GPT model security access method based on deep learning

By constructing hidden space manifolds and introducing target protection distribution manifolds, combining optimal transportation theory and dynamic noise distribution, the problems of privacy protection and semantic information retention in the GPT model are solved, and dynamic privacy protection and high semantic consistency data generation are achieved.

CN119961971AActive Publication Date: 2025-05-09BEIJING QINGXUNDA TECHNOLOGY DEVELOPMENT CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510039952.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-10
Publication Date
2025-05-09
Estimated Expiration
2045-01-10

AI Technical Summary

Technical Problem

When applied to GPT models, it is difficult to effectively protect the privacy of user input data while maintaining model inference performance, especially in terms of the retention of data semantic information and dynamic adjustment of privacy protection intensity.

Method used

By constructing a hidden space manifold of user input data, introducing a target protection distribution manifold, and calculating the mapping function using the optimal transportation theory to generate protection data. This method combines dynamic noise distribution and mapping functions to dynamically adjust the covariance matrix to control the protection intensity, ensuring that the protected data retains semantic information while protecting privacy.

Benefits of technology

It realizes dynamic protection of user privacy, and can adjust the protection intensity in real time according to different scenarios to reduce the risk of privacy leakage. At the same time, high semantic consistency data is generated while protecting privacy, and maintain the inference performance of the GPT model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119961971A_ABST
    Figure CN119961971A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of artificial intelligence data security, and discloses a GPT model security access method based on deep learning, and the method comprises the steps: 1, constructing a hidden space manifold of user input data, processing the user input data through a variational auto-encoder, mapping the user input data to a hidden space representation through the encoder, and obtaining a hidden space representation; probability distribution of the hidden space is obtained, in the probability distribution of the hidden space, priori distribution of the hidden space is set as Gaussian distribution, and the hidden space representation is used as embedded representation of a user input data manifold so as to construct a hidden space manifold; and 2, according to the hidden space manifold constructed in the step 1, defining a target protection distribution manifold. The target protection distribution is introduced into the hidden space manifold of the data input by the user, dynamic protection of the privacy of the user is realized in combination with a mode of dynamically adjusting the covariance matrix, and the effects of adjusting the protection intensity in real time according to different scenes and effectively reducing the privacy leakage risk are obtained.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence data security technology, and specifically to a GPT model security access method based on deep learning. Background Art

[0002] With the rapid development of deep learning technology, large-scale pre-trained language models represented by GPT have achieved remarkable results in the field of natural language processing. They have shown extremely high generation capabilities in machine translation, dialogue generation, and text summarization tasks. However, in actual applications, the GPT model requires users to input data for reasoning, and the input data contains highly sensitive information, such as personal privacy, medical records, financial data, etc. Therefore, how to protect the privacy of user input data while maintaining the reasoning performance of the model is a key issue in current research and application.

[0003] Existing privacy protection methods, such as differential privacy and homomorphic encryption, can provide a certain degree of privacy protection, but they have obvious limitations in practical applications. Differential privacy methods protect privacy by introducing noise into the data. Noise can effectively conceal sensitive information, but at the same time it will lead to the loss of data semantic information and reduce the reasoning accuracy of the GPT model. Homomorphic encryption protects privacy by encrypting the input data, but the encryption calculation complexity is high, which significantly increases the reasoning time of the model and cannot meet the performance requirements of practical applications. In addition, most methods use static privacy protection strategies and cannot dynamically adjust the privacy protection strength according to different task scenarios and user needs.

[0004] In response to the above problems, research in recent years has attempted to combine mathematical optimization methods with deep learning models, and provide efficient solutions for privacy protection through methods such as manifold modeling and optimal transport theory. For example, manifold modeling can represent the local structural characteristics of user input data, and optimal transport theory can achieve the best match between different distributions, thereby achieving a balance between privacy protection and data semantics preservation. However, most research lacks practical application optimization for GPT models, especially in terms of how to generate dynamic protection data and how to adapt protection data to GPT model reasoning.

[0005] Therefore, those skilled in the art provide a deep learning-based GPT model security access method to solve the above-mentioned problems. Summary of the invention

[0006] In view of the deficiencies in the prior art, the present invention provides a GPT model security access method based on deep learning to solve the problems raised in the above background technology.

