Method for performing federated learning by using data encryption to predict dangerous situation
The method addresses data privacy and efficiency issues in federated learning by using encryption-based sub-modules for CCTV data analysis, enhancing security and model performance in risk prediction systems.
Patent Information
- Application Number
- PCT/KR2024/020482
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-29
- Filing Date
- 2024-12-17
- Publication Date
- 2025-07-03
AI Technical Summary
Existing machine learning methods for risk prediction using CCTV data face challenges with data privacy violations, security issues, and inefficiencies in data movement, particularly in federated learning systems.
A method for performing federated learning using data encryption, where local learning data is processed through both encryption-based and non-encryption-based sub-modules to generate final predictions, allowing secure and efficient model updates across distributed devices.
This approach enhances data privacy by preventing data transmission to central servers, reduces inefficiencies in data movement, and improves model performance by leveraging diverse data sources while maintaining security and accuracy.
Smart Images

Figure KR2024020482_03072025_PF_FP_ABST
Abstract
Description
How to Use Federated Learning to Predict Risky Situations Using Data Encryption
[0001] The present invention relates to a method for predicting a risk situation, and more specifically, to a technique for performing federated learning using data encryption for predicting a risk situation.
[0002] With the recent increase in Closed Circuit Television (CCTV) installations, interest in intelligent video analytics technology for efficient monitoring is growing. Intelligent video analytics analyzes video information to automatically detect abnormal behavior and send alerts to managers, enabling proactive prevention of accidents and prompt response to minimize damage when they occur. Conventional machine learning, which utilizes images captured by CCTV to perform risk prediction, relies on centralized data collection and training. However, this approach poses challenges such as privacy violations, security issues, and inefficient data transfer.
[0003] Meanwhile, federated learning is a technique proposed to address these issues. Federated learning allows each entity or organization to train a model through communication with a central server, without sending its own data to the central server. Federated learning can be effectively utilized for risk prediction in areas where data privacy and security are crucial.
[0004] Republic of Korea Patent Publication No. 10-2023-0128597 (September 5, 2023) discloses an indoor risk situation prediction and notification service based on real-time media analysis.
[0005] The present disclosure provides a method for performing federated learning by utilizing data encryption for risk situation prediction, which can flexibly perform federated learning on a sub-module basis and a model basis, based on a model including parallel sub-modules (encryption-based sub-modules and non-encryption-based sub-modules).
[0006] Meanwhile, the technical task to be achieved by the present disclosure is not limited to the technical task mentioned above, and may include various technical tasks within a scope obvious to a person skilled in the art from the contents described below.
[0007] According to one embodiment of the present disclosure for achieving the aforementioned task, a method for performing federated learning by utilizing encryption of data performed by a computing device is disclosed. The method may include the steps of: receiving a first type of global sub-module and a second type of global sub-module; inputting local learning data into the first type of global sub-module to perform a first global sub-prediction based on non-encryption; encrypting the local learning data and then inputting it into the second type of global sub-module to perform a second global sub-prediction based on encryption; obtaining a final prediction based on the first global sub-prediction and the second global sub-prediction; and performing local learning on the first type of global sub-module and the second type of global sub-module based on the final prediction to obtain the first type of local sub-module and the second type of local sub-module.
[0008] In one embodiment, the method may further include providing parameter information of the first type of local sub-module and parameter information of the second type of local sub-module to the global device.
[0009] In one embodiment, the method further comprises: identifying a data sharing type of a local device; determining a range of data to be provided to the global device among the local learning data based on the identified sharing type; and providing data of the determined range among the local learning data, wherein the sharing type may include a first type in which all local learning data is shared, but personal information data or security data is shared in an encrypted state and the remaining data is shared in an unencrypted state; a second type in which a limited range of local learning data excluding personal information data or security data is shared in an unencrypted state; and a third type in which no local learning data is shared.
[0010] In one embodiment, the local learning data includes image type data, and the personal information data or the security data included in the local learning data can be identified by recognizing a personal information-related body part or a security-related object included in the image based on object recognition.
[0011] In one embodiment, the global learning or local learning associated with the federated learning may be performed on a sub-module basis or on a model basis in which sub-modules are combined.
[0012] In one embodiment, the global learning may include: updating a first type of global sub-module based on parameter information of all first type of local sub-modules received from all local devices; and updating a second type of global sub-module based on parameter information of all second type of local sub-modules received from all local devices.
[0013] In one embodiment, the global learning may include an operation of collecting local learning data received from each local device in different ranges according to a sharing type, thereby obtaining a first group of unencrypted data and a second group of data already received in an encrypted state; an operation of further updating the first type of global sub-module and the second type of global sub-module together by utilizing the data of the first group; and an operation of further updating only the second type of global sub-module by utilizing the data of the second group.
[0014] In one embodiment, the operation of further updating the first type global sub-module and the second type global sub-module together by utilizing the data of the first group may include: inputting the data of the first group into the first type global sub-module to perform the first global sub-prediction based on non-encryption; inputting the data of the first group into the second type global sub-module to perform the second global sub-prediction based on encryption; obtaining a final global prediction based on the first global sub-prediction and the second global sub-prediction; and further updating the first type global sub-module and the second type global sub-module together based on the final global prediction.
[0015] In one embodiment, the operation of further updating only the second type of global sub-module by utilizing the data of the second group may include: inputting the data of the second group into the second type of global sub-module to perform an encryption-based second global sub-prediction; and further updating only the second type of global sub-module based on the encryption-based second global sub-prediction.
[0016] In one embodiment, the act of encrypting the local learning data may include at least one of: converting the local learning data into an encrypted hash value; or converting a portion of an image included in the local learning data into an encrypted image pattern.
[0017] In one embodiment, the local learning data includes a local image captured by a local camera, the first type of local sub-module performs a first local sub-prediction for a dangerous situation based on the local image, the second type of local sub-module performs a second local sub-prediction for a dangerous situation based on data generated by encrypting the local image, and a local model including the first type of local sub-module and the second type of local sub-module can generate final prediction information by synthesizing sub-predictions of the first type of local sub-module and the second type of local sub-module.
[0018] According to one embodiment of the present disclosure for achieving the above-described task, a computer program stored in a computer-readable storage medium is disclosed. When the computer program is executed on one or more processors, the computer program causes the one or more processors to perform the following operations for performing federated learning by utilizing data encryption, the operations including: receiving a first type of global sub-module and a second type of global sub-module; inputting local learning data into the first type of global sub-module to perform a first global sub-prediction based on non-encryption; encrypting the local learning data and then inputting it into the second type of global sub-module to perform a second global sub-prediction based on encryption; obtaining a final prediction based on the first global sub-prediction and the second global sub-prediction; And based on the final prediction, it may include an operation of performing local learning on the first type of global sub-module and the second type of global sub-module to obtain the first type of local sub-module and the second type of local sub-module.
[0019] In one embodiment, the method may further include providing parameter information of the first type of local sub-module and parameter information of the second type of local sub-module to the global device.
[0020] In one embodiment, the operation further includes: identifying a data sharing type of a local device; determining a range of data to be provided to the global device among the local learning data based on the identified sharing type; and providing data of the determined range among the local learning data, wherein the sharing type may include a first type in which all local learning data is shared, but personal information data or security data is shared in an encrypted state and the remaining data is shared in an unencrypted state; a second type in which a limited range of local learning data excluding personal information data or security data is shared in an unencrypted state; and a third type in which no local learning data is shared.
[0021] In one embodiment, the global learning or local learning associated with the federated learning may be performed on a sub-module basis or on a model basis in which sub-modules are combined.
[0022] In one embodiment, the global learning may include: updating a first type of global sub-module based on parameter information of all first type of local sub-modules received from all local devices; and updating a second type of global sub-module based on parameter information of all second type of local sub-modules received from all local devices.
[0023] In one embodiment, the global learning may include an operation of collecting local learning data received from each local device in different ranges according to a sharing type, thereby obtaining a first group of unencrypted data and a second group of data already received in an encrypted state; an operation of further updating the first type of global sub-module and the second type of global sub-module together by utilizing the data of the first group; and an operation of further updating only the second type of global sub-module by utilizing the data of the second group.
