Privacy security leakage risk assessment method for large-scale data
By establishing a model of the data environment and privacy protection requirements, quantifying privacy leakage risks, quantifying the correlation of mutual information and dynamically adjusting the noise intensity, the problem of insufficient privacy protection intensity in large-scale data environments is solved, and efficient privacy leakage risk assessment and protection is achieved.
Patent Information
- Application Number
- CN202510503247.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-22
- Publication Date
- 2025-05-23
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing privacy protection technologies face performance bottlenecks and insufficient privacy protection strength in large-scale data environments, especially in the case of multiple query requests, it is difficult to effectively evaluate the joint impact of multiple query requests on data privacy.
By establishing a data environment and privacy protection requirements model, the privacy leakage risk is quantified based on differential privacy theory, the mutual information in information theory is used to quantify the correlation between the data set and query results, and a dynamic noise adjustment mechanism is used to adjust the noise intensity in real time according to the optimal balance between privacy risks and computing resources.
It realizes accurate assessment and protection of privacy leakage risks in a large-scale data environment, dynamically adjusts the intensity of privacy protection, avoids the risk of privacy leakage caused by insufficient allocation of static privacy budgets, and improves the accuracy and efficiency of privacy protection.
Smart Images

Figure CN120030600A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of big data privacy protection, and in particular to a privacy security leakage risk assessment method for large-scale data. Background Art
[0002] In today's big data era, data privacy protection has become an important issue in data management and data processing. With the surge in data volume, especially in the fields of medicine, finance, social media, etc., the risk of leakage of personal privacy data has increased significantly. Existing privacy protection technologies, such as differential privacy and homomorphic encryption, provide certain guarantees for privacy protection, but in large-scale data environments, these technologies still face problems such as performance bottlenecks and insufficient privacy protection.
[0003] Existing privacy protection technologies generally rely on static privacy budget allocation and fixed protection strategies. For example, differential privacy technology prevents sensitive information leakage by adding noise. However, this method often adopts a unified privacy budget allocation and fails to fully consider the privacy protection needs of different data nodes. Specifically, some highly sensitive data may not be able to provide sufficient privacy protection due to a low privacy budget; while for some low-sensitivity data nodes, an excessively high privacy budget may cause a waste of computing resources and reduce system efficiency.
[0004] As data queries become increasingly complex, most privacy protection schemes in the existing technology only focus on the privacy leakage assessment of a single query operation. Especially in the case of multiple query requests, the interaction of multiple queries may lead to a higher risk of privacy leakage. It is difficult for existing technologies to effectively evaluate the joint impact of multiple query requests on data privacy. For example, although differential privacy can introduce noise into each query result, its independence and simplicity make it impossible to fully consider the relationship between query requests. In a multi-query scenario, simple noise injection is not enough to resist complex privacy leakage threats, resulting in the risk of privacy leakage being underestimated. Summary of the invention
[0005] In view of the shortcomings of the existing technology, the present invention provides a privacy security leakage risk assessment method for large-scale data, which solves the problem that privacy protection technology generally relies on static privacy budget allocation and fixed protection strategies.
[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: A privacy security leakage risk assessment method for large-scale data, comprising the following steps:
[0007] Establish a data environment and privacy protection requirements model, model the data of each data node in a large-scale data environment, and clarify the privacy protection requirements of each data node;
[0008] Privacy leakage risk assessment, based on differential privacy theory, quantifies the privacy leakage risk of each data node and uses privacy risk assessment methods to calculate the probability of privacy leakage;
[0009] Privacy protection models in information theory quantify the correlation between data sets and query results through mutual information, reduce the risk of data leakage, and determine the noise intensity;
[0010] The dynamic noise adjustment mechanism adjusts the noise intensity in real time according to the optimal balance between privacy risks and computing resources, ensuring a reasonable ratio between privacy protection requirements and computing overhead.
[0011] Preferably, the method further comprises:
[0012] Establish and solve game theory models, use game theory models to simulate the privacy protection strategy between distributed nodes, and solve the optimal noise intensity through games to achieve the optimal balance between privacy protection and data utility of each node;
[0013] Nash equilibrium solution and global optimal strategy determination: Under the framework of game theory, the collaborative privacy protection strategy between nodes is solved through Nash equilibrium to optimize the privacy protection mechanism of distributed data systems;
[0014] Resource sharing and collaborative optimization: In a distributed data environment, through resource sharing and collaborative game between nodes, we can optimize privacy protection strategies, reduce computing resource consumption, and maximize data utility.
