Linear regression method based on privacy protection

By introducing a linear regression method based on privacy protection in vertical federated learning, the collaboration and encrypted transformation matrix between participants is used to solve the problem of high complexity in the existing technology, and effective protection of data privacy and efficient calculation of linear regression are achieved.

CN120012039AActive Publication Date: 2025-05-16WUYI UNIV

Patent Information

Application Number
CN202510047063.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-13
Publication Date
2025-05-16
Estimated Expiration
2045-01-13

AI Technical Summary

Technical Problem

When implementing linear regression, existing vertical federated learning technologies usually need to introduce complex encryption and obfuscation circuits in order to ensure data security, resulting in high implementation complexity and is not suitable for practical applications.

Method used

A linear regression method based on privacy protection is proposed. Through collaboration between participants, the encrypted data transforms the encryption matrix using the column corresponding to the respective private original data, determines the product matrix or its transformation form, and calculates the multiplication encrypted linear regression coefficient vector without directly sharing the data.

Benefits of technology

It reduces the implementation complexity, meets the actual application needs, and effectively protects data privacy through the collaboration of encryption and transformation matrix.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012039A_ABST
    Figure CN120012039A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a linear regression method based on privacy protection. The method comprises the steps that a current participant receives an inverse decomposition factor matrix of a regularization symmetric matrix or a transformation form of the inverse decomposition factor matrix of the regularization symmetric matrix influenced by a column encrypted data transformation encryption matrix corresponding to private original data of a former participant; the current participant and the former participant cooperate to determine respective product matrixes or transformation forms thereof; the current participant sends an inverse decomposition factor matrix or a transformation form thereof to a subsequent participant; or, the current participant obtains and utilizes the product matrix of the front participant and the current participant or the transformation form of the product matrix to cooperate with the front participant and the label data owner to determine the multiplication encryption linear regression coefficient vector; multiplying the encrypted linear regression coefficient vector to be equal to the product of the inverse decomposition factor matrix containing the front participant and the current participant and the first product vector; according to the method provided by the invention, the implementation complexity can be reduced, and actual application requirements are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to but is not limited to the field of machine learning technology, and in particular to a linear regression method based on privacy protection. Background Art

[0002] Vertical Federated Learning (VFL) is a distributed machine learning method that allows multiple parties to jointly train a shared machine learning model while protecting the privacy of their respective data. This method is particularly suitable for datasets that have the same samples (such as users or transactions) but different characteristics, such as banks and e-commerce companies in the same region, which may have similar user bases but different business characteristics. Challenges faced by vertical federated learning include privacy protection, data alignment, communication efficiency, and security issues. To address these challenges, researchers have proposed a variety of techniques, such as additive homomorphic encryption, secure multi-party computation, and differential privacy. Vertical federated learning has a wide range of applications in finance, healthcare, advertising, and recommendation systems. For example, banks and insurance companies can jointly train a credit scoring model without directly sharing their respective customer data. In vertical federated learning, the data is vertically divided, that is, each participant has a different set of features. For example, one participant may have a user's transaction data, while another participant may have the user's social network data. In this way, each participant can jointly train a more comprehensive model without directly accessing the other party's data.

[0003] In the existing vertical federated learning technology for linear regression, in order to ensure the data security of each data owner, it is often necessary to encrypt the service provider and the evaluator, or introduce obfuscation circuits to ensure the security of data calculation and interaction processes. However, the above methods are highly complex and not conducive to implementation in practical applications. Summary of the invention

[0004] The following is a summary of the subject matter described in detail herein. This summary is not intended to limit the scope of the claims.

[0005] The embodiment of the present application provides a linear regression method based on privacy protection, which can reduce the implementation complexity and meet the actual application needs.

[0006] To achieve the above-mentioned purpose, the first aspect of an embodiment of the present application proposes a linear regression method based on privacy protection, including: the current participant receives the inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by the column encrypted data transformation encryption matrix corresponding to the private original data of the previous participant or the transformed form of the inverse decomposition factor matrix; the current participant cooperates with the previous participant to use the column encrypted data transformation encryption matrix corresponding to their respective private original data to determine the product matrix of the column encrypted data transformation encryption matrix of the previous participant and the current participant or the transformed form of the product matrix; the current participant sends the inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by the column encrypted data transformation encryption matrix of the previous participant and the current participant in whole or in part to the subsequent participant; or the current participant The participant obtains and utilizes the product matrix or its transformed form of the column encrypted data transformation encryption matrix of the previous participant and the current participant, and cooperates with the previous participant and the label data owner to determine the multiplied encrypted linear regression coefficient vector, wherein the subsequent participant is the participant who subsequently provides the private original data; the multiplied encrypted linear regression coefficient vector is equal to the product of the inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by the column encrypted data transformation encryption matrix of the previous participant and the current participant and the first product vector, the first product vector is determined by the transpose of the inverse decomposition factor matrix and the product of the column encrypted data transformation encryption matrix of the previous participant and the label and the product of the column encrypted data transformation encryption matrix of the current participant and the label; the transformation form of the matrix satisfies, and the matrix can be calculated by the transformation form without other information.

[0007] In some embodiments, the product matrix of the column encrypted data transformation encryption matrices of the previous participant and the current participant is equal to the product of the transpose of the column encrypted data transformation encryption matrix of the previous participant and the column encrypted data transformation encryption matrix of the current participant. The product matrix of the column encrypted data transformation encryption matrix of the previous participant and the current participant, or its transformed form, is determined or directly calculated by the previous participant in collaboration with the current participant based on a preset secure multi-party computing protocol.

[0008] In some embodiments, the column encrypted data transformation encryption matrix corresponding to the private original data of any of the participants is equal to the product of the column encrypted data matrix of the arbitrary participant and the first mask matrix of the arbitrary participant; wherein the column encrypted data matrix of the arbitrary participant is composed of the original data matrix formed by the private original data of the arbitrary participant as a sub-matrix, and the column encrypted data matrix includes each sub-column in the original data matrix and the mask column generated by the arbitrary participant itself or obtained from the trusted node, and the number of items contained in the mask column is equal to the number of items of the arbitrary participant itself. The number of items contained in each column of the original data matrix is ​​the same; and the first mask matrix of any participant is a reversible matrix, which is generated by the arbitrary participant itself or obtained from a trusted node; wherein, the multiplication of the encrypted linear regression coefficient vector is equal to adding the influence of the mask column of each participant to the target linear regression coefficient column vector, and then right-multiplying it by the column vector obtained by the block diagonal matrix composed of the first mask matrices of each participant, wherein the block diagonal matrix contains the inverse matrix of the first mask matrix of each participant as a submatrix located on the diagonal of the block diagonal matrix.

[0009] In some embodiments, the influence of the column encrypted data transformation encryption matrix of the previous participant is equivalent to including the column encrypted data transformation encryption matrix of the previous participant as a sub-matrix, and the influence of the column encrypted data transformation encryption matrix of the previous participant and the current participant is equivalent to including the column encrypted data transformation encryption matrix of the previous participant and the column encrypted data transformation encryption matrix of the current participant as sub-matrices; wherein, the regularized symmetric matrix of a matrix is ​​the sum of the symmetric matrix of the matrix plus the regularization term, wherein the regularization term is a matrix, which contains the product of the symmetric matrix of the first mask matrix of the related participant and the preset regularization coefficient as a sub-matrix; the symmetric matrix of a matrix is ​​equal to the product of the transpose of the matrix and the matrix itself; the inverse decomposition factor matrix of the regularized symmetric matrix is ​​the decomposition factor matrix of the inverse matrix of the regularized symmetric matrix, and the decomposition factor matrix is ​​a square root matrix or LDL T One of the L factor matrices of the decomposition.

[0010] In some embodiments, the current participant collaborates with the previous participant to use the column encrypted data transformation encryption matrix corresponding to their respective private original data to determine the product matrix of the column encrypted data transformation encryption matrices of the previous participant and the current participant or the transformed form of the product matrix; the current participant sends the inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by the column encrypted data transformation encryption matrix of the previous participant and the current participant or the transformed form of the inverse decomposition factor matrix to the subsequent participant in whole or in part; or, the current participant obtains and uses the product matrix or the transformed form of the column encrypted data transformation encryption matrix of the previous participant and the current participant, and collaborates with the previous participant and the label data owner to determine the multiplied encrypted linear regression coefficient vector, wherein the subsequent participant is the subsequent participant who provides the private original data, including: the current participant collaborates with the previous participant to use the column encrypted data transformation encryption matrix of the current participant and the transformed form of the regularized symmetric matrix of the matrix affected by the column encrypted data transformation encryption matrix of the current participant in whole or in part to the subsequent participant. The column encrypted data transformation encryption matrix of the preceding participant determines the product matrix or its transformation form of the two, and the product matrix or its transformation form is obtained by the current participant; the current participant uses the product matrix or its transformation form of the column encrypted data transformation encryption matrices of the preceding participant and the current participant to obtain the inverse decomposition factor matrix or the transformation form of the regularized symmetric matrix of the matrix affected by the column encrypted data transformation encryption matrices of the preceding participant and the current participant, and then sends all or part of the inverse decomposition factor matrix or the transformation form of the inverse decomposition factor matrix to the subsequent participant; when all the participants participate in the calculation to obtain the inverse decomposition factor matrix or the transformation form of the regularized symmetric matrix of the matrix affected by their respective column encrypted data transformation encryption matrices, the current participant then uses its own inverse decomposition factor matrix or the transformation form of the inverse decomposition factor matrix to collaborate with the preceding participant and the label data owner to determine the multiplication encrypted linear regression coefficient vector.

[0011] In some embodiments, the current participant obtains and utilizes the product matrix or its transformed form of the column encrypted data transformation encryption matrix of the previous participant and the current participant, and collaborates with the previous participant and the label data owner to determine the multiplied encrypted linear regression coefficient vector, including: after all the participants participate in the calculation to obtain the inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by their respective column encrypted data transformation encryption matrices or the transformed form of the inverse decomposition factor matrix, determining the multiplied encrypted linear regression coefficient vector, using the column encrypted data transformation encryption matrix of the previous participant and the current participant. The inverse decomposition factor matrix of the regularized symmetric matrix of the affected matrix, the column encrypted data transformation encryption matrix of the previous participant and the label product, and the column encrypted data transformation encryption matrix of the current participant and the label product; the column encrypted data transformation encryption matrix and label product of any participant is equal to the product of the transpose of the column encrypted data transformation encryption matrix of the corresponding participant and the label column vector of the label owner; the column encrypted data transformation encryption matrix and label product of any participant is determined by the collaboration between the arbitrary participant and the label owner based on a preset secure multi-party computing protocol or directly calculated.

[0012] In some embodiments, the multiplied encrypted linear regression coefficient vector is determined by using the inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by the column encrypted data transformation encryption matrix of the previous participant and the current participant, the product of the column encrypted data transformation encryption matrix of the previous participant and the label, and the product of the column encrypted data transformation encryption matrix of the current participant and the label. The multiplied encrypted linear regression coefficient vector is equal to the product of the inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by the column encrypted data transformation encryption matrix of the previous participant and the current participant and a first product vector. The first product vector is further determined by multiplying the transpose of the inverse decomposition factor matrix with a concatenated vector containing the product of the column encrypted data transformation encryption matrix of the previous participant and the label and the product of the column encrypted data transformation encryption matrix of the current participant and the label as sub-vectors. When the decomposition factor matrix is ​​a square root matrix, the first product vector is equal to the second product vector, or when the decomposition factor matrix is ​​an LDL matrix, the first product vector is equal to the second product vector. T Decomposed L factor matrix, the first product vector is equal to LDL T The product of the decomposed D factor matrix and the second product vector.

