Privacy protection and data security access method for graph neural network
By using 2-out-of-2 addition secret sharing and 2-out-of-4 copy secret sharing technology in the graph neural network, the problem of inefficient access to multi-party privacy protection arrays is solved, and efficient data security access and reconstruction of plaintext data is achieved.
Patent Information
- Application Number
- CN202510022849.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-07
- Publication Date
- 2025-05-06
AI Technical Summary
The existing multi-party privacy protection array access method is inefficient in resource-constrained scenarios, resulting in high computing overhead, low communication efficiency and reduced accuracy.
2-out-of-2 addition secret sharing and 2-out-of-4 copy secret sharing technology are used to rotate and randomize the ciphertext array through four-party interaction to achieve secure access to data, and reconstruct plaintext data through plaintext reconstruction algorithm.
In the case of protecting array elements and index information from being leaked, it significantly saves time and overhead and server costs, and improves the efficiency of privacy-protecting data access.
Smart Images

Figure CN119939658A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security technology, and specifically relates to a privacy protection and data security access method for graph neural networks. Background Art
[0002] Graph Neural Networks (GNNs) have been widely used in recommendation systems, social network analysis, financial risk control and other fields. The core of GNNs is to achieve in-depth analysis of complex data by mining the relationships between nodes in the graph structure and their feature information. However, the training and reasoning of GNN models usually require processing a large amount of data and performing a large amount of calculations, which requires a large amount of computing and storage resources, resulting in the inability of home computers or mobile devices with limited resources to handle large-scale training and reasoning tasks. In addition, as the complexity of the model increases, the demand for computing resources is also growing, which makes it expensive and limited for individuals or small teams to upgrade these resources. Cloud computing provides powerful computing power with high scalability, flexibility and cost-effectiveness. Therefore, outsourcing the training and reasoning process of the model to cloud computing has become a popular trend. However, graph data often contains sensitive information, such as user behavior data, social relationships and transaction records. Directly using GNNs to process this data without proper protection may lead to privacy leakage.
[0003] In order to solve the risk of privacy leakage in the use of graph neural networks, privacy-preserving graph neural networks (PPGNN) have gradually become a research hotspot. PPGNN combines privacy protection technology with graph neural network technology, and can achieve effective learning of graph data under the premise of protecting data privacy. Common privacy protection technologies include homomorphic encryption, multi-party secure computing, federated learning, and differential privacy. For example, federated learning shares model parameters among multiple data holders through a distributed training mechanism without directly sharing data, thereby reducing the risk of privacy leakage; while differential privacy hides information by introducing noise in data or gradients. However, while these methods protect privacy, they also bring problems such as high computational overhead, low communication efficiency, and reduced accuracy, which limits the widespread application of PPGNN in resource-constrained scenarios.
[0004] As the research on PPGNN deepens, one of its core issues is how to efficiently and securely access array elements. In privacy-preserving graph neural networks, adjacency matrices are usually stored and calculated in array form. Therefore, in this context, privacy-preserving array access methods have gradually become a research focus. Existing array access methods face the challenge of low efficiency in multi-party privacy protection scenarios. For example, the three-party secure array access algorithm mentioned in the paper "SecGNN: Privacy-Preserving Graph Neural Network Training and Inference as a Cloud Service" requires two additional rounds of waiting time during the calculation process.
[0005] As mentioned in the review, in response to the practical needs of privacy-preserving graph neural networks, designing an efficient privacy-preserving array access method can not only solve the privacy protection problem of sensitive data in outsourced PPGNN computing scenarios, but also provide technical support for a wider range of privacy computing scenarios. Therefore, this problem has become one of the key technical challenges that need to be solved in the field of information security. Summary of the invention
[0006] The purpose of the present invention is to solve the shortcomings of the existing multi-party privacy protection array access method to improve the efficiency of data security access under privacy protection.
[0007] The technical solution of the present invention is as follows:
[0008] A privacy protection and data security access method for graph neural networks, which is suitable for secure access to data under privacy protection. The entities of the method include a plaintext array a and an index I holder, and a participant P performing method calculations. i (i∈{0,1,2,3}) and obtain the target object of access data a[I], the processing process includes the following steps:
[0009] Step 1: Secret sharing of plaintext data;
[0010] The plaintext array a and the index I holder use the secret sharing algorithm to generate a 2-out-of-4 copy secret share in, x is group a or I, and each participant holds a secret fragment [a] i , [a] ′ i , [I] i and [I]′ i , i∈{0,1,2,3}.
[0011] Step 2: Secret fragment conversion;
[0012] Each participant executes the secret fragment conversion algorithm (Algorithm 2) to convert the 2-out-of-4 replication secret sharing into a 2-out-of-2 addition secret sharing. and Convert to and .
[0013] Step 3: Rotate the ciphertext array and randomize the index;
[0014] All parties involved are based on and Rotate the ciphertext array and randomize the index.
[0015] Step 4: Privacy-preserving data access;
[0016] Each participant uses the rotated ciphertext array and randomized index to access data and obtain the data in ciphertext state.
[0017] Step 5 reconstructs the plaintext access data;
[0018] Any two participants send the secret fragments to the target object, and the target object uses the plaintext reconstruction algorithm (Algorithm 5) to reconstruct the plaintext data a[I].
[0019] Beneficial Effects
[0020] The present invention uses 2-out-of-2 addition secret sharing and 2-out-of-4 replication secret sharing technology, and through four-party interaction, can achieve secure access to data while protecting array elements and index information from being leaked. In scenarios where there are multiple calls to the privacy-preserving array access method, the present invention can significantly save time and server costs.
[0021] Specifically, the present invention is based on secret sharing technology, and the four participants are P0, P1, P2, and P3. First, the plaintext array and index are split into secret slices through 2-out-of-4 replication secret sharing and distributed to the participants P0, P1, P2, and P3. Subsequently, the secret sharing conversion protocol is used to convert it into 2-out-of-2 addition secret sharing and perform array element rotation and index randomization. Next, secure access to data is completed through four-party interaction.
[0022] The present invention has provable security, and considering a semi-honest security model, the probability that an attacker obtains array elements and indexes is negligible. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 The overall process of array access for privacy protection of the method of the present invention;
[0024] Figure 2 This is an example diagram of the privacy protection graph neural network training and reasoning process of the method of the present invention;
[0025] Figure 3 The total time comparison result of the performance test of the embodiment of the present invention;
[0026] Figure 4 The following is a comparison result of communication time in the performance test of the embodiment of the present invention. DETAILED DESCRIPTION
[0027] The technical solution provided by the present application will be further described below in conjunction with specific embodiments and accompanying drawings. The advantages and features of the present application will become more apparent with the following description.
[0028] The present invention belongs to the field of information security technology, and discloses a privacy protection and data security access method for graph neural networks. The method comprises: step 1 plaintext data secret sharing, step 2 ciphertext array and index rotation, step 3 privacy protection data access, step 4 privacy protection data access, and step 5 reconstruction of plaintext access data. The above steps use 2-out-of-2 addition secret sharing and 2-out-of-4 replication secret sharing technology. Based on multi-party secure computing, the present invention shares the plaintext array and plaintext index addition secret as secret fragments, and sends them to a four-party server with semi-honest security for holding. Through the interaction of the four-party servers, the array can be accessed in the ciphertext state to protect the privacy of the array and index. The scheme has the following characteristics: (1) high security: the array and index information are hidden in the secret sharing fragments to avoid the leakage of private information, and it has provable security; (2) high efficiency: through the four-party interaction, the additional waiting time when accessing the privacy protection array can be effectively avoided. The embodiment shows that the method has high performance and economic benefits. The technical scheme provided by the present invention will be further described in conjunction with specific embodiments and their accompanying drawings.
[0029] The symbols used in the present invention are shown in Table 1.
