Dynamic data desensitization system and method based on federal learning technology

The dynamic data desensitization system based on federated learning technology, combined with a dynamic desensitization engine, federated process mining, and blockchain auditing, solves the problem that static desensitization cannot meet diverse needs, ensures the security and accuracy of data in cross-departmental sharing and analysis, and improves the company's data security protection capabilities.

CN120671172APending Publication Date: 2025-09-19东风悦享科技有限公司
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510634352.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-16
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing technologies are unable to dynamically adjust according to employee roles, data access scenarios, and data lineage relationships, making privacy protection difficult. Traditional static desensitization methods cannot meet diverse data needs, and excessive desensitization affects the accuracy of data analysis.

Method used

A dynamic data desensitization system based on federated learning technology is adopted. The dynamic desensitization engine determines data lineage based on employee roles and access scenarios. Combined with the federated process mining module and blockchain audit chain, adaptive data desensitization and process monitoring are achieved, and RPA compliance robots are used for automated repair and defense operations.

Benefits of technology

It achieves dynamic data desensitization based on different roles and scenarios, protects data privacy, ensures the security of data during cross-departmental sharing and analysis, and improves the company's data security protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120671172A_ABST
    Figure CN120671172A_ABST
Patent Text Reader

Abstract

The invention provides a dynamic data desensitization system based on a federated learning technology, and the system comprises a dynamic desensitization engine which is used for calculating a desensitization strategy weight according to a strategy weight functional expression, selecting a desensitization strategy matched with the desensitization strategy weight, and carrying out the desensitization processing of data; the federated flow mining module is used for calculating flow model parameters, uploading the flow model parameters to the federated flow mining module, extracting flow model features of a department, sharing feature vectors, and ensuring that the shared features cannot be reversely pushed back to original log data according to a differential privacy noise control algorithm; the block chain auditing chain is used for writing the hash value into the block chain to form an operation fingerprint and sending alarm information according to the operation fingerprint; and the RPA compliance robot is used for resetting the account permission, backtracking the influenced data copy, performing desensitization processing again and sending an investigation processing notification to compliance personnel.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data desensitization technology, and in particular to a dynamic data desensitization system and method based on federated learning technology. Background Art

[0002] In business operations, data silos between departments are severe. For example, the sales department holds extensive customer information, the finance department holds financial transaction data, and the human resources department manages sensitive data such as employee salaries. When cross-departmental collaboration occurs, such as when sales and finance jointly analyze customer value and payment collection, sharing this sensitive data poses a significant risk of data leakage. A leak could severely damage the company's reputation and customer trust. Therefore, this type of data needs to be desensitized. Traditional data desensitization methods often use static policies, such as uniformly masking all customer names. However, in real-world dynamic business scenarios, different roles have varying data granularity requirements. For example, when analyzing customer geographic distribution, market researchers may only need to de-obfuscate customer names while retaining regional information. Senior management, however, may require more detailed, yet anonymized, statistical metrics, such as sales performance by region, when making strategic decisions. Static desensitization cannot meet these diverse needs. Furthermore, business processes often span multiple systems. For example, the procurement approval chain begins with a purchase requisition, progresses through approvals across multiple departments, and involves various systems, including ERP. Currently, fully tracing this complex process is difficult. Manual audits not only consume significant time and manpower but also easily overlook irregularities, such as unauthorized approval redirections. With the introduction of stringent regulations such as the GDPR (General Data Protection Regulation), which aims to strengthen the protection of personal data and regulate corporate data processing, companies often resort to excessive redaction measures to meet compliance requirements. In supply chain management, excessive redaction can lead to the loss of key data features, making it impossible for supply chain forecasting models to accurately analyze data trends, resulting in inaccurate forecasts and impacting production planning and inventory management. Summary of the Invention

[0003] In view of this, the present invention provides a dynamic data desensitization system and method based on federated learning technology to solve the technical problems that the existing technology cannot be dynamically adjusted according to employee roles, data access scenarios and data lineage relationships, and data sharing relies on original log data, making privacy protection difficult.