[0024] In one embodiment, the act of encrypting the local learning data may include at least one of: converting the local learning data into an encrypted hash value; or converting a portion of an image included in the local learning data into an encrypted image pattern.
[0025] In one embodiment, the local learning data includes a local image captured by a local camera, the first type of local sub-module performs a first local sub-prediction for a dangerous situation based on the local image, the second type of local sub-module performs a second local sub-prediction for a dangerous situation based on data generated by encrypting the local image, and a local model including the first type of local sub-module and the second type of local sub-module can generate final prediction information by synthesizing sub-predictions of the first type of local sub-module and the second type of local sub-module.
[0026] A computing device according to one embodiment of the present disclosure for achieving the above-described task is disclosed. The device comprises at least one processor; and a memory, wherein the at least one processor is configured to receive a first type of global sub-module and a second type of global sub-module; input local learning data into the first type of global sub-module to perform a first global sub-prediction based on non-encryption; input the encrypted local learning data into the second type of global sub-module to perform a second global sub-prediction based on encryption; obtain a final prediction based on the first global sub-prediction and the second global sub-prediction; and perform local learning on the first type of global sub-module and the second type of global sub-module based on the final prediction, thereby obtaining the first type of local sub-module and the second type of local sub-module.
[0027] In one embodiment, the at least one processor may be further configured to provide parameter information of the first type of local sub-module and parameter information of the second type of local sub-module to the global device.
[0028] In one embodiment, the at least one processor is further configured to identify a data sharing type of the local device; determine a range of data to be provided to the global device among the local learning data based on the identified sharing type; and provide data of the determined range among the local learning data, wherein the sharing type may include a first type in which all local learning data is shared, but personal information data or security data is shared in an encrypted state and the remaining data is shared in an unencrypted state; a second type in which a limited range of local learning data excluding personal information data or security data is shared in an unencrypted state; and a third type in which no local learning data is shared.
[0029] In one embodiment, the global learning or local learning associated with the federated learning may be performed on a sub-module basis or on a model basis in which sub-modules are combined.
[0030] In one embodiment, the global learning may include: updating a first type of global sub-module based on parameter information of all first type of local sub-modules received from all local devices; and updating a second type of global sub-module based on parameter information of all second type of local sub-modules received from all local devices.
[0031] In one embodiment, the global learning may include an operation of collecting local learning data received from each local device in different ranges according to a sharing type, thereby obtaining a first group of unencrypted data and a second group of data already received in an encrypted state; an operation of further updating the first type of global sub-module and the second type of global sub-module together by utilizing the data of the first group; and an operation of further updating only the second type of global sub-module by utilizing the data of the second group.
[0032] In one embodiment, the act of encrypting the local learning data may include at least one of: converting the local learning data into an encrypted hash value; or converting a portion of an image included in the local learning data into an encrypted image pattern.
[0033] In one embodiment, the local learning data includes a local image captured by a local camera, the first type of local sub-module performs a first local sub-prediction for a dangerous situation based on the local image, the second type of local sub-module performs a second local sub-prediction for a dangerous situation based on data generated by encrypting the local image, and a local model including the first type of local sub-module and the second type of local sub-module can generate final prediction information by synthesizing sub-predictions of the first type of local sub-module and the second type of local sub-module.
[0034] The present disclosure is based on a model including parallel sub-modules (encryption-based sub-modules and non-encryption-based sub-modules), and can flexibly perform federated learning on a sub-module basis and a model basis.
[0035] In addition, the present disclosure can improve the performance of a model by performing learning in modules even when there is an imbalance between encrypted and non-encrypted data when performing additional learning at the global level.
[0036] In addition, the present disclosure can secure prediction performance by updating only the encryption-related module even in situations where the encryption method is changed and a model update is required, or when it is difficult to update the entire model due to network conditions.
[0037] Meanwhile, the effects of the present disclosure are not limited to the effects mentioned above, and various effects may be included within a range apparent to those skilled in the art from the contents described below.
[0038] FIG. 1 is a block diagram of a computing device for performing federated learning using data encryption according to one embodiment of the present disclosure.
[0039] FIG. 2 is a conceptual diagram illustrating a neural network according to one embodiment of the present disclosure.
[0040] FIG. 3 is a conceptual diagram schematically illustrating an operation of performing federated learning by utilizing encryption of data according to one embodiment of the present disclosure.
[0041] FIG. 4 is a schematic conceptual diagram of a local device according to one embodiment of the present disclosure.
[0042] FIG. 5 is a schematic conceptual diagram of a global device according to one embodiment of the present disclosure.
[0043] FIG. 6 is a schematic conceptual diagram of an update operation of a global model according to one embodiment of the present disclosure.
[0044] FIG. 7 is a flowchart illustrating a method for performing federated learning by utilizing encryption of data according to one embodiment of the present disclosure.
[0045] FIG. 8 is a simplified, general schematic diagram of an exemplary computing environment in which embodiments of the present disclosure may be implemented.
[0046] Various embodiments are now described with reference to the drawings. In this specification, various descriptions are provided to facilitate understanding of the present disclosure. However, it will be apparent that these embodiments may be practiced without these specific details.
[0047] As used herein, the terms "component," "module," "system," and the like refer to computer-related entities, hardware, firmware, software, a combination of software and hardware, or an execution of software. For example, a component may be, but is not limited to, a procedure running on a processor, a processor, an object, a thread of execution, a program, and / or a computer. For example, both an application running on a computing device and the computing device may be a component. One or more components may reside within a processor and / or a thread of execution. A component may be localized within a single computer. A component may be distributed between two or more computers. Furthermore, these components may execute from various computer-readable media having various data structures stored therein. Components may communicate via local and / or remote processes, for example, by signals comprising one or more data packets (e.g., data from one component interacting with another component in a local system, a distributed system, and / or data transmitted to another system via a network such as the Internet via signals).
[0048] Furthermore, the term "or" is intended to mean an inclusive "or" rather than an exclusive "or." That is, unless otherwise specified or clear from context, "X employs A or B" is intended to mean either of the natural inclusive permutations. That is, if X employs A; X employs B; or X employs both A and B, "X employs A or B" can apply to any of these cases. Furthermore, the term "and / or" as used herein should be understood to refer to and include all possible combinations of one or more of the associated items listed.
[0049] Additionally, the terms "comprises" and / or "comprising" should be understood to imply the presence of the features and / or components in question. However, it should be understood that the terms "comprises" and / or "comprising" do not exclude the presence or addition of one or more other features, components, and / or groups thereof. Furthermore, unless otherwise specified or clear from the context to refer to the singular form, the singular in the specification and claims should generally be construed to mean "one or more."
[0050] And, the term "at least one of A or B" should be interpreted to mean "if it includes only A", "if it includes only B", or "if it is combined in the composition of A and B".
[0051] Those skilled in the art should further appreciate that the various illustrative logical blocks, configurations, modules, circuits, means, logics, and algorithm steps described in connection with the embodiments disclosed herein may be implemented as electronic hardware, computer software, or combinations of both. To clearly illustrate the interchangeability of hardware and software, various illustrative components, blocks, configurations, means, logics, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Skilled artisans may implement the described functionality in varying ways for each particular application. However, such implementation decisions should not be interpreted as causing a departure from the scope of the present disclosure.
[0052] The description of the disclosed embodiments is provided to enable a person skilled in the art to make or use the present invention. Various modifications to these embodiments will be apparent to those skilled in the art. The general principles defined herein may be applied to other embodiments without departing from the scope of the present disclosure. Therefore, the present invention is not limited to the embodiments disclosed herein. The present invention is to be construed in the widest scope consistent with the principles and novel features disclosed herein.
[0053] In the present disclosure, network function, artificial neural network and neural network can be used interchangeably.
[0054]
[0055] FIG. 1 is a block diagram of a computing device for performing federated learning by utilizing encryption of data according to one embodiment of the present disclosure.
[0056] The configuration of the computing device (100) illustrated in FIG. 1 is merely a simplified example. In one embodiment of the present disclosure, the computing device (100) may include other configurations for performing the computing environment of the computing device (100), and only some of the disclosed configurations may constitute the computing device (100).
[0057] A computing device (100) may include a processor (110), memory (130), and network unit (150).
