A privacy protection federated learning backdoor defense method based on multi-head geometric perception
Patent Information
- Application Number
- CN202611003551.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-07
- Publication Date
- 2026-09-11
- Estimated Expiration
- 2046-07-07
AI Technical Summary
[0006]本发明的主要目的在于提供一种基于多头几何感知的隐私保护联邦学习后门防御方法,以解决隐私保护联邦学习中密文环境难以执行后门验证、非独立同分布数据导致良性更新漂移、隐蔽后门更新难以与正常异构更新区分的问题
Smart Images

Figure CN122513095B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of artificial intelligence security and privacy protection technology, and relates to federated learning, privacy-preserving machine learning, homomorphic encryption and backdoor attack defense methods. In particular, it relates to a privacy-preserving federated learning backdoor defense method based on multi-head geometric perception. Background Technology
[0002] Federated learning, as a distributed machine learning paradigm, allows multiple clients to collaboratively train a shared global model without directly uploading their local raw data. This paradigm reduces the privacy risks associated with centralized data collection; however, model parameters or gradient updates uploaded by clients during training may still leak local data distribution, privacy attributes, and even training sample information. To further enhance privacy protection, existing solutions typically combine federated learning with techniques such as differential privacy, secure multi-party computation, or homomorphic encryption to perturb, secretly share, or perform ciphertext computation on client model updates.
[0003] However, homomorphic encryption also introduces new security challenges: servers cannot directly view model parameters or gradient plaintext, making traditional backdoor defense methods that rely on plaintext parameter distribution, coordinate anomalies, gradient direction, or neuron activation features difficult to apply directly. Backdoor attacks in federated learning are typically achieved by malicious clients through polluting local data, tampering with training objectives, or manipulating model parameters. These attacks can enable the global model to maintain high performance on normal samples while outputting attacker-specified labels on samples with preset triggers, thus possessing strong stealth and harmfulness. In privacy-preserving federated learning, malicious updates may be encrypted and hidden; simultaneously, non-independent, identically distributed data can cause significant benign gradient drift between normal clients, making it even more difficult to distinguish between malicious backdoor updates and normal heterogeneous updates.
[0004] Existing backdoor defense methods are mostly geared towards plaintext federated learning scenarios, requiring the server to directly access model parameters or gradients. Meanwhile, privacy-preserving federated learning defense methods often employ similarity aggregation rules designed for Byzantine attacks, making it difficult to fully capture the complex anomalies in local parameter regions, directional relationships, and magnitude shifts during covert backdoor updates. Furthermore, existing solutions generally lack fine-grained backdoor verification mechanisms for encrypted environments and cannot effectively adapt to benign drift caused by non-independent, identically distributed data, resulting in a trade-off between defense accuracy and model usability.
[0005] In summary, to address the problem that existing technologies cannot perform fine-grained backdoor verification in a encrypted environment and effectively distinguish between malicious backdoor updates and benign heterogeneous updates while protecting the privacy of client model parameters, a privacy-preserving federated learning backdoor defense method based on multi-head geometric perception is proposed. Summary of the Invention
[0006] The main objective of this invention is to provide a privacy-preserving federated learning backdoor defense method based on multi-head geometric perception, in order to solve the problems of backdoor verification being difficult to perform in encrypted environments, benign update drift caused by non-independent and identically distributed data, and difficulty in distinguishing hidden backdoor updates from normal heterogeneous updates in privacy-preserving federated learning.
[0007] Based on the first main aspect of the present invention, a privacy-preserving federated learning backdoor defense method based on multi-head geometry perception is provided, comprising four types of entities: a key generation center, an aggregation server, a collaborative server, and several clients. The method includes:
[0008] The key generation center generates client public-private key pairs and server public-private key pairs; the client public-private key pairs are sent to each client; the aggregation server initializes the global model and distributes the global model encrypted with the client public key to each client;
[0009] The client receives and decrypts the encrypted global model, performs local training using the objective function, and obtains a local model. The local model is then divided into several sub-vectors, and the sub-vectors are encrypted using the server's public key before being uploaded to the aggregation server.
[0010] The aggregation server uses homomorphic encryption to calculate the intermediate geometric statistics of the encrypted subvector, and derives the ciphertext intermediate geometric statistics in the ciphertext domain based on the intermediate geometric statistics and sends them to the cooperating server.
[0011] The collaborative server decrypts the intermediate geometric statistics of the ciphertext, constructs four deterministic geometric heads for each sub-vector, thereby forming a multi-head target matrix corresponding to each sub-vector and performing joint backdoor detection to obtain a set of malicious clients; for clients not included in the set of malicious clients, the aggregation weight is calculated and encrypted and sent to the aggregation server, and weighted aggregation is performed in the ciphertext domain to obtain the encrypted next round global model;
[0012] The aggregation server and the collaboration server perform a mask re-encryption process, converting the next-round global model encrypted with the server's public key into the next-round global model encrypted with the client's public key, and then distributing it to each client. The above steps are repeated until the preset number of training rounds or the global model meets the convergence condition.
[0013] The above technical solution describes four types of entities and their interaction process: a key generation center, an aggregation server, a collaboration server, and several clients. By organically combining the steps of encrypted distribution of the global model, encrypted uploading of sub-vectors after local training, calculation of geometric statistics by the aggregation server in the ciphertext domain, construction of multi-head geometric features by the collaboration server after encryption to perform backdoor detection, and security model update based on mask re-encryption, the entire federated learning process can effectively detect and defend against backdoor attacks without exposing the model parameters to the aggregation server and collaboration server. This solves the difficulties of backdoor detection under privacy protection constraints and the problem of secure connection between the detection and training processes.
