Artificial Intelligence-Based Medical Data Privacy Protection Method and System
By conducting feature analysis and risk assessment of medical data, dividing security domains and using federated learning and deep neural network models for encryption and verification, the shortcomings of medical data privacy protection in the existing technology are solved, and efficient privacy protection and data utilization are achieved.
Patent Information
- Application Number
- CN202510135255.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-07
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-02-07
AI Technical Summary
Existing medical data privacy protection methods are difficult to refinely evaluate the sensitivity and privacy risks of different types of medical data, and it is difficult to balance privacy protection and data utility in data sharing and model training. It lacks flexible protection mechanisms and adaptive adjustment capabilities, making it difficult to deal with complex and changeable privacy threats.
Using artificial intelligence-based methods, medical data is characterized and risk assessment, multiple security domains are divided and distributed collaboration mechanisms are established, data processing and model training are carried out between security domains through federated learning, deep neural network models and dynamic key matrices are used for encryption and verification, dynamically adjusting the data access granularity and triggering corresponding protection rules.
It improves the security and privacy protection level of medical data, realizes physical isolation and logical collaboration of data, enhances refined control of data access behavior, and effectively prevents the risks of data leakage and abuse.
Smart Images

Figure CN119577841B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to artificial intelligence technology, and in particular to a medical data privacy protection method and system based on artificial intelligence. Background Art
[0002] Existing medical data privacy protection methods have some deficiencies. First, there is a lack of a refined evaluation mechanism for the sensitivity and privacy risks of medical data, making it difficult to formulate differentiated protection strategies for different types of medical data. Second, in the process of data sharing and model training, it is difficult to achieve a good balance between protecting privacy and ensuring data utility, which often affects the accuracy and usability of the model. Finally, existing methods lack flexible protection mechanisms and adaptive adjustment capabilities when dealing with dynamic access behaviors and potential privacy attacks, and it is difficult to effectively cope with complex and changeable privacy threats. Summary of the Invention
[0003] Embodiments of the present invention provide a medical data privacy protection method and system based on artificial intelligence, which can solve the problems in the prior art.
[0004] In the first aspect of the embodiments of the present invention,
[0005] A medical data privacy protection method based on artificial intelligence is provided, including:
[0006] Performing feature analysis on the medical data to be processed to obtain sensitive information, where the sensitive information includes patient basic information, clinical diagnosis information, medical image information, and medical test information; establishing a scoring matrix based on the sensitive information, generating a privacy risk assessment result according to the scoring matrix in combination with historical data leakage records, dividing the medical data into multiple security domains according to the privacy risk assessment result, establishing local data storage nodes in each security domain, and establishing a distributed cooperation mechanism between security domains in a federated learning manner;
[0007] Preprocessing the local medical data at the local data storage node to obtain training samples, constructing a deep neural network model, converting the feature information of the training samples into a vector space and constructing a dynamic key matrix, encrypting the gradient information generated during the training process in blocks based on the dynamic key matrix, performing distributed aggregation operations and integrity verification on the encrypted gradient information using a multi-party secure computing protocol, updating the parameters of the deep neural network model at the federated learning central node and synchronizing them to the local data storage node after passing the verification until a preset convergence condition is reached; forming a medical data privacy protection plan including data access rules, data masking rules, and data transfer rules based on the trained deep neural network model;
[0008] Authenticate the access request according to the user role permissions and match the permissions, perform anomaly detection on the authenticated access request from the aspects of access time characteristics, access behavior characteristics and access content characteristics. When it is detected that the access behavior deviates from the normal behavior baseline, calculate the anomaly degree score, dynamically adjust the data access granularity according to the anomaly degree score, and trigger the corresponding protection rules in the medical data privacy protection scheme.
[0009] In an alternative embodiment,
[0010] The steps of establishing a scoring matrix based on the sensitive information, generating a privacy risk assessment result according to the scoring matrix combined with the historical data leakage records, dividing the medical data into multiple security domains according to the privacy risk assessment result, establishing local data storage nodes in each security domain, and adopting a federated learning method to establish a distributed cooperation mechanism between security domains include:
[0011] Perform multi-dimensional scoring on the sensitive information. The multi-dimensional scoring includes the sensitivity scoring based on information entropy, the integrity scoring based on the non-empty attribute ratio, the data association degree scoring based on association rules, and the timeliness scoring based on the time decay function. Construct a scoring matrix according to the multi-dimensional scoring; calculate the feature similarity between the sensitive information and the historical data leakage records, and perform weighted fusion of the feature similarity and the scoring matrix to obtain the risk assessment result;
[0012] Set multiple layers of risk thresholds based on the risk assessment result, calculate the security distance between sensitive information. The security distance is composed of the Hamming distance of the risk difference degree and the data association degree. Use the hierarchical clustering method to divide the data with a security distance greater than the corresponding risk threshold into different security domains, and calculate the minimum security distance between the new sensitive information and the existing security domains to determine its domain belonging;
[0013] Respectively establish local data storage nodes in the divided security domains, generate an asymmetric encryption key pair for each local data storage node and establish a secure communication channel, define the communication primitives between security domains including data sending, receiving and verification, and transmit encrypted data between security domains using a homomorphic encryption-based data exchange format; adopt the practical Byzantine fault tolerance algorithm to perform consistency consensus on cross-security domain data exchange, use the threshold signature scheme to verify data integrity, optimize the cross-domain data query efficiency through the Bloom filter index, and construct a federated learning distributed cooperation mechanism between security domains.
[0014] In an alternative embodiment,
[0015] Preprocessing local medical data at the local data storage node to obtain training samples, constructing a deep neural network model, converting the feature information of the training samples into a vector space and constructing a dynamic key matrix, block-encrypting the gradient information generated during the training process based on the dynamic key matrix, and performing distributed aggregation operations and integrity verification on the encrypted gradient information using a multi-party secure computing protocol. After passing the verification, updating the parameters of the deep neural network model at the federated learning central node and synchronizing them to the local data storage node until the preset convergence condition is reached, the steps include:
[0016] Using a multiple chained equation to iteratively predict and fill missing values in local medical data, detecting and processing outliers in combination with the interquartile range method, and performing standardization transformation on the processed features to obtain training samples; constructing a deep neural network model, the deep neural network model includes a feature-level attention mechanism and a sample-level attention mechanism, and uses a composite loss function for training and an adaptive weight adjustment strategy;
[0017] Mapping discrete features in the training samples to continuous vectors through a hierarchical word vector method and a subword encoding method, performing feature dimensionality reduction based on locality-sensitive hashing to construct a multi-table hash index, and dynamically adjusting the number of hash tables of the multi-table hash index by setting a failure probability threshold and a recall rate parameter; constructing a Toeplitz matrix based on the session key shared among data nodes, and generating a dynamic key matrix by performing a random orthogonal transformation on the Toeplitz matrix;
[0018] Calculating the gradient information of the training samples on the deep neural network model, determining the optimal block size based on the gradient sparsity and amplitude distribution, encrypting each gradient block using the dynamic key matrix and generating a zero-knowledge proof, and superimposing random noise calibrated based on differential privacy on the encrypted gradient; distributing aggregation permissions using a threshold secret sharing scheme based on the multi-party secure computing protocol, the local data storage node performing weighted local aggregation on the encrypted gradients and calculating partial sums, and reconstructing the global gradient through a secret sharing protocol; performing integrity verification on the global gradient using a Merkle tree, and proving the correctness of the gradient aggregation process of the local data storage nodes participating in the federated learning through a batch verification mechanism;
[0019] Calculating the bias correction value and momentum term of the gradient of the deep neural network model, updating the parameters of the deep neural network model based on the bias correction value and momentum term, and synchronizing the updated parameters of the deep neural network model to each local data storage node. Stop training when the change value of the composite loss function, the gradient norm value, and the parameter change value are all less than the preset threshold.
[0020] In an alternative embodiment,
[0021] Steps for constructing a deep neural network model, where the deep neural network model includes a feature-level attention mechanism and a sample-level attention mechanism, and adopts a composite loss function for training and an adaptive weight adjustment strategy, include:
[0022] Construct a deep neural network model that includes a feature-level attention mechanism and a sample-level attention mechanism, where the feature-level attention mechanism converts the feature matrix of training samples through a linear transformation matrix and calculates feature attention scores to obtain a feature-weighted output, and the sample-level attention mechanism divides the feature-weighted output into multiple attention heads and performs sample relationship encoding to obtain a sample representation, and introduces a residual connection and a feed-forward network to the sample representation to obtain a final output;
[0023] Calculate the feature-level attention loss based on predefined feature importance weights, where the feature-level attention loss includes a logarithmic loss term of feature attention scores and an orthogonal constraint term of the feature attention weight matrix; construct a sample relationship encoding matrix and a graph Laplacian matrix based on clinical similarity to calculate the sample-level relationship consistency loss; calculate the prediction interpretation alignment loss based on the cross-entropy between the prediction output and the true label and the alignment constraint between the input feature gradient contribution and the feature-weighted output; combine the feature-level attention loss, the sample-level relationship consistency loss, and the prediction interpretation alignment loss to obtain a composite loss function;
[0024] Calculate the gradient ratio of each loss term with respect to the parameters of the deep neural network model to obtain a dynamic adjustment factor, and adaptively adjust the weight coefficients in the composite loss function based on the performance metrics on the validation set and the dynamic adjustment factor;
[0025] Train the deep neural network model using the composite loss function, perform gradient clipping during the training process, and normalize the attention weights in the feature-level attention mechanism and the sample-level attention mechanism respectively.
[0026] In an alternative embodiment,
[0027] Steps for calculating the gradient information of the training samples on the deep neural network model, determining the optimal block size based on gradient sparsity and amplitude distribution, encrypting each gradient block using the dynamic key matrix, and generating a zero-knowledge proof, and adding random noise calibrated based on differential privacy to the encrypted gradients, include:
[0028] Calculate the gradient information of the training samples on the deep neural network model, and construct an inter-layer gradient correlation matrix, where the inter-layer gradient correlation matrix is used to characterize the dependence relationship between gradients of different layers, identify the target gradient layer based on the dependence relationship, and prioritize the gradients of the target gradient layer to generate a gradient feature vector;
[0029] Calculate the sparsity index for the gradient feature vector. The sparsity index is obtained by setting a gradient threshold and counting the proportion of gradient elements exceeding the gradient threshold. Calculate the amplitude distribution of the gradient feature vector and obtain the amplitude entropy. The amplitude entropy is used to characterize the uncertainty of the gradient distribution. Calculate the within-block variance of the candidate block partitioning scheme. The within-block variance characterizes the gradient consistency within the block;
[0030] Construct a gradient correlation graph based on the gradient feature vector. The vertices of the gradient correlation graph represent gradient elements, and the edges of the gradient correlation graph represent the correlation strength between gradient elements. Perform community detection on the gradient correlation graph to obtain an initial block partitioning scheme. Calculate the graph cut cost between different blocks, and optimize the initial block partitioning scheme based on the graph cut cost; Based on the optimized initial block partitioning scheme, construct a multi-objective optimization problem with the sparsity index, amplitude entropy, within-block variance, and graph cut cost. Introduce gradient sparsity constraints and block size constraints, and obtain the optimal block size by solving the Pareto optimal solution. Use the gradient descent method to adaptively update the weight coefficients of each objective in the multi-objective optimization problem;
[0031] Partition the parameter gradient based on the optimal block size, apply a dynamic key matrix to encrypt each gradient block and generate a zero-knowledge proof. The zero-knowledge proof includes a gradient commitment, a key commitment, and an encryption proof; Calculate the local sensitivity of the parameter gradient with respect to the adjacent dataset, determine the amplitude of the differential privacy noise based on the local sensitivity, and allocate a differentiated privacy budget for each encrypted gradient block according to the gradient norm. Add the corresponding differential privacy noise to the encrypted gradient block.
[0032] In an alternative embodiment,
[0033] The steps of authenticating the access request according to the user role permissions and matching the permissions, detecting anomalies in the verified access request from the access time features, access behavior features, and access content features, calculating the anomaly degree score when detecting that the access behavior deviates from the normal behavior baseline, dynamically adjusting the data access granularity according to the anomaly degree score, and triggering the corresponding protection rules in the medical data privacy protection scheme include:
[0034] Authenticate the access request, verify the matching relationship between the user identifier and the target permission based on the role permission mapping matrix, and generate an access token containing the user identifier, timestamp, and digital signature after successful verification;
[0035] Extract the original features based on the access token, construct multi-dimensional features including an access time feature vector, an access behavior feature vector, and an access content feature vector, perform logarithmic transformation on the time interval and access duration in the access time feature vector, perform min-max normalization on the access behavior feature vector, and perform mean normalization and variance standardization on the access content feature vector; use an adaptive weight matrix to fuse the multi-dimensional features, calculate the correlation weight coefficient through feature correlation, perform weighted combination on the multi-dimensional features based on the correlation weight coefficient to obtain the fused features, input the fused features into a Gaussian mixture model for training, use the weighted combination of multiple Gaussian distributions to fit the feature distribution of normal access behaviors, and obtain the normal behavior baseline based on the trained Gaussian mixture model;
[0036] Calculate anomaly feature metrics including log-likelihood probability, minimum Mahalanobis distance, and temporal correlation metric for the new access request features, construct an optimization problem with regularization constraints, use the alternating direction method of multipliers to solve the fusion weight coefficients of each anomaly feature metric, and weight the anomaly feature metrics with the corresponding fusion weight coefficients to obtain the anomaly degree score; map the access request to one of the access control levels of full access, desensitized access, summary access, and denied access according to the anomaly degree score, and trigger the corresponding protection rules in the medical data privacy protection scheme.
[0037] In an alternative embodiment,
[0038] The steps of calculating anomaly feature metrics including log-likelihood probability, minimum Mahalanobis distance, and temporal correlation metric for the new access request features, constructing an optimization problem with regularization constraints, using the alternating direction method of multipliers to solve the fusion weight coefficients of each anomaly feature metric, and weighting the anomaly feature metrics with the corresponding fusion weight coefficients to obtain the anomaly degree score include:
[0039] Construct a feature space for the new access request, calculate the log-likelihood probability of the feature space through a hierarchical adaptive probability density estimation method, the probability density estimation method includes constructing multi-layer feature representations to obtain intermediate features, introducing an adaptive weight matrix based on the hyperbolic tangent function at each layer, constructing a hierarchical probability density distribution, and introducing a dynamic temperature coefficient based on the spatio-temporal distance of access behaviors to adjust the probability density to obtain the log-likelihood probability; calculate the minimum Mahalanobis distance in the feature space, and calculate the temporal correlation metric based on the historical access sequence, and form an anomaly feature metric vector with the log-likelihood probability, minimum Mahalanobis distance, and temporal correlation metric;
[0040] Construct the fusion weight coefficients of each abnormal feature metric by solving a multi-objective constrained optimization problem. The multi-objective constrained optimization problem includes introducing a feature correlation regularization term based on mutual information and a temporal stability constraint term based on time intervals, adaptively adjusting the regularization coefficient using a dynamic parameter update mechanism, and solving it based on an improved alternating direction method of multipliers. The improved alternating direction method of multipliers determines the dynamic step size of the penalty factor based on the difference between the fusion weight coefficients of two adjacent iterations, performs non-negativity and normalization constraint processing on the auxiliary variables during the solution process using a projection algorithm, and performs iterative optimization using a dual variable update strategy that matches the dynamic step size of the penalty factor. The optimal fusion weight coefficients are obtained when the difference between the fusion weight coefficients of two adjacent iterations is less than a preset allowable range and the dual residual is less than a predetermined convergence parameter;
[0041] Weight the abnormal feature metric with the optimal fusion weight coefficient to obtain an initial abnormal degree score, dynamically adjust the initial abnormal degree score using an adaptive correction mechanism based on mean deviation and spatio-temporal distance, and normalize the corrected initial abnormal degree score using a time-varying adjustment factor to obtain the final abnormal degree score.
[0042] In the second aspect of the embodiments of the present invention,
[0043] Provide a medical data privacy protection system based on artificial intelligence, including:
[0044] A first unit for performing feature analysis on the medical data to be processed to obtain sensitive information. The sensitive information includes patient basic information, clinical diagnosis information, medical image information, and medical test information. Establish a scoring matrix based on the sensitive information, generate a privacy risk assessment result in combination with historical data leakage records according to the scoring matrix, divide the medical data into multiple security domains according to the privacy risk assessment result, establish local data storage nodes in each security domain, and establish a distributed cooperation mechanism between security domains using federated learning;
[0045] A second unit for preprocessing the local medical data in the local data storage node to obtain training samples, constructing a deep neural network model, converting the feature information of the training samples into a vector space and constructing a dynamic key matrix, encrypting the gradient information generated during the training process in blocks based on the dynamic key matrix, performing distributed aggregation operations and integrity verification on the encrypted gradient information using a multi-party secure computing protocol, and updating the parameters of the deep neural network model at the federated learning center node and synchronizing them to the local data storage node after passing the verification until a preset convergence condition is reached; forming a medical data privacy protection plan including data access rules, data desensitization rules, and data transfer rules based on the trained deep neural network model;
[0046] A third unit is used to authenticate access requests and match permissions according to user role permissions, detect anomalies in the authenticated access requests from the aspects of access time characteristics, access behavior characteristics, and access content characteristics. When it is detected that the access behavior deviates from the normal behavior baseline, calculate the anomaly degree score, dynamically adjust the data access granularity according to the anomaly degree score, and trigger the corresponding protection rules in the medical data privacy protection scheme. In the third aspect of the embodiments of the present invention,
[0047] Provided is an electronic device, including:
[0048] A processor;
[0049] A memory for storing instructions executable by the processor;
[0050] Wherein, the processor is configured to call the instructions stored in the memory to execute the method described above.
[0051] In the fourth aspect of the embodiments of the present invention,
[0052] Provided is a computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the method described above is implemented.
[0053] Through feature analysis and risk assessment of medical data, the present invention divides the data into multiple security domains and establishes a distributed cooperation mechanism, effectively improving the data security and privacy protection level. At the same time, the federated learning method is adopted to avoid the direct sharing of raw data, further reducing the risk of data leakage.
[0054] The present invention uses a deep neural network model combined with a dynamic key matrix to encrypt the gradient information during the training process, and uses a multi-party secure computing protocol for distributed aggregation and verification, ensuring the security and reliability of model training. Based on the trained model, a comprehensive data privacy protection scheme is formulated, providing a strong guarantee for subsequent data access and use.
[0055] The present invention performs authentication and anomaly detection according to user permissions, and dynamically adjusts the data access granularity based on the anomaly degree, realizing refined control of data access behavior. At the same time, the corresponding protection rules are triggered, further enhancing the privacy protection ability of medical data and effectively preventing various risks of data leakage and abuse. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] Figure 1 It is a schematic flowchart of the method for protecting medical data privacy based on artificial intelligence according to the embodiments of the present invention;
[0057] Figure 2 It is a schematic structural diagram of the system for protecting medical data privacy based on artificial intelligence according to the embodiments of the present invention;
[0058] Figure 3 This is the flowchart of the medical data privacy protection system based on artificial intelligence according to the embodiments of the present invention;
[0059] Figure 4 This is the architecture diagram of the medical data privacy protection system based on artificial intelligence according to the embodiments of the present invention;
[0060] Figure 5 This is the data processing flowchart of the medical data privacy protection method based on artificial intelligence according to the embodiments of the present invention;
[0061] Figure 6 This is the algorithm flowchart of the medical data privacy protection method based on artificial intelligence according to the embodiments of the present invention. Detailed implementation manners
[0062] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are only a part rather than all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0063] The technical solutions of the present invention will be described in detail below with specific embodiments. These specific embodiments may be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.
[0064] Refer to Figures 1-6 , and describe the technical solutions of the medical data privacy protection method and system based on artificial intelligence of the present application:
[0065] S1. Perform feature analysis on the medical data to be processed to obtain sensitive information, where the sensitive information includes patient basic information, clinical diagnosis information, medical imaging information, and medical test information. Establish a scoring matrix based on the sensitive information, generate a privacy risk assessment result according to the scoring matrix in combination with historical data leakage records, divide the medical data into multiple security domains according to the privacy risk assessment result, establish local data storage nodes in each security domain, and establish a distributed cooperation mechanism between security domains in a federated learning manner;
[0066] S2. Preprocess the local medical data at the local data storage node to obtain training samples, construct a deep neural network model, convert the feature information of the training samples into a vector space and construct a dynamic key matrix, perform block encryption on the gradient information generated during the training process based on the dynamic key matrix, and use a multi-party secure computing protocol to perform distributed aggregation operations and integrity verification on the encrypted gradient information. After passing the verification, update the parameters of the deep neural network model at the federated learning central node and synchronize them to the local data storage node until the preset convergence condition is reached; form a medical data privacy protection plan including data access rules, data desensitization rules, and data transfer rules based on the trained deep neural network model;
[0067] S3. Authenticate the access request and match the permissions according to the user role permissions, perform anomaly detection on the access request that passes the verification from the aspects of access time characteristics, access behavior characteristics, and access content characteristics. When it is detected that the access behavior deviates from the normal behavior baseline, calculate the anomaly degree score, dynamically adjust the data access granularity according to the anomaly degree score, and trigger the corresponding protection rules in the medical data privacy protection plan.
[0068] In an alternative implementation manner,
[0069] The steps of establishing a scoring matrix based on the sensitive information, generating a privacy risk assessment result according to the scoring matrix combined with the historical data leakage records, dividing the medical data into multiple security domains according to the privacy risk assessment result, establishing local data storage nodes in each security domain, and adopting a federated learning method to establish a distributed cooperation mechanism between security domains include:
[0070] Perform multi-dimensional scoring on the sensitive information. The multi-dimensional scoring includes sensitivity scoring based on information entropy, integrity scoring based on the non-empty attribute ratio, data association degree scoring based on association rules, and timeliness scoring based on the time decay function. Construct a scoring matrix according to the multi-dimensional scoring; calculate the feature similarity between the sensitive information and the historical data leakage records, and perform weighted fusion of the feature similarity and the scoring matrix to obtain a risk assessment result;
[0071] Set multi-level risk thresholds based on the risk assessment result, calculate the security distance between sensitive information. The security distance is composed of the weighted Hamming distance of the risk difference degree and the data association degree. Use the hierarchical clustering method to divide the data with a security distance greater than the corresponding risk threshold into different security domains, and calculate the minimum security distance between the newly added sensitive information and the existing security domains to determine its domain belonging;
[0072] Local data storage nodes are established respectively in the divided security domains, an asymmetric encryption key pair is generated for each local data storage node, and a secure communication channel is established. Communication primitives between security domains including data sending, receiving, and verification are defined, and encrypted data is transmitted between security domains using a data exchange format based on homomorphic encryption. The practical Byzantine fault tolerance algorithm is used for consensus on cross-security domain data exchange, the threshold signature scheme is used to verify data integrity, the cross-domain data query efficiency is optimized through Bloom filter indexing, and a federated learning distributed collaboration mechanism between security domains is constructed.
[0073] Exemplarily, first, multi-dimensional scoring is performed on sensitive information in medical data to construct a scoring matrix. The multi-dimensional scoring includes sensitivity scoring based on information entropy, integrity scoring based on the proportion of non-empty attributes, data correlation scoring based on association rules, and timeliness scoring based on a time decay function.
[0074] For sensitivity scoring, an information entropy calculation method is adopted. Taking the patient's name as an example, assume there are 1000 records in the dataset, among which 800 records have unique names and 200 records have duplicate names. Calculate the information entropy of the name field, and a higher entropy value is obtained, indicating a higher sensitivity level of this field.
[0075] Integrity scoring is achieved by calculating the proportion of non-empty attributes. For example, among 1000 patient records, there are 950 non-empty records in the age field, so the integrity score of the age field is 0.95.
[0076] Data correlation scoring uses an association rule mining algorithm. For example, it is found through analysis that the patient's diagnosis results are highly correlated with attributes such as age and gender, then the correlation scores of these attributes are higher.
[0077] Timeliness scoring adopts a time decay function. For example, for a medical record from a year ago, its timeliness score may be 0.8, while for a record from five years ago, it may drop to 0.5.
[0078] The scoring results of these four dimensions are combined into a scoring matrix, where each row represents a sensitive information attribute and each column corresponds to a scoring dimension.
[0079] Next, the feature similarity between the sensitive information and the historical data leakage records is calculated. Suppose there is a historical leakage record involving the patient's name, age, and address, and these fields are also included in the current dataset, then calculate the similarity of their feature vectors. The obtained similarity is weighted and fused with the scoring matrix to obtain the final risk assessment result.
[0080] Based on the risk assessment results, set multiple risk thresholds. For example, three risk levels of high, medium, and low can be set, and the corresponding thresholds are 0.8, 0.5, and 0.3 respectively. Then calculate the security distance between sensitive information, which is composed of the Hamming distance of the risk difference degree and the data correlation degree weighted.
[0081] Adopt the hierarchical clustering method to divide the data with a security distance greater than the corresponding risk threshold into different security domains. For example, divide the high-risk patient identity information, medium-risk medical records, and low-risk statistical data into three different security domains respectively. For newly added sensitive information, calculate its minimum security distance from the existing security domains to determine the security domain it belongs to.
[0082] Establish local data storage nodes in the divided security domains respectively. Generate an asymmetric encryption key pair for each node, such as an RSA key pair. Establish a secure communication channel, and the SSL / TLS protocol can be adopted. Define the communication primitives between security domains, including data sending, receiving, and verification operations.
[0083] Adopt homomorphic encryption technology to encrypt the data to ensure calculation and transmission in the encrypted state. For example, using the Paillier homomorphic encryption algorithm, addition operations can be performed without decrypting.
[0084] To ensure the consistency of cross-security domain data exchange, adopt the Practical Byzantine Fault Tolerance (PBFT) algorithm. Assume there are 4 security domain nodes, and at most 1 node is allowed to have a fault or malicious behavior. Consensus on data exchange is reached through multiple rounds of voting.
[0085] Use the threshold signature scheme to verify data integrity. For example, adopt the (3, 4) threshold signature scheme, which requires the signatures of at least 3 security domain nodes to verify the data integrity.
[0086] Optimize the cross-domain data query efficiency through the Bloom filter. Map the data characteristics of each security domain to the Bloom filter, and first check the Bloom filter during query to quickly determine whether the target data may exist in a certain security domain.
[0087] Finally, build a federated learning distributed collaboration mechanism between security domains based on the above mechanism. Each security domain trains the model locally and only exchanges model parameters without directly sharing the original data, so as to achieve collaborative learning while protecting data privacy.
[0088] Through multi-dimensional scoring and analysis of historical data leakage records, the present invention comprehensively evaluates the privacy risks of medical data, improving the accuracy and reliability of risk assessment; adopts security domain partitioning and federated learning methods to achieve physical isolation and logical collaboration of data, while protecting sensitive information, ensuring the full utilization of data value; through multiple security mechanisms such as homomorphic encryption, practical Byzantine fault tolerance algorithm, and threshold signature, constructs a highly secure distributed collaboration environment, effectively preventing the risks of data leakage and tampering.
[0089] In an alternative embodiment,
[0090] The steps of preprocessing local medical data at the local data storage node to obtain training samples, constructing a deep neural network model, converting the feature information of the training samples into a vector space and constructing a dynamic key matrix, block-encrypting the gradient information generated during the training process based on the dynamic key matrix, and performing distributed aggregation operations and integrity verification on the encrypted gradient information using a multi-party secure computing protocol, and after passing the verification, updating the parameters of the deep neural network model at the federated learning central node and synchronizing them to the local data storage node until a preset convergence condition is reached include:
[0091] Using multiple chained equations to iteratively predict and fill missing values in local medical data, detecting and processing outliers in combination with the interquartile range method, and performing standardized transformation on the processed features to obtain training samples; constructing a deep neural network model, the deep neural network model includes a feature-level attention mechanism and a sample-level attention mechanism, and uses a composite loss function for training and an adaptive weight adjustment strategy;
[0092] Mapping discrete features in the training samples to continuous vectors through a hierarchical word vector method and a sub-word encoding method, performing feature dimensionality reduction based on locality-sensitive hashing to construct a multi-table hash index, and dynamically adjusting the number of hash tables of the multi-table hash index by setting a failure probability threshold and a recall rate parameter; constructing a Toeplitz matrix based on a session key shared among data nodes, and generating a dynamic key matrix by randomly orthogonal transforming the Toeplitz matrix;
[0093] Calculate the gradient information of the training samples on the deep neural network model, determine the optimal block size based on the gradient sparsity and amplitude distribution, apply the dynamic key matrix to encrypt each gradient block and generate zero-knowledge proofs, and superimpose random noise calibrated based on differential privacy on the encrypted gradients; distribute and aggregate permissions using a threshold secret sharing scheme based on the multi-party secure computing protocol. The local data storage nodes perform weighted local aggregation on the encrypted gradients and calculate partial sums, and reconstruct the global gradient through the secret sharing protocol; use a Merkle tree to verify the integrity of the global gradient, and prove the correctness of the gradient aggregation process of the local data storage nodes participating in federated learning through a batch verification mechanism;
[0094] Calculate the bias correction value and momentum term of the deep neural network model gradient, update the deep neural network model parameters based on the bias correction value and momentum term, synchronize the updated deep neural network model parameters to each local data storage node, and stop training when the change value of the composite loss function, the gradient norm value, and the parameter change value are all less than the preset threshold.