[0004] The present invention provides a dynamic data desensitization system based on federated learning technology, the system comprising: a dynamic desensitization engine for obtaining employee roles based on account information, determining data lineage based on current access scenarios and employee roles, thereby retrieving data from the database based on data lineage, and performing data desensitization based on the policy weight function w = σ(Wrr+Wss+Wll+b) calculates the desensitization strategy weight, selects the desensitization strategy that matches the desensitization strategy weight, and desensitizes the data, where w is the desensitization strategy weight, r is the role vector, s is the scene vector, l is the lineage vector, σ is the activation function, Wr, Ws, Wl are trainable weight matrices, and b is the bias term; the federated process mining module is used to use federated learning technology to calculate the process model parameters: θ=(A, B, π) based on the desensitized event log from the original system logs retained locally by the department, and upload them to the federated process mining module. The process model features of the department are extracted based on the hidden Markov model, and the feature vector is shared. According to the differential privacy noise control algorithm, adaptive Laplace noise is injected into the shared feature vector. The magnitude and distribution of the noise are controlled according to the following formula to ensure that the shared features cannot be reversed to the original log data. , , where A is the state transfer matrix, B is the observation probability matrix, π is the initial state distribution, and Total Privacy represents the total privacy protection strength. Indicates the ratio of the number of masked fields to the total number of sensitive automatic fields. Represents the noise value, MaskLoss is the masking loss, NoiseLoss is the noise loss, λ1 and λ2 are preset coefficients; the blockchain audit chain is connected to the dynamic desensitization engine and the federated process mining module respectively, and is used to write the hash value of the desensitization policy version and the process template into the blockchain through the distributed ledger technology of the blockchain to form an operation fingerprint. When there is a risk of data leakage in data access or process operation, an alarm message is sent according to the operation fingerprint; the RPA compliance robot is connected to the blockchain audit chain. After receiving the alarm message, it is used to reset the account permissions according to the account information, specific operation content and illegal operation time in the alarm message, trace back the affected data copy, re-desensitize the data, and send an investigation and processing notice to the compliance personnel.

[0005] Furthermore, the system also includes: a display interface, connected to the RPA compliance robot, for displaying desensitized data and notifications of investigations and handling of data leakage risks.

[0006] The present invention also provides a dynamic data desensitization method based on federated learning technology, the method comprising: step 1, the dynamic desensitization engine obtains the employee role according to the account information filled in when the operator logs into the account, and determines the data lineage according to the current access scenario and the employee role; step 2, retrieves the data in the database according to the data lineage, and calculates the data according to the policy weight function w = σ(Wrr+Wss+Wll+b) calculates the desensitization strategy weight, selects the desensitization strategy that matches the desensitization strategy weight, and desensitizes the data, where w is the desensitization strategy weight, r is the role vector, s is the scene vector, l is the lineage vector, σ is the activation function, Wr, Ws, Wl are trainable weight matrices, and b is the bias term; Step 3, the federated process mining module uses federated learning technology to calculate the process model parameters θ=(A, B, π) based on the desensitized event log from the original system log retained locally by the department, and uploads it to the federated process mining module. The process model features of the department are extracted based on the hidden Markov model, and the feature vector is shared. According to the differential privacy noise control algorithm, adaptive Laplace noise is injected into the shared feature vector. The magnitude and distribution of the noise are controlled according to the following formula to ensure that the shared features cannot be reversed to the original log data. , , where A is the state transfer matrix, B is the observation probability matrix, π is the initial state distribution, and Total Privacy represents the total privacy protection strength. Indicates the ratio of the number of masked fields to the total number of sensitive automatic fields. represents the noise value, MaskLoss is the masking loss, NoiseLoss is the noise loss, and λ1 and λ2 are preset coefficients; Step 4, the blockchain audit chain writes the hash value of the desensitization policy version and the process template into the blockchain through the blockchain's distributed ledger technology to form an operation fingerprint; Step 5, when there is a risk of data leakage in data access or process operation, an alarm message is sent based on the operation fingerprint; Step 6, after receiving the alarm message, the RPA compliance robot resets the account permissions based on the account information in the alarm message, backtracks the affected data copy, re-desensitizes the data, and sends an investigation and processing notice to the compliance personnel.

