A medical image differential privacy protection method based on wavelet multi-resolution correlation analysis
Patent Information
- Application Number
- CN202311491174.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-09
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2043-11-09
AI Technical Summary
[0008]本发明的技术解决问题:针对小波多分辨率分析场景下,图像经小波分解后各小波频带的小波系数存在数据关联,导致经典差分隐私机制应用于图像小波频带隐私保护时难以满足差分隐私保护的问题,提供一种基于多分辨率关联分析的医疗图像差分隐私保护方法,尤其是基于标准化互信息的图像小波频带关联度衡量方法,并基于关联差分隐私机制设计差分隐私保护算法,解决图像在发布共享时面临的数据隐私泄漏问题
[0035](1)本发明提出的基于小波多分辨率关联分析的医疗图像差分隐私保护方法能够在一定程度上衡量图像在小波多分辨率分析场景下,不同的小波频带系数存在的数据关联,依据数据关联程度对图像进行关联差分隐私扰动,相比经典差分隐私机制能够为图像提供更加严格的差分隐私保护。
Smart Images

Figure CN117788254B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a differential privacy protection method for medical images based on multi-resolution correlation analysis, belonging to the field of network security technology. Background Technology
[0002] The era of big data urgently demands that medical institutions and research institutes publish and share medical image data. Medical image data contains physical information about the patient's internal organs, which constitutes patient privacy; therefore, privacy and security issues cannot be ignored during the publication and sharing of medical images. Common image protection methods include data encryption and data perturbation. Traditional data encryption methods, due to their complex computational overhead and low data utility, present many inconveniences in the application of the big data era. With the development of deep learning models, traditional image data perturbation techniques such as pixelation and bounding box blurring are no longer sufficient to protect image privacy and security. How to prevent the leakage of sensitive information in medical images is a major challenge currently faced in the open sharing of medical images.
[0003] In 2006, Dwork proposed differential privacy, which effectively addressed the main problems of traditional privacy protection models based on data perturbation, namely their reliance on attacker background knowledge and lack of mathematical proof of privacy protection levels. Differential privacy assumes that the attacker possesses the strongest background knowledge and provides rigorous proofs of privacy protection strength. It is one of the most advanced privacy protection technologies currently available and has been widely used in machine learning, recommender systems, and other fields.
[0004] Image differential privacy is a relatively new application of differential privacy. Based on the different image processing techniques employed, existing research can be broadly categorized into image differential privacy protection methods based on spatial domain processing and those based on transform domain processing. Representative methods based on spatial domain processing include those based on image mosaic processing, matrix singular value decomposition, and matrix nonnegativity decomposition. Transform domain processing is another important image processing method, with representative methods based on discrete Fourier transform, discrete cosine transform, and discrete wavelet transform.
[0005] Wavelet transform is a widely used image processing technique. JPEG 2000, a next-generation image compression standard, uses 5 / 3 integer wavelet transform to achieve lossless image compression and restoration, aiming to replace the JPEG standard based on discrete cosine transform. Through integer wavelet transform, the image is decomposed into low-frequency subbands and high-frequency subbands in three different directions: horizontal, vertical, and diagonal. The low-frequency subbands retain most of the original image information, while the horizontal, vertical, and diagonal high-frequency subbands retain image details in different directions. This method of performing wavelet transform on an image and decomposing the original image into multiple wavelet frequency bands is called wavelet multi-resolution analysis. Wavelet multi-resolution analysis technology is widely used in the field of medical image processing, and is extensively used in many scenarios such as image compression, image enhancement, image denoising, and image fusion.
[0006] Classical differential privacy mechanisms assume that the protected data are independent and identically distributed. However, some scholars have pointed out that when data in a dataset is correlated, classical differential privacy mechanisms fail to achieve the original level of privacy protection, a point verified experimentally. To address this issue, improved versions of classical differential privacy mechanisms have been proposed, primarily along three technical routes: introducing correlation parameters to describe data relationships, providing a simple and intuitive improvement; defining Gaussian correlation models and Markov chain correlation models for specific application scenarios to describe more complex data relationships; and researching new privacy protection frameworks to fundamentally solve the differential privacy protection problem for correlated data.
