Decision tree evaluation method, device, equipment and medium based on secure multi-party computing
Through the decision tree evaluation method based on secure multi-party computing, the feature attribute calculation is calculated using replication secret sharing technology and mapping matrix, the problem of insufficient communication cost and practicality of the decision tree evaluation algorithm in the existing technology is solved, and an efficient and secure decision tree evaluation is achieved.
Patent Information
- Application Number
- CN202211533464.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-01
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2042-12-01
AI Technical Summary
The existing protocols for decision tree evaluation algorithms have shortcomings in terms of communication cost, practicality and security, especially in deep and sparse decision tree models. The time complexity and communication complexity of existing solutions increase exponentially with the depth of the decision tree, resulting in impracticality.
The decision tree evaluation method based on secure multi-party computing is adopted, and the secret values of the client and the model provider are divided into secret shares through replication secret sharing technology, and each participant holds its corresponding secret share to participate in the calculation. The feature attributes are determined using the mapping matrix and feature vectors, and the comparison results of the decision nodes are obtained through linear transformation and dot product operations, and the evaluation results are finally determined.
It reduces communication costs, improves the practicality and security of the protocol, avoids adding fake nodes to the decision tree, significantly improves efficiency, and expands to security outsourcing scenarios, and improves the scope of application of the protocol.
Smart Images

Figure CN115842627B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of machine learning technology, and in particular to a decision tree evaluation method, device, equipment and medium based on secure multi-party computing. Background Art
[0002] Machine learning algorithms are widely used to solve various classification and prediction problems. During the execution of the algorithm, the parties involved need to exchange private data. However, once the private data is leaked, it will not only harm the interests of the data holder, but also violate relevant laws, such as the Personal Information Protection Law. Therefore, it is crucial to safely execute machine learning algorithms while ensuring the confidentiality of private data.
[0003] In recent years, secure multi-party computation has been widely studied. This technology allows multiple participants to complete a computation together without disclosing the input of the participants. After the computation is completed, the computation result can be made public to all participants or only disclosed to designated participants. Secure multi-party computation is recognized as one of the most important technical routes to achieve privacy protection in machine learning. Existing research can be divided into two categories: one is to study general protocols that can achieve privacy protection for multiple machine learning algorithms; the other is to study dedicated protocols for a specific machine learning algorithm. At present, in the dedicated protocols for decision tree evaluation algorithms, most of the existing schemes convert the decision tree into a full binary tree by adding fake nodes to hide the structural information of the decision tree. However, since fake nodes require the same computational and communication costs as real nodes and cannot be distinguished by the participants, the time complexity and communication complexity of this method are independent of the number of real nodes, but increase exponentially with the depth of the decision tree. For deep and sparse decision tree models, this method is very impractical.
[0004] In summary, how to develop a dedicated protocol for decision tree evaluation algorithm to reduce communication costs while improving the practicality and security of the protocol is a problem that needs to be solved. Summary of the invention
[0005] In view of this, the purpose of the present invention is to provide a decision tree evaluation method, device, equipment and medium based on secure multi-party computing, which can reduce the communication cost and improve the practicality and security of the protocol for the dedicated protocol of the decision tree evaluation algorithm. The specific scheme is as follows:
[0006] In a first aspect, the present application discloses a decision tree evaluation method based on secure multi-party computing, comprising:
[0007] Obtain the secret value shared by the client and the model provider, and divide the secret value into a preset number of shares by replicating the secret sharing technology to determine the secret share corresponding to each participant; wherein the participants include the client, the model provider and the computing service provider; the client provides a feature vector, and the model provider provides a pre-trained decision tree model; the decision tree model includes decision nodes, leaf nodes, a mapping matrix and a traversal matrix;
[0008] Determine the characteristic attributes corresponding to each participant at each decision node using the mapping matrix corresponding to each participant and the characteristic vector corresponding to each participant based on the secret share, so as to obtain the comparison result of the decision node through the characteristic attributes;
[0009] A linear transformation is performed on the comparison result, and a dot product operation is performed on the comparison result after the linear transformation and the traversal matrix corresponding to each participant in the secret share, so as to determine an evaluation result based on the result of the dot product operation and the label vector carried by the leaf node.
[0010] Optionally, obtaining the comparison result of the decision node by using the feature attribute includes:
[0011] Traversing the decision tree model and determining the magnitude relationship between the feature attribute and the threshold vector provided by the model provider;
[0012] If the characteristic attribute of the current decision node is less than the threshold vector, the comparison result of the decision node is set to 1, and the right child node of the current decision node is selected to continue traversing until the current node is the leaf node and the traversal is stopped to obtain the label of the leaf node;
[0013] If the characteristic attribute of the current decision node is not less than the threshold vector, the comparison result of the decision node is taken as 0, and the left child node of the current decision node is selected to continue traversing until the current node is the leaf node and the traversal is stopped to obtain the label of the leaf node.
