Secure and Robust Federated Learning System and Federated Learning Method Using Multi-Party Homomorphic Encryption

The federated learning system uses homomorphic encryption and secret sharing to securely aggregate gradients across edge devices, enhancing confidentiality and reducing communication costs by eliminating the need for a TTP, ensuring secure and efficient model updates.

JP7701721B2Active Publication Date: 2025-07-02THE GOVERNING COUNCIL OF THE UNIV OF TORONTO +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2021111934
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-07-06
Publication Date
2025-07-02
Estimated Expiration
2041-07-06

AI Technical Summary

Technical Problem

Existing federated learning systems face challenges in maintaining data confidentiality and reducing communication costs, particularly due to the need for a trusted third party (TTP) that can lead to key leakage and increased communication overhead.

Method used

A federated learning system using homomorphic encryption and secret sharing techniques, where edge devices generate encrypted gradients that are aggregated and decrypted without exposing private keys, allowing secure model updates without a TTP.

Benefits of technology

Improves confidentiality and reduces communication costs by enabling secure aggregation of gradients without a TTP, ensuring that only edge devices can decrypt their own data, and allowing the learning process to continue even if some nodes become inoperable.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007701721000004
    Figure 0007701721000004
  • Figure 0007701721000005
    Figure 0007701721000005
  • Figure 0007701721000006
    Figure 0007701721000006
Patent Text Reader

Abstract

To improve secrecy and to reduce communication costs without installing a TTP.SOLUTION: In a federated learning system comprises edges and a server, the edges encrypt gradient information by a common public key and transmit the encrypted gradients to the server; the server adds encrypted gradients received from the plurality of edges, to generate an encrypted aggregated gradient and transmits it to the edges; the edges encrypt the encrypted aggregated gradient to generate edge switch shares and transmit them the server; the server adds the edge switch shares received from the plurality of edges, generates encrypted aggregated gradients for decoding, decodes the generated encrypted aggregated gradient for decoding to generate an aggregated gradient, and transmits it to the edges; and the edges performs learning processing of an AI model using the aggregated gradient received from the server.SELECTED DRAWING: Figure 8
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a federated learning system and a federated learning method.

Background Art

[0002] As one of the machine learning methods, federated learning has been proposed as a machine learning method capable of generating an AI model based on data on each edge device without aggregating data on distributed edge devices on a server (Non-Patent Document 1). Federated learning is characterized by transmitting data (e.g., gradient information) necessary for generating an AI model to a server instead of transmitting original data from an edge device, thereby enabling protection of the privacy of data on the edge device.

[0003] However, if the gradient information is transmitted to the server without being anonymized, there is a possibility that the original data can be inferred from the eavesdropped gradient information. Therefore, a federated learning method that anonymizes gradient information has been proposed.

[0004] Non-Patent Document 1 describes a technique for reducing communication volume while maintaining data confidentiality based on a protocol called Secure Multi-Party Computation. Non-Patent Document 2 describes a technique for improving security by using homomorphic encryption in order to securely aggregate model update information such as gradients. In federated learning using homomorphic encryption, it is difficult to manage keys used for encryption and decryption, and generally, the keys are managed by a trusted third party (TTP: Trusted Third Party).

Prior Art Documents

Non-Patent Documents

[0005]

Non-Patent Document 1

[0006] In the technology described in Non-Patent Document 1, although the communication volume can be reduced conventionally, a large amount of communication is still required. Also, during the learning process of the AI model, since all edge nodes need to exist, if some edge nodes become unusable due to communication failure or the like, the learning process cannot be continued.

[0007] In Non-Patent Document 2, two problems arise by managing keys in federated learning using a TTP. First, if the private key managed by the TTP is leaked or the TTP colludes with the server during federated learning, the gradients of each edge device may be decrypted and leaked. Second, by installing a TTP, the communication cost increases.

[0008] An object of the present invention is to provide a federated learning system that improves confidentiality and reduces communication cost without installing a TTP. [Means for Solving the Problems]

[0009] A typical example of the invention disclosed in the present application is as follows. That is, a federated learning system that aggregates gradient information representing the results of learning an AI model in an edge device, comprising an edge device that generates an AI model by learning, and a server device that collects the gradient information from the edge device, wherein the edge device includes an edge key generation unit that generates an edge key pair including an edge public key and an edge private key, using the learning data, the AI model and a learning unit that performs learning. In the server device, in the server key generation unit, the server public key is generated by adding the edge public keys included in the edge key pair, The server device includes a server key generation unit that generates a decryption key pair including a decryption public key and a decryption private key, and an encryption / decryption unit that executes data processing. The edge device generates an encrypted gradient obtained by encrypting the gradient information with a common public key in the learning unit, transmits the generated encrypted gradient to the server device, the server device adds the encrypted gradients received from a plurality of the edge devices in the encryption / decryption unit to generate an encrypted aggregated gradient, transmits the generated encrypted aggregated gradient to the edge device, the edge device generates an edge switch share obtained by encrypting the encrypted aggregated gradient in the learning unit, transmits the generated edge switch share to the server device, the server device adds the edge switch shares received from a plurality of the edge devices in the encryption / decryption unit to generate an encrypted aggregated gradient for decryption, using the homomorphic encryption, the decrypts the generated encrypted aggregated gradient for decryption to generate an aggregated gradient, and transmits the aggregated gradient to the edge device, and the learning unit of the edge device learns the AI model using the aggregated gradient received from the server device. using the homomorphic encryption, with the decryption public key with the decryption private key

Advantages of the Invention

[0010] According to one aspect of the present invention, without installing a TTP, confidentiality can be improved and communication costs can be reduced. Problems, configurations, and effects other than those described above will be clarified by the description of the following embodiments.