[0015] Real-time feedback and adjustment of privacy leakage risks: Based on real-time privacy risk assessment results and computing resource status, the privacy protection strategy is dynamically adjusted to ensure the continuous minimization of privacy leakage risks.
[0016] Preferably, the privacy leakage risk assessment step includes the following contents:
[0017] Based on the differential privacy framework, the probability distribution analysis of the query results of each data node is performed to evaluate the risk of privacy leakage of each data node;
[0018] Using the privacy budget model, determine the maximum privacy leakage risk allowed for each data node;
[0019] Using the probability tolerance function, the privacy risk assessment results are compared with the privacy protection requirements of the nodes to ensure that the privacy protection requirements of each node are met.
[0020] Preferably, the privacy protection model in information theory is implemented by the following steps:
[0021] Calculate the mutual information between the data set and the query results to quantify the correlation between the data set and the query results;
[0022] According to the relationship between the mutual information value and the data utility function, the noise intensity is adjusted to achieve a balance between privacy leakage and data utility;
[0023] Through additive noise control, the information transfer between the data set and the query results is adjusted to ensure that the probability of privacy leakage is lower than the set threshold.
[0024] Preferably, the dynamic noise adjustment mechanism achieves the adjustment of the optimal noise intensity by:
[0025] Based on the privacy protection loss function and computational cost function, the privacy protection requirements and computational resource consumption of each node are dynamically calculated;
[0026] Design an optimization objective function to balance privacy protection and computational overhead, and optimize the objective function to achieve the optimal balance between privacy protection and computational resources;
[0027] The noise intensity is adjusted according to the optimization results to ensure a reasonable balance between privacy protection and computing resources and minimize the risk of privacy leakage.
[0028] Preferably, the game theory model includes the following contents:
[0029] Establish a utility function for each data node, considering the trade-off between node privacy protection and data utility;
[0030] Through game theory analysis, the optimal privacy protection strategy for each node is solved, so that each node can choose the best privacy protection strategy when the strategies of other nodes are known;
[0031] The game process of multiple nodes is simulated to obtain the global optimal privacy protection strategy to ensure the optimal balance between the system's privacy protection requirements and data utility.
[0032] Preferably, the Nash equilibrium solving step includes the following contents:
[0033] Based on the game theory model, the utility function of each node is calculated. The utility function takes into account the balance between privacy protection and computing resources.
[0034] During the game, the privacy protection strategy of the node is adjusted to maximize the utility of the node and ensure that the privacy protection strategy between nodes does not change, that is, to achieve Nash equilibrium;
[0035] Through multiple rounds of game optimization, the globally optimal privacy protection strategy is obtained to ensure that the privacy protection needs of all nodes are balanced globally.
[0036] Preferably, the resource sharing and collaborative optimization steps include the following:
[0037] Nodes share computing resources and collaboratively optimize privacy protection strategies, thereby reducing computing resource consumption;
[0038] Use the collaborative game model to analyze the collaborative behavior between nodes and calculate the optimal privacy protection strategy after each node shares resources;
[0039] By sharing computing resources and collaborative optimization, the globally optimal privacy protection strategy is implemented in a distributed environment, maximizing the privacy protection efficiency and reducing the system computing overhead.
[0040] Preferably, the real-time feedback and adjustment steps of the privacy leakage risk include the following:
[0041] Monitor the risk of privacy leakage in the data processing process in real time, and adjust the privacy protection strategy by calculating the difference between the current privacy leakage probability and the preset risk threshold;
[0042] Adjust the noise intensity based on the real-time assessment results of privacy risks to ensure that the risk of privacy leakage is always within an acceptable range;
[0043] Combined with the real-time computing resource status of the node, the noise intensity is dynamically adjusted to ensure a reasonable balance between privacy protection effect and computing resource consumption.
[0044] A system for large-scale data privacy security leakage risk assessment, comprising:
[0045] Data collection module, used to collect data from each node in a large-scale data environment;
[0046] The privacy risk assessment module is used to assess the data privacy risk of each node, calculate the probability of privacy leakage, and evaluate the strength of privacy protection;
[0047] The noise control module is used to dynamically adjust the noise intensity and control the privacy protection level based on the privacy risk assessment results;
[0048] Game analysis module, used to simulate the game behavior between nodes and determine the privacy protection strategy by solving the game equilibrium;
[0049] The resource sharing and collaborative optimization module is used to collaboratively optimize privacy protection strategies and reduce computing overhead by sharing computing resources.
