Privacy range counting query method based on evolution data
By using technical means such as multi-scene update and multi-attribute frequency perturbation module in the Internet of Things, the problem of privacy leakage in the range count query of evolution data is solved, and efficient privacy protection and accurate query of finite and infinite evolution data is achieved.
Patent Information
- Application Number
- CN202510141097.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-08
- Publication Date
- 2025-05-27
AI Technical Summary
The prior art is difficult to effectively solve the privacy leakage problem when involving range counting queries for evolved data in the Internet of Things, especially when dealing with infinite evolution data and vertical range counting queries.
Multi-scene update module, multi-attribute frequency disturbance module, adaptive interval merging module and frequency adjustment module are adopted to ensure privacy protection and improve query accuracy by performing noise addition processing on the participant side, frequency distribution data processing and interval merging on the server side.
Implement privacy range counting queries for finite and infinite evolution data, ensuring protection of participant privacy, and improving the accuracy of range counting queries, suitable for specific timestamps and vertical range counting queries.
Smart Images

Figure CN120045604A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data privacy protection, and in particular to a privacy range counting query method based on evolving data. Background Art
[0002] Devices in the Internet of Things (IoT) continuously generate data, giving rise to a large number of applications. For example, navigation software predicts road congestion in real time by calculating the number of cars on the road, and air conditioners achieve intelligent control by analyzing indoor temperature. As a basic task in data analysis and data mining, range counting query can count the scale of data that meets a specified query range. However, collecting or processing sensitive data may disclose the privacy of data contributors. For evolving data involving more privacy information, such privacy leakage will be more serious.
[0003] Local differential privacy (LDP) is an extended version of the de facto standard differential privacy, which eliminates the trust in the server. Most existing studies based on local differential privacy are dedicated to obtaining the frequency distribution of the entire domain. Categorical data and numerical data can both be transformed into discrete values, and the range of these discrete values is called the domain. Existing work focuses on obtaining the overall frequency distribution of continuously changing data. The main idea of these works is based on memorizing data changes and w-event local differential privacy. However, query users are often interested in the count of a certain range in the domain, that is, range counting query. For example, a hospital is more interested in the number of elderly patients. To solve this problem, many studies have investigated range counting queries on static datasets based on hierarchies, coarsened domains, or wavelet transforms. However, these methods cannot be applied to continuously changing data because the division of privacy budgets caused by repeated reports will cause the real data to be overwhelmed by noise. Some related work is designed for range counting queries on continuously changing data, but it can only handle limited evolving data and does not consider longitudinal range counting queries, that is, focusing on the count of evolving data within a certain range within a certain period of time. Summary of the Invention
[0004] The technical problem to be solved by the present invention is to provide a privacy-protected and effective range counting query method based on evolving data, which supports both limited and infinite evolving data, is applicable to range counting queries and longitudinal range counting queries at specific timestamps, and maximally improves the accuracy of range counting queries.
[0005] The technical solution adopted by the present invention to solve its technical problems is: to provide a privacy range counting query method based on evolving data, which is characterized by including a multi-scenario update module, a multi-attribute frequency perturbation module, an adaptive interval merging module, and a frequency adjustment module, wherein:
[0006] The multi-scenario update module is specifically as follows: Combining three data evolution forms in real life, in Scenario 1, data is reported by new participants joined within the current timestamp, and each participant only reports data to the server once without involving repeated reporting; in Scenario 2, only a fixed number of participants are willing to report data repeatedly, and the module dynamically adjusts the participant allocation according to requirements; in Scenario 3, new participants join at each timestamp, and on the basis of ensuring privacy protection, the participants are willing to report data repeatedly.
[0007] The multi-attribute frequency perturbation module is specifically as follows: Adaptive hash bins are constructed according to the discrete numerical range of attributes. Participants reporting data encode their own data into the corresponding hash bins through a hash function, and then through perturbation and data aggregation, the server collects the frequency distribution data of the participants.
[0008] The adaptive interval merging module is specifically as follows: According to the frequency distribution data obtained by the server, find all the merging possibilities where the sum of the interval frequencies is less than the threshold Among them, m is the number of merged intervals, var is the noise variance of the interval frequency. Interval merging reduces the noise error by reducing the number of intervals, but it will bring non-uniform errors to the queries within the merged intervals. Therefore, when the adaptive interval merging module selects interval merging, it considers both the characteristics of the frequency distribution and the probability of the interval being queried. In addition, the module also utilizes the sparsity of the evolving data. When the data changes little, the module will use the frequency distribution updated last time as an approximation.
[0009] The frequency adjustment module is specifically as follows: First, through non-negative processing, the frequencies less than 0 are set to 0, and then through weighted frequency adjustment, the total frequency sum is made equal to one.
[0010] Specifically, the present invention has the following advantages:
[0011] 1) The present invention is a privacy range counting query method for finite and infinite evolving data: There are corresponding update frameworks for both finite and infinite real-world update scenarios, which can ensure the privacy of participants while obtaining data, and theoretically prove the privacy protection performance boundary of this method.
[0012] 2) The present invention does not rely on any trusted third party: Participants perform perturbations locally without sending real data to a third party, completely eliminating the dependence on trusted third-party devices in existing related work, and is more conducive to promoting the commercial implementation of data privacy protection.
[0013] 3) The adaptive interval merging algorithm adopted by the present invention can improve the accuracy of range counting queries on the basis of protecting the privacy of participants, thereby improving data utility. Brief Description of the Drawings
[0014] Figure 1 It is the system data flow diagram of the present invention.
[0015] Figure 2 It is a system structure diagram of the present invention.