[0058] The processor (110) may be configured with one or more cores, and may include a processor for data analysis and deep learning, such as a central processing unit (CPU), a general purpose graphics processing unit (GPGPU), and a tensor processing unit (TPU) of a computing device. The processor (110) may read a computer program stored in the memory (130) to perform data processing for machine learning according to an embodiment of the present disclosure. According to an embodiment of the present disclosure, the processor (110) may perform operations for learning a neural network. The processor (110) may perform calculations for learning a neural network, such as processing input data for learning in deep learning (DL), extracting features from input data, calculating errors, and updating weights of a neural network using backpropagation. At least one of the CPU, GPGPU, and TPU of the processor (110) may process learning of a network function. For example, a CPU and a GPGPU can jointly process network function learning and data classification using network functions. Furthermore, in one embodiment of the present disclosure, processors of multiple computing devices can be jointly used to process network function learning and data classification using network functions. Furthermore, a computer program executed on a computing device according to one embodiment of the present disclosure may be a CPU, GPGPU, or TPU executable program.
[0059] According to one embodiment of the present disclosure, the memory (130) can store any form of information generated or determined by the processor (110) and any form of information received by the network unit (150).
[0060] According to one embodiment of the present disclosure, the memory (130) may include at least one type of storage medium among a flash memory type, a hard disk type, a multimedia card micro type, a card type memory (e.g., SD or XD memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a magnetic disk, and an optical disk. The computing device (100) may also operate in relation to web storage that performs the storage function of the memory (130) on the internet. The description of the above-described memory is merely an example, and the present disclosure is not limited thereto.
[0061] The network unit (150) according to one embodiment of the present disclosure can use various wired communication systems such as a public switched telephone network (PSTN), xDSL (x Digital Subscriber Line), RADSL (Rate Adaptive DSL), MDSL (Multi Rate DSL), VDSL (Very High Speed DSL), UADSL (Universal Asymmetric DSL), HDSL (High Bit Rate DSL), and a local area network (LAN).
[0062] In addition, the network unit (150) presented in this specification can use various wireless communication systems such as CDMA (Code Division Multi Access), TDMA (Time Division Multi Access), FDMA (Frequency Division Multi Access), OFDMA (Orthogonal Frequency Division Multi Access), SC-FDMA (Single Carrier-FDMA) and other systems.
[0063] In the present disclosure, the network unit (150) may be configured regardless of the communication mode, such as wired or wireless, and may be configured as various communication networks, such as a local area network (LAN), a personal area network (PAN), and a wide area network (WAN). In addition, the network may be the well-known World Wide Web (WWW), and may also utilize a wireless transmission technology used for short-distance communication, such as infrared (IrDA: Infrared Data Association) or Bluetooth.
[0064] The techniques described in this specification can be used in other networks as well as the networks mentioned above.
[0065]
[0066] FIG. 2 illustrates an exemplary structure of an artificial intelligence-based model according to one embodiment of the present disclosure.
[0067] Throughout this specification, the terms artificial intelligence model, artificial intelligence-based model, computational model, neural network, network function, and neural network may be used interchangeably.
[0068] A neural network can be composed of a set of interconnected computational units, generally referred to as nodes. These nodes can also be referred to as neurons. A neural network consists of at least one node. The nodes (or neurons) that make up a neural network can be interconnected by one or more links.
[0069] Within a neural network, one or more nodes connected via links can form a relationship between input nodes and output nodes. The concept of input nodes and output nodes is relative, meaning that any node that is in an output node relationship with one node can also be in an input node relationship with another node, and vice versa. As described above, the relationship between input nodes and output nodes can be created based on links. One input node can be connected to one or more output nodes via links, and vice versa.
[0070] In a relationship between input nodes and output nodes connected through a single link, the data of the output node can have its value determined based on the data input to the input node. Here, the link interconnecting the input nodes and output nodes can have a weight. The weight can be variable and can be varied by the user or an algorithm so that the neural network can perform a desired function. For example, when one or more input nodes are interconnected to one output node through each link, the output node can determine the output node value based on the values input to the input nodes connected to the output node and the weight set on the link corresponding to each input node.
[0071] As described above, a neural network is a network in which one or more nodes are interconnected through one or more links, forming input and output node relationships within the network. The characteristics of a neural network can be determined based on the number of nodes and links within the network, the relationships between the nodes and links, and the weights assigned to each link. For example, if two neural networks have the same number of nodes and links but different weight values for the links, the two neural networks can be perceived as different from each other.
[0072] A neural network can be composed of a set of one or more nodes. A subset of the nodes comprising the neural network can form a layer. Some of the nodes comprising the neural network can form a layer based on their distances from the initial input node. For example, a set of nodes that are n distances from the initial input node can form n layers. The distance from the initial input node can be defined by the minimum number of links required to reach the node from the initial input node. However, this definition of a layer is arbitrary for illustrative purposes, and the degree of a layer within a neural network can be defined in a different way than described above. For example, a layer of nodes can be defined by its distance from the final output node.
[0073] In one embodiment of the present disclosure, a set of neurons or nodes may be defined as a layer.
[0074] An initial input node may refer to one or more nodes within a neural network into which data is directly input without going through links with other nodes. Alternatively, within a neural network, it may refer to nodes that do not have other input nodes connected by links in the relationship between nodes based on links. Similarly, a final output node may refer to one or more nodes within a neural network that do not have output nodes in their relationship with other nodes. Furthermore, a hidden node may refer to nodes that constitute a neural network other than the initial input node and the final output node.
[0075] A neural network according to one embodiment of the present disclosure may be a neural network in which the number of nodes in an input layer may be the same as the number of nodes in an output layer, and the number of nodes decreases and then increases as it progresses from the input layer to the hidden layer. In addition, a neural network according to another embodiment of the present disclosure may be a neural network in which the number of nodes in an input layer may be less than the number of nodes in an output layer, and the number of nodes decreases as it progresses from the input layer to the hidden layer. In addition, a neural network according to another embodiment of the present disclosure may be a neural network in which the number of nodes in an input layer may be greater than the number of nodes in an output layer, and the number of nodes increases as it progresses from the input layer to the hidden layer. A neural network according to another embodiment of the present disclosure may be a neural network in a combined form of the neural networks described above.
[0076] A deep neural network (DNN) can refer to a neural network that includes multiple hidden layers in addition to input and output layers. Using a DNN, one can identify latent structures in data. This can include images, text, videos, audio, protein sequence structures, gene sequence structures, peptide sequence structures, the latent structure of music (e.g., what objects are in the image, what the content and emotion of the text are, what the content and emotion of the audio are, etc.), and / or the binding affinity between peptides and MHC. A DNN can include a convolutional neural network (CNN), a recurrent neural network (RNN), an autoencoder, a restricted Boltzmann machine (RBM), a deep belief network (DBN), a Q-network, a U-network, a Siamese network, a generative adversarial network (GAN), a transformer, and more. The description of the deep neural network described above is only an example and the present disclosure is not limited thereto.
[0077] The artificial intelligence-based model of the present disclosure can be represented by a network structure of any structure described above, including an input layer, a hidden layer, and an output layer.
[0078] The neural network that can be used in the artificial intelligence-based model of the present disclosure may be trained using at least one of supervised learning, unsupervised learning, semi-supervised learning, transfer learning, active learning, or reinforcement learning. Training of the neural network may be a process of applying knowledge to the neural network to perform a specific action.
[0079] Neural networks can be trained to minimize output errors. This process involves repeatedly inputting training data into the neural network, calculating the neural network output and target error for the training data, and backpropagating the neural network error from the output layer to the input layer to update the weights of each node in the neural network to reduce the error. In supervised learning, training data with the correct answer for each training data is used (i.e., labeled training data). In unsupervised learning, the correct answer may not be labeled for each training data. For example, in supervised learning for data classification, the training data may be data with each category labeled. Labeled training data is input to the neural network, and the error can be calculated by comparing the output (category) of the neural network with the training data labels. Alternatively, in unsupervised learning for data classification, the error can be calculated by comparing the input training data with the neural network output. The calculated error is backpropagated in the neural network in the backward direction (i.e., from the output layer to the input layer), and the connection weights of each node in each layer of the neural network can be updated according to the backpropagation. The amount of change in the connection weights of each node to be updated can be determined by the learning rate. The neural network's calculation of the input data and the backpropagation of the error can constitute a learning cycle (epoch). The learning rate can be applied differently depending on the number of iterations of the neural network's learning cycle. For example, a high learning rate can be used in the early stages of neural network training to quickly achieve a certain level of performance, thereby increasing efficiency. A lower learning rate can be used in the later stages of training to increase accuracy.
