Safety reasoning method and device of model, electronic equipment and storage medium

By matrix replacement of model parameters and inference data when the model is deployed to the cloud platform, the problem of privacy leakage risk during model deployment is solved, and efficient privacy protection and rapid inference process are achieved.

CN119990336AActive Publication Date: 2025-05-13PENG CHENG LAB

Patent Information

Application Number
CN202510466565.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-05-13
Estimated Expiration
2045-04-15

AI Technical Summary

Technical Problem

When the model is deployed to the cloud platform, there is a risk of privacy leakage during the uploading of model parameters and inference data, resulting in serious privacy leakage risks.

Method used

A security reasoning method for the model is proposed. By randomly generating a permutation matrix between the model developer side and the cloud platform, matrix permutation processing of model parameters and inference data is ensured to ensure the privacy protection of the data during transmission.

Benefits of technology

It effectively reduces the risk of leakage of model parameters and inference data, improves the security of private data, and reduces the calculation and communication overhead caused by ciphertext calculation, improves processing speed and reduces communication overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119990336A_ABST
    Figure CN119990336A_ABST
Patent Text Reader

Abstract

The invention discloses a safe reasoning method and device of a model, electronic equipment and a storage medium, and relates to the technical field of model privacy reasoning. In the security reasoning method, a cloud platform cannot obtain a parameter set of a model based on each hidden parameter set; the cloud platform cannot obtain the original reasoning data based on the second hidden reasoning; and the user side performs recovery reconstruction processing based on the first permutation matrix, the first reasoning result and the second reasoning result to obtain a target reasoning result. A user side cannot obtain a parameter set of the model, so that the user side cannot obtain privacy of a model developer side. According to the method, the original reasoning data and the parameter set of the model do not need to be converted into the ciphertext by adopting a traditional protocol, and the parameter set of the model and the randomly generated permutation matrix are subjected to matrix multiplication processing, so that the calculation and communication overhead caused by ciphertext calculation is saved, the processing speed is higher, and the communication overhead is smaller.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of model privacy reasoning technology, and in particular to a model security reasoning method, device, electronic device and storage medium. Background Art

[0002] In related technologies, more and more models are deployed on cloud platforms to provide customers with high-quality services, such as chat, virtual assistants, and code generation. However, this service model requires model developers to upload model parameters to the cloud platform, and users to upload inference data to the cloud platform. This process may lead to the leakage of model parameters and inference data, resulting in serious privacy leakage risks. Summary of the invention

[0003] The present application aims to solve at least one of the technical problems existing in the prior art. To this end, the present application proposes a secure reasoning method, device, electronic device and storage medium for a model, which can protect the privacy of the model's parameter set and reasoning data, reduce the risk of privacy data leakage, and thus improve the security of privacy data.

[0004] To achieve the above-mentioned purpose, the first aspect of the present application provides a model security reasoning method, which is applied to a model developer side, and the model developer side is provided with the model; The method comprises: randomly generating a first permutation matrix based on a preset input sequence length, randomly generating a second permutation matrix based on the dimension of the model, and randomly generating a third permutation matrix based on the dimension of a linear layer of a feedforward neural network of the model; Performing matrix permutation processing on the first permutation matrix and the attention mechanism parameter set of the linear layer of the model to obtain a first hidden parameter set, performing matrix permutation processing on the first permutation matrix and the embedding layer parameter set of the model to obtain a second hidden parameter set, and performing matrix permutation processing on the second permutation matrix, the third permutation matrix, and the linear layer parameter set in the feedforward neural network to obtain a third hidden parameter set; receiving first hidden reasoning data sent by the user terminal, performing first privacy protection reasoning based on the first hidden reasoning data, the first hidden parameter set, the second hidden parameter set, and the third hidden parameter set to obtain a first reasoning result; Sending the first hidden parameter set, the second hidden parameter set, and the third hidden parameter set to the cloud platform, so that the cloud platform performs a second privacy protection reasoning based on the second hidden reasoning data, the first hidden parameter set, the second hidden parameter set, and the third hidden parameter set to obtain a second reasoning result, and sending the second reasoning result to the user end, where the first hidden reasoning data and the second hidden reasoning data are obtained by the user end by processing the original reasoning data based on a secret sharing algorithm; The first permutation matrix and the first inference result are sent to the user terminal, so that the user terminal performs recovery and reconstruction processing based on the first permutation matrix, the first inference result and the second inference result to obtain a target inference result.

[0005] To achieve the above-mentioned purpose, the second aspect of the present application provides a model security reasoning method, which is applied to a cloud platform. The method includes: Receive a first hidden parameter set, a second hidden parameter set, and a third hidden parameter set sent by a model developer; wherein the first hidden parameter set is obtained by the model developer based on the attention mechanism parameter set of the linear layer of the model and a randomly generated first permutation matrix; the second hidden parameter set is obtained by the model developer based on the embedding layer parameter set of the model and a randomly generated second permutation matrix; the third hidden parameter set is obtained by the model developer based on the linear layer parameter set of the model's pre-coronavirus neural network and a randomly generated third permutation matrix; receiving second hidden inference data sent by a user terminal; A first permutation matrix is ​​randomly generated based on a preset input sequence length; a second permutation matrix is ​​randomly generated based on the dimension of the model; and a third permutation matrix is ​​randomly generated based on the dimension of a linear layer of a feedforward neural network of the model; Performing matrix permutation processing on the first permutation matrix and the attention mechanism parameter set of the linear layer of the model to obtain a first hidden parameter set; performing matrix permutation processing on the first permutation matrix and the embedding layer parameter set of the model to obtain a second hidden parameter set; performing matrix permutation processing on the second permutation matrix, the third permutation matrix and the linear layer parameter set in the feedforward neural network to obtain a third hidden parameter set; receiving first hidden reasoning data sent by the user terminal, performing second privacy protection reasoning based on the first hidden reasoning data, the first hidden parameter set, the second hidden parameter set, and the third hidden parameter set to obtain a second reasoning result; The second reasoning result is sent to the user end, so that the user end performs recovery and reconstruction processing based on the first permutation matrix, the first reasoning result and the second reasoning result to obtain a target reasoning result; wherein the first reasoning result is obtained by the model developer end performing a first privacy protection reasoning based on the first hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set.

[0006] To achieve the above-mentioned purpose, the third aspect of the present application provides a model security reasoning method, which is applied to a security reasoning system, wherein the security reasoning system includes a model developer end, a user end and a cloud platform; The method comprises: The model developer randomly generates a first permutation matrix based on a preset input sequence length; randomly generates a second permutation matrix based on the dimension of the model; and randomly generates a third permutation matrix based on the dimension of the linear layer of the feedforward neural network of the model; The model developer performs matrix permutation processing on the first permutation matrix and the attention mechanism parameter set of the linear layer of the model to obtain a first hidden parameter set; performs matrix permutation processing on the first permutation matrix and the embedding layer parameter set of the model to obtain a second hidden parameter set; performs matrix permutation processing on the second permutation matrix, the third permutation matrix and the linear layer parameter set in the feedforward neural network to obtain a third hidden parameter set; The model developer terminal sends the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to the cloud platform; The user end processes the original reasoning data based on the secret sharing algorithm to obtain first hidden reasoning data and second hidden reasoning data, and sends the first hidden reasoning data to the model developer end, and sends the second hidden reasoning data to the cloud platform; The model developer end performs a first privacy protection reasoning based on the first hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to obtain a first reasoning result; and sends the first reasoning result to the user end; The cloud platform performs a second privacy protection reasoning based on the second hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to obtain a second reasoning result; and sends the second reasoning result to the user end; The user end performs recovery and reconstruction processing based on the first permutation matrix, the first reasoning result, and the second reasoning result to obtain a target reasoning result.

[0007] To achieve the above-mentioned purpose, the fourth aspect of the present application provides a model security reasoning device, which is applied to a model developer side, and the model developer side is provided with the model; The device comprises: A generation module is configured to randomly generate a first permutation matrix based on a preset input sequence length; randomly generate a second permutation matrix based on the dimension of the model; and randomly generate a third permutation matrix based on the dimension of a linear layer of a feedforward neural network of the model; A parameter processing module is configured to perform matrix permutation processing on the first permutation matrix and the attention mechanism parameter set of the linear layer of the model to obtain a first hidden parameter set; perform matrix permutation processing on the first permutation matrix and the embedding layer parameter set of the model to obtain a second hidden parameter set; perform matrix permutation processing on the second permutation matrix, the third permutation matrix and the linear layer parameter set in the feedforward neural network to obtain a third hidden parameter set; an inference module, configured to receive first hidden inference data sent by the user terminal, perform first privacy protection inference based on the first hidden inference data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set, and obtain a first inference result; A first sending module is configured to send the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to the cloud platform, so that the cloud platform performs a second privacy protection reasoning based on the second hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to obtain a second reasoning result, and sends the second reasoning result to the user end; wherein the first hidden reasoning data and the second hidden reasoning data are obtained by the user end by processing the original reasoning data based on a secret sharing algorithm; The second sending module is configured to send the first permutation matrix and the first reasoning result to the user terminal, so that the user terminal performs recovery and reconstruction processing based on the first permutation matrix, the first reasoning result and the second reasoning result to obtain a target reasoning result.

[0008] To achieve the above-mentioned purpose, the fifth aspect embodiment of the present application provides an electronic device, which includes a memory and a processor, the memory stores a computer program, and the processor implements the security reasoning method of the model described in any one of the first aspect embodiment, the second aspect embodiment, and the third aspect embodiment when executing the computer program.

[0009] To achieve the above-mentioned objectives, the sixth aspect embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the security reasoning method of the model described in any one of the first aspect embodiment, the second aspect embodiment, and the third aspect embodiment.

[0010] According to the secure reasoning method, device, electronic device and storage medium of the model of the embodiment of the present application, the user end processes the original reasoning data based on the secret sharing algorithm to obtain the first hidden reasoning data and the second hidden reasoning data; the model developer end performs the first privacy protection reasoning based on the first hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to obtain the first reasoning result. In the process of performing the first privacy protection reasoning, the model developer end cannot obtain the second hidden reasoning data; therefore, the model developer end cannot obtain the original reasoning data based on the first hidden reasoning data, so the model developer end cannot obtain the privacy of the user end. The cloud platform performs the second privacy protection reasoning based on the second hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to obtain the second reasoning result; the cloud platform cannot obtain the parameter set of the model based on each hidden parameter set, so the cloud platform cannot obtain the privacy of the model developer end; the cloud platform cannot obtain the original reasoning data based on the second hidden reasoning, so the cloud platform cannot obtain the privacy of the user end; the user end performs recovery and reconstruction processing based on the first permutation matrix, the first reasoning result and the second reasoning result to obtain the target reasoning result. The user end cannot obtain the parameter set of the model, so the user end cannot obtain the privacy of the model developer end. In this way, the present application can protect the privacy of model parameters and inference data, reduce the risk of privacy leakage, and thus improve the security of private data. Compared with the traditional secure inference method, the present application does not need to use the traditional protocol to convert the original inference data and the parameter set of the model into ciphertext, but instead performs matrix multiplication on the parameter set of the model and the randomly generated permutation matrix, and performs secret sharing on the original inference data, saving the computational and communication overhead caused by the ciphertext calculation. Therefore, the secure inference method of the present application has a faster processing speed and lower communication overhead.

[0011] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through the practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] The present application is further described below with reference to the accompanying drawings and embodiments, wherein: Figure 1 This is a schematic diagram of the structure of the security reasoning system of the embodiment of the present application; Figure 2 A flowchart of the steps of the secure reasoning method for the model applied to the model developer side; Figure 3 for Figure 2 A specific flow chart of step S230; Figure 4 for Figure 3 A specific flow chart of step S340; Figure 5 for Figure 4 A schematic diagram of a specific step flow of step S460; Figure 6 for Figure 5 A specific flow chart of step S570; Figure 7 A secure reasoning method for a model applied to a cloud platform in an embodiment of the present application; Figure 8 The application of the embodiment of the present application is Figure 1 A flowchart of a safety reasoning method for a model of a safety reasoning system; Fig. 9 A schematic diagram of the functional modules of a safety reasoning device for a model according to an embodiment of the present application; Fig.10 A schematic diagram of the hardware structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0013] The embodiments of the present application are described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present application, and cannot be understood as limiting the present application.

[0014] In the description of the present application, it should be understood that descriptions involving orientation, such as up, down, front, back, left, right, etc., indicating orientations or positional relationships, are based on the orientations or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the present application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be understood as a limitation on the present application.

[0015] In the description of this application, "several" means more than one, "more" means more than two, "greater than", "less than", "exceed", etc. are understood to exclude the number itself, and "above", "below", "within", etc. are understood to include the number itself. If there is a description of "first" or "second", it is only used for the purpose of distinguishing technical features, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features or implicitly indicating the order of the indicated technical features.

[0016] In the description of this application, unless otherwise clearly defined, terms such as setting, installing, connecting, etc. should be understood in a broad sense, and technicians in the relevant technical field can reasonably determine the specific meanings of the above terms in this application based on the specific content of the technical solution.

[0017] In the description of the present application, the description with reference to the terms "one embodiment", "some embodiments", "illustrative embodiments", "examples", "specific examples", or "some examples" means that the specific features, structures, materials, or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.

[0018] First, some nouns involved in this application are analyzed: Transformer model: The Transformer model is a revolutionary architecture in the field of natural language processing. The Transformer model includes an attention mechanism and a feedforward neural network. Self-Attention Mechanism: The self-attention mechanism allows the model to focus on different parts of the input sequence at different positions, thereby capturing dependencies within the sequence. Specifically, for each position in the input sequence, the self-attention mechanism calculates the correlation between that position and other positions in the sequence (i.e., the attention weight), and then performs a weighted summation of the input sequence based on these weights to generate a new representation. Feed-Forward Neural Network (FFNN): It is the simplest type of neural network, in which each neuron is arranged in layers, each neuron is only connected to the neurons in the previous layer, receives the output of the previous layer, and outputs it to the next layer, with no feedback between layers. This network structure allows information to flow in only one direction, from the input layer through the hidden layer and finally to the output layer.

[0019] Secure Multi-Party Computation (SMPC) Protocol: The SMPC protocol is a cryptographic technique that allows multiple parties to perform computations without revealing private inputs to each other, and only returns the computation results to the participants without revealing any other private information. The goal of SMPC is to achieve computations between multiple parties while protecting data privacy.

[0020] The secret sharing algorithm is an important research topic in the field of cryptography and information security. It allows the owner of a secret to share the secret with multiple participants while ensuring that a single participant cannot obtain any information about the secret. The secret can only be reconstructed when multiple participants cooperate. The secret sharing algorithm can divide data A into two secret data, A0 and A1, respectively, [[A]] = [A0] + [A1]. Therefore, A can also be reconstructed based on A0 and A1.

[0021] More and more models are deployed on cloud platforms to provide customers with high-quality services, such as chat, virtual assistants, and code generation. However, this service model requires the model developer to upload the model parameters to the cloud platform, and the user to upload the inference data to the cloud platform. This process may cause the leakage of model parameters and inference data, leading to serious privacy leakage risks. In order to reduce the risk of privacy leakage, traditional technologies usually directly call the existing SMPC protocol to implement privacy-preserving Transformer Inference (PPTI). However, this method requires the original inference data to be converted into ciphertext, and the ciphertext calculation requires high computing and communication overhead, resulting in a very slow privacy-preserving inference process.

[0022] Based on this, the embodiments of the present application propose a secure reasoning method, device, electronic device and storage medium for a model, which can protect the privacy of the model's parameter set and reasoning data, reduce the risk of privacy leakage, and save the computing and communication overhead caused by ciphertext calculation, thereby faster processing speed and lower communication overhead.

[0023] First, the security reasoning system of the embodiment of the present application is introduced. Figure 1 , Figure 1 The schematic diagram of the structure of the security reasoning system of the embodiment of the present application. The security reasoning system includes a model developer end P0, a user end P2 and a cloud platform P1. The model developer end deploys a model, and the model is a Transformer model. The model developer end randomly generates a first permutation matrix, a second permutation matrix and a third permutation matrix. Figure 1 In the example, the first permutation matrix is ​​π, the second permutation matrix is ​​π1, and the third permutation matrix is ​​π2. The model developer performs matrix multiplication on each parameter set of the Transformer model with π, π1, and π2 to obtain multiple hidden parameter sets (this process is called Figure 1 Parameter substitution in Figure 1 middle, Represents multiple hidden parameter sets. Then π is sent to the user end, and multiple hidden parameter sets are sent to the cloud platform. The user end processes the original reasoning data X based on the secret sharing algorithm to obtain the first hidden reasoning data [X]0 and the second reasoning hidden data [X]1. The model developer end performs privacy-preserving reasoning based on multiple hidden parameter sets and [X]0 to obtain the first reasoning result [Yπ]0. The cloud platform performs privacy-preserving reasoning based on [X]1 and multiple hidden parameter sets to obtain the second reasoning result [Yπ]1. Then the user end reconstructs and restores the reasoning result based on [Yπ]0 and [Yπ]1 to obtain Yπ, and then permutes Yπ based on π to obtain the target reasoning result Y.

[0024] It should be noted that the model developer end, cloud platform, and user end can be terminals or servers. In some embodiments, the terminal can be a smart phone, tablet computer, laptop computer, desktop computer, router, programmable switch, network card, etc.; the server can be configured as an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application that implements the vehicle recognition model training method, etc., but is not limited to the above forms.

[0025] The present application can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, etc. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific services or implement specific abstract data types. The present application can also be practiced in distributed computing environments, in which services are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.