[0014] As a further preferred embodiment, in the aforementioned method, the objective function includes an amplitude regularization term and a direction regularization term, as detailed below:
[0015] ;
[0016] in, Represent the objective function; Indicates the local model; Indicates the first Round global model; Indicates the communication rounds in federated learning; This represents the client's local experience loss function; Represents the regularization coefficient. This represents the magnitude regularization term, used to constrain the magnitude offset of the local model relative to the global model; This represents the direction regularization term, used to constrain the directional differences between the local model and the global model.
[0017] By adding amplitude and direction regularization terms to the objective function, the amplitude and direction offsets of the local model relative to the global model are constrained. This suppresses the benign drift caused by data heterogeneity in normal clients, while malicious backdoor updates exhibit more obvious abnormal characteristics because they deviate from the constraints of the global model in amplitude and direction. This improves the ability of subsequent geometric perception detection to distinguish between benign heterogeneity and malicious backdoors.
[0018] As a further preferred embodiment, in the aforementioned method, the execution steps of dividing into several sub-vectors are as follows;
[0019] When partitioning the local model into subvectors, each client's local model is divided into subvectors whose product is based on the preset number of model layers and classification task categories; or the local model is partitioned into subvectors based on the preset layer structure, channel structure, category parameter structure, or fixed length rules.
[0020] This invention can divide the local model into fine-grained sub-vectors through different rules, which can amplify the abnormal traces left by backdoor attacks in the local parameter region, avoid the dilution effect of overall parameter comparison on abnormal signals in traditional methods, and solve the problem of difficult capture of hidden backdoors in privacy-preserving federated learning.
[0021] As a further preferred embodiment, in the aforementioned method, the homomorphic encryption includes addition, multiplication, and rotation of homomorphic encryption;
[0022] The intermediate geometric statistics include the client-to-client inner product, the squared norm of the client subvector, the local-to-global inner product, and the squared norm of the global subvector, as detailed below:
[0023] ;
[0024] in, Indicates the inter-client product; Both represent client-side indexes, used to distinguish different clients; Indicates the subvector index; Represents the transpose of a vector; Indicates the first The local model obtained after the client's local training is completed. Subvectors; Indicates the first The local model obtained after the client's local training is completed. Subvectors; Represents the squared norm of the client-side subvector; Represents the local-global inner product; Indicates the current global model at the [number]th [year]. The parameter values on each subvector; This represents the sub-vector corresponding to the current global model; Represents the squared norm of the global subvector;
[0025] The steps for deriving the intermediate geometric statistics of the ciphertext in the ciphertext domain and sending them to the cooperative server are as follows:
[0026] Based on the inter-client inner product, the squared norm of the client subvector, the local-global inner product, and the squared norm of the global subvector, the aggregation server further derives the residual inner product, the squared norm of the residual, and the residual-global inner product in the ciphertext domain, specifically:
[0027] ;
[0028] in, Represents the inner product of residuals; Indicates the inter-client product; Indicates the first Local-global inner product of each client; Represents the squared norm of the global subvector; Represents the squared residual norm; Represents the squared norm of the client-side subvector; Represents the local-global inner product; Represents the squared norm of the global subvector; This represents the residual-global inner product; in this formula Both represent client-side indexes, used to distinguish different clients; Indicates the subvector index.
[0029] In the above technical solution, the geometric statistics calculated by the aggregation server in the ciphertext domain are provided. This enables the complete calculation of all statistical information required for subsequent multi-head geometric verification without decrypting the ciphertext model, using the addition, multiplication and rotation operations of homomorphic encryption. This overcomes the technical problem that model parameters cannot be directly obtained for backdoor verification in the ciphertext environment, and provides a data foundation for backdoor detection for privacy protection by collaborative servers.
[0030] As a further preferred embodiment, in the aforementioned method, the steps for constructing the four deterministic geometric heads are as follows:
[0031] The collaborative server uses a private key to decrypt intermediate geometric statistics and constructs four deterministic geometric heads for each subvector; the four deterministic geometric heads include the original parameter head, the orientation head, the residual head, and the residual orientation head;
[0032] The original parameter header preserves the original parameter relationships of the client model subvectors; the direction header describes the angular consistency of the client model updates; the residual header measures the drift of the local model relative to the global model; and the residual direction header describes the directional relationship of this drift.
[0033] The execution steps for forming the multi-head target matrix corresponding to each sub-vector are as follows:
[0034] For each deterministic geometry head, firstly, the collaborative server uses the intermediate geometry statistics obtained from decryption to calculate the attention scores among clients, and performs normalization processing on each row of attention scores to form a client attention matrix;
[0035] Secondly, calculate the Euclidean distance between clients to form an Euclidean distance matrix; then calculate the local-global similarity features and local-global distance features between each client and the global model to form local-global geometric features;
[0036] The collaborative server concatenates the four attention matrices, four Euclidean distance matrices, and four sets of local-global geometric features corresponding to the same sub-vector to form the multi-head target matrix corresponding to that sub-vector.
[0037] By combining attention relationships, distance relationships, and local-global relationships from four geometric perspectives—original parameters, normalization direction, residual drift, and residual direction—the similarities and differences between various clients are comprehensively characterized. This avoids the problem that a single perspective is insufficient to effectively distinguish between malicious backdoor updates and normal updates, and provides rich feature representations for joint backdoor detection.
[0038] As a further preferred embodiment, in the aforementioned method, the execution steps for performing joint backdoor detection are as follows:
[0039] The collaborative server first concatenates the corresponding row vectors of the same client in all multi-head target matrices to form the multi-head target vector of the client. It then performs binary spectral clustering on the multi-head target vectors of all clients. Based on the assumption that the number of malicious clients is less than half of the total number of participating clients, it compares the two client clusters obtained after clustering. The client cluster with fewer clients is the first abnormal client set.
[0040] Secondly, the collaborative server performs isolated forest detection on the multi-head target matrix of each sub-vector to obtain the abnormal score vector of all clients on that sub-vector; the abnormal scores on all sub-vectors are stacked to form a score matrix, and the average abnormal score of the clients is calculated.
[0041] The threshold is set based on the median of the average abnormal scores of all clients, or the threshold is set according to actual needs; when the average abnormal score of a client is less than the difference between the median of the average abnormal scores of all clients and the threshold, the client is added to the second abnormal client set.
[0042] The set of malicious clients is obtained by taking the union of the first set of abnormal clients and the second set of abnormal clients.
[0043] This invention employs a fusion of binary spectral clustering and isolated forest detection in the joint backdoor detection step. Spectral clustering identifies small clusters of malicious groups from the global client relationship structure, while isolated forest captures clients that deviate from the normal distribution from the local anomaly scores of each sub-vector. The results are then integrated through a union. This complementary mechanism can cover different types of backdoor attack modes, such as centralized and decentralized ones. At the same time, it uses the benign majority hypothesis to control false positives, solving the problems of insufficient coverage of attack modes and poor detection robustness of single detection methods.
[0044] As a further preferred embodiment, in the aforementioned method, the steps for calculating the aggregation weight are as follows:
[0045] Calculate the aggregate score on each subvector of each benign client, then average the aggregate scores on all subvectors to obtain the average score, and finally normalize the average score of all benign clients to obtain the aggregate weight.
[0046] The aggregation server performs a ciphertext weighted summation on the corresponding encrypted local models according to the encrypted aggregation weights of each benign client, and completes the next round of global model aggregation;
[0047] The execution steps of the mask re-encryption process are as follows:
[0048] The aggregation server adds a random mask to the next round of global model encrypted with the server's public key, obtains the encrypted mask model, and sends it to the collaboration server.
[0049] After decrypting the encryption mask model, the collaboration server re-encrypts it using the client's public key and returns it to the aggregation server.
[0050] The aggregation server removes the random mask from the client's public key encryption field to obtain the next round of global model encrypted with the client's public key.
[0051] This invention, through the above design, can adaptively reduce the interference of potential abnormal clients on the global model after eliminating malicious clients, ensuring the secure aggregation of the model. At the same time, the mask re-encryption process allows the collaborative server to access the encrypted global model, solving the problem of how to securely generate a backdoor-free global model and distribute it to clients.
[0052] Based on a second key aspect of the present invention, a privacy-preserving federated learning backdoor defense system based on multi-head geometry awareness, implementing the aforementioned method, is provided, comprising:
[0053] The initialization and key distribution module is used to generate and distribute public and private key pairs;
[0054] The local training module receives the global model, adds a regularization term aligned with subsequent detection metrics to the local training objective to perform local training, and divides the trained local model into several sub-vectors, encrypts them using the server's public key, and uploads them to the aggregation server.
[0055] The ciphertext intermediate geometric statistics calculation module is used to collect encrypted subvectors, calculate intermediate geometric statistics in the ciphertext domain without decryption, and send them to the collaborative server.
[0056] The multi-head target matrix construction module is used by the collaborative server to decrypt the encrypted intermediate geometric statistics and construct the multi-head target matrix corresponding to each sub-vector based on four deterministic geometric heads.
[0057] The joint backdoor detection module is used to detect malicious clients by combining spectral clustering and isolated forest based on the multi-head target matrix of all sub-vectors.
[0058] The secure weighted aggregation module is used by the collaboration server to calculate the aggregation weight for clients that have not been identified as malicious and send it to the aggregation server in encrypted form. The aggregation server then performs weighted aggregation on the encrypted data based on the aggregation weight to update the global model.
[0059] The mask re-encryption and model distribution module is used to convert the aggregated global model encrypted by the collaboration server into the next round of global model encrypted by the client's public key by adding random masks, decrypting, re-encrypting, and removing masks, and then distribute it to each client.
[0060] Based on a third key aspect of the present invention, an electronic device is provided, comprising: a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus;
[0061] The memory stores a computer program that, when executed by the processor, causes the processor to perform the aforementioned privacy-preserving federated learning backdoor defense method based on multi-head geometric perception.
[0062] Based on a fourth key aspect of the present invention, a computer-readable storage medium is provided having a computer program stored thereon that, when executed, implements the aforementioned privacy-preserving federated learning backdoor defense method based on multi-head geometry perception.
[0063] Compared with existing technologies, this invention provides a privacy-preserving federated learning backdoor defense method based on multi-head geometric perception. First, this invention divides client model updates into multiple sub-vectors for fine-grained verification, amplifying the abnormal traces left by backdoor attacks in local parameter regions and avoiding the dilution of abnormal signals through overall comparison. Based on this, by constructing a multi-head geometric representation and introducing attention relationships, Euclidean distance, and local-global geometric features, it comprehensively characterizes the relationships and magnitude shifts between client updates from different geometric perspectives. This solves the technical problem of difficulty in performing backdoor verification in encrypted environments, enabling effective differentiation between covert backdoor updates and normal heterogeneous updates.
[0064] Secondly, this invention introduces a regularization term aligned with subsequent detection metrics during the local training phase. By combining amplitude and direction regularization terms, the local model's offset relative to the global model is constrained. This mitigates benign drift caused by non-independent and identically distributed data while preserving the unique anomaly patterns characteristic of backdoor attacks. This design overcomes the technical shortcomings of existing privacy-preserving federated learning defense methods, which rely solely on similarity aggregation rules and struggle to capture complex parameter anomalies. It achieves improved sensitivity and specificity of backdoor detection while maintaining the accuracy of the primary task.
[0065] Finally, this invention fully protects the privacy information of client model parameters and the global model through homomorphic encryption, a non-collusive dual-server architecture, and a mask re-encryption process. The aggregation server only processes geometric statistics in the encrypted state, the collaboration server can only decrypt preset statistics and cannot restore the original model sub-vectors, and the client's private key is only used locally to decrypt the global model. Thus, backdoor detection and weighted aggregation are completed without leaking client model sub-vectors and coordinate-level gradients. While ensuring the original security attributes of privacy-preserving federated learning, this invention achieves fine-grained backdoor defense in the encrypted environment, adaptive tolerance to non-independent and identically distributed data, and alignment and unification of detection and training objectives. Attached Figure Description
[0066] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, obtaining other drawings based on these drawings without creative effort still falls within the scope of the present invention.
[0067] Figure 1 The following is an execution flowchart of a privacy-preserving federated learning backdoor defense method based on multi-head geometry perception in one embodiment of the present invention;
[0068] Figure 2 A schematic diagram of the system architecture of a privacy-preserving federated learning backdoor defense method based on multi-head geometry perception is shown in one embodiment of the present invention;
[0069] Figure 3 The diagram illustrates the overall process of a privacy-preserving federated learning backdoor defense method based on multi-head geometry perception in one embodiment of the present invention. Detailed Implementation
[0070] The preferred embodiments of the present invention will be described in detail below to provide a clearer understanding of the purpose, features, and advantages of the invention. It should be understood that the following embodiments are not intended to limit the scope of the invention, but are merely illustrative of the essential spirit of the technical solution of the invention.
[0071] In the following description, certain specific details are set forth for the purpose of illustrating various disclosed embodiments in order to provide a thorough understanding of the various disclosed embodiments. However, those skilled in the art will recognize that embodiments may be practiced without one or more of these specific details. In other instances, well-known techniques associated with the invention may not have been shown or described in detail to avoid unnecessarily obscuring the description of the embodiments.
[0072] Throughout this specification, references to "an embodiment" or "an embodiment" indicate that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. Therefore, the appearance of "in an embodiment" or "an embodiment" in various places throughout the specification does not necessarily refer to the same embodiment. Furthermore, a particular feature, structure, or characteristic may be combined in any manner in one or more embodiments.
[0073] The following is a description of the specific meanings of technical terms, English abbreviations, and formula parameters that may be used in this invention:
[0074] Federated learning: A distributed machine learning framework that allows clients to collaboratively train a global model without sharing their local raw data.
[0075] Spectral clustering: A graph-based clustering algorithm that treats data samples as nodes in a graph, uses the similarity between samples as the weight of the edges, and maps the original high-dimensional data to a low-dimensional feature space by calculating the eigenvectors of the Laplacian matrix of the graph. Then, it uses traditional clustering methods to divide the eigenvectors.
[0076] Isolation Forest: An unsupervised anomaly detection algorithm based on tree structure. It recursively divides the data space by randomly selecting a feature and a split value, and constructs multiple random binary trees. For each sample, it calculates the average path length in all trees. The shorter the path, the higher the probability of an anomaly.
[0077] CKKS scheme: A homomorphic encryption scheme that supports approximate algorithm operations. Unlike traditional exact homomorphic encryption, CKKS allows addition and multiplication operations on encrypted floating-point numbers, yielding decryption results that approximate the plaintext operations.
[0078] Homomorphic encryption: a form of encryption that allows specific types of mathematical operations to be performed directly on ciphertext, and the result of decryption after the operation is the same as the result of performing the same operation on the plaintext.
[0079] Combination Figure 1 As shown, this invention provides a privacy-preserving federated learning backdoor defense method based on multi-head geometry awareness, which consists of four types of entities: a key generation center, an aggregation server, a collaborative server, and several clients. The method includes the following steps S100~S500:
[0080] S100, the key generation center generates client public-private key pairs and server public-private key pairs; sends the client public-private key pairs to each client; the aggregation server initializes the global model and distributes the global model encrypted with the client public key to each client;
[0081] S200: The client receives and decrypts the encrypted global model, performs local training using the objective function, and obtains a local model; the local model is divided into several sub-vectors, and the sub-vectors are encrypted using the server's public key before being uploaded to the aggregation server;
[0082] S300, the aggregation server uses homomorphic encryption to calculate the intermediate geometric statistics of the encrypted sub-vector, and derives the ciphertext intermediate geometric statistics in the ciphertext domain based on the intermediate geometric statistics and sends it to the cooperating server.
[0083] S400, the collaborative server decrypts the intermediate geometric statistics of the ciphertext, constructs four deterministic geometric heads for each sub-vector, thereby forming a multi-head target matrix corresponding to each sub-vector and performing joint backdoor detection to obtain a set of malicious clients; for clients not included in the set of malicious clients, the aggregation weight is calculated and encrypted and sent to the aggregation server, and weighted aggregation is performed in the ciphertext domain to obtain the encrypted next round global model;
[0084] In S500, the aggregation server and the collaboration server perform a mask re-encryption process, converting the next-round global model encrypted with the server's public key into the next-round global model encrypted with the client's public key, and then distributing it to each client. The above steps are repeated until the preset number of training rounds or the global model meets the convergence condition.
[0085] In the following feasible embodiments, combined with Figure 2 , Figure 3 The method provided by the present invention will be described in detail below:
[0086] Specifically, the system in this embodiment includes a key generation center (KGC) and an aggregation server. Collaboration server as well as Client .in, Indicates the total number of clients. Indicates the first client, This indicates the second client. Indicates the first One client.
[0087] The Key Generation Center (KGC) is a trusted entity used to generate and distribute public and private key pairs.
[0088] Aggregator server Responsible for collecting ciphertext model updates, performing homomorphic intermediate value calculations, and ciphertext aggregation;
[0089] Collaboration server With aggregation server Non-collusion is used to decrypt preset geometric statistics, construct multi-head target matrices, perform malicious client detection, and generate aggregate weights.
[0090] The client is responsible for receiving the global model, training the local model using local data, and uploading the encrypted local model sub-vectors.
[0091] In this embodiment, the first The round global model is represented as , No. The model trained locally on each client is represented as follows: The number of model layers is The number of task categories is , No. The local model obtained after the client's local training is completed. The subvectors are represented as The current global model corresponds to the subvector representation as follows: .
[0092] For ease of explanation, let , , .
[0093] in, Indicates the communication round index of federated learning; Indicates the client number; Indicates the subvector number; for The simplified symbols introduced by the abbreviation represent the meaning and Same, that is Indicates the first The local model obtained after the client's local training is completed. Subvectors; for The simplified symbols introduced by the abbreviation represent the meaning and Same means that the corresponding sub-vector of the current global model; Represents the residual vector; Indicates the client index; Indicates the subvector index.
[0094] The method steps of the present invention will be described in detail in the following feasible embodiments:
[0095] In one feasible embodiment, step 100, namely initialization and key distribution, is described in detail.
[0096] Key Generation Center (KGC) generates public and private key pairs for collaborative servers. It also generates a client public / private key pair for the client to decrypt the global model. .in This represents the server's public key; This represents the server's private key; Indicates the client's public key; This represents the client's private key.
[0097] The Key Generation Center (KGC) sends the server's private key to the collaborating server, sends the client's private key to each client, and publishes or distributes the corresponding public key.
[0098] The aggregation server initializes the global model, encrypts it using the client's public key, and sends it to the client.
[0099] In one feasible embodiment, step 200 is described in detail.
[0100] Step 200 includes sub-step 201: detection alignment local training and sub-step 202: subvector partitioning and encrypted upload.
[0101] The following is a detailed explanation of sub-step 201: Detecting Alignment with Local Training:
[0102] The client receives the global model encrypted with the client's public key and decrypts it using the client's private key to obtain the [database name]. Round global model .
[0103] Unlike traditional training methods that only minimize local experience loss, this invention incorporates a regularization term consistent with subsequent detection metrics into the local training objective. Its objective function is:
[0104] ;
[0105] in, Represent the objective function; Indicates the local model; Indicates the first Round global model; Indicates the communication rounds in federated learning; This represents the client's local experience loss function; Represents the regularization coefficient. Indicates the amplitude regularization term; Indicates the direction regularization term.
[0106] Client-side local experience loss function The specific form of expression is: ; in, This represents the number of local training samples on the client side; in this formula... To categorize the number of task categories, Indicates a category index; The training samples and their corresponding class labels; This is an indicator function (it takes the value 1 if the condition inside the parentheses is true, and 0 otherwise). This indicates that the model is based on the training samples. Predicted as the first The probability of a class; in this formula Indicates the training sample index; This indicates the local model.
[0107] Specifically, This is used to constrain the magnitude offset of the local model relative to the global model; where, Indicates the amplitude regularization term; Indicates the local model; Indicates the first Round global model; Indicates the communication rounds in federated learning; This represents the square of the Euclidean norm of a vector.
[0108] ,in , This represents the cosine similarity after cropping. This represents the inner product of the normalized local model vector and the global model vector. This represents the clipping function. Indicates the local model; Indicates the first Round global model; It is the logarithmic stability constant; Indicates the direction regularization term; This indicates the communication round of federated learning.
[0109] Directional regularization can reduce benign drift of normal clients caused by non-independent and identically distributed data, making it easier for subsequent backdoor detection to distinguish between malicious anomalies and normal heterogeneity.
[0110] The following is a detailed explanation of sub-step 202: sub-vector partitioning and encrypted upload:
[0111] After the client completes local training, it divides the local model into categories based on network layers and category-related parameters. The subvectors can also be divided based on network layer structure, output channels, convolutional kernel groups, class-related parameters, or preset length. The number of model layers is... The number of task categories is .
[0112] The client performs homomorphic encryption on each subvector using the server's public key and uploads the encrypted subvector to the aggregation server.
[0113] In a feasible embodiment, step 300, namely the calculation of the intermediate geometric statistics of the ciphertext, is described in detail:
[0114] Without decrypting the client model subvectors, the aggregation server uses homomorphic encryption operations such as addition, multiplication, and rotation to calculate the intermediate geometric statistics corresponding to each subvector.
[0115] The intermediate geometric statistics include the inter-client inner product. Client-side subvector norm squared Local-Global Inner Product and the square of the global subvector norm Specifically:
[0116] ;
[0117] in, This represents the inner product between clients; in this formula Both represent client-side indexes, used to distinguish different clients; Indicates the subvector index; Represents the transpose of a vector; Indicates the first The local model obtained after the client's local training is completed. Subvectors; Indicates the first The local model obtained after the client's local training is completed. Subvectors; Represents the squared norm of the client-side subvector; Represents the local-global inner product; Indicates the current global model at the [number]th [year]. The parameter values on each subvector; This represents the sub-vector corresponding to the current global model; This represents the squared norm of the global subvector.
[0118] Based on the above statistics, the aggregation server further derives the residual inner product in the ciphertext domain. Residual norm squared and residual-global inner product Specifically:
[0119] ;
[0120] in, Represents the inner product of residuals; Indicates the inter-client product; Indicates the first Local-global inner product of each client; Represents the squared norm of the global subvector; Represents the squared residual norm; Represents the squared norm of the client-side subvector; Represents the local-global inner product; Represents the squared norm of the global subvector; This represents the residual-global inner product; in this formula Both represent client-side indexes, used to distinguish different clients; Indicates the subvector index.