[0014] Optionally, performing a linear transformation on the comparison result includes:
[0015] The comparison result is multiplied by 2 and then subtracted by 1, so as to change the comparison result pointing to the left child node to -1 and keep the comparison result pointing to the right child node unchanged.
[0016] Optionally, the step of obtaining the secret value shared by the client and the model provider, and dividing the secret value into a preset number of shares by using a replication secret sharing technology to determine the secret share corresponding to each participant, includes:
[0017] Obtaining the secret value shared by the client and the model provider, and dividing the secret value into shares equal to the number of the participants to obtain a first share, a second share, and a third share;
[0018] Setting the first share to 0 and generating a second share value using a pseudo-random number generator;
[0019] The third share value is determined based on the secret value and the second share value, and then the first share value, the second share value and the third share value are allocated to determine the secret share corresponding to each participant.
[0020] Optionally, the determining, based on the secret share, using a mapping matrix corresponding to each participant and a feature vector corresponding to each participant to respectively determine a feature attribute corresponding to each participant at each decision node, so as to obtain a comparison result of the decision node through the feature attribute, includes:
[0021] Based on the secret share, the mapping matrix corresponding to each participant and the feature vector corresponding to each participant are used to determine the feature attributes corresponding to each participant at each decision node, and the difference between the feature attributes and the threshold vector is decomposed by an adder circuit. If the highest bit of the decomposed difference is 1, it is determined that the feature attribute is less than the threshold vector; if the highest bit of the decomposed difference is 0, it is determined that the feature attribute is greater than the threshold vector.
[0022] Optionally, performing a dot product operation on the comparison result after the linear transformation and the traversal matrix corresponding to each participant, so as to determine an evaluation result based on the result of the dot product operation and the label vector carried by the leaf node, includes:
[0023] Performing a dot product operation on the comparison result after the linear transformation and the traversal matrix corresponding to each participant, determining the difference between the result of the dot product operation and the order of the target subset of the decision node set, so as to use the difference to judge whether the result of the dot product operation is equal to the order of the target subset of the decision node set; wherein the target subset is the set of decision nodes included in the path from the current leaf node to the root node in the decision tree model;
[0024] Decomposing the difference by using an adder circuit, and performing a logical OR operation on all bits obtained after the decomposition to obtain a result vector;
[0025] The evaluation result is determined using the result vector and the label vector carried by the leaf node.
[0026] Optionally, the decision tree evaluation method based on secure multi-party computing further includes:
[0027] When the number of the decision nodes is greater than a preset threshold, the traversal matrix is compressed using a divide-and-conquer method to obtain a target number of sub-traversal matrices;
[0028] The decision nodes are divided into the sub-traversal matrices according to a preset node division rule.
[0029] In a second aspect, the present application discloses a decision tree evaluation device based on secure multi-party computing, comprising:
[0030] A replication secret sharing module is used to obtain the secret value shared by the client and the model provider, and divide the secret value into a preset number of shares through the replication secret sharing technology to determine the secret share corresponding to each participant; wherein the participants include the client, the model provider and the computing service provider; the client provides a feature vector, and the model provider provides a pre-trained decision tree model; the decision tree model includes decision nodes, leaf nodes, mapping matrices and traversal matrices;
[0031] A decision module, configured to determine the characteristic attributes corresponding to each participant at each decision node by using the mapping matrix corresponding to each participant and the characteristic vector corresponding to each participant based on the secret share, so as to obtain a comparison result of the decision node through the characteristic attributes;
[0032] An evaluation module is used to perform a linear transformation on the comparison result, and to perform a dot product operation on the comparison result after the linear transformation and the traversal matrix corresponding to each participant, so as to determine the evaluation result based on the result of the dot product operation and the label vector carried by the leaf node.
[0033] In a third aspect, the present application discloses an electronic device, comprising a processor and a memory; wherein the memory is used to store a computer program, and the computer program is loaded and executed by the processor to implement the decision tree evaluation method based on secure multi-party computing as described above.
[0034] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein the computer program, when executed by a processor, implements the decision tree evaluation method based on secure multi-party computing as described above.