[0080] In neural network training, training data can typically be a subset of real-world data (i.e., the data to be processed using the trained neural network). Therefore, there can be a learning cycle where errors on the training data decrease but errors on the real-world data increase. Overfitting is a phenomenon where excessive training on the training data leads to increased errors on the real-world data. For example, a neural network trained on yellow cats may fail to recognize cats when shown non-yellow colors, a type of overfitting. Overfitting can increase errors in machine learning algorithms. Various optimization methods can be used to prevent overfitting. These methods include increasing the training data, regularization, dropout, which disables some nodes in the network during the learning process, and the use of batch normalization layers.
[0081]
[0082] FIG. 3 is a conceptual diagram schematically illustrating an operation of performing federated learning by utilizing encryption of data according to one embodiment of the present disclosure.
[0083] Referring to FIG. 3, a computing device (100) may include a global device (10) and a local device (20) for performing federated learning by utilizing data encryption. The local device (20) may include a plurality of local devices (21, 22, ... 2n). The local device (20) may include, but is not limited to, CCTV, user equipment, etc. According to one embodiment, the global learning or local learning related to the federated learning may be performed in units of sub-modules, or in units of models in which sub-modules are combined.
[0084] According to one embodiment of the present disclosure, the local device (20) may include a local model including the first type of local sub-module and the second type of local sub-module. For example, the first type of local sub-module may perform a first local sub-prediction for a dangerous situation based on the local image. In addition, the second type of local sub-module may perform a second local sub-prediction for a dangerous situation based on data generated by encrypting the local image. In addition, the local model including the first type of local sub-module and the second type of local sub-module may generate final prediction information by synthesizing the sub-predictions of the first type of local sub-module and the second type of local sub-module. In addition, the local device (20) may provide parameter information of the first type of local sub-module and parameter information of the second type of local sub-module to the global device (10). Hereinafter, local learning of the local model included in the local device (20) will be described in more detail with reference to FIG. 4.
[0085] According to one embodiment of the present disclosure, the global device (10) can input local learning data into the first type of global sub-module to perform a first global sub-prediction based on non-encryption. In addition, the global device (10) can encrypt the local learning data and then input it into the second type of global sub-module to perform a second global sub-prediction based on encryption. In addition, the global device (10) can obtain a final prediction based on the first global sub-prediction and the second global sub-prediction. For example, the global device (10) can obtain parameter information of the first type of local sub-module and parameter information of the second type of local sub-module from the local device (20) and perform an update. In addition, the global device (10) can perform local learning on the first type of global sub-module and the second type of global sub-module based on the final prediction to obtain the first type of local sub-module and the second type of local sub-module. This process can be repeated multiple times to improve the global model of the global device (10) and the local model of the local device (20). Meanwhile, for users who have consented to the use of their personal information, accuracy can be improved by using the first global sub-model trained using unencrypted data. Furthermore, for users who have not consented to the use of their personal information, personal information can be protected by using the second global sub-model trained using encrypted data. The global learning of the global model included in the global device (10) will be described in more detail below with reference to FIGS. 5 and 6.
[0086] Meanwhile, data privacy can be protected by utilizing data encryption for federated learning to predict risk situations. For example, each individual or organization (local device) does not transmit its own data (local learning data) to the central server (global device). Instead, it transmits only the parameters (weights) learned from the local model, allowing the central server (global device) to verify the data (local learning data) of each individual or organization (local device). Furthermore, utilizing data encryption for federated learning to predict risk situations can reduce data transfer inefficiencies. For example, since each individual or organization (local device) does not transmit its own data (local learning data) to the central server (global device), the cost and time associated with data transfer can be reduced. Furthermore, utilizing data encryption for federated learning to predict risk situations can improve model performance by leveraging various data sources. Each individual or organization (local device) possesses different data, and through federated learning, the global device can utilize this diverse data to train a model, thereby improving model performance.
[0087]
[0088] FIG. 4 is a schematic conceptual diagram of a local device according to one embodiment of the present disclosure.
[0089] According to one embodiment of the present disclosure, federated learning is a method of machine learning in which multiple entities or organizations collaborate to train a model without sharing distributed data. The local device (20) trains a local model using its own data (local training data), and each local device (21, 22, ... 2n) can transmit parameters (e.g., weights) of the trained local model to the global device (10). In addition, the global device (10) can update the global model using parameters (e.g., weights) received from the local device (20), and the global device (10) can transmit the updated global model to each local device (21, 22, ... 2n). The local device (20) can update the local model based on the global model acquired from the global device (10). For example, the local device (20) may include one or more devices, and for convenience of explanation, the present disclosure will be described below focusing on an embodiment in which federated learning is performed by utilizing encryption of data in one local device (20).
[0090] In one embodiment, the local device (20) may include a closed-circuit television (CCTV), a user device (a smartphone), etc. The local device (20) may include a local model that collects images or videos and performs predictions by utilizing an artificial intelligence model on its own. For example, if the local device (20) is a CCTV, each CCTV may detect objects and predict dangerous situations based on data collected using the local model (local learning data). In addition, if the local device (20) is a user device (a smartphone), each user device may utilize the local model to extract features based on data acquired from the user device (local learning data) and predict dangerous situations. For example, features extracted based on data acquired from the user device may include, but are not limited to, the user's location, activity pattern, number of steps, heart rate, etc.
[0091] According to one embodiment of the present disclosure, a local model included in a local device (20) may include a first type of local sub-module (201) and a second type of local sub-module (202). The local model may be an artificial intelligence model trained to perform risk prediction. The local model may be trained using local learning data (1) and may utilize various algorithms to optimize weights. The initial local model may be initialized with arbitrary weights and may perform learning using local learning data (1). At this time, the local model may perform learning to perform risk prediction using various algorithms. The local device (20) may provide parameter information of the local model for which learning has been completed to the global device (20) and obtain an updated global model of the global device (20). For reference, local learning related to federated learning may be performed on a sub-module basis or on a model basis in which sub-modules are combined. The following describes in more detail the operation of predicting risk situations performed in the sub-modules.
[0092] According to one embodiment of the present disclosure, a first type of local sub-module (201) can perform a first local sub-prediction (201-1) for a dangerous situation based on local learning data (1). For example, the local learning data (1) can include image-type data. In addition, the local learning data can include local images captured by a local camera (e.g., CCTV). The first local sub-module (201) can perform the first local sub-prediction (201-1) for a dangerous situation by utilizing the non-encrypted local learning data (1).
[0093] According to one embodiment of the present disclosure, the second type of local sub-module (202) can perform a second local sub-prediction (202-2) for a dangerous situation based on data generated by encrypting the local image (1-2). The second local sub-module (202) can perform the second local sub-prediction (202-2) for a dangerous situation after encrypting the local learning data (1). For example, the second type of local sub-module (202) can encrypt the local image by converting the local learning data (1) into an encrypted hash value. For example, the second type of local sub-module (202) can encrypt the local image by converting the local image into a byte format and applying a hash function to the local image converted into binary data. In addition, the second type of local sub-module (202) can also encrypt the local learning data by converting a portion of an image included in the local learning data (1) into an encrypted image pattern. For example, the second type of local sub-module (202) can perform object recognition on the local image included in the local learning data by utilizing a local model that recognizes and classifies objects. In addition, the local model can encrypt the image portion using a symmetric key algorithm (AES, DES, etc.) or a hash function (SHA-256, etc.) for a body part related to personal information or a region related to security included in the image. For example, the local model can also encrypt the local image by encrypting the body part related to personal information or the region related to security as a pixel value. However, the operation of encrypting (1-2) the local learning data (local image) is not limited to this, and various embodiments may exist.
