Method and system for optimizing differential privacy noise calculation complexity based on ViT model
By performing matrix decomposition and rank reduction processing on the ViT model weight matrix, noise is added to the orthogonal matrix after rank reduction, solving the problem of high computational complexity of existing differential privacy technologies, improving model training efficiency and ensuring privacy.
Patent Information
- Application Number
- CN202510064460.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-15
- Publication Date
- 2025-05-13
AI Technical Summary
Existing differential privacy technologies add noise to the entire weight matrix of the model, resulting in high computational complexity, affecting model training and fine-tuning efficiency, and potentially degrading model performance.
By performing matrix decomposition, rank reduction processing and data simplification on the model weight matrix to be added, the noise is added to the orthogonal matrix after rank reduction, and periodic privacy protection evaluation is carried out to adjust the singular value retention ratio or noise injection amount.
Significantly reduce the complexity of noise calculation, improve the computing efficiency of the model fine-tuning stage, avoid the impact on model performance, ensure the privacy of model parameters, and save computing resources.
Smart Images

Figure CN119989892A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to a method and system for optimizing the computational complexity of differential privacy noise based on a ViT model. Background Art
[0002] With the rapid development of deep learning technology, the Visual Transformer (ViT) model has achieved remarkable results in image recognition, natural language processing and other fields. The ViT model is a deep learning model based on the Transformer architecture. It achieves efficient feature extraction and modeling by dividing the input image into multiple small blocks and performing serial processing. However, since the ViT model needs to process a large amount of sensitive data during the training process, how to protect this data has become an important issue. Differential privacy is an advanced privacy protection technology that achieves data privacy protection by adding noise to the model weights. The basic idea of differential privacy technology is that during the model training process, by appropriately adjusting the model weights, the output of the model will not change significantly even if the data of a single sample is modified. This ensures that even if an attacker obtains the output of the model, the specific information of a single sample cannot be inferred.
[0003] Existing differential privacy technologies usually achieve data privacy protection by directly adding noise to the entire weight matrix of the model. This method can guarantee the privacy of the model to a certain extent, but since noise needs to be added to the entire weight matrix, the computational complexity is high, which will have an adverse effect on the training and fine-tuning efficiency of the model. Moreover, since the noise is added to the entire weight matrix, it may affect the performance of the model and cause the accuracy of the model to decrease.
[0004] In summary, although the existing differential privacy technology can protect the privacy of the model to a certain extent, it has certain limitations in practical applications due to its high computational complexity. First, high computational complexity will increase the time and computing resource consumption of model training, which is an important issue for application scenarios with limited resources. Secondly, high computational complexity will also affect the fine-tuning efficiency of the model, causing the model to perform poorly when faced with complex tasks. Therefore, how to reduce the complexity of noise calculation and improve computational efficiency while ensuring the privacy of the model has become an important issue facing current differential privacy technology. Summary of the invention
[0005] The present invention provides a method and system for optimizing the computational complexity of differential privacy noise based on the ViT model, so as to solve the technical problems existing in the prior art of high computational overhead and influence on model accuracy.
[0006] In order to solve the above technical problems, the present invention provides the following technical solutions:
[0007] On the one hand, the present invention provides a method for optimizing the computational complexity of differential privacy noise based on the ViT model, and the method for optimizing the computational complexity of differential privacy noise based on the ViT model includes:
[0008] Preprocessing the weight matrix of the model to which noise is to be added to obtain a preprocessed matrix; wherein the preprocessing includes: matrix decomposition, matrix rank reduction and matrix data simplification;
[0009] Add differential privacy noise to the preprocessed matrix;
[0010] The parameters of the ViT model are updated according to the matrix after adding noise, and the model is trained and fine-tuned.
[0011] Furthermore, the preprocessing of the weight matrix of the model to which noise is to be added includes:
[0012] Performing matrix decomposition on the weight matrix of the model to which noise is to be added, decomposing the weight matrix of the model to which noise is to be added into two orthogonal matrices and a diagonal matrix containing singular values;
[0013] According to a preset singular value retention ratio, a number of singular values in the diagonal matrix are selectively retained;
[0014] Perform rank reduction on the two orthogonal matrices respectively.
