A data privacy measurement method for intelligent networked vehicles

By combining a personalized dynamic privacy measurement model and a spatiotemporal sensitive model with user preferences and a sliding time window mechanism, the dynamic changes and real-time nature of privacy measurement in intelligent connected vehicles are solved, achieving accurate privacy risk assessment and effective data protection.

CN120068079BActive Publication Date: 2026-04-17BEIJING UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING UNIV OF POSTS & TELECOMM
Filing Date
2025-01-09
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing methods for measuring data privacy in intelligent connected vehicles fail to effectively consider dynamic changes in vehicles, lack personalized privacy measurements, and cannot meet real-time requirements, resulting in insufficient precision and flexibility in privacy protection.

Method used

A personalized dynamic privacy measurement model is constructed. The privacy attribute weights are calculated using the analytic hierarchy process and combined with user privacy preferences. The model is then updated using a sliding time window mechanism. This results in a spatiotemporally sensitive dynamic privacy measurement model. The probability distribution of privacy leakage is calculated using the gamma distribution, and a comprehensive privacy risk value is generated through weighted averaging.

Benefits of technology

It enables personalized and space- and time-sensitive privacy protection in intelligent connected vehicles, meets dynamic and real-time requirements, and provides accurate privacy risk assessment and effective data privacy protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068079B_ABST
    Figure CN120068079B_ABST
Patent Text Reader

Abstract

This application provides a data privacy measurement method for intelligent connected vehicles, comprising: calