Data privacy protection method and device, equipment, storage medium and computer program product

By constructing an attack defense model based on publishing intent, efficiency maximization, and purchase history inference, the problem of insufficient privacy protection for data buyers is solved, and privacy security is guaranteed for data element buyers.

CN119808136BActive Publication Date: 2026-05-19CHINA MOBILE ZIJIN INNOVATION INST CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE ZIJIN INNOVATION INST CO LTD
Filing Date
2024-11-14
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing data privacy protection schemes mainly focus on protecting the privacy of data providers and data trading platforms, but do not address the privacy protection of data buyers, resulting in the risk of privacy leaks for data buyers.

Method used

By acquiring the purchase intent set published by data element buyers, determining the upper and lower bounds of confidence, establishing an attack model based on publishing intent, efficiency maximization, and purchase record inference, and constructing a uniform attack defense model, an efficiency maximization attack defense model, and a purchase record inference attack defense model to protect privacy.

Benefits of technology

It protects the privacy and security of data element purchasers and reduces the risk of privacy leaks for them.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119808136B_ABST
    Figure CN119808136B_ABST
Patent Text Reader

Abstract

The application discloses a data privacy protection method and device, equipment, a storage medium and a computer program product. The method comprises the following steps: determining an upper bound of confidence and a lower bound of confidence of a purchase intention set according to the number of real intentions included in the purchase intention set; establishing a publication intention-based attack model, an efficiency maximization attack model and a purchase record inference attack model for a data element purchaser based on the purchase intention set, the upper bound of confidence, the lower bound of confidence, data element background knowledge and the purchase record of the data element purchaser; constructing a uniform publication intention-based attack defense model, an efficiency maximization attack defense model and a purchase record inference attack defense model according to the attack models, and taking a confidence threshold as a constraint condition; and protecting the privacy of the data element purchaser according to the attack defense models, so that the privacy safety of the data element purchaser is ensured, and the risk of privacy leakage of the data element purchaser is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data security technology, and in particular to a data privacy protection method, apparatus, device, storage medium, and computer program product. Background Technology

[0002] Data has become the fifth major factor of production after land, labor, capital, and technology, serving as a fundamental resource and the core engine of the digital economy. The advent of the era of large-scale models further necessitates large-scale, high-quality, and diverse datasets to enhance model performance and generalization capabilities, highlighting the crucial role of data.

[0003] However, existing data privacy protection schemes mainly focus on protecting the privacy of data providers and data trading platforms, without addressing the privacy protection of data buyers, leaving data buyers at risk of privacy breaches. Summary of the Invention

[0004] The main purpose of this application is to provide a data privacy protection method, apparatus, device, storage medium, and computer program product, which aims to solve the technical problem that existing data privacy protection schemes mainly focus on protecting the privacy of data providers and data trading platforms, but do not address the privacy protection of data buyers, thus posing a risk of privacy leakage to data buyers.

[0005] To achieve the above objectives, this application provides a data privacy protection method, the data privacy protection method comprising:

[0006] Obtain a set of purchase intentions published by data element buyers, wherein the set of purchase intentions includes at least one genuine intention;

[0007] The upper and lower bounds of the confidence level of the purchase intent set are determined based on the number of genuine intents included in the purchase intent set.

[0008] Based on the purchase intent set, the upper confidence bound, the lower confidence bound, the background knowledge of the data elements, and the purchase records of the data element buyers, establish an attack model based on the release intent, an efficiency maximization attack model, and a purchase record inference attack model targeting the data element buyers.

[0009] Based on the attack model based on publishing intent, the efficiency maximization attack model, and the purchase record inference attack model, a uniform attack defense model based on publishing intent, an efficiency maximization attack defense model, and a purchase record inference attack defense model are constructed with confidence thresholds as constraints.

[0010] Privacy protection is provided for the data element purchasers based on the uniform attack defense model based on publishing intent, the efficiency maximization attack defense model, and the purchase record inference attack defense model.

[0011] Optionally, the step of protecting the privacy of the data element buyer based on the uniform attack defense model based on the publishing intent, the efficiency maximization attack defense model, and the purchase record inference attack defense model includes:

[0012] The purchase intent set is expanded to minimize the optimization problem in the uniform attack defense model based on release intent or the efficiency maximization attack defense model.

[0013] Based on the total number of data records that the data element buyer intends to purchase, a sample is taken to obtain the purchase data set corresponding to the data element buyer, so as to ensure that the purchase data set meets the privacy protection constraints corresponding to the purchase record inference attack defense model.

[0014] Optionally, expanding the purchase intent set to minimize the optimization problem in the uniform attack defense model based on release intent or the efficiency maximization attack defense model includes:

[0015] Set the purchase intent set to be the same as the actual intent, and in each iteration, traverse each dimension in the data space;

[0016] Search for optional neighborhood feature values ​​along the traversal dimension, and select the best neighborhood feature value from the optional neighborhood feature values;

[0017] After traversing each dimension, the best neighborhood feature value is added to the purchase intent set to minimize the optimization problem in the uniform attack defense model based on the release intent or the efficiency maximization attack defense model.

[0018] Optionally, the step of searching for optional neighborhood feature values ​​along the traversal dimension and selecting the best neighborhood feature value from the optional neighborhood feature values ​​includes:

[0019] The cumulative distance of feature values ​​is calculated as iterates through the dimensions, and the feature value with the shortest cumulative distance is selected as the optional neighborhood feature value.

[0020] Calculate the number of additional records for the optional neighborhood feature values, the incremental impact of privacy protection constraints, and the effectiveness score;

[0021] The optimal neighborhood feature value is selected from the optional neighborhood feature values ​​based on the number of additional records, the incremental impact of the privacy protection constraints, and the effectiveness score.

[0022] Optionally, the step of sampling based on the total number of data records to be purchased by the data element purchaser to obtain the purchase data set corresponding to the data element purchaser, to ensure that the purchase data set satisfies the privacy protection constraints corresponding to the purchase record inference attack defense model, includes:

[0023] A data set is generated by randomly sampling the total number of data records that the data element buyer intends to purchase, and data sets that do not meet the privacy protection constraints are removed.

[0024] Calculate the utilization rate of the remaining dataset and select the remaining dataset with the highest utilization rate as the purchase dataset.

[0025] Optionally, the step of sampling based on the total number of data records to be purchased by the data element purchaser to obtain the purchase data set corresponding to the data element purchaser, to ensure that the purchase data set satisfies the privacy protection constraints corresponding to the purchase record inference attack defense model, includes:

[0026] The total number of data records that the data element buyer wants to purchase is initialized into a purchase data set through distribution sampling based on the total number of data records that the buyer wants to purchase.

[0027] The initialized dataset is processed by adding or deleting data, and the processed dataset is checked to see if it meets the privacy protection constraints.

[0028] If the privacy protection constraints are met, the acceptance probability of the processed dataset is calculated.

[0029] The decision on whether to select the processed dataset as the purchase dataset is based on the acceptance probability.

[0030] Furthermore, to achieve the above objectives, this application also proposes a data privacy protection device, which includes:

[0031] The intent acquisition module is used to acquire a set of purchase intents published by data element buyers, wherein the set of purchase intents includes at least one genuine intent.

[0032] The boundary determination module is used to determine the upper bound and lower bound of the confidence level of the purchase intent set based on the number of genuine intents included in the purchase intent set;

[0033] The model building module is used to build an attack model based on the purchase intent set, the upper confidence bound, the lower confidence bound, the background knowledge of the data elements, and the purchase records of the data element buyers, targeting the data element buyers based on the release intent, the efficiency maximization attack model, and the purchase record inference attack model.

