A method, apparatus, and device for processing information
The privacy protection model trained by joint discriminator processes the bypass information of the deep learning model, determines the information type and applies matching processing strategies, solving the problem of key information leakage model in the existing technology, and achieving more effective privacy protection.
Patent Information
- Application Number
- CN202210428192.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-22
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2042-04-22
AI Technical Summary
In the prior art, the privacy protection method of deep learning models only protects key information defined in advance, and attackers can still obtain key information of the model through bypass information, resulting in privacy leakage.
The joint discriminator is used as the privacy protection model, and the target model's bypass information samples and preset loss functions are trained, and historical bypass information is obtained and processed, information types are determined and matching processing strategies are applied, and the bypass information is disturbed to protect model privacy.
While ensuring the accuracy of bypass information, disturbing bypass information makes it impossible for attackers to obtain key information of the model by analyzing bypass information, improving the privacy protection effect of the model.
Smart Images

Figure CN114741729B_ABST
Abstract
Description
Technical Field
[0001] This document relates to the field of computer technology, and particularly to a method, apparatus, and device for processing information. Background Art
[0002] In recent years, artificial intelligence technology has been widely used. For example, biometric technology, specifically access control devices based on face recognition or fingerprint recognition, face recognition payment, and FaceID unlocking, etc. Taking biometric technology as an example, the core part of most biometric systems is a deep learning model. Therefore, if the deep learning model is leaked (for example, if the structure and function of the target model are located, the target model is more likely to be cracked), it will cause losses to the property and information of users and merchants.
[0003] Currently, the privacy protection method for deep learning models usually directly protects the key information of the deep learning model (such as the structure of the deep learning model, the weights of the deep learning model, and the functions of the deep learning model, etc.). For example, the structure and weights of the deep learning model are obfuscated and encrypted, making it difficult to analyze and obtain the structure and weights of the deep learning model. However, the above method only protects some pre-defined key information of machine learning models, and moreover, in addition to key information, the deep learning model also includes other information. Attackers may also obtain the key information of the deep learning model through the acquisition, analysis, and analysis of the above information. Based on this, a technical solution for protecting the privacy of the bypass information corresponding to the model is needed to prevent the bypass information from causing the leakage of the key information of the model. Summary of the Invention
[0004] The purpose of the embodiments of this specification is to provide a technical solution for protecting the privacy of the bypass information corresponding to the model to prevent the bypass information from causing the leakage of the key information of the model.
[0005] To achieve the above technical solution, the embodiments of this specification are implemented as follows:
[0006] A method for processing information provided by an embodiment of this specification, the method includes: obtaining historical bypass information corresponding to a target model to be protected, where the historical bypass information is unencrypted historical information generated during the operation of the target model or historical information that is easily obtained and does not require information protection processing during the operation of the target model. Based on the historical bypass information and a pre-trained privacy protection model, perform privacy protection processing on the historical bypass information to obtain privacy-protected bypass information, where the privacy protection model is a joint discriminator and is obtained by training a model using bypass information samples of the target model and a preset loss function. When the target model is running, obtain the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and based on the obtained information type, determine a bypass information processing strategy that matches the information type. Based on the bypass information processing strategy that matches the information type and the privacy-protected bypass information, process the bypass information corresponding to the currently running target model to protect the bypass information corresponding to the currently running target model.
[0007] A method for processing information provided by an embodiment of this specification, which is applied to a server, the method includes: obtaining historical bypass information corresponding to a target model to be protected, where the historical bypass information is unencrypted historical information generated during the operation of the target model or historical information that is easily obtained and does not require information protection processing during the operation of the target model. Based on the historical bypass information and a pre-trained privacy protection model, perform privacy protection processing on the historical bypass information to obtain privacy-protected bypass information, where the privacy protection model is a joint discriminator and is obtained by training a model using bypass information samples of the target model and a preset loss function. Send the privacy-protected bypass information to a target device deployed with the target model, where the privacy-protected bypass information is used to trigger the target device to obtain the information type to which the information included in the bypass information corresponding to the currently running target model belongs when running the target model, and based on the obtained information type, determine a bypass information processing strategy that matches the information type. Based on the bypass information processing strategy that matches the information type and the privacy-protected bypass information, process the bypass information corresponding to the currently running target model to protect the bypass information corresponding to the currently running target model.
[0008] A method for processing information provided in an embodiment of this specification is applied to a target device on which a target model to be protected is deployed. The method includes: receiving privacy-protected bypass information sent by a server, where the privacy-protected bypass information is obtained by the server through performing privacy protection processing on historical bypass information corresponding to the target model based on the historical bypass information and a pre-trained privacy protection model. The historical bypass information is unencrypted historical information generated during the operation of the target model or historical information that is easily obtained and does not require information protection processing during the operation of the target model. The privacy protection model is a joint discriminator and is obtained by training a model through bypass information samples of the target model and a preset loss function. When the target model is running, obtain the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and based on the obtained information type, determine a bypass information processing strategy that matches the information type. Based on the bypass information processing strategy that matches the information type and the privacy-protected bypass information, process the bypass information corresponding to the currently running target model to protect the bypass information corresponding to the currently running target model.
[0009] An information processing device provided in an embodiment of this specification includes: a historical information acquisition module that acquires historical bypass information corresponding to a target model to be protected, where the historical bypass information is unencrypted historical information generated during the operation of the target model or historical information that is easily obtained and does not require information protection processing during the operation of the target model. A privacy protection module that performs privacy protection processing on the historical bypass information based on the historical bypass information and a pre-trained privacy protection model to obtain privacy-protected bypass information, where the privacy protection model is a joint discriminator and is obtained by training a model through bypass information samples of the target model and a preset loss function. A strategy acquisition module that, when the target model is running, acquires the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and based on the obtained information type, determines a bypass information processing strategy that matches the information type. A bypass information processing module that processes the bypass information corresponding to the currently running target model based on the bypass information processing strategy that matches the information type and the privacy-protected bypass information to protect the bypass information corresponding to the currently running target model.
[0010] An information processing device provided in an embodiment of this specification, the device includes: a historical information acquisition module, which acquires historical bypass information corresponding to a target model to be protected, and the historical bypass information is unencrypted historical information generated during the operation of the target model or historical information that is easily acquired and does not require information protection processing during the operation of the target model. A privacy protection module, which performs privacy protection processing on the historical bypass information based on the historical bypass information and a pre-trained privacy protection model to obtain privacy-protected bypass information, and the privacy protection model is a joint discriminator, and is obtained by training the model through bypass information samples of the target model and a preset loss function. An information sending module, which sends the privacy-protected bypass information to a target device deployed with the target model, and the privacy-protected bypass information is used to trigger the target device to obtain the information type to which the information included in the bypass information corresponding to the currently running target model belongs when running the target model, and based on the obtained information type, determine a bypass information processing strategy matching the information type, and based on the bypass information processing strategy matching the information type and the privacy-protected bypass information, process the bypass information corresponding to the currently running target model to protect the bypass information corresponding to the currently running target model.
[0011] An information processing device provided in an embodiment of this specification, on which a target model to be protected is deployed, the device includes: an information receiving module, which receives the privacy-protected bypass information sent by a server, and the privacy-protected bypass information is obtained by the server performing privacy protection processing on the historical bypass information based on the historical bypass information corresponding to the target model and a pre-trained privacy protection model, and the historical bypass information is unencrypted historical information generated during the operation of the target model or historical information that is easily acquired and does not require information protection processing during the operation of the target model, and the privacy protection model is a joint discriminator, and is obtained by training the model through bypass information samples of the target model and a preset loss function. A strategy determination module, when the target model is running, acquires the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and based on the obtained information type, determines a bypass information processing strategy matching the information type. An information processing module, which processes the bypass information corresponding to the currently running target model based on the bypass information processing strategy matching the information type and the privacy-protected bypass information to protect the bypass information corresponding to the currently running target model.
[0012] An information processing device provided by an embodiment of this specification, the information processing device includes: a processor; and a memory arranged to store computer-executable instructions, the executable instructions, when executed, cause the processor to: obtain historical bypass information corresponding to a target model to be protected, the historical bypass information being unencrypted historical information generated during the operation of the target model or historical information that is easily obtained and does not require information protection processing during the operation of the target model. Based on the historical bypass information and a pre-trained privacy protection model, perform privacy protection processing on the historical bypass information to obtain privacy-protected bypass information, the privacy protection model being a joint discriminator, and being trained through bypass information samples of the target model and a preset loss function. When the target model is running, obtain the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and based on the obtained information type, determine a bypass information processing strategy matching the information type. Based on the bypass information processing strategy matching the information type and the privacy-protected bypass information, process the bypass information corresponding to the currently running target model to protect the bypass information corresponding to the currently running target model.
[0013] An information processing device provided by an embodiment of this specification, the information processing device includes: a processor; and a memory arranged to store computer-executable instructions, the executable instructions, when executed, cause the processor to: obtain historical bypass information corresponding to a target model to be protected, the historical bypass information being unencrypted historical information generated during the operation of the target model or historical information that is easily obtained and does not require information protection processing during the operation of the target model. Based on the historical bypass information and a pre-trained privacy protection model, perform privacy protection processing on the historical bypass information to obtain privacy-protected bypass information, the privacy protection model being a joint discriminator, and being trained through bypass information samples of the target model and a preset loss function. Send the privacy-protected bypass information to a target device deployed with the target model, the privacy-protected bypass information being used to trigger the target device to obtain, when running the target model, the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and based on the obtained information type, determine a bypass information processing strategy matching the information type, and based on the bypass information processing strategy matching the information type and the privacy-protected bypass information, process the bypass information corresponding to the currently running target model to protect the bypass information corresponding to the currently running target model.
[0014] An information processing device provided in an embodiment of this specification deploys a target model to be protected. The information processing device includes: a processor; and a memory arranged to store computer-executable instructions, and when the executable instructions are executed, the processor: receives privacy-protected bypass information sent by a server, where the privacy-protected bypass information is obtained by the server performing privacy protection processing on historical bypass information corresponding to the target model based on a pre-trained privacy protection model. The historical bypass information is unencrypted historical information generated during the operation of the target model or historical information that is easily obtained and does not require information protection processing during the operation of the target model. The privacy protection model is a joint discriminator and is obtained by training the model through bypass information samples of the target model and a preset loss function. When the target model is running, obtain the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and based on the obtained information type, determine a bypass information processing strategy matching the information type. Based on the bypass information processing strategy matching the information type and the privacy-protected bypass information, process the bypass information corresponding to the currently running target model to protect the bypass information corresponding to the currently running target model.
[0015] An embodiment of this specification also provides a storage medium for storing computer-executable instructions, and when the executable instructions are executed by a processor, the following process is implemented: obtain historical bypass information corresponding to a target model to be protected, where the historical bypass information is unencrypted historical information generated during the operation of the target model or historical information that is easily obtained and does not require information protection processing during the operation of the target model. Based on the historical bypass information and a pre-trained privacy protection model, perform privacy protection processing on the historical bypass information to obtain privacy-protected bypass information. The privacy protection model is a joint discriminator and is obtained by training the model through bypass information samples of the target model and a preset loss function. When the target model is running, obtain the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and based on the obtained information type, determine a bypass information processing strategy matching the information type. Based on the bypass information processing strategy matching the information type and the privacy-protected bypass information, process the bypass information corresponding to the currently running target model to protect the bypass information corresponding to the currently running target model.
[0016] An embodiment of this specification also provides a storage medium for storing computer-executable instructions. When the executable instructions are executed by a processor, the following process is implemented: obtaining historical bypass information corresponding to a target model to be protected, where the historical bypass information is historical information generated during the operation of the target model that has not been encrypted or historical information that is easily obtained and does not require information protection processing during the operation of the target model. Based on the historical bypass information and a pre-trained privacy protection model, performing privacy protection processing on the historical bypass information to obtain privacy-protected bypass information. The privacy protection model is a joint discriminator and is obtained by training the model through bypass information samples of the target model and a preset loss function. Sending the privacy-protected bypass information to a target device where the target model is deployed. The privacy-protected bypass information is used to trigger the target device to obtain the information type to which the information included in the bypass information corresponding to the currently running target model belongs when running the target model, and based on the obtained information type, determining a bypass information processing strategy matching the information type. Based on the bypass information processing strategy matching the information type and the privacy-protected bypass information, processing the bypass information corresponding to the currently running target model to protect the bypass information corresponding to the currently running target model.
