters ω. i Blinding is performed. Because the server cannot compute encrypted data under different public keys, S needs to decrypt the data using the master key mk and then perform a weighted average of the data using the FedAvg algorithm. Servers S′ and S are assumed to be semi-honest and uncooperative. To ensure that S cannot know the model parameter data, the model parameters in the ciphertext state need to be blinded in server S′. Each model parameter ω... i Add random number τ i Specifically, S′ is each ω in turn. i Generate random number τ i (i = 1…n), random number τ i obey Under a uniform distribution, S′ will τ i Encrypt using each client's public key in sequence to obtain... S′ will generate the encrypted random number With the corresponding Enc pki (ω i By performing fully homomorphic addition and multiplication operations sequentially, blinded encrypted information is obtained. and will and PK i Send to server S. Additive homomorphic encryption is insufficient to support the calculation of the federated averaging algorithm; multiplicative homomorphic encryption is needed to solve the problem. A multi-key fully homomorphic encryption scheme is adopted to achieve fully homomorphic operations for addition and multiplication.
[0077] In one embodiment, for each γ j Remove the corresponding values using fully homomorphic operations respectively To obtain the parameters of each second encryption model Specifically include:
[0078] Each γ j Each with the corresponding Perform a fully homomorphic operation on the second addition and multiplication, which are the inverses of the first addition and multiplication, to obtain n second encryption model parameters.
[0079] In this embodiment, the blinding and deblinding processes are inverse operations of each other. The server S′ selects the second addition and multiplication, which are the inverses of the first addition and multiplication during blinding, to perform a fully homomorphic deblinding operation, thereby obtaining global model parameters that have eliminated blinding information. These parameters are still encrypted on the server S′ and are sent by the server S′ to each client for decryption.
[0080] A complete example process of this embodiment is as follows:
[0081] 1) Key generation:
[0082] 1.1) Server-side initialization: Server S is initialized by generating public parameters PP = (N, k, g) and master key mk = (p... ′ ,q ′ ), and sends PP to S′, and S′ sends PP to the client.
[0083] 1.2) Clients generate their own public / private key pairs: Each client Ci generates its own public / private key pair based on PP, with the public key pk... i The private key is used to encrypt local data, and is used to decrypt data returned by the server.
[0084] 2) Client-side process optimization:
[0085] 2.1) Local Model Training and Encryption: The client Ci trains a Broad Learning System (BLS) model based on local data Di, generating local model parameters ωi. Model parameters ωi are then generated through pseudo-inverse computation and encrypted using a multi-key fully homomorphic encryption algorithm Enc to obtain Enc. pki (ω i ), and Enc pki (ω i ) and public key pk i Send to server S′. Fully homomorphic encryption is implemented using IBM's HElib open-source fully homomorphic encryption library.
[0086] 2.2) Single-round communication and dynamic model update: The client can upload the latest model at any time. After the server S′ collects a sufficient number of models, it triggers aggregation. If the client updates the model before aggregation, the new model will overwrite the old model, ensuring that the server uses the latest data.
[0087] 3) Server-side process optimization:
[0088] 3.1) Data update of server S′: Server S′ receives the public key pk sent by the client. i With encrypted model parameters
[0089] 3.2) Blinding Processing: Server S′ performs ciphertext processing on each client. Add a random blinding factor τ i Generate blinded ciphertext Server S′ on model parameters ω i Blinding: Because the server cannot compute encrypted data under different public keys, S needs to decrypt the data using the master key mk and perform a weighted average of the data using the FedAvg algorithm. Assuming that servers S′ and S are semi-honest and uncooperative, to ensure that S cannot know the model parameter data, the model parameters in the ciphertext state need to be blinded in server S′. This involves blinding each model parameter ω... i Add random number τ i S′ is each ω in turn. i Generate random number τ i (i = 1…n), random number τ i obey The uniform distribution below; S′ will τ i Encrypt using each client's public key in sequence to obtain... S′ will generate the encrypted random number With the corresponding ω i By performing fully homomorphic addition and multiplication operations sequentially, the blinded encrypted information is obtained. and will and PK i Send to server S. Additive homomorphic encryption is insufficient to support the calculation of the federated averaging algorithm; multiplicative homomorphic encryption is needed to solve the problem. Therefore, a multi-key fully homomorphic encryption scheme that combines addition and multiplication operations is adopted.
