Linear regression method based on privacy protection
By adopting the encryption method and regularized symmetric matrix transformation form determined by each participant in vertical federated learning, the problem of high complexity in linear regression implementation in the prior art is solved, and a simple and efficient linear regression method for privacy protection is realized.
Patent Information
- Application Number
- CN202510047061.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-13
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-01-13
AI Technical Summary
When implementing linear regression in vertical federated learning, the prior art requires the introduction of complex obfuscating circuits and encryption service providers, resulting in high implementation complexity and increased difficulty.
A linear regression method based on privacy protection is proposed. Each participant determines the initial encryption method by itself, avoiding the use of complex obfuscated circuits, and using the transformation form of regularized symmetric matrix and product matrix for encryption processing, realizing a simple and efficient linear regression process.
It reduces the complexity of the linear regression process, meets the actual application needs, saves data transmission overhead, and improves the encryption effect.
Smart Images

Figure CN120012038A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to but is not limited to the field of machine learning technology, and in particular to a linear regression method based on privacy protection. Background Art
[0002] Multiple regression analysis refers to a statistical analysis method that considers one variable as the dependent variable and one or more other variables as independent variables, establishes a linear or nonlinear mathematical model quantitative relationship between multiple variables, and uses sample data for analysis. Linear regression is a statistical analysis method that uses regression analysis in mathematical statistics to determine the interdependence between variables. As the simplest machine learning model, it has a wide range of uses in finance, economics, and medicine. Linear regression can be used to fit a prediction model to the values of an observed data set.
[0003] Vertical Federated Learning (VFL) is a distributed machine learning technology that allows multiple participants to jointly train on their own data to build a shared machine learning model. This learning method is suitable for scenarios where there is a lot of sample overlap and little feature overlap. For example, supermarkets and banks in the same area have similar users (samples) but different businesses (features). The key to vertical federated learning is that samples must overlap and features must be complementary, so that the features of each sample can be expanded, so that the effect of the joint training model is generally better than the effect of training using each private feature.
[0004] Related methods for implementing vertical federated learning often require the introduction of encryption service providers and evaluators to ensure the execution and effectiveness of encryption. Some linear regression methods with encryption requirements require the introduction of complex obfuscation circuits, making the implementation of linear regression difficult. Summary of the invention
[0005] The following is a summary of the subject matter described in detail herein. This summary is not intended to limit the scope of the claims.
[0006] The embodiment of the present application provides a linear regression method based on privacy protection, which is simpler to implement and encryption does not require the use of complex obfuscation circuits and other technologies.
[0007] To achieve the above-mentioned purpose, the first aspect of an embodiment of the present application proposes a linear regression method based on privacy protection, including: for any i-th participant, the i-th participant determines the regularized symmetric matrix of the column encrypted data transformation encryption matrix corresponding to its own original data matrix or other transformation forms of the regularized symmetric matrix, and sends the regularized symmetric matrix or its transformation form to the first computing node, wherein the transformation form of the regularized symmetric matrix satisfies, and the regularized symmetric matrix can be obtained by the transformation form without calculating other information; the j-th participant cooperates with the i-th participant to determine the product matrix or or a transformed form of the product matrix, and the first computing node saves the product matrix or the transformed form of the product matrix; wherein the transformed form of the product matrix satisfies, and the product matrix can be obtained by the transformed form without calculating other information; i and j are both integers greater than or equal to 1 and less than or equal to m, j is not equal to i and j is less than i, and m is the total number of all the participants; the first computing node uses the regularized symmetric matrix or its transformed form of the column encrypted data transformation encryption matrix of each of the participants, as well as the product matrix or its transformed form between the j-th participant and the ith participant, and collaborates with each of the participants and the label data owner to determine the multiplied encrypted linear regression coefficient vector.
[0008] In some embodiments, the product matrix of the column encrypted data transformation encryption matrices of the jth participant and the i-th participant is equal to the product of the transpose of the column encrypted data transformation encryption matrix of the jth participant and the column encrypted data transformation encryption matrix of the i-th participant, and the transformation form of the product matrix includes the transpose of the product matrix, that is, the product of the transpose of the column encrypted data transformation encryption matrix of the i-th participant and the column encrypted data transformation encryption matrix of the j-th participant, and the product matrix of the column encrypted data transformation encryption matrices of the j-th participant and the i-th participant or its transformation form is determined by the j-th participant and the i-th participant in collaboration based on a preset secure multi-party computing protocol or directly calculated.
[0009] In some embodiments, the column encrypted data transformation encryption matrix corresponding to the original data matrix of the i-th participant is equal to the product of the column encrypted data matrix of the i-th participant and the first mask matrix of the i-th participant; wherein the column encrypted data matrix contains the original data matrix as a sub-matrix, and includes each sub-column in the original data matrix and the mask column generated by the participant or obtained from the trusted node, and the number of items contained in the mask column is the same as the number of items contained in each column of the original data matrix of the participant; and the first mask matrix of the i-th participant is a reversible matrix, which is generated by the i-th participant or obtained from the trusted node.
[0010] In some embodiments, the multiplication of the encrypted linear regression coefficient vector is equal to adding the influence of the mask column of each of the participants to the target linear regression coefficient column vector, and then right-multiplying it by a block diagonal matrix composed of the first mask matrices of each of the participants, wherein the block diagonal matrix uses the inverse matrix of the first mask matrix of each of the participants as a submatrix located on the diagonal of the block diagonal matrix.
[0011] In some embodiments, the first computing node utilizes the regularized symmetric matrix or its transformation form of the column encrypted data transformation encryption matrix of each of the participants, as well as the product matrix or its transformation form between the j-th participant and the ith participant, and collaborates with each of the participants and the label data owner to determine the multiplied encrypted linear regression coefficient vector, including: the label data owner collaborates with any one of the participants, determines the column encrypted data transformation encryption matrix and the label product or its transformation form of each of the participants according to the label column vector of the label data owner and the column encrypted data transformation encryption matrix of the participant, and stores the column encrypted data transformation encryption matrix and the label product or its transformation form of each of the participants in any one or more of the participants, the label data owner, the first computing node and the trusted storage node, wherein the transformation form of the column encrypted data transformation encryption matrix and the label product satisfies, and the column encrypted data transformation encryption matrix and the label product can be calculated by the transformation form; any ith participant regularizes its own symmetric matrix to obtain the ith The regularized symmetric matrix or its transformation form of the column encrypted data transformation encryption matrix of the i-th participant is obtained, and the regularized symmetric matrix or its transformation form is sent to the first computing node, wherein, when the first mask matrix of the ith participant is not an orthogonal matrix, the above-mentioned regularization processing also uses the first mask matrix of the ith participant; any ith participant cooperates with the jth participant, using their respective column encrypted data transformation encryption matrices to determine the product matrix or its transformation form of the column encrypted data transformation encryption matrices of the jth participant and the i-th participant, and the first computing node saves the product matrix or the transformation form of the product matrix; the first computing node uses the regularized symmetric matrix of the column encrypted data transformation encryption matrix of the i-th participant, and the product matrix or its transformation form of the column encrypted data transformation encryption matrix of the j-th participant and the i-th participant, and cooperates with one or more nodes storing the column encrypted data transformation encryption matrix of each participant and the label product or its transformation form to determine the multiplied encrypted linear regression coefficient vector.