[0017] An embodiment of this specification also provides a storage medium for storing computer-executable instructions. When the executable instructions are executed by a processor, the following process is implemented: receiving privacy-protected bypass information sent by a server, where the privacy-protected bypass information is obtained by the server performing privacy protection processing on historical bypass information based on historical bypass information corresponding to a target model and a pre-trained privacy protection model. The historical bypass information is historical information generated during the operation of the target model that has not been encrypted or historical information that is easily obtained and does not require information protection processing during the operation of the target model. The privacy protection model is a joint discriminator and is obtained by training the model through bypass information samples of the target model and a preset loss function. When the target model runs, obtaining the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and based on the obtained information type, determining a bypass information processing strategy matching the information type. Based on the bypass information processing strategy matching the information type and the privacy-protected bypass information, processing the bypass information corresponding to the currently running target model to protect the bypass information corresponding to the currently running target model. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] To more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments recorded in this specification. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0019] Figure 1 This is an embodiment of a method for processing information in this specification;
[0020] Figure 2 This is another embodiment of a method for processing information in this specification;
[0021] Figure 3A This is yet another embodiment of a method for processing information in this specification;
[0022] Figure 3B This is a schematic diagram of a process for processing information in this specification;
[0023] Figure 3C This is a schematic diagram of the structure of a system for processing information in this specification;
[0024] Figure 4A This is yet another embodiment of a method for processing information in this specification;
[0025] Figure 4B This is another schematic diagram of a process for processing information in this specification;
[0026] Figure 5 This is an embodiment of a device for processing information in this specification;
[0027] Figure 6 This is another embodiment of a device for processing information in this specification;
[0028] Figure 7 This is yet another embodiment of a device for processing information in this specification;
[0029] Figure 8 This is an embodiment of a device for processing information in this specification. Detailed implementation manners
[0030] The embodiments of this specification provide a method, device, and equipment for processing information.
[0031] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this specification without making creative efforts shall fall within the scope of protection of this specification.
[0032] Embodiment 1
[0033] As Figure 1 shown, the embodiment of this specification provides a method for processing information. The execution subject of this method can be a terminal device or a server. Among them, the terminal device can be a certain terminal device such as a mobile phone or a tablet computer, or a computer device such as a notebook computer or a desktop computer, or can also be an IoT device (specifically such as a smart watch or a vehicle-mounted device, etc.). The server can be an independent server or a server cluster composed of multiple servers. The server can be a background server such as a financial service or an online shopping service, or can also be a background server of a certain application program, etc. This method can specifically include the following steps:
[0034] In step S102, obtain the historical bypass information corresponding to the target model to be protected. The historical bypass information is the historical information generated during the operation of the target model that has not been encrypted or the historical information that is easily obtained and does not require information protection processing during the operation of the target model.
[0035] Among them, the target model can be a model for any user or function, such as a model for risk prevention and control, a model for biometric identification, etc. The target model can be constructed by a variety of different algorithms. For example, the target model can be constructed based on a convolutional neural network algorithm, or can also be constructed based on a classification algorithm, etc. It can be specifically set according to the actual situation, and the embodiments of this specification do not limit this. The historical bypass information is the historical information that is not encrypted during the operation of the target model or the historical information that is easily obtained (such as can be obtained without any restrictive conditions or additional conditions, etc.) and does not require information protection processing during the operation of the target model. The historical bypass information can be information that is not strongly related to the privacy information (or called key information) of the target model. For the target model, the historical bypass information can include, for example, the historical running duration of the target model, the historical memory difference between when the target model is running and when it is not running (that is, the memory occupied when the target model is running), the historical volume of the target model, the historical size of the input image of the target model, the historical size of the output image of the target model, the number of times the target model runs in a historical request, etc. It can also be specifically set according to the actual situation. Correspondingly, the key information (or privacy information) of the target model can include, for example, the structure of the target model, the functions of the target model (specifically such as face detection, face comparison, etc.), the weights of the target model, etc. It can also be specifically set according to the actual situation. Based on this, the bypass information can be the information that is not encrypted during the operation of the target model or the information that is easily obtained and does not require information protection processing during the operation of the target model. The bypass information can be information that is not strongly related to the privacy information (or called key information) of the target model. For the target model, the bypass information can include, for example, the running duration of the target model, the memory difference between when the target model is running and when it is not running (that is, the memory occupied when the target model is running), the volume of the target model, the size of the input image of the target model, the size of the output image of the target model, the number of times the target model runs in a request, etc. It can also be specifically set according to the actual situation.
[0036] In practice, in recent years, artificial intelligence technology has been widely used. For example, biometric technology, specifically such as access control devices based on face recognition or fingerprint recognition, face recognition payment, and FaceID unlocking, etc. Taking biometric technology as an example, the core part of most biometric systems is a deep learning model. Therefore, if the deep learning model is leaked (for example, the structure and functions of the target model are located, then the target model is more likely to be broken), it will cause losses to the property and information of users and merchants.
[0037] At present, the privacy protection method of deep learning models usually directly protects the key information of deep learning models (such as the structure of deep learning models, the weights of deep learning models, and the functions of deep learning models, etc.). For example, the structure and weights of deep learning models are confused and encrypted, making it difficult to parse and obtain the structure and weights of deep learning models. However, the above method only protects some key information of pre-defined machine learning models. Moreover, in addition to key information, deep learning models also include other information. Attackers may also obtain the key information of deep learning models through the acquisition, parsing, and analysis of the above information. Based on this, a technical solution for privacy protection of the bypass information corresponding to the model is needed to prevent the leakage of the key information of the model caused by the bypass information. The embodiments of this specification provide a feasible technical solution, which may specifically include the following content:
[0038] In order to protect the bypass information corresponding to a certain model (i.e., the target model), it is necessary to first determine the true content of the bypass information corresponding to the target model. To this end, the historical bypass information corresponding to the target model to be protected can be obtained. Specifically, the historical bypass information corresponding to the target model within a certain period of time can be obtained. Specifically, for example, the relevant information of the operating environment during the operation of the target model within the most recent 1 day (or 24 hours), and the relevant information of the operating environment before and after the start of the target model can be obtained. The information obtained above can be used as the historical bypass information corresponding to the target model within a certain period of time. In practical applications, in addition to the relevant information of the most recent 24 hours, the relevant information of time periods such as the most recent 12 hours, 5 hours, 2 days, 30 days, etc. can also be obtained. Specifically, it can be set according to the actual situation, and the embodiments of this specification do not limit this.
[0039] It should be noted that the historical bypass information obtained above can be the historical bypass information obtained from a certain device. If there are multiple devices similar to the above, the historical bypass information can be obtained from each device. Specifically, it can be set according to the actual situation, and the embodiments of this specification do not limit this.
[0040] In step S104, based on the historical bypass information and the pre-trained privacy protection model, the historical bypass information is subjected to privacy protection processing to obtain the privacy-protected bypass information. The privacy protection model is a combined discriminator and is obtained by training the model with the bypass information samples of the target model and a preset loss function.
[0041] Among them, the privacy protection model can be a model for protecting the privacy of the side-channel information corresponding to a certain model. The privacy protection model can be constructed through a variety of different algorithms. For example, the privacy protection model can be constructed through a neural network algorithm, or through a generative adversarial network (GAN) algorithm, etc. It can be specifically set according to the actual situation, and the embodiments of this specification do not limit this. The discriminator can be a model used for joint training with the privacy protection model to improve the performance of the privacy protection model. The discriminator can be constructed through a variety of different algorithms. For example, the discriminator can be constructed through a neural network algorithm, etc. It can be specifically set according to the actual situation. The discriminator and the privacy protection model are jointly trained to improve the performance of the privacy protection model. The discriminator can be used to classify information and / or process information to obtain corresponding results. The loss function can be set according to the discriminator and the privacy protection model. The loss function can be constructed through a variety of functions. For example, the loss function corresponding to the discriminator, the loss function corresponding to the privacy protection model, etc. can be used to construct the above loss function, etc. It can be specifically set according to the actual situation, and the embodiments of this specification do not limit this.
[0042] In implementation, the side-channel information samples of the target model can be obtained in a variety of different ways. Specifically, during the operation of the target model, the device running the target model can record the side-channel information corresponding to the target model. When the side-channel information samples need to be obtained, the side-channel information recorded in the above device within a certain period of time can be obtained, and the obtained side-channel information can be used as the side-channel information samples of the target model. Or, the side-channel information within a certain period of time can also be obtained from a specified database, and the obtained side-channel information can be used as the side-channel information samples of the target model, etc. It can be specifically set according to the actual situation, and the embodiments of this specification do not limit this. In addition, the loss function can also be set according to the actual situation, as well as the algorithms for constructing the privacy protection model and the discriminator. The model architectures of the privacy protection model and the discriminator can be constructed respectively. Then, based on the above-obtained side-channel information samples and the preset loss function, model training can be performed to obtain the trained privacy protection model and the trained discriminator.
[0043] After obtaining the historical bypass information through the above method, the historical bypass information can be input into the trained privacy protection model, so that the trained privacy protection model performs privacy protection processing on the historical bypass information to obtain the bypass information after privacy protection. Alternatively, the historical bypass information can be subjected to specified processing to obtain the processed historical bypass information, and the processed historical bypass information can be input into the trained privacy protection model, so that the trained privacy protection model performs privacy protection processing on the historical bypass information to obtain the bypass information after privacy protection. For example, through statistics, it can be obtained that the volume of the model included in the historical bypass information is 10, and the memory occupied during the operation of the model is 20%. Then, through the processing of the above privacy protection model, the bypass information after privacy protection can be obtained as the volume of the model is 18, and the memory occupied during the operation of the model is 46%, etc.
[0044] In step S106, when the target model is running, obtain the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and based on the obtained information type, determine a bypass information processing strategy that matches the information type.
[0045] Among them, the information type can be, for example, the volume of the model, the memory occupied during the operation of the model, etc., and can be specifically set according to the actual situation, and the embodiments of this specification do not limit this. The bypass information processing strategy can be a strategy for processing the bypass information that does not meet the specified conditions to make it meet the specified conditions, and the specified conditions can be set according to the actual situation, and the embodiments of this specification do not limit this. The bypass information processing strategy is specifically, for example, if the volume of the model does not reach volume V, then add random data to the model so that the volume of the model reaches V.
[0046] In implementation, when the target model is running, the bypass information corresponding to the currently running target model can be collected. Specifically, for example, the volume during the operation of the target model, the memory occupied during the operation of the model, and other bypass information can be obtained. The bypass information can be divided into one or more information types according to the actual situation. Then, when the target model is running, the collected bypass information can be analyzed to determine which information type each bypass information belongs to, so as to determine the information type to which the information included in the bypass information corresponding to the currently running target model belongs. In addition, a corresponding bypass information processing strategy can be set for the bypass information of each information type, so that based on the determined information type, the bypass information processing strategy corresponding to each information type can be obtained.
[0047] In step S108, based on the bypass information processing strategy that matches the information type and the bypass information after privacy protection, process the bypass information corresponding to the currently running target model to protect the bypass information corresponding to the currently running target model.
[0048] In implementation, after obtaining the bypass information processing strategy matching the information type and the bypass information after privacy protection through the above method, the bypass information after privacy protection can be used as the reference information (or standard information). When the subsequent target model runs, the bypass information during operation uses the bypass information after privacy protection as the reference information or standard information, so that the bypass information during the subsequent target model operation needs to meet the above reference information or standard information. Based on this, each information type included in the bypass information corresponding to the currently running target model can be compared or matched with the above reference information respectively. If the information of a certain information type included in the bypass information corresponding to the currently running target model does not match the above reference information, the bypass information processing strategy matching the information type can be obtained to process the information of this information type, and the bypass information matching the above reference information can be obtained. Similarly, the information of other information types can also be processed in the above way. Finally, it can be ensured that each information type included in the bypass information corresponding to the currently running target model meets the above reference information, thereby achieving the purpose of protecting the bypass information corresponding to the currently running target model.
