Image classification security aggregation method in multilayer federated learning environment
By employing key generation and encryption mechanisms in a multi-layered federated learning environment to identify and eliminate malicious gradients, the problem of malicious client attacks is solved, the robustness and practicality of the image classification model are improved, the scalability and communication efficiency of the system are enhanced, and client data privacy is protected.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HEFEI UNIV OF TECH
- Filing Date
- 2026-01-19
- Publication Date
- 2026-04-28
AI Technical Summary
In a multi-layered federated learning environment, malicious clients may propagate harmful gradients, affecting the training performance of image classification models. Existing technologies struggle to effectively identify and resist such attacks without additional data assumptions.
A multi-layer federated learning secure aggregation method is adopted. Through key generation and encryption mechanisms between the central server, intermediate nodes and clients, malicious gradients are identified and eliminated. The legitimacy of the client is verified by similarity and weight calculation, and encrypted gradient aggregation is performed to ensure the security and accuracy of model training.
It improves the robustness and practicality of image classification models, enhances the scalability and communication efficiency of multi-layer federated learning systems, while protecting client data privacy and avoiding additional data assumption overhead.
Smart Images

Figure CN121935965A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of artificial intelligence model security, specifically involving secure training technology for multi-layer federated learning of image classification models, identifying malicious attacks during the training process, and improving the robustness and practicality of image classification models. Background Technology
[0002] Image classification is a core task in computer vision, defined as outputting a classification description of the image content given an input image. With the rapid development of related technologies, image classification has been widely applied in various fields such as security monitoring, facial recognition, and medical imaging disease diagnosis. Currently, the mainstream implementation of image classification is based on deep learning methods, and the training of high-precision deep learning models often relies on massive amounts of high-quality labeled data. However, the data faced by current image classification tasks exhibits significant characteristics: the scale of unlabeled data is far greater than that of labeled data, and a large amount of labeled data is scattered across discrete clients, making centralized integration difficult. Therefore, traditional deep learning methods are ill-suited to the current application environment.
[0003] With the increasing demand for data privacy protection, federated learning (FL), as a distributed machine learning paradigm, has gained widespread attention. In federated learning, multiple clients collaboratively train a global image classification model without sharing the original data, solving the problem of data dispersion. However, federated learning has security vulnerabilities in open network environments; for example, malicious or corrupted gradients from clients can significantly degrade model performance. To improve system scalability and communication efficiency, hierarchical federated learning (HFL) has been proposed. This structure introduces multiple nodes between the central server and clients, achieving multi-level aggregation. However, the hierarchical structure also brings new security challenges; malicious clients can exploit edge nodes to propagate harmful gradients, thereby affecting the training effect of the image classification model and greatly reducing its practicality.
[0004] Several defensive methods for federated learning exist, such as those based on trusted execution environments or weighted aggregation. However, these methods typically rely on additional data assumptions, such as assuming the server knows part of the client data distribution during aggregation and holds additional datasets for auxiliary verification. This limits their applicability in complex real-world scenarios. Therefore, there is an urgent need for a method that does not require strict data assumptions and can resist malicious gradients in multi-layered federated environments. Summary of the Invention
[0005] To address the vulnerability of federated learning to malicious gradient attacks in existing technologies, this invention proposes a secure aggregation method for multi-layer federated learning. This method aims to identify malicious gradients during training without additional data assumptions, thereby improving the accuracy of image classification models while protecting client data privacy.
