Privacy Access Control Method and System in the Internet of Things Environment

By using IoT conversation desensitization networks and privacy access control networks trained in IoT environments, the problem of privacy leakage and processing pressure in traditional methods is solved, and efficient and secure privacy access control is achieved.

CN119094152BActive Publication Date: 2025-07-22CHENGDU LECHAOREN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410984443.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-22
Publication Date
2025-07-22
Estimated Expiration
2044-07-22

AI Technical Summary

Technical Problem

When traditional IoT privacy access control methods face complex and changeable IoT environments and massive data, it is difficult to effectively cover all scenarios, which poses a risk of privacy leakage and is under huge pressure to deal with it.

Method used

By obtaining IoT session logs and loading them into IoT session desensitization network trained based on significance feature errors, after data desensitization, the target session log is generated and the privacy access control network is optimized to ensure the accuracy of significance feature data matching and access control.

Benefits of technology

It realizes the preservation of key features while protecting user privacy, improves the security of IoT systems and the efficiency of privacy access control, and can more accurately identify abnormal behaviors and adjust access policies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119094152B_ABST
    Figure CN119094152B_ABST
Patent Text Reader

Abstract

This application provides a privacy access control method and system in the Internet of Things environment. First, obtain the Internet of Things session logs of the first Internet of Things service environment and load them into the Internet of Things session desensitization network trained based on the significant feature error. The Internet of Things session desensitization network ensures that the significant feature data in the desensitized target session logs matches the original logs. Subsequently, use these desensitized target session logs to optimize the privacy access control network of the second Internet of Things service environment to improve the accuracy and efficiency of privacy access control. Thus, by combining data desensitization and privacy access control technologies, it aims to protect user privacy while retaining key data features, thereby achieving secure and efficient privacy access control in the Internet of Things environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of Internet of Things technology. Specifically, it relates to a privacy access control method and system in an Internet of Things environment. Background Art

[0002] With the rapid development of Internet of Things technology, more and more devices are connected to the Internet, forming a huge Internet of Things system. The communication and interaction between these devices generate a large amount of data, including a lot of user privacy information. How to protect this privacy information from being leaked while effectively performing data processing and access control has become an urgent problem to be solved in the development of Internet of Things technology.

[0003] In the traditional Internet of Things service environment, privacy access control usually relies on preset rules and policies. However, this method often seems powerless in the face of complex and changing Internet of Things environments and massive amounts of data. On the one hand, the preset rules and policies are difficult to cover all scenarios and situations, easily causing the risk of privacy leakage; on the other hand, with the continuous increase of Internet of Things devices and the continuous growth of data volume, traditional privacy access control methods face huge processing pressures. Summary of the Invention

[0004] In view of this, the purpose of this application is to provide a privacy access control method and system in an Internet of Things environment, aiming to achieve efficient and secure privacy access control in the Internet of Things environment by combining data desensitization and privacy access control technologies.

[0005] According to the first aspect of this application, a privacy access control method in an Internet of Things environment is provided. The method includes:

[0006] Obtain the Internet of Things session log of the first Internet of Things service environment;

[0007] Load the Internet of Things session log into the Internet of Things session desensitization network, which is generated by network learning based on the significant feature error. The significant feature error is determined based on the sample significant feature data in the first desensitized data sequence generated after data desensitization of the first sample Internet of Things session data sequence in the first Internet of Things service environment, and the sample significant feature data in the second desensitized data sequence generated after data desensitization of the second sample Internet of Things session data sequence in the second Internet of Things service environment;

[0008] Obtain the target session log of the second Internet of Things service environment generated by the Internet of Things session desensitization network for data desensitization of the Internet of Things session log, and the significant feature data included in the target session log matches the significant feature data included in the Internet of Things session log;

[0009] After optimizing the privacy access control network of the second Internet of Things service environment based on the target session log of the second Internet of Things service environment, perform the target privacy access control task based on the optimized privacy access control network.

[0010] In a possible implementation manner of the first aspect, before loading the Internet of Things session log into the Internet of Things session desensitization network, the method further includes:

[0011] Obtain the first sample Internet of Things session data sequence, the second sample Internet of Things session data sequence, and a candidate neural network, where the candidate neural network includes a first desensitization prediction unit and a second desensitization prediction unit, and the sample Internet of Things session data in the first sample Internet of Things session data sequence and the second sample Internet of Things session data sequence are all marked with prior label knowledge for indicating the sample significant feature data;

[0012] Load the first sample Internet of Things session data sequence into the first desensitization prediction unit to perform data desensitization to generate a first desensitized data sequence of the second Internet of Things service environment marked with the sample significant feature data, and load the second sample Internet of Things session data sequence into the second desensitization prediction unit to perform data desensitization to generate a second desensitized data sequence of the first Internet of Things service environment marked with the sample significant feature data;

[0013] Determine the significant feature error based on the sample significant feature data in the second desensitized data sequence and the sample significant feature data in the first desensitized data sequence;

[0014] Train the candidate neural network based on the significant feature error to generate the Internet of Things session desensitization network.

[0015] In a possible implementation manner of the first aspect, the obtaining the first sample Internet of Things session data sequence, the second sample Internet of Things session data sequence, and the candidate neural network includes:

[0016] Obtain the sample Internet of Things session data of the first Internet of Things service environment and obtain the sample Internet of Things session data of the second Internet of Things service environment;

[0017] Perform prior knowledge annotation of the sample significant feature data on the obtained sample Internet of Things session data of the first Internet of Things service environment to generate the first sample Internet of Things session data sequence;

[0018] Perform prior knowledge annotation on the sample significant feature data of the obtained partial sample Internet of Things session data of the second Internet of Things service environment to generate the second sample Internet of Things session data sequence.

[0019] In a possible implementation manner of the first aspect, determining the significant feature error based on the sample significant feature data in the second desensitized data sequence and the sample significant feature data in the first desensitized data sequence includes:

[0020] Generate a first significant feature error based on the feature distance between the sample significant feature data in the first desensitized data sequence and the sample significant feature data in the first sample Internet of Things session data sequence;

[0021] Generate a second significant feature error based on the feature distance between the sample significant feature data in the second desensitized data sequence and the sample significant feature data in the second sample Internet of Things session data sequence;

[0022] Generate the significant feature error based on the first significant feature error and the second significant feature error.