[0090] 3.3) Weight Selection: Server S uses the master key mk to decrypt the blinded ciphertext, obtaining the plaintext α. i =ω i +τ i Server S aggregates α using the FedAvg algorithm. i Generate a temporary global model β and encrypt it. Returning to S′. Data decryption and weight aggregation: S is first decrypted using the master key decryption algorithm mDec. get Blinded plaintext; S is weighted by the FedAvg algorithm and α is used for the calculation. i β was calculated i =β, then S sends the public key pk through S′. i Encryption beta i, will get Send to S′. Dominant model strategy and weight adjustment: Server S removes the blinding factor τ. i The model parameters are obtained, and the accuracy of each client model is evaluated using a validation set. The client model with the highest validation accuracy is selected as the dominant model and assigned the maximum weight M. The remaining weights (1-M) / (N-1) are evenly distributed among the other models. The weights are dynamically adjusted by the step size decay of the dominant weight, and the global model is iteratively optimized until convergence or the maximum number of rounds is reached. This part is called the safe federated averaging algorithm, and the pseudocode is shown in Table 1 below.
[0091] Table 1. Secure Federated Average Algorithm
[0092]
[0093] 3.4) Removal of blinding and model distribution: Server S′ distributes the model according to the aggregated weights Y. i Weighted average τ using the FedAvg algorithm i Obtain the average blinding factor τ fed ,β-τ fed That is, removing the blinding factor. This process requires removing the blinding information through fully homomorphic operations. To improve data security, Y i It also uses encrypted transmission, and is compatible with τ. i After encryption, a fully homomorphic weighted average is performed to generate the final global model parameters ω. fed , will ω fed After encryption, the data is distributed to each client, and the client decrypts it to update its local model.
[0094] This embodiment 1 combines multi-key fully homomorphic encryption with single-round communication. The client only needs to upload the encryption parameters once, supports dynamic client joining / leaving, and does not require pre-shared keys. The server completes aggregation through blinding processing and a dominant model strategy, and the number of communication rounds is consistent with plaintext federated learning. Dynamic weights and validation set optimization are used to adjust data imbalance. Based on the validation set, the dominant model selection and weight decay mechanism improve the model accuracy in data imbalance scenarios and mitigate the impact of uneven data distribution. A dual-server architecture is used to protect privacy. Server S′ is responsible for blinding processing, and server S is responsible for aggregation calculation, ensuring that neither side can obtain the real parameters, while protecting the privacy of the weight calculation process and enhancing security. A lightweight wide network architecture is used: the width learning system (BLS) is used to reduce the size of model parameters, reduce communication overhead, and adapt to low-computing-power devices. The advantages of this embodiment 1 compared with existing technologies are shown in Table 2.
[0095] Table 2 Comparison of the advantages of the method in this embodiment with the prior art
[0096]
[0097] This embodiment 1 utilizes a combination of multi-key fully homomorphic encryption and single-model federated learning. A dual-server blind aggregation architecture ensures model parameter security, a single-round communication mechanism adapts to low-computing-power devices, and a dynamic weight adjustment strategy optimizes performance in data imbalance scenarios. This constructs a federated learning framework that supports dynamic participation, privacy protection, efficient communication, efficient aggregation, and robustness against data imbalance. This solution is suitable for privacy-sensitive scenarios such as healthcare, finance, and the Internet of Things, providing secure and reliable technical support for cross-institutional collaborative modeling and solving problems such as privacy leakage, inefficient communication, and model bias in cross-institutional collaboration.
[0098] Example 2:
[0099] like Figure 2 As shown, this application provides a method for protecting the privacy of federated learning data, the method being applied to a second server and comprising:
[0100] S21. Receive the first blinded encryption model parameters from the first server. The first blinded encryption model parameters are obtained by the first server receiving the first encryption model parameters encrypted based on each public key from multiple clients participating in federated learning, assigning each blinding factor to each first encryption model parameter based on the fully homomorphic operation of each public key, and then blinding them.
