Privacy protection method and device for preventing collusion of multiple servers, equipment and medium

By determining the privacy protection conversion strategy based on the data type in a multi-server collusion scenario and using data reuse to generate noise data corresponding to the privacy budget, the problem of linear superposition of privacy budget consumption is solved, and effective user privacy protection and data availability are achieved.

CN120805167APending Publication Date: 2025-10-17INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510659722.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-21
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

In the multi-server collusion scenario, the privacy protection perturbation mechanism of existing technologies leads to linear accumulation of privacy budget consumption and cannot effectively protect user privacy.

Method used

By determining the privacy protection conversion strategy according to the data type of the perturbation output under the privacy protection perturbation mechanism, and using data reuse to generate noise data corresponding to the privacy budget, the privacy budget consumption caused by repeated noise addition is avoided.

Benefits of technology

It effectively protects user privacy in multi-server collusion scenarios, avoids additional privacy budget consumption, and ensures data availability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120805167A_ABST
    Figure CN120805167A_ABST
Patent Text Reader

Abstract

The invention provides a privacy protection method and device for preventing collusion of multiple servers, equipment and a medium, and the method comprises the steps: determining a first privacy protection conversion strategy corresponding to a data type according to the data type of disturbance output under a privacy protection disturbance mechanism; obtaining a first noise value corresponding to the first privacy budget according to the original data and conversion information corresponding to the first privacy budget; obtaining a second noise value corresponding to a second privacy budget according to the first noise value and a first privacy protection conversion strategy; determining a second privacy protection conversion strategy corresponding to the data type according to the disturbance output data type; according to the original data, the second noise value and the second privacy protection conversion strategy, a third noise value corresponding to the first privacy budget is obtained, the purpose that noise data corresponding to the claimed privacy budget can be obtained by achieving data collection of any server through data multiplexing is achieved, and therefore extra privacy budget consumption is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data security, and in particular to a privacy protection method and device for preventing collusion of multiple servers, equipment and medium. BACKGROUND

[0002] In the big data era, data collection, sharing and analysis have become the norm, and mining valuable information from data is an important issue. How to collect data under the premise of protecting user privacy is an important problem. In terms of privacy protection, differential privacy (DP) is widely recognized as a powerful standard for privacy protection, which can provide quantitative privacy protection without assuming prior knowledge of attackers. Among them, local differential privacy (LDP) can provide privacy protection in the data collection stage.

[0003] For example, in order to support category type data perturbation and frequency estimation tasks, asymmetric random response (UE), generalized random response (GRR), square wave (SW) protocol and corresponding aggregation analysis method are designed. In order to support numerical data perturbation and mean estimation tasks, random rounding (SR), piecewise (PM) protocol is designed. In order to support numerical data perturbation and various numerical estimation tasks, Laplace, Gaussian protocol is designed. In general, different perturbation mechanisms are designed for various types of data and aggregation analysis targets to realize LDP-compliant data collection and analysis.

[0004] The current perturbation mechanism only considers the single server scenario. However, there are scenarios where multiple servers collect and share data, and the same data may be collected by multiple servers with different privacy budgets. Direct repeated noise addition will cause the privacy budget to be consumed linearly. SUMMARY

[0005] In view of the problems existing in the prior art, the present application provides a privacy protection method and device for preventing collusion of multiple servers, equipment and medium.

[0006] The present application provides a privacy protection method for preventing collusion of multiple servers, comprising: Under the privacy protection perturbation mechanism, according to the data type of the perturbation output, a first privacy protection conversion strategy corresponding to the data type is determined; the first privacy protection conversion strategy represents the constraint relationship between the privacy protection processing form corresponding to the first privacy budget range and the privacy protection processing form corresponding to the second privacy budget range; the minimum value in the first privacy budget range is greater than the maximum value in the second privacy budget range; According to the original data and the conversion information corresponding to the first privacy budget, a first noise value corresponding to the first privacy budget is obtained; the first privacy budget is a privacy budget in the first privacy budget range; According to the first noise value and the first privacy protection conversion strategy, a second noise value corresponding to a second privacy budget is obtained; the second privacy budget is a privacy budget in the second privacy budget range; According to the data type of the perturbed output, a second privacy protection conversion strategy corresponding to the data type is determined; the second privacy protection conversion strategy represents the relationship between the noise value corresponding to the first privacy budget range, the noise value corresponding to the second privacy budget range, and the original data; According to the original data, the second noise value, and the second privacy protection conversion strategy, a third noise value corresponding to the first privacy budget is obtained.