[0023] In a possible implementation manner of the first aspect, before training the candidate neural network based on the significant feature error, the method further includes:

[0024] Load the first desensitized data sequence into the second desensitized prediction unit for data desensitization prediction to generate a first reconstructed session data sequence of the first Internet of Things service environment;

[0025] Load the second desensitized data sequence into the first desensitized prediction unit for data desensitization prediction to generate a second reconstructed session data sequence of the second Internet of Things service environment;

[0026] Generate a first reconstruction error parameter based on the correlation between the first reconstructed session data sequence and the first sample Internet of Things session data sequence;

[0027] Generate a second reconstruction error parameter based on the correlation between the second reconstructed session data sequence and the second sample Internet of Things session data sequence;

[0028] Generate the reconstruction error parameter based on the first reconstruction error parameter and the second reconstruction error parameter;

[0029] Training the candidate neural network based on the significant feature error includes:

[0030] Generate the global error parameter corresponding to the candidate neural network based on the reconstruction error parameter and the significance feature error, and train the candidate neural network based on the global error parameter.

[0031] In a possible implementation manner of the first aspect, the candidate neural network further includes a first discrimination unit for discriminating the validity of the session log in the second Internet of Things service environment, and a second discrimination unit for discriminating the validity of the session log in the first Internet of Things service environment;

[0032] Before training the candidate neural network based on the global error parameter, the method further includes:

[0033] Load the first desensitized data sequence into the first discrimination unit to generate a first discrimination result;

[0034] Load the second desensitized data sequence into the second discrimination unit to generate a second discrimination result;

[0035] Load the second sample Internet of Things session data sequence into the first discrimination unit to generate a third discrimination result;

[0036] Load the first sample Internet of Things session data sequence into the second discrimination unit to generate a fourth discrimination result;

[0037] Generate a first discrimination comparison error parameter based on the first discrimination result and the third discrimination result;

[0038] Generate a second discrimination comparison error parameter based on the second discrimination result and the fourth discrimination result;

[0039] Generate a discrimination comparison error parameter based on the first discrimination comparison error parameter and the second discrimination comparison error parameter;

[0040] In a possible implementation manner of the first aspect, generating the global error parameter corresponding to the candidate neural network based on the reconstruction error parameter and the significance feature error includes:

[0041] Obtain the training participation coefficient of the reconstruction error parameter and the training participation coefficient of the significance feature error;

[0042] Fuse the reconstruction error parameter and the significance feature error based on the training participation coefficient of the reconstruction error parameter and the training participation coefficient of the significance feature error to generate a fused error parameter;

[0043] Generate the global error parameter corresponding to the candidate neural network based on the fused error parameter and the discrimination comparison error parameter.

[0044] In a possible implementation of the first aspect, training the candidate neural network based on the global error parameter includes:

[0045] Locking the weight configuration information of the first discrimination unit and the second discrimination unit, and training the first desensitization prediction unit and the second desensitization prediction unit based on the global error parameter;

[0046] Locking the weight configuration information of the first desensitization prediction unit and the second desensitization prediction unit, and training the first discrimination unit and the second discrimination unit based on the discrimination comparison error parameter.

[0047] In a possible implementation of the first aspect, obtaining the target session log of the second Internet of Things service environment generated by data desensitization of the Internet of Things session log by the Internet of Things session desensitization network includes:

[0048] Obtaining the target session log of the second Internet of Things service environment generated by data desensitization by the first desensitization prediction unit of the Internet of Things session desensitization network.

[0049] In a possible implementation of the first aspect, the significant feature data included in the target session log is the feature part labeled for the privacy access control task; the step of optimizing the privacy access control network of the second Internet of Things service environment based on the target session log of the second Internet of Things service environment includes:

[0050] Obtaining the privacy access control network of the second Internet of Things service environment, where the privacy access control network is used to execute the privacy access control task according to the significant feature data;

[0051] Obtaining a sample learning data sequence, where the sample learning data sequence includes a target session log and annotation data for indicating the significant feature data;

[0052] Optimizing the privacy access control network based on the sample learning data sequence.

[0053] According to the second aspect of the present application, there is provided a privacy access control system in an Internet of Things environment. The privacy access control system in the Internet of Things environment includes a machine-readable storage medium and a processor. The machine-readable storage medium stores machine-executable instructions. When the processor executes the machine-executable instructions, the privacy access control system in the Internet of Things environment implements the foregoing privacy access control method in the Internet of Things environment.

[0054] According to a third aspect of the present application, there is provided a computer-readable storage medium storing computer-executable instructions, which, when executed, implement the aforementioned privacy access control method in the Internet of Things environment.

[0055] According to any of the above aspects, the technical effect of the present application is as follows:

[0056] By obtaining the Internet of Things session logs of the first Internet of Things service environment and loading the Internet of Things session logs into the Internet of Things session desensitization network trained based on the significant feature error, the data can be effectively desensitized. It can not only remove or replace sensitive information in the logs, but also ensure that the significant feature data in the desensitized data sequence matches the original data, thereby protecting user privacy while retaining the key features of the data. Further, using the desensitized target session logs to optimize the privacy access control network of the second Internet of Things service environment can significantly improve the accuracy and efficiency of privacy access control. The optimized privacy access control network can more accurately identify abnormal behaviors in the Internet of Things environment and timely adjust access control policies, thereby enhancing the security and privacy protection capabilities of the entire Internet of Things system. Thus, by combining data desensitization and the privacy access control network, while protecting user privacy, the security of the Internet of Things service environment and the intelligence of data processing are effectively improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0057] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0058] Figure 1 It is a schematic flow chart of the privacy access control method in the Internet of Things environment provided by the embodiments of the present application.

[0059] Figure 2 It is a schematic component structure diagram of the privacy access control system in the Internet of Things environment provided by the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0060] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the following will clearly and completely describe the technical solutions in the embodiments of this application with reference to the accompanying drawings in the embodiments of this application. It should be understood that the accompanying drawings in this application are only for the purpose of illustration and description, and are not used to limit the protection scope of this application. In addition, it should be understood that the schematic drawings are not drawn to scale. The flowcharts used in this application illustrate the operations implemented in some embodiments according to the embodiments of this application. It should be understood that the operations in the flowchart may not be implemented in sequence, and steps without a logical context relationship may be reversed or implemented simultaneously. In addition, those skilled in the art can add multiple other operations to the flowchart or delete multiple operations from the flowchart under the guidance of the content of this application.

[0061] Before introducing the embodiments of this application in detail, first, the meanings of some terms involved in the following embodiments are explained.

[0062] The following is a detailed explanation and illustrative example of the first Internet of Things service environment, Internet of Things session logs, sample salient feature data, and salient feature data:

[0063] 1. First Internet of Things service environment, second Internet of Things service environment

[0064] The first Internet of Things service environment and the second Internet of Things service environment respectively refer to a specific Internet of Things application scenario, which contains multiple Internet of Things devices. These Internet of Things devices are interconnected through a network and can perform data transmission and interaction. The first Internet of Things service environment and the second Internet of Things service environment may be a smart home system, an industrial Internet of Things monitoring system, a smart city traffic management system, etc. In this environment, various devices such as sensors, actuators, and controllers achieve intelligent management and control through Internet of Things technology.

