Secure aggregation processing system for cross-domain model parameters based on federated learning
By employing decentralized identity and reputation management, dynamic aggregation node election, verifiable proof generation, and distributed consistent ledger verification, this approach addresses the trust bottleneck and compliance issues in existing federated learning technologies. It achieves secure and efficient cross-domain model parameter aggregation, thereby enhancing the system's anti-attack capabilities and model performance.
Patent Information
- Application Number
- CN202511168653.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-20
- Publication Date
- 2025-11-11
AI Technical Summary
Existing federated learning technologies rely on centralized servers, which pose trust bottlenecks and single points of failure risks. The computational integrity of the aggregation process is difficult to verify, the compliance of parameters submitted by participants cannot be effectively verified, and model performance is affected when there are significant differences in data distribution. Furthermore, there is a lack of effective defense mechanisms and dynamic incentive mechanisms.
A decentralized identity and reputation management module is used to register digital identities and multi-dimensional reputation scores for participating nodes, dynamically elect aggregation nodes, generate verifiable proof packages through local secure processing, verify model parameter updates using a distributed consistent ledger, configure a trusted adaptive aggregation module for secure aggregation, and implement a reputation feedback mechanism.
It achieves secure aggregation of model parameters while protecting privacy, enhances the system's trustworthiness and anti-attack capabilities, improves the overall performance and collaboration efficiency of the model, and dynamically adjusts the reputation scores of participants to promote high-quality collaboration.
Smart Images

Figure CN120934736A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of artificial intelligence and data security, specifically to a cross-domain model parameter secure aggregation processing system based on federated learning. Background Technology
[0002] In industries driven by modern information technology, such as financial risk control, medical diagnosis, and autonomous driving, the performance of artificial intelligence models largely depends on the scale and diversity of the training data they use. However, due to privacy regulations, data security rules, and competitive business relationships, data from different institutions often exists in silos, unable to be directly aggregated and shared. This creates a core contradiction: on the one hand, there is an urgent need for large-scale, multi-dimensional data; on the other hand, there are real barriers preventing the free flow of data. Therefore, the market urgently needs a technological solution that can break down data silos and achieve multi-party data value synergy while ensuring the data rights and privacy security of all parties.
[0003] To address this challenge, federated learning technology has emerged. Current mainstream federated learning solutions employ a centralized aggregation architecture, with a central server coordinating multiple participating nodes. This architecture allows each participant to participate in the joint training of a global model without sending their local raw data, simply by uploading intermediate training results (such as model parameter updates). This approach technically separates model training from raw data storage, providing a fundamental and feasible path for collaborative machine learning while protecting data privacy.
[0004] Currently, the basic framework of federated learning is relatively mature, with FedAvg and its variants becoming the standard paradigm, supported by open-source platforms such as TensorFlow Federated and FATE. However, communication bottlenecks, device and data heterogeneity, and convergence optimization under Non-IID data remain prominent challenges. Cross-domain collaboration mechanisms are developing rapidly, with domain adaptation technologies, game theory or blockchain incentive mechanisms, and related standardized protocols (such as IEEE P3652.1) gradually advancing. However, they are limited by the lack of trust across organizations, the complexity of compliance with regulations such as GDPR, and the challenges of dynamic resource scheduling. Secure aggregation is a core breakthrough direction. In terms of encryption technology, homomorphic encryption (such as Paillier), secure multi-party computation (such as secret sharing), and hybrid schemes are widely used. Differential privacy achieves privacy protection through localized and centralized noise addition, and trusted execution environments (such as Intel SGX) rely on hardware isolation to execute aggregation. However, these three approaches face problems such as excessive computational overhead, privacy-utility trade-offs, hardware dependence, and side-channel vulnerabilities. Cutting-edge trends focus on lightweight security solutions (such as parameter compression and efficient zero-knowledge proofs), anti-malicious attack technologies (such as Byzantine robust aggregation and verifiable computation), cross-chain and blockchain integration, large-scale model federated training (such as PEFT technology), and AI-driven dynamic defense. Industrial applications have already been implemented in fields such as healthcare, finance, and the Internet of Things, relying on technologies like HE / TEE and DP+MPC to meet compliance requirements. However, these applications are limited by insufficient resources for small and medium-sized institutions and unclear cross-domain legal jurisdiction.
[0005] Overall, the framework is relatively mature, but it is constrained by communication and optimization. The maturity of cross-domain collaboration and secure aggregation needs to be improved. The core bottlenecks are concentrated in the triangular contradiction of efficiency-security-utility, cross-domain trust and compliance obstacles, and cost and ecosystem issues for industrial implementation. Future breakthroughs need to focus on collaborative innovation in algorithms, architecture, hardware and standards layers.
[0006] The practical application of existing technologies has revealed their inherent shortcomings in handling complex collaborative scenarios. First, their reliance on centralized aggregation servers constitutes a systemic trust bottleneck and a single point of failure risk. In cross-institutional collaborations lacking a natural foundation of trust, it is difficult for any party to act as the central server, which fundamentally restricts the formation of the federation. Second, the aggregation server lacks effective verification methods for model updates submitted by each participant. It cannot audit the update calculation process, which provides an opportunity for malicious nodes to submit constructed parameters to disrupt the global model. The system lacks an effective defense mechanism against such internal attacks. Finally, existing technologies generally use fixed aggregation algorithms. When there are significant differences in the data distribution among the participants, the model performance will be affected. At the same time, the system lacks a governance mechanism that can dynamically link the historical behavior of nodes with their future rights in the federation, which is not conducive to incentivizing high-quality long-term collaboration. Summary of the Invention
[0007] This invention is made to solve the above-mentioned problems and aims to provide a cross-domain model parameter secure aggregation processing system based on federated learning. It solves the problems of existing federated learning technology solutions in the model parameter aggregation process, such as reliance on a fixed centralized server, difficulty in verifying the computational integrity of the aggregation process by the participants, and inability to effectively verify the compliance of the parameters submitted by the participants while protecting privacy.