[0095] Exemplarily, first, preprocess the local medical data. Use multiple chained equations to iteratively predict and fill in the missing values. For example, for the missing values of continuous features such as patient age and blood pressure, a multiple regression model can be established based on other relevant features for prediction. Combine the interquartile range method to detect and process outliers. For example, data points exceeding 1.5 times the interquartile range of the upper and lower quartile intervals are regarded as outliers and replaced with the median. Then perform a standardized transformation on the processed features to normalize features with different dimensions into a unified interval to obtain standardized training samples.
[0096] Next, construct a deep neural network model. This model includes a feature-level attention mechanism and a sample-level attention mechanism. Feature-level attention can adaptively assign importance weights to different features, while sample-level attention can focus on more representative samples. Use a composite loss function for training, such as combining cross-entropy loss and focal loss, and use an adaptive weight adjustment strategy to dynamically balance each part of the loss. For example, the initial weight ratio can be set to 1:1, and then dynamically adjusted according to the change trend of each loss during the training process.
[0097] Vectorize the discrete features in the training samples. Adopt the hierarchical word vector method. For hierarchical categorical features such as diagnostic results, first train word vectors among the major categories and then fine-tune them in the sub-categories. For long-tail features such as drug names, use the sub-word encoding method to split them into smaller semantic units for encoding. Then, construct a multi-table hash index based on locality-sensitive hashing for feature dimensionality reduction, and dynamically adjust the number of hash tables by setting the failure probability threshold (such as 0.01) and the recall rate parameter (such as 0.9). Construct a Toeplitz matrix based on the session key shared among data nodes, and generate a dynamic key matrix by randomly orthogonal transforming this matrix for subsequent gradient encryption.
[0098] Calculate the gradient information of the training samples on the deep neural network model. Determine the optimal block size based on the gradient sparsity and amplitude distribution. For example, the gradients can be sorted by amplitude, and the minimum number of blocks that makes the cumulative sum reach 80% of the total sum is selected as the optimal number of blocks. Apply the dynamic key matrix to encrypt each gradient block and generate a zero-knowledge proof, and superimpose random noise calibrated based on differential privacy on the encrypted gradients. The noise amplitude can be dynamically adjusted according to the preset privacy budget ε through the Laplace mechanism.
[0099] Adopt a multi-party secure computing protocol for distributed gradient aggregation. Distribute the aggregation authority based on the (t, n) threshold secret sharing scheme, where t is the minimum number of shares required to recover the secret and n is the total number of participating parties. The local data storage nodes perform weighted local aggregation on the encrypted gradients and calculate the partial sum, and reconstruct the global gradient through the secret sharing protocol. Use a Merkle tree to verify the integrity of the global gradient, and prove the correctness of the gradient aggregation process of the local data storage nodes participating in federated learning through a batch verification mechanism.
[0100] Finally, calculate the bias correction value and momentum term of the deep neural network model gradient, and update the model parameters based on the corrected gradient. Synchronize the updated model parameters to each local data storage node. Stop training when the change values of the composite loss function, the gradient norm value, and the parameter change value are all less than the preset threshold (such as 0.001). The whole process continuously optimizes the model performance through multiple rounds of iteration.
[0101] The present invention preprocesses medical data through multiple chained equations and the interquartile range method, effectively improving the data quality and usability; adopts a deep neural network model with dual attention mechanisms at the feature level and sample level, significantly enhancing the model's learning ability for key features and important samples, thereby improving the model's prediction accuracy; vectorizes discrete features through hierarchical word vectors and subword encoding methods, and combines local sensitive hashing for feature dimensionality reduction, effectively solving the problem of processing high-dimensional sparse features in medical data; the application of a dynamic key matrix and differential privacy mechanism provides strong privacy protection for gradient information, effectively preventing attacks such as model inversion and membership inference; the introduction of a multi-party secure computing protocol and a batch verification mechanism ensures the security and correctness of the distributed gradient aggregation process, while improving the efficiency of federated learning. The overall solution realizes the collaborative analysis of multi-party medical data while protecting data privacy, providing strong support for big data mining and intelligent diagnosis in the medical field.
[0102] In an alternative embodiment,
[0103] The steps of constructing a deep neural network model, where the deep neural network model includes a feature-level attention mechanism and a sample-level attention mechanism, and adopting a composite loss function for training and an adaptive weight adjustment strategy include:
[0104] Construct a deep neural network model including a feature-level attention mechanism and a sample-level attention mechanism, where the feature-level attention mechanism transforms the feature matrix of training samples through a linear transformation matrix and calculates the feature attention score to obtain a feature-weighted output, and the sample-level attention mechanism divides the feature-weighted output into multiple attention heads and performs sample relationship encoding to obtain a sample representation, and introduces a residual connection and a feed-forward network to the sample representation to obtain a final output;
[0105] Calculate the feature-level attention loss based on predefined feature importance weights, where the feature-level attention loss includes a logarithmic loss term of the feature attention score and an orthogonal constraint term of the feature attention weight matrix; calculate the sample-level relationship consistency loss based on the clinical similarity to construct a sample relationship encoding matrix and a graph Laplacian matrix; calculate the prediction interpretation alignment loss based on the cross-entropy between the prediction output and the true label and the alignment constraint between the input feature gradient contribution and the feature-weighted output; combine the feature-level attention loss, the sample-level relationship consistency loss, and the prediction interpretation alignment loss to obtain a composite loss function;
[0106] Calculate the gradient ratio of each loss term with respect to the parameters of the deep neural network model to obtain a dynamic adjustment factor, and adaptively adjust the weight coefficients in the composite loss function based on the performance metrics on the validation set and the dynamic adjustment factor;
[0107] The deep neural network model is trained using the composite loss function, and gradient clipping is performed during the training process. Additionally, the attention weights in the feature-level attention mechanism and the sample-level attention mechanism are normalized respectively.
[0108] Exemplarily, first, a deep neural network model including a feature-level attention mechanism and a sample-level attention mechanism is constructed. The feature-level attention mechanism transforms the feature matrix of the training samples through a linear transformation matrix and calculates the feature attention scores to obtain the feature-weighted output. Specifically, assume the input feature matrix is X with dimensions (n, d), where n is the number of samples and d is the feature dimension. The dimension of the linear transformation matrix W is (d, d). The transformed feature matrix is obtained through matrix multiplication, and then the feature attention scores α with dimensions (n, d) are calculated through the softmax function. Finally, the element-wise multiplication of α and X is performed to obtain the feature-weighted output Y.
[0109] The sample-level attention mechanism divides the feature-weighted output Y into multiple attention heads and performs sample relationship encoding to obtain the sample representation. Assume it is divided into h attention heads, and the dimension of each head is d / h. For each attention head, the similarity matrix S with dimensions (n, n) between samples is calculated. Then, softmax normalization is performed on S to obtain the sample attention weight matrix A. The matrix multiplication of A and the features of this attention head is performed to obtain the sample representation Z. Finally, the Zs of the h heads are concatenated to obtain the complete sample representation. A residual connection is introduced to the sample representation, that is, it is added to the original input X. Then, a final output F is obtained through a feed-forward neural network.
[0110] Next, a composite loss function is constructed. First, the feature-level attention loss is calculated based on the predefined feature importance weights. This loss consists of two parts: the logarithmic loss term of the feature attention scores α, which is used to make α close to the predefined importance; and the orthogonal constraint term of the feature attention weight matrix W, which is used to enhance the expressive ability of W. Then, based on the clinical similarity, the sample relationship encoding matrix R and the graph Laplacian matrix L are constructed, and the sample-level relationship consistency loss is calculated. This loss measures the consistency between the sample representation Z learned by the model and the predefined sample relationship R. Finally, the prediction interpretation alignment loss is calculated based on the cross-entropy between the prediction output F and the true label y and the alignment constraint between the gradient contribution of the input feature X to F and the feature-weighted output Y. These three losses are weighted and combined to obtain the composite loss function.
[0111] During the training process, an adaptive weight adjustment strategy is adopted. First, the gradient ratios of each loss term with respect to the model parameters are calculated to obtain a dynamic adjustment factor. Specifically, the L2 norm of the gradients of each loss term with respect to all model parameters is calculated, and then the ratios between them are calculated. Based on the performance metrics (such as accuracy, F1 score, etc.) on the validation set and the dynamic adjustment factor, the weight coefficients of each loss term in the composite loss function are adaptively adjusted. For example, the validation set performance can be used as a reward signal, and a reinforcement learning algorithm can be used to update the weight coefficients in combination with the dynamic adjustment factor.