Brief Description of the Drawings

[0011]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Mode for Carrying Out the Invention

[0012] Hereinafter, embodiments of the present invention will be described with reference to the drawings. In the federated learning system according to this embodiment, when aggregating the gradient information (hereinafter sometimes referred to as gradient) held by each edge device (hereinafter sometimes referred to as edge) in the server, homomorphic encryption is used to anonymize the gradient of each edge. Thereby, the security of the gradient of each edge can be enhanced. Further, at the time of decryption, by utilizing the properties of secret sharing and homomorphic encryption, the private key of each edge can be safely decrypted without transmitting it outside the edge.

[0013] As a preparation stage, keys used for encryption and decryption of homomorphic encryption are generated by the server and each edge before the learning process of the AI model. At this time, share information (hereinafter sometimes referred to as share) generated from the private key of each edge is generated, and the generated shares are distributed and shared by each edge. This share is used when decrypting the aggregated gradient generated in the process of the learning process of the AI model. Further, a decryption key pair used at this time is generated and transmitted to each edge. Further, after generating a common public key generated by aggregating the public keys of each edge in the server, the common public key is transmitted to each edge.

[0014] When training the AI model, gradients are calculated through deep learning or the like based on the training data of each edge. Next, the gradients of each edge are encrypted with the aforementioned common public key and sent to the server. When aggregating the gradients of each edge on the server, by utilizing the properties of homomorphic encryption, the gradients of each edge can be simply added to generate the aggregated gradients in the encrypted state. When decrypting the aggregated gradients and sending them back to each edge, the aggregated gradients are obtained based on the share information for secret sharing obtained from each edge, the decryption key pair, the encrypted aggregated gradients, and the reconstruction coefficients of each edge. Each edge updates the AI model based on the aggregated gradients. As a result, each edge can securely send the gradients to the server while maintaining confidentiality and generate an AI model that also takes into account the gradient content of other edges.

[0015] Embodiments of the present invention will be described with reference to FIGS. 1 to 9. It should be noted that this embodiment is merely an example for implementing the present invention and does not limit the technical scope of the present invention.

[0016] In the following description, the "computer program" may be used as the subject for explanation. By being executed by a processor, the computer program executes predetermined processing while using a memory and a communication port (communication control device). Therefore, the processor can be used as the subject instead of the computer program, or a computer having a processor can also be used as the subject for explanation.

[0017] Note that at least a part or all of the computer program may be implemented by dedicated hardware. The computer program may be modularized. The computer program may be fixed to a recording medium and distributed, or may be distributed from a program distribution server via a communication network. By the processor reading and executing the computer program, the functions described below are realized.

[0018] In the following description, unless otherwise specified, all public-key cryptosystems are based on fully homomorphic encryption schemes, and the use of BFV is assumed for all fully homomorphic encryption schemes, which will be described later.

[0019] FIG. 1 is a diagram showing the overall configuration of the federated learning system 1.

[0020] The federated learning system 1 has, for example, a server 2 and a plurality of edges 3. Each edge 3 can communicate with the server 2 through a network (e.g., the Internet) 4 where confidentiality is not guaranteed. In this embodiment, the number of edges is set to 4, but any number of 2 or more may be used.

[0021] FIG. 2 is a block diagram showing a configuration example of the hardware and software of the server 2.

[0022] The server 2 has, for example, an input / output device 21, a central processing unit 22, a communication control device 23, and a storage device 24.

[0023] The input / output device 21 is a device for inputting and outputting information to and from the user. The input / output device 21 has an information input device 211 and an information output device 212. Examples of the information input device 211 include a keyboard, a mouse, a touch panel (none of which are shown). Examples of the information output device 212 include a display, a printer (none of which are shown). A device that combines both the information input device and the information output device may also be used. Note that the input / output device 21 may be a terminal connected to the server 2 via the network 4. In this case, the server 2 has the function of a web server, the terminal accesses the server 2 using a predetermined protocol (e.g., http), and the web browser of the terminal realizes the display function. Also, the terminal may execute a dedicated application to realize the display function. Further, the input / output device 21 may be an interface for outputting the result of the calculation by the server 2 to another computer system. Thus, the input / output device 21 can adopt various forms.

[0024] The central processing unit 22 has a microprocessor and a program memory (both not shown), and executes necessary arithmetic processing, control processing, etc. for functioning as the federated learning system 1. The central processing unit 22 executes predetermined computer programs 221 to 223. Note that a part of the processing performed by the microprocessor executing the program may be executed by other arithmetic units (for example, hardware such as an ASIC or an FPGA). The program memory is a storage device that stores the programs executed by the microprocessor, stores invariant programs (for example, BIOS), etc., and includes a ROM that is a non-volatile storage element and a RAM that is a high-speed and volatile storage element such as a DRAM (Dynamic Random Access Memory).

[0025] The control program 221 controls the cooperation processing in the server 2 and each edge 3, and instructs and manages the processing from the server 2 to each edge 3.

[0026] The server key generation program 222 generates the common public key 241 from the edge public key of the edge key pair 341 acquired from the edge 3. Further, the server key generation program 222 generates a decryption key pair 242 for decrypting the encrypted aggregated gradient 244 described later, and transmits the public key included in the decryption key pair 242 to each edge 3.

[0027] The server encryption / decryption program 223 determines the active edges that are communicable edges, and generates the active encrypted aggregated gradient 243 from the encrypted edge gradient 346 acquired from the active edges. Further, in order to obtain the aggregated gradient 245, a decryption edge is selected from the active edges, and the active encrypted aggregated gradient 243 and the reconstruction coefficient 347 of the edge are transmitted to the selected decryption edge. Further, the edge switch share 348 is received from the edge 3 serving as the decryption edge, and the aggregated gradient 245 is generated from the edge switch share 348 and the secret key of the decryption key pair 242, and transmitted to each edge 3.