[0007] To achieve the above objectives, the present invention is implemented through the following technical solutions: A GPT model security access method based on deep learning, comprising:

[0008] Step 1: construct a latent space manifold of user input data, use a variational autoencoder to process the user input data, map the user input data to a latent space representation through the encoder, and obtain a probability distribution of the latent space. In the latent space probability distribution, the prior distribution of the latent space is set to a Gaussian distribution, and the latent space representation is used as an embedded representation of the user input data manifold to construct the latent space manifold;

[0009] Step 2: According to the latent space manifold constructed in step 1, define the target protection distribution manifold, and introduce the protection distribution on the latent space manifold. The target protection distribution is described by Gaussian distribution. The covariance matrix in the target protection distribution is used to control the strength of data protection.

[0010] Step 3: Based on the target protection distribution manifold defined in step 2, a mapping model is established from the user input data latent space manifold to the target protection distribution manifold. The mapping model calculates the data matching between the input manifold and the target manifold to establish a mapping function between the manifolds. The mapping function is used to convert the input data latent space representation into the target protection distribution representation.

[0011] Step 4: Based on the mapping model established in step 3, generate protection data. The protection data is obtained by combining the latent space representation of the user input data with the dynamic noise distribution through a mapping function. The dynamic noise distribution is set based on the target protection distribution manifold. The protection data includes the mapped latent space representation and the generated dynamic noise.

[0012] Step 5: Input the protection data generated in step 4 into the GPT model, use the GPT model for reasoning, perform semantic understanding on the latent space representation of the protection data during the reasoning process, complete the processing of the protection data in combination with the generated dynamic noise, and output the reasoning result.

[0013] Preferably, the construction of the latent space manifold in step 1 uses the probability distribution described by the following formula:

[0014] P(x)=∫P(x|z)P(z)dz,

[0015] Among them, P(x) represents the distribution of user input data,

[0016] P(z) represents the prior distribution of the latent space, which is set to Gaussian distribution N(0, I).

[0017] z represents the latent space representation of the user input data, P(x|z) is the generative distribution from the latent space to the input data, and dz represents the variable integrated in the latent space.

[0018] Preferably, the target protection distribution manifold in step 2 is described by the following formula:

[0019] Q(y)~N(0,Σ),

[0020] Among them, Q(y) represents the target protection distribution, y represents the protection data generated by noise on the latent space manifold, N(0, Σ) is a Gaussian distribution with a mean of 0 and a covariance matrix of Σ.

[0021] The mean value of 0 indicates that the noise of the target protection distribution is symmetric around the center of the input data distribution in the latent space, and the covariance matrix Σ determines the amplitude and direction of the noise.

[0022] Preferably, the covariance matrix Σ is dynamically adjusted according to the privacy protection requirement, and the adjustment method is expressed by the following formula:

[0023]

[0024] Among them, Σ t represents the covariance matrix at the current moment, Σ t-1 represents the covariance matrix of the previous moment, B represents the adjustment rate, Σ is the covariance matrix,

[0025] R(Σ) represents the privacy protection risk function, which is used to evaluate the impact of the current covariance matrix on the risk of privacy leakage.

[0026] Preferably, the establishment of the mapping model in step 3 solves the mapping function from the input manifold to the target manifold by the following formula:

[0027]

[0028] Among them, φ(x) represents the mapping function, φ * represents the optimal mapping function, x is the input data coordinate, dP(x) is the probability measure on the input manifold, and c(x, φ(x)) represents the transportation cost function from the input manifold to the target manifold, which is described by the following formula:

[0029] c(x,φ(x))=g ij (x i -φ i (x))(x j -φ j (x)),

[0030] Among them, g ij represents the metric tensor on the manifold, x i and x j are the i-th and j-th coordinate components of the input data point x, φ i (x) and φ j (x) are the i-th and j-th coordinate components of the mapped data point φ(x).

[0031] Preferably, the mapping function is represented by a potential function ψ(x), and the mapping function is solved as follows:

[0032]

[0033] Among them, φ(x) represents the mapping function, represents the rate of change of the potential function ψ(x) at x;

[0034] The optimization goal of the potential function ψ(x) is to minimize the following loss function:

[0035]

[0036] in, is the gradient of the potential function, represents the optimal transport loss function between manifolds, g ij represents the metric tensor on the manifold, x i and x j are the i-th and j-th coordinate components of the input data point x, and is the gradient component of the potential function ψ(x) in the i-th and j-th dimension coordinates, and dP(x) is the probability measure on the input manifold.