[0065] For example, assume that a smart home system is the first Internet of Things service environment. In this smart home system, there are devices such as smart bulbs, smart thermostats, smart door locks, and smart security cameras. These devices can be connected through a wireless network to achieve remote control and data interaction. Users can control these devices through a mobile phone APP or a smart voice assistant, such as turning on the lights, adjusting the temperature, and viewing the real-time images of the security cameras.

[0066] 2. Internet of Things session logs

[0067] Internet of Things session logs refer to the data records generated when various devices communicate and interact in the Internet of Things service environment. These logs contain key information such as connection requests, data transmission, and control instructions between devices, and are important bases for analyzing the behavior of the Internet of Things system, optimizing system performance, and ensuring system security.

[0068] For example, in a smart home system, the IoT session logs may record the following: when the smart bulb is turned on or off, how the smart thermostat adjusts the indoor temperature, abnormal events captured by the smart security camera, etc. These log data are usually recorded in the form of timestamps, device identifiers, event types, data content, etc., for subsequent analysis and processing.

[0069] 3. Sample significant feature data

[0070] For example, sample significant feature data refers to those data features in the IoT session data that play a key role in analyzing or predicting the behavior of the IoT system. These features may include specific communication patterns, peak data transfer volumes, device status changes, etc., which can reflect information such as the operating state of the IoT system, user behavior habits, and potential security risks.

[0071] For example, in a smart home system, the sample significant feature data may include: the switching frequency of the smart bulb in a specific time period (reflecting the user's living habits), the temperature adjustment mode of the smart thermostat in extreme weather (reflecting the system's adaptability), and abnormal moving objects captured by the smart security camera at night (reflecting potential security risks), etc. These data features are of great significance for understanding the behavior pattern of the IoT system, optimizing system performance, and preventing security risks.

[0072] 4. Significant feature data

[0073] Significant feature data refers to those data features that are identified through analysis and processing in the IoT session logs and are crucial for understanding and predicting the behavior of the IoT system. These data features are not only representative in the current dataset but also can be generalized to a wider IoT service environment. The difference between significant feature data and sample significant feature data is that the former is the conclusive data obtained through analysis and processing, while the latter is a part of the original data.

[0074] For example, in a smart home system, through the analysis and processing of the IoT session logs, the following significant feature data may be identified: the switching frequency of the smart bulb is significantly higher in the evening than during the day (reflecting the user's daily routine), the energy consumption of the smart thermostat is significantly higher in winter than in summer (reflecting the impact of seasonal changes on energy consumption), and the number of abnormal events captured by the smart security camera increases significantly on weekends (reflecting the change in the user's activity pattern on weekends). These data features are of guiding significance for optimizing the performance of the smart home system, improving the user experience, and preventing security risks.

[0075] Figure 1The flowchart shows the privacy access control method and system provided by the embodiments of the present application in the Internet of Things environment. It should be understood that in other embodiments, the order of some steps in the privacy access control method in the Internet of Things environment of this embodiment can be shared according to actual needs, or some of the steps can also be omitted or maintained. The detailed steps of the privacy access control method in the Internet of Things environment include:

[0076] In step S110, obtain the Internet of Things session logs of the first Internet of Things service environment.

[0077] In this embodiment, the privacy access control system in the Internet of Things environment acts as a server and collects Internet of Things session logs from the first Internet of Things service environment (for example, a smart home system). These Internet of Things session logs record the communication and interaction data between various Internet of Things devices (such as smart bulbs, smart thermostats, smart security cameras, etc.) in the first Internet of Things service environment. This data can include information such as connection requests, data transmissions, and control instructions between devices. The server extracts these Internet of Things session logs from the Internet of Things service environment through a secure communication protocol and prepares for subsequent processing.

[0078] In step S120, load the Internet of Things session logs into the Internet of Things session desensitization network, which is generated by network learning based on the significant feature error. The significant feature error is determined based on the sample significant feature data in the first desensitized data sequence generated after data desensitization of the first sample Internet of Things session data sequence of the first Internet of Things service environment, and the sample significant feature data in the second desensitized data sequence generated after data desensitization of the second sample Internet of Things session data sequence of the second Internet of Things service environment.

[0079] In this embodiment, the server loads the collected Internet of Things session logs into a specially trained Internet of Things session desensitization network, which is generated by network learning based on the significant feature error. During the training process, the Internet of Things session desensitization network uses the sample Internet of Things session data sequence (already desensitized) from the first Internet of Things service environment and the sample Internet of Things session data sequence of the second Internet of Things service environment (which may be another smart home system or industrial Internet of Things environment). The sample significant feature data in these two data sequences are used to determine the significant feature error, thereby guiding the training of the Internet of Things session desensitization network. After loading the logs into the Internet of Things session desensitization network, the Internet of Things session desensitization network will desensitize these logs to remove or replace sensitive information.

[0080] Step S130: Obtain the target session log of the second IoT service environment generated by performing data desensitization on the IoT session log by the IoT session desensitization network, where the significant feature data included in the target session log matches the significant feature data included in the IoT session log.

[0081] After being processed by the IoT session desensitization network, the server obtains the desensitized target session logs. These target session logs have now been converted into a format suitable for the second IoT service environment, and the significant feature data therein matches the significant feature data in the original IoT session log. This means that key features such as important interaction information and device behavior patterns have been retained during the desensitization process, but specific sensitive data (such as user identity information, device serial numbers, etc.) has been replaced or deleted.

[0082] Step S140: After optimizing the privacy access control network of the second IoT service environment based on the target session log of the second IoT service environment, perform the target privacy access control task based on the optimized privacy access control network.

[0083] In this embodiment, the server now uses these desensitized target session logs to optimize the privacy access control network in the second IoT service environment. This privacy access control network is responsible for restricting or allowing access to IoT devices and data according to set rules. By analyzing the significant feature data in the target session log, the privacy access control network can learn which device interactions are common and which are unusual in the second IoT service environment, and update its access control policy accordingly. For example, if it is found that a certain device frequently sends a large amount of data late at night, this may be an abnormal behavior, and the privacy access control network can adjust the policy accordingly to restrict the access rights of this behavior. The optimized privacy access control network will more effectively protect the data security and user privacy in the second IoT service environment.

