A parameter identification method and device, a storage medium, and a computer program product

By calculating the Euclidean distance and Gaussian kernel function to determine the security threshold, and identifying and aggregating security model parameters, the problem of malicious parameter identification under generalized Byzantine attacks is solved, improving the accuracy of model training and the efficiency of resource utilization.

CN122268611APending Publication Date: 2026-06-23CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD
Filing Date
2026-02-02
Publication Date
2026-06-23

AI Technical Summary

Technical Problem

Under the federated learning architecture, generalized Byzantine attacks make it difficult to identify malicious parameters, reduce the accuracy of model training, and existing security detection solutions are resource-intensive, inflexible, and difficult to handle Non-IID data.

Method used

By receiving model parameters from multiple clients, calculating the Euclidean distance, performing two sorting operations to extract the security threshold, using the Gaussian kernel function to determine density information, and identifying and aggregating the security model parameters.

Benefits of technology

It improves the accuracy of malicious parameter identification, reduces resource consumption, is highly adaptable, enhances the accuracy and efficiency of model training, and is applicable to both IID and Non-IID data formats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122268611A_ABST
    Figure CN122268611A_ABST
Patent Text Reader

Abstract

The application provides a parameter identification method and device, a storage medium and a computer program product. The method comprises the following steps: receiving a plurality of groups of model parameters of a plurality of clients; each client corresponds to a group of model parameters, and each group of model parameters comprises model parameters of a plurality of dimensions; obtaining a plurality of distances between the mth dimension model parameters of each client and a plurality of mth dimension model parameters of the plurality of clients respectively; m is a positive integer; sorting the plurality of distances corresponding to each client in ascending order to obtain a plurality of sorted distances corresponding to each client; extracting the nth column distance from the plurality of sorted distances corresponding to the plurality of clients as a safety threshold; n is a positive integer; and identifying the mth safety model parameter from the mth dimension model parameters by using the safety threshold.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security, and in particular to a parameter identification method and apparatus, storage medium, and computer program product. Background Technology

[0002] With the advent of the artificial intelligence era, big data-driven model training technology has been proposed and widely applied in various fields. In dedicated cloud scenarios, large-scale model service platforms supporting intelligent computing services can fine-tune models using historical user data to achieve target capabilities. Currently, this model training process is conducted under a federated learning architecture. However, federated learning architectures are often susceptible to generalized Byzantine attacks. Attackers can contaminate and tamper with the original data through different dimensions, causing different malicious parameters to have similar variances, making it difficult to identify malicious parameters and thus reducing the accuracy of model training. Summary of the Invention

[0003] This application provides a parameter identification method and apparatus, a storage medium, and a computer program product.

[0004] The technical solution of this application is implemented as follows: Firstly, this application proposes a parameter identification method, the method comprising: It receives multiple sets of model parameters from multiple clients; each client corresponds to a set of model parameters, and each set of model parameters includes model parameters in multiple dimensions. Obtain the multiple distances between the m-th dimension model parameters of each client and the multiple m-th dimension model parameters of multiple clients; m is a positive integer; Sort the multiple distances corresponding to each client in ascending order to obtain the sorted multiple distances for each client; The nth column distance is extracted as the security threshold from multiple sorted distances corresponding to multiple clients; n is a positive integer. The security model parameters of the m-th dimension are identified from the m-th dimension model parameters using the security threshold.

[0005] Secondly, this application proposes a parameter identification device, the device comprising: The receiving unit is used to receive multiple sets of model parameters from multiple clients; each client corresponds to a set of model parameters, and each set of model parameters includes model parameters in multiple dimensions. The acquisition unit is used to acquire multiple distances between the m-th dimension model parameters of each client and multiple m-th dimension model parameters of multiple clients; m is a positive integer; The sorting unit is used to sort the multiple distances corresponding to each client in ascending order to obtain the sorted multiple distances corresponding to each client. The extraction unit is used to extract the nth column distance as a security threshold from multiple sorted distances corresponding to multiple clients; n is a positive integer. The identification unit is used to identify the m-th dimension security model parameter from the m-th dimension model parameter using the security threshold.