[0037] Preferably, the mapping function is solved by optimizing the gradient descent method, and the potential function is updated as follows:

[0038]

[0039] Among them, ψ t represents the potential function of the current iteration, ψ t-1 represents the potential function of the previous iteration, α is the learning rate, Represents the partial derivative of the loss function L(ψ) with respect to the potential function ψ(x).

[0040] Preferably, the generation of the protection data in step 4 includes the following process:

[0041] x ′ =φ(x)+η,

[0042] Among them, x ′ represents the generated protection data, φ(x) is the mapping function, and η is the dynamic noise sampled in the target protection distribution Q(y).

[0043] Preferably, the protection data x ′ The generation of satisfies the following disturbance intensity constraints:

[0044] ∥φ(x)-x∥≤∈,

[0045] Among them, φ(x) is the mapping function, x is the user's original input data,

[0046] ∈ represents the upper bound of the perturbation intensity, which is used to ensure the semantic consistency between the protection data and the user input data.

[0047] Preferably, in step 5, the protected data x ′ When input into the GPT model for reasoning, the latent space representation of the protected data is combined with dynamic noise for semantic processing, and the accuracy of the reasoning result y is evaluated by the BLEU score and the generated text fluency score;

[0048] The BLEU is an automated evaluation indicator used to measure the similarity between generated text and reference text.

[0049] The present invention provides a GPT model security access method based on deep learning. It has the following beneficial effects:

[0050] 1. The present invention introduces the target protection distribution into the latent space manifold of the user input data and combines it with the method of dynamically adjusting the covariance matrix to achieve dynamic protection of user privacy, thereby achieving the effect of being able to adjust the protection strength in real time according to different scenarios and effectively reducing the risk of privacy leakage.

[0051] 2. The present invention calculates the mapping function between the user input manifold and the target protection manifold based on the optimal transportation theory, thereby retaining the semantic information of the user input data during the generation process of the protection data, thereby achieving the effect of generating highly semantically consistent data while protecting privacy.

[0052] 3. The present invention generates protection data by combining the mapping function with the dynamic noise distribution, sets the disturbance intensity limit of the protection data, and achieves a dynamic balance between the privacy protection intensity and the semantic integrity of the protection data, thereby obtaining a privacy protection effect that adapts to different task scenarios.

[0053] 4. The present invention implements efficient semantic understanding of privacy-preserving data by inputting the protection data into the GPT model and combining the latent space representation of the protection data with the dynamic noise distribution for semantic processing, thereby achieving the effect that the protection data can maintain high reasoning quality while protecting privacy. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] Figure 1 It is a flow chart of the present invention. DETAILED DESCRIPTION

[0055] In order to make the technical personnel in the technical field understand the scheme of the present invention, the technical scheme in the embodiment of the present invention will be clearly and completely described below in combination with the drawings in the embodiment of the present invention. Obviously, the described embodiment is a partial embodiment of the present invention, not a complete embodiment. Based on the embodiment of the present invention, other embodiments obtained by ordinary technicians in the field without creative work should fall within the scope of protection of the present invention.

[0056] The present invention is described in detail below in conjunction with the accompanying drawings:

[0057] Example:

[0058] Please refer to the attached Figure 1 , an embodiment of the present invention provides a GPT model security access method based on deep learning, comprising:

[0059] Step 1: construct a latent space manifold of user input data, use a variational autoencoder to process the user input data, map the user input data to a latent space representation through the encoder, and obtain a probability distribution of the latent space. In the latent space probability distribution, the prior distribution of the latent space is set to a Gaussian distribution, and the latent space representation is used as an embedded representation of the user input data manifold to construct the latent space manifold;

[0060] Step 2: According to the latent space manifold constructed in step 1, define the target protection distribution manifold, and introduce the protection distribution on the latent space manifold. The target protection distribution is described by Gaussian distribution. The covariance matrix in the target protection distribution is used to control the strength of data protection.

[0061] Step 3: Based on the target protection distribution manifold defined in step 2, a mapping model is established from the user input data latent space manifold to the target protection distribution manifold. The mapping model calculates the data matching between the input manifold and the target manifold to establish a mapping function between the manifolds. The mapping function is used to convert the input data latent space representation into the target protection distribution representation.

[0062] Step 4: Based on the mapping model established in step 3, generate protection data. The protection data is obtained by combining the latent space representation of the user input data with the dynamic noise distribution through a mapping function. The dynamic noise distribution is set based on the target protection distribution manifold. The protection data includes the mapped latent space representation and the generated dynamic noise.