[0006] To achieve the above-mentioned objectives, the present invention adopts the following technical solution: The present invention discloses a secure aggregated image classification method for multi-layer federated learning, characterized in that it is applied to a system consisting of an upper-layer central server, a middle-layer... Each node, the lower layer In a multi-layered federated learning scenario consisting of clients and a key generation center, the central server manages all nodes, wherein the first... Individual node management One client, ,and The secure aggregated image classification method includes the following steps: Step 1: Define the current iteration round number as and initialize ; Step 2: The central server constructs and initializes the first... Global image classification model under round-by-round iteration And issued the first Each node manages all clients; the key generation center generates public and private key pairs for the server. and the Public and private key pairs of each node ;in, This represents the server's public key. This represents the server's private key. Indicates the first The public key of each node, Indicates the first The private key of each node; The central server will use the public key. Distribute to all nodes; No. Each node will The adjacent first Public key of each node After the interchange, to form the first New public-private key pairs for each node and the New public-private key pairs for each node ,in, ; No. Each node will Distribute to all clients under its jurisdiction; Step 3: The node managed by the first Each client utilizes its own local image dataset For the received first Global image classification model under round-by-round iteration Perform local training to obtain the first The client in the first gradient under round iteration and the length of its gradient and to After normalization, we obtain the first... The client in the first Gradient after normalization in round iteration ;in, express Norm; No. One client uses right Encryption is performed to obtain the first In the first iteration Encryption gradient for each client Then, with gradient length Upload together to the first There are nodes, among which... Indicates using public key Perform encryption operations; Step 4: After receiving the encryption gradients from all clients within its jurisdiction, the node jointly connects with its neighboring nodes. Each node performs normalized verification of the encryption gradient, thereby adding the re-encryption gradient of the verified client to the set of legitimate clients. In the middle, the first Node pairs The re-encryption gradient in the original is restored to obtain the restored re-encryption gradient; Step 5: Based on the restored re-encryption gradient, the node calculates the... One client and The similarity between all other clients within the same client is obtained as the first... In the first iteration Similarity set of clients ,in, express The number of clients in the middle, Indicates the first In the first iteration The client and the first Similarity between clients Indicates using the server's public key right The result of encryption; Take the first The median similarity of the similarity set of the nth client is used as the th The client in the first Score under round iteration And use the Softmax function to The score of the client is processed to obtain the score of the first client. The client in the first Weights under round iteration ; Step 6: Take each node Median gradient length of all clients and combined The weights of all clients within the domain are aggregated with the re-encryption gradient after restoration to obtain the first... The node at the th Aggregation results under round iteration ; Step 7: The central server uses the server private key Aggregation results for all nodes Decryption is performed to obtain the first... Decryption aggregation result of all nodes under round iteration ,in, Indicates the first The node at the th The aggregated result after decryption in round iteration; Step 8: Use equation (4) to... Update to obtain the first Global Image Classification Model under Round Iteration Concurrently sent to each client: (4) Step 9: After assigning t+1 to t, return to step 3 and execute sequentially until the maximum number of iterations is reached, thus obtaining the final global image classification model, which is used to predict the category of the image.
[0007] The image classification secure aggregation method in a multi-layer federated learning environment described in this invention is also characterized in that step 4 includes: Step 4.1: The Node pairs After shuffling, we get the first... In the first iteration Encryption gradient after client perturbation And send to the adjacent first One node; Step 4.2: The adjacent first The node is initialized. The set of legitimate clients for each node ; The adjacent first Each node calculates The inner product yields the encryption gradient. length and using its own private key right After decryption, determine the decryption result. If the value is "1", the verification is successful, and step 4.3 is executed; otherwise, the verification fails, and the process returns to step 4.1 to verify the encryption gradients of other clients until the next client is reached. After all clients within the jurisdiction of each node have been verified, the final set of legitimate clients is obtained. Concurrently sent to the first One node; Step 4.3, the adjacent first Each node uses a private key pair After decryption, then use the server's public key. Encrypt the decrypted result to obtain the first... In the first iteration Re-encryption gradient for each client And save In; among them, Indicates using the server's public key Perform encryption operations.
[0008] Furthermore, in step 5, the calculation is performed using equation (1). : (1) In equation (1), , These are two preset weighting coefficients; Represents cosine similarity. Indicates Euclidean distance; Indicates to The restored encryption gradient; Calculate the first using equation (2) The client in the first Weights under round iteration : (2) In equation (2), express Inner The client in the first The score under round-by-round iteration.