[0030] Table 1 Symbols used in the present invention
[0031]
[0032] A privacy protection and data security access method for graph neural networks. The entities of the method include a plaintext array a and an index I holder, and a participant P performing method calculations. i (i∈{0,1,2,3}) and obtain the target object of access data a[I], the processing process includes the following steps: (e.g. Figure 1 )
[0033] Step 1: Secret sharing of plaintext data;
[0034] The plaintext array a and the index I holder use the secret sharing algorithm to generate a 2-out-of-4 copy secret share in, x is group a or I, and each participant holds a secret fragment [a] i , [a] ′ i , [I] i and[I] ′ i , i∈{0,1,2,3}.
[0035] Step 2 Secret Fragment Conversion;
[0036] Each participant executes the secret fragment conversion algorithm (Algorithm 2) to convert the 2-out-of-4 replication secret sharing into a 2-out-of-2 addition secret sharing. and Convert to and .
[0037] Step 3: Rotate the ciphertext array and randomize the index;
[0038] All parties involved are based on and Rotate the ciphertext array and randomize the index.
[0039] Step 4: Privacy-preserving data access;
[0040] Each participant uses the rotated ciphertext array and randomized index to access data and obtain the data in ciphertext state.
[0041] Step 5 reconstructs the plaintext access data;
[0042] Any two participants send the secret fragments to the target object, and the target object uses the plaintext reconstruction algorithm (Algorithm 5) to reconstruct the plaintext data a[I].
[0043] The above step 1 reuses the 2-out-of-4 replicated secret sharing algorithm proposed in the paper "PrivPy: Enabling Scalable and General Privacy-Preserving Machine Learning", and is therefore not an original part of the present invention.
[0044] Furthermore, the step 1 comprises:
[0045] Step 1.1 The plaintext array and the index holder use a secret sharing algorithm to generate secret fragments. For the convenience of description, the present invention only takes the secret sharing process of a plaintext element as an example, and the secret sharing algorithm is as described in Algorithm 1:
[0046] Algorithm 1: The secret sharing algorithm SS(x) has the following input: is a plaintext element, and the output is a secret shared fragment The process includes:
[0047] S1.1.1 Data holder from the ring Uniformly randomly select element r from;
[0048] S1.1.2 The data holder calculates [x]0 = r (mod m), [x]1 = xr (mod m), and sends [x]0 to P0 and [x]1 to P1;
[0049] S1.1.3 P0 and P1 are based on the random number seed 01 Generate the same random number r locally and independently 01 ;
[0050] S1.1.4P0 receives [x]0 and sets [x]′0=[x]0-r 01 (mod m), P0 then sends [x]0 to P3 and [x]′0 to P2;
[0051] S1.1.5P1 receives [x]1 and sets [x]′1=[x]0+r 01 (mod m), P1 then sends [x]1 to P2 and [x]′1 to P3;
[0052] S1.1.6P2 Let [x]2 = [x]1, [x]′2 = [x]′0;
[0053] S1.1.7P3 Let [x]3 = [x]0, [x]′3 = [x]′1;
[0054] S1.1.8 Output
[0055] Step 1.2 After the execution of Algorithm 1, each participant holds a secret fragment, namely
[0056] P0 holds [x]0 = r (mod m), [x]′0 = [x]0 - r 01 (mod m),
[0057] P1 holds [x]1 = xr (mod m), [x]′1 = [x]0 + r 01 (mod m),
[0058] P2 holds [x]2 = [x]1 = xr (mod m), [x]′2 = [x]′0 = [x]0-r 01 (mod m),
[0059] P3 holds [x]3 = [x]0 = r (mod m), [x]′3 = [x]′1 = [x]0 + r 01 (mod m).
[0060] After executing Algorithm 1, the plaintext array a and index I obtain the secret fragment [a] i , [a]′ i , [I] i and [I]′ i , i∈{0,1,2,3}.
[0061] To simplify the representation, the modulus m will be ignored in the following description.
