The invention discloses a
federated learning privacy protection and
attack defense method, which relates to the technical field of
artificial intelligence and
information privacy security crossing, and comprises the following steps: a
client performs training based on local data and generates update, dynamically allocates privacy budget by evaluating the contribution degree of each
network layer to model performance, and finally performs
privacy protection and
attack defense. The method comprises the following steps: reducing
noise at a key layer to retain the utility of a model, enhancing disturbance at a non-key layer to improve
privacy protection, uploading an update after
noise addition to a
server, predicting an update to be submitted by a
client based on a historical training process by the
server, calculating a deviation value between an actual update and a predicted update, and constructing a behavior evaluation value by combining multiple rounds of deviations. The method comprises the following steps: identifying and isolating abnormal clients by utilizing clustering analysis, dividing normal clients into fixed groups for intra-group aggregation, periodically executing global aggregation to update a model, starting an intra-group
recovery mechanism when
abnormality is detected, and performing local retraining and reconstruction aggregation output by the normal clients in the same group, thereby realizing safe and efficient
federated learning.