[0034] The model building module is also used to construct a uniform attack defense model based on publishing intent, an efficiency maximization attack defense model, and a purchase record inference attack defense model based on confidence thresholds, according to the attack model based on publishing intent, the efficiency maximization attack model, and the purchase record inference attack model.

[0035] The privacy protection module is used to protect the privacy of the data element purchaser based on the uniform attack defense model based on the publishing intent, the efficiency maximization attack defense model, and the purchase record inference attack defense model.

[0036] In addition, to achieve the above objectives, this application also proposes a data privacy protection device, which includes a memory, a processor, and a data privacy protection program stored in the memory and executable on the processor, the data privacy protection program being configured to implement the data privacy protection method as described above.

[0037] In addition, to achieve the above objectives, this application also proposes a storage medium storing a data privacy protection program, which, when executed by a processor, implements the data privacy protection method as described above.

[0038] In addition, to achieve the above objectives, this application also provides a computer program product, which includes a data privacy protection program that, when executed by a processor, implements the data privacy protection method as described above.

[0039] One or more technical solutions proposed in this application have at least the following technical effects:

[0040] This application discloses a method for obtaining purchase intent sets published by data element buyers. These purchase intent sets include at least one genuine intent. An upper and lower confidence bound for the purchase intent set are determined based on the number of genuine intents included. Based on the purchase intent set, the upper and lower confidence bounds, background knowledge of the data elements, and the purchase records of the data element buyers, attack models based on publishing intent, efficiency maximization, and purchase record inference are established. Based on these attack models, a uniform attack defense model, an efficiency maximization attack defense model, and a purchase record inference attack defense model are constructed, constrained by a confidence threshold. Privacy protection for data element buyers is achieved using these models. Because this application considers various background knowledge that attackers might exploit, it models the privacy protection of data element buyers in data circulation transactions to address the aforementioned problems, thereby ensuring the privacy security of data element buyers and reducing the risk of privacy leakage. Attached Figure Description

[0041] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0042] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0043] Figure 1 This is a flowchart illustrating the first embodiment of the data privacy protection method of this application;

[0044] Figure 2 This is a flowchart illustrating the second embodiment of the data privacy protection method of this application;

[0045] Figure 3 This is a flowchart illustrating the third embodiment of the data privacy protection method of this application;

[0046] Figure 4 This is a flowchart of a uniform attack / efficiency maximization attack defense algorithm based on publishing intent, according to an embodiment of the data privacy protection method of this application.

[0047] Figure 5 This is a schematic diagram of extended feature values ​​on the horizontal axis according to an embodiment of the data privacy protection method of this application;

[0048] Figure 6 This is a flowchart of a Monte Carlo simulation algorithm according to an embodiment of the data privacy protection method of this application;

[0049] Figure 7 This is a flowchart of the Markov chain Monte Carlo algorithm according to an embodiment of the data privacy protection method of this application;

[0050] Figure 8 This is a schematic diagram of the module structure of the data privacy protection device in an embodiment of this application;

[0051] Figure 9 This is a schematic diagram of the device structure of the hardware operating environment involved in the data privacy protection method in this application embodiment.

[0052] The realization of the purpose, functional features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0053] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.

[0054] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.

[0055] Currently, data has become the fifth major factor of production after land, labor, capital, and technology, becoming a fundamental resource and the core engine of digital economic development. Especially with the advent of the era of large-scale models, there is an even greater need for large-scale, high-quality, and diverse datasets to improve model performance and generalization capabilities, further highlighting the importance of data as a key factor.

[0056] Today, big data applications and services rely heavily on data from multiple sources. Whether in popular fields like big data mining, data science, or artificial intelligence, there is a strong demand for diverse data sources, especially for the secondary use of data. The data marketplace, as an online platform, connects data providers and users, promoting the discovery, exchange, sharing, and integration of data resources.

[0057] Privacy and its protection are particularly important in the data circulation market because data transactions can potentially expose the privacy of all parties involved. Broadly speaking, privacy protection refers to the ability of an individual or group to prevent their information from being identified or accessed without authorization. Data providers face privacy risks; for example, hospitals possess valuable medical data that medical device companies may need. Even if hospitals can protect individual identity security while collecting and anonymizing patient treatment data, buyers may still obtain information about the success rate of treatment for specific diseases when this data is offered in the data market, potentially exposing the hospital's privacy. Furthermore, data transactions can also involve third-party privacy breaches, namely the privacy breaches of the providers of data trading platforms. For example, companies providing machine learning model building services to data buyers may face the risk of model theft, which also infringes on the company's privacy. However, current research and technology on privacy protection in data transactions largely focus on protecting the privacy of data providers and data trading platforms, while the privacy of buyers is often neglected. In reality, information such as the buyer's identity, purchase location and time, purchased products, price, and quantity can all be accidentally leaked during the transaction. Frequent customer information leaks on e-commerce platforms highlight the urgency of protecting buyer privacy.

[0058] Privacy protection has become a critical technology area, involving a variety of innovative methods and patents. These technologies include privacy-preserving computation techniques, such as homomorphic encryption, secure multi-party computation, and federated learning, which enable analysis and collaborative computation without exposing the original details of data. Data anonymization and de-identification techniques, such as K-anonymization and L-diversity algorithms, achieve privacy protection by obfuscating personal information. Blockchain technology is also being used to build transparent and secure data exchange platforms, combined with smart contracts and zero-knowledge proofs to enhance privacy protection. Furthermore, data watermarking and traceability technologies ensure transparency regarding data copyright and dissemination paths, while hardware and software integrated solutions, such as dedicated cryptographic processors and secure enclaves, improve the efficiency of privacy-preserving computation.

[0059] For example, related technologies propose a method and system for protecting privacy in big data transactions. Through firewall isolation, homomorphic encryption, data anonymization, and blockchain notarization, effective protection of data privacy for both buyers and sellers is achieved during the transaction process. Buyers request data samples through trial order requests for fusion experiments, confirming their needs before purchasing the big data. Sellers, on the other hand, use blockchain to notarize and encrypt the big data before transmission. The server ultimately delivers the computational results based on the big data using federated learning technology.

[0060] Related technologies also propose a blockchain-based method for data circulation and privacy protection, involving steps such as calculating the asymmetric key of the data user, obtaining file data and file keywords, calculating the ciphertext of the file data and the ciphertext of the keyword index, and determining access permissions, in order to achieve secure data circulation and privacy protection. However, using asymmetric key encryption may introduce a high computational load, affecting data circulation efficiency, especially with large data volumes, where the encryption and decryption processes may become bottlenecks.

[0061] The related technologies also propose a secure and compliant method for protecting personal data privacy, which uses differential privacy algorithms, chaotic asymmetric encryption algorithms, and multi-source heterogeneous data governance technologies to achieve multi-layered encryption protection of data.

[0062] However, relevant data privacy protection schemes mainly focus on protecting the privacy of data providers and data trading platforms, without addressing the privacy protection of data buyers, leaving data buyers at risk of privacy leaks.

