User opinion privacy protection method and system based on federated learning and privacy differential
By adopting federated learning and privacy differences in user opinion analysis, combined with secret sharing and homomorphic encryption technology, the problem of insufficient user privacy protection in the existing technology is solved, and efficient privacy protection and data analysis are achieved.
Patent Information
- Application Number
- CN202411919145.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-25
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-12-25
AI Technical Summary
The existing technology is difficult to effectively protect user privacy during the process of collecting and analyzing user opinions. The centralized learning model poses data leakage and security risks. Static data desensitization methods cannot cope with complex privacy attacks and lack end-to-end holistic considerations.
A method based on federated learning and privacy differences is adopted to avoid direct sharing of raw data by local training on the client and adding noise perturbation; aggregation of security parameters is used on the server side to generate privacy protection policies to protect user privacy.
It effectively improves the level of data privacy protection, balances data availability and privacy protection, adapts to the performance differences of different terminal devices, and achieves end-to-end privacy protection.
Smart Images

Figure CN119358035B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to privacy protection technology, and in particular to a user opinion privacy protection method and system based on federated learning and privacy differential. Background Art
[0002] With the rapid development of the Internet, user opinion analysis plays an increasingly important role in business decision-making, product improvement, and user experience optimization. However, in the process of collecting and analyzing user opinions, how to effectively protect user privacy has become an urgent problem to be solved. The existing technology has the following three shortcomings:
[0003] First, the existing user opinion collection and analysis methods generally adopt a centralized learning model. This model requires users to upload their original opinion data directly to a central server for processing, which is not only prone to leakage of user sensitive information, but also may lead to illegal acquisition or tampering of data due to security loopholes in the data transmission process. At the same time, a large amount of user data stored in a centralized manner is also very easy to become a target of hacker attacks, posing a major security risk.
[0004] Second, although the commonly used data desensitization and anonymization technologies can protect user privacy to a certain extent, these methods are often static and single processing methods and cannot cope with increasingly complex privacy attacks. Especially in the data analysis process, it is difficult for existing technologies to balance the relationship between data availability and privacy protection. Excessive privacy protection will significantly reduce the analytical value of data, while insufficient protection will expose user privacy.
[0005] Third, existing privacy protection solutions lack end-to-end holistic considerations. Most solutions only focus on privacy protection in a specific link, such as the data collection stage or storage stage, and ignore the privacy protection needs of data throughout its entire life cycle, including collection, transmission, storage, and calculation. At the same time, existing technologies rarely consider the impact of performance differences between different terminal devices on privacy protection effects, and are unable to adjust privacy protection strategies adaptively based on actual conditions.
[0006] The existence of the above technical problems has seriously restricted the promotion and development of user opinion analysis technology in practical applications. Therefore, it is urgent to propose a user opinion privacy protection scheme that can fully protect user privacy, ensure data availability, and has strong adaptability. Summary of the invention
[0007] The embodiments of the present invention provide a user opinion privacy protection method and system based on federated learning and privacy differential, which can solve the problems in the prior art.
[0008] According to a first aspect of the embodiments of the present invention,
[0009] Provides a user opinion privacy protection method based on federated learning and privacy differential, including:
[0010] On the server side, receiving a federated learning participation request from at least two clients, wherein the federated learning participation request carries identification information and device performance parameters of each of the clients; for each of the clients, based on the identification information, dividing a preset user opinion data set into corresponding sub-data sets; determining the number of local training rounds and the number of iterations per round for each client according to the device performance parameters of each of the clients; and sending the sub-data sets, the number of local training rounds and the number of iterations per round to the corresponding client;
[0011] On each of the clients, according to the received sub-dataset, a differential privacy machine learning algorithm is used to obtain corresponding local model parameters through multiple rounds of local training, where each round of local training includes multiple iterations, and in each iteration, the local model parameters are perturbed by Laplace noise; and the local model parameters obtained by training are sent to the server;
[0012] On the server side, based on the local model parameters collected from each client, secret sharing technology and homomorphic encryption technology are used to obtain global model parameters through privacy-preserving parameter aggregation; the global model parameters are used to update the preset federated learning model to obtain a privacy protection strategy; the privacy protection strategy is sent to each client; at each client, the privacy protection strategy sent by the server is received, and when a pending opinion posted by a target user is received, a target opinion after privacy protection is obtained based on the privacy protection strategy; the target opinion after privacy protection is sent to the server side for business analysis and mining processing.
[0013] On each of the clients, based on the received sub-datasets, a differential privacy machine learning algorithm is used to obtain corresponding local model parameters through multiple rounds of local training, including:
[0014] In each round of training, a preset number of small batch sample sets are randomly extracted from the sub-dataset using a balanced sampling strategy, and the loss function of the current local model on the small batch sample set is calculated based on the small batch sample set; a calculation graph is constructed to symbolically define the loss function, and the partial derivatives of the loss function with respect to the parameters of each layer of the neural network are solved by back propagation to obtain the gradient values of each parameter; the calculated gradient values of each model parameter are spliced to form a complete model parameter gradient vector as the gradient value of the current model parameter;
[0015] Set the gradient clipping threshold, obtain the number of components of the current model parameter gradient value, and create a corresponding clipping mask vector according to the number of components; traverse the gradient values of the current model parameters to obtain the absolute value of each gradient component; for the gradient components whose absolute values do not exceed the clipping threshold, set them to 1 at the corresponding clipping mask vector position; for the gradient components whose absolute values exceed the clipping threshold, set them to the proportional coefficient of the clipping threshold divided by the absolute value of the component at the corresponding clipping mask vector position; according to the clipping mask vector, perform component-level gradient clipping on the gradient value of the current model parameter, wherein the following processing is performed on each gradient component: if the corresponding clipping mask vector component is 1, the gradient component remains unchanged; if the corresponding clipping mask vector component is less than 1, the value of the gradient component is multiplied by the corresponding proportional coefficient, and scaled to the clipping threshold boundary to obtain the clipped gradient value;
[0016] The sensitivity parameters of the current training round are determined according to the privacy budget allocation of each round of training and the clipping threshold, and a random noise vector obeying the Laplace distribution is generated using the sensitivity parameters. The gradient value after noise perturbation is obtained based on the random noise vector and the clipped gradient value. An adaptive learning rate optimization algorithm is used to automatically adjust the learning rate of the current iteration according to historical gradient information, and the current model parameters are updated using the adjusted learning rate and the gradient value after noise perturbation to obtain the model parameters after this iteration. Through multiple iterations, the model parameters obtained in the last iteration are used as the local model parameters of the current training round.
[0017] Determining the sensitivity parameter of the current training round according to the privacy budget allocation of each round of training and the clipping threshold, generating a random noise vector obeying the Laplace distribution using the sensitivity parameter, and obtaining the gradient value after noise disturbance based on the random noise vector and the clipped gradient value, including:
[0018] According to the total number of training rounds of federated learning and the total number of clients, determine the privacy budget available to each client in each round of local training, and evenly distribute the privacy budget of each round to each training iteration step; obtain the privacy budget of the current training round, and calculate the sensitivity parameter of the current training round according to the privacy budget and a preset gradient clipping threshold, wherein the sensitivity parameter is inversely proportional to the privacy budget and proportional to the clipping threshold;
[0019] The probability density function of the Laplace distribution is constructed using the sensitivity parameter, and the reciprocal of the sensitivity parameter is used as the scale parameter of the Laplace distribution; according to the number of components of the gradient vector after gradient clipping, a random noise vector having the same number of components as the gradient vector is randomly sampled from the constructed Laplace distribution; wherein the random sampling process uses the inverse transformation method of the Laplace distribution to randomly sample a probability value from a uniform distribution, and uses the probability value as the value of the cumulative distribution function based on the Laplace distribution, so as to obtain an equation with a random noise variable as an unknown;
[0020] Solve the equation with the random noise variable as the unknown variable to obtain the random noise variable as a random noise sample, and obtain a random noise vector that obeys the Laplace distribution through multiple random samplings; add the clipped gradient value and the random noise vector component by component, add the gradient component at the corresponding position in the clipped gradient value to the random noise component, and obtain a gradient vector with Laplace noise added, and use the gradient vector with Laplace noise added as the gradient value after noise disturbance.
[0021] Based on the local model parameters collected from each client, secret sharing technology and homomorphic encryption technology are used to obtain global model parameters through privacy-preserving parameter aggregation, including:
[0022] The server generates random polynomial coefficients for a secret sharing scheme and a public-private key pair for homomorphic encryption, and sends the random polynomial coefficients and the public key to each client; each client participating in the aggregation uses the random polynomial coefficients to divide each component of its local model parameter vector into a number of secret shares equal to the total number of clients, and sets the local model parameter component to the random polynomial coefficient;
[0023] The client generates a random mask for each local model parameter component using the public key sent by the server, and encrypts the random mask with the public key to obtain a ciphertext mask; adds each secret share to the corresponding ciphertext mask to obtain a masked secret share; sends the masked secret share of each local model parameter component to the corresponding client; and sends the ciphertext mask and the encrypted negative mask to the server at the same time;
[0024] The server collects the masked secret shares sent by each client, sums the masked secret share values at the same coordinate point, and uses Lagrange interpolation to obtain the aggregated secret share under homomorphic mask; then adds the ciphertext masks collected from each client, and uses the homomorphic property to obtain the aggregated homomorphic mask; the server adds the aggregated secret share under the homomorphic mask and the aggregated homomorphic mask, decrypts it using the private key, and sums the decrypted result with the negative mask collected from each client, and finally obtains the unmasked aggregated model parameters as the global model parameters.
