A test task-based federated learning freeloading defense method and related equipment
By introducing test task mixing and strategic information disclosure into federated learning, and designing optimal task allocation strategies and game-theoretic defense mechanisms, the problem of free-rider behavior affecting model performance is solved, achieving efficient and low-cost free-rider suppression and improving system robustness and model accuracy.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- XI AN JIAOTONG UNIV
- Filing Date
- 2025-08-27
- Publication Date
- 2026-07-24
Smart Images

Figure CN121052409B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of machine learning, and specifically relates to a federated learning free-rider defense method and related equipment based on test tasks. Background Technology
[0002] Federated learning, a distributed machine learning framework, enables parties to collaboratively train a global model without sharing data, and is widely used in data privacy-sensitive scenarios such as healthcare and finance. However, some clients may free-ride by uploading invalid or low-quality local updates to gain benefits from the global model, severely impacting model performance and system fairness. Existing defense technologies are mostly based on post-event detection, requiring round-by-round evaluation of each client's contribution, resulting in high resource consumption and a lack of pre-emptive deterrence mechanisms, making it difficult to meet the needs of large-scale deployment. Summary of the Invention
[0003] To address the problems existing in the prior art, this invention provides a federated learning free-rider defense method and related equipment based on test tasks. Its purpose is to design the optimal task allocation strategy and defense mechanism based on game theory analysis through test task mixing and strategic information disclosure mechanism, so as to achieve efficient and low-cost suppression of free-rider behavior.
[0004] To solve the above-mentioned technical problems, the present invention is achieved through the following technical solution:
[0005] According to a first aspect of the present invention, a method for preventing free-riding in federated learning based on test tasks is provided, applied to a federated learning system consisting of a federated learning server and several federated learning clients communicating with the federated learning server, the method comprising:
[0006] During each training round, the server randomly mixes real tasks and test tasks and hides the task types from all clients; the real tasks are used to train the global model; the test tasks are constructed by the server based on a reference dataset and are used to detect the training quality of the client's updated model.
[0007] When publishing a task, the server strategically discloses the task requirements based on the principle of maximizing the server's expected utility.
[0008] The client updates its posterior belief in the task type based on the received task requirements and selects a participation strategy based on the principle of maximizing the client's expected utility.
[0009] The server evaluates the training quality of the client-submitted updated model on test tasks, detects and penalizes free-riding behavior, and aggregates the global model on real tasks.
[0010] The interaction process between the server and the client is modeled as a free-rider inhibition game. The perfect Bayesian Nash equilibrium of the free-rider inhibition game is solved to determine the optimal task publishing strategy of the server and the optimal participation strategy of the client.
[0011] After multiple rounds of iterative training, the server distributes rewards to the client based on the evaluated training quality.
[0012] In one possible implementation of the first aspect, the server's expected utility function is defined as:
[0013]
[0014] U b (θ,s,a)=U m (θ,s,a)-P(θ,s,a)
[0015] θ∈Θ={θ r ,θ t}
[0016] In the formula, φ represents the expected utility of the server. b (·) Select the task requirement disclosure policy for the server; φ w (·) represents the participation strategy selected by the client; U b (·) represents the server's utility; U m (·) represents the model benefit corresponding to the global model obtained from training; P(·) represents the reward paid by the server to all clients; s is the task requirement disclosed by the server; The set of task requirements disclosed by the server; 'a' represents the client's participation behavior; θ represents the set of client participation behaviors; θ represents the task type; Θ represents the set of task types; θ r For real-world tasks; θ t This is a test task; b represents the server; w represents the client.
[0017] In one possible implementation of the first aspect,
[0018]
[0019] Where α and β are system parameters used to adjust the impact of data on model performance; γ is the model utility conversion coefficient; and αln(1+βX) represents the model accuracy. Defined as the total amount of aggregated data from real task clients; pw(·) represents the reward received by the client; For all clients; The set of clients assigned to real tasks; x w The amount of data used by the client in training.
[0020] In one possible implementation of the first aspect, the client's expected utility function is defined as:
[0021]
[0022] U w (θ,s,a)=p w (θ,s,a)-c w (θ,s,a)-l w (θ,a)
[0023] θ∈{θ r ,θ t}
[0024] In the formula, For the client's expected utility; U w (·) represents the utility of the client; c w (·) represents the computational and communication costs incurred by the client due to participation in federated learning; w (·) indicates a reputational penalty suffered by the client for free-riding.