[0028] The communication control device 23 is a network interface device that controls communication with each edge 3 via the network 4.

[0029] The storage device 24 is a large-capacity and non-volatile storage device such as a magnetic storage device (HDD) or a flash memory (SSD), and stores data to be processed by the central processing unit 22, processed data, and the like. The storage device 24 stores, for example, a common public key 241, a decryption key pair 242, an active encrypted aggregated gradient 243, a decryption encrypted aggregated gradient 244, and an aggregated gradient 245. The common public key 241 is generated by adding the public keys of the edge key pairs 341 acquired from each edge 3, and is used when encrypting the gradients of each edge 3. The decryption key pair 242 is used for generating the edge switch share 348 and obtaining the aggregated gradient 245 from the edge switch share 348. The active encrypted aggregated gradient 243 is generated from the encrypted edge gradient 346. The decryption encrypted aggregated gradient 244 is used when obtaining the aggregated gradient 245. The aggregated gradient 245 is used for generating the AI model 349 in each edge 3.

[0030] The program executed by the central processing unit 22 is provided to the server 2 via a removable medium (such as a CD-ROM or a flash memory) or the network 4, and is stored in a non-volatile program memory which is a non-temporary storage medium. Therefore, the server 2 preferably has an interface for reading data from a removable medium.

[0031] The server 2 is a computer system configured physically on one computer or on a plurality of computers configured logically or physically, and may operate on a virtual computer constructed on a plurality of physical computer resources. For example, the control program 221, the server key generation program 222, and the server encryption / decryption program 223 may each operate on a separate physical or logical computer, or may be combined and operate on one physical or logical computer.

[0032] FIG. 3 is a block diagram showing a configuration example of the hardware and software of Edge 3.

[0033] Edge 3 has, for example, an input / output device 31, a central processing unit 32, a communication control device 33, and a storage device 34.

[0034] The input / output device 31 is a device that inputs and outputs information to and from the user. The input / output device 31 has an information input device 311 and an information output device 312. Examples of the information input device 311 include a keyboard, a mouse, and a touch panel (none of which are shown). Examples of the information output device 312 include a display and a printer (none of which are shown). A device that combines both the information input device and the information output device may also be used. Note that the input / output device 31 may be a terminal connected to Edge 3 via a network. In this case, Edge 3 has the function of a web server, the terminal accesses Edge 3 using a predetermined protocol (e.g., http), and the web browser of the terminal realizes the display function. Also, the terminal may execute a dedicated application to realize the display function. Further, the input / output device 31 may be an interface that outputs the result of the calculation by Edge 3 to another computer system. Thus, the input / output device 31 can adopt various forms.

[0035] The central processing unit 32 has a microprocessor and a program memory (both not shown), and executes necessary arithmetic processing, control processing, etc. for functioning as the federated learning system 1. The central processing unit 32 executes predetermined computer programs 321 to 322. Note that a part of the processing performed by the microprocessor executing the program may be executed by another arithmetic device (e.g., hardware such as an ASIC or FPGA). The program memory is a storage device that stores the programs executed by the microprocessor, stores invariant programs (e.g., BIOS), etc., and includes a non-volatile storage element such as a ROM and a high-speed and volatile storage element such as a DRAM (Dynamic Random Access Memory).

[0036] The edge key generation program 321 generates an edge key pair 341 at each edge 3, generates an edge secret key share 342 from the secret key of the edge key pair 341, and generates an edge share 343 from the edge secret key share 342.

[0037] The learning program 322 generates an edge gradient 345 in the process of performing machine learning on the learning data 344 at each edge 3, encrypts it with the common public key 241 obtained from the server 2 to generate an encrypted edge gradient 346, and transmits it to the server 2. Each edge 3 selected for decryption generates an edge switch share 348 and transmits it to the server 2. The server 2 generates an aggregated gradient 245 from the edge switch share 348 and the secret key of the edge key pair 341, and transmits it to each edge 3. The edge 3 executes a process of updating the AI model 349 based on the aggregated gradient 245 obtained from the server 2.

[0038] The communication control device 33 is a network interface device that controls communication with the server 2 and other edges 3 via the network 4.

[0039] The memory device 34 is a large-capacity and non-volatile memory device such as a magnetic memory device (HDD) or a flash memory (SSD), and is a device that stores data to be processed by the central processing unit 32, processed data, and the like. The memory device 34 stores, for example, an edge key pair 341, an edge secret key share 342, an edge share 343, learning data 344, an edge gradient 345, an encrypted edge gradient 346, a reconstruction coefficient 347, an edge switch share 348, and an AI model 349. The edge key pair 341 is individually generated at each edge 3 and is composed of a public key and a secret key. The public key is used to generate the common public key 241 at the server 2. The secret key is used to generate the edge secret key share 342. The edge secret key share 342 is used to generate the edge share 343. The edge share 343 is used to generate the edge switch share 348. The learning data 344 is stored in the memory device 34 before the start of processing and is used to learn the AI model 349, and usually has different data sets at each edge 3. The edge gradient 345 is data generated during the learning process of the AI model 349. The encrypted edge gradient 346 is data obtained by encrypting the edge gradient 345 with the common public key 241 of the server 2. The reconstruction coefficient 347 is a value necessary for reconstructing the common secret key from the edge share 343 including the edge secret key share 342 (described later in Equation (2)), is transmitted from the server 2, and is used to generate the edge switch share 348. The edge switch share 348 is generated based on the active encrypted aggregated gradient 243, the reconstruction coefficient 347, the edge secret key share 342, and the public key of the decryption key pair 242. The AI model 349 is updated based on the aggregated gradient 245 generated by aggregating the edge gradients 345 generated during the process of learning the learning data 344 at each edge 3 at the server 2, and can be utilized for an AI application or the like.