[0025] The preset federated learning model is updated using the global model parameters to obtain a privacy protection strategy, including:
[0026] Obtaining global model parameters obtained through secret sharing and homomorphic encryption aggregation, loading the global model parameters into a preset federated learning model, and updating the weight parameters of the federated learning model using the global model parameters through a gradient descent algorithm to obtain an updated federated learning model; inputting a data feature set and a privacy protection requirement description of the federated learning task into the updated federated learning model, extracting a privacy attribute feature vector of the input data using a convolutional neural network, and inputting the privacy attribute feature vector into a support vector machine for classification to identify sensitive information in the data;
[0027] For the privacy attribute feature vector corresponding to the identified sensitive information, a multi-objective optimization model including privacy protection strength, data utility loss and computational overhead is constructed; the multi-objective optimization model is solved by a multi-objective evolutionary algorithm, and the non-dominated solution set of multiple objectives is screened and optimized according to the fitness function to obtain the Pareto optimal solution set; the solution that meets the privacy protection requirements and resource constraints of the current federated learning task is selected from the Pareto optimal solution set as the optimal privacy protection solution;
[0028] According to the optimal privacy protection scheme, a nonlinear mapping model of privacy protection strength and data utility loss is established, and the nonlinear mapping model uses a Gaussian radial basis kernel function to represent the nonlinear relationship between privacy protection strength and data utility loss. The nonlinear mapping model is optimized using a model parameter optimization algorithm, wherein minimizing the data utility loss is taken as the optimization goal, and the privacy protection strength is not less than a preset threshold as a constraint condition, so as to obtain the key parameter configuration that meets the minimum privacy protection strength requirement and minimizes the data utility loss, and generate a privacy protection strategy.
[0029] For the privacy attribute feature vector corresponding to the identified sensitive information, a multi-objective optimization model including privacy protection strength, data utility loss and computational overhead is constructed, including:
[0030] The parameter configuration of various privacy protection mechanisms is used as the decision variables of the multi-objective optimization model, and the decision variables include the type and degree of data transformation, the selection of encryption algorithm and key length, and the probability distribution function of data scrambling; the privacy protection strength objective function is constructed, in which the mutual information between the original data distribution and the data distribution after privacy protection is calculated by using the privacy measurement method based on mutual information. The smaller the mutual information, the higher the privacy protection strength. The negative value of the mutual information is used as the objective function to maximize the privacy protection strength;
[0031] Construct a data utility loss objective function, in which a similarity measurement method based on attribute normalization is used to calculate the normalized Euclidean distance between the original data record and the privacy-protected data record on each attribute, and the weighted average of the distances of each attribute is used as the data utility loss. The larger the distance, the greater the availability loss. Minimizing the utility loss is used as the objective function; construct a computational cost objective function, in which the time complexity and space complexity of the key operations of the privacy protection mechanism are analyzed to obtain the functional relationship between the computational cost and the mechanism parameters, and the objective function of minimizing the computational cost is constructed based on the functional relationship;
[0032] The privacy protection requirements of the current data processing task are formalized as numerical requirements for the privacy protection strength, and the lower bound constraints of the privacy protection strength objective function are constructed. Based on the currently available computing resources, quantitative restrictions are imposed on the time and storage overheads of the privacy protection mechanism, and the upper bound constraints of the computational overhead objective function are constructed. According to the privacy protection strength objective function, the data utility loss objective function, the computational overhead objective function, as well as the upper and lower bound constraints, a multi-objective optimization model is constructed.
[0033] When receiving a pending opinion posted by a target user, obtaining the target opinion after privacy protection based on the privacy protection policy includes:
[0034] Performing natural language processing on the opinions to be processed, extracting key information therein, and identifying private data in the key information, wherein the private data includes user name, address, telephone number, and email address; desensitizing the private data according to the privacy protection policy to obtain a desensitized opinion text; wherein, according to the desensitization method and desensitization intensity parameter set by the privacy protection policy, performing semantic replacement on the private data, using a generalized and pseudonymized data transformation method, replacing the private data with an equivalent expression that has similar semantics but cannot directly identify the individual's identity;
[0035] According to the privacy protection strategy, the privacy data and its fragments are summarized, and the natural language generation technology is used to rewrite the fragment description while keeping the semantics unchanged; for the privacy data defined as high-risk by the privacy protection strategy, the deletion method is used for desensitization; the differential privacy technology is used to add random noise to the desensitized opinion text to obtain the target opinion after privacy protection; in the target opinion after privacy protection, part-of-speech tagging and dependency syntactic analysis are used to extract the polarity characteristics of the target opinion after privacy protection; the latent semantic analysis technology is used to perform topic clustering on the target opinion after privacy protection and extract topic features; based on the sentiment dictionary, the sentiment score weighted average method is used to calculate the sentiment intensity value of the target opinion after privacy protection in each sentiment dimension, and construct the sentiment tendency feature;
[0036] Based on the combination of polarity features, topic features, and sentiment tendency features, a user opinion feature vector is constructed; an opinion feature vector library is constructed based on local user opinion historical data; a similarity list is obtained based on the similarity between the user opinion feature vector and each historical opinion feature vector in the opinion feature vector library; the credibility of the target opinion after privacy protection is evaluated based on the similarity list; and the target opinion after privacy protection whose credibility is higher than a preset threshold is retained.
[0037] According to a second aspect of the embodiments of the present invention,
[0038] Provides a user opinion privacy protection system based on federated learning and privacy differential, including:
[0039] The first unit is used to receive, at a server side, a federated learning participation request from at least two clients, wherein the federated learning participation request carries identification information and device performance parameters of each of the clients; for each of the clients, based on the identification information, divide a preset user opinion data set into corresponding sub-data sets; determine the number of local training rounds and the number of iterations per round for each client according to the device performance parameters of each of the clients; and send the sub-data set, the number of local training rounds and the number of iterations per round to the corresponding client;
[0040] The second unit is used to obtain corresponding local model parameters through multiple rounds of local training using a differential privacy machine learning algorithm based on the received sub-data set on each client, wherein each round of local training includes multiple iterations, and in each iteration, the local model parameters are perturbed using Laplace noise; and the local model parameters obtained through training are sent to the server;
[0041] The third unit is used to obtain global model parameters through privacy-preserving parameter aggregation based on the local model parameters collected from each client on the server side, using secret sharing technology and homomorphic encryption technology; update the preset federated learning model using the global model parameters to obtain a privacy protection strategy; send the privacy protection strategy to each client; receive the privacy protection strategy sent by the server side at each client, and when receiving the pending opinion posted by the target user, obtain the target opinion after privacy protection based on the privacy protection strategy; send the target opinion after privacy protection to the server side for business analysis and mining processing.
[0042] According to a third aspect of the embodiments of the present invention,
[0043] An electronic device is provided, comprising:
[0044] processor;
[0045] a memory for storing processor-executable instructions;
[0046] The processor is configured to call the instructions stored in the memory to execute the aforementioned method.
[0047] According to a fourth aspect of the embodiments of the present invention,
[0048] A computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the aforementioned method is implemented.
[0049] The beneficial effects of this application are as follows:
[0050] 1. Improve data privacy protection:
[0051] The present invention combines federated learning with differential privacy to train the model locally on the client and add noise disturbance to the model parameters, thus avoiding direct sharing of original user data. At the same time, secret sharing and homomorphic encryption technology are used on the server for secure aggregation, further protecting user privacy and effectively reducing the risk of data leakage.
[0052] 2. Improve model training efficiency and accuracy:
[0053] The present invention dynamically allocates training tasks according to the device performance parameters of each client and makes rational use of computing resources. Through multiple rounds of iterative training and parameter aggregation, the accuracy of the model can be improved while protecting privacy. In addition, the use of federated learning can also make full use of the data scattered in each client, expand the scale of training data, and improve model performance.
[0054] 3. Enhance the flexibility and practicality of the system:
[0055] The present invention establishes a complete interactive mechanism between the server and the client, which can adapt to different scales and types of user opinion data. By sending the trained privacy protection strategy to the client, real-time privacy protection processing of newly generated opinion data is achieved, making the system have good scalability and practical value. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] Figure 1 A flowchart of a method for protecting user opinion privacy based on federated learning and privacy differential according to an embodiment of the present invention;
[0057] Figure 2 This is a structural diagram of a user opinion privacy protection system based on federated learning and privacy differential according to an embodiment of the present invention. DETAILED DESCRIPTION
[0058] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0059] The technical solution of the present invention is described in detail with specific embodiments below. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described in detail in some embodiments.