[0063] Therefore, to overcome the above-mentioned deficiencies, this application provides a solution comprising: obtaining a set of purchase intentions published by data element buyers, wherein the set of purchase intentions includes at least one genuine intention; determining an upper and lower confidence limit for the purchase intention set based on the number of genuine intentions included in the purchase intention set; establishing an attack model based on the published intention, an efficiency maximization attack model, and a purchase record inference attack model targeting data element buyers based on the purchase intention set, the upper and lower confidence limits, background knowledge of data elements, and purchase records of data element buyers; constructing a uniform attack defense model based on the published intention, the efficiency maximization attack model, and the purchase record inference attack model, with a confidence threshold as a constraint, using the uniform attack defense model based on the published intention, the efficiency maximization attack model, and the purchase record inference attack model, and performing privacy protection for data element buyers based on the uniform attack defense model based on the published intention, the efficiency maximization attack defense model, and the purchase record inference attack defense model; and providing privacy protection for data element buyers based on the uniform attack defense model based on the published intention, the efficiency maximization attack defense model, and the purchase record inference attack defense model. Since this application considers various background knowledge that attackers may exploit, it models the problem of privacy protection for data element buyers in data circulation transactions to solve the above-mentioned problems, thereby ensuring the privacy security of data element buyers and reducing the risk of privacy leakage for data element buyers.

[0064] It should be noted that the executing entity in this embodiment may be a data privacy protection device with data processing, network communication and program running functions, such as a server, or other electronic devices that can achieve the same or similar functions. This embodiment does not limit this.

[0065] Based on this, the embodiments of this application provide a data privacy protection method, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the data privacy protection method of this application.

[0066] In the first embodiment, the data privacy protection method includes:

[0067] Step S10: Obtain the purchase intent set published by data element buyers, wherein the purchase intent set includes at least one genuine intent.

[0068] It should be understood that data is a broad collection of information, while data elements are units with specific value and meaning extracted from data. This extraction process typically involves a series of operations such as data cleaning and processing, and needs to consider potential privacy breaches arising from transactions. The goal is to make data more aligned with market demands and improve its usability and security. Suppose a buyer in a data circulation transaction wants to... Data is obtained from the middle, among which Represents the dimensions (also called attributes) of data. (Used...) Representing data space The data distribution. Without loss of generality, let's assume that each dimension... Both are limited. Data buyers want data space. The subset of data, namely the buyer's true intention, that is, the data the buyer wants to purchase, can be analyzed using the conjunctive paradigm. It means that, among them .when When, it can be written as In other words, data buyers do not specify dimensions. Specify any constraints.

[0069] In an efficient data circulation market, it is assumed that data buyers honestly express their true intentions, meaning that all data records reflecting these true intentions are genuinely meaningful to the buyer. For example, consider a dataset representing customer transactions on an e-commerce platform, which has three dimensions: It refers to product categories (such as electronics, clothing, books, etc.). It refers to payment methods (such as bank cards, credit cards, e-wallets, etc.). This refers to the shipping address (e.g., Beijing, Shanghai, Guangdong, etc.). Assume an online e-retailer, as the buyer in this data element circulation transaction, is interested in purchasing a specific subset of data to help analyze targeted marketing campaigns. The buyer's true purchasing intent is... If a buyer's true purchasing intent is directly disclosed, the potential goals of the data element buyer can be easily obtained by competitors, revealing their focus on selling electronics to customers in Beijing. This information could put the data element buyer under greater competitive pressure, as competitors could use it to refine their marketing strategies, strengthen their market competitiveness, and develop customer attraction strategies targeting customers in the same geographic area. Therefore, data element buyers need privacy protections to prevent attackers from determining the buyer's true intent based on information observed from them.

[0070] Consider different assumptions about observable information and corresponding attack models. To quantify the attacker's true intent to intrude into the privacy of data element buyers, for... Given a specific data record, this application needs to calculate the attacker's confidence level in whether that record represents the true intent of a data element purchaser. This application summarizes and categorizes three attack types: attacks based on publishing intent, efficiency maximization attacks, and purchase record inference attacks, and models each of these three attack types.

[0071] Understandably, the first attack model is based on the purchasing intent published by the data element buyer. To protect the true purchasing intent of data element buyers and maintain their privacy, data element buyers can publish a... The superset of true intention, i.e. (i.e., the set of purchase intentions published by data element buyers) so that potential data element providers can understand the interests of data buyers. And there is the following assumption: in an attack based on published purchase intentions, the attacker can only observe the purchase intentions published by data element buyers and does not possess the data space. Related information.

[0072] Since the published purchase intent is the only information the attacker possesses about the buyer's intent, therefore for If a data record in the publication is not within the intended scope of the publication, an attacker can determine that the buyer is not interested in that data record. For data records included in the publication intent, the attacker's confidence level regarding whether that data record is included in the buyer's true intent can be analyzed as follows:

[0073] Since the attacker has no information about the data space, such as probability density, the best assumption is... Each possible point in the equation has the same probability of occurring, that is... The data distribution in the proposal is uniform. Therefore, an attack based on the intent of the release is called a uniform attack based on the intent of the release.

[0074] Step S20: Determine the upper and lower bounds of the confidence level of the purchase intent set based on the number of genuine intents included in the purchase intent set.

[0075] It should be understood that, since the attacker has no information about the data space, such as probability density, the best assumption is... Each possible point in the equation has the same probability of occurring, that is... The data distribution in the proposal is uniform. Therefore, an attack based on the intent of the release is called a uniform attack based on the intent of the release.

[0076] Since genuine purchase intent is a subset of published purchase intent, and the minimum size of genuine purchase intent is 1 (meaning that genuine purchase intent contains at least one specific value in each published intent), the lower bound of the confidence level is: This information is known to both the data element buyer and any attacker. Similarly, the upper bound for the confidence level is: This information is known only to the data element purchaser; attackers are unaware of it.

[0077] Step S30: Based on the purchase intent set, the upper confidence bound, the lower confidence bound, the background knowledge of the data elements, and the purchase records of the data element buyers, establish an attack model based on the release intent, an efficiency maximization attack model, and a purchase record inference attack model targeting the data element buyers.

[0078] For ease of understanding, examples are given below, but these are not intended to limit the scope of this application. The steps for establishing an attack model based on release intent include:

[0079] Since the published purchase intent is the only information the attacker possesses about the buyer's intent, therefore for If a data record in the publication is not within the intended scope of the publication, an attacker can determine that the buyer is not interested in that data record. For data records included in the publication intent, the attacker's confidence level regarding whether that data record is included in the buyer's true intent can be analyzed as follows:

[0080] Since the attacker has no information about the data space, such as probability density, the best assumption is... Each possible point in the equation has the same probability of occurring, that is... The data distribution in the proposal is uniform. Therefore, an attack based on the intent of the release is called a uniform attack based on the intent of the release.

[0081] Since genuine purchase intent is a subset of published purchase intent, and the minimum size of genuine purchase intent is 1 (meaning that genuine purchase intent contains at least one specific value in each published intent), the lower bound of the confidence level is: This information is known to both the data element buyer and any attacker. Similarly, the upper bound for the confidence level is: This information is known only to the data element buyer, not to the attacker. Therefore, we can conclude that: .in, This indicates that a certain data record exists in the intent published by the data element buyer. In this scenario, attackers use uniform attacks based on publishing intent to manipulate data records. The confidence level of the true intent of data element buyers.

[0082] For ease of understanding, examples are given below, but these are not intended to limit the scope of this application. The steps for establishing an efficiency-maximizing attack model include:

[0083] Beyond observable publishing intent, attackers may also possess background knowledge about the data. Attackers can leverage this background knowledge to increase their confidence in whether the data records reflect the true intent of the data buyer. The core idea of ​​an efficiency maximization attack is that, to achieve economic efficiency, data element buyers tend to maximize the efficiency of their published purchasing intents. That is, a large portion of the published purchasing intents reflects the true intent of the data element buyer. Therefore, this type of attack is called an efficiency maximization attack. Furthermore, it is assumed that in an efficiency maximization attack, the attacker can observe the purchasing intent published by the data element buyer and also possesses knowledge of the data space. Data distribution information .