[0084] Based on the above steps, by obtaining the IoT session logs of the first IoT service environment and loading the IoT session logs into the IoT session desensitization network trained based on the saliency feature error, the data can be effectively desensitized. It can not only remove or replace the sensitive information in the logs, but also ensure that the saliency feature data in the desensitized data sequence matches the original data, thus protecting user privacy while retaining the key features of the data. Further, using the desensitized target session logs to optimize the privacy access control network of the second IoT service environment can significantly improve the accuracy and efficiency of privacy access control. The optimized privacy access control network can more accurately identify abnormal behaviors in the IoT environment and timely adjust the access control strategy, thereby enhancing the security and privacy protection capabilities of the entire IoT system. Thus, by combining data desensitization and the privacy access control network, while protecting user privacy, the security of the IoT service environment and the intelligence of data processing are effectively improved.

[0085] In a possible implementation manner, before loading the IoT session logs into the IoT session desensitization network, the method further includes:

[0086] Step S101, obtaining the first sample IoT session data sequence, the second sample IoT session data sequence, and a candidate neural network, where the candidate neural network includes a first desensitization prediction unit and a second desensitization prediction unit, and the sample IoT session data in the first sample IoT session data sequence and the second sample IoT session data sequence are both labeled with prior label knowledge for indicating the sample saliency feature data.

[0087] In this embodiment, the server first accesses its data storage and retrieves the sample IoT session data sequences of the first IoT service environment and the second IoT service environment from it. These sample IoT session data sequences were collected and labeled previously and contain communication sessions between various IoT devices. The sample IoT session data in each sample IoT session data sequence is labeled with prior label knowledge, which indicates the sample saliency features in the data, such as important communication patterns, data transmission types, or key device behaviors, etc.

[0088] At the same time, the server also loads a candidate neural network, which is designed for the desensitization task of IoT session data and includes two main desensitization prediction units: the first desensitization prediction unit and the second desensitization prediction unit, which are respectively used to process the session data from different IoT service environments.

[0089] Step S102: Load the first sample IoT session data sequence into the first desensitization prediction unit to perform data desensitization to generate the first desensitized data sequence of the second IoT service environment labeled with the sample significant feature data, and load the second sample IoT session data sequence into the second desensitization prediction unit to perform data desensitization to generate the second desensitized data sequence of the first IoT service environment labeled with the sample significant feature data.

[0090] In this embodiment, the server starts to load the first sample IoT session data sequence into the first desensitization prediction unit. After these first sample IoT session data sequences are desensitized, the first desensitized data sequence of the second IoT service environment is generated. In this process, the desensitization prediction unit will identify and retain the significant features in the data, while removing or replacing other sensitive information.

[0091] Similarly, the server also loads the second sample IoT session data sequence into the second desensitization prediction unit for data desensitization processing to generate the second desensitized data sequence of the first IoT service environment.

[0092] Step S103: Determine the significant feature error based on the sample significant feature data in the second desensitized data sequence and the sample significant feature data in the first desensitized data sequence.

[0093] In this embodiment, the server has now generated two sets of desensitized data sequences: the first desensitized data sequence and the second desensitized data sequence. To evaluate the effect of the desensitization process and further optimize the desensitization network, the server can compare the sample significant feature data in the first desensitized data sequence and the second desensitized data sequence.

[0094] By calculating the difference between the sample significant feature data in the second desensitized data sequence and the sample significant feature data in the first desensitized data sequence, the server determines the significant feature error. This significant feature error reflects the retention degree of the significant features during the desensitization process. The smaller the error, the stronger the ability of the desensitization network to retain the significant features when processing data.

[0095] Step S104: Train the candidate neural network based on the significant feature error to generate the IoT session desensitization network.

[0096] After determining the evaluation index of the significant feature error, the server starts to use this significant feature error to train the candidate neural network. Through the backpropagation algorithm, the server adjusts the weights and parameters in the candidate neural network and optimizes it with the goal of minimizing the significant feature error.

[0097] During the training process, the server can iterate through the entire dataset multiple times, and each iteration adjusts the parameters of the candidate neural network based on the current saliency feature error. As the training progresses, the candidate neural network gradually learns how to better preserve the saliency features of the data during the desensitization process.

[0098] Finally, when the training reaches the preset stop conditions (such as the number of iterations, error convergence, etc.), the server will obtain an optimized IoT session desensitization network. This IoT session desensitization network can maximize the preservation of the saliency features in the IoT session data while protecting user privacy, providing strong support for subsequent data analysis and privacy access control.

[0099] In a possible implementation manner, step S101 may include:

[0100] Step S1011, obtain the sample IoT session data of the first IoT service environment and obtain the sample IoT session data of the second IoT service environment.

[0101] In this embodiment, the server collects a series of sample IoT session data from the first IoT service environment through a secure network connection. These sample IoT session data may include various sensor readings, communication records between devices, interaction logs between users and devices, etc. The server ensures the use of encryption and verification mechanisms during data transmission to ensure data integrity and security.

[0102] Similar to the first IoT service environment, the server also obtains another series of sample IoT session data from the second IoT service environment in a secure manner. These sample IoT session data also contain rich IoT activity information, but may be different from the data in the first IoT service environment because the two environments may use different devices, communication protocols, or data processing logics.

[0103] Step S1012, perform prior knowledge annotation of the sample saliency feature data on the obtained sample IoT session data of the first IoT service environment to generate the first sample IoT session data sequence.

[0104] In this embodiment, the server uses a built-in or externally provided expert system to perform a detailed analysis of the sample IoT session data collected from the first IoT service environment. By analyzing the features of the data, such as communication frequency, data transmission volume, device behavior patterns, etc., the server identifies the saliency features in the data, such as abnormal communication, key device status changes, etc. Then, the server annotates these saliency features on the corresponding data in the form of prior knowledge labels, thereby generating the first sample IoT session data sequence.

[0105] Step S1013: Perform prior knowledge annotation on the sampled significant feature data of the obtained partial sampled Internet of Things session data of the second Internet of Things service environment to generate the second sampled Internet of Things session data sequence.

[0106] For the data of the second Internet of Things service environment, the server adopts a similar processing method. However, considering resource limitations or differences in data processing strategies, the server may only perform detailed prior knowledge annotation on part of the data. These selected data undergo the same analysis process as the data of the first Internet of Things service environment, including identifying significant features and adding prior knowledge labels. Finally, the server generates the second sampled Internet of Things session data sequence, which provides important reference information for subsequent neural network training and data desensitization.

[0107] In a possible implementation manner, step S103 may include:

[0108] Step S1031: Generate a first significant feature error based on the feature distance between the sampled significant feature data in the first desensitized data sequence and the sampled significant feature data in the first sampled Internet of Things session data sequence.

[0109] In this embodiment, the server first obtains the first desensitized data sequence and the first sampled Internet of Things session data sequence. Both the first desensitized data sequence and the first sampled Internet of Things session data sequence contain sampled significant feature data, that is, key information points in the data, such as specific communication patterns, data transmission volume peaks, etc.