[0006] Thirdly, this application proposes a parameter identification device, which includes a processor, a memory, and a communication bus; the processor implements the above-mentioned parameter identification method when executing the running program stored in the memory.

[0007] Fourthly, this application proposes a storage medium on which a computer program is stored, which, when executed by a processor, implements the above-mentioned parameter identification method.

[0008] Fifthly, this application proposes a computer program product, including a computer program that, when executed by a processor, implements the above-mentioned parameter identification method.

[0009] This application provides a parameter identification method, apparatus, storage medium, and computer program product. The method includes: receiving multiple sets of model parameters from multiple clients; wherein each client corresponds to a set of model parameters, and each set of model parameters includes model parameters of multiple dimensions; obtaining multiple distances between the m-th dimension model parameter of each client and the multiple m-th dimension model parameters of the multiple clients; where m is a positive integer; sorting the multiple distances corresponding to each client in ascending order to obtain sorted multiple distances corresponding to each client; extracting the n-th column distance from the multiple sorted multiple distances corresponding to the multiple clients as a security threshold; where n is a positive integer; and identifying the m-th dimension secure model parameter from the m-th dimension model parameters using the security threshold. Using the above implementation scheme, for the m-th dimension model parameters of each client, after obtaining multiple distances between multiple m-th dimension model parameters of multiple clients, the multiple distances are sorted and the nth column of the sorted distance is extracted as a security threshold. This allows for a more accurate representation of the security threshold of the m-th dimension model parameters of each client. During the security identification process, corresponding security thresholds are set for model parameters of different dimensions based on the sorting of distances, enabling more accurate screening of malicious parameters of different dimensions, improving the accuracy of malicious parameter identification, and thus improving the accuracy of model training. Attached Figure Description

[0010] Figure 1 A flowchart illustrating a parameter identification method provided in an embodiment of this application; Figure 2 A schematic diagram of an exemplary federated learning architecture provided for embodiments of this application; Figure 3 A flowchart illustrating an exemplary training method provided in this application embodiment; Figure 4 A schematic diagram of the structure of a parameter identification device provided in this application embodiment. Figure 1 ; Figure 5 A schematic diagram of the structure of a parameter identification device provided in this application embodiment. Figure 2 .

[0011] It should be noted that the terms "first" and "second" mentioned above are only used to distinguish between different options and do not represent the degree of superiority or inferiority of the options or their priority in the implementation process. Detailed Implementation

[0012] In order to gain a more detailed understanding of the features and technical content of the embodiments of this application, the implementation of the embodiments of this application will be described in detail below with reference to the accompanying drawings. The accompanying drawings are for reference and illustration only and are not intended to limit the embodiments of this application.

[0013] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0014] In the following description, references to "some embodiments" refer to a subset of all possible embodiments. It is understood that "some embodiments" may be the same or different subsets of all possible embodiments and may be combined with each other without conflict. It should also be noted that the terms "first, second, third" used in the embodiments of this application are merely for distinguishing similar objects and do not represent a specific ordering of objects. It is understood that "first, second, third" may be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.

[0015] Existing security testing methods have the following main shortcomings: 1. Security detection capabilities are not comprehensive enough, resulting in poor defense performance in generalized Byzantine attack scenarios. In generalized Byzantine attack scenarios, attackers can contaminate and tamper with raw data through different dimensions, making it difficult to achieve good detection results, or even rendering the detection ineffective.

[0016] 2. Non-independent and identically distributed data is difficult to process, resulting in low model accuracy. In practical applications of Lightroom, the data stored by different clients (data owners) may vary significantly in type due to various objective factors such as device performance, distribution environment, etc., and may be stored in Non-IID format. This Non-IID data will cause a large deviation from the actual model parameters after aggregation by security policies, leading to a decrease in the accuracy of the finally trained model.