[0084] If an attacker knows the data distribution within the subspace of a buyer's published purchase intent, then given a data record that matches the published intent, the attacker's upper confidence bound for that record belonging to the buyer's intent is equal to the record's... The probability is directly proportional to the value. That is... .in, Represents data space Data records obtained from data distribution calculations in The probability of.

[0085] For ease of understanding, the following examples are provided, but they do not limit this application. The steps for establishing a purchase record inference attack model include:

[0086] In some cases, attackers may obtain purchase records of data element buyers and attempt to infer their intentions. To protect their privacy, data element buyers may purchase more data records than their true intentions. Suppose a data element buyer purchases a set of data records... This includes data records containing genuine purchase intentions as well as some redundant data records used for deception to protect privacy. Attackers may attempt to infer from these purchase records whether a data element buyer is interested in a given data record; this type of attack is called a purchased record inference attack. Furthermore, it is assumed that in a purchased record inference attack, the attacker not only possesses the set of data record records purchased by the data element buyer, but also has information about the data space. Background knowledge of data distribution in China, namely .

[0087] Given a data record, an attacker can infer whether the record is of interest to a data buyer in two steps. First, the attacker can use the set of data records observed by the data buyer to infer a pseudo-publishing intent of the data element buyer. That is, the attacker can try to find a minimal intent. This ensures that every purchase data record is included in this intent, which can be represented as... The solution to this problem can be written as: .in, yes The Dimensional features.

[0088] Given data space If a data record in a dataset is not included in a false release intent, the attacker knows that the record is not of interest to the buyer of the data element. For records included in a false release intent, based on the distribution of records purchased in the false release intent and the attacker's background knowledge, the attacker's confidence level in whether the record is in the buyer's true intent can be analyzed.

[0089] Attackers can infer the observed data distribution from the purchased data records set. For data records in the context of a false release intent. It can be estimated The probability of it appearing in the purchase collection is: .in, Indicates in Chinese data records The frequency of occurrence, and Represents a set The number of elements in the array.

[0090] In the simplest case, an attacker can only observe the data records purchased by the data element buyer and does not have control over the data space. Any background knowledge of the data distribution in the data. Then, given a record that matches the false publishing intent, the attacker's upper bound on the confidence level that the record belongs to the true intent of a data element buyer is compared to the record's... The probability of it appearing in the middle is directly proportional to the probability of it appearing in the middle, that is .

[0091] If the attacker controls the data space Data distribution in Then by comparison and observed distribution Attackers can infer the purchased data records based on the efficiency maximization assumption. The probability of this belonging to the true intention. In the observed distribution. middle, The more frequently it appears, and in The lower the probability of it appearing, The more likely it is to be a genuine intention.

[0092] In terms of quantity, for a single purchase data record It can be done The value, or proportion, of a sample set is used to measure the proportion of a given distribution. In the case of the observed distribution Frequency of occurrence The possibility. First, according to Calculating the intention of pseudo-publication In The probabilities of occurrence are as follows .

[0093] if ,and The value is very small, so the data record This is very likely the true intention. In order to calculate its... The value can be used for model-free hypothesis testing using Monte Carlo simulation and permutation tests. Specifically, according to Extracting from the intent of a false release Group records, the size of each group of records is the same as the set purchased by the buyer. Same (denoted as) ).for China satisfies Each data record ,calculate of Value (i.e., the proportion in the sample set where records) The probability of occurrence is at least equal to (Consistent). Therefore, the upper bound of the attacker's confidence that the record is included in the buyer's intent regarding the data element can be written as: .

[0094] Based on the above description of the three types of attacks, we can conclude that:

[0095] 1) The attack model based on publishing intent is used to represent scenarios where attackers launch attacks solely based on the purchasing intent published by data buyers. It assumes that the data buyers' published intents are a superset of the true intents, and that the attacker lacks information about the data space. Assuming the data distribution in the data space is uniform, the attacker derives upper and lower bounds on their confidence level regarding whether each data record is included in the buyer's true intent by calculating the ratio of the maximum and minimum values ​​of the number of published intents to the total number of published intents.

[0096] (2) The efficiency maximization attack model represents a scenario where the attacker not only bases their attack on the purchase intent published by the data buyer, but also combines background knowledge and data distribution information. The basis is that data element buyers tend to maximize the efficiency of publishing their purchase intent, and the attacker has access to data distribution information. The attacker's confidence that the record belongs to the data buyer's intent is proportional to the probability of the record appearing.

[0097] (3) The purchase record inference attack model is used to represent a scenario where the attacker not only has a grasp of the probability distribution of the data space, but also has obtained the actual purchase records of the data buyers, and attempts to infer the buyers' true purchase intentions through these records. The basis is that the upper bound of the attacker's confidence that the record belongs to the true intention of the data element buyer is proportional to the probability of the record appearing in the purchase records. If the attacker observes that a certain data appears more frequently in the distribution of published data, and the lower the probability of it appearing in the data space, then it is more likely to belong to the true intention.

[0098] Step S40: Based on the attack model based on publishing intent, the efficiency maximization attack model, and the purchase record inference attack model, construct the uniform attack defense model based on publishing intent, the efficiency maximization attack defense model, and the purchase record inference attack defense model with confidence threshold as constraints.

[0099] It should be understood that buyer privacy attack modeling is a scenario simulation conducted to understand the behavior and capabilities of attackers, while buyer privacy protection task modeling is based on these attack scenarios to design effective defense schemes to ensure the privacy and security of data buyers. Attack modeling allows for the understanding of potential threats, enabling the development of protection strategies and ultimately achieving privacy security.

[0100] Given a buyer's true intent and a maximum confidence threshold specified by the buyer. In a uniform intent attack and efficiency maximization attack model, a data element buyer either publishes a single purchase intent, or in a purchase record inference attack, purchases a wider range of data records, ensuring that any attacker's confidence in the records in the published intent or the records purchased by the data element buyer that reflect the buyer's true intent is no higher than [a certain percentage]. If satisfied, the published intent is called... -The privacy protection intent to publish the data record set to be purchased is called... - Privacy protection for purchase history records.

[0101] Since data buyers need to pay for the data records they intend to publish or purchase, it is economically necessary to minimize the scope of those records. The data buyer privacy issue is thus minimized. - Privacy protection of records of publishing intent or purchases.

[0102] For ease of understanding, examples are given below, but these are not intended to limit the scope of this application. The steps for constructing a uniform attack defense model based on release intent include:

[0103] For uniform attacks based on publishing intent, the following formula must be ensured: The upper bound of the confidence level expressed in the text does not exceed ,Right now ,Right now Therefore, privacy protection defenses against uniform attacks based on publishing intent can be modeled as an optimization problem: .

[0104] For ease of understanding, examples are given below, but these are not intended to limit the scope of this application. The steps for constructing an attack defense model that maximizes efficiency include:

[0105] In efficiency-maximizing attack scenarios, it is crucial to ensure that the upper bound of the confidence level based on the attacker's background knowledge of the data distribution does not exceed the confidence threshold of all data records belonging to genuine intent. According to the efficiency maximization attack model, the attacker's upper confidence bound for the record belonging to the buyer's intent is related to the record. The probability is directly proportional to the probability, therefore for any They all It can be seen that... In other words .

[0106] Therefore, defense against attacks that maximize efficiency can be modeled as an optimization problem: .

[0107] For ease of understanding, the following examples are provided, but they do not limit this application. The steps for constructing a purchase record inference attack defense model include:

[0108] In a purchase record inference attack scenario, it is also necessary to ensure that the upper bound of the confidence level based on the attacker's background knowledge of the data distribution is not higher than the confidence threshold of all data records belonging to the true intent. Based on the purchase records, we can infer the upper bound of the attacker's confidence that the data element's buyer intent includes that record in the attack model. Therefore, for any... They all ,Right now .