[0013] In some embodiments, there are m participants who provide their own private original data, m is an integer greater than or equal to 2; the current participant is the i-th participant, where i is any integer greater than or equal to 2 and less than or equal to m; the previous participant is the j-th participant, where j is any positive integer less than i; the subsequent participant is the k-th participant, where k is any integer greater than i and less than or equal to m, and the current participant cooperates with the previous participant to use the column encrypted data corresponding to their respective private original data to transform the encryption matrix to determine the product matrix of the column encrypted data transformation encryption matrix of the previous participant and the current participant or the transformation form of the product matrix, including: the i-th participant cooperates with the j-th participant to use the column encrypted data corresponding to their respective private original data to transform the encryption matrix to determine the product matrix of the column encrypted data transformation encryption matrix of the j-th participant and the i-th participant or the transformation form of the product matrix, where j takes any positive integer less than i.

[0014] In some embodiments, when the current participant is the i-th participant and i is less than or equal to m-1, the preceding participant is the i-1th participant, and the subsequent participant is the i+1th participant, the i-1th participant sends all or part of the inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by the column encrypted data transformation encryption matrix corresponding to the private original data of a total of i-1 participants from the 1st participant to the i-1th participant, or the transformed form of the inverse decomposition factor matrix to the i-th participant, and the i-th participant receives the inverse decomposition factor matrix or its transformed form; the i-1th participant The party cooperates with each of the participants from the first participant to the i-1th participant respectively, uses the column encrypted data transformation encryption matrix corresponding to the respective private original data to determine the product matrix or the transformation form of the column encrypted data transformation encryption matrix of the i-th participant and each of the i-1 participants, and then uses the product matrix or its transformation form to obtain and send to the i+1th participant all or part of the column encrypted data transformation encryption matrix corresponding to the private original data of the i-th participant. The inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by the matrix or the transformed form of the inverse decomposition factor matrix; when the current participant is the i-th participant and i is equal to m, the previous participant is the m-1-th participant, and the m-1-th participant sends all or part of the inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by the matrix or the transformed form of the inverse decomposition factor matrix to the m-th participant, and the m-th participant receives the inverse decomposition factor matrix or Its transformation form; the m-th participant cooperates with each of the m-1 participants from the 1st participant to the m-1th participant respectively, uses the column encrypted data corresponding to the respective private original data to transform the encryption matrix, determines the product matrix of the column encrypted data transformation encryption matrix of the m-th participant and each of the m-1 participants or the transformation form of the product matrix, and then uses the product matrix or its transformation form to cooperate with the label data owner and the m-1 participants from the 1st participant to the m-1th participant to determine the multiplied encrypted linear regression coefficient vector;The multiplied encrypted linear regression coefficient vector is equal to the product of the inverse decomposition factor matrix of the regularized symmetric matrix containing the matrix affected by the column encrypted data transformation encryption matrix of the m participants from the first participant to the m-th participant and the first product vector, the first product vector is further determined by the second product vector obtained by multiplying the transpose of the inverse decomposition factor matrix with the concatenated vector containing the column encrypted data transformation encryption matrix of the m participants from the first participant to the m-th participant and the label product as a sub-vector, when the decomposition factor matrix is ​​the square root matrix, the first product vector is equal to the second product vector, or when the decomposition factor matrix is ​​LDL; T Decomposed L factor matrix, the first product vector is equal to LDL T The product of the decomposed D factor matrix and the second product vector.

[0015] To achieve the above-mentioned purpose, the second aspect of the present application proposes a linear regression system based on privacy protection, and the linear regression system based on privacy protection is used to execute the linear regression method based on privacy protection described in the first aspect.

[0016] To achieve the above-mentioned purpose, the third aspect of the present application proposes a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program is running, it controls the device where the computer-readable storage medium is located to execute the privacy protection-based linear regression method as described in the first aspect.

[0017] The embodiments of the present application include at least the following beneficial effects: a participant who owns private original data encrypts his own original data matrix by himself, and no other participant knows the specific encryption method except the participant himself. After all participants have completed the encryption, the participants are arranged, and the first participant determines its own inverse decomposition factor matrix according to its own column encryption transformation encryption matrix obtained by encrypting the original data matrix. The first participant sends its own inverse decomposition factor matrix or its transformation form to the second participant. The second participant determines the inverse decomposition factor matrix or its transformation form including the influence of the column encryption transformation encryption matrices of the first participant and the second participant according to the inverse decomposition factor matrix of the first participant and its own column encryption transformation encryption matrix, and sends it to the third participant, and so on, until the last participant calculates the inverse decomposition factor matrix including the influence of the column encryption transformation encryption matrices of all participants from the first participant to the last participant. The last participant then collaborates with the owner of the label data to determine the multiplication of the encrypted linear regression coefficient vector by the inverse decomposition factor matrix of the last participant and the label data of the owner of the label data. Compared with the prior art, the present invention does not need to introduce trusted computing nodes and encryption service providers, nor does it need to implement very complex obfuscation circuits, thereby reducing the implementation complexity and meeting practical application needs.

[0018] Other features and advantages of the present application will be described in the following description, and partly become apparent from the description, or understood by practicing the present application. The purpose and other advantages of the present application can be realized and obtained by the structures specifically pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The accompanying drawings are used to provide further understanding of the technical solution of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the technical solution of the present application and do not constitute a limitation on the technical solution of the present application.

[0020] Figure 1 An optional flowchart of a privacy-preserving linear regression method provided in an embodiment of the present application. DETAILED DESCRIPTION

[0021] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0022] In the description of this application, “several” means one or more, “more” means more than two, “greater than”, “less than”, “exceed”, etc. are understood to exclude the number, and “above”, “below”, “within”, etc. are understood to include the number.

[0023] It should be noted that, although the functional modules are divided in the device schematic diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the device or the order in the flowchart. The terms "first", "second", etc. in the specification, claims or the above drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0024] It should be noted that in each specific embodiment of the present application, when it comes to the need to perform relevant processing based on data related to the characteristics of the target object such as target object attribute information or attribute information set, the permission or consent of the target object will be obtained first, and the collection, use and processing of these data will comply with relevant laws, regulations and standards. Among them, the target object can be a user. In addition, when the embodiment of the present application needs to obtain the target object attribute information, the target object's separate permission or separate consent will be obtained by means of a pop-up window or jumping to a confirmation page, etc., and after the separate permission or separate consent of the target object is clearly obtained, the necessary target object-related data for enabling the normal operation of the embodiment of the present application will be obtained.

[0025] In the existing vertical federated learning technology for linear regression, in order to ensure the data security of each data owner, it is often necessary to encrypt the service provider and the evaluator, or introduce obfuscation circuits to ensure the security of data calculation and interaction processes. However, the above methods are highly complex and not conducive to implementation in practical applications.

[0026] Based on this, the embodiment of the present application provides a linear regression method based on privacy protection, which can reduce the implementation complexity and meet the actual application needs.

[0027] The linear regression method based on privacy protection provided in the embodiment of the present application is specifically illustrated by the following embodiments. First, the linear regression method based on privacy protection in the embodiment of the present application is described.

[0028] The linear regression method based on privacy protection provided in the embodiment of the present application relates to the field of computer technology. The linear regression method based on privacy protection provided in the embodiment of the present application can be applied to a terminal, can be applied to a server side, or can be software running in a terminal or a server side. In some embodiments, the terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, etc.; the server side can be configured as an independent physical server, or a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; the software can be an application that implements a linear regression method based on privacy protection, etc., but is not limited to the above forms.

[0029] The present application can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, etc. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application can also be practiced in distributed computing environments, in which tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.

[0030] The secure inner product of two parties holding vectors x and y is adopted. That is, Party A holding x and Party B holding y can obtain the inner product of x and y through the secure inner product with privacy protection, and put the results of the inner product on Party A and Party B respectively. The inner product of vectors x and y is obtained by adding the results of Party A and Party B.

[0031] The secure inner product joint computation method supported by a trusted initializer relies on the trusted initializer not colluding with the data provider. The specific process is as follows:

[0032] Participants: The data provider 1 is called P1, the data provider 2 is called P2, and the trusted initializer is called TI.

[0033] Input: The column vector x owned by P1; the column vector y owned by P2.

[0034] Input: P1 gets s1 and P2 gets s2, and they satisfy s1 + s2 = <x, y>, where <x, y> represents the inner product of vectors x and y.

[0035] Scheme:

[0036] 1. TI generates random vectors a and b, and a random number r, and lets z = <a, b> - r. TI sends (a, r) to P1 and sends (b, z) to P2.

[0037] 2. P1 sends x + a to P2.

[0038] 3. P2 sends y - b to P1.

[0039] 4. P1 calculates its shard output s1 = <x, y - b> - r.

[0040] 5. P2 calculates its shard output s2 = <x + a, b> - z.

[0041] It is easy to verify that s1 + s2 = <x, y - b> - r + <x + a, b> - z = <x, y> - <x, b> - r + <x, b> + <a, b> - z == <x, y> + <a, b> - r – z. Substituting z = <a, b> - r into it, we can get s1 + s2 = <x, y>.

[0042] The above secure inner product joint calculation method is used to calculate A and b. It is easy to see that A = X T X + λI is a matrix symmetric about the diagonal, so only half of the non - diagonal terms need to be calculated. Generally, is locally calculated by user i who owns data X i ; while (i is not equal to j. Here, it is assumed that only the upper - triangular half is calculated, so i < j; actually, the lower - triangular part where i > j can also be calculated) needs to be jointly calculated by two parties. It can be jointly calculated by the first - participating user i using its own data X i and the second - participating user j using its own data X j , based on the privacy - preserving SMM algorithm, and can be obtained by transposing the calculation result. Among them, or The result is the addition sharding, and the result is saved by user i and user j respectively. The participants can restore the local calculated part of the matrix by splicing it according to the local calculation result, and fill the part without local calculation result with 0: Specifically, for Only user i has a result, and all other m-1 users fill this position with 0; Only user i and user j save the result of addition sharding, and all other m-2 users fill this position with 0. After the above processing, each participant has a matrix Ai, Ai represents the symmetric matrix A=X owned by user i T The i-th additive slice (i=1,2,…,m) in X+λI, corresponding to

[0043] Assume that the label vector y is in the mth user, then Quantity included (i=1,2,…,m-1) is obtained by two-party secure calculation by the i-th user and the m-th user, and the results are placed in the i-th user and the m-th user respectively, and the results of the i-th user and the m-th user are added together to obtain and The mth user uses his own data to obtain it. Each participant also fills the part without local calculation results with 0. After the above processing, each participant has the vector Indicates the number of The i-th additive slice (i=1,2,…,m) of

[0044]

[0045] The above participants can be called data providers P1, P2, ..., Pm, and each data provider Pi (i = 1, 2, ..., m) obtains A through the above steps. i and A i is the symmetric matrix A=X owned by user i T The ith additive slice in X+λI, and Owned by user i The i-th addition slice of .