[0050] The present invention provides a privacy security leakage risk assessment method for large-scale data. It has the following beneficial effects:
[0051] 1. The present invention adopts a privacy leakage risk assessment method based on differential privacy and dynamic allocation of privacy budget, achieving the technical effect of accurately assessing and protecting privacy leakage risks in a large-scale data environment. Compared with the prior art solution that relies solely on static privacy protection strategies, the present invention can dynamically allocate privacy budgets according to the sensitivity and access frequency of data nodes, and flexibly adjust the privacy protection strength, thereby effectively avoiding the privacy leakage risk caused by insufficient static privacy budget allocation. This dynamic adjustment mechanism not only improves the accuracy of privacy protection, but also effectively reduces the possibility of privacy leakage while ensuring data query efficiency, solving the defect of insufficient privacy protection strength of traditional solutions in large-scale data environments.
[0052] 2. The present invention further quantifies the risk of privacy leakage by introducing the mutual information theory, significantly improving the accuracy of privacy leakage assessment. Compared with the prior art solution that only protects through the noise mechanism of differential privacy, the present invention can comprehensively consider the correlation between the query results and the original data, and accurately assess the risk of data privacy leakage under the interaction of multiple query requests. This improvement effectively solves the problem that the traditional solution cannot comprehensively assess the risk of privacy leakage caused by multiple query combinations. Through the calculation of the mutual information, sensitive data that may be inferred by attackers through multiple query requests is also effectively prevented, further enhancing the strength of data privacy protection.
[0053] 3. The present invention adopts a dynamic noise adjustment mechanism based on real-time privacy leakage monitoring, so that privacy protection can flexibly respond to changes in data access frequency in practical applications, thereby improving the privacy protection efficiency and scalability of the system. Compared with the solutions in the prior art that cannot adjust the privacy protection strategy in real time, the present invention can automatically optimize privacy protection measures when the data access mode changes through real-time monitoring of privacy leakage risks, thereby minimizing the waste of computing resources while ensuring privacy security. This real-time adjustment mechanism greatly improves the efficiency and flexibility of privacy protection in large-scale data environments, and avoids the shortcomings of insufficient or excessive protection of traditional static solutions in dynamic data access scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] Figure 1 It is a flow chart of the present invention. DETAILED DESCRIPTION
[0055] The following will be combined with the drawings in the specification of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0056] Please see attached Figure 1 :
[0057] A privacy security leakage risk assessment method for large-scale data includes the following steps:
[0058] Establish a data environment and privacy protection requirements model, model the data of each data node in a large-scale data environment, and clarify the privacy protection requirements of each data node;
[0059] Privacy leakage risk assessment, based on differential privacy theory, quantifies the privacy leakage risk of each data node and uses privacy risk assessment methods to calculate the probability of privacy leakage;
[0060] Privacy protection models in information theory quantify the correlation between data sets and query results through mutual information, reduce the risk of data leakage, and determine the noise intensity;
[0061] Dynamic noise adjustment mechanism, which adjusts the noise intensity in real time according to the optimal balance between privacy risk and computing resources, ensuring a reasonable balance between privacy protection requirements and computing overhead
[0062] Data environment model construction, privacy leakage risk assessment, privacy protection in information theory, dynamic noise adjustment, game theory optimization and collaborative game, resource sharing and collaborative optimization, and real-time feedback and adjustment of privacy leakage risks. The following is a detailed description of each implementation step with examples.
[0063] Construction of data environment and privacy protection demand model
[0064] In a large-scale data environment, data nodes have different privacy protection requirements, so we first need to establish a data environment and privacy protection requirements model. Assume that a data system contains multiple distributed nodes, each of which stores different types of data, which may include personal sensitive information, company financial data, etc. Different data nodes have different requirements for privacy protection, and the specific requirements depend on factors such as the sensitivity of the data, the access frequency of the node, and the degree of data sharing.
[0065] In order to quantify the privacy protection requirements of each node, the following method can be used:
[0066] Data classification and sensitivity assessment: Classify the data of each node, for example, divide the data into high sensitivity, medium sensitivity and low sensitivity categories. Highly sensitive data may include personal identity information, health data, etc. These data require stronger privacy protection measures.
[0067] Privacy budget allocation: Based on the sensitivity of the data, a privacy budget allocation model is used to allocate a privacy budget to each node. The privacy budget is used to quantify the priority of data protection and determine the maximum privacy leakage risk that each data node can bear.
[0068] Privacy protection demand model: The core of the privacy protection demand model is to determine the privacy protection strength of each node through the privacy budget. According to actual needs, privacy protection needs can be met through different encryption algorithms, differential privacy methods, etc.