[0012] In some embodiments, any ith party performs regularization processing on its own symmetric matrix to obtain a regularized symmetric matrix of the column encrypted data transformation encryption matrix of the ith party, including: the regularized symmetric matrix of the column encrypted data transformation encryption matrix of the ith party is the sum of the symmetric matrix of the column encrypted data transformation encryption matrix of the ith party plus the regularization term, and the regularization term is the product of the symmetric matrix of the first mask matrix of the ith party and the regularization coefficient; wherein, the symmetric matrix of the column encrypted data transformation encryption matrix is equal to the product of the transpose of the column encrypted data transformation encryption matrix and the column encrypted data transformation encryption matrix itself, and the symmetric matrix of the first mask matrix of the ith party is equal to the product of the transpose of the first mask matrix of the ith party and the first mask matrix itself.
[0013] In some embodiments, the arbitrary i-th participant cooperates with the j-th participant to determine the product matrix or its transformation form of the column encrypted data transformation encryption matrix of the j-th participant and the i-th participant using their respective column encrypted data transformation encryption matrices, including: the arbitrary i-th participant cooperates with the j-th participant to determine the product matrix or its transformation form through the column encrypted data transformation encryption matrix of the i-th participant and the column encrypted data transformation encryption matrix of the j-th participant, and the first computing node obtains the A product matrix or a transformed form thereof; wherein the product matrix of the column encrypted data transformation encryption matrix of the ith participant and the column encrypted data transformation encryption matrix of the jth participant is equal to the product of the transpose of the column encrypted data transformation encryption matrix of the jth participant and the column encrypted data transformation encryption matrix of the ith participant, and the transformed form of the product matrix includes the transpose of the product matrix, i.e., the product of the transpose of the column encrypted data transformation encryption matrix of the ith participant and the column encrypted data transformation encryption matrix of the jth participant.
[0014] In some embodiments, the first computing node uses the regularized symmetric matrix of the column encrypted data transformation encryption matrix of the i-th participant, and the product matrix of the column encrypted data transformation encryption matrix of the j-th participant and the i-th participant or its transformation form, and cooperates with one or more nodes storing the product of the column encrypted data transformation encryption matrix of each participant and the label or its transformation form to determine the multiplied encrypted linear regression coefficient vector, including: the multiplied encrypted linear regression coefficient vector is equal to the regularized pair of the column encrypted data transformation encryption matrices of all the participants The inverse matrix of the matrix is the product of the column encrypted data transformation encryption matrix of all the participants and the label product; wherein the sub-matrices contained in the regularized symmetric matrix of the column encrypted data transformation encryption matrix of all the participants include: the regularized symmetric matrix of the column encrypted data transformation encryption matrix of each of the participants, and the product matrix of the column encrypted data transformation encryption matrices of any two different participants; and the column encrypted data transformation encryption matrix of all the participants and the label product are composed of the column encrypted data transformation encryption matrix of each of the participants and the label product.
[0015] In some embodiments, the label data owner cooperates with any one of the participants respectively, determines the product of the column encrypted data transformation encryption matrix and the label or its transformation form of each participant according to the label column vector of the label data owner and the column encrypted data transformation encryption matrix of the participant, and stores the product of the column encrypted data transformation encryption matrix and the label or its transformation form of each participant in any one or more nodes among the participants, the label data owner, the first computing node and the trusted storage node, including: the label data owner cooperates with any i-th participant, determines the product of the column encrypted data transformation encryption matrix and the label or its transformation form of the i-th participant based on a preset secure multi-party computing protocol or based on a direct calculation method, that is, the product of the transpose of the column encrypted data transformation encryption matrix of the i-th participant and the label column vector or its transformation form, and stores the calculated product of the column encrypted data transformation encryption matrix and the label or its transformation form of the i-th participant in multiple participants, the label data owner, the first computing node and one or more nodes among the trusted storage nodes.
[0016] To achieve the above-mentioned purpose, the second aspect of the present application proposes a privacy protection-based linear regression system, which is used to execute the privacy protection-based linear regression method described in the first aspect.
[0017] To achieve the above-mentioned purpose, the third aspect of the present application proposes a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program is running, it controls the device where the computer-readable storage medium is located to execute the privacy protection-based linear regression method as described in the first aspect.
[0018] The embodiments of the present application include at least the following beneficial effects: after each participant encrypts the original data matrix owned by it respectively, the participant determines its own symmetric matrix based on the encrypted matrix transformed by the encrypted column data obtained by itself, and any two different participants determine the product matrix by transforming the encrypted matrix through their respective encrypted column data. The first computing node obtains the symmetric matrix of each participant and the product matrix of any two participants, and then uses the label column vector of the label data owner to calculate the multiplied encrypted linear regression coefficient vector; compared with the prior art, the method proposed in the present application does not need to introduce an encryption service provider, the initial encryption method is determined by each participant, and there is no need to implement a highly complex obfuscation circuit, thereby reducing the complexity of the linear regression process and meeting the actual application requirements; and, by setting a first computing node, the first computing node is used to store the intermediate generated data and perform overall calculations on all participants and label data owners. Therefore, the linear regression method proposed in the present application can be completed only by the user who owns the data and the first computing node in collaboration, thereby saving data transmission overhead and improving the encryption effect.
[0019] Other features and advantages of the present application will be described in the following description, and partly become apparent from the description, or understood by practicing the present application. The purpose and other advantages of the present application can be realized and obtained by the structures specifically pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The accompanying drawings are used to provide further understanding of the technical solution of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the technical solution of the present application and do not constitute a limitation on the technical solution of the present application.
[0021] Figure 1 An optional flowchart of a privacy-preserving linear regression method provided in an embodiment of the present application. DETAILED DESCRIPTION
[0022] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0023] In the description of this application, “several” means one or more, “more” means more than two, “greater than”, “less than”, “exceed”, etc. are understood to exclude the number, and “above”, “below”, “within”, etc. are understood to include the number.
[0024] It should be noted that, although the functional modules are divided in the device schematic diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the device or the order in the flowchart. The terms "first", "second", etc. in the specification, claims or the above drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
[0025] It should be noted that in each specific embodiment of the present application, when it comes to the need to perform relevant processing based on data related to the characteristics of the target object such as target object attribute information or attribute information set, the permission or consent of the target object will be obtained first, and the collection, use and processing of these data will comply with relevant laws, regulations and standards. Among them, the target object can be a user. In addition, when the embodiment of the present application needs to obtain the target object attribute information, the target object's separate permission or separate consent will be obtained by means of a pop-up window or jumping to a confirmation page, etc., and after the separate permission or separate consent of the target object is clearly obtained, the necessary target object-related data for enabling the normal operation of the embodiment of the present application will be obtained.
[0026] Related methods for implementing vertical federated learning often require the introduction of encryption service providers and evaluators to ensure the execution and effectiveness of encryption. Some linear regression methods with encryption requirements require the introduction of complex obfuscation circuits, making the implementation of linear regression difficult.
[0027] Based on this, the embodiment of the present application provides a linear regression method based on privacy protection, which is simpler to implement and encryption does not require the use of complex obfuscation circuits and other technologies.
[0028] The privacy protection-based linear regression method provided in the embodiment of the present application is specifically illustrated by the following embodiments. First, the vertical federated learning method in the embodiment of the present application is described.
[0029] The vertical federated learning method provided in the embodiment of the present application relates to the field of computer technology. The vertical federated learning method provided in the embodiment of the present application can be applied to a terminal, can be applied to a server side, or can be software running in a terminal or a server side. In some embodiments, the terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, etc.; the server side can be configured as an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application that implements the vertical federated learning method, etc., but is not limited to the above forms.
[0030] The present application can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, etc. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application can also be practiced in distributed computing environments, in which tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0031] In linear regression learning, suppose there are n training samples, where the i-th (i=1,2,…,n) training sample includes a column vector consisting of d input variables And the corresponding output variable y i ,here represents a column vector including d terms, and y i is a scalar. Regression is the problem of learning a function f such that Close to y i ,Right now For example, the input variables could be a person's age, weight, body mass index, etc., and the output could be their likelihood of contracting a disease. Once such a model is completed, for a new x value, without a given y value paired with it, the fitted model can be used to predict a y value. Linear regression is learning a Make here is a column vector containing d terms, (·) T As mentioned above, there are n training samples, where the i-th (i=1,2,…,n) training sample includes a column vector consisting of d input variables And the corresponding output variable y i . Put y i (i=1,2,…,n) written as a column vector Bundle (i=1,2,…,n) written as a matrix Defined by this and A = X T X+λI, where λ is the regularization coefficient, usually a real number greater than or equal to zero; then, The linear equation can be solved by get.
[0032] Machine learning is a branch of artificial intelligence that enables computer systems to learn from data and make decisions or predictions. This process involves algorithms and statistical models that enable computers to improve the performance of models through loss functions designed by the models without being explicitly programmed. The goal of machine learning is to enable computers to automatically detect patterns in data and use these patterns to predict future data or make decisions.
[0033] The process of vertical federated learning usually includes encrypted sample alignment and encrypted model training. In the encrypted sample alignment stage, the privacy intersection technology is used to align the training sample data with overlapping IDs without exposing the original data. In the encrypted model training stage, the participants calculate the intermediate results based on the current model, exchange them after encryption, and then calculate their own encrypted gradients and send them to the coordinator. The coordinator decrypts the gradients and sends them back to the participants for their respective model updates.
[0034] Vertical federated learning is widely used in fields such as finance, healthcare, security, and education. It solves the problem of data silos and enables different institutions to use their own data resources to jointly build more powerful machine learning models.
[0035] The secure inner product of two parties holding vectors x and y is adopted. That is, Party A holding x and Party B holding y can obtain the inner product of x and y through the secure inner product with privacy protection, and put the results of the inner product on Party A and Party B respectively. The inner product of vectors x and y is obtained by adding the results of Party A and Party B.
[0036] Secure two-party inner product supported by a trusted initializer, whose security depends on the trusted initializer not colluding with the data provider. The specific process is as follows:
[0037] Participants: The data provider 1 is called P1, the data provider 2 is called P2, and the trusted initializer is called TI.
[0038] Inputs: The column vector x owned by P1; the column vector y owned by P2.
[0039] Outputs: P1 gets s1, and P2 gets s2, and they satisfy s1 + s2 = <x, y>, where <x, y> represents the inner product of vectors x and y.
[0040] There are multiple implementation methods for the secure inner product protocol. The specific scheme of one implementation method is as follows:
[0041] 1. TI generates random vectors a and b, and a random number r, and lets z = <a, b> - r. TI sends (a, r) to P1 and sends (b, z) to P2.
[0042] 2. P1 sends x + a to P2.
[0043] 3. P2 sends y - b to P1.
[0044] 4. P1 calculates its shard output s1 = <x, y - b> - r.
[0045] 5. P2 calculates its shard output s2 = <x + a, b> - z.
[0046] It is easy to verify that s1 + s2 = <x, y - b> - r + <x + a, b> - z = <x, y> - <x, b> - r + <x, b> + <a, b> - z == <x, y> + <a, b> - r – z. Substituting z = <a, b> - r into it, we can get s1 + s2 = <x, y>.
[0047] The above secure inner product protocol is used to calculate A and b. It is easy to see that A = X T X + λI is a matrix symmetric about the diagonal, so only half of the non-diagonal terms need to be calculated. Generally, is locally calculated by user i who owns the data X i ; while (i is not equal to j. Here, it is assumed that only the upper triangular half is calculated, so i < j; actually, the lower triangular part with i > j can also be calculated) requires two-party joint calculation. It can be done by the first participant user i using its own data X i and the second participant user j using its own data Xj The first and second participants jointly calculate based on the privacy-preserving secure multi-party computing algorithm and It can be obtained by transposing the calculation result. Among them, or The result is the addition sharding, and the result is saved by user i and user j respectively. The participants can restore the local calculated part of the matrix by splicing it according to the local calculation result, and fill the part without local calculation result with 0: Specifically, for Only user i has a result, and all other m-1 users fill this position with 0; Only user i and user j save the result of addition sharding, and all other m-2 users fill this position with 0. After the above processing, each participant has a matrix Ai, Ai represents the regularized symmetric matrix A=X owned by user i T The i-th additive slice (i=1,2,…,m) in X+λI, corresponding to
[0048] Assume that the label vector y is in the mth user, then Quantity included (i=1,2,…,m-1) is obtained by the i-th user and the m-th user through two-party secure calculation, and the results are placed in the i-th user and the m-th user respectively, and the results of the i-th user and the m-th user are added together to obtain and The mth user uses his own data to obtain it. Each participant also fills the part without local calculation results with 0. After the above processing, each participant has the vector Indicates the number of The i-th additive slice (i=1,2,…,m) of
[0049] The above participants can be called data providers P1, P2, ..., Pm, and each data provider Pi (i = 1, 2, ..., m) obtains A through the above steps. i and A i is the symmetric matrix A=X owned by user i T The ith additive slice in X+λI, and Owned by user i The i-th addition slice of .
[0050] Reference Figure 1 As shown, the linear regression method based on privacy protection provided by the first embodiment of the present invention includes steps S11 to S12:
[0051] Step S11, for any i-th participant, the i-th participant determines the regularized symmetric matrix or other transformation form of the column encrypted data transformation encryption matrix corresponding to its own original data matrix, and sends the regularized symmetric matrix or its transformation form to the first computing node, wherein the transformation form of the regularized symmetric matrix satisfies, and the regularized symmetric matrix can be obtained by the transformation form without calculating other information; the j-th participant cooperates with the i-th participant to determine the product matrix of the column encrypted data transformation encryption matrices of the j-th participant and the i-th participant or the transformation form of the product matrix, and the first computing node saves the product matrix or the transformation form of the product matrix; wherein, the transformation form of the product matrix satisfies, and the product matrix can be obtained by the transformation form without calculating other information; i and j are both integers greater than or equal to 1 and less than or equal to m, j is not equal to i and j is less than i, and m is the total number of all participants;
[0052] Step S12: The first computing node uses the regularized symmetric matrix or its transformation form of the column encrypted data transformation encryption matrix of each participant, as well as the product matrix or its transformation form between the j-th participant and the ith participant, and collaborates with each participant and the label data owner to determine the multiplied encrypted linear regression coefficient vector.
[0053] It can be understood that after each participant encrypts the original data matrix owned by it, the participant determines its own symmetric matrix based on the encrypted matrix transformed by the encrypted column data obtained by itself, and any two different participants determine the product matrix by transforming the encrypted matrix through their respective encrypted column data. The first computing node obtains the symmetric matrix of each participant and the product matrix of any two participants, and then uses the label column vector of the label data owner to calculate the multiplied encrypted linear regression coefficient vector; compared with the prior art, the method proposed in this application does not require the introduction of an encryption service provider, and the initial encryption method is determined by each participant, and there is no need to implement a highly complex obfuscation circuit, thereby reducing the complexity of the linear regression process and meeting the actual application needs; and, by setting a first computing node, the first computing node is used to store the intermediate generated data and perform coordinated calculations on all participants and label data owners. Therefore, the linear regression method proposed in this application can be completed only by the user who owns the data and the first computing node in collaboration, thereby saving data transmission overhead and improving the encryption effect.