[0049] The embodiment of the present specification provides a method for processing information. By obtaining the historical bypass information corresponding to the target model to be protected, based on the historical bypass information and a pre-trained privacy protection model, the historical bypass information is subjected to privacy protection processing to obtain the bypass information after privacy protection. The privacy protection model is a joint discriminator, which is obtained by training the model through the bypass information samples of the target model and a preset loss function. Based on this, when the target model runs, the information type to which the information included in the bypass information corresponding to the currently running target model belongs is obtained, and based on the obtained information type, the bypass information processing strategy matching the information type is determined. Based on the bypass information processing strategy matching the information type and the bypass information after privacy protection, the bypass information corresponding to the currently running target model is processed to protect the bypass information corresponding to the currently running target model. In this way, the bypass information corresponding to the target model is protected by the privacy protection model. While ensuring a certain accuracy of the bypass information (the bypass information needs to ensure a certain accuracy, such as data like time consumption; because the bypass information is often some important indicators for performance analysis), the bypass information is perturbed so that the attacker cannot obtain the key information of the target model by analyzing the bypass information.
[0050] Embodiment 2
[0051] Such as Figure 2As shown in the figure, an embodiment of this specification provides a method for processing information. The execution subject of this method may be a terminal device or a server. Among them, the terminal device may be a certain terminal device such as a mobile phone or a tablet computer, or may also be a computer device such as a laptop or a desktop computer. Or, it may also be an IoT device (specifically such as a smart watch or a vehicle-mounted device, etc.). The server may be an independent server, or may also be a server cluster composed of multiple servers. The server may be a background server such as a financial service or an online shopping service, or may also be a background server of a certain application program, etc. The method may specifically include the following steps:
[0052] In step S202, obtain a bypass information sample of the target model.
[0053] Among them, the target model may be a model for biometric processing, specifically such as a face recognition model, a fingerprint recognition model, a palmprint recognition model, or an iris recognition model, etc. The target model can be constructed in various ways. For example, it can be constructed through a neural network model, or can also be constructed through other deep learning models, which can be specifically set according to the actual situation. The embodiments of this specification do not limit this.
[0054] In practice, different users can perform biometric processing through the target model, and can record the bypass information generated during the biometric processing. When it is necessary to obtain a bypass information sample of the target model, the above-generated bypass information can be obtained as the bypass information sample of the target model, or the bypass information of the target model can be obtained from a specified database, and the obtained bypass information can be used as the bypass information sample of the target model, which can be specifically set according to the actual situation. The embodiments of this specification do not limit this.
[0055] In step S204, input the above bypass information sample into the privacy protection model to obtain a privacy-protected bypass information sample.
[0056] Among them, the privacy protection model is constructed through a multi-layer perceptron MLP. In the MLP, except for the input layer and the output layer, it can have multiple hidden layers in the middle. The simplest MLP only contains one hidden layer, that is, a three-layer structure. The layers of the MLP are fully connected. The bottom layer of the MLP is the input layer, the middle is the hidden layer, and the last is the output layer. The privacy protection model can specifically be constructed by a three-layer MLP, which can be specifically set according to the actual situation. The embodiments of this specification do not limit this. The privacy protection model can achieve deep differential privacy protection for data, that is, the input of the privacy protection model is bypass information, and the output is the privacy-protected bypass information. The privacy protection model plays a role in differential privacy protection.
[0057] In step S206, the above bypass information sample and the privacy-protected bypass information sample are input into the discriminator to obtain corresponding output results, and based on the output results and a preset loss function, it is determined whether the privacy protection model and the discriminator converge. If not, the privacy protection model and the discriminator are continuously trained based on the bypass information sample and the loss function until the privacy protection model and the discriminator converge, obtaining the trained privacy protection model. The output results include whether the bypass information sample has undergone privacy protection processing and the prediction results of the key information of the target model. The key information of the target model includes the structure and function of the target model.
[0058] Among them, the discriminator is constructed by a multi-layer perceptron MLP. Specifically, for example, the discriminator can be constructed by a three-layer MLP, etc., which can be specifically set according to the actual situation, and the embodiments of this specification do not limit this. The input of the discriminator is the bypass information before privacy protection and the bypass information after privacy protection. The output of the discriminator consists of two parts. The first part is the binary classification result, that is, to judge whether the input data is data that has undergone privacy protection. The second part is the prediction result of the key information of the target model, that is, in the form of classification, to predict the structure and function of the target model (the weights of the target model cannot be predicted, so they are not included).
[0059] In addition, the loss function can be composed of one or more of the distribution function of the bypass information, the adversarial loss function, the key information prediction loss function, and the loss function based on the prior margin. The distribution function of the bypass information can be determined based on minimizing the data distribution between the bypass information sample and the privacy-protected bypass information sample. The adversarial loss function is determined based on the accuracy of the output result of whether the bypass information sample has undergone privacy protection processing. Specifically, for the binary classification result of the first part of the discriminator, it is required that the classification accuracy of the first part of the discriminator is as close as possible to 50% (that is, the difference from 50% is within the preset threshold range). The key information prediction loss function is determined based on the accuracy of the prediction result of the key information of the target model. Specifically, for the data after privacy protection, the accuracy of key information prediction should be as low as possible to achieve the effect of privacy protection. The loss function based on the prior margin is determined based on the difference between the bypass information sample and the privacy-protected bypass information sample being less than the preset margin. Specifically, for each bypass information, a prior margin is given, and it is required that the difference between the privacy-protected bypass information and the bypass information before privacy protection is less than the margin.
[0060] It should be noted that after constructing the privacy protection model in the above manner, the privacy protection model can be deployed in a specified device, such as it can be deployed in a server or a terminal device, etc., which can be specifically set according to the actual situation, and the embodiments of this specification do not limit this.
[0061] In step S208, obtain the historical bypass information corresponding to the target model to be protected, where the historical bypass information is the unencrypted historical information generated during the operation of the target model or the historical information that is easily obtained and does not require information protection processing during the operation of the target model.
[0062] In practice, for multiple devices running the target model, the historical bypass information corresponding to the target model within a certain period (such as within 24 hours, etc.) can be obtained from each device. For specific details, please refer to the foregoing content and will not be elaborated here.
[0063] In step S210, calculate the average value of the information of different information types included in the historical bypass information respectively.
[0064] In practice, for example, for the information type of the volume of the target model, if the volumes of the target model within 24 hours are 10, 15, 16, 18, 20, 12, 14, 15, 16, and 17, then the average value of the information of this information type is 15.3. In the same way, the average values of the information of other information types can be calculated respectively, so as to obtain the average values of the information of different information types included in the historical bypass information.
[0065] In step S212, input the average values of the information of different information types included in the calculated historical bypass information into the pre-trained privacy protection model to obtain the privacy-protected bypass information.
[0066] In practice, for example, the average value 15.3 corresponding to the information type of the volume of the target model can be input into the privacy protection model. Through the processing of the privacy protection model, privacy-protected bypass information such as 18 can be obtained. Specifically, it can also be set according to the actual situation. In the above way, the privacy-protected bypass information corresponding to the average values of the information of different information types included in the historical bypass information can be obtained.
[0067] In step S214, when the target model is running, obtain the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and based on the obtained information type, determine the bypass information processing strategy matching this information type.
[0068] Taking the information type including the volume of the target model as an example, the specific processing of the above step S108 can refer to the processing of the following step S216, etc.
[0069] In step S216, if the volume of the current target model is smaller than the reference volume of the target model indicated in the side-channel information after privacy protection, the volume of the current target model is expanded based on the side-channel information processing strategy matching this information type until the volume of the current target model reaches the reference volume of the target model, and the processed side-channel information is obtained.
[0070] In implementation, expanding the volume of the current target model based on the side-channel information processing strategy matching this information type may include multiple different processing methods. For example, the volume of the current target model can be expanded using random bytes until the volume of the current target model reaches the reference volume of the target model. In addition, if the volume of the current target model is not smaller than the reference volume of the target model indicated in the side-channel information after privacy protection, it may not be necessary to process the volume of the target model.
[0071] In addition, if the information type includes the memory occupied and / or the running duration when the target model runs, the specific processing in the above step S108 can be performed in the following manner: if the memory occupied when the current target model runs is smaller than the reference memory of the target model indicated in the side-channel information after privacy protection, the memory occupied when the current target model runs is expanded based on the malloc function in the side-channel information processing strategy matching the information type until the memory occupied when the current target model runs reaches the reference memory of the target model, and the processed side-channel information is obtained; and / or, if the running duration of the current target model is smaller than the reference running duration of the target model indicated in the side-channel information after privacy protection, the running duration of the current target model is expanded based on the sleep function in the side-channel information processing strategy matching this information type until the running duration of the current target model reaches the reference running duration of the target model, and the processed side-channel information is obtained.
[0072] If the memory occupied when the current target model runs is not smaller than the reference memory of the target model indicated in the side-channel information after privacy protection, it may not be necessary to process the memory occupied when the target model runs. If the running duration of the current target model is not smaller than the reference running duration of the target model indicated in the side-channel information after privacy protection, it may not be necessary to process the running duration of the target model.
[0073] In addition, if the information type includes the size of the input image of the target model and / or the size of the output image of the target model, the specific processing of step S108 above can be handled in the following manner: If the size of the input image of the current target model is smaller than the reference input image size of the target model indicated in the bypass information after privacy protection, then based on the bypass information processing strategy matching this information type, scale the size of the input image of the target model until the size of the input image of the current target model reaches the reference input image size of the target model, obtaining the processed bypass information; and / or, if the size of the output image of the current target model is smaller than the reference output image size of the target model indicated in the bypass information after privacy protection, then based on the bypass information processing strategy matching this information type, scale the size of the output image of the current target model until the size of the output image of the current target model reaches the reference output image size of the target model, obtaining the processed bypass information.
[0074] If the size of the input image of the current target model is not smaller than the reference input image size of the target model indicated in the bypass information after privacy protection, then there is no need to process the size of the input image of the target model. If the size of the output image of the current target model is not smaller than the reference output image size of the target model indicated in the bypass information after privacy protection, then there is no need to process the size of the output image of the target model.
[0075] In addition, if the information type includes the number of runs of the target model, the specific processing of step S108 above can be handled in the following manner: If the number of runs of the current target model is smaller than the reference number of runs of the target model indicated in the bypass information after privacy protection, then based on the bypass information processing strategy matching this information type, adjust the number of runs of the current target model until the number of runs of the current target model reaches the reference number of runs of the target model, obtaining the processed bypass information.
[0076] If the number of runs of the current target model is not smaller than the reference number of runs of the target model indicated in the bypass information after privacy protection, then there is no need to process the number of runs of the target model.
[0077] In step S218, based on a preset information perturbation strategy, perform perturbation processing on the information in the processed bypass information that has not undergone information processing, obtaining the perturbed bypass information.
[0078] Among them, the information perturbation strategy can include multiple types, such as an information perturbation strategy based on a Gaussian distribution, etc., and can be specifically set according to the actual situation.
[0079] In implementation, in order to fully protect the side-channel information of the target model, an information perturbation strategy based on Gaussian distribution can be used to perturb the unprocessed information in the processed side-channel information to obtain perturbed side-channel information.
[0080] In step S220, the perturbed side-channel information is encrypted and the encrypted perturbed side-channel information is transmitted to a specified device.
[0081] It should be noted that the encrypted information obtained after encrypting the perturbed side-channel information can only be decrypted by authorized devices or users, thus ensuring the security of the side-channel information.
[0082] The embodiments of this specification provide a method for processing information. By obtaining historical side-channel information corresponding to a target model to be protected, based on the historical side-channel information and a pre-trained privacy protection model, privacy protection processing is performed on the historical side-channel information to obtain privacy-protected side-channel information. The privacy protection model is a joint discriminator and is obtained by training the model through side-channel information samples of the target model and a preset loss function. Based on this, when the target model is running, the information type to which the information included in the side-channel information corresponding to the currently running target model belongs is obtained, and based on the obtained information type, a side-channel information processing strategy matching the information type is determined. Based on the side-channel information processing strategy matching the information type and the privacy-protected side-channel information, the side-channel information corresponding to the currently running target model is processed to protect the side-channel information corresponding to the currently running target model. In this way, the privacy protection model is used to perform privacy protection on the side-channel information corresponding to the target model. While ensuring a certain accuracy of the side-channel information (the side-channel information needs to ensure a certain accuracy, such as data like time-consuming; because side-channel information is often some important indicators for performance analysis), the side-channel information is perturbed so that attackers cannot obtain key information of the target model by analyzing the side-channel information. In addition, by starting from the perspective of side-channel information protection and combining deep differential privacy and adversarial training techniques for privacy protection, it can have good complementarity with the protection methods for key information, and using them together can improve the security of the overall system.