[0040] The program executed by the central processing unit 32 is provided to Edge 3 via a removable medium (such as a CD-ROM or flash memory) or a network and stored in a non-volatile program memory, which is a non-temporary storage medium. Therefore, Edge 3 may have an interface for reading data from a removable medium.

[0041] Edge 3 is a computer system configured physically on one computer or logically or physically on a plurality of computers and may operate on a virtual computer built on a plurality of physical computer resources. For example, the edge key generation program 321 and the learning program 322 may each operate on a separate physical or logical computer or may be combined and operate on one physical or logical computer.

[0042] <Overview of the processing executed by the federated learning system> The processing overview of the federated learning system 1 will be described. When the control program 221 of the server 2 instructs each Edge 3 to start federated learning, the central processing unit 32 of each Edge 3 starts the edge key generation program 321 to generate an edge key pair 341, which is a public key cryptosystem key pair of the homomorphic encryption of each Edge 3, and stores it in the storage device 34. Also, each Edge 3 transmits the public key of the edge key pair 341 to the server 2. Next, each Edge 3 generates an edge secret key share 342 from the secret key of the edge key pair 341 and stores it in the storage device 34. Also, when each Edge 3 transmits the edge secret key share 342 to the server 2, the server 2 transmits the edge secret key share 342 to other Edge 3s. Note that the transmission of the edge secret key share 342 to other Edge 3s may be directly transmitted between Edge 3s without going through the server 2. Next, each Edge 3 generates an edge share 343 from the edge secret key share 342 by adding its own edge secret key share 342 and the received edge secret key share 342 and stores it in the storage device 34.

[0043] The server key generation program 222 of server 2 generates a common public key 241 from the public keys of the edge key pairs 341 obtained from each edge 3, and stores it in the storage device 24. Further, server 2 transmits the common public key 241 to each edge 3. Next, server 2 generates a decryption key pair 242, which is a key pair of a public key cryptosystem of a homomorphic encryption used for decrypting the encrypted aggregated gradient 244 for decryption, and stores it in the storage device 24. Further, server 2 transmits the public key of the decryption key pair 242 to each edge 3.

[0044] Next, when the central processing unit 32 of each edge 3 receives a learning process instruction from server 2, it starts the learning program 322 and performs machine learning based on the pre-stored learning data 344. At this point, an AI model 349 is stored in each edge 3, and all the AI models 349 of each edge 3 are the same. Each edge 3 generates an edge gradient 345 during the learning process, stores the generated edge gradient 345 in the storage device 34, encrypts the edge gradient 345 using the common public key 241 to generate an encrypted edge gradient 346, and stores it in the storage device 34. Next, each edge 3 transmits the encrypted edge gradient 346 to server 2.

[0045] When the server decryption program 223 of server 2 receives the encrypted edge gradient 346 of each edge 3, it generates an active encrypted aggregated gradient 243 and stores it in the storage device 24. At this time, the encrypted edge gradient 346 of the edge 3 without a response is not used. Next, server 2 confirms the edge 3 (active edge) that is the transmission source of the encrypted edge gradient 346. Also, a decryption edge, which is the edge 3 used when decrypting the active encrypted aggregated gradient 243, is selected from the active edges. The active encrypted aggregated gradient 243 and the reconstruction coefficient 347 corresponding to the edge 3 are transmitted to the selected decryption edge.

[0046] The learning program 322 for each decryption edge receives the actively encrypted aggregated gradient 243 and the reconstruction coefficient 347 from the server 2, and stores the reconstruction coefficient 347 in the storage device 34. Also, based on the actively encrypted aggregated gradient 243, the reconstruction coefficient 347, and the edge share 343, the learning program 322 generates an edge switch share 348 using the public key of the decryption key pair 242, stores it in the storage device 34, and transmits the edge switch share 348 to the server 2.

[0047] Based on the edge switch share 348 received from each decryption edge, the server decryption program 223 of the server 2 generates a decryption encrypted aggregated gradient 244 and stores it in the storage device 24. Next, the server 2 generates an aggregated gradient 245 from the decryption encrypted aggregated gradient 244 and the secret key of the decryption key pair 242, stores it in the storage device 24, and transmits the aggregated gradient 245 to each edge 3.

[0048] The learning program 322 of each edge 3 updates the AI model 349 based on the aggregated gradient 245 received from the server 2. At this time, if the learning end condition is satisfied, the process ends. If the condition is not satisfied, the server 2 instructs each edge 3 to perform the learning process again.

[0049] <Key generation process> Figure 7 is a flowchart of the key generation process.

[0050] In S701, the control program 221 instructs each edge 3 to generate a key. Hereinafter, an example in which the edge 3 is composed of four edges A to D as shown in FIG. 4 will be described. At the time of the key generation process, all four edges 3 are operating.

[0051] In S702, when each of the four edges 3 receives the key generation instruction, the edge key generation program 321 of each edge 3 generates an edge key pair 341 and transmits the public key of the edge key pair 341 to the server 2. When the server 2 receives the public key of the edge key pair 341 of each edge 3, the server key generation program 222 transmits the public key of the edge key pair 341 of each edge 3 to each edge 3.