[0112] Finally, the constructed composite loss function is used to train the deep neural network model. Gradient clipping is performed during each parameter update to limit the L2 norm of the gradients within a preset threshold to prevent gradient explosion. At the same time, the attention weight matrix W in the feature-level attention mechanism and the attention weight matrix A in the sample-level attention mechanism are respectively normalized. For W, L2 normalization can be adopted, that is, each column vector is divided by its L2 norm. For A, row normalization is performed after softmax to ensure that the sum of the attention weights of each sample to other samples is 1.
[0113] Through the above steps, a deep neural network model with both feature-level and sample-level dual attention mechanisms, trained using a composite loss function, and having the ability of adaptive weight adjustment can be obtained.
[0114] By introducing the feature-level and sample-level dual attention mechanisms, the present invention improves the model's ability to capture important features and sample relationships, thereby enhancing the model's expressive ability and generalization performance; the sample-level attention mechanism can capture the complex relationships between samples, which is beneficial for processing datasets with internal structures, such as patient similarity in medical diagnosis; adopting the composite loss function training strategy, combining the feature-level attention loss, sample-level relationship consistency loss, and prediction interpretation alignment loss, enables the model to optimize the prediction performance while also maintaining the consistency of the predefined feature importance and sample relationships. This multi-objective optimization method improves the interpretability and credibility of the model, and is particularly suitable for fields that require high interpretability, such as medical diagnosis and financial risk assessment; introducing the adaptive weight adjustment strategy can dynamically balance the importance of different loss terms during the training process, avoiding the bias that may be brought by artificially setting fixed weights, and adjusting the weights by combining the validation set performance and gradient information, enabling the model to better adapt to the characteristics of specific tasks and datasets, and improving the robustness and adaptability of the model.
[0115] In an alternative embodiment,
[0116] The steps of calculating the gradient information of the training sample on the deep neural network model, determining the optimal block size based on the gradient sparsity and amplitude distribution, encrypting each gradient block with the dynamic key matrix and generating a zero-knowledge proof, and superimposing random noise calibrated based on differential privacy on the encrypted gradient include:
[0117] Calculate the gradient information of the training sample on the deep neural network model, and construct an inter-layer gradient correlation matrix, which is used to characterize the dependence relationship between gradients of different layers. Based on the dependence relationship, identify the target gradient layer, and prioritize the gradients of the target gradient layer to generate a gradient feature vector;
[0118] Calculate the sparsity index for the gradient feature vector, which is obtained by setting a gradient threshold and counting the proportion of gradient elements exceeding the gradient threshold. Calculate the amplitude distribution of the gradient feature vector and obtain the amplitude entropy, which is used to characterize the uncertainty of the gradient distribution. Calculate the within-block variance of the candidate block scheme, and the within-block variance characterizes the gradient consistency within the block;
[0119] Construct a gradient correlation graph based on the gradient feature vector, where the vertices of the gradient correlation graph represent gradient elements, and the edges of the gradient correlation graph represent the correlation strength between gradient elements. Perform community discovery on the gradient correlation graph to obtain an initial block scheme, calculate the graph cut cost between different blocks, and optimize the initial block scheme based on the graph cut cost; Based on the optimized initial block scheme, construct a multi-objective optimization problem with the sparsity index, amplitude entropy, within-block variance, and graph cut cost, introduce gradient sparsity constraints and block size constraints, obtain the optimal block size through Pareto optimal solution, and adaptively update the weight coefficients of each objective in the multi-objective optimization problem using the gradient descent method;
[0120] Block the parameter gradient based on the optimal block size, encrypt each gradient block with the dynamic key matrix and generate a zero-knowledge proof, where the zero-knowledge proof includes a gradient commitment, a key commitment, and an encryption proof; Calculate the local sensitivity of the parameter gradient relative to the adjacent dataset, determine the amplitude of the differential privacy noise based on the local sensitivity, and allocate a differentiated privacy budget for each encrypted gradient block according to the gradient norm, and superimpose the corresponding differential privacy noise on the encrypted gradient block.
[0121] Exemplarily, first, calculate the gradient information of the training samples on the deep neural network model and construct an inter-layer gradient correlation matrix. This matrix is used to characterize the dependence relationship between gradients of different layers. For example, for a 5-layer neural network, a 5x5 correlation matrix can be constructed, and each element in the matrix represents the correlation coefficient of the gradients between two layers. Identify the target gradient layer based on this dependence relationship, and prioritize the gradients of the target gradient layer to generate a gradient feature vector. For example, the top 3 layers with the highest correlation coefficients can be selected as the target gradient layers, and they are sorted according to the magnitude of the gradients to obtain a feature vector containing gradient values.
[0122] Next, calculate the sparsity index for the gradient feature vector. Specifically, a gradient threshold, such as 0.01, can be set, and the proportion of gradient elements exceeding this threshold is statistically calculated to obtain the sparsity index. At the same time, calculate the magnitude distribution of the gradient feature vector to obtain the magnitude entropy, which is used to characterize the uncertainty of the gradient distribution. In addition, it is also necessary to calculate the within-block variance of the candidate block partitioning scheme to characterize the gradient consistency within the blocks. For example, the feature vector can be evenly divided into 10 blocks, and the variance of the gradient values within each block is calculated.
[0123] Then, construct a gradient correlation graph based on the gradient feature vector. The vertices of this graph represent gradient elements, and the edges represent the correlation strength between gradient elements. Perform community detection on this graph to obtain an initial block partitioning scheme. Calculate the graph cut cost between different partitions, and optimize the initial scheme based on the graph cut cost. For example, the Louvain algorithm can be used for community detection to obtain 20 initial partitions, and then the sum of the edge weights between the partitions is calculated as the graph cut cost, and adjacent partitions with smaller graph cut costs are merged.
[0124] Based on the optimized initial block partitioning scheme, construct a multi-objective optimization problem with the sparsity index, magnitude entropy, within-block variance, and graph cut cost. Introduce gradient sparsity constraints and block size constraints, and obtain the optimal block size by solving the Pareto optimality. Use the gradient descent method to adaptively update the weight coefficients of each objective in the multi-objective optimization problem. For example, the initial weights can be set to 0.25 each, and then the weights are dynamically adjusted according to the results of each iteration, and finally the optimal number of partitions, such as 15, is obtained.
[0125] Partition the parameter gradients based on the optimal block size, and apply a dynamic key matrix to encrypt each gradient block and generate a zero-knowledge proof. The zero-knowledge proof includes a gradient commitment, a key commitment, and an encryption proof. For example, the Pedersen commitment scheme can be used to generate commitments for the gradients and keys, and a zero-knowledge proof for proving the correctness of the encryption is constructed.
[0126] Finally, calculate the local sensitivity of the parameter gradient with respect to the adjacent dataset, and determine the amplitude of the differential privacy noise based on the local sensitivity. Allocate a differentiated privacy budget for each encrypted gradient block according to the gradient norm, and superimpose the corresponding differential privacy noise on the encrypted gradient block. For example, the Laplace mechanism can be used to generate noise, and the noise amplitude is proportional to the sensitivity and the privacy budget. For blocks with a larger gradient norm, more privacy budget is allocated, so that less noise is added.
[0127] By constructing an inter-layer gradient correlation matrix and a gradient correlation graph, the present invention realizes the effective identification and chunking of important gradient information in a deep neural network, improves the pertinence and efficiency of gradient encryption; adopts a multi-objective optimization method to determine the optimal chunk size, achieving a good balance between protecting privacy and maintaining model performance, ensuring both the encryption intensity and reducing the computational overhead; combines zero-knowledge proof and differential privacy technology, while protecting the gradient privacy, can also verify the correctness of the encryption process, improving the security and credibility of the entire deep learning process.
[0128] In an alternative embodiment,
[0129] The steps of authenticating the access request according to the user role permissions and matching the permissions, detecting anomalies for the access requests that pass the verification from the aspects of access time characteristics, access behavior characteristics and access content characteristics, calculating the anomaly degree score when detecting that the access behavior deviates from the normal behavior baseline, dynamically adjusting the data access granularity according to the anomaly degree score, and triggering the corresponding protection rules in the medical data privacy protection scheme include:
[0130] Authenticate the access request, verify the matching relationship between the user identifier and the target permission based on the role permission mapping matrix, and generate an access token containing the user identifier, timestamp and digital signature after passing the verification;
[0131] Extract the original features based on the access token, construct a multi-dimensional feature including an access time feature vector, an access behavior feature vector and an access content feature vector, perform logarithmic transformation on the time interval and access duration in the access time feature vector, perform min-max normalization on the access behavior feature vector, and perform mean normalization and variance standardization on the access content feature vector; fuse the multi-dimensional features using an adaptive weight matrix, calculate the correlation weight coefficient through feature correlation, perform weighted combination on the multi-dimensional features based on the correlation weight coefficient to obtain a fused feature, input the fused feature into a Gaussian mixture model for training, use the weighted combination of multiple Gaussian distributions to fit the feature distribution of normal access behaviors, and obtain the normal behavior baseline based on the trained Gaussian mixture model;
[0132] Calculate anomaly feature metrics for the new access request feature, including log-likelihood probability, minimum Mahalanobis distance, and temporal correlation metric, construct an optimization problem with regularization constraints, use the alternating direction multiplier method to solve the fusion weight coefficients of each anomaly feature metric, and weight the anomaly feature metric with the corresponding fusion weight coefficient to obtain an anomaly degree score; map the access request to one of the access control levels of full access, desensitized access, summary access, and denied access according to the anomaly degree score, and trigger the corresponding protection rules in the medical data privacy protection scheme.
