High-security data collection method and medium

By adopting the localized federated learning framework for edge-end desensitization and anonymization process during data collection, the data privacy leakage problem is solved, and a high-security data collection method is realized to ensure the protection of user privacy in data transmission and storage.

CN120358059APending Publication Date: 2025-07-22INSPUR FINANCIAL INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510536712.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

The prior art has the risk of privacy leakage during data collection, especially in the traditional centralized data processing mode, where user-sensitive information is easily illegally obtained, and the existing federated learning methods still have room for improvement in edge-end data desensitization encryption and model parameter upload.

Method used

The localized federated learning framework is used to desensitize and encrypt user input data at the edge, and only the encrypted model parameters are uploaded to the cloud for training. User privacy is protected through anonymization processing and encryption encoding, ensuring that the cloud cannot trace the original data.

Benefits of technology

It effectively reduces the risk of user sensitive information leakage, protects user privacy, improves the security and reliability of the data collection process, and ensures the value of data utilization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358059A_ABST
    Figure CN120358059A_ABST
Patent Text Reader

Abstract

The invention discloses a high-security data collection method and a medium, and the method comprises the following steps: carrying out the edge-end desensitization encryption of data inputted by a user through a localized federated learning framework in a data collection process, uploading a model parameter obtained through the processing after encryption to a cloud end for model training, and carrying out the data collection. Original data is not uploaded; according to the method, edge-end desensitization encryption can be performed on data input by a user in a data collection process by adopting a localized federated learning framework, and only model parameters instead of original data are uploaded to the cloud for training, so that the risk of sensitive information leakage of the user is greatly reduced; the data is desensitized and encrypted at the local end, so that the privacy of the user is protected from the source; and the model training can be completed without uploading the original data in the federated learning mode, so that the problem of privacy leakage possibly occurring in the data transmission and storage process is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data privacy protection, and particularly to a high-security data collection method and medium. Background Art

[0002] With the rapid development of information technology, the collection, transmission, and utilization of data have become increasingly widespread in various fields. In many scenarios, such as finance, healthcare, and government affairs, the collected data often contains a large amount of sensitive information of users, such as ID numbers, medical records, bank card numbers, etc. However, traditional data collection and training methods usually directly upload the original data to the cloud or a centralized server for processing, and this method has a great risk of privacy leakage. Once a security vulnerability occurs in the data transmission link or the data storage server is attacked, the sensitive information of users may be illegally obtained and misused, causing serious losses to users.

[0003] To solve the data privacy protection problem, some existing technologies adopt methods such as encrypted transmission. However, this method usually only simply encrypts the original data, and there may still be a risk of privacy leakage during the data processing process, especially when the encryption key management is poor or the encryption algorithm is cracked. In addition, the traditional centralized data processing mode lacks the ability to locally process user data and cannot effectively protect the data privacy of users at the local end.

[0004] In recent years, as an emerging distributed machine learning technology, federated learning has gradually been applied to protect data privacy. However, existing federated learning methods still have room for improvement and optimization in terms of edge-side data desensitization encryption and how to ensure that only model parameters irrelevant to sensitive information are uploaded to the cloud for training, in order to further improve the effect and efficiency of privacy protection.

[0005] Therefore, it is necessary to adopt more advanced and effective privacy protection technologies during the data collection process, especially under the federated learning framework, to deeply protect the privacy of user input data and reduce the risk of leakage of user sensitive information. Summary of the Invention

[0006] The object of the present invention is to provide a high-security data collection method and medium, and thereby solve all or one of the above problems existing in the prior art.

[0007] To solve the above technical problems, the specific technical solution of the present invention is as follows: On the one hand, the present invention provides a high-security data collection method, including the following steps: During the data collection process, adopt a local federated learning framework to perform edge-side desensitization encryption on user input data; Upload the model parameters obtained after processing the encrypted data to the cloud for model training, rather than uploading the original data.

[0008] Furthermore, the localized federated learning framework includes edge devices and a cloud server. The edge devices are used to perform local preprocessing and desensitization encryption on user input data.

[0009] Furthermore, the desensitization encryption is to encrypt the original data based on a preset encryption algorithm, so that the original sensitive information cannot be directly obtained during the local and cloud training processes of the encrypted data.

[0010] Furthermore, the edge desensitization encryption process includes anonymizing and encrypting user input data such as ID numbers and medical records.

[0011] Furthermore, after the edge device completes desensitization encryption, it uses the federated learning algorithm to perform local model training on the encrypted data to generate encrypted model parameters.

[0012] Furthermore, after uploading the processed encrypted model parameters to the cloud, the cloud server performs federated aggregation on the model parameters received from multiple users to update the global model.

[0013] Furthermore, when the cloud server updates the global model, it cannot obtain the original user data and can only process and update the model parameters.

[0014] Furthermore, the anonymization process includes operations such as replacing, masking, or generalizing identifiable information such as ID numbers, so that the encrypted data cannot be directly corresponding to specific users.

[0015] Furthermore, the high-security data collection method further includes: the localized federated learning framework controls the cloud server so that it cannot trace or recover the original user data.

[0016] On the other hand, the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the high-security data collection method are implemented.

[0017] The beneficial effects of the technical solution of the present invention are: 1. The high-security data collection method described in the present invention can use a localized federated learning framework to perform edge-side desensitization and encryption on user input data during the data collection process, and only upload model parameters instead of raw data to the cloud for training, greatly reducing the risk of leakage of user sensitive information. Desensitizing and encrypting data on the local side protects user privacy from the source; while the federated learning method can complete model training without uploading raw data, avoiding privacy leakage problems that may occur during data transmission and storage. This method effectively protects user privacy while ensuring the value of data utilization, improving the security and reliability of the data collection process.