[0007] Furthermore, the method also includes: step 7, displaying the desensitized data and the prompt of the investigation and processing notification on the display interface.

[0008] Furthermore, step 3 includes: step 31, obtaining the original system logs retained locally by the department and uploading them to the federated process mining module; step 32, mining and analyzing the original data, extracting and sharing the feature vectors of the process model; step 33, using differential privacy technology to inject appropriate noise into the shared feature vectors, and by controlling the magnitude and distribution of the noise, ensuring that the shared features cannot be reversed to the original log data.

[0009] Furthermore, the feature vector includes the average time consumption of the process nodes and the abnormal jump frequency.

[0010] Furthermore, resetting the account permissions includes freezing the account's access permissions.

[0011] Furthermore, the preset desensitization strategy is set according to the company's internal regulations and national laws and regulations.

[0012] Furthermore, the step 5 also includes: automatically generating an audit report, which includes the time, personnel, and specific operation content of the illegal operation.

[0013] Furthermore, the investigation and handling notice includes: a description of the risk event, the time of discovery, the data involved, and possible sources of risk.

[0014] The present invention provides a dynamic data desensitization system and method based on federated learning technology. This technical solution ensures the security of data during cross-departmental sharing and analysis, and fully mines the value of data through the collaborative work of a dynamic role-based data desensitization engine and a federated process mining framework. When the system detects potential data leakage risks or compliance issues, it uses RPA robots to automatically perform a series of repair and defense operations, greatly improving the company's data security protection capabilities. It adapts general blockchain technology to the company's internal control needs, records operation fingerprints through the blockchain's tamper-proof characteristics, and combines smart contracts to realize the automated execution of compliance rules, providing an efficient and reliable technical means for enterprise process compliance management. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 This is a framework diagram of a dynamic data desensitization system based on federated learning technology provided by the present invention; Figure 2 This is a flow chart of a dynamic data desensitization method based on federated learning technology provided by the present invention; Figure 3 It is a decision flow chart of the dynamic desensitization engine provided by the present invention. DETAILED DESCRIPTION

[0016] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0017] Example 1: The present invention provides a dynamic data desensitization system and method based on federated learning technology, which includes a dynamic desensitization engine, a federated process mining module, a blockchain audit chain, an RPA compliance robot, and a display interface. Figure 1 The method comprises the following steps: Figure 2 shown.

[0018] Step 1: The dynamic desensitization engine obtains the employee role based on the account information filled in when the operator logs in to the account, and determines the data lineage based on the current access scenario and employee role; Step 2: retrieve the data from the database according to the data lineage, and use the strategy weight function w = σ(W r r+W s s+W l l+b) calculates the desensitization strategy weight and selects the desensitization strategy that matches the desensitization strategy weight to desensitize the data, where w is the desensitization strategy weight, r is the role vector, s is the scene vector, l is the blood relationship vector, σ is the activation function, and W r , W s , W l is the trainable weight matrix, b is the bias term; Step 3: The federated process mining module uses federated learning technology to calculate the process model parameters θ=(A, B, π) from the original system logs retained locally by the department based on the desensitized event logs, and uploads them to the federated process mining module. The department's process model features are extracted based on the hidden Markov model, and the feature vector is shared. Based on the differential privacy noise control algorithm, adaptive Laplace noise is injected into the shared feature vector. The magnitude and distribution of the noise are controlled according to the following formula to ensure that the shared features cannot be reversed to the original log data. , , Among them, A is the state transfer matrix, B is the observation probability matrix, π is the initial state distribution, and Total Privacy represents the total privacy protection strength. Indicates the ratio of the number of masked fields to the total number of sensitive automatic fields. Indicates the noise value, MaskLoss is the masking loss, NoiseLoss is the noise loss, λ1 and λ2 are the preset coefficients; Federated learning (Federated Machine Learning, also known as federated learning, federated learning, federated learning, and federated machine learning) is a machine learning framework that effectively helps multiple organizations utilize data and conduct machine learning modeling while meeting user privacy, data security, and government regulatory requirements. Process mining, also known as workflow mining, is a technique for extracting useful information from workflow logs. For example, workflow logs from ERP systems can be used to identify workflow models, organize models, and then analyze them to identify process issues. Currently, workflow mining can be categorized into workflow model mining, workflow organizational structure mining, and workflow work distribution, depending on the mining perspective.