[0133] Exemplarily, first, authenticate the access request. The system maintains a role permission mapping matrix for storing the permission information corresponding to different user roles. When receiving an access request, the system extracts the user identifier in the request and looks up the corresponding role and permission of the user in the role permission mapping matrix. The system compares the target permission of the request with the actual permission of the user to verify whether they match. If the match is successful, the system generates an access token containing the user identifier, the current timestamp, and a digital signature. The digital signature is encrypted using the private key of the system to ensure the authenticity and integrity of the token.
[0134] For example, assume that a doctor user "Dr. Smith" requests access to a patient's medical record. The system looks up in the role permission mapping matrix that the role of "Dr. Smith" is "attending doctor" and has the permission to "view medical records". The system verifies that the target permission of the request "view medical records" matches the actual permission of the user, so it generates an access token containing the user identifier "Dr. Smith", the timestamp "2023-06-15 10:30:00", and the corresponding digital signature.
[0135] Next, the system extracts the original features based on the access token and constructs a multi-dimensional feature vector. These features include access time features, access behavior features, and access content features.
[0136] The access time features include the time point when the access occurs, the duration, etc. The system performs a logarithmic transformation on the time interval and access duration to reduce the data range and make it closer to a normal distribution.
[0137] The access behavior features include the user's operation sequence, access frequency, etc. The system performs min-max normalization on these features, mapping the values to the interval [0, 1]. For example, if the user's access count in the past hour is 5 times, and the historical maximum is 10 times and the minimum is 0 times, then the normalized feature value is (5 - 0) / (10 - 0) = 0.5.
[0138] The access content features include the type of data accessed, the amount of data, etc. The system performs mean normalization and variance standardization on these features. First, the mean and standard deviation of the features are calculated, and then each feature value is subtracted by the mean and divided by the standard deviation. For example, if the amount of data accessed by a user is 100MB, the historical mean of this feature is 80MB, and the standard deviation is 20MB, then the standardized feature value is (100 - 80) / 20 = 1.
[0139] To fuse multi-dimensional features, the system adopts an adaptive weight matrix. First, the correlation between features is calculated to obtain the associated weight coefficients. Then, based on these coefficients, the multi-dimensional features are weighted and combined to obtain the fused features. For example, if the weights of the time feature, behavior feature, and content feature are 0.3, 0.4, and 0.3 respectively, the fused feature can be represented as the weighted sum of these three feature vectors.
[0140] The system uses a Gaussian mixture model to fit the feature distribution of normal access behaviors. The Gaussian mixture model consists of multiple Gaussian distributions, and each Gaussian distribution represents a typical normal access pattern. The system uses the expectation-maximization algorithm to train the Gaussian mixture model, continuously adjusting the model parameters until convergence. After training is completed, the resulting model is the normal behavior baseline.
[0141] For a new access request, the system calculates multiple anomaly feature metrics. The log-likelihood probability represents the probability that the new sample belongs to the normal behavior model, and the smaller the value, the more likely it is to be an anomaly. The minimum Mahalanobis distance measures the distance from the new sample to the nearest normal behavior cluster, and the larger the distance, the more likely it is to be an anomaly. The temporal correlation metric calculates the similarity between the new sample and historical samples, and the lower the similarity, the more likely it is to be an anomaly.
[0142] The system constructs an optimization problem to solve the fusion weight coefficients of these anomaly feature metrics. The optimization objective is to minimize the weighted sum of the anomaly metrics, while adding a regularization constraint to prevent overfitting. The system uses the alternating direction method of multipliers to solve this optimization problem and obtains the optimal weight coefficients for each anomaly feature metric.
[0143] Multiply the anomaly feature metrics by the corresponding fusion weight coefficients and sum them up to obtain the final anomaly degree score. The system maps the access request to different access control levels according to this score. For example, if the anomaly degree score is less than 0.2, full access is allowed; if the score is between 0.2 and 0.5, desensitized access is implemented; if the score is between 0.5 and 0.8, only summary access is allowed; if the score is greater than 0.8, access is denied.
[0144] Finally, the system triggers the corresponding protection rules in the medical data privacy protection scheme according to the determined access control level. For example, for desensitized access, the system may hide the patient's name and ID number and only display insensitive information such as age and gender. For aggregated access, the system may only return statistical data without showing specific individual records.
[0145] Through multi-dimensional feature analysis and adaptive weight fusion, the present invention improves the accuracy and robustness of anomaly detection. The system can capture complex abnormal access patterns and effectively reduce the false positive rate and false negative rate. By adopting a dynamically adjusted access control strategy, while protecting data privacy, it maximizes data usage efficiency. The system takes corresponding protection measures according to the degree of anomaly, which not only ensures data security but also does not overly restrict normal data access requirements. The present invention has good scalability and adaptability. By continuously learning and updating the normal behavior baseline, the system can adapt to changing access patterns and emerging threats, providing long-term security protection for medical data.
[0146] In an alternative embodiment,
[0147] The steps of calculating anomaly feature metrics including log-likelihood probability, minimum Mahalanobis distance, and temporal correlation metric for the new access request feature, constructing an optimization problem with regularization constraints, solving the fusion weight coefficients of each anomaly feature metric using the alternating direction method of multipliers, and weighting the anomaly feature metric with the corresponding fusion weight coefficient to obtain the anomaly degree score include:
[0148] Construct a feature space for the new access request, calculate the log-likelihood probability of the feature space through a hierarchical adaptive probability density estimation method. The probability density estimation method includes constructing multi-layer feature representations to obtain intermediate features, introducing an adaptive weight matrix based on the hyperbolic tangent function at each layer, constructing a hierarchical probability density distribution, and introducing a dynamic temperature coefficient based on the spatio-temporal distance of access behavior to adjust the probability density to obtain the log-likelihood probability; calculate the minimum Mahalanobis distance in the feature space, and calculate the temporal correlation metric based on the historical access sequence, and form an anomaly feature metric vector with the log-likelihood probability, minimum Mahalanobis distance, and temporal correlation metric;
[0149] Construct the fusion weight coefficients for solving each abnormal feature metric of the multi-objective constrained optimization problem. The multi-objective constrained optimization problem includes introducing a feature correlation regularization term based on mutual information and a temporal stability constraint term based on time interval, adaptively adjusting the regularization coefficient using a dynamic parameter update mechanism, and solving based on the improved alternating direction method of multipliers. The improved alternating direction method of multipliers determines the dynamic step size of the penalty factor through the difference in the fusion weight coefficients between two adjacent iterations, performs non-negativity and normalization constraint processing on the auxiliary variables during the solution process using a projection algorithm, and performs iterative optimization using a dual variable update strategy that matches the dynamic step size of the penalty factor. When the difference in the fusion weight coefficients between two adjacent iterations is less than the preset allowable range and the dual residual is less than the predetermined convergence parameter, the optimal fusion weight coefficients are obtained;
[0150] Weight the abnormal feature metric with the optimal fusion weight coefficient to obtain the initial abnormal degree score, dynamically adjust the initial abnormal degree score using an adaptive correction mechanism based on mean deviation and spatio-temporal distance, and normalize the corrected initial abnormal degree score using a time-varying adjustment factor to obtain the final abnormal degree score.
[0151] Exemplarily, first, construct a feature space for the new access request. Calculate the log-likelihood probability of the feature space through a hierarchical adaptive probability density estimation method. This method includes constructing multi-layer feature representations to obtain intermediate features, and introducing an adaptive weight matrix based on the hyperbolic tangent function at each layer. Specifically, a three-layer structure can be adopted. The first layer inputs the original features, and the second and third layers respectively extract intermediate features. The weight matrix of each layer is adaptively adjusted through the hyperbolic tangent function. For example, the weight can be expressed as tanh(w), where w is a learnable parameter. Construct a hierarchical probability density distribution, and introduce a dynamic temperature coefficient based on the spatio-temporal distance of access behavior to adjust the probability density. For example, the temperature coefficient can be set as T = 1 / (1 + d), where d is the average spatio-temporal distance between the current access and historical accesses. Finally, obtain the log-likelihood probability.
[0152] Next, calculate the minimum Mahalanobis distance in the feature space. The Mahalanobis distance between the feature vector and the historical data center can be calculated using the covariance matrix, and the minimum value is selected as the abnormal metric. At the same time, calculate the temporal correlation metric based on the historical access sequence. The similarity between the current access sequence and the historical normal sequence can be calculated using the dynamic time warping algorithm, and the reciprocal of the similarity is used as the temporal correlation metric. The log-likelihood probability, minimum Mahalanobis distance, and temporal correlation metric form an abnormal feature metric vector.
[0153] Then, a multi-objective constrained optimization problem is constructed to solve the fusion weight coefficients of each abnormal feature metric. This optimization problem includes introducing a feature correlation regularization term based on mutual information and a temporal stability constraint term based on time intervals. For the feature correlation regularization term, the mutual information between features can be calculated and added as a regularization term to the objective function. The temporal stability constraint term can be constructed by calculating the difference in weight coefficients within adjacent time windows. A dynamic parameter update mechanism is used to adaptively adjust the regularization coefficient. For example, the regularization coefficient can be dynamically adjusted according to the number of iterations. The optimization problem is solved based on the improved alternating direction method of multipliers. This method determines the dynamic step size of the penalty factor based on the difference in fusion weight coefficients between two adjacent iterations. The projection algorithm is used to perform non-negativity and normalization constraint processing on the auxiliary variables during the solution process to ensure that the weight coefficients are non-negative and sum to 1. An iterative optimization is performed using a dual variable update strategy that matches the dynamic step size of the penalty factor. The optimal fusion weight coefficients are obtained when the difference in fusion weight coefficients between two adjacent iterations is less than a preset tolerance range (such as 0.001) and the dual residual is less than a predetermined convergence parameter.