[0015] Furthermore, adding differential privacy noise to the preprocessed matrix includes:
[0016] Add differential privacy noise to the two orthogonal matrices after rank reduction.
[0017] Furthermore, the elements in the differential privacy noise obey Gaussian distribution.
[0018] Furthermore, after updating the parameters of the ViT model according to the matrix after adding noise, and performing model training and fine-tuning, the optimization method of the differential privacy noise calculation complexity based on the ViT model also includes:
[0019] During the model training and fine-tuning process, privacy protection assessments are performed regularly to ensure that the privacy of the model meets the preset security standards. If it is found that the privacy of the model does not meet the preset security standards, the singular value retention ratio or noise injection amount is adjusted to further enhance privacy protection.
[0020] On the other hand, the present invention also provides a system for optimizing the computational complexity of differential privacy noise based on the ViT model, and the system for optimizing the computational complexity of differential privacy noise based on the ViT model includes:
[0021] A matrix preprocessing module, used for preprocessing the weight matrix of the model to be added with noise to obtain a preprocessed matrix; wherein the preprocessing includes: matrix decomposition, matrix rank reduction and matrix data simplification;
[0022] The noise adding module is used to add differential privacy noise to the preprocessed matrix;
[0023] The model training and fine-tuning module is used to update the parameters of the ViT model according to the matrix after adding noise, and perform model training and fine-tuning.
[0024] Furthermore, the matrix preprocessing module is specifically used for:
[0025] Performing matrix decomposition on the weight matrix of the model to which noise is to be added, decomposing the weight matrix of the model to which noise is to be added into two orthogonal matrices and a diagonal matrix containing singular values;
[0026] According to a preset singular value retention ratio, a number of singular values in the diagonal matrix are selectively retained;
[0027] Perform rank reduction on the two orthogonal matrices respectively.
[0028] Furthermore, the noise adding module is specifically used for:
[0029] Add differential privacy noise to the two orthogonal matrices after rank reduction.
[0030] Furthermore, the elements in the differential privacy noise obey Gaussian distribution.
[0031] Furthermore, the system also includes a privacy protection assessment module, which is used to:
[0032] During the model training and fine-tuning process, privacy protection assessments are performed regularly to ensure that the privacy of the model meets the preset security standards. If it is found that the privacy of the model does not meet the preset security standards, the singular value retention ratio or noise injection amount is adjusted to further enhance privacy protection.
[0033] On the other hand, the present invention further provides an electronic device, comprising a processor and a memory; wherein the memory stores at least one instruction, and the instruction is loaded and executed by the processor to implement the above method.
[0034] In yet another aspect, the present invention further provides a computer-readable storage medium, wherein at least one instruction is stored in the storage medium, and the instruction is loaded and executed by a processor to implement the above method.
[0035] The beneficial effects brought about by the technical solution provided by the present invention include at least:
[0036] 1. Reduce computational complexity: This paper optimizes the traditional method of adding noise to the entire weight matrix to adding noise to two orthogonal matrices after rank reduction through matrix decomposition and rank reduction. This optimization method can significantly reduce the complexity of noise injection and improve the computational efficiency of the model fine-tuning stage.
[0037] 2. Improve model performance: By adding differential privacy noise to the two orthogonal matrices after rank reduction instead of adding noise to the entire weight matrix, the parameters of the original model are not changed, thus avoiding the impact on model performance. This can ensure the accuracy of the model and improve the prediction effect of the model.
[0038] 3. Saving computing resources: The optimization method of the present invention can further reduce the data dimension and the amount of calculation by reducing the number of singular values, and can process large-scale data without increasing the computing cost. Due to the reduction of computing complexity, computing resources can be saved, computing costs can be reduced, and computing efficiency can be improved. Thus, the problem of wasting computing resources and increasing computing costs is avoided.
[0039] 4. Enhanced privacy protection: The optimization method of the present invention can not only reduce computational complexity, improve model performance, save computing resources, but also ensure the privacy of model parameters. By adding differential privacy noise to the two orthogonal matrices after rank reduction, the leakage of sensitive information can be effectively prevented and user privacy can be protected.