[0019] Step 4: The blockchain audit chain writes the hash value of the desensitization policy version and process template into the blockchain through the blockchain's distributed ledger technology to form the operation fingerprint; Step 5: When data access or process operation presents a risk of data leakage, an alarm message is sent based on the operation fingerprint; In step 6, after receiving the alert, the RPA compliance robot resets the account permissions based on the account information in the alert, retraces the affected data copy, performs desensitization again, and sends an investigation and processing notice to the compliance personnel.

[0020] RPA (Robotic process automation) is a business process automation technology based on software robots and artificial intelligence (AI). An RPA system is an application that provides an alternative way to automate manual end-user processes by mimicking the way end-users manually operate on computers.

[0021] Step 7: Display the anonymized data and the investigation and processing notification prompt on the display interface.

[0022] The present invention provides a dynamic data desensitization system and method based on federated learning technology. This technical solution ensures the security of data during cross-departmental sharing and analysis, and fully mines the value of data through the collaborative work of a dynamic role-based data desensitization engine and a federated process mining framework. When the system detects potential data leakage risks or compliance issues, it uses RPA robots to automatically perform a series of repair and defense operations, greatly improving the company's data security protection capabilities. It adapts general blockchain technology to the company's internal control needs, records operation fingerprints through the blockchain's tamper-proof characteristics, and combines smart contracts to realize the automated execution of compliance rules, providing an efficient and reliable technical means for enterprise process compliance management.

[0023] Example 2: The present invention provides a dynamic data desensitization system and method based on federated learning technology, which includes a dynamic desensitization engine, a federated process mining module, a blockchain audit chain, an RPA compliance robot, and a display interface. Figure 1 The method comprises the following steps: Figure 2 shown.

[0024] Step 1: The dynamic desensitization engine obtains the employee role based on the account information filled in when the operator logs in to the account, and determines the data lineage based on the current access scenario and employee role; In actual dynamic business scenarios, different roles have different granularity requirements for data. For example, when analyzing the geographical distribution of customers, market researchers may only need to blur the customer names but retain the regional information; while senior managers may need more detailed but anonymous statistical indicators when making strategic decisions, such as the proportion of sales performance in each region. However, traditional data desensitization methods often adopt static strategies, such as uniform field masking for all customer names, which cannot meet such diverse needs. Therefore, the technical solution provided in this application dynamically determines the desensitization required for relevant data based on employee roles and access scenarios, thereby meeting the diverse needs of enterprises for data desensitization.

[0025] Step 2: retrieve the data from the database according to the data lineage, and use the strategy weight function w = σ(W r r+W s s+W l l+b) calculates the desensitization strategy weight and selects the desensitization strategy that matches the desensitization strategy weight to desensitize the data, where w is the desensitization strategy weight, r is the role vector, s is the scene vector, l is the blood relationship vector, σ is the activation function, and W r , W s , W l is the trainable weight matrix, b is the bias term; This application dynamically adjusts the desensitization strategy based on employee roles (Role), access scenarios (Context), and data lineage (Lineage) to perform desensitization processing. For example, when financial personnel view sales data for financial analysis, customer names can be masked, but at the same time, customer regional distribution information can be retained so that financial personnel can analyze sales performance and collection status from a regional perspective. The rules that match the desensitization weights include desensitization strength and desensitization operator library. For example, the desensitization strength strategy matching rules are: strong desensitization (w<0.3), medium desensitization (0.3≤w<0.7), weak desensitization (w≥0.7); another example is the desensitization operator library shown in Table 1. Therefore, desensitization processing can be performed according to the desensitization strength and data type of the data to be desensitized.