[0035] The present application provides a decision tree evaluation method based on secure multi-party computing, including: obtaining a secret value shared by a client and a model provider, and dividing the secret value into a preset number of shares by replicating the secret sharing technology, so as to determine the secret share corresponding to each participant; wherein the participants include the client, the model provider and the computing service provider; the client provides a feature vector, and the model provider provides a pre-trained decision tree model; the decision tree model includes decision nodes, leaf nodes, a mapping matrix and a traversal matrix; based on the secret share, using the mapping matrix corresponding to each participant and the feature vector corresponding to each participant to determine the feature attributes corresponding to each participant at each decision node, so as to obtain the comparison result of the decision node through the feature attributes; performing a linear transformation on the comparison result, and performing a dot product operation on the comparison result after the linear transformation and the traversal matrix corresponding to each participant, so as to determine the evaluation result based on the result of the dot product operation and the label vector carried by the leaf node. It can be seen that the client inputs the feature vector that it does not want to be leaked into the trained decision tree model provided by the model provider to perform some classification or prediction problems. Through the replication secret sharing technology, each participant holds their own secret share to participate in the calculation. All participants cannot recover the privacy data of other participants through intermediate data. The privacy data of the provider and the customer of the decision tree model will not be leaked, and only the customer obtains the final evaluation result, which has high security. By converting the decision tree traversal process into a dot product calculation, the structure of the decision tree is hidden, and the addition of false nodes in the decision tree is avoided, which reduces the communication cost and significantly improves the efficiency. In addition, since the participants of the replication secret sharing technology can be different entities, the decision tree evaluation method based on secure multi-party computing can also be extended to the security outsourcing scenario, so that the model provider and the customer do not need to participate in the calculation online, but only need to share their own input securely, which further improves the practicality of the protocol and has a wider range of applications. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.
[0037] Figure 1 A flowchart of a decision tree evaluation method based on secure multi-party computing disclosed in this application;
[0038] Figure 2 A schematic diagram of a decision tree disclosed in this application;
[0039] Figure 3 A schematic diagram of a decision tree evaluation system based on secure multi-party computing disclosed in this application;
[0040] Figure 4 A schematic diagram of a security outsourcing process disclosed in this application;
[0041] Figure 5 A flowchart of a specific decision tree evaluation method based on secure multi-party computing disclosed in this application;
[0042] Figure 6 A schematic diagram of a decision tree evaluation device based on secure multi-party computing disclosed in this application;
[0043] Figure 7 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION
[0044] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0045] Currently, in the dedicated protocols for decision tree evaluation algorithms, most of the existing solutions convert the decision tree into a full binary tree by adding fake nodes to hide the structural information of the decision tree. However, since fake nodes require the same computational and communication costs as real nodes and cannot be distinguished by the participants, the time complexity and communication complexity of this method are independent of the number of real nodes, but grow exponentially with the depth of the decision tree. For deep and sparse decision tree models, this method is very impractical.
[0046] To this end, the present application provides a decision tree evaluation scheme based on secure multi-party computing, which can target a dedicated protocol for decision tree evaluation algorithms, reduce communication costs while improving the practicality and security of the protocol.
[0047] The embodiment of the present invention discloses a decision tree evaluation method based on secure multi-party computing, see Figure 1 As shown, the method includes:
[0048] Step S11: Obtain the secret value shared by the client and the model provider, and divide the secret value into a preset number of shares through the replication secret sharing technology to determine the secret share corresponding to each participant; wherein the participants include the client, the model provider and the computing service provider; the client provides a feature vector, and the model provider provides a pre-trained decision tree model; the decision tree model includes decision nodes, leaf nodes, a mapping matrix and a traversal matrix.
[0049] Decision tree is one of the most important machine learning models and is widely used in many fields, such as face recognition, disease diagnosis, business decision-making, etc. Usually, decision trees are represented by binary trees, and their structural information is also considered to be part of the privacy data, such as Figure 2 The figure shows a schematic diagram of a decision tree. The decision tree model consists of m decision nodes and m+1 leaf nodes.
[0050] In the embodiment of the present application, the Replicated Secret Sharing technology is used to protect the confidentiality of private data. When protecting data, the dedicated protocol for the decision tree evaluation algorithm has multiple participants in the calculation, such as Figure 3 The following is a schematic diagram of the system structure of the decision tree evaluation method. The client needs a trained decision tree model to help him solve some classification or prediction problems, and its input is a feature vector x. The model provider can be a consulting company or research institution, which has a trained decision tree model. Therefore, the user solves the problem through the provider's model.
[0051] It is understandable that, firstly, the client's feature vector x usually involves sensitive information, such as the patient's health status, personal income, etc., which should not be disclosed to the provider; secondly, the decision tree model is trained by the provider with a lot of resources, which is the provider's trade secret and cannot be disclosed; and the training data of some models can be restored through model inversion attacks. Therefore, in order to protect the confidentiality of the private data of the client and the provider, the user and the provider need to jointly execute a decision tree evaluation protocol based on secure multi-party computing. Since the replication secret sharing technology requires three participants, an independent third party is added as a computing service provider to assist in completing the protocol.