[0121] The aforementioned intermediate geometric statistics are sent from the aggregation server to the collaboration server in encrypted form.
[0122] The aggregation server does not possess the server's private key and therefore cannot directly obtain the plaintext of the client's model parameters; the collaboration server only obtains the preset geometric statistics for subsequent model verification.
[0123] In one feasible embodiment, step 400 is described in detail:
[0124] Step 400 includes sub-step 401: multi-head target matrix construction, sub-step 402: joint backdoor detection, and sub-step 403: security weighted aggregation.
[0125] The following is a detailed explanation of sub-step 401: Construction of the multi-headed target matrix:
[0126] The collaborative server uses the server's private key to decrypt intermediate geometric statistics and constructs four deterministic geometric heads for each subvector.
[0127] The four types of geometry headers include the original parameter header, the orientation header, the residual header, and the residual orientation header, which are represented as follows:
[0128] ;
[0129] in, Indicates the raw parameter header; Indicates the first The local model obtained after the client's local training is completed. Subvectors; Indicates direction; This represents the normalized stability constant to prevent the denominator from being zero. Indicates residual amount; Represents the residual vector; Indicates the direction of the residual; Indicates the client index; Indicates the subvector index.
[0130] The original parameter header preserves the original parameter relationships of the client model subvectors; the direction header describes the angular consistency of the client model updates; the residual header measures the drift of the local model relative to the global model; and the residual direction header describes the directional relationship of this drift.
[0131] For each geometry head, the collaborative server constructs an inter-client attention matrix. The original parameter head uses... As an attention score; orientation head adopted As an attention score; residual head adopted As attention score; residual orientation head adopted As an attention score.
[0132] in Indicates the first Sub-vector dimensions Indicates the temperature coefficient; Represents the inner product of residuals; Indicates the inter-client product; Represents the squared norm of the client-side subvector; Indicates the first Squared norm of each client subvector; Represents the squared residual norm; Indicates the first On the nth subvector, the th The squared residual norm of each client; in this formula Both represent client-side indexes, used to distinguish different clients; Indicates the subvector index; This represents the normalized stability constant, preventing the denominator from being zero.
[0133] Perform attention score for each line Normalization yields the attention matrix.
[0134] Since the attention matrix mainly describes relationship and direction information, this invention further constructs an Euclidean distance matrix as amplitude offset compensation.
[0135] Original parameter head distance is The direction head distance is The residual head distance is The distance from the head in the residual direction is .
[0136] in, Represents the squared norm of the client-side subvector; Indicates the first Squared norm of each client subvector; Represents the inner product of residuals; This represents the normalized stability constant to prevent the denominator from being zero. Represents the squared residual norm; Indicates the first On the nth subvector, the th The squared residual norm of each client; in this formula Both represent client-side indexes, used to distinguish different clients; Indicates the subvector index.
[0137] Meanwhile, the present invention constructs local-global geometric features for each geometric head, which includes a local-global similarity feature and a local-global distance feature.
[0138] The raw parameter header can be used and The steering head can be adopted and The residual head can be adopted. and The residual direction head can be adopted. and .
[0139] in, Represents the local-global inner product; For the first Sub-vector dimensions; Represents the squared residual norm; Temperature coefficient; Represents the squared norm of the client-side subvector; Represents the squared norm of the global subvector; This represents the normalized stability constant to prevent the denominator from being zero. This represents the residual-global inner product; in this formula Indicates the client index; Indicates the subvector index.
[0140] For the Each subvector concatenates four attention matrices, four Euclidean distance matrices, and four sets of local-global geometric features to form a multi-head target matrix. .in, Represents a multi-target matrix; Represents the attention matrix; Represents the Euclidean distance matrix; Represents local-global geometric features; Indicates the subvector index; Indicates the geometry header type.
[0141] The number of participating clients is In this case, the dimension of each multi-head target matrix is ,in This indicates the total number of clients.
[0142] The following is a detailed explanation of sub-step 402: Joint backdoor detection:
[0143] The collaborative server first concatenates the corresponding row vectors of the same client in all multi-head target matrices to form the multi-head target vector of that client.
[0144] Perform binary spectral clustering on the multi-head target vectors of all clients. Based on the assumption that the number of malicious clients is less than half of the total number of participating clients, the smaller cluster is selected as the first set of anomalous clients.
[0145] The collaboration server also performs isolated forest detection on the multi-head target matrix of each subvector to obtain the anomaly score vector of all clients on that subvector.
[0146] Stack the outlier scores on all subvectors into a fractional matrix and calculate the average outlier score for each client.
[0147] Let the median of the average anomaly score for all clients be... Threshold can be set Alternatively, a threshold can be set based on system security requirements. At that time, add the client to the second set of abnormal clients. .in, This represents the average anomaly score for the client. This represents the median of the average anomaly score among clients. This represents the threshold.
[0148] The final malicious client set is ,in, Represents a set of malicious clients; This represents the first set of abnormal clients; This represents the second set of abnormal clients.
[0149] The following is a detailed explanation of sub-step 403: safe weighted aggregation:
[0150] The collaboration server only calculates the aggregate weight for clients that have not been identified as malicious.
[0151] To ensure aggregation stability, aggregation weights can be calculated based on the original local-global similarity. For benign clients... , its first The aggregate score of the subvectors can be expressed as:
[0152] ;
[0153] in, This indicates that benign clients are... The aggregate score of each subvector; Indicates the first The local model obtained after the client's local training is completed. Subvectors; This represents the sub-vector corresponding to the current global model; Indicates the first Sub-vector dimensions; Indicates the transpose sign; in this formula Indicates the client index. Indicates the communication round index of federated learning. Indicates the subvector index; The function is defined as a positive function. , This represents a real number variable used to remove negative or invalid similarities.