[0054] The linear regression method based on privacy protection of the present invention is a method for providing data privacy protection for data owners based on an application scenario in which m (m≥2) data owners providing private data, a label data owner with label data, and a first computing node jointly participate in vertical federated learning, wherein the m (m≥2) data owners providing private original data are referred to as m participants. The above-mentioned label data owner may be referred to as the label owner, and the label owner may be one of the aforementioned m participants, or may be other participants other than the aforementioned m participants, that is, one of the m participants may own both the original data and the label data. The above-mentioned first computing node may be one of the aforementioned m participants, or may be the label owner, or may be other trusted computing nodes other than the above-mentioned m participants and the label owner.
[0055] The original data matrix X formed by the private original data of the i-th participant (i=1, 2, ..., m) among the m participants i Construct a column-encrypted data matrix with the original data matrix as submatrices The above column encrypted data matrix With the reversible matrix Ω i The product of is represented as the column encryption data transformation encryption matrix The above reversible matrix Ω i is called the first mask matrix of the ith participant. For i=1, 2…m, the ith participant calculates And send or equivalently send to the first computing node; on the other hand, for j = 1, 2 ... i-1, have the column encryption data transformation encryption matrix The i-th participant transforms the encrypted matrix with the column encrypted data The jth participant collaborates to calculate the matrix And the above R is obtained by the first computing node j,i The i-th participant and the j-th participant collaborate to calculate It is based on secure multi-party computing protocols, or is directly calculated. The direct calculation means that the i-th participant sends or equivalently sends its own column encrypted data transformation encryption matrix to the j-th participant, and the j-th participant directly calculates it; or, the j-th participant sends or equivalently sends its own column encrypted data transformation encryption matrix to the i-th participant, and the i-th participant directly calculates it. The equivalent sending means not sending the matrix itself, but sending other transformation forms of the matrix, and the receiving party can obtain the matrix itself from the received transformation form.
[0056] The above secure multi-party computation is a universal cryptographic primitive that allows distributed parties to collaborate in computing any function of each party’s private data without revealing their private data. is to calculate the product of two matrices. As we all know, the product of matrices can be expressed as the inner product of the vectors contained in the matrices. Accordingly, the calculation of the above The secure multi-party computing protocol used can usually be a secure inner product protocol, which is a subset of many secure multi-party computing protocols and includes many different schemes; and the secure inner product protocol introduced above in this application document is only one of many secure inner product protocols. The secure multi-party computing protocol used may also be other secure multi-party computing protocols that are not secure inner product protocols.
[0057] has a label column vector that can be represented as The owner of the label data and the owner of the column encrypted data transform encryption matrix The i-th participant collaborates to calculate Where i is greater than or equal to 1 and less than or equal to m. The tag data owner and the i-th participant collaborate to calculate It is based on the secure multi-party computing protocol, or is directly calculated. The direct calculation is that the i-th participant sends its own column encrypted data transformation encryption matrix or equivalently sends it to the label data owner, and the label data owner directly calculates it. It is easy to see that the calculation of the above The secure multi-party computing protocol used may generally be a secure inner product protocol, or other secure multi-party computing protocols that are not secure inner product protocols.
[0058] Finally, with each R i,i (i=1, 2…m) and R j,i The matrix R composed of (j=1, 2…i-1) [1:m],[1:m] The first computing node with Several nodes (i=1,2…m) collaborate to calculate of To obtain the multiplied encrypted linear regression coefficient vector The concatenated column vector Represents the matrix R [1:m],[1:m] The inverse matrix of R [1:m],[1:m] is satisfied The following will be a symmetric matrix of R [1:m],[1:m] and concatenate column vectors Provide further explanation.
[0059] In this patent application document, the encrypted data of participants 1, 2, ..., i (i is greater than or equal to 1 and less than or equal to m) is transformed into a concatenated matrix of the encrypted matrix It is referred to as the column encryption data transformation encryption matrix for a total of i participants. is called the symmetric matrix of the encrypted data transformation encryption matrix of the i-participating parties; correspondingly, is called the regularized symmetric matrix of the column encryption data transformation encryption matrix of the i-participants, and is referred to as the first regularized symmetric matrix of the i-participants, where and It reflects the first mask matrix Ω of each of the i participants. 1 ,Ω 2 …Ω i The above Ω [1:i] is along Ω [1:i] The diagonal alignment of the matrix Ω 1 ,Ω 2 ,…,Ω i The resulting block diagonal matrix can also be expressed as Ω using the well-known MATLAB software blkdiag function [1:i] =blkdiag(Ω 1 ,Ω 2 ,…,Ω i ); because Ω 1 ,Ω 2 ,…,Ω i are the first mask matrices of participants 1, 2, ..., i, respectively. In this application document, Ω [1:i] is called the block diagonal matrix composed of the first mask matrices of the i participants, and Ω [1:i] It is referred to as the first mask matrix of the total i participants. Note that when i is greater than or equal to 2, the above is the first regularized symmetric matrix of multiple participants. [1:i] is an orthogonal matrix, then the above can be simplified to It is equivalent to the symmetric matrix The regularization matrix of the usual form is .
[0060] Above in is the column encryption data transformation encryption matrix of m participants, and Ω [1:m] is the first mask matrix of m participants. Correspondingly, R [1:m],[1:m] is the regularized symmetric matrix of the encrypted data transformation matrix of m participants. It can be deduced that R [1:m],[1:m] It can be expressed as
[0061]
[0062] Among them, R [1:m],[1:m] The matrix blocks on the diagonal are (i=1, 2…m), and R [1:m],[1:m] The matrix blocks that are not on the diagonal are (i=1, 2…m, j=1, 2…m and i is not equal to j). [1:m],[1:m] It is a symmetric matrix, which can be easily derived Corresponding to the above
[0063] In the embodiments given below, for R [1:m],[1:m] For each matrix block that is not on the diagonal, only the matrix block to the upper right of the diagonal is calculated. (i = 1, 2 ... m, j = 1, 2 ... m, and j is less than i), and if R is needed [1:m],[1:m] The matrix block on the lower left of the mid-diagonal (i=1, 2…m, j=1, 2…m, and j is less than i), then use It is easy to see that for any set of i and j that satisfies "i = 1, 2...m, j = 1, 2...m, and j is less than i", the calculation or Any one of them will do. If you need to use another one, use This relationship is obtained. Based on this principle, it is easy to obtain various variations of the embodiments given below. In this application document, for any set of i and j that satisfies "i = 1, 2 ... m, j = 1, 2 ... m, and j is less than i", It is called the product matrix of the column encryption data transformation encryption matrix of the jth participant and the column encryption data transformation encryption matrix of the ith participant, which is equal to the product of the transpose of the column encryption data transformation encryption matrix of the jth participant and the column encryption data transformation encryption matrix of the ith participant, and is simply referred to as the product matrix of the column encryption data transformation encryption matrices of the jth participant and the ith participant. On the other hand, as mentioned above Corresponding The above R j,i It is easy to see that in actual implementation, the calculation of the above R j,i Or the above R j,i One of the transformation forms of .