[0007] The brick-wall property of wavelet transform leads to varying degrees of data correlation between wavelet coefficients within wavelet frequency bands in wavelet multi-resolution analysis scenarios. Attackers can use adjacent wavelet coefficients to infer the value of target wavelet coefficients. Considering this data correlation when performing differential privacy protection on wavelet frequency bands, it is essential to design a method that can describe the data correlation within image wavelet frequency bands and address the weakening of differential privacy protection by such correlation. To ensure that images still satisfy differential privacy during wavelet multi-resolution analysis, this invention combines information theory with correlation mining, applying it to the differential privacy protection of correlated data, providing more stringent differential privacy protection for medical image data in wavelet multi-resolution analysis applications. Summary of the Invention
[0008] The technical problem addressed by this invention is that in wavelet multi-resolution analysis scenarios, the wavelet coefficients of different wavelet frequency bands in an image after wavelet decomposition exhibit data correlation, making it difficult for classical differential privacy mechanisms to meet the requirements of differential privacy protection when applied to image wavelet frequency band privacy protection. This invention provides a differential privacy protection method for medical images based on multi-resolution correlation analysis, particularly a method for measuring the correlation degree of image wavelet frequency bands based on standardized mutual information. Furthermore, a differential privacy protection algorithm is designed based on the correlation differential privacy mechanism to solve the data privacy leakage problem faced when images are published and shared.
[0009] The technical solution adopted in this invention is: a differential privacy protection method for medical images based on wavelet multi-resolution correlation analysis, which includes the following steps:
[0010] Step 1: Perform multi-level wavelet decomposition on the medical image to be protected.
[0011] The image is decomposed into multiple levels using the 5 / 3 integer wavelet transform from the JPEG 2000 standard. For ease of understanding, this invention uses a two-level wavelet decomposition, but the method is applicable to wavelet decomposition of images at any level. After image decomposition, wavelet bands LL1, HL1, LH1, and HH1 are obtained. The low-frequency band LL1 is then decomposed into two levels to obtain LL2, HL2, LH2, and HH2.
[0012] Step 2: Calculate the correlation between wavelet frequency bands obtained from wavelet decomposition of the image.
[0013] 2.1 Registration of wavelet frequency bands with different resolutions
[0014] For the wavelet frequency bands LL2, HL2, LH2, HH2, HL1, LH1, and HH1 obtained in step one, perform resolution registration on any two wavelet frequency bands PX and X using inverse wavelet transform, and calculate the number of inverse transforms required, T = log2(R). PX / R X ), where R Px For PX resolution, R X Let X be the resolution. The wavelet band PX with the lower resolution is taken as the low-frequency band, and the zero matrix with the same resolution as PX is taken as the high-frequency band. The inverse wavelet transform is iteratively performed until it has the same resolution as the wavelet band X.
[0015] 2.2 Calculate the information entropy H(PX) and H(X) and the conditional entropy H(PX|X) of any two wavelet frequency bands PX and X respectively; count the probability of the occurrence of each wavelet coefficient value in the wavelet frequency band, and calculate the information entropy H(PX) and H(X) of the wavelet frequency bands PX and X, as well as their conditional entropy H(PX|X), according to the definition of information entropy and conditional entropy in information theory.
[0016] 2.3 Calculate the mutual information I(PX, X) between wavelet band PX and X based on H(PX), H(X), and H(PX|X), and further calculate the normalized mutual information NMI(PX, X). Let the normalized mutual information be the correlation degree δ between PX and X. PX,X .
[0017] 2.4 Repeat steps 2.1 to 2.3 until the correlation δ between each pair of frequency bands LL2, HL2, LH2, HH2, HL1, LH1, and HH1 is reached. ij All calculations have been completed.
[0018] Step 3: Calculate the overall correlation of the images
[0019] 3.1 Constructing the wavelet frequency band correlation matrix
[0020] Based on the correlation δ between any two wavelet frequency bands calculated in step two ij Construct a two-dimensional correlation matrix δ. The element in the i-th row and j-th column of the matrix represents the correlation between wavelet band i and wavelet band j. Set the correlation between the wavelet band and itself to 1, that is, set the diagonal elements of the matrix to 1.