[0026]

[0027] Table 1 Desensitization operator library Step 3: The federated process mining module uses federated learning technology to calculate the process model parameters θ=(A, B, π) from the original system logs retained locally by the department based on the desensitized event logs, and uploads them to the federated process mining module. The department's process model features are extracted based on the hidden Markov model, and the feature vector is shared. Based on the differential privacy noise control algorithm, adaptive Laplace noise is injected into the shared feature vector. The magnitude and distribution of the noise are controlled according to the following formula to ensure that the shared features cannot be reversed to the original log data. , , Among them, A is the state transfer matrix, B is the observation probability matrix, π is the initial state distribution, and Total Privacy represents the total privacy protection strength. Indicates the ratio of the number of masked fields to the total number of sensitive automatic fields. Indicates the noise value, MaskLoss is the masking loss, NoiseLoss is the noise loss, λ1 and λ2 are the preset coefficients; Due to the serious data silos between departments in enterprise operations, for example, the sales department holds extensive customer information, the finance department holds financial transaction data, and the HR department manages sensitive data such as employee salaries. When cross-departmental collaboration occurs, such as when sales and finance jointly analyze customer value and payment collection, sharing this sensitive data poses a significant risk of data leakage. Once leaked, it can severely damage the company's reputation and customer trust. Therefore, cross-departmental information sharing requires data processing. The collaborative work of a dynamic role-based data desensitization engine and a federated process mining framework ensures data security during cross-departmental sharing and analysis while fully mining its value, providing the company with precise process optimization insights. Each department locally retains raw system logs, such as procurement process logs in the ERP system and sales process logs in the CRM system. These feature vectors, rather than the raw log data, are then shared. These feature vectors include the average time spent on process nodes and the frequency of abnormal jumps. Using federated learning technology, each department extracts key process model features, such as approval time and abnormal jumps. This not only protects the privacy of each department's raw data but also enables collaborative analysis of cross-departmental processes. Differential privacy is a cryptographic technique designed to maximize the accuracy of data queries while minimizing the chance of identifying records when querying from a statistical database. Using differential privacy (DP) technology, appropriate noise is injected into shared feature vectors. For example, the average duration of a process node is 3.2 days, but after noise injection, it becomes 3.5 days. By cleverly controlling the magnitude and distribution of the noise, the shared features cannot be inferred back to the original log data, effectively hiding sensitive information such as the identity of specific approvers while ensuring the accuracy and availability of process mining results.

[0028] Step 4: The blockchain audit chain writes the hash value of the desensitization policy version and process template into the blockchain through the blockchain's distributed ledger technology to form the operation fingerprint; This application's general blockchain technology is adapted to meet the needs of enterprise internal control, particularly for scenarios such as the separation of authority requirement in the basic enterprise internal control standards. Key parameters for data access and process operations, such as desensitization policy versions and process model hash values, are written to the blockchain using its distributed ledger technology. Leveraging the blockchain's immutable nature, this information is recorded as an operational fingerprint, making it tamper-proof and traceable, providing a reliable basis for subsequent audits.

[0029] Step 5: When data access or process operation presents a risk of data leakage, an alarm message is sent based on the operation fingerprint; In step 6, after receiving the alert, the RPA compliance robot resets the account permissions based on the account information in the alert, retraces the affected data copy, performs desensitization again, and sends an investigation and processing notice to the compliance personnel.

[0030] Step 7: Display the anonymized data and the investigation and processing notification prompt on the display interface.