[0110] To evaluate the impact of the desensitization process on the significant features in the data, the server uses a feature distance calculation method (such as Euclidean distance, cosine similarity, etc.) to quantify the difference between the sampled significant feature data in the first desensitized data sequence and the corresponding feature data in the first sampled Internet of Things session data sequence. This difference value, that is, the feature distance, reflects the retention degree of the significant features after the desensitization process.

[0111] After the server calculates this feature distance, it defines it as the first significant feature error. The smaller the first significant feature error, the smaller the impact of the desensitization process on the significant features in the first sampled Internet of Things session data, and the better the desensitization effect.

[0112] Step S1032: Generate a second significant feature error based on the feature distance between the sampled significant feature data in the second desensitized data sequence and the sampled significant feature data in the second sampled Internet of Things session data sequence.

[0113] Similar to step S1031, the server then obtains the second desensitized data sequence and the second sample IoT session data sequence. Similarly, these second desensitized data sequences and the second sample IoT session data sequences also contain sample saliency feature data.

[0114] The server uses the same feature distance calculation method to quantify the difference between the sample saliency feature data in the second desensitized data sequence and the corresponding feature data in the second sample IoT session data sequence. The calculated feature distance is defined as the second saliency feature error.

[0115] Step S1033, generating the saliency feature error based on the first saliency feature error and the second saliency feature error.

[0116] After obtaining the first saliency feature error and the second saliency feature error, the server needs to comprehensively analyze these two errors to evaluate the effect of the entire desensitization process.

[0117] The server can adopt various methods to generate the final saliency feature error, such as taking the average value, weighted average value, maximum value, etc. of the two errors. This comprehensive error value more comprehensively reflects the impact of the desensitization process on the data saliency features in two different IoT service environments.

[0118] For example, the server can calculate the weighted sum of the first saliency feature error and the second saliency feature error as the final saliency feature error, and this weighted sum can be adjusted according to factors such as the importance and data volume of the two IoT service environments. In this way, the server obtains a saliency feature error value that can comprehensively reflect the desensitization effect.

[0119] In a possible implementation manner, before step S104, the method further includes:

[0120] Step A110, loading the first desensitized data sequence into the second desensitization prediction unit for data desensitization prediction, and generating the first reconstructed session data sequence of the first IoT service environment.

[0121] In this embodiment, the server first loads the first desensitized data sequence, which has been processed by the first desensitization prediction unit and has had sensitive information removed, into the second desensitization prediction unit. The task of the second desensitization prediction unit is to attempt to reconstruct these already desensitized data to predict their original form. This process is similar to a decoding process, aiming to check whether the desensitized data retains enough information for reconstructing the original data.

[0122] After being processed by the second desensitization prediction unit, the server obtains a set of reconstructed session data sequences, which are called the first reconstructed session data sequences of the first Internet of Things service environment. These first reconstructed session data sequences are the original data forms predicted based on the desensitized data and are used for subsequent comparison with the original sample data to evaluate the effects of desensitization and reconstruction.

[0123] Step A120: Load the second desensitized data sequence into the first desensitization prediction unit for data desensitization prediction to generate the second reconstructed session data sequence of the second Internet of Things service environment.

[0124] Similar to step A110, the server then loads the second desensitized data sequence into the first desensitization prediction unit for data desensitization prediction. These second desensitized data sequences are from the second Internet of Things service environment and have been desensitized by the second desensitization prediction unit.

[0125] Through the processing of the first desensitization prediction unit, the server obtains the second reconstructed session data sequences of the second Internet of Things service environment. These second reconstructed session data sequences are the original data forms predicted based on the second desensitized data sequence and are also used for subsequent comparison and evaluation with the original sample data.

[0126] Step A130: Generate a first reconstruction error parameter based on the correlation between the first reconstructed session data sequence and the first sample Internet of Things session data sequence.

[0127] The server compares the first reconstructed session data sequence with the original first sample Internet of Things session data sequence, and evaluates the degree of coincidence between the reconstructed data and the original data by calculating the correlation between the two (such as using metrics like correlation coefficient, mean square error, etc.). This correlation metric is defined as the first reconstruction error parameter, which reflects the degree of retention of the original data during the desensitization and reconstruction processes.

[0128] Step A140: Generate a second reconstruction error parameter based on the correlation between the second reconstructed session data sequence and the second sample Internet of Things session data sequence.

[0129] Similarly, the server also compares the second reconstructed session data sequence with the original second sample Internet of Things session data sequence and calculates the correlation metric between the two, which is defined as the second reconstruction error parameter.

[0130] Step A150: Generate the reconstruction error parameter based on the first reconstruction error parameter and the second reconstruction error parameter.

[0131] The server comprehensively processes the first reconstruction error parameter and the second reconstruction error parameter, such as taking the average value, weighted sum or other statistical methods, to obtain an overall reconstruction error parameter, which more comprehensively reflects the effects of the desensitization and reconstruction processes in two different Internet of Things service environments.

[0132] Step S104 includes: generating a global error parameter corresponding to the candidate neural network based on the reconstruction error parameter and the significant feature error, and training the candidate neural network based on the global error parameter.

[0133] After obtaining the reconstruction error parameter and the previously calculated significant feature error, the server combines these two error parameters to generate a global error parameter, which comprehensively considers the retention degree of significant features in the desensitization process and the accuracy of the reconstructed data, and is an important indicator for evaluating the performance of the candidate neural network.

[0134] Finally, the server uses this global error parameter to train the candidate neural network. Through optimization techniques such as the backpropagation algorithm, the weights and parameters of the network are adjusted to minimize the global error parameter as the goal of training. This process aims to improve the ability of the neural network to retain significant features and reconstruct the original data in the desensitization process.

[0135] In a possible implementation manner, the candidate neural network further includes a first discrimination unit for discriminating the validity of session logs in the second Internet of Things service environment, and a second discrimination unit for discriminating the validity of session logs in the first Internet of Things service environment.

[0136] Before the step S104, the method further includes:

[0137] Step B110: loading the first desensitized data sequence into the first discrimination unit to generate a first discrimination result, loading the second desensitized data sequence into the second discrimination unit to generate a second discrimination result, loading the second sample Internet of Things session data sequence into the first discrimination unit to generate a third discrimination result, and loading the first sample Internet of Things session data sequence into the second discrimination unit to generate a fourth discrimination result.

[0138] In this embodiment, when designing the candidate neural network, in addition to including units for data desensitization and reconstruction, two discrimination units are particularly added. The first discrimination unit is designed to specifically discriminate the validity of session logs in the second Internet of Things service environment, while the second discrimination unit is used to discriminate the validity of session logs in the first Internet of Things service environment. These two discrimination units can identify abnormal or invalid logs by analyzing the characteristics and data patterns of session logs, thereby improving the reliability and security of data.