[0007] According to the privacy protection method provided by the application, when the privacy protection perturbation mechanism is an asymmetric random response perturbation mechanism, and the data type of the perturbed output is a category type data, the first privacy protection conversion strategy includes: Among them, for a bit of a category type data 0 / 1, if the bit is 1, the UE keeps the bit as 1 with a probability of , and flips it to 0 with a probability of ; if the bit is 0, the UE flips the bit to 1 with a probability of , and keeps it as 0 with a probability of , and are the conversion information of the privacy budget; 、 are the and values corresponding to the first privacy budget , , are the and values corresponding to the second privacy budget ; is the probability transition matrix corresponding to the first privacy budget , is the probability transition matrix corresponding to the second privacy budget ; A is a constraint matrix; Accordingly, the second noise value corresponding to the second privacy budget is obtained according to the first noise value and the first privacy protection conversion strategy, comprising: Determine a constraint matrix according to the first privacy-preserving conversion strategy, conversion information of the privacy budget, a pre-configured normalization constraint, and a pre-configured non-negativity constraint; Obtaining the second noise value according to the first noise value and the constraint matrix; The constraint matrix includes: Wherein, the first noise value 0 is The probability of flipping to 1, otherwise it remains 0; the first noise value 1 is The probability remains 1, otherwise it flips to 0.

[0008] According to a privacy protection method for preventing multi-server collusion provided by the present invention, the second privacy protection conversion strategy includes: in, To correspond to the second privacy budget The second noise value, For the original data, When The probability remains unchanged; When The probability remains unchanged; When The probability remains unchanged; When The probability remains unchanged.

[0009] According to a privacy protection method for preventing multi-server collusion provided by the present invention, the pre-configured normalization constraints and non-negativity constraints include: Normalization constraint checks include: the sum of each row of the constraint matrix is ​​1; Non-negativity constraint checks include: , there is a UE mechanism According to a privacy protection method for preventing multi-server collusion provided by the present invention, When the privacy-preserving perturbation mechanism is a Laplace perturbation mechanism, and the data type of the perturbation output is numerical data, the first privacy-preserving conversion strategy accordingly includes: Among them, a random number that conforms to the Laplace probability density function Added to the original data to get the noise value, , representing a random number Obey the Laplace probability density function, where , is the conversion information of privacy budget, For sensitivity, is the privacy budget; the Fourier form of the Laplace probability density function is ;make and They correspond to the first privacy budget respectively and the Second Privacy Budget of value; is the constraint function, which means The probability of keeping the first noise value unchanged is The probability of adding a random number to the first noise value , .

[0010] Accordingly, obtaining a second noise value corresponding to a second privacy budget according to the first noise value and the first privacy protection conversion strategy includes: Determine a constraint function according to the first privacy-preserving conversion strategy, conversion information of the privacy budget, a pre-configured normalization constraint, and a pre-configured non-negativity constraint; The second noise value is obtained according to the first noise value and the constraint function.

[0011] According to a privacy protection method for preventing multi-server collusion provided by the present invention, the second privacy protection conversion strategy includes: Among them, according to the corresponding second privacy budget The second noise value and original data Generate the corresponding first privacy budget The third noise value , and First Privacy Budget Add the following to the original data Random numbers, second privacy budget Add the following to the original data A random number.

[0012] According to a privacy protection method for preventing multi-server collusion provided by the present invention, the pre-configured normalization constraints and non-negativity constraints include: Normalization constraint test includes: the constraint function is valued at 0 The Dicker function of , the sum of the probability densities is 1; The non-negativity constraint check includes: the constraint function is greater than 0.

[0013] The present invention also provides a privacy protection device for preventing multi-server collusion, comprising: The first determining module is configured to determine a first privacy protection conversion strategy corresponding to a data type of the perturbed output according to the data type under the privacy protection perturbation mechanism; the first privacy protection conversion strategy represents a constraint relationship between a privacy protection processing form corresponding to a first privacy budget range and a privacy protection processing form corresponding to a second privacy budget range; a minimum value in the first privacy budget range is greater than a maximum value in the second privacy budget range; The first calculating module is configured to obtain a first noise value corresponding to the first privacy budget according to original data and conversion information corresponding to the first privacy budget; the first privacy budget is a privacy budget in the first privacy budget range. The second calculating module is configured to obtain a second noise value corresponding to a second privacy budget according to the first noise value and the first privacy protection conversion strategy; the second privacy budget is a privacy budget in the second privacy budget range. The second determining module is configured to determine a second privacy protection conversion strategy corresponding to a data type of the perturbed output; the second privacy protection conversion strategy represents a relationship between a noise value corresponding to the first privacy budget range, a noise value corresponding to the second privacy budget range and the original data. The third calculating module is configured to obtain a third noise value corresponding to the first privacy budget according to the original data, the second noise value and the second privacy protection conversion strategy.

[0014] The application further provides an electronic device, including a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned privacy protection method for preventing multi-server collusion when executing the program.

[0015] The application further provides a non-transitory computer readable storage medium, which stores a computer program, wherein the computer program is executable on a processor to implement the above-mentioned privacy protection method for preventing multi-server collusion.

[0016] The application further provides a computer program product, which includes a computer program, wherein the computer program is executable on a processor to implement the above-mentioned privacy protection method for preventing multi-server collusion.