[0009] Furthermore, in step 6, the first equation is obtained using equation (3). The node at the th Aggregation results under round iteration : (3).
[0010] The present invention provides an electronic device, including a memory and a processor, wherein the memory is used to store a program that supports the processor in executing the multi-layer federated learning image classification method, and the processor is configured to execute the program stored in the memory.
[0011] The present invention discloses a computer-readable storage medium on which a computer program is stored, wherein the computer program, when executed by a processor, performs the steps of the multi-layer federated learning image classification method.
[0012] Compared with existing technologies, the beneficial effects of this invention are reflected in: 1. This invention proposes a secure hierarchical federated learning framework, specifically adapted to hierarchical federated learning scenarios for image classification models. It enables federated learning technology to be efficiently applied in multi-level systems, improving the scalability and communication efficiency of federated training of image classification models. 2. This invention eliminates malicious clients by using similarity among client-fed learning, solving the problem of requiring additional data for security training in existing technologies. It reduces additional overhead while maintaining the training accuracy of the image classification model. 3. This invention uses fully homomorphic encryption (FHE) technology to encrypt the gradient data of the image classification model, and relies on edge nodes to build an encryption process verification mechanism to achieve privacy protection of data during the training process of the image classification model. Attached Figure Description
[0013] Figure 1 This is a flowchart illustrating the present invention; Figure 2 This is a diagram showing the experimental results comparing the defensive effects of the present invention. Detailed Implementation
[0014] In this example, a secure aggregation image classification method for multi-layer federated learning is applied to a system consisting of a central server in the upper layer and a middle layer... Each node, the lower layer In a multi-layered federated learning scenario consisting of clients and a key generation center, the central server manages all nodes, among which the first... Individual node management One client, ,and In this example, K If we set 100 and M to 5, each intermediate node manages 20 clients, completing their initial aggregation. This secure aggregation image classification method is as follows: Figure 1 As shown, it includes the following steps: Step 1: Define the current iteration round number as and initialize ; Step 2: The central server builds and initializes the first... Global image classification model under round-by-round iteration And issued the first Each node manages all clients; the key generation center generates public and private key pairs for the server. and the Public and private key pairs of each node ;in, This represents the server's public key. This represents the server's private key. Indicates the first The public key of each node, Indicates the first The private key of each node; this embodiment uses a convolutional neural network (CNN) containing ReLU units, a soft-max function, and cross-entropy loss as the global neural network structure. The specific model structure is adjusted appropriately according to the effect of different datasets; the key generation center uses the CKKS fully homomorphic encryption algorithm to generate public and private key pairs. Its encryption algorithm allows ciphertext addition and ciphertext multiplication operations on floating-point ciphertext vectors, such as... Figure 1 As shown, it is possible to reduce the weight of a malicious client from the ciphertext space in step ⑦.
[0015] The central server will use the public key Distribute to all nodes; No. Each node will The adjacent first Public key of each node After the interchange, to form the first New public-private key pairs for each node and the New public-private key pairs for each node ,in, ;like Figure 1 As shown, the main reason for using step ③ for key exchange is to prevent nodes from decrypting the data uploaded by the client when they have the corresponding private key, thereby infringing on the client's privacy. No. Each node will Distribute to all clients under its jurisdiction.