[0031] The present invention provides a dynamic data desensitization system and method based on federated learning technology. This technical solution ensures the security of data during cross-departmental sharing and analysis, and fully mines the value of data through the collaborative work of a dynamic role-based data desensitization engine and a federated process mining framework. When the system detects potential data leakage risks or compliance issues, it uses RPA robots to automatically perform a series of repair and defense operations, greatly improving the company's data security protection capabilities. It adapts general blockchain technology to the company's internal control needs, records operation fingerprints through the blockchain's tamper-proof characteristics, and combines smart contracts to realize the automated execution of compliance rules, providing an efficient and reliable technical means for enterprise process compliance management.

[0032] Example 3: The present invention provides a dynamic data desensitization system and method based on federated learning technology, which includes a dynamic desensitization engine, a federated process mining module, a blockchain audit chain, an RPA compliance robot, and a display interface. Figure 1 The method comprises the following steps: Figure 2 shown.

[0033] Step 1: The dynamic desensitization engine obtains the employee role based on the account information filled in when the operator logs in to the account, and determines the data lineage based on the current access scenario and employee role; Step 2: retrieve the data from the database according to the data lineage, and use the strategy weight function w = σ(W r r+W s s+W l l+b) calculates the desensitization strategy weight and selects the desensitization strategy that matches the desensitization strategy weight to desensitize the data, where w is the desensitization strategy weight, r is the role vector, s is the scene vector, l is the blood relationship vector, σ is the activation function, and W r , W s , W l is the trainable weight matrix, b is the bias term; The preset desensitization strategy is set according to the company's internal regulations and national laws and regulations.

[0034] Step 3: The federated process mining module uses federated learning technology to calculate the process model parameters θ=(A, B, π) from the original system logs retained locally by the department based on the desensitized event logs, and uploads them to the federated process mining module. The department's process model features are extracted based on the hidden Markov model, and the feature vector is shared. Based on the differential privacy noise control algorithm, adaptive Laplace noise is injected into the shared feature vector. The magnitude and distribution of the noise are controlled according to the following formula to ensure that the shared features cannot be reversed to the original log data. , , Among them, A is the state transfer matrix, B is the observation probability matrix, π is the initial state distribution, and Total Privacy represents the total privacy protection strength. Indicates the ratio of the number of masked fields to the total number of sensitive automatic fields. Indicates the noise value, MaskLoss is the masking loss, NoiseLoss is the noise loss, λ1 and λ2 are the preset coefficients; Step 4: The blockchain audit chain writes the hash value of the desensitization policy version and process template into the blockchain through the blockchain's distributed ledger technology to form the operation fingerprint; Step 5: When data access or process operation presents a risk of data leakage, an alarm message is sent based on the operation fingerprint; An enterprise's business processes often span multiple systems. Take the procurement approval chain, for example. Starting with a purchase request, the process undergoes approvals from multiple departments and involves various systems, including ERP. Currently, fully tracing this complex process is difficult. Manual audits not only consume significant time and manpower but also easily overlook violations, such as unauthorized approval redirections. The technical solution provided in this application uses blockchain-based operation fingerprints to trace back these operations. This application also combines the blockchain technology in step 4 with smart contracts to automate the enforcement of compliance rules, providing an efficient and reliable technical approach for enterprise compliance management. Automated smart contract auditing involves pre-setting compliance rules based on the enterprise's internal control requirements and compliance standards, such as "senior executives are prohibited from accessing the salary details of front-line employees." When the system detects data access or process manipulation, the smart contract automatically runs to perform a compliance check. Once a violation is detected, a real-time alert is triggered and a detailed audit report is automatically generated, including information such as the time, person responsible, and specific content of the violation.

[0035] In step 6, after receiving the alert, the RPA compliance robot resets the account permissions based on the account information in the alert, retraces the affected data copy, performs desensitization again, and sends an investigation and processing notice to the compliance personnel.