[0040] 5. High flexibility: The optimization method of the present invention can be applied to various optimization problems of differential privacy noise computational complexity based on the ViT model, and has broad application prospects. Whether for small-scale data or large-scale data, the optimization method of the present invention can provide an effective and practical solution. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0042] Figure 1 It is a schematic diagram of the execution flow of the optimization method for the computational complexity of differential privacy noise based on the ViT model provided in an embodiment of the present invention;
[0043] Figure 2 It is a system block diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0044] In order to make the objectives, technical solutions and advantages of the present invention more clear, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.
[0045] First of all, it should be noted that in the embodiments of the present invention, words such as "exemplarily" and "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" in the present invention should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of the word "exemplarily" is intended to present the concept in a concrete way. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or it can be either of the two.
[0046] First embodiment
[0047] This embodiment provides a method for optimizing the computational complexity of differential privacy noise based on the ViT model. The method can be implemented by an electronic device. The execution process of the method is as follows: Figure 1 As shown, the following steps are included:
[0048] S1, preprocessing the weight matrix of the model to be added with noise to obtain a preprocessed matrix; wherein the preprocessing includes: matrix decomposition, matrix rank reduction and matrix data simplification;
[0049] Specifically, in this embodiment, the above S1 specifically includes:
[0050] S11, matrix decomposition step: decompose the model's weight matrix into the product of three matrices: an orthogonal matrix, a diagonal matrix (including singular values), and an orthogonal matrix. The purpose of this step is to decompose the complex weight matrix into smaller matrices that are easier to handle, in preparation for subsequent rank reduction processing.
[0051] Take a weight matrix in the ViT model as an example, and perform matrix decomposition to decompose it into two orthogonal matrices and a diagonal matrix. Assume that the size of this weight matrix is , then we can decompose it into a An orthogonal matrix, A diagonal matrix, a Through this decomposition form, the complexity of the weight matrix can be effectively reduced.
[0052] S12, singular value retention step: According to a preset singular value retention ratio, a number of singular values in the diagonal matrix are selectively retained. Assuming that the singular value retention ratio is p, the number of retained singular values is np, and the remaining singular values are set to zero. The purpose of this step is to simplify the data by reducing the number of singular values.
[0053] S13, perform rank reduction processing on the two decomposed orthogonal matrices to obtain a new diagonal matrix with the dimension of The purpose of this step is to further reduce the data dimension and the amount of calculation. Combined with the operation of reducing the number of singular values, the complexity of noise injection can be effectively reduced.
[0054] S2, adding differential privacy noise to the preprocessed matrix;
[0055] Specifically, in this embodiment, the implementation process of S2 is as follows: differential privacy noise is added to the two orthogonal matrices after rank reduction, rather than adding noise directly to the entire weight matrix. The purpose of this step is to avoid the impact on model performance by adding noise to a smaller and easier-to-process matrix, while reducing the complexity of noise injection and improving the computational efficiency of the model fine-tuning stage. Assume that the dimension of the orthogonal matrix is , then the dimension of the noise added to each orthogonal matrix is also The elements in the added noise matrix obey a Gaussian distribution with a mean of 0 and a variance of σ², where σ² is the noise variance. By adding differential privacy noise to the orthogonal matrix, the privacy of the model parameters is ensured and the level of data protection is improved.
[0056] S3, update the parameters of the ViT model according to the matrix after adding noise, and perform model training and fine-tuning;
[0057] Among them, since the amount of noise injection is effectively controlled, the performance of the model will not be significantly affected.
[0058] S4, during the model training and fine-tuning process, regularly conduct privacy protection assessments to ensure that the privacy of the model meets the preset security standards. If insufficient privacy protection is found, further adjust the singular value retention ratio or noise injection amount to further enhance privacy protection.