[0021] 3.2 Calculate the overall correlation of wavelet band coefficients in the image.
[0022] Based on the correlation matrix δ, calculate the sum δ of each row. i. Let Γ = max{δ i.} represents the overall data correlation of the image wavelet frequency band.
[0023] Step 4: Use a correlation-based differential privacy mechanism to perform differential privacy protection on the wavelet frequency band.
[0024] 4.1 Design of Differential Privacy Perturbation Algorithm Based on Medical Image Data Features
[0025] Medical images are discrete integers with values ranging from [0, 255]. Bounded discrete data can be used to design differential privacy perturbation algorithms using the differential privacy index mechanism. For an image pixel or wavelet coefficient pixel to be differentially privacy perturbed, its neighboring element is defined as another element whose value differs from the pixel by 1.
[0026] For each wavelet frequency band matrix subband, obtain the maximum value Max and the minimum value Min. Let the set Range be the range of all integer values between Min and Max, i.e., Range = [Min, Max]. Design the utility function f = |Range| - abs(pixel - r). For each element r in the Range set, i.e., pixel, calculate its utility value f(r) for all possible perturbation results, where |Range| is the size of the set Range, and abs() is the absolute value calculation function.
[0027] Calculate the weight wr = exp(εf(r) / 2Γ) for each r in the Range set, where ε is the privacy budget and Γ is the image data correlation degree calculated in step three; calculate the sum of the weights of all r, Sum = ∑w r And calculate the output probability P(r) = w for each r. r / Sum outputs an r as the differential privacy perturbation value of the wavelet band coefficient pixel according to probability P(r).
[0028] 4.2 Perturb all wavelet coefficients in the wavelet band
[0029] Differential privacy perturbation is performed on each wavelet coefficient in the wavelet subband until all coefficients in the band have been protected by differential privacy. The parallel combination theorem of differential privacy guarantees that the perturbed subband' satisfies ε-differential privacy.
[0030] 4.3 Correlation differential privacy protection for all wavelet frequency bands
[0031] The wavelet frequency bands LL2, HL2, LH2, HH2, HL1, LH1, and HH1 are sequentially associated with differential privacy perturbations using the methods in steps 4.1 and 4.2 to obtain the differential privacy-protected wavelet frequency bands LL′2, HL′2, LH′2, HH′2, HL′1, LH′1, and HH′1.
[0032] Step 5: Restore the image to its original resolution as the final privacy-protected image.
[0033] For the differential privacy-preserving wavelet bands LL′2, HL′2, LH′2, HH′2, HL′1, LH′1, and HH′1 obtained in step four, first, perform inverse wavelet transform on LL′2, HL′2, LH′2, and HH′2 to obtain LL′1; then, perform inverse wavelet transform on LL′1, HL′1, LH′1, and HH′1 to obtain the differential privacy-preserving image Image'. The post-processing immune property of differential privacy ensures that Image' satisfies ε-differential privacy.
[0034] The advantages of this invention compared to the prior art are:
[0035] (1) The medical image differential privacy protection method based on wavelet multi-resolution correlation analysis proposed in this invention can measure the data correlation of different wavelet frequency band coefficients in the wavelet multi-resolution analysis scenario to a certain extent. Based on the degree of data correlation, the image is subjected to correlation differential privacy perturbation, which can provide more stringent differential privacy protection for the image compared with the classic differential privacy mechanism.
[0036] (2) Based on the characteristics of medical image data, the present invention designs a differential privacy perturbation algorithm and designs a utility function to evaluate the utility of all possible output results before outputting the differential privacy perturbation data. The value with the highest data utility is output according to probability as the differential privacy perturbation result, thereby improving the data availability of the differential privacy protection method. Attached Figure Description
[0037] Figure 1 This is a schematic diagram of multi-resolution analysis;
[0038] Figure 2 This is a schematic diagram illustrating the use of wavelet transform to perform multi-level decomposition of an image for multi-resolution analysis.
[0039] Figure 3 This is a flowchart of the method of the present invention.