[0101] S22. Decrypt each first blinding encryption model parameter to obtain the first blinding model parameter, assign each first blinding model parameter to each aggregation weight and aggregate to obtain the second blinding model parameter, encrypt the second blinding model parameter and each aggregation weight based on each public key to obtain the second blinding encryption model parameter and encrypted aggregation weight;
[0102] S23. Send the second blinding encryption model parameters and encryption aggregation weights to the first server, so that the first server can deblind the second blinding encryption model parameters according to the encryption aggregation weights and the fully homomorphic operation of each blinding factor based on each public key to obtain the second encryption model parameters, and send the second encryption model parameters to each client, so that each client can decrypt the second encryption model parameters to obtain the aggregation model parameters.
[0103] In one embodiment, S23, the second blinded encryption model parameters and the encryption aggregation weights are sent to the first server, so that the first server can deblind the second blinded encryption model parameters according to the encryption aggregation weights and the fully homomorphic operation of each blinding factor based on each public key to obtain the second encryption model parameters, and send the second encryption model parameters to each client, so that each client can decrypt the second encryption model parameters to obtain the aggregation model parameters, specifically including:
[0104] PK based on each public key j Second blind encryption model parameters and encrypted aggregate weight and the corresponding PKj Send to the first server, where Enc represents the encryption algorithm that satisfies multi-key fully homomorphic operations, β is the second blinding model parameter, and Y... i These are the aggregation weights, i = (1…n) corresponding to the n clients C participating in federated learning. i , pk j It is each client C i The public key, i = j, is used to enable the first server to use each pk. j Encrypt each blinding factor τ i get Calculation based on each pk j Encryption-weighted average blinding factor For each γ j Remove the corresponding values using fully homomorphic operations respectively To obtain the parameters of each second encryption model Will Based on i = j, send the corresponding client C. i This enables each client C i Each uses its own PK i =pk j corresponding private key decryption Obtain the aggregation model parameters ω fed .
[0105] In one embodiment, S22, decrypting each first blinding encryption model parameter to obtain first blinding model parameters, assigning each first blinding model parameter an aggregation weight and aggregating them to obtain second blinding model parameters, and encrypting the second blinding model parameters and each aggregation weight based on each public key to obtain second blinding encryption model parameters and encrypted aggregation weights, specifically including:
[0106] The parameters of each first blind encryption model are decrypted using the master key mk and the master key decryption algorithm mDec. Obtain the parameters of the first blinding model
[0107] According to each α i The output results are obtained by calculating the input data in the validation set. The stability of each α is evaluated based on the error between the output results and the actual results in the validation set. i Model accuracy;
[0108] Each α is assigned according to the accuracy of each model. i Aggregate weight Y i and aggregate α i Obtain the parameters of the second blinding model
[0109] For the second blinded model parameters β and each aggregate weight Y i Based on each public key PK j=pk i Encryption to obtain parameters of the second blind encryption model and encrypted aggregate weight
[0110] Among them, pk i It is client C i It is generated based on the public parameter PP sent by the second server, and the master key mk of the second server has a pair with pk. i The ability to decrypt encrypted data.
[0111] In one embodiment, S21, receiving first blinded encryption model parameters from a first server, wherein the first server receives first encryption model parameters encrypted based on each public key from multiple clients participating in federated learning, assigns each blinding factor to each first encryption model parameter based on a fully homomorphic operation of each public key, and then blinds it, specifically including:
[0112] Receive n first blind encryption model parameters from the first server PK with the corresponding n public keys i n The first server receives data from n clients C participating in federated learning. i PK based on their respective public keys i The n first encryption model parameters are encrypted. PK with n public keys i Generate n random numbers τ i Random number τ i obey A uniform distribution is given for each random number τ. i Use the corresponding PK i Encrypt to obtain n encrypted random numbers Will With the corresponding Obtained by performing the first addition and multiplication operations with completely homomorphic properties, where ω i Indicates client C i Using local data D i The parameters of the local model generated during training.
[0113] In one implementation, the first server for each γ j Remove the corresponding values using fully homomorphic operations respectively To obtain the parameters of each second encryption model Specifically include:
[0114] The first server will distribute each γ j Each with the corresponding Perform a fully homomorphic operation on the second addition and multiplication, which are the inverses of the first addition and multiplication, to obtain n second encryption model parameters.