[0026] The first aspect of the present application provides a method for secure reasoning of a model. The method for secure reasoning of the first aspect of the present application is applied to Figure 1 Model developer side in . Figure 2 , Figure 2The following is a flowchart of the steps of the security reasoning method for the model applied to the model developer side. The security reasoning method for the model applied to the model developer side includes but is not limited to the following steps: Step S210, randomly generating a first permutation matrix based on a preset input sequence length; randomly generating a second permutation matrix based on the dimension of the model; and randomly generating a third permutation matrix based on the dimension of the linear layer of the feedforward neural network of the model; Specifically, the model developer randomly generates a set of permutation matrices: ; The set of permutation matrices is used to permute model parameters of different dimensions. Among them, π is the first permutation matrix, π1 is the second permutation matrix, and π2 is the third permutation matrix; n is the preset input sequence length, d is the dimension of the model; k is the dimension of the linear layer of the model's feedforward neural network.

[0027] It is worth noting that the original reasoning data on the user side is the input of the Transformer model. Usually, the sequence length of the original reasoning data is the input sequence length. When the sequence length of the original reasoning data is less than the input sequence length, the original reasoning data is supplemented to make the sequence length of the original reasoning data the same as the input sequence length. When the sequence length of the original reasoning data is greater than the input sequence length, the original reasoning data is deleted to make the sequence length of the original reasoning data the same as the input sequence length. It should be noted that the user can input the original reasoning data on the user side through a device such as a mouse, keyboard, or touch screen.

[0028] Step S220, performing matrix permutation processing on the first permutation matrix and the attention mechanism parameter set of the linear layer of the model to obtain a first hidden parameter set; performing matrix permutation processing on the first permutation matrix and the embedding layer parameter set of the model to obtain a second hidden parameter set; performing matrix permutation processing on the first permutation matrix, the second permutation matrix, the third permutation matrix and the linear layer parameter set in the feedforward neural network to obtain a third hidden parameter set; Specifically, the attention mechanism parameter set includes , the first permutation matrix is ​​used to permute the attention mechanism parameter set to obtain the first hidden parameter set, which is expressed as: ; The embedding layer parameter set includes , using the first permutation matrix Permutate to obtain the second hidden parameter set, which is .

[0029] The set of parameters for the linear layer in a feedforward neural network consists of , the third permutation matrix is ​​used to permute the linear layer parameter set in the feedforward neural network to obtain the third hidden parameter set, which is expressed as: .

[0030] It should be noted that the above attention mechanism parameter set, embedding layer parameter set, and the specific illustration of the linear layer parameter set in the feedforward neural network are only examples and cannot be understood as limitations on the present application. In addition, the present application does not specifically limit the parameters in the attention mechanism parameter set, embedding layer parameter set, and linear layer parameter set in the feedforward neural network. The parameters in the attention mechanism parameter set, embedding layer parameter set, and linear layer parameter set in the feedforward neural network in different Transformer models are different.

[0031] Step S230, receiving first hidden reasoning data sent by the user terminal, performing first privacy protection reasoning based on the first hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set, and obtaining a first reasoning result; Step S240, sending the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to the cloud platform, so that the cloud platform performs a second privacy protection reasoning based on the second hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set, obtains a second reasoning result, and sends the second reasoning result to the user end; wherein the first hidden reasoning data and the second hidden reasoning data are obtained by the user end by processing the original reasoning data based on the secret sharing algorithm; It should be noted that since the cloud platform cannot obtain the first permutation matrix, the second permutation matrix, and the third permutation matrix, the cloud platform cannot obtain the attention mechanism parameter set, the embedding layer parameter set, and the linear layer parameter set in the feedforward neural network based on the first hidden parameter set, the second hidden parameter set, and the third hidden parameter set. Therefore, the cloud platform cannot obtain the model parameters, which protects the model parameters of the model developer and reduces the risk of model parameter leakage.

[0032] It is worth noting that in order to reconstruct the original reasoning data, it is necessary to base it on both the first hidden reasoning data and the second hidden reasoning data. In step S230, during the process of performing the first privacy protection reasoning, the model developer side cannot obtain the second hidden reasoning data, so the model developer side cannot reconstruct the original reasoning data. In step S240, during the process of performing the second privacy protection reasoning, the cloud platform cannot obtain the first hidden reasoning data, so the cloud platform cannot reconstruct the original reasoning data. Therefore, neither the cloud platform nor the model developer side can obtain the original reasoning data, which protects the original reasoning data of the user side and reduces the risk of leakage of the original reasoning data.

[0033] It should be noted that secret sharing is based on integer rings , in Ring Z L The specific process is as follows: , ; Where X is the original inference data, [X]0 is the first hidden inference data, [X]1 is the second hidden inference data, L is the preset modulus, L is 2 32 or 2 64 Based on [X]0 and [X]1, X can be reconstructed.

[0034] Step S250 , sending the first permutation matrix and the first reasoning result to the user terminal, so that the user terminal performs a recovery and reconstruction process based on the first permutation matrix, the first reasoning result and the second reasoning result to obtain a target reasoning result.

[0035] Specifically, in step S250, after the user terminal obtains the first reasoning result [Yπ]0 and the second reasoning result [Yπ]1, according to the secret sharing algorithm, Yπ can be reconstructed based on [Yπ]0 and [Yπ]1, and then the inverted matrix π of the first permutation matrix π is obtained. T , so that Yπ and π T Multiply them to get the target inference result Y.

[0036] The embodiment of the present application implements the privacy protection reasoning process of the model through the above steps S210 to S250. In this process, the user end processes the original reasoning data based on the secret sharing algorithm to obtain the first hidden reasoning data and the second hidden reasoning data; the model developer end performs the first privacy protection reasoning based on the first hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to obtain the first reasoning result. In the process of performing the first privacy protection reasoning, since the model developer end cannot obtain the second hidden reasoning data; therefore, the model developer end cannot obtain the original reasoning data based on the first hidden reasoning data, so the model developer end cannot obtain the privacy of the user end. The cloud platform performs the second privacy protection reasoning based on the second hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to obtain the second reasoning result; the cloud platform cannot obtain the parameter set of the model based on each hidden parameter set, so the cloud platform cannot obtain the privacy of the model developer end; the cloud platform cannot obtain the original reasoning data based on the second hidden reasoning, so the cloud platform cannot obtain the privacy of the user end; the user end performs recovery and reconstruction processing based on the first permutation matrix, the first reasoning result and the second reasoning result to obtain the target reasoning result. The user end cannot obtain the parameter set of the model, so the user end cannot obtain the privacy of the model developer end. In this way, the present application can protect the privacy of model parameters and reasoning data, reduce the risk of privacy leakage, and thus improve the security of privacy data. And compared with the traditional security reasoning method, the present application does not need to convert the original reasoning data and the parameter set of the model into ciphertext, but instead performs matrix multiplication on the parameter set of the model and the randomly generated permutation matrix, and performs secret sharing on the original reasoning data, saving the computational and communication overhead caused by the ciphertext calculation. Therefore, the security reasoning method of the present application has a faster processing speed and lower communication overhead.

[0037] In some embodiments, reference Figure 3 , Figure 3 for Figure 2 A specific flow chart of step S230 in FIG. 1 . Step S230 includes the following steps: Step S310, performing matrix multiplication processing on the second hidden parameter set and the first hidden inference data to obtain a first intermediate matrix; It should be noted that matrix multiplication includes MatMul and ScalMul. In mathematics and computer science, matrix multiplication (MatMul) is a binary operation that multiplies two matrices to obtain a new matrix. Scalar multiplication (ScalMul) is the multiplication of a scalar (plaintext) and a vector or matrix (ciphertext).

[0038] In step S310, ScalMul multiplication is used to After processing with [X]0, the first intermediate matrix is , in ScalMul multiplication, as plaintext, and [X]0 as ciphertext.

[0039] Step S320, sending the first intermediate matrix to the cloud platform, so that the cloud platform performs reconstruction processing based on the first intermediate matrix and the second intermediate matrix to obtain a first reconstructed matrix, and inputs the first reconstructed matrix into a normalization function to obtain a normalized matrix, and processes the normalized matrix based on a secret sharing algorithm to obtain a first normalized matrix and a second normalized matrix; wherein the second intermediate matrix is ​​obtained by the cloud platform based on the second hidden inference data and the second hidden parameter set; Specifically, in step S320, the cloud platform The first intermediate matrix obtained by matrix multiplication with [X]1 is Then the cloud platform and Reconstruct and get ;Will Input to the normalization function, specifically: ; Among them, Zπ is the normalized matrix, LayerNorm is the normalization function. Then Zπ is processed based on the secret sharing algorithm to obtain the first normalized matrix [Zπ]0 and the second normalized matrix [Zπ]1.

[0040] Step S330, receiving a first normalized matrix sent by the cloud platform and a first hidden matrix sent by the user terminal; performing matrix multiplication processing on the first normalized matrix and the first hidden matrix to obtain a first normalized hidden matrix; wherein the first hidden matrix is ​​obtained by the user terminal processing a randomly generated fourth permutation matrix based on a secret sharing algorithm; Specifically, the user end randomly generates a fourth permutation matrix [α], and then the user end processes the randomly generated fourth permutation matrix based on the secret sharing algorithm to obtain the first hidden matrix [Zπ]0 and the second hidden matrix [Zπ]1. The first hidden matrix is ​​sent to the model developer end, and the second hidden matrix is ​​sent to the cloud platform. Then the model developer end multiplies the first normalized matrix [Zπ]0 with the first hidden matrix α0 based on the matrix multiplication MatMul to obtain the first normalized hidden matrix [α0Zπ]0.