[0008] This invention provides a secure cross-domain model parameter aggregation processing system based on federated learning, characterized by: a decentralized identity and reputation management module, used to register digital identities for multiple participating nodes accessing the system and initialize corresponding multi-dimensional reputation scores, and record the digital identities, associated public keys, and multi-dimensional reputation scores in a distributed consistent ledger; a dynamic aggregation node election module, connected to the decentralized identity and reputation management module, used to elect a dynamic aggregation node from candidate nodes with a trusted execution environment based on the multi-dimensional reputation scores at the beginning of each training round; and a local security processing and proof generation module, configured on each participating node, used to perform local model training to generate model parameter updates after obtaining the identity of the dynamically aggregated node elected in this round, encrypt the model parameter updates using the public key of the dynamic aggregation node, and generate a verifiable proof package, which at least contains information for... The system includes: a proof of compliance for the computation process and data metadata; an encrypted transmission and on-chain verification module, used to send encrypted model parameter updates to the dynamic aggregation node and submit verifiable proof packages to the distributed consensus ledger, where the consensus mechanism verifies the validity of the verifiable proof packages to confirm legitimate contributions; a trusted adaptive aggregation and execution proof module, configured in the trusted execution environment of the dynamic aggregation node, used to perform secure aggregation operations based on the legitimate contributions confirmed by the distributed consensus ledger, generating a new global model, and generating an execution proof recording specific information about the aggregation process after the aggregation task is completed; and a global state update and reputation feedback module, used to record the execution proof in the distributed consensus ledger and update the multi-dimensional reputation scores of multiple participating nodes based on the execution proof and the verification results of legitimate contributions, thereby completing the closed loop of one round of processing. The updated reputation scores are used for the next round of dynamic aggregation node election.
[0009] The cross-domain model parameter secure aggregation processing system based on federated learning provided by this invention may also have the following features: the specific steps of the decentralized identity and reputation management module to initialize the multidimensional reputation score include: setting two independent sub-items, contribution reputation and aggregate reputation, for each participating node; and combining the values of contribution reputation and aggregate reputation into a multidimensional reputation score through a preset weighted summation formula.
[0010] The cross-domain model parameter secure aggregation processing system based on federated learning provided by this invention may also have the following feature: the specific steps for the dynamic aggregation node election module to elect dynamic aggregation nodes include: reading the latest multidimensional reputation scores of all candidate nodes from the distributed consistent ledger; executing a weighted random election algorithm; and recording the identity identifiers of the dynamic aggregation nodes output by the election algorithm in the distributed consistent ledger. The probability of each candidate node being selected is proportional to the value of its multidimensional reputation score.
[0011] The cross-domain model parameter secure aggregation processing system based on federated learning provided by this invention may also have the following features: the specific steps of the local security processing and proof generation module in generating a verifiable proof package include: performing local model training to obtain model parameter updates; generating a computational integrity proof, which is used to verify that the computation process of model parameter updates conforms to a preset training protocol and that its data norm is within a preset numerical range; generating a verifiable metadata proof, which is used to verify the authenticity of statistical metadata extracted from local data; and finally encapsulating the computational integrity proof and the verifiable metadata proof to form a verifiable proof package.
[0012] The cross-domain model parameter secure aggregation processing system based on federated learning provided by this invention may also have the following features: the specific steps for generating verifiable metadata proof include: extracting at least one of the data magnitude, category distribution, or gradient sparsity from the local dataset as statistical metadata; and using zero-knowledge proof technology to generate a proof that can confirm that the statistical metadata was generated from the local dataset, but does not disclose the specific value of the statistical metadata or the content of the local dataset.
[0013] The cross-domain model parameter secure aggregation processing system based on federated learning provided by this invention may also have the following features: the specific steps of consensus verification by the encrypted transmission and on-chain verification module include: submitting the verifiable proof package to the distributed consensus ledger; obtaining the verifiable proof package by the consensus node in the distributed consensus ledger network, and performing verification algorithms on the computational integrity proof and the verifiable metadata proof contained therein; and determining that the submission in which both proofs are verified is a legitimate contribution.
[0014] The cross-domain model parameter secure aggregation processing system based on federated learning provided by this invention may also have the following features: the specific steps of the trusted adaptive aggregation and execution proof module in generating a new global model and execution proof include: the trusted execution environment of the dynamic aggregation node generates and broadcasts its remote proof report to all participating nodes; after receiving the verification pass signal of the remote proof report from each participating node, it receives and decrypts all encrypted model parameter updates within the trusted execution environment; then, based on the statistical metadata contained in all legitimate contributions and recorded in the distributed consistency ledger, it dynamically selects an aggregation function from a preset aggregation function policy library; then, it uses the selected aggregation function to calculate all decrypted model parameter updates to generate a new global model; after the aggregation calculation is completed, it generates an execution proof signed by the hardware key of the trusted execution environment, which at least records the number of legitimate contributions processed in this aggregation task, the identifier of the selected aggregation function, and the computation time.
[0015] The cross-domain model parameter secure aggregation processing system based on federated learning provided by this invention may also have the following features: the specific steps of dynamically selecting aggregation functions from a preset policy library include: an aggregation policy arbitration engine configured in a trusted execution environment obtains statistical metadata of all legitimate contributions from a distributed consistent ledger; the aggregation policy arbitration engine performs a global distribution analysis on all obtained statistical metadata; and the aggregation policy arbitration engine matches and selects aggregation functions from the policy library based on the analysis results of the global distribution.