[0052] In S703, the edge key generation program 321 for each edge 3 generates an edge secret key share 342 from the secret key of the edge key pair 341 based on Shamir's secret sharing method. Shamir's secret sharing method is a technique proposed by Shamir et al. in 1979. In Shamir's secret sharing method, the secret information is divided into data called a plurality of shares. These shares are created so that the original secret information can be restored when a certain defined combination is assembled. The simplest method is the (k,n) threshold method. In this embodiment, the following description is based on the (k,n) threshold method. In the (k,n) threshold method, among the n shares, the shares are created so that the original secret information can be restored when k or more threshold shares are assembled. That is, it is guaranteed that the original secret information does not leak in k-1 or fewer shares. In FIG. 4, s11, s12, s13, and s14 are edge secret key shares 342 generated from the secret key of edge A, respectively. If a certain number or more of s11, s12, s13, and s14 are collected, the secret key of edge A can be obtained. In the case of FIG. 4, s12 is transmitted to edge B, s13 is transmitted to edge C, and s14 is transmitted to edge D. As a result, the secret key of edge A is secretly distributed among a plurality of edges 3. That is, by dispersing and sharing the shares of each other's secret keys at each edge 3, it is not necessary to install a TTP. When transmitting the edge secret key share 342 to another edge 3, it is encrypted with the public key of the edge key pair 341 of each edge 3 held by the server 2 and transmitted via the server 2. At the received edge 3, it is decrypted using the secret key of the edge key pair 341 of the edge 3. Thereby, the edge secret key share 342 can be safely transmitted.

[0053] In S704, first, the edge key generation program 321 of each edge 3 generates an edge share 343 from the edge secret key share 342 based on the Shamir's secret sharing method. In FIG. 4, s'1, s'2, s'3, and s'4 are edge shares 343 respectively. For example, s'1 can be calculated as the sum of the edge secret key share s11 of edge A, the edge secret key share s12 of edge B, the edge secret key share s13 of edge C, and the edge secret key share s14 of edge D. Next, each edge share 343 is sent to the server 2. Since the edge share 343 is composed of shares of the secret keys of each edge 3, by aggregating a certain number or more of edge shares 343, the information encrypted with the common public key 241 can be decrypted. Also, at this time, since it is not necessary to expose the secret key of the edge key pair 341 of each edge 3 outside the edge 3, the edge gradient 345 at the edge 3 can be kept confidential.

[0054] In S705, as shown in FIG. 5, the server 2 generates a common public key (cpk) 241 from the public keys pk1, pk2, pk3, and pk4 of the edge key pairs 341 of each edge 3 received by the control program 221. For example, the common public key cpk can be generated as the sum of the public keys pk1 + pk2 + pk3 + pk4. The common public key 241 is used when encrypting the edge gradient 345 at each edge 3. Also, the generated common public key 241 is sent to each edge 3.

[0055] In S706, the server 2 generates a decryption key pair 242 which is a key pair of public key cryptography for decrypting the encrypted aggregated gradient 244 for decryption. Also, the public key of the decryption key pair 242 is sent to each edge 3.

[0056] <Learning Process> FIG. 8 is a flowchart of the learning process.

[0057] In S801, the control program 221 instructs the learning process for each edge 3. Hereinafter, as shown in FIG. 6, an example in which the edge 3 is composed of four edges A to D will be described in the same manner as the key generation process. At this time, edge A, edge B, and edge C are active edges operating normally, and edge D is a non-active edge that is not operating normally due to communication failures or malfunctions. In this embodiment, by using Shamir's secret sharing method and homomorphic encryption, learning can be continued even if some of the edges 3 become non-active edges during the learning process.

[0058] In S802, when each edge 3 receives the learning process instruction, the learning program 322 of each edge 3 reads the learning data 344 and executes the machine learning process. An edge gradient 345 representing the gradient information used when updating the AI model 349 is output during the machine learning process. At this time, if a non-active edge is included among the four edges 3, the machine learning process is not executed on that edge 3. That is, on edge D, the machine learning process is not executed at this point.

[0059] In S803, the learning program 322 of each edge 3 encrypts the edge gradient 345 using the common public key 241, generates an encrypted edge gradient 346, and transmits it to the server 2.

[0060] In S804, the server decryption program 223 of server 2 generates the active encrypted aggregation gradient 243 from the encrypted edge gradients 346 received from each edge 3. Encrypting x with the public key pk using homomorphic encryption is represented as Enc(pk,x). Utilizing the property that Enc(pk,x)+Enc(pk,y)=Enc(pk,x+y), the sum of the encrypted edge gradients 346 of each edge 3 is equal to the result of encrypting the sum of each edge gradient 345. In the case shown in FIG. 6, since edge A, edge B, and edge C are active edges, the active encrypted aggregation gradient (ct) 243 is generated by the sum of the encrypted edge gradients 346 collected from these three edges 3, that is, Enc(cpk,g1)+Enc(cpk,g2)+Enc(cpk,g3)=Enc(cpk,g1+g2+g3).

[0061] In S805, the server decryption program 223 of server 2 checks for active edges. In the case shown in FIG. 6, edges A, B, and C are active edges. Also, active edges are selected for decrypting the active encrypted aggregated gradient 243. For example, as shown in FIG. 9, edges A and C are selected as the decryption edges. At each active edge, in order to obtain the aggregated gradient 245 necessary for updating the AI model 349, it is necessary to decrypt the active encrypted aggregated gradient 243, and a common secret key corresponding to the common public key 241 used during encryption is required for decryption. However, the common secret key cannot be obtained. This is because, to generate the common secret key, it is necessary to aggregate the secret keys of the edge key pairs 341 of each edge 3 at server 2, but in that case, server 2 would be able to obtain the edge gradient 345 of each edge 3, and the confidentiality of the edge gradient 345 would be lost. Therefore, the secret key of the edge key pair 341 of each edge 3 is held only by that edge 3. Thus, in this embodiment, the Shamir's secret sharing method is used to obtain the aggregated gradient 245 without using the common secret key. In this embodiment, in the Shamir's secret sharing method, the threshold value, which is the number required for decryption, will be described as 2 hereinafter. When the threshold value is 2, the active encrypted aggregated gradient 243 can be decrypted using the edge switch shares 348, which will be described later, collected from any two of the active edges. In this embodiment, an example will be described in which edges A and C are selected as the edges 3 for decryption (hereinafter may be referred to as decryption edges).