[0060] Figure 1 FIG. 1 is a flow chart of a method for protecting user opinion privacy based on federated learning and privacy differential according to an embodiment of the present invention. Figure 1 As shown, the method includes:
[0061] S101. On the server side, receiving a federated learning participation request from at least two clients, wherein the federated learning participation request carries identification information and device performance parameters of each of the clients; for each of the clients, based on the identification information, dividing a preset user opinion data set into corresponding sub-data sets; determining the number of local training rounds and the number of iterations per round for each client according to the device performance parameters of each of the clients; and sending the sub-data sets, the number of local training rounds and the number of iterations per round to the corresponding client;
[0062] S102. On each of the clients, according to the received sub-dataset, using a differential privacy machine learning algorithm, obtaining corresponding local model parameters through multiple rounds of local training, each round of local training includes multiple iterations, and in each iteration, using Laplace noise to perturb the local model parameters; sending the local model parameters obtained through training to the server;
[0063] S103. On the server side, based on the local model parameters collected from each client, secret sharing technology and homomorphic encryption technology are used to obtain global model parameters through privacy-preserving parameter aggregation; the global model parameters are used to update the preset federated learning model to obtain a privacy protection strategy; the privacy protection strategy is sent to each client; at each client, the privacy protection strategy sent by the server is received, and when a pending opinion posted by a target user is received, a target opinion after privacy protection is obtained based on the privacy protection strategy; the target opinion after privacy protection is sent to the server side for business analysis and mining processing.
[0064] This embodiment provides a method for protecting user opinion privacy based on federated learning and privacy differential. The method first receives federated learning participation requests from multiple clients on the server side, and the requests include client identification information and device performance parameters. The server divides the preset user opinion data set into corresponding sub-data sets according to the client identification information, and determines the number of local training rounds and the number of iterations per round for each client according to the device performance parameters. Then the server sends the sub-data sets, the number of local training rounds and the number of iterations per round to the corresponding client.
[0065] On the client side, based on the received sub-dataset, a differential privacy machine learning algorithm is used to perform multiple rounds of local training to obtain local model parameters. Specifically, each round of local training includes multiple iterations, and in each iteration, Laplace noise is used to perturb the local model parameters. For example, Laplace noise with a mean of 0 and a standard deviation of 0.1 can be added to the model parameters after each iteration. After the training is completed, the client sends the obtained local model parameters to the server side.
[0066] After the server collects the local model parameters of each client, it uses secret sharing technology and homomorphic encryption technology to obtain the global model parameters through privacy-preserving parameter aggregation. Specifically, the additive homomorphic encryption scheme can be used to encrypt the local model parameters of each client and then aggregate them, and finally decrypt them to obtain the global model parameters. The server uses the global model parameters to update the preset federated learning model, obtain the privacy protection strategy, and send the strategy to each client.
[0067] After the client receives the privacy protection policy sent by the server, when a target user posts an opinion to be processed, the client processes the opinion based on the policy and obtains the target opinion after privacy protection. For example, sensitive words in the opinion can be replaced or deleted. The client then sends the target opinion after privacy protection to the server for subsequent business analysis and mining processing.
[0068] In order to better illustrate the technical solution of this implementation method, a specific data case is given below:
[0069] Assume that there are three clients participating in federated learning, namely clients A, B, and C. The user opinion dataset preset on the server contains 10,000 pieces of data.
[0070] After receiving the participation requests from the three clients, the server divides the data set into three sub-data sets according to the client identification information, which contain 3000, 3500, and 3500 data respectively. According to the device performance parameters, the number of local training rounds for clients A, B, and C is determined to be 5, 8, and 8 rounds respectively, and the number of iterations per round is 50, 80, and 80 times respectively.
[0071] The server sends the divided sub-datasets and training parameters to the corresponding clients. After receiving the data, each client starts local training. Taking client A as an example, in 5 rounds of training, each round of training contains 50 iterations. After each iteration, the model parameters are perturbed by adding Laplace noise with a mean of 0 and a standard deviation of 0.1. After the training is completed, client A obtains the perturbed local model parameters and sends them to the server.
[0072] After the server collects the local model parameters of the three clients, it aggregates them using an additive homomorphic encryption scheme. First, the three groups of parameters are encrypted separately, then the encrypted parameters are added together, and finally decrypted to obtain the global model parameters. The server uses the global model parameters to update the federated learning model, obtain the privacy protection strategy, and send the strategy to the three clients.
[0073] Suppose client A receives a user opinion to be processed: "I am very dissatisfied with a certain brand of mobile phone. The quality is too poor!" Based on the received privacy protection policy, client A processes the opinion and replaces "a certain brand" with "this brand" to obtain the processed opinion: "I am very dissatisfied with this brand of mobile phone. The quality is too poor!" The processed opinion is then sent to the server for subsequent analysis.
[0074] The beneficial effects of this embodiment are mainly reflected in the following three aspects:
[0075] First, through federated learning, user opinion data does not need to be uploaded to the central server, but is stored locally for training, effectively protecting user privacy. Each client only needs to upload the trained model parameters, greatly reducing the risk of data leakage.
[0076] Secondly, the differential privacy mechanism is introduced in the local training process, which further enhances the privacy protection of user data by adding random noise to the model parameters. Even if the model parameters are obtained by attackers, it is difficult to restore the original user data.
[0077] Finally, secret sharing and homomorphic encryption technology are used when aggregating parameters on the server side to achieve secure computing in an encrypted state and avoid information leakage in the intermediate process. The original data and intermediate results are effectively protected throughout the process, while an effective global model can be obtained, achieving a good balance between privacy protection and model effect.
[0078] In an optional implementation, each of the clients uses a differential privacy machine learning algorithm based on the received sub-dataset to obtain corresponding local model parameters through multiple rounds of local training, including:
[0079] In each round of training, a preset number of small batch sample sets are randomly extracted from the sub-dataset using a balanced sampling strategy, and the loss function of the current local model on the small batch sample set is calculated based on the small batch sample set; a calculation graph is constructed to symbolically define the loss function, and the partial derivatives of the loss function with respect to the parameters of each layer of the neural network are solved by back propagation to obtain the gradient values of each parameter; the calculated gradient values of each model parameter are spliced to form a complete model parameter gradient vector as the gradient value of the current model parameter;
[0080] Set the gradient clipping threshold, obtain the number of components of the current model parameter gradient value, and create a corresponding clipping mask vector according to the number of components; traverse the gradient values of the current model parameters to obtain the absolute value of each gradient component; for the gradient components whose absolute values do not exceed the clipping threshold, set them to 1 at the corresponding clipping mask vector position; for the gradient components whose absolute values exceed the clipping threshold, set them to the proportional coefficient of the clipping threshold divided by the absolute value of the component at the corresponding clipping mask vector position; according to the clipping mask vector, perform component-level gradient clipping on the gradient value of the current model parameter, wherein the following processing is performed on each gradient component: if the corresponding clipping mask vector component is 1, the gradient component remains unchanged; if the corresponding clipping mask vector component is less than 1, the value of the gradient component is multiplied by the corresponding proportional coefficient, and scaled to the clipping threshold boundary to obtain the clipped gradient value;
[0081] The sensitivity parameters of the current training round are determined according to the privacy budget allocation of each round of training and the clipping threshold, and a random noise vector obeying the Laplace distribution is generated using the sensitivity parameters. The gradient value after noise perturbation is obtained based on the random noise vector and the clipped gradient value. An adaptive learning rate optimization algorithm is used to automatically adjust the learning rate of the current iteration according to historical gradient information, and the current model parameters are updated using the adjusted learning rate and the gradient value after noise perturbation to obtain the model parameters after this iteration. Through multiple iterations, the model parameters obtained in the last iteration are used as the local model parameters of the current training round.
[0082] In this embodiment, the specific technical details of using the differential privacy machine learning algorithm for local training on the client are described in detail. This technical solution achieves privacy protection of user opinion data through key technologies such as balanced sampling, gradient clipping, noise perturbation, and adaptive learning rate.
[0083] The client first receives the sub-dataset assigned by the server, which contains the user opinion text and its corresponding label information. In order to improve the training effect, the original text data needs to be preprocessed, including word segmentation, stop word removal, and standardization. Taking the e-commerce review data as an example, the original review "This product is of good quality, I will buy it next time" can be obtained after preprocessing into a standardized feature sequence "product-quality-good-buy".
[0084] In each round of local training, a balanced sampling strategy is first used to randomly extract small batches of samples from the preprocessed sub-dataset. Specifically, if the sub-dataset contains 1,000 comments, of which 600 are positive comments and 400 are negative comments, and the sample size per batch is set to 32, samples are extracted from positive and negative samples at a ratio of 3:2 during sampling to ensure a balanced ratio of positive and negative samples in each small batch.
[0085] For the extracted small batch samples, a deep neural network model is constructed for training. The network structure adopts a typical text classification model, which includes a word embedding layer, a convolution layer, a pooling layer, and a fully connected layer. Taking the above comments as an example, after word embedding, a word vector matrix is obtained, and the dimension is the sequence length multiplied by the embedding dimension (such as 4×100). The loss function is symbolically defined through the calculation graph, and the cross entropy is used as the loss function to calculate the difference between the current model prediction result and the true label.
[0086] Next, the gradient of the loss function to each layer parameter is calculated through the back propagation algorithm. All the calculated parameter gradient values are concatenated into a gradient vector in a predefined order. For example, if the total number of parameters in each layer of the model is 10,000, the gradient vector dimension is 10,000×1.