[0040] The symbols in the diagram are explained as follows:
[0041] Image represents an image that requires differential privacy protection;
[0042] Image′ represents the image after differential privacy protection;
[0043] δ LL,HL This indicates the correlation between the low-frequency subband and the horizontal high-frequency subband;
[0044] δ LL,LH This indicates the correlation between the low-frequency subband and the vertical high-frequency subband;
[0045] δ HL,HH This indicates the correlation between the horizontal high-frequency subband and the diagonal high-frequency subband;
[0046] δ LH,HH This indicates the correlation between the vertical high-frequency subband and the diagonal high-frequency subband;
[0047] δ represents the wavelet band correlation matrix;
[0048] Γ represents the overall correlation of the wavelet band coefficients in the image;
[0049] LL n HL n LH n HHn These represent the low-frequency sub-band, horizontal high-frequency sub-band, vertical high-frequency sub-band, and diagonal high-frequency sub-band of the nth-level wavelet decomposition.
[0050] LL′ n HL′ n 、LH′ n HH′ n The terms represent the low-frequency subband, horizontal high-frequency subband, vertical high-frequency subband, and diagonal high-frequency subband of the nth-level wavelet decomposition with differential privacy protection. Detailed Implementation
[0051] The proposed method for differential privacy protection of medical images based on wavelet multi-resolution correlation analysis needs to solve the following two problems: (1) How to measure the data correlation of wavelet bands and perform appropriate correlation differential privacy perturbation based on the degree of data correlation to ensure that the image after perturbation still satisfies differential privacy; (2) What differential privacy mechanism should be used to design the wavelet band correlation differential privacy protection algorithm to ensure that the privacy-protected image satisfies differential privacy while maximizing the availability of output data.
[0052] To address problem (1), this invention calculates wavelet band correlation based on standardized mutual information. Information entropy is an effective tool for characterizing the information content of an information system. Information theory posits that the more ordered the system, the lower the information entropy; conversely, the more chaotic the system, the higher the information entropy. Therefore, information entropy can serve as a measure of the uncertainty of a system. Mutual information based on information entropy theory can be used to measure the correlation between two variables and can effectively characterize linear and nonlinear relationships between variables.
[0053] To calculate the mutual information of wavelet bands PX and X, it is necessary to first obtain the marginal probability distributions p(px) and p(x) of PX and X respectively, as well as the joint probability distribution p(px, x) of PX and X. For the wavelet coefficients in the wavelet band matrix, their probability distribution functions are actually extremely difficult to obtain. Therefore, it is necessary to estimate the probability distribution functions using nonparametric methods based on existing empirical data: for the wavelet band X, statistically analyze the different coefficients X(i) existing in its matrix and the frequency N of each coefficient. X(i) The marginal probability distribution p(x) of wavelet band X can be obtained by estimating the probability using frequency. Regarding the calculation method of the joint probability distribution p(px,x) of PX and X, count the frequency of each combination of values (px,x) in PX and X occurring simultaneously, and divide the frequency of each combination of values by the number of elements in PX or X to obtain the joint probability distribution of PX and X.
[0054] The above method requires wavelet bands PX and X to have the same resolution. However, after multi-level wavelet decomposition of an image, numerous wavelet bands with different resolutions exist. Wavelet bands with different resolutions have different numbers of wavelet coefficients, making it impossible to establish a bijective relationship (px, x) between wavelet coefficients of different resolutions using the above method. Note that the 5 / 3 integer wavelet transform is a linear transform; performing a linear transform on a random variable does not change the information content of the random variable. The zero matrix contains no information. Therefore, performing an inverse wavelet transform on the low-resolution wavelet band PX and the zero matrix will not change the information entropy of the original PX, and thus will not change the mutual information between PX and X. Instead, the mutual information between the two wavelet bands can be calculated by performing an inverse transform on PX and the zero matrix to perform resolution registration between PX and X.
[0055] Since the correlation between data and itself is 1, the correlation with other data must be less than the correlation with itself. Therefore, the correlation between data in two wavelet frequency bands should be a value within the interval [0, 1]. The value of mutual information does not meet the requirement of being within the interval [0, 1]. Therefore, the concept of standardized mutual information (NMI) is adopted, and the mutual information (MI) is standardized to the interval [0, 1], which can then be used as the correlation between two wavelet frequency bands.