[0025] In one possible implementation of the first aspect,
[0026]
[0027]
[0028] In the formula, ζ is the conversion coefficient between unit data volume and reward; p basic Based on participation compensation fee; a0 represents the client's free-riding behavior; I g e is the number of global aggregation rounds; com For unit global round communication cost; I l This refers to the number of local training rounds; e tra Calculate the cost per unit sample; rep This is a reputation penalty value.
[0029] In one possible implementation of the first aspect, the following conditions must be satisfied simultaneously when solving for the perfect Bayesian Nash equilibrium of the free-rider inhibition game:
[0030] (i) Server Optimization Strategy
[0031]
[0032] (ii) Client-optimal strategy
[0033]
[0034] (iii) Client-side belief alignment:
[0035]
[0036] In the formula, Φ b This indicates that the server's task requires disclosure of the policy set; Φ w This represents the client's set of engagement strategies; p b (·) represents the server's preset task type probability; λ w (·) represents the client's belief.
[0037] In one possible implementation of the first aspect, the perfect Bayesian Nash equilibrium includes pooling equilibrium, semi-separated equilibrium, and fully mixed equilibrium;
[0038] The solution to the perfect Bayesian Nash equilibrium of the free-rider suppression game is as follows:
[0039] When p b (θ r )<κ0, and satisfy At this time, the corresponding equilibrium is a semi-separated equilibrium, and the strategy of the semi-separated equilibrium is as follows:
[0040]
[0041]
[0042]
[0043]
[0044] When κ0≤p b (θ r When )≤κ1, the corresponding equilibrium is a fully mixed equilibrium, and the strategy of the fully mixed equilibrium is as follows:
[0045]
[0046]
[0047]
[0048]
[0049] When p b (θ r )>k1, and the external beliefs of the equilibrium path satisfy μ w When (s0)≥κ0, the corresponding equilibrium is a pooling equilibrium, and the strategy of the pooling equilibrium is as follows:
[0050]
[0051]
[0052] in,
[0053]
[0054]
[0055]
[0056] In the formula, x c Indicates the amount of data required for a complex task; x e Indicates the amount of data required for a simple task; ψ w The contribution weight of client w; X c X is the total amount of data required for complex tasks; e λ0 represents the total amount of data required for a simple task; s0 represents the client's initial belief; s0 represents the complex task requirements disclosed by the server; and s1 represents the simple task requirements disclosed by the server.
[0057] In one possible implementation of the first aspect, the task requirements include at least one of task complexity, target performance, and data volume requirements.
[0058] According to a second aspect of the present invention, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the aforementioned federated learning free-rider defense method based on a test task.
[0059] According to a third aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing a computer program that, when executed by a processor, implements the aforementioned federated learning free-rider defense method based on a test task.
[0060] Compared with the prior art, the present invention has at least the following beneficial effects:
[0061] Existing defense technologies largely rely on post-event detection, requiring round-by-round evaluation of each client's contribution, resulting in significant resource overhead. This invention, however, introduces a mixed test task mechanism and strategic information disclosure. During each training round, the server randomly mixes real and test tasks, hiding the task types from all clients. Simultaneously, based on the principle of maximizing expected utility, it strategically discloses task requirements, effectively enhancing the client's uncertainty regarding task types. This achieves both pre-emptive deterrence and post-event detection of free-riding behavior without requiring frequent, high-overhead detection, thus reducing defense overhead.
[0062] This invention models the interaction process between the server and the client as a free-rider suppression game and theoretically solves for a perfect Bayesian Nash equilibrium, enabling both the server and the client to converge to the optimal strategy combination. Thus, the system can adaptively adjust its strategy under different task scenarios, effectively suppressing free-rider behavior. Regardless of the complex and ever-changing task environment, it ensures the robust operation of the system while maintaining fairness among clients, preventing free-riding behavior by some clients from disrupting the overall system balance.