[0062] In S806, the server decryption program 223 of server 2 transmits the active encrypted aggregated gradient 243 and the reconstruction coefficient 347 corresponding to the edge 3 to the decryption edges (edges A and C). The reconstruction coefficient 347 corresponding to each decryption edge is obtained from the Vandermonde matrix for edges A and C, which are the decryption edges.

[0063] In S807, the learning program 322 for each decoding edge generates an edge switch share (ks1, ks3) 348 from the active encrypted aggregated gradient 243, the reconstruction coefficient 347, the edge share 343, and the public key of the decryption key pair 242, and sends it to the server 2. The purpose of generating the edge switch share 348 will be described. In order to decrypt the active encrypted aggregated gradient 243, usually, a common secret key paired with the common public key 241 used at the time of encryption is required. However, if a common secret key is simply generated, not only the active encrypted aggregated gradient 243 but also the encrypted edge gradient 346 can be decrypted, and the confidentiality of the edge gradient 345 will be lost. Therefore, an edge switch share 348 is generated and encrypted with the public key of the decryption key pair 242, including the edge share 343 required for decrypting the active encrypted aggregated gradient 243 at the time of generation. As described above, the edge share 343 is composed of shares of the secret keys of each edge 3. For this reason, by aggregating the edge switch shares 348 generated from the edge shares 343 and decrypting them with the secret key of the decryption key pair 242, the active encrypted aggregated gradient 243 can be decrypted without generating a common secret key. As a result, the active encrypted aggregated gradient 243 can be decrypted while maintaining the confidentiality of the edge gradient 345. The details of the method for generating the edge switch share 348 will be described later.

[0064] In S808, when server 2 receives edge switch shares (ks1, ks3) 348 from each decryption edge, server encryption decryption program 223 generates an encrypted aggregated gradient for decryption (Ct’) 244 from the received edge switch shares 348. In this embodiment, the edge switch shares ks1 and ks3 are added to generate the encrypted aggregated gradient ct’ for decryption. Next, the aggregated gradient 245 is obtained from the encrypted aggregated gradient 244 for decryption and the private key of the decryption key pair 242. Next, the aggregated gradient 245 is transmitted to all edges 3. At this time, if communication becomes impossible with some of the edges, server 2 interrupts the process until all edges 3 can receive. Also, the information of the edges 3 with which communication has become impossible is accumulated, and at the timing of updating the AI model 349 in S809, the past aggregated gradients 245 are sequentially transmitted and applied to the AI models 349 of each edge 3. Thereby, the AI models 349 of all edges 3 can always be kept the same.

[0065] The processing of S807 and S808 will be described in more detail. The edge switch share 348 includes the edge share 343 of each edge 3 that is an element of the common private key corresponding to the common public key 241 used when generating the active encrypted aggregated gradient 243, and the reconstruction coefficient 347 corresponding to the edge share 343. From this, if the number of active edges is equal to or greater than the above-described threshold k, the aggregated gradient 245 can be obtained without the common private key.

[0066] More specifically, the active encrypted aggregated gradient 243 is represented as ct = (c0, c1), the encrypted aggregated gradient 244 for decryption is represented as ct’, the common private key is represented as s, the reconstruction coefficient 347 of edge i is represented as ri, the edge share 343 of edge i is represented as s’i, the public key of the decryption key pair 242 is represented as tpk = (p’0, p’1), the private key of the decryption key pair 242 is represented as tsk, the set of all edges 3 is represented as P, and the edge switch share 348 of each decryption edge is represented as ksi = (h0,i, h1,i).

[0067] As described above, in order to obtain the aggregated gradient 245, a common secret key corresponding to the common public key 241 is required, but the common secret key cannot be used. Therefore, as in the left side of Equation (1), the edge switch shares 348 are added only for the decryption edges to generate the encrypted aggregated gradient for decryption (ct’) 244, and it is considered to decrypt it with the secret key tsk of the key pair 242 for decryption. Note that BFV.Decrypt(sk,x) represents decrypting x with the secret key sk in the homomorphic encryption scheme BFV.

[0068]

Number

[0069] This means that if the encrypted aggregated gradient for decryption (ct’) 244 is decrypted with the secret key tsk of the key pair 242 for decryption, the result of decrypting the active encrypted aggregated gradient (ct) 243 with s, that is, the aggregated gradient 245 can be obtained. Therefore, first, a process of obtaining the encrypted aggregated gradient for decryption (ct’) 244 is performed. In order to obtain the encrypted aggregated gradient for decryption (ct’) 244, based on Shamir's secret sharing method, first, the edge switch share (ksi) 348 is obtained from the following Equation (2). Here, ui is a value generated by random sampling. e0,i and e1,i are values sampled based on the noise distribution of RLWE. That is, Equation (2) represents that the edge switch share (ksi) 348 is generated from ct, ri, tpk, and s’i.

[0070]

Number

[0071] At Server 2, the encrypted aggregated gradient for decryption (ct’) 244 is obtained from the edge switch shares (ksi) 348 collected from each decryption edge by the following Equation (3).

[0072]

Number

[0073] Finally, the server 2 can decrypt the encrypted aggregated gradient (ct’) 244 with the private key of the decryption key pair 242 to obtain the aggregated gradient 245. Since the edge switch share 348 is encrypted with the public key 241 of the common public key and the public key tpk of the decryption key pair 242, by decrypting the encrypted aggregated gradient (ct’) 244 obtained by aggregating the edge switch shares 348, Σ in Equation (3) i h 0,i The common secret key can be constructed from the terms, and the encryption with the common public key 241 is also decrypted. By doing so, without exposing the private key of the edge key pair 341 at each edge 3 outside the edge 3, only the common secret key can be extracted, and the server 2 can obtain the aggregated gradient 245.