[0063] Step 5: Input the protection data generated in step 4 into the GPT model, use the GPT model for reasoning, perform semantic understanding on the latent space representation of the protection data during the reasoning process, complete the processing of the protection data in combination with the generated dynamic noise, and output the reasoning result.

[0064] Benefits of step 1: By using a variational autoencoder to process user input data, the data is mapped to a latent space representation, and the latent space probability distribution is modeled as a Gaussian distribution, completing the abstract representation of the manifold structure of the input data. The latent space representation can effectively capture the local features of the data, reduce the data dimension, and simplify the subsequent calculation process. In addition, the assumption of Gaussian distribution lays a mathematical foundation for the introduction of transportation theory, allowing the privacy protection process to be carried out with a rigorous mathematical model. The benefit of step 1 is that it can efficiently describe the distribution of input data while providing support for subsequent protection data generation;

[0065] The benefit of step 2: Introduce the target protection distribution in the latent space manifold, and use Gaussian distribution to describe the target protection distribution, where the covariance matrix is ​​used to control the strength of the protection data. This process provides a basis for the dynamic noise generation mechanism, so that the strength of privacy protection can be flexibly adjusted according to different scenarios. By defining the target protection distribution, it is ensured that there is good mathematical operability between the protected data and the original data. The benefit of step 2 is that it provides high flexibility and adaptability for privacy protection, and can achieve dynamic adjustment in different application scenarios;

[0066] Benefits of step 3: By calculating the data match between the input manifold and the target manifold based on the transport theory, a mapping model is established to generate a mapping function from the input manifold to the target protection manifold. The mapping function can convert the latent space representation of the user input data into the target protection distribution representation in an optimal way, while minimizing the semantic loss in the data conversion process. Step 3 uses the optimal transport theory to solve the problem of semantic preservation in the process of protecting data generation, ensuring that the original semantic information of the data is completely preserved during the privacy protection process. The benefit of step 3 is that it significantly improves the semantic consistency of the protected data and avoids the negative impact of privacy protection on data quality;

[0067] Benefits of step 4: Based on the mapping model, the protection data is generated by combining the mapping function with the dynamic noise distribution. The addition of dynamic noise enhances the privacy protection strength while ensuring the compatibility of the protection data with the input data. The protection data contains the latent space representation after mapping and the generated dynamic noise. By setting the perturbation intensity limit, the relationship between the privacy protection strength and the semantic integrity is dynamically balanced. The benefit of step 4 is that it realizes the dynamic generation of protection data, so that the protection strength can adapt to different privacy demand scenarios, while ensuring the quality and reliability of the protection data;

[0068] Benefits of step 5: By inputting the generated protected data into the GPT model, combined with the latent space representation of the protected data and the dynamic noise distribution, the GPT model can perform semantic processing on the protected data and generate inference results. Step 5 optimizes the adaptation method between the protected data and the GPT model to ensure that the privacy-preserving data can be correctly understood by the GPT model and generate inference results.

[0069] The construction of the latent space manifold in step 1 uses the probability distribution described by the following formula:

[0070] P(x)=∫P(x|z)P(z)dz,

[0071] Among them, P(x) represents the distribution of user input data,

[0072] P(z) represents the prior distribution of the latent space, which is set to Gaussian distribution N(0, I).

[0073] z represents the latent space representation of the user input data, P(x|z) is the generative distribution from the latent space to the input data, and dz represents the variable integrated in the latent space.

[0074] By mapping high-dimensional user input data x to a low-dimensional latent space representation z, the data dimension is reduced, effectively simplifying the complexity of subsequent calculations. The low-dimensional latent space representation retains the main features of the input data and reduces the demand for computing resources;

[0075] The construction of latent space manifold establishes the latent structure modeling of user input data through P(z). The latent space prior distribution P(z) is assumed to be a Gaussian distribution, which can describe the global distribution characteristics of the input data, while P(x|z) describes the local generation characteristics of the data. The two-layer modeling method can capture the complex characteristics and internal connections of the input data and accurately represent the distribution of the data;

[0076] The integral form in the formula provides a unified mathematical description for the manifold construction of the input data. The joint distribution of P(x|z) and P(z) fully characterizes the generation process from the latent space to the original data. The modeling method based on probability distribution lays a theoretical foundation for the subsequent transportation theory and the definition of protection distribution, so that the latent space manifold can be naturally embedded in the privacy protection process;

[0077] The introduction of the integral variable z in the latent space enables the generated distribution P(x|z) to dynamically adjust the characteristics of the generated data according to the latent space representation, allowing the generation of adaptive protection data for different types of input data and application scenarios, providing support for subsequent dynamic noise generation and mapping;

[0078] Through the latent space representation z mapping, the original high-dimensional data x is decomposed into a low-dimensional representation and generative distribution of the latent space, reducing the dependence on the original input data and reducing the exposure of sensitive information, providing a barrier for subsequent privacy protection mechanisms.