[0052] In the embodiment of the present application, the secret value shared by the client and the model provider is first shared in secret. The client shares the feature vector x, and the model provider provides a pre-trained decision tree model, which mainly includes a threshold vector y, a label vector v, an order vector c, a mapping matrix M, a traversal matrix T, etc. The secret value is split into shares equal to the number of participants to obtain a first share, a second share, and a third share. For example, the secret value a is represented as [a] = (a0, a1, a2). It should be noted that all calculations of the secret value are performed in loop Z2. l On, where a=(a0+a1+a2)mod2 l .
[0053] Further, the first share is set to 0, and a second share value is generated by a pseudo-random number generator; the third share value is determined based on the secret value and the second share value, and then the first share value, the second share value and the third share value are allocated to determine the secret share corresponding to each participant. For example, suppose P0, P1, and P2 represent three participants, and each participant holds its own secret share, that is, each participant P α (α∈{0,1,2}) holds a α-1 and a α+1 , denoted as [a] α =(a α-1 , a α+1 ); For example, P0 holds (a1, a2), P1 holds (a0, a2), and P2 holds (a0, a1). When sharing secret values, P α With P α+1 A pseudo-random number generator (PRG) and a key are pre-set, a α is set to 0, a α-1 Generated by PRG, therefore, a α+1 =aa α-1 By P α Calculate and send to P α-1。
[0054] Step S12: Based on the secret share, the mapping matrix corresponding to each participant and the feature vector corresponding to each participant are used to determine the feature attributes corresponding to each participant at each decision node, so as to obtain the comparison result of the decision node through the feature attributes.
[0055] In the embodiment of the present application, the model provider provides a pre-trained decision tree model in which a mapping matrix M and a traversal matrix T are pre-generated. Figure 2 In the decision tree model, there are m decision nodes and m+1 leaf nodes. The jth decision node is denoted as D j , the kth leaf node is denoted as Lk ; Each decision node contains a comparison: cmp (j) =1{x σ(j) <y (j)}, where x σ(j) represents an attribute in the feature vector, x is the feature value, y is the threshold specified by the model provider, σ represents the mapping: j∈{1, 2, ..., m}→i∈{1, 2, ..., n}, which is used to represent the process of selecting attribute values for each decision node, i is the sequence number of the feature vector, cmp (j) Indicates the comparison result between the two.
[0056] The function of the mapping matrix M is to select the attribute value of the feature vector for the decision node in the decision tree model. j With a decision node D j Corresponding, m j The number of elements of is equal to the number of elements of the eigenvector x. It should be noted that m j Except for the σ(j)th element which is set to 1, the rest of the elements are set to 0. j The dot product with x can extract D j The required property xσ (j) .
[0057] In the embodiment of the present application, after the input sharing stage, each participant holds their own secret share, and further, each participant jointly calculates x σ =M·x, that is, based on the secret share, the mapping matrix corresponding to each participant and the feature vector corresponding to each participant are used to determine the feature attributes corresponding to each participant at each decision node.
[0058] Furthermore, the comparison result of the decision node is obtained through the characteristic attribute, and the participants make a security comparison and jointly calculate cmp (j) =1{x σ(j) <y (j)}. In the process of security comparison, the participants first calculate the difference a between the two through the subtraction module, and then extract the most significant bit of a after bit decomposition through the adder circuit. If the most significant bit is 0, it means that the difference is a positive number; if the most significant bit is 1, it means that the difference is a negative number, so as to make a comparison. In the embodiment of the present application, when traversing the decision tree, the traversal starts from the root node. If the current node is x σ(j) Less than y (j) , then cmp (j) If it is equal to 1, select the right child node and continue traversing; otherwise, cmp (j)If it is equal to 0, select the left child node and continue traversing. This iteration continues until the current node is a leaf node. Each leaf node stores a label v (k) ,The label of the leaf node finally selected is obtained in the traversal based on the comparison result of the decision node.
[0059] Specifically, the comparison result of the decision node obtained through the feature attribute includes: traversing the decision tree model and determining the size relationship between the feature attribute and the threshold vector provided by the model provider; if the feature attribute of the current decision node is less than the threshold vector, the comparison result of the decision node is taken as 1, and the right child node of the current decision node is selected to continue traversing until the current node is the leaf node and the traversal is stopped to obtain the label of the leaf node; if the feature attribute of the current decision node is not less than the threshold vector, the comparison result of the decision node is taken as 0, and the left child node of the current decision node is selected to continue traversing until the current node is the leaf node and the traversal is stopped to obtain the label of the leaf node.
[0060] Step S13: Perform a linear transformation on the comparison result, and perform a dot product operation on the comparison result after the linear transformation and the traversal matrix corresponding to each participant, so as to determine an evaluation result based on the result of the dot product operation and the label vector carried by the leaf node.