[0059] Specifically, in this embodiment, the application scenario of the method is: using the ViT model for image classification tasks, and optimizing the computational complexity of differential privacy noise while ensuring data privacy. For this, the ViT model we use is a model with 12 Transformer layers, the selected singular value retention ratio is 50%, and the noise injected is Gaussian noise. Through matrix decomposition and rank reduction processing, the amount of data to which noise needs to be added is reduced, thereby effectively reducing the complexity of noise calculation. At the same time, by adding differential privacy noise to the orthogonal matrix, the privacy of the model parameters is further enhanced, and the level of data protection is improved. Through this method, the computational efficiency of the ViT model in the fine-tuning stage can be significantly improved while ensuring data privacy.
[0060] In summary, this embodiment provides a method for optimizing the computational complexity of differential privacy noise based on the ViT model, and the method for optimizing the computational complexity of differential privacy noise based on the ViT model can be widely used in application fields such as artificial intelligence training and reasoning, data privacy protection, and computer vision. In the field of artificial intelligence training and reasoning, the differential privacy noise computational complexity optimization method of the present invention can significantly improve the computational efficiency of the ViT model in the fine-tuning stage, shorten the training time, and reduce the consumption of computing resources. This has important application value for industries that require rapid iteration and deployment of AI models, such as autonomous driving and financial risk assessment. In the field of data privacy protection, the method of the present invention ensures the privacy of model parameters and improves the level of data protection by adding differential privacy noise to the orthogonal matrix. This has important application significance for industries that need to process a large amount of sensitive data, such as medical health, personal privacy protection, etc. In the field of computer vision, the method of the present invention can be applied to tasks such as image classification, object detection, and image segmentation, and improves the performance and accuracy of the model by improving the computational efficiency of the model fine-tuning stage. This has broad application prospects for industries that require efficient processing of image data, such as security monitoring and intelligent manufacturing. In general, with the continuous improvement of data privacy protection awareness and the increasing popularization of deep learning applications, the differential privacy noise computational complexity optimization method of the present invention has broad application prospects and market demand in multiple fields.
[0061] Second embodiment
[0062] This embodiment provides a system for optimizing the computational complexity of differential privacy noise based on the ViT model. The system for optimizing the computational complexity of differential privacy noise based on the ViT model includes the following modules:
[0063] A matrix preprocessing module, used for preprocessing the weight matrix of the model to be added with noise to obtain a preprocessed matrix; wherein the preprocessing includes: matrix decomposition, matrix rank reduction and matrix data simplification;
[0064] The noise adding module is used to add differential privacy noise to the preprocessed matrix;
[0065] The model training and fine-tuning module is used to update the parameters of the ViT model according to the matrix after adding noise, and perform model training and fine-tuning;
[0066] The privacy protection evaluation module is used to perform privacy protection evaluation regularly during model training and fine-tuning to ensure that the privacy of the model meets the preset security standards. If it is found that the privacy protection does not meet the preset security standards, the singular value retention ratio or noise injection amount is adjusted to further enhance privacy protection.
[0067] It should be noted that the optimization system for the computational complexity of differential privacy noise based on the ViT model of this embodiment corresponds to the optimization method for the computational complexity of differential privacy noise based on the ViT model of the first embodiment mentioned above; the functions implemented by each functional module in the optimization system for the computational complexity of differential privacy noise based on the ViT model of this embodiment correspond one by one to the various process steps in the optimization method for the computational complexity of differential privacy noise based on the ViT model of the first embodiment mentioned above; therefore, they will not be repeated here.
[0068] Third embodiment
[0069] This embodiment provides an electronic device, such as Figure 2 As shown, the electronic device includes: a processor and a memory; wherein the processor and the memory can be connected via a communication bus; the memory stores at least one instruction, and the instruction is loaded and executed by the processor to implement the method of the first embodiment. In addition, the electronic device may also include a transceiver, the processor and the transceiver can be connected via a communication bus, and the transceiver is used to communicate with other devices.