[0079] The target protection distribution manifold in step 2 is described by the following formula:

[0080] Q(y)~N(0,Σ),

[0081] Among them, Q(y) represents the target protection distribution, y represents the protection data generated by noise on the latent space manifold, N(0, Σ) is a Gaussian distribution with a mean of 0 and a covariance matrix of Σ.

[0082] The mean value of 0 indicates that the noise of the target protection distribution is symmetric around the center of the input data distribution in the latent space, and the covariance matrix Σ determines the amplitude and direction of the noise.

[0083] The covariance matrix Σ is dynamically adjusted according to the privacy protection requirements, and the adjustment method is expressed by the following formula:

[0084]

[0085] Among them, Σ t represents the covariance matrix at the current moment, Σ t-1 represents the covariance matrix of the previous moment, B represents the adjustment rate, Σ is the covariance matrix,

[0086] R(Σ) represents the privacy protection risk function, which is used to evaluate the impact of the current covariance matrix on the risk of privacy leakage.

[0087] The covariance matrix Σ of the target protection distribution manifold determines the amplitude and direction of the noise. By dynamically adjusting the formula, the intensity and distribution characteristics of the noise are adjusted in real time according to different privacy protection requirements. For example, in scenarios with high privacy requirements, the adjustment of the covariance matrix will increase the noise amplitude and reduce the possibility of privacy leakage. In scenarios with low privacy requirements, the noise intensity is reduced to retain the semantic consistency of the data. The dynamic adjustment mechanism makes the protection data more adaptable and can flexibly cope with a variety of task scenarios;

[0088] The mean of 0 indicates that the noise is symmetrical around the input data distribution center, so that the addition of noise is balanced in the latent space manifold and avoids deviation from the distribution of the input data. The adjustment method of the covariance matrix Σ is optimized through the gradient of the privacy protection risk function R(Σ) to evaluate the risk of privacy leakage caused by the current noise distribution. Through the dynamic optimization of the risk function, the probability of privacy leakage can be significantly reduced, and the protection of user privacy can be enhanced.

[0089] The dynamically adjusted covariance matrix controls the intensity of the noise and determines the direction of the noise. By properly designing the direction of Σ, disturbances to the data semantics can be avoided. Compared with the traditional fixed noise distribution, the dynamic adjustment mechanism can strike a balance between privacy protection and semantic integrity, ensuring that the generated protected data is more accurate in preserving the characteristics of the original data;

[0090] Dynamic adjustment of the covariance matrix is ​​achieved through the process of gradient descent optimization R(Σ). Compared with global optimization and regeneration of noise distribution, the gradient-based local optimization method improves computational efficiency. The gradient calculation cost of the privacy-preserving risk function is low, which is suitable for large-scale data scenarios, so that this method can significantly reduce computational overhead while ensuring the strength of privacy protection;

[0091] In the dynamic adjustment formula of the covariance matrix, the adjustment rate B is the key parameter that determines the sensitivity of the dynamic adjustment. By setting different B values, this formula can adapt to the privacy requirements of different task scenarios.

[0092] The mapping model in step 3 is established by solving the mapping function from the input manifold to the target manifold through the following formula:

[0093]

[0094] Among them, φ(x) represents the mapping function, φ * represents the optimal mapping function, x is the input data coordinate, dP(x) is the probability measure on the input manifold, and c(x, φ(x)) represents the transportation cost function from the input manifold to the target manifold, which is described by the following formula:

[0095] c(x,φ(x))=g ij (x i -φ i (x))(x j -φ j (x)),

[0096] Among them, g ij represents the metric tensor on the manifold, x i and x j are the i-th and j-th coordinate components of the input data point x, φ i (x) and φ j (x) are the i-th and j-th coordinate components of the mapped data point φ(x).