[0017] The application provides a privacy protection method and device for preventing collusion of multiple servers, a device, and a medium. The method comprises the following steps: determining a privacy protection conversion strategy corresponding to a data type according to a data type output by a privacy protection disturbance mechanism; and performing noise conversion on the privacy protection conversion strategy and original data, so that noise data corresponding to a claimed privacy budget can be obtained through data reuse for data collection of any server, privacy budget consumption linear superposition caused by repeated noise addition is avoided, additional privacy budget consumption is generated, and data usability is ensured. BRIEF DESCRIPTION OF DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the present application or prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative effort.

[0019] Figure 1 is a flowchart of the privacy protection method for preventing collusion of multiple servers provided by the present application.

[0020] Figure 2 is a structural diagram of the privacy protection device for preventing collusion of multiple servers provided by the present application.

[0021] Figure 3 is a structural diagram of the privacy protection device for preventing collusion of multiple servers provided by the present application.

[0022] Figure 4 is a structural diagram of the electronic device provided by the present application. DETAILED DESCRIPTION

[0023] In order to make the purpose, technical solutions and advantages of the present application clearer, the technical solutions in the present application will be described clearly and completely in combination with the drawings in the present application. Obviously, the described embodiments are some embodiments of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative effort belong to the protection scope of the present application.

[0024] The privacy protection method, device, equipment and medium for preventing collusion of multiple servers of the present application will be described below. Figures 1-4

[0025] Figure 1 is a flowchart of the privacy protection method for preventing collusion of multiple servers provided by the present application, which is shown in Figure 1 The method comprises the following steps: ​Step 11, under the privacy protection perturbation mechanism, according to the data type of the perturbed output, determine the first privacy protection conversion strategy corresponding to the data type; the first privacy protection conversion strategy represents the constraint relationship between the privacy protection processing form corresponding to the first privacy budget range and the privacy protection processing form corresponding to the second privacy budget range; the minimum value in the first privacy budget range is greater than the maximum value in the second privacy budget range.

[0026] Step 12, according to the conversion information corresponding to the original data and the first privacy budget, obtain the first noise value corresponding to the first privacy budget; the first privacy budget is a privacy budget in the first privacy budget range.

[0027] Step 13, according to the first noise value and the first privacy protection conversion strategy, obtain the second noise value corresponding to the second privacy budget; the second privacy budget is a privacy budget in the second privacy budget range.

[0028] Step 14, according to the data type of the perturbed output, determine the second privacy protection conversion strategy corresponding to the data type; the second privacy protection conversion strategy represents the relationship between the noise value corresponding to the first privacy budget range, the noise value corresponding to the second privacy budget range and the original data.

[0029] Step 15, according to the original data, the second noise value and the second privacy protection conversion strategy, obtain the third noise value corresponding to the first privacy budget.

[0030] For steps 11 and 15, it needs to be explained that in the big data era, data collection, sharing and analysis have become the norm, and it is an important task to mine valuable information from data. How to collect data under the premise of protecting user privacy is an important problem. In terms of privacy protection, differential privacy (Differential Privacy, DP) is widely recognized as a powerful standard for privacy protection, which can provide quantitative privacy protection without assuming prior knowledge of attackers. Among them, local differential privacy (Local Differential Privacy, LDP) can provide privacy protection in the data collection stage.

[0031] For example, in order to support category type data perturbation and frequency estimation tasks, asymmetric random response (UE), GRR, SW protocol and corresponding aggregation analysis method are designed. In order to support numerical type data perturbation and mean estimation task, SR, PM protocol is designed. In order to support numerical type data perturbation and various numerical type estimation tasks, Laplace, Gaussian protocol is designed. In general, different perturbation mechanisms are designed for various types of data and aggregation analysis targets, which are used to realize LDP-compliant data collection and analysis.

[0032] The current perturbation mechanism only considers the single server scenario. But the same data can be collected by multiple servers with different privacy budgets, and direct repeated noise addition will cause the privacy budget consumption to be linearly superimposed. To this end, the present application provides a privacy protection method against collusion of multiple servers, which can realize data collection of any server using data reuse to obtain noise data corresponding to the claimed privacy budget, thereby ensuring data availability, and server collusion will not obtain additional information and cause additional privacy budget consumption. For example, noise values corresponding to a smaller privacy budget can be generated based on noise values corresponding to a larger privacy budget.

[0033] In the present application, the collected data can be divided into categorical data and numerical data. Categorical data refers to data used to represent categories or labels, such as gender, color, brand, etc. They are usually limited to a few options and cannot be mathematically operated. For example, gender is divided into male and female, and color may have red, blue, green, etc. These data are more used for grouping or classification, rather than for calculation. Numerical data, on the other hand, can be quantified and have actual numerical significance. For example, age, temperature, income, etc. These data can be mathematically operated, such as addition, subtraction, multiplication, and division, to calculate the average age or compare the high and low of two temperatures. Numerical data can be further divided into discrete and continuous types, such as the number of people, which is discrete (cannot have half a person), and temperature, which is continuous (can have decimals).