[0063] This invention evaluates and allocates rewards based on the training quality of client-submitted model updates during testing tasks. While suppressing free-riding behavior, it ensures the positive impact of high-quality updates on global model training. High-quality client updates receive corresponding rewards, encouraging more clients to honestly participate in training and provide excellent model updates, thereby improving the performance of the global model. It also achieves fairness in client incentives, ensuring that clients who actively participate and contribute high-quality updates receive their due rewards.
[0064] This invention only requires designing task mixing and information disclosure strategies on the server side, and the client does not need additional hardware support or additional communication overhead. This makes the invention highly scalable and adaptable to federated learning systems of different sizes, such as edge computing, the Internet of Things and other large-scale federated learning application scenarios.
[0065] By employing a game-theoretic equilibrium strategy, this invention implements a free-rider defense mechanism that links test task obfuscation with information disclosure. This effectively induces free-rider clients to rationally choose their participation strategies under uncertainty, reducing the interference of malicious behavior on the system and thus improving system security. Simultaneously, by suppressing free-rider behavior, the quality of global model training data is ensured, thereby improving the accuracy of the global model.
[0066] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description
[0067] To more clearly illustrate the technical solutions in the specific embodiments of the present invention, the drawings used in the description of the specific embodiments will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0068] Figure 1 A flowchart illustrating a federated learning free-rider defense method based on test tasks, as described in this invention.
[0069] Figure 2This invention provides a system model for a federated learning free-rider defense method based on test tasks.
[0070] Figure 3 This is a game theory flowchart illustrating a federated learning free-rider defense method based on a test task, as described in an embodiment of the present invention.
[0071] Figure 4 This invention relates to a game tree for a federated learning free-rider defense method based on a test task, as described in an embodiment of the present invention.
[0072] Figure 5 The simulation results are for the example. Detailed Implementation
[0073] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0074] like Figure 1 and Figure 2 As shown, this invention provides a method for preventing free-riding in federated learning based on test tasks, applicable to a federated learning system composed of a federated learning server and several federated learning clients (i.e., participants) communicating with the federated learning server. The free-riding prevention method specifically includes the following steps:
[0075] Step 1: In each round of training, the server randomly mixes real tasks and test tasks, and hides the task types from all clients, so the clients cannot distinguish the task types; wherein, the real tasks are used to train the global model; the test tasks are constructed by the server based on the reference dataset and are used to detect the training quality of the client's updated model.
[0076] In other words, during the training process, the federated learning server randomly mixes real tasks and test tasks and releases them to the clients. The task type (real task or test task) is hidden from all clients in order to guide the clients to make a strategy choice that is more conducive to the fairness of the system under uncertain conditions.
[0077] Step 2: When the server publishes a task, it strategically discloses the task requirements based on the principle of maximizing the server's expected utility, in order to interfere with the client's judgment of the task type.
[0078] In this embodiment, the task requirements include at least one of the following: task complexity, target performance, and data volume requirements.
[0079] Specifically, when issuing tasks, the server strategically discloses task requirements (including task complexity, target performance, data volume requirements, etc.), forming an information disclosure mechanism. The server can design pure or mixed strategy disclosure schemes according to different task types, and interfere with the client's accurate identification of the task type by adjusting the disclosure combination to shape its belief, prompting the client to tend to choose honest training under the risk-reward trade-off.
[0080] In this embodiment, the server's expected utility function is defined as:
[0081]
[0082] U b (θ,s,a)=U m (θ,s,a)-P(θ,s,a)
[0083] θ∈{θ r ,θ t}
[0084] In the formula, φ represents the expected utility of the server. b (·) Select the task requirement disclosure policy for the server; φ w (·) represents the participation strategy selected by the client; U b (·) represents the server's utility; U m (·) represents the model benefit corresponding to the global model obtained from training; P(·) represents the reward paid by the server to all clients; s is the task requirement disclosed by the server; The set of task requirements disclosed by the server; 'a' represents the client's participation behavior; For the set of client participation behaviors; θ represents the task type; θ r For real-world tasks; θ t This is a test task; b represents the server; w represents the client.
[0085] In this implementation, the model benefit corresponding to the trained global model depends on the total amount of data aggregated by federated learning, and the model benefit U m (θ,s,a) is represented as:
[0086]
[0087] In the formula, α and β are system parameters used to adjust the impact of data on model performance; γ is the model utility conversion coefficient; αln(1+βX) represents the model accuracy, which reflects the law of diminishing marginal returns, that is, the greater the contribution of data, the more the gain of new data on model returns gradually decreases; Defined as the total amount of aggregated data from real task clients. For all clients; The set of clients assigned to real tasks; x w The amount of data used by the client in training.