[0061] In the embodiment of the present application, the function of traversing the matrix T is to simulate the process of traversing the decision tree. All decision nodes are regarded as a set S, and at the leaf node L k The decision nodes on the path to the root node are placed in the subset S of S k In, S k The order of k . Will traverse the row vectors of the matrix t k With leaf node L k Correspondingly, t k The number of elements in is the same as the number of decision nodes. It should be noted that for each decision node D j If it is not in S k In the (k,j) (the k-th row and j-th column element of matrix T) is set to 0; if D j In S k In, and L k In D j , then put t (k,j) Set to -1; if D j In S k In, and L k In D j t (k,j)Set to 1.
[0062] In order to reduce communication costs and avoid adding false nodes in the decision tree, the traversal process of the decision tree is converted into a dot product operation. In this process, the variant obtained by linearly transforming the comparison result obtained in step S12 is recorded as That is, using Determine the result after the linear transformation. It can be understood that since the value is 0 when traversing the left child node and the value is 1 when traversing the right child node, the comparison result pointing to the left child node is changed to -1 through this linear transformation, while the comparison result pointing to the right child node remains unchanged. If L k The label v in (k) is the classification result, then there is only t k and The dot product is equal to c k .
[0063] In the embodiment of the present application, the comparison result after the linear transformation is subjected to a dot product operation with the traversal matrix, and the result of the dot product operation is recorded as ctr (k) In determining the evaluation results, the calculation After that, a security equality test is needed to determine the result vector of each participant, and finally through v * = p·v Determine the evaluation results of each participant, and the customer will evaluate v * Perform secret reconstruction to restore the final evaluation results. It should be noted that p (j) =1{ctr (k) =c (k)}, through ctr (k) With c (k) The corresponding elements of p are determined by judging whether they are equal according to the index. (j) In the judgment process, the participants first calculate the difference a between the two through the subtraction module, and then perform an OR operation on all the bits of a after bit decomposition through the adder circuit. The result can be used to determine whether the two secret values are equal.
[0064] It is understandable that in the process of multiplication and vector dot product, the existing operation rules can be referred to, such as
[0065] Among them, μ0+μ1+μ2=0.
[0066] In addition, the calculation of addition and constant multiplication, such as a+b=(a0+a1+a2)+(b0+b1+b2)=(a0+b0)+(a1+b1)+(a2+b2), δa=δa0+δa1+δa2, also refers to the existing calculation rules in the calculation process, which will not be repeated here. It can be seen that compared with the existing solutions that mostly use homomorphic encryption technology, the calculation complexity is higher. The embodiment of the present application only requires simple arithmetic operations and has very good computing performance.
[0067] The present application provides a decision tree evaluation method based on secure multi-party computing, including: obtaining a secret value shared by a client and a model provider, and dividing the secret value into a preset number of shares by replicating the secret sharing technology, so as to determine the secret share corresponding to each participant; wherein the participants include the client, the model provider and the computing service provider; the client provides a feature vector, and the model provider provides a pre-trained decision tree model; the decision tree model includes decision nodes, leaf nodes, a mapping matrix and a traversal matrix; based on the secret share, using the mapping matrix corresponding to each participant and the feature vector corresponding to each participant to determine the feature attributes corresponding to each participant at each decision node, so as to obtain the comparison result of the decision node through the feature attributes; performing a linear transformation on the comparison result, and performing a dot product operation on the comparison result after the linear transformation and the traversal matrix corresponding to each participant, so as to determine the evaluation result based on the result of the dot product operation and the label vector carried by the leaf node. It can be seen that the client inputs the feature vector that it does not want to be leaked into the trained decision tree model provided by the model provider to perform some classification or prediction problems. Through the replication secret sharing technology, each participant holds their own secret share to participate in the calculation. All participants cannot recover the privacy data of other participants through intermediate data. The privacy data of the provider and the customer of the decision tree model will not be leaked, and only the customer obtains the final evaluation result, which has high security. By converting the decision tree traversal process into a dot product calculation, the structure of the decision tree is hidden, and the addition of false nodes in the decision tree is avoided, which reduces the communication cost and significantly improves the efficiency. In addition, since the participants of the replication secret sharing technology can be different entities, the decision tree evaluation method based on secure multi-party computing can also be extended to the security outsourcing scenario, so that the model provider and the customer do not need to participate in the calculation online, but only need to share their own input securely, which further improves the practicality of the protocol and has a wider range of applications.