[0083] Embodiment III
[0084] As Figure 3A and Figure 3B shown, the embodiments of this specification provide a method for processing information. The execution subject of this method can be a server. Among them, the server can be an independent server, or a server cluster composed of multiple servers, etc. The server can be a background server such as a financial business or an online shopping business, or a background server of a certain application program, etc. This method can specifically include the following steps:
[0085] In step S302, obtain the historical bypass information corresponding to the target model to be protected, where the historical bypass information is the unencrypted historical information generated during the operation of the target model or the historical information that is easily obtained and does not require information protection processing during the operation of the target model.
[0086] In step S304, based on the historical bypass information and the pre-trained privacy protection model, perform privacy protection processing on the historical bypass information to obtain the privacy-protected bypass information. The privacy protection model is a joint discriminator and is trained through the bypass information samples of the target model and a preset loss function.
[0087] In step S306, send the privacy-protected bypass information to the target device on which the target model is deployed. The privacy-protected bypass information is used to trigger the target device to obtain the information type to which the information contained in the bypass information corresponding to the currently running target model belongs when running the target model, and based on the obtained information type, determine the bypass information processing strategy matching the information type. Based on the bypass information processing strategy matching the information type and the privacy-protected bypass information, process the bypass information corresponding to the currently running target model to protect the bypass information corresponding to the currently running target model.
[0088] The specific system architecture is as Figure 3C shown. The processing of the above steps S302 to S306 can refer to the relevant content in the above-mentioned Embodiment 1 or Embodiment 2, and will not be elaborated here.
[0089] In addition, the server can train the privacy protection model through the following processing, which specifically may include: obtaining the bypass information samples of the target model, inputting the above bypass information samples into the privacy protection model to obtain the privacy-protected bypass information samples, inputting the above bypass information samples and the privacy-protected bypass information samples into the discriminator to obtain the corresponding output results, and based on the output results and the preset loss function, determine whether the privacy protection model and the discriminator converge. If not, continue to train the privacy protection model and the discriminator based on the bypass information samples and the loss function until the privacy protection model and the discriminator converge to obtain the trained privacy protection model. The output results include whether the bypass information samples have undergone privacy protection processing and the prediction results of the key information of the target model. The key information of the target model includes the structure and function of the target model.
[0090] Among them, the loss function can be composed of one or more of the distribution function of the bypass information, the adversarial loss function, the key information prediction loss function, and the prior margin-based loss function. The distribution function of the bypass information is determined based on minimizing the data distribution between the bypass information samples and the privacy-protected bypass information samples. The adversarial loss function is determined based on the accuracy of the output result indicating whether the bypass information samples have been processed for privacy protection. The key information prediction loss function is determined based on the accuracy of the prediction result of the key information of the target model. The prior margin-based loss function is determined based on the difference between the bypass information samples and the privacy-protected bypass information samples being less than a preset margin.
[0091] In addition, the target model is a model for biometric processing, the privacy protection model is constructed by a multi-layer perceptron MLP, and the discriminator is constructed by a multi-layer perceptron MLP.
[0092] In addition, the processing of step S304 can be various. The following provides an optional processing method, which specifically may include the following: calculate the average value of the information of different information types included in the historical bypass information respectively; input the calculated average value of the information of different information types included in the historical bypass information into a pre-trained privacy protection model to obtain the privacy-protected bypass information.
[0093] For the above specific processing, reference can be made to the relevant content in Embodiment 1 or Embodiment 2 above, which will not be elaborated here.
[0094] An embodiment of this specification provides a method for processing information. By obtaining historical side-channel information corresponding to a target model to be protected, and based on the historical side-channel information and a pre-trained privacy protection model, performing privacy protection processing on the historical side-channel information to obtain privacy-protected side-channel information. The privacy protection model is a joint discriminator, which is obtained by training the model through side-channel information samples of the target model and a preset loss function. Based on this, when the target model is running, obtain the information type to which the information included in the side-channel information corresponding to the currently running target model belongs, and based on the obtained information type, determine a side-channel information processing strategy matching the information type. Based on the side-channel information processing strategy matching the information type and the privacy-protected side-channel information, process the side-channel information corresponding to the currently running target model to protect the side-channel information corresponding to the currently running target model. In this way, through the privacy protection model, privacy protection is performed on the side-channel information corresponding to the target model. While ensuring a certain accuracy of the side-channel information (the side-channel information needs to ensure a certain accuracy, such as data like elapsed time; because side-channel information is often some important indicators for performance analysis), perturb the side-channel information so that attackers cannot obtain the key information of the target model by analyzing the side-channel information. In addition, by starting from the perspective of side-channel information protection and combining deep differential privacy and adversarial training techniques for privacy protection, it can have good complementarity with the protection method for key information, and using them together can improve the security of the overall system.
[0095] Embodiment 4
[0096] As Figure 4A and Figure 4B As shown, an embodiment of this specification provides a method for processing information. The execution subject of this method can be a target device, and the target device can be a terminal device or a server. Among them, the terminal device can be a certain terminal device such as a mobile phone, a tablet computer, etc., and can also be a computer device such as a laptop computer or a desktop computer, or can also be an IoT device (specifically such as a smart watch, a vehicle-mounted device, etc.). The server can be an independent server, or can also be a server cluster composed of multiple servers, etc. The server can be a background server for financial services or online shopping services, etc., or can also be a background server for a certain application program, etc. This method can specifically include the following steps:
[0097] In step S402, receive the privacy-protected bypass information sent by the server. The privacy-protected bypass information is obtained by the server through performing privacy protection processing on the historical bypass information based on the historical bypass information corresponding to the target model and the pre-trained privacy protection model. The historical bypass information is the unencrypted historical information generated during the operation of the target model or the historical information that is easily obtained and does not require information protection processing during the operation of the target model. The privacy protection model is a joint discriminator, which is obtained by training the model through the bypass information samples of the target model and a preset loss function.
[0098] In step S404, when the target model is running, obtain the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and based on the obtained information type, determine the bypass information processing strategy that matches the information type.
[0099] In step S406, based on the bypass information processing strategy that matches the information type and the privacy-protected bypass information, process the bypass information corresponding to the currently running target model to protect the bypass information corresponding to the currently running target model.
[0100] For the processing of the above steps S402 to S406, reference can be made to the relevant content in the above-mentioned Embodiment 1 or Embodiment 2, which will not be elaborated here.
[0101] In addition, taking the information type including the volume of the target model as an example, the specific processing of the above step S406 can be performed in the following manner: If the volume of the current target model is smaller than the reference volume of the target model indicated in the privacy-protected bypass information, then based on the bypass information processing strategy that matches the information type, perform an expansion process on the volume of the current target model until the volume of the current target model reaches the reference volume of the target model, and obtain the processed bypass information.
[0102] In addition, if the information type includes the memory occupied by the target model during runtime and / or the runtime duration, the specific processing of step S406 above can be handled in the following manner: If the memory occupied by the current target model during runtime is less than the baseline memory of the target model indicated in the privacy-protected side-channel information, then based on the malloc function in the side-channel information processing strategy that matches the information type, the memory occupied by the current target model during runtime is expanded until the memory occupied by the current target model during runtime reaches the baseline memory of the target model, obtaining the processed side-channel information; and / or, if the runtime duration of the current target model is less than the baseline runtime duration of the target model indicated in the privacy-protected side-channel information, then based on the sleep function in the side-channel information processing strategy that matches the information type, the runtime duration of the current target model is expanded until the runtime duration of the current target model reaches the baseline runtime duration of the target model, obtaining the processed side-channel information.
[0103] If the memory occupied by the current target model during runtime is not less than the baseline memory of the target model indicated in the privacy-protected side-channel information, then there is no need to process the memory occupied by the target model during runtime. If the runtime duration of the current target model is not less than the baseline runtime duration of the target model indicated in the privacy-protected side-channel information, then there is no need to process the runtime duration of the target model.
[0104] In addition, if the information type includes the size of the input image of the target model and / or the size of the output image of the target model, the specific processing of step S406 above can be handled in the following manner: If the size of the input image of the current target model is less than the baseline input image size of the target model indicated in the privacy-protected side-channel information, then based on the side-channel information processing strategy that matches the information type, the size of the input image of the target model is scaled until the size of the input image of the current target model reaches the baseline input image size of the target model, obtaining the processed side-channel information; and / or, if the size of the output image of the current target model is less than the baseline output image size of the target model indicated in the privacy-protected side-channel information, then based on the side-channel information processing strategy that matches the information type, the size of the output image of the current target model is scaled until the size of the output image of the current target model reaches the baseline output image size of the target model, obtaining the processed side-channel information.
[0105] If the size of the input image of the current target model is not less than the size of the reference input image of the target model indicated in the bypass information after privacy protection, then it may not be necessary to process the size of the input image of the target model. If the size of the output image of the current target model is not less than the size of the reference output image of the target model indicated in the bypass information after privacy protection, then it may not be necessary to process the size of the output image of the target model.
[0106] In addition, if the information type includes the number of runs of the target model, the specific processing in step S406 above can be carried out in the following way: If the number of runs of the current target model is less than the reference number of runs of the target model indicated in the bypass information after privacy protection, then based on the bypass information processing strategy matching this information type, adjust the number of runs of the current target model until the number of runs of the current target model reaches the reference number of runs of the target model, and obtain the processed bypass information.
[0107] If the number of runs of the current target model is not less than the reference number of runs of the target model indicated in the bypass information after privacy protection, then it may not be necessary to process the number of runs of the target model.
[0108] In addition, to fully protect the bypass information of the target model, an information perturbation strategy such as a Gaussian distribution-based one can be used to perturb the information in the processed bypass information that has not been processed. Specifically, based on a preset information perturbation strategy, perturb the information in the processed bypass information that has not been processed to obtain the perturbed bypass information, encrypt the perturbed bypass information, and transmit the encrypted perturbed bypass information to a specified device.
[0109] The above specific processing can refer to the relevant content in the above Embodiment 1 or Embodiment 2, and will not be elaborated here.
[0110] The embodiment of this specification provides a method for processing information. By obtaining the historical side-channel information corresponding to the target model to be protected, and based on the historical side-channel information and a pre-trained privacy protection model, performing privacy protection processing on the historical side-channel information to obtain the side-channel information after privacy protection. The privacy protection model is a joint discriminator, which is obtained by training the model with the side-channel information samples of the target model and a preset loss function. Based on this, when the target model is running, obtain the information type to which the information contained in the side-channel information corresponding to the currently running target model belongs, and based on the obtained information type, determine a side-channel information processing strategy that matches the information type. Based on the side-channel information processing strategy that matches the information type and the side-channel information after privacy protection, process the side-channel information corresponding to the currently running target model to protect the side-channel information corresponding to the currently running target model. In this way, through the privacy protection model, privacy protection is performed on the side-channel information corresponding to the target model. While ensuring a certain accuracy of the side-channel information (the side-channel information needs to ensure a certain accuracy, such as data like time-consuming; because side-channel information is often some important indicators for performance analysis), perturb the side-channel information so that attackers cannot obtain the key information of the target model by analyzing the side-channel information. In addition, by starting from the perspective of side-channel information protection and combining deep differential privacy and adversarial training techniques for privacy protection, it can have good complementarity with the protection method for key information, and using them together can improve the security of the overall system.
[0111] Embodiment 5
[0112] The above is the method for processing information provided by the embodiments of this specification. Based on the same idea, the embodiments of this specification also provide an information processing device, as Figure 5 shown.
[0113] The information processing device includes: a historical information acquisition module 501, a privacy protection module 502, a policy acquisition module 503, and a side-channel information processing module 504, where:
[0114] The historical information acquisition module 501 acquires the historical side-channel information corresponding to the target model to be protected. The historical side-channel information is the unencrypted historical information generated during the operation of the target model or the historical information that is easily obtained and does not require information protection processing during the operation of the target model;
[0115] The privacy protection module 502 performs privacy protection processing on the historical side-channel information based on the historical side-channel information and a pre-trained privacy protection model to obtain the side-channel information after privacy protection. The privacy protection model is a joint discriminator, which is obtained by training the model with the side-channel information samples of the target model and a preset loss function;
[0116] A policy acquisition module 503, when the target model is running, acquires the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and determines a bypass information processing policy matching the information type based on the acquired information type;
[0117] A bypass information processing module 504 processes the bypass information corresponding to the currently running target model based on the bypass information processing policy matching the information type and the privacy-protected bypass information, so as to protect the bypass information corresponding to the currently running target model.
[0118] In the embodiments of the present specification, the information type includes the volume of the target model.