[0097] The mapping function is represented by the potential function ψ(x), and the solution of the mapping function is:

[0098]

[0099] Among them, φ(x) represents the mapping function, represents the rate of change of the potential function ψ(x) at x;

[0100] The optimization goal of the potential function ψ(x) is to minimize the following loss function:

[0101]

[0102] in, is the gradient of the potential function, represents the optimal transport loss function between manifolds, g ij represents the metric tensor on the manifold, x i and x j are the i-th and j-th coordinate components of the input data point x, and is the gradient component of the potential function ψ(x) in the i-th and j-th dimension coordinates, and dP(x) is the probability measure on the input manifold.

[0103] The solution of the mapping function is optimized by gradient descent method, and the potential function is updated as follows:

[0104]

[0105] Among them, ψ t represents the potential function of the current iteration, ψ t-1 represents the potential function of the previous iteration, α is the learning rate, Represents the partial derivative of the loss function L(ψ) with respect to the potential function ψ(x).

[0106] Through the optimal transportation theory, the mapping function φ(x) between the input manifold and the target manifold can complete the distribution transformation of data in an optimal way. The transportation cost function c(x, φ(x)) is minimized to ensure the correspondence between data points during the mapping process, while retaining the semantic information of the input data to the greatest extent. The mapping method based on optimal transportation effectively solves the problem of insufficient data semantic consistency in traditional noise generation technology;

[0107] By defining the transport cost function c(x, φ(x)) and introducing the manifold metric tensor g ij ,This method can consider the local geometric characteristics of data in the mapping from input manifold to target manifold. The manifold metric tensor reflects the local relationship of data points in space, which can reduce the loss of data features in the mapping process and avoid semantic distortion caused by protecting the generation of data;

[0108] The solution of the mapping function φ(x) is represented by the potential function ψ(x) and optimized by the gradient descent method. The introduction of the potential function simplifies the complex mapping problem into an optimization problem of a single scalar function, significantly reducing the complexity of the mapping calculation. Compared with directly calculating the mapping relationship between high-dimensional manifolds, this method has higher computational efficiency and is suitable for processing large-scale data sets and high-dimensional input manifolds.

[0109] Through gradient optimization of the potential function, this method can dynamically adjust the mapping function and approach the optimal mapping in each iteration. The gradient descent method ensures the gradual convergence of the loss function L(ψ), making the mapping function more adaptable in a dynamic environment. The dynamic optimization feature is particularly suitable for changing requirements in privacy protection scenarios, and can adjust the mapping relationship according to real-time changes in input data and target distribution.

[0110] The generation of protection data in step 4 includes the following processes:

[0111] x ′ =φ(x)+η,

[0112] Among them, x ′ represents the generated protection data, φ(x) is the mapping function, and η is the dynamic noise sampled in the target protection distribution Q(y).

[0113] Protect Datax ′ The generation of satisfies the following disturbance intensity constraints:

[0114] ∥φ(x)-x∥≤∈,

[0115] Among them, φ(x) is the mapping function, x is the user's original input data,

[0116] ∈ represents the upper bound of the perturbation intensity, which is used to ensure the semantic consistency between the protection data and the user input data.

[0117] By introducing dynamic noise η into the protected data, the privacy protection of the original input data is achieved. The addition of dynamic noise can effectively cover up the sensitive information of the user input data, making it impossible for attackers to reconstruct the original data. The noise generation method based on sampling in the target protection distribution makes the protection mechanism highly unpredictable, which significantly improves the security of privacy protection.

[0118] The perturbation intensity restriction condition in the process of protecting data generation prevents the mapped protected data from deviating from the semantic range of the user input data. The mapping function φ(x) is used to project the input data onto the target protection manifold, while the upper bound of the perturbation intensity ∈ limits the deviation range of the data during the mapping process. This preserves the semantic consistency of the user input data to the greatest extent while protecting privacy, and avoids the loss of actual value of the generated data due to excessive perturbations;

[0119] The protection data is generated by combining the mapping function φ(x) and the dynamic noise η, which makes the data protection mechanism dynamic. Compared with the static privacy protection method, the introduction of dynamic noise can flexibly adjust the generation method of protection data according to the characteristics of the target protection distribution. The dynamic generation mechanism enables the protection data to better adapt to different task scenarios, while avoiding the shortcomings caused by a single protection strategy;

[0120] Generated protection data x ′ It also includes the output φ(x) of the mapping function and the dynamic noise η, so that the protected data has high randomness and can maintain contextual consistency with the original data, ensuring that the protected data has high semantic availability while protecting privacy, and can be correctly understood and reasoned by the downstream GPT model;

[0121] By combining the mapping function φ(x) and dynamic noise, the generated protection data is no longer directly dependent on the user input data x. ′ The semantic properties of derive more from the target protection manifold and mapping function rather than the user's original input data.