[0074] In S809, at each edge 3, the learning program 322 updates the AI model 349 based on the aggregated gradient 245 received from the server 2. As described in S808, in the present invention, even if some edges 3 become incommunicable at the time of S808, the AI model 349 can be kept the same by transmitting the aggregated gradient 245 later. Also, if it is not necessary to keep the AI model 349 the same, the aggregated gradient 245 transmitted at that timing may be discarded for the edge 3 that has become incommunicable.

[0075] In S810, the learning program 322 of each edge 3 determines whether learning is completed. If learning is not completed, it returns to S801. If learning is completed, the process ends. Various means can be applied to determine whether learning is completed, such as when the value output by the loss function used in machine learning becomes a certain value or less.

[0076] Note that in this embodiment, since the gradients are additive in federated learning, the additive property of homomorphic encryption is used, but applications using the multiplicative property of homomorphic encryption are also possible.

[0077] As described above, in the federated learning system 1 of this embodiment, the edge 3 has an edge key generation unit (edge key generation program 321) that generates an edge key pair 341 including an edge public key and an edge private key, and a learning unit (learning program 322) that learns the AI model 349 using the learning data 344. The server 2 has a server key generation unit (server key generation program 222) that generates a decryption key pair 242 including a decryption public key and a decryption private key, and an encryption / decryption unit (server encryption / decryption program 223) that executes data processing. The learning program 322 encrypts the edge gradient 345 representing the learning result of the AI model 349 with the common public key and transmits the encrypted edge gradient 346 to the server 2. The server encryption / decryption program 223 adds the encrypted edge gradients 346 received from a plurality of edges 3 to generate an active encrypted aggregated gradient 243, and transmits it to the edge 3. The learning program 322 generates an edge switch share 348 obtained by encrypting the active encrypted aggregated gradient 243, and transmits it to the server 2. The server encryption / decryption program 223 adds the edge switch shares 348 received from a plurality of edges 3 to generate a decryption encrypted aggregated gradient 244, decrypts the decryption encrypted aggregated gradient 244 using the private key of the decryption key pair 242 to generate an aggregated gradient 245, and transmits it to the edge 3. Since the learning program 322 learns the AI model 349 using the aggregated gradient 245 received from the server 2, it is possible to aggregate the gradient information of each edge 3 while keeping it confidential without installing a TTP, and to generate an AI model 349 that also takes into account the learning data 344 of other edges 3. In addition, since it is not necessary to transmit the private key of each edge 3 to the outside, the gradient information of each edge 3 can be decrypted only by that edge 3, and the confidentiality can be improved compared to the case where a TTP is installed. Also, since each edge 3 communicates only with the server 2 during the learning of the AI model 349, the communication cost can be reduced. Furthermore, even if some of the edges 3 become inoperable during the learning process, the learning process can continue.

[0078] Also, since the result of adding the encrypted edge gradients 346 is equal to the result of adding and encrypting the edge gradients 345, it is possible to aggregate the edge gradients 345 while keeping them confidential by encryption.

[0079] Also, the edge key generation program 321 generates an edge secret key share 342 from the secret key of the generated edge key pair 341 based on Shamir's secret sharing method, and adds the edge secret key shares generated by a plurality of edges 3 (for example, the edge secret key share generated by its own edge 3 and the edge secret key share generated by other edges 3) to generate an edge share 343. Therefore, since it is not necessary to transmit the secret key of each edge 3 to the outside, the gradient information of each edge 3 can be decrypted only by that edge 3, and the confidentiality can be improved compared to the case where a TTP is installed.

[0080] Also, the edge key generation program 321 generates an edge secret key share 342 from the edge secret key based on Shamir's secret sharing method, and adds the edge secret key shares 342 generated by a plurality of edges 3 to generate an edge share 343. Therefore, the keys can be distributed and managed by a plurality of edges without disclosing the edge secret key, and the confidentiality can be improved compared to the case where a TTP is installed.

[0081] Also, the learning program 322 encrypts the active encrypted aggregated gradient 243, the edge share 343, and the reconstruction coefficient 347 using the public key tpk of the decryption key pair to generate an edge switch share 348. Therefore, elements capable of constructing a common secret key can be distributed and managed by a plurality of edges, the confidentiality of the common secret key can be ensured, and the gradient information of each edge 3 can be kept confidential.

[0082] Also, the server decryption program receives edge switch shares 348 from a predetermined number (for example, the threshold k in the (k,n) threshold method) or more nodes 3, adds the received edge switch shares 348 to generate a decryption encrypted aggregated gradient 244, decrypts the generated decryption encrypted aggregated gradient 244 using the secret key of the decryption key pair 242 to generate an aggregated gradient 245, and transmits it to the edge 3 that transmitted the edge switch share. Therefore, even if some edges become inoperable, the learning process can continue.

[0083] In addition, in the process of decrypting the generated encrypted aggregated gradient 244 for decryption, the server decryption program constructs a common secret key and generates an aggregated gradient 245 in which the edge gradients 345 are aggregated by decrypting the encryption with the common public key. Therefore, without extracting the common secret key outside, the encrypted aggregated gradient ct’(244) for decryption generated by aggregating the encrypted edge gradient 346 encrypted with the common public key can be decrypted to generate the aggregated gradient 245, the confidentiality of the common secret key can be ensured, and the gradient information of each edge 3 can be kept confidential.

[0084] Note that the present invention is not limited to the above-described embodiments, and includes various modifications and equivalent configurations within the scope of the appended claims. For example, the above-described embodiments have been described in detail for easy understanding of the present invention, and the present invention is not necessarily limited to those having all the configurations described. Also, a part of the configuration of one embodiment may be replaced with the configuration of another embodiment. Also, the configuration of another embodiment may be added to the configuration of one embodiment. Also, for a part of the configuration of each embodiment, addition, deletion, or replacement with other configurations may be made.

