Gradient Noise Constraint for Secure Joint Training

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In joint training models for machine learning, there is a risk of data leakage from active participants to passive participants during gradient transfer, compromising data security while affecting the efficiency and accuracy of the training process.

Innovation Solution

The method involves acquiring gradient correlation information for reference samples, determining a constraint condition for data noise based on positive and negative examples, correcting initial gradient transfer values to ensure consistency across different sample labels, and sending the corrected gradient transfer information to passive participants, thereby protecting data security and maintaining training efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If gradient transfer information is sent from active participant to passive participant for joint training, then training effectiveness is improved, but data security deteriorates due to potential data leakage

Engineering Contradiction:
Improvetraining effectivenessVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces noise as an intermediary element that is added to the gradient transfer information. This noise acts as a mediator that obscures the direct relationship between the original data and the gradient information, allowing the passive participant to receive training signals without being able to infer sensitive information about the active participant's data. The noise serves as a protective layer that enables information flow while preventing data leakage.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent modifies the parameters of the gradient transfer information by adding controlled noise with specific statistical properties. The noise is designed with particular variance and distribution characteristics that allow it to mask sensitive information while preserving the essential training signal. By changing the parameters of the gradient information through noise addition, the system achieves both training effectiveness and data protection.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If noise is added to gradient transfer information to protect data security, then data leakage is prevented, but training efficiency deteriorates due to noise interference

Engineering Contradiction:
Improvedata securityVSAvoidtraining efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent carefully controls the parameters of the added noise, specifically its variance and distribution, to optimize the balance between protection and efficiency. The noise parameters are tuned so that they provide sufficient masking for data security while minimizing the distortion of the training signal. This parameter optimization ensures that the noise provides protection without excessively degrading training efficiency.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system employs feedback mechanisms to monitor the impact of noise on training convergence and performance. By observing how the noise affects the training process, the system can adjust noise parameters or apply correction techniques to maintain training efficiency. The feedback loop allows the system to adapt the noise characteristics to achieve both security and efficiency goals.

Inventive Principle:
Principle #23Feedback

3Reliability

If noise is added to gradient transfer information, then data security is improved, but convergence stability deteriorates due to noise-induced fluctuations

Engineering Contradiction:
Improvedata securityVSAvoidconvergence stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent controls the parameters of the added noise, particularly its variance and distribution characteristics, to ensure that the noise provides security protection without causing excessive fluctuations that would destabilize convergence. The noise parameters are carefully selected to balance the masking effect with the stability requirement, preventing divergence while maintaining data protection.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system applies noise with predetermined characteristics that are designed to cushion against potential convergence issues. By selecting noise parameters in advance that are known to maintain stability, the system prevents convergence problems before they occur. The pre-designed noise characteristics act as a cushion that protects both data security and convergence stability.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS20240005210A1Data protection method, apparatus, medium and device
Publication Date: 2024.01.04 LEMON INC(GB)
  • US20240005210A1 patent drawing
  • US20240005210A1 patent drawing

AI summary

The present disclosure relates to a data protection method, an apparatus, a medium and a device. The method includes: acquiring gradient association information respectively corresponding to reference samples of a target batch of an active party of a joint training model; according to the proportion occupied respectively by reference samples of positive examples and reference samples of negative examples in all reference samples of the target batch, determining a constraint condition of the data noise to be added; determining information of said data noise according to the gradient association information and the constraint condition corresponding to the reference samples; correcting, according to the information of said data noise, an initial gradient transmission value corresponding to each reference sample, so as to obtain target gradient transmission information; and sending the target gradient transmission information to a passive party of the joint training model.