[0016] The cross-domain model parameter secure aggregation processing system based on federated learning provided by this invention may also have the following features: the specific steps for the global state update and reputation feedback module to update the multi-dimensional reputation score include: submitting the execution proof to the distributed consensus ledger; increasing the value of the contribution reputation sub-item of all participating nodes that have made legitimate contributions based on the verification results of legitimate contributions; and adjusting the value of the aggregation reputation sub-item of the current round of dynamic aggregation nodes based on the aggregation task performance index recorded in the execution proof.
[0017] The cross-domain model parameter secure aggregation processing system based on federated learning provided by this invention may also have the following features: the specific steps of updating the aggregation reputation of the dynamic aggregation node according to the aggregation task performance indicators recorded in the execution proof include: the reputation smart contract deployed on the distributed consistent ledger automatically parses the received execution proof; the reputation smart contract extracts quantitative indicators related to aggregation efficiency and stability from the execution proof; and the reputation smart contract increases or decreases the value of the aggregation reputation sub-item of the dynamic aggregation node according to the quantitative indicators and through preset calculation rules. Attached Figure Description
[0018] Figure 1 This is a structural block diagram of the cross-domain model parameter secure aggregation processing system based on federated learning in an embodiment of the present invention;
[0019] Figure 2 This is a schematic diagram of the workflow of the local security processing and proof generation module in an embodiment of the present invention;
[0020] Figure 3 This is a schematic diagram of the workflow of the trusted adaptive aggregation and execution proof module in an embodiment of the present invention. Detailed Implementation
[0021] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0022] This embodiment provides a cross-domain model parameter secure aggregation processing system based on federated learning.
[0023] Figure 1 This is a structural block diagram of the cross-domain model parameter secure aggregation processing system based on federated learning in an embodiment of the present invention.
[0024] like Figure 1 As shown, the cross-domain model parameter secure aggregation processing system based on federated learning in this embodiment includes a decentralized identity and reputation management module 10, a dynamic aggregation node election module 20, a local secure processing and proof generation module 30, an encrypted transmission and on-chain verification module 40, a trusted adaptive aggregation and proof execution module 50, and a global state update and reputation feedback module 60. These modules interact with data and synchronize states through a distributed consistent ledger.
[0025] The decentralized identity and reputation management module 10 is used to register unique digital identities and public keys for asymmetric encryption for multiple participating nodes requesting to join federated learning. If a participating node declares it has a Trusted Execution Environment (TEE), this module also verifies its hardware identity verification. After registration, the module initializes a multidimensional reputation score for each participating node and records the node's identity, public key, and reputation score in a distributed consistent ledger. The specific implementation process is as follows:
[0026] The decentralized identity and reputation management module 10 is a fundamental component of the entire system. Its functionality is implemented through a set of smart contracts deployed on a distributed consistent ledger. This module is responsible for the identity authentication and registration of new participating nodes, and for establishing and maintaining a continuously updated multi-dimensional reputation score for all registered nodes.
[0027] When an external participating node requests to join the federation, it needs to interact with the decentralized identity and reputation management module 10 to complete the registration. This registration process includes the following steps: First, the participating node submits an ID containing its unique identifier to the distributed consistent ledger. i and the public key PK used for subsequent communication encryption i The registration transaction. Secondly, if the participating node is configured with a Trusted Execution Environment (TEE), it also needs to attach a verifiable TEE identity certificate issued by the hardware manufacturer to the transaction.
[0028] Upon receiving the registration transaction, the registration management smart contract within the decentralized identity and reputation management module 10 automatically executes the verification process. The verification process checks the submitted ID. i Check if it already exists in the ledger and verify the submitted public key PK. i The format is specified. For transactions with accompanying TEE identity verification, the verification process also checks the validity of that verification. Upon successful verification, the smart contract creates a new data entry on the distributed consistent ledger, which must contain at least an ID. i PK i And a Boolean TEE eligibility flag. Nodes with a true TEE eligibility flag have the ID... i It will be automatically added to a Dynamic Aggregator Node (DAN) candidate pool C.
[0029] The core function of the decentralized identity and reputation management module 10 is to establish and maintain a multi-dimensional reputation score system. This system aims to quantitatively evaluate the historical behavior of each participating node. For each registered participating node P... i Its multidimensional reputation score at the end of the t-th round of training It is calculated using the following formula:
[0030]
[0031] In the formula, Representative node P i Total reputation score at the end of round t; This score represents the credibility of their contributions and is used to quantify the reliability of their participation in training as a client and the submission of legitimate contributions. This score represents the node's aggregate reputation and is used to quantify its efficiency and stability in performing aggregation tasks as a dynamic aggregation node. For nodes without a configured TEE, this score is always zero. α and β are non-negative weighted hyperparameters preset in the reputation management smart contract, and their sum is 1. These two parameters are used to adjust the relative importance of contribution behavior and aggregation behavior in the overall reputation score assessment.
[0032] When a node successfully registers for the first time, i.e., at t=0, the decentralized identity and reputation management module 10 initializes its reputation score. Its initial contribution reputation... With initial aggregate reputation It is set to a predefined, non-zero global initial value. This ensures that newly added nodes with TEE eligibility also have an initial probability of being selected by the dynamic aggregation node election module 20. All subsequent updates to the reputation score are triggered by the global state update and reputation feedback module 60, while the decentralized identity and reputation management module 10 is only responsible for providing secure storage and query interfaces.
[0033] The dynamic aggregation node election module 20 is activated at the start of each round of federated learning training. This module obtains the latest multi-dimensional reputation scores of all candidate nodes with trusted execution environments from the distributed consistent ledger. Based on the obtained reputation scores, the dynamic aggregation node election module 20 executes a preset weighted election algorithm to elect a dynamic aggregation node and outputs its identity identifier to the distributed consistent ledger for querying by all participating nodes. Its specific implementation process is as follows:
[0034] The dynamic aggregation node election module 20 is implemented by a set of election smart contracts deployed on a distributed consistent ledger. This module is automatically triggered when each round of federated learning training task starts, and its core function is to elect a node as the dynamic aggregation node for this round based on the real-time reputation status of each candidate node.