[0016] Step 3: The node managed by the first Each client utilizes its own local image dataset For the j-th image sample from the i-th client, for The corresponding real category label, where n is the total number of local image samples of the i-th client, is used to represent the received... Global image classification model under round-by-round iteration Local training is performed. This embodiment uses the MNIST, Fashion-MMNIST, and CIFAR-10 datasets to train and evaluate the model. The MNIST and Fashion-MMNIST datasets each consist of 70,000 grayscale images across 10 categories, while CIFAR-10 consists of color images, with each category containing 6,000 training examples and 1,000 test examples. For MNIST and Fashion-MMNIST, the total number of iterations t is set to 50, and for CIFAR-10, the total number of iterations t is set to 100. The client uses cross-entropy loss as the supervised loss for training the local neural network, and then uses stochastic gradient descent to optimize the learning rate. To update the weights of the local neural network, in this example... Take 1e-3; after training, obtain the first... The client in the first gradient under round iteration and the length of its gradient and to After normalization, we obtain the first... The client in the first Gradient after normalization in round iteration ;in, express Norm; where normalization operation means limiting the length of a vector to 1, specifically: That is, the vector divided by its own length.
[0017] No. One client uses right Encryption is performed to obtain the first In the first iteration Encryption gradient for each client Then, with gradient length Upload together to the first There are nodes, among which... Indicates using public key Encryption is performed; the gradient length is uploaded so that during subsequent aggregation, the nodes can restore the gradient length to a certain extent, preventing the gradient from being too long or too short due to normalization from affecting the training effect of the global image classification model.
[0018] Step 4: After receiving the encryption gradients from all clients within its jurisdiction, the node jointly connects with its neighboring nodes. Each node performs normalized verification of the encryption gradient, thereby adding the re-encryption gradient of the verified client to the set of legitimate clients. In the middle, the first Node pairs The re-encryption gradient in the original is restored to obtain the restored re-encryption gradient; Step 4.1: The Node pairs After shuffling, we get the first... In the first iteration Encryption gradient after client perturbation And send to the adjacent first Each node can shuffle the parameter positions of the gradient without affecting the gradient length, and can prevent adjacent nodes from directly obtaining the original information carried by the gradient when decrypting the gradient.
[0019] Step 4.2: The adjacent first The node is initialized. The set of legitimate clients for each node ; The adjacent first Each node calculates The inner product yields the encryption gradient. length and using its own private key right After decryption, determine the decryption result. Whether it is "1" (CKKS, as a homomorphic encryption algorithm for floating-point numbers, allows for tolerable errors during encryption and decryption; this gradient length verification process is used to determine...) Is it within 1± Within the scope, in this example If the gradient is 1e-5, then the verification is successful, and step 4.3 is executed; otherwise, the verification fails, the failed gradient is discarded in this iteration, and the process returns to step 4.1 to verify the encryption gradients of other clients, until the 1e-5 gradient is obtained. After all clients within the jurisdiction of each node have been verified, the final set of legitimate clients is obtained. Concurrently sent to the first Each node.
[0020] Step 4.3, the adjacent first Each node uses a private key pair After decryption, then use the server's public key. Encrypt the decrypted result to obtain the first... In the first iteration Re-encryption gradient for each client And save In; among them, Indicates using the server's public key Perform encryption operations.
[0021] Step 5: Based on the restored re-encryption gradient, the nth node calculates the i-th node using equation (1). One client and Inner Similarity between clients , obtained the In the first iteration Similarity set of clients ,in, express The number of clients in the middle, Indicates the first In the first iteration The client and the first Similarity between clients Indicates using the server's public key right The result of encryption.
[0022] (1) In equation (1), , These are two preset weighting coefficients; Represents cosine similarity. Indicates Euclidean distance; Indicates to The restored encryption gradient; in this example, and Take 0.5 respectively, where Used to evaluate the angular relationship between vectors in space; the smaller the angle, the better. The larger the value, the more similar the numbers. Used to evaluate the distance relationship between vectors; a larger distance indicates greater dissimilarity. In a normalized vector state... The calculation can be simplified to: ,in, This represents the dot product operation. It can be simplified to ; Take the first The median similarity of the similarity set of the nth client is used as the th The client in the first Score under round iteration And use the Softmax function to The score of the client is processed, and the score of the first client is obtained using equation (2). The client in the first Weights under round iteration Softmax is a commonly used function that amplifies the differences in probability distributions, as shown in equation (2). It can further enhance the detection effect of malicious clients and greatly reduce their weight.