[0062] Furthermore, the step 2 comprises:
[0063] Step 2.1 Each participant executes the secret fragment conversion algorithm (Algorithm 2) to convert the 2-out-of-4 replication secret sharing into a 2-out-of-2 addition secret sharing. For the convenience of description, the present invention only takes the secret fragment conversion process of one plaintext element as an example, and the Algorithm 2 is designed as follows:
[0064] Algorithm 2: Secret fragment conversion algorithm Its input is the replica secret fragment of each participant, output <x>It is additive secret sharing; the process of Algorithm 2 includes:
[0065] S2.1.1 P0 and P1 are based on the random number seed 01 Generate a random number r′ 01 , -r′ 01 ;
[0066] S2.1.2P0 Let [x]0 = r + r′ 01 , P1 let [x]1 = xrr′ 01 , P2 and P3 let [x]2 and [x]3 be
[0067] S2.1.3 Output <x>=([x]0,[x]1), each party holds a new secret fragment (i.e., P0 and P1 hold [x]0 and [x]1 respectively, and P2 and P3 hold a secret fragment of ).
[0068] Step 2.2 By calling Algorithm 2, each participant will and Convert to< / x> < / x> and .
[0069] Furthermore, the step 3 comprises:
[0070] Step 3.1 Each participant shall and The ciphertext array is rotated and the index is randomized. The process is shown in Algorithm 3:
[0071] Algorithm 3: Ciphertext rotation and index randomization algorithm ER( , ), whose input is the array and index of each participant, and output is the rotated ciphertext array 'With the randomized index '; The process of Algorithm 3 includes:
[0072] S3.1.1 P0 and P1 are based on the random number seed 01 Generate random numbers
[0073] Where t is the length of array a;
[0074] S3.1.2 Use of P0 and P1 Rotate[a] i , where i∈{0,1}:
[0075]
[0076] S3.1.3 P i pass Offset index [I] i , that is, where i∈{0,1};
[0077] S3.1.4 To protect the privacy of each element, P0 and P1 use cover[a]′ i Elements in:
[0078]
[0079] S3.1.5 P0 outputs [a]″0 and [j]0, P1 outputs [a]″1 and [j]1, P2 and P3 output
[0080] Step 3.2 P0 sends [a]″0 and [j]0 to P2, and P1 sends [a]″1 and [j]1 to P3;
[0081] Further, the step 4 comprises:
[0082] Step 4.1 P2 and P3 use the locally owned fragments [I]2 and [I]3 and the received [j]0 and [j]1 to restore the randomized index h. Taking P2 as an example, P3 recovery h is similar to P2.
[0083] Step 4.2 Each participant executes Algorithm 4 to access array element a[I] without leaking any information; Algorithm 4 is designed as follows:
[0084] Algorithm 4: Privacy-preserving data access algorithm Its input h is the randomized index. is the rotated array, and the output is the accessed ciphertext data The process of Algorithm 4 includes:
[0085] S4.2.1 P2 and P3 based on random number seed 23 Generate random numbers
[0086] S4.2.2 P2 Send To P1, Give P0;
[0087] S4.2.3 P3 Send To P0, To P1;
[0088] S4.2.4 P0 command
[0089] S4.2.5 P1 Order
[0090] S4.2.6 P2 Order
[0091] S4.2.7 P3 Order
[0092] Further, the step 5 comprises:
[0093] Step 5.1 Each participant accesses the ciphertext data based on Algorithm 4 in Step 4 Reconstruct the plaintext data a[I], the process is shown in Algorithm 5:
[0094] Algorithm 5: Plaintext reconstruction algorithm The input is the 2-out-of-4 replicated secret sharing fragments held by any two parties (P0 and P1 are taken as examples here), and the output is the accessed plaintext data a[I]. The process of Algorithm 5 includes:
[0095] S5.1.1 P0 sends the local [a[I]]0 to the target object, and P1 sends the local [a[I]]1 to the target object;
[0096] S5.1.2 The target object reconstructs the plaintext a[I]=[a[I]]0+[a[I]]1.
[0097] The overall process of the privacy protection and data security access method for graph neural network proposed in this invention is as follows: Figure 1 shown.
