Electronic judicial expertise data integrity verification method and system based on federal learning

Through the federated learning method, single point of failure, privacy leakage, insufficient credibility and scalability in the traditional electronic judicial identification data integrity verification method is solved, and data efficiency, security and trustworthiness verification are achieved.

CN119989424AInactive Publication Date: 2025-05-13NORTHWEST NORMAL UNIVERSITY
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510095505.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The traditional electronic judicial identification data integrity verification method has problems with single point of failure risk, data privacy leakage, insufficient data credibility, and efficiency and scalability.

Method used

A federated learning-based method is adopted to realize decentralized checking and privacy protection of data through steps such as data preprocessing, federated learning model training, data verification, verification result storage and dynamic model update.

Benefits of technology

It improves the privacy protection of data and the credibility of verification results, reduces the risk of single point of failure, and enhances the scalability and real-time adaptability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989424A_ABST
    Figure CN119989424A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of data integrity verification, and discloses an electronic judicial expertise data integrity verification method and system based on federal learning, which can be easily expanded to more nodes to meet the data processing requirements of large-scale judicial cases. The system supports the dynamic updating of a federal learning model, can adjust a verification mechanism in real time according to the change of newly added data or verification rules, and ensures the adaptability and foresight of the system. According to the electronic judicial expertise data integrity verification method and system based on federated learning, the verification model is cooperatively trained through federated learning, the verification result is recorded in combination with the block chain technology, privacy protection and credibility enhancement of data are achieved, and the problems of single-point failure and privacy risk of a traditional centralized verification method are solved. According to the system, the cross-organization cooperation efficiency, the verification result transparency and the expansion capability of the system are remarkably improved, and an innovative solution is provided for the security and integrity of electronic judicial expertise data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data integrity verification, and in particular relates to a method and system for verifying the integrity of electronic forensic data based on federated learning. Background Art

[0002] Traditional electronic forensic data integrity verification methods mainly rely on centralized data storage and verification methods, which are performed by uploading data to a server or database for integrity verification. For example, hash values ​​or digital signature technologies are used to generate verification codes for data, which are stored in a single trusted node and then compared with subsequent data verification requests. This method can provide basic data integrity protection in a single node environment.

[0003] Through the above analysis, the problems and defects of the prior art are as follows:

[0004] (1) Single point failure risk: Centralized storage and verification rely on a single server. Once the node is attacked (such as a DDoS attack) or the data is tampered with, the overall verification mechanism will fail.

[0005] (2) Data privacy leakage: Electronic forensic data usually contains highly sensitive information, and centralized storage has the risk of data leakage, especially when cross-organizational data collaboration.

[0006] (3) Insufficient data credibility: Traditional verification methods make it difficult to achieve multi-party supervision of data processing and verification processes, resulting in limited credibility of verification results.

[0007] (4) Efficiency and scalability issues: The performance of centralized methods deteriorates when the data volume is large and cross-regional collaboration is involved. In particular, when large-scale judicial cases are involved, data synchronization and verification efficiency become bottlenecks. Summary of the invention

[0008] In view of the problems existing in the prior art, the present invention provides a method and system for verifying the integrity of electronic forensic data based on federated learning.

[0009] The present invention is implemented as follows: a method for verifying the integrity of electronic forensic data based on federated learning includes:

[0010] Step 1, data preprocessing;

[0011] Each judicial appraisal agency pre-processes the local data, including formatting and noise filtering operations; the data is stored locally in encrypted form;

[0012] Step 2: Federated learning model training;

[0013] Each node inputs the characteristics of local data into the federated learning collaboration module to jointly train a unified integrity verification model;

[0014] During the model training process, data privacy is protected through the differential privacy mechanism, and the intermediate results and verification logs of the training process are recorded through the blockchain to ensure that the process is transparent and cannot be tampered with;

[0015] Step 3, data verification;

[0016] Local verification: Each node uses a local integrity verification model to generate a verification hash value for the data and compares the result with the reference value of the global model to complete local verification;

[0017] Global verification: When sharing or verifying data across organizations, cross-node verification is performed through the global model of federated learning to ensure the consistency and integrity of data on all nodes;

[0018] Step 4, verification result storage;

[0019] The verification results are recorded in the blockchain storage module in the form of data summary and timestamped to ensure the authenticity and traceability of the verification;

[0020] Generate detailed reports for review by relevant judicial institutions for data tampering or anomalies found during verification;

[0021] Step 5, dynamic model update;

[0022] When new data is added or the verification rules are adjusted, each node participates in the federated learning collaboration and dynamically updates the integrity verification model to ensure the adaptability and real-time performance of the system.