[0041] It should be noted that the second privacy protection reasoning process of the cloud platform is carried out simultaneously with the first privacy protection reasoning process of the model developer, and they cooperate with each other. Specifically, in the second privacy protection reasoning process of the cloud platform, the cloud platform multiplies the second normalized matrix [Zπ]1 with the second hidden matrix α1 based on matrix multiplication to obtain the second normalized hidden matrix [α1Zπ]1.

[0042] Step S340, obtaining a first inference result based on the first normalized hidden matrix, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set.

[0043] The embodiment of the present application implements the operations of table lookup and layer normalization on the first hidden reasoning data through steps S310 to S330, and realizes the conversion of the first hidden reasoning data into a vector, that is, a first normalized hidden matrix. The first normalized hidden matrix can be used as an input of the attention mechanism, so that the model developer side can obtain the first reasoning result based on the first normalized hidden matrix, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set in step S340.

[0044] In some embodiments, reference Figure 4 , Figure 4 for Figure 3 A specific flow chart of step S340 in FIG. 1 is shown in FIG. 1 . Step S340 includes the following steps: Step S410, performing matrix multiplication processing on the first hidden parameter set and the first normalized hidden matrix to obtain a first query representation matrix, a first key representation matrix and a first value representation matrix; It is worth noting that the first hidden parameter set and the first normalized hidden matrix are processed using ScalMul multiplication, specifically: ; ; ; Among them, [Q]0 is the first query representation matrix, [K]0 is the first key representation matrix, and [V]0 represents the first value representation matrix.

[0045] Step S420, performing matrix multiplication processing on the first value representation matrix and the first hidden matrix to obtain a first attention hidden matrix; Specifically, the first value representation matrix [V]0 and the first hidden matrix α0 are processed by ScalMul multiplication to obtain the first attention hidden matrix [Vα0]0.

[0046] It should be noted that in the second privacy protection inference process of the cloud platform, the ScalMul multiplication is used to process the first hidden parameter set and the second normalized hidden matrix [α1Zπ]1, specifically: ; ; ; Among them, [Q]1 is the second query representation matrix, [K]1 is the second key representation matrix, and [V]1 is the second value representation matrix. Then the cloud platform uses ScalMul multiplication to process the second value representation matrix [V]1 and the second hidden matrix α1 to obtain the second attention hidden matrix [Vα1]1.

[0047] Step S430, obtaining a first intermediate attention matrix based on the first query representation matrix and the first key representation matrix; performing matrix multiplication processing on the first intermediate attention matrix and the first hidden matrix to obtain a second attention hidden matrix; Specifically, the first query representation matrix and the first key representation matrix are processed by ScalMul multiplication to obtain the first intermediate attention matrix, which is: ; The first intermediate attention matrix is ​​[O]0, , Represents the dimension of the Transformer model, Represents the number of heads in the multi-head attention mechanism in the Transformer model, Represents a mask matrix.

[0048] Then, ScalMul multiplication is used to perform α0 processing on the first intermediate attention matrix [O]0 and the first hidden matrix to obtain the second attention hidden matrix [Oα0]0.

[0049] It should be noted that in the second privacy protection reasoning process of the cloud platform, the second query representation matrix and the second key representation matrix are processed by ScalMul multiplication to obtain the second intermediate attention matrix, which is specifically: ; The second intermediate attention matrix is ​​[O]1, , Represents the dimension of the Transformer model, Represents the number of heads in the multi-head attention mechanism in the Transformer model, Represents the mask matrix. Then, the second intermediate attention matrix [O]1 and the second hidden matrix are processed by ScalMul multiplication to obtain the third attention hidden matrix [Oα1]1.

[0050] Step S440, sending the second attention hidden matrix to the cloud platform, so that the cloud platform reconstructs the attention hidden matrix based on the second attention hidden matrix and the third attention hidden matrix to obtain the attention reconstruction hidden matrix, and inputs the attention reconstruction hidden matrix into the classification function to obtain the classification hidden matrix, and processes the classification hidden matrix based on the secret sharing algorithm to obtain the first classification hidden matrix and the second classification hidden matrix; wherein the third attention hidden matrix is ​​obtained by the cloud platform based on the second normalized matrix and the second hidden matrix, and the second hidden matrix is ​​obtained by the user end by processing the fourth permutation matrix based on the secret sharing algorithm; Specifically, after obtaining the third attention hidden matrix [Oα1]1, the cloud platform reconstructs the attention reconstruction hidden matrix O1π based on the third attention hidden matrix [Oα1]1 and the second attention hidden matrix [Oα0]0, and then inputs the attention reconstruction hidden matrix O1π into the classification function, specifically: ; Among them, O2π is the classification hidden matrix, and Softmax is the classification function. Then the cloud platform processes the classification hidden matrix based on the secret sharing algorithm to obtain the first classification hidden matrix [O2π]0 and the second classification hidden matrix [O2π]1.

[0051] Step S450, receiving a first classification hidden matrix sent by the cloud platform, and obtaining a first target attention hidden matrix based on the first classification hidden matrix, the first attention hidden matrix, and the first normalized hidden matrix; Specifically, the first classification hidden matrix [O2π]0 is multiplied by the first attention hidden matrix [Vα0]0 to obtain [O3]0, and then [O4π]0 is calculated, which is specifically: ; Then the first target attention hidden matrix [O4]0=[O4π]0+[α0Zπ]0, where [α0Zπ]0 is the first normalized hidden matrix.

[0052] It should be noted that in the second privacy-preserving inference process of the cloud platform, the second classification hidden matrix [O2π]1 is multiplied by the second attention hidden matrix [Vα1]1 to obtain [O3]1, and then [O4π]1 is calculated, specifically: ; Then the second target attention hidden matrix [O4]1=[O4π]1+[α1Zπ]1, where [α1Zπ]1 is the second normalized hidden matrix.

[0053] Step S460, obtaining a first inference result based on the first target attention hidden matrix, the second hidden parameter set and the third hidden parameter set.

[0054] In some embodiments, reference Figure 5 , Figure 5 for Figure 4 A specific step flow diagram of step S460 in FIG. 4 is shown in FIG. 4. Step S460 may include the following steps: Step S510, sending the first target attention hidden matrix to the cloud platform, so that the cloud platform reconstructs the first target attention hidden matrix and the second target attention hidden matrix to obtain the attention hidden reconstruction matrix; and inputs the attention hidden reconstruction matrix into the normalization function to obtain the attention hidden normalized matrix; and processes the attention hidden normalized matrix based on the secret sharing algorithm to obtain the first attention hidden normalized matrix and the second attention hidden normalized matrix; wherein the second target attention hidden matrix is ​​obtained by the cloud platform based on the second classification hidden matrix and the second hidden matrix; Specifically, [O4]0 is sent to the cloud platform, and the cloud platform reconstructs [O4]1 and [O4]0 to obtain O4. Among them, [O4]1 is the second target attention hidden matrix, [O4]1=[O4π]1+[α1Zπ]1. The cloud platform inputs O4 into the normalization function to obtain the attention hidden normalized matrix L1π, and processes the attention hidden normalized matrix L1π based on the secret sharing algorithm to obtain the first attention hidden normalized matrix [L1π]0 and the second attention hidden normalized matrix [L1π]1.

[0055] Step S520, receiving a first attention hidden normalization matrix sent by the cloud platform; performing matrix multiplication processing on the first attention hidden normalization matrix, the second hidden parameter set and the third hidden parameter set to obtain a first linear transformation hidden matrix; Specifically, the process of obtaining the first linear transformation hidden matrix is ​​expressed as: ; Among them, [O5π2]0 is the first linear transformation hidden matrix.

[0056] It should be noted that in the second privacy protection reasoning process of the cloud platform, the process of obtaining the second linear transformation hidden matrix is: ; Among them, [O5π2]1 is the second linear transformation hidden matrix.

[0057] Step S530, sending the first linear transformation hidden matrix to the cloud platform, so that the cloud platform reconstructs based on the first linear transformation hidden matrix and the second linear transformation hidden matrix to obtain a linear transformation hidden reconstruction matrix; and inputting the linear transformation hidden reconstruction matrix into the Gaussian error linear function to obtain a Gaussian error hidden matrix; processing the Gaussian error hidden matrix based on the secret sharing algorithm to obtain a first Gaussian error hidden matrix and a second Gaussian error hidden matrix; wherein the second linear transformation hidden matrix is ​​obtained by the cloud platform based on the second attention hidden normalization matrix; Specifically, the cloud platform reconstructs the first linear transformation hidden matrix [O5π2]0 and the second linear transformation hidden matrix [O5π2]1 to obtain the linear transformation hidden reconstruction matrix O5π2. Then O5π2 is input into the Gaussian error linear function, specifically: ; Among them, Gπ2 is the Gaussian error hidden matrix, and GeLU represents the Gaussian error linear function. Then the cloud platform processes Gπ2 based on the secret sharing algorithm to obtain the first Gaussian error hidden matrix [Gπ2]0 and the second Gaussian error hidden matrix [Gπ2]1. Then the cloud platform sends the first Gaussian error hidden matrix [Gπ2]0 to the model developer.