[0154] The average score is obtained by averaging the aggregated scores of benign clients across all subvectors. Then, the average score of all benign clients is normalized to obtain the aggregate weight. .in, This indicates the client-side index.
[0155] The collaborative server will encrypt the aggregate weight. The data is sent to the aggregation server, which performs weighted aggregation in the encrypted domain.
[0156] ;
[0157] in, This indicates the next round of the global model, encrypted using the server's public key. Indicates the first Round global model; This represents the server's public key; in this formula Indicates the client index. Indicates the communication round index of federated learning; Represents a set of malicious clients; Indicates aggregate weight; Indicates the first The model is trained locally on the client side.
[0158] In one feasible embodiment, step 500, namely mask re-encryption and model distribution, is described in detail:
[0159] To enable clients to decrypt the global model in the next training round, and to prevent collaborative servers from obtaining the unmasked global model, the aggregation server adds a random mask to the next round's global model, which is encrypted using the server's public key. The encrypted mask model is obtained and sent to the collaboration server.
[0160] The collaboration server uses its private key to decrypt the masked model, then uses the client's public key to re-encrypt it and return it to the aggregation server.
[0161] The aggregation server removes the random mask from the client's public key encryption field, obtains the next round of global model encrypted with the client's public key, and sends it to the client.
[0162] The above steps are repeated until the preset number of training rounds is reached or the global model meets the convergence condition. The homomorphic encryption scheme in this invention preferentially adopts the CKKS scheme, but other homomorphic encryption schemes that support the required addition and multiplication operations can also be used.
[0163] The spectral clustering and isolated forest in this invention can be replaced with other anomaly detection algorithms that can handle multi-head target matrices according to actual deployment requirements; the sub-vector partitioning rules, temperature coefficient, stability constant, regularization coefficient and anomaly detection threshold in this invention can all be adjusted according to the model structure and task safety requirements.
[0164] The technical terms, principles, or means related to the technical solutions of the present invention mentioned in the above embodiments, which are not described in detail above, are all well-known technologies or common practices that are known to those skilled in the art.
[0165] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of this invention is defined by the appended claims and their equivalents.
Claims
1. A privacy-preserving federated learning backdoor defense method based on multi-head geometric perception, characterized in that, Composed of four types of entities: a key generation center, an aggregation server, a collaboration server, and several clients, this method includes: The key generation center generates client public-private key pairs and server public-private key pairs; the client public-private key pairs are sent to each client; the aggregation server initializes the global model and distributes the global model encrypted with the client public key to each client; The client receives and decrypts the encrypted global model, performs local training using the objective function, and obtains a local model. The local model is then divided into several sub-vectors, and the sub-vectors are encrypted using the server's public key before being uploaded to the aggregation server. The aggregation server uses homomorphic encryption to calculate the intermediate geometric statistics of the encrypted subvector, and derives the ciphertext intermediate geometric statistics in the ciphertext domain based on the intermediate geometric statistics and sends them to the cooperating server. The collaborative server decrypts the intermediate geometric statistics of the ciphertext, constructs four deterministic geometric heads for each sub-vector, thereby forming a multi-head target matrix corresponding to each sub-vector and performing joint backdoor detection to obtain a set of malicious clients; for clients not included in the set of malicious clients, the aggregation weight is calculated and encrypted and sent to the aggregation server, and weighted aggregation is performed in the ciphertext domain to obtain the encrypted next round global model; The aggregation server and the collaboration server perform a mask re-encryption process, converting the next-round global model encrypted with the server's public key into the next-round global model encrypted with the client's public key, and then sending it to each client. The above steps are repeated until the preset number of training rounds or the global model meets the convergence condition. The four deterministic geometry heads include the original parameter head, the orientation head, the residual head, and the residual orientation head.
2. The privacy-preserving federated learning backdoor defense method based on multi-head geometric perception according to claim 1, characterized in that, The objective function includes an amplitude regularization term and a direction regularization term, as detailed below: ; in, Represent the objective function; Indicates the local model; Indicates the first Round global model; Indicates the communication rounds in federated learning; This represents the client's local experience loss function; Represents the regularization coefficient. This represents the magnitude regularization term, used to constrain the magnitude offset of the local model relative to the global model; This represents the direction regularization term, used to constrain the directional differences between the local model and the global model.
3. The privacy-preserving federated learning backdoor defense method based on multi-head geometric perception according to claim 1, characterized in that, The execution steps for dividing the vector into several sub-vectors are as follows; When partitioning the local model into subvectors, each client's local model is divided into subvectors whose product is based on the preset number of model layers and classification task categories; or the local model is partitioned into subvectors based on the preset layer structure, channel structure, category parameter structure, or fixed length rules.
4. The privacy-preserving federated learning backdoor defense method based on multi-head geometric perception according to claim 1, characterized in that, The homomorphic encryption includes addition, multiplication, and rotation in homomorphic encryption; The intermediate geometric statistics include the client-to-client inner product, the squared norm of the client subvector, the local-to-global inner product, and the squared norm of the global subvector, as detailed below: ; in, This represents the inner product between clients; in this formula Both represent client-side indexes, used to distinguish different clients; Indicates the subvector index; Represents the transpose of a vector; Indicates the first The local model obtained after the client's local training is completed. Subvectors; Indicates the first The local model obtained after the client's local training is completed. Subvectors; Represents the squared norm of the client-side subvector; Represents the local-global inner product; Indicates the current global model at the [number]th [year]. The parameter values on each subvector; This represents the sub-vector corresponding to the current global model; Represents the squared norm of the global subvector; The steps for deriving the intermediate geometric statistics of the ciphertext in the ciphertext domain and sending them to the cooperative server are as follows: Based on the inter-client inner product, the squared norm of the client subvector, the local-global inner product, and the squared norm of the global subvector, the aggregation server further derives the residual inner product, the squared norm of the residual, and the residual-global inner product in the ciphertext domain, specifically: ; in, Represents the inner product of residuals; Indicates the inter-client product; Indicates the first Local-global inner product of each client; Represents the squared norm of the global subvector; Represents the squared residual norm; Represents the squared norm of the client-side subvector; Represents the local-global inner product; Represents the squared norm of the global subvector; This represents the residual-global inner product; in this formula Both represent client-side indexes, used to distinguish different clients; Indicates the subvector index.