[0023] Data preprocessing is the basis of the entire verification process. Each judicial appraisal agency systematically processes local data, including formatting, denoising and encryption operations:

[0024] 1) Formatting: Normalize data in a unified standard format to ensure data consistency and availability. For example, convert text records into a unified coding form or structured database format.

[0025] 2) Noise filtering: Through signal processing algorithms (such as low-pass filters or median filters), potential redundant information or interference signals in the data are eliminated to ensure the purity and reliability of the data.

[0026] 3) Encrypted storage: Use symmetric encryption (such as AES) or asymmetric encryption (such as RSA) technology to locally encrypt the processed data to prevent unauthorized access or tampering, providing security for subsequent federated learning.

[0027] In the federated learning stage, the forensic identification agencies do not directly share the original data, but instead collaborate to train the integrity verification model:

[0028] 1) Feature extraction: Locally extract features (such as hash values ​​and integrity identifiers of key fields) through data analysis, generate feature vectors, and input them into the federated learning module.

[0029] 2) Differential privacy protection: During the local computing process, random noise is added to protect feature data to ensure personal data privacy while maintaining the model training effect.

[0030] 3) Distributed training: Through the federated learning framework, each node only uploads model parameter updates without transmitting original data. The intermediate results and logs during the training process are recorded through blockchain technology to ensure transparency and tamper-proof.

[0031] The local validation model is used to quickly assess the integrity of local data:

[0032] 1) Hash value generation: Run a hash algorithm (such as SHA-256) on the data block to generate a unique checksum to identify the integrity of the data.

[0033] 2) Local model verification: Compare the generated hash value with the output of the local integrity verification model to determine whether the data meets the integrity requirements.

[0034] 3) Anomaly detection: Identify potential tampered or abnormal data and mark suspicious data blocks through anomaly detection algorithms (such as K-Means clustering or support vector machine SVM).

[0035] In cross-organizational data sharing or verification scenarios, the global model of federated learning is used to verify the consistency and integrity of data:

[0036] 1) Global model reasoning: Each node uploads local data features to the global verification model. The model compares the consistency of data across nodes and generates integrity verification results.

[0037] 2) Cross-node verification: The verification values ​​of different nodes are compared through the global model. If the data between nodes is inconsistent, the deep verification process is started to find the specific differences.

[0038] 3) Data consistency confirmation: Confirm the consistency of data among all nodes. If any anomaly is found, record the relevant information for subsequent processing.

[0039] After the verification is completed, the results are reliably stored and traceable:

[0040] 1) Data summary generation: Generate a data summary (such as blockchain hash value) for the verification result, including data integrity status, verification timestamp and operation log.

[0041] 2) Blockchain storage: Write data summaries and timestamps into the blockchain to ensure the immutability and traceability of the verification process.

[0042] 3) Abnormal report generation: Generate a detailed report for any tampered or abnormal data found during the verification process, including the specific location of the abnormal data, the abnormal category, and the impact assessment, for review by the judicial appraisal agency.

[0043] In order to adapt to the new data and changes in verification rules, each node collaboratively updates the integrity verification model:

[0044] 1) New data feature extraction: When new data is added, each node re-extracts features and adds them to model training to ensure the real-time verification of the model.

[0045] 2) Dynamically adjust rules: Adjust verification rules according to forensic identification needs (such as adding data types or optimizing anomaly detection algorithms).

[0046] 3) Model iterative training: Distributed model updates are achieved through the federated learning framework, and the model update process is recorded on the blockchain to ensure the transparency and verifiability of each iteration.

[0047] In the embodiment of the present invention, the specific data preprocessing is:

[0048] The original data D stored locally by each judicial appraisal agency i ; Form feature set X through preprocessing i ; The specific process includes formatting data: unifying the data structure Struct(X i );

[0049] Noise filtering: remove outliers X' i ={x∈X i |Valid(x)};

[0050] Data encryption: through the encryption function Enc(X i ') to form encrypted data X i = Enc(X' i );

[0051] All data is preprocessed and saved in the local node without exposing the original data.