[0046] The linear regression method based on privacy protection of the present invention is a method for providing data privacy protection for data owners based on an application scenario in which m (m ≥ 2) data owners providing private data and a label data owner owning label data jointly participate in vertical federated learning, wherein the m (m ≥ 2) data owners providing private original data are referred to as m participants. The above-mentioned label data owner can be referred to as the label owner, and the label owner can be one of the aforementioned m participants, or can be another participant other than the aforementioned m participants. The linear regression method based on privacy protection can be understood as firstly using a method of protecting the privacy of their respective private original data by the m participants participating in vertical federated learning, and jointly calculating the regularized symmetric matrix X of the concatenation matrix X of the original data matrices of the m participants. T The inverse matrix of X+λI (X T X+λI) -1 The decomposition factor matrix is ​​then used to calculate the target linear regression coefficient vector based on the theory of vertical federated learning linear regression coefficients. The process, in which the factorization matrix is ​​the square root matrix and LDL T The process of calculating the target linear regression coefficient vector can be understood as follows: m participants in vertical federated learning adopt the method of protecting their own private original data X i Privacy approach, collaborative computing meets FF T =(X T X+λI) -1 The matrix F, or satisfies LDL T =(X T X+λI) -1 The matrix L and matrix D of m participants are as follows: where matrix F is the regularized symmetric matrix X of the concatenation matrix X of the original data matrices of m participants. T The inverse matrix of X+λI (X T X+λI) -1 The square root matrix of , matrix L and matrix D represent the regularized symmetric matrix X of the concatenation matrix X of the original data matrices of m participants. T The inverse matrix of X+λI (X T X+λI) -1 LDL T The decomposition factor matrix contains the L factor matrix and the D factor matrix; then by Calculate the target linear regression coefficient vector Because FF T =(X T X+λI) -1 Substitution Can get On the other hand, we can also use the L factor matrix L and the D factor matrix D, Calculate the target linear regression coefficient vector

[0047] The embodiments of the present application are further described below in conjunction with the accompanying drawings.

[0048] like Figure 1 As shown, Figure 1 An optional flow chart of a linear regression method based on privacy protection provided in an embodiment of the present application, the linear regression method based on privacy protection can be executed by a server, or can also be executed by a terminal, or can also be executed by a server in cooperation with a terminal, the linear regression method based on privacy protection includes but is not limited to the following steps S11 to S12:

[0049] Step S11, the current participant receives the inverse decomposition factor matrix or the transformed form of the inverse decomposition factor matrix of the regularized symmetric matrix affected by the column encrypted data transformation encryption matrix corresponding to the private original data of the previous participant; the current participant cooperates with the previous participant to determine the product matrix or the transformed form of the product matrix of the column encrypted data transformation encryption matrix of the previous participant and the current participant using the column encrypted data transformation encryption matrix corresponding to their respective private original data; the current participant sends the inverse decomposition factor matrix or the transformed form of the inverse decomposition factor matrix of the regularized symmetric matrix affected by the column encrypted data transformation encryption matrix of the previous participant and the current participant in whole or in part to the subsequent participant;

[0050] Step S12, alternatively, the current participant obtains and utilizes the product matrix or its transformed form of the encryption matrix of the column encrypted data transformation of the previous participant and the current participant, and collaborates with the previous participant and the label data owner to determine the multiplied encrypted linear regression coefficient vector, wherein the subsequent participant is the subsequent participant who provides private original data.

[0051] The multiplication of the encrypted linear regression coefficient vector is equal to the product of the inverse decomposition factor matrix of the regularized symmetric matrix affected by the column encrypted data transformation encryption matrix of the previous participant and the current participant and the first product vector; the transformation form of any matrix satisfies, and the arbitrary matrix can be obtained by the transformation form without calculating other information.

[0052] It can be understood that the participant who owns the original data matrix encrypts his own original data matrix by himself. Except for the participant himself, no other participant knows the specific encryption method. After all participants have completed the encryption, the participants are arranged. The first participant determines its own inverse decomposition factor matrix according to its own column encryption transformation encryption matrix obtained by encrypting the original data matrix. The first participant sends or equivalently sends its own column encryption transformation encryption matrix and inverse decomposition factor matrix to the second participant. The second participant determines the inverse decomposition factor matrix including the influence of the column encryption transformation encryption matrix of the first and second participants according to the column encryption transformation encryption matrix and the inverse decomposition factor matrix of the first participant and its own column encryption transformation encryption matrix, and sends or equivalently sends the inverse decomposition factor matrix to the third participant, and so on, until the last participant, that is, the mth participant, calculates its own inverse decomposition factor matrix. The inverse decomposition factor matrix of the last participant includes the influence of the column encryption transformation encryption matrix corresponding to the original data matrices of all m participants. The mth participant then collaborates with the tag data owner and a total of m-1 participants from the first participant to the m-1th participant to determine a multiplication encrypted linear regression coefficient vector, which is equal to the product of an inverse decomposition factor matrix of a regularized symmetric matrix affected by the column encrypted data transformation encryption matrix of the m participants from the first participant to the mth participant and a vector. Compared with the prior art, the present invention does not need to introduce trusted computing nodes and encryption service providers, nor does it need to implement a very complex obfuscation circuit, thereby reducing the implementation complexity and meeting the actual application requirements.

[0053] First, an embodiment of the present invention is introduced, which is referred to as Embodiment 1 of the present invention. Embodiment 1 of the present invention includes step S11 and step S12, and step S11 includes step S111 and step S112, which are described as follows.

[0054] In the specific implementation process, step S11 includes step S111 to step S112, step S111 includes sub-steps S111-a to S111-e, and step S112 includes sub-steps S112-a to S112-f; sub-steps S111-a to S111-e included in step S111 are first introduced below:

[0055] Sub-step S111-a: This sub-step is an optional sub-step of adding mask columns. In this sub-step, the first participant adds one or more mask columns after its original data matrix X1. This is an optional step. If the first participant hopes to achieve a better privacy protection effect, he / she can choose this step. Usually, a single mask vector can achieve the privacy protection effect, and the first participant can also use multiple mask columns to achieve a better privacy protection effect by increasing the number of mask columns. The first participant generates a data matrix with added mask columns based on the original data matrix X1 composed of private original data and the added encrypted mask matrix Δ1. It is also referred to as the column-encrypted data matrix.

[0056] Specifically, the column-encrypted data matrix is ​​the data matrix with mask columns added The original data matrix X1 of the first participant has τ1 columns containing τ1 features of the original data, and the encrypted mask matrix Δ1 has The columns may be generated by the first party, and usually the column-added encryption mask matrix Δ1 is randomly generated. It means that after the original data matrix X1 with τ1 columns, there is an additional The column-added encryption mask matrix Δ1 is obtained to obtain the common Column-by-column encrypted data matrix Notice can be equal to 0, which is equivalent to the first party not adding an additional column encryption mask matrix Δ1 to encrypt the original data; in addition, it is usually allowed If it is equal to 1, it can have a good encryption effect. The column-added encrypted mask matrix Δ1 is actually a column-added encrypted mask column vector with only one column. When the first participant does not select this optional step of adding mask columns, then there is the following step.

[0057] Sub-step S111-b: This sub-step is an optional sub-step of multiplying the first mask matrix for encryption. In this sub-step, the first participant uses the matrix containing its own original data matrix X1 as the matrix of the sub-matrix (i.e., the column encrypted data matrix) Multiply the first mask matrix Ω1 on the left to get the product of the column encrypted data matrix and the first mask matrix Said The first mask matrix Ω is referred to as the column encryption data transformation encryption matrix of the first participant. i is used for encryption and is a reversible matrix. The first mask matrix Ω1 can be a unit matrix, then That is, this sub-step does not have any actual operation, which is equivalent to not selecting this step.

[0058] Sub-step S111-c: The first participant transforms the encryption matrix using its own column encryption data Obtain the square root matrix P1 of the inverse matrix of the regularized symmetric matrix of the first party's column encrypted data transformation encryption matrix, where P1 satisfies Here λ represents a scalar, called the regularization coefficient, which is usually a real number greater than or equal to zero, and represents the influence of the first mask matrix Ω1 used for the transformation; when the first mask matrix Ω1 is an orthogonal matrix, then the above It can be simplified to the common regularization matrix Here I represents the identity matrix. Note that the first participant can multiply P1 by an arbitrary orthogonal matrix Θ1 to obtain the updated P1=P1Θ1; on the other hand, this substep calculates the matrix that satisfies The matrix P1 can be used, and the specific calculation can be performed by various different methods. The square root matrix P1 of the inverse matrix of the regularized symmetric matrix of the encryption matrix of the column encrypted data transformation of the first participant mentioned above is a kind of decomposition factor matrix of the inverse matrix of the regularized symmetric matrix of the encryption matrix of the column encrypted data transformation of the first participant. In the following text, the square root matrix of the inverse matrix is ​​referred to as the inverse square root, and the decomposition factor matrix of the inverse matrix is ​​referred to as the inverse decomposition factor matrix. The inverse decomposition factor matrix is ​​the abbreviation of the inverse matrix of the decomposition factor matrix, and also the abbreviation of the decomposition factor matrix of the inverse matrix. Mathematically, the inverse matrix of a matrix decomposition factor matrix is ​​equal to the decomposition factor matrix of the inverse matrix of the matrix.

[0059] In this application document, (·) T represents the transpose of a real matrix (including vectors), or represents the conjugate transpose of a complex matrix (including vectors), as described above In and In Putting two matrices together, or a scalar and a matrix together, means multiplication, for example middle express take And λI represents the scalar λ multiplied by the identity matrix I.

[0060] In this application document, The symmetric matrix called the first party column encryption data transformation encryption matrix is ​​the first party column encryption data transformation encryption matrix Transpose Multiply the encrypted data of the first party column to transform the encrypted matrix The product obtained; It is called the regularized symmetric matrix of the first participant's column encryption data transformation encryption matrix, also referred to as the first regularized symmetric matrix of the first participant. Obviously, it is also the first regularized symmetric matrix of a single participant. It is called the inverse matrix of the regularized symmetric matrix of the first party's column encryption data transformation encryption matrix. The above regularized symmetric matrix In this case, λI is a matrix related to regularization. In some cases, λI can be in the form of A diagonal matrix of , where the entries on the diagonal can take different values.

[0061] In order to enhance the confidentiality, it is usually required that P1 is not a triangular matrix. If the first regularized symmetric matrix of the first participant is obtained by using the inverse Cholesky decomposition algorithm (It contains As a special case), the inverse matrix of the Cholesky decomposition matrix is ​​taken as P1, then P1 is a triangular matrix. At this time, an arbitrary orthogonal matrix Θ1 is usually used to right-multiply P1 to obtain the updated P1=P1Θ1, so that P1 is not triangular. In this step, in order to achieve the encryption effect, after the first participant obtains a P1, even if P1 is no longer a triangular matrix, an orthogonal matrix Θ1 known only to the first participant is used to right-multiply P1 to obtain the updated P1=P1Θ1.