[0034] For different types, different privacy protection conversion strategies need to be configured for different privacy protection perturbation mechanisms. That is, different privacy protection conversion strategies correspond to different processing processes of the perturbation mechanism. For each processing process, the privacy protection conversion strategy fits, which can be disassembled into the corresponding privacy protection processing form.

[0035] For example, the processing process of the perturbation mechanism for categorical data under the UE perturbation mechanism can be disassembled into the form of a probability transition matrix. The processing process of the perturbation mechanism for numerical data under the Laplace perturbation mechanism can be disassembled into the Fourier form using Fourier transform. The privacy protection processing forms under different privacy budgets also have constraint relationships. Based on this, the constraint relationship between the privacy protection processing forms is constructed as a privacy protection conversion strategy. This strategy can realize data collection of any server using data reuse to obtain noise data corresponding to the claimed privacy budget from noise data of other privacy budgets.

[0036] In the present application, in differential privacy, the privacy budget (usually denoted by ε) controls the amount of noise added when querying or publishing data. The larger the ε, the weaker the privacy protection, but the data is more accurate; the smaller the ε, the stronger the protection, but the data may be less accurate. The privacy budget can be popularly understood as: under the premise of protecting personal privacy, when analyzing or publishing data, the amount of "leaked privacy information" allowed. Each time the data is analyzed, a certain amount is consumed, and when it is used up, it cannot continue to be analyzed, otherwise the risk of privacy leakage will be greater.

[0037] Since the privacy budget (usually denoted by ε) controls the amount of noise added when querying or publishing data, for this purpose, there is reasonable conversion information corresponding to each privacy budget, which can be used to determine the amount of noise of the original data. For this purpose, according to the original data and the conversion information corresponding to the first privacy budget, a first noise value corresponding to the first privacy budget is obtained. The first noise value is the data obtained by adding noise to the original data. In the present application, noise data corresponding to a larger privacy budget is generated according to noise data corresponding to a smaller privacy budget. Therefore, according to the first noise value and the first privacy protection conversion strategy, a second noise value corresponding to a second privacy budget is obtained; the second privacy budget is a privacy budget in the second privacy budget range. Since the first privacy protection conversion strategy represents the constraint relationship between the privacy protection processing form corresponding to the first privacy budget range and the privacy protection processing form corresponding to the second privacy budget range, noise data corresponding to a smaller privacy budget can be obtained based on the conversion strategy under the condition that noise data corresponding to a larger privacy budget is known.

[0038] In the present application, considering the data reuse of the true value of the original data, the true value and the noise data corresponding to a smaller privacy budget are used again to generate noise data corresponding to a larger privacy budget according to the privacy protection conversion strategy.

[0039] For this purpose, the second privacy protection conversion strategy corresponding to the data type is still determined according to the data type of the perturbed output; the second privacy protection conversion strategy represents the relationship between the noise value corresponding to the first privacy budget range, the noise value corresponding to the second privacy budget range, and the original data.

[0040] At this time, according to the original data, the second noise value, and the second privacy protection conversion strategy, a third noise value corresponding to the first privacy budget is obtained. The third noise value is noise data corresponding to a larger privacy budget.

[0041] The application provides a privacy protection method against collusion of multiple servers, which comprises the following steps: determining a privacy protection conversion strategy corresponding to a data type according to a data type of a disturbance output under a privacy protection disturbance mechanism, and performing noise conversion on the privacy protection conversion strategy and original data, so as to achieve the purpose that data reuse is used to realize that data collection of any server can obtain noise data corresponding to a claimed privacy budget, avoid linear superposition of privacy budget consumption caused by repeated noise addition, produce additional privacy budget consumption, and ensure data availability.

[0042] In a further method of the above method, when the privacy protection disturbance mechanism is a UE disturbance mechanism, and the data type of the disturbance output is category type data, the processing procedure of the disturbance mechanism for the category type data is correspondingly disassembled into a form of a probability transition matrix, and two probability transition matrices corresponding to different privacy budgets are obtained.

[0043] For a bit of a category type data, if the bit is 1, the UE keeps the bit as 1 with a probability of and flips it to 0 with a probability of if the bit is 0, the UE flips the bit to 1 with a probability of and keeps it as 0 with a probability of and are conversion information of the privacy budget.

[0044] The UE provides a privacy protection level of 、 are the and values corresponding to a first privacy budget , , are the and values corresponding to a second privacy budget .

[0045] is a probability transition matrix corresponding to the first privacy budget , is a probability transition matrix corresponding to the second privacy budget ; and A is a constraint matrix.

[0046] The probability transition matrix and the multiplication constraint of the UE can be formalized as follows: Solving the formalized matrix above. By solving the multiplication constraint, the corresponding matrix can be obtained as follows. The meaning is that the first noise value 0 is kept with a probability of ​​The probability of flipping to 1, otherwise it remains 0; the first noise value 1 is The probability remains 1, otherwise it flips to 0.