[0087] In order to limit the range of gradient values, a gradient clipping mechanism is introduced. Set the clipping threshold to 0.1 and create a clipping mask vector of the same length as the gradient vector. Traverse each component in the gradient vector. If the absolute value of a component is 0.08, which is less than the clipping threshold, the corresponding mask vector position is set to 1; if the absolute value of the component is 0.15, which exceeds the clipping threshold, the corresponding mask vector position is set to 0.1 / 0.15≈0.67. The gradient value is clipped component-wise according to the mask vector. For the position with a mask value of 0.67, the original gradient 0.15 is scaled to 0.15×0.67=0.1.
[0088] When adding differential privacy protection, first calculate the sensitivity based on the privacy budget and clipping threshold of the current training round. Assuming the total privacy budget is 1 and the number of training rounds is 10, the privacy budget for each training round is 0.1. Generate a random noise vector that follows the Laplace distribution based on the sensitivity. The dimension of the noise vector is the same as the gradient vector. Add the noise vector to the clipped gradient vector to get the perturbed gradient value.
[0089] The Adam optimizer is used as the adaptive learning rate algorithm, which dynamically adjusts the learning rate of each parameter based on historical gradient information. The initial learning rate is set to 0.001, and the actual learning rate of the current iteration is automatically adjusted through the exponentially decaying momentum term and the second-order momentum term. The adjusted learning rate is multiplied by the perturbed gradient value to update the current model parameters.
[0090] Repeat the above iteration process for a preset number of times in each round of training, such as 100 iterations. The model parameters obtained in the last iteration are used as the local model parameters for the current training round. After all training rounds are completed, the final local model parameters are sent to the server for secure aggregation.
[0091] Through the above technical solution, the effectiveness of model training is guaranteed while protecting user privacy. After experimental verification, the solution can achieve a classification accuracy of more than 90% in the e-commerce review classification task, while meeting the requirements of differential privacy protection.
[0092] In an optional implementation, the sensitivity parameter of the current training round is determined according to the privacy budget allocation of each training round and the clipping threshold, a random noise vector obeying the Laplace distribution is generated using the sensitivity parameter, and a gradient value after noise perturbation is obtained based on the random noise vector and the clipped gradient value, including:
[0093] According to the total number of training rounds of federated learning and the total number of clients, determine the privacy budget available to each client in each round of local training, and evenly distribute the privacy budget of each round to each training iteration step; obtain the privacy budget of the current training round, and calculate the sensitivity parameter of the current training round according to the privacy budget and a preset gradient clipping threshold, wherein the sensitivity parameter is inversely proportional to the privacy budget and proportional to the clipping threshold;
[0094] The probability density function of the Laplace distribution is constructed using the sensitivity parameter, and the reciprocal of the sensitivity parameter is used as the scale parameter of the Laplace distribution; according to the number of components of the gradient vector after gradient clipping, a random noise vector having the same number of components as the gradient vector is randomly sampled from the constructed Laplace distribution; wherein the random sampling process uses the inverse transformation method of the Laplace distribution to randomly sample a probability value from a uniform distribution, and uses the probability value as the value of the cumulative distribution function based on the Laplace distribution, so as to obtain an equation with a random noise variable as an unknown;
[0095] Solve the equation with the random noise variable as the unknown variable to obtain the random noise variable as a random noise sample, and obtain a random noise vector that obeys the Laplace distribution through multiple random samplings; add the clipped gradient value and the random noise vector component by component, add the gradient component at the corresponding position in the clipped gradient value to the random noise component, and obtain a gradient vector with Laplace noise added, and use the gradient vector with Laplace noise added as the gradient value after noise disturbance.
[0096] In the federated learning system, in order to protect the privacy of client data, differential privacy technology can be used to protect gradient information. The specific implementation process is as follows:
[0097] First, a privacy budget is allocated to each client based on the total number of training rounds of federated learning and the total number of clients participating in the training. Assume that the total number of training rounds is 100, the total number of clients is 10, and the total privacy budget available to each client is 1. Then the privacy budget available to each client in each round of local training is 1 / (100*10)=0.001. This budget value is evenly distributed to each iteration step in each round of training. If each round of training contains 50 iteration steps, the privacy budget for each step is 0.001 / 50=0.00002.
[0098] Next, obtain the privacy budget value of the current training round, and calculate the sensitivity parameter of the current training round in combination with the pre-set gradient clipping threshold. The sensitivity parameter is inversely proportional to the privacy budget and directly proportional to the clipping threshold. For example, if the privacy budget of the current round is 0.001 and the clipping threshold is 4, the sensitivity parameter can be calculated as 4 / 0.001=4000.
[0099] Then, the calculated sensitivity parameter is used to construct the probability density function of the Laplace distribution. The reciprocal of the sensitivity parameter is used as the scale parameter of the Laplace distribution, that is, 1 / 4000=0.00025. According to the number of components of the gradient vector after gradient clipping, random sampling is performed from the constructed Laplace distribution to generate the same number of random noise vectors.
[0100] The random sampling process uses the inverse transformation method of the Laplace distribution. First, a probability value p is randomly sampled from the uniform distribution [0,1] and substituted into the inverse function of the cumulative distribution function of the Laplace distribution. For example, if p=0.7 is obtained by sampling, the equation is: 0.7=1-0.5*exp(-|x| / 0.00025). Solving this equation can obtain a random noise sample x≈-0.0000866. Repeating this process multiple times can obtain a random noise vector that obeys the Laplace distribution.
[0101] Finally, add the clipped gradient value and the random noise vector component by component. Assuming that the clipped gradient component value is 0.05 and the corresponding random noise component is -0.0000866, the result after addition is 0.0499134. Repeat this operation for all components to obtain the gradient vector with Laplace noise added as the final gradient value after noise perturbation.
[0102] Using the above method for differential privacy protection has the following beneficial effects:
[0103] 1. By reasonably allocating the privacy budget and introducing random noise, the client's data privacy is effectively protected, preventing the original data from being inferred through gradient information.
[0104] 2. By combining gradient clipping and Laplace mechanism, useful gradient information is retained as much as possible while protecting privacy, thus balancing privacy protection and model performance.
[0105] 3. The dynamically adjusted sensitivity parameters enable the noise addition process to adapt to the needs of different training stages, improving the flexibility and effectiveness of privacy protection.
[0106] In an optional implementation, based on the local model parameters of each client collected, secret sharing technology and homomorphic encryption technology are used to obtain global model parameters through privacy-preserving parameter aggregation, including:
[0107] The server generates random polynomial coefficients for a secret sharing scheme and a public-private key pair for homomorphic encryption, and sends the random polynomial coefficients and the public key to each client; each client participating in the aggregation uses the random polynomial coefficients to divide each component of its local model parameter vector into a number of secret shares equal to the total number of clients, and sets the local model parameter component to the random polynomial coefficient;
[0108] The client generates a random mask for each local model parameter component using the public key sent by the server, and encrypts the random mask with the public key to obtain a ciphertext mask; adds each secret share to the corresponding ciphertext mask to obtain a masked secret share; sends the masked secret share of each local model parameter component to the corresponding client; and sends the ciphertext mask and the encrypted negative mask to the server at the same time;
[0109] The server collects the masked secret shares sent by each client, sums the masked secret share values at the same coordinate point, and uses Lagrange interpolation to obtain the aggregated secret share under homomorphic mask; then adds the ciphertext masks collected from each client, and uses the homomorphic property to obtain the aggregated homomorphic mask; the server adds the aggregated secret share under the homomorphic mask and the aggregated homomorphic mask, decrypts it using the private key, and sums the decrypted result with the negative mask collected from each client, and finally obtains the unmasked aggregated model parameters as the global model parameters.
[0110] This embodiment provides a method for aggregating model parameters for privacy protection based on federated learning. The method first generates random polynomial coefficients for secret sharing and a public-private key pair for homomorphic encryption by a server. The server sends the random polynomial coefficients and the public key to each client participating in the aggregation.
[0111] After each client receives the random polynomial coefficient, it uses the coefficient to divide each component of the local model parameter vector into multiple secret shares. Specifically, assuming that there are n clients participating in the aggregation, each model parameter component is divided into n secret shares. Taking a model parameter component value of client A as an example, the received random polynomial coefficients [a0, a1, ..., an-1] are used to construct the polynomial f(x) = value + a1x + a2x^2 + ... + an-1x^(n-1), where a0 = value. Then f(1), f(2), ..., f(n) are calculated as n secret shares. In this way, any n-1 or fewer secret shares cannot restore the original parameter value, and only when all n secret shares are collected can value be reconstructed.
[0112] Next, the client uses the public key sent by the server to generate a random mask for each local model parameter component. Taking the parameter component value as an example, the client randomly generates a mask r and encrypts r with the public key to obtain the ciphertext mask Enc(r). Then each secret share si of value is added to the corresponding ciphertext mask to obtain the masked secret share si +Enc(r). The client sends the masked secret share of each parameter component to the corresponding other clients. At the same time, the client sends the ciphertext mask Enc(r) and the encrypted negative mask Enc(-r) to the server.
[0113] After the server collects the masked secret shares sent by each client, it sums the masked secret share values at the same coordinate point. For example, for the parameter component value, the server collects n masked secret shares s1+Enc(r1), s2+Enc(r2), ..., sn+Enc(rn). The server adds these n values and obtains S = (s1+s2+...+sn) + Enc(r1+r2+...+rn). Lagrange interpolation can be used to recover the aggregated secret value under homomorphic masking from S, that is, value+Enc(r1+r2+...+rn).