[0070] Next, combine Figure 2 The following is a detailed introduction to the various components of the electronic device:
[0071] Among them, the processor is the control center of the electronic device, and the electronic device may include multiple processors, each of which may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). The processor here may be a processor or a general term for multiple processing elements. For example, the processor is one or more central processing units (CPUs), or other general-purpose processors, application specific integrated circuits (ASICs), or one or more integrated circuits configured to implement an embodiment of the present invention, such as one or more microprocessors (digital signal processors, DSPs), or one or more field programmable gate arrays (field programmable gate arrays, FPGAs), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc. The processor may execute various functions of the electronic device by running or executing software programs stored in the memory and calling data stored in the memory.
[0072] In a specific implementation, as an embodiment, the processor may include one or more CPUs, such as Figure 2 The CPU0 and CPU1 shown in the figure are, of course, only exemplary.
[0073] The memory is used to store the software program for executing the solution of the present invention, and the execution is controlled by the processor. The specific implementation method can refer to the above method embodiment and will not be repeated here.
[0074] Optionally, the memory may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory may be integrated with the processor or exist independently and accessed through the interface circuit ( Figure 2 The processor is coupled to the processor (not shown), which is not specifically limited in this embodiment of the present invention.
[0075] The transceiver may include a receiver and a transmitter ( Figure 2 The receiver is used to implement the receiving function, and the transmitter is used to implement the sending function. The transceiver can be integrated with the processor or exist independently and communicate with the electronic device through the interface circuit ( Figure 2 (not shown) is coupled to the processor, which is not specifically limited in this embodiment of the present invention.
[0076] In addition, it should be noted that Figure 2 The structure of the electronic device shown in the figure does not constitute a limitation on the device, and the actual device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently. In addition, the technical effects achieved by the electronic device when executing the method of the first embodiment above can refer to the technical effects described in the first embodiment above, so they are not repeated here.
[0077] Fourth embodiment
[0078] This embodiment provides a computer-readable storage medium, which stores at least one instruction, and the instruction is loaded and executed by a processor to implement the method of the first embodiment. The computer-readable storage medium may be a ROM, a random access memory, a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc. The instructions stored therein may be loaded by a processor in a terminal to execute the method.
[0079] In addition, it should be noted that the present invention can be provided as a method, an apparatus or a computer program product. Therefore, the embodiment of the present invention can be in the form of a full or partial hardware embodiment, a full or partial software embodiment or an embodiment combining software and hardware. Moreover, when implemented using software, the embodiment of the present invention can be in the form of a computer program product implemented on one or more computer-usable storage media containing computer-usable program codes. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the process or function described in the embodiment of the present invention is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center by wired (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center containing one or more available media sets. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a DVD), or a semiconductor medium. The semiconductor medium may be a solid state drive.
[0080] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, an embedded processor, or other programmable data processing terminal device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0081] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing terminal device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, so that a series of operation steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable terminal device provide for implementing the process in the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0082] It should also be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. The terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or terminal device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or terminal device. In the absence of more restrictions, the elements defined by the sentence "including one..." do not exclude the existence of other identical elements in the process, method, article or terminal device including the elements. In addition, the term "and / or" is only an association relationship describing the associated objects, indicating that there can be three relationships, for example, A and / or B, which can represent: A exists alone, A and B exist at the same time, and B exists alone, wherein A and B can be singular or plural. In addition, the character " / " in this article generally indicates that the objects before and after are in an "or" relationship, but it may also indicate an "and / or" relationship. Please refer to the context for specific understanding. "At least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b or c can be represented by: a, b, c, ab, ac, bc, or abc, where a, b, c can be single or plural.
[0083] In addition, it can be understood that in various embodiments of the present invention, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0084] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0085] In several embodiments provided by the present invention, it should be understood that the disclosed equipment, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of functional modules / units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point, the coupling or direct coupling or communication connection between each other shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms. The unit described as a separate component may or may not be physically separated, and the component displayed as a unit may or may not be a physical unit, that is, it may be located in one place, or it may be distributed on multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the scheme of this embodiment. In addition, each functional unit in each embodiment of the present invention can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.
[0086] If the method is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0087] Finally, it should be noted that the above is only a preferred embodiment of the present invention. It should be pointed out that although the preferred embodiment of the present invention has been described, for ordinary technicians in this technical field, once the basic creative concept of the present invention is known, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as the protection scope of the present invention. Therefore, the attached claims are intended to be interpreted as including the preferred embodiment and all changes and modifications that fall within the scope of the embodiments of the present invention.