[0068] The technical solution in this application can be extended to security outsourcing scenarios, such as Figure 4The figure shows the workflow applied to outsourcing expansion. The model provider can deploy the evaluation service to the cloud service provider, which acts as the computing service provider. When the customer needs the evaluation service, the input is submitted to the cloud service provider through secret sharing technology, and the cloud service provider completes the calculation together. Finally, the customer restores the evaluation result through secret sharing technology. In this process, except for the input and output, other calculations are performed by the three parties. The computing service provider has no input and output, and the data it contacts are all random numbers, so there is no risk of privacy leakage. After the agreement ends, the customer combines the data of the other two parties to restore the final evaluation result. Neither the provider nor the customer needs to stay online, nor does it need to participate in the calculation online. They only need to share their own input securely, and there is no requirement for the computing power of both parties, so the practicality of the protocol is further improved and the application scope is wider.
[0069] In order to further reduce the communication cost, the embodiment of the present invention discloses a specific decision tree evaluation method based on secure multi-party computing, see Figure 5 As shown, the method includes:
[0070] Step S21: when the number of the decision nodes is greater than a preset threshold, the traversal matrix is compressed using a divide-and-conquer method to obtain a target number of sub-traversal matrices.
[0071] Step S22: Divide the decision nodes into the sub-traversal matrices according to a preset node division rule.
[0072] In the embodiment of the present application, if the number of decision nodes in the current decision tree model is too large, the traversal matrix can be compressed to reduce the communication cost. For example, the model provider can compress the traversal matrix T of the decision tree with more than 100 decision nodes. The provider will leaf nodes are divided into a group, denoted as G′1; The leaf nodes from the mth leaf node to the m+1th leaf node are divided into a group, denoted as G2. Since all decision nodes are regarded as a set S, the subset S of S k The leaf node L k To the decision node on the path to the root node, when compressing the traversal matrix T, let and Provider based on and These three sets divide the traversal matrix T into three matrices T1 * and
[0073] In the embodiment of the present application, the division rule is: The column vectors corresponding to the decision nodes in are divided into The column vectors corresponding to the decision nodes in are divided into T1 * , The column vectors corresponding to the decision nodes in are divided into in, Remain unchanged, T1 * No. to row m+1 and 1st to Rows are removed and these removed elements are treated as public 0s in computations.
[0074] In the embodiment of the present application, the model provider can use the divide-and-conquer method to continuously * and The compression is performed until the number of compressions reaches the upper limit s. During this process, the constraint (m+1) / 2 can be set S >β to determine the size of s, where β defaults to 100. When calculating ctr, the participants can recover T through a series of compressed small matrices. * , compared with the original traversal matrix T, only the order of the column vectors has changed, and the participants have changed to T * Calculate ctr.
[0075] Correspondingly, the embodiment of the present application also discloses a decision tree evaluation device based on secure multi-party computing, see Figure 6 As shown, the device comprises:
[0076] The replication secret sharing module 11 is used to obtain the secret value shared by the client and the model provider, and divide the secret value into a preset number of shares through the replication secret sharing technology to determine the secret share corresponding to each participant; wherein the participants include the client, the model provider and the computing service provider; the client provides a feature vector, and the model provider provides a pre-trained decision tree model; the decision tree model includes decision nodes, leaf nodes, mapping matrices and traversal matrices;
[0077] A decision module 12, configured to determine the characteristic attributes corresponding to each participant at each decision node based on the secret share by using the mapping matrix corresponding to each participant and the characteristic vector corresponding to each participant, so as to obtain the comparison result of the decision node through the characteristic attributes;
[0078] The evaluation module 13 is used to perform a linear transformation on the comparison result, and perform a dot product operation on the comparison result after the linear transformation and the traversal matrix corresponding to each participant, so as to determine the evaluation result based on the result of the dot product operation and the label vector carried by the leaf node.
[0079] Among them, for more specific working processes of the above-mentioned modules, please refer to the corresponding contents disclosed in the aforementioned embodiments, which will not be repeated here.
[0080] It can be seen that through the above scheme of this embodiment, by obtaining the secret value shared by the client and the model provider respectively, and dividing the secret value into a preset number of shares through the replication secret sharing technology, the secret share corresponding to each participant is determined; wherein, the participants include the client, the model provider and the computing service provider; the client provides a feature vector, and the model provider provides a pre-trained decision tree model; the decision tree model includes decision nodes, leaf nodes, mapping matrices and traversal matrices; based on the secret share, the mapping matrix corresponding to each participant and the feature vector corresponding to each participant are used to determine the feature attributes corresponding to each participant at each decision node, so as to obtain the comparison result of the decision node through the feature attributes; the comparison result is linearly transformed, and the comparison result after the linear transformation is dot-producted with the traversal matrix corresponding to each participant, so as to determine the evaluation result based on the result of the dot product operation and the label vector carried by the leaf node. It can be seen that the client inputs the feature vector that it does not want to be leaked into the trained decision tree model provided by the model provider to perform some classification or prediction problems. Through the replication secret sharing technology, each participant holds their own secret share to participate in the calculation. All participants cannot recover the privacy data of other participants through intermediate data. The privacy data of the provider and the customer of the decision tree model will not be leaked, and only the customer obtains the final evaluation result, which has high security. By converting the decision tree traversal process into a dot product calculation, the structure of the decision tree is hidden, and the addition of false nodes in the decision tree is avoided, which reduces the communication cost and significantly improves the efficiency. In addition, since the participants of the replication secret sharing technology can be different entities, the decision tree evaluation method based on secure multi-party computing can also be extended to the security outsourcing scenario, so that the model provider and the customer do not need to participate in the calculation online, but only need to share their own input securely, which further improves the practicality of the protocol and has a wider range of applications.