[0098] Taking the privacy-preserving graph neural network training and reasoning scenario as an example, the following introduces the various participants in this application scenario. Figure 2 :
[0099] The data owner is the owner of the plaintext graph data. He lacks computing resources suitable for graph neural network training and reasoning, and needs to input the data into the cloud server for outsourced graph neural network model training and reasoning.
[0100] The cloud server deployed in the untrusted cloud environment is a participant (i.e., the computing party participating in the algorithm calculation in the present invention), and the participating party completes the training and reasoning of the graph neural network model through interaction.
[0101] In the training and reasoning process of the privacy-preserving graph neural network model (taking the graph convolution layer as an example), it is necessary to aggregate the states of neighboring nodes, so the array access algorithm needs to be called multiple times. Below, only the secure array access process in this application scenario is described.
[0102] First, the data owner executes step 1 and runs Algorithm 1 to generate the secret fragments of the plaintext array and index and sends them to the participants, each of whom holds [a] i , [a]′ i , [I] i and [I]′ i , where i∈{0,1,2,3}. Then, the participants execute step 2 and run Algorithm 2 to and Convert to and , that is, each participant converts the replicated secret sharing fragments they hold into additive secret sharing fragments. Then, the participant will execute step 3 and run algorithm 3 to rotate the ciphertext array and randomize the ciphertext index. Finally, the participant executes step 4 and runs algorithm 4 to access the data with privacy protection. The ciphertext data obtained in step 4 can be used in the subsequent steps of graph neural network model training and inference, or directly execute algorithm 5 in step 5 to obtain the ciphertext data. Reconstructed into plaintext data a[I].
[0103] Figure 2 An intuitive description of the proposed application scenario is given. The threat model of the method described in the present invention is a semi-honest security model, that is, all participants are semi-honest and non-collusive. This also implies that each participant will run the algorithm honestly, but their goal is to obtain the privacy of the data owner to the greatest extent based on the intermediate records during the operation of the algorithm. In the present invention, it is assumed that the communication channels of each participant are secure and no information will be leaked during the transmission process.
[0104] Test effect verification
[0105] The privacy protection and data security access method for graph neural network proposed in the present invention is tested by simulating four cloud servers using four processes. The processor of the experimental equipment is Intel(R) Core(TM) i7-13700KF, which contains 8 CPUs and 16GB memory. The parameter of the present invention is l=64, and the selected data sets are graph data sets Cora, CiteSeer and PubMed, which have 2708, 3327 and 19717 nodes respectively, and the feature numbers are 1433, 3703 and 500 respectively. In addition, the present invention uses tc (traffic control) tool to simulate the local LAN environment, and the bandwidth is set to 10GBps and the delay is 0.3ms.
[0106] The present invention runs a round of secure data access algorithm on Cora, CiteSeer and PubMed datasets respectively. The performance test results are shown in Figure 3 and Figure 4 Compared with the paper "Secgnn: Privacy-preserving graph neural network training and inference as a cloud service", the total time of the method of the present invention is improved by 1.39 to 1.99 times, and the communication efficiency is improved by 1.28 to 2.65 times. The experimental results show that the method of the present invention can accumulate greater advantages and economic benefits in scenarios where the secure array access algorithm is called multiple times (such as privacy-preserving graph model training and inference).
[0107] The above description is only a description of the preferred embodiments of the present application, and is not intended to limit the scope of the present application. Any changes or modifications made by any person skilled in the art based on the above disclosed technical contents shall be deemed as equivalent effective embodiments and shall fall within the scope of protection of the technical solution of the present application.
Claims
1. A privacy protection and data security access method for graph neural networks, which is suitable for secure access to data under privacy protection. The entities of the method include the plaintext array a and the index I holder, and the participant P who performs the method calculation i (i∈{0,1,2,3}) and obtain the target object of access data a[I], characterized in that, The processing process includes the following steps: Step 1: Secret sharing of plaintext data; The plaintext array a and the index I holder use the secret sharing algorithm to generate a 2-out-of-4 copy secret share in, x is group a or I, and each participant holds a secret fragment [a] i , [a]′ i , [I] i and [I]′ i , i∈{0,1,2,3}; Step 2: Secret fragment conversion; Each participant executes the secret fragment conversion algorithm (Algorithm 2) to convert the 2-out-of-4 replication secret sharing into a 2-out-of-2 addition secret sharing. and Convert to and ; Step 3: Rotate the ciphertext array and randomize the index; All parties involved are based on and Rotate the ciphertext array and randomize the index; Step 4: Privacy-preserving data access; Each participant uses the rotated ciphertext array and randomized index to access data and obtain the data in ciphertext state. Step 5 reconstructs the plaintext access data; Any two participants send the secret fragments to the target object, and the target object uses the plaintext reconstruction algorithm (Algorithm 5) to reconstruct the plaintext data a[I].