[0052] Furthermore, the federated learning model trains:

[0053] Mathematical model: Federal average;

[0054] In the training of the federated learning model, it is assumed that there are N participating nodes, and each node i holds a local feature dataset Xi and a corresponding local integrity model w i ; The overall model training is completed through the following steps:

[0055] 1) Local training:

[0056] Each node uses the local dataset Xi to train the local model w i , by minimizing the local loss function L i (w) Complete model update:

[0057]

[0058] Where η is the learning rate, is the gradient of the loss function;

[0059] 2) Global model aggregation:

[0060] The federated learning coordination server receives model updates uploaded by all nodes Update the global model based on weighted average

[0061]

[0062] Where n i is the amount of data at node i, is the global model of round t+1;

[0063] 3) Privacy protection: Differential privacy: Introducing noise N(0, σ 2 ), the uploaded model weight is Ensure sensitive data is not inferred;

[0064] Blockchain storage: each round of model aggregation results and logs during training T i Recorded in the blockchain, anti-tampering and traceable; through the above training process, the system generates a unified integrity verification model w g , this model will be used for local and global verification of each node.

[0065] Further, the data verification:

[0066] Mathematical model: hash check

[0067] In the data verification process, local and global verification use hash verification mechanisms respectively, combined with the verification model w generated by federated learning. g ,conduct;

[0068] 1) Local verification:

[0069] Each node is based on the local data Xi ; Calculate the data summary (hash value) H(X i ); the hash value is generated by the following formula:

[0070]

[0071] where h(·) is a hash function (such as SHA-256), Represents a linear combination of model weights and data;

[0072] 2) Global verification:

[0073] When cross-organizational data is shared or verified, each node uploads the local hash value to the federated learning collaboration module, and the global model w g

[0074] Verify data consistency; the error function of the verification is:

[0075] ΔH=11H(X i )-H(X j )|, are the indices of two samples; the i-th data sample Xi and the j-th data sample Xj in the data set;

[0076] If ΔH=0, the data integrity is consistent; if ΔH≠0, data tampering is detected;

[0077] 3) Anomaly Detection:

[0078] When data is abnormal, the system generates a detailed report, including abnormal data nodes, timestamps, causes of errors, etc., for review by judicial agencies.

[0079] Further, the verification result is stored in:

[0080] After the verification is completed, the verification result R is stored in the blockchain in summary form:

[0081] R={H(X i ), T i , Status}

[0082] Where T i It is a timestamp, and Status is the verification status (complete or abnormal); blockchain storage ensures the authenticity and traceability of the results.

[0083] Further, the dynamic model is updated:

[0084] When new data or rules change, each node retrains the local model based on the new data And participate in the global model update of federated learning; the update process is the same as the model training steps to ensure that the system adapts to new needs in real time.

[0085] Another object of the present invention is to provide an electronic forensic data integrity verification system based on federated learning, comprising:

[0086] The data preprocessing module is used to preprocess local data through various judicial appraisal institutions, including formatting and noise filtering operations; the data is stored locally in encrypted form;

[0087] The federated learning collaboration module is used to generate a unified data integrity verification model through the federated learning framework, where each node can collaboratively train and generate a unified data integrity verification model without exchanging original data. It also enables dynamic updates of distributed verification models, where each node can participate in the update in real time based on changes in local data.

[0088] The integrity verification module is used to generate a verification hash value or digital signature for the data locally using a distributed verification model. The global model of federated learning collaboration is responsible for cross-node data consistency verification.

[0089] The blockchain storage module is used to store the verification results generated by each node in the blockchain to achieve a decentralized storage method and prevent tampering; a timestamp is added to each data verification record to ensure the traceability of the verification process;

[0090] The privacy protection module is used to protect sensitive data using homomorphic encryption during data training and transmission, and to introduce noise interference during federated learning to protect data privacy.

[0091] Another object of the present invention is to provide a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the electronic forensic data integrity verification method based on federated learning.

[0092] Another object of the present invention is to provide a computer-readable storage medium storing a computer program, which, when executed by a processor, enables the processor to perform the steps of the electronic forensic data integrity verification method based on federated learning.