[0109] Therefore, it is necessary to ensure of Value greater than or equal to Taking utility as the primary consideration, where buyers seek to maximize the ratio of records with genuine intent to records with posting intent, defense against purchase record inference attacks can be modeled as an optimization problem: .

[0110] Step S50: Protect the privacy of the data element purchaser based on the uniform attack defense model based on the publishing intent, the efficiency maximization attack defense model, and the purchase record inference attack defense model.

[0111] Understandably, solving the uniform attack defense model based on publishing intent, the efficiency maximization attack defense model, and the purchase record inference attack defense model constructed in the above steps can ultimately protect the privacy of data element buyers.

[0112] This embodiment takes into account the various background knowledge that attackers may exploit, and solves the above-mentioned problems by modeling the privacy protection of data element buyers in data circulation transactions, thereby ensuring the privacy security of data element buyers and reducing the risk of privacy leakage of data element buyers.

[0113] Reference Figure 2 , Figure 2 This is a flowchart illustrating the second embodiment of the data privacy protection method of this application, based on the above. Figure 1 The first embodiment shown illustrates a second embodiment of the data privacy protection method of this application.

[0114] In the second embodiment, step S50 includes:

[0115] Step S501: Expand the purchase intent set to minimize the optimization problem in the uniform attack defense model based on release intent or the efficiency maximization attack defense model.

[0116] It should be understood that, for the above three defense task models, this embodiment proposes corresponding algorithms to solve the problem of data buyer privacy protection, namely: a uniform attack / efficiency maximization attack defense algorithm based on publishing intent, and a purchase record inference attack defense algorithm.

[0117] Understandably, to address uniform attacks and efficiency maximization attacks based on publishing intent, an "expansion" strategy is adopted. This involves expanding the set of true purchase intent feature values ​​to find the optimal neighborhood feature values ​​and adding them to the publishing intent, thereby minimizing the optimization problem resulting from the privacy-preserving constraint transformation. This approach ensures that the published intent, while satisfying privacy constraints, minimizes the range of data records related to both the publishing intent and the purchase, thus reducing the likelihood of attackers inferring the buyer's true intent from the publishing intent and protecting the buyer's privacy.

[0118] Step S502: Sampling is performed based on the total number of data records that the data element buyer intends to purchase to obtain the purchase data set corresponding to the data element buyer, so as to ensure that the purchase data set meets the privacy protection constraints corresponding to the purchase record inference attack defense model.

[0119] It should be understood that the purchase record inference attack algorithm adopts a "sampling" strategy. The Monte Carlo simulation algorithm uses random sampling to generate datasets and merges and filters data sets that meet privacy protection constraints. The Markov chain Monte Carlo algorithm calculates the state transition probability of the dataset by iteratively selecting data record addition or deletion operations. By sampling according to the Monte Carlo simulation algorithm or iterating according to the Markov chain Monte Carlo algorithm, the privacy and security of the data element purchaser can be guaranteed because the final selected dataset is within the privacy constraints.

[0120] This embodiment proposes corresponding algorithms to address the privacy protection problem of data buyers for the three defense task models mentioned above. These algorithms are a uniform attack / efficiency maximization attack defense algorithm based on publishing intent and a purchase record inference attack defense algorithm. This reduces the possibility of attackers inferring the true intent of buyers through publishing intent and protects the privacy and security of data element buyers.

[0121] Reference Figure 3 , Figure 3 This is a flowchart illustrating the third embodiment of the data privacy protection method of this application, based on the above. Figure 1 The first embodiment shown presents a third embodiment of the data privacy protection method of this application.

[0122] In the third embodiment, step S501 includes:

[0123] Step S5011: Set the purchase intent set to be the same as the actual intent, and in each iteration, traverse each dimension in the data space.

[0124] It should be understood that, given a data space and the buyer's true purchasing intent for data elements It can continuously expand the set of feature values ​​in the true purchase intention. Until a release intent PI (i.e., purchase intent set) that can fully disguise and protect the true intent is obtained, that is, satisfying the constraints of the optimization problem in the uniform attack defense model or the efficiency maximization attack defense model based on release intent.

[0125] Step S5012: Search for optional neighborhood feature values ​​on the traversal dimension, and select the best neighborhood feature value from the optional neighborhood feature values.

[0126] It should be understood that searching for alternative neighborhood feature values ​​along the traversal of a dimension and selecting the best neighborhood feature value from the alternative neighborhood feature values ​​may include calculating the cumulative distance of feature values ​​along the traversal of the dimension and selecting the feature value with the shortest cumulative distance as the alternative neighborhood feature value; calculating the number of additional records, the incremental impact of privacy constraints, and the validity score of the alternative neighborhood feature value; and selecting the best neighborhood feature value from the alternative neighborhood feature values ​​based on the number of additional records, the incremental impact of privacy constraints, and the validity score.

[0127] For ease of understanding, please refer to Figure 4 This explanation is provided, but does not limit the scope of this application. Figure 4 This is a flowchart of a uniform attack / efficiency maximization attack defense algorithm based on publishing intent, according to an embodiment of the data privacy protection method of this application. Figure 4 In this context, the uniform attack / efficiency maximization attack defense algorithm based on release intent can be divided into the following three steps:

[0128] Step 1: Search for optional neighborhood feature values. For example... Figure 5 As shown, Figure 5 This is a schematic diagram of extended feature values ​​on the horizontal axis according to an embodiment of the data privacy protection method of this application. Figure 5 In the image, the intended message is represented by the blue area; in this example, That is, the data space has two dimensions. The horizontal dimension... Indicates educational level, vertical direction Indicates job category. Dimension The characteristic value in the release intent is It can Possible feature value expansion includes adding "Associate Degree" and "Bachelor's Degree", etc.

[0129] Step 1.1: Calculate the cumulative distance of eigenvalues. First, for each expanded eigenvalue, calculate the cumulative distance between the eigenvalue and ... The cumulative distance between all eigenvalues. (Eigenvalues) The cumulative distance is defined as Assuming the index is... If these qualifications are assigned to "Associate Degree", "Bachelor's Degree", "Master's Degree", and "Doctoral Degree" respectively, then "Associate Degree" and... The cumulative distance between all features is 5, and "Bachelor" is relative to The cumulative distance is 3.

[0130] Step 1.2: Select the feature value with the shortest cumulative distance. Then, select the feature value with the shortest cumulative distance as... The eigenvalue of the nearest neighbor on the dimension is "Bachelor". Above, there is no semantic distance between feature values, that is Each pair of eigenvalues ​​on the dimension has the same distance. Therefore, for dimension... Features in the publishing intent on All remaining features “unemployed”, “private enterprise” and “individual” are considered as potential extended feature values.

[0131] After iterating over each dimension, four possible expanded neighborhood feature values ​​were obtained: "Bachelor's degree" and "unemployed" in different dimensions. "Private enterprises" and "individuals" in terms of dimensions.

[0132] Step 2: Determine the optimal neighborhood feature value. To determine the optimal feature value, this application designs a scoring function to comprehensively measure the effectiveness of adding the feature value to the publishing intent. The scoring considers two factors: first, the number of additional data records added to the buyer's publishing intent of the data element after adding the feature value; and second, the incremental impact of adding the feature value on meeting privacy protection constraints.

[0133] Step 2.1: Calculate the number of additional records to add neighborhood feature values. Given a dimension to be added. latent eigenvalues First, consider the number of additional data records added to the buyer's publishing intent of the data element after adding this feature value. Given eigenvalues and current release intent The number of added features is .