[0114] At the same time, the server also collects the ciphertext masks Enc(r1), Enc(r2), ..., Enc(rn) sent by each client. The server adds these ciphertext masks together and uses the properties of homomorphic encryption to obtain the aggregated homomorphic mask Enc(r1+r2+...+rn).
[0115] Finally, the server adds the aggregated secret value value+Enc(r1+r2+...+rn) under the homomorphic mask to the aggregated homomorphic mask Enc(r1+r2+...+rn), decrypts it with the private key, and obtains value+(r1+r2+...+rn). Then the result is summed with the collected negative masks Enc(-r1), Enc(-r2), ..., Enc(-rn) of each client and decrypted to finally obtain the unmasked aggregate model parameter value. Repeat the above process to obtain the aggregated result of all model parameters as the global model parameter.
[0116] The beneficial effects of this method include:
[0117] 1) Through secret sharing technology, the privacy of local model parameters of each client is effectively protected to prevent parameter leakage.
[0118] 2) By using homomorphic encryption technology, parameter aggregation is achieved in an encrypted state, ensuring the security of the calculation process.
[0119] 3) Combining secret sharing and homomorphic encryption, accurate model parameter aggregation is achieved while protecting privacy, ensuring the performance of the global model.
[0120] In an optional implementation, the preset federated learning model is updated using the global model parameters to obtain a privacy protection strategy, including:
[0121] Obtaining global model parameters obtained through secret sharing and homomorphic encryption aggregation, loading the global model parameters into a preset federated learning model, and updating the weight parameters of the federated learning model using the global model parameters through a gradient descent algorithm to obtain an updated federated learning model; inputting a data feature set and a privacy protection requirement description of the federated learning task into the updated federated learning model, extracting a privacy attribute feature vector of the input data using a convolutional neural network, and inputting the privacy attribute feature vector into a support vector machine for classification to identify sensitive information in the data;
[0122] For the privacy attribute feature vector corresponding to the identified sensitive information, a multi-objective optimization model including privacy protection strength, data utility loss and computational overhead is constructed; the multi-objective optimization model is solved by a multi-objective evolutionary algorithm, and the non-dominated solution set of multiple objectives is screened and optimized according to the fitness function to obtain the Pareto optimal solution set; the solution that meets the privacy protection requirements and resource constraints of the current federated learning task is selected from the Pareto optimal solution set as the optimal privacy protection solution;
[0123] According to the optimal privacy protection scheme, a nonlinear mapping model of privacy protection strength and data utility loss is established, and the nonlinear mapping model uses a Gaussian radial basis kernel function to represent the nonlinear relationship between privacy protection strength and data utility loss. The nonlinear mapping model is optimized using a model parameter optimization algorithm, wherein minimizing the data utility loss is taken as the optimization goal, and the privacy protection strength is not less than a preset threshold as a constraint condition, so as to obtain the key parameter configuration that meets the minimum privacy protection strength requirement and minimizes the data utility loss, and generate a privacy protection strategy.
[0124] This embodiment provides a method for generating a privacy protection strategy based on federated learning. The method first obtains the global model parameters obtained by secret sharing and homomorphic encryption aggregation. Specifically, the Shamir secret sharing scheme can be used to divide the local model parameters of each participant into multiple parts, and the Paillier homomorphic encryption algorithm can be used to encrypt the divided parameters. Then, the aggregation is performed in the encrypted domain through the secure multi-party computing protocol, and finally the global model parameters are decrypted.
[0125] The obtained global model parameters are loaded into the preset federated learning model. The federated learning model can be a pre-trained neural network model, such as a convolutional neural network or a recurrent neural network. Then, the weight parameters of the federated learning model are updated using the global model parameters through the gradient descent algorithm. Specifically, the stochastic gradient descent (SGD) or Adam optimizer can be used to iteratively update the model weights with the goal of minimizing the loss function until convergence or reaching the preset number of iterations. Finally, the updated federated learning model is obtained.
[0126] The data feature set and privacy protection requirement description of the federated learning task are input into the updated federated learning model. The data feature set can include multiple features such as numerical and categorical, and the privacy protection requirement description can include a list of sensitive attributes, privacy protection strength requirements, etc. The convolutional neural network is used to extract the privacy attribute feature vector of the input data. Specifically, multi-layer convolution and pooling operations can be used to extract local and global features of the data, and finally a fixed-dimensional feature vector is obtained through a fully connected layer.
[0127] The extracted privacy attribute feature vector is input into the support vector machine for classification to identify sensitive information in the data. The support vector machine uses the radial basis kernel function to classify the feature vector into two categories by maximizing the classification interval, and divides it into two categories: sensitive information and non-sensitive information. The identification result can be represented by a 01 label, 1 for sensitive information and 0 for non-sensitive information.
[0128] For the privacy attribute feature vector corresponding to the identified sensitive information, a multi-objective optimization model including privacy protection strength, data utility loss and computational overhead is constructed. The privacy protection strength can be represented by the privacy budget ε in differential privacy, the data utility loss can be represented by the mean square error between the original data and the noisy data, and the computational overhead can be represented by the algorithm running time. The three objective functions are combined to form a multi-objective optimization problem.
[0129] The multi-objective evolutionary algorithm is used to solve the multi-objective optimization model. Specifically, the NSGA-II algorithm can be used to generate a new population through genetic operations such as crossover and mutation, and select excellent individuals based on non-dominated sorting and crowding calculation. During the iterative optimization process, the non-dominated solution set of multiple objectives is screened and optimized according to the fitness function, and finally the Pareto optimal solution set is obtained. From the Pareto optimal solution set, the solution that meets the privacy protection requirements and resource constraints of the current federated learning task is selected as the optimal privacy protection solution.
[0130] According to the optimal privacy protection scheme, a nonlinear mapping model of privacy protection strength and data utility loss is established. The nonlinear mapping model uses the Gaussian radial basis kernel function to represent the nonlinear relationship between privacy protection strength and data utility loss. The expression of the Gaussian radial basis kernel function is K(x,x')=exp(-||x-x'||^2 / (2σ^2)), where x and x' represent the privacy protection strength and data utility loss respectively, and σ is the kernel function parameter.
[0131] The nonlinear mapping model is optimized using the model parameter optimization algorithm. The optimization goal is to minimize the data utility loss, and the privacy protection strength is not less than the preset threshold as a constraint. The particle swarm optimization algorithm can be used for parameter optimization, and the optimal solution is searched by iteratively updating the particle position and velocity. Finally, the key parameter configuration that meets the minimum privacy protection strength requirements and minimizes the data utility loss is obtained, and the privacy protection strategy is generated.
[0132] In the specific implementation, the following data case can be used: suppose there is a data set containing 10,000 records and 20 features, of which 5 features are marked as sensitive information. Set the privacy protection strength threshold ε=1, and the computing resource limit is 10 minutes. First, extract the 20-dimensional feature vector through the convolutional neural network, and then use the support vector machine to identify 5 sensitive features. Construct a three-objective optimization model, and use the NSGA-II algorithm to solve and obtain 100 Pareto optimal solutions. Select the solution with ε=0.8, 5% data utility loss, and 8 minutes of computing time as the optimal solution. Finally, optimize the nonlinear mapping model, obtain the Gaussian kernel function parameter configuration with σ=0.5, and generate the final privacy protection strategy.
[0133] The beneficial effects of this method include:
[0134] 1. By combining federated learning with differential privacy, we can improve model performance while protecting data privacy, and achieve a balance between privacy protection and data utility.
[0135] 2. A multi-objective optimization method is used to comprehensively consider the privacy protection strength, data utility and computational overhead to obtain a more comprehensive and practical privacy protection solution.
[0136] 3. The nonlinear mapping model is used to characterize the relationship between privacy protection strength and data utility, and the optimal configuration is obtained through parameter optimization, which improves the accuracy and adaptability of the privacy protection strategy.
[0137] In an optional implementation, for the privacy attribute feature vector corresponding to the identified sensitive information, a multi-objective optimization model including privacy protection strength, data utility loss and computational overhead is constructed, including:
[0138] The parameter configuration of various privacy protection mechanisms is used as the decision variables of the multi-objective optimization model, and the decision variables include the type and degree of data transformation, the selection of encryption algorithm and key length, and the probability distribution function of data scrambling; the privacy protection strength objective function is constructed, in which the mutual information between the original data distribution and the data distribution after privacy protection is calculated by using the privacy measurement method based on mutual information. The smaller the mutual information, the higher the privacy protection strength. The negative value of the mutual information is used as the objective function to maximize the privacy protection strength;
[0139] Construct a data utility loss objective function, in which a similarity measurement method based on attribute normalization is used to calculate the normalized Euclidean distance between the original data record and the privacy-protected data record on each attribute, and the weighted average of the distances of each attribute is used as the data utility loss. The larger the distance, the greater the availability loss. Minimizing the utility loss is used as the objective function; construct a computational cost objective function, in which the time complexity and space complexity of the key operations of the privacy protection mechanism are analyzed to obtain the functional relationship between the computational cost and the mechanism parameters, and the objective function of minimizing the computational cost is constructed based on the functional relationship;
[0140] The privacy protection requirements of the current data processing task are formalized as numerical requirements for the privacy protection strength, and the lower bound constraints of the privacy protection strength objective function are constructed. Based on the currently available computing resources, quantitative restrictions are imposed on the time and storage overheads of the privacy protection mechanism, and the upper bound constraints of the computational overhead objective function are constructed. According to the privacy protection strength objective function, the data utility loss objective function, the computational overhead objective function, as well as the upper and lower bound constraints, a multi-objective optimization model is constructed.