[0062] Sub-step S111-d: When the first implementation of the sending step of this embodiment is adopted, the first participant sends the inverse decomposition factor matrix P1 of its first regularized symmetric matrix or the transformed form of the inverse decomposition factor matrix P1 to the second participant in this sub-step; or, when the second implementation of the sending step of this embodiment is adopted, the first participant sends P1 or its transformed form to the m-1 participants 2, 3...m in this sub-step. The transformed form of the inverse decomposition factor matrix P1 satisfies that the inverse decomposition factor matrix P1 can be obtained by the transformed form without calculating other information.

[0063] Sub-step S111-e: The control variable i corresponding to the above-mentioned first participant (i.e., the first data owner) is equal to 1. In this sub-step, first increase the value of i by 1; then, if the value of i is greater than m, enter step S12; if the value of i is less than or equal to m, enter step S112. As mentioned above, vertical federated learning has m participants who own their own private original data, also known as m data owners, where m is an integer greater than or equal to 1; in addition, there are label owners. This step is explained as follows: When i is greater than m, then the next step is mainly for the label data owner to join, and accordingly enter step S12; when i is less than or equal to m, then the next step is mainly for the i-th participant, i.e., the i-th data owner to join, and accordingly enter step S112.

[0064] In the present invention, the concatenation matrix of encrypted data of i (i is less than or equal to m) participants 1, 2, ..., i is It is referred to as the column encrypted data matrix of the i-th participant. Note that the column encrypted data matrix of the j-th participant (j is greater than or equal to 1 and less than or equal to i) is is the original data matrix X consisting of the original data privately owned by the jth participant j Add an additional column to the encrypted mask matrix Δ j The obtained value can be obtained without increasing the number of columns of the encrypted mask matrix Δ j Thus there is On the other hand, the column encrypted data matrix of the jth participant (j is greater than or equal to 1 and less than or equal to i) is Multiply the first mask matrix Ω of the jth participant on the left j Get the product of the column encrypted data matrix and the first mask matrix, that is, the column encrypted data transformation encryption matrix The present invention uses the concatenation matrix of the encrypted data transformation encryption matrix of the i (i is less than or equal to m) participants 1, 2, ..., i. It is referred to as the column encryption data transformation encryption matrix for a total of i participants.

[0065] It is easy to see that the previous step S111 used It can also be expressed as That is, the column encrypted data matrix of a common participant The previous step S111 used It can also be expressed as That is, the column encryption data of a participant is transformed into an encryption matrix

[0066] In this application document, It is called the symmetric matrix of the encrypted data transformation encryption matrix of the i-participating parties. It is called the regularized symmetric matrix of the column encryption data transformation encryption matrix of the i-participants, referred to as the first regularized symmetric matrix of the i-participants, where is along Ω [1:i] The diagonals of the matrices Ω1, Ω2, …, Ω i The resulting block diagonal matrix can also be expressed as Ω using the well-known MATLAB software blkdiag function [1:i] =blkdiag(Ω1,Ω2,…,Ω i ); because Ω1, Ω2, …, Ω i are the first mask matrices of participants 1, 2, ..., i, respectively. In this application document, Ω [1:i]It is called the block diagonal matrix composed of the first mask matrices of the i participants, referred to as the first mask matrix of the i participants. Obviously, when i is greater than or equal to 2, the above is the first regularized symmetric matrix of multiple parties. Correspondingly, It is the inverse matrix of the regularized symmetric matrix of the column encryption data transformation encryption matrix of the i-participating parties, referred to as the inverse matrix of the first regularized symmetric matrix of the i-participating parties.

[0067] It is easy to see that the column encryption data of the i participants is transformed into the encryption matrix The regularized symmetric matrix is the column encryption data transformation encryption matrix of any participant among the total i participants from the first participant to the i-th participant (j=1, 2, ..., i) as a matrix of submatrices The regularized symmetric matrix of . Regularized symmetric matrix middle, It is called the regularization term, and correspondingly, the regularized symmetric matrix yes The symmetric matrix Upper regularization term The regularization term can be derived as Regularization term The first mask matrix Ω containing any one of the i participants from the 1st participant to the i-th participant j The symmetric matrix The product of the preset regularization coefficient λ As a sub-matrix, where j = 1, 2, ..., i.

[0068] In this embodiment, the i-th participant equivalently calculates the inverse decomposition factor matrix P of the first regularized symmetric matrix of the i-th participants. i , it is satisfied The square root matrix of [1:i] is an orthogonal matrix, then the above can be simplified to When Ω [1:i] is an orthogonal matrix, then the above can be simplified to The above P i It is the square root matrix of the inverse matrix of the regularized symmetric matrix of the orthogonal transformation result of the column encrypted data of i participants. It is a kind of decomposition factor matrix of the inverse matrix of the regularized symmetric matrix of the orthogonal transformation result of the column encrypted data of i participants, which can be referred to as the inverse decomposition factor matrix of the first regularized symmetric matrix of i participants.

[0069] The following sub-steps S112-a to S112-h introduce that participant i (i=2, 3, ... m) receives P i-1 or its transformed form, using the received P i-1 or its transformed form, and its own data matrix X i , calculate P i method; when i is less than or equal to m-1, the participant i calculates P i After that, put P i or its transformed form to the next participant, i.e., participant i+1, or P i Relative P i-1 The added columns or their transformed forms are sent to the mi participants i+1, i+2, ..., m. In order to further protect the data privacy of participants 1, 2, ..., i-1, this embodiment includes an implementation method using a secure multi-party computing protocol, in which the encrypted matrix can be transformed when participant i does not receive the encrypted column data of participants 1, 2, ..., i-1. In the case of i .

[0070] In step S112, the i-th participant (i is greater than or equal to 2 and less than or equal to m), i.e., the i-th data owner, receives the inverse decomposition factor matrix P of the first regularized symmetric matrix of i-1 participants. i-1 ; The i-th participant uses his own column to encrypt the data matrix (Note Δ i can be an empty matrix, as a special case), put P i-1 Update to P i ; Here P i is the inverse factor matrix of the first regularized symmetric matrix of the above i participants. When i is less than or equal to m-1, the participant i calculates P i After that, put P i or its transformed form to the next participant, i.e., participant i+1, or P i Relative P i-1 The matrix composed of the added columns or its transformed form is sent to the mi participants i+1, i+2, ..., m. The transformed form of the above arbitrary matrix satisfies, and the arbitrary matrix can be obtained by the transformed form without calculating other information.

[0071] The above step S112 includes the following sub-steps S112-a to S112-h, a total of 6 sub-steps:

[0072] Sub-step S112-a: The i-th participant, i.e., the i-th data owner, obtains the inverse decomposition factor matrix P of the first regularized symmetric matrix of i-1 participants according to the received information. i-1 When the sending step of this embodiment adopts the first implementation mode, the i-th participant receives the P sent by the i-1-th participant. i-1 or its variant; when the sending step of this embodiment adopts the second implementation mode, the i-th participant receives the P sent by the participants 1, 2, ..., i-1 respectively or equivalently. i-1 A part of or its transformed form, thereby merging to obtain P i-1 .

[0073] Sub-step S112-b: This sub-step is an optional sub-step for adding mask columns. In this sub-step, the data matrix X i The i-th participant in his data matrix X i Adding one or more columns of masks at the end is an optional step. The data matrix X constructed by the i-th participant based on the private original data i And add the encrypted mask matrix Δ i The generated data matrix with added mask columns It is also referred to as the column-encrypted data matrix.

[0074] Specifically, the column-encrypted data matrix is ​​the data matrix with mask columns added The original data matrix X of the i-th participant i There is τ i The column contains τ i The original data of features is added with encrypted mask matrix Δ i have The columns can be generated by the i-th participant, usually adding columns to the encrypted mask matrix Δ i is randomly generated. Indicates that when there is τ i The columns of the original data matrix X i Added later Column-added encryption mask matrix Δ i To obtain common Column-by-column encrypted data matrix in Can be equal to 0, which is equivalent to the i-th participant not adding columns to the encryption mask matrix Δ i to encrypt the original data; in addition, it is usually If it is equal to 1, it can have a good encryption effect. Column-added encryption mask matrix Δ iIn fact, it is a mask column vector with only one column. If the i-th participant does not choose this optional step of adding a mask column, then there will be It is easy to see that the added column encryption mask matrix Δ i The number of items contained in each column is the same as the original data matrix X i Each column contains the same number of items; the added column encryption mask matrix Δ i Each column of can be generated by the i-th participant itself or obtained from a trusted node.

[0075] Sub-step S112-c: This sub-step is an optional sub-step of multiplying the first mask matrix for encryption. In this sub-step, the i-th participant uses the original data matrix X containing itself i Matrix as a submatrix (i.e. column-encrypted data matrix) Multiply the first mask matrix Ω of the i-th participant by the left i Get the product of the column encrypted data matrix of the i-th participant and the first mask matrix of the i-th participant Said The column encryption data transformation encryption matrix of the i-th participant is referred to as the first mask matrix Ω. i is used for encryption, as mentioned above, Ω i It is called the first mask matrix of the i-th participant, which is a reversible matrix generated by the i-th participant itself or obtained from a trusted node. The i-th participant can also use Ω i Encryption, which is equivalent to Ω i It is the unit matrix I, that is, this step does not have any actual operation, that is, this step is not selected.

[0076] Sub-step S112-d: transform the encryption matrix with column encrypted data The i-th participant transforms the encrypted matrix with column encrypted data The jth participant collaborates and determines the product matrix based on the preset secure multi-party computing protocol or by direct calculation. or its variant form, and the i-th participant obtains the above R j,i or its transformation, where j is greater than or equal to 1 and less than or equal to i-1. For each j greater than or equal to 1 and less than or equal to i-1, perform the operation of this step to obtain a total of i-1 product matrices R j,i or its variant, where j = 1, 2…i-1. is the column encryption data transformation encryption matrix of the jth participant Transpose Transform the encrypted matrix with the column encrypted data of the i-th party The product of the encrypted data transformation matrix of the j-th participant and the i-th participant is referred to as the product matrix of the encrypted data transformation matrix of the j-th participant and the i-th participant. (j=1,2…i-1), which can be expressed as a concatenation matrix It is easy to see that the above concatenation matrix V i is the column encryption data transformation encryption matrix for a total of i-1 participants Transpose Transform the encrypted matrix with the column encrypted data of the i-th party The product of It is referred to as the product matrix of the column encryption data transformation encryption matrix of the i-1 participants and the column encryption data transformation encryption matrix of the i-th participant, and the above i-1 participants are participants 1, 2…i-1. When the i-th participant obtains R j,i , then an easy-to-understand implementation method is that the i-th participant is R j,i The transformation form of R j,i , and then used for subsequent calculations.

[0077] It is easy to see that the above R j,i The transformation form can be That is, the column encryption data transformation encryption matrix of the i-th participant Transpose Transform the encrypted matrix with the column encrypted data of the jth party The product of , then the implementation method can be modified accordingly, which is an obvious deformation of the implementation method.