[0069] Privacy Leakage Risk Assessment
[0070] Privacy leakage risk assessment is the core part of the present invention. To ensure data privacy security, the privacy leakage risk of data nodes must be comprehensively assessed. The present invention uses a differential privacy framework to quantify the privacy leakage risk of data nodes.
[0071] Differential privacy is a technology that protects privacy by adding noise to data query results. In this invention, the specific implementation steps of the differential privacy framework are as follows:
[0072] Data analysis and privacy assessment,For each data node, a differential privacy algorithm is used to assess the privacy leakage risk.,First, the privacy leakage probability of each data node needs to be determined.,Specifically, for a query result, differential privacy ensures that even if the attacker knows part of the data set, the query result will not change significantly, thus ensuring privacy.
[0073] Privacy leakage probability calculation: According to the definition of differential privacy, for each data node Data , privacy leakage risk It can be expressed as ;
[0074] in Budget for privacy, is the tolerance of the leakage probability. In this way, the system can quantify the risk of privacy leakage and adjust the privacy budget and privacy protection strength of each node as needed.
[0075] Privacy-preserving models in information theory
[0076] In order to further enhance privacy protection, the present invention combines the mutual information model in information theory, quantifies the correlation between the data set and the query results, and adjusts the noise intensity according to the mutual information amount, thereby reducing the risk of privacy leakage.
[0077] Calculation of mutual information: Mutual Information Reflects the data set With the query results In the present invention, the mutual information value between the data set and the query result is used to evaluate the risk of privacy leakage. The higher the mutual information, the greater the possibility that the query result leaks the original data.
[0078] Noise intensity adjustment: By adding noise to the query results, the mutual information can be reduced, thereby reducing the risk of data leakage. In this process, the intensity of noise addition should be adjusted according to the mutual information value to ensure that the risk of privacy leakage is controlled within a predetermined range.
[0079] Dynamic noise adjustment mechanism
[0080] In a large-scale distributed data environment, privacy protection mechanisms must be flexible and dynamically adjustable to adapt to changing data access patterns and privacy protection requirements. This paper proposes a dynamic noise adjustment mechanism to balance privacy protection and computing resource consumption.
[0081] Compute the privacy protection loss function: Based on the privacy protection strength and computational overhead, design a loss function to measure the balance between privacy protection and computational overhead. The loss function contains two parts: privacy leakage risk and computational resource consumption. By optimizing the loss function, the optimal balance between privacy protection and computational overhead can be found.
[0082] Dynamically adjust noise intensity: Dynamically adjust noise intensity based on real-time privacy leakage assessment results and computing resource status. Noise intensity should be adjusted as privacy protection requirements and computing resources change to ensure that the risk of privacy leakage is minimized while avoiding excessive consumption of computing resources.
[0083] Game Theory Optimization and Cooperative Games
[0084] In order to further optimize the privacy protection strategy, the present invention adopts a game theory model to simulate the interaction between distributed data nodes and determine the optimal privacy protection strategy for each node.
[0085] Node utility function design: Design a utility function for each data node, which takes into account the trade-off between the privacy protection and data utility of the node. The utility function includes factors such as privacy protection strength, data utility, and computing resource consumption.
[0086] Game equilibrium solution: The optimal privacy protection strategy for each node is solved through the game theory model. In this process, each node selects the optimal strategy based on the strategies of other nodes, thereby optimizing the global privacy protection strategy. The solution of game theory can be achieved through methods such as Nash equilibrium.
[0087] Resource sharing and collaborative optimization
[0088] In a large-scale distributed data environment, computing resource sharing and collaborative optimization between nodes are the key to improving the efficiency of privacy protection. The present invention realizes resource sharing through a collaborative game model, optimizes privacy protection strategies, and reduces computing resource consumption.
[0089] Resource sharing model: Nodes can collaboratively optimize privacy protection strategies by sharing computing resources (e.g., computing power, storage space, etc.). Through sharing, nodes can reduce computing overhead and achieve the optimal configuration of privacy protection strategies.
[0090] Collaborative game optimization: Using the collaborative game model, nodes can adjust their privacy protection strategies based on shared resources to achieve the global optimal strategy. Collaborative game optimization can calculate the optimal privacy protection strategy of nodes and apply it by simulating multiple rounds of games.
[0091] Real-time feedback and adjustment of privacy leakage risks
[0092] The present invention provides a real-time feedback mechanism for privacy leakage risk so as to make dynamic adjustments during the implementation of the privacy protection strategy.