[0017] 3. Hyperparameter tuning is computationally expensive and lacks flexibility. Most existing density-related security detection schemes use fixed thresholds (hyperparameters) as reference values ​​for density calculation to screen raw data. This approach makes the model's performance highly dependent on the hyperparameter values, and it also requires hyperparameter tuning before training, consuming more computational resources and time. When the trained model changes, hyperparameter tuning needs to be repeated, making the scheme lack real-time adjustment capabilities.

[0018] To address the above problems, embodiments of this application provide a parameter identification method, such as... Figure 1 As shown, the method may include: S101. Receive multiple sets of model parameters from multiple clients; where each client corresponds to a set of model parameters, and each set of model parameters includes model parameters in multiple dimensions.

[0019] The parameter identification method provided in this application embodiment can be applied to model training scenarios under federated learning architectures such as private clouds and public clouds, or under centralized architectures.

[0020] In one embodiment, the federated learning method includes a central server and clients, such as... Figure 2 As shown, the client reports model parameter d and / or malicious parameter g to the central server, and the central server sends aggregated model parameter x to the client based on the reported model parameter and / or malicious parameter.

[0021] In this embodiment of the application, multiple clients upload a set of model parameters obtained from the training after this round of model training. Each set of model parameters includes model parameters with multiple dimensions, that is, the dimensions of the model parameters uploaded by multiple clients are consistent.

[0022] S102. Obtain the multiple distances between the m-th dimension model parameters of each client and the multiple m-th dimension model parameters of multiple clients respectively; m is a positive integer.

[0023] In this embodiment of the application, the multiple distances between the m-th dimension model parameters of each client and the multiple m-th dimension model parameters of multiple clients can be Euclidean distances.

[0024] In one embodiment, the Euclidean distance can be calculated using formula (1). .

[0025] (1) in, Let m be the model parameters of client k. Let m be the model parameters of client j. Let t be the total number of clients and t be the iteration round.

[0026] In one embodiment, m is a positive integer less than or equal to the number of dimensions of the model parameters.

[0027] S103. Sort the multiple distances corresponding to each client in ascending order to obtain the sorted multiple distances corresponding to each client.

[0028] In this embodiment, the multiple distances corresponding to each client can be used to form a distance set D for the m-th dimension model parameters. Each client's multiple distances occupy one row of the distance set D.

[0029] For example, the distance set D of the m-th dimension model parameters can be seen in Table 1. The first row contains N distances between client 1 and N other clients, the second row contains N distances between client 2 and N other clients, and so on, with the Nth row containing N distances between client N and N other clients.

[0030] Table 1

[0031] In this embodiment of the application, the multiple distances corresponding to each client are sorted in ascending order, which can be done by sorting each row of elements in the distance set D in ascending order.

[0032] For example, the distance set D of the sorted m-th dimension model parameters can be found in Table 2.

[0033] Table 2

[0034] S104. Extract the nth column distance from multiple sorted distances corresponding to multiple clients as a security threshold; n is a positive integer.

[0035] In one embodiment, the value of n is determined based on a threshold of the number of attacked clients.

[0036] For example, if the number of attacked clients among multiple clients that upload multiple model parameters of the same dimension does not exceed half of the total number of clients, then half of the total number of clients is taken as the threshold for the number of attacked clients. In this case, n is half of the total number of clients, i.e., N / 2.

[0037] For example, referring to Table 2, the first one can be... Columns As the distance in the nth column.

[0038] In this embodiment of the application, two sorting operations can also be performed. That is, after extracting the distance of the nth column, the distance of the nth column is sorted in ascending order to obtain the sorted distance of the nth column; then, the distance of the lth row is extracted from the sorted distance of the nth column as a safety threshold, where l is a positive integer.

[0039] In one embodiment, the value of l can be the same as the value of n, or the value of l can be determined based on a threshold of the number of attacked clients.

[0040] For example, for Sort in ascending order to get .

[0041] For example, it can be The first in OK As the distance of the l-th row.

[0042] It is understood that, in this embodiment, by utilizing the distance between model parameters and selecting the threshold reference value for density calculation through two sorting operations, adaptive threshold selection can be achieved. This allows for adaptive adjustment of the safety threshold in each round of training iterations. Furthermore, it eliminates the need for modification and re-tuning of hyperparameters during training tasks and model switching, reducing resource usage and training time, and enabling real-time automatic adjustment.