[0115] Example 3:
[0116] like Figure 3 As shown, this application provides a federated learning data privacy protection device, the device being a first server, and comprising:
[0117] The blinding module 11 is used to receive first encryption model parameters encrypted with each public key from multiple clients participating in federated learning, assign each blinding factor to each first encryption model parameter based on the fully homomorphic operation of each public key and blind it to obtain the first blinded encryption model parameter, send the first blinded encryption model parameter to the second server, so that the second server decrypts each first blinded encryption model parameter to obtain the first blinded model parameter, assign each aggregation weight to each first blinded model parameter and aggregate to obtain the second blinded model parameter, and encrypt the second blinded model parameter and each aggregation weight based on each public key to obtain the second blinded encryption model parameter and encrypted aggregation weight;
[0118] The deblinding module 12, connected to the blinding module 11, is used to receive the second blinding encryption model parameters and encryption aggregation weights from the second server, and to perform deblinding on the second blinding encryption model parameters based on the encryption aggregation weights and each blinding factor using fully homomorphic operations on each public key to obtain the second encryption model parameters. The second encryption model parameters are then sent to each client so that each client can decrypt the second encryption model parameters to obtain the aggregation model parameters.
[0119] In one embodiment, the deblinding module 12 specifically includes:
[0120] The parameter and weight receiving unit is used to receive parameters based on each public key PK from the second server. j Second blind encryption model parameters and encrypted aggregate weight and the corresponding PK j Where Enc represents an encryption algorithm that satisfies multi-key fully homomorphic operations, β is the second blinding model parameter, and Y... i These are the aggregation weights, i = (1…n) corresponding to the n clients C participating in federated learning. i , pk j It is each client C i The public key, i = j;
[0121] The weighted deblinding unit, connected to the parameter and weight receiving unit, is used to absorb each pk. j Encrypt each blinding factor τ i get Calculation based on each pk j Encryption-weighted average blinding factor For each γ jRemove the corresponding values using fully homomorphic operations respectively To obtain the parameters of each second encryption model
[0122] The aggregation parameter sending unit, connected to the weighted deblinding unit, is used to send... Based on i = j, send the corresponding client C. i This enables each client C i Each uses its own PK i =pk j corresponding private key decryption Obtain the aggregation model parameters ω fed .
[0123] In one embodiment, the blinding module 11 specifically includes:
[0124] The blinding parameter sending unit is used to transmit n first blinding encryption model parameters. PK with the corresponding n public keys i Send it to the second server so that the second server can decrypt each item using the master key mk and the master key decryption algorithm mDec. Obtain the parameters of the first blinding model According to each α I The input data in the validation set is used to obtain the output results. The stability of each α is evaluated based on the error between the output results and the actual results in the validation set. I The model accuracy is determined, and each α is assigned according to the accuracy of each model. i Aggregate weight Y I and aggregate α i Obtain the parameters of the second blinding model For the second blinded model parameters β and each aggregate weight Y i Based on each public key PK j =pk i Encryption to obtain parameters of the second blind encryption model and encrypted aggregate weight Among them, pk i It is client C i It is generated based on the public parameter PP sent by the second server, and the master key mk of the second server has a pair with pk. i The ability to decrypt encrypted data.
[0125] In one embodiment, the blinding module 11 further includes:
[0126] An encrypted parameter receiving unit is used to receive parameters from n clients C participating in federated learning. i PK based on their respective public keys i The n first encryption model parameters are encrypted. PK with n public keysi , where ω i Indicates client C i Using local data D i Local model parameters generated during training;
[0127] The random number encryption unit, connected to the encryption parameter receiving unit, is used to generate n random numbers τ. i Random number τ i obey A uniform distribution is given for each random number τ. i Use the corresponding PK I Encrypt to obtain n encrypted random numbers
[0128] The fully homomorphic positive operation unit, connected to the random number encryption unit, is used to... With the corresponding Perform fully homomorphic operations on the first addition and multiplication to obtain n parameters for the first blind encryption model.
[0129] In one embodiment, the weighted unblinding unit specifically includes:
[0130] The fully homomorphic inverse operation unit, connected to the fully homomorphic forward operation unit, is used to convert each γ j Each with the corresponding Perform a fully homomorphic operation on the second addition and multiplication, which are the inverses of the first addition and multiplication, to obtain n second encryption model parameters.
[0131] Example 4:
[0132] like Figure 4 As shown, this application provides a federated learning data privacy protection device, which is a second server and includes:
[0133] The receiving module 21 is used to receive the first blinded encryption model parameters from the first server. The first blinded encryption model parameters are obtained by the first server receiving the first encryption model parameters encrypted based on each public key from multiple clients participating in federated learning, assigning each blinding factor to each first encryption model parameter based on the fully homomorphic operation of each public key, and then blinding them.