[0056] To address problem (2), this invention designs a correlation differential privacy perturbation algorithm based on a differential privacy exponential mechanism. The differential privacy exponential mechanism is defined as follows: for a utility function f: U×Range→R, there exists an input dataset... The utility function generates a utility value f(D, r) for each (D, r) in the U×Range. The exponential mechanism selects and outputs the result r from the Range with a probability proportional to exp(εf(D, r) / 2Δf), where Δf is the sensitivity of the utility function f. The exponential mechanism maps the input individuals of the entire set U to a certain output of the Range, and the utility function calculates a different utility value for each individual. The higher the utility value, the greater the probability that the individual will be output. Therefore, the differential privacy exponential mechanism can maximize data utility while ensuring that the protected data meets differential privacy requirements.
[0057] Generally, the exponential mechanism is often used for differential privacy protection of non-numerical data. In fact, the exponential mechanism can be used for differential privacy perturbation of discrete data. Medical images are mainly grayscale images, and the image data are discrete integers with values in the range [0, 255]. The wavelet coefficients obtained after the 5 / 3 integer wavelet transform of the medical image are also discrete integers. Therefore, the exponential mechanism can be used for differential privacy protection of medical images.
[0058] The specific implementation steps of a differential privacy protection method for medical images based on wavelet multi-resolution correlation analysis are as follows:
[0059] Step 1: Perform integer wavelet decomposition on the medical image to be protected.
[0060] The image Image is decomposed into integer wavelet components using a 5 / 3 integer wavelet transform. For ease of understanding, this invention uses a two-level wavelet decomposition, but in practice, the method is applicable to wavelet decomposition of images at any level. First, the original image Image is decomposed into wavelet bands LL1, HL1, LH1, and HH1. Then, LL1 is further decomposed into LL2, HL2, LH2, and HH2.
[0061] Step 2: Calculate the correlation between wavelet frequency bands obtained from wavelet decomposition of the image.
[0062] 2.1 Registration of wavelet frequency bands with different resolutions
[0063] For the wavelet frequency bands LL2, HL2, LH2, HH2, HL1, LH1, and HH1 obtained in step one, perform resolution registration on any two wavelet frequency bands PX and X using inverse wavelet transform, and calculate the number of inverse transforms required, T = log2(R). PX / R X ), where R PX For PX resolution, P X Let X be the resolution. The wavelet band PX with the lower resolution is taken as the low-frequency band, and the zero matrix with the same resolution as PX is taken as the high-frequency band. Inverse wavelet transform is performed until it has the same resolution as the wavelet band X.
[0064] 2.2 Calculate the information entropy H(PX) and H(X) and the conditional entropy H(PX|X) of wavelet bands PX and X respectively; count the probability of each value appearing in the wavelet band, and calculate the information entropy H(PX) and H(X) of wavelet bands PX and X and their conditional entropy H(PX|X) according to the relevant definitions of information theory.
[0065] 2.3 Calculate the mutual information I(PX, X) and normalized mutual information NMI(PX, X) of wavelet band PX and X based on H(PX), H(X) and H(PX|X), and let the normalized mutual information be the correlation degree δ between PX and X. PX,X .
[0066] 2.4 Repeat steps 2.1 to 2.3 until the correlation δ between any two wavelet bands LL2, HL2, LH2, HH2, HL1, LH1, and HH1 in the image is reached. ij All calculations have been completed.
[0067] Step 3: Calculate the overall correlation of the images
[0068] 3.1 Constructing the wavelet frequency band correlation matrix
[0069] Based on the correlation δ between any two wavelet frequency bands calculated in step two ij Construct a two-dimensional correlation matrix δ. The element in the i-th row and j-th column of the matrix represents the correlation between wavelet band i and wavelet band j. Set the correlation between the wavelet band and itself to 1, that is, set the diagonal elements of the matrix to 1.
[0070] 3.2 Calculate the overall correlation of wavelet band coefficients in the image
[0071] Based on the correlation matrix δ, calculate the sum δ of each row. i. Let Γ = max{δ i.} represents the overall data correlation of the image wavelet frequency band.