[0023] (2) In equation (2), express Inner The client in the first The score under round-by-round iteration.
[0024] Step 6: Take each node Median gradient length of all clients To prevent gradient length scaling attacks from affecting gradient length restoration, and combined with The weights of all clients are aggregated, and the re-encryption gradients are obtained using equation (3). The node at the th Aggregation results under round iteration ; (3).
[0025] In this example, by using a similarity metric between benign client gradients, poisoning attacks and scaling attacks from malicious clients are effectively reduced during the initial node aggregation (which hinder model training and reduce the recognition ability of the global image classification model by uploading gradients that are opposite to or have a longer update length than the gradient update direction of the global image classification model). Step 7: The central server uses the server's private key Aggregation results for all nodes Decryption is performed to obtain the first... Decryption aggregation result of all nodes under round iteration ,in, Indicates the first The node at the th The aggregated result after decryption in round iteration.
[0026] Step 8: Use equation (4) to... Update to obtain the first Global Image Classification Model under Round Iteration Concurrently sent to each client: (4) Step 9: After assigning t+1 to t, return to step 3 and execute sequentially until the maximum number of iterations is reached, thus obtaining the final global image classification model, which is used to predict the category of the image.
[0027] In this embodiment, an electronic device includes a memory and a processor. The memory stores a program that supports the processor in executing the above-described method, and the processor is configured to execute the program stored in the memory.
[0028] In this embodiment, a computer-readable storage medium stores a computer program, which is executed by a processor to perform the steps of the above method.
[0029] Example: To verify the effectiveness of the method of the present invention, this example uses the commonly used image classification datasets MNIST, Fashion-MNIST and CIFAR-10, and compares the test accuracy of the global image classification models of various aggregation algorithms under the condition of poisoning attack.
[0030] like Figure 2 As shown, on the Fashion-MNIST dataset, when 30% of malicious clients launch a Krum poisoning attack (a poisoning attack targeting the Krum aggregation algorithm), the test accuracy of the global image classification model using various aggregation algorithms changes. The horizontal axis represents the number of iterations, and the vertical axis represents the accuracy. Different colored lines represent different aggregation algorithms. The aggregation algorithms selected for comparison in this example are: FedAvg (Federated Average), Krum, Trimmed-mean, PBFL (Privacy-Preserving Byzantine-Robust Federated Learning), and Romoa (Robust Model Aggregation). Some aggregation algorithms show a significant drop in accuracy when subjected to poisoning attacks, while those that do not show a significant drop require some experimental assumptions, such as the server having additional benign datasets for auxiliary training. The method of this invention ensures the accuracy of the image classification model and client privacy without requiring additional training assumptions.
Claims
1. A secure aggregation image classification method for multi-layer federated learning, characterized in that, It is applied to the upper-layer central server and the middle-layer Each node, the lower layer In a multi-layered federated learning scenario consisting of clients and a key generation center, the central server manages all nodes, wherein the first... Individual node management One client, ,and The secure aggregated image classification method includes the following steps: Step 1: Define the current iteration round number as and initialize ; Step 2: The central server constructs and initializes the first... Global image classification model under round-by-round iteration And issued the first Each node manages all clients; the key generation center generates public and private key pairs for the server. and the Public and private key pairs of each node ;in, This represents the server's public key. This represents the server's private key. Indicates the first The public key of each node, Indicates the first The private key of each node; The central server will use the public key. Distribute to all nodes; No. Each node will The adjacent first Public key of each node After the interchange, to form the first New public-private key pairs for each node and the New public-private key pairs for each node ,in, ; No. Each node will Distribute to all clients under its jurisdiction; Step 3: The node managed by the first Each client utilizes its own local image dataset For the received first Global image classification model under round-by-round iteration Perform local training to obtain the first The client in the first gradient under round iteration and the length of its gradient and to After normalization, we obtain the first... The client in the first Gradient after normalization in