[0139] Before training the candidate neural network, the server needs to load different data sequences into the corresponding discrimination units for processing.

[0140] First, the server loads the first desensitized data sequence into the first discrimination unit. These data are desensitized and are intended to test the discrimination ability of the first discrimination unit for desensitized data. After processing, the first discrimination unit outputs the first discrimination result, which reflects the validity of the session logs in the first desensitized data sequence.

[0141] Next, the server loads the second desensitized data sequence into the second discrimination unit and obtains the second discrimination result. This process is to test the discrimination accuracy of the second discrimination unit for desensitized data from the second Internet of Things service environment.

[0142] To evaluate the discrimination ability of the discrimination unit for the original sample data, the server also loads the second sample Internet of Things session data sequence into the first discrimination unit and generates the third discrimination result. Similarly, the first sample Internet of Things session data sequence is loaded into the second discrimination unit, generating the fourth discrimination result.

[0143] Step B120, generate a first discrimination comparison error parameter based on the first discrimination result and the third discrimination result, generate a second discrimination comparison error parameter based on the second discrimination result and the fourth discrimination result, and generate a discrimination comparison error parameter based on the first discrimination comparison error parameter and the second discrimination comparison error parameter.

[0144] After obtaining the four discrimination results, the server starts error analysis.

[0145] First, the server compares the first discrimination result and the third discrimination result. Since the first discrimination result is based on desensitized data and the third discrimination result is based on the original sample data, by comparing the two, the impact of the desensitization process on the discrimination result can be evaluated. The server calculates the difference between the two and defines it as the first discrimination comparison error parameter.

[0146] Next, the server compares the second discrimination result and the fourth discrimination result, and similarly calculates the difference between the two and defines it as the second discrimination comparison error parameter.

[0147] Finally, the server combines the first discrimination comparison error parameter and the second discrimination comparison error parameter, and generates an overall discrimination comparison error parameter through certain statistical methods (such as weighted average, standard deviation analysis, etc.). This discrimination comparison error parameter reflects the performance difference of the discrimination unit when processing desensitized data and original data, providing an important reference basis for the subsequent training of the neural network.

[0148] In a possible implementation, generating the global error parameter corresponding to the candidate neural network based on the reconstruction error parameter and the saliency feature error includes:

[0149] Step S1041: Obtain the training participation coefficient of the reconstruction error parameter and the training participation coefficient of the saliency feature error.

[0150] Step S1042: Based on the training participation coefficient of the reconstruction error parameter and the training participation coefficient of the saliency feature error, fuse the reconstruction error parameter and the saliency feature error to generate a fused error parameter.

[0151] Step S1043: Based on the fused error parameter and the discrimination comparison error parameter, generate the global error parameter corresponding to the candidate neural network.

[0152] In this embodiment, before training the candidate neural network, the server needs to first determine the weights of different error parameters during the training process, which involves two important training participation coefficients: the training participation coefficient of the reconstruction error parameter and the training participation coefficient of the saliency feature error.

[0153] These two coefficients are usually determined by experts based on experience or through experiments, and they reflect the relative contributions of the reconstruction error and the saliency feature error to the global error during the training process. For example, if the reconstruction error is considered more important, its training participation coefficient can be set relatively high.

[0154] The server obtains these training participation coefficients from the configuration file, database, or user input to prepare for subsequent error fusion.

[0155] After obtaining the training participation coefficients of the reconstruction error parameter and the saliency feature error, the server starts error fusion.

[0156] Specifically, the server first multiplies the reconstruction error parameter and the saliency feature error by their respective training participation coefficients, so as to weight the errors according to their importance. Then, the server adds these two weighted errors to generate a fused error parameter.

[0157] This fused error parameter comprehensively considers the reconstruction quality and the retention of saliency features, and is an important indicator for evaluating the performance of the candidate neural network.

[0158] The discrimination comparison error parameter reflects the performance difference of the discrimination unit when processing desensitized data and original data. To also incorporate this error parameter into the consideration of the global error, the server can combine it with the fused error parameter.

[0159] Specifically, the server can perform a weighted sum of the discrimination comparison error parameter and the fusion error parameter to generate a global error parameter, which comprehensively considers the reconstruction quality, the retention of significant features, and the performance of the discrimination unit, and is an important basis for evaluating and optimizing the candidate neural network.

[0160] After obtaining the global error parameter, the server can use this parameter to train and optimize the candidate neural network. By continuously adjusting the weights and parameters of the network and aiming to minimize the global error parameter for training, the comprehensive capabilities of the neural network in aspects such as desensitization processing, data reconstruction, and discrimination log validity can be improved.

[0161] In a possible implementation manner, training the candidate neural network based on the global error parameter includes:

[0162] Step S1044, lock the weight configuration information of the first discrimination unit and the second discrimination unit, and train the first desensitization prediction unit and the second desensitization prediction unit based on the global error parameter.

[0163] Step S1045, lock the weight configuration information of the first desensitization prediction unit and the second desensitization prediction unit, and train the first discrimination unit and the second discrimination unit based on the discrimination comparison error parameter.

[0164] In this embodiment, during the training process, the server will first lock the weight configuration information of the first discrimination unit and the second discrimination unit, which means that during this part of the training process, the weights of these two discrimination units will not be updated or changed. The purpose of locking the weights is to optimize the desensitization prediction unit and the discrimination unit separately, rather than optimizing all units simultaneously, so that the training process can be more focused and targeted.

[0165] After locking the weights of the discrimination units, the server will focus on training the first desensitization prediction unit and the second desensitization prediction unit. At this time, the server can use the previously calculated global error parameter as a guidance for training. The global error parameter comprehensively considers the reconstruction quality, the retention of significant features, and the performance of the discrimination unit, so it is a good training metric.

[0166] The server uses the backpropagation algorithm to pass the global error parameter back to the desensitization prediction unit and adjusts the weights of the first desensitization prediction unit and the second desensitization prediction unit according to this error. Through multiple iterative trainings, the server aims to reduce the global error, thereby improving the performance of the desensitization prediction unit.

[0167] After completing the training of the desensitization prediction unit, the server can lock the weights of these two units. The purpose of doing so is to focus on optimizing the performance of the discrimination unit in the subsequent training without affecting the desensitization prediction unit that has been optimized before.

[0168] After locking the weights of the desensitization prediction unit, the server will use the discrimination comparison error parameter to train the first discrimination unit and the second discrimination unit. The discrimination comparison error parameter reflects the performance difference of the discrimination unit when processing desensitized data and original data, so it is a key indicator for optimizing the discrimination unit.