[0134] Step 2.2: Calculate the privacy constraint impact increment of adding the neighborhood feature value. Next, to measure the impact of adding this feature value on satisfying the optimization problem constraints in the uniform attack defense model or the efficiency maximization attack defense model based on publishing intent, the increment on the right-hand side of the constraint after adding the feature value is used. Let's represent it. For a uniform attack based on publishing intent, it can be represented as follows: For efficiency maximization attacks, the increment of the constraint after adding eigenvalues ​​is... .

[0135] Step 2.3: Calculate the effectiveness score for adding neighborhood feature values. For each neighborhood feature value, the number of data records added. Incremental impact of constraints Normalization is performed using the minimum-maximum method. A formula is defined to calculate the added neighborhood feature values. The score is .in, It is the weight of the evaluation factors. and They are respectively The normalized addition quantity and constraint effect increment under the constraints are as follows. This represents the maximum number of additions to all possible neighborhood feature values.

[0136] Step 3: Select neighborhood feature values ​​based on validity scores. Finally, the data element buyer selects the feature values ​​to include in the intended publication based on the scores of all neighborhood feature values, thus achieving privacy protection.

[0137] Step S5013: After traversing each dimension, the best neighborhood feature value is added to the purchase intent set to minimize the optimization problem in the uniform attack defense model based on the release intent or the efficiency maximization attack defense model.

[0138] For ease of understanding, examples are given below, but these are not intended to limit this application. The core idea of ​​the uniform attack / efficiency maximization attack defense algorithm based on publishing intent is: to use the initial publishing intent... Set to be the same as the true intent, that is, for In each iteration, the data space is traversed. Each dimension in; for each dimension and the set of features corresponding to its publishing intent. ,choose The nearest neighbor eigenvalues ​​are used. After traversing each dimension, the nearest neighbor eigenvalues ​​are added to the publishing intent PI to minimize the optimization problem in the uniform attack defense model or the efficiency maximization attack defense model based on publishing intent.

[0139] This embodiment addresses uniform attacks and efficiency maximization attacks based on publishing intent by employing an "expansion" strategy. It expands the set of true purchase intent feature values, finds the optimal neighborhood feature values, and adds them to the publishing intent to minimize the optimization problem resulting from the privacy-preserving constraint transformation. This approach ensures that the published intent, while satisfying privacy constraints, minimizes the range of data records related to the publishing intent and the purchase, thereby reducing the possibility of attackers inferring the buyer's true intent through the publishing intent and protecting the buyer's privacy.

[0140] In the third embodiment, step S502 includes:

[0141] Step S5021: Randomly sample and generate a data set based on the total number of data records that the data element buyer wants to purchase, and remove data sets that do not meet the privacy protection constraints.

[0142] It should be understood that the optimization problem derived from inferring the attack defense model based on purchase records, in order to make the function of Value for any All greater than or equal to First, it is necessary to determine the buyer's publishing intent (which the attacker perceives as a false publishing intent). Therefore, given the buyer's true intention, the proposed extended method is first used to calculate the published intention.

[0143] Then, given the total number of data records the buyer wants to purchase for the given data elements. and the published purchase intention It is necessary to Records assigned Each feature value combination in the array. To this end, this application proposes two algorithms: (1) Monte Carlo simulation algorithm; (2) Markov chain Monte Carlo algorithm.

[0144] Step S5022: Calculate the utilization rate of the remaining data set and select the remaining data set with the highest utilization rate as the data set to be purchased.

[0145] For ease of understanding, please refer to Figure 6 This explanation is provided, but does not limit the scope of this application. Figure 6 This is a flowchart of a Monte Carlo simulation algorithm according to an embodiment of the data privacy protection method of this application. Figure 6 In this context, the Monte Carlo simulation algorithm can be divided into the following four steps:

[0146] Step 1: Generate a dataset through random sampling. Datasets Each dataset contains samples taken from published intents. 1 record.

[0147] Step 2: Remove datasets that do not meet privacy constraints. Delete datasets that do not meet privacy constraints, i.e., for... , of Value less than .

[0148] Step 3: Calculate the utilization rate of the remaining datasets. For each dataset remaining after deletion, calculate the utilization rate, which is the ratio of data records with actual purchase intent to data records with posting intent. Given a given remaining dataset... Utilization rate .

[0149] Step 4: Select the dataset with the highest utilization rate as the dataset to be purchased. Utilization rate is the primary consideration. Data element buyers strive to maximize the ratio of genuine intent to posted intent records, so the dataset with the highest utilization rate is ultimately selected as the dataset to be purchased.

[0150] This embodiment targets purchase record inference attack algorithms by employing a "sampling" strategy. The Monte Carlo simulation algorithm uses random sampling to generate datasets, merges and filters data sets that meet privacy protection constraints. By iterating the sampling according to the Monte Carlo simulation algorithm, the final selected dataset is ensured to be within the privacy constraints, thereby protecting the privacy and security of the data element purchaser.

[0151] In the third embodiment, step S502 further includes:

[0152] Step S5021': Initialize the purchase data set by distribution sampling based on the total number of data records that the data element purchaser wants to purchase.

[0153] Step S5022': Perform addition and deletion operations on the initialized data set, and verify whether the processed data set satisfies the privacy protection constraints.

[0154] Step S5023': If the privacy protection constraints are met, calculate the acceptance probability of the processed data set.

[0155] Step S5024': Based on the acceptance probability, decide whether to select the processed data set as the purchase data set.

[0156] For ease of understanding, please refer to Figure 7 This explanation is provided, but does not limit the scope of this application. Figure 7 This is a flowchart of the Markov chain Monte Carlo algorithm, an embodiment of the data privacy protection method of this application. Figure 7 In this context, the Markov chain Monte Carlo algorithm can be divided into the following four steps:

[0157] Step 1: Initialize the purchase dataset based on distribution sampling. First, infer the pseudo-publication intent in the attack defense model based on the purchase records. In The probability of occurrence, based on data distribution Extract Use data records to initialize the purchase dataset. .

[0158] Step 2: Select basic processing operations for the dataset. Given an initial recordset. This dataset contains records of data elements that the buyer truly wants (the buyer's true intent) as well as some disguised data records used to conceal privacy. Four basic processing operations are defined for this dataset:

[0159] a) Delete a fake data record and add a data record that reflects the buyer's true intent;

[0160] b) Delete one fake data record and add another fake data record;

[0161] c) Delete a data record that reflects the buyer's true intent and add a fake data record;

[0162] d) Delete a data record from the buyer's true intent and add another data record from the buyer's true intent.

[0163] By selecting different disguised data records or data records reflecting the buyer's true intent, multiple operation choices exist, forming a Markov chain state space. For each iteration, an operation is randomly selected from a, b, c, and d, and the current dataset is updated accordingly. Transform into .

[0164] Step 3: Check if privacy constraints are met and calculate the acceptance probability. After completing Step 2, first check... Does it meet privacy protection constraints? If so, then calculate... Acceptance probability .in, This is the utilization function in step 3 of the Monte Carlo simulation algorithm.

[0165] Step 4: Repeat steps 2 and 3 repeatedly until the privacy constraint is satisfied again. In each iteration, continue to select the next operation and update the purchased dataset until the privacy constraint in the purchase record inference attack defense model is no longer satisfied, i.e., for... , of Value less than And during the iteration process, when the privacy threshold... With the attacker's record The minimum difference between the current confidence levels is less than a certain threshold. When this happens, the Markov chain Monte Carlo algorithm will terminate.

[0166] Step 5: Decide whether to select the dataset as the purchase dataset based on the acceptance probability. This is based on the calculated acceptance probability, i.e., the dataset's state... Transferred to The probability is used to decide whether to choose. As a purchase dataset.