[0081] Furthermore, the present application also discloses an electronic device. Figure 7 This is a structural diagram of an electronic device 20 according to an exemplary embodiment, and the content in the diagram cannot be considered as any limitation on the scope of use of the present application.
[0082] Figure 7A schematic diagram of the structure of an electronic device 20 provided in an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the decision tree evaluation method based on secure multi-party computing disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be a computer.
[0083] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device, and the communication protocol it follows is any communication protocol that can be applied to the technical solution of the present application, and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs and is not specifically limited here.
[0084] In addition, the memory 22 as a carrier for resource storage may be a read-only memory, a random access memory, a disk or an optical disk, etc. The resources stored thereon may include an operating system 221, a computer program 222 and data 223, etc. The data 223 may include various data. The storage method may be temporary storage or permanent storage.
[0085] The operating system 221 is used to manage and control the hardware devices and computer program 222 on the electronic device 20, which can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program that can be used to complete the decision tree evaluation method based on secure multi-party computing performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include a computer program that can be used to complete other specific tasks.
[0086] Further, the embodiment of the present application also discloses a computer-readable storage medium, wherein the computer-readable storage medium mentioned here includes a random access memory (Random Access Memory, RAM), a memory, a read-only memory (Read-Only Memory, ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a magnetic disk or an optical disk, or any other form of storage medium known in the technical field. Wherein, when the computer program is executed by the processor, the aforementioned decision tree evaluation method based on secure multi-party computing is implemented. For the specific steps of the method, reference can be made to the corresponding contents disclosed in the aforementioned embodiments, which will not be repeated here.
[0087] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.
[0088] The steps of the decision tree evaluation or algorithm based on secure multi-party computing described in conjunction with the embodiments disclosed herein can be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module can be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0089] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the statement "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0090] The decision tree evaluation method, device, equipment and medium based on secure multi-party computing provided by the present invention are introduced in detail above. Specific examples are used in this article to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea; at the same time, for those skilled in the art, according to the idea of the present invention, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as limiting the present invention.
Claims
1. A decision tree evaluation method based on secure multi-party computing, characterized in that: include: Obtain the secret value shared by the client and the model provider, and divide the secret value into a preset number of shares by replicating the secret sharing technology to determine the secret share corresponding to each participant; wherein the participants include the client, the model provider and the computing service provider; the client provides a feature vector, and the model provider provides a pre-trained decision tree model; the decision tree model includes decision nodes, leaf nodes, a mapping matrix and a traversal matrix; Based on the secret share, the mapping matrix corresponding to each participant and the feature vector corresponding to each participant are used to determine the feature attributes corresponding to each participant at each decision node, so as to obtain the comparison result of the decision node through the feature attributes; Performing a linear transformation on the comparison result, and performing a dot product operation on the comparison result after the linear transformation and the traversal matrix corresponding to each participant, so as to determine an evaluation result based on the result of the dot product operation and the label vector carried by the leaf node; The step of performing a dot product operation on the comparison result after the linear transformation and the traversal matrix corresponding to each participant so as to determine an evaluation result based on the result of the dot product operation and the label vector carried by the leaf node includes: Performing a dot product operation on the comparison result after the linear transformation and the traversal matrix corresponding to each participant, determining the difference between the result of the dot product operation and the order of the target subset of the decision node set, so as to use the difference to judge whether the result of the dot product operation is equal to the order of the target subset of the decision node set; wherein the target subset is the set of decision nodes included in the path from the current leaf node to the root node in the decision tree model; Decomposing the difference by using an adder circuit, and performing a logical OR operation on all bits obtained after the decomposition to obtain a result vector; The evaluation result is determined using the result vector and the label vector carried by the leaf node.