[0088] In this embodiment, the reward paid by the server to all clients, that is, the total server payment, is the sum of the payments made by all clients, expressed as:
[0089]
[0090] In the formula, p w (·) indicates the reward received by the client.
[0091] Step 3: The client updates its posterior belief in the task type based on the received task requirements, and selects a participation strategy based on the principle of maximizing the client's expected utility.
[0092] In other words, based on the received task requirements, the client uses Bayesian update rules to form a posterior belief about the task type, and chooses whether to perform free-riding behavior or honest training based on the client's expected utility maximization principle. The client can use pure strategies or hybrid strategies to deal with the server's disclosure strategy.
[0093] In this embodiment, the client's expected utility function is defined as:
[0094]
[0095] U w (θ,s,a)=p w (θ,s,a)-c w (θ,s,a)-l w (θ,a)
[0096] θ∈{θ r ,θ t}
[0097] In the formula, For the client's expected utility; U w (·) represents the utility of the client; c w (·) represents the computational and communication costs incurred by the client due to participation in federated learning; w (·) indicates a reputational penalty suffered by the client for free-riding.
[0098] Specifically, the server pays the client a reward based on the task type θ, the task requirements s disclosed by the server, and the client's participation behavior a, using the payment function p. w (θ,s,a) represents the reward received by the client as follows:
[0099]
[0100] In the formula, ζ is the conversion coefficient between unit data volume and reward; p basic The compensation fee is based on participation; a0 represents the free-riding behavior of the client.
[0101] In other words, for the real task θ r The amount of data used for training is proportional to the amount of data received by the client; for the test task θ t If the client engages in free-riding behavior (a0), the payment is zero; if the client trains honestly under the test task, the basic participation fee (p) is paid. basic p basic =I g (I l e tra x w +e com ).
[0102] Specifically, the client incurs computational and communication costs during task execution, the cost function of which is c. w (θ,s,a) is represented as:
[0103]
[0104] In the formula, I g e is the number of global aggregation rounds; com For unit global round communication cost; I l This refers to the number of local training rounds; e tra Calculate the cost per unit sample.
[0105] In other words, for clients that engage in free-riding behavior (a0), they only upload gradients and incur communication overhead; honest clients must bear both local training computation costs and communication overhead.
[0106] Specifically, if a client is detected as engaging in free-riding behavior during a test task, a reputation penalty is incurred, with a loss function l. w (θ,a), that is, the reputational penalty suffered by the client for free-riding, is represented as:
[0107]
[0108] In the formula, l rep This is a reputation penalty value.
[0109] It should be understood that in step 3, before the server discloses the task requirement s, the client holds a prior belief about the task type θ. Assuming the client knows the task type distribution, its prior belief can be expressed as: in This represents the proportion of real-world tasks. This represents the proportion of test tasks. After observing the task requirements s disclosed by the server, the client updates its posterior belief λ according to Bayes' theorem.w (θ|s). Here, the server influences the client's behavioral decisions by adjusting the task requirements s of the federated learning. To simplify the analysis, two types of task requirements are adopted: complex task requirements s0 and simple task requirements s1. The server influences the client's behavioral decisions by adjusting the federated learning task requirements. Complex task requirements are usually associated with real tasks, while test tasks are usually accompanied by simple task requirements. To increase uncertainty, some test tasks may adopt complex task requirements, while some real tasks may adopt simple task requirements.
[0110] It should be noted that complex tasks require high computing power and training resources, typically manifested in a large amount of local data and high overhead for iterative training; while simple tasks have relatively low resource and performance requirements, usually requiring only a small amount of local data.
[0111] Step 4: The server evaluates the training quality of the client-submitted updated model on the test task, detects and penalizes free-riding behavior, and aggregates the global model on the real task.
[0112] Specifically, the server uses a reference dataset to evaluate the training quality of the updated model submitted by the client in the test task. The evaluation can be carried out by the following methods: gradient matching detection based on model similarity, contribution quantification based on Shapley value, and model performance comparison based on the reference dataset.