[0119] If the volume of the currently running target model is less than the reference volume of the target model indicated in the privacy-protected bypass information, the bypass information processing module 504 expands the volume of the currently running target model based on the bypass information processing policy matching the information type until the volume of the currently running target model reaches the reference volume of the target model, and obtains the processed bypass information.
[0120] In the embodiments of the present specification, the information type includes the memory occupied and / or the running duration when the target model is running. If the memory occupied by the currently running target model is less than the reference memory of the target model indicated in the privacy-protected bypass information, the bypass information processing module 504 expands the memory occupied by the currently running target model based on the malloc function in the bypass information processing policy matching the information type until the memory occupied by the currently running target model reaches the reference memory of the target model, and obtains the processed bypass information; and / or, if the running duration of the currently running target model is less than the reference running duration of the target model indicated in the privacy-protected bypass information, the bypass information processing module 504 expands the running duration of the currently running target model based on the sleep function in the bypass information processing policy matching the information type until the running duration of the currently running target model reaches the reference running duration of the target model, and obtains the processed bypass information.
[0121] In the embodiments of this specification, the information type includes the size of the input image of the target model and / or the size of the output image of the target model. For the bypass information processing module 504, if the size of the input image of the current target model is smaller than the benchmark input image size of the target model indicated in the privacy-protected bypass information, then based on a bypass information processing strategy matching the information type, the size of the input image of the target model is scaled until the size of the input image of the current target model reaches the benchmark input image size of the target model, and the processed bypass information is obtained; and / or, if the size of the output image of the current target model is smaller than the benchmark output image size of the target model indicated in the privacy-protected bypass information, then based on a bypass information processing strategy matching the information type, the size of the output image of the current target model is scaled until the size of the output image of the current target model reaches the benchmark output image size of the target model, and the processed bypass information is obtained.
[0122] In the embodiments of this specification, the information type includes the number of runs of the target model. For the bypass information processing module 504, if the number of runs of the current target model is smaller than the benchmark number of runs of the target model indicated in the privacy-protected bypass information, then based on a bypass information processing strategy matching the information type, the number of runs of the current target model is adjusted until the number of runs of the current target model reaches the benchmark number of runs of the target model, and the processed bypass information is obtained.
[0123] In the embodiments of this specification, the apparatus further includes:
[0124] A perturbation module that perturbs the information in the processed bypass information that has not been processed based on a preset information perturbation strategy to obtain perturbed bypass information;
[0125] An encryption module that encrypts the perturbed bypass information and transmits the encrypted perturbed bypass information to a specified device.
[0126] In the embodiments of this specification, the apparatus further includes:
[0127] A sample acquisition module that acquires a bypass information sample of the target model;
[0128] A sample processing module that inputs the bypass information sample into the privacy protection model to obtain a privacy-protected bypass information sample;
[0129] The model training module inputs the bypass information samples and the privacy-protected bypass information samples into a discriminator to obtain corresponding output results, and determines whether the privacy protection model and the discriminator converge based on the output results and a preset loss function. If not, the privacy protection model and the discriminator are continuously trained based on the bypass information samples and the loss function until the privacy protection model and the discriminator converge, obtaining the trained privacy protection model. The output results include whether the bypass information samples have undergone privacy protection processing and the prediction results of the key information of the target model. The key information of the target model includes the structure and function of the target model.
[0130] In the embodiments of this specification, the loss function is composed of one or more of the distribution function of the bypass information, the adversarial loss function, the key information prediction loss function, and the loss function based on the prior margin. The distribution function of the bypass information is determined based on minimizing the data distribution between the bypass information samples and the privacy-protected bypass information samples. The adversarial loss function is determined based on the accuracy of the output results of whether the bypass information samples have undergone privacy protection processing. The key information prediction loss function is determined based on the accuracy of the prediction results of the key information of the target model. The loss function based on the prior margin is determined based on the difference between the bypass information samples and the privacy-protected bypass information samples being less than a preset margin.
[0131] In the embodiments of this specification, the target model is a model for biometric processing. The privacy protection model is constructed by a multi-layer perceptron (MLP), and the discriminator is constructed by a multi-layer perceptron (MLP).
[0132] In the embodiments of this specification, the privacy protection module 502 includes:
[0133] A calculation unit that calculates the average value of the information of different information types included in the historical bypass information respectively;
[0134] A privacy protection unit that inputs the average value of the information of different information types included in the calculated historical bypass information into a pre-trained privacy protection model to obtain privacy-protected bypass information.
[0135] An embodiment of this specification provides an information processing device. By obtaining historical side-channel information corresponding to a target model to be protected, and based on the historical side-channel information and a pre-trained privacy protection model, performing privacy protection processing on the historical side-channel information to obtain privacy-protected side-channel information. The privacy protection model is a joint discriminator, which is obtained by training the model with side-channel information samples of the target model and a preset loss function. Based on this, when the target model is running, obtain the information type to which the information included in the side-channel information corresponding to the currently running target model belongs, and based on the obtained information type, determine a side-channel information processing strategy matching the information type. Based on the side-channel information processing strategy matching the information type and the privacy-protected side-channel information, process the side-channel information corresponding to the currently running target model to protect the side-channel information corresponding to the currently running target model. In this way, through the privacy protection model, privacy protection is performed on the side-channel information corresponding to the target model. While ensuring a certain accuracy of the side-channel information (the side-channel information needs to ensure a certain accuracy, such as data like time-consuming; because side-channel information is often some important indicators for performance analysis), perturb the side-channel information so that attackers cannot obtain the key information of the target model by analyzing the side-channel information. In addition, by starting from the perspective of side-channel information protection, combining deep differential privacy and adversarial training techniques for privacy protection can have good complementarity with the protection methods for key information, and using them together can improve the security of the overall system.
[0136] Embodiment Six
[0137] The above is the information processing method provided by the embodiments of this specification. Based on the same idea, the embodiments of this specification also provide an information processing device, as Figure 6 shown.
[0138] The information processing device includes: a historical information acquisition module 601, a privacy protection module 602, and an information sending module 603, where:
[0139] The historical information acquisition module 601 acquires historical side-channel information corresponding to a target model to be protected, where the historical side-channel information is unencrypted historical information generated during the operation of the target model or historical information that is easily obtained and does not require information protection processing during the operation of the target model;
[0140] The privacy protection module 602 performs privacy protection processing on the historical side-channel information based on the historical side-channel information and a pre-trained privacy protection model to obtain privacy-protected side-channel information. The privacy protection model is a joint discriminator, which is obtained by training the model with side-channel information samples of the target model and a preset loss function;
[0141] The information sending module 603 sends the privacy-protected side-channel information to the target device where the target model is deployed. The privacy-protected side-channel information is used to trigger the target device to obtain the information type to which the information included in the side-channel information corresponding to the currently running target model belongs when running the target model, and based on the obtained information type, determine a side-channel information processing strategy matching the information type. Based on the side-channel information processing strategy matching the information type and the privacy-protected side-channel information, process the side-channel information corresponding to the currently running target model to protect the side-channel information corresponding to the currently running target model.
[0142] An embodiment of this specification provides an information processing device. It obtains sample data for training a target model, and this sample data does not contain label information for training the target model. Then, according to the preset number of node selection times, each time a model node that meets the preset discard probability is selected from the model nodes included in the target model, and the selected model node is removed from the target model to obtain a target model composed of the remaining model nodes. The sample data is input into each of the above target models for feature extraction processing to obtain sample features corresponding to each target model. Preset noise data is added to each of these sample features to obtain noise sample features. The noise sample features are sent to the server, and the server performs federated training on the target model based on the noise sample features. In this way, by means of the Dropout mechanism, some model nodes are temporarily discarded from the target model each time according to a certain preset discard probability (but all model nodes are retained during prediction), which can not only improve the generalization of the target model, but also enable the target model obtained by the unsupervised method to achieve higher performance. In addition, before the sample features on the terminal device are sent to the server, noise data is added to the sample features to obtain noise sample features, thereby protecting the user privacy information in the sample data on the terminal device to the greatest extent and making it difficult to restore the original data. Since there is no label information in the sample data under unsupervised learning, the influence of the added noise data on the performance of the target model is limited, and it can increase the robustness of the trained target model.
[0143] Embodiment Seven
[0144] The above is the information processing method provided by the embodiments of this specification. Based on the same idea, the embodiments of this specification also provide an information processing device, as Figure 7 shown.
[0145] The information processing device includes: an information receiving module 701, a policy determination module 702, and an information processing module 703, where:
[0146] An information receiving module 701 receives the privacy-protected bypass information sent by the server. The privacy-protected bypass information is obtained by the server through performing privacy protection processing on the historical bypass information based on the historical bypass information corresponding to the target model and a pre-trained privacy protection model. The historical bypass information is unencrypted historical information generated during the operation of the target model or historical information that is easily obtained and does not require information protection processing during the operation of the target model. The privacy protection model is a joint discriminator and is obtained by training the model through the bypass information samples of the target model and a preset loss function.
[0147] A policy determination module 702, when the target model is running, obtains the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and determines a bypass information processing policy matching the information type based on the obtained information type.
[0148] An information processing module 703 processes the bypass information corresponding to the currently running target model based on the bypass information processing policy matching the information type and the privacy-protected bypass information, so as to protect the bypass information corresponding to the currently running target model.
[0149] The embodiment of the present specification provides an information processing device. By obtaining the historical bypass information corresponding to the target model to be protected, performing privacy protection processing on the historical bypass information based on the historical bypass information and a pre-trained privacy protection model to obtain the privacy-protected bypass information, where the privacy protection model is a joint discriminator and is obtained by training the model through the bypass information samples of the target model and a preset loss function. Based on this, when the target model is running, obtain the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and determine a bypass information processing policy matching the information type based on the obtained information type. Process the bypass information corresponding to the currently running target model based on the bypass information processing policy matching the information type and the privacy-protected bypass information, so as to protect the bypass information corresponding to the currently running target model. In this way, the bypass information corresponding to the target model is protected by the privacy protection model. While ensuring a certain accuracy of the bypass information (the bypass information needs to ensure a certain accuracy, such as data like time consumption; because the bypass information is often some important indicators for performance analysis), the bypass information is perturbed so that the attacker cannot obtain the key information of the target model by analyzing the bypass information. In addition, by starting from the perspective of bypass information protection and combining deep differential privacy and adversarial training techniques for privacy protection, it can have good complementarity with the protection method for key information, and using them together can improve the security of the overall system.
[0150] Embodiment Eight
[0151] The above is the information processing device provided by the embodiments of this specification. Based on the same concept, the embodiments of this specification also provide an information processing device, as Figure 8 shown.
[0152] The information processing device may be a terminal device or a server provided in the above embodiments, etc.
[0153] The information processing device may vary greatly due to different configurations or performances, and may include one or more processors 801 and a memory 802. One or more application programs or data may be stored in the memory 802. Among them, the memory 802 may be short-term storage or persistent storage. The application programs stored in the memory 802 may include one or more modules (not shown in the figure), and each module may include a series of computer-executable instructions in the information processing device. Further, the processor 801 may be configured to communicate with the memory 802 and execute a series of computer-executable instructions in the memory 802 on the information processing device. The information processing device may also include one or more power supplies 803, one or more wired or wireless network interfaces 804, one or more input / output interfaces 805, and one or more keyboards 806.
[0154] Specifically, in this embodiment, the information processing device includes a memory and one or more programs. One or more of the programs are stored in the memory, and one or more of the programs may include one or more modules, and each module may include a series of computer-executable instructions in the information processing device, and is configured to be executed by one or more processors. The one or more programs include the following computer-executable instructions:
[0155] Obtain historical bypass information corresponding to the target model to be protected. The historical bypass information is historical information generated during the operation of the target model that has not been encrypted, or historical information that is easily obtained and does not require information protection processing during the operation of the target model;
[0156] Based on the historical bypass information and a pre-trained privacy protection model, perform privacy protection processing on the historical bypass information to obtain privacy-protected bypass information. The privacy protection model is a joint discriminator and is obtained by training the model with bypass information samples of the target model and a preset loss function;
[0157] When the target model is running, obtain the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and based on the obtained information type, determine a bypass information processing strategy that matches the information type;
[0158] Based on the bypass information processing strategy that matches the information type and the privacy-protected bypass information, process the bypass information corresponding to the currently running target model to protect the bypass information corresponding to the currently running target model.