Claims
1. A method for optimizing the computational complexity of differential privacy noise based on the ViT model, characterized in that: The optimization method of the differential privacy noise computation complexity based on the ViT model includes: Preprocessing the weight matrix of the model to which noise is to be added to obtain a preprocessed matrix; wherein the preprocessing includes: matrix decomposition, matrix rank reduction and matrix data simplification; Add differential privacy noise to the preprocessed matrix; The parameters of the ViT model are updated according to the matrix after adding noise, and the model is trained and fine-tuned.
2. The method for optimizing the computational complexity of differential privacy noise based on the ViT model as claimed in claim 1, characterized in that: The preprocessing of the weight matrix of the model to which noise is to be added comprises: Performing matrix decomposition on the weight matrix of the model to which noise is to be added, decomposing the weight matrix of the model to which noise is to be added into two orthogonal matrices and a diagonal matrix containing singular values; According to a preset singular value retention ratio, a number of singular values in the diagonal matrix are selectively retained; Perform rank reduction on the two orthogonal matrices respectively.
3. The method for optimizing the computational complexity of differential privacy noise based on the ViT model as claimed in claim 2, characterized in that: The adding of differential privacy noise to the preprocessed matrix includes: Add differential privacy noise to the two orthogonal matrices after rank reduction.
4. The method for optimizing the computational complexity of differential privacy noise based on the ViT model as claimed in claim 1, characterized in that: The elements in the differential privacy noise obey Gaussian distribution.
5. The method for optimizing the computational complexity of differential privacy noise based on the ViT model as claimed in claim 2, characterized in that: After updating the parameters of the ViT model according to the matrix after adding noise, and performing model training and fine-tuning, the optimization method of the differential privacy noise calculation complexity based on the ViT model also includes: During the model training and fine-tuning process, privacy protection assessments are performed regularly to ensure that the privacy of the model meets the preset security standards. If it is found that the privacy of the model does not meet the preset security standards, the singular value retention ratio or noise injection amount is adjusted to further enhance privacy protection.
6. A system for optimizing the computational complexity of differential privacy noise based on the ViT model, characterized in that: The optimization system for calculating the complexity of differential privacy noise based on the ViT model includes: A matrix preprocessing module, used for preprocessing the weight matrix of the model to be added with noise to obtain a preprocessed matrix; wherein the preprocessing includes: matrix decomposition, matrix rank reduction and matrix data simplification; The noise adding module is used to add differential privacy noise to the preprocessed matrix; The model training and fine-tuning module is used to update the parameters of the ViT model according to the matrix after adding noise, and perform model training and fine-tuning.
7. The optimization system for computing complexity of differential privacy noise based on the ViT model as claimed in claim 6, characterized in that: The matrix preprocessing module is specifically used for: Performing matrix decomposition on the weight matrix of the model to which noise is to be added, decomposing the weight matrix of the model to which noise is to be added into two orthogonal matrices and a diagonal matrix containing singular values; According to a preset singular value retention ratio, a number of singular values in the diagonal matrix are selectively retained; Perform rank reduction on the two orthogonal matrices respectively.
8. The optimization system for computing complexity of differential privacy noise based on the ViT model as claimed in claim 7, characterized in that: The noise adding module is specifically used for: Add differential privacy noise to the two orthogonal matrices after rank reduction.
9. The optimization system for computing complexity of differential privacy noise based on the ViT model as claimed in claim 6, characterized in that: The elements in the differential privacy noise obey Gaussian distribution.
10. The optimization system for computing complexity of differential privacy noise based on the ViT model as claimed in claim 7, characterized in that: The system further includes a privacy protection assessment module, which is used to: During the model training and fine-tuning process, privacy protection assessments are performed regularly to ensure that the privacy of the model meets the preset security standards. If it is found that the privacy of the model does not meet the preset security standards, the singular value retention ratio or noise injection amount is adjusted to further enhance privacy protection.