[0134] The aggregation module 22, connected to the receiving module 21, is used to decrypt each first blinding encryption model parameter to obtain the first blinding model parameter, assign each first blinding model parameter to an aggregation weight and aggregate to obtain the second blinding model parameter, and encrypt the second blinding model parameter and each aggregation weight based on each public key to obtain the second blinding encryption model parameter and encrypted aggregation weight.
[0135] The sending module 23, connected to the aggregation module 22, is used to send the second blinded encryption model parameters and the encryption aggregation weight to the first server, so that the first server can perform deblinding on the second blinded encryption model parameters based on the encryption aggregation weight and the fully homomorphic operation of each blinding factor based on each public key to obtain the second encryption model parameters, and send the second encryption model parameters to each client, so that each client can decrypt the second encryption model parameters to obtain the aggregation model parameters.
[0136] In one embodiment, the sending module 23 is specifically used for:
[0137] PK based on each public key j Second blind encryption model parameters and encrypted aggregate weight and the corresponding PK j Send to the first server, where Enc represents the encryption algorithm that satisfies multi-key fully homomorphic operations, β is the second blinding model parameter, and Y... i These are the aggregation weights, i = (1…n) corresponding to the n clients C participating in federated learning. i , pk j It is each client C i The public key, i = j, is used to enable the first server to use each pk. j Encrypt each blinding factor τ i get Calculation based on each pk j Encryption-weighted average blinding factor For each γ j Remove the corresponding values using fully homomorphic operations respectively To obtain the parameters of each second encryption model Will Based on i = j, send the corresponding client C. i This enables each client C i Each uses its own PK i =pk j corresponding private key decryption Obtain the aggregation model parameters ω fed .
[0138] In one embodiment, the aggregation module 22 specifically includes:
[0139] The master key decryption unit is used to decrypt each parameter of the first blind encryption model using the master key mk and the master key decryption algorithm mDec. Obtain the parameters of the first blinding model
[0140] The parameter accuracy evaluation unit, connected to the master key decryption unit, is used to evaluate the accuracy of each α parameter. iThe output results are obtained by calculating the input data in the validation set. The stability of each α is evaluated based on the error between the output results and the actual results in the validation set. i Model accuracy;
[0141] The weighted aggregation unit, connected to the parameter accuracy evaluation unit, is used to assign α to each model according to its accuracy. i Aggregate weight Y i and aggregate α i Obtain the parameters of the second blinding model
[0142] The parameter and weight encryption unit, connected to the weighted aggregation unit, is used to encrypt the parameters β and aggregate weights Y of the second blinded model. i Based on each public key PK j =pk i Encryption to obtain parameters of the second blind encryption model and encrypted aggregate weight
[0143] Among them, pk i It is client C i It is generated based on the public parameter PP sent by the second server, and the master key mk of the second server has a pair with pk. i The ability to decrypt encrypted data.
[0144] In one embodiment, the receiving module 21 is specifically used for:
[0145] Receive n first blind encryption model parameters from the first server PK with the corresponding n public keys i n The first server receives data from n clients C participating in federated learning. i PK based on their respective public keys i The n first encryption model parameters are encrypted. PK with n public keys i Generate n random numbers τ i Random number τ i obey A uniform distribution is given for each random number τ. i Use the corresponding PK i Encrypt to obtain n encrypted random numbers Will With the corresponding Obtained by performing the first addition and multiplication operations with completely homomorphic properties, where ω i Indicates client C i Using local data D i The parameters of the local model generated during training.
[0146] In one implementation, the first server for each γ j Remove the corresponding values using fully homomorphic operations respectively To obtain the parameters of each second encryption model Specifically include:
[0147] The first server will distribute each γ j Each with the corresponding Perform a fully homomorphic operation on the second addition and multiplication, which are the inverses of the first addition and multiplication, to obtain n second encryption model parameters.
[0148] Example 5:
[0149] Embodiment 5 of this application provides a computer-readable storage medium storing a computer program. When the computer program is run by a processor, it implements the federated learning data privacy protection method as described in Embodiment 1 or 2, or the federated learning data privacy protection device as described in Embodiment 3 or 4.