[0047] During the solution process, constraint checking is required.

[0048] Normalization constraint test. It can be seen that the sum of each row of the obtained matrix is ​​1, which satisfies the normalization constraint.

[0049] Non-negativity constraint test. , there is a UE mechanism According to the above constraints, it can be proved that , satisfying the non-negativity constraint.

[0050] From the above, we can see that the constraint matrix is ​​determined based on the first privacy protection conversion strategy, the conversion information of the privacy budget, and the configured normalization constraints and non-negativity constraints; and the second noise value is obtained based on the first noise value and the constraint matrix.

[0051] In the present invention, the establishment and solution of the true value constraint is used to realize the generation of the noise value corresponding to the first privacy budget based on the noise value corresponding to the second privacy budget and the original data under the UE mechanism. Assume that the function to achieve this generation goal is , is the corresponding noise value, is the original data. According to the structural form of the constraint matrix, it is considered that Can be When The probability remains unchanged; When The probability remains unchanged; When The probability remains unchanged; When The probability of remains unchanged. In order to meet the distribution requirements and privacy requirements, it can be expressed as the left side of the following formula, and The value corresponding to the function's process is expressed as the right side of the following formula.

[0052] Therefore, we can see that based on the original data, the second noise value, and the probability value on the right side of the above formula, we can obtain the third noise value corresponding to the first privacy budget. This third noise value is the noise data with a larger privacy budget.

[0053] In a further method of the above method, when the privacy-preserving perturbation mechanism is a Laplace perturbation mechanism, and the data type of the perturbation output is numerical data, the core of the Laplace mechanism is to generate a random number that conforms to the Laplace probability density function. adding to the original data to obtain a noise value, denotes a random number obeys a Laplace probability density function, wherein is conversion information of a privacy budget, is a sensitivity, is the privacy budget; a Fourier form of the Laplace probability density function is ; let and be values corresponding to a first privacy budget and a second privacy budget respectively.

[0054] The Fourier form of the Laplace and the convolution constraint can be formalized as follows: .

[0055] Solving the Fourier formalized function described above, it can be obtained that is a constraint function, indicating that the first noise value is kept unchanged with a probability of , and the first noise value is added with a random number with a probability of , In the solving process, constraint checking needs to be performed.

[0056] The normalization constraint checking includes that the Dirac function of the constraint function is 1 at 0, and the sum of the probability densities is 1; The non-negativity constraint checking includes that the constraint function is greater than 0.

[0057] It can be known from the above that the constraint function is determined according to the first privacy protection conversion strategy, the conversion information of the privacy budget and the configured normalization constraint and non-negativity constraint; and the second noise value is obtained according to the first noise value and the constraint function.

[0058] In the present application, the posterior probability calculation is used to realize that, under the Laplace mechanism, the third noise value corresponding to the first privacy budget is generated according to the second noise value corresponding to the second privacy budget and the original data , and are respectively a random number added to the original data under the first privacy budget and a random number added to the original data under the second privacy budget The random number is a random number of the first privacy budget. According to the previous constraint function result and the posterior probability, the corresponding probability density function can be obtained as shown in the following formula: The application is aimed at category data, and a matrix-based data reuse is constructed to generate noise category data corresponding to a smaller privacy budget according to noise category data corresponding to a larger privacy budget. For numerical data, a Fourier transform-based data reuse is constructed to generate noise numerical data corresponding to a smaller privacy budget according to noise numerical data corresponding to a larger privacy budget. The application constructs a data reuse considering real values, and generates noise data corresponding to a larger privacy budget according to real values and noise data corresponding to a smaller privacy budget by using privacy constraints, distribution constraints and posterior probabilities.

[0059] The anti-multi-server collusion privacy protection device provided by the application is described below. The anti-multi-server collusion privacy protection device described below can be correspondingly referred to the anti-multi-server collusion privacy protection method described above.

[0060] Figure 2 The structure schematic diagram of the anti-multi-server collusion privacy protection device provided by the application is shown, referring to Figure 2 The device comprises a first determination module 21, a first calculation module 22, a second calculation module 23, a second determination module 24 and a third calculation module 25, wherein: The first determination module is configured to determine a first privacy protection conversion strategy corresponding to a data type according to a data type of a disturbance output under a privacy protection disturbance mechanism; the first privacy protection conversion strategy represents a constraint relationship between a privacy protection processing form corresponding to a first privacy budget range and a privacy protection processing form corresponding to a second privacy budget range; a minimum value in the first privacy budget range is greater than a maximum value in the second privacy budget range; The first calculation module is configured to obtain a first noise value corresponding to the first privacy budget according to original data and conversion information corresponding to the first privacy budget; the first privacy budget is a privacy budget in the first privacy budget range; The second calculation module is configured to obtain a second noise value corresponding to the second privacy budget according to the first noise value and the first privacy protection conversion strategy; the second privacy budget is a privacy budget in the second privacy budget range; The second determination module is configured to determine a second privacy protection conversion strategy corresponding to a data type according to a data type of a disturbance output; the second privacy protection conversion strategy represents a relationship between a noise value corresponding to the first privacy budget range, a noise value corresponding to the second privacy budget range and the original data; The third calculation module is configured to obtain a third noise value corresponding to the first privacy budget according to the original data, the second noise value and the second privacy protection conversion strategy.