[0064] The technical solution of the present invention includes step S11 and step S12, which are described as follows. The following first introduces sub-steps S112-a to S112-e included in step S11, where the initial i is set to 1:
[0065] Sub-step S112-a: This sub-step is an optional sub-step for adding mask columns. In this sub-step, the original data matrix X i The i-th participant in his original data matrix X i Adding one or more columns of masks later is an optional step; when this sub-step is not selected, the number of columns of the added masks is 0, that is, adding 0 columns of masks. The original data matrix X formed by the i-th participant based on the private original data i And add the encrypted mask matrix Δ i The generated data matrix with added mask columns It is also referred to as the column-encrypted data matrix.
[0066] Specifically, the column-encrypted data matrix is the data matrix with mask columns added The data matrix X of the i-th participant i There is τ i The column contains τ i The original data of features is added with encrypted mask matrix Δ i have The column is generated by the i-th participant or obtained from a trusted node. Indicates that when there is τ i The columns of the data matrix X i Added later Column-added encryption mask matrix Δ i To obtain common Column-by-column encrypted data matrix in Can be equal to 0, which is equivalent to the i-th participant not adding columns to the encryption mask matrix Δ i to encrypt the original data; in addition, it is usually If it is equal to 1, it can have a good encryption effect. Column-added encryption mask matrix Δ i In fact, it is a mask column vector with only one column. If the i-th participant does not choose this optional step of adding a mask column, then there will be
[0067] Sub-step S112-b: This sub-step is an optional sub-step of multiplying a reversible matrix for encryption. In this sub-step, the i-th participant uses the original data matrix X containing itself i Matrix as a submatrix (i.e. column-encrypted data matrix) Multiply the left side by a reversible matrix Ω i Get the product of the column encrypted data matrix and the reversible matrix As mentioned above, the above reversible matrix Ω iThe first mask matrix of the i-th participant is generated by the i-th participant or obtained from a trusted node. is the encryption matrix obtained by multiplying the column encryption data matrix by the first mask matrix, referred to as the column encryption data transformation encryption matrix of the i-th participant, because it is well known that multiplying the column encryption data matrix by the first mask matrix can be regarded as transforming the column encryption data matrix, and the transformation refers to multiplying the first mask matrix. The i-th participant can also not use Ω i Encryption, which is equivalent to Ω i It is the unit matrix I, that is, this step does not have any actual operation, that is, this sub-step is not selected.
[0068] Note that the above sub-steps S112-a and S112-b provide a mechanism for double encryption by using the above-mentioned mask columns and the first mask matrix respectively. When implementing the technology of the present invention, at least one of the above-mentioned double encryption mechanisms is usually adopted to ensure encryption. Correspondingly, if the number of mask columns is set to 0 in sub-step S112-a (i.e., the encryption mechanism of sub-step S112-a is not adopted), then the first mask matrix in sub-step S112-b usually cannot be the unit matrix to ensure the encryption effect; or, when the first mask matrix in sub-step S112-b is the unit matrix (i.e., the encryption mechanism of sub-step S112-b is not adopted), then the number of mask columns in sub-step S112-a usually cannot be set to 0 to ensure the encryption effect.
[0069] In order to achieve the encryption effect, the column-added encryption mask matrix Δ generated by the i-th participant or obtained from the trusted node in sub-step S112-a i , and the first mask matrix Ω generated by the i-th participant or obtained from the trusted node in sub-step S112-b i , must be known only to the i-th participant, or only to the i-th participant and the trusted node. i and the first mask matrix Ω i , which can usually be generated by the i-th participant or by a trusted node and then sent to the i-th participant, and the generation is usually generated in a random manner to achieve confidentiality. The simplest and most common implementation is for the i-th participant to generate the above-mentioned column-added encryption mask matrix Δ in a random manner i And the first mask matrix Ω i .
[0070] Sub-step S112-c: The i-th participant calculates And put R i,i Send or equivalently send to the first computing node. middle, is the column encryption data transformation encryption matrix of the i-th participant Transpose With oneself The product of is referred to as the symmetric matrix of the encryption matrix of the column encryption data transformation of the i-th participant. It is called the regularized symmetric matrix of the encryption matrix for column encrypted data transformation of the i-th participant, referred to as the first regularized symmetric matrix of the i-th participant. Obviously, it is the first regularized symmetric matrix of a single participant, namely the i-th participant. Because the regularization coefficient λ is usually a real number greater than or equal to zero, it is easy to see that when the regularization coefficient λ is equal to zero, the regularized symmetric matrix of the encryption matrix for column encrypted data transformation of the i-th participant is equal to the symmetric matrix of the encryption matrix for column encrypted data transformation of the i-th participant, that is, the above regularized symmetric matrix contains the symmetric matrix as a special case. middle, The first mask matrix Ω of the i-th participant is represented by i The influence of i is an orthogonal matrix, then is equal to the identity matrix I, and the above Simplified to It is equivalent to the symmetric matrix The equivalent transmission refers to sending one or more regularization matrices with R i,i The relevant matrix, and the receiver who receives the matrix can use it to calculate R i,i , for example, sending directly Or send separately and And the receiver tries to get λ. It is easy to see that when the first mask matrix Ω of the i-th participant i is not an orthogonal matrix, then the above regularization process obtains a regularized symmetric matrix In the process, the first mask matrix Ω of the i-th participant is used i ; When the first mask matrix Ω of the i-th participant i is an orthogonal matrix, then the above regularization process obtains the regularized symmetric matrix In the process of i .
[0071] Sub-step S112-d: transform the encryption matrix with column encrypted data The i-th participant transforms the encrypted matrix with the column encrypted data The jth participant collaborates to calculate the matrix And the above R is obtained by the first computing node j,i, where j is greater than or equal to 1 and less than or equal to i-1. For each j greater than or equal to 1 and less than or equal to i-1, perform this step and obtain a total of i-1 matrices R j,i , where j = 1, 2…i-1. is the column encryption data transformation encryption matrix of the jth participant Transpose Transform the encrypted matrix with the column encrypted data of the i-th party The product of is referred to as the product matrix of the encrypted data transformation matrix of the j-th participant and the i-th participant. The above i-1 product matrices (j=1,2…i-1), which can be expressed as a concatenation matrix It is easy to see that the above concatenation matrix V i is the column encryption data transformation encryption matrix for a total of i-1 participants Transpose Transform the encrypted matrix with the column encrypted data of the i-th party The product of It is referred to as the product matrix of the column encryption data transformation encryption matrix of i-1 participants and the column encryption data transformation encryption matrix of the i-th participant, and the above i-1 participants are participants 1, 2...i-1.
[0072] It is easy to see that the above product matrix R j,i Other forms may also be used, such as That is, the column encryption data transformation encryption matrix of the i-th participant Transpose Transform the encrypted matrix with the column encrypted data of the jth party The product of , then the embodiment can be modified accordingly, which is an obvious variation of the implementation method.