[0150] The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, computer program units, or other data). Computer-readable storage media include, but are not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory or other memory technologies, CD-ROM (Compact Disc Read-Only Memory), DVD or other optical disc storage, cartridges, magnetic tapes, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer.
[0151] Additionally, this application may provide a computer device including a memory and a processor, wherein the memory stores a computer program, and when the processor runs the computer program stored in the memory, the processor executes the federated learning data privacy protection method as described in Embodiment 1 or 2. This computer device may be a federated learning data privacy protection device as described in Embodiment 3 or 4.
[0152] The memory is connected to the processor. The memory can be flash memory, read-only memory or other types of memory. The processor can be a central processing unit or a microcontroller.
[0153] Embodiments 1-5 of this application provide a method, apparatus, and medium for protecting data privacy in federated learning. During model aggregation, different weights are selected to address the data imbalance problem among clients. Dual servers are integrated for blinding / deblinding and encryption / decryption processing, ensuring that no single server can obtain completely accurate client data. Simultaneously, the influence of weights on the blinding factor is eliminated during the deblinding process, allowing clients to obtain accurate global model parameters. All transmitted data is encrypted. Server computation is based on fully homomorphic operations, which directly operate on ciphertext without decryption, and the result remains encrypted, identical to the result of the same operation on plaintext, thus guaranteeing the aggregation effect and data security of federated learning.
[0154] It is understood that the above embodiments are merely exemplary implementations used to illustrate the principles of this application, and this application is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and substance of this application, and these modifications and improvements are also considered to be within the scope of protection of this application.
Claims
1. A method for protecting data privacy in federated learning, characterized in that, The method is applied to a first server and includes: The system receives first encryption model parameters encrypted with each public key from multiple clients participating in federated learning. It assigns each blinding factor to each first encryption model parameter based on the fully homomorphic operation of each public key and blinds it to obtain first blinded encryption model parameters. It sends the first blinded encryption model parameters to a second server, which decrypts each first blinded encryption model parameter to obtain the first blinded model parameters. It assigns each aggregation weight to each first blinded model parameter and aggregates them to obtain second blinded model parameters. It encrypts the second blinded model parameters and each aggregation weight based on each public key to obtain second blinded encryption model parameters and encrypted aggregation weights. The system receives the second blinded encryption model parameters and encryption aggregation weights from the second server. Based on the encryption aggregation weights and each blinding factor, it performs a fully homomorphic operation on the second blinded encryption model parameters using each public key to obtain the second encryption model parameters. The system then sends the second encryption model parameters to each client, enabling each client to decrypt the second encryption model parameters to obtain the aggregation model parameters.
2. The method according to claim 1, characterized in that, The system receives the second blinded encryption model parameters and encryption aggregation weights from the second server. Based on the encryption aggregation weights and each blinding factor, it performs a fully homomorphic operation on the second blinded encryption model parameters using each public key to obtain the second encryption model parameters. These parameters are then sent to each client, enabling each client to decrypt them and obtain the aggregation model parameters. Specifically, this includes: Receive public key-based PK data from the second server j Second blind encryption model parameters and encrypted aggregate weight and the corresponding PK j Where Enc represents an encryption algorithm that satisfies multi-key fully homomorphic operations, β is the second blinding model parameter, and Y... i These are the aggregation weights, i = (1…n) corresponding to the n clients C participating in federated learning. i , pk j It is each client C i The public key, i = j; Use each PK j Encrypt each blinding factor τ i get Calculation based on each pk j Encryption-weighted average blinding factor For each γ j Remove the corresponding values using fully homomorphic operations respectively To obtain the parameters of each second encryption model Will Based on i = j, send the corresponding client C. i This enables each client C i Each uses its own PK i =pk j corresponding private key decryption Obtain the aggregation model parameters ω fed .