[0159] In the embodiments of this specification, the information type includes the volume of the target model,
[0160] The processing of the bypass information corresponding to the currently running target model based on the bypass information processing strategy that matches the information type and the privacy-protected bypass information includes:
[0161] If the volume of the currently running target model is less than the benchmark volume of the target model indicated in the privacy-protected bypass information, then based on the bypass information processing strategy that matches the information type, perform an expansion process on the volume of the currently running target model until the volume of the currently running target model reaches the benchmark volume of the target model, obtaining the processed bypass information.
[0162] In the embodiments of this specification, the information type includes the memory occupied by the target model during operation and / or the running duration,
[0163] The processing of the bypass information corresponding to the currently running target model based on the bypass information processing strategy that matches the information type and the privacy-protected bypass information includes:
[0164] If the memory occupied by the currently running target model is less than the benchmark memory of the target model indicated in the privacy-protected bypass information, then based on the malloc function in the bypass information processing strategy that matches the information type, perform an expansion process on the memory occupied by the currently running target model until the memory occupied by the currently running target model reaches the benchmark memory of the target model, obtaining the processed bypass information; and / or,
[0165] If the running duration of the currently running target model is less than the benchmark running duration of the target model indicated in the privacy-protected bypass information, then based on the sleep function in the bypass information processing strategy that matches the information type, perform an expansion process on the running duration of the currently running target model until the running duration of the currently running target model reaches the benchmark running duration of the target model, obtaining the processed bypass information.
[0166] In the embodiments of this specification, the information type includes the size of the input image of the target model and / or the size of the output image of the target model.
[0167] Processing the bypass information corresponding to the currently running target model based on the bypass information processing strategy matching the information type and the privacy-protected bypass information includes:
[0168] If the size of the input image of the currently running target model is smaller than the reference input image size of the target model indicated in the privacy-protected bypass information, then based on the bypass information processing strategy matching the information type, scale the size of the input image of the target model until the size of the input image of the currently running target model reaches the reference input image size of the target model, obtaining the processed bypass information; and / or,
[0169] If the size of the output image of the currently running target model is smaller than the reference output image size of the target model indicated in the privacy-protected bypass information, then based on the bypass information processing strategy matching the information type, scale the size of the output image of the currently running target model until the size of the output image of the currently running target model reaches the reference output image size of the target model, obtaining the processed bypass information.
[0170] In the embodiments of this specification, the information type includes the number of runs of the target model.
[0171] Processing the bypass information corresponding to the currently running target model based on the bypass information processing strategy matching the information type and the privacy-protected bypass information includes:
[0172] If the number of runs of the currently running target model is smaller than the reference number of runs of the target model indicated in the privacy-protected bypass information, then based on the bypass information processing strategy matching the information type, adjust the number of runs of the currently running target model until the number of runs of the currently running target model reaches the reference number of runs of the target model, obtaining the processed bypass information.
[0173] The embodiments of this specification further include:
[0174] Performing perturbation processing on the information in the processed bypass information that has not undergone information processing based on a preset information perturbation strategy, obtaining the perturbed bypass information;
[0175] Performing encryption processing on the perturbed bypass information and transmitting the encrypted perturbed bypass information to a specified device.
[0176] In the embodiments of this specification, it further includes:
[0177] Obtain a bypass information sample of the target model;
[0178] Input the bypass information sample into the privacy protection model to obtain a privacy-protected bypass information sample;
[0179] Input the bypass information sample and the privacy-protected bypass information sample into a discriminator to obtain corresponding output results, and determine whether the privacy protection model and the discriminator converge based on the output results and a preset loss function. If not, continue to train the privacy protection model and the discriminator based on the bypass information sample and the loss function until the privacy protection model and the discriminator converge, obtaining the trained privacy protection model. The output results include whether the bypass information sample has been subjected to privacy protection processing and the prediction results of the key information of the target model. The key information of the target model includes the structure and function of the target model.
[0180] In the embodiments of this specification, the loss function is composed of one or more of a distribution function of bypass information, an adversarial loss function, a key information prediction loss function, and a loss function based on a prior margin. The distribution function of the bypass information is determined based on minimizing the data distribution between the bypass information sample and the privacy-protected bypass information sample. The adversarial loss function is determined based on the accuracy of the output result of whether the bypass information sample has been subjected to privacy protection processing. The key information prediction loss function is determined based on the accuracy of the prediction result of the key information of the target model. The loss function based on the prior margin is determined based on the difference between the bypass information sample and the privacy-protected bypass information sample being less than a preset margin.
[0181] In the embodiments of this specification, the target model is a model for biometric processing. The privacy protection model is constructed by a multi-layer perceptron (MLP), and the discriminator is constructed by a multi-layer perceptron (MLP).
[0182] In the embodiments of this specification, performing privacy protection processing on the historical bypass information based on the historical bypass information and a pre-trained privacy protection model to obtain privacy-protected bypass information includes:
[0183] Calculate the average value of the information of different information types included in the historical bypass information respectively;
[0184] Input the average value of the information of different information types included in the calculated historical bypass information into the pre-trained privacy protection model to obtain privacy-protected bypass information.
[0185] Specifically, in this embodiment, the information processing device includes a memory and one or more programs, where one or more programs are stored in the memory, and one or more programs may include one or more modules, and each module may include a series of computer-executable instructions in the information processing device, and is configured to be executed by one or more processors. The one or more programs include computer-executable instructions for performing the following:
[0186] Obtain historical bypass information corresponding to the target model to be protected, where the historical bypass information is historical information that is not encrypted during the operation of the target model or historical information that is easily obtained and does not require information protection processing during the operation of the target model;
[0187] Based on the historical bypass information and a pre-trained privacy protection model, perform privacy protection processing on the historical bypass information to obtain privacy-protected bypass information. The privacy protection model is a joint discriminator and is obtained by training the model through bypass information samples of the target model and a preset loss function;
[0188] Send the privacy-protected bypass information to the target device on which the target model is deployed. The privacy-protected bypass information is used to trigger the target device to obtain the information type to which the information included in the bypass information corresponding to the currently running target model belongs when running the target model, and based on the obtained information type, determine a bypass information processing strategy matching the information type. Based on the bypass information processing strategy matching the information type and the privacy-protected bypass information, process the bypass information corresponding to the currently running target model to protect the bypass information corresponding to the currently running target model.
[0189] Specifically, in this embodiment, the information processing device includes a memory and one or more programs, where one or more programs are stored in the memory, and one or more programs may include one or more modules, and each module may include a series of computer-executable instructions in the information processing device, and is configured to be executed by one or more processors. The one or more programs include computer-executable instructions for performing the following:
[0190] Receive the privacy-protected side-channel information sent by the server, where the privacy-protected side-channel information is obtained by the server through performing privacy protection processing on the historical side-channel information corresponding to the target model based on the historical side-channel information corresponding to the target model and a pre-trained privacy protection model. The historical side-channel information is the unencrypted historical information generated during the operation of the target model or the historical information that is easily obtained and does not require information protection processing during the operation of the target model. The privacy protection model is a joint discriminator and is obtained through model training using the side-channel information samples of the target model and a preset loss function.
[0191] When the target model is running, obtain the information type to which the information included in the side-channel information corresponding to the currently running target model belongs, and based on the obtained information type, determine a side-channel information processing strategy matching the information type.
[0192] Based on the side-channel information processing strategy matching the information type and the privacy-protected side-channel information, process the side-channel information corresponding to the currently running target model to protect the side-channel information corresponding to the currently running target model.
[0193] An embodiment of this specification provides an information processing device. By obtaining the historical side-channel information corresponding to the target model to be protected, performing privacy protection processing on the historical side-channel information based on the historical side-channel information and a pre-trained privacy protection model to obtain the privacy-protected side-channel information, where the privacy protection model is a joint discriminator and is obtained through model training using the side-channel information samples of the target model and a preset loss function. Based on this, when the target model is running, obtain the information type to which the information included in the side-channel information corresponding to the currently running target model belongs, and based on the obtained information type, determine a side-channel information processing strategy matching this information type. Based on the side-channel information processing strategy matching this information type and the privacy-protected side-channel information, process the side-channel information corresponding to the currently running target model to protect the side-channel information corresponding to the currently running target model. In this way, the side-channel information corresponding to the target model is protected by the privacy protection model. While ensuring a certain accuracy of the side-channel information (the side-channel information needs to ensure a certain accuracy, such as data like time consumption; because side-channel information is often some important indicators for performance analysis), the side-channel information is perturbed so that attackers cannot obtain the key information of the target model by analyzing the side-channel information. In addition, by starting from the perspective of side-channel information protection and combining deep differential privacy and adversarial training techniques for privacy protection, it can have good complementarity with the protection methods for key information, and using them together can improve the security of the overall system.
[0194] Embodiment Nine
[0195] Further, based on the aboveFigures 1 to 4B For the method shown, one or more embodiments of this specification also provide a storage medium for storing computer-executable instruction information. In a specific embodiment, the storage medium can be a USB flash drive, optical disc, hard disk, etc. When the computer-executable instruction information stored in the storage medium is executed by a processor, the following process can be achieved:
[0196] Obtain the historical bypass information corresponding to the target model to be protected. The historical bypass information is the unencrypted historical information generated during the operation of the target model or the historical information that is easily obtained and does not require information protection processing during the operation of the target model;
[0197] Based on the historical bypass information and a pre-trained privacy protection model, perform privacy protection processing on the historical bypass information to obtain the privacy-protected bypass information. The privacy protection model is a joint discriminator and is obtained by training the model with the bypass information samples of the target model and a preset loss function;
[0198] When the target model is running, obtain the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and based on the obtained information type, determine a bypass information processing strategy that matches the information type;
[0199] Based on the bypass information processing strategy that matches the information type and the privacy-protected bypass information, process the bypass information corresponding to the currently running target model to protect the bypass information corresponding to the currently running target model.
[0200] In the embodiments of this specification, the information type includes the volume of the target model,
[0201] The processing of the bypass information corresponding to the currently running target model based on the bypass information processing strategy that matches the information type and the privacy-protected bypass information includes:
[0202] If the volume of the currently running target model is smaller than the benchmark volume of the target model indicated in the privacy-protected bypass information, then based on the bypass information processing strategy that matches the information type, perform an expansion process on the volume of the currently running target model until the volume of the currently running target model reaches the benchmark volume of the target model, to obtain the processed bypass information.
[0203] In the embodiments of this specification, the information type includes the memory occupied and / or the running duration when the target model is running,
[0204] Processing the side-channel information corresponding to the currently running target model based on the side-channel information processing strategy matching the information type and the side-channel information after privacy protection, includes:
[0205] If the memory occupied by the current running of the target model is less than the benchmark memory of the target model indicated in the side-channel information after privacy protection, then based on the malloc function in the side-channel information processing strategy matching the information type, expand the memory occupied by the current running of the target model until the memory occupied by the current running of the target model reaches the benchmark memory of the target model, to obtain the processed side-channel information; and / or,
[0206] If the running duration of the current target model is less than the benchmark running duration of the target model indicated in the side-channel information after privacy protection, then based on the sleep function in the side-channel information processing strategy matching the information type, expand the running duration of the current target model until the running duration of the current target model reaches the benchmark running duration of the target model, to obtain the processed side-channel information.
[0207] In the embodiments of this specification, the information type includes the size of the input image of the target model and / or the size of the output image of the target model.
[0208] Processing the side-channel information corresponding to the currently running target model based on the side-channel information processing strategy matching the information type and the side-channel information after privacy protection, includes:
[0209] If the size of the input image of the current target model is less than the benchmark input image size of the target model indicated in the side-channel information after privacy protection, then based on the side-channel information processing strategy matching the information type, scale the size of the input image of the target model until the size of the input image of the current target model reaches the benchmark input image size of the target model, to obtain the processed side-channel information; and / or,
[0210] If the size of the output image of the current target model is less than the benchmark output image size of the target model indicated in the side-channel information after privacy protection, then based on the side-channel information processing strategy matching the information type, scale the size of the output image of the current target model until the size of the output image of the current target model reaches the benchmark output image size of the target model, to obtain the processed side-channel information.
[0211] In the embodiments of this specification, the information type includes the number of runs of the target model.
[0212] Processing the side-channel information corresponding to the currently running target model based on the side-channel information processing strategy matching the information type and the side-channel information after privacy protection, includes:
[0213] If the number of runs of the currently running target model is less than the benchmark number of runs of the target model indicated in the side-channel information after privacy protection, then based on the side-channel information processing strategy matching the information type, adjust the number of runs of the currently running target model until the number of runs of the currently running target model reaches the benchmark number of runs of the target model, to obtain the processed side-channel information.