[0061] Since the device of the embodiment of the application has the same principle as the above-mentioned embodiment method, more detailed explanation will not be repeated here.

[0062] It should be noted that the related function modules in the embodiments of the application can be realized by a hardware processor.

[0063] The privacy protection device against multi-server collusion provided by the application achieves the purpose of realizing data acquisition of any server to obtain noise data corresponding to the claimed privacy budget by data reuse, avoids linear superposition of privacy budget consumption caused by repeated noise addition, produces additional privacy budget consumption, and ensures data availability.

[0064] Figure 3 The structure of the privacy protection device against multi-server collusion provided by the application is shown in the structure diagram, which is shown in FIG. 1. Figure 3 The device includes a disturbance mechanism classification module, a matrix form construction module, a matrix constraint solving module, a Fourier form construction module, an inverse Fourier transform solving module, a real value constraint establishment and solving module, and a posterior probability calculation module, wherein: The disturbance mechanism classification module is used to send the disturbance mechanism to the matrix form construction module or the Fourier form construction module according to whether the output of the disturbance mechanism is category data or numerical data. The matrix form construction module is used to convert the disturbance mechanism of the category data into a matrix form according to the first privacy budget and the second privacy budget, construct a first privacy protection conversion strategy, and send it to the matrix constraint solving module. The matrix constraint solving module is used to perform matrix solving to obtain a constraint matrix, and then perform normalization constraint inspection and non-negativity constraint inspection on the constraint matrix. If the inspection passes, the second noise value corresponding to the second privacy budget is obtained according to the first noise value corresponding to the first privacy budget and the constraint matrix, and the second noise value is sent to the real value constraint establishment and solving module. The real value constraint establishment and solving module is used to express the constraint according to the distribution requirement and the privacy requirement, use the second noise value sent by the matrix constraint solving module, and obtain the third noise value corresponding to the first privacy budget according to the original data, the second noise value, and the second privacy protection conversion strategy. The Fourier form construction module is used to convert the disturbance mechanism of the numerical data into a Fourier form according to the first privacy budget and the second privacy budget, construct a first privacy protection conversion strategy, and send it to the inverse Fourier transform solving module. The inverse Fourier transform solving module is configured to perform inverse Fourier transform to obtain a constraint function, and then perform normalization constraint test and non-negativity constraint test on the constraint function, and if the test is passed, obtain a second noise value corresponding to a second privacy budget according to a first noise value corresponding to a first privacy budget and the constraint function, and send the second noise value to the posterior probability calculation module; The posterior probability calculation module is configured to obtain a third noise value corresponding to the first privacy budget according to the original data, the second noise value and a second privacy protection conversion strategy by using the second noise value sent by the inverse Fourier transform solving module according to the probability density functions corresponding to the two different privacy budgets and the posterior probability formula.

[0065] The privacy protection device provided by the application can achieve the purpose of obtaining noise data corresponding to the claimed privacy budget by using data multiplexing to realize data acquisition of any server, avoid linear superposition of privacy budget consumption caused by repeated noise addition, produce additional privacy budget consumption, and ensure data availability.

[0066] Figure 4 An example of an entity structure diagram of an electronic device is shown in FIG. 1. Figure 4As shown, the electronic device can include a processor 41, a communications interface 42, a memory 43, and a communications bus 44, wherein the processor 41, the communications interface 42, and the memory 43 communicate with each other through the communications bus 44. The processor 41 can invoke the logic instructions in the memory 43 to execute the anti-multiple-server collusion privacy protection method, which includes: under a privacy protection perturbation mechanism, determining a first privacy protection conversion strategy corresponding to a data type according to a perturbed output data type; the first privacy protection conversion strategy represents a constraint relationship between a privacy protection processing form corresponding to a first privacy budget range and a privacy protection processing form corresponding to a second privacy budget range; the minimum value in the first privacy budget range is greater than the maximum value in the second privacy budget range, obtaining a first noise value corresponding to the first privacy budget according to the original data and the conversion information corresponding to the first privacy budget; the first privacy budget is a privacy budget in the first privacy budget range, obtaining a second noise value corresponding to a second privacy budget according to the first noise value and the first privacy protection conversion strategy; the second privacy budget is a privacy budget in the second privacy budget range, determining a second privacy protection conversion strategy corresponding to the data type according to the perturbed output data type; the second privacy protection conversion strategy represents a relationship between the noise value corresponding to the first privacy budget range, the noise value corresponding to the second privacy budget range, and the original data, and obtaining a third noise value corresponding to the first privacy budget according to the original data, the second noise value, and the second privacy protection conversion strategy.