[0113] The server applies reputational penalties or incentive reductions to detected free-riding behavior. For real-world tasks, the server does not perform real-time detection but only aggregates the global model according to a standard process.
[0114] Step 5: Model the interaction process between the server and the client as a free-rider inhibition game, and solve for the perfect Bayesian Nash equilibrium of the free-rider inhibition game to determine the optimal task publishing strategy for the server and the optimal participation strategy for the client. (See [link to relevant documentation]). Figure 3 and Figure 4 .
[0115] Specifically, the definition of free-rider suppression game includes:
[0116] The participants include servers and clients;
[0117] The utility functions of the participants include the server's expected utility function and the client's expected utility function;
[0118] The behavior of the participants includes the task requirements disclosed by the server and the participation behavior of the client;
[0119] The strategies of the participants include the task requirement disclosure strategy chosen by the server and the participation strategy chosen by the client;
[0120] Client-side beliefs.
[0121] In this implementation, the following conditions must be met simultaneously when solving for the perfect Bayesian Nash equilibrium of the free-rider inhibition game:
[0122] (i) Server Optimization Strategy
[0123]
[0124] (ii) Client-optimal strategy
[0125]
[0126] (iii) Client belief consistency, meaning that the belief update is reasonable and follows the Bayesian update rule:
[0127]
[0128] In the formula, Φ b This indicates that the server's task requires disclosure of the policy set; Φ w This represents the client's set of engagement strategies; p b (·) represents the server's preset task type probability; λ w (·) represents the client belief; Θ represents the set of task types; θ′ represents the task type.
[0129] In this embodiment, perfect Bayesian Nash equilibrium includes pure policy equilibrium (i.e., pooled equilibrium) and mixed policy equilibrium (including semi-separate equilibrium and fully mixed equilibrium). Specific details are as follows:
[0130] Pooling balance means that the server applies the same task requirements to both real and test tasks, making it impossible for the client to determine the task type based on the task requirements.
[0131] Semi-separate load balancing: The server applies the same task requirements to one type of task, while assigning different task requirements to another type of task with a set probability.
[0132] In a fully hybrid equilibrium, the server assigns different task requirements to different task types with set probabilities, forming a fuzzy signaling mechanism that induces clients to make rational decisions under uncertainty.
[0133] In this embodiment, the solution for the perfect Bayesian Nash equilibrium of the free-rider inhibition game is as follows:
[0134] 1) When the proportion of actual tasks satisfies p b (θ r ) < κ0 and the following conditions are satisfied:
[0135]
[0136] The corresponding equilibrium is a semi-separated equilibrium, and the strategy of the semi-separated equilibrium is as follows:
[0137]
[0138]
[0139]
[0140]
[0141] 2) When the proportion of actual tasks satisfies κ0≤p b (θ r When )≤κ1, the corresponding equilibrium is a fully mixed equilibrium, and the strategy of the fully mixed equilibrium is as follows:
[0142]
[0143]
[0144]
[0145]
[0146] 3) When the proportion of actual tasks satisfies p b (θ r )>κ1, and the external beliefs of the equilibrium path satisfy μ w When (s0)≥κ0, the corresponding equilibrium is a pooling equilibrium, and the strategy of the pooling equilibrium is as follows:
[0147]
[0148]
[0149] in,
[0150]
[0151]
[0152]
[0153] In the formula, x c Indicates the amount of data required for a complex task; x e Indicates the amount of data required for a simple task; ψ w The contribution weight of client w; X c X is the total amount of data required for complex tasks; eλ0 represents the total amount of data required for a simple task; s0 represents the client's initial belief; s0 represents the complex task requirements disclosed by the server; and s1 represents the simple task requirements disclosed by the server.
[0154] Step 6: After multiple rounds of iterative training, the server distributes rewards to the client based on the evaluated training quality.
[0155] In other words, after multiple training iterations, the server assigns corresponding rewards to the client based on the evaluated training quality, and continues subsequent training based on the updated global model.