[0058] Step S540, receiving a first Gaussian error hidden matrix sent by the cloud platform; obtaining a first added hidden matrix based on the first Gaussian error hidden matrix and the first attention hidden normalized matrix; Specifically, the first added hidden matrix is ​​expressed as: ; Among them, [O6π2]0 represents the first added hidden matrix.

[0059] It should be noted that in the second privacy protection reasoning process of the cloud platform, the second added hidden matrix is ​​expressed as: ; Among them, [O6π2]1 represents the second added hidden matrix.

[0060] Step S550, sending the first additive hidden matrix to the cloud platform, so that the cloud platform reconstructs based on the first additive hidden matrix and the second additive hidden matrix to obtain an additive reconstructed matrix; and inputs the additive reconstructed matrix into a normalization function to obtain an additive hidden normalized matrix; and processes the additive hidden normalized matrix based on a secret sharing algorithm to obtain a first additive hidden normalized matrix and a second additive hidden normalized matrix; wherein the second additive hidden matrix is ​​obtained by the cloud platform based on the second Gaussian error hidden matrix; Specifically, the cloud platform reconstructs O6π2 based on [O6π2]0 and [O6π2]1, then inputs O6π2 into the normalization function to obtain the additive hidden normalized matrix L2π, and processes L2π based on the secret sharing algorithm to obtain the first additive hidden normalized matrix [L2π]0 and the second additive hidden normalized matrix [L2π]1. The cloud platform then sends the first additive hidden normalized matrix [L2π]0 to the model developer.

[0061] Step S560, receiving a first additive hidden normalized matrix sent by the cloud platform; Step S570, performing parameter adaptation processing on the first added hidden normalized matrix to obtain a first inference result.

[0062] The embodiment of the present application realizes the use of the attention mechanism to perform attention processing on the first hidden reasoning data through the above steps S510 to S570, so as to capture information in different subspaces and improve the expressiveness of the model. Similarly, in the second privacy protection reasoning process of the cloud platform, the attention mechanism is used to perform attention processing on the second hidden reasoning data to capture information in different subspaces and improve the expressiveness of the model. Moreover, in steps S510 to S570, the cloud platform cannot obtain specific model parameters or specific original reasoning data; the model developer side cannot obtain specific original reasoning data, thereby reducing the risk of privacy leakage.

[0063] In some embodiments, reference Figure 6 , Figure 6 for Figure 5 A specific flow chart of step S570 in FIG. 5 is shown in FIG. 5. Step S570 includes but is not limited to the following steps: Step S610, performing matrix permutation processing on the first permutation matrix and the linear parameter set of the parameter adaptation layer of the model to obtain a fourth hidden parameter set; performing matrix permutation processing on the second permutation matrix and the nonlinear parameter set of the parameter adaptation layer of the model to obtain a fifth hidden parameter set; It should be noted that the parameter adaptation layer (Adaptation Layer): In some cases, in order to adapt to different tasks or data sets, one or more parameter adaptation layers may be added to the Transformer model. These layers usually contain linear layers and non-linear layers, which are used to adjust the output of the model to better match the requirements of specific tasks, combining linear transformations and non-linear activation functions to achieve more complex feature mapping and data conversion.

[0064] Specifically, the linear parameter set of the parameter adaptation layer of the model is Wp, the nonlinear parameter set of the parameter adaptation layer of the model is Wc, the fourth hidden parameter set is Wpπ, and the fifth hidden parameter set is Wcπ.

[0065] Step S620, performing matrix multiplication processing on the first added hidden normalized matrix and the fourth hidden parameter set to obtain a first adapted hidden matrix; Specifically, the first additive hidden normalized matrix [L2π]0 is multiplied by the fourth hidden parameter set Wpπ using MatMul multiplication to obtain a first adapted hidden matrix [Sπ]0.

[0066] It should be noted that in the second privacy protection inference process of the cloud platform, the MatMul multiplication is used to multiply the second additive hidden normalized matrix [L2π]1 with the fourth hidden parameter set Wpπ to obtain the second adapted hidden matrix [Sπ]1.

[0067] Step S630, sending the first adaptive hidden matrix, the fourth hidden parameter set and the fifth hidden parameter set to the cloud platform, so that the cloud platform reconstructs based on the first adaptive hidden matrix and the second adaptive hidden matrix to obtain an adaptive hidden reconstruction matrix, and inputs the adaptive hidden reconstruction matrix into a hyperbolic tangent function to obtain a hyperbolic hidden matrix; and processing the hyperbolic hidden matrix based on a secret sharing algorithm to obtain a first hyperbolic hidden matrix and a second hyperbolic hidden matrix; wherein the second adaptive hidden matrix is ​​obtained by the cloud platform based on the fourth hidden parameter set and the second additive hidden normalized matrix; Specifically, the cloud platform reconstructs the first adaptation hidden matrix [Sπ]0 and the second adaptation hidden matrix [Sπ]1 to obtain the adaptation hidden reconstruction matrix Sπ. Then the adaptation hidden reconstruction matrix Sπ is input into the hyperbolic tangent function, specifically: ; Where Tπ is the hyperbolic hidden matrix and Tanh is the hyperbolic tangent function. The cloud platform then processes the hyperbolic hidden matrix Tπ based on the secret sharing algorithm to obtain the first hyperbolic hidden matrix [Tπ]0 and the second hyperbolic hidden matrix [Tπ]1, and sends the first hyperbolic hidden matrix [Tπ]0 to the model developer.

[0068] Step S640, receiving a first hyperbolic hidden matrix sent by the cloud platform, and obtaining a first inference result based on the first hyperbolic hidden matrix and a fifth hidden parameter set.

[0069] Specifically, the model developer uses ScalMul multiplication to multiply the first hyperbolic hidden matrix [Tπ]0 with the fifth hidden parameter set Wcπ to obtain the first inference result [Yπ]0. In the second privacy-preserving inference process on the cloud platform, ScalMul multiplication is used to multiply the second hyperbolic hidden matrix [Tπ]1 with the fifth hidden parameter set Wcπ to obtain the second inference result [Yπ]1.

[0070] Through the above steps S610 to S640, the present application realizes obtaining a first reasoning result based on a first added hidden normalized matrix, and at the same time, the cloud platform obtains a second reasoning result based on a second added hidden normalized matrix. After the model developer sends the first reasoning result [Yπ]0 to the user end, and the cloud platform sends the second reasoning result [Yπ]1 to the user end, the user end can reconstruct and restore the reasoning result based on [Yπ]0 and [Yπ]1 to obtain Yπ, and then replace Yπ based on π to obtain the target reasoning result Y. In this way, the target reasoning result is obtained based on the original reasoning data of the user end, and the leakage of the original reasoning data of the user end and the model parameters of the model developer end can be avoided during the reasoning process.

[0071] The second aspect of the present application provides a security reasoning method for a model applied to a cloud platform. Figure 7 , Figure 7 This is a security reasoning method for a model applied to a cloud platform in an embodiment of the present application. Figure 7 The schematic method includes the following steps: Step S710, receiving a first hidden parameter set, a second hidden parameter set and a third hidden parameter set sent by the model developer end; wherein the first hidden parameter set is obtained by the model developer end based on the attention mechanism parameter set of the linear layer of the model and a randomly generated first permutation matrix; the second hidden parameter set is obtained by the model developer end based on the embedding layer parameter set of the model and a randomly generated second permutation matrix; the third hidden parameter set is obtained by the model developer end based on the linear layer parameter set of the previous history neural network of the model and a randomly generated third permutation matrix; Step S720, receiving second hidden inference data sent by the user terminal; Step S730, randomly generating a first permutation matrix based on a preset input sequence length; randomly generating a second permutation matrix based on the dimension of the model; and randomly generating a third permutation matrix based on the dimension of the linear layer of the feedforward neural network of the model; Step S740, performing matrix permutation processing on the first permutation matrix and the attention mechanism parameter set of the linear layer of the model to obtain a first hidden parameter set; performing matrix permutation processing on the first permutation matrix and the embedding layer parameter set of the model to obtain a second hidden parameter set; performing matrix permutation processing on the first permutation matrix, the second permutation matrix, the third permutation matrix and the linear layer parameter set in the feedforward neural network to obtain a third hidden parameter set; Step S750, receiving first hidden reasoning data sent by the user terminal, performing second privacy protection reasoning based on the first hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set, and obtaining a second reasoning result; Step S760, sending the second inference result to the user end, so that the user end performs recovery and reconstruction based on the first permutation matrix, the first inference result and the second inference result to obtain the target inference result; wherein the first inference result is obtained by the model developer end by performing the first privacy protection inference based on the first hidden inference data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set.