[0036] Resetting account permissions includes freezing account access rights. The notification regarding the investigation and handling of data leakage risks includes a description of the risk event, the time of discovery, the data involved, and possible risk sources. Unlike traditional solutions that focus on post-event auditing, this invention uses RPA to prevent risks in real time. When the system detects a potential data leakage risk or compliance issue, the RPA robot can quickly and automatically perform a series of remediation and prevention actions. First, the RPA robot quickly resets the abnormal account permissions to prevent further escalation of the risk. For example, if an account is found to have a large number of abnormal data accesses within a short period of time, the account's access rights are immediately frozen. Second, the RPA robot backtracks the affected data copies and re-masses the data according to the latest desensitization policy to ensure data security. Finally, the RPA robot automatically sends an email to the compliance department, detailing the risk event, including the time of discovery, the data involved, and possible risk sources, to facilitate further investigation and resolution, thus eliminating the risk in its infancy and significantly improving the company's data security capabilities. Step 7: Display the anonymized data and the investigation and processing notification prompt on the display interface.

[0037] The present invention provides a dynamic data desensitization system and method based on federated learning technology. This technical solution ensures the security of data during cross-departmental sharing and analysis, and fully mines the value of data through the collaborative work of a dynamic role-based data desensitization engine and a federated process mining framework. When the system detects potential data leakage risks or compliance issues, it uses RPA robots to automatically perform a series of repair and defense operations, greatly improving the company's data security protection capabilities. It adapts general blockchain technology to the company's internal control needs, records operation fingerprints through the blockchain's tamper-proof characteristics, and combines smart contracts to realize the automated execution of compliance rules, providing an efficient and reliable technical means for enterprise process compliance management.

[0038] In summary, the embodiments of the present invention provide a dynamic data desensitization system and method based on federated learning technology. This technical solution involves internal enterprise data governance, process mining, and privacy computing. It is a cross-departmental operation optimization solution that integrates dynamic role-based data desensitization, federated process mining, and blockchain audit tracking. This application can address the blind spots of a single technology, such as the inability to defend against privacy inference through data correlation and the inability to protect sensitive fields that are directly accessed. At the same time, a hierarchical protection system is constructed, and the original business data or log data enters the dynamic desensitization engine (field-level data is desensitized based on access users, usage scenarios, etc.). The desensitized data can be used directly for data query or analysis, and can also be combined with federated process mining desensitized data for joint enterprise process operation analysis. In addition, the combination of blockchain audit tracking chain and smart contracts shortens the time to generate audit reports.

[0039] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A dynamic data desensitization system based on federated learning technology, characterized in that: The system comprises: Dynamic desensitization engine is used to obtain employee roles based on account information, determine data lineage based on current access scenario and employee role, retrieve data from the database based on data lineage, and use the policy weight function w = σ(W r r+W s s+W l l+b) calculates the desensitization strategy weight, selects the desensitization strategy that matches the desensitization strategy weight, and desensitizes the data, where w is the desensitization strategy weight, r is the role vector, s is the scene vector, l is the blood relationship vector, σ is the activation function, and W r , W s , W l is the trainable weight matrix, b is the bias term; The federated process mining module is used to calculate the process model parameters: θ = (A, B, π) from the original system logs retained locally by the department based on the desensitized event logs through federated learning technology. The parameters are then uploaded to the federated process mining module. The department's process model features are extracted based on the hidden Markov model, and the feature vectors are shared. Adaptive Laplace noise is injected into the shared feature vectors based on the differential privacy noise control algorithm. The magnitude and distribution of the noise are controlled according to the following formula to ensure that the shared features cannot be reversed to the original log data. , , Among them, A is the state transfer matrix, B is the observation probability matrix, π is the initial state distribution, and Total Privacy represents the total privacy protection strength. Indicates the ratio of the number of masked fields to the total number of sensitive automatic fields. Indicates the noise value, MaskLoss is the masking loss, NoiseLoss is the noise loss, λ1 and λ2 are the preset coefficients; The blockchain audit chain is connected to the dynamic desensitization engine and the federated process mining module. It is used to write the hash value of the desensitization policy version and process template into the blockchain through the blockchain's distributed ledger technology to form an operation fingerprint. When data access or process operation presents a data leakage risk, an alarm message is sent based on the operation fingerprint. The RPA compliance robot is connected to the blockchain audit chain. After receiving the alarm information, it is used to reset the account permissions based on the account information, specific operation content and time of the illegal operation in the alarm information, trace back the affected data copies, re-desensitize the data, and send an investigation and processing notice to the compliance personnel.