[0018] 2. The computer-readable storage medium described in the present invention can enable the cooperation of the boot system module to implement the above method, and the computer-readable storage medium described in the present invention also effectively improves the operability of the above method. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0020] Figure 1 It is a schematic flowchart of the high-security data collection method described in Embodiment 1 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0021] The following will elaborate on the preferred embodiments of the present invention in conjunction with the drawings, so that the advantages and features of the present invention can be more easily understood by those skilled in the art, thereby making a clearer and more definite definition of the protection scope of the present invention.

[0022] In the description of the present invention, it should be noted that the embodiments described in the present invention are some embodiments of the present invention, rather than all embodiments; all other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the protection scope of the present invention.

[0023] In the description, claims and the above-mentioned drawings of this document, terms such as "first", "second", etc. are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of this document described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, device, product or equipment that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or equipment.

[0024] Embodiment 1. This embodiment provides a high-security data collection method, as Figure 1 shown, including the following steps: S100. During the data collection process, a localized federated learning framework is adopted to perform edge-side desensitization encryption on the user input data; S200. Upload the model parameters obtained after processing the encrypted data to the cloud for model training, instead of uploading the original data.

[0025] Furthermore, the localized federated learning framework includes an edge-side device and a cloud server. The edge-side device is used to perform local preprocessing and desensitization encryption on the user input data.

[0026] Furthermore, the desensitization encryption is to perform encryption processing on the original data based on a preset encryption algorithm, so that the original sensitive information cannot be directly obtained during the local and cloud training processes of the encrypted data.

[0027] Furthermore, the edge-side desensitization encryption process includes anonymizing and encrypting and encoding user input data such as ID numbers and medical records.

[0028] Furthermore, after the edge-side device completes the desensitization encryption, it uses the federated learning algorithm to perform local model training on the encrypted data to generate encrypted model parameters.

[0029] Furthermore, after uploading the model parameters obtained after processing the encrypted data to the cloud, the cloud server performs federated aggregation on the model parameters received from multiple users to update the global model.

[0030] Furthermore, when the cloud server updates the global model, it cannot obtain the original user data and can only process and update the model parameters.

[0031] Furthermore, the anonymization process includes operations such as replacing, masking or generalizing identifiable information such as ID numbers, so that the encrypted data cannot be directly corresponding to specific users.

[0032] Furthermore, the high-security data collection method further includes: the localized federated learning framework controls the cloud server so that it cannot trace or recover the original user data.

[0033] It should be noted that the examples here are only for explaining the present invention and should not limit the protection scope of the present invention accordingly. Embodiment 2

[0034] This embodiment provides a computer-readable storage medium, including: The storage medium is used to store computer software instructions for implementing the high-security data collection method described in Embodiment 1 above. It includes a program set for the high-security data collection method described above, and implements the high-security data collection method described in Embodiment 1 by executing the built-in executable program.

[0035] In addition, the computer-readable storage medium of this embodiment can adopt any combination of one or more readable storage media. Among them, the readable storage medium includes systems, devices or components of electricity, light, electromagnetism, infrared rays or semiconductors, or any combination of the above.

[0036] It should be understood that in various embodiments herein, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments herein.

[0037] It should also be understood that in the embodiments herein, the term "and / or" is only a description of the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after.

[0038] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this article.

[0039] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0040] In the several embodiments provided in this document, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Additionally, the displayed or discussed couplings or direct couplings or communication connections to each other can be indirect couplings or communication connections through some interfaces, devices, or units, and can also be in electrical, mechanical, or other forms of connection.

[0041] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of the embodiments in this document.

[0042] In addition, in each embodiment of this document, the functional units can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.

[0043] If the above-mentioned integrated units are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the essence of the technical solution in this document, or the part that contributes to the prior art, or all or part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of this document. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0044] The above are only embodiments of the present invention, and do not thereby limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall similarly be included within the patent protection scope of the present invention.

Claims

1. A high-security data collection method, characterized in that It includes the following steps: During the data collection process, a localized federated learning framework is adopted to perform edge-side desensitization encryption on the user input data; The model parameters obtained after encryption and processing are uploaded to the cloud for model training, instead of uploading the original data.

2. The high-security data collection method according to claim 1, characterized in that The localized federated learning framework includes edge-side devices and cloud servers. The edge-side devices are used to perform local preprocessing and desensitization encryption on the user input data.

3. The high-security data collection method according to claim 1, characterized in that The desensitization encryption is to encrypt the original data based on a preset encryption algorithm, so that the original sensitive information cannot be directly obtained during the local and cloud training processes of the encrypted data.

4. The high-security data collection method according to claim 1, wherein The edge-side desensitization encryption process includes anonymizing and encrypting and encoding user input data such as ID numbers and medical records.

5. The high-security data collection method according to claim 1, characterized in that After the edge-side devices complete desensitization encryption, the federated learning algorithm is used to perform local model training on the encrypted data to generate encrypted model parameters.

6. The high-security data collection method according to claim 1, wherein, After the encrypted model parameters obtained after processing are uploaded to the cloud, the cloud server performs federated aggregation based on the model parameters of multiple users received to update the global model.

7. The high-security data collection method according to claim 1, characterized in that When the cloud server updates the global model, it cannot obtain the original user data and can only process and update the model parameters.

8. The high-security data collection method according to claim 4, characterized in that The anonymization process includes operations such as replacing, masking, or generalizing identifiable information such as ID numbers, so that the encrypted data cannot be directly corresponding to specific users.

9. The high-security data collection method according to claim 1, wherein The high-security data collection method further includes: the localized federated learning framework controls the cloud server so that the original user data cannot be traced or restored.

10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, the steps of the high-security data collection method described in any one of claims 1 to 9 are implemented.