[0169] The server also passes the discrimination comparison error parameter back to the discrimination unit through the backpropagation algorithm and adjusts the weights of the first discrimination unit and the second discrimination unit according to this error. Through multiple iterative trainings, the server aims to reduce the discrimination comparison error, thereby improving the discrimination ability of the discrimination unit for the validity of session logs.

[0170] Through such a phased training method, the server can optimize the performance of the desensitization prediction unit and the discrimination unit respectively, and finally obtain a candidate neural network that can not only effectively desensitize and reconstruct data, but also accurately discriminate the validity of session logs.

[0171] In a possible implementation manner, step S130 may include: obtaining the target session log of the second Internet of Things service environment generated by the first desensitization prediction unit of the Internet of Things session desensitization network.

[0172] In a possible implementation manner, the significant feature data included in the target session log is the feature part marked for the privacy access control task. The step of optimizing the privacy access control network of the second Internet of Things service environment based on the target session log of the second Internet of Things service environment includes:

[0173] Step S141, obtaining the privacy access control network of the second Internet of Things service environment, where the privacy access control network is used to perform the privacy access control task according to the significant feature data.

[0174] Step S142, obtaining a sample learning data sequence, where the sample learning data sequence includes the target session log and annotation data for indicating the significant feature data.

[0175] Step S143, optimizing the privacy access control network based on the sample learning data sequence.

[0176] In this embodiment, in the scenario of a smart home system, the server communicates with the smart center in the home to obtain the privacy access control network that has been deployed. This privacy access control network is designed specifically for this smart home system and is used to ensure the privacy and data security of family members. It is responsible for controlling the information access permissions between smart devices to prevent unauthorized access and data leakage.

[0177] In the scenario of an industrial Internet of Things environment, the server connects to the control center of the factory to obtain the privacy access control network that has been established within the factory. This network is used to protect the security of industrial equipment and production data, ensuring that only authorized personnel can access sensitive information and control systems.

[0178] Furthermore, in the smart home system, the server extracts sample learning data sequences from the desensitized target session logs. These data sequences record the interaction information between family members and smart devices, such as lighting control, temperature adjustment, and security system arming. At the same time, these data also contain annotation information indicating which data belong to privacy-sensitive information that needs special protection, such as family members' identity information and device control passwords.

[0179] In the industrial Internet of Things environment, the server obtains sample learning data sequences from the desensitized target session logs. These data record the operating status of industrial equipment, production data, and related control instructions. The annotation data indicates which information is critical and needs to be protected, such as production formulas and equipment maintenance records.

[0180] Furthermore, in the smart home system, the server uses the extracted sample learning data sequences to optimize the privacy access control network. By comparing the output results of the network with the annotation data, the server adjusts the parameters and rules of the network to improve the accuracy and efficiency of privacy access control. In this way, when family members interact with smart devices, the privacy access control network can more accurately determine whether an access request is legal and take corresponding protection measures.

[0181] In the industrial Internet of Things environment, the server uses the sample learning data sequences to train and optimize the privacy access control network. By simulating various access requests and attack scenarios, the server continuously adjusts the defense strategies and access rules of the network to ensure that only legitimate users can access sensitive data and control systems. This helps to improve the information security level of the factory and prevent malicious attacks and data leakage.

[0182] Figure 2The privacy access control system 100 in the IoT environment shown includes: a processor 1001 and a memory 1003. Among them, the processor 1001 and the memory 1003 are connected, such as connected through a bus 1002. Optionally, the privacy access control system 100 in the IoT environment may further include a transceiver 1004, and the transceiver 1004 can be used for data interaction between this server and other servers, such as sending and / or receiving data, etc. It should be noted that in actual scheduling, the transceiver 1004 is not limited to one, and the structure of the privacy access control system 100 in the IoT environment does not constitute a limitation to the embodiments of the present application.

[0183] The processor 1001 can be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute various exemplary logic blocks, modules, and circuits described in connection with the disclosure of the present application. The processor 1001 can also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.

[0184] The bus 1002 may include a path for transmitting information between the above components. The bus 1002 can be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. The bus 1002 can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, Figure 2 only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus.

[0185] The memory 1003 can be a ROX (Read Only Xemory), or other types of static storage devices that can store static information and instructions, a RAX (Random Access Xemory), or other types of dynamic storage devices that can store information and instructions. It can also be an EEPROX (Electrically Erasable Programmable Read Only Xemory), a CD-ROX (Compact Disc Read Only Xemory), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, other magnetic storage devices, or any other medium that can be used to carry or store program code and can be read by a computer, which is not limited herein.

[0186] The memory 1003 is used to store the program code for implementing the embodiments of the present application and is controlled by the processor 1001 for execution. The processor 1001 is used to execute the program code stored in the memory 1003 to implement the steps shown in the foregoing method embodiments.

[0187] The embodiments of the present application provide a computer-readable storage medium, on which program code is stored. When the program code is executed by a processor, the steps and corresponding content of the foregoing method embodiments can be implemented.

[0188] It should be understood that although the flowcharts in the embodiments of the present application indicate various operation steps by arrows, the execution order of these steps is not limited to the order indicated by the arrows. Unless otherwise clearly stated herein, in some implementation scenarios of the embodiments of the present application, the implementation steps in each flowchart can be executed in other orders based on requirements. In addition, some or all of the steps in each flowchart may include multiple sub-steps or multiple stages according to the actual implementation scenarios. Some or all of these sub-steps or stages can be executed at the same time, and each sub-step or stage of these sub-steps or stages can also be executed at different times respectively. In the scenario where the execution times are different, the execution order of these sub-steps or stages can be flexibly configured according to requirements, and the embodiments of the present application do not limit this.

[0189] The above are only optional implementation manners of some implementation scenarios of the present application. It should be noted that for those of ordinary skill in the art, without departing from the technical concept of the solution of the present application, using other similar implementation means based on the technical idea of the present application also belongs to the protection scope of the embodiments of the present application.

Claims

1. A privacy access control method in the Internet of Things environment, characterized in that, The method includes: Obtaining the Internet of Things (IoT) session logs of a first IoT service environment; Loading the IoT session logs into an IoT session desensitization network, which is generated by network learning based on the saliency feature error. The saliency feature error is determined based on the sample saliency feature data in the first desensitized data sequence generated after data desensitization of the first sample IoT session data sequence of the first IoT service environment and the sample saliency feature data in the second desensitized data sequence generated after data desensitization of the second sample IoT session data sequence of the second IoT service environment. The sample saliency feature data refers to the data features that play a key role in analyzing or predicting the behavior of the IoT system in the IoT session data; Obtaining the target session logs of the second IoT service environment generated by the IoT session desensitization network after performing data desensitization on the IoT session logs. The saliency feature data included in the target session logs matches the saliency feature data included in the IoT session logs. The saliency feature data refers to the important data features identified after analysis and processing in the IoT session logs for understanding and predicting the behavior of the IoT system; After optimizing the privacy access control network of the second IoT service environment based on the target session logs of the second IoT service environment, performing the target privacy access control task based on the optimized privacy access control network.