[0093] Real-time risk monitoring: Assess the risk of privacy leakage through real-time monitoring of data queries and calculate the difference between the current privacy leakage probability and the preset risk threshold.
[0094] Real-time adjustment: According to the real-time assessment results of privacy leakage risks, the noise intensity is adjusted to ensure that the privacy protection effect always meets the preset privacy security requirements. At the same time, combined with the computing resource status of the node, the noise intensity is dynamically adjusted to ensure a reasonable ratio between privacy protection and computing resources.
[0095] Summarize
[0096] Through the detailed description of the above implementation methods, the present invention provides a large-scale data privacy security leakage risk assessment method, which combines differential privacy, information theory, game theory and collaborative optimization technology, and can effectively assess the risk of privacy leakage and dynamically adjust the privacy protection strategy. At the same time, methods such as dynamic noise adjustment and real-time feedback mechanism are adopted to enable the privacy protection strategy to adapt to the ever-changing data access mode and privacy requirements. The technical solution of the present invention has a wide range of application prospects, and is particularly suitable for privacy protection and risk assessment in distributed data environments.
[0097] Step: Construction of data environment and privacy protection requirements model
[0098] In the present invention, the steps mainly involve building a privacy protection demand model for a large-scale data environment. The goal of the model is to quantify the privacy protection needs of different data nodes and allocate corresponding privacy budgets according to the sensitivity of the data and the privacy needs of the nodes. The privacy protection demand model provides a basis for subsequent privacy leakage risk assessment, noise intensity adjustment, and game optimization. In a large-scale data environment, due to the diversity of data types, node functions, privacy leakage risks, and computing resources, the differentiated characteristics of privacy protection needs need to be fully considered.
[0099] In this embodiment, the steps for constructing the privacy protection requirement model are as follows:
[0100] First, for each data node, classify it according to the data type and sensitivity level. These data nodes may include sensitive data nodes, non-sensitive data nodes, and data nodes containing public information. According to the sensitivity of the data, it can be divided into high sensitivity, medium sensitivity, and low sensitivity categories. High-sensitivity data may include personal identity information, health information, financial data, etc., which have very strict requirements for privacy protection; while low-sensitivity data may include public statistics or anonymized data, and its privacy protection requirements are relatively low.
[0101] Specifically, when building a privacy protection demand model, it is first necessary to conduct a sensitivity assessment on the data of each data node and allocate a privacy budget for it based on the assessment results.
[0102] The privacy budget is an important parameter for measuring the strength of privacy protection in this invention. It reflects the upper limit of the privacy leakage risk that each node can bear. The allocation of the privacy budget is not only related to the sensitivity level of the data, but also closely related to factors such as the frequency of data access, the computing power of the node, and the degree of data sharing. The reasonable allocation of the privacy budget helps to determine the subsequent privacy protection strategy, such as the intensity of noise in the differential privacy mechanism and the selection of privacy protection strategies in the game theory model.
[0103] To this end, this embodiment uses the following two methods to quantify the privacy budget of each node:
[0104] Data sensitivity assessment: Data is divided into different categories according to its sensitivity, and each category of data nodes has a different upper limit when allocating privacy budgets. For example, the privacy budget of highly sensitive data is higher, while the privacy budget of low-sensitivity data is relatively lower. Highly sensitive data may need to be protected by strict differential privacy or encryption algorithms, while low-sensitivity data can be guaranteed by weaker privacy protection measures.
[0105] Node access frequency: Data nodes with higher access frequencies usually store more important data, and these nodes require more privacy protection budget to prevent frequent query operations from exposing too much sensitive information. Conversely, nodes with lower access frequencies have relatively lower requirements for privacy protection.
[0106] In one possible implementation, the privacy budget allocation process can be modeled according to the following formula:
[0107]
[0108] in, Representative The privacy budget of each node is Represents the weight coefficient, which reflects the relative importance of various factors (such as sensitivity, access frequency, computing power, etc.). Representative The node in The score on each factor. and rating Make adjustments based on the specific application scenario and characteristics of the data node.
[0109] It should be noted that the construction of a privacy protection demand model is not just a static allocation of privacy budget, but a dynamic adjustment process.
[0110] Specifically, when the access pattern of data nodes changes or new sensitive data is introduced, the allocation of privacy budget should be dynamically adjusted according to the new situation. For example, if the data access frequency of a node suddenly increases, the privacy budget of the node needs to be appropriately increased to strengthen the intensity of privacy protection and prevent excessive disclosure of sensitive information. On the contrary, if the data access frequency of some nodes decreases or the sensitivity of the node data decreases, its privacy budget can be reduced accordingly to reduce the consumption of computing resources.