[0072] Step 4: Use a correlation-based differential privacy mechanism to perform differential privacy protection on the wavelet frequency band.
[0073] 4.1 Design a differential privacy perturbation algorithm based on image data features
[0074] For each wavelet frequency band matrix subband, obtain the maximum value Max and the minimum value Min. Let the set Range be the range of all integer values between Min and Max, i.e., Range = [Min, Max]. Design the utility function f = |Range| - abs(pixel - r), and calculate the utility value f(r) for each r in the Range set, where |Range| is the size of the set Range, abs() is the absolute value function, and pixel is the wavelet coefficient to be subjected to differential privacy perturbation.
[0075] Calculate the weight w for each r in the Range set. r =exp(εf(r) / 2Γ), where ε is the privacy budget and Γ is the image data correlation degree calculated in step three; calculate the sum of weights of all r: Sum = ∑w r And calculate the output probability P(r) = w for each r. r / Sum, output r with probability P(r) as the differential privacy perturbation value of the wavelet band coefficient pixel.
[0076] Under classical differential privacy theory, the sensitivity Δf of the utility function f can be proven to be 1. However, in wavelet multiresolution analysis, due to the data correlation between wavelet bands, modifying the coefficients of one wavelet band will cause significant changes in the values of the coefficients of other associated wavelet bands. Setting Δf = 1 will not satisfy ε-differential privacy. By using a correlation-based differential privacy mechanism, Δf is amplified to the correlation degree Γ of the entire image, thus achieving ε-differential privacy.
[0077] 4.2 Perturb all wavelet coefficients in the wavelet band
[0078] Differential privacy perturbation is performed on each wavelet coefficient in the wavelet subband until all coefficients in the band have been protected by differential privacy. The parallel combination theorem of differential privacy guarantees that the perturbed subband' satisfies ε-differential privacy.
[0079] 4.3 Correlation differential privacy protection for all wavelet frequency bands
[0080] The wavelet bands LL2, HL2, LH2, HH2, HL1, LH1, and HH1 are sequentially subjected to correlated differential privacy perturbations using the methods described in 4.1 and 4.2 to obtain the differential privacy-protected wavelet bands LL′2, HL′2, LH′2, HH′2, HL′1, LH′1, and HH′1.
[0081] Step 5: Restore the image to its original resolution as the final privacy-protected image.
[0082] For the differential privacy-preserving wavelet bands LL′2, HL′2, LH′2, HH′2, HL′1, LH′1, and HH′1 obtained in step four, perform inverse wavelet transform on LL′2, HL′2, LH′2, and HH′2 to obtain LL′1; perform inverse wavelet transform on LL′1, HL′1, LH′1, and HH′1 to obtain the differential privacy-preserving image Image'. The post-processing immunity property of differential privacy ensures that Image' satisfies ε-differential privacy.
[0083] The contents not described in detail in this specification are existing technologies known to those skilled in the art.
[0084] The above description is merely a preferred embodiment of the medical image differential privacy protection method based on wavelet multi-resolution correlation analysis of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the medical image differential privacy protection method based on wavelet multi-resolution correlation analysis of the present invention. These improvements and modifications should also be considered as protection within the scope of the medical image differential privacy protection method based on wavelet multi-resolution correlation analysis of the present invention.