[0122] Step 5 will protect data x ′ When input into the GPT model for reasoning, the latent space representation of the protected data is combined with dynamic noise for semantic processing, and the accuracy of the reasoning result y is evaluated by the BLEU score and the generated text fluency score;

[0123] BLEU is an automated evaluation metric used to measure the similarity between generated text and reference text.

[0124] By combining the latent space representation and dynamic noise of protected data, the GPT model can correctly understand the semantic information of protected data while protecting privacy, avoiding the problem of semantic loss caused by data perturbation in traditional privacy protection methods, ensuring the semantic availability and integrity of protected data, and thus ensuring the quality of inference results generated by the GPT model;

[0125] The BLEU score is introduced as the evaluation standard for reasoning results. By comparing the n-gram matching between the generated text and the reference text, the accuracy of the reasoning results can be intuitively quantified. At the same time, combined with the fluency score of the generated text, the BLEU score is supplemented for the lack of grammar and context coherence, making the evaluation of the reasoning results more comprehensive. The multi-dimensional evaluation method provides a quantifiable feedback mechanism for improving and optimizing the model;

[0126] The protection data is generated through mapping functions and dynamic noise, which will have a certain impact on the reasoning process of the GPT model. By combining latent space representation and dynamic noise, the GPT model can automatically adjust the semantic processing method of input data during reasoning to adapt to the characteristics of the protection data to the greatest extent. Adaptability effectively improves the synergy between privacy-preserving data and the GPT model;

[0127] The privacy protection mechanism for protecting data will introduce a certain amount of randomness, but by evaluating the BLEU score and text fluency of the inference results, this method can find a balance between privacy protection and inference performance. The evaluation results of inference performance provide an important basis for optimizing the protected data generation process, and further optimize the synergistic effect of privacy protection and inference performance;

[0128] The BLEU score reflects the quality of the generated text in terms of consistency with the reference text, while the fluency score measures the readability and contextual coherence of the generated text. By combining the evaluation indicators, we ensure that the reasoning results of the GPT model are accurate and have good practicality, providing text generation results for practical applications;

[0129] Through quantitative evaluation of BLEU scores and fluency scores, this method can provide effective feedback on the quality of generated text and the adaptability of protected data. The evaluation indicators can be used as a basis for subsequent optimization of protected data generation methods and adjustment of GPT model parameters, thereby continuously improving the overall performance of the system.

[0130] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A GPT model security access method based on deep learning, characterized in that: include: Step 1: construct a latent space manifold of user input data, use a variational autoencoder to process the user input data, map the user input data to a latent space representation through the encoder, and obtain a probability distribution of the latent space. In the latent space probability distribution, the prior distribution of the latent space is set to a Gaussian distribution, and the latent space representation is used as an embedded representation of the user input data manifold to construct the latent space manifold; Step 2: According to the latent space manifold constructed in step 1, define the target protection distribution manifold, and introduce the protection distribution on the latent space manifold. The target protection distribution is described by Gaussian distribution. The covariance matrix in the target protection distribution is used to control the strength of data protection. Step 3: Based on the target protection distribution manifold defined in step 2, a mapping model is established from the user input data latent space manifold to the target protection distribution manifold. The mapping model calculates the data matching between the input manifold and the target manifold to establish a mapping function between the manifolds. The mapping function is used to convert the input data latent space representation into the target protection distribution representation. Step 4: Based on the mapping model established in step 3, generate protection data. The protection data is obtained by combining the latent space representation of the user input data with the dynamic noise distribution through a mapping function. The dynamic noise distribution is set based on the target protection distribution manifold. The protection data includes the mapped latent space representation and the generated dynamic noise. Step 5: Input the protection data generated in step 4 into the GPT model, use the GPT model for reasoning, perform semantic understanding on the latent space representation of the protection data during the reasoning process, complete the processing of the protection data in combination with the generated dynamic noise, and output the reasoning result.

2. According to a deep learning-based GPT model security access method according to claim 1, it is characterized in that: The construction of the latent space manifold in step 1 uses the probability distribution described by the following formula: P(x)=∫P(x|z)P(z)dz, Among them, P(x) represents the distribution of user input data, P(z) represents the prior distribution of the latent space, which is set to Gaussian distribution N(0, I). z represents the latent space representation of the user input data, P(x|z) is the generative distribution from the latent space to the input data, and dz represents the variable integrated in the latent space.