[0094] According to one embodiment of the present disclosure, a local model including the first type of local sub-module (201) and the second type of local sub-module (202) can generate final prediction information by synthesizing the sub-predictions (201-1, 202-2) of the first type of local sub-module (201) and the second type of local sub-module (202). For example, the local model can obtain a final prediction for a dangerous situation by utilizing an ensemble technique (Ensemble Learning) for the first local sub-prediction (201-1) and the second local sub-prediction (202-2). The ensemble technique is a methodology for determining an optimal result by combining the results of several individual models. However, the present invention is not limited thereto, and an optimal final prediction can be obtained through various methods.
[0095] According to one embodiment of the present disclosure, the local device (20) provides parameters of an initially learned local model to the global device (10), and the global device (10) performs local learning on the first type of global sub-module (101) and the second type of global sub-module (102) based on the final prediction, thereby updating the local model based on the acquired first type of local sub-module (201) and the second type of local sub-module (202).
[0096]
[0097] Below, the operation of updating the global device (10) based on information obtained from the local device (20) through FIGS. 5 and 6 will be described in more detail.
[0098] Figure 5 is a schematic conceptual diagram of a global device according to one embodiment of the present disclosure. For example, the global device (10) may be a central server. The global device (10) may perform tasks such as initializing, updating, and distributing a global model. Furthermore, the global device (10) may collect parameters acquired from a local device (20) and update the global model based on the collected parameters.
[0099] According to one embodiment of the present disclosure, a global model included in a global device (10) may include a first type of global sub-module (101) and a second type of global sub-module (102). The global model may be an artificial intelligence model trained to perform risk prediction. The global model may update the model using parameters acquired from the local device (20) and perform risk prediction using local learning data (1). The global device (10) may update the global model and transmit the updated model to the local device (20). For reference, global learning related to federated learning may be performed in units of sub-modules or in units of models in which sub-modules are combined.
[0100] According to one embodiment, the first type of global sub-module (101) may be a model capable of performing a first global sub-prediction (101-1) based on non-encryption by utilizing local learning data (1). For example, the local learning data (1) may include image-type data. In addition, the local learning data may include local images captured by a local camera (e.g., CCTV). The first type of global sub-module (101) may perform a first global sub-prediction (101-1) for a dangerous situation by utilizing the non-encrypted local learning data (1).
[0101] In addition, the second type of global sub-module (102) may be a model that performs an encryption-based second global sub-prediction (102-2) by utilizing the encrypted local learning data after encrypting (1-2) the local learning data (1). For example, the second type of global sub-module (102) may encrypt a local image by converting the local learning data (1) into an encrypted hash value. For example, the second type of global sub-module (102) may encrypt a local image by converting a local image into a byte format and applying a hash function to the local image converted into binary data. In addition, the second type of global sub-module (102) may encrypt the local learning data by converting a portion of an image included in the local learning data (1) into an encrypted image pattern. For example, the second type of global sub-module (102) may perform object recognition on the local image included in the local learning data by utilizing a global model that recognizes and classifies objects. Additionally, the global model can encrypt image portions using a symmetric key algorithm (e.g., AES, DES) or a hash function (e.g., SHA-256) to encrypt personal information-related body parts or security-related areas contained within the image. For example, the global model can also encrypt local images by encrypting personal information-related body parts or security-related areas as pixel values. However, the operation of encrypting local training data (local images) (1-2) is not limited to this, and various embodiments may exist.
[0102] In addition, the global device (10) can obtain a final prediction based on the first global sub-prediction (101-1) and the second global sub-prediction (102-2). For example, the global device (10) can obtain a final prediction for a risk situation by utilizing an ensemble technique (Ensemble Learning) for the first global sub-prediction (101-1) and the second global sub-prediction (102-2). The ensemble technique is a methodology that determines an optimal result by combining the results of multiple individual models. However, the present invention is not limited thereto, and an optimal final prediction can be obtained through various methods.
[0103] In addition, the global device (10) can perform local learning on the first type of global sub-module (101) and the second type of global sub-module (102) based on the final prediction, thereby obtaining the first type of local sub-module (201) and the second type of local sub-module (202). The global device (10) can provide the obtained first type of local sub-module (201) and the second type of local sub-module (202) to the local device (20), and can synthesize and update the parameters of the model learned in the local device (20). By repeating this process multiple times, the global model of the global device (10) and the local model of the local device (20) can be improved.
[0104]
[0105] FIG. 6 is a schematic conceptual diagram of an update operation of a global model according to one embodiment of the present disclosure.
[0106] According to one embodiment of the present disclosure, the local device (20) described above through FIG. 4 can provide parameter information of the first type of local sub-module (201) and parameter information of the second type of local sub-module (202) to the global device (10). The global device (10) can update the global model based on the information obtained from the local device (20). For example, the parameter information may include, but is not limited to, weights, gradients, and fine-tuning information. The global device (10) can update and improve the global model by synthesizing the obtained parameter information.
[0107] According to one embodiment of the present disclosure, a local device (10) can share different types of data with a global device (20). First, the local device (20) can identify a data sharing type. For example, the sharing types may include a first type, a second type, and a third type. For example, the first type may be a type that shares all local learning data, but shares personal information data or security data in an encrypted state, and shares the remaining data in an unencrypted state. In addition, the second type may be a type that shares a limited range of local learning data, excluding personal information data or security data, in an unencrypted state. In addition, the third type may be a type that does not share any local learning data. For example, the local learning data may include image-type data. In addition, the personal information data or the security data included in the local learning data may be identified by recognizing a personal information-related body part or a security-related object included in the image based on object recognition. Next, the local device (20) can determine the range of data to be provided to the global device (20) from among the local learning data (1) based on the identified shared type. In addition, the local device (20) can provide data from the determined range from among the local learning data (1). Meanwhile, by providing different types of local learning data (1) from the local device (20) to the global device (20), it is possible to predict a risk situation by utilizing much more diverse and rich information than simply transmitting parameter information. In addition, by providing different types of local learning data (1) from the local device (20) to the global device (20), each data type has unique characteristics, and by utilizing them together, the diversity and accuracy of the model can be improved.In addition, by providing different types of local learning data (1) from a local device (20) to a global device (20), common patterns or features can be extracted from various data types, which can help in obtaining information through effective feature extraction and interaction between data.
[0108] According to one embodiment of the present disclosure, the global device (10) can collect local learning data (1) received in different ranges from each local device (21, 22, ... 2n) according to the sharing type, and obtain a first group of unencrypted data (11) and a second group of data (12) already received in an encrypted state. For example, the global device (10) can update the first type of global sub-module (101) based on parameter information of all the first type of local sub-modules received from all the local devices (21, 22, ... 2n). For example, the global device (10) can update the first type of global sub-module (101) based on parameter information of all the first type of non-encrypted local sub-modules received from all the local devices (21, 22, ... 2n). Additionally, the global device (10) may update the second type global sub-module (102) based on parameter information of all second type local sub-modules received from all local devices (21, 22, ... 2n). For example, the global device (10) may update the second type global sub-module (102) based on parameter information of all second type local sub-modules based on encryption received from all local devices (21, 22, ... 2n).
[0109] According to one embodiment of the present disclosure, the global device (10) can further update the first type global sub-module (101) and the second type global sub-module (102) together by utilizing the first group of data (11). For example, referring to (a) of FIG. 6, the first group of data (11) may include unencrypted local learning data. In addition, the global device (10) can input the first group of data (11) into the first type of global sub-module (101) to perform the first global sub-prediction (101-1) based on non-encryption. In addition, the global device (10) can input the first group of data (11) into the second type of global sub-module (102) to perform the second global sub-prediction (102-2) based on encryption. Additionally, the global device (10) can obtain a final global prediction based on the first global sub-prediction (101-1) and the second global sub-prediction (102-2). Additionally, the global device (10) can additionally update the first type of global sub-module (101) and the second type of global sub-module (102) together based on the final global prediction.
[0110] According to one embodiment of the present disclosure, the global device (10) can further update only the second type global sub-module (102) by utilizing the second group of data (12). For example, referring to (b) of FIG. 6, the second group of data (12) may include local learning data in an encrypted state. In addition, the global device (10) can input the second group of data (12) into the second type of global sub-module (102) to perform an encryption-based second global sub-prediction (102-2). In addition, the global device (10) can further update only the second type of global sub-module (102) based on the encryption-based second global sub-prediction (102-2). Meanwhile, the global device (10) can secure prediction performance by updating only the second type of global sub-module (102) by utilizing local learning data in an encrypted state, even in situations where the encryption method is changed and a model update is required or it is difficult to update the entire model due to network conditions.