[0035] In this embodiment, the election process is initiated by a scheduling smart contract. Once the scheduling contract detects that the state of the previous training task has been marked as completed by the global state update and reputation feedback module 60, it automatically calls the election function of this module 20, thereby starting a new round of election.
[0036] After the election process begins, the dynamic aggregation node election module 20 first reads the current list of the dynamic aggregation node candidate pool C from the distributed consistent ledger, and then queries each candidate node P in the pool. j The latest multidimensional reputation score of ∈C recorded by the decentralized identity and reputation management module 10 at the end of the previous round (i.e., round t-1).
[0037] After obtaining the reputation scores of all candidate nodes, the dynamic aggregation node election module 20 executes a reputation-based weighted random election algorithm. Based on this algorithm, candidate node P... i The probability of being selected as a dynamic aggregation node in round t Defined as:
[0038]
[0039] In the formula, Representative candidate node P i The probability of being selected in round t; Representative candidate node P i Total credit score at the end of the previous round; This represents the sum of the total reputation scores of all candidate nodes in the dynamic aggregation node candidate pool C at the end of the previous round.
[0040] To implement this weighted random election on a distributed consistent ledger, the election smart contract within the dynamic aggregation node election module 20 executes the following steps: First, it calculates the sum of the reputation scores R of all candidate nodes. total Secondly, generate a value in the interval [0, R]. total A pseudo-random number is generated within this interval. The seed for this pseudo-random number comes from the block hash of this round or other consensus-based on-chain information to ensure the determinism and reproducibility of the election process. Finally, the reputation scores of all candidate nodes are arranged into consecutive sub-intervals within this interval. The candidate node whose sub-interval the pseudo-random number falls into is selected as the dynamic aggregation node for this round.
[0041] After the election results are determined, the dynamic aggregation node election module 20 will assign the identity ID of the elected dynamic aggregation node. DAN The state variable, dedicated to recording the state of this round, is written to the distributed consistent ledger. This write operation is recorded as a transaction and is agreed upon and recorded across the entire network, thus enabling the public broadcast of the election results. All participating nodes can query this state variable to obtain the identity of the node that performed the aggregation task in this round and its public key.
[0042] A local security processing and proof generation module 30 is configured on each participating node. After obtaining the identity and public key of the dynamic aggregation node in this round, the local security processing and proof generation module 30 uses its local data to train the model and generate model parameter updates. Subsequently, the local security processing and proof generation module 30 uses the obtained public key to encrypt the model parameter updates and generates a verifiable proof package. This proof package contains cryptographic proofs used to verify the compliance of the local computation process and the authenticity of the local data metadata.
[0043] Figure 2This is a schematic diagram of the workflow of the local security processing and proof generation module in an embodiment of the present invention.
[0044] like Figure 2 As shown, the local security processing and proof generation module 30 is implemented in the local computing environment of each participating node. This module is activated upon receiving the identity of the dynamic aggregation node in this round. Its main function is to perform local model training and generate an output containing encrypted model updates and a verifiable proof package for the training results.
[0045] In this embodiment, the workflow of the local security processing and proof generation module 30 includes the following steps:
[0046] First, the local security processing and proof generation module 30 obtains the global model W from the distributed consistent ledger at the end of the previous training round. t-1 And the public key PK of the dynamic aggregation node elected in this round. DAN .
[0047] Secondly, the local security processing and proof generation module 30 calls the local private dataset D. i In the global model W t-1 Based on this, a preset training algorithm (one or more epochs of stochastic gradient descent) is executed to obtain an updated local model W. local Model parameter update amount Then by calculating W local With W t-1 The difference is achievable.
[0048] Then, the local security processing and proof generation module 30 generates a verifiable proof package for the output of this training. This proof package is constructed using a zero-knowledge proof system (zk-SNARKs in this embodiment) and contains two core parts: a computational integrity proof Π comp,i and a verifiable metadata certificate Π meta,i .
[0049] Then, compute the integrity proof Π comp,i The generation of this data aims to confirm two facts to the outside world: firstly, the model parameters are updated. It follows a predetermined training protocol and is based on a private dataset D. i and the publicly available global model W t-1 The calculation is as follows: First, to prevent gradient attacks, the L2 norm of the update does not exceed a globally set threshold τ. The local security processing and proof generation module 30 generates a zero-knowledge proof for the following publicly disclosed computational statement without exposing private data D. i :
[0050]
[0051] In the formula, Train(·) represents the preset training function.
[0052] Verifiable metadata proof Π meta,i The generation aims to provide data features useful for subsequent adaptive aggregation in a privacy-preserving manner. The local security processing and proof generation module 30 first generates data from the local dataset D. i Extract a set of statistical metadata M i In this embodiment, M i It can be a value containing the size of the data |D i | and a hash commitment of the vector of the number of samples in each category in the dataset. Subsequently, the local security processing and proof generation module 30 generates a proof for the following statement, confirming M. i The computation source is a private dataset D. i :
[0053]
[0054] In the formula, ExtractMetadata(·) represents the preset metadata extraction function.
[0055] Finally, the local security processing and proof generation module 30 uses the obtained public key pk of the dynamic aggregation node. DAN Updating model parameters for plaintext Perform encryption to generate ciphertext. In this embodiment, a hybrid encryption scheme is used to improve efficiency, namely, generating a one-time symmetric session key pair. Encrypt it, then use PK. DAN Encrypt the session key.
