作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程

• •    

面向联邦原型学习的格陷门条件身份追溯机制

  • 发布日期:2026-07-30

Lattice Trapdoor-based Controllable Identity Traceability Mechanism for Federated Prototype Learning

  • Published:2026-07-30

摘要: 近年来,为了克服传统联邦学习在面临设备系统异构和通信带宽受限时的瓶颈,联邦原型学习(FPL)通过聚合低维的特征原型而非庞大的高维模型参数,极大降低了通信开销。FPL的开放式分布式架构使其在实际部署中面临着安全威胁:缺乏严格准入机制的网络极易遭受外部攻击者的身份伪造;同时内部恶意节点可通过上传恶意构造的虚假原型实施投毒攻击,严重破坏全局特征空间。针对FPL在开放网络环境下易遭身份伪造,且现有统计学防御机制在非独立同分布场景下难以区分恶意扰动与良性异构特征导致诚实长尾节点被误剔除的问题,提出了一种面向FPL的格陷门可控身份追溯机制(FedLHT)。该机制将安全防线从概率性统计检测转化为确定性数学计算,构建了事前匿名、事中验证与事后追责的完整轻量级防御架构。在初始化阶段,基于格密码构造无证书签名体系,利用原像采样算法实现身份标识与格上短向量私钥的密码学绑定,实现了验证权与追溯权的物理解耦;在匿名准入阶段,通过注入格上误差生成隐匿真实身份的可追溯标签,并结合拒绝采样技术输出非交互式签名,在保障信息论匿名性的同时消除签名对私钥的统计依赖。在聚合验证阶段,将非线性群运算全面降级为格上矩阵-向量的线性乘加计算,实现了轻量级的批处理准入;在靶向追溯阶段,监管实体利用独占的格陷门主基及其短正交化性质求解有界距离解码问题,从异常误差项中靶向恢复恶意节点的真实身份,进而驱动全局模型精准剥离恶意历史贡献以实现自愈。该机制的安全性严格规约至平均情况下的带误差学习(LWE)问题与小整数解(SIS)问题,从根本上赋予了系统抵抗未来大规模量子计算机攻击的后量子安全属性。在模型自愈层面充分利用了特征原型向量的线性叠加同态特性。锁定恶意身份后服务器仅需在全局原型池中执行低开销的向量减法,即可在常数级时间内抹除恶意节点的历史贡献,实现了训练过程的无缝衔接。与隐私保护联邦学习投毒防御机制(ShieldFL)及基于信任引导的鲁棒联邦学习机制(FLTrust)等方案相比,全局模型准确率在CIFAR-10数据集上维持在83.65%以上;在数据异构程度系数为1.0的严苛Non-IID环境下,对诚实长尾数据的保留率高达98.75%,实现了零误判响应。此外,在40个并发客户端规模下,客户端局部耗时仅1.22毫秒,服务器端身份验证总开销低至6.42毫秒,有效克服了传统双线性配对群签名方案的计算瓶颈,适用于资源受限的移动物联网场景。

Abstract: Federated Prototype Learning (FPL) significantly reduces communication overhead but faces critical security risks in open networks, including identity forgery and poisoning attacks. Existing statistical defenses struggle to distinguish malicious perturbations from benign heterogeneous features under non-independent and identically distributed (Non-IID) settings, often wrongfully eliminating honest long-tail clients. To address these vulnerabilities, this paper proposes a lattice trapdoor-based controllable identity tracing scheme for FPL, termed Federated Lattice Hidden Trapdoor (FedLHT). Shifting from probabilistic statistical detection to deterministic mathematical computation, FedLHT establishes a lightweight framework for pre-training anonymity, real-time authentication, and post-attack accountability. It constructs a certificateless signature system via lattice cryptography, utilizing preimage sampling to bind client identities with private keys. Traceable tags and rejection sampling guarantee information-theoretic anonymity. During aggregation, nonlinear group operations are linearized over lattices for lightweight batch verification. For targeted tracing, regulators utilize the lattice trapdoor master basis to solve the bounded distance decoding problem, accurately recovering malicious identities from abnormal noise. FedLHT's security is rigorously reduced to average-case Learning With Errors (LWE) and Short Integer Solution (SIS) problems, ensuring post-quantum security. Furthermore, utilizing the linear additive homomorphism of prototypes, the server seamlessly erases malicious historical contributions via lightweight vector subtraction for rapid model self-recovery. Compared with state-of-the-art defenses, such as ShieldFL (Mitigating Poisoning Attacks in Privacy-Preserving Federated Learning) and FLTrust (Byzantine-robust Federated Learning via Trust Bootstrapping), the proposed mechanism maintains a global model accuracy above 84.65% on the CIFAR-10 dataset. Furthermore, in a severe Non-IID setting with a heterogeneity coefficient of 1.0, it achieves a 98.75% retention rate for honest long-tail data, realizing zero-misjudgment response. For 40 concurrent clients, local computing and server-side authentication overheads are merely 1.22 ms and 6.42 ms, effectively overcoming computational bottlenecks of traditional pairing-based schemes for resource-constrained Internet of Things (IoT) scenarios.