[0141] The specific implementation method of constructing a multi-objective optimization model including privacy protection strength, data utility loss and computational overhead for the privacy attribute feature vector corresponding to the identified sensitive information is as follows:
[0142] First, the parameter configuration of various privacy protection mechanisms is used as the decision variable of the multi-objective optimization model. The decision variables include the type and degree of data transformation, the choice of encryption algorithm and key length, the probability distribution function of data scrambling, etc. For example, for data transformation, you can choose differential privacy, k-anonymity and other mechanisms, and the degree of transformation is expressed by ε value or k value; for encryption algorithm, you can choose AES, RSA, etc., and the key length is expressed by the number of bits; for data scrambling, you can choose Laplace distribution, exponential distribution, etc.
[0143] Next, construct the objective function of privacy protection strength. The mutual information between the original data distribution and the privacy-protected data distribution is calculated using a privacy measurement method based on mutual information. The specific steps are: first estimate the probability distribution of the original data and the protected data, and then calculate the mutual information of the two distributions. The smaller the mutual information, the higher the privacy protection strength, so the negative value of the mutual information is used as the objective function to maximize the privacy protection strength. For example, assuming that the mutual information between the original data X and the protected data Y is I(X;Y)=0.8 bits, the objective function can be expressed as max(-I(X;Y))=max(-0.8).
[0144] Then, the objective function of data utility loss is constructed. The normalized Euclidean distance between the original data record and the privacy-protected data record on each attribute is calculated using a similarity measurement method based on attribute normalization. The specific steps are: first, each attribute is normalized, then the Euclidean distance of each record on each attribute is calculated, and finally the weighted average of the distances of each attribute is used as the data utility loss. The larger the distance, the greater the loss of availability, so the minimization of utility loss is used as the objective function. For example, assuming that the normalized Euclidean distances of a record on the two attributes of age and income are 0.2 and 0.3 respectively, and the weights are 0.6 and 0.4 respectively, then the utility loss of the record is 0.2×0.6+0.3×0.4=0.24.
[0145] Next, construct the computational cost objective function. Analyze the time complexity and space complexity of the key operations of the privacy protection mechanism, and obtain the functional relationship between the computational cost and the mechanism parameters. Construct the objective function of minimizing the computational cost based on the functional relationship. For example, for the differential privacy mechanism, its time complexity is related to the data size n and the privacy budget ε, which can be expressed as O(n / ε). Assuming that the actual running time t is proportional to the theoretical time complexity, that is, t=c·n / ε, where c is a constant, then minimizing t can be used as the objective function.
[0146] The privacy protection requirements of the current data processing task are formalized as the numerical requirements of the privacy protection strength, and the lower bound constraint of the privacy protection strength objective function is constructed. For example, if the mutual information is required to be no more than 0.5 bits, the constraint can be expressed as I(X;Y)≤0.5.
[0147] According to the currently available computing resources, the time and storage costs of the privacy protection mechanism are quantitatively restricted, and the upper bound constraint of the computing cost objective function is constructed. For example, assuming that the available computing time is 10 seconds and the storage space is 1GB, the constraint can be expressed as t≤10s, s≤1GB.
[0148] Finally, a multi-objective optimization model is constructed based on the privacy protection strength objective function, data utility loss objective function, computational cost objective function, upper bound constraints, and lower bound constraints. The three objective functions are normalized and weighted summed to obtain a comprehensive objective function. The weights can be adjusted according to the needs of specific application scenarios. For example, assuming that the weights of the three objective functions are 0.4, 0.4, and 0.2, respectively, the comprehensive objective function can be expressed as: f=0.4×(-I(X;Y))+0.4×(-d)+0.2×(-t), where d is the data utility loss and t is the computation time. Considering all constraints at the same time, a complete multi-objective optimization model is obtained.
[0149] For the constructed multi-objective optimization model, intelligent optimization algorithms such as genetic algorithm and particle swarm algorithm can be used to solve the optimal parameter configuration of the privacy protection mechanism. The specific steps are as follows: first, a set of initial solutions are randomly generated, each solution contains the value of each decision variable; then the objective function value and constraint satisfaction corresponding to each solution are calculated; then the solutions are evaluated and sorted according to the objective function value; then new solutions are generated through selection, crossover, mutation and other operations; repeat the above steps until the termination condition is reached, and the optimal solution is output as the parameter configuration scheme of the privacy protection mechanism.
[0150] In practical applications, the model can be adjusted and optimized according to the specific data set and privacy protection requirements. For example, for a personal data set containing attributes such as name, age, and income, age and income can be used as sensitive attributes and protected by combining k-anonymity and differential privacy. Through the multi-objective optimization model, the optimal k value and ε value can be obtained, which can maximize data availability while ensuring privacy security.
[0151] The beneficial effects of this technical solution are mainly reflected in the following three aspects:
[0152] First, by constructing a multi-objective optimization model, a balance is achieved among privacy protection strength, data utility, and computational overhead. The weight of each objective can be flexibly adjusted according to the needs of specific application scenarios to obtain the optimal parameter configuration scheme for the privacy protection mechanism.
[0153] Secondly, the privacy measurement method based on mutual information and the similarity measurement method based on attribute normalization can more accurately evaluate the privacy protection strength and data utility loss, providing a reliable objective function for the optimization model.
[0154] Finally, by introducing the computational overhead objective function and constraints, the feasibility of the privacy protection scheme is ensured, and efficient privacy protection can be achieved under limited computing resources.
[0155] In an optional implementation, when receiving the pending opinion posted by the target user, obtaining the target opinion after privacy protection based on the privacy protection policy includes:
[0156] Performing natural language processing on the opinions to be processed, extracting key information therein, and identifying private data in the key information, wherein the private data includes user name, address, telephone number, and email address; desensitizing the private data according to the privacy protection policy to obtain a desensitized opinion text; wherein, according to the desensitization method and desensitization intensity parameter set by the privacy protection policy, performing semantic replacement on the private data, using a generalized and pseudonymized data transformation method, replacing the private data with an equivalent expression that has similar semantics but cannot directly identify the individual's identity;
[0157] According to the privacy protection strategy, the privacy data and its fragments are summarized, and the natural language generation technology is used to rewrite the fragment description while keeping the semantics unchanged; for the privacy data defined as high-risk by the privacy protection strategy, the deletion method is used for desensitization; the differential privacy technology is used to add random noise to the desensitized opinion text to obtain the target opinion after privacy protection; in the target opinion after privacy protection, part-of-speech tagging and dependency syntactic analysis are used to extract the polarity characteristics of the target opinion after privacy protection; the latent semantic analysis technology is used to perform topic clustering on the target opinion after privacy protection and extract topic features; based on the sentiment dictionary, the sentiment score weighted average method is used to calculate the sentiment intensity value of the target opinion after privacy protection in each sentiment dimension, and construct the sentiment tendency feature;
[0158] Based on the combination of polarity features, topic features, and sentiment tendency features, a user opinion feature vector is constructed; an opinion feature vector library is constructed based on local user opinion historical data; a similarity list is obtained based on the similarity between the user opinion feature vector and each historical opinion feature vector in the opinion feature vector library; the credibility of the target opinion after privacy protection is evaluated based on the similarity list; and the target opinion after privacy protection whose credibility is higher than a preset threshold is retained.
[0159] When receiving a pending opinion posted by a target user, the opinion is first subjected to natural language processing. This includes using word segmentation technology to segment the text into words or phrases, removing stop words, and extracting keywords and phrases. For example, for an opinion such as "I bought a piece of clothing at the mall at No. 123 Beijing Road yesterday and spent 299 yuan", key information such as "No. 123 Beijing Road", "mall", "clothes", and "299 yuan" can be extracted.
[0160] Next, identify the private data in the extracted key information. The private data here includes user name, address, phone number, email address, etc. You can use a pre-defined regular expression pattern or named entity recognition model to identify these private data. In the above example, "No. 123 Beijing Road" will be identified as address information.
[0161] Then, according to the pre-set privacy protection strategy, the identified privacy data is desensitized. The desensitization method and intensity can be flexibly set according to the sensitivity of the data. For address information, a generalization method can be used to replace "No. 123 Beijing Road" with "a certain street in a certain city". For phone numbers, a pseudonymization method can be used to replace the actual number with a randomly generated number. For user names, words with similar semantics but unable to identify specific individuals can be used to replace them, such as replacing "Zhang San" with "Mr. So-and-so".
[0162] In addition to direct replacement, the entire segment containing private data can also be summarized and rewritten. For example, "I bought a piece of clothing at the mall at No. 123 Beijing Road yesterday" can be rewritten as "I recently went shopping at a mall." This method can better protect user privacy while maintaining the overall semantics of the opinion. For private data defined as high risk, it is directly processed by deletion.