Claims
1. A differential privacy protection method for medical images based on wavelet multi-resolution correlation analysis, characterized in that, It includes the following steps: Step 1: Perform integer wavelet decomposition on the medical image to be protected. The image Image is decomposed into multi-level integer wavelet decomposition using wavelet transform. Step 2: Calculate the correlation between wavelet frequency bands obtained from wavelet decomposition of the image. Based on all wavelet frequency bands obtained from step one, calculate the correlation between any two wavelet frequency bands, including: performing resolution registration on any two wavelet frequency bands PX and X; sequentially performing inverse wavelet transform on the wavelet frequency band PX with the smaller resolution and a zero matrix of the same resolution until the wavelet frequency band has the same resolution as the wavelet frequency band X; calculating the information entropy H(PX), H(X) and conditional entropy H(PX|X) of wavelet frequency bands PX and X respectively; calculating the mutual information and normalized mutual information NMI(PX, X) between wavelet frequency bands PX and X based on H(PX), H(X) and H(PX|X), and letting the normalized mutual information be the correlation between PX and X δ. PX,X ; Step 3: Calculate the overall correlation of the images Calculate the overall correlation of the wavelet frequency band coefficients in the image, including: the correlation δ between wavelet frequency band i and wavelet frequency band j calculated according to the method in step two. ij Construct the wavelet frequency band correlation matrix δ; for the correlation matrix δ, calculate the sum of each row to obtain δ. i· And take the maximum value as the overall data correlation degree Γ of the image; Step 4: Perform correlation differential privacy protection for each wavelet frequency band. Correlational differential privacy protection is performed on each wavelet frequency band, including: using the correlation degree Γ of the wavelet coefficients of the image as the sensitivity of the differential privacy query function, designing a correlational differential privacy perturbation algorithm, performing differential privacy perturbation on each wavelet coefficient in the wavelet frequency band matrix subband to obtain the perturbated wavelet frequency band subband′; and performing perturbation processing on all wavelet frequency bands in sequence to obtain the differential privacy-protected wavelet frequency band. Step 5: Input the differential privacy-preserving wavelet frequency bands obtained in Step 4 into the inverse integer wavelet transform in sequence to restore the original resolution image as the final privacy-preserving image.
2. The medical image differential privacy protection method based on wavelet multi-resolution correlation analysis according to claim 1, characterized in that, The multi-level integer wavelet decomposition is converted into a two-level wavelet decomposition.
3. The differential privacy protection method for medical images based on wavelet multi-resolution correlation analysis according to claim 1 or 2, characterized in that: Step two, the specific process is as follows: 2.1 Registration of wavelet frequency bands with different resolutions For the wavelet frequency bands obtained in step one, perform resolution registration on any two wavelet frequency bands PX and X using inverse wavelet transform, and calculate the number of inverse transforms required, T = log2(R). PX / R X ), where R PX For PX resolution, R X Let X be the resolution; take the wavelet frequency band PX with the smaller resolution as the low frequency band and the zero matrix with the same resolution as PX as the high frequency band, and perform inverse wavelet transform iteratively until it has the same resolution as the wavelet frequency band X. 2.2 Calculate the information entropy H(PX) and H(X) and the conditional entropy H(PX|X) for each of the two wavelet frequency bands PX and X respectively; count the probability of the occurrence of each wavelet coefficient value in the wavelet frequency band, and calculate the information entropy H(PX) and H(X) of the wavelet frequency bands PX and X, as well as their conditional entropy H(PX|X), according to the definition of information entropy and conditional entropy in information theory; 2.3 Calculate the mutual information I(PX, X) between wavelet band PX and X based on H(PX), H(X), and H(PX|X), and further calculate the normalized mutual information NMI(PX, X). Let the normalized mutual information be the correlation degree δ between PX and X. PX,X ; 2.4 Repeat steps 2.1 to 2.3 until the correlation between any two frequency bands is δ. ij All calculations have been completed.
4. The differential privacy protection method for medical images based on wavelet multi-resolution correlation analysis according to claim 1 or 2, characterized in that: The specific process in step four is as follows: For each wavelet frequency band matrix subband, obtain the maximum value Max and minimum value Min of the elements in the matrix, and let the set Range be the range of all integer values between Min and Max, that is, Range = [Min, Max]; Design a utility function f = |Range| - abs(pixel - r), calculate the utility value f(r) for each r in the Range set, that is, evaluate the utility of all possible perturbation results r of the pixel, where |Range| is the size of the Range set, abs() is the absolute value function, and pixel is the wavelet coefficient to be subjected to differential privacy perturbation in the subband matrix; Calculate the weight w for each r in the Range set. r =exp(εf(r) / 2Γ), where ε is the privacy budget and Γ is the image data correlation degree calculated in step three; Calculate the sum of the weights of all r: Sum = ∑w r And calculate the output probability P(r) = w for each r. r / Sum, outputs an r as the differential privacy perturbation value of the wavelet band coefficient pixel according to probability P(r); Differential privacy perturbation is applied to each wavelet coefficient in the wavelet subband until all coefficients in the band are differentially privacy protected.