3. According to a deep learning-based GPT model security access method according to claim 1, it is characterized in that: The target protection distribution manifold in step 2 is described by the following formula: Q(y)~N(0,Σ), Among them, Q(y) represents the target protection distribution, y represents the protection data generated by noise on the latent space manifold, N(0, Σ) is a Gaussian distribution with a mean of 0 and a covariance matrix of Σ. The mean value of 0 indicates that the noise of the target protection distribution is symmetric around the center of the input data distribution in the latent space, and the covariance matrix Σ determines the amplitude and direction of the noise.

4. According to a deep learning-based GPT model security access method according to claim 3, it is characterized in that: The covariance matrix Σ is dynamically adjusted according to the privacy protection requirements, and the adjustment method is expressed by the following formula: Among them, Σ t represents the covariance matrix at the current moment, Σ t-1 represents the covariance matrix of the previous moment, B represents the adjustment rate, Σ is the covariance matrix, R(Σ) represents the privacy protection risk function, which is used to evaluate the impact of the current covariance matrix on the risk of privacy leakage.

5. According to a deep learning-based GPT model security access method according to claim 1, it is characterized in that: The mapping model in step 3 is established by solving the mapping function from the input manifold to the target manifold through the following formula: Among them, φ(x) represents the mapping function, φ * represents the optimal mapping function, x is the input data coordinate, dP(x) is the probability measure on the input manifold, and c(x, φ(x)) represents the transportation cost function from the input manifold to the target manifold, which is described by the following formula: c(x,φ(x))=g ij (x i -f i (x))(x j -f j (x)), Among them, g ij represents the metric tensor on the manifold, x i and x j are the i-th and j-th coordinate components of the input data point x, φ i (x) and φ j (x) are the i-th and j-th coordinate components of the mapped data point φ(x).

6. A GPT model security access method based on deep learning according to claim 5, characterized in that: The mapping function is represented by the potential function ψ(x), and the mapping function is solved as follows: Among them, φ(x) represents the mapping function, represents the rate of change of the potential function ψ(x) at x; The optimization goal of the potential function ψ(x) is to minimize the following loss function: in, is the gradient of the potential function, represents the optimal transport loss function between manifolds, g ij represents the metric tensor on the manifold, x i and x j are the i-th and j-th coordinate components of the input data point x, and is the gradient component of the potential function ψ(x) in the i-th and j-th dimension coordinates, and dP(x) is the probability measure on the input manifold.

7. A GPT model security access method based on deep learning according to claim 6, characterized in that: The mapping function is solved by gradient descent method for optimization, and the potential function is updated as follows: Among them, ψ t represents the potential function of the current iteration, ψ t-1 represents the potential function of the previous iteration, α is the learning rate, Represents the partial derivative of the loss function L(ψ) with respect to the potential function ψ(x).

8. According to a deep learning-based GPT model security access method according to claim 1, it is characterized in that: The generation of the protection data in step 4 includes the following process: x ′ =φ(x)+η, Among them, x ′ represents the generated protection data, φ(x) is the mapping function, and η is the dynamic noise sampled in the target protection distribution Q(y).

9. A GPT model security access method based on deep learning according to claim 8, characterized in that: The protected data x ′ The generation of satisfies the following disturbance intensity constraints: ∥φ(x)-x∥≤∈, Among them, φ(x) is the mapping function, x is the user's original input data, ∈ represents the upper bound of the perturbation intensity, which is used to ensure the semantic consistency between the protection data and the user input data.

10. A GPT model security access method based on deep learning according to claim 1, characterized in that: Step 5 will protect data x ′ When input into the GPT model for reasoning, the latent space representation of the protected data is combined with dynamic noise for semantic processing, and the accuracy of the reasoning result y is evaluated by the BLEU score and the generated text fluency score; The BLEU is an automated evaluation indicator used to measure the similarity between generated text and reference text.

Citation Information

Patent Citations

  • Multi-working-condition process fault monitoring and diagnosing method

    CN115079660A

  • Image generation method based on Gaussian mixture variational auto-encoder

    CN117036862A

  • Image generation method and device based on thermonuclear theory on Riemannian manifold

    CN119130785A

  • Ray-based lightweight distributed reinforcement learning training platform design method

    CN119151019A