[0085] Also, the above-described respective configurations, functions, processing units, processing means, etc. may be realized in hardware by designing a part or all of them, for example, by means of an integrated circuit, or may be realized in software by a processor interpreting and executing a program for realizing each function.

[0086] Information such as programs, tables, files, etc. for realizing each function can be stored in a storage device such as a memory, a hard disk, an SSD (Solid State Drive), or a recording medium such as an IC card, an SD card, or a DVD.

[0087] Also, the control lines and information lines show those considered necessary for explanation, and do not necessarily show all the control lines and information lines necessary for implementation. In practice, it may be considered that almost all the configurations are interconnected.

Explanation of Reference Numerals

[0088] 1 Federated learning system 2 Server 3 Edge 4 Network 21 Input / output device 22 Central processing unit 23 Communication control device 24 Storage device 31 Input / output device 32 Central processing unit 33 Communication control device 34 Storage device 211 Information input device 212 Information output device 221 Control program 222 Server key generation program 223 Server decryption program 241 Common public key 242 Decryption key pair 243 Active encrypted aggregated gradient 244 Decryption encrypted aggregated gradient 245 Aggregated gradient 311 Information input device 312 Information output device 321 Edge key generation program 322 Learning program 341 Edge key pair 342 Edge private key share 343 Edge share 344 Learning data 345 Edge gradient 346 Encrypted edge gradient 347 Reconstruction coefficient 348 Edge switch share 349 AI model

Claims

1. A federated learning system that aggregates gradient information representing the results of learning of an AI model in an edge device, comprising: an edge device that generates an AI model by learning; and a server device that collects the gradient information from the edge device, wherein the edge device includes an edge key generation unit that generates an edge key pair including an edge public key and an edge private key, and a learning unit that learns the AI model using learning data; the server device includes a server key generation unit that generates a decryption key pair including a decryption public key and a decryption private key, and an encryption / decryption unit that executes data processing; the server device generates a common public key by adding the edge public key included in the edge key pair in the server key generation unit; the edge device generates an encrypted gradient obtained by encrypting the gradient information with the common public key using a homomorphic encryption in the learning unit, and transmits the generated encrypted gradient to the server device; the server device generates an encrypted aggregated gradient by adding the encrypted gradients received from a plurality of the edge devices in the encryption / decryption unit, and transmits the generated encrypted aggregated gradient to the edge device; the edge device generates an edge switch share obtained by encrypting the encrypted aggregated gradient with the decryption public key using a homomorphic encryption in the learning unit, and transmits the generated edge switch share to the server device; the server device generates a decryption encrypted aggregated gradient by adding the edge switch shares received from a plurality of the edge devices in the encryption / decryption unit, decrypts the generated decryption encrypted aggregated gradient with the decryption private key to generate an aggregated gradient, and transmits the generated aggregated gradient to the edge device; the edge device is a federated learning system that learns the AI model using the aggregated gradient received from the server device in the learning unit.

2. The federated learning system according to claim 1, wherein a result of adding the encrypted gradients is equal to a result of adding and encrypting the gradients generated by the edge device.

3. The federated learning system according to claim 1, wherein the edge key generation unit generates an edge private key share from the edge private key based on Shamir's secret sharing method, and generates an edge share by adding the edge private key shares generated by a plurality of the edge devices.

4. The federated learning system according to claim 3, wherein a reconstruction coefficient, which is a value necessary for reconstructing a common secret key from the edge share, is determined, and the learning unit encrypts the encrypted aggregated gradient, the edge share, and the reconstruction coefficient with the decryption public key to generate an edge switch share. The federated learning system is characterized by this.

5. The federated learning system according to claim 4, wherein the encryption / decryption unit receives the edge switch share from a predetermined number or more of the edge devices, adds the received edge switch shares to generate an encrypted aggregated gradient for decryption, decrypts the generated encrypted aggregated gradient for decryption with a decryption secret key to generate the aggregated gradient, and transmits the aggregated gradient to the edge device that transmitted the edge switch share. The federated learning system is characterized by this.

6. The federated learning system according to claim 5, wherein the encryption / decryption unit constructs the common secret key in the process of decrypting the generated encrypted aggregated gradient for decryption, and generates the aggregated gradient by decrypting the encrypted aggregated gradient for decryption with the constructed common secret key. The federated learning system is characterized by this.

7. A federated learning method by a federated learning system that aggregates gradient information representing the result of learning an AI model in an edge device, wherein an edge device generates an edge key pair including an edge public key and an edge secret key, and learns the AI model using learning data, and a server device that collects the gradient information from the edge device, generates a decryption key pair including a decryption public key and a decryption secret key, and executes data processing are provided, and the federated learning method includes the server device adding the edge public key included in the edge key pair to generate a common public key, the edge device generating an encrypted gradient by encrypting the gradient information with the common public key using a homomorphic encryption, and transmitting the generated encrypted gradient to the server device, the server device adding the encrypted gradients received from a plurality of the edge devices to generate an encrypted aggregated gradient, and transmitting the generated encrypted aggregated gradient to the edge device, and the edge device generating an edge switch share by encrypting the encrypted aggregated gradient with the decryption public key using a homomorphic encryption, and transmitting the generated edge switch share to the server device. The server device adds the edge switch shares received from a plurality of the edge devices to generate an encrypted aggregated gradient for decoding, decrypts the generated encrypted aggregated gradient for decoding with the decryption private key to generate an aggregated gradient, and transmits the generated aggregated gradient to the edge device. A federated learning method in which the edge device learns the AI model using the aggregated gradient received from the server device.

Citation Information

Patent Citations

  • Execution authority decentralization method and system

    JP2008048121A

  • Method for collaborative learning of an artificial neural network without disclosing training data

    US20200394518A1

  • Update method for neural network, terminal device, calculation device, and program

    WO2021106077A1