The invention relates to the technical field of
federated learning privacy defense, in particular to a privacy enhancement method for
federated learning classification task gradient attacks, which comprises the following steps of: S1, initializing
global model parameters, and performing
batch processing division on participant training samples participating in
federated learning; s2, a local micro-batch gradient is calculated, and the local micro-batch gradient is calculated; step S3, according to the micro-batch gradient calculated in the step S2, threshold limit
cutting is carried out, and a gradient parameter is obtained; step S4, micro-batches are used as a sample unit for adding
noise, gradient parameters of participants with strong privacy requirements are frozen, and
Gaussian noise is added into the clipped gradient parameters; s5, gradient parameter loss is calculated; and S6, aggregating the gradient parameter loss of all participants in the step S5 through an aggregation
algorithm to update
global model parameters in the training, and calculating the joint
differential privacy model accuracy and loss budget. According to the method, the
privacy protection granularity and the model performance are well balanced.