[0167] By sampling using Monte Carlo simulation algorithms or iterating using Markov chain Monte Carlo algorithms, the dataset to be purchased is ultimately selected within privacy constraints, thereby ensuring the privacy and security of the data element buyer.

[0168] This embodiment targets purchase record inference attack algorithms and employs a "sampling" strategy. The Markov Chain Monte Carlo algorithm calculates the state transition probability of the dataset by iteratively selecting data record addition or deletion operations. According to the Markov Chain Monte Carlo algorithm iteration, the final selected dataset is within the privacy constraints, thereby protecting the privacy and security of the data element purchaser.

[0169] This application has the following advantages compared with related technologies:

[0170] 1. Three attack models—based on publishing intent attack, efficiency maximization attack, and purchase record inference attack—are derived from modeling privacy attacks on data element circulation and transactions. Three defense task models are derived from modeling privacy protection tasks on data element circulation and transactions. Two privacy protection defense algorithms are constructed based on the three attack models and the corresponding three defense task models: the uniform attack / efficiency maximization attack defense algorithm based on publishing intent and the purchase record inference attack defense algorithm, to achieve privacy protection for data buyers.

[0171] 2. For the three attack models, the specific method is to define the data space, data dimension, data probability distribution, etc., and calculate the upper and lower bounds of the attacker's confidence in whether the data record is included in the buyer's true intention.

[0172] 3. For the modeling of the three defense task models, the specific method is to give a buyer's true intention and a maximum confidence threshold specified by the buyer. The issue of protecting the privacy of data buyers is the most computationally intensive. - Privacy protection is provided for the set of records containing the intent to publish or purchase data, and the upper bound of the confidence level required by an attacker to determine whether such data records are included in the true intent of the purchaser does not exceed [a certain limit]. This problem is then transformed into an optimization problem that satisfies privacy protection constraints.

[0173] 4. For the two privacy-preserving defense algorithms, the specific methods are as follows: The uniform attack / efficiency maximization attack defense algorithm based on publishing intent defines the number of data records added and the incremental impact on privacy constraints. It calculates the score of the neighborhood feature values ​​of the added genuine purchase intent feature values, and the data element buyer selects the feature values ​​included in the published intent for purchase. The purchase record inference attack defense algorithm includes two optional algorithms: Monte Carlo simulation algorithm and Markov chain Monte Carlo algorithm. These algorithms respectively calculate the utilization rate under privacy-preserving constraints through sampling and iteratively select data record addition or deletion operations to calculate the state transition probability of the dataset. Within the privacy constraints, the algorithm ultimately selects the dataset to purchase, thereby ensuring the privacy and security of the data element buyer.

[0174] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the data privacy protection method of this application. Any simple modifications based on this technical concept are within the protection scope of this application.

[0175] This application also provides a data privacy protection device, please refer to... Figure 8 The data privacy protection device includes:

[0176] The intent acquisition module 10 is used to acquire a set of purchase intents published by data element buyers, wherein the set of purchase intents includes at least one genuine intent.

[0177] The boundary determination module 20 is used to determine the upper bound and lower bound of the confidence level of the purchase intent set based on the number of genuine intents included in the purchase intent set;

[0178] The model building module 30 is used to build an attack model based on the purchase intent, an efficiency maximization attack model, and a purchase record inference attack model against the purchasers of the data elements, based on the purchase intent set, the upper confidence bound, the lower confidence bound, the background knowledge of the data elements, and the purchase records of the purchasers of the data elements.

[0179] The model building module 30 is further configured to construct a uniform attack defense model based on publishing intent, an efficiency maximization attack defense model, and a purchase record inference attack defense model based on publishing intent, with confidence threshold as a constraint, based on the attack model based on publishing intent, the efficiency maximization attack model, and the purchase record inference attack model.

[0180] The privacy protection module 40 is used to protect the privacy of the data element purchaser based on the uniform attack defense model based on the publishing intent, the efficiency maximization attack defense model, and the purchase record inference attack defense model.

[0181] The data privacy protection device provided in this application, employing the data privacy protection method described in the above embodiments, addresses the technical problem that existing data privacy protection schemes primarily focus on protecting the privacy of data providers and data trading platforms, neglecting the privacy protection of data buyers, thus posing a risk of privacy leakage for data buyers. Compared to the prior art, the beneficial effects of the data privacy protection device provided in this application are the same as those of the data privacy protection method provided in the above embodiments, and other technical features in the data privacy protection device are the same as those disclosed in the methods of the above embodiments, and will not be elaborated upon here.

[0182] This application provides a data privacy protection device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the data privacy protection method in Embodiment 1 above.

[0183] The following is for reference. Figure 9 This document illustrates a structural diagram of a data privacy protection device suitable for implementing embodiments of this application. The data privacy protection device in these embodiments may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), and in-vehicle terminals (e.g., in-vehicle navigation terminals), as well as fixed terminals such as digital TVs and desktop computers. Figure 9 The data privacy protection device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0184] like Figure 9As shown, the data privacy protection device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in ROM (Read Only Memory) 1002 or a program loaded from storage device 1003 into RAM (Random Access Memory) 1004. RAM 1004 also stores various programs and data required for the operation of the data privacy protection device. The processing unit 1001, ROM 1002, and RAM 1004 are interconnected via bus 1005. Input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to I / O interface 1006: input devices 1007 including, for example, touch screens, touchpads, keyboards, mice, image sensors, microphones, accelerometers, gyroscopes, etc.; output devices 1008 including, for example, LCDs (Liquid Crystal Displays), speakers, vibrators, etc.; storage devices 1003 including, for example, magnetic tapes, hard disks, etc.; and communication devices 1009. Communication device 1009 allows the data privacy protection device to communicate wirelessly or wiredly with other devices to exchange data. While the figures show data privacy protection devices with various systems, it should be understood that implementation or possession of all the systems shown is not required. More or fewer systems may be implemented alternatively.

[0185] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from ROM 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.

[0186] The data privacy protection device provided in this application, employing the data privacy protection method described in the above embodiments, addresses the technical problem that existing data privacy protection schemes primarily focus on protecting the privacy of data providers and data trading platforms, neglecting the privacy protection of data buyers, thus posing a risk of privacy leakage for data buyers. Compared to the prior art, the beneficial effects of the data privacy protection device provided in this application are the same as those of the data privacy protection method provided in the above embodiments, and other technical features of this data privacy protection device are the same as those disclosed in the previous embodiment method, and will not be repeated here.

[0187] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.

[0188] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0189] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, which are used to execute the data privacy protection method described in the above embodiments.

[0190] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, RAM (Random Access Memory), ROM (Read Only Memory), EPROM (Erasable Programmable Read Only Memory), or flash memory, optical fiber, CD-ROM (CD-Read Only Memory), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.

[0191] The aforementioned computer-readable storage medium may be included in a data privacy protection device; or it may exist independently and not be assembled into a data privacy protection device.

[0192] The aforementioned computer-readable storage medium carries one or more programs, which, when executed by the data privacy protection device, cause the data privacy protection device to perform the data privacy protection method described in the above embodiments.

[0193] Computer program code for performing the operations of this application can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including LAN (Local Area Network) or WAN (Wide Area Network)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0194] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0195] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.

[0196] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the above-described data privacy protection method. This addresses the technical problem that existing data privacy protection schemes primarily focus on protecting the privacy of data providers and data trading platforms, without addressing the privacy protection of data buyers, thus posing a risk of privacy leakage for data buyers. Compared to the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the data privacy protection method provided in the above embodiments, and will not be elaborated upon here.