round iteration ;in, express Norm; No. One client uses right Encryption is performed to obtain the first In the first iteration Encryption gradient for each client Then, with gradient length Upload together to the first There are nodes, among which... Indicates using public key Perform encryption operations; Step 4: After receiving the encryption gradients from all clients within its jurisdiction, the node jointly connects with its neighboring nodes. Each node performs normalized verification of the encryption gradient, thereby adding the re-encryption gradient of the verified client to the set of legitimate clients. In the middle, the first Node pairs The re-encryption gradient in the original is restored to obtain the restored re-encryption gradient; Step 5: Based on the restored re-encryption gradient, the node calculates the... One client and The similarity between all other clients within the same client is obtained as the first... In the first iteration Similarity set of clients ,in, express The number of clients in the middle, Indicates the first In the first iteration The client and the first Similarity between clients Indicates using the server's public key right The result of encryption; Take the first The median similarity of the similarity set of the nth client is used as the th The client in the first Score under round iteration And use the Softmax function to The score of the client is processed to obtain the score of the first client. The client in the first Weights under round iteration ; Step 6: Take each node Median gradient length of all clients and combined The weights of all clients within the domain are aggregated with the re-encryption gradient after restoration to obtain the first... The node at the th Aggregation results under round iteration ; Step 7: The central server uses the server private key Aggregation results for all nodes Decryption is performed to obtain the first... Decryption aggregation result of all nodes under round iteration ,in, Indicates the first The node at the th The aggregated result after decryption in round iteration; Step 8: Use equation (4) to... Update to obtain the first Global Image Classification Model under Round Iteration Concurrently sent to each client: (4) Step 9: After assigning t+1 to t, return to step 3 and execute sequentially until the maximum number of iterations is reached, thus obtaining the final global image classification model, which is used to predict the category of the image.
2. The secure aggregation method for image classification in a multi-layered federated learning environment according to claim 1, characterized in that, Step 4 includes: Step 4.1: The Node pairs After shuffling, we get the first... In the first iteration Encryption gradient after client perturbation And send to the adjacent first One node; Step 4.2: The adjacent first The node is initialized. The set of legitimate clients for each node ; The adjacent first Each node calculates The inner product yields the encryption gradient. length and using its own private key right After decryption, determine the decryption result. If the value is "1", the verification is successful, and step 4.3 is executed; otherwise, the verification fails, and the process returns to step 4.1 to verify the encryption gradients of other clients until the next client is reached. After all clients within the jurisdiction of each node have been verified, the final set of legitimate clients is obtained. Concurrently sent to the first One node; Step 4.3, the adjacent first Each node uses a private key pair After decryption, then use the server's public key. Encrypt the decrypted result to obtain the first... In the first iteration Re-encryption gradient for each client And save In; among them, Indicates using the server's public key Perform encryption operations.
3. The secure aggregation method for image classification in a multi-layered federated learning environment according to claim 1, characterized in that, In step 5, the calculation is performed using equation (1). : (1) In equation (1), , These are two preset weighting coefficients; Represents cosine similarity. Indicates Euclidean distance; Indicates to The restored encryption gradient; Calculate the first using equation (2) The client in the first Weights under round iteration : (2) In equation (2), express Inner The client in the first The score under round-by-round iteration.
4. The secure aggregation method for image classification in a multi-layered federated learning environment according to claim 1, characterized in that, In step 6, the first equation is obtained using equation (3). The node at the th Aggregation results under round iteration : (3)。 5. An electronic device, comprising a memory and a processor, characterized in that, The memory is used to store a program that supports the processor in executing any of the multi-layer federated learning image classification methods of claims 1-4, the processor being configured to execute the program stored in the memory.
6. A computer-readable storage medium storing a computer program thereon, characterized in that, The computer program, when run by a processor, performs the steps of any of the multi-layer federated learning image classification methods described in claims 1-4.