[0093] Another object of the present invention is to provide an information data processing terminal, which is used to implement the electronic forensic identification data integrity verification system based on federated learning.

[0094] In combination with the above technical solutions and the technical problems solved, the advantages and positive effects of the technical solutions to be protected by the present invention are as follows:

[0095] 1. Data Privacy Protection:

[0096] The federated learning framework avoids the centralized sharing of raw data and protects the privacy of electronic forensic data through differential privacy and encryption techniques.

[0097] 2. Efficient collaboration and scalability:

[0098] The federated averaging algorithm realizes collaborative verification across organizations, and the system can be expanded to a multi-node environment to meet the needs of large-scale judicial case data processing.

[0099] 3. Credibility of verification results

[0100] Hash verification combined with blockchain storage mechanism ensures the immutability of the verification process and the traceability of the results, enhancing the credibility of forensic appraisal.

[0101] In addition, the technical solution of the present invention also has real-time adaptability:

[0102] The dynamic model update mechanism enables the system to quickly adapt to new data or verification rules, maintaining efficiency and foresight. Through the combination of the federated learning model and the hash verification mechanism, the system achieves efficient, secure and reliable verification of electronic forensic data, providing a solid technical guarantee for the forensic process.

[0103] 1) Enhanced data security

[0104] Federated learning combines blockchain technology to avoid the single point of failure and data leakage risks of centralized storage, while protecting the privacy of data during transmission and training through homomorphic encryption and differential privacy technologies.

[0105] 2) Decentralized verification mechanism

[0106] Through the federated learning framework, the integrity verification of electronic forensic data is completed collaboratively by multiple nodes, avoiding dependence on a single trusted center and improving the system's reliability and risk resistance.

[0107] 3) Efficiency of cross-organizational collaboration

[0108] The various judicial appraisal institutions do not need to share original data, but only need to collaborate in verification through feature data, which reduces the cost of cross-organizational data sharing and improves collaboration efficiency.

[0109] 4) Credibility and transparency of verification results

[0110] The verification results are recorded in the blockchain, which is tamper-proof and traceable, providing technical guarantee for the authenticity of forensic identification data.

[0111] 5) System Scalability

[0112] Using a federated learning framework and distributed storage design, the system can easily expand to more nodes and adapt to the data processing needs of large-scale judicial cases.

[0113] 6) Real-time dynamic update capability

[0114] The system supports dynamic updates of federated learning models and can adjust the verification mechanism in real time according to new data or changes in verification rules to ensure the adaptability and foresight of the system.

[0115] The electronic forensic data integrity verification method and system based on federated learning in this invention realizes data privacy protection and credibility enhancement through collaborative training of verification models through federated learning and records verification results in combination with blockchain technology, overcoming the single point failure and privacy risk problems of traditional centralized verification methods. The system significantly improves cross-organizational collaboration efficiency, transparency of verification results, and system expansion capabilities, providing an innovative solution for the security and integrity of electronic forensic data. BRIEF DESCRIPTION OF THE DRAWINGS

[0116] Figure 1 It is a flow chart of a method for verifying the integrity of electronic forensic data based on federated learning provided in an embodiment of the present invention.

[0117] Figure 2 It is a flow chart of the federated learning model training method provided by an embodiment of the present invention.

[0118] Figure 3 It is a flow chart of a data verification method provided by an embodiment of the present invention.

[0119] Figure 4 It is a structural block diagram of an electronic forensic data integrity verification system based on federated learning provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0120] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0121] like Figure 1 As shown, an electronic forensic data integrity verification method based on federated learning provided by an embodiment of the present invention includes the following steps:

[0122] S101, data preprocessing;

[0123] Each judicial appraisal agency pre-processes the local data, including formatting and noise filtering operations; the data is stored locally in encrypted form;

[0124] S102, federated learning model training;

[0125] Each node inputs the characteristics of local data into the federated learning collaboration module to jointly train a unified integrity verification model;

[0126] During the model training process, data privacy is protected through the differential privacy mechanism, and the intermediate results and verification logs of the training process are recorded through the blockchain to ensure that the process is transparent and cannot be tampered with;

[0127] S103, data verification;

[0128] Local verification: Each node uses a local integrity verification model to generate a verification hash value for the data and compares the result with the reference value of the global model to complete local verification;