[0163] After completing the above desensitization process, in order to further enhance the privacy protection effect, differential privacy technology can be used to add random noise to the processed text. Specifically, this can be achieved by randomly inserting, deleting or replacing some insignificant words in the text. In this way, even if someone obtains the desensitized text, it is difficult to infer the specific content of the original text without changing the overall semantics.
[0164] Next, feature extraction is performed on the processed opinion text. First, the words in the text are tagged with part-of-speech using a part-of-speech tagging tool, and then the grammatical structure information of the text is extracted through dependency syntax analysis. Based on this information, the polarity features of the text can be identified, that is, the overall tendency of the opinion can be determined to be positive, negative, or neutral.
[0165] At the same time, latent semantic analysis technology is used to cluster the text into topics. This includes building a word-document matrix, extracting latent topics using dimensionality reduction techniques such as singular value decomposition, and then determining the topic distribution of the text based on the weight of each word on different topics. For example, for an opinion such as "the service attitude of this mall is very good, but the variety of goods is not enough", two main topics may be extracted: "service" and "goods".
[0166] In addition, it is necessary to analyze the emotional tendency characteristics of the text. First, establish an emotional dictionary containing various emotional words and their intensity values. Then identify these emotional words in the text and calculate the weights according to their positions and modification relationships in the text. Finally, through the weighted average method, the intensity values of the text in different emotional dimensions such as "joy", "anger", and "disappointment" are obtained.
[0167] Based on the polarity features, topic features and sentiment features extracted above, a multi-dimensional user opinion feature vector is constructed. For example, a feature vector may contain information such as [polarity: 0.8, topic 1: 0.6, topic 2: 0.3, joy: 0.7, anger: 0.1].
[0168] At the same time, the system will maintain an opinion feature vector library based on historical data. When a new opinion feature vector is generated, the similarity will be calculated with all the vectors in the library to obtain a similarity list. The similarity can be calculated using methods such as cosine similarity.
[0169] Finally, the credibility of the target opinion is evaluated based on this similarity list. The evaluation method can be to take the average credibility of several historical opinions with the highest similarity, or to calculate the credibility based on the weighted similarity. If the credibility obtained by the evaluation is higher than the preset threshold (such as 0.7), the opinion is retained; otherwise, it is filtered out.
[0170] The beneficial effects of this method are mainly reflected in three aspects:
[0171] First, through multi-level privacy protection processing, the user's personal privacy information is effectively protected and the risk of information leakage is reduced. At the same time, the application of differential privacy technology further enhances the security of data, making it difficult to restore the original information even if the data is illegally obtained.
[0172] Secondly, the use of natural language processing and machine learning technology to extract and analyze multi-dimensional features of user opinions can comprehensively and accurately capture the semantic information and emotional tendencies of opinions. This lays the foundation for subsequent opinion classification, clustering and analysis, and helps to better understand and utilize user feedback.
[0173] Finally, by comparing with historical data and evaluating the credibility, possible spam or malicious comments were effectively filtered out, improving the quality and reliability of the opinion database. This not only helps to improve the accuracy of subsequent data analysis, but also provides more valuable reference information for decision makers.
[0174] Figure 2 FIG. 1 is a schematic diagram of the structure of a user opinion privacy protection system based on federated learning and privacy differential according to an embodiment of the present invention. Figure 2 As shown, the system comprises:
[0175] The first unit is used to receive, at a server side, a federated learning participation request from at least two clients, wherein the federated learning participation request carries identification information and device performance parameters of each of the clients; for each of the clients, based on the identification information, divide a preset user opinion data set into corresponding sub-data sets; determine the number of local training rounds and the number of iterations per round for each client according to the device performance parameters of each of the clients; and send the sub-data set, the number of local training rounds and the number of iterations per round to the corresponding client;
[0176] The second unit is used to obtain corresponding local model parameters through multiple rounds of local training using a differential privacy machine learning algorithm based on the received sub-data set on each client, wherein each round of local training includes multiple iterations, and in each iteration, the local model parameters are perturbed using Laplace noise; and the local model parameters obtained through training are sent to the server;
[0177] The third unit is used to obtain global model parameters through privacy-preserving parameter aggregation based on the local model parameters collected from each client on the server side, using secret sharing technology and homomorphic encryption technology; update the preset federated learning model using the global model parameters to obtain a privacy protection strategy; send the privacy protection strategy to each client; receive the privacy protection strategy sent by the server side at each client, and when receiving the pending opinion posted by the target user, obtain the target opinion after privacy protection based on the privacy protection strategy; send the target opinion after privacy protection to the server side for business analysis and mining processing.
[0178] According to a third aspect of the embodiments of the present invention,
[0179] An electronic device is provided, comprising:
[0180] processor;
[0181] a memory for storing processor-executable instructions;
[0182] The processor is configured to call the instructions stored in the memory to execute the aforementioned method.
[0183] A fourth aspect of the embodiments of the present invention is:
[0184] A computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the aforementioned method is implemented.
[0185] The present invention may be a method, an apparatus, a system and / or a computer program product. The computer program product may include a computer-readable storage medium carrying computer-readable program instructions for executing various aspects of the present invention.
[0186] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A user opinion privacy protection method based on federated learning and privacy differential, characterized in that: include: On the server side, receiving a federated learning participation request from at least two clients, wherein the federated learning participation request carries identification information and device performance parameters of each of the clients; for each of the clients, dividing a preset user opinion data set into corresponding sub-data sets based on the identification information; Determining the number of local training rounds and the number of iterations per round for each client according to the device performance parameters of each client; Send the sub-dataset, the number of local training rounds and the number of iterations per round to the corresponding client; On each of the clients, according to the received sub-dataset, a differential privacy machine learning algorithm is used to obtain corresponding local model parameters through multiple rounds of local training, where each round of local training includes multiple iterations, and in each iteration, the local model parameters are perturbed by Laplace noise; Sending the local model parameters obtained through training to the server; On the server side, based on the local model parameters collected from each client, secret sharing technology and homomorphic encryption technology are used to obtain global model parameters through privacy-preserving parameter aggregation; the global model parameters are used to update the preset federated learning model to obtain a privacy protection strategy; the privacy protection strategy is sent to each client; on each client, the privacy protection strategy sent by the server is received, and when a pending opinion posted by a target user is received, the target opinion after privacy protection is obtained based on the privacy protection strategy; Sending the privacy-protected target opinions to the server for business analysis and mining processing; The preset federated learning model is updated using the global model parameters to obtain a privacy protection strategy, including: Obtaining global model parameters obtained through secret sharing and homomorphic encryption aggregation, loading the global model parameters into a preset federated learning model, and updating the weight parameters of the federated learning model using the global model parameters through a gradient descent algorithm to obtain an updated federated learning model; inputting a data feature set and a privacy protection requirement description of the federated learning task into the updated federated learning model, extracting a privacy attribute feature vector of the input data using a convolutional neural network, and inputting the privacy attribute feature vector into a support vector machine for classification to identify sensitive information in the data; For the privacy attribute feature vector corresponding to the identified sensitive information, a multi-objective optimization model including privacy protection strength, data utility loss and computational overhead is constructed; the multi-objective optimization model is solved by a multi-objective evolutionary algorithm, and the non-dominated solution set of multiple objectives is screened and optimized according to the fitness function to obtain the Pareto optimal solution set; the solution that meets the privacy protection requirements and resource constraints of the current federated learning task is selected from the Pareto optimal solution set as the optimal privacy protection solution; According to the optimal privacy protection scheme, a nonlinear mapping model of privacy protection strength and data utility loss is established, and the nonlinear mapping model uses a Gaussian radial basis kernel function to represent the nonlinear relationship between privacy protection strength and data utility loss. The nonlinear mapping model is optimized using a model parameter optimization algorithm, wherein minimizing the data utility loss is taken as the optimization goal, and the privacy protection strength is not less than a preset threshold as a constraint condition, so as to obtain the key parameter configuration that meets the minimum privacy protection strength requirement and minimizes the data utility loss, and generate a privacy protection strategy.
2. The method according to claim 1, wherein each of the clients uses a differential privacy machine learning algorithm based on the received sub-dataset to obtain corresponding local model parameters through multiple rounds of local training, including: In each round of training, a preset number of small batch sample sets are randomly extracted from the sub-dataset using a balanced sampling strategy, and the loss function of the current local model on the small batch sample set is calculated based on the small batch sample set; a calculation graph is constructed to symbolically define the loss function, and the partial derivatives of the loss function with respect to the parameters of each layer of the neural network are solved by back propagation to obtain the gradient values of each parameter; the calculated gradient values of each model parameter are spliced to form a complete model parameter gradient vector as the gradient value of the current model parameter; Set the gradient clipping threshold, obtain the number of components of the current model parameter gradient value, and create a corresponding clipping mask vector according to the number of components; traverse the gradient values of the current model parameters to obtain the absolute value of each gradient component; for the gradient components whose absolute values do not exceed the clipping threshold, set them to 1 at the corresponding clipping mask vector position; for the gradient components whose absolute values exceed the clipping threshold, set them to the proportional coefficient of the clipping threshold divided by the absolute value of the component at the corresponding clipping mask vector position; according to the clipping mask vector, perform component-level gradient clipping on the gradient value of the current model parameter, wherein the following processing is performed on each gradient component: if the corresponding clipping mask vector component is 1, the gradient component remains unchanged; if the corresponding clipping mask vector component is less than 1, the value of the gradient component is multiplied by the corresponding proportional coefficient, and scaled to the clipping threshold boundary to obtain the clipped gradient value; The sensitivity parameters of the current training round are determined according to the privacy budget allocation of each round of training and the clipping threshold, and a random noise vector obeying the Laplace distribution is generated using the sensitivity parameters. The gradient value after noise perturbation is obtained based on the random noise vector and the clipped gradient value. An adaptive learning rate optimization algorithm is used to automatically adjust the learning rate of the current iteration according to historical gradient information, and the current model parameters are updated using the adjusted learning rate and the gradient value after noise perturbation to obtain the model parameters after this iteration. Through multiple iterations, the model parameters obtained in the last iteration are used as the local model parameters of the current training round.