[0156] The following simulation of a federated learning scenario illustrates the free-rider defense method based on test tasks proposed in this invention. The simulation environment includes a federated learning server and 40 participating devices (clients), with 80% being real tasks and the remainder being test tasks. The training task is based on the MNIST dataset, where the MNIST training process includes 10 rounds of global communication. Each client has a local batch size of 64, a learning rate of 0.01, and each round of local training contains one epoch. In the simulation, it is assumed that there are policy-driven free-rider clients, accounting for 30% or 50%, employing a typical free-rider strategy: uploading parameters with random noise added to the global model. The server, through the mechanism proposed in this invention, randomly mixes real and test tasks and guides clients to honestly participate in training through a task requirement disclosure strategy. Combined with policy optimization based on perfect Bayesian Nash equilibrium, free-rider behavior is suppressed.
[0157] The performance evaluation focuses on comparing the global model accuracy of the proposed method with existing solutions like FedAvg under different hitchhiking ratios. Figure 5 The test results on MNIST are presented, showing that the present invention significantly outperforms FedAvg in various scenarios. Particularly noteworthy is its superior accuracy compared to FedAvg's performance with only 30% of clients free-riding, even with 50% of clients participating. This demonstrates its strong robustness. The performance improvement is primarily attributed to the game-theoretic constraint design that combines a testing task mechanism with strategic information disclosure. This effectively reduces the probability of strategic free-riding behavior, enhances model aggregation quality, and improves overall federated learning performance.
[0158] In another embodiment of the present invention, a computer device is provided, comprising a processor and a memory. The memory stores a computer program, which includes program instructions. The processor executes the program instructions stored in the computer storage medium. The processor may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing and control core of the terminal, suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions from the computer storage medium to achieve a corresponding method flow or corresponding function. The processor described in this embodiment of the present invention can be used in the operation of a federated learning free-rider defense method based on test tasks.
[0159] In another embodiment of the present invention, a storage medium is provided, specifically a computer-readable storage medium (Memory), which is a memory device in a computer device used to store programs and data. It is understood that the computer-readable storage medium here can include both the built-in storage medium in the computer device and extended storage media supported by the computer device. The computer-readable storage medium provides storage space that stores the terminal's operating system. Furthermore, the storage space also stores one or more instructions suitable for loading and execution by a processor. These instructions can be one or more computer programs (including program code). It should be noted that the computer-readable storage medium here can be high-speed RAM or non-volatile memory, such as at least one disk storage device. The processor can load and execute one or more instructions stored in the computer-readable storage medium to implement the corresponding steps of the federated learning free-rider defense method based on test tasks in the above embodiments.
[0160] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0161] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0162] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0163] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0164] This invention also provides a computer program product for executing any of the above-described test-task-based federated learning free-rider defense methods. Since the computer program product provided by this invention belongs to the same inventive concept as the test-task-based federated learning free-rider defense method described above, it possesses all the advantages of the test-task-based federated learning free-rider defense method described above. Therefore, the beneficial effects of the computer program product provided by this invention will not be elaborated upon here.
[0165] In this invention, the terms "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to a specific feature, structure, material, or characteristic described in connection with that embodiment or example, which is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0166] Finally, it should be noted that the above-described embodiments are merely specific implementations of the present invention, used to illustrate the technical solutions of the present invention, and not to limit them. The scope of protection of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that any person skilled in the art can still modify or easily conceive of changes to the technical solutions described in the foregoing embodiments within the scope of the technology disclosed in the present invention, or make equivalent substitutions for some of the technical features; and these modifications, changes, or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered within the scope of protection of the present invention.
Claims
1. A federated learning free-rider defense method based on test tasks, characterized in that, The free-rider defense method, applied to a federated learning system consisting of a federated learning server and several federated learning clients communicating with the federated learning server, includes: During each training round, the server randomly mixes real tasks and test tasks and hides the task types from all clients; the real tasks are used to train the global model; the test tasks are constructed by the server based on a reference dataset and are used to detect the training quality of the client's updated model. When publishing a task, the server strategically discloses the task requirements based on the principle of maximizing the server's expected utility. The client updates its posterior belief in the task type based on the received task requirements and selects a participation strategy based on the principle of maximizing the client's expected utility. The server evaluates the training quality of the client-submitted updated model on test tasks, detects and penalizes free-riding behavior, and aggregates the global model on real tasks. The interaction process between the server and the client is modeled as a free-rider inhibition game. The perfect Bayesian Nash equilibrium of the free-rider inhibition game is solved to determine the optimal task publishing strategy of the server and the optimal participation strategy of the client. After multiple rounds of iterative training, the server distributes rewards to the client based on the evaluated training quality.