[0111]
[0112] Below, we will briefly review the operating flow of the present invention based on the detailed description above.
[0113] FIG. 7 is a flowchart illustrating a method for performing federated learning by utilizing encryption of data according to one embodiment of the present disclosure.
[0114] The method for performing federated learning by utilizing data encryption, as illustrated in FIG. 7, can be performed by the computing device (100) described above. Therefore, even if omitted below, the description of the computing device (100) can be equally applied to the description of the method for performing federated learning by utilizing data encryption.
[0115] Referring to FIG. 7, a method for performing federated learning by utilizing encryption of data may include a step of receiving a first type of global sub-module and a second type of global sub-module (S110), a step of inputting local learning data into the first type of global sub-module to perform a first global sub-prediction based on non-encryption (S120), a step of encrypting the local learning data and then inputting it into the second type of global sub-module to perform a second global sub-prediction based on encryption (S130), a step of obtaining a final prediction based on the first global sub-prediction and the second global sub-prediction (S140), and a step of performing local learning on the first type of global sub-module and the second type of global sub-module based on the final prediction to obtain a first type of local sub-module and a second type of local sub-module (S150).
[0116] Step S110 is a step of receiving a first type global sub-module and a second type global sub-module.
[0117] Step S120 is a step of inputting local learning data into the first type of global sub-module to perform a first global sub-prediction based on non-encryption. For example, the local learning data includes image-type data, and the personal information data or the security data included in the local learning data can be identified by recognizing a personal information-related body part or a security-related object included in the image based on object recognition.
[0118] Step S130 is a step of encrypting the local learning data and then inputting it into the second type of global sub-module to perform a second global sub-prediction based on encryption. For example, the operation of encrypting the local learning data may include at least one of: converting the local learning data into an encrypted hash value; or converting a portion of an image included in the local learning data into an encrypted image pattern.
[0119] Step S140 is a step of obtaining a final prediction based on the first global sub-prediction and the second global sub-prediction.
[0120] Step S150 is a step of performing local learning on the first type of global sub-module and the second type of global sub-module based on the final prediction, thereby obtaining the first type of local sub-module and the second type of local sub-module.
[0121] According to one embodiment, the method may further include the step of providing parameter information of the first type of local sub-module and parameter information of the second type of local sub-module to the global device.
[0122] According to one embodiment, the method may further include the steps of identifying a data sharing type of a local device, determining a range of data to be provided to the global device among the local learning data based on the identified sharing type, and providing data of the determined range among the local learning data. Here, the sharing type may include a first type in which all local learning data is shared, but personal information data or security data is shared in an encrypted state and the remaining data is shared in an unencrypted state, a second type in which a limited range of local learning data excluding personal information data or security data is shared in an unencrypted state, and a third type in which no local learning data is shared.
[0123]
[0124] The steps described in the above description may be further divided into additional steps or combined into fewer steps, depending on the implementation of the present disclosure. Furthermore, some steps may be omitted as needed, and the order of the steps may be changed.
[0125]
[0126] Meanwhile, a computer-readable medium storing a data structure according to an embodiment of the present disclosure is disclosed.
[0127] A data structure can refer to the organization, management, and storage of data to enable efficient access and modification. A data structure can refer to the organization of data to solve a specific problem (e.g., data retrieval, data storage, or data modification in the shortest possible time). A data structure can also be defined as the physical or logical relationships between data elements designed to support specific data processing functions. Logical relationships between data elements can include connections between user-defined data elements. Physical relationships between data elements can include actual relationships between data elements physically stored on a computer-readable storage medium (e.g., persistent storage). Specifically, a data structure can include a collection of data, relationships between data, and functions or commands applicable to the data. An effectively designed data structure allows a computing device to perform operations while minimizing the use of its resources. Specifically, a computing device can improve the efficiency of operations, reading, inserting, deleting, comparing, exchanging, and searching through an effectively designed data structure.
[0128] Data structures can be categorized as linear or nonlinear, depending on their form. A linear data structure can be a structure in which only one data item is linked to the next. Linear data structures can include lists, stacks, queues, and deques. A list can refer to a series of data sets with an internal order. Lists can also include linked lists. A linked list is a data structure in which data is linked in a single line, each item having a pointer. In a linked list, a pointer can contain information about the next or previous item. Linked lists can be expressed as singly linked lists, doubly linked lists, or circular linked lists, depending on their form. A stack can be a data listing structure with limited data access. A stack can be a linear data structure in which data operations (e.g., insertion or deletion) can only be performed at one end of the data structure. Data stored in a stack can be a Last-in-First-out (LIFO) data structure. A queue is a data structure with limited access to data. Unlike a stack, it can be a first-in, first-out (FIFO) data structure, with later data being retrieved later. A deck can be a data structure that can process data at both ends.
[0129] A nonlinear data structure can be a structure in which multiple pieces of data are connected behind a single piece of data. Nonlinear data structures can include graph data structures. A graph data structure can be defined by vertices and edges, and an edge can include a line connecting two different vertices. Graph data structures can include tree data structures. A tree data structure can be a data structure in which there is only one path connecting two different vertices among multiple vertices included in the tree. In other words, it can be a data structure that does not form a loop in a graph data structure.
[0130] Throughout this specification, the terms computational model, neural network, network function, and neural network may be used interchangeably. Hereinafter, they are collectively referred to as neural networks. The data structure may include a neural network. And the data structure including the neural network may be stored on a computer-readable medium. The data structure including the neural network may also include preprocessed data for processing by the neural network, data input to the neural network, weights of the neural network, hyperparameters of the neural network, data obtained from the neural network, activation functions associated with each node or layer of the neural network, loss functions for learning the neural network, etc. The data structure including the neural network may include any of the components disclosed above. That is, the data structure including the neural network may be configured to include all or any combination of preprocessed data for processing by the neural network, data input to the neural network, weights of the neural network, hyperparameters of the neural network, data obtained from the neural network, activation functions associated with each node or layer of the neural network, loss functions for learning the neural network, etc. In addition to the aforementioned configurations, a data structure including a neural network may include any other information that determines the characteristics of the neural network. Furthermore, the data structure may include any form of data used or generated in the computational process of the neural network, and is not limited to the aforementioned. The computer-readable medium may include a computer-readable recording medium and / or a computer-readable transmission medium. A neural network may be composed of a set of interconnected computational units, which may generally be referred to as nodes. These nodes may also be referred to as neurons. A neural network is composed of at least one node.
[0131] The data structure may include data input to a neural network. The data structure including the data input to the neural network may be stored on a computer-readable medium. The data input to the neural network may include training data input during the neural network training process and / or input data input to the neural network after training has been completed. The data input to the neural network may include data that has undergone preprocessing and / or data that is the target of preprocessing. Preprocessing may include a data processing process for inputting data to the neural network. Accordingly, the data structure may include data that is the target of preprocessing and data generated by the preprocessing. The above-described data structure is merely an example, and the present disclosure is not limited thereto.
[0132] The data structure may include weights of the neural network. (In this specification, the terms "weight" and "parameter" may be used interchangeably.) The data structure including the weights of the neural network may be stored in a computer-readable medium. The neural network may include a plurality of weights. The weights may be variable and may be varied by a user or an algorithm so that the neural network can perform a desired function. For example, when one or more input nodes are interconnected to one output node by respective links, the output node may determine a data value output from the output node based on values input to the input nodes connected to the output node and weights set for links corresponding to each input node. The above-described data structure is merely an example, and the present disclosure is not limited thereto.
[0133] By way of example and not limitation, the weights may include weights that vary during the neural network training process and / or weights that have completed neural network training. The weights that vary during the neural network training process may include weights at the start of the training cycle and / or weights that vary during the training cycle. The weights that have completed neural network training may include weights that have completed the training cycle. Accordingly, a data structure including the weights of a neural network may include a data structure including weights that vary during the neural network training process and / or weights that have completed neural network training. Therefore, the above-described weights and / or combinations of each weight are included in the data structure including the weights of a neural network. The above-described data structures are merely examples and the present disclosure is not limited thereto.