[0197] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the data privacy protection method described above.

[0198] The computer program product provided in this application addresses the technical problem that existing data privacy protection schemes primarily focus on protecting the privacy of data providers and data trading platforms, without addressing the privacy protection of data buyers, thus posing a risk of privacy leakage for data buyers. Compared to existing technologies, the beneficial effects of the computer program product provided in this application are the same as those of the data privacy protection methods provided in the above embodiments, and will not be elaborated upon here.

[0199] The above description is only a part of the embodiments of this application and does not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.

Claims

1. A data privacy protection method, characterized in that, The data privacy protection methods include: Obtain a set of purchase intentions published by data element buyers, wherein the set of purchase intentions includes at least one genuine intention; The upper and lower bounds of the confidence level of the purchase intent set are determined based on the number of genuine intents included in the purchase intent set. Based on the purchase intent set, the upper confidence bound, the lower confidence bound, the background knowledge of the data elements, and the purchase records of the data element buyers, establish an attack model based on the release intent, an efficiency maximization attack model, and a purchase record inference attack model targeting the data element buyers. Based on the attack model based on publishing intent, the efficiency maximization attack model, and the purchase record inference attack model, a uniform attack defense model based on publishing intent, an efficiency maximization attack defense model, and a purchase record inference attack defense model are constructed with confidence thresholds as constraints. Privacy protection is provided for the data element purchasers based on the uniform attack defense model based on publishing intent, the efficiency maximization attack defense model, and the purchase record inference attack defense model. The step of protecting the privacy of data element buyers based on the uniform attack defense model based on publishing intent, the efficiency maximization attack defense model, and the purchase record inference attack defense model includes: The purchase intent set is expanded to minimize the optimization problem in the uniform attack defense model based on release intent or the efficiency maximization attack defense model. Based on the total number of data records that the data element buyer wants to purchase, a sample is taken to obtain the purchase data set corresponding to the data element buyer, so as to ensure that the purchase data set meets the privacy protection constraints corresponding to the purchase record inference attack defense model. The step of sampling based on the total number of data records to be purchased by the data element purchaser to obtain the purchase data set corresponding to the data element purchaser, to ensure that the purchase data set meets the privacy protection constraints corresponding to the purchase record inference attack defense model, includes: A data set is generated by randomly sampling the total number of data records that the data element buyer intends to purchase, and data sets that do not meet the privacy protection constraints are removed. Calculate the utilization rate of the remaining dataset and select the remaining dataset with the highest utilization rate as the purchase dataset; The step of sampling based on the total number of data records to be purchased by the data element purchaser to obtain the purchase data set corresponding to the data element purchaser, to ensure that the purchase data set meets the privacy protection constraints corresponding to the purchase record inference attack defense model, includes: The total number of data records that the data element buyer wants to purchase is initialized into the purchase data set through distribution sampling based on the total number of data records that the buyer wants to purchase. The initialized dataset is processed by adding or deleting data, and the processed dataset is checked to see if it meets the privacy protection constraints. If the privacy protection constraints are met, the acceptance probability of the processed dataset is calculated. The decision on whether to select the processed dataset as the purchase dataset is based on the acceptance probability.

2. The data privacy protection method as described in claim 1, characterized in that, The expansion of the purchase intent set to minimize the optimization problem in the uniform attack defense model based on release intent or the efficiency maximization attack defense model includes: Set the purchase intent set to be the same as the actual intent, and in each iteration, traverse each dimension in the data space; Search for optional neighborhood feature values ​​along the traversal dimension, and select the best neighborhood feature value from the optional neighborhood feature values; After traversing each dimension, the best neighborhood feature value is added to the purchase intent set to minimize the optimization problem in the uniform attack defense model based on the release intent or the efficiency maximization attack defense model.

3. The data privacy protection method as described in claim 2, characterized in that, The step of searching for optional neighborhood feature values ​​along the traversal dimension and selecting the best neighborhood feature value from the optional neighborhood feature values ​​includes: The cumulative distance of feature values ​​is calculated as iterates through the dimensions, and the feature value with the shortest cumulative distance is selected as the optional neighborhood feature value. Calculate the additional number of records for the optional neighborhood feature values, the incremental impact of privacy protection constraints, and the effectiveness score; The optimal neighborhood feature value is selected from the optional neighborhood feature values ​​based on the number of additional records, the incremental impact of the privacy protection constraints, and the effectiveness score.

4. A data privacy protection device, characterized in that, The data privacy protection device includes: The intent acquisition module is used to acquire a set of purchase intents published by data element buyers, wherein the set of purchase intents includes at least one genuine intent. The boundary determination module is used to determine the upper bound and lower bound of the confidence level of the purchase intent set based on the number of genuine intents included in the purchase intent set; The model building module is used to build an attack model based on the purchase intent set, the upper confidence bound, the lower confidence bound, the background knowledge of the data elements, and the purchase records of the data element buyers, targeting the data element buyers based on the release intent, the efficiency maximization attack model, and the purchase record inference attack model. The model building module is also used to construct a uniform attack defense model based on publishing intent, an efficiency maximization attack defense model, and a purchase record inference attack defense model based on confidence thresholds, according to the attack model based on publishing intent, the efficiency maximization attack model, and the purchase record inference attack model. The privacy protection module is used to protect the privacy of the data element purchaser based on the uniform attack defense model based on the publishing intent, the efficiency maximization attack defense model, and the purchase record inference attack defense model. The step of protecting the privacy of data element buyers based on the uniform attack defense model based on publishing intent, the efficiency maximization attack defense model, and the purchase record inference attack defense model includes: The purchase intent set is expanded to minimize the optimization problem in the uniform attack defense model based on release intent or the efficiency maximization attack defense model. Based on the total number of data records that the data element buyer wants to purchase, a sample is taken to obtain the purchase data set corresponding to the data element buyer, so as to ensure that the purchase data set meets the privacy protection constraints corresponding to the purchase record inference attack defense model. The step of sampling based on the total number of data records to be purchased by the data element purchaser to obtain the purchase data set corresponding to the data element purchaser, to ensure that the purchase data set meets the privacy protection constraints corresponding to the purchase record inference attack defense model, includes: A data set is generated by randomly sampling the total number of data records that the data element buyer intends to purchase, and data sets that do not meet the privacy protection constraints are removed. Calculate the utilization rate of the remaining dataset and select the remaining dataset with the highest utilization rate as the purchase dataset; The step of sampling based on the total number of data records to be purchased by the data element purchaser to obtain the purchase data set corresponding to the data element purchaser, to ensure that the purchase data set meets the privacy protection constraints corresponding to the purchase record inference attack defense model, includes: The total number of data records that the data element buyer wants to purchase is initialized into the purchase data set through distribution sampling based on the total number of data records that the buyer wants to purchase. The initialized dataset is processed by adding or deleting data, and the processed dataset is checked to see if it meets the privacy protection constraints. If the privacy protection constraints are met, the acceptance probability of the processed dataset is calculated. The decision on whether to select the processed dataset as the purchase dataset is based on the acceptance probability.

5. A data privacy protection device, characterized in that, The data privacy protection device includes: a memory, a processor, and a data privacy protection program stored in the memory and executable on the processor, wherein the data privacy protection program, when executed by the processor, implements the data privacy protection method as described in any one of claims 1 to 3.

6. A storage medium, characterized in that, The storage medium stores a data privacy protection program, which, when executed by a processor, implements the data privacy protection method as described in any one of claims 1 to 3.

7. A computer program product, characterized in that, The computer program product includes a data privacy protection program, which, when executed by a processor, implements the data privacy protection method as described in any one of claims 1 to 3.