The invention discloses a federal learning model leakage
traceability method based on model structure
confusion, and the method comprises an initialization step: S1, a
server copies an initial model for subsequent
structure comparison, and generates a unique binary user identity (UID) for each
client; a UID embedding step S2, before each round of training is started, independently executing structure
confusion for each
client model by the
server, embedding a
client UID into a model structure, and then issuing the model to the client; a model structure
recovery step S3, when one round of training is finished, the
server executes structure
recovery on each client model, and then executes
model aggregation; and S4, when a model ownership owner doubts that a model with an
unknown source comes from leakage in a training process, the structure of the model is detected, and a suspicious UID is extracted through
structure comparison with an initial model so as to find a leakage person. The method has the characteristics of no negative influence on the performance of the original model, low embedding
time overhead, high robustness and the like.