[0056] After completing all the above steps, the local security processing and proof generation module 30 will update the encrypted model. and by Π comp,i Π meta,i and metadata M i The verifiable proof package, as its final output, is passed to the encrypted transmission and on-chain verification module 40 for further processing.
[0057] The encrypted transmission and on-chain verification module 40 is responsible for processing the data output by the local security processing and proof generation module 30. The encrypted transmission and on-chain verification module 40 sends the encrypted model parameter updates to the dynamic aggregation node of this round via a peer-to-peer communication channel. Simultaneously, the encrypted transmission and on-chain verification module 40 submits verifiable proof packages to the distributed consensus ledger. The consensus mechanism of the distributed consensus ledger verifies the validity of the proof packages; only submissions that pass verification are recognized as legitimate contributions to this round.
[0058] The encrypted transmission and on-chain verification module 40 is implemented jointly by the client software of the participating nodes and the verification smart contract deployed on the distributed consensus ledger. This module is responsible for the secure distribution and decentralized verification of the output of the local security processing and proof generation module 30. Its specific implementation process is as follows:
[0059] In this embodiment, the workflow of the encrypted transmission and on-chain verification module 40 is divided into two parallel paths: an off-chain data transmission path and an on-chain proof verification path.
[0060] For off-chain data transmission paths, the encrypted transmission and on-chain verification module 40 obtains the model parameter update ciphertext generated by the local security processing and proof generation module 30 and encrypted using the public key of the dynamic aggregation node. This module sends the encrypted data directly to the network address of the current dynamic aggregation node via a secure peer-to-peer network protocol. This path is specifically designed for transmitting large amounts of model parameters to avoid writing large amounts of data to the distributed consistent ledger, thereby ensuring the system's operational efficiency and economy.
[0061] For the on-chain proof verification path, the encrypted transmission and on-chain verification module 40 obtains the verifiable proof package generated by the local security processing and proof generation module 30. In this embodiment, the module constructs a commit transaction, the data fields of which include:
[0062] The identity ID of the participating node i Proof of computational integrity Π comp,i Verifiable metadata proof Π meta,i Public metadata M i And the hash value associated with the plaintext model parameter update for computational integrity proof.
[0063] The encrypted transmission and on-chain verification module 40 broadcasts the submission transaction to the distributed consensus ledger network. Before packaging the transaction into a new block, the consensus nodes in the network execute a verification smart contract deployed on the ledger. This verification smart contract contains the following verification logic:
[0064] First, the contract calls a pre-built zero-knowledge proof verification function to prove the computational integrity of the data contained in the transaction. comp,i Perform verification. The public inputs to this verification function include: the hash value H(W) of the previous round of the global model. t-1 ), global norm threshold τ, and hash values contained in the transaction.
[0065] Secondly, if the computational integrity proof verification passes, the contract continues to call the verification function to verify the verifiable metadata proof Π. meta,i Perform verification. The public input of this verification function is the metadata M contained in the transaction. i .
[0066] The submitted transaction is only considered valid if both of the above proofs pass verification. The verification smart contract will identify the participating node's identity ID. i and its submitted metadata M i Add it to an on-chain list dedicated to recording all legitimate contributions for this round. If any proof fails to verify, the transaction is marked as invalid, and its submission will be ignored in subsequent aggregation processes.
[0067] In this way, the encrypted transmission and on-chain verification module 40 ensures that only contributions from compliant participating nodes are accepted by the system, and provides the subsequent trusted adaptive aggregation and execution proof module 50 with an immutable trusted data source containing the identities and metadata of all legitimate contributors.
[0068] The Trusted Adaptive Aggregation and Execution Proof Module 50, configured on the dynamically selected aggregation node in this round, performs its core aggregation computation within the node's trusted execution environment. First, the Trusted Adaptive Aggregation and Execution Proof Module 50 generates and broadcasts its remote proof report for verification. Then, within the trusted execution environment, it decrypts all model parameter updates corresponding to legitimate contributions confirmed by the Encrypted Transmission and On-Chain Verification Module 40. The Trusted Adaptive Aggregation and Execution Proof Module 50 performs the aggregation computation, generating a new global model. Upon completion of the task, it generates an execution proof recording detailed information about the aggregation process.
[0069] Figure 3 This is a schematic diagram of the workflow of the trusted adaptive aggregation and execution proof module in an embodiment of the present invention.
[0070] like Figure 3 As shown, the Trusted Adaptive Aggregation and Execution Proof Module 50 is deployed on the selected dynamic aggregation node, and its core computational logic is executed in the isolated memory of the Trusted Execution Environment (TEE) configured on the node.
[0071] In this embodiment, the workflow of the trusted adaptive aggregation and execution proof module 50 in one aggregation round is as follows:
[0072] First, before the aggregation task begins, the trusted execution environment isolation memory of the trusted adaptive aggregation and execution proof module 50 is initialized. This isolation memory generates a remote proof report containing a hash digest of the running aggregation code, the hardware security identity information of the isolation memory, and is digitally signed by a hardware private key built into the isolation memory that cannot be accessed by external software. This remote proof report is published to the distributed consensus ledger for all participating nodes to download and verify. Only after verifying that the signature of the report and the code hash digest match the expected aggregation code will a participating node send a session key to the isolation memory to decrypt its model parameter updates.
[0073] Secondly, the trusted adaptive aggregation and execution proof module 50 securely obtains from the distributed consistent ledger the identity list S of all legitimate contributing nodes in this round, confirmed by the encrypted transmission and on-chain verification module 40. t and its corresponding metadata At the same time, it securely receives session keys from each participating node into encrypted memory in isolated memory.