[0129] Global verification: When sharing or verifying data across organizations, cross-node verification is performed through the global model of federated learning to ensure the consistency and integrity of data on all nodes;

[0130] S104, storing the verification result;

[0131] The verification results are recorded in the blockchain storage module in the form of data summary and timestamped to ensure the authenticity and traceability of the verification;

[0132] Generate detailed reports for review by relevant judicial institutions for data tampering or anomalies found during verification;

[0133] S105, dynamic model update;

[0134] When new data is added or verification rules are adjusted, each node participates in federated learning collaboration and dynamically updates the integrity verification model to ensure system adaptability and real-time performance;

[0135] Data preprocessing provided by the embodiment of the present invention:

[0136] The original data D stored locally by each judicial appraisal agency i ; Form feature set X through preprocessing i ; The specific process includes formatting data: unifying the data structure Struct(X i );

[0137] Noise filtering: remove outliers X' i ={x∈X i |Valid(x)};

[0138] Data encryption: through the encryption function Enc(X i ') to form encrypted data X i = Enc(X' i );

[0139] All data is preprocessed and saved in the local node without exposing the original data.

[0140] like Figure 2 As shown, the federated learning model training provided by the embodiment of the present invention is:

[0141] Mathematical model: Federal average;

[0142] In the training of the federated learning model, it is assumed that there are N participating nodes, and each node i holds a local feature dataset Xi and a corresponding local integrity model w i ; The overall model training is completed through the following steps:

[0143] S201, local training:

[0144] Each node uses the local dataset Xi to train the local model w i , by minimizing the local loss function L i (w) Complete model update:

[0145]

[0146] Where η is the learning rate, is the gradient of the loss function;

[0147] S202, global model aggregation:

[0148] The federated learning coordination server receives model updates uploaded by all nodes Update the global model based on weighted average

[0149]

[0150] Where n i is the amount of data at node i, is the global model of round t+1;

[0151] S203, Privacy Protection:

[0152] Differential privacy: Introducing noise N(0, σ) in model updates 2 ), the uploaded model weight is Ensure sensitive data is not inferred;

[0153] Blockchain storage: each round of model aggregation results and logs during training T i Recorded in the blockchain, anti-tampering and traceable; through the above training process, the system generates a unified integrity verification model w g , this model will be used for local and global verification of each node.

[0154] like Figure 3 As shown, the data verification provided by the embodiment of the present invention is:

[0155] Mathematical model: hash check

[0156] In the data verification process, local and global verification use hash verification mechanisms respectively, combined with the verification model w generated by federated learning. g ,conduct;

[0157] S301, local verification:

[0158] Each node is based on the local data X i ; Calculate the data summary (hash value) H(X i ); the hash value is generated by the following formula:

[0159]

[0160] where h(·) is a hash function (such as SHA-256), Represents a linear combination of model weights and data;

[0161] S302, global verification:

[0162] When cross-organizational data is shared or verified, each node uploads the local hash value to the federated learning collaboration module, and the global model w g

[0163] Verify data consistency; the error function of the verification is:

[0164] ΔH=11H(X i )-H(X j )|, are the indices of two samples; the i-th data sample Xi and the j-th data sample Xj in the data set;

[0165] If ΔH=0, the data integrity is consistent; if ΔH≠0, data tampering is detected;

[0166] S303, anomaly detection:

[0167] When data is abnormal, the system generates a detailed report, including abnormal data nodes, timestamps, causes of errors, etc., for review by judicial agencies.

[0168] The verification result storage provided by the embodiment of the present invention is:

[0169] After the verification is completed, the verification result R is stored in the blockchain in summary form:

[0170] R={H(X i ), T i , Status}

[0171] Where T i It is a timestamp, and Status is the verification status (complete or abnormal); blockchain storage ensures the authenticity and traceability of the results.

[0172] The dynamic model update provided by the embodiment of the present invention:

[0173] When new data or rules change, each node retrains the local model based on the new data And participate in the global model update of federated learning; the update process is the same as the model training steps to ensure that the system adapts to new needs in real time.