[0154] Finally, the abnormal feature metrics are weighted with the optimal fusion weight coefficients to obtain the initial abnormal degree score. An adaptive correction mechanism based on mean deviation and spatio-temporal distance is used to dynamically adjust the initial abnormal degree score. Specifically, the deviation between the current score and the mean of historical scores can be calculated and weighted correction is performed in combination with the spatio-temporal distance. The corrected initial abnormal degree score is normalized by a time-varying adjustment factor to obtain the final abnormal degree score. The time-varying adjustment factor can be dynamically adjusted according to the system running time.
[0155] Through multi-layer feature representation and an adaptive weight matrix, the present invention improves the modeling ability for complex access patterns, enhances the accuracy and robustness of anomaly detection, introduces a dynamic temperature coefficient based on the spatio-temporal distance of access behavior, makes the probability density estimation more flexible, and can better adapt to the access behavior characteristics in different scenarios; solving the fusion weight coefficients by using a multi-objective constrained optimization problem comprehensively considers feature correlation and temporal stability, improves the interpretability and stability of the anomaly detection results, and the improved alternating direction method of multipliers speeds up the convergence rate of the optimization problem and improves the efficiency of the algorithm through the dynamic step size and the matching dual variable update strategy; the adaptive correction mechanism based on mean deviation and spatio-temporal distance, combined with the time-varying adjustment factor, realizes the dynamic adjustment and normalization processing of the abnormal degree score, enhances the method's ability to identify abnormal behaviors in different spatio-temporal backgrounds, and improves the adaptability and comparability of the detection results.
[0156] Figure 2 FIG. is a schematic structural diagram of a medical data privacy protection system based on artificial intelligence according to an embodiment of the present invention, as Figure 2 shown, the system includes:
[0157] The first unit is used to perform feature analysis on medical data to be processed to obtain sensitive information, where the sensitive information includes patient basic information, clinical diagnosis information, medical imaging information, and medical test information. A scoring matrix is established based on the sensitive information, and a privacy risk assessment result is generated by combining the scoring matrix with historical data leakage records. The medical data is divided into multiple security domains according to the privacy risk assessment result, local data storage nodes are established in each security domain, and a distributed collaboration mechanism is established between security domains in a federated learning manner;
[0158] The second unit is used to preprocess local medical data at the local data storage node to obtain training samples, construct a deep neural network model, convert the feature information of the training samples into a vector space and construct a dynamic key matrix, perform block encryption on the gradient information generated during the training process based on the dynamic key matrix, perform distributed aggregation operations and integrity verification on the encrypted gradient information using a multi-party secure computing protocol, update the parameters of the deep neural network model at the federated learning central node and synchronize them to the local data storage node after passing the verification until a preset convergence condition is reached; A medical data privacy protection solution including data access rules, data desensitization rules, and data transfer rules is formed based on the trained deep neural network model;
[0159] The third unit is used to perform identity authentication and permission matching on access requests according to user role permissions, perform anomaly detection on the access requests that pass the verification from the aspects of access time characteristics, access behavior characteristics, and access content characteristics. When it is detected that the access behavior deviates from the normal behavior baseline, calculate the anomaly degree score, dynamically adjust the data access granularity according to the anomaly degree score, and trigger the corresponding protection rules in the medical data privacy protection solution.
[0160] In the third aspect of the embodiments of the present invention,
[0161] There is provided an electronic device, including:
[0162] A processor;
[0163] A memory for storing instructions executable by the processor;
[0164] Wherein, the processor is configured to call the instructions stored in the memory to execute the method described above.
[0165] In the fourth aspect of the embodiments of the present invention,
[0166] There is provided a computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the method described above is implemented.
[0167] The present invention may be a method, an apparatus, a system, and / or a computer program product. The computer program product may include a computer-readable storage medium having thereon computer-readable program instructions for performing various aspects of the present invention.
[0168] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A medical data privacy protection method based on artificial intelligence, characterized in that: include: Perform feature analysis on the medical data to be processed to obtain sensitive information, the sensitive information includes basic patient information, clinical diagnosis information, medical imaging information and medical test information, establish a scoring matrix based on the sensitive information, generate a privacy risk assessment result based on the scoring matrix combined with historical data leakage records, divide the medical data into multiple security domains based on the privacy risk assessment result, establish a local data storage node in each security domain, and establish a distributed collaboration mechanism between security domains using a federated learning approach; Preprocess the local medical data at the local data storage node to obtain training samples, build a deep neural network model, convert the feature information of the training samples into a vector space and build a dynamic key matrix, encrypt the gradient information generated during the training process in blocks based on the dynamic key matrix, use a multi-party secure computing protocol to perform distributed aggregation operations and integrity verification on the encrypted gradient information, and after verification, update the deep neural network model parameters at the federated learning center node and synchronize them to the local data storage node until a preset convergence condition is reached; form a medical data privacy protection scheme based on the trained deep neural network model that includes data access rules, data desensitization rules, and data flow rules; Authentication and permission matching are performed on access requests based on user role permissions, and anomaly detection is performed on verified access requests based on access time characteristics, access behavior characteristics, and access content characteristics. When it is detected that the access behavior deviates from the normal behavior baseline, an anomaly degree score is calculated, and the data access granularity is dynamically adjusted based on the anomaly degree score, and the corresponding protection rules in the medical data privacy protection scheme are triggered.
2. The method according to claim 1, characterized in that The steps of establishing a scoring matrix based on the sensitive information, generating a privacy risk assessment result based on the scoring matrix combined with historical data leakage records, dividing the medical data into multiple security domains based on the privacy risk assessment result, establishing a local data storage node in each security domain, and establishing a distributed collaboration mechanism between security domains using a federated learning method include: Perform multi-dimensional scoring on sensitive information, the multi-dimensional scoring includes a sensitivity score based on information entropy, an integrity score based on the proportion of non-empty attributes, a data association score based on association rules, and a timeliness score based on a time decay function, and construct a scoring matrix based on the multi-dimensional scoring; calculate the feature similarity between the sensitive information and historical data leakage records, and perform weighted fusion of the feature similarity and the scoring matrix to obtain a risk assessment result; Based on the risk assessment results, a multi-layer risk threshold is set, and the safety distance between sensitive information is calculated. The safety distance is composed of the weighted Hamming distance of risk difference and data association. The hierarchical clustering method is used to divide the data with a safety distance greater than the corresponding risk threshold into different security domains. The minimum safety distance between the newly added sensitive information and the existing security domain is calculated to determine its domain affiliation; Local data storage nodes are established in the divided security domains, asymmetric encryption key pairs are generated for each local data storage node and a secure communication channel is established. Security inter-domain communication primitives including data sending, receiving and verification are defined, and a data exchange format based on homomorphic encryption is used to transmit encrypted data between security domains. A practical Byzantine fault-tolerant algorithm is used to achieve consistency consensus on cross-security domain data exchange, a threshold signature scheme is used to verify data integrity, and the efficiency of cross-domain data query is optimized through Bloom filter indexing, to build a distributed collaboration mechanism for federated learning between security domains.
3. The method according to claim 1, characterized in that The steps of preprocessing local medical data at the local data storage node to obtain training samples, constructing a deep neural network model, converting feature information of the training samples into a vector space and constructing a dynamic key matrix, encrypting gradient information generated during the training process in blocks based on the dynamic key matrix, performing distributed aggregation operations and integrity verification on the encrypted gradient information using a multi-party secure computing protocol, and updating the deep neural network model parameters at the federated learning center node and synchronizing them to the local data storage node after the verification is passed until a preset convergence condition is reached include: Multiple chain equations are used to iteratively predict and fill missing values in local medical data, and the interquartile range method is used to detect and process outliers. The processed features are standardized and transformed to obtain training samples; a deep neural network model is constructed, which includes a feature-level attention mechanism and a sample-level attention mechanism, and a composite loss function training and adaptive weight adjustment strategy are used; The discrete features in the training samples are mapped into continuous vectors through a hierarchical word vector method and a subword encoding method, and a multi-table hash index is constructed based on local sensitive hashing to perform feature dimension reduction. The multi-table hash index dynamically adjusts the number of hash tables by setting a failure probability threshold and a recall rate parameter; a Toeplitz matrix is constructed based on a session key shared between data nodes, and a dynamic key matrix is generated by randomly orthogonally transforming the Toeplitz matrix; Calculate the gradient information of the training sample on the deep neural network model, determine the optimal block size based on the gradient sparsity and amplitude distribution, apply the dynamic key matrix to each gradient block to encrypt and generate a zero-knowledge proof, and superimpose random noise based on differential privacy calibration in the encrypted gradient; distribute aggregation authority based on a threshold secret sharing scheme based on a multi-party secure computing protocol, the local data storage node performs weighted local aggregation on the encrypted gradient and calculates the partial sum, and reconstructs the global gradient through a secret sharing protocol; use a Merkle tree to verify the integrity of the global gradient, and use a batch verification mechanism to prove the correctness of the gradient aggregation process of the local data storage nodes participating in federated learning; Calculate the deviation correction value and momentum term of the deep neural network model gradient, update the deep neural network model parameters based on the deviation correction value and momentum term, synchronize the updated deep neural network model parameters to each local data storage node, and stop training when the composite loss function change value, the gradient norm value and the parameter change value are all less than a preset threshold.