[0072] The secure reasoning method for the model applied to the cloud platform in the embodiment of the present application realizes the privacy protection reasoning process through steps S710 to S760. In this process, the user end processes the original reasoning data based on the secret sharing algorithm to obtain the first hidden reasoning data and the second hidden reasoning data; the model developer end performs the first privacy protection reasoning based on the first hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to obtain the first reasoning result. In the process of performing the first privacy protection reasoning, since the model developer end cannot obtain the second hidden reasoning data; therefore, the model developer end cannot obtain the original reasoning data based on the first hidden reasoning data, so the model developer end cannot obtain the privacy of the user end. The cloud platform performs the second privacy protection reasoning based on the second hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to obtain the second reasoning result; the cloud platform cannot obtain the parameter set of the model based on each hidden parameter set, so the cloud platform cannot obtain the privacy of the model developer end; the cloud platform cannot obtain the original reasoning data based on the second hidden reasoning, so the cloud platform cannot obtain the privacy of the user end; the user end performs recovery and reconstruction processing based on the first permutation matrix, the first reasoning result and the second reasoning result to obtain the target reasoning result. The user side cannot obtain the parameter set of the model, so the user side cannot obtain the privacy of the model developer side. In this way, the present application can protect the privacy of model parameters and reasoning data and reduce the risk of privacy leakage. And compared with the traditional secure reasoning method, the present application does not need to convert the original reasoning data and the parameter set of the model into ciphertext, but performs matrix multiplication on the parameter set of the model and the randomly generated permutation matrix, and performs secret sharing on the original reasoning data, which saves the computational and communication overhead caused by the ciphertext calculation. Therefore, the secure reasoning method of the present application has faster processing speed and lower communication overhead.

[0073] The third aspect of the present application provides an embodiment of a Figure 1 The safety reasoning method of the model of the safety reasoning system. Figure 8 , Figure 8 The application of the embodiment of the present application is Figure 1 Flow chart of the security reasoning method of the model of the security reasoning system. Figure 8 Illustrated methods include: Step S810, the model developer randomly generates a first permutation matrix based on a preset input sequence length; randomly generates a second permutation matrix based on the dimension of the model; and randomly generates a third permutation matrix based on the dimension of the linear layer of the feedforward neural network of the model; Step S820: the model developer performs matrix permutation processing on the first permutation matrix and the attention mechanism parameter set of the linear layer of the model to obtain a first hidden parameter set; performs matrix permutation processing on the first permutation matrix and the embedding layer parameter set of the model to obtain a second hidden parameter set; performs matrix permutation processing on the first permutation matrix, the second permutation matrix, the third permutation matrix and the linear layer parameter set in the feedforward neural network to obtain a third hidden parameter set; Step S830, the model developer sends the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to the cloud platform; Step S840: The user end processes the original reasoning data based on the secret sharing algorithm to obtain first hidden reasoning data and second hidden reasoning data, and sends the first hidden reasoning data to the model developer end, and sends the second hidden reasoning data to the cloud platform; Step S850: the model developer performs a first privacy protection reasoning based on the first hidden reasoning data, the first hidden parameter set, the second hidden parameter set, and the third hidden parameter set to obtain a first reasoning result; and sends the first reasoning result to the user end; Step S860: the cloud platform performs a second privacy protection reasoning based on the second hidden reasoning data, the first hidden parameter set, the second hidden parameter set, and the third hidden parameter set to obtain a second reasoning result; and sends the second reasoning result to the user terminal; Step S870: The user terminal performs restoration and reconstruction processing based on the first permutation matrix, the first reasoning result, and the second reasoning result to obtain a target reasoning result.

[0074] The secure reasoning method for the model of the secure reasoning system of the embodiment of the present application implements the privacy protection reasoning process through steps S810 to S870. In this process, the user end processes the original reasoning data based on the secret sharing algorithm to obtain the first hidden reasoning data and the second hidden reasoning data; the model developer end performs the first privacy protection reasoning based on the first hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to obtain the first reasoning result. In the process of performing the first privacy protection reasoning, since the model developer end cannot obtain the second hidden reasoning data; therefore, the model developer end cannot obtain the original reasoning data based on the first hidden reasoning data, so the model developer end cannot obtain the privacy of the user end. The cloud platform performs the second privacy protection reasoning based on the second hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to obtain the second reasoning result; the cloud platform cannot obtain the parameter set of the model based on each hidden parameter set, so the cloud platform cannot obtain the privacy of the model developer end; the cloud platform cannot obtain the original reasoning data based on the second hidden reasoning, so the cloud platform cannot obtain the privacy of the user end; the user end performs recovery and reconstruction processing based on the first permutation matrix, the first reasoning result and the second reasoning result to obtain the target reasoning result. The user side cannot obtain the parameter set of the model, so the user side cannot obtain the privacy of the model developer side. In this way, the present application can protect the privacy of model parameters and reasoning data and reduce the risk of privacy leakage. And compared with the traditional secure reasoning method, the present application does not need to convert the original reasoning data and the parameter set of the model into ciphertext, but performs matrix multiplication on the parameter set of the model and the randomly generated permutation matrix, and performs secret sharing on the original reasoning data, which saves the computational and communication overhead caused by the ciphertext calculation. Therefore, the secure reasoning method of the present application has faster processing speed and lower communication overhead.

[0075] Table 1

[0076] Refer to Table 1, which is a comparison of the privacy protection reasoning time of models with different Transformer architectures using the secure reasoning method of the model of this application and other models in the related art. Models with different Transformer architectures include the BERT series models, whose encoder structure is mainly used for natural language understanding (NLU) tasks, and the GPT-2 series models, whose decoder structure is mainly used for natural language generation (NLG). The BERT series models include BERT BASE Model, BERT LARGE Model. The GPT-2 series models include GPT-2 BASE Model, GPT-2 LARGE Model.

[0077] Referring to Table 1, other secure reasoning methods for models in related technologies include PUMA, MPCFormer, and SecFormer. PUMA implements privacy-preserving reasoning through multi-party secure computation (MPC) technology. It adopts a 2-out-of-3Replicated Secret Sharing scheme, similar to the ABY3 protocol, and can quickly and securely perform Transformer model reasoning in three-party scenarios. MPCFormer is a framework that combines secure multi-party computation (MPC) and knowledge distillation (KD) to achieve fast, efficient, and private Transformer model reasoning. SecFormer is a framework for privacy-preserving reasoning that aims to provide fast, efficient, and accurate reasoning services for Transformer models. SecFormer improves the reasoning performance of the Transformer model in privacy-preserving scenarios by combining secure multi-party computation (SMPC) and optimized numerical calculation methods.

[0078] In Table 1, the Embedding layer is the embedding layer, and the Adaptation layer is the parameter adaptation layer. The data in Table 1 is in seconds. The data in Table 1 is obtained by conducting experiments on two servers equipped with A100 graphics cards, and the server bandwidth is set to 3Gbps, and the round-trip delay is 0.8 milliseconds.

[0079] As can be seen from Table 1, for the BERT series models, the speed of executing PPTI using the secure reasoning method of the model proposed in this application is 5.1-30.3 times faster than the existing method. For the GPT-2 series models, the speed of executing PPTI using the secure reasoning method of the model proposed in this application is 5.0-27.2 times faster than the existing method.

[0080] The fourth aspect of the present application provides a model security reasoning device, which is applied to the model developer side. Fig. 9 , Fig. 9 This is a functional module diagram of a safety reasoning device for a model according to an embodiment of the present application. The device includes: The generation module 910 is configured to randomly generate a first permutation matrix based on a preset input sequence length; randomly generate a second permutation matrix based on the dimension of the model; and randomly generate a third permutation matrix based on the dimension of the linear layer of the feedforward neural network of the model; The parameter processing module 920 is configured to perform matrix permutation processing on the first permutation matrix and the attention mechanism parameter set of the linear layer of the model to obtain a first hidden parameter set; perform matrix permutation processing on the first permutation matrix and the embedding layer parameter set of the model to obtain a second hidden parameter set; perform matrix permutation processing on the second permutation matrix, the third permutation matrix and the linear layer parameter set in the feedforward neural network to obtain a third hidden parameter set; The reasoning module 930 is configured to receive the first hidden reasoning data sent by the user terminal, perform the first privacy protection reasoning based on the first hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set, and obtain a first reasoning result; The first sending module 940 is configured to send the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to the cloud platform, so that the cloud platform performs a second privacy protection reasoning based on the second hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set, obtains a second reasoning result, and sends the second reasoning result to the user end; wherein the first hidden reasoning data and the second hidden reasoning data are obtained by the user end by processing the original reasoning data based on the secret sharing algorithm; The second sending module 950 is configured to send the first permutation matrix and the first reasoning result to the user end, so that the user end performs recovery and reconstruction processing based on the first permutation matrix, the first reasoning result and the second reasoning result to obtain a target reasoning result.