[0174] like Figure 4 As shown, an electronic forensic data integrity verification system based on federated learning provided by an embodiment of the present invention includes:

[0175] The data preprocessing module is used to preprocess local data through various judicial appraisal institutions, including formatting and noise filtering operations; the data is stored locally in encrypted form;

[0176] The federated learning collaboration module is used to generate a unified data integrity verification model through the federated learning framework, where each node can collaboratively train and generate a unified data integrity verification model without exchanging original data. It also enables dynamic updates of distributed verification models, where each node can participate in the update in real time based on changes in local data.

[0177] The integrity verification module is used to generate a verification hash value or digital signature for the data locally using a distributed verification model. The global model of federated learning collaboration is responsible for cross-node data consistency verification.

[0178] The blockchain storage module is used to store the verification results generated by each node in the blockchain to achieve a decentralized storage method and prevent tampering; a timestamp is added to each data verification record to ensure the traceability of the verification process;

[0179] The privacy protection module is used to protect sensitive data using homomorphic encryption during data training and transmission, and to introduce noise interference during federated learning to protect data privacy.

[0180] Each forensic identification agency first processes local data through a data preprocessing module. This step includes data formatting to ensure that the data meets uniform standards, as well as noise filtering operations to remove irrelevant or erroneous information in the data. The processed data is stored locally in encrypted form to ensure data security and prevent unauthorized access.

[0181] In the federated learning collaboration module, each node (i.e., each forensic identification agency) works together through the federated learning framework. They jointly train to generate a unified data integrity verification model without exchanging original data. This distributed training method protects the privacy of the data. At the same time, the module also supports the dynamic update of the distributed verification model. Each node can participate in the update of the model in real time according to the changes in local data to ensure the accuracy and timeliness of the model.

[0182] The integrity check module uses a distributed check model to generate a check hash value or digital signature for the data locally. These check values ​​are used to verify the integrity of the data. At the same time, the global model of federated learning collaboration is responsible for cross-node data consistency verification, ensuring that the data between nodes is logically consistent, further improving the reliability of data integrity verification.

[0183] The blockchain storage module stores the verification results generated by each node in the blockchain. As a decentralized storage method, blockchain has tamper-proof characteristics and can effectively protect the security of the verification results. In addition, the module also adds a timestamp to each data verification record to ensure the traceability of the verification process, so that the generation time and source of the verification results can be traced at any time.

[0184] The privacy protection module plays an important role in data training and transmission. It uses homomorphic encryption technology to protect sensitive data and ensure that the data will not be leaked during transmission and processing. At the same time, during the federated learning process, the module also introduces noise interference to further protect the privacy of the data. This dual protection mechanism ensures the privacy and security of the data.

[0185] In summary, the electronic forensic data integrity verification system based on federated learning achieves comprehensive, accurate and secure verification of electronic forensic data through the joint action of modules such as data preprocessing, federated learning collaboration, integrity verification, blockchain storage and privacy protection. The close collaboration between the modules ensures the integrity, consistency and privacy of the data, providing reliable technical support for electronic forensic data.

[0186] 1. Specific application fields or related products of the present invention

[0187] 1) Judicial appraisal institutions

[0188] It is suitable for data integrity verification of judicial appraisal institutions to ensure the reliability and authenticity of electronic judicial appraisal data. The system can be widely used in the judicial field, including data protection and verification in case handling, appraisal report generation, storage and other links.

[0189] 2) Data storage and blockchain applications

[0190] Used for electronic data management that requires long-term evidence storage, such as contract evidence storage, intellectual property protection, electronic evidence storage, etc., combined with blockchain technology to prevent data tampering.

[0191] 3) Distributed Data Collaboration Platform

[0192] It is applied to scenarios of multi-organization collaborative data analysis, such as medical data research, financial data sharing, etc., to achieve privacy protection of data collaboration through federated learning technology.

[0193] 4) Electronic evidence management platform

[0194] It is specially designed to handle the integrity of electronic evidence, such as judicial evidence storage of emails, chat records, pictures, and videos, to ensure the integrity of evidence during transmission and storage.

[0195] 5) Data management system in security-sensitive areas

[0196] It is used in industries that require high data security and privacy protection, such as data management in the military field and data storage and analysis in government agencies.

[0197] 6) Enterprise data sharing and compliance management

[0198] Used for distributed data collaboration within or across enterprises, especially data sharing and analysis that meets data compliance requirements (such as GDPR).