4. The method according to claim 3, characterized in that The steps of constructing a deep neural network model, wherein the deep neural network model includes a feature-level attention mechanism and a sample-level attention mechanism, and adopting a composite loss function training and an adaptive weight adjustment strategy include: Constructing a deep neural network model including a feature-level attention mechanism and a sample-level attention mechanism, wherein the feature-level attention mechanism transforms the feature matrix of the training sample through a linear transformation matrix and calculates the feature attention score to obtain a feature weighted output, and the sample-level attention mechanism divides the feature weighted output into multiple attention heads and performs sample relationship encoding to obtain a sample representation, and introduces a residual connection and a feedforward network to the sample representation to obtain a final output; Calculating feature-level attention loss based on predefined feature importance weights, the feature-level attention loss includes a logarithmic loss term of feature attention scores and an orthogonal constraint term of feature attention weight matrix; constructing a sample relationship encoding matrix and a graph Laplacian matrix based on clinical similarity to calculate sample-level relationship consistency loss; calculating prediction explanation alignment loss based on the cross entropy between the predicted output and the true label and the alignment constraint between the input feature gradient contribution and the feature weighted output; combining the feature-level attention loss, sample-level relationship consistency loss and prediction explanation alignment loss to obtain a composite loss function; Calculate the gradient ratio of each loss item relative to the deep neural network model parameter to obtain a dynamic adjustment factor, and adaptively adjust the weight coefficient in the composite loss function based on the performance index on the validation set and the dynamic adjustment factor; The deep neural network model is trained using the composite loss function, gradient clipping is performed during the training process, and the attention weights in the feature-level attention mechanism and the sample-level attention mechanism are normalized respectively.
5. The method according to claim 3, characterized in that: The steps of calculating the gradient information of the training sample on the deep neural network model, determining the optimal block size based on the gradient sparsity and amplitude distribution, applying the dynamic key matrix to encrypt each gradient block and generating a zero-knowledge proof, and superimposing the random noise based on differential privacy calibration in the encrypted gradient include: Calculate the gradient information of the training sample on the deep neural network model, and construct an inter-layer gradient correlation matrix, wherein the inter-layer gradient correlation matrix is used to characterize the dependency relationship between gradients of different layers, identify the target gradient layer based on the dependency relationship, and prioritize the gradients of the target gradient layer to generate a gradient feature vector; Calculate a sparsity index for the gradient feature vector, the sparsity index is obtained by setting a gradient threshold and counting the proportion of gradient elements exceeding the gradient threshold, calculate the amplitude distribution of the gradient feature vector and calculate the amplitude entropy, the amplitude entropy is used to characterize the uncertainty of the gradient distribution, calculate the intra-block variance of the candidate block scheme, the intra-block variance characterizes the gradient consistency within the block; A gradient correlation graph is constructed based on the gradient feature vector, wherein the vertices of the gradient correlation graph represent gradient elements, and the edges of the gradient correlation graph represent the strength of correlation between gradient elements. A community discovery is performed on the gradient correlation graph to obtain an initial block scheme, and the graph cut costs between different blocks are calculated, and the initial block scheme is optimized based on the graph cut costs. Based on the optimized initial block scheme, a multi-objective optimization problem is constructed using the sparsity index, amplitude entropy, intra-block variance, and graph cut costs, and gradient sparsity constraints and block size constraints are introduced. The optimal block size is obtained by solving the Pareto optimal solution, and the weight coefficients of each objective in the multi-objective optimization problem are adaptively updated using the gradient descent method. The parameter gradient is divided into blocks based on the optimal block size, and each gradient block is encrypted using a dynamic key matrix and a zero-knowledge proof is generated, wherein the zero-knowledge proof includes a gradient commitment, a key commitment, and an encryption proof; the local sensitivity of the parameter gradient relative to the adjacent data set is calculated, and the amplitude of the differential privacy noise is determined based on the local sensitivity, and a differentiated privacy budget is allocated to each encrypted gradient block according to the gradient norm, and the corresponding differential privacy noise is superimposed on the encrypted gradient block.
6. The method according to claim 1, characterized in that The steps of authenticating and matching access requests according to user role permissions, performing anomaly detection on verified access requests based on access time features, access behavior features, and access content features, calculating anomaly scores when access behaviors deviate from normal behavior baselines, dynamically adjusting data access granularity according to the anomaly scores, and triggering corresponding protection rules in the medical data privacy protection scheme include: Authenticate the access request, verify the matching relationship between the user ID and the target permission based on the role permission mapping matrix, and generate an access token containing the user ID, timestamp and digital signature after verification; Extracting original features based on the access token, constructing a multidimensional feature including an access time feature vector, an access behavior feature vector and an access content feature vector, performing logarithmic transformation on the time interval and access duration in the access time feature vector, performing minimum and maximum value normalization processing on the access behavior feature vector, and performing mean normalization and variance standardization processing on the access content feature vector; fusing the multidimensional features using an adaptive weight matrix, calculating associated weight coefficients through feature correlation, performing weighted combination of the multidimensional features based on the associated weight coefficients to obtain fused features, inputting the fused features into a Gaussian mixture model for training, using a weighted combination of multiple Gaussian distributions to fit the feature distribution of normal access behavior, and obtaining a normal behavior baseline based on the trained Gaussian mixture model; The abnormal feature metrics including log-likelihood probability, minimum Mahalanobis distance and temporal correlation metric are calculated for the new access request features, an optimization problem with regularization constraints is constructed, the alternating direction multiplier method is used to solve the fusion weight coefficient of each abnormal feature metric, and the abnormal feature metric is weighted with the corresponding fusion weight coefficient to obtain an abnormality degree score; according to the abnormality degree score, the access request is mapped to one of the access control levels among full access, desensitized access, aggregate access and denied access, and the corresponding protection rules in the medical data privacy protection scheme are triggered.
7. The method according to claim 6, characterized in that The steps of calculating abnormal feature metrics including log-likelihood probability, minimum Mahalanobis distance and time series correlation metric for new access request features, constructing an optimization problem with regularization constraints, solving the fusion weight coefficient of each abnormal feature metric by using the alternating direction multiplier method, and weighting the abnormal feature metric with the corresponding fusion weight coefficient to obtain an abnormality degree score include: Constructing a feature space for a new access request, and calculating the log-likelihood probability of the feature space by a hierarchical adaptive probability density estimation method, wherein the probability density estimation method includes constructing a multi-layer feature representation to obtain intermediate features, introducing an adaptive weight matrix based on a hyperbolic tangent function in each layer, constructing a hierarchical probability density distribution, and introducing a dynamic temperature coefficient based on the spatiotemporal distance of the access behavior to adjust the probability density to obtain the log-likelihood probability; calculating the minimum Mahalanobis distance in the feature space, and calculating a temporal correlation measure based on a historical access sequence, and forming an abnormal feature measurement vector with the log-likelihood probability, the minimum Mahalanobis distance, and the temporal correlation measure; A multi-objective constrained optimization problem is constructed to solve the fusion weight coefficient of each abnormal feature metric. The multi-objective constrained optimization problem includes introducing a feature correlation regularization term based on mutual information and a time series stability constraint term based on time interval, and using a dynamic parameter update mechanism to adaptively adjust the regularization coefficient. The problem is solved based on an improved alternating direction multiplier method. The improved alternating direction multiplier method determines the dynamic step size of the penalty factor by the difference between the fusion weight coefficients of two adjacent iterations. The auxiliary variables in the solution process are subjected to non-negative and normalized constraint processing by a projection algorithm. An iterative optimization is performed using a dual variable update strategy that matches the dynamic step size of the penalty factor. The optimal fusion weight coefficient is obtained when the difference between the fusion weight coefficients of two adjacent iterations is less than a preset allowable range and the dual residual is less than a predetermined convergence parameter. The abnormal feature metric is weighted with the optimal fusion weight coefficient to obtain an initial abnormality degree score, and an adaptive correction mechanism based on mean deviation and spatiotemporal distance is used to dynamically adjust the initial abnormality degree score. The corrected initial abnormality degree score is normalized by a time-varying adjustment factor to obtain the final abnormality degree score.
8. An artificial intelligence-based medical data privacy protection system, used to implement the method described in any one of claims 1 to 7, characterized in that: include: The first unit is used to perform feature analysis on the medical data to be processed to obtain sensitive information, wherein the sensitive information includes basic patient information, clinical diagnosis information, medical imaging information and medical test information, establish a scoring matrix based on the sensitive information, generate a privacy risk assessment result based on the scoring matrix combined with historical data leakage records, divide the medical data into multiple security domains based on the privacy risk assessment result, establish a local data storage node in each security domain, and establish a distributed collaboration mechanism between security domains using a federated learning method; The second unit is used to pre-process the local medical data at the local data storage node to obtain training samples, build a deep neural network model, convert the feature information of the training samples into a vector space and build a dynamic key matrix, encrypt the gradient information generated during the training process in blocks based on the dynamic key matrix, and use a multi-party secure computing protocol to perform distributed aggregation operations and integrity verification on the encrypted gradient information. After the verification is passed, the deep neural network model parameters are updated at the federated learning center node and synchronized to the local data storage node until a preset convergence condition is reached; a medical data privacy protection scheme including data access rules, data desensitization rules and data flow rules is formed based on the trained deep neural network model; The third unit is used to authenticate and match access requests according to user role permissions, perform anomaly detection on verified access requests based on access time characteristics, access behavior characteristics and access content characteristics, and calculate anomaly degree scores when it is detected that the access behavior deviates from the normal behavior baseline, dynamically adjust the data access granularity according to the anomaly degree scores, and trigger corresponding protection rules in the medical data privacy protection scheme.
9. An electronic device, characterized in that: include: processor; a memory for storing processor-executable instructions; The processor is configured to call the instructions stored in the memory to execute the method described in any one of claims 1 to 7.
10. A computer-readable storage medium having computer program instructions stored thereon, characterized in that: When the computer program instructions are executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Cross-safety-domain access control system and method based on privacy protection
CN103391192A
Power data privacy protection method, system and device under multi-party cooperation and medium
CN116663052A