[0073] This step calculates The jth participant cooperates with the ith participant and determines or directly calculates based on the preset secure multi-party computing protocol. The direct calculation is that the ith participant transforms its own column encryption data into an encryption matrix Send it to the jth participant, who uses his own and received Directly calculated Or, the jth participant transforms its own column encrypted data into the encryption matrix Sent to the i-th participant, who uses his own and received Directly calculated
[0074] As mentioned above, the above calculation The secure multi-party computing protocol used can usually be a secure inner product protocol, or other secure multi-party computing protocols that are not secure inner product protocols. The secure inner product protocol refers to performing confidential calculations when calculating the inner product of two vectors to ensure that the input data, i.e., the information of the two vectors, is not disclosed. It is a well-known prior art and has a variety of different implementation methods. Usually, the j-th participant and the i-th participant each obtain R through calculation. j,i The jth participant then sends the partial result it has obtained to the ith participant, and the ith participant adds the two partial results to get R j,i ; In the above calculation process, the jth participant It does not need to be sent directly to the i-th participant. It does not need to be sent directly to the jth party, but usually includes and The encrypted ciphertext is further sent. Note that there are some secure inner product protocols in the prior art, in which the i-th participant, the j-th participant and the first computing node all participate in the calculation agreed upon by the secure inner product protocol, and the three nodes collaborate to calculate The final result R j,i In the above secure inner product protocol, it is not just the i-th participant and the j-th participant who collaborate to calculate R j,i , but only with the participation of the first computing node can R be calculated j,i .
[0075] Sub-step S112-e (sub-step of iterative control): If the value of i is less than or equal to m-1, increase the value of i by 1 and return to sub-step S112-a to start the next iteration; otherwise, when the value of i is equal to m, enter the following step S12.
[0076] In order to further protect the data privacy of participants 1, 2, ..., i-1, as mentioned above, this embodiment includes an implementation method using a secure multi-party computing protocol (Secure Multi-Party Computation protocols), which can transform the encryption matrix when participant i does not receive the column encrypted data of participants 1, 2, ..., i-1 And participants 1, 2, ..., i-1 have not received the column encrypted data transformation encryption matrix of participant i In the case of (j=1,2…i-1).
[0077] When the value of i is equal to m, the first computing node has obtained all (i=1,2…m) and (i=1,2…m, and correspondingly j=1,2…i-1). The first computation node can thus obtain the symmetric matrix R [1:m],[1:m] It is called the regularized symmetric matrix of the column encryption data transformation encryption matrix of m participants, referred to as the first regularized symmetric matrix of m participants, because it is easy to see that in is the column encryption data transformation encryption matrix of m participants, and Ω [1:m] is the first mask matrix of m participants. [1:m] is an orthogonal matrix, then the above Simplified to It is equivalent to the symmetric matrix The regularization matrix of the usual form is .
[0078] In the next step S12, the tag data owner transforms the encryption matrix with the first computing node and the owner of the respective column encrypted data according to the private tag column vector. m participants (i.e., m data owners) collaborate to calculate the multiplication of the encrypted linear regression coefficient vector That is, the product of the encryption mask and the linear regression coefficient vector.
[0079] The steps of calculating the multiplication and encryption of the linear regression coefficient vector in the embodiment of the present invention are as follows: the label data owner uses a private label column vector The label data is transformed into the encryption matrix with each column encrypted data m participants (i=1, 2…m) collaborate to calculate For i = 1, 2...m; the above m column vectors (i=1, 2…m) can be expressed as a concatenated column vector Afterwards, all related nodes including the first computing node collaborate to compute To obtain the multiplied encrypted linear regression coefficient vector In this patent application document, It is called the inverse matrix of the regularized symmetric matrix of the column encryption data transformation encryption matrix of the i-participants, and is referred to as the inverse matrix of the first regularized symmetric matrix of the i-participants. It is called the inverse matrix of the regularized symmetric matrix of the column encryption data transformation encryption matrix of the m participants, and is simply called the inverse matrix of the first regularized symmetric matrix of the m participants.
[0080] The above is the column encryption data transformation encryption matrix of the i-th participant Transpose The label column vector of the owner of the label data The product of the column encryption data transformation encryption matrix of the i-th participant and the label is referred to as the product of the column encryption data transformation encryption matrix of the m participants. The transpose of the label column vector The product of is Right now This shows that the concatenated column vector It is the product of the transpose of the column encryption matrix of the m-participants' column encryption data transformation and the label column vector, referred to as the product of the column encryption matrix of the m-participants' column encryption data transformation and the label.
[0081] The step S12 includes step S121 to step S122.
[0082] Step S121: Have a label column vector that can be represented as The owner of the label data and the owner of the column encrypted data transform encryption matrix The i-th participant collaborates to calculate the product of the i-th participant's column encrypted data transformation encryption matrix and the label And put Stored in several nodes, where i is greater than or equal to 1 and less than or equal to m. For each i greater than or equal to 1 and less than or equal to m, perform this step and obtain a total of m Where i = 1, 2…m. This sub-step calculates the product of the encrypted matrix of the column encrypted data of the i-th participant and the label. There are many ways to implement this. Here are some possible implementations:
[0083] Implementation method 1) Obtaining calculation results from the i-th specific node (i=1,2…m). This implementation method calculates It is determined or directly calculated by the label data owner and the i-th participant in collaboration based on a preset secure multi-party computing protocol. The specific implementation method based on the secure multi-party computing protocol can be that the i-th participant and the label data owner each obtain a partial result, and then they send their respective partial results to the i-th specific node, and the i-th specific node combines the two partial results to obtain In addition, when the i-th specific node is not the i-th participant or the tag data owner, for example, the i-th specific node is the first computing node, then the prior art already has some secure multi-party computing protocols, in which the i-th specific node, the i-th participant and the tag data owner collaborate to compute The final result Stored in the i-th specific node. On the other hand, the direct calculation is performed by the i-th participant Send it to the owner of the label data, and then the owner of the label data uses the label column vector he owns and received Calculated Then send it to the i-th specific node. It is easy to see that when the i-th specific node is the i-th participant or the owner of the tag data, part of the above sending is sent to itself, which actually does not require any operation.
[0084] Implementation method 2) Calculation results (i=1,2…m) is divided into two parts, namely and They are placed on two nodes called the i-th node A and the i-th node B respectively. and satisfy This implementation usually uses a secure multi-party computing protocol. And the calculation results Divide and By placing them at two nodes respectively, adding the calculation results placed at two nodes respectively, we can get The two nodes, ie, the i-th node A and the i-th node B, may be the tag data owner and the i-th participant, or other two nodes.
[0085] This step has a simple implementation method: when the implementation method 1 is adopted, and the i-th specific node is the owner of the label data, then all the calculation results (i=1,2…m) are all on the tag data owner side.
[0086] Step S122: The regularized symmetric matrix R of the column encrypted data transformation encryption matrix having a total of m participants [1:m],[1:m] The first computing node and the encrypted data of the i-th participant column are transformed into the encrypted matrix and the label product Several nodes (i=1,2…m) collaborate to calculate To obtain the multiplied encrypted linear regression coefficient vector It is easy to see the above It is the result of multiplying the inverse matrix of the regularized symmetric matrix of the column encrypted data transformation encryption matrix of the m participants by the product of the column encrypted data transformation encryption matrix of the m participants and the label. There are many possible implementation methods for this step, and several of them are listed below:
[0087] Implementation method 1) When step S121 adopts implementation method 1, then in this step, having R [1:m],[1:m] The first computing node with Each i-th specific node (where i = 1, 2…m) cooperates to calculate Calculated It can be placed on one node or on multiple nodes.