[0134] A data structure including neural network weights can be stored in a computer-readable storage medium (e.g., memory, hard disk) after going through a serialization process. Serialization can be a process of converting a data structure into a form that can be stored on the same or different computing devices and later reconstructed and used. A computing device can serialize the data structure to transmit and receive data over a network. The serialized data structure including neural network weights can be reconstructed on the same or different computing devices through deserialization. The data structure including neural network weights is not limited to serialization. Furthermore, the data structure including neural network weights can include a data structure that increases computational efficiency while minimizing the use of computing device resources (e.g., a B-Tree, a Trie, an m-way search tree, an AVL tree, a Red-Black Tree in nonlinear data structures). The foregoing is merely an example, and the present disclosure is not limited thereto.
[0135] The data structure may include hyperparameters of a neural network. Furthermore, the data structure including the hyperparameters of the neural network may be stored on a computer-readable medium. The hyperparameters may be variables that can be varied by the user. The hyperparameters may include, for example, a learning rate, a cost function, the number of learning cycle repetitions, weight initialization (e.g., setting a range of weight values to be subject to weight initialization), and the number of hidden units (e.g., the number of hidden layers, the number of nodes in the hidden layer). The above-described data structure is merely an example, and the present disclosure is not limited thereto.
[0136]
[0137] FIG. 8 is a simplified, general schematic diagram of an exemplary computing environment in which embodiments of the present disclosure may be implemented.
[0138] Although the present disclosure has been described above as being generally implemented by a computing device, those skilled in the art will appreciate that the present disclosure may also be implemented in combination with computer-executable instructions and / or other program modules that may be executed on one or more computers and / or as a combination of hardware and software.
[0139] Generally, program modules include routines, programs, components, data structures, and the like that perform specific tasks or implement specific abstract data types. Furthermore, those skilled in the art will appreciate that the methods of the present disclosure can be implemented with other computer system configurations, including single-processor or multiprocessor computer systems, minicomputers, mainframe computers, as well as personal computers, handheld computing devices, microprocessor-based or programmable consumer electronics, and the like, each of which may be operatively connected to one or more associated devices.
[0140] The described embodiments of the present disclosure can also be practiced in distributed computing environments, where certain tasks are performed by remote processing devices that are linked through a communications network. In a distributed computing environment, program modules may be located in both local and remote memory storage devices.
[0141] Computers typically include a variety of computer-readable media. Computer-readable media can be any media that can be accessed by a computer, and includes both volatile and nonvolatile media, transitory and non-transitory media, removable and non-removable media. By way of example, and not limitation, computer-readable media can include computer-readable storage media and computer-readable transmission media. Computer-readable storage media includes both volatile and nonvolatile media, transitory and non-transitory media, removable and non-removable media implemented in any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. Computer-readable storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital video disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be accessed by a computer and used to store the desired information.
[0142] Computer-readable transmission media typically includes any information delivery media that embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal, such as a carrier wave or other transport mechanism. The term modulated data signal means a signal that has one or more of its characteristics set or changed so as to encode information in the signal. By way of example, and not limitation, computer-readable transmission media includes wired media, such as a wired network or direct-wired connection, and wireless media, such as acoustic, RF, infrared, or other wireless media. Combinations of any of the above are also intended to be included within the scope of computer-readable transmission media.
[0143] An exemplary environment for implementing various aspects of the present disclosure is illustrated, including a computer (1102), which includes a processing unit (1104), system memory (1106), and a system bus (1108). The system bus (1108) connects system components, including but not limited to the system memory (1106), to the processing unit (1104). The processing unit (1104) may be any of a variety of commercially available processors. Dual processors and other multiprocessor architectures may also be utilized as the processing unit (1104).
[0144] The system bus (1108) may be any of several types of bus structures that may be additionally interconnected to a memory bus, a peripheral bus, and a local bus using any of a variety of commercial bus architectures. The system memory (1106) includes read-only memory (ROM) (1110) and random access memory (RAM) (1112). A basic input / output system (BIOS) is stored in non-volatile memory (1110), such as ROM, EPROM, or EEPROM, and includes basic routines that help transfer information between components within the computer (1102), such as during start-up. The RAM (1112) may also include high-speed RAM, such as static RAM, for caching data.
[0145] The computer (1102) also includes an internal hard disk drive (HDD) (1114) (e.g., EIDE, SATA) - which may also be configured for external use within a suitable chassis (not shown), a magnetic floppy disk drive (FDD) (1116) (e.g., for reading from or writing to a removable diskette (1118)), and an optical disk drive (1120) (e.g., for reading from or writing to a CD-ROM disk (1122) or other high-capacity optical media such as a DVD). The hard disk drive (1114), the magnetic disk drive (1116), and the optical disk drive (1120) may be connected to the system bus (1108) by a hard disk drive interface (1124), a magnetic disk drive interface (1126), and an optical drive interface (1128), respectively. The interface (1124) for implementing an external drive includes at least one or both of Universal Serial Bus (USB) and IEEE 1394 interface technologies.
[0146] These drives and their associated computer-readable media provide non-volatile storage of data, data structures, computer-executable instructions, and the like. In the case of the computer (1102), the drives and media correspond to storing any data in a suitable digital format. While the description of computer-readable media above refers to HDDs, removable magnetic disks, and removable optical media such as CDs or DVDs, those of ordinary skill in the art will appreciate that other types of computer-readable media, such as zip drives, magnetic cassettes, flash memory cards, cartridges, and the like, may also be used in the exemplary operating environment, and that any such media may contain computer-executable instructions for performing the methods of the present disclosure.
[0147] A number of program modules, including an operating system (1130), one or more application programs (1132), other program modules (1134), and program data (1136), may be stored in the drive and RAM (1112). All or portions of the operating system, applications, modules, and / or data may also be cached in RAM (1112). It will be appreciated that the present disclosure may be implemented in various commercially available operating systems or combinations of operating systems.
[0148] A user may enter commands and information into the computer (1102) via one or more wired / wireless input devices, such as a keyboard (1138) and a pointing device such as a mouse (1140). Other input devices (not shown) may include a microphone, an IR remote control, a joystick, a game pad, a stylus pen, a touch screen, and the like. These and other input devices are often connected to the processing unit (1104) via an input device interface (1142) that is connected to the system bus (1108), but may be connected by other interfaces such as a parallel port, an IEEE 1394 serial port, a game port, a USB port, an IR interface, and the like.
[0149] A monitor (1144) or other type of display device is also connected to the system bus (1108) via an interface, such as a video adapter (1146). In addition to the monitor (1144), the computer typically includes other peripheral output devices (not shown), such as speakers, a printer, and so on.
[0150] The computer (1102) may operate in a networked environment using logical connections to one or more remote computers, such as remote computer(s) (1148), via wired and / or wireless communications. The remote computer(s) (1148) may be a workstation, a computing device computer, a router, a personal computer, a portable computer, a microprocessor-based entertainment device, a peer device, or other conventional network node, and generally include many or all of the components described for the computer (1102), although for simplicity, only the memory storage device (1150) is shown. The logical connections shown include wired / wireless connections to a local area network (LAN) (1152) and / or a larger network, such as a wide area network (WAN) (1154). Such LAN and WAN networking environments are common in offices and companies and facilitate enterprise-wide computer networks, such as intranets, all of which may be connected to a worldwide computer network, such as the Internet.
[0151] When used in a LAN networking environment, the computer (1102) is connected to a local network (1152) via a wired and / or wireless communication network interface or adapter (1156). The adapter (1156) may facilitate wired or wireless communications to the LAN (1152), which may also include a wireless access point installed therein for communicating with the wireless adapter (1156). When used in a WAN networking environment, the computer (1102) may include a modem (1158), be connected to a communications computing device on the WAN (1154), or have other means of establishing communications over the WAN (1154), such as via the Internet. The modem (1158), which may be internal or external and wired or wireless, is connected to the system bus (1108) via a serial port interface (1142). In a networked environment, program modules or portions thereof described for the computer (1102) may be stored in a remote memory / storage device (1150). It will be appreciated that the network connections depicted are exemplary and other means of establishing a communications link between the computers may be used.