[0078] This step calculates The first implementation method or its variant form is to use secure multi-party computing protocols, especially secure inner product protocol; the secure inner product protocol refers to the confidentiality calculation when calculating the inner product of two vectors to ensure that the information of input data is not leaked. It is a well-known prior art and has many different implementation methods. Usually, the j-th participant and the i-th participant each obtain R through calculation. j,i or part of its transformed form, and then the jth participant sends the partial result obtained by himself to the ith participant, and the ith participant accumulates the two partial results to obtain R j,i or its transformation; in the above calculation process, the jth participant It does not need to be sent directly to the i-th participant, but the i-th participant It does not need to be sent directly to the jth party, although it usually includes and Alternatively, this sub-step can also be implemented by direct calculation, with the jth participant sending Send it to the i-th participant, and then the i-th participant uses his own and received Directly calculated or its variant.

[0079] Sub-step S112-e: The i-th participant uses the concatenation matrix V obtained in the previous sub-step i , that is, the product matrix of the column encryption data transformation encryption matrix of the i-1 participants and the column encryption data transformation encryption matrix of the i-th participant, and the calculation satisfies The square root matrix At this step, we can use an orthogonal matrix Θ i Right multiplication To Updated to When the first mask matrix Ω of the i-th participant i is an orthogonal matrix, the above Simplified to

[0080] If we use the inverse Cholesky decomposition to find the Then use an orthogonal matrix Θ i Right multiplication get Make In this step, in order to achieve the encryption effect, user i usually obtains a Afterwards, even if It is not triangular, and uses an orthogonal matrix Θ that only you know. i Multiply right by G i get

[0081] The square root matrix above is the inverse factorization matrix P of the regularized symmetric matrix of the column encrypted data transformation encryption matrix of the i-participants i The submatrix in the , that is, the inverse factor matrix P of the first regularized symmetric matrix of the i participants i The submatrices in As shown, where × represents a submatrix not involved in the current discussion.

[0082] Sub-step S112-f: In this sub-step, the i-th participant uses the inverse decomposition factor matrix P of the first regularized symmetric matrix of the i-th participants i The submatrix in And the product matrix V of the column encryption data transformation encryption matrix of the i-1 participants and the column encryption data transformation encryption matrix of the i-th participant i , the inverse factorization matrix P of the first regularized symmetric matrix of the i-1 participants i-1 Update to the inverse factorization matrix P of the first regularized symmetric matrix of the i participants i A specific implementation method may be that the i-th data owner calculates In P i-1 Add multiple columns to the right of In P i-1 Add a submatrix with all zeros just below P i-1 Add a submatrix to the lower right corner Thus, P i-1 Update to P i .

[0083] Sub-step S112-g: If the value of i is less than or equal to m-1, the i-th participant adopts the first implementation method of the sending step to send P i or its transformed form is sent to the next participant, that is, the i+1th participant, or the i-th participant adopts the second implementation method of the sending step to send P i Relative P i-1 The added non-zero columns are or its transformed form, and sent to participants i+1, i+2, ..., m, which are m-i+1 participants. The transformed form of the above arbitrary matrix satisfies, and the arbitrary matrix can be obtained by the transformed form without calculating other information.

[0084] Sub-step S112-h (sub-step of iterative control): If the value of i is less than or equal to m-1, increase the value of i by 1 and return to sub-step S112-a to start the next iteration; otherwise, when the value of i is equal to m, enter the following step S12.

[0085] In this application, (·) T represents the transpose of a real matrix (including vectors), or the conjugate transpose of a complex matrix (including vectors); two matrices put together, or a scalar and a matrix put together, represent multiplication. λI is a matrix related to regularization. In some cases, λI can take the form of The diagonal matrix of , where the entries on the diagonal can take different values; even λI can be an arbitrary matrix.

[0086] It is easy to see that in the above sub-steps S112-d, S112-e, S112-f and S112-g, the i-th participant cooperates with the j-th participant to use the column encrypted data transformation encryption matrix corresponding to their respective private original data to determine the product matrix of the column encrypted data transformation encryption matrix of the i-th participant and the j-th participant or its variant, where j is greater than or equal to 1 and less than or equal to i-1; the i-th participant obtains and uses the above R j,i Or its transformation form, the inverse factor matrix P of the first regularized symmetric matrix of the i-1 participants i-1 Update to the inverse factorization matrix P of the first regularized symmetric matrix of the i participants i When the value of i is less than or equal to m-1, the i-th participant puts P i or its transformed form to the next participant, the i+1th participant, or i Part of it is sent to several participants including the i+1th participant, that is, P i Relative P i-1 The added non-zero columns are sent to participants i+1, i+2, ..., m, which are m-i+1 participants.

[0087] Usually, after node 1 sends a piece of information to node 2, node 2 forwards it to node 3, which is also regarded as node 1 sending the piece of information to node 3; and the above-mentioned scenario of forwarding by one node can also be extended to the scenario of forwarding by multiple nodes, that is, after node 1 sends a piece of information to node 2a, it is forwarded by node 2b, node 2c and at least one node, and then forwarded to node 3 by the last node among the at least one node, which is also regarded as node 1 sending the piece of information to node 3. Correspondingly, in the above-mentioned step S11 including step S111 and step S112, considering the effect of m-1 iterations of step S112, the i-th participant, the j-th participant and the k-th participant are respectively regarded as the current participant, the previous participant and the subsequent participant, where i is any integer greater than or equal to 2 and less than or equal to m, j is any positive integer less than the said i, and k is any integer greater than i and less than or equal to m. It can be seen that the above-mentioned i-th participant, j-th participant and k-th participant satisfy the following relationship:

[0088] When sub-step S111-d and sub-step S112-g both adopt the first implementation method of the sending step of this embodiment, the j-th participant sends the inverse decomposition factor matrix or its transformation form of the regularized symmetric matrix of the column encrypted data transformation encryption matrix corresponding to the j-participant private original data from the first participant to the j-th participant, and when j is less than or equal to i-2, there are forwardings from participants j+1, j+2, ..., i-1; the i-th participant receives the above-mentioned inverse decomposition factor matrix or its transformation form sent by the j-th participant, and it is obviously the inverse decomposition factor matrix or its transformation form of the regularized symmetric matrix affected by the column encrypted data transformation encryption matrix corresponding to the j-participant private original data; the i-th participant cooperates with the j-th participant to use The column encrypted data transformation encryption matrix corresponding to the respective private original data is used to determine the product matrix or its transformation form of the column encrypted data transformation encryption matrix of the j-th participant and the i-th participant, and then the i-th participant uses the above product matrix or its transformation form to obtain and send to the k-th participant the inverse decomposition factor matrix or its transformation form of the regularized symmetric matrix of the column encrypted data transformation encryption matrix corresponding to the private original data of the i participants from the first participant to the i-th participant, which is the inverse decomposition factor matrix or its transformation form of the regularized symmetric matrix affected by the column encrypted data transformation encryption matrix of the j-th participant and the i-th participant, and when k is greater than or equal to i+2, there are forwardings from participants i+1, i+2, ..., k-1. If the effect of m-1 iterations of step S112 is not considered, and only one execution of step S112 is considered when i is any positive integer greater than or equal to 2 and less than or equal to m, then the above j is equal to i-1, and k is equal to i+1.

[0089] When both sub-step S111-d and sub-step S112-g adopt the second implementation method of the sending step of this embodiment, the j-th participant transforms the regularized symmetric matrix of the encryption matrix corresponding to the column encrypted data of the j-th participant's private original data from the first participant to the j-th participant into the inverse decomposition factor matrix of the encryption matrix or a part of its transformed form (i.e., P j Relative P j-1The i-th participant receives the above-mentioned inverse decomposition factor matrix or a part of its transformed form sent by the j-th participant, which is obviously a part of the inverse decomposition factor matrix or its transformed form of the regularized symmetric matrix affected by the column encrypted data transformation encryption matrix corresponding to the j-th participant's private original data; the i-th participant cooperates with the j-th participant, using the column encrypted data transformation encryption matrix corresponding to their respective private original data to determine the product matrix or its transformed form of the column encrypted data transformation encryption matrix of the j-th participant and the i-th participant, and then the i-th participant uses the above-mentioned product matrix or its transformed form to obtain and send to the k-th participant a part of the inverse decomposition factor matrix or its transformed form of the regularized symmetric matrix of the column encrypted data transformation encryption matrix corresponding to the private original data of the i participants from the first participant to the i-th participant (i.e., P i Relative P i-1 The added non-zero columns or their transformed forms) are the inverse factor matrix of the regularized symmetric matrix affected by the column encrypted data transformation encryption matrix of the j-th participant and the i-th participant, or a part of their transformed forms. If the effect of m-1 iterations of step S112 is not considered, and only one execution of step S112 is considered when i is any positive integer greater than or equal to 2 and less than or equal to m, then the above j is equal to i-1, and k is equal to i+1.

[0090] When the value of i is equal to m, the mth participant calculates P in the above sub-step S112-f. m In the next step S12, we have a label column vector that can be represented as The owner of the label data and the multiplication of the encrypted square root matrix P of m participants m And the encryption matrix of each column encryption data transformation m participants (i.e., m data owners) collaborate to calculate the multiplication of the encrypted linear regression coefficient vector Said It is to add the mask column Δ of each participant to the target linear regression coefficient vector i (i=1,2…m), and then right-multiply the column vector obtained by a multiplication encryption matrix, wherein the multiplication encryption matrix is ​​a block diagonal matrix Ω composed of the first mask matrices of m participants. [1:m] The inverse matrix

[0091] The steps of calculating the multiplication encrypted linear regression coefficient vector in the second embodiment of the present invention mainly include: the label data owner uses a private label column vector The label data is transformed into the encryption matrix with each column encrypted data m participants (i=1, 2…m) collaborate to calculate each (i=1, 2…m), and then calculate To obtain the multiplication of the encrypted linear regression coefficient vector

[0092] The step S12 includes step S121 to step S122.

[0093] Step S121: Have a label column vector that can be represented as The owner of the label data and the owner of the column encrypted data transform encryption matrix The i-th participant collaborates based on a preset secure multi-party computing protocol or direct calculation to determine Here, i is greater than or equal to 1 and less than or equal to m. For each i greater than or equal to 1 and less than or equal to m, perform this step to obtain a total of m Where i = 1, 2…m. is the column encryption data transformation encryption matrix of the i-th participant Transpose The label column vector of the owner of the label data The product of the encrypted data transformation matrix and the label of the i-th participant column is referred to as the product of the encrypted data transformation matrix and the label of the i-th participant column. This substep calculates the product of the encrypted data transformation matrix and the label of the i-th participant column. There are many ways to implement this. Here are some possible implementations:

[0094] Implementation method 1) Obtaining calculation results from the i-th specific node (i=1,2…m). We can use the secure multi-party computing protocol, especially the secure inner product protocol, to calculate The specific implementation method can be that the i-th participant and the label data owner each obtain a partial result, and then they send their respective partial results to the i-th specific node, and the i-th specific node merges the two partial results to obtain On the other hand, the i-th participant can also Send it to the owner of the label data, and then the owner of the label data uses the label column vector he owns and received By direct calculation, we can get Then send it to the i-th specific node. It is easy to see that when the i-th specific node is the i-th participant or the owner of the tag data, part of the above sending is sent to itself, which actually does not require any operation.

