Two-Party Decision Tree Model Privacy Prediction Method and System Based on Homomorphic Encryption Nesting

Through the nested two-party decision tree model of homomorphic encryption, it achieves efficient inference performance while protecting data privacy, solving the problems of privacy leakage and performance trade-offs in the existing technology, and is suitable for real-time applications and multi-party collaboration scenarios.

CN119760752BActive Publication Date: 2025-07-08SHANDONG UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510258125.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-07-08
Estimated Expiration
2045-03-06

AI Technical Summary

Technical Problem

The existing technology has the risk of privacy leakage in decision tree reasoning services. Traditional privacy protection methods have trade-offs on performance and computing communication overhead, and relying on third-party trust brings security risks and additional costs, which cannot meet the needs of real-time application and flexibility.

Method used

The two-party decision tree model with homomorphic encryption is adopted to ensure the privacy protection of data and models while maintaining efficiency through direct interaction between the model provider and the data owner.

Benefits of technology

It realizes the ability to provide efficient inference performance while protecting data privacy, eliminates dependence on third-party trust, adapts to more practical application scenarios, simplifies interaction strategies, and is suitable for real-time applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119760752B_ABST
    Figure CN119760752B_ABST
Patent Text Reader

Abstract

The present invention discloses a privacy prediction method and system for a two-party decision tree model based on homomorphic encryption nesting, belonging to the technical field of homomorphic encryption. The data owner traverses the encrypted model initially encrypted by the model provider according to the prediction sample set, and shuffles the path based on the comparison result between the preset threshold and the eigenvalue, generates an encrypted path set and transmits it to the model provider; the model provider evaluates the path based on the encrypted path set, converts the encrypted path into a ciphertext state based on the evaluation result and sends it to the data owner; the data owner calculates the weight according to the path evaluation result of the ciphertext state path, generates a ciphertext prediction result in combination with the secrecy requirement of the prediction result and sends it to the model provider, thereby ensuring the privacy protection of the model and data while maintaining high efficiency; and solves the problems of large privacy protection communication and computational overhead in the prior art.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of homomorphic encryption technology, and particularly to a privacy prediction method and system based on a two-party decision tree model. Background Art

[0002] The statements in this section only mention the background art related to the present invention and do not necessarily constitute prior art.

[0003] With the popularization of machine learning inference services, decision tree models play an important role in multiple fields because they can make decisions in a structured and interpretable way. A decision tree divides data into multiple branches according to specific conditions, forming a flowchart-like structure that guides decisions from the root node to the leaf nodes. In a decision tree inference service, the provider has a trained machine learning model, and the customer submits data to obtain prediction results, which involves both the privacy of the model itself and the privacy of the input data.

[0004] However, these decision tree inference services also bring risks of privacy leakage. Once the model information is leaked, significant losses will be caused. At the same time, the data involved in decision tree inference services often contains sensitive personal information. Data owners are usually interested in obtaining service results while hoping to ensure that model providers cannot access their data.

[0005] In a typical service center privacy protection decision tree framework, there are mainly two computing entities, including a model provider who has a trained model and a data owner; traditional privacy protection methods have an obvious trade-off between privacy protection and performance, especially in a large-scale distributed environment, where the computational and communication overheads are too large, resulting in limited real-time inference in practical applications.

[0006] In addition, traditional service-centered models limit the flexibility of decision tree inference. When deploying decision tree services between different companies, the goals of each party are usually different. For example, for a model provider, it hopes to continuously obtain data through inference results to support decision-making or optimize its model performance; at the same time, the amount of data of the data owner steadily increases over time.

[0007] With the powerful computing and storage capabilities of cloud computing, cloud-based outsourcing frameworks have become the main design choice. One of the main advantages of introducing a third party is to simplify the design of privacy protection protocols. For example, if the third party does not understand the decision tree model, the data can be utilized more effectively to prevent the third party from obtaining privacy information through the data.

[0008] However, relying on a trusted (at least semi - honest) third party introduces important security assumptions. Although using a trusted third party simplifies some aspects of the framework, it also brings many problems. To guard against attacks from malicious adversaries, there are often significant performance trade - offs in the design, and these protocols are also vulnerable to collision attacks. In addition, relying on a third party may affect the real - time cooperation between the model provider and the data owner.

[0009] To provide the service, they first need to identify a trusted third party that can perform the necessary computing and communication tasks and install the required software. Hiring a third party usually also incurs additional financial costs. Moreover, frameworks relying on third - party services have potential risks in privacy protection and cannot meet the data privacy requirements in some specific application scenarios. Summary of the Invention

[0010] To address the deficiencies of the prior art, the present invention provides a privacy prediction method, system, electronic device, computer - readable storage medium, and computer program product for a two - party decision tree model based on homomorphic encryption nesting, which allows direct interaction between the model provider and the data owner, and uses homomorphic encryption and model obfuscation techniques to ensure the privacy protection of the model and data while maintaining high efficiency.

[0011] In a first aspect, the present invention provides a privacy prediction method for a two - party decision tree model based on homomorphic encryption nesting;

[0012] A privacy prediction method for a two - party decision tree model based on homomorphic encryption nesting includes:

[0013] The model provider performs an obfuscation operation and homomorphic encryption on the decision tree model, obtains the encrypted model, and transmits it to the data owner;

[0014] The data owner traverses the encrypted model according to the prediction sample set and shuffles the path based on the comparison result between the preset threshold and the feature value, generates an encrypted path set, and transmits it to the model provider;

[0015] The model provider performs path evaluation based on the encrypted path set, converts the encrypted path to ciphertext state based on the evaluation result, and sends it to the data owner;

[0016] The data owner calculates the weight according to the path evaluation result of the ciphertext - state path, generates a ciphertext prediction result in combination with the secrecy requirement of the prediction result, and sends it to the model provider. The model provider decrypts the ciphertext prediction result to obtain the real prediction result.

[0017] In some embodiments, the specific operation of performing the obfuscation operation on the decision tree model is: randomly rotating the nodes in the decision tree model and inserting virtual nodes and virtual trees into the decision tree model.

[0018] In some embodiments, the decision tree model performs homomorphic encryption specifically as follows: different homomorphic encryption schemes are used to encrypt the thresholds and leaf node weights in the decision tree model.

[0019] In some embodiments, the step of traversing the encrypted model according to the prediction sample set and shuffling the path based on the comparison result between the preset threshold and the feature value to generate an encrypted path set specifically includes:

[0020] Based on the prediction samples in the prediction sample set, traverse the encrypted model from the root node to the leaf node. During the traversal process, compare the feature value corresponding to each intermediate node with the preset threshold, and replace the intermediate node based on the comparison result.

[0021] In some embodiments, the step of performing path evaluation based on the encrypted path set and converting the encrypted path into a ciphertext state based on the evaluation result specifically includes:

[0022] Evaluate each encrypted path in the encrypted path set. If each node in the encrypted path is correct, convert the node into the first ciphertext state; otherwise, convert it into the second ciphertext state.

[0023] In some embodiments, the step of calculating weights according to the path evaluation result of the ciphertext state path and generating a ciphertext prediction result in combination with the confidentiality requirement of the prediction result specifically includes:

[0024] Calculate weights according to the path evaluation result corresponding to the ciphertext state path and the ciphertext state, obtain the confidentiality requirement of the prediction result of the data provider, and determine whether to perform masking processing on the calculation result according to the confidentiality requirement of the prediction result to generate a ciphertext prediction result.

[0025] In a second aspect, the present invention provides a two-party decision tree model privacy prediction system based on homomorphic encryption nesting;

[0026] A two-party decision tree model privacy prediction system based on homomorphic encryption nesting includes a model provider and a data owner;

[0027] The model provider performs a confusion operation and homomorphic encryption on the decision tree model, obtains the encrypted model, and transmits it to the data owner;

[0028] The data owner traverses the encrypted model according to the prediction sample set and shuffles the path based on the comparison result between the preset threshold and the feature value, generates an encrypted path set, and transmits it to the model provider;

[0029] The model provider performs path evaluation based on the encrypted path set, converts the encrypted path into a ciphertext state based on the evaluation result, and sends it to the data owner;

[0030] The data owner calculates weights based on the path evaluation results of the ciphertext state paths, generates ciphertext prediction results in combination with the confidentiality requirements of the prediction results, and sends them to the model provider. The model provider decrypts the ciphertext prediction results to obtain the true prediction results.

[0031] In some embodiments, the specific process of traversing the encryption model according to the prediction sample set and shuffling the paths based on the comparison results between the preset threshold and the eigenvalue to generate an encryption path set is as follows:

[0032] Based on the prediction samples in the prediction sample set, traverse the encryption model from the root node to the leaf node. During the traversal process, compare the eigenvalue corresponding to each intermediate node with the preset threshold, and replace the intermediate node based on the comparison result.

[0033] In some embodiments, the specific process of performing path evaluation based on the encryption path set and converting the encryption path into the ciphertext state based on the evaluation results is as follows:

[0034] Evaluate each encryption path in the encryption path set. If each node in the encryption path is correct, convert the node into the first ciphertext state; otherwise, convert it into the second ciphertext state.

[0035] In some embodiments, the specific process of calculating weights according to the path evaluation results of the ciphertext state paths and generating ciphertext prediction results in combination with the confidentiality requirements of the prediction results is as follows:

[0036] Calculate weights based on the path evaluation results and the ciphertext state corresponding to the ciphertext state paths, obtain the confidentiality requirements of the prediction results of the data provider, and determine whether to perform masking processing on the calculation results according to the confidentiality requirements of the prediction results to generate ciphertext prediction results.

[0037] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0038] 1. The technical solution provided by the present invention can ensure high - efficient inference performance while protecting data privacy through innovative data encryption and distributed cooperation technologies, and at the same time eliminates the dependence on the trust of third parties, adapting to more practical application scenarios.

[0039] 2. The technical solution provided by the present invention implements a simplified interaction strategy, allows direct interaction between the model provider and the data owner, performs preliminary encryption through the data provider method, effectively shares the computing burden, and is applicable to real - time application scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] The accompanying drawings forming a part of the present invention are used to provide a further understanding of the present invention. The schematic embodiments and descriptions thereof of the present invention are used to explain the present invention and do not constitute an improper limitation to the present invention.

[0041] Figure 1 It is a schematic flowchart of a two-party decision tree model privacy prediction method based on homomorphic encryption nesting provided by an embodiment of the present invention;

[0042] Figure 2 It is an example diagram of node right rotation provided by an embodiment of the present invention. Detailed implementation manners

[0043] It should be noted that the following detailed descriptions are all exemplary and are intended to provide further descriptions of the present invention. Unless otherwise specified, all technical and scientific terms used in the present invention have the same meanings as those commonly understood by those of ordinary skill in the technical field to which the present invention belongs.

[0044] It should be noted that the terms used herein are only for describing specific implementation manners and are not intended to limit the exemplary embodiments according to the present invention. As used herein, unless otherwise clearly specified in the context, the singular forms are also intended to include the plural forms. In addition, it should be understood that the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0045] In the case of no conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.

[0046] Embodiment 1

[0047] The computational overhead and communication overhead of the existing privacy protection methods in decision tree reasoning are too large, affecting the real-time performance in its actual application to prediction; therefore, the present invention provides a two-party decision tree model privacy prediction method based on homomorphic encryption nesting, which uses the direct interaction between the model provider and the data owner, and through homomorphic encryption and model obfuscation technologies, ensures the privacy security of data and models.

[0048] Next, in combination with Figure 1 - Figure 2 , a two-party decision tree model privacy prediction method based on homomorphic encryption nesting disclosed in this embodiment will be described in detail. The two-party decision tree model privacy prediction method based on homomorphic encryption nesting includes the following steps:

[0049] S1. The model provider and the data owner confirm their willingness to cooperate and negotiate global security parameters.

[0050] Among them, the global security parameters include the homomorphic encryption algorithm combination, key length, etc., which are used to perform homomorphic encryption on the decision tree model subsequently; negotiating the global security parameters means that the model provider and the data owner determine the parameters such as the homomorphic encryption algorithm combination and key length for subsequent applications.

[0051] S2. The model provider performs obfuscation operations and homomorphic encryption on the decision tree model, obtains the encrypted model, and transmits it to the data owner.

[0052] As an implementation manner, S2 specifically includes:

[0053] S201. The model provider randomly rotates the nodes in the decision tree model through a rotation algorithm, and inserts virtual nodes and virtual trees into the decision tree model after the random rotation is completed.

[0054] Exemplarily, let represent an intermediate node, let represent its left child node, and let represent its right child node. , is also an intermediate node; the specific process of performing a right rotation operation on the decision tree model through the rotation algorithm is described in detail as follows:

[0055] (1) Disconnect the connection between and . Let represent the subtree with as the root at this time, let represent the left subtree of , and let represent the right subtree of . Replace the two child nodes of , that is, its corresponding left subtree and right subtree, with .

[0056] (2) Replace the left child nodes of the child nodes in with and respectively.

[0057] Similarly, the specific process of performing a left rotation operation on the decision tree model through the rotation algorithm is as follows:

[0058] (a) Disconnect the connection between and . Let represent the subtree with as the root at this time, let represent the left subtree of , and let represent the right subtree of . Replace the two child nodes of The two child nodes, i.e., its corresponding left subtree and right subtree, are replaced with .

[0059] (b)Replace the right child nodes of the child nodes in with and respectively.

[0060] Based on this, by randomly rotating nodes in the decision tree, while keeping the decision logic behavior of the decision tree model unchanged, the tree structure of the decision tree model is confused and the order of feature comparison is disrupted, which helps to improve the privacy and security of prediction.

[0061] Subsequently, insert virtual nodes into the decision tree model after random rotation; the steps for inserting virtual nodes are as follows:

[0062] Step 1. Find two thresholds and in the sample space, satisfying . Here, represents any feature value that may appear in the sample space; can be selected as the minimum value in the sample space; can be selected as the maximum value in the sample space.

[0063] Here, the sample space refers to the data sample space supported by this decision tree model.

[0064] Step 2. Randomly select a node in the tree, and let the subtree rooted at this node be , and replace it with a virtual node , which has a random feature index and threshold or .

[0065] Step 3. If the threshold of the virtual node is , then set its right child node to , and set the left child node to a randomly generated subtree; if the threshold of the virtual node is , then perform the opposite operation.

[0066] After that, insert virtual trees into the decision tree model with virtual nodes inserted and disrupt the order of the tree. The steps for inserting virtual trees are as follows:

[0067] Step (1) Assume that virtual trees are to be inserted, and construct an array , satisfying .

[0068] Step (2) Randomly generate A tree, each tree contains only one correct path, and set the weight of the th tree to , and set other parameters randomly.

[0069] Here, by setting the threshold to or , it can be achieved that each tree contains only one correct path. The method is as follows: Set the threshold of all edges extending to the left on only one path to , and the threshold of the edges extending to the right to . Only the paths that meet this condition are correct paths, and at least one edge of other paths violates this principle.

[0070] Step (3) inserts the generated virtual tree into the original tree.

[0071] S202. The model provider homomorphically encrypts the decision tree model inserted with the virtual tree through two sets of homomorphic encryption schemes.

[0072] Specifically, first, the model provider initializes two sets of homomorphic encryption schemes, denoted as and respectively. Here, represents the encryption algorithm corresponding to the first set of homomorphic encryption schemes, represents the decryption algorithm corresponding to the first set of homomorphic encryption schemes, represents the encryption algorithm corresponding to the second set of homomorphic encryption schemes, represents the decryption algorithm corresponding to the second set of homomorphic encryption schemes, represents the public key corresponding to the second set of homomorphic encryption schemes, represents the private key corresponding to the second set of homomorphic encryption schemes.

[0073] Here, since 's encryption key will not be shared with any other party, its encryption key is omitted here.

[0074] In this embodiment, the encryption and decryption algorithms adopted by the first set of homomorphic encryption schemes can be Paillier, and the homomorphic encryption and decryption algorithms adopted by the second set of homomorphic encryption schemes can be RLWE.

[0075] Then, the model provider encrypts the thresholds and leaf node weights in the decision tree model through and in sequence.

[0076] Finally, the model provider publishes the encrypted tree (denoted as ), and the encryption parameters and and transmits the encrypted model to the data owner. This step realizes the following conversion:

[0077]

[0078] ;

[0079] Among them, represents the threshold of the j-th node in the i-th encrypted tree, represents the threshold of the j-th node in the i-th tree, represents the weight of the j-th node in the i-th encrypted tree, represents the weight of the j-th node in the i-th tree, , respectively represent the threshold and weight stored in the node.

[0080] S3. The data owner traverses the encrypted model according to the prediction sample set and shuffles the path based on the comparison result between the preset threshold and the feature value, generates an encrypted path set and transmits it to the model provider. Specifically, it includes:

[0081] S301. The data owner selects the samples to be predicted from the sample set it owns to obtain a prediction sample set.

[0082] Exemplarily, if the power grid is the model provider and the power plant station is the data owner, the sample set is a data sample including features such as wind power, water power, and time period. The purpose of the data owner is to predict the power generation power at a specific time point through the model of the model provider.

[0083] S302. For each prediction sample in the prediction sample set, the data owner inputs the prediction sample into the encrypted model, traverses all possible paths from the root node to the leaf node, and obtains a set of paths ; during the traversal process, the data owner replaces the intermediate node with the comparison result between the feature value corresponding to each intermediate node and the threshold.

[0084] Specifically, for the prediction sample , starting from the root node for path traversal, the data provider calculates the difference between the threshold corresponding to the intermediate node and the corresponding feature value, expressed as:

[0085] ;

[0086] Among them, represents a random positive value, represents the prediction sample at the feature value, represents the node stored feature, represents the node stored threshold.

[0087] Obviously, the positive or negative sign of the decryption result indicates whether the eigenvalue is greater than or less than the threshold. For each intermediate node in the path , if the node is the left child node of the parent node, the data provider replaces it with ; otherwise, it replaces it with , that is .

[0088] By adjusting the order of subtraction, the data owner ensures that all comparison results along the correct path are non-positive. After removing its root node, each path is represented as:

[0089] ;

[0090] wherein, represents the weight stored in the leaf node corresponding to this path, and d represents the path depth.

[0091] S4. The model provider performs path evaluation based on the encrypted path set, and converts the encrypted path into a ciphertext state based on the evaluation result and sends it to the data owner.

[0092] Specifically, after receiving the shuffled path set , the model provider evaluates each path ; for each path, if all in the path are non-positive, that is, it means that the corresponding comparison result of "branch to the left child node or the right child node" is correct, then it replaces it with ; otherwise, it replaces it with .

[0093] Thanks to the characteristics of the Paillier encryption system, the encryption of each value is randomized. Subsequently, the model provider sends the replaced set to the data owner.

[0094] S5. The data owner calculates the weight according to the path evaluation result of the ciphertext state path, and generates a ciphertext prediction result in combination with the prediction result confidentiality requirement and sends it to the model provider.

[0095] Specifically, after receiving , the data owner performs a multiplication operation on each path , which is expressed as:

[0096] ;

[0097] In this multiplication operation, is regarded as a scalar, while represents the replaced path , the intermediate nodes in the path have been replaced with or , that is, this operation can be regarded as a ciphertext-scalar multiplication under the first set of homomorphic encryption schemes.

[0098] Next, the data owner sums up all the results to obtain:

[0099] .

[0100] Furthermore, according to the characteristics and design of the decision tree model, only the correct path in is replaced with , while the wrong path is replaced with . Therefore, the calculation result is expressed as:

[0101] ;

[0102] where represents the weight in the wrong path, represents the weight in the correct path, represents the expected prediction result.

[0103] Furthermore, if the task requires the prediction result to be disclosed to the model provider, then is sent to the model provider; otherwise, if the prediction result should be kept confidential from the data owner, the data owner randomly selects a mask , and calculates , because is known to the data owner. Then, the data owner adds in the following way:

[0104] ;

[0105] where represents the ciphertext-scalar addition performed on , and the generation of noise comes from linear transformation.

[0106] S6. The model provider decrypts the ciphertext prediction result to obtain the true prediction result.

[0107] Specifically, after receiving , the model provider calculates the prediction result in plaintext format:

[0108] .

[0109] Furthermore, if the prediction result needs to be disclosed to the data owner, this means has been masked, and the model provider will Send it to the data owner, who will remove the previously added mask to obtain the true prediction result.

[0110] Embodiment 2

[0111] Based on the two-party decision tree model privacy prediction method based on homomorphic encryption nesting described in Embodiment 1, this embodiment discloses a two-party decision tree model privacy prediction system based on homomorphic encryption nesting, including a model provider and a data owner;

[0112] The model provider performs a confusion operation and homomorphic encryption on the decision tree model, obtains the encrypted model and transmits it to the data owner;

[0113] The data owner traverses the encrypted model according to the prediction sample set and shuffles the path based on the comparison result between the preset threshold and the feature value, generates an encrypted path set and transmits it to the model provider;

[0114] The model provider performs path evaluation based on the encrypted path set, converts the encrypted path into ciphertext state based on the evaluation result and sends it to the data owner;

[0115] The data owner calculates the weight according to the path evaluation result of the ciphertext state path, generates a ciphertext prediction result in combination with the confidentiality requirement of the prediction result and sends it to the model provider, and the model provider decrypts the ciphertext prediction result to obtain the true prediction result.

[0116] In the above embodiments, the descriptions of each embodiment have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0117] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A privacy prediction method for a two-party decision tree model based on homomorphic encryption nesting, characterized in that, Including: The model provider performs a confusion operation and homomorphic encryption on the decision tree model, obtains the encrypted model, and transmits it to the data owner; The data owner traverses the encrypted model according to the prediction sample set and shuffles the path based on the comparison result between the preset threshold and the feature value, generates an encrypted path set, and transmits it to the model provider; The model provider performs path evaluation based on the encrypted path set, converts the encrypted path into a ciphertext state based on the evaluation result, and sends it to the data owner; The data owner calculates weights according to the path evaluation result of the ciphertext state path, generates a ciphertext prediction result in combination with the confidentiality requirement of the prediction result, and sends it to the model provider. The model provider decrypts the ciphertext prediction result to obtain the true prediction result.

2. The two-party decision tree model privacy prediction method based on homomorphic encryption nesting according to claim 1, characterized in that The specific operation of performing a confusion operation on the decision tree model is: randomly rotating the nodes in the decision tree model and inserting virtual nodes and virtual trees into the decision tree model.

3. The two-party decision tree model privacy prediction method based on homomorphic encryption nesting according to claim 1, characterized in that The specific operation of performing homomorphic encryption on the decision tree model is: encrypting the thresholds and leaf node weights in the decision tree model using different homomorphic encryption schemes.

4. The two-party decision tree model privacy prediction method based on homomorphic encryption nesting according to claim 1, characterized in that, The specific operation of traversing the encrypted model according to the prediction sample set and shuffling the path based on the comparison result between the preset threshold and the feature value to generate an encrypted path set is: Based on the prediction samples in the prediction sample set, traversing the encrypted model from the root node to the leaf node. During the traversal process, comparing the feature value corresponding to each intermediate node with the preset threshold, and replacing the intermediate node based on the comparison result.

5. The privacy prediction method for the two-party decision tree model based on homomorphic encryption nesting according to claim 1, wherein, The specific operation of performing path evaluation based on the encrypted path set and converting the encrypted path into a ciphertext state based on the evaluation result is: Evaluating each encrypted path in the encrypted path set. If each node in the encrypted path is correct, converting the node into the first ciphertext state; otherwise, converting it into the second ciphertext state.

6. The two-party decision tree model privacy prediction method based on homomorphic encryption nesting according to claim 1, characterized in that The specific operation of calculating weights according to the path evaluation result of the ciphertext state path and generating a ciphertext prediction result in combination with the confidentiality requirement of the prediction result is: Calculating weights according to the path evaluation result corresponding to the ciphertext state path and the ciphertext state, obtaining the confidentiality requirement of the prediction result of the data provider, and judging whether to perform mask processing on the calculation result to generate a ciphertext prediction result according to the confidentiality requirement of the prediction result.

7. A two-party decision tree model privacy prediction system based on homomorphic encryption nesting, characterized in that Including a model provider and a data owner; The model provider performs a confusion operation and homomorphic encryption on the decision tree model, obtains the encrypted model, and transmits it to the data owner; The data owner traverses the encrypted model according to the prediction sample set and shuffles the path based on the comparison result between the preset threshold and the feature value, generates an encrypted path set, and transmits it to the model provider; The model provider performs path evaluation based on the encrypted path set, converts the encrypted path into a ciphertext state based on the evaluation result, and sends it to the data owner; The data owner calculates weights according to the path evaluation result of the ciphertext state path, generates a ciphertext prediction result in combination with the confidentiality requirement of the prediction result, and sends it to the model provider. The model provider decrypts the ciphertext prediction result to obtain the true prediction result.

8. The two-party decision tree model privacy prediction system based on homomorphic encryption nesting according to claim 7, wherein Performing path traversal on the encryption model according to the prediction sample set and shuffling paths based on the comparison result between a preset threshold and a feature value to generate an encrypted path set specifically includes: Based on the prediction samples in the prediction sample set, performing path traversal on the encryption model from the root node to the leaf node. During the traversal process, comparing the feature value corresponding to each intermediate node with the preset threshold, and replacing the intermediate node based on the comparison result.

9. The two-party decision tree model privacy prediction system based on homomorphic encryption nesting according to claim 7, characterized in that Performing path evaluation based on the encrypted path set and converting the encrypted path into a ciphertext state based on the evaluation result specifically includes: Evaluating each encrypted path in the encrypted path set. If each node in the encrypted path is correct, converting the node into the first ciphertext state; otherwise, converting it into the second ciphertext state.

10. The two-party decision tree model privacy prediction system based on homomorphic encryption nesting according to claim 7, characterized in that, Calculating weights according to the path evaluation result of the ciphertext state path and generating a ciphertext prediction result in combination with the secrecy requirement of the prediction result specifically includes: Calculating weights according to the path evaluation result corresponding to the ciphertext state path and the ciphertext state, obtaining the secrecy requirement of the prediction result of the data provider, and judging whether to perform masking processing on the calculation result according to the secrecy requirement of the prediction result to generate a ciphertext prediction result.

Citation Information

Patent Citations

  • Privacy protection method for outsourcing reasoning of gradient boosting decision tree

    CN115967526A

  • Method and system for synchronizing data between trusted DCS (Distributed Control System) terminals

    CN119155305A