[0199] II. Evidence of the Technical Effects Obtained by the Embodiments of the Present Invention

[0200] 1) Improve the security of data integrity verification

[0201] By combining federated learning and blockchain technology, the transmission of original data between different nodes can be avoided, the risk of data leakage can be reduced, and the security of data integrity verification can be improved.

[0202] 2) Realize distributed data collaborative training

[0203] Each node performs collaborative training based on local data without the need to transmit original data, thus achieving distributed model updates across nodes and improving the adaptability and efficiency of the verification model.

[0204] 3) Enhance the immutability of data storage

[0205] Using blockchain technology, the verification results are stored in a decentralized network and timestamp records are added to ensure the traceability and non-tamperability of data records.

[0206] 4) Protecting Data Privacy

[0207] Homomorphic encryption and noise interference technology are introduced during the training and transmission process to avoid the exposure of sensitive data and achieve comprehensive protection of data privacy.

[0208] 5) Optimize cross-node data consistency verification

[0209] Use the global model to integrate and analyze the distributed verification results to ensure the accuracy of data consistency verification between nodes and reduce the possibility of erroneous verification.

[0210] 6) Ability to adapt to dynamic data environment

[0211] The system supports real-time verification and updating of dynamically changing data, ensuring that the verification model can continuously adapt to the needs of data updates in the field of forensic identification and improving the real-time and practicality of the system.

[0212] It should be noted that the embodiments of the present invention can be implemented by hardware, software, or a combination of software and hardware. The hardware part can be implemented using dedicated logic; the software part can be stored in a memory and executed by an appropriate instruction execution system, such as a microprocessor or dedicated design hardware. It can be understood by a person of ordinary skill in the art that the above-mentioned devices and methods can be implemented using computer executable instructions and / or contained in a processor control code, such as a carrier medium such as a disk, CD or DVD-ROM, a programmable memory such as a read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. Such code is provided on the carrier medium. The device and its modules of the present invention can be implemented by hardware circuits such as very large-scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, etc., or programmable hardware devices such as field programmable gate arrays, programmable logic devices, etc., can also be implemented by software executed by various types of processors, and can also be implemented by a combination of the above-mentioned hardware circuits and software, such as firmware.

[0213] The above description is only a specific implementation mode of the present invention, but the protection scope of the present invention is not limited thereto. Any modifications, equivalent substitutions and improvements made by any technician familiar with the technical field within the technical scope disclosed by the present invention and within the spirit and principle of the present invention should be covered by the protection scope of the present invention.

Claims

1. A method for verifying the integrity of electronic forensic data based on federated learning, characterized in that: The following steps are involved: Step 1, data preprocessing; Each judicial appraisal agency pre-processes the local data, including formatting and noise filtering operations; the data is stored locally in encrypted form; Step 2: Federated learning model training; Each node inputs the characteristics of local data into the federated learning collaboration module to jointly train a unified integrity verification model; During the model training process, data privacy is protected through the differential privacy mechanism, and the intermediate results and verification logs of the training process are recorded through the blockchain to ensure that the process is transparent and cannot be tampered with; Step 3, data verification; Local verification: Each node uses a local integrity verification model to generate a verification hash value for the data and compares the result with the reference value of the global model to complete local verification; Global verification: When sharing or verifying data across organizations, cross-node verification is performed through the global model of federated learning; Step 4, verification result storage; The verification result is recorded in the blockchain storage module in the form of a data summary and a timestamp is attached; Generate detailed reports for review by relevant judicial institutions for data tampering or anomalies found during verification; Step 5, dynamic model update; When new data is added or the verification rules are adjusted, each node participates in the federated learning collaboration and dynamically updates the integrity verification model.

2. The electronic forensic data integrity verification method based on federated learning as claimed in claim 1, characterized in that: The data preprocessing: The original data D stored locally by each judicial appraisal agency i ; Form feature set X through preprocessing i ; The specific process includes formatting data: unifying the data structure Struct(X i ); Noise filtering: remove outliers X' i ={x∈X i |Valid(x)}; Data encryption: through the encryption function Enc(X i ') to form encrypted data X i = Enc(X' i ); All data is preprocessed and saved in the local node without exposing the original data.