[0081] The secure reasoning device of the model of the embodiment of the present application is used to execute the secure reasoning method of the model of the embodiment of the first aspect of the present application. When executing the method, the user end processes the original reasoning data based on the secret sharing algorithm to obtain the first hidden reasoning data and the second hidden reasoning data; the model developer end performs the first privacy protection reasoning based on the first hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to obtain the first reasoning result. In the process of performing the first privacy protection reasoning, since the model developer end cannot obtain the second hidden reasoning data; therefore, the model developer end cannot obtain the original reasoning data based on the first hidden reasoning data, so the model developer end cannot obtain the privacy of the user end. The cloud platform performs the second privacy protection reasoning based on the second hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to obtain the second reasoning result; the cloud platform cannot obtain the parameter set of the model based on each hidden parameter set, so the cloud platform cannot obtain the privacy of the model developer end; the cloud platform cannot obtain the original reasoning data based on the second hidden reasoning, so the cloud platform cannot obtain the privacy of the user end; the user end performs recovery and reconstruction processing based on the first permutation matrix, the first reasoning result and the second reasoning result to obtain the target reasoning result. The user side cannot obtain the parameter set of the model, so the user side cannot obtain the privacy of the model developer side. In this way, the present application can protect the privacy of model parameters and reasoning data and reduce the risk of privacy leakage. And compared with the traditional secure reasoning method, the present application does not need to convert the original reasoning data and the parameter set of the model into ciphertext, but performs matrix multiplication on the parameter set of the model and the randomly generated permutation matrix, and performs secret sharing on the original reasoning data, which saves the computational and communication overhead caused by the ciphertext calculation. Therefore, the secure reasoning method of the present application has faster processing speed and lower communication overhead.

[0082] It should be noted that the specific implementation method of the security reasoning device of the model is basically the same as the specific implementation method of the privacy protection method of the model in the first aspect embodiment, and will not be repeated here. On the premise of meeting the requirements of the embodiments of this application, the security reasoning device of the model can also set other functional modules to implement the privacy protection method of the model in the first aspect embodiment.

[0083] The fifth aspect of the present application provides an electronic device, the electronic device includes a memory and a processor, the memory stores a computer program, and the processor implements the safety reasoning method of the model in the above embodiment when executing the computer program. The electronic device can be any smart terminal including a tablet computer, a car computer, etc.

[0084] In one embodiment, referring to Fig.10 , Fig.10 The hardware structure of the electronic device of the embodiment of the present application is illustrated, and the electronic device includes: The processor 101 may be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (Application Specific Integrated Circuit, ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application; The memory 102 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 102 can store an operating system and other applications. When the technical solution provided in the embodiment of this specification is implemented by software or firmware, the relevant program code is stored in the memory 102, and the processor 101 calls and executes the security reasoning method of the model in the embodiment of this application; Input / output interface 103, used to implement information input and output; The communication interface 104 is used to realize the communication interaction between the device and other devices. The communication can be realized through a wired manner (such as USB, network cable, etc.) or a wireless manner (such as mobile network, WIFI, Bluetooth, etc.); A bus 105 , which transmits information between various components of the device (e.g., the processor 101 , the memory 102 , the input / output interface 103 , and the communication interface 104 ); The processor 101 , the memory 102 , the input / output interface 103 and the communication interface 104 are connected to each other in communication within the device via the bus 105 .

[0085] To achieve the above-mentioned purpose, the fourth aspect of the present application provides a computer-readable storage medium, wherein the storage medium stores a computer program, and when the computer program is executed by a processor, the security reasoning method of the model of the first aspect of the present application is implemented.

[0086] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely disposed relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0087] The embodiments described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0088] Those skilled in the art will appreciate that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or a combination of certain steps, or different steps.

[0089] The device embodiments described above are merely illustrative, and the units described as separate components may or may not be physically separated, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0090] Those skilled in the art will appreciate that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices may be implemented as software, firmware, hardware, or a suitable combination thereof.

[0091] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0092] It should be understood that in the present application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the objects associated before and after are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0093] In the several embodiments provided in the present application, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are merely schematic. For example, the division of the above units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0094] The units described above as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0095] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0096] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including multiple instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (Read-Only Memory, referred to as ROM), random access memory (Random Access Memory, referred to as RAM), disk or optical disk and other media that can store programs.

[0097] The preferred embodiments of the present invention are described above with reference to the accompanying drawings, but the scope of the rights of the present invention is not limited thereto. Any modification, equivalent substitution and improvement made by a person skilled in the art without departing from the scope and essence of the present invention should be within the scope of the rights of the present invention.

Claims

1. A secure reasoning method for a model, characterized in that: Applied to a model developer end, the model developer end being provided with the model; The method comprises: randomly generating a first permutation matrix based on a preset input sequence length, randomly generating a second permutation matrix based on the dimension of the model, and randomly generating a third permutation matrix based on the dimension of a linear layer of a feedforward neural network of the model; Performing matrix permutation processing on the first permutation matrix and the attention mechanism parameter set of the linear layer of the model to obtain a first hidden parameter set, performing matrix permutation processing on the first permutation matrix and the embedding layer parameter set of the model to obtain a second hidden parameter set, and performing matrix permutation processing on the first permutation matrix, the second permutation matrix, the third permutation matrix, and the linear layer parameter set in the feedforward neural network to obtain a third hidden parameter set; receiving first hidden reasoning data sent by a user terminal, performing first privacy protection reasoning based on the first hidden reasoning data, the first hidden parameter set, the second hidden parameter set, and the third hidden parameter set to obtain a first reasoning result; Sending the first hidden parameter set, the second hidden parameter set, and the third hidden parameter set to the cloud platform, so that the cloud platform performs a second privacy protection reasoning based on the second hidden reasoning data, the first hidden parameter set, the second hidden parameter set, and the third hidden parameter set to obtain a second reasoning result, and sending the second reasoning result to the user end; the first hidden reasoning data and the second hidden reasoning data are obtained by the user end processing the original reasoning data based on a secret sharing algorithm; The first permutation matrix and the first inference result are sent to the user terminal, so that the user terminal performs recovery and reconstruction processing based on the first permutation matrix, the first inference result and the second inference result to obtain a target inference result.

2. The security reasoning method of the model according to claim 1, characterized in that: The performing a first privacy protection reasoning based on the first hidden reasoning data, the first hidden parameter set, the second hidden parameter set, and the third hidden parameter set to obtain a first reasoning result includes: Performing matrix multiplication processing on the second hidden parameter set and the first hidden inference data to obtain a first intermediate matrix; Sending the first intermediate matrix to the cloud platform so that the cloud platform performs reconstruction processing based on the first intermediate matrix and the second intermediate matrix to obtain a first reconstructed matrix, and inputting the first reconstructed matrix into a normalization function to obtain a normalized matrix, and processing the normalized matrix based on a secret sharing algorithm to obtain a first normalized matrix and a second normalized matrix; wherein the second intermediate matrix is ​​obtained by the cloud platform based on the second hidden inference data and the second hidden parameter set; Receiving the first normalized matrix sent by the cloud platform and the first hidden matrix sent by the user terminal; performing matrix multiplication processing on the first normalized matrix and the first hidden matrix to obtain a first normalized hidden matrix; wherein the first hidden matrix is ​​obtained by the user terminal processing a randomly generated fourth permutation matrix based on a secret sharing algorithm; The first inference result is obtained based on the first normalized hidden matrix, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set.

3. The security reasoning method of the model according to claim 2, characterized in that: The obtaining the first inference result based on the first normalized hidden matrix, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set includes: Performing matrix multiplication processing on the first hidden parameter set and the first normalized hidden matrix to obtain a first query representation matrix, a first key representation matrix, and a first value representation matrix; Performing matrix multiplication processing on the first value representation matrix and the first hidden matrix to obtain a first attention hidden matrix; Obtaining a first intermediate attention matrix based on the first query representation matrix and the first key representation matrix; performing matrix multiplication processing on the first intermediate attention matrix and the first hidden matrix to obtain a second attention hidden matrix; Sending the second attention hidden matrix to the cloud platform so that the cloud platform reconstructs the second attention hidden matrix and the third attention hidden matrix to obtain an attention reconstruction hidden matrix, and inputting the attention reconstruction hidden matrix into a classification function to obtain a classification hidden matrix, and processing the classification hidden matrix based on a secret sharing algorithm to obtain a first classification hidden matrix and a second classification hidden matrix; wherein the third attention hidden matrix is ​​obtained by the cloud platform based on the second normalized matrix and the second hidden matrix, and the second hidden matrix is ​​obtained by the user end by processing the fourth permutation matrix based on a secret sharing algorithm; Receiving a first classification hidden matrix sent by the cloud platform, and obtaining a first target attention hidden matrix based on the first classification hidden matrix, the first attention hidden matrix, and the first normalized hidden matrix; The first inference result is obtained based on the first target attention hidden matrix, the second hidden parameter set and the third hidden parameter set.