[0088] let Then you can get And it can be expressed as
[0089] Right now
[0090] Where Γ(:,i)(i=1,2…m) represents the Column to All columns of the column can be called the product of the encrypted data transformation matrix and the label corresponding to the i-th participant column Correspondingly, we can calculate One implementation method of placing them on multiple nodes is to have R [1:m],[1:m] The first computing node with The i-th specific node (i=1,2…m) cooperates and calculates of
[0091] Quantity (i=1, 2, ..., m) and placed in the i-th coefficient storage node, which may be the i-th specific node, or the first calculation node, or other nodes.
[0092] Implementation method 2) When step S121 adopts implementation method 2, then in this step, having R [1:m],[1:m] The first computing node and each have part The two nodes (i=1,2…m), ie, the i-th node A and the i-th node B, cooperate to calculate Note that the values of i above are 1, 2, ..., m. It can be placed on one node or on multiple nodes.
[0093] Bundle Substitution Can get Accordingly, One way to implement it by placing it on multiple nodes is to have R [1:m],[1:m] The first computing node with the The i-th node A (i=1,2…m) cooperates and calculates The amount (i=1, 2, ..., m) is placed in the i-th coefficient storage node A, which may be the i-th node A, or the first computing node, or other nodes; on the other hand, the node with R [1:m],[1:m]The first computing node with the The i-th node B (i=1,2…m) cooperates and calculates The amount (i=1, 2, ..., m) is placed in the i-th coefficient storage node B, and the i-th coefficient storage node B may be the i-th node B, or the first computing node, or other nodes.
[0094] From the above As you can see, the calculation The regularized symmetric matrix R of the encrypted matrix is first transformed by the m participants to encrypt the data [1:m],[1:m] Get the inverse matrix of the regularized symmetric matrix of the column encrypted data transformation encryption matrix of m participants Finally, we can get the inverse matrix and The product of It is the product of the column encrypted data transformation encryption matrix and the label of a total of m participants.
[0095] The multiplied encrypted linear regression coefficient vector and the encrypted mask matrix Δ containing each participant i (where i = 1, 2, ... m) the target linear regression coefficient vector affected The relationship between That is, multiply the encrypted linear regression coefficient vector is the target linear regression coefficient vector containing the influence of the added column encrypted mask matrix of each participant Right multiplication matrix The encrypted result is the matrix It is a block diagonal matrix Ω composed of m participants multiplying the encryption mask [1:m] When step S121 adopts the simple implementation method, that is, all the calculation results (i=1,2…m) are all in the tag data owner side, then this step can also be implemented in a simple way: that is, the owner R [1:m],[1:m] The first computing node with The label data owner cooperates to calculate And put Place it on the first computing node or the owner of the label data. Placed on the first computing node, the label data owner Sent to the first computing node, which calculates Or, when Placed on the label data owner, the first computing node will [1:m],[1:m] Send or equivalently send to the owner of the label data, and the owner of the label data will calculate The equivalent transmission R [1:m],[1:m] , which means sending one or more matrices, and the receiver can obtain R from this matrix [1:m],[1:m] , for example, sending or R [1:m],[1:m] The factorization matrix of The factorization matrix of .
[0096] Calculate the above multiplication encrypted linear regression coefficient vector Afterwards, the subsequent steps of the above embodiment of the present invention achieve the following effect: if there are several participants among the participants 1 to m who use the column-increasing encryption mask matrix with non-zero columns, then the several participants are sequentially multiplied by the encrypted square root matrix P m Sum and multiply the encrypted linear regression coefficient vector At least partially eliminate the influence of the added column encryption mask matrix Δ, where the multiplication of the encrypted square root matrix P m is a matrix The square root matrix can be obtained by When each participant who uses the non-zero column-increment encrypted mask matrix multiplies the encrypted linear regression coefficient vector The influence of the participant's added column encryption mask matrix Δ is at least partially eliminated, or when there is no participant using a non-zero column added column encryption mask matrix, then the most recently updated multiplied encrypted linear regression coefficient vector The participants or nodes The corresponding items of participant i (where i is greater than or equal to 1 and less than or equal to m) are sent to participant i, and the participant i uses its first mask matrix Ω i The inverse matrix Decryption obtains the corresponding items in the target linear regression coefficient vector.
[0097] In the present invention, for simplicity of description, it is assumed that the column encrypted data matrix of the i-th participant is The columns are arranged in the following order: The front τ i The columns are the original data matrix X i ,then The columns are the mask matrix Δ i In practice The columns may also be arranged in other ways, and the specific implementation of the present invention may be slightly modified accordingly, which is well known to those skilled in the art.
[0098] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
[0099] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely disposed relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0100] It can be understood by those skilled in the art that Figure 1 The technical solutions shown in the figure do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than those shown in the figure, or a combination of certain steps, or different steps.
[0101] Those skilled in the art will appreciate that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices may be implemented as software, firmware, hardware, or a suitable combination thereof.
[0102] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0103] It should be understood that in the present application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the objects associated before and after are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0104] The preferred embodiments of the present invention are described above with reference to the accompanying drawings, but the scope of the rights of the present invention is not limited thereto. Any modification, equivalent substitution and improvement made by a person skilled in the art without departing from the scope and essence of the present invention should be within the scope of the rights of the present invention.
Claims
1. A linear regression method based on privacy protection, characterized in that: include: For any i-th participant, the i-th participant determines the regularized symmetric matrix of the column encrypted data transformation encryption matrix corresponding to its own original data matrix or other transformation forms of the regularized symmetric matrix, and sends the regularized symmetric matrix or its transformation form to the first computing node, wherein the transformation form of the regularized symmetric matrix satisfies, and the regularized symmetric matrix can be obtained by the transformation form without calculating other information; the j-th participant cooperates with the i-th participant to determine the product matrix of the column encrypted data transformation encryption matrix of the j-th participant and the i-th participant or the transformation form of the product matrix, and the first computing node saves the product matrix or the transformation form of the product matrix; wherein the transformation form of the product matrix satisfies, and the product matrix can be obtained by the transformation form without calculating other information; the i and j are both integers greater than or equal to 1 and less than or equal to m, j is not equal to i and j is less than i, and m is the total number of all the participants; The first computing node utilizes the regularized symmetric matrix or its transformation form of the column encrypted data transformation encryption matrix of each of the participants, as well as the product matrix or its transformation form between the j-th participant and the ith participant, and collaborates with each of the participants and the label data owner to determine the multiplied encrypted linear regression coefficient vector.
2. The privacy-preserving linear regression method according to claim 1, characterized in that: The product matrix of the column encrypted data transformation encryption matrices of the jth participant and the i-th participant is equal to the product of the transpose of the column encrypted data transformation encryption matrix of the jth participant and the column encrypted data transformation encryption matrix of the i-th participant, and the transformation form of the product matrix includes the transpose of the product matrix, that is, the product of the transpose of the column encrypted data transformation encryption matrix of the i-th participant and the column encrypted data transformation encryption matrix of the j-th participant. The product matrix of the column encrypted data transformation encryption matrices of the jth participant and the i-th participant or its transformation form is determined by the j-th participant and the i-th participant in collaboration based on a preset secure multi-party computing protocol or obtained by direct calculation.
3. The privacy-preserving linear regression method according to claim 1, characterized in that: The column encrypted data transformation encryption matrix corresponding to the original data matrix of the i-th participant is equal to the product of the column encrypted data matrix of the i-th participant and the first mask matrix of the i-th participant; wherein the column encrypted data matrix contains the original data matrix as a submatrix, and includes each subcolumn in the original data matrix and the mask column generated by the participant or obtained from the trusted node, and the number of items contained in the mask column is the same as the number of items contained in each column of the original data matrix of the participant; and the first mask matrix of the i-th participant is a reversible matrix, which is generated by the i-th participant or obtained from the trusted node.