3. The electronic forensic data integrity verification method based on federated learning as claimed in claim 1, characterized in that: The federated learning model training: Mathematical model: Federal average; In the training of the federated learning model, it is assumed that there are N participating nodes, and each node i holds a local feature dataset Xi and a corresponding local integrity model w i ; The overall model training is completed through the following steps: 1) Local training: Each node uses the local dataset Xi to train the local model w i , by minimizing the local loss function L i (w) Complete model update: Where η is the learning rate, is the gradient of the loss function; 2) Global model aggregation: The federated learning coordination server receives model updates uploaded by all nodes Update the global model based on weighted average where n i is the amount of data at node i, is the global model of round t+1; 3) Privacy protection: Differential privacy: Introducing noise N(0, σ 2 ), the uploaded model weight is Ensure sensitive data is not inferred; Blockchain storage: each round of model aggregation results and logs during training T i Recorded in the blockchain, anti-tampering and traceable; through the above training process, the system generates a unified integrity verification model w g , this model will be used for local and global verification of each node.

4. The electronic forensic data integrity verification method based on federated learning as claimed in claim 1, characterized in that: The data verification: Mathematical model: hash check In the data verification process, local and global verification use hash verification mechanisms respectively, combined with the verification model w generated by federated learning. g ,conduct; 1) Local verification: Each node is based on the local data X i ; Calculate the data summary (hash value) H(X i ); the hash value is generated by the following formula: where h(·) is a hash function (such as SHA-256), Represents a linear combination of model weights and data; 2) Global verification: When cross-organizational data is shared or verified, each node uploads the local hash value to the federated learning collaboration module, and the global model w g Verify data consistency; the error function of the verification is: ΔH=11H(X i )-H(X j )|, are the indices of two samples; the i-th data sample Xi and the j-th data sample Xj in the data set; If ΔH=0, the data integrity is consistent; if ΔH≠0, data tampering is detected; 3) Anomaly Detection: When data is abnormal, the system generates a detailed report, including abnormal data nodes, timestamps, causes of errors, etc., for review by judicial agencies.

5. The electronic forensic data integrity verification method based on federated learning as claimed in claim 1, characterized in that: The verification result is stored in: After the verification is completed, the verification result R is stored in the blockchain in summary form: R={H(X i ),T i ,Status} Where T i It is a timestamp, and Status is the verification status (complete or abnormal); blockchain storage ensures the authenticity and traceability of the results.

6. The electronic forensic data integrity verification method based on federated learning as claimed in claim 1, characterized in that: The dynamic model updates: When new data or rules change, each node retrains the local model based on the new data And participate in the global model update of federated learning; the update process is the same as the model training steps to ensure that the system adapts to new needs in real time.

7. A system for verifying the integrity of electronic forensic data based on federated learning, which implements the method for verifying the integrity of electronic forensic data based on federated learning as claimed in any one of claims 1 to 6, characterized in that: The electronic forensic data integrity verification system based on federated learning includes: The data preprocessing module is used to preprocess local data through various judicial appraisal institutions, including formatting and noise filtering operations; the data is stored locally in encrypted form; The federated learning collaboration module is used to generate a unified data integrity verification model through the federated learning framework, where each node can collaboratively train and generate a unified data integrity verification model without exchanging original data. It also enables dynamic updates of distributed verification models, where each node can participate in the update in real time based on changes in local data. The integrity verification module is used to generate a verification hash value or digital signature for the data locally using a distributed verification model. The global model of federated learning collaboration is responsible for cross-node data consistency verification. The blockchain storage module is used to store the verification results generated by each node in the blockchain to achieve a decentralized storage method and prevent tampering; a timestamp is added to each data verification record to ensure the traceability of the verification process; The privacy protection module is used to protect sensitive data using homomorphic encryption during data training and transmission, and to introduce noise interference during federated learning to protect data privacy.

8. A computer device, characterized in that: The computer device includes a memory and a processor, the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the electronic forensic data integrity verification method based on federated learning as described in any one of claims 1-6.

9. A computer-readable storage medium storing a computer program, which, when executed by a processor, enables the processor to perform the steps of the electronic forensic data integrity verification method based on federated learning as described in any one of claims 1 to 6.

10. An information data processing terminal, characterized in that: The information data processing terminal is used to implement the electronic forensic identification data integrity verification system based on federated learning as described in claim 7.

Citation Information

Cited By

  • A federated learning method and system fusing attack tracing and data integrity auditing

    CN122640242A