4. The safety reasoning method of the model according to claim 3, characterized in that: The obtaining the first inference result based on the first target attention hidden matrix, the second hidden parameter set and the third hidden parameter set includes: Sending the first target attention hidden matrix to the cloud platform, so that the cloud platform reconstructs the first target attention hidden matrix and the second target attention hidden matrix to obtain an attention hidden reconstruction matrix; and inputting the attention hidden reconstruction matrix into a normalization function to obtain an attention hidden normalized matrix; and processing the attention hidden normalized matrix based on a secret sharing algorithm to obtain a first attention hidden normalized matrix and a second attention hidden normalized matrix; wherein the second target attention hidden matrix is ​​obtained by the cloud platform based on the second classification hidden matrix and the second hidden matrix; Receiving the first attention hidden normalization matrix sent by the cloud platform; performing matrix multiplication processing on the first attention hidden normalization matrix, the second hidden parameter set and the third hidden parameter set to obtain a first linear transformation hidden matrix; The first linear transformation hidden matrix is ​​sent to the cloud platform, so that the cloud platform reconstructs the first linear transformation hidden matrix and the second linear transformation hidden matrix to obtain a linear transformation hidden reconstruction matrix; and the linear transformation hidden reconstruction matrix is ​​input into a Gaussian error linear function to obtain a Gaussian error hidden matrix; the Gaussian error hidden matrix is ​​processed based on a secret sharing algorithm to obtain a first Gaussian error hidden matrix and a second Gaussian error hidden matrix; wherein the second linear transformation hidden matrix is ​​obtained by the cloud platform based on the second attention hidden normalization matrix; Receiving the first Gaussian error hidden matrix sent by the cloud platform; obtaining a first added hidden matrix based on the first Gaussian error hidden matrix and the first attention hidden normalization matrix; Sending the first additive hidden matrix to the cloud platform so that the cloud platform reconstructs the first additive hidden matrix and the second additive hidden matrix to obtain an additive reconstruction matrix; and inputting the additive reconstruction matrix into a normalization function to obtain an additive hidden normalized matrix; and processing the additive hidden normalized matrix based on a secret sharing algorithm to obtain a first additive hidden normalized matrix and a second additive hidden normalized matrix; wherein the second additive hidden matrix is ​​obtained by the cloud platform based on the second Gaussian error hidden matrix; Receiving the first additive hidden normalized matrix sent by the cloud platform; Perform parameter adaptation processing on the first added hidden normalized matrix to obtain the first inference result.

5. The security reasoning method of the model according to claim 4 is characterized in that: The performing parameter adaptation processing on the first added hidden normalized matrix to obtain the first inference result includes: Performing matrix permutation processing on the first permutation matrix and the linear parameter set of the parameter adaptation layer of the model to obtain a fourth hidden parameter set; performing matrix permutation processing on the second permutation matrix and the nonlinear parameter set of the parameter adaptation layer of the model to obtain a fifth hidden parameter set; Performing matrix multiplication processing on the first added hidden normalized matrix and the fourth hidden parameter set to obtain a first adapted hidden matrix; Sending the first adaptive hidden matrix, the fourth hidden parameter set and the fifth hidden parameter set to the cloud platform, so that the cloud platform reconstructs based on the first adaptive hidden matrix and the second adaptive hidden matrix to obtain an adaptive hidden reconstruction matrix, and inputs the adaptive hidden reconstruction matrix into a hyperbolic tangent function to obtain a hyperbolic hidden matrix; and processing the hyperbolic hidden matrix based on a secret sharing algorithm to obtain a first hyperbolic hidden matrix and a second hyperbolic hidden matrix; wherein the second adaptive hidden matrix is ​​obtained by the cloud platform based on the fourth hidden parameter set and the second additive hidden normalized matrix; The first hyperbolic hidden matrix sent by the cloud platform is received, and the first inference result is obtained based on the first hyperbolic hidden matrix and the fifth hidden parameter set.

6. A secure reasoning method for a model, characterized in that: Applied to a cloud platform, the method includes: Receive a first hidden parameter set, a second hidden parameter set, and a third hidden parameter set sent by a model developer; wherein the first hidden parameter set is obtained by the model developer based on the attention mechanism parameter set of the linear layer of the model and a randomly generated first permutation matrix; the second hidden parameter set is obtained by the model developer based on the embedding layer parameter set of the model and a randomly generated second permutation matrix; the third hidden parameter set is obtained by the model developer based on the linear layer parameter set of the model's pre-coronavirus neural network and a randomly generated third permutation matrix; receiving second hidden inference data sent by a user terminal; A first permutation matrix is ​​randomly generated based on a preset input sequence length; a second permutation matrix is ​​randomly generated based on the dimension of the model; and a third permutation matrix is ​​randomly generated based on the dimension of a linear layer of a feedforward neural network of the model; Performing matrix permutation processing on the first permutation matrix and the attention mechanism parameter set of the linear layer of the model to obtain a first hidden parameter set; performing matrix permutation processing on the first permutation matrix and the embedding layer parameter set of the model to obtain a second hidden parameter set; performing matrix permutation processing on the first permutation matrix, the second permutation matrix, the third permutation matrix and the linear layer parameter set in the feedforward neural network to obtain a third hidden parameter set; receiving first hidden reasoning data sent by the user terminal, performing second privacy protection reasoning based on the first hidden reasoning data, the first hidden parameter set, the second hidden parameter set, and the third hidden parameter set to obtain a second reasoning result; The second reasoning result is sent to the user end, so that the user end performs recovery and reconstruction processing based on the first permutation matrix, the first reasoning result and the second reasoning result to obtain a target reasoning result; wherein the first reasoning result is obtained by the model developer end performing a first privacy protection reasoning based on the first hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set.

7. A secure reasoning method for a model, characterized in that: Applied to a security reasoning system, the security reasoning system includes a model developer end, a user end and a cloud platform; The method comprises: The model developer randomly generates a first permutation matrix based on a preset input sequence length; randomly generates a second permutation matrix based on the dimension of the model; and randomly generates a third permutation matrix based on the dimension of the linear layer of the feedforward neural network of the model; The model developer performs matrix permutation processing on the first permutation matrix and the attention mechanism parameter set of the linear layer of the model to obtain a first hidden parameter set; performs matrix permutation processing on the first permutation matrix and the embedding layer parameter set of the model to obtain a second hidden parameter set; performs matrix permutation processing on the first permutation matrix, the second permutation matrix, the third permutation matrix and the linear layer parameter set in the feedforward neural network to obtain a third hidden parameter set; The model developer terminal sends the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to the cloud platform; The user end processes the original reasoning data based on the secret sharing algorithm to obtain first hidden reasoning data and second hidden reasoning data, and sends the first hidden reasoning data to the model developer end, and sends the second hidden reasoning data to the cloud platform; The model developer end performs a first privacy protection reasoning based on the first hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to obtain a first reasoning result; and sends the first reasoning result to the user end; The cloud platform performs a second privacy protection reasoning based on the second hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to obtain a second reasoning result; and sends the second reasoning result to the user end; The user end performs recovery and reconstruction processing based on the first permutation matrix, the first reasoning result, and the second reasoning result to obtain a target reasoning result.

8. A safety reasoning device for a model, characterized in that: Applied to a model developer end, the model developer end being provided with the model; The device comprises: A generation module is configured to randomly generate a first permutation matrix based on a preset input sequence length; randomly generate a second permutation matrix based on the dimension of the model; and randomly generate a third permutation matrix based on the dimension of a linear layer of a feedforward neural network of the model; A parameter processing module is configured to perform matrix permutation processing on the first permutation matrix and the attention mechanism parameter set of the linear layer of the model to obtain a first hidden parameter set; perform matrix permutation processing on the first permutation matrix and the embedding layer parameter set of the model to obtain a second hidden parameter set; perform matrix permutation processing on the second permutation matrix, the third permutation matrix and the linear layer parameter set in the feedforward neural network to obtain a third hidden parameter set; an inference module, configured to receive first hidden inference data sent by the user terminal, perform first privacy protection inference based on the first hidden inference data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set, and obtain a first inference result; A first sending module is configured to send the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to the cloud platform, so that the cloud platform performs a second privacy protection reasoning based on the second hidden reasoning data, the first hidden parameter set, the second hidden parameter set and the third hidden parameter set to obtain a second reasoning result, and sends the second reasoning result to the user end; wherein the first hidden reasoning data and the second hidden reasoning data are obtained by the user end by processing the original reasoning data based on a secret sharing algorithm; The second sending module is configured to send the first permutation matrix and the first reasoning result to the user terminal, so that the user terminal performs recovery and reconstruction processing based on the first permutation matrix, the first reasoning result and the second reasoning result to obtain a target reasoning result.

9. An electronic device, characterized in that: The electronic device includes a memory and a processor, the memory stores a computer program, and the processor implements the safety reasoning method of the model described in any one of claims 1 to 7 when executing the computer program.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the safety reasoning method of the model described in any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Privacy reasoning method and system based on Transform network model, medium and electronic equipment

    CN117077162A

  • Privacy reasoning method, first node and second terminal

    CN119416892A

Cited By

  • Data security processing method and computing node

    CN120710779A