[0067] In addition, the logic instructions in the memory 43 described above can be implemented in the form of a software functional unit and sold or used as an independent product, which can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application essentially or the part that contributes to the prior art or part of the technical solutions can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the method described in various embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.

[0068] In another aspect, the present application also provides a computer program product comprising a computer program, which can be stored on a non-transitory computer-readable storage medium, and the computer program, when executed by a processor, enables a computer to perform the privacy protection method against collusion of multiple servers provided by the above method, which comprises: under a privacy protection perturbation mechanism, determining a first privacy protection conversion strategy corresponding to a data type of perturbed output data according to the data type; the first privacy protection conversion strategy representing a constraint relationship between a privacy protection processing form corresponding to a first privacy budget range and a privacy protection processing form corresponding to a second privacy budget range; a minimum value in the first privacy budget range being greater than a maximum value in the second privacy budget range, obtaining a first noise value corresponding to the first privacy budget according to original data and conversion information corresponding to the first privacy budget; the first privacy budget being a privacy budget in the first privacy budget range, obtaining a second noise value corresponding to a second privacy budget according to the first noise value and the first privacy protection conversion strategy; the second privacy budget being a privacy budget in the second privacy budget range, determining a second privacy protection conversion strategy corresponding to the data type of the perturbed output data according to the data type; the second privacy protection conversion strategy representing a relationship between the noise value corresponding to the first privacy budget range, the noise value corresponding to the second privacy budget range and the original data, and obtaining a third noise value corresponding to the first privacy budget according to the original data, the second noise value and the second privacy protection conversion strategy.

[0069] In another aspect, the present application also provides a non-transitory computer-readable storage medium having a computer program stored thereon, and the computer program, when executed by a processor, enables a computer to perform the privacy protection method against collusion of multiple servers provided by the above method, which comprises: under a privacy protection perturbation mechanism, determining a first privacy protection conversion strategy corresponding to a data type of perturbed output data according to the data type; the first privacy protection conversion strategy representing a constraint relationship between a privacy protection processing form corresponding to a first privacy budget range and a privacy protection processing form corresponding to a second privacy budget range; a minimum value in the first privacy budget range being greater than a maximum value in the second privacy budget range, obtaining a first noise value corresponding to the first privacy budget according to original data and conversion information corresponding to the first privacy budget; the first privacy budget being a privacy budget in the first privacy budget range, obtaining a second noise value corresponding to a second privacy budget according to the first noise value and the first privacy protection conversion strategy; the second privacy budget being a privacy budget in the second privacy budget range, determining a second privacy protection conversion strategy corresponding to the data type of the perturbed output data according to the data type; the second privacy protection conversion strategy representing a relationship between the noise value corresponding to the first privacy budget range, the noise value corresponding to the second privacy budget range and the original data, and obtaining a third noise value corresponding to the first privacy budget according to the original data, the second noise value and the second privacy protection conversion strategy.

[0070] The device embodiments described above are merely illustrative, wherein the units described as separate components can or can not be physically separated, and the components displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed to multiple network units. Part or all of the modules can be selected to achieve the purpose of the embodiment scheme according to actual needs. Those skilled in the art can understand and implement it without creative labor.

[0071] Through the description of the above embodiments, those skilled in the art can clearly understand that the embodiments can be realized by means of software and the necessary general hardware platform, and of course can also be realized by hardware. Based on such understanding, the above technical solutions can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, etc., and includes a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods described in each embodiment or some parts of the embodiments.

[0072] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A privacy protection method against multi-server collusion, characterized in that: include: Under the privacy-preserving perturbation mechanism, determining, according to the data type of the perturbation output, a first privacy-preserving conversion strategy corresponding to the data type; The first privacy-preserving conversion strategy represents a constraint relationship between a privacy-preserving processing form corresponding to a first privacy budget range and a privacy-preserving processing form corresponding to a second privacy budget range; a minimum value within the first privacy budget range is greater than a maximum value within the second privacy budget range; Obtaining a first noise value corresponding to the first privacy budget based on the original data and conversion information corresponding to the first privacy budget; the first privacy budget is a privacy budget within the first privacy budget range; Obtaining a second noise value corresponding to a second privacy budget according to the first noise value and the first privacy protection conversion strategy; the second privacy budget is a privacy budget within the second privacy budget range; Determining, based on a data type of the perturbation output, a second privacy-preserving conversion strategy corresponding to the data type; the second privacy-preserving conversion strategy characterizing a relationship between a noise value corresponding to the first privacy budget range, a noise value corresponding to the second privacy budget range, and the original data; A third noise value corresponding to the first privacy budget is obtained according to the original data, the second noise value, and the second privacy protection conversion strategy.