4. The privacy-preserving linear regression method according to claim 3, characterized in that: The multiplied encrypted linear regression coefficient vector is equal to the column vector obtained by adding the influence of the mask column of each participant to the target linear regression coefficient column vector, and then right-multiplying it by the block diagonal matrix composed of the first mask matrices of each participant, wherein the block diagonal matrix uses the inverse matrix of the first mask matrix of each participant as a submatrix located on the diagonal of the block diagonal matrix.
5. The privacy-preserving linear regression method according to claim 1, characterized in that: The first computing node uses the regularized symmetric matrix or its transformation form of the column encrypted data transformation encryption matrix of each of the participants, and the product matrix between the j-th participant and the i-th participant or its transformation form, and cooperates with each of the participants and the label data owner to determine the multiplication encrypted linear regression coefficient vector, including: The label data owner cooperates with any one of the participants respectively, determines the column encrypted data transformation encryption matrix and the label product or its transformation form of each of the participants according to the label column vector of the label data owner and the column encrypted data transformation encryption matrix of the participant, and stores the column encrypted data transformation encryption matrix and the label product or its transformation form of each of the participants in any one or more nodes among the participant, the label data owner, the first computing node and the trusted storage node, wherein the transformation form of the column encrypted data transformation encryption matrix and the label product satisfies, and the column encrypted data transformation encryption matrix and the label product can be calculated from the transformation form; Any i-th participant performs regularization processing on its own symmetric matrix to obtain a regularized symmetric matrix or a transformed form of the column encrypted data transformation encryption matrix of the i-th participant, and sends the regularized symmetric matrix or the transformed form to the first computing node, wherein when the first mask matrix of the i-th participant is not an orthogonal matrix, the above regularization processing also uses the first mask matrix of the i-th participant; Any ith participant cooperates with the jth participant to use their respective column encrypted data transformation encryption matrices to determine a product matrix or a transformation form of the column encrypted data transformation encryption matrices of the jth participant and the ith participant, and the first computing node saves the product matrix or the transformation form of the product matrix; The first computing node uses the regularized symmetric matrix of the column encrypted data transformation encryption matrix of the i-th participant, and the product matrix of the column encrypted data transformation encryption matrices of the j-th participant and the i-th participant or its transformation form, and cooperates with one or more nodes storing the product of the column encrypted data transformation encryption matrix of each participant and the label or its transformation form to determine the multiplied encrypted linear regression coefficient vector.
6. The privacy-preserving linear regression method according to claim 5, characterized in that: The arbitrary i-th participant performs regularization processing on the symmetric matrix of the participant to obtain a regularized symmetric matrix of the column encrypted data transformation encryption matrix of the i-th participant, including: The regularized symmetric matrix of the column encrypted data transformation encryption matrix of the i-th participant is the sum of the symmetric matrix of the column encrypted data transformation encryption matrix of the i-th participant plus the regularization term, and the regularization term is the product of the symmetric matrix of the first mask matrix of the i-th participant and the regularization coefficient; wherein, the symmetric matrix of the column encrypted data transformation encryption matrix is equal to the product of the transpose of the column encrypted data transformation encryption matrix and the column encrypted data transformation encryption matrix itself, and the symmetric matrix of the first mask matrix of the i-th participant is equal to the product of the transpose of the first mask matrix of the i-th participant and the first mask matrix itself.
7. The privacy-preserving linear regression method according to claim 5, characterized in that: The arbitrary i-th participant cooperates with the j-th participant to use their respective column encrypted data transformation encryption matrices to determine the product matrix of the column encrypted data transformation encryption matrices of the j-th participant and the i-th participant or a transformation form thereof, including: Any i-th participant cooperates with the j-th participant to determine a product matrix or a transformed form thereof through the column encrypted data transformation encryption matrix of the i-th participant and the column encrypted data transformation encryption matrix of the j-th participant, and the product matrix or a transformed form thereof is obtained by the first computing node; Among them, the product matrix of the column encrypted data transformation encryption matrix of the ith participant and the column encrypted data transformation encryption matrix of the jth participant is equal to the product of the transpose of the column encrypted data transformation encryption matrix of the jth participant and the column encrypted data transformation encryption matrix of the ith participant, and the transformation form of the product matrix includes the transpose of the product matrix, that is, the product of the transpose of the column encrypted data transformation encryption matrix of the ith participant and the column encrypted data transformation encryption matrix of the jth participant.
8. The privacy-preserving linear regression method according to claim 5, characterized in that: The first computing node uses the regularized symmetric matrix of the column encrypted data transformation encryption matrix of the i-th participant, and the product matrix of the column encrypted data transformation encryption matrix of the j-th participant and the i-th participant or its transformation form, and cooperates with one or more nodes storing the product of the column encrypted data transformation encryption matrix of each participant and the label or its transformation form to determine the multiplied encrypted linear regression coefficient vector, including: The multiplied encrypted linear regression coefficient vector is equal to the product of the inverse matrix of the regularized symmetric matrix of the column encrypted data transformation encryption matrix of all the participants and the product of the column encrypted data transformation encryption matrix of all the participants and the label; Among them, the regularized symmetric matrix of the column encrypted data transformation encryption matrix of all the participants includes sub-matrices including: the regularized symmetric matrix of the column encrypted data transformation encryption matrix of each of the participants, and the product matrix of the column encrypted data transformation encryption matrices of any two different participants; and the product of the column encrypted data transformation encryption matrix and the label of all the participants is composed of the product of the column encrypted data transformation encryption matrix and the label of each of the participants.
9. The privacy-preserving linear regression method according to claim 5, characterized in that: The label data owner cooperates with any one of the participants respectively, determines the product of the column encrypted data transformation encryption matrix and the label or its transformation form of each participant according to the label column vector of the label data owner and the column encrypted data transformation encryption matrix of the participant, and stores the product of the column encrypted data transformation encryption matrix and the label or its transformation form of each participant in any one or more nodes among the participant, the label data owner, the first computing node and the trusted storage node, including: The label data owner cooperates with any ith participant to determine the product of the column encrypted data transformation encryption matrix of the ith participant and the label or its transformation form based on a preset secure multi-party computing protocol or based on a direct calculation method, that is, the product of the transpose of the column encrypted data transformation encryption matrix of the ith participant and the label column vector or its transformation form. The calculated product of the column encrypted data transformation encryption matrix of the ith participant and the label or its transformation form is stored in one or more nodes among the multiple participants, the label data owner, the first computing node and the trusted storage node.
10. A linear regression system based on privacy protection, characterized in that: The privacy protection-based linear regression system is used to execute the privacy protection-based linear regression method described in any one of claims 1 to 9.
11. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored computer program; wherein, when the computer program is run, it controls the device where the computer-readable storage medium is located to execute the privacy protection-based linear regression method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Method and device for jointly training service prediction model by two parties for protecting data privacy
CN111241570A
Data privacy protection system based on secure two-party calculation linear regression algorithm
CN112182649A
Data regression processing method, terminal and equipment
CN115495709A
Privacy protection-based linear regression method and system, storage medium and equipment
CN117171498A
Privacy calculation method and device for secure tripartite matrix hybrid multiplication
CN117290866A
Cited By
Privacy preserving-based linear regression method
WO2026148840A1