5. The privacy-preserving federated learning backdoor defense method based on multi-head geometric perception according to claim 1, characterized in that, The steps for constructing the four deterministic geometry heads are as follows: The collaborative server uses a private key to decrypt intermediate geometric statistics and constructs four deterministic geometric heads for each subvector; The original parameter header preserves the original parameter relationships of the client model subvectors; the direction header describes the angular consistency of the client model updates; the residual header measures the drift of the local model relative to the global model; and the residual direction header describes the directional relationship of this drift. The execution steps for forming the multi-head target matrix corresponding to each sub-vector are as follows: For each deterministic geometry head, firstly, the collaborative server uses the intermediate geometry statistics obtained from decryption to calculate the attention scores among clients, and performs normalization processing on each row of attention scores to form a client attention matrix; Secondly, calculate the Euclidean distance between clients to form an Euclidean distance matrix; then calculate the local-global similarity features and local-global distance features between each client and the global model to form local-global geometric features; The collaborative server concatenates the four attention matrices, four Euclidean distance matrices, and four sets of local-global geometric features corresponding to the same sub-vector to form the multi-head target matrix corresponding to that sub-vector.
6. The privacy-preserving federated learning backdoor defense method based on multi-head geometric perception according to claim 1, characterized in that, The execution steps for performing the joint backdoor detection are as follows: The collaborative server first concatenates the corresponding row vectors of the same client in all multi-head target matrices to form the multi-head target vector of the client. It then performs binary spectral clustering on the multi-head target vectors of all clients. Based on the assumption that the number of malicious clients is less than half of the total number of participating clients, it compares the two client clusters obtained after clustering. The client cluster with fewer clients is the first abnormal client set. Secondly, the collaborative server performs isolated forest detection on the multi-head target matrix of each sub-vector to obtain the anomaly score vector of all clients on that sub-vector; Stack the outlier scores on all subvectors to form a score matrix, and calculate the average outlier score for each client. Set a threshold based on the median of the average anomaly score of all clients, or set a threshold according to actual needs; When the average abnormal score of a client is less than the difference between the median of the average abnormal scores of all clients and the threshold, the client is added to the second abnormal client set. The set of malicious clients is obtained by taking the union of the first set of abnormal clients and the second set of abnormal clients.
7. The privacy-preserving federated learning backdoor defense method based on multi-head geometric perception according to claim 1, characterized in that, The steps for calculating the aggregate weights are as follows: Calculate the aggregate score on each subvector of each benign client, then average the aggregate scores on all subvectors to obtain the average score, and finally normalize the average score of all benign clients to obtain the aggregate weight. The aggregation server performs a ciphertext weighted summation on the corresponding encrypted local models according to the encrypted aggregation weights of each benign client, and completes the next round of global model aggregation; The execution steps of the mask re-encryption process are as follows: The aggregation server adds a random mask to the next round of global model encrypted with the server's public key to obtain an encrypted mask model and sends it to the collaboration server. After decrypting the encryption mask model, the collaboration server re-encrypts it using the client's public key and returns it to the aggregation server. The aggregation server removes the random mask from the client's public key encryption field to obtain the next round of global model encrypted with the client's public key.
8. A privacy-preserving federated learning backdoor defense system based on multi-head geometry perception, implementing the method of any one of claims 1 to 7, characterized in that, include: The initialization and key distribution module is used to generate and distribute public and private key pairs; The local training module receives the global model, adds a regularization term aligned with subsequent detection metrics to the local training objective to perform local training, and divides the trained local model into several sub-vectors, encrypts them using the server's public key, and uploads them to the aggregation server. The ciphertext intermediate geometric statistics calculation module is used to collect encrypted subvectors, calculate intermediate geometric statistics in the ciphertext domain without decryption, and send them to the collaborative server. The multi-head target matrix construction module is used by the collaborative server to decrypt the intermediate geometric statistics of the ciphertext and construct the multi-head target matrix corresponding to each sub-vector based on four deterministic geometric heads. The joint backdoor detection module is used to detect malicious clients by combining spectral clustering and isolated forest based on the multi-head target matrix of all sub-vectors. The secure weighted aggregation module is used by the collaboration server to calculate the aggregation weight for clients that have not been identified as malicious and send it to the aggregation server in encrypted form. The aggregation server then performs weighted aggregation on the encrypted data based on the aggregation weight to update the global model. The mask re-encryption and model distribution module is used to convert the aggregated global model encrypted by the collaboration server into the next round of global model encrypted by the client's public key by adding random masks, decrypting, re-encrypting, and removing masks, and then distribute it to each client.
9. An electronic device, comprising: The processor, communication interface, memory, and communication bus are connected, with the processor, communication interface, and memory communicating with each other via the communication bus. The feature is that the memory stores a computer program, which, when executed by the processor, causes the processor to execute the privacy-preserving federated learning backdoor defense method based on multi-head geometric perception as described in any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed, it implements the privacy-preserving federated learning backdoor defense method based on multi-head geometry perception as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Defense method and device for convenient vehicle attack in federated learning with privacy protection
CN117077192A
Robustness clustering federated learning method with trusted anchor client and storage medium
CN117494842A