2. The privacy protection method against multi-server collusion according to claim 1, characterized in that: When the privacy-preserving perturbation mechanism is an asymmetric random response perturbation mechanism, and the data type of the perturbation output is categorical data, the first privacy-preserving conversion strategy accordingly includes: Among them, for a bit 0 / 1 of a category data, if the bit is 1, the UE The probability of keeping the bit at 1 is The probability of flipping to 0; if the bit is 0, UE The probability of flipping the bit to 1 is The probability remains 0, and The value is the conversion information of the privacy budget; 、 To correspond to the first privacy budget of and value, , To correspond to the second privacy budget of and value; To correspond to the first privacy budget The probability transfer matrix, To correspond to the second privacy budget The probability transfer matrix; A is the constraint matrix; Accordingly, obtaining a second noise value corresponding to a second privacy budget according to the first noise value and the first privacy protection conversion strategy includes: Determine a constraint matrix according to the first privacy-preserving conversion strategy, conversion information of the privacy budget, a pre-configured normalization constraint, and a pre-configured non-negativity constraint; Obtaining the second noise value according to the first noise value and the constraint matrix; The constraint matrix includes: Wherein, the first noise value 0 is The probability of flipping to 1, otherwise it remains 0; the first noise value 1 is The probability remains 1, otherwise it flips to 0.

3. The privacy protection method against multi-server collusion according to claim 2, characterized in that: The second privacy protection conversion strategy includes: in, To correspond to the second privacy budget The second noise value, For the original data, When The probability remains unchanged; When The probability remains unchanged; When The probability remains unchanged; When The probability remains unchanged.

4. The privacy protection method against multi-server collusion according to claim 2, characterized in that: Pre-configured normalization constraints and non-negativity constraints include: Normalization constraint checks include: the sum of each row of the constraint matrix is ​​1; Non-negativity constraint checks include: , there is a UE mechanism 5. The privacy protection method against multi-server collusion according to claim 1, characterized in that: When the privacy-preserving perturbation mechanism is a Laplace perturbation mechanism, and the data type of the perturbation output is numerical data, the first privacy-preserving conversion strategy accordingly includes: Among them, a random number that conforms to the Laplace probability density function Added to the original data to get the noise value, , representing a random number Obey the Laplace probability density function, where , is the conversion information of privacy budget, For sensitivity, is the privacy budget; the Fourier form of the Laplace probability density function is ;make and They correspond to the first privacy budget respectively and the Second Privacy Budget of value; is the constraint function, which means The probability of keeping the first noise value unchanged is The probability of adding a random number to the first noise value , . Accordingly, obtaining a second noise value corresponding to a second privacy budget according to the first noise value and the first privacy protection conversion strategy includes: Determine a constraint function according to the first privacy-preserving conversion strategy, conversion information of the privacy budget, a pre-configured normalization constraint, and a pre-configured non-negativity constraint; The second noise value is obtained according to the first noise value and the constraint function.

6. The privacy protection method against multi-server collusion according to claim 5, characterized in that: The second privacy protection conversion strategy includes: Among them, according to the corresponding second privacy budget The second noise value and original data Generate the corresponding first privacy budget The third noise value , and First Privacy Budget Add the following to the original data Random numbers, second privacy budget Add the following to the original data A random number.

7. The privacy protection method against multi-server collusion according to claim 5, characterized in that: Pre-configured normalization constraints and non-negativity constraints include: Normalization constraint test includes: the constraint function is valued at 0 The Dicker function of , the sum of the probability densities is 1; Non-negativity constraint checking includes: the constraint function is greater than 0.

8. A privacy protection device for preventing multi-server collusion, characterized in that: include: A first determining module is configured to determine, according to the data type of the perturbation output, a first privacy protection conversion strategy corresponding to the data type under the privacy protection perturbation mechanism; The first privacy-preserving conversion strategy represents a constraint relationship between a privacy-preserving processing form corresponding to a first privacy budget range and a privacy-preserving processing form corresponding to a second privacy budget range; a minimum value within the first privacy budget range is greater than a maximum value within the second privacy budget range; a first calculation module, configured to obtain a first noise value corresponding to the first privacy budget based on the original data and conversion information corresponding to the first privacy budget; the first privacy budget being a privacy budget within the first privacy budget range; a second calculation module, configured to obtain a second noise value corresponding to a second privacy budget according to the first noise value and the first privacy protection conversion strategy; the second privacy budget being a privacy budget within the second privacy budget range; A second determining module, configured to determine, according to a data type of the perturbation output, a second privacy protection conversion strategy corresponding to the data type; The second privacy protection conversion strategy represents the relationship between the noise value corresponding to the first privacy budget range, the noise value corresponding to the second privacy budget range, and the original data; A third calculation module is configured to obtain a third noise value corresponding to the first privacy budget based on the original data, the second noise value, and the second privacy protection conversion strategy.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the privacy protection method for preventing multi-server collusion as described in any one of claims 1 to 7 is implemented.

10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the privacy protection method for preventing multi-server collusion as described in any one of claims 1 to 7 is implemented.