[0111] As an option, the dynamic adjustment of the privacy budget can also be optimized based on the following feedback mechanism:
[0112] Real-time privacy leakage monitoring: By monitoring the privacy leakage risk of data nodes in real time, insufficient privacy protection can be discovered in a timely manner and the corresponding privacy budget can be adjusted. For example, when executing a query operation, the correlation between the query result and the original data is analyzed in real time. If the risk of privacy leakage is found to increase, the privacy budget can be increased in a timely manner, otherwise it can be reduced.
[0113] Collaborative optimization between nodes: In a multi-node distributed system, collaborative optimization between nodes also plays an important role. For example, when multiple nodes jointly process data, the privacy budget of each node can be dynamically adjusted according to the overall privacy leakage risk through collaborative game to optimize the overall privacy protection of the system.
[0114] In some embodiments, the dynamic adjustment of the privacy budget also involves consideration of the following factors:
[0115] Computing resource constraints: The increase in privacy protection strength is usually accompanied by an increase in computing overhead. Therefore, when allocating the privacy budget, it is necessary to comprehensively consider the computing resources of the nodes to ensure that the privacy protection needs are maximized without exceeding the computing resource limits.
[0116] Data sharing degree: If the data of a node needs to be shared with other nodes, the privacy budget should be increased accordingly to prevent the risk of privacy leakage during data sharing.
[0117] For example, the following is the allocation process of a node’s privacy budget:
[0118] Assuming that the data of a node belongs to a highly sensitive category and the node is frequently accessed, according to the privacy budget allocation formula, its privacy budget will be relatively high and may be set to If the data of this node needs to be shared with other nodes, its privacy budget may be further increased to ensure privacy protection during data sharing. For example, after the access pattern changes, the privacy budget of this node can be adjusted to , to increase protection.
[0119] It can be understood that the privacy protection requirement model of the present invention can effectively support the implementation of various privacy protection technologies.
[0120] Such as differential privacy, homomorphic encryption, etc. Through the reasonable allocation and dynamic adjustment of the privacy budget, different data nodes can choose appropriate privacy protection technologies according to their privacy protection needs, and make dynamic adjustments according to actual conditions, so as to maximize the protection of user privacy and ensure that the risk of privacy leakage is within an acceptable range.
[0121] Step 1: Privacy Leakage Risk Assessment
[0122] The core task of this step is to conduct privacy leakage risk assessment on each data node in a large-scale data environment. In this process, the system calculates the privacy leakage probability of each data node and quantifies the privacy information that may be exposed when the data node performs data query and analysis, thereby providing a basis for subsequent privacy protection measures (such as differential privacy mechanism, noise adjustment, etc.).
[0123] The present invention adopts a privacy leakage risk assessment method based on the differential privacy framework. Differential privacy is a commonly used privacy protection mechanism that introduces noise into the query results so that the inquirer cannot obtain detailed information about a single data entry from the query results, thereby effectively reducing the risk of privacy leakage. By introducing appropriate noise, it can be ensured that even if the attacker has information about part of the data set, he cannot infer other unexposed data.
[0124] In this embodiment, the steps of privacy leakage risk assessment are as follows:
[0125] First, consider each data node Assume that there are multiple data nodes in the system, and the query of each data node may involve some sensitive information. ,The system will calculate the probability of privacy leakage by evaluating the ,privacy information that may be exposed in the query results.
[0126] Specifically, the risk of privacy leakage This can be modeled using the basic principles of differential privacy. The key idea of differential privacy is to introduce noise so that the query results are sufficiently indistinguishable from the changes in any data entry. Data query results in ,Its privacy leakage risk can be expressed as;
[0127]
[0128] in, Indicates The privacy leakage risk of each node is is the privacy budget of differential privacy, is the tolerance for the probability of query leakage. It should be noted that and The balance between A higher value means stronger privacy protection, but may also lead to more noise introduction, thus affecting the accuracy of the query.
[0129] As an option, in practice, the calculation of privacy leakage risk does not rely solely on a single query request. ;
[0130] Instead, the risk of privacy leakage can be further quantified by joint analysis of multiple query requests. For example, when multiple query requests frequently access the same data set, a single query may cause less privacy leakage, but the combination of multiple queries may cause a higher risk of privacy leakage. Therefore, in the present invention, the privacy leakage risk assessment not only considers the impact of a single query, but also comprehensively considers the interaction of multiple query requests.