2. The decision tree evaluation method based on secure multi-party computing according to claim 1, characterized in that: The obtaining the comparison result of the decision node by using the feature attribute includes: Traversing the decision tree model and determining the magnitude relationship between the feature attribute and the threshold vector provided by the model provider; If the characteristic attribute of the current decision node is less than the threshold vector, the comparison result of the decision node is set to 1, and the right child node of the current decision node is selected to continue traversing until the current node is the leaf node and the traversal is stopped to obtain the label of the leaf node; If the characteristic attribute of the current decision node is not less than the threshold vector, the comparison result of the decision node is taken as 0, and the left child node of the current decision node is selected to continue traversing until the current node is the leaf node and the traversal is stopped to obtain the label of the leaf node.
3. The decision tree evaluation method based on secure multi-party computing according to claim 2 is characterized in that: The performing a linear transformation on the comparison result comprises: The comparison result is multiplied by 2 and then subtracted by 1, so as to change the comparison result pointing to the left child node to -1 and keep the comparison result pointing to the right child node unchanged.
4. The decision tree evaluation method based on secure multi-party computing according to claim 1, characterized in that: The step of obtaining the secret value shared by the client and the model provider, and dividing the secret value into a preset number of shares by using a replication secret sharing technology to determine the secret share corresponding to each participant, includes: Obtaining the secret value shared by the client and the model provider, and dividing the secret value into shares equal to the number of the participants to obtain a first share, a second share, and a third share; The first share value is set to 0, and a second share value is generated using a pseudo-random number generator; A third share value is determined based on the secret value and the second share value, and then the first share value, the second share value and the third share value are allocated to determine the secret share corresponding to each participant.
5. The decision tree evaluation method based on secure multi-party computing according to claim 2, characterized in that: The determining, based on the secret share, of the feature attributes corresponding to each participant at each decision node by using the mapping matrix corresponding to each participant and the feature vector corresponding to each participant, so as to obtain the comparison result of the decision node through the feature attributes, includes: Based on the secret share, the mapping matrix corresponding to each participant and the feature vector corresponding to each participant are used to determine the feature attributes corresponding to each participant at each decision node, and the difference between the feature attributes and the threshold vector is decomposed by an adder circuit. If the highest bit of the decomposed difference is 1, it is determined that the feature attribute is less than the threshold vector; if the highest bit of the decomposed difference is 0, it is determined that the feature attribute is greater than the threshold vector.
6. The decision tree evaluation method based on secure multi-party computing according to any one of claims 1 to 5, characterized in that: Also includes; When the number of the decision nodes is greater than a preset threshold, the traversal matrix is compressed using a divide-and-conquer method to obtain a target number of sub-traversal matrices; The decision nodes are divided into the sub-traversal matrices according to a preset node division rule.
7. A decision tree evaluation device based on secure multi-party computing, characterized in that: include: A replication secret sharing module is used to obtain the secret value shared by the client and the model provider, and divide the secret value into a preset number of shares through the replication secret sharing technology to determine the secret share corresponding to each participant; wherein the participants include the client, the model provider and the computing service provider; the client provides a feature vector, and the model provider provides a pre-trained decision tree model; the decision tree model includes decision nodes, leaf nodes, mapping matrices and traversal matrices; A decision module, configured to determine the characteristic attributes corresponding to each participant at each decision node by using the mapping matrix corresponding to each participant and the characteristic vector corresponding to each participant based on the secret share, so as to obtain a comparison result of the decision node through the characteristic attributes; An evaluation module, configured to perform a linear transformation on the comparison result, and perform a dot product operation on the comparison result after the linear transformation and the traversal matrix corresponding to each participant in the secret share, so as to determine an evaluation result based on the result of the dot product operation and the label vector carried by the leaf node; The evaluation module is specifically used for: Performing a dot product operation on the comparison result after the linear transformation and the traversal matrix corresponding to each participant, determining the difference between the result of the dot product operation and the order of the target subset of the decision node set, so as to use the difference to judge whether the result of the dot product operation is equal to the order of the target subset of the decision node set; wherein the target subset is the set of decision nodes included in the path from the current leaf node to the root node in the decision tree model; Decomposing the difference by using an adder circuit, and performing a logical OR operation on all bits obtained after the decomposition to obtain a result vector; The evaluation result is determined using the result vector and the label vector carried by the leaf node.
8. An electronic device, characterized in that: The electronic device includes a processor and a memory; wherein the memory is used to store a computer program, and the computer program is loaded and executed by the processor to implement the decision tree evaluation method based on secure multi-party computing as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that: Used to store computer programs; wherein the computer program, when executed by a processor, implements the decision tree evaluation method based on secure multi-party computing as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Matrix multiplication task outsourcing method supporting privacy protection based on edge computing
CN111984990A
Key-value pair model safety training and reasoning method based on safety multi-party calculation
CN113535808A