2. A privacy protection and data security access method for graph neural network as claimed in claim 1, characterized in that: The step 2 comprises: Step 2.1 Each participant executes the secret fragment conversion algorithm (Algorithm 2) to convert the 2-out-of-4 replication secret sharing into a 2-out-of-2 addition secret sharing; Step 2.2 By calling Algorithm 2, each participant will and Convert to and 。 3. A privacy protection and data security access method for graph neural network as claimed in claim 2, characterized in that: The process of Algorithm 2 includes: S2.1.1 P0 and P1 are based on the random number seed 01 Generate a random number r′ 01 , -r′ 01 ; S2.1.2P0 Let [x]0 = r + r′ 01 , P1 let [x]1 = xrr′ 01 , P2 and P3 let [x]2 and [x]3 be S2.1.3 Output <x>=([x]0,[x]1), each party holds a new secret fragment (i.e., P0 and P1 hold [x]0 and [x]1 respectively, and P2 and P3 hold a secret fragment of ).< / x> 4. A privacy protection and data security access method for graph neural network as claimed in claim 1, characterized in that: The step 3 comprises: Step 3.1 Each participant shall and Rotate the ciphertext array and randomize the index; Step 3.2 P0 sends [a]″0 and [j]0 to P2, and P1 sends [a]″1 and [j]1 to P3.
5. A privacy protection and data security access method for graph neural network as claimed in claim 4, characterized in that: The process of the rotation and index randomization algorithm of the ciphertext array in step 3.1 includes: S3.1.1 P0 and P1 are based on the random number seed 01 Generate random numbers Where t is the length of array a; S3.1.2 Use of P0 and P1 Rotate[a] i , where i∈{0,1}: S3.1.3 P i pass Offset index [I] i , that is, where i∈{0,1}; S3.1.4 To protect the privacy of each element, P0 and P1 use cover[a]′ i Elements in: S3.1.5P0 outputs [a]″0 and [j]0, P1 outputs [a]″1 and [j]1, P2 and P3 output 6. A privacy protection and data security access method for graph neural network as claimed in claim 1, characterized in that: The step 4 comprises: Step 4.1 P2 and P3 use the locally owned fragments [I]2 and [I]3 and the received [j]0 and [j]1 to restore the randomized index Step 4.2 Each participant executes Algorithm 4 to access array element a[I] without leaking any information.
7. A privacy protection and data security access method for graph neural network according to claim 6, characterized in that: The process of Algorithm 4 in step 4.2 includes: S4.2.1 P2 and P3 based on random number seed 23 Generate random numbers S4.2.2 P2 Send To P1, Give P0; S4.2.3 P3 Send To P0, To P1; S4.2.4 P0 command S4.2.5P1 Order S4.2.6P2 Order S4.2.7P3 Order 8. A privacy protection and data security access method for graph neural network as claimed in claim 1, characterized in that: The step 5 comprises: Step 5.1 Each participant accesses the ciphertext data based on Algorithm 4 in Step 4 Execute Algorithm 5 to restore the plaintext data a[I].
9. A privacy protection and data security access method for graph neural network as claimed in claim 8, characterized in that: The process of Algorithm 5 in step 5.1 includes: S5.1.1P0 sends the local [a[I]]0 to the target object, and P1 sends the local [a[I]]1 to the target object; S5.1.2 The target object reconstructs the plaintext a[I]=[a[I]]0+[a[I]]1.