2. The federated learning free-rider defense method based on test tasks according to claim 1, characterized in that, The expected utility function of a server is defined as: U b (θ,s,a)=U m (θ,s,a)-P(θ,s,a) θ∈θ={θ r ,i t } In the formula, φ represents the expected utility of the server. b (·) Select the task requirement disclosure policy for the server; φ w (·) represents the participation strategy selected by the client; U b (·) represents the server's utility; U m (·) represents the model benefit corresponding to the global model obtained from training; P(·) represents the reward paid by the server to all clients; s is the task requirement disclosed by the server; The set of task requirements disclosed by the server; 'a' represents the client's participation behavior; θ represents the set of client participation behaviors; θ represents the task type; Θ represents the set of task types; θ r For real missions; θ t This is a test task; b represents the server; w represents the client.
3. The federated learning free-rider defense method based on test tasks according to claim 2, characterized in that, Where α and β are system parameters used to adjust the impact of data on model performance; γ is the model utility conversion coefficient; and αln(1+βX) represents the model accuracy. Defined as the total amount of aggregated data from real task clients; p w (·) indicates the reward received by the client; For all clients; The set of clients assigned to real tasks; x w The amount of data used by the client in training.
4. The federated learning free-rider defense method based on test tasks according to claim 3, characterized in that, The client's expected utility function is defined as: U w (θ,s,a)=p w (θ,s,a)-c w (θ,s,a)-l w (θ,a) θ∈{θ r ,i t } In the formula, For the client's expected utility; U w (·) represents the utility of the client; c w (·) represents the computational and communication costs incurred by the client due to participation in federated learning; w (·) indicates a reputational penalty suffered by the client for free-riding.
5. The federated learning free-rider defense method based on test tasks according to claim 4, characterized in that, In the formula, ζ is the conversion coefficient between unit data volume and reward; p basic The compensation fee is based on participation; a0 represents the client's free-riding behavior. I g e is the number of global aggregation rounds; com For unit global round communication cost; I l This refers to the number of local training rounds; e tra Calculate the cost per unit sample; rep This is a reputation penalty value.
6. The federated learning free-rider defense method based on test tasks according to claim 5, characterized in that, To find the perfect Bayesian Nash equilibrium of the free-rider inhibition game, the following conditions must be met simultaneously: (i) Server Optimal Strategy (ii) Client-optimal strategy (iii) Client-side belief alignment: In the formula, Φ b This indicates that the server's task requires disclosure of the policy set; Φ w This represents the client's set of engagement strategies; p b (·) represents the server's preset task type probability; λ w (·) represents the client's belief.
7. The federated learning free-rider defense method based on test tasks according to claim 6, characterized in that, The perfect Bayesian Nash equilibrium includes pooling equilibrium, semi-separated equilibrium, and fully mixed equilibrium. The solution to the perfect Bayesian Nash equilibrium of the free-rider suppression game is as follows: When p b (θ r )<κ0, and satisfy At this time, the corresponding equilibrium is a semi-separated equilibrium, and the strategy of the semi-separated equilibrium is as follows: When κ0≤p b (θ r When )≤κ1, the corresponding equilibrium is a fully mixed equilibrium, and the strategy of the fully mixed equilibrium is as follows: When p b (θ r )>κ1, and the external beliefs of the equilibrium path satisfy μ w When (s0)≥k0, the corresponding equilibrium is pooling equilibrium, and the strategy of pooling equilibrium is as follows: in, In the formula, x c Indicates the amount of data required for a complex task; x e Indicates the amount of data required for a simple task; ψ w The contribution weight of client w; X c X is the total amount of data required for complex tasks; e λ0 represents the total amount of data required for a simple task; s0 represents the client's initial belief; s0 represents the complex task requirements disclosed by the server; and s1 represents the simple task requirements disclosed by the server.
8. The federated learning free-rider defense method based on test tasks according to claim 1, characterized in that, The task requirements include at least one of the following: task complexity, target performance, and data volume requirements.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements a test task-based federated learning free-rider defense method as described in any one of claims 1 to 8.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements a test task-based federated learning free-rider defense method as described in any one of claims 1 to 8.