[0074] Then, an aggregation strategy arbitration engine configured within isolated memory is activated. This engine processes the acquired global metadata. The analysis is performed. In this embodiment, the analysis includes calculating the variance of the data size of each participating node, or analyzing the Gini coefficient of the distribution of each node category. Based on the analysis results, the engine uses a pre-defined aggregation function library. In this process, a aggregation function is deterministically selected that best suits the current global data distribution characteristics. For example, if the analysis results show that the variance of the data volume of each participant is below a certain threshold, then the standard federated average algorithm is selected; if the analysis results show that there is a serious imbalance in the distribution of data categories, then an aggregation algorithm designed to correct the distribution bias is selected.
[0075] Next, the trusted adaptive aggregation and execution proof module 50, within isolated memory, uses the received session key to decrypt all valid model parameter update ciphertexts, obtaining the plaintext update set. Subsequently, the trusted adaptive aggregation and execution proof module 50 uses the aggregation function selected by the aggregation strategy arbitration engine. Combining the global model W from the previous round t-1 The new global model W for this round is calculated. t The calculation process is defined by the following formula:
[0076]
[0077] In the formula, W t W represents the newly generated global model in this round. t-1Represents the global model from the previous round; This represents the k-th aggregate function selected from the function library, whose inputs are the plaintext update set and the metadata set.
[0078] After the calculation is completed, the Trusted Adaptive Aggregation and Execution Proof Module 50 immediately executes the Secure Erasure Procedure to destroy all decrypted model parameter updates and session keys stored in the isolated memory.
[0079] Finally, the Trusted Adaptive Aggregation and Execution Proof Module 50 generates a Proof-of-Execution (PoE). This proof is a data structure containing a summary of the aggregation task, including: the number of participating nodes that successfully aggregated in this round |S t | The selected aggregation function identifier k, the total time spent on aggregation calculation, and the newly generated global model W t The hash value H(W) t The complete data structure for this execution proof is signed by a hardware private key in isolated memory.
[0080] The final output of the Trusted Adaptive Aggregation and Execution Proof Module 50 is the new global model W. t The storage address, and this signed execution certificate.
[0081] The global state update and reputation feedback module 60 is triggered after the trusted adaptive aggregation and execution proof module 50 completes its task. This module 60 submits the execution proof to the distributed consensus ledger for recording, and based on the execution proof and the verification results of the legitimate contributions in this round, calls the smart contract on the distributed consensus ledger to update the multi-dimensional reputation scores of each participating node. The updated reputation scores will be used as input by the dynamic aggregation node election module 20 in the next round of elections, thus forming a complete working loop. Its specific implementation process is as follows:
[0082] The global state update and reputation feedback module 60 is implemented by a set of reputation smart contracts deployed on a distributed consistent ledger. This module is activated upon receiving the execution proof generated by the trusted adaptive aggregation and execution proof module 50. It is responsible for completing the global state update for this round of federated learning and adjusting the multidimensional reputation scores of each node based on their actual behavior.
[0083] In this embodiment, when module 60 receives a signed Proof of Execution (PoE) submitted by a dynamic aggregation node, its internal reputation smart contract first executes a verification procedure. This procedure uses the public key registered by the dynamic aggregation node during registration to verify the digital signature of the PoE. Only PoEs with successful signature verification are accepted to ensure the authenticity of their origin and the integrity of their content.
[0084] After successful verification, module 60 performs a global state update. The contract extracts the hash value H(W) of the new global model from PoE. t This data is then written into a global state variable of the distributed consistent ledger, serving as the baseline model for the next round of training.
[0085] Next, module 60 executes the core logic of reputation feedback. This logic consists of two parts:
[0086] The first part pertains to all participating nodes that made legitimate contributions. The reputation smart contract reads the list S of legitimate contributions for this round from the ledger. t For each participating node P in the list... i ∈S t Its contribution to reputation C rep,i This will result in a fixed numerical increase. The update rule is defined by the following formula:
[0087]
[0088] In the formula, Representative node P i Contribution reputation after this round (round t); This represents its reputation for contribution in the previous round; δ c It is a constant reward value greater than zero that is preset in the contract.
[0089] For those not recorded in the list of legitimate contributions S t The contribution reputation of participating nodes remains unchanged in this round.
[0090] The second part concerns the dynamically aggregated node selected in this round (let's assume it's node P). j The reputation smart contract parses verified PoEs and extracts the aggregate task performance metrics recorded within them. Its aggregate reputation A rep,j The update rules are defined by the following formula:
[0091]
[0092] In the formula, Represents dynamic aggregation node P j Aggregated reputation after this round of updates; This represents its accumulated reputation in the previous round; It is a reward function whose calculation result depends on the performance metrics included in PoE.
[0093] In this embodiment, the output value of the function g(·) is positively correlated with the number of participating nodes in the PoE that successfully aggregated, and negatively correlated with the total time spent on the aggregate computation. This design allows nodes that perform aggregation tasks more efficiently and stably to receive higher aggregation reputation rewards. For other candidate nodes that were not selected as dynamic aggregation nodes, their aggregation reputation remains unchanged in this round.
[0094] After completing the update calculation of all credit scores, this module will calculate the new total credit score. The data is written back to the data entries on the distributed consistent ledger of each node. Finally, this module marks the status of this round of training task as completed, thereby providing a trigger signal for the dynamic aggregation node election module 20 to start the next round of election.
[0095] Taking a specific work scenario as an example, the specific workflow of the cross-domain model parameter security aggregation processing system based on federated learning in this embodiment is as follows:
[0096] In this embodiment, three medical institutions (labeled as nodes A, B, and C) collaborate to train a tumor-assisted diagnostic model using their own private, non-shared patient medical image data. All three institutions' computing nodes are configured with a Trusted Execution Environment (TEE) and have completed registration on a distributed consistent ledger through the decentralized identity and reputation management module 10, obtaining initial multidimensional reputation scores.