[0043] S105. Identify the m-th dimension security model parameters from the m-th dimension model parameters using the security threshold.

[0044] In this embodiment, the m-th dimension density information of each client can be determined first using a security threshold and multiple distances; then, the multiple m-th dimension density information of multiple clients are compared with the first threshold in sequence, and the m-th dimension security model parameter is identified from the m-th dimension model parameter based on the comparison result.

[0045] Specifically, the process of determining the m-th dimension density information of each client using a security threshold and multiple distances includes: inputting the security threshold and multiple distances into a Gaussian kernel function to obtain the Gaussian kernel density of each client; and determining the Gaussian kernel density of each client as the m-th dimension density information of each client.

[0046] In one embodiment, the m-th dimension density information of client k is calculated using a Gaussian kernel function. The process can be found in formula (2).

[0047] (2) in, As a safety threshold, Let be the Euclidean distance between the m-th dimension model parameters of client k and the m-th dimension model parameters of client j.

[0048] In one embodiment, the first threshold can be a threshold for the number of attacked clients, that is, the value of the first threshold can be the same as the value of n.

[0049] In one embodiment, if Then it represents the corresponding Unsafe; if Then it represents the corresponding Security. For each security model parameter of each client, the security status can be determined using the calculated density information of each dimension.

[0050] In one embodiment, security model parameters are collected to obtain a security model parameter set. .

[0051] Furthermore, after identifying the m-th dimension security model parameter from the m-th dimension model parameter using the security threshold, the security model parameters of multiple dimensions can be aggregated to obtain the aggregated model parameter; the aggregated model parameter can then be sent to multiple clients.

[0052] Specifically, the process of aggregating security model parameters from multiple dimensions to obtain aggregated model parameters includes: aggregating the security model parameters of each dimension based on multiple density information of each dimension to obtain aggregated security model parameters for each dimension; wherein, multiple density information corresponds to multiple clients; and converging the aggregated security model parameters of each dimension to obtain aggregated model parameters.

[0053] In one embodiment, the process of aggregating the security model parameters of each dimension based on multiple density information of each dimension to obtain the aggregated security model parameters of each dimension can be found in formulas (3) and (4).

[0054] (3) (4) in, These are the parameters of the m-th dimension of the security model after aggregation. For the m-th dimension of the security model parameter element of client j, For the m-th dimension density information of client j, This represents the m-th dimension density information for client i.

[0055] Understandable, The design also utilizes multiple density information in each dimension, which can effectively reduce the impact of large deviations or poor quality safety model parameters on model training, thereby improving the accuracy and efficiency of model training.

[0056] In one embodiment, after obtaining the aggregated security model parameters for each dimension, the aggregated model parameters for each dimension are... By converging, we can obtain the complete parameters of the aggregation model. .

[0057] Understandably, for Non-IID data stored under the FL architecture, the security detection method proposed in this application calculates the density value of each dimension of the model parameter element and compares it with the security reference value. It filters out low-density insecure values, retains high-density secure elements, and further uses the density values ​​to design adaptive aggregation weights for aggregation, thus updating the model. This approach not only effectively detects malicious data but also retains more secure elements, achieving efficient model aggregation and ensuring the accuracy of the trained model. Simultaneously, it largely preserves the original secure model parameters, minimizing modifications to them. This ensures that Non-IID data, after aggregation using security strategies, has minimal difference from the actual model parameters, improving the accuracy of model training. Therefore, the security detection method proposed in this application can effectively achieve security detection and ensure model accuracy in both IID and Non-IID data formats.

[0058] In one embodiment, the aggregated model parameters can be distributed to each client for the next round of training.

[0059] Understandably, for each client's m-th dimension model parameter, after obtaining multiple distances between multiple clients' m-th dimension model parameters, the distances are sorted and the nth column of the sorted distance is extracted as a security threshold. This allows for a more accurate representation of the security threshold of each client's m-th dimension model parameter. During the security identification process, corresponding security thresholds are set for model parameters of different dimensions based on the sorting of distances, enabling more accurate screening of malicious parameters of different dimensions, improving the accuracy of malicious parameter identification, and thus improving the accuracy of model training.