[0152] The computer (1102) operates to communicate with any wireless device or object that is arranged and operates via wireless communication, such as a printer, a scanner, a desktop and / or portable computer, a portable data assistant (PDA), a communication satellite, any equipment or location associated with a radio-detectable tag, and a telephone. This includes at least Wi-Fi and Bluetooth wireless technologies. Accordingly, the communication may be a predefined structure as in a conventional network, or may simply be an ad hoc communication between at least two devices.
[0153] Wi-Fi (Wireless Fidelity) enables connections to the Internet and other devices without wires. Wi-Fi is a wireless technology that allows devices, such as computers, to send and receive data anywhere within the coverage area of a base station, both indoors and outdoors, similar to cell phones. Wi-Fi networks use wireless technologies called IEEE 802.11 (a, b, g, etc.) to provide secure, reliable, and high-speed wireless connections. Wi-Fi can be used to connect computers to each other, to the Internet, and to wired networks (using IEEE 802.3 or Ethernet). Wi-Fi networks can operate in the unlicensed 2.4 and 5 GHz radio bands, at data rates of, for example, 11 Mbps (802.11a) or 54 Mbps (802.11b), or in products that include both bands (dual-band).
[0154] Those skilled in the art will appreciate that information and signals may be represented using any of a variety of different technologies and techniques. For example, the data, instructions, commands, information, signals, bits, symbols, and chips referenced in the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.
[0155] Those skilled in the art will appreciate that the various illustrative logical blocks, modules, processors, means, circuits, and algorithm steps described in connection with the embodiments disclosed herein may be implemented as electronic hardware, various forms of programs or design code (referred to herein, for convenience, as software), or a combination of both. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Those skilled in the art may implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present disclosure.
[0156] The various embodiments presented herein can be implemented as a method, apparatus, or article of manufacture using standard programming and / or engineering techniques. The term article of manufacture includes a computer program, carrier, or media accessible from any computer-readable storage device. For example, computer-readable storage media include, but are not limited to, magnetic storage devices (e.g., hard disks, floppy disks, magnetic strips, etc.), optical disks (e.g., CDs, DVDs, etc.), smart cards, and flash memory devices (e.g., EEPROMs, cards, sticks, key drives, etc.). Furthermore, various storage media presented herein include one or more devices and / or other machine-readable media for storing information.
[0157] It should be understood that the specific order or hierarchy of steps in the presented processes is merely an example of exemplary approaches. It should be understood that the specific order or hierarchy of steps in the processes may be rearranged within the scope of the present disclosure based on design priorities. The appended method claims provide elements of various steps in a sample order, but are not intended to be limited to the specific order or hierarchy presented.
[0158] The description of the disclosed embodiments is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments without departing from the scope of the present disclosure. Therefore, the present disclosure is not intended to be limited to the embodiments disclosed herein, but is to be construed in the broadest scope consistent with the principles and novel features disclosed herein.
[0159] As described above, the relevant contents have been described in the best form for carrying out the invention.
Claims
1. A method for performing federated learning by utilizing data encryption performed by a computing device. A step of receiving a first type global sub-module and a second type global sub-module; A step of inputting local learning data into the first type of global sub-module to perform a first global sub-prediction based on non-encryption; A step of encrypting the above local learning data and then inputting it into the second type of global sub module to perform a second global sub prediction based on encryption; A step of obtaining a final prediction based on the first global sub-prediction and the second global sub-prediction; and A step of performing local learning on the first type global sub-module and the second type global sub-module based on the final prediction to obtain the first type local sub-module and the second type local sub-module. Including, method.
2. In paragraph 1, A step of providing parameter information of the first type of local sub-module and parameter information of the second type of local sub-module to a global device. Including more, method.
3. In paragraph 2, The above method, Step for identifying the data sharing type of the local device; A step of determining the range of data to be provided to the global device among the local learning data based on the identified shared type; and A step of providing data of a determined range among the above local learning data. Including more, The above sharing type is, The first type shares all local learning data, but personal data or security data is shared in an encrypted state, and the remaining data is shared in an unencrypted state; A second type that shares a limited range of local learning data unencrypted, excluding personal data or security data; and A third type that does not share any local learning data Including, method.
4. In paragraph 3, The above local learning data includes image type data, The personal information data or the security data included in the local learning data is identified by recognizing a personal information-related body part or a security-related object included in an image based on object recognition. method.
5. In paragraph 1, The global learning or local learning related to the above federated learning is performed in units of sub-modules or in units of models in which sub-modules are combined. method.
6. In paragraph 5, The above global learning is, An operation of updating a global sub-module of the first type based on parameter information of all first type local sub-modules received from all local devices; and An operation of updating the second type global sub-module based on parameter information of all second type local sub-modules received from all of the above local devices; Including, method.
7. In paragraph 6, The above global learning is, An operation of collecting local learning data received from different ranges from each local device according to a sharing type, thereby obtaining a first group of unencrypted data and a second group of data already received in an encrypted state; An operation of additionally updating the first type global sub-module and the second type global sub-module together by utilizing the data of the first group; and An operation of additionally updating only the global sub-module of the second type by utilizing the data of the second group. Including, method.
8. In paragraph 7, An operation of additionally updating the first type global sub-module and the second type global sub-module together by utilizing the data of the first group is as follows: An operation of inputting data of the first group into the first type global sub-module to perform the first global sub-prediction based on non-encryption; An operation of inputting data of the first group into the second type of global sub-module to perform the second global sub-prediction based on encryption; An operation of obtaining a final global prediction based on the first global sub-prediction and the second global sub-prediction; and An operation of additionally updating the first type global sub-module and the second type global sub-module together based on the final global prediction. Including, method.
9. In paragraph 7, An operation of further updating only the second type of global sub-module by utilizing the data of the second group is as follows: An operation of inputting data of the second group into the second type of global sub module to perform a second global sub prediction based on encryption; and An operation of additionally updating only the second type of global sub-module based on the second global sub-prediction based on the above encryption. Including, method.
10. In paragraph 1, The operation of encrypting the above local learning data is as follows: An operation of converting the above local learning data into an encrypted hash value; or An operation of converting a portion of an image included in the above local learning data into an encrypted image pattern; Containing at least one of: method.
11. In paragraph 1, The above local learning data includes local images captured by a local camera, The first type of local sub-module performs a first local sub-prediction for a dangerous situation based on the local image, The second type of local sub module performs a second local sub prediction for a dangerous situation based on data generated by encrypting the local image, A local model including the first type of local sub-module and the second type of local sub-module generates final prediction information by synthesizing the sub-predictions of the first type of local sub-module and the second type of local sub-module. method.
12. A computer program stored in a computer-readable storage medium, wherein, when the computer program is executed on one or more processors, the computer program causes the one or more processors to perform the following operations for performing federated learning by utilizing encryption of data, the operations being: An operation for receiving a first type global sub-module and a second type global sub-module; An operation of inputting local learning data into the first type of global sub-module to perform a first global sub-prediction based on non-encryption; An operation of encrypting the above local learning data and then inputting it into the second type of global sub-module to perform a second global sub-prediction based on encryption; An operation of obtaining a final prediction based on the first global sub-prediction and the second global sub-prediction; and An operation of performing local learning on the first type global sub-module and the second type global sub-module based on the final prediction to obtain the first type local sub-module and the second type local sub-module. Including, A computer program stored on a computer-readable storage medium.
13. As a computing device, at least one processor; and Memory Including, At least one processor of the above, Receiving a first type global sub-module and a second type global sub-module; By inputting local learning data into the first type of global sub-module, a first global sub-prediction based on non-encryption is performed; After encrypting the above local learning data, it is input into the second type of global sub-module to perform second global sub-prediction based on encryption; Obtaining a final prediction based on the first global sub-prediction and the second global sub-prediction; and Based on the final prediction, local learning is performed on the first type of global sub-module and the second type of global sub-module to obtain the first type of local sub-module and the second type of local sub-module. device.
Citation Information
Patent Citations
Encryption model training method and device, image encryption method and device and encrypted face image recognition method and device
CN113592696A
Deep neural network model protection method and device, electronic equipment and medium
CN114676396A
Neural network update method, terminal device, computing device and program
JP7388445B2
Method of communication for wireless universal serialbus
KR1020070053417A
Light source device for sign using optical fiber
KR1020240145602A