[0131] In this case, the privacy leakage risk can be expressed as:
[0132]
[0133] in, and Respectively The privacy budget and leakage probability of a query request, is the total number of query requests involved in the node. In this way, the overall impact of multiple query requests on privacy can be more comprehensively evaluated.
[0134] Specifically, the privacy leakage risk assessment method of the present invention not only considers the factors of differential privacy,
[0135] Other avenues of information leakage are also considered. For example, through techniques such as association analysis or regression analysis, attackers may be able to infer undisclosed data items from query results. Therefore, in addition to the noise mechanism of differential privacy, privacy leakage risk assessment can also combine mutual information theory to further quantify the privacy leakage risk of data queries. Mutual information measures the amount of information shared between two variables. In the context of privacy protection, mutual information is used to measure the relationship between query results and original data. If the correlation between query results and original data is too high, it means that attackers can use query results to infer more original data, thereby increasing the risk of privacy leakage.
[0136] Mutual Information The calculation formula is 200 years
[0137]
[0138] in, and Represent the original data set and query results respectively. is the joint probability distribution, and is a separate probability distribution. By calculating the mutual information between the query results and the original dataset, the privacy leakage risk caused by the query operation can be further evaluated.
[0139] In one possible implementation, the privacy leakage risk assessment process is as follows:
[0140] For each data node Process the query request in and calculate the privacy leakage risk of the query result .
[0141] For each query request ,The privacy leakage probability of the query result is calculated through the differential privacy framework, and the privacy budget To adjust the noise intensity to ensure that the risk of privacy leakage is controlled within a predetermined safety range.
[0142] The mutual information theory is used to further evaluate the correlation between the query request and the original data and calculate the possible privacy leakage risk. If the mutual information value is too high, the noise intensity is increased to reduce the correlation between the query result and the original data.
[0143] Exemplarily, in some embodiments, the privacy leakage risk assessment may also be combined with a dynamic noise adjustment mechanism.
[0144] The privacy protection strength is dynamically adjusted based on real-time monitoring and query frequency. For example, when a query operation is frequently executed, the system may automatically increase the noise intensity to improve the privacy protection effect. At the same time, when the query requests decrease or the access pattern changes, the noise intensity can be appropriately reduced to improve computing efficiency.
[0145] It should be noted that the real-time and accuracy of privacy leakage risk assessment are crucial to the privacy protection of the system.
[0146] Therefore, the system should timely evaluate the risk of privacy leakage according to the changes in real-time data and computing resources, and adjust the privacy protection strategy according to the evaluation results. Through this flexible risk assessment and dynamic adjustment mechanism, it can ensure that privacy protection measures are always effective in practical applications and minimize the risk of privacy leakage.
[0147] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A privacy security leakage risk assessment method for large-scale data, characterized in that: The following steps are involved: Establish a data environment and privacy protection requirements model, model the data of each data node in a large-scale data environment, and clarify the privacy protection requirements of each data node; Privacy leakage risk assessment, based on differential privacy theory, quantifies the privacy leakage risk of each data node and uses privacy risk assessment methods to calculate the probability of privacy leakage; Privacy protection models in information theory quantify the correlation between data sets and query results through mutual information, reduce the risk of data leakage, and determine the noise intensity; The dynamic noise adjustment mechanism adjusts the noise intensity in real time according to the optimal balance between privacy risks and computing resources, ensuring a reasonable ratio between privacy protection requirements and computing overhead.
2. According to claim 1, a privacy security leakage risk assessment method for large-scale data is characterized in that: The method further comprises: Establish and solve game theory models, use game theory models to simulate the privacy protection strategy between distributed nodes, and solve the optimal noise intensity through games to achieve the optimal balance between privacy protection and data utility of each node; Nash equilibrium solution and global optimal strategy determination: Under the framework of game theory, the collaborative privacy protection strategy between nodes is solved through Nash equilibrium to optimize the privacy protection mechanism of distributed data systems; Resource sharing and collaborative optimization: In a distributed data environment, through resource sharing and collaborative game between nodes, we can optimize privacy protection strategies, reduce computing resource consumption, and maximize data utility. Real-time feedback and adjustment of privacy leakage risks: Based on real-time privacy risk assessment results and computing resource status, the privacy protection strategy is dynamically adjusted to ensure the continuous minimization of privacy leakage risks.
3. According to claim 1, a privacy security leakage risk assessment method for large-scale data is characterized in that: The privacy leakage risk assessment steps include the following: Based on the differential privacy framework, the probability distribution analysis of the query results of each data node is performed to evaluate the risk of privacy leakage of each data node; Using the privacy budget model, determine the maximum privacy leakage risk allowed for each data node; Using the probability tolerance function, the privacy risk assessment results are compared with the privacy protection requirements of the nodes to ensure that the privacy protection requirements of each node are met.