[0214] In the embodiments of this specification, it further includes:
[0215] Performing perturbation processing on the information in the processed side-channel information that has not undergone information processing based on a preset information perturbation strategy, to obtain the perturbed side-channel information;
[0216] Performing encryption processing on the perturbed side-channel information, and transmitting the encrypted perturbed side-channel information to a specified device.
[0217] In the embodiments of this specification, it further includes:
[0218] Obtaining a side-channel information sample of the target model;
[0219] Inputting the side-channel information sample into the privacy protection model to obtain a side-channel information sample after privacy protection;
[0220] Inputting the side-channel information sample and the side-channel information sample after privacy protection into a discriminator to obtain corresponding output results, and based on the output results and a preset loss function, determining whether the privacy protection model and the discriminator converge. If not, then continue to train the privacy protection model and the discriminator based on the side-channel information sample and the loss function until the privacy protection model and the discriminator converge, to obtain the trained privacy protection model. The output results include whether the side-channel information sample has undergone privacy protection processing, and the prediction results of the key information of the target model. The key information of the target model includes the structure and function of the target model.
[0221] In the embodiments of this specification, the loss function is composed of one or more of the distribution function of the bypass information, the adversarial loss function, the key information prediction loss function, and the prior margin-based loss function. The distribution function of the bypass information is determined based on minimizing the data distribution between the bypass information samples and the privacy-protected bypass information samples. The adversarial loss function is determined based on the accuracy of the output result of whether the bypass information samples have been subjected to privacy protection processing. The key information prediction loss function is determined based on the accuracy of the prediction result of the key information of the target model. The prior margin-based loss function is determined based on the difference between the bypass information samples and the privacy-protected bypass information samples being less than a preset margin.
[0222] In the embodiments of this specification, the target model is a model for biometric processing. The privacy protection model is constructed by a multi-layer perceptron (MLP), and the discriminator is constructed by a multi-layer perceptron (MLP).
[0223] In the embodiments of this specification, performing privacy protection processing on the historical bypass information based on the historical bypass information and a pre-trained privacy protection model to obtain privacy-protected bypass information includes:
[0224] Calculating the average value of the information of different information types included in the historical bypass information respectively;
[0225] Inputting the calculated average value of the information of different information types included in the historical bypass information into the pre-trained privacy protection model to obtain privacy-protected bypass information.
[0226] In another specific embodiment, the storage medium may be a USB flash drive, an optical disc, a hard disk, etc. When the computer-executable instruction information stored in the storage medium is executed by a processor, the following process can be implemented:
[0227] Obtaining historical bypass information corresponding to the target model to be protected, where the historical bypass information is the unencrypted historical information generated during the operation of the target model or the historical information that is easily obtained and does not require information protection processing during the operation of the target model;
[0228] Performing privacy protection processing on the historical bypass information based on the historical bypass information and a pre-trained privacy protection model to obtain privacy-protected bypass information, where the privacy protection model is a combined discriminator and is obtained by training the model through the bypass information samples of the target model and a preset loss function;
[0229] Send the privacy-protected side-channel information to the target device on which the target model is deployed. The privacy-protected side-channel information is used to trigger the target device to obtain the information type to which the information contained in the side-channel information corresponding to the currently running target model belongs when running the target model, and based on the obtained information type, determine a side-channel information processing strategy matching the information type. Based on the side-channel information processing strategy matching the information type and the privacy-protected side-channel information, process the side-channel information corresponding to the currently running target model to protect the side-channel information corresponding to the currently running target model.
[0230] In another specific embodiment, the storage medium may be a USB flash drive, an optical disc, a hard disk, etc. When the computer-executable instruction information stored in the storage medium is executed by a processor, the following process can be implemented:
[0231] Receive the privacy-protected side-channel information sent by the server. The privacy-protected side-channel information is obtained by the server through privacy protection processing of the historical side-channel information based on the historical side-channel information corresponding to the target model and a pre-trained privacy protection model. The historical side-channel information is unencrypted historical information generated during the operation of the target model or historical information that is easily obtained and does not require information protection processing during the operation of the target model. The privacy protection model is a joint discriminator and is obtained by training the model through the side-channel information samples of the target model and a preset loss function;
[0232] When the target model is running, obtain the information type to which the information contained in the side-channel information corresponding to the currently running target model belongs, and based on the obtained information type, determine a side-channel information processing strategy matching the information type;
[0233] Based on the side-channel information processing strategy matching the information type and the privacy-protected side-channel information, process the side-channel information corresponding to the currently running target model to protect the side-channel information corresponding to the currently running target model.
[0234] An embodiment of this specification provides a storage medium. By obtaining historical side-channel information corresponding to a target model to be protected, based on the historical side-channel information and a pre-trained privacy protection model, performing privacy protection processing on the historical side-channel information to obtain privacy-protected side-channel information. The privacy protection model is a combined discriminator, which is obtained by training the model with side-channel information samples of the target model and a preset loss function. Based on this, when the target model is running, obtain the information type to which the information included in the side-channel information corresponding to the currently running target model belongs, and based on the obtained information type, determine a side-channel information processing strategy matching the information type. Based on the side-channel information processing strategy matching the information type and the privacy-protected side-channel information, process the side-channel information corresponding to the currently running target model to protect the side-channel information corresponding to the currently running target model. In this way, through the privacy protection model, privacy protection is performed on the side-channel information corresponding to the target model. While ensuring a certain accuracy of the side-channel information (the side-channel information needs to ensure a certain accuracy, such as data like time consumption; because side-channel information is often some important indicators for performance analysis), perturb the side-channel information so that attackers cannot obtain the key information of the target model by analyzing the side-channel information. In addition, by starting from the perspective of side-channel information protection, combining deep differential privacy and adversarial training techniques for privacy protection, it can have good complementarity with the protection methods for key information, and using them together can improve the security of the overall system.
[0235] The above describes specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0236] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to circuit structures such as diodes, transistors, switches, etc.) or software improvements (improvements to method flows). However, with the development of technology, many method flow improvements today can be regarded as direct improvements to hardware circuit structures. Almost all designers obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement to a method flow cannot be implemented with a hardware entity module. For example, a Programmable Logic Device (PLD) (e.g., a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logical function is determined by the user programming the device. The designer can program by themselves to "integrate" a digital system on a single PLD, without having to ask a chip manufacturer to design and fabricate a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compiler used in program development and writing. The original code before compilation also has to be written in a specific programming language, which is called a Hardware Description Language (HDL). There is not only one type of HDL, but many types, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones currently are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also be aware that by simply performing a little logical programming on the method flow using the above-mentioned several hardware description languages and programming it into the integrated circuit, it is easy to obtain the hardware circuit that implements the logical method flow.
[0237] The controller can be implemented in any suitable manner. For example, the controller can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of the controller include, but are not limited to, the following microcontrollers: ARC625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that, in addition to implementing the controller in the form of pure computer-readable program code, it is entirely possible to logically program the method steps to enable the controller to be implemented in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers, embedded microcontrollers, etc. to achieve the same function. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be regarded as the structures within the hardware component. Or even, the devices for implementing various functions can be regarded as either software modules for implementing the method or structures within the hardware component.
[0238] The systems, devices, modules, or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0239] For the convenience of description, when describing the above devices, they are described separately as various units according to their functions. Of course, when implementing one or more embodiments of this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0240] Those skilled in the art should understand that the embodiments of this specification can be provided as a method, a system, or a computer program product. Therefore, one or more embodiments of this specification can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, one or more embodiments of this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.
[0241] Embodiments of this specification are described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this specification. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable serial-parallel devices for fraud cases to generate a machine, such that the instructions executed by the processor of the computer or other programmable serial-parallel devices for fraud cases generate means for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.
[0242] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable serial-parallel devices for fraud cases to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.
[0243] These computer program instructions can also be loaded onto a computer or other programmable serial-parallel devices for fraud cases, such that a series of operation steps are executed on the computer or other programmable devices to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable devices provide steps for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.
[0244] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0245] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.
[0246] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0247] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0248] It should be understood by those skilled in the art that the embodiments of this specification may be provided as methods, systems or computer program products. Therefore, one or more embodiments of this specification may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.
[0249] One or more embodiments of the present specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. One or more embodiments of the present specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0250] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and for the relevant parts, reference can be made to the partial description of the method embodiment.
[0251] The above description is only for the embodiments of this specification and is not intended to limit this application. For those skilled in the art, various modifications and changes can be made to this specification. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this specification shall be included within the scope of the claims of this specification.
Claims
1. A method for processing information, the method comprising: Obtaining historical bypass information corresponding to a target model to be protected, where the historical bypass information is historical information generated during the operation of the target model that has not been encrypted, or historical information that is easily obtained and does not require information protection processing during the operation of the target model; Performing privacy protection processing on the historical bypass information based on the historical bypass information and a pre-trained privacy protection model to obtain privacy-protected bypass information, where the privacy protection model is a joint discriminator and is obtained by training the model using bypass information samples of the target model and a preset loss function; When the target model is running, obtaining the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and determining a bypass information processing strategy matching the information type based on the obtained information type; Using the privacy-protected bypass information as reference information, and processing the bypass information corresponding to the currently running target model that does not match the reference information by using a bypass information processing strategy matching the information type, so as to protect the bypass information corresponding to the currently running target model.
2. The method according to claim 1, where the information type includes the volume of the target model, The processing the bypass information corresponding to the currently running target model that does not match the reference information by using a bypass information processing strategy matching the information type includes: If the volume of the currently running target model is less than the reference volume of the target model indicated in the privacy-protected bypass information, then based on the bypass information processing strategy matching the information type, expanding the volume of the currently running target model until the volume of the currently running target model reaches the reference volume of the target model to obtain processed bypass information.
3. The method according to claim 1, where the information type includes the memory occupied and / or the running duration when the target model is running, The processing the bypass information corresponding to the currently running target model that does not match the reference information by using a bypass information processing strategy matching the information type includes: If the memory occupied by the currently running target model is less than the reference memory of the target model indicated in the privacy-protected bypass information, then based on the malloc function in the bypass information processing strategy matching the information type, expanding the memory occupied by the currently running target model until the memory occupied by the currently running target model reaches the reference memory of the target model to obtain processed bypass information; and / or, If the running duration of the currently running target model is less than the reference running duration of the target model indicated in the privacy-protected bypass information, then based on the sleep function in the bypass information processing strategy matching the information type, expanding the running duration of the currently running target model until the running duration of the currently running target model reaches the reference running duration of the target model to obtain processed bypass information.
4. The method according to claim 1, wherein the information type includes the size of the input image of the target model and / or the size of the output image of the target model, The processing of the bypass information corresponding to the currently running target model that does not match the reference information by using a bypass information processing strategy matching the information type includes: If the size of the input image of the currently running target model is smaller than the reference input image size of the target model indicated in the privacy-protected bypass information, then based on the bypass information processing strategy matching the information type, the size of the input image of the target model is scaled until the size of the input image of the currently running target model reaches the reference input image size of the target model, and the processed bypass information is obtained; and / or, If the size of the output image of the currently running target model is smaller than the reference output image size of the target model indicated in the privacy-protected bypass information, then based on the bypass information processing strategy matching the information type, the size of the output image of the currently running target model is scaled until the size of the output image of the currently running target model reaches the reference output image size of the target model, and the processed bypass information is obtained.
5. The method according to claim 1, wherein the information type includes the number of runs of the target model, The processing of the bypass information corresponding to the currently running target model that does not match the reference information by using a bypass information processing strategy matching the information type includes: If the number of runs of the currently running target model is smaller than the reference number of runs of the target model indicated in the privacy-protected bypass information, then based on the bypass information processing strategy matching the information type, the number of runs of the currently running target model is adjusted until the number of runs of the currently running target model reaches the reference number of runs of the target model, and the processed bypass information is obtained.
6. The method according to any one of claims 1-5, wherein the method further includes: Performing perturbation processing on the information in the processed bypass information that has not been processed based on a preset information perturbation strategy to obtain perturbed bypass information; Encrypting the perturbed bypass information and transmitting the encrypted perturbed bypass information to a specified device.