3. The method according to claim 2, characterized in that, The first blinded encryption model parameters are sent to the second server, which then decrypts each parameter to obtain the first blinded model parameters. The second server assigns aggregate weights to each parameter and aggregates them to obtain the second blinded model parameters. Finally, the second blinded model parameters and aggregate weights are encrypted using public keys to obtain the second blinded encryption model parameters and encrypted aggregate weights. Specifically, this includes: n parameters of the first blind encryption model PK with the corresponding n public keys i Send it to the second server so that the second server can decrypt each item using the master key mk and the master key decryption algorithm mDec. Obtain the parameters of the first blinding model According to each α i The input data in the validation set is used to obtain the output results. The stability of each α is evaluated based on the error between the output results and the actual results in the validation set. i The model accuracy is determined, and each α is assigned according to the accuracy of each model. i Aggregate weight Y i and aggregate α i Obtain the parameters of the second blinding model For the second blinded model parameters β and each aggregate weight Y i Based on each public key PK j =pk i Encryption to obtain parameters of the second blind encryption model and encrypted aggregate weight Among them, pk i It is client C i It is generated based on the public parameter PP sent by the second server, and the master key mk of the second server has a pair with pk. i The ability to decrypt encrypted data.
4. The method according to claim 3, characterized in that, The system receives first encryption model parameters encrypted with each public key from multiple clients participating in federated learning. It then assigns blinding factors to each first encryption model parameter through a fully homomorphic operation based on each public key and blinds the parameters to obtain the first blinded encryption model parameters. Specifically, this includes: Receive data from n clients C participating in federated learning. i PK based on their respective public keys i The n first encryption model parameters are encrypted. PK with n public keys i , where ω i Indicates client C i Using local data D i Local model parameters generated during training; Generate n random numbers τ i Random number τ i obey A uniform distribution is given for each random number τ. i Use the corresponding PK i Obtain n encrypted random numbers Will With the corresponding Perform fully homomorphic operations on the first addition and multiplication to obtain n parameters for the first blind encryption model.
5. The method according to claim 4, characterized in that, For each γ j Remove the corresponding values using fully homomorphic operations respectively To obtain the parameters of each second encryption model Specifically include: Each γ j Each with the corresponding Perform a fully homomorphic operation on the second addition and multiplication, which are the inverses of the first addition and multiplication, to obtain n second encryption model parameters.
6. A method for protecting data privacy in federated learning, characterized in that, The method is applied to a second server and includes: The first blinded encryption model parameter is received from the first server. The first blinded encryption model parameter is obtained by the first server receiving the first encryption model parameter based on each public key from multiple clients participating in federated learning, assigning each blinding factor to each first encryption model parameter based on each public key and blinding it. Decrypt each first blinded encryption model parameter to obtain the first blinded model parameters, assign each first blinded model parameter to an aggregation weight and aggregate them to obtain the second blinded model parameters, and encrypt the second blinded model parameters and each aggregation weight based on each public key to obtain the second blinded encryption model parameters and encrypted aggregation weights; The second blinding encryption model parameters and encryption aggregation weights are sent to the first server, which then performs a fully homomorphic operation on the second blinding encryption model parameters based on the encryption aggregation weights and each blinding factor using each public key to obtain the second encryption model parameters. The second encryption model parameters are then sent to each client, which decrypts the second encryption model parameters to obtain the aggregation model parameters.
7. The method according to claim 6, characterized in that, The second blinded encryption model parameters and the encryption aggregation weights are sent to the first server. The first server then performs a fully homomorphic operation on the second blinded encryption model parameters based on the encryption aggregation weights and each blinding factor using each public key to obtain the second encryption model parameters. These second encryption model parameters are then sent to each client, allowing each client to decrypt them to obtain the aggregation model parameters. Specifically, this includes: PK based on each public key j Second blind encryption model parameters and encrypted aggregate weight and the corresponding PK j Send to the first server, where Enc represents the encryption algorithm that satisfies multi-key fully homomorphic operations, β is the second blinding model parameter, and Y... i These are the aggregation weights, i = (1…n) corresponding to the n clients C participating in federated learning. i , pk j It is each client C i The public key, i = j, is used to enable the first server to use each pk. j Encrypt each blinding factor τ i get Calculation based on each pk j Encryption-weighted average blinding factor For each γ j Remove the corresponding values using fully homomorphic operations respectively To obtain the parameters of each second encryption model Will Based on i = j, send the corresponding client C. i This enables each client C i Each uses its own PK i =pk j corresponding private key decryption Obtain the aggregation model parameters ω fed .