[0097] At the start of a training round t, the dynamic aggregation node election module 20 is activated. The dynamic aggregation node election module 20 obtains the latest reputation scores of nodes A, B, and C from the distributed consistent ledger and conducts an election using a weighted random election algorithm. In this embodiment, it is assumed that node B is selected as the dynamic aggregation node for this round due to its higher historical reputation score. The election result, i.e., the identity ID of node B, is... B The dynamic aggregation node election module 20 records this information in the distributed consistency ledger.
[0098] After monitoring the election results, the local security processing and proof generation modules 30 of nodes A, B, and C respectively retrieve the global model W from the ledger for the previous round. t-1 And the public key pk of node B B Each node uses local image data for training and calculates its own model parameter updates. and Subsequently, the local security processing and proof generation module 30 of each node generated a computational integrity proof and a verifiable metadata proof for its computation results, and used the public key PK. B The model parameter updates are encrypted.
[0099] The encrypted transmission and on-chain verification module 40 begins operation. Nodes A, B, and C respectively send their encrypted model parameter updates to node B via a peer-to-peer channel. Simultaneously, they submit their respective verifiable proof packages to the distributed consensus ledger. In this embodiment, it is assumed that the proof packages of nodes A and B pass all verifications of the smart contract and are thus recognized as legitimate contributions. However, node C, due to using incompatible data preprocessing steps during local training, causes its generated computational integrity proof to fail on-chain verification. Therefore, the list of legitimate contributions S in this round is... t It only contains the identity identifiers of node A and node B.
[0100] The Trusted Adaptive Aggregation and Execution Proof Module 50 starts in the trusted execution environment of Node B. The Trusted Adaptive Aggregation and Execution Proof Module 50 first broadcasts its remote proof report, and after receiving confirmation from Node A, securely receives its session key. Simultaneously, the Trusted Adaptive Aggregation and Execution Proof Module 50 obtains the list of legitimate contributions S from the distributed consistent ledger. t ={ID A ID B} and the corresponding metadata {M A M B Its internal aggregation strategy arbitration engine analyzes the metadata and selects a federated average aggregation function from a preset library. The trusted adaptive aggregation and execution proof module 50 decrypts the data within isolated memory. and It then performed aggregate calculations, generating a new global model W. t After the calculation is completed, the Trusted Adaptive Aggregation and Execution Proof Module 50 generates an execution proof containing detailed information about this round of aggregation and signed by the TEE hardware private key of Node B.
[0101] The global state update and reputation feedback module 60 receives the execution proof submitted by node B. After verifying its signature, the reputation smart contract of module 60 is triggered. The contract adds the contribution reputation C to nodes A and B, who made legitimate contributions. rep Simultaneously, based on the aggregation efficiency recorded in the execution proof, the contract increases node B's aggregation reputation A. rep For node C whose contribution is rejected, its reputation score remains unchanged in this round. After all reputation scores are updated, they are recorded back into the distributed consistent ledger. This round of training ends, and the system enters a standby state, ready to start the next round of election.
[0102] The present invention has the following beneficial effects:
[0103] 1. This invention adopts distributed consistent ledger management system rules and combines them with dynamic aggregation nodes composed of trusted execution environments to construct a decentralized model parameter aggregation framework. This framework enables the periodic rotation of aggregation task executors and hardware-level security isolation. Compared with existing technologies that rely on fixed centralized servers for aggregation, this invention eliminates the trust dependence on a single entity and the risk of single point of failure, and solves the fundamental problem of difficulty in conducting effective federated learning in cross-institutional collaboration due to trust barriers.
[0104] 2. This invention establishes a two-way, verifiable computational integrity verification mechanism by using locally generated verifiable proof packages and remote proof reports broadcast by aggregation nodes. This mechanism can not only verify the compliance of updates submitted by participants, but also enable participants to reverse verify the correctness of the aggregation process, achieving end-to-end process trustworthiness. This overcomes the technical shortcomings of existing technologies that only focus on input data privacy but cannot effectively prevent model poisoning attacks or malicious aggregation behaviors.
[0105] 3. This invention deeply couples verifiable metadata, an adaptive aggregation strategy arbitration engine, and a multi-dimensional reputation feedback mechanism. The system can dynamically adjust the aggregation strategy according to the real-time distribution of global data and quantify the historical behavior of nodes as the basis for obtaining system rights in the future. This enables the system to achieve self-optimization and self-governance capabilities, solves the problem of poor model performance in complex data environments caused by the use of fixed aggregation algorithms in existing technologies, and overcomes the limitation of lacking effective incentive mechanisms to maintain long-term stability and healthy collaboration in the federated ecosystem.
[0106] The above embodiments are preferred embodiments of the present invention and are not intended to limit the scope of protection of the present invention.
Claims
1. A cross-domain model parameter secure aggregation processing system based on federated learning, characterized in that, include: The decentralized identity and reputation management module is used to register digital identities for multiple participating nodes accessing the system and initialize corresponding multi-dimensional reputation scores, and record the digital identities, associated public keys and multi-dimensional reputation scores in a distributed consistent ledger; The dynamic aggregation node election module, connected to the decentralized identity and reputation management module, is used to elect a dynamic aggregation node from candidate nodes with a trusted execution environment at the beginning of each training round, based on the multidimensional reputation score. The local security processing and proof generation module is configured on each participating node. After obtaining the identity of the dynamically aggregated node elected in this round, it performs local model training to generate model parameter updates, encrypts the model parameter updates using the public key of the dynamically aggregated node, and generates a verifiable proof package. The verifiable proof package contains at least proofs to verify the compliance of the calculation process and data element information. The encrypted transmission and on-chain verification module is used to send the encrypted model parameter update to the dynamic aggregation node and submit the verifiable proof package to the distributed consensus ledger. The consensus mechanism of the distributed consensus ledger verifies the validity of the verifiable proof package to confirm the legitimate contribution. The Trusted Adaptive Aggregation and Execution Proof Module is configured in the Trusted Execution Environment of the Dynamic Aggregation Node. It is used to perform secure aggregation operations based on the legitimate contributions confirmed by the distributed consistent ledger, generate a new global model, and generate an execution proof that records specific information about the aggregation process after the aggregation task is completed. The global state update and reputation feedback module is used to record the execution proof in the distributed consistency ledger, and update the multidimensional reputation score of the multiple participating nodes based on the execution proof and the verification result of the legitimate contribution, thereby completing the closed loop of one round of processing. The updated reputation score is used for the next round of dynamic aggregation node election.