2. The privacy access control method in the Internet of Things environment according to claim 1, wherein Before loading the IoT session logs into the IoT session desensitization network, the method further includes: Obtaining the first sample IoT session data sequence, the second sample IoT session data sequence, and a candidate neural network. The candidate neural network includes a first desensitization prediction unit and a second desensitization prediction unit. The sample IoT session data in the first sample IoT session data sequence and the second sample IoT session data sequence are both labeled with prior label knowledge for indicating the sample saliency feature data; Loading the first sample IoT session data sequence into the first desensitization prediction unit to generate the first desensitized data sequence of the second IoT service environment labeled with the sample saliency feature data after data desensitization, and loading the second sample IoT session data sequence into the second desensitization prediction unit to generate the second desensitized data sequence of the first IoT service environment labeled with the sample saliency feature data after data desensitization; Determining the saliency feature error based on the sample saliency feature data in the second desensitized data sequence and the sample saliency feature data in the first desensitized data sequence; Training the candidate neural network based on the saliency feature error to generate the IoT session desensitization network.

3. The privacy access control method in the Internet of Things environment according to claim 2, characterized in that, The obtaining of the first sample IoT session data sequence, the second sample IoT session data sequence, and the candidate neural network includes: Obtain the sample Internet of Things session data of the first Internet of Things service environment, and obtain the sample Internet of Things session data of the second Internet of Things service environment; Perform prior knowledge annotation of the sample significant feature data on the obtained sample Internet of Things session data of the first Internet of Things service environment to generate the first sample Internet of Things session data sequence; Perform prior knowledge annotation of the sample significant feature data on the obtained partial sample Internet of Things session data of the second Internet of Things service environment to generate the second sample Internet of Things session data sequence.

4. The privacy access control method in the Internet of Things environment according to claim 2, characterized in that, The determining the significant feature error based on the sample significant feature data in the second desensitized data sequence and the sample significant feature data in the first desensitized data sequence includes: Generate a first significant feature error based on the feature distance between the sample significant feature data in the first desensitized data sequence and the sample significant feature data in the first sample Internet of Things session data sequence; Generate a second significant feature error based on the feature distance between the sample significant feature data in the second desensitized data sequence and the sample significant feature data in the second sample Internet of Things session data sequence; Generate the significant feature error based on the first significant feature error and the second significant feature error.

5. The privacy access control method in the Internet of Things environment according to claim 2, wherein Before training the candidate neural network based on the significant feature error, the method further includes: Load the first desensitized data sequence into the second desensitized prediction unit for data desensitization prediction to generate the first reconstructed session data sequence of the first Internet of Things service environment; Load the second desensitized data sequence into the first desensitized prediction unit for data desensitization prediction to generate the second reconstructed session data sequence of the second Internet of Things service environment; Generate a first reconstruction error parameter based on the correlation between the first reconstructed session data sequence and the first sample Internet of Things session data sequence; Generate a second reconstruction error parameter based on the correlation between the second reconstructed session data sequence and the second sample Internet of Things session data sequence; Generate the reconstruction error parameter based on the first reconstruction error parameter and the second reconstruction error parameter; The training the candidate neural network based on the significant feature error includes: Generate the global error parameter corresponding to the candidate neural network based on the reconstruction error parameter and the significant feature error, and train the candidate neural network based on the global error parameter.

6. The privacy access control method in the Internet of Things environment according to claim 5, characterized in that, The candidate neural network further includes a first discrimination unit for discriminating the validity of the session log in the second Internet of Things service environment, and a second discrimination unit for discriminating the validity of the session log in the first Internet of Things service environment; Before training the candidate neural network based on the global error parameter, the method further includes: Load the first desensitized data sequence into the first discrimination unit to generate a first discrimination result; Load the second desensitized data sequence into the second discrimination unit to generate a second discrimination result; Load the second sample IoT session data sequence into the first authentication unit to generate a third authentication result; Load the first sample IoT session data sequence into the second authentication unit to generate a fourth authentication result; Generate a first authentication comparison error parameter based on the first authentication result and the third authentication result; Generate a second authentication comparison error parameter based on the second authentication result and the fourth authentication result; Generate an authentication comparison error parameter based on the first authentication comparison error parameter and the second authentication comparison error parameter; The generating the global error parameter corresponding to the candidate neural network based on the reconstruction error parameter and the significant feature error includes: Obtain the training participation coefficient of the reconstruction error parameter and the training participation coefficient of the significant feature error; Fuse the reconstruction error parameter and the significant feature error based on the training participation coefficient of the reconstruction error parameter and the training participation coefficient of the significant feature error to generate a fused error parameter; Generate the global error parameter corresponding to the candidate neural network based on the fused error parameter and the authentication comparison error parameter.

7. The privacy access control method in the Internet of Things environment according to claim 6, characterized in that, The training the candidate neural network based on the global error parameter includes: Lock the weight configuration information of the first authentication unit and the second authentication unit, and train the first desensitization prediction unit and the second desensitization prediction unit based on the global error parameter; Lock the weight configuration information of the first desensitization prediction unit and the second desensitization prediction unit, and train the first authentication unit and the second authentication unit based on the authentication comparison error parameter.

8. The privacy access control method in the Internet of Things environment according to claim 7, characterized in that, The obtaining the target session log of the second IoT service environment generated by the IoT session desensitization network for data desensitization of the IoT session log includes: Obtain the target session log of the second IoT service environment generated by the first desensitization prediction unit of the IoT session desensitization network for data desensitization.

9. The privacy access control method in the Internet of Things environment according to any one of claims 1-8, characterized in that, The significant feature data included in the target session log is the feature part labeled for the privacy access control task; the step of optimizing the privacy access control network of the second IoT service environment based on the target session log of the second IoT service environment includes: Obtain the privacy access control network of the second IoT service environment, and the privacy access control network is used to perform the privacy access control task according to the significant feature data; Obtain a sample learning data sequence, and the sample learning data sequence includes a target session log and annotation data for indicating the significant feature data; Optimize the privacy access control network based on the sample learning data sequence.

10. A privacy access control system in the Internet of Things environment, characterized in that, It includes a processor and a computer-readable storage medium, and the computer-readable storage medium stores machine-executable instructions, and when the machine-executable instructions are executed by the processor, the privacy access control method in the IoT environment according to any one of claims 1-9 is implemented.

Citation Information

Patent Citations

  • Data processing method and system applied to network service

    CN117785964A

  • Enterprise big data mining method and system based on artificial intelligence

    CN118094639A