2. The dynamic data desensitization system based on federated learning technology according to claim 1, characterized in that: The system also includes: a display interface connected to the RPA compliance robot, which is used to display desensitized data and notifications of investigation and handling of data leakage risks.

3. A method for a dynamic data desensitization system based on federated learning technology according to claims 1-2, characterized in that: The method comprises: Step 1: The dynamic desensitization engine obtains the employee role based on the account information filled in when the operator logs in to the account, and determines the data lineage based on the current access scenario and employee role; Step 2: retrieve the data from the database according to the data lineage, and use the strategy weight function w = σ(W r r+W s s+W l l+b) calculates the desensitization strategy weight and selects the desensitization strategy that matches the desensitization strategy weight to desensitize the data, where w is the desensitization strategy weight, r is the role vector, s is the scene vector, l is the blood relationship vector, σ is the activation function, and W r , W s , W l is the trainable weight matrix, b is the bias term; Step 3: The federated process mining module uses federated learning technology to calculate the process model parameters θ=(A, B, π) from the original system logs retained locally by the department based on the desensitized event logs, and uploads them to the federated process mining module. The department's process model features are extracted based on the hidden Markov model, and the feature vector is shared. Based on the differential privacy noise control algorithm, adaptive Laplace noise is injected into the shared feature vector. The magnitude and distribution of the noise are controlled according to the following formula to ensure that the shared features cannot be reversed to the original log data. , , Among them, A is the state transfer matrix, B is the observation probability matrix, π is the initial state distribution, and Total Privacy represents the total privacy protection strength. Indicates the ratio of the number of masked fields to the total number of sensitive automatic fields. Indicates the noise value, MaskLoss is the masking loss, NoiseLoss is the noise loss, λ1 and λ2 are the preset coefficients; Step 4: The blockchain audit chain writes the hash value of the desensitization policy version and process template into the blockchain through the blockchain's distributed ledger technology to form the operation fingerprint; Step 5: When data access or process operation presents a risk of data leakage, an alarm message is sent based on the operation fingerprint; In step 6, after receiving the alert, the RPA compliance robot resets the account permissions based on the account information in the alert, retraces the affected data copy, performs desensitization again, and sends an investigation and processing notice to the compliance personnel.

4. The dynamic data desensitization method based on federated learning technology according to claim 3 is characterized in that: The method further comprises: Step 7: Display the anonymized data and the investigation and processing notification prompt on the display interface.

5. The dynamic data desensitization method based on federated learning technology according to claim 3, characterized in that: The step 3 also includes: using a tree-structured privacy budget allocation method to optimize multiple queries of long process logs.

6. The dynamic data desensitization method based on federated learning technology according to claim 3, characterized in that: The feature vector includes the mean time consumption of process nodes, abnormal jump frequency, and activity correlation matrix.

7. The dynamic data desensitization method based on federated learning technology according to claim 3, characterized in that: Resetting the account permissions includes freezing the access permissions of the account.

8. The dynamic data desensitization method based on federated learning technology according to claim 3, characterized in that: The preset desensitization strategy is set according to the company's internal regulations and national laws and regulations.

9. The dynamic data desensitization method based on federated learning technology according to claim 3, characterized in that: The step 5 also includes: automatically generating an audit report, which includes the time, personnel, and specific operation content of the illegal operation.

10. The dynamic data desensitization method based on federated learning technology according to claim 3, characterized in that: The investigation and handling notice includes: a description of the risk event, the time of discovery, the data involved, and possible sources of risk.

Citation Information

Cited By

  • Private data desensitization method based on big data algorithm

    CN121256852A