[0095] Implementation method 2) Calculation results (i=1,2…m) is divided into two parts, namely and Placed on two nodes called the i-th node A and the i-th node B respectively, the above and satisfy This implementation usually uses a secure multi-party computing protocol, especially a secure inner product protocol, to calculate And the calculation results Divide and By placing them at two nodes respectively, adding the calculation results placed at two nodes respectively, we can get The two nodes, ie, the i-th node A and the i-th node B, may be the label data owner and the i-th participant, or other two credible nodes.

[0096] The above m column vectors (i=1,2…m) can be represented as a concatenated column vector It satisfies That is, the encrypted data of each participant is transformed into the product of the encrypted matrix and the label Can be combined into the above concatenated column vector It is a column encryption data transformation encryption matrix for a total of m participants Transpose Column vector with labels The product of , referred to as the product of the column encrypted data transformation encryption matrix and the label of a total of m participants.

[0097] This step has a simple implementation method: when the implementation method 1 is adopted, and the i-th specific node is the owner of the label data, then all the calculation results (i=1,2…m) are all on the tag data owner side.

[0098] Step S122: Possess P m The m participants and the Several nodes (i=1,2…m) collaborate to calculate To obtain the multiplication of the encrypted linear regression coefficient vector It is easy to see that from the above You can get the above The multiplied encrypted linear regression coefficient vector = The inverse factorization matrix P of the regularized symmetric matrix of the column encrypted data transformation encryption matrix of m participants m With the second product vector The second product vector ξ is equal to the inverse factorization matrix P m Transpose Multiply the column encrypted data of m participants by transforming the encrypted matrix and the label product The results, among which It is a concatenated vector containing the encrypted data transformation matrix of each participant from the first participant to the mth participant and the product of the label as a subvector. There are many possible implementation methods for this step, and several of them are listed below:

[0099] Implementation method 1) When step S121 adopts implementation method 1, then in this step, having P m The m participants and the Each i-th specific node (i=1,2…m) cooperates to calculate With The i-th specific node that cooperates can be P m The mth participant, or all of them have at least part of P m All m participants, or all of them have at least some of P m At least two parties. Calculated It can be placed on one node or on multiple nodes.

[0100] let Then you can get And it can be expressed as

[0101] Right now Where Γ(:,i)(i=1,2…m) represents the Column to All columns of the column. Accordingly, the calculated One implementation method of placing them on multiple nodes can be: The amount (i=1, 2, ..., m) is placed in the i-th coefficient storage node, and the i-th coefficient storage node may be the i-th specific node, or a certain participant, or other credible node.

[0102] Implementation method 2) When step S121 adopts implementation method 2, then in this step, having P m The m participants each own part The two nodes (i=1,2…m), ie, the i-th node A and the i-th node B, cooperate to calculate Calculated It can be placed on one node or on multiple nodes.

[0103] Bundle Substitution Can get Accordingly, One implementation method of placing them on multiple nodes can be: The amount (i=1, 2, ..., m) is placed in the i-th coefficient storage node A, where the i-th coefficient storage node A may be the i-th node A, or a participant, or other credible node; The amount (i=1, 2...m) is placed in the i-th coefficient storage node B, and the i-th coefficient storage node B can be the i-th node B, or a participant, or other nodes.

[0104] From the above As you can see, It is obtained by calculating the product of three parts, and the three parts are: the inverse decomposition factor matrix P of the first regularized symmetric matrix of m participants (that is, the column encryption data transformation encryption matrix of m participants including the regularized symmetric matrix of transformation influence) m , the transpose of the above inverse factorization matrix And the product of the encrypted data transformation matrix and the label of the m participants It can also be done by having P m The m participants first calculate Then calculate

[0105] The multiplied encrypted linear regression coefficient vector and the target linear regression coefficient vector The relationship between That is, multiply the encrypted linear regression coefficient vector is the target linear regression coefficient vector Multiply the block diagonal matrix Ω composed of the first mask matrices of the m participants on the right [1:m] The inverse matrix The encrypted result. If a node needs to obtain the entire P m , then the following scenarios can be included: When the node is the mth participant, the node has obtained P in the previous sub-step m ; When the node is any one of the participants 1, 2, ..., m-1, then the node has only P m For some items in P m The items that the node does not have in the P are sent to the node, and the relevant participants may be the mth participant, or all other participants except the node, or at least two of all other participants except the node; when the node is a node other than the m participants 1, 2, ..., m, the relevant participants need to send P mThe relevant party may be the mth party, or all the m parties, i.e., parties 1, 2, ..., m, or at least two of the m parties. When the relevant parties include at least two parties, the above-mentioned parties each send P m A portion of the data is given to a certain node, which aggregates the data sent by several participants to obtain P m .

[0106] When step S121 adopts the simple implementation method, that is, all the calculation results (i=1,2…m) are all in the tag data owner, then this step can also be implemented in a simple way: that is, the owner P m The mth participant and the owner The label data owner cooperates to calculate And put Placed in the mth participant or the tag data owner. Placed on the mth participant, the owner of the label data will Sent to the mth participant and calculated by the mth participant Or, when Placed on the tag data owner, the mth participant will place P m Sent to the owner of the label data, and calculated by the owner of the label data

[0107] Calculate the above multiplication encrypted linear regression coefficient vector Afterwards, the subsequent steps of the above embodiment of the present invention achieve the following effect: if there are several participants among the participants 1 to m who use the column-increasing encryption mask matrix with non-zero columns, then the several participants are sequentially multiplied by the encrypted square root matrix P m Sum and multiply the encrypted linear regression coefficient vector At least partially eliminate the influence of its column-added encryption mask matrix Δ. When each participant using a non-zero column-added encryption mask matrix multiplies the encrypted linear regression coefficient vector The influence of the participant's added column encryption mask matrix Δ is at least partially eliminated, or when there is no participant using a non-zero column added column encryption mask matrix, then the most recently updated multiplied encrypted linear regression coefficient vector The participants or nodes The corresponding items of participant i (where i is greater than or equal to 1 and less than or equal to m) are sent to participant i, and the participant i uses the inverse matrix of its own private first mask matrix, that is, Decryption obtains the corresponding items in the target linear regression coefficient vector.

[0108] In the present invention, for simplicity of description, it is assumed that the column encrypted data matrix of the i-th participant is The columns are arranged in the following order: The front τ i The columns are the original data matrix X i ,then The columns are the encrypted mask matrix Δ i In practice The columns may also be arranged in other ways, and the specific implementation of the present invention may be slightly modified accordingly, which is well known to those skilled in the art.

[0109] Based on the implementation method of using square root decomposition for the inverse matrix of the regularized symmetric matrix in the first embodiment of the present invention, another commonly used LDL T The decomposed implementation method is the second embodiment of the present application. For example, the above FF T =(X T X+λI) -1 The matrix F is the inverse matrix (X T X+λI) -1 The square root matrix can be regarded as a symmetric matrix (X T X+λI) -1 A decomposition factor matrix, the corresponding symmetric matrix can also use another commonly used LDL T LDL in the process of breakdown T Factor matrix replacement, and LDL T The factor matrix includes a triangular L factor matrix and a diagonal D factor matrix. The L factor matrix can be expanded to a general square matrix, that is, the L factor matrix can be a non-triangular matrix or a triangular matrix, and the D factor matrix is ​​still a diagonal matrix. T The factor matrix can be slightly modified from the first embodiment of the present invention to obtain the LDL-based T The specific implementation of the factor matrix decomposition is referred to as Embodiment 2. The main difference between Embodiment 2 and Embodiment 1 is that the matrix sent by the i-th participant to the i+1-th participant is different, where i=1, 2, ..., m-1.

[0110] In the second embodiment, the participant i equivalently calculates the LDL of the inverse matrix of the first regularized symmetric matrix of the total i participants (that is, the regularized symmetric matrix of the column encrypted data transformation encryption matrix of the total i participants) T Decomposition factor matrix, including satisfying The L factor matrix and D factor matrix D i . The above is called the inverse L factor of the first regularized symmetric matrix of the i-participants; and the above Di It is called the inverse D factor of the first regularized symmetric matrix of i participants, or the D factor of i participants. When i is equal to 1, and D1 are also called the inverse L factor of the first regularized symmetric matrix of the first participant and the inverse D factor of the first participant, respectively.

[0111] Use satisfaction The L factor matrix L i and D factor matrix D i , represents the LDL of the inverse matrix of the second regularized symmetric matrix of i participants T Decomposition factor matrix, that is, L factor matrix L i and D factor matrix D i Then it can be deduced that the above matrix and L i satisfy That is, the matrix is the matrix L i Right multiply by a first reversible matrix The result after multiplication and encryption. Correspondingly, the matrix It is called the multiplication encryption L factor matrix of i participants, which is a kind of multiplication encryption factor matrix of i participants; correspondingly, the matrix It is called the multiplication encryption L factor matrix of the first participant, and can also be called the multiplication encryption L factor matrix of 1 participant. It is a kind of multiplication encryption decomposition factor matrix of 1 participant.

[0112] Since some steps in Example 3 are repeated in Example 2, the entire implementation process will be described in detail below based on Step S11 and Step S12 in Example 2 by introducing the specific modifications required relative to Example 2.

[0113] In the aforementioned second embodiment, step S11 includes steps S111 and S112, and step S12 includes steps S121 and S122. In order to modify the second embodiment to an embodiment of a factor matrix decomposition method based on the LDLT decomposition method, steps S111 and S112 included in step S11 need to be modified to steps S111' and S112' described below, respectively, and step S122 included in step S12 needs to be modified to step S122' described below, and step S121 included in step S12 remains unchanged. The following introduces steps S111' and S112' included in step S11 obtained by the above modification, and step S122' included in step S12.

[0114] Step S111': In order to obtain step S111', sub-steps S111-a, S111-b and S111-e of step S111 of embodiment 2 remain unchanged, while sub-steps S111-c and S111-d are modified into sub-steps S111'-c and sub-steps S111'-d, respectively. Accordingly, step S111' includes the above-mentioned sub-steps S111-a, S111-b, S111'-c, S111'-d and S111-e in sequence, wherein sub-steps S111-c' and S111-d' are as follows:

[0115] Sub-step S111'-c: In the first implementation of this sub-step, the first participant uses the well-known LDLT decomposition technique to obtain of and D1, where is the inverse L factor of the first regularized symmetric matrix of the first participant, and D1 is the inverse D factor of the first regularized symmetric matrix of the first participant; when the first reversible matrix Ω1 is an orthogonal matrix, then the above can be simplified to Accordingly, is called the inverse L factor of the first regularized symmetric matrix of the first participant, and D1 is called the inverse D factor of the first regularized symmetric matrix of the first participant. Alternatively, in the second implementation of this sub-step, the first participant continues to use sub-step S111-c of the second embodiment to obtain a matrix satisfying The inverse factor matrix P1 of the first regularized symmetric matrix of the first participant is used, and a diagonal matrix D1 is set with any positive number on the diagonal line, and then D1 and P1 are used to calculate

[0116] It can be verified that satisfy Right now is the multiplication encryption L factor matrix of the first participant. When the first participant does not have high requirements for the protection of his privacy data, he can also let is equal to the identity matrix I, so we have

[0117] Sub-step S111'-d: When the first implementation method of the sending step of this embodiment is adopted, the first participant in this sub-step converts the multiplication encryption L factor matrix of the first participant into and the D factor matrix D1 of the first participant or their transformed forms are sent to the second participant; or, when the second implementation method of the sending step of this embodiment is adopted, the first participant in this sub-step sends and D1 or their transformed forms are sent to participants 2, 3…m, which are m-1 participants. and D1 in transformed form, and other forms of D1, and the receiver can use only and other forms of D1 to obtain and D1, for example, sending and One of these three forms.