3. The method according to claim 2, characterized in that Determining the sensitivity parameter of the current training round according to the privacy budget allocation of each training round and the clipping threshold, generating a random noise vector obeying the Laplace distribution using the sensitivity parameter, and obtaining the gradient value after noise disturbance based on the random noise vector and the clipped gradient value, including: According to the total number of training rounds of federated learning and the total number of clients, determine the privacy budget available to each client in each round of local training, and evenly distribute the privacy budget of each round to each training iteration step; obtain the privacy budget of the current training round, and calculate the sensitivity parameter of the current training round according to the privacy budget and a preset gradient clipping threshold, wherein the sensitivity parameter is inversely proportional to the privacy budget and proportional to the clipping threshold; The probability density function of the Laplace distribution is constructed using the sensitivity parameter, and the reciprocal of the sensitivity parameter is used as the scale parameter of the Laplace distribution; according to the number of components of the gradient vector after gradient clipping, a random noise vector having the same number of components as the gradient vector is randomly sampled from the constructed Laplace distribution; wherein the random sampling process uses the inverse transformation method of the Laplace distribution to randomly sample a probability value from a uniform distribution, and uses the probability value as the value of the cumulative distribution function based on the Laplace distribution, so as to obtain an equation with a random noise variable as an unknown; Solve the equation with the random noise variable as the unknown variable to obtain the random noise variable as a random noise sample, and obtain a random noise vector that obeys the Laplace distribution through multiple random samplings; add the clipped gradient value and the random noise vector component by component, add the gradient component at the corresponding position in the clipped gradient value to the random noise component, and obtain a gradient vector with Laplace noise added, and use the gradient vector with Laplace noise added as the gradient value after noise disturbance.
4. The method according to claim 1, characterized in that Based on the local model parameters collected from each client, secret sharing technology and homomorphic encryption technology are used to obtain global model parameters through privacy-preserving parameter aggregation, including: The server generates random polynomial coefficients for a secret sharing scheme and a public-private key pair for homomorphic encryption, and sends the random polynomial coefficients and the public key to each client; each client participating in the aggregation uses the random polynomial coefficients to divide each component of its local model parameter vector into a number of secret shares equal to the total number of clients, and sets the local model parameter component to the random polynomial coefficient; The client generates a random mask for each local model parameter component using the public key sent by the server, and encrypts the random mask with the public key to obtain a ciphertext mask; adds each secret share to the corresponding ciphertext mask to obtain a masked secret share; sends the masked secret share of each local model parameter component to the corresponding client; and sends the ciphertext mask and the encrypted negative mask to the server at the same time; The server collects the masked secret shares sent by each client, sums the masked secret share values at the same coordinate point, and uses Lagrange interpolation to obtain the aggregated secret share under homomorphic mask; then adds the ciphertext masks collected from each client, and uses the homomorphic property to obtain the aggregated homomorphic mask; the server adds the aggregated secret share under the homomorphic mask and the aggregated homomorphic mask, decrypts it using the private key, and sums the decrypted result with the negative mask collected from each client, and finally obtains the unmasked aggregated model parameters as the global model parameters.
5. The method according to claim 1, characterized in that For the privacy attribute feature vector corresponding to the identified sensitive information, a multi-objective optimization model including privacy protection strength, data utility loss and computational overhead is constructed, including: The parameter configuration of various privacy protection mechanisms is used as the decision variables of the multi-objective optimization model, and the decision variables include the type and degree of data transformation, the selection of encryption algorithm and key length, and the probability distribution function of data scrambling; the privacy protection strength objective function is constructed, in which the mutual information between the original data distribution and the data distribution after privacy protection is calculated by using the privacy measurement method based on mutual information. The smaller the mutual information, the higher the privacy protection strength. The negative value of the mutual information is used as the objective function to maximize the privacy protection strength; Construct a data utility loss objective function, in which a similarity measurement method based on attribute normalization is used to calculate the normalized Euclidean distance between the original data record and the privacy-protected data record on each attribute, and the weighted average of the distances of each attribute is used as the data utility loss. The larger the distance, the greater the availability loss. Minimizing the utility loss is used as the objective function; construct a computational cost objective function, in which the time complexity and space complexity of the key operations of the privacy protection mechanism are analyzed to obtain the functional relationship between the computational cost and the mechanism parameters, and the objective function of minimizing the computational cost is constructed based on the functional relationship; The privacy protection requirements of the current data processing task are formalized as numerical requirements for the privacy protection strength, and the lower bound constraints of the privacy protection strength objective function are constructed. Based on the currently available computing resources, quantitative restrictions are imposed on the time and storage overheads of the privacy protection mechanism, and the upper bound constraints of the computational overhead objective function are constructed. According to the privacy protection strength objective function, the data utility loss objective function, the computational overhead objective function, as well as the upper and lower bound constraints, a multi-objective optimization model is constructed.
6. The method according to claim 1, characterized in that When receiving a pending opinion posted by a target user, obtaining the target opinion after privacy protection based on the privacy protection policy includes: Performing natural language processing on the opinions to be processed, extracting key information therein, and identifying private data in the key information, wherein the private data includes user name, address, telephone number, and email address; desensitizing the private data according to the privacy protection policy to obtain a desensitized opinion text; wherein, according to the desensitization method and desensitization intensity parameter set by the privacy protection policy, performing semantic replacement on the private data, using a generalized and pseudonymized data transformation method, replacing the private data with an equivalent expression that has similar semantics but cannot directly identify the individual's identity; According to the privacy protection strategy, the privacy data and its fragments are summarized, and the natural language generation technology is used to rewrite the fragment description while keeping the semantics unchanged; for the privacy data defined as high-risk by the privacy protection strategy, the deletion method is used for desensitization; the differential privacy technology is used to add random noise to the desensitized opinion text to obtain the target opinion after privacy protection; in the target opinion after privacy protection, part-of-speech tagging and dependency syntactic analysis are used to extract the polarity characteristics of the target opinion after privacy protection; the latent semantic analysis technology is used to perform topic clustering on the target opinion after privacy protection and extract topic features; based on the sentiment dictionary, the sentiment score weighted average method is used to calculate the sentiment intensity value of the target opinion after privacy protection in each sentiment dimension, and construct the sentiment tendency feature; Based on the combination of polarity features, topic features, and sentiment tendency features, a user opinion feature vector is constructed; an opinion feature vector library is constructed based on local user opinion historical data; a similarity list is obtained based on the similarity between the user opinion feature vector and each historical opinion feature vector in the opinion feature vector library; the credibility of the target opinion after privacy protection is evaluated based on the similarity list; and the target opinion after privacy protection whose credibility is higher than a preset threshold is retained.
7. A user opinion privacy protection system based on federated learning and privacy differential, used to implement the method described in any one of claims 1 to 6, characterized in that: include: The first unit is configured to receive, at a server side, a federated learning participation request from at least two clients, wherein the federated learning participation request carries identification information and device performance parameters of each of the clients; and for each of the clients, based on the identification information, divide a preset user opinion data set into corresponding sub-data sets; Determining the number of local training rounds and the number of iterations per round for each client according to the device performance parameters of each client; Send the sub-dataset, the number of local training rounds and the number of iterations per round to the corresponding client; A second unit is used to obtain corresponding local model parameters through multiple rounds of local training using a differential privacy machine learning algorithm on each client according to the received sub-data set, where each round of local training includes multiple iterations, and in each iteration, the local model parameters are perturbed using Laplace noise; Sending the local model parameters obtained through training to the server; The third unit is used to obtain global model parameters by a privacy-preserving parameter aggregation method based on the local model parameters collected from each client on the server side using secret sharing technology and homomorphic encryption technology; update the preset federated learning model using the global model parameters to obtain a privacy protection strategy; send the privacy protection strategy to each client; receive the privacy protection strategy sent by the server on each client, and when receiving the pending opinion issued by the target user, obtain the target opinion after privacy protection based on the privacy protection strategy; The privacy-protected target opinions are sent to the server for business analysis and mining processing.
8. An electronic device, characterized in that: include: processor; a memory for storing processor-executable instructions; The processor is configured to call the instructions stored in the memory to execute the method according to any one of claims 1 to 6.
9. A computer-readable storage medium having computer program instructions stored thereon, characterized in that: When the computer program instructions are executed by a processor, the method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Federated learning differential privacy protection method for adding noise based on Rayleigh divergence
CN113127931A
Dynamic evaluation method and system for information sensitivity of smart power grid
CN114036570A
Data security aggregation method and system based on multi-homomorphic attributes
CN116933899A