[0060] Based on the above embodiments, this application proposes a training method. This method includes two modules: a client module and a central server module. The client module receives model update parameters from the central server, trains the model using local data, and then uploads the newly obtained model update parameters to the central server. Malicious clients may upload fake model update data. The central server module collects the model parameters uploaded by each client, aggregates the parameters according to a set strategy, and then distributes the aggregated model parameters to each client. The process of parameter identification by the central server in iteration t+1 can be found in [reference needed]. Figure 3 It includes the following parts.

[0061] Client-side model parameter upload: N clients upload model parameters respectively. To the central server, among which, It is an M-dimensional column vector.

[0062] The central server consists of the following components: Model parameter collection: The central server collects model parameters uploaded by N clients. .

[0063] Euclidean distance calculation: The central server calculates the m-th dimension model parameters for client k. With the m-th dimension model parameters of client j Euclidean distance between each pair .

[0064] Two sorting steps: Central server for Euclidean distance Perform two sorting operations to obtain the security threshold corresponding to each dimension of the model parameter for each client. .

[0065] (1) First sorting: The Euclidean distances between the m-th dimension model parameters of one client and the m-th dimension model parameters of multiple clients are grouped into a row to form the distance set D of the m-th dimension model parameters. The elements in each row of the distance set D are sorted in ascending order D1.

[0066] (2) Second sorting: D1 is drawn from the first sorting point. Find the elements in column D2 and sort them in ascending order. Extract the first element from D2. Row elements serve as the safety threshold for the m-th dimension model parameters. .

[0067] Local density calculation: The central server uses a security threshold. And based on the density calculation defined by the Gaussian kernel density .

[0068] Element detection: The central server will Compared with reference value (Assuming the number of times the same dimension of model parameters is attacked across all clients does not exceed a certain limit) (Comparison, as a basis for judgment) The basis for whether it is safe.

[0069] Element aggregation: The central server aggregates the security elements of each dimension and combines the aggregated elements of each dimension to obtain complete aggregation model parameters.

[0070] The above-mentioned Euclidean distance calculation, double sorting, local density calculation, element detection, and element aggregation are all part of the algorithm processing flow of the embodiments of this application.

[0071] Aggregate Parameter Distribution: The central server distributes the aggregated model parameters to multiple clients for the next round of training.

[0072] Understandably, this application utilizes the density information of model parameters as a detection reference, enabling security parameter detection and effective model training in generalized Byzantine attack scenarios. Furthermore, designing adaptive aggregation weights using density values ​​can improve the quality of the trained model.

[0073] This application provides a parameter identification device. For example... Figure 4 As shown, the parameter identification device 1 includes: The receiving unit 10 is used to receive multiple sets of model parameters from multiple clients; wherein each client corresponds to a set of model parameters, and each set of model parameters includes model parameters in multiple dimensions. The acquisition unit 11 is used to acquire multiple distances between the m-th dimension model parameters of each client and multiple m-th dimension model parameters of multiple clients; m is a positive integer; The sorting unit 12 is used to sort the multiple distances corresponding to each client in ascending order to obtain the sorted multiple distances corresponding to each client. Extraction unit 13 is used to extract the nth column distance as a security threshold from multiple sorted distances corresponding to multiple clients; n is a positive integer; The identification unit 14 is used to identify the m-th dimension security model parameter from the m-th dimension model parameter using the security threshold.

[0074] Optionally, the sorting unit 12 is further configured to sort the nth column distance in ascending order to obtain the sorted nth column distance; The extraction unit 13 is also used to extract the distance of the lth row from the sorted nth column distance as the security threshold, where l is a positive integer.

[0075] Optionally, the parameter identification device further includes: a determination unit; The determining unit is used to determine the m-th dimension density information of each client using the security threshold and the multiple distances; The identification unit 14 is further configured to compare multiple m-th dimension density information of multiple clients sequentially with a first threshold, and identify the m-th dimension security model parameter from the m-th dimension model parameter based on the comparison result.