[0118] Step S112': In order to obtain step S112', step S112 of embodiment 2 includes sub-steps S112-a, S112-b, S112-c, S112-d, S112-e, S112-f, S112-g and S112-h, sub-steps S112-b, S112-c, S112-d and S112-h remain unchanged, while sub-steps S112-a, S112-e, S112-f and S112-g are modified to sub-steps S112'-a, S112'-e, S112'-f and S112'-g respectively. Accordingly, step S112' includes the above-mentioned sub-steps S112'-a, S112-b, S112-c, S112-d, S112'-e, S112'-f, S112'-g and S112-h in sequence, wherein sub-steps S112'-a, S112'-e, S112'-f and S112'-g are as follows:

[0119] Sub-step S112-a: The i-th participant, i.e., the i-th data owner, obtains the multiplication encryption L factor matrix of a total of i-1 participants based on the received information and the D-factor matrix D of i-1 participants i-1 When the sending step of this embodiment adopts the first implementation mode, the i-th participant receives the i-1-th participant's and D i-1 or their transformation forms; when the sending step of this embodiment adopts the second implementation mode, the i-th participant receives the and D i-1 or part of their transformed forms, thereby merging to obtain and D i-1 .

[0120] Sub-step S112'-e: The i-th participant uses the concatenation matrix V obtained in the previous sub-step i , that is, the product of the column encryption data transformation encryption matrix of the i-1 participants and the column encryption data transformation encryption matrix of the i-th participant, and the calculation satisfies LDL T Factorization, including L factor and D factor Above is the inverse L factor of the first regularized symmetric matrix of the i participants The submatrix in is the inverse D factor of the first regularized symmetric matrix of the i-participants i When the first reversible matrix Ω i is an orthogonal matrix, the above Simplified to

[0121] The above It is the inverse L factor of the first regularized symmetric matrix of the encrypted data transformation matrix of the i-participating parties. The submatrix in It is the inverse D factor of the first regularized symmetric matrix of the encrypted data transformation matrix of the i-participating parties. i The sub-matrix in .

[0122] The first implementation of this substep uses the well-known LDL T Decomposition technology. The second implementation of this sub-step follows the sub-step S112-e of the second embodiment to calculate the The square root matrix Then set the diagonal matrix to be any positive number. And calculate

[0123] Sub-step S112'-f: In this sub-step, the i-th participant uses the inverse L factor of the first regularized symmetric matrix of the i-th participants The submatrix in The inverse D factor D of the first regularized symmetric matrix of i participants i The submatrix in And the product V of the column encryption data transformation encryption matrix of the i-1 participants and the column encryption data transformation encryption matrix of the i-th participant i , the inverse L factor of the first regularized symmetric matrix of the i-1 participants Update to the inverse L factor of the first regularized symmetric matrix of the i participants And the inverse D factor D of the first regularized symmetric matrix of the i-1 participants i-1 Update to the inverse D factor D of the first regularized symmetric matrix of the i participants i A specific implementation method may be that the i-th data owner D i-1 Updated to D i On the other hand, the i-th data owner calculates relatively The number of non-zero columns added is Then through Bundle Updated to That is Add multiple columns to the right of exist Add a submatrix with all zeros just below Add a submatrix to the lower right corner Thus Updated to

[0124] Sub-step S112'-g: If the value of i is less than or equal to m-1, the i-th participant adopts the first implementation method of the sending step to and D i or their transformed forms are sent to the next participant, that is, the i+1th participant, or the i-th participant adopts the second implementation method of the sending step to relatively The added non-zero columns are or its variants, and D i Relative D i-1 Increased diagonal matrix or its transformed form, and sent to participants i+1, i+2, ..., m, which are m-i+1 participants. and D i The transformation form of and D i other forms, and the recipient may not use other information, by and D i Other forms of recovery and D i , for example, sending and One of these three forms.

[0125] In this embodiment, step S12 includes steps S121 and S122', wherein step S121 is the same as step S121 in the second embodiment, and step S122' is described in detail below:

[0126] Step S122': Possess and D m The m participants and the Several nodes (i=1,2…m) collaborate to calculate To obtain the multiplication of the encrypted linear regression coefficient vector Above is the inverse L factor of the first regularized symmetric matrix of m participants, and the above D m is the inverse D factor of the first regularized symmetric matrix of m participants. It is easy to see that the multiplication of the encrypted linear regression coefficient vector =Equal to the inverse factor matrix (i.e. inverse L factor) of the regularized symmetric matrix of the column encrypted data transformation encryption matrix of m participants The inverse D factor of the regularized symmetric matrix is m , and the second product vector The second product vector is equal to the inverse factorization matrix Transpose Multiply the encrypted data of m participants by transforming the encrypted matrix and the product of the label The results, among which It is a concatenated vector containing the product of the encrypted data transformation encryption matrix of each participant column from the 1st participant to the mth participant and the label as a sub-vector.

[0127] There are many possible implementations of this step, and several of them are listed below:

[0128] Implementation method 1) When step S121 adopts implementation method 1, then in this step, and D m The m participants and the Each i-th specific node (i=1,2…m) cooperates to calculate With The i-th specific node that cooperates can be and D m The mth party, or all of them have at least part and D m All m parties, or all of them have at least some and D m At least two parties. Calculated It can be placed on one node or on multiple nodes.

[0129] let Then you can get And it can be expressed as

[0130] Right now Where Γ(:,i)(i=1,2…m) represents the Column to All columns of the column. Accordingly, the calculated One implementation method of placing them on multiple nodes can be: The amount (i=1, 2, ..., m) is placed in the i-th coefficient storage node, and the i-th coefficient storage node may be the i-th specific node, or a certain participant, or other node.

[0131] Implementation method 2) When step S121 adopts implementation method 2, then in this step, and D m The m participants each own part The two nodes (i=1,2…m), ie, the i-th node A and the i-th node B, cooperate to calculate Calculated It can be placed on one node or on multiple nodes.

[0132] Bundle Substitution Can get Accordingly, One implementation method of placing them on multiple nodes can be: The amount (i=1, 2, ..., m) is placed in the i-th coefficient storage node A, where the i-th coefficient storage node A may be the i-th node A, or a participant, or other node; The amount (i=1, 2...m) is placed in the i-th coefficient storage node B, and the i-th coefficient storage node B can be the i-th node B, or a participant, or other nodes.

[0133] The multiplied encrypted linear regression coefficient vector and the target linear regression coefficient vector The relationship between That is, multiply the encrypted linear regression coefficient vector is the target linear regression coefficient vector Right multiplication The encrypted result.

[0134] When a specific node needs to obtain and D m , the following scenarios can be used: When the specific node is the mth participant, the specific node has obtained and D m ; When the specific node is any of the participants 1, 2, ..., m-1, then the specific node only has and D m For some items in and D m The items that are not in the specific node in the list are sent to the specific node, and the relevant participants may be the mth participant, or all other participants except the specific node, or at least two of all other participants except the specific node; when the specific node is a node other than the m participants 1, 2, ..., m, the relevant participants need to send and D m Sent to a specific node, the above-mentioned relevant participant can be the mth participant, or all the m participants, that is, participants 1, 2..., m, or a number of participants that are not less than two of all the m participants. When the relevant participants include a number of participants that are not less than two, the above-mentioned several participants each send and D m A part of it is given to a specific node, which aggregates the data sent by several participants and obtains and D m .

[0135] When step S121 adopts the simple implementation method, that is, all the calculation results (i=1,2…m) are all on the tag data owner side, then this step can also be implemented in a simple way: and D m The mth participant and the owner The label data owner cooperates to calculate And put Placed in the mth participant or the tag data owner. Placed on the mth participant, the owner of the label data will Sent to the mth participant and calculated by the mth participant Or, when Placed on the tag data owner, the mth participant will and D m Sent to the owner of the label data, and calculated by the owner of the label data

[0136] Calculate the above multiplication encrypted linear regression coefficient vector Afterwards, the effect achieved by the subsequent steps of the above embodiment of the present invention is: if there are several participants using the column-increasing encryption mask matrix with non-zero columns among the participants 1 to m, the several participants are sequentially D m Sum and multiply the encrypted linear regression coefficient vector At least partially eliminate the influence of its column-added encryption mask matrix Δ. When each participant using a non-zero column-added encryption mask matrix multiplies the encrypted linear regression coefficient vector The influence of the participant's added column encryption mask matrix Δ is at least partially eliminated, or when there is no participant using a non-zero column added column encryption mask matrix, then the most recently updated multiplied encrypted linear regression coefficient vector The participants or nodes The corresponding items of participant i (where i is greater than or equal to 1 and less than or equal to m) are sent to participant i, and the participant i uses the inverse matrix of its own private first mask matrix, that is, Decryption obtains the corresponding items in the target linear regression coefficient vector.

[0137] It can be understood by those skilled in the art that Figure 1 The technical solutions shown in the figure do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than those shown in the figure, or a combination of certain steps, or different steps.

[0138] Those skilled in the art will appreciate that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices may be implemented as software, firmware, hardware, or a suitable combination thereof.

[0139] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0140] It should be understood that in the present application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the objects associated before and after are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0141] The preferred embodiments of the present invention are described above with reference to the accompanying drawings, but the scope of the rights of the present invention is not limited thereto. Any modification, equivalent substitution and improvement made by a person skilled in the art without departing from the scope and essence of the present invention should be within the scope of the rights of the present invention.

Claims

1. A linear regression method based on privacy protection, characterized in that: include: The current participant receives the inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by the column encrypted data transformation encryption matrix corresponding to the private original data of the previous participant or the transformation form of the inverse decomposition factor matrix; the current participant cooperates with the previous participant to determine the product matrix of the column encrypted data transformation encryption matrix of the previous participant and the current participant or the transformation form of the product matrix by using the column encrypted data transformation encryption matrix corresponding to their respective private original data; the current participant sends the inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by the column encrypted data transformation encryption matrix of the previous participant and the current participant or the transformation form of the inverse decomposition factor matrix to the subsequent participant in whole or in part; or the current participant obtains and uses the product matrix or the transformation form of the column encrypted data transformation encryption matrix of the previous participant and the current participant to cooperate with the previous participant and the label data owner to determine the multiplication encrypted linear regression coefficient vector, wherein the subsequent participant is the participant who subsequently provides the private original data; The multiplied encrypted linear regression coefficient vector is equal to the product of the inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by the column encrypted data transformation encryption matrix of the previous participant and the current participant and the first product vector, and the first product vector is determined by the transpose of the inverse decomposition factor matrix and the product of the column encrypted data transformation encryption matrix of the previous participant and the label and the column encrypted data transformation encryption matrix of the current participant and the label; the transformation form of the matrix satisfies, and the matrix can be calculated by the transformation form without other information.