4. According to claim 1, a privacy security leakage risk assessment method for large-scale data is characterized in that: The privacy protection model in information theory is implemented through the following steps: Calculate the mutual information between the data set and the query results to quantify the correlation between the data set and the query results; According to the relationship between the mutual information value and the data utility function, the noise intensity is adjusted to achieve a balance between privacy leakage and data utility; Through additive noise control, the information transfer between the data set and the query results is adjusted to ensure that the probability of privacy leakage is lower than the set threshold.
5. According to claim 1, a privacy security leakage risk assessment method for large-scale data is characterized in that: The dynamic noise adjustment mechanism achieves the adjustment of the optimal noise intensity by: Based on the privacy protection loss function and computational cost function, the privacy protection requirements and computational resource consumption of each node are dynamically calculated; Design an optimization objective function to balance privacy protection and computational overhead, and optimize the objective function to achieve the optimal balance between privacy protection and computational resources; The noise intensity is adjusted according to the optimization results to ensure a reasonable balance between privacy protection and computing resources and minimize the risk of privacy leakage.
6. A privacy security leakage risk assessment method for large-scale data according to claim 1, characterized in that: The game theory model includes the following: Establish a utility function for each data node, considering the trade-off between node privacy protection and data utility; Through game theory analysis, the optimal privacy protection strategy for each node is solved, so that each node can choose the best privacy protection strategy when the strategies of other nodes are known; The game process of multiple nodes is simulated to obtain the global optimal privacy protection strategy to ensure the optimal balance between the system's privacy protection requirements and data utility.
7. A privacy security leakage risk assessment method for large-scale data according to claim 1, characterized in that: The Nash equilibrium solving step includes the following contents: Based on the game theory model, the utility function of each node is calculated. The utility function takes into account the balance between privacy protection and computing resources. During the game, the privacy protection strategy of the node is adjusted to maximize the utility of the node and ensure that the privacy protection strategy between nodes does not change, that is, to achieve Nash equilibrium; Through multiple rounds of game optimization, the globally optimal privacy protection strategy is obtained to ensure that the privacy protection needs of all nodes are balanced globally.
8. The privacy security leakage risk assessment method for large-scale data according to claim 1 is characterized in that: The resource sharing and collaborative optimization steps include the following: Nodes share computing resources and collaboratively optimize privacy protection strategies, thereby reducing computing resource consumption; Use the collaborative game model to analyze the collaborative behavior between nodes and calculate the optimal privacy protection strategy after each node shares resources; By sharing computing resources and collaborative optimization, the globally optimal privacy protection strategy is implemented in a distributed environment, maximizing the privacy protection efficiency and reducing the system computing overhead.
9. A privacy security leakage risk assessment method for large-scale data according to claim 1, characterized in that: The real-time feedback and adjustment steps of the privacy leakage risk include the following: Monitor the risk of privacy leakage in the data processing process in real time, and adjust the privacy protection strategy by calculating the difference between the current privacy leakage probability and the preset risk threshold; Adjust the noise intensity based on the real-time assessment results of privacy risks to ensure that the risk of privacy leakage is always within an acceptable range; Combined with the real-time computing resource status of the node, the noise intensity is dynamically adjusted to ensure a reasonable balance between privacy protection effect and computing resource consumption.
10. A system for large-scale data privacy security leakage risk assessment, characterized in that: A privacy security leakage risk assessment method for large-scale data according to any one of claims 1 to 9, characterized by comprising: Data collection module, used to collect data from each node in a large-scale data environment; The privacy risk assessment module is used to assess the data privacy risk of each node, calculate the probability of privacy leakage, and evaluate the strength of privacy protection; The noise control module is used to dynamically adjust the noise intensity and control the privacy protection level based on the privacy risk assessment results; Game analysis module, used to simulate the game behavior between nodes and determine the privacy protection strategy by solving the game equilibrium; The resource sharing and collaborative optimization module is used to collaboratively optimize privacy protection strategies and reduce computing overhead by sharing computing resources.
Citation Information
Patent Citations
AI model private domain and public domain cooperative processing system based on data security and privacy protection
CN119106450A
Private data protection method based on deep learning
CN119203227A
User data intelligent protection method and system based on differential privacy
CN119720263A
Privacy-aware query management system
US20170169253A1
Cited By
Data encryption method and system for privacy computing and storage medium
CN122247589A