A robustness evaluation method and system for data stream local differential privacy algorithm

By setting the evaluation target frequency and selecting evaluation users in the local differential privacy algorithm of the data stream and adaptively adjusting the release strategy, the problem of being unable to evaluate the robustness of the local differential privacy algorithm of the data stream in the existing technology is solved, and efficient robustness evaluation and frequency distribution adjustment in dynamic data streams are achieved.

CN119622259BActive Publication Date: 2025-10-03XI AN JIAOTONG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411729002.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-28
Publication Date
2025-10-03
Estimated Expiration
2044-11-28

AI Technical Summary

Technical Problem

Existing robustness evaluation methods are only applicable to static local differential privacy algorithms, not to data stream local differential privacy algorithms, and cannot effectively evaluate their robustness in dynamic data streams.

Method used

By setting the evaluation target frequency at each timestamp, selecting the evaluation users, and calculating the privacy budget and number of users of the release strategy, and using the dissimilarity calculation module and fine-grained algorithm robustness evaluation method, the local differential privacy algorithm of the data stream is adaptively judged to enter the release strategy or approximate strategy, and the release frequency is adjusted to minimize the proximity distance to meet the robustness evaluation target.

Benefits of technology

An adaptive robustness evaluation of the local differential privacy algorithm for data streams is implemented, ensuring that its release frequency distribution in dynamic data streams is close to the evaluation target frequency, thereby improving the overall robustness and privacy security consistency of the algorithm.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119622259B_ABST
    Figure CN119622259B_ABST
Patent Text Reader

Abstract

The present invention provides a robustness evaluation method and system for a data stream local differential privacy algorithm. The method judges the robustness of the algorithm by the proximity between the algorithm release frequency distribution at each timestamp and the algorithm robustness evaluation target distribution. The method adopts a branch judgment mechanism, which can adaptively judge at each timestamp which strategy the data stream local differential privacy algorithm enters to achieve a better evaluation effect for the robustness evaluation of the algorithm. Based on the judgment of the branch judgment mechanism, the method affects the dissimilarity calculation module of the data stream local differential privacy algorithm so that the privacy algorithm can enter the strategy expected by the evaluator, and is divided into two types: input evaluation and output evaluation. If the data stream local differential privacy algorithm enters the release strategy, the method provides a fine-grained algorithm robustness evaluation method for the frequency statistics local differential privacy algorithm in the release strategy. The method is also divided into two types: input evaluation and output evaluation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of data security, and in particular relates to a robustness evaluation method and system for a data stream local differential privacy algorithm. Background Art

[0002] As one of the specific technologies in the field of privacy computing, the data stream local differential privacy algorithm can safely and efficiently complete data statistics tasks such as frequency statistics without collecting original user data. When performing data statistics, the algorithm first collects user data at the current timestamp using the frequency statistics local differential privacy algorithm and calculates the dissimilarity between the user data and the published data at the previous timestamp. , and at the same time, the potential publication error of the current timestamp is calculated as . The algorithm will then determine and The relative size of Greater than , indicating that publishing data at this timestamp will result in a smaller error, and the algorithm will enter the publishing strategy, using a frequency statistics local differential privacy algorithm for data publishing. Conversely, the algorithm will enter the approximation strategy, using the previous moment's publishing frequency as the current timestamp's publishing frequency. Some studies have discussed the robustness of local differential privacy algorithms and found that the collector of local differential privacy algorithms is very sensitive to the distribution of data sent by users. Other studies have discussed the robustness of frequency statistics local differential privacy algorithms. Other studies have proposed local differential privacy algorithms for mean and variance statistics and discussed the robustness of the algorithm. Because the goal of its robustness evaluation algorithm can be adjusted according to the expectations of the evaluator, it is also called a fine-grained robustness evaluation algorithm. However, existing robustness evaluation methods for local differential privacy algorithms are only applicable to evaluating static local differential privacy algorithms and are not suitable for evaluating data stream local differential privacy algorithms. Summary of the Invention

[0003] The purpose of the present invention is to provide a robustness evaluation method and system for a data stream local differential privacy algorithm. The evaluation party of the method changes the release frequency of the data stream local differential privacy algorithm by sending prepared data to the data stream local differential privacy algorithm server. Make it close to the target frequency of assessment set by the assessor , that is, when the length is On the data stream of , solve the following optimization problem:

[0004]

[0005] That is, the evaluator hopes to minimize the frequency of the algorithm's release at each timestamp. and the target frequency of evaluation set by the evaluator at each timestamp Approach distance At the same time, the evaluator evaluates the robustness of the local differential privacy algorithm of the data stream based on the proximity distance; The average closeness distance between the release frequency of the data stream local differential privacy algorithm and the evaluation target frequency on the data stream The larger it is, the more robust the algorithm is. This evaluation method can adaptively select the strategy for entering the local differential privacy algorithm of the data stream to achieve the above robustness evaluation goal.

[0006] In order to achieve the above object, the present invention adopts the following technical solutions:

[0007] A robustness evaluation method for a data stream local differential privacy algorithm, including:

[0008] Step 1: Assessment preparation and selection of branching strategy;

[0009] At each timestamp, the evaluator first sets the target frequency for the timestamp. And from the total Select a user users as evaluation users, The users are the remaining users; at the same time, the evaluator calculates the privacy budget used by the server to publish the policy at this timestamp from the evaluated users. And the number of users sampled by the server at that timestamp for publishing policies ,in The number of users sampled at this timestamp for evaluating the release strategy. is the number of remaining users sampled for the release strategy at this timestamp. To achieve the goal of robustness evaluation, the evaluator will calculate the proximity between the release frequency of the data stream local differential privacy algorithm entering the release strategy and the approximate strategy and the evaluation target frequency, and determine which strategy the algorithm enters at this timestamp to minimize the proximity distance.

[0010] Step 2: Evaluate the dissimilarity calculation module of the local differential privacy algorithm for data streams;

[0011] According to the judgment rule in step 1, the evaluator can determine which strategy the local differential privacy algorithm of the data stream enters to minimize the proximity distance based on the timestamp. If the approximate strategy can minimize the proximity distance, the evaluator will minimize the dissimilarity. , so that the algorithm enters the approximate strategy; otherwise, the evaluation side will maximize , which enables the algorithm to enter the release strategy;

[0012] Step 3: Fine-grained algorithm robustness evaluation of the frequency statistics local differential privacy algorithm;

[0013] According to step 2, maximize or minimize Based on the judgment, the evaluator will perform different operations to meet the fine-grained algorithm robustness evaluation, that is, change the release frequency of the data stream local differential privacy algorithm as much as possible to make it close to the evaluation target frequency; when the evaluator chooses to maximize the dissimilarity, the data stream local differential privacy algorithm will enter the release strategy and use the frequency statistics local differential privacy algorithm for frequency statistics and release; the evaluator needs to carry out a fine-grained algorithm robustness evaluation for the frequency statistics local differential privacy algorithm to make its release frequency distribution close to the evaluation target frequency distribution; otherwise, when the evaluator chooses to minimize the dissimilarity, the data stream local differential privacy algorithm will enter the approximate strategy and directly use the release frequency of the previous timestamp as the release frequency of this timestamp, so the evaluator does not need to perform additional operations.

[0014] A further improvement of the present invention is that in step 1, the evaluator determines which strategy the algorithm enters at the timestamp based on the calculated release frequency of the data stream local differential privacy algorithm entering the release strategy or approximate strategy and the proximity of the evaluation target frequency, including:

[0015] Step 1.1: Calculate the proximity distance of the data stream local differential privacy algorithm into the approximate strategy: ,in, is the publishing frequency of the previous timestamp, is the target frequency for evaluation at that timestamp, The size of the field for user input;

[0016] Step 1.2: Calculate the average distance between the data stream local differential privacy algorithm and the release strategy: ,in, It represents the algorithm release frequency after performing fine-grained algorithm robustness evaluation on the frequency statistics of the local differential privacy algorithm for the release strategy;

[0017] Step 1.3: Compare the proximity of the control data flow local differential privacy algorithm to the approximate strategy and proximity to entry release strategy ,if If the value is smaller, the evaluator hopes that the data stream local differential privacy algorithm will enter the approximate strategy; otherwise, the evaluator hopes that the data stream local differential privacy algorithm will enter the release strategy.

[0018] A further improvement of the present invention is that the evaluation methods for the data stream local differential privacy algorithm dissimilarity calculation module in step 2 are divided into two types, including input evaluation and output evaluation.

[0019] A further improvement of the present invention is that input evaluation refers to designing input data for evaluating the user's local differential privacy algorithm to affect the calculation mechanism of dissimilarity to evaluate the robustness of the algorithm; assuming that there are Users are used to calculate the dissimilarity of the data stream local differential privacy algorithm, where named evaluation user, The input distribution of the residual user’s local differential privacy algorithm is , among which Item is , then maximizing or minimizing the dissimilarity is to solve the following optimization problem:

[0020]

[0021]

[0022] in, is the input frequency distribution of the local differential privacy algorithm, and the evaluator maximizes or minimizes it by influencing the frequency distribution The goal of this frequency distribution is item Calculated as ,in Indicates that there are evaluation users The input value of the local differential privacy algorithm is .

[0023] A further improvement of the present invention is that the output evaluation refers to the evaluator bypassing the local perturbation step of the local differential privacy algorithm and directly sending the calculated data to the server to affect the calculation of the dissimilarity, so as to achieve the purpose of testing the robustness of the algorithm; minimizing the dissimilarity, that is, minimizing When the evaluator minimizes its upper bound implementation, where is the release frequency distribution of the local differential privacy algorithm:

[0024]

[0025] in are the parameters of the local differential privacy algorithm, Indicates that there is The value sent to the server by the evaluation user is ; When maximizing the dissimilarity, the evaluator first calculates , maximizing the dissimilarity is to make , , that is, use all evaluation users to send to the server This can achieve the goal of maximizing the dissimilarity.

[0026] A further improvement of the present invention is that the fine-grained algorithm robustness evaluation method for the frequency statistical local differential privacy algorithm in step 3 is divided into two types: input evaluation and output evaluation, and both meet the "privacy security consistency" requirement;

[0027] Input evaluation is designed to evaluate the frequency distribution of user inputs in order to achieve the goal of fine-grained algorithm robustness evaluation. The publishing strategy of the local differential privacy algorithm for data streams is used by users, where named evaluation user, The input distribution of the local differential privacy algorithm for the remaining users at this timestamp is , among which Item is , then completing the fine-grained algorithm robustness evaluation at this timestamp is to solve the following optimization problem:

[0028]

[0029]

[0030] in, is the input frequency distribution of the local differential privacy algorithm, the first The calculation is ,in Indicates that there are evaluation users The input value of the local differential privacy algorithm is ; At the same time, calculate the proximity distance of the input evaluation when the number of evaluation users is large enough ,in, Indicates that the privacy budget used is Frequency statistics local differential privacy algorithm for The error of frequency statistics of users; thus, The larger the number of users, the closer the distance The smaller it is, the more it meets the goal of robustness evaluation, that is, the evaluation shows "privacy and security consistency";

[0031] In the output evaluation, the user is evaluated to bypass the local perturbation of the local differential privacy algorithm and send data directly to the server to achieve the effect of fine-grained algorithm robustness evaluation; in order to make the release frequency close to the target frequency, that is, to minimize , the evaluator minimizes its upper bound implementation, where is the release frequency distribution of the local differential privacy algorithm:

[0032]

[0033] in are the parameters of the local differential privacy algorithm, Indicates that there is The value sent to the server by the evaluation user is ; When there are enough evaluation users, the evaluation proximity distance is output ,in is a constant ;akin, The larger the size or the more total users, The smaller it is, the more it meets the goal of robustness evaluation, that is, the evaluation shows "privacy-security consistency".

[0034] A robustness evaluation system for a data stream local differential privacy algorithm, including:

[0035] Selection module, used for evaluation preparation and selection of branching strategies;

[0036] At each timestamp, the evaluator first sets the target frequency for the timestamp. And from the total Select a user users as evaluation users, The users are the remaining users; at the same time, the evaluator calculates the privacy budget used by the server to publish the policy at this timestamp from the evaluated users. And the number of users sampled by the server at that timestamp for publishing policies ,in The number of users sampled at this timestamp for evaluating the release strategy. is the number of remaining users sampled for the release strategy at this timestamp. To achieve the goal of robustness evaluation, the evaluator will calculate the proximity between the release frequency of the data stream local differential privacy algorithm entering the release strategy and the approximate strategy and the evaluation target frequency, and determine which strategy the algorithm enters at this timestamp to minimize the proximity distance.

[0037] The first evaluation module is used to evaluate the dissimilarity calculation module of the local differential privacy algorithm for data streams;

[0038] According to the judgment rules of the selection module, the evaluator can determine which strategy the timestamp makes the data stream local differential privacy algorithm enter to minimize the proximity distance. If the approximate strategy can minimize the proximity distance, the evaluator will minimize the dissimilarity. , so that the algorithm enters the approximate strategy; otherwise, the evaluation side will maximize , which enables the algorithm to enter the release strategy;

[0039] The second evaluation module is a fine-grained algorithm robustness evaluation of the frequency statistics local differential privacy algorithm;

[0040] According to the first evaluation module, the maximum or minimum Based on the judgment, the evaluator will perform different operations to meet the fine-grained algorithm robustness evaluation, that is, change the release frequency of the data stream local differential privacy algorithm as much as possible to make it close to the evaluation target frequency; when the evaluator chooses to maximize the dissimilarity, the data stream local differential privacy algorithm will enter the release strategy and use the frequency statistics local differential privacy algorithm for frequency statistics and release; the evaluator needs to carry out a fine-grained algorithm robustness evaluation for the frequency statistics local differential privacy algorithm to make its release frequency distribution close to the evaluation target frequency distribution; otherwise, when the evaluator chooses to minimize the dissimilarity, the data stream local differential privacy algorithm will enter the approximate strategy and directly use the release frequency of the previous timestamp as the release frequency of this timestamp, so the evaluator does not need to perform additional operations.

[0041] Compared with the prior art, the present invention has at least the following beneficial technical effects:

[0042] This invention provides a robustness assessment method and system for a data stream local differential privacy algorithm. This method first provides a branching decision mechanism that adaptively determines, at each timestamp, which strategy (publication strategy or approximation strategy) the data stream local differential privacy algorithm should adopt to minimize the algorithm robustness assessment distance across the entire data stream, thereby achieving the goal of robustness assessment. This branching decision mechanism leverages the "privacy-security consistency" of fine-grained algorithm robustness assessment methods.

[0043] Furthermore, the evaluator maximizes or minimizes the dissimilarity calculation mechanism by influencing the local differential privacy algorithm of the data stream. , thereby controlling the data stream local differential privacy algorithm to enter the strategy expected by the evaluator for data statistics and release. There are two evaluation methods for the dissimilarity calculation mechanism of the data stream local differential privacy algorithm: output evaluation and input evaluation.

[0044] Furthermore, when a data stream local differential privacy algorithm enters a release strategy for data release, this method can influence the frequency-based local differential privacy algorithm in the release strategy so that its release frequency distribution approaches the target frequency distribution expected by the evaluator. Based on the degree of proximity between the two distributions, the evaluator can determine the robustness of the algorithm. It can be shown that this fine-grained algorithm robustness evaluation method for the frequency-based local differential privacy algorithm satisfies "privacy-safety consistency." This fine-grained algorithm robustness evaluation method for the frequency-based local differential privacy algorithm also includes input evaluation and output evaluation. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 Schematic diagram of the process of the present invention.

[0046] Figure 2 Schematic diagram of the logical architecture of the present invention.

[0047] Figure 3 This is a trend diagram of the approach distance changing with the total privacy budget of the present invention.

[0048] Figure 4 It is a structural block diagram of the system of the present invention. DETAILED DESCRIPTION

[0049] Hereinafter, only certain exemplary embodiments are briefly described. As will be appreciated by those skilled in the art, the described embodiments may be modified in various ways without departing from the spirit or scope of the present invention. Therefore, the drawings and description are to be considered as illustrative in nature and not restrictive.

[0050] It will be understood that when used in this specification and the appended claims, the terms “comprises” and “comprising” indicate the presence of described features, integers, steps, operations, elements and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof.

[0051] It should also be understood that the terms used in the present specification are only for the purpose of describing particular embodiments and are not intended to limit the present invention. As used in the present specification and the appended claims, the singular forms "a", "an", and "the" are intended to include the plural forms unless the context clearly indicates otherwise.

[0052] It should be further understood that the term "and / or" used in the present description and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.

[0053] The accompanying drawings illustrate various schematic diagrams of structures according to embodiments disclosed herein. These figures are not drawn to scale; for clarity, some details are exaggerated and some details may be omitted. The shapes of the various regions and layers shown in the figures, as well as their relative sizes and positional relationships, are merely exemplary and may deviate in practice due to manufacturing tolerances or technical limitations. Those skilled in the art may design regions / layers with different shapes, sizes, and relative positions as needed.

[0054] The embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0055] Example 1

[0056] Reference Figure 1This embodiment provides a robustness evaluation method for a data stream local differential privacy algorithm, which specifically includes the following steps:

[0057] Step 1: Evaluation preparation and branch strategy selection: At each timestamp, the evaluator first sets the evaluation target frequency for that timestamp. And from the total Select a user users as evaluation users, The users are the remaining users; at the same time, the evaluator calculates the privacy budget used by the server to publish the policy at this timestamp from the evaluated users. And the number of users sampled by the server at that timestamp for publishing policies ,in The number of users sampled at this timestamp for evaluating the release strategy. is the number of remaining users sampled for the release strategy at this timestamp. To achieve the goal of robustness evaluation, the evaluator will calculate the release frequency of the data stream local differential privacy algorithm entering the release strategy and approximate strategy and the proximity distance of the evaluation target frequency, and determine which strategy the algorithm enters at this timestamp to minimize the proximity distance. The specific steps are as follows:

[0058] Step 1.1: Calculate the proximity distance of the data stream local differential privacy algorithm into the approximate strategy: ,in, is the publishing frequency of the previous timestamp, is the target frequency for evaluation at that timestamp, The size of the field for user input;

[0059] Step 1.2: Calculate the average distance between the data stream local differential privacy algorithm and the release strategy: ,in, It represents the algorithm release frequency after performing fine-grained algorithm robustness evaluation on the frequency statistics of the local differential privacy algorithm for the release strategy;

[0060] Step 1.3: Compare the proximity of the control data flow local differential privacy algorithm to the approximate strategy and proximity to entry release strategy ,if If the value is smaller, the evaluator hopes that the data stream local differential privacy algorithm will enter the approximate strategy; otherwise, the evaluator hopes that the data stream local differential privacy algorithm will enter the release strategy.

[0061] Step 2: Evaluate the dissimilarity calculation module of the local differential privacy algorithm for the data stream. According to the above judgment rules, the evaluator can determine which strategy the local differential privacy algorithm of the data stream enters to minimize the proximity distance. If the approximate strategy can minimize the proximity distance, the evaluator will minimize the dissimilarity. , so that the algorithm enters the approximate strategy; otherwise, the evaluation side will maximize , which enables the algorithm to enter the release strategy. There are two evaluation methods for the dissimilarity calculation module of the local differential privacy algorithm for data streams: input evaluation and output evaluation.

[0062] Input evaluation refers to the design of input data for evaluating the user's local differential privacy algorithm to influence the calculation mechanism of dissimilarity to evaluate the robustness of the algorithm. Users are used to calculate the dissimilarity of the data stream local differential privacy algorithm, where named evaluation user, The input distribution of the residual user’s local differential privacy algorithm is , among which Item is , then maximizing or minimizing the dissimilarity is to solve the following optimization problem:

[0063]

[0064]

[0065] in, is the input frequency distribution of the local differential privacy algorithm. The evaluator can maximize or minimize the frequency distribution by influencing it. The goal of this frequency distribution is item It can be calculated as ,in Indicates that there are evaluation users The input value of the local differential privacy algorithm is .

[0066] Output evaluation means that the evaluator bypasses the local perturbation step of the local differential privacy algorithm and directly sends the calculated data to the server to affect the calculation of dissimilarity, so as to achieve the purpose of testing the robustness of the algorithm. Minimizing dissimilarity, that is, minimizing When the evaluator can minimize its upper bound implementation, where is the release frequency distribution of the local differential privacy algorithm:

[0067]

[0068] in are the parameters of the local differential privacy algorithm, Indicates that there is The value sent to the server by the evaluation user is When maximizing the dissimilarity, the evaluator first calculates , maximizing the dissimilarity is to make , , that is, use all evaluation users to send to the server This can achieve the goal of maximizing the dissimilarity.

[0069] Step 3: Fine-grained algorithm robustness evaluation method for frequency statistical local differential privacy algorithm; according to the previous step, maximize or minimize Based on the judgment, the evaluator will perform different operations to meet the fine-grained algorithm robustness evaluation, namely, changing the data stream local differential privacy algorithm's publication frequency as much as possible to make it close to the evaluation target frequency. When the evaluator chooses to maximize dissimilarity, the data stream local differential privacy algorithm will enter the publication strategy and use the frequency statistics local differential privacy algorithm to perform frequency statistics and publication. The evaluator needs to conduct a fine-grained algorithm robustness evaluation for this frequency statistics local differential privacy algorithm to make its publication frequency distribution close to the evaluation target frequency distribution. Otherwise, when the evaluator chooses to minimize dissimilarity, the data stream local differential privacy algorithm will enter the approximation strategy and directly use the publication frequency of the previous timestamp as the publication frequency of this timestamp, so the evaluator does not need to perform additional operations. The fine-grained algorithm robustness evaluation methods for this frequency statistics local differential privacy algorithm are also divided into two types: input evaluation and output evaluation.

[0070] Input evaluation is designed to evaluate the frequency distribution of user inputs in order to achieve the goal of fine-grained algorithm robustness evaluation. The publishing strategy of the local differential privacy algorithm for data streams is used by users, where named evaluation user, The input distribution of the local differential privacy algorithm for the remaining users at this timestamp is , among which Item is , then completing the fine-grained algorithm robustness evaluation at this timestamp is to solve the following optimization problem:

[0071]

[0072]

[0073] in, is the input frequency distribution of the local differential privacy algorithm, the first The term can be calculated as ,in Indicates that there are evaluation users The input value of the local differential privacy algorithm is At the same time, the proximity distance of the input evaluation can be calculated when the number of evaluation users is large enough ,in, Indicates that the privacy budget used is Frequency statistics local differential privacy algorithm for The error in frequency statistics of users. The larger the number of users, the closer the distance The smaller it is, the more it meets the goal of robustness evaluation, that is, the evaluation shows "privacy-security consistency".

[0074] In the output evaluation, the user is evaluated to bypass the local perturbation of the local differential privacy algorithm and send data directly to the server to achieve the effect of fine-grained algorithm robustness evaluation. In order to make the release frequency close to the target frequency, that is, to minimize , the evaluator can minimize its upper bound implementation, where is the release frequency distribution of the local differential privacy algorithm:

[0075]

[0076] in are the parameters of the local differential privacy algorithm, Indicates that there is The value sent to the server by the evaluation user is It can be proved that when there are enough evaluation users, the output evaluation is close to ,in is a constant. Similarly, The larger the number of users, the closer the distance The smaller it is, the more it meets the goal of robustness evaluation, that is, the evaluation shows "privacy-security consistency".

[0077] In this description, it is important to understand that the term "timestamp" refers to a time point marked at a certain interval in the time stream, used to represent and record changes that occur within a period of time after the mark. "Data provider" refers to the person or enterprise that provides data. "Local differential privacy" refers to the fact that two datasets with only one inconsistent data point can obtain probabilistically similar results after performing a specified calculation. "Robustness evaluation method" refers to the evaluation party's evaluation of the robustness of an algorithm by comparing the proximity of the algorithm release frequency distribution at each timestamp to the algorithm robustness evaluation target distribution.

[0078] In order to test the impact of different privacy budgets on the performance of this evaluation method, several algorithm robustness evaluation methods for data stream local differential privacy algorithms are compared. Experiments are conducted using a data set of 700,000 data providers, 432 timestamps, and 150 discrete values. The sliding window of the data stream local differential privacy algorithm is set to 20, and the evaluation target distribution is uniformly distributed at each timestamp. The mean square error is used to calculate the proximity between the release frequency and the evaluation target frequency. The smaller the mean square error, the worse the algorithm robustness. The results are as follows: Figure 3 As shown in the figure, as the total privacy budget of the data stream local differential privacy algorithm increases, the mean squared error of all evaluations decreases. The mean squared error of this method (input evaluation IAE and output evaluation OAE) is lower than that of other methods (input evaluation IUE and ISE, output evaluation OUE and OSE), which can more deeply test the robustness of the privacy algorithm. At the same time, compared with the input evaluation, the output evaluation has a smaller mean squared error, showing better performance.

[0079] refer to Figure 2 , the present invention provides a robustness evaluation method for a data stream local differential privacy algorithm, and its logical method includes two stages: evaluating the dissimilarity calculation module of the data stream local differential privacy algorithm and evaluating the release strategy of the data stream local differential privacy algorithm. In order to improve the evaluation effect on the entire data stream, the algorithm will first determine which strategy the data stream local differential privacy algorithm enters to minimize the approach distance to achieve the purpose of robustness evaluation before conducting the evaluation of the dissimilarity calculation module. It is worth noting that the evaluator cannot directly control the decision selection mechanism of the data stream local differential privacy algorithm to make it enter its desired strategy, but can make the algorithm enter its desired decision by affecting the size of the dissimilarity, thereby performing a more accurate algorithm robustness evaluation.

[0080] Example 2

[0081] Reference Figure 4 This embodiment provides a robustness evaluation system for a data stream local differential privacy algorithm, including:

[0082] Selection module, used for evaluation preparation and selection of branching strategies;

[0083] At each timestamp, the evaluator first sets the target frequency for the timestamp. And from the total Select a user users as evaluation users, The users are the remaining users; at the same time, the evaluator calculates the privacy budget used by the server to publish the policy at this timestamp from the evaluated users. And the number of users sampled by the server at that timestamp for publishing policies ,in The number of users sampled at this timestamp for evaluating the release strategy. is the number of remaining users sampled for the release strategy at this timestamp; the evaluator calculates the release frequency of the data stream local differential privacy algorithm entering the release strategy and the approximate strategy and the proximity distance of the evaluation target frequency, and determines which strategy the algorithm enters at this timestamp to minimize the proximity distance;

[0084] The first evaluation module is used to evaluate the dissimilarity calculation module of the local differential privacy algorithm for data streams;

[0085] According to the judgment rules of the selection module, the evaluator can determine which strategy the timestamp makes the data stream local differential privacy algorithm enter to minimize the proximity distance. If the approximate strategy can minimize the proximity distance, the evaluator will minimize the dissimilarity. , so that the algorithm enters the approximate strategy; otherwise, the evaluation side will maximize , which enables the algorithm to enter the release strategy;

[0086] The second evaluation module is a fine-grained algorithm robustness evaluation of the frequency statistics local differential privacy algorithm;

[0087] According to the first evaluation module, the maximum or minimum Based on the judgment, the evaluator will perform different operations to meet the fine-grained algorithm robustness evaluation, that is, change the release frequency of the data stream local differential privacy algorithm as much as possible to make it close to the evaluation target frequency; when the evaluator chooses to maximize the dissimilarity, the data stream local differential privacy algorithm will enter the release strategy and use the frequency statistics local differential privacy algorithm for frequency statistics and release; the evaluator needs to carry out a fine-grained algorithm robustness evaluation for the frequency statistics local differential privacy algorithm to make its release frequency distribution close to the evaluation target frequency distribution; otherwise, when the evaluator chooses to minimize the dissimilarity, the data stream local differential privacy algorithm will enter the approximate strategy and directly use the release frequency of the previous timestamp as the release frequency of this timestamp, so the evaluator does not need to perform additional operations.

[0088] The above shows and describes the basic principles and main features of the present invention and the advantages of the present invention. It is obvious to those skilled in the art that the present invention is not limited to the details of the above exemplary embodiments, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention. Therefore, from all points of view, the embodiments should be regarded as illustrative and non-restrictive. The scope of the present invention is defined by the appended claims rather than the above description, and it is intended that all changes that fall within the meaning and range of equivalents of the claims are included in the present invention. Any reference signs in the claims should not be construed as limiting the claim to which they relate.

[0089] In addition, it should be understood that although this specification describes the embodiments, not every embodiment contains only one independent technical solution. This description is for clarity only. Those skilled in the art should consider the specification as a whole. The technical solutions in each embodiment can also be appropriately combined to form other embodiments that can be understood by those skilled in the art. The above content is only for the purpose of illustrating the technical concept of the present invention and cannot be used to limit the scope of protection of the present invention. Any changes made based on the technical solution in accordance with the technical concept proposed by the present invention fall within the scope of protection of the claims of the present invention.

Claims

1. A robustness evaluation method for a data stream local differential privacy algorithm, characterized in that: include: Step 1: Assessment preparation and selection of branching strategy; At each timestamp, the evaluator first sets the target frequency for the timestamp. And from the total Select a user users as evaluation users, The users are the remaining users; at the same time, the evaluator calculates the privacy budget used by the server to publish the policy at this timestamp from the evaluated users. And the number of users sampled by the server at that timestamp for publishing policies ,in The number of users sampled at this timestamp for evaluating the release strategy. is the number of remaining users sampled for the release strategy at this timestamp. To achieve the goal of robustness evaluation, the evaluator will calculate the proximity between the release frequency of the data stream local differential privacy algorithm entering the release strategy and the approximate strategy and the evaluation target frequency, and determine which strategy the algorithm enters at this timestamp to minimize the proximity distance. Step 2: Evaluate the dissimilarity calculation module of the local differential privacy algorithm for data streams; According to the judgment rule in step 1, the evaluator can determine which strategy the local differential privacy algorithm of the data stream enters to minimize the proximity distance based on the timestamp. If the approximate strategy can minimize the proximity distance, the evaluator will minimize the dissimilarity. , so that the algorithm enters the approximate strategy; otherwise, the evaluation side will maximize , which enables the algorithm to enter the release strategy; Step 3: Fine-grained algorithm robustness evaluation of the frequency statistics local differential privacy algorithm; According to step 2, maximize or minimize Based on the judgment, the evaluator will perform different operations to meet the fine-grained algorithm robustness evaluation, that is, change the release frequency of the data stream local differential privacy algorithm as much as possible to make it close to the evaluation target frequency; when the evaluator chooses to maximize the dissimilarity, the data stream local differential privacy algorithm will enter the release strategy and use the frequency statistics local differential privacy algorithm for frequency statistics and release; the evaluator needs to carry out a fine-grained algorithm robustness evaluation for the frequency statistics local differential privacy algorithm to make its release frequency distribution close to the evaluation target frequency distribution; otherwise, when the evaluator chooses to minimize the dissimilarity, the data stream local differential privacy algorithm will enter the approximate strategy and directly use the release frequency of the previous timestamp as the release frequency of this timestamp, so the evaluator does not need to perform additional operations.

2. The robustness evaluation method of a data stream local differential privacy algorithm according to claim 1 is characterized in that: In step 1, the evaluator determines which strategy the algorithm enters at the timestamp based on the calculated frequency of the data stream local differential privacy algorithm entering the release strategy or approximate strategy and the proximity of the evaluation target frequency, including: Step 1.1: Calculate the proximity distance of the data stream local differential privacy algorithm into the approximate strategy: ,in, is the publishing frequency of the previous timestamp, is the target frequency for evaluation at that timestamp, The size of the field for user input; Step 1.2: Calculate the average distance between the data stream local differential privacy algorithm and the release strategy: ,in, It represents the algorithm release frequency after performing fine-grained algorithm robustness evaluation on the frequency statistics of the local differential privacy algorithm for the release strategy; Step 1.3: Compare the proximity of the control data flow local differential privacy algorithm to the approximate strategy and proximity to entry release strategy ,if If the value is smaller, the evaluator hopes that the data stream local differential privacy algorithm will enter the approximate strategy; otherwise, the evaluator hopes that the data stream local differential privacy algorithm will enter the release strategy.

3. The robustness evaluation method of a data stream local differential privacy algorithm according to claim 2, characterized in that: There are two evaluation methods for the data stream local differential privacy algorithm dissimilarity calculation module in step 2, including input evaluation and output evaluation.

4. The robustness evaluation method for a data stream local differential privacy algorithm according to claim 3 is characterized in that: Input evaluation refers to the design of input data for evaluating the user's local differential privacy algorithm to influence the calculation mechanism of dissimilarity to evaluate the robustness of the algorithm; assuming that there are Users are used to calculate the dissimilarity of the data stream local differential privacy algorithm, where named evaluation user, The input distribution of the residual user’s local differential privacy algorithm is , among which Item is , then maximizing or minimizing the dissimilarity is to solve the following optimization problem: in, is the input frequency distribution of the local differential privacy algorithm, and the evaluator maximizes or minimizes it by influencing the frequency distribution The goal of this frequency distribution is item Calculated as ,in Indicates that there are evaluation users The input value of the local differential privacy algorithm is .

5. The robustness evaluation method of a data stream local differential privacy algorithm according to claim 4 is characterized in that: Output evaluation means that the evaluator bypasses the local perturbation step of the local differential privacy algorithm and directly sends the calculated data to the server to influence the calculation of dissimilarity, thereby achieving the purpose of testing the robustness of the algorithm; Minimize the dissimilarity, that is, minimize When the evaluator minimizes its upper bound implementation, where is the release frequency distribution of the local differential privacy algorithm: in are the parameters of the local differential privacy algorithm, Indicates that there is The value sent to the server by the evaluation user is ; When maximizing the dissimilarity, the evaluator first calculates , maximizing the dissimilarity is to make , , that is, use all evaluation users to send to the server This can achieve the goal of maximizing the dissimilarity.

6. The robustness evaluation method of a data stream local differential privacy algorithm according to claim 5, characterized in that: In step 3, there are two fine-grained robustness evaluation methods for the frequency statistics local differential privacy algorithm: input evaluation and output evaluation, both of which meet the "privacy-security consistency" requirement. Input evaluation is designed to evaluate the frequency distribution of user inputs in order to achieve the goal of fine-grained algorithm robustness evaluation. The publishing strategy of the local differential privacy algorithm for data streams is used by users, where named evaluation user, The input distribution of the local differential privacy algorithm for the remaining users at this timestamp is , among which Item is , then completing the fine-grained algorithm robustness evaluation at this timestamp is to solve the following optimization problem: in, is the input frequency distribution of the local differential privacy algorithm, the first The calculation is ,in Indicates that there are evaluation users The input value of the local differential privacy algorithm is ; At the same time, calculate the proximity distance of the input evaluation when the number of evaluation users is large enough ,in, Indicates that the privacy budget used is Frequency statistics local differential privacy algorithm for The error of frequency statistics of users; thus, The larger the number of users, the closer the distance The smaller it is, the more it meets the goal of robustness evaluation, that is, the evaluation shows "privacy and security consistency"; In the output evaluation, the user is evaluated to bypass the local perturbation of the local differential privacy algorithm and send data directly to the server to achieve the effect of fine-grained algorithm robustness evaluation; in order to make the release frequency close to the target frequency, that is, to minimize , the evaluator minimizes its upper bound implementation, where is the release frequency distribution of the local differential privacy algorithm: in are the parameters of the local differential privacy algorithm, Indicates that there is The value sent to the server by the evaluation user is ; When there are enough evaluation users, the evaluation proximity distance is output ,in is a constant ;akin, The larger the number of users, the closer the distance The smaller it is, the more it meets the goal of robustness evaluation, that is, the evaluation shows "privacy-security consistency".

7. A robustness evaluation system for a data stream local differential privacy algorithm, characterized in that: include: Selection module, used for evaluation preparation and selection of branching strategies; At each timestamp, the evaluator first sets the target frequency for the timestamp. And from the total Select a user users as evaluation users, The users are the remaining users; at the same time, the evaluator calculates the privacy budget used by the server to publish the policy at this timestamp from the evaluated users. And the number of users sampled by the server at that timestamp for publishing policies ,in The number of users sampled at this timestamp for evaluating the release strategy. is the number of remaining users sampled for the release strategy at this timestamp. To achieve the goal of robustness evaluation, the evaluator will calculate the proximity between the release frequency of the data stream local differential privacy algorithm entering the release strategy and the approximate strategy and the evaluation target frequency, and determine which strategy the algorithm enters at this timestamp to minimize the proximity distance. The first evaluation module is used to evaluate the dissimilarity calculation module of the local differential privacy algorithm for data streams; According to the judgment rules of the selection module, the evaluator can determine which strategy the timestamp makes the data stream local differential privacy algorithm enter to minimize the proximity distance. If the approximate strategy can minimize the proximity distance, the evaluator will minimize the dissimilarity. , so that the algorithm enters the approximate strategy; otherwise, the evaluation side will maximize , which enables the algorithm to enter the release strategy; The second evaluation module is a fine-grained algorithm robustness evaluation of the frequency statistics local differential privacy algorithm; According to the first evaluation module, the maximum or minimum Based on the judgment, the evaluator will perform different operations to meet the fine-grained algorithm robustness evaluation, that is, change the release frequency of the data stream local differential privacy algorithm as much as possible to make it close to the evaluation target frequency; when the evaluator chooses to maximize the dissimilarity, the data stream local differential privacy algorithm will enter the release strategy and use the frequency statistics local differential privacy algorithm for frequency statistics and release; the evaluator needs to carry out a fine-grained algorithm robustness evaluation for the frequency statistics local differential privacy algorithm to make its release frequency distribution close to the evaluation target frequency distribution; otherwise, when the evaluator chooses to minimize the dissimilarity, the data stream local differential privacy algorithm will enter the approximate strategy and directly use the release frequency of the previous timestamp as the release frequency of this timestamp, so the evaluator does not need to perform additional operations.

8. The robustness evaluation system for a data stream local differential privacy algorithm according to claim 7, characterized in that: In the selection module, the evaluator determines which strategy the algorithm enters at the timestamp based on the calculated frequency of the release strategy or approximate strategy entered by the local differential privacy algorithm of the data stream and the proximity of the evaluation target frequency, including: The calculation data stream local differential privacy algorithm enters the approximate strategy close distance is ,in, is the publishing frequency of the previous timestamp, is the target frequency for evaluation at that timestamp, The size of the field for user input; The average distance between the local differential privacy algorithm of data stream and the release strategy is calculated as ,in, It represents the algorithm release frequency after performing fine-grained algorithm robustness evaluation on the frequency statistics of the local differential privacy algorithm for the release strategy; Comparing the close distance of the control data flow local differential privacy algorithm into the approximate strategy and proximity to entry release strategy ,if If the value is smaller, the evaluator hopes that the data stream local differential privacy algorithm will enter the approximate strategy; otherwise, the evaluator hopes that the data stream local differential privacy algorithm will enter the release strategy.

9. The robustness evaluation system for a data stream local differential privacy algorithm according to claim 8, characterized in that: The evaluation methods for the data stream local differential privacy algorithm dissimilarity calculation module in the first evaluation module are divided into two types, including input evaluation and output evaluation; Input evaluation refers to the design of input data for evaluating the user's local differential privacy algorithm to influence the calculation mechanism of dissimilarity to evaluate the robustness of the algorithm; assuming that there are Users are used to calculate the dissimilarity of the data stream local differential privacy algorithm, where named evaluation user, The input distribution of the residual user’s local differential privacy algorithm is , among which Item is , then maximizing or minimizing the dissimilarity is to solve the following optimization problem: in, is the input frequency distribution of the local differential privacy algorithm, and the evaluator maximizes or minimizes it by influencing the frequency distribution The goal of this frequency distribution is item Calculated as ,in Indicates that there are evaluation users The input value of the local differential privacy algorithm is ; Output evaluation means that the evaluator bypasses the local perturbation step of the local differential privacy algorithm and directly sends the calculated data to the server to affect the calculation of dissimilarity, so as to achieve the purpose of testing the robustness of the algorithm; minimizing dissimilarity, that is, minimizing When the evaluator minimizes its upper bound implementation, where is the release frequency distribution of the local differential privacy algorithm: in are the parameters of the local differential privacy algorithm, Indicates that there is The value sent to the server by the evaluation user is ; When maximizing the dissimilarity, the evaluator first calculates , maximizing the dissimilarity is to make , , that is, use all evaluation users to send to the server This can achieve the goal of maximizing the dissimilarity.

10. The robustness evaluation system for a data stream local differential privacy algorithm according to claim 9, characterized in that: The second evaluation module uses two fine-grained robustness evaluation methods for the frequency-based local differential privacy algorithm: input evaluation and output evaluation, both of which meet the "privacy-security consistency" requirement. Input evaluation is designed to evaluate the frequency distribution of user inputs in order to achieve the goal of fine-grained algorithm robustness evaluation. The publishing strategy of the local differential privacy algorithm for data streams is used by users, where named evaluation user, The input distribution of the local differential privacy algorithm for the remaining users at this timestamp is , among which Item is , then completing the fine-grained algorithm robustness evaluation at this timestamp is to solve the following optimization problem: in, is the input frequency distribution of the local differential privacy algorithm, the first The calculation is ,in Indicates that there are evaluation users The input value of the local differential privacy algorithm is ; At the same time, calculate the proximity distance of the input evaluation when the number of evaluation users is large enough ,in, Indicates that the privacy budget used is Frequency statistics local differential privacy algorithm for The error of frequency statistics of users; thus, The larger the number of users, the closer the distance The smaller it is, the more it meets the goal of robustness evaluation, that is, the evaluation shows "privacy and security consistency"; In the output evaluation, the user is evaluated to bypass the local perturbation of the local differential privacy algorithm and send data directly to the server to achieve the effect of fine-grained algorithm robustness evaluation; in order to make the release frequency close to the target frequency, that is, to minimize , the evaluator minimizes its upper bound implementation, where is the release frequency distribution of the local differential privacy algorithm: in are the parameters of the local differential privacy algorithm, Indicates that there is The value sent to the server by the evaluation user is ; When there are enough evaluation users, the evaluation proximity distance is output ,in is a constant ;akin, The larger the number of users, the closer the distance The smaller it is, the more it meets the goal of robustness evaluation, that is, the evaluation shows "privacy-security consistency".

Citation Information

Patent Citations

  • Infinite data flow real-time privacy protection method and system based on dynamic budget allocation

    CN114417423A

  • Localized differential privacy protection method based on self-adaption high-dimensional data

    CN116340992A