2. The privacy-preserving linear regression method according to claim 1, characterized in that: The product matrix of the column encrypted data transformation encryption matrices of the previous participant and the current participant is equal to the product of the transpose of the column encrypted data transformation encryption matrix of the previous participant and the column encrypted data transformation encryption matrix of the current participant. The product matrix of the column encrypted data transformation encryption matrices of the previous participant and the current participant, or its transformed form, is obtained by direct calculation by the previous participant in collaboration with the current participant or by determination based on a preset secure multi-party computing protocol.

3. The privacy-preserving linear regression method according to claim 1, characterized in that: The column encrypted data transformation encryption matrix corresponding to the private original data of any participant among the participants is equal to the product of the column encrypted data matrix of the arbitrary participant and the first mask matrix of the arbitrary participant; wherein the column encrypted data matrix of the arbitrary participant is composed of the original data matrix formed by the private original data of the arbitrary participant as a sub-matrix, and the column encrypted data matrix includes each sub-column in the original data matrix and the mask column generated by the arbitrary participant itself or obtained from the trusted node, and the number of items contained in the mask column is equal to the number of items in the original data matrix of the arbitrary participant itself. The number of items contained in each column of the data matrix is ​​the same; and the first mask matrix of any participant is a reversible matrix, which is generated by the arbitrary participant itself or obtained from a trusted node; wherein the multiplication of the encrypted linear regression coefficient vector is equal to adding the influence of the mask column of each participant to the target linear regression coefficient column vector, and then right-multiplying the column vector obtained by the block diagonal matrix composed of the first mask matrices of each participant, wherein the block diagonal matrix contains the inverse matrix of the first mask matrix of each participant as a submatrix located on the diagonal of the block diagonal matrix.

4. The privacy-preserving linear regression method according to claim 3, characterized in that: Including the column encrypted data transformation encryption matrix influence of the previous participant is equivalent to including the column encrypted data transformation encryption matrix of the previous participant as a sub-matrix, and including the column encrypted data transformation encryption matrix influence of each of the previous participant and the current participant is equivalent to including the column encrypted data transformation encryption matrix of the previous participant and the column encrypted data transformation encryption matrix of the current participant as sub-matrices; Wherein, the regularized symmetric matrix of a matrix is ​​the sum of the symmetric matrix of the matrix plus the regularization term, wherein the regularization term is a matrix containing the product of the symmetric matrix of the first mask matrix of the relevant participant and the preset regularization coefficient as a submatrix; the symmetric matrix of a matrix is ​​equal to the product of the transpose of the matrix and the matrix itself; the inverse decomposition factor matrix of the regularized symmetric matrix is ​​the decomposition factor matrix of the inverse matrix of the regularized symmetric matrix, and the decomposition factor matrix is ​​a square root matrix or LDL T One of the L factor matrices of the decomposition.

5. The privacy-preserving linear regression method according to claim 1, characterized in that: The current participant cooperates with the previous participant, and uses the column encrypted data transformation encryption matrix corresponding to their respective private original data to determine the product matrix of the column encrypted data transformation encryption matrix of the previous participant and the current participant or the transformation form of the product matrix; the current participant sends the inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by the column encrypted data transformation encryption matrix of the previous participant and the current participant in whole or in part to the subsequent participant; or the current participant obtains and uses the product matrix or the transformation form of the column encrypted data transformation encryption matrix of the previous participant and the current participant, and cooperates with the previous participant and the label data owner to determine the multiplication encrypted linear regression coefficient vector, wherein the subsequent participant is the participant who subsequently provides the private original data, including: The current participant cooperates with the previous participant to determine a product matrix or a transformed form thereof by using the column encrypted data transformation encryption matrix of the current participant and the column encrypted data transformation encryption matrix of the previous participant, and the product matrix or the transformed form thereof is obtained by the current participant; The current participant uses the product matrix or its transformed form of the column encrypted data transformation encryption matrix of the previous participant and the current participant to obtain the inverse decomposition factor matrix or the transformed form of the inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by the column encrypted data transformation encryption matrix of the previous participant and the current participant, and then sends all or part of the inverse decomposition factor matrix or the transformed form of the inverse decomposition factor matrix to the subsequent participant; When all the participants participate in the calculation to obtain the inverse decomposition factor matrix or the transformed form of the inverse decomposition factor matrix of the regularized symmetric matrix containing the matrix affected by the encryption matrix of the respective column encrypted data transformation, the current participant then uses its own inverse decomposition factor matrix or the transformed form of the inverse decomposition factor matrix to collaborate with the previous column participant and the label data owner to determine the multiplied encrypted linear regression coefficient vector.

6. The privacy-preserving linear regression method according to claim 4, characterized in that: The current participant obtains and utilizes the product matrix or its transformed form of the encrypted matrix of the column encrypted data transformation of the previous participant and the current participant, and cooperates with the previous participant and the label data owner to determine the multiplied encrypted linear regression coefficient vector, including: When all the participants participate in the calculation to obtain the inverse decomposition factor matrix of the regularized symmetric matrix containing the matrix affected by their respective column encrypted data transformation encryption matrices or the transformed form of the inverse decomposition factor matrix, determine the multiplied encrypted linear regression coefficient vector, using the inverse decomposition factor matrix of the regularized symmetric matrix containing the matrix affected by the respective column encrypted data transformation encryption matrices of the previous participant and the current participant, the product of the column encrypted data transformation encryption matrix of the previous participant and the label, and the product of the column encrypted data transformation encryption matrix of the current participant and the label; the product of the column encrypted data transformation encryption matrix and the label of any participant is equal to the product of the transpose of the column encrypted data transformation encryption matrix of the corresponding participant and the label column vector of the label owner; the product of the column encrypted data transformation encryption matrix and the label of any participant is determined or directly calculated by the collaboration between the any participant and the label owner based on a preset secure multi-party computing protocol.

7. The privacy-preserving linear regression method according to claim 6, characterized in that: The multiplied encrypted linear regression coefficient vector is determined by using the inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by the column encrypted data transformation encryption matrix of the previous participant and the current participant, the product of the column encrypted data transformation encryption matrix of the previous participant and the label, and the product of the column encrypted data transformation encryption matrix of the current participant and the label. The multiplied encrypted linear regression coefficient vector is equal to the product of the inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by the column encrypted data transformation encryption matrix of the previous participant and the current participant and a first product vector. The first product vector is further determined by multiplying the transpose of the inverse decomposition factor matrix with a concatenated vector containing the product of the column encrypted data transformation encryption matrix of the previous participant and the label and the product of the column encrypted data transformation encryption matrix of the current participant and the label as sub-vectors. When the decomposition factor matrix is ​​a square root matrix, the first product vector is equal to the second product vector, or when the decomposition factor matrix is ​​an LDL matrix, the first product vector is equal to the second product vector. T Decomposed L factor matrix, the first product vector is equal to LDL T The product of the decomposed D factor matrix and the second product vector.

8. The privacy-preserving linear regression method according to claim 7, characterized in that: There are m participants who provide their own private original data, m is an integer greater than or equal to 2; the current participant is the i-th participant, where i is any integer greater than or equal to 2 and less than or equal to m; the previous participant is the j-th participant, where j is any positive integer less than i; the subsequent participant is the k-th participant, where k is any integer greater than i and less than or equal to m, and the current participant cooperates with the previous participant to transform the encryption matrix of the column encrypted data corresponding to their own private original data, and determines the product matrix of the column encrypted data transformation encryption matrix of the previous participant and the current participant or the transformation form of the product matrix, including: The i-th participant cooperates with the j-th participant to determine the product matrix of the column encrypted data transformation encryption matrices of the j-th participant and the i-th participant or the transformation form of the product matrix by using the column encrypted data transformation encryption matrix corresponding to their respective private original data, where j takes any positive integer less than i.

9. The privacy-preserving linear regression method according to claim 8, characterized in that: When the current participant is the i-th participant and i is less than or equal to m-1, the preceding participant is the i-1-th participant, and the subsequent participant is the i+1-th participant, the i-1-th participant sends the inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by the column encrypted data transformation encryption matrix corresponding to the private original data of the i-1 participants from the 1st participant to the i-1-th participant, or a transformed form of the inverse decomposition factor matrix, in whole or in part, to the i-th participant, and the i-th participant receives the inverse decomposition factor matrix or its transformed form; The i-th participant cooperates with each of the participants from the first participant to the i-1th participant respectively, and uses the column encrypted data transformation encryption matrix corresponding to the respective private original data to determine the product matrix or the transformation form of the column encrypted data transformation encryption matrix of the i-th participant and each of the i-1 participants, and then uses the product matrix or the transformation form to obtain and send to the i+1th participant in whole or in part the inverse decomposition factor matrix or the transformation form of the inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by the column encrypted data transformation encryption matrix corresponding to the private original data of the i-th participant; When the current participant is the i-th participant and i is equal to m, the preceding participant is the m-1-th participant, and the m-1-th participant sends the inverse decomposition factor matrix of the regularized symmetric matrix of the matrix affected by the column encrypted data transformation encryption matrix corresponding to the private original data of the m-1 participants from the first participant to the m-1-th participant or the transformed form of the inverse decomposition factor matrix in whole or in part to the m-th participant, and the m-th participant receives the inverse decomposition factor matrix or its transformed form; the m-th participant cooperates with each of the m-1 participants from the first participant to the m-1-th participant, respectively, and uses the column encrypted data transformation encryption matrix corresponding to their respective private original data to determine the product matrix of the column encrypted data transformation encryption matrix of the m-th participant and each of the m-1 participants or the transformed form of the product matrix, and then uses The product matrix or its transformed form cooperates with the label data owner and the m-1 participants from the 1st participant to the m-1th participant to determine the multiplied encrypted linear regression coefficient vector; the multiplied encrypted linear regression coefficient vector is equal to the product of the inverse decomposition factor matrix of the regularized symmetric matrix containing the matrix affected by the column encrypted data transformation encryption matrix of the m participants from the 1st participant to the mth participant and the first product vector, the first product vector is further determined by the second product vector obtained by multiplying the transpose of the inverse decomposition factor matrix with the concatenated vector containing the column encrypted data transformation encryption matrix of the m participants from the 1st participant to the mth participant and the label product as a sub-vector, when the decomposition factor matrix is ​​the square root matrix, the first product vector is equal to the second product vector, or when the decomposition factor matrix is ​​LDL T Decomposed L factor matrix, the first product vector is equal to LDL T The product of the decomposed D factor matrix and the second product vector.

10. A linear regression system based on privacy protection, characterized in that: The privacy protection-based linear regression system is used to execute the privacy protection-based linear regression method described in any one of claims 1 to 9.

11. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored computer program; wherein, when the computer program is run, it controls the device where the computer-readable storage medium is located to execute the privacy protection-based linear regression method as described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Correlation coefficient calculation method and system and computer storage medium

    CN116304515A

  • Privacy protection-based linear regression method and system, storage medium and equipment

    CN118195024A

  • Linear regression method based on privacy protection

    CN118313481A

  • Data privacy protection method based on multi-party security computing

    CN119180056A

  • A distributed multi-party security model training framework for privacy protection

    EP3602379A2

Cited By

  • Linear regression method based on privacy protection

    WO2026148843A1