2. The cross-domain model parameter secure aggregation processing system based on federated learning as described in claim 1, Its features are: in, The specific steps for initializing the multidimensional reputation score in the decentralized identity and reputation management module include: For each of the aforementioned participating nodes, set two independent sub-items: contribution reputation and aggregate reputation; The values of the contribution reputation and the aggregate reputation are combined into the multidimensional reputation score using a preset weighted summation formula.
3. The cross-domain model parameter secure aggregation processing system based on federated learning as described in claim 1, Its features are: in, The specific steps for the dynamic aggregation node election module to elect a dynamic aggregation node include: Read the latest multidimensional reputation scores of all candidate nodes from the distributed consistent ledger; execute a weighted random election algorithm; record the identity identifier of the dynamically aggregated node output by the election algorithm in the distributed consistent ledger. The probability of each candidate node being selected is proportional to the value of its multidimensional reputation score.
4. The cross-domain model parameter secure aggregation processing system based on federated learning as described in claim 1, Its features are: in, The specific steps for the local security processing and proof generation module to generate a verifiable proof package include: Perform local model training to obtain updated model parameters; generate a computational integrity certificate, which verifies that the computation process of the updated model parameters conforms to a preset training protocol and that its data norm is within a preset numerical range. A verifiable metadata certificate is generated to verify the authenticity of the statistical metadata extracted from local data; finally, the computational integrity certificate and the verifiable metadata certificate are encapsulated to form the verifiable certificate package.
5. The cross-domain model parameter secure aggregation processing system based on federated learning as described in claim 4, Its features are: in, The specific steps for generating the verifiable metadata proof include: Extract at least one of the following as statistical metadata from the local dataset: data magnitude, class distribution, or gradient sparsity; Using zero-knowledge proof technology, a proof is generated that can confirm that the statistical metadata was generated from the local dataset, but does not reveal the specific value of the statistical metadata or the content of the local dataset.
6. The cross-domain model parameter secure aggregation processing system based on federated learning according to claim 1, characterized in that: in, The specific steps for consensus verification by the encrypted transmission and on-chain verification module include: The verifiable proof package is submitted to the distributed consensus ledger; the consensus nodes in the distributed consensus ledger network obtain the verifiable proof package and perform verification algorithms on the computational integrity proof and verifiable metadata proof contained therein; the submission in which both proofs are verified is determined to be the legitimate contribution.
7. The cross-domain model parameter secure aggregation processing system based on federated learning according to claim 1, characterized in that: in, The specific steps by which the trusted adaptive aggregation and execution proof module generates a new global model and execution proof include: The trusted execution environment of the dynamic aggregation node generates and broadcasts its remote proof report to all participating nodes. After receiving the verification pass signal of the remote proof report from each participating node, it receives and decrypts all encrypted model parameter updates within the trusted execution environment. Then, based on the statistical metadata contained in all legitimate contributions and recorded in the distributed consistency ledger, it dynamically selects an aggregation function from a preset aggregation function strategy library. Then, it uses the selected aggregation function to calculate all decrypted model parameter updates to generate a new global model. After the aggregation calculation is completed, it generates an execution proof signed by the hardware key of the trusted execution environment. This execution proof records at least the number of legitimate contributions processed in this aggregation task, the identifier of the selected aggregation function, and the computation time.
8. The cross-domain model parameter secure aggregation processing system based on federated learning as described in claim 7, Its features are: in, The specific steps for dynamically selecting aggregate functions from a pre-defined strategy library include: An aggregation strategy arbitration engine configured within the trusted execution environment obtains the statistical metadata of all legitimate contributions from the distributed consistent ledger; the aggregation strategy arbitration engine performs a global distribution analysis on all obtained statistical metadata. The aggregation strategy arbitration engine matches and selects aggregation functions from the strategy library based on the analysis results of the global distribution.
9. The cross-domain model parameter secure aggregation processing system based on federated learning as described in claim 1, Its features are: in, The specific steps for the global state update and reputation feedback module to update the multidimensional reputation score include: The execution proof is submitted to the distributed consistency ledger; based on the verification results of the legitimate contribution, the contribution reputation sub-item of all participating nodes that made legitimate contributions is incremented. Based on the performance metrics of the aggregation task recorded in the execution proof, the aggregation reputation sub-item of the dynamic aggregation node in this round is numerically adjusted.
10. The cross-domain model parameter secure aggregation processing system based on federated learning according to claim 9, Its features are: in, The specific steps for updating the aggregation reputation of the dynamic aggregation node based on the aggregation task performance metrics recorded in the execution proof include: The received execution proof is automatically parsed by a reputation smart contract deployed on the distributed consensus ledger; The reputation smart contract extracts quantitative indicators related to aggregation efficiency and stability from the execution proof; based on the quantitative indicators, the reputation smart contract increases or decreases the value of the aggregation reputation sub-item of the dynamic aggregation node through preset calculation rules.
Citation Information
Cited By
Information data operation processing system based on security isolation gatekeeper
CN121530746A
An information data operation processing system based on a secure isolation gateway
CN121530746B
Multi-source data management method and device based on federal mechanism
CN121658689A
A multi-source data management method and device based on a federal mechanism
CN121658689B