[0016] Figure 3 It is the adaptive interval merging judgment diagram of the present invention. DETAILED DESCRIPTION
[0017] The present invention will be further described below in conjunction with specific embodiments. It should be understood that these embodiments are only used to illustrate the present invention and are not intended to limit the scope of the present invention. In addition, it should be understood that after reading the content taught by the present invention, those skilled in the art can make various changes or modifications to the present invention, and these equivalent forms fall within the scope limited by the appended claims of the application equally.
[0018] like Figure 1 As shown, a privacy range counting query method based on evolving data includes participants, a server and a queryer. Participants are users who provide data, and different update scenarios are involved according to the wishes of the participants. According to the specific update scenario, the server will adaptively allocate participants so that the server can obtain frequency distribution data while avoiding participants from repeatedly reporting data to reduce the privacy protection level. Participants will add noise to real data according to the perturbation method of the present invention and send the noisy data to the server. The server collects the noisy data reported by the participants and then processes the data to obtain frequency distribution data. As the evolving data is updated, the server continuously counts the distribution data of the participants. The queryer sends a query request to the server according to its own needs, and the server returns the statistical range counting result to the queryer based on the obtained frequency distribution data.
[0019] like Figure 2 As shown, the system structure of a privacy range count query method based on evolving data includes a multi-attribute update module, a multi-attribute frequency perturbation module, an adaptive interval merging module and a frequency adjustment module. The multi-attribute update module is used to allocate participants to meet the update of evolving data; the multi-attribute frequency perturbation module is used for participants to perturb real data; the adaptive interval merging module is used for the server to adaptively determine the interval merging operation; the frequency adjustment module is used for the server to adjust the frequency distribution data to improve the utility. The privacy range count query algorithm based on evolving data is described as follows:
[0020] Step 1: Enter the update scenario and determine the participant allocation method;
[0021] Step 2: Divide the participants who report data at the current timestamp into a detection group and a pure reporting group, and the server sends query information to the participants in the detection group;
[0022] Step 3: The participants in the detection group add noise to the real data according to the rules of multi-attribute frequency perturbation and send the noisy data to the server;
[0023] Step 4: The server counts the noisy data, obtains the frequency distribution data of the participants in the detection group through the unbiased processing of the frequency perturbation module, processes the frequency distribution data through the frequency adjustment module, and then performs an adaptive interval merging operation based on the frequency distribution data. After completing the adaptive interval merging operation, the server sends query information to the participants in the pure reporting group;
[0024] Step 5: The participants in the pure reporting group add noise to the real data according to the query information sent by the server and the rules of multi-attribute frequency perturbation and send the noisy data to the server;
[0025] Step 6: The server collects the noisy data of the participants in the pure reporting group, obtains the frequency distribution data of the participants in the pure reporting group through unbiased processing, and further adjusts and processes the frequency distribution data of the detection group and the frequency distribution data of the pure reporting group through the frequency adjustment module, and finally obtains the frequency distribution data at the current timestamp;
[0026] Step 7: Answer various range counting queries of the querying party;
[0027] The algorithm ends.
[0028] Figure 3 Shows how the adaptive merging interval module makes merging judgments. Figure 3 There are two merging options, namely merging option 1 and merging option 2, and different boxes are used to represent the intervals of the merging operation. Since the variance noise scale carried by each interval is the same, reducing the number of intervals can reduce the noise scale. However, after the interval merging, there may be a situation where the query range does not completely cover the merged range, and usually the result is returned based on the principle of average distribution. Then the merging operation will bring additional errors, namely non-uniform errors. Therefore, the interval merging operation should be reasonably selected, and the merging operation with a large possible query should be selected. As Figure 3 can be seen, the types of queries involved in merging option 2 are more than those in merging option 1, so merging operation 2 is selected.
Claims
1. A privacy range counting query method based on evolving data, characterized in that: Includes the following parts: (1) Multi-scenario update module; (2) Multi-attribute frequency perturbation module; (3) Adaptive interval merging module; (4) Frequency adjustment module.
2. The privacy range counting query method based on evolving data according to claim 1 is characterized in that: The multi-scenario update module is specifically as follows: combining three forms of data evolution in real life, in scenario 1, data is reported by new participants who join within the current timestamp, and each participant only reports data to the server once, without repeated reporting; in scenario 2, only a fixed number of participants are willing to repeatedly report data, and the module dynamically adjusts the allocation of participants according to demand; in scenario 3, new participants join at each timestamp, and participants are willing to repeatedly report data on the basis of ensuring privacy protection.
3. The privacy range counting query method based on evolving data according to claim 1 is characterized in that: The multi-attribute frequency perturbation module specifically comprises: adaptively constructing hash boxes according to the discrete numerical range of the attributes, and the participants who report the data encode their own data into the corresponding hash boxes through the hash function, and then the server collects the frequency distribution data of the participants through perturbation and data aggregation.
4. The privacy range counting query method based on evolving data according to claim 1 is characterized in that: The adaptive interval merging module is specifically: according to the frequency distribution data obtained by the server, find all interval frequencies and less than the threshold The merging possibilities are selected and the merging possibilities with high query probability are prioritized, where m is the number of merged intervals and var is the noise variance of the interval frequency. Interval merging reduces noise errors by reducing the number of intervals, but it will bring non-uniform errors to the queries within the merged intervals. Therefore, the adaptive interval merging module considers both the characteristics of frequency distribution and the probability of interval being queried when selecting interval merging. In addition, the module also uses the sparsity of evolving data. When the data does not change much, the module uses the frequency distribution of the last update as an approximation.
5. The privacy range counting query method based on evolving data according to claim 1 is characterized in that: The frequency adjustment module specifically includes: firstly performing non-negative processing to set the frequencies less than 0 to 0, and then performing weighted frequency adjustment to make the total frequency sum equal to one.