8. The method according to claim 7, characterized in that, Decrypting each first blinded encryption model parameter yields the first blinded model parameters. Assigning aggregation weights to each first blinded model parameter and aggregating them yields the second blinded model parameters. Encrypting the second blinded model parameters and aggregation weights based on public keys yields the second blinded encryption model parameters and encrypted aggregation weights. Specifically, this includes: The parameters of each first blind encryption model are decrypted using the master key mk and the master key decryption algorithm mDec. Obtain the parameters of the first blinding model According to each α i The output results are obtained by calculating the input data in the validation set. The stability of each α is evaluated based on the error between the output results and the actual results in the validation set. i Model accuracy; Each α is assigned according to the accuracy of each model. i Aggregate weight Y i and aggregate α i Obtain the parameters of the second blinding model For the second blinded model parameters β and each aggregate weight Y i Based on each public key PK j =pk i Encryption to obtain parameters of the second blind encryption model and encrypted aggregate weight Among them, pk i It is client C i It is generated based on the public parameter PP sent by the second server, and the master key mk of the second server has a pair with pk. i The ability to decrypt encrypted data.
9. The method according to claim 8, characterized in that, The system receives first blinded encryption model parameters from the first server. These parameters are obtained by the first server receiving first encryption model parameters encrypted with each public key from multiple clients participating in federated learning, assigning blinding factors to each first encryption model parameter based on a fully homomorphic operation of each public key, and then blinding them. Specifically, these parameters include: Receive n first blind encryption model parameters from the first server PK with the corresponding n public keys i n The first server receives data from n clients C participating in federated learning. i PK based on their respective public keys i The n first encryption model parameters are encrypted. PK with n public keys i Generate n random numbers τ i Random number τ i obey A uniform distribution is given for each random number τ. i Use the corresponding PK i Obtain n encrypted random numbers Will With the corresponding Obtained by performing the first addition and multiplication operations with completely homomorphic properties, where ω i Indicates client C i Using local data D i The parameters of the local model generated during training.
10. The method according to claim 9, characterized in that, The first server for each γ j Remove the corresponding values using fully homomorphic operations respectively To obtain the parameters of each second encryption model Specifically include: The first server will distribute each γ j Each with the corresponding Perform a fully homomorphic operation on the second addition and multiplication, which are the inverses of the first addition and multiplication, to obtain n second encryption model parameters.
11. A federated learning data privacy protection device, characterized in that, The device is a first server and includes: The blinding module is used to receive first encryption model parameters encrypted with each public key from multiple clients participating in federated learning, assign blinding factors to each first encryption model parameter based on the fully homomorphic operation of each public key and blind it to obtain first blinded encryption model parameters, send the first blinded encryption model parameters to the second server, and enable the second server to decrypt each first blinded encryption model parameter to obtain the first blinded model parameters, assign each first blinded model parameter with each aggregation weight and aggregate to obtain second blinded model parameters, and encrypt the second blinded model parameters and each aggregation weight based on each public key to obtain second blinded encryption model parameters and encrypted aggregation weights; The deblinding module, connected to the blinding module, receives the second blinding encryption model parameters and encryption aggregation weights from the second server. Based on the encryption aggregation weights and each blinding factor, it performs a fully homomorphic operation on the second blinding encryption model parameters using each public key to obtain the second encryption model parameters. The second encryption model parameters are then sent to each client, enabling each client to decrypt the second encryption model parameters to obtain the aggregation model parameters.
12. A federated learning data privacy protection device, characterized in that, The device is a second server and includes: The receiving module is used to receive the first blinded encryption model parameters from the first server. The first blinded encryption model parameters are obtained by the first server receiving the first encryption model parameters encrypted based on each public key from multiple clients participating in federated learning, assigning each blinding factor to each first encryption model parameter based on the fully homomorphic operation of each public key, and then blinding them. The aggregation module, connected to the receiving module, is used to decrypt each first blinded encryption model parameter to obtain the first blinded model parameter, assign each first blinded model parameter to an aggregation weight and aggregate them to obtain the second blinded model parameter, and encrypt the second blinded model parameter and each aggregation weight based on each public key to obtain the second blinded encryption model parameter and encrypted aggregation weight. The sending module, connected to the aggregation module, is used to send the second blinded encryption model parameters and the encryption aggregation weight to the first server. The first server then performs a fully homomorphic operation on the second blinded encryption model parameters based on the encryption aggregation weight and each blinding factor using each public key to obtain the second encryption model parameters. The second encryption model parameters are then sent to each client, allowing each client to decrypt the second encryption model parameters to obtain the aggregation model parameters.
13. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the federated learning data privacy protection method as described in any one of claims 1-5 or 6-10.