7. The method according to claim 1, wherein the method further includes: Obtaining a bypass information sample of the target model; Inputting the bypass information sample into the privacy protection model to obtain a privacy-protected bypass information sample; Input the bypass information sample and the privacy-protected bypass information sample into a discriminator to obtain corresponding output results, and based on the output results and a preset loss function, determine whether the privacy protection model and the discriminator converge. If not, continue to train the privacy protection model and the discriminator based on the bypass information sample and the loss function until the privacy protection model and the discriminator converge, obtaining the trained privacy protection model. The output results include whether the bypass information sample has undergone privacy protection processing and the prediction results of the key information of the target model. The key information of the target model includes the structure and function of the target model.
8. The method according to claim 7, wherein the loss function is composed of one or more of a distribution function of bypass information, an adversarial loss function, a key information prediction loss function, and a loss function based on a prior margin. The distribution function of bypass information is determined based on minimizing the data distribution between the bypass information sample and the privacy-protected bypass information sample. The adversarial loss function is determined based on the accuracy of the output result of whether the bypass information sample has undergone privacy protection processing. The key information prediction loss function is determined based on the accuracy of the prediction result of the key information of the target model. The loss function based on a prior margin is determined based on the difference between the bypass information sample and the privacy-protected bypass information sample being less than a preset margin.
9. The method according to claim 7, wherein the target model is a model for biometric processing, the privacy protection model is constructed by a multi-layer perceptron (MLP), and the discriminator is constructed by a multi-layer perceptron (MLP).
10. The method according to claim 1, wherein the step of performing privacy protection processing on the historical bypass information based on the historical bypass information and a pre-trained privacy protection model to obtain privacy-protected bypass information comprises: Calculating the average value of the information of different information types included in the historical bypass information respectively; Inputting the calculated average value of the information of different information types included in the historical bypass information into the pre-trained privacy protection model to obtain privacy-protected bypass information.
11. A method for processing information, applied to a server, the method comprising: Obtaining historical bypass information corresponding to a target model to be protected, where the historical bypass information is unencrypted historical information generated during the operation of the target model or historical information that is easily obtained and does not require information protection processing during the operation of the target model; Performing privacy protection processing on the historical bypass information based on the historical bypass information and a pre-trained privacy protection model to obtain privacy-protected bypass information, where the privacy protection model is a joint discriminator obtained by training a model through the bypass information sample of the target model and a preset loss function; Send the privacy-protected side-channel information to the target device on which the target model is deployed. The privacy-protected side-channel information is used to trigger the target device to obtain the information type to which the information contained in the side-channel information corresponding to the currently running target model belongs when running the target model, and based on the obtained information type, determine a side-channel information processing strategy matching the information type. Use the privacy-protected side-channel information as the reference information, and adopt the side-channel information processing strategy matching the information type to process the side-channel information corresponding to the currently running target model that does not match the reference information, so as to protect the side-channel information corresponding to the currently running target model.
12. A method for processing information, which is applied to a target device on which a target model to be protected is deployed. The method includes: Receive the privacy-protected side-channel information sent by the server. The privacy-protected side-channel information is obtained by the server through privacy protection processing of the historical side-channel information based on the historical side-channel information corresponding to the target model and a pre-trained privacy protection model. The historical side-channel information is unencrypted historical information generated during the operation of the target model or historical information that is easily obtained and does not require information protection processing during the operation of the target model. The privacy protection model is a joint discriminator and is obtained by training the model through the side-channel information samples of the target model and a preset loss function; When the target model is running, obtain the information type to which the information contained in the side-channel information corresponding to the currently running target model belongs, and based on the obtained information type, determine a side-channel information processing strategy matching the information type; Use the privacy-protected side-channel information as the reference information, and adopt the side-channel information processing strategy matching the information type to process the side-channel information corresponding to the currently running target model that does not match the reference information, so as to protect the side-channel information corresponding to the currently running target model.
13. An information processing device, the device includes: A historical information acquisition module, which acquires the historical side-channel information corresponding to the target model to be protected. The historical side-channel information is unencrypted historical information generated during the operation of the target model or historical information that is easily obtained and does not require information protection processing during the operation of the target model; A privacy protection module, which performs privacy protection processing on the historical side-channel information based on the historical side-channel information and a pre-trained privacy protection model to obtain privacy-protected side-channel information. The privacy protection model is a joint discriminator and is obtained by training the model through the side-channel information samples of the target model and a preset loss function; A strategy acquisition module, when the target model is running, acquires the information type to which the information contained in the side-channel information corresponding to the currently running target model belongs, and based on the obtained information type, determines a side-channel information processing strategy matching the information type; The bypass information processing module uses the privacy-protected bypass information as the reference information, and adopts a bypass information processing strategy matching the information type to process the bypass information of the currently running target model that does not match the reference information, so as to protect the bypass information of the currently running target model.
14. An information processing device, the device includes: A historical information acquisition module acquires historical bypass information corresponding to a target model to be protected, where the historical bypass information is unencrypted historical information generated during the operation of the target model or historical information that is easily obtained and does not require information protection processing during the operation of the target model; A privacy protection module performs privacy protection processing on the historical bypass information based on the historical bypass information and a pre-trained privacy protection model, and obtains privacy-protected bypass information. The privacy protection model is a joint discriminator, and is obtained by training the model through bypass information samples of the target model and a preset loss function; An information sending module sends the privacy-protected bypass information to a target device on which the target model is deployed. The privacy-protected bypass information is used to trigger the target device to obtain the information type to which the information included in the bypass information of the currently running target model belongs when running the target model, and based on the obtained information type, determine a bypass information processing strategy matching the information type, use the privacy-protected bypass information as the reference information, and adopt a bypass information processing strategy matching the information type to process the bypass information of the currently running target model that does not match the reference information, so as to protect the bypass information of the currently running target model.
15. An information processing device deploys a target model to be protected, and the device includes: An information receiving module receives the privacy-protected bypass information sent by the server. The privacy-protected bypass information is obtained by the server performing privacy protection processing on the historical bypass information based on the historical bypass information corresponding to the target model and a pre-trained privacy protection model. The historical bypass information is unencrypted historical information generated during the operation of the target model or historical information that is easily obtained and does not require information protection processing during the operation of the target model. The privacy protection model is a joint discriminator, and is obtained by training the model through bypass information samples of the target model and a preset loss function; A strategy determination module, when the target model is running, obtains the information type to which the information included in the bypass information of the currently running target model belongs, and determines a bypass information processing strategy matching the information type based on the obtained information type; An information processing module uses the bypass information after privacy protection as reference information, and processes the bypass information corresponding to the currently running target model that does not match the reference information by using a bypass information processing strategy matching the information type, so as to protect the bypass information corresponding to the currently running target model.
16. An information processing device, the information processing device includes: A processor; And A memory arranged to store computer-executable instructions, the executable instructions, when executed, cause the processor to: Obtain historical bypass information corresponding to a target model to be protected, where the historical bypass information is unencrypted historical information generated during the operation of the target model or historical information that is easily obtained and does not require information protection processing during the operation of the target model; Based on the historical bypass information and a pre-trained privacy protection model, perform privacy protection processing on the historical bypass information to obtain bypass information after privacy protection, where the privacy protection model is a joint discriminator and is obtained by training the model through bypass information samples of the target model and a preset loss function; When the target model is running, obtain the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and determine a bypass information processing strategy matching the information type based on the obtained information type; Use the bypass information after privacy protection as reference information, and process the bypass information corresponding to the currently running target model that does not match the reference information by using a bypass information processing strategy matching the information type, so as to protect the bypass information corresponding to the currently running target model.
17. An information processing device, the information processing device includes: A processor; And A memory arranged to store computer-executable instructions, the executable instructions, when executed, cause the processor to: Obtain historical bypass information corresponding to a target model to be protected, where the historical bypass information is unencrypted historical information generated during the operation of the target model or historical information that is easily obtained and does not require information protection processing during the operation of the target model; Based on the historical bypass information and a pre-trained privacy protection model, perform privacy protection processing on the historical bypass information to obtain bypass information after privacy protection, where the privacy protection model is a joint discriminator and is obtained by training the model through bypass information samples of the target model and a preset loss function; Send the privacy-protected side-channel information to the target device on which the target model is deployed. The privacy-protected side-channel information is used to trigger the target device to obtain the information type to which the information contained in the side-channel information corresponding to the currently running target model belongs when running the target model, and based on the obtained information type, determine a side-channel information processing strategy matching the information type. Use the privacy-protected side-channel information as the reference information, and adopt the side-channel information processing strategy matching the information type to process the side-channel information corresponding to the currently running target model that does not match the reference information, so as to protect the side-channel information corresponding to the currently running target model.
18. A processing device for information, on which a target model to be protected is deployed. The processing device for information includes: A processor; And A memory arranged to store computer-executable instructions, and the executable instructions, when executed, cause the processor to: Receive the privacy-protected side-channel information sent by the server. The privacy-protected side-channel information is obtained by the server after performing privacy protection processing on the historical side-channel information based on the historical side-channel information corresponding to the target model and a pre-trained privacy protection model. The historical side-channel information is unencrypted historical information generated during the running of the target model or historical information that is easily obtained and does not require information protection processing during the running of the target model. The privacy protection model is a joint discriminator, and is obtained by training the model through the side-channel information samples of the target model and a preset loss function; When the target model is running, obtain the information type to which the information contained in the side-channel information corresponding to the currently running target model belongs, and based on the obtained information type, determine a side-channel information processing strategy matching the information type; Use the privacy-protected side-channel information as the reference information, and adopt the side-channel information processing strategy matching the information type to process the side-channel information corresponding to the currently running target model that does not match the reference information, so as to protect the side-channel information corresponding to the currently running target model.
19. A storage medium, which is used to store computer-executable instructions, and the executable instructions, when executed by a processor, implement the following process: Obtain the historical side-channel information corresponding to the target model to be protected. The historical side-channel information is unencrypted historical information generated during the running of the target model or historical information that is easily obtained and does not require information protection processing during the running of the target model; Based on the historical side-channel information and a pre-trained privacy protection model, perform privacy protection processing on the historical side-channel information to obtain privacy-protected side-channel information. The privacy protection model is a joint discriminator, and is obtained by training the model through the side-channel information samples of the target model and a preset loss function; When the target model is running, obtain the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and based on the obtained information type, determine a bypass information processing strategy matching the information type; Use the privacy-protected bypass information as the reference information, and adopt a bypass information processing strategy matching the information type to process the bypass information corresponding to the currently running target model that does not match the reference information, so as to protect the bypass information corresponding to the currently running target model.
20. A storage medium, which is used to store computer-executable instructions, and the executable instructions, when executed by a processor, implement the following process: Obtain the historical bypass information corresponding to the target model to be protected, where the historical bypass information is the unencrypted historical information generated during the operation of the target model or the historical information that is easily obtained and does not require information protection processing during the operation of the target model; Based on the historical bypass information and a pre-trained privacy protection model, perform privacy protection processing on the historical bypass information to obtain privacy-protected bypass information. The privacy protection model is a joint discriminator and is obtained by training the model through the bypass information samples of the target model and a preset loss function; Send the privacy-protected bypass information to the target device on which the target model is deployed. The privacy-protected bypass information is used to trigger the target device to obtain the information type to which the information included in the bypass information corresponding to the currently running target model belongs when the target model is running, and based on the obtained information type, determine a bypass information processing strategy matching the information type, use the privacy-protected bypass information as the reference information, and adopt a bypass information processing strategy matching the information type to process the bypass information corresponding to the currently running target model that does not match the reference information, so as to protect the bypass information corresponding to the currently running target model.
21. A storage medium, which is used to store computer-executable instructions, and the executable instructions, when executed by a processor, implement the following process: Receive the privacy-protected bypass information sent by the server. The privacy-protected bypass information is obtained by the server performing privacy protection processing on the historical bypass information based on the historical bypass information corresponding to the target model and a pre-trained privacy protection model. The historical bypass information is the unencrypted historical information generated during the operation of the target model or the historical information that is easily obtained and does not require information protection processing during the operation of the target model. The privacy protection model is a joint discriminator and is obtained by training the model through the bypass information samples of the target model and a preset loss function; When the target model is running, obtain the information type to which the information included in the bypass information corresponding to the currently running target model belongs, and based on the obtained information type, determine a bypass information processing strategy matching the information type; Use the side-channel information after privacy protection as the reference information, and adopt a side-channel information processing strategy matching the information type to process the side-channel information of the currently running target model that does not match the reference information, so as to protect the side-channel information of the currently running target model.
Citation Information
Patent Citations
Method and device for protecting neural network model security
CN112100628A
Model construction method, device and equipment based on privacy protection
CN113221717A