[0076] Optionally, the determining unit is further configured to input the security threshold and the plurality of distances into a Gaussian kernel function to obtain the Gaussian kernel density of each client; and to determine the Gaussian kernel density of each client as the m-th dimension density information of each client.

[0077] Optionally, the parameter identification device further includes: an aggregation unit and a distribution unit; The aggregation unit is used to aggregate security model parameters from multiple dimensions to obtain aggregated model parameters. The sending unit is used to send the aggregation model parameters to the multiple clients.

[0078] Optionally, the aggregation unit is further configured to aggregate the security model parameters of each dimension based on the multiple density information of each dimension to obtain the aggregated security model parameters of each dimension; wherein the multiple density information corresponds to multiple clients respectively; and the aggregated security model parameters of each dimension are converged to obtain the aggregated model parameters.

[0079] Optionally, the value of n is determined based on a threshold of the number of attacked clients.

[0080] This application provides a parameter identification device that receives multiple sets of model parameters from multiple clients. Each client corresponds to a set of model parameters, and each set of model parameters includes model parameters in multiple dimensions. Multiple distances are obtained between the m-th dimension model parameter of each client and the multiple m-th dimension model parameters of the multiple clients, where m is a positive integer. The multiple distances corresponding to each client are sorted in ascending order to obtain sorted multiple distances corresponding to each client. The n-th column distance is extracted from the sorted multiple distances corresponding to the multiple clients as a security threshold, where n is a positive integer. The security threshold is used to identify the m-th dimension safe model parameter from the m-th dimension model parameters. Therefore, the parameter identification device proposed in this embodiment, for the m-th dimension model parameter of each client, after obtaining multiple distances between multiple m-th dimension model parameters of multiple clients, sorts the multiple distances and extracts the nth column distance of the sorted distance as a security threshold, so as to more accurately represent the security threshold of the m-th dimension model parameter of each client. In the process of security identification, the corresponding security threshold is set for the model parameters of different dimensions according to the sorting of distances, so that malicious parameters of different dimensions can be more accurately screened out, improving the accuracy of malicious parameter identification, and thus improving the accuracy of model training.

[0081] Figure 5 This is a schematic diagram of the composition structure of a parameter identification device 1 provided in an embodiment of this application. In practical applications, based on the same disclosed concept of the above embodiments, such as... Figure 5 As shown, the parameter identification device 1 in this embodiment includes: a processor 15, a memory 16, and a communication bus 17.

[0082] The processor 15 described above can be at least one of the following: Application Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array (FPGA), CPU, controller, microcontroller, and microprocessor. It is understood that, for different devices, the electronic device used to implement the above processor function can also be other types, and this embodiment does not specifically limit it.

[0083] In this embodiment, the communication bus 17 is used to establish communication between the processor 15 and the memory 16; when the processor 15 executes the running program stored in the memory 16, it implements the following parameter identification method: The system receives multiple sets of model parameters from multiple clients; each client corresponds to a set of model parameters, and each set of model parameters includes model parameters in multiple dimensions; it obtains multiple distances between the m-th dimension model parameter of each client and the multiple m-th dimension model parameters of the multiple clients; m is a positive integer; it sorts the multiple distances corresponding to each client in ascending order to obtain the sorted multiple distances corresponding to each client; it extracts the n-th column distance from the multiple sorted multiple distances corresponding to the multiple clients as a security threshold; n is a positive integer; and it uses the security threshold to identify the m-th dimension safe model parameter from the m-th dimension model parameters.

[0084] Furthermore, the processor 15 is also used to sort the nth column distance in ascending order to obtain the sorted nth column distance; and to extract the lth row distance from the sorted nth column distance as the security threshold, where l is a positive integer.

[0085] Furthermore, the processor 15 is also configured to determine the m-th dimension density information of each client using the security threshold and the plurality of distances; to compare the plurality of m-th dimension density information of the plurality of clients sequentially with the first threshold, and to identify the m-th dimension security model parameter from the m-th dimension model parameter based on the comparison result.

[0086] Furthermore, the processor 15 is also configured to input the security threshold and the plurality of distances into a Gaussian kernel function to obtain the Gaussian kernel density of each client; and to determine the Gaussian kernel density of each client as the m-th dimension density information of each client.

[0087] Furthermore, the processor 15 is also used to aggregate security model parameters from multiple dimensions to obtain aggregated model parameters; and to send the aggregated model parameters to the multiple clients.

[0088] Furthermore, the processor 15 is also configured to aggregate the security model parameters of each dimension based on the multiple density information of each dimension to obtain the aggregated security model parameters of each dimension; wherein the multiple density information corresponds to multiple clients respectively; and to aggregate the aggregated security model parameters of each dimension to obtain the aggregated model parameters.

[0089] Furthermore, the value of n is determined based on a threshold of the number of attacked clients.

[0090] This application provides a storage medium storing a computer program thereon. The computer-readable storage medium stores one or more programs, which can be executed by one or more processors and applied in a terminal. The computer program implements the parameter recognition method described above.

[0091] Based on the above embodiments, this application provides a computer program product, including a computer program that can be executed by one or more processors, and the computer program implements the parameter identification method described above.

[0092] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0093] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the related technology, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause an image display device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this disclosure.

[0094] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application.

Claims

1. A parameter identification method, characterized in that, The method includes: It receives multiple sets of model parameters from multiple clients; each client corresponds to a set of model parameters, and each set of model parameters includes model parameters in multiple dimensions. Obtain the multiple distances between the m-th dimension model parameters of each client and the multiple m-th dimension model parameters of multiple clients; m is a positive integer; Sort the multiple distances corresponding to each client in ascending order to obtain the sorted multiple distances for each client; The nth column distance is extracted as the security threshold from multiple sorted distances corresponding to multiple clients; n is a positive integer. The security model parameters of the m-th dimension are identified from the m-th dimension model parameters using the security threshold.

2. The method according to claim 1, characterized in that, The method further includes: Sort the distances in the nth column in ascending order to obtain the sorted distances in the nth column; The distance of the l-th row is extracted from the distance of the n-th column after sorting as the security threshold, where l is a positive integer.

3. The method according to claim 1, characterized in that, The step of identifying the m-th dimension security model parameter from the m-th dimension model parameters using the security threshold includes: The m-th dimension density information of each client is determined using the security threshold and the multiple distances; Multiple m-th dimension density information from multiple clients are sequentially compared with a first threshold, and the m-th dimension security model parameter is identified from the m-th dimension model parameter based on the comparison result.

4. The method according to claim 3, characterized in that, The process of determining the m-th dimension density information for each client using the security threshold and the multiple distances includes: The security threshold and the multiple distances are input into the Gaussian kernel function to obtain the Gaussian kernel density for each client; The Gaussian kernel density of each client is determined as the m-th dimension density information of each client.

5. The method according to claim 1, characterized in that, After identifying the m-th dimension security model parameter from the m-th dimension model parameters using the security threshold, the method further includes: By aggregating security model parameters from multiple dimensions, we obtain aggregated model parameters; The aggregation model parameters are sent to the multiple clients.

6. The method according to claim 5, characterized in that, The aggregation of security model parameters from multiple dimensions to obtain aggregated model parameters includes: The security model parameters for each dimension are aggregated based on multiple density information for each dimension to obtain aggregated security model parameters for each dimension; wherein, the multiple density information corresponds to multiple clients respectively. The aggregated security model parameters for each dimension are combined to obtain the aggregated model parameters.

7. The method according to claim 1, characterized in that, The value of n is determined based on a threshold of the number of attacked clients.

8. A parameter identification device, characterized in that, The parameter identification device includes a processor, a memory, and a communication bus; when the processor executes the running program stored in the memory, it implements the method as described in any one of claims 1-7.

9. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1-7.

10. A computer program product, comprising a computer program, characterized in that, The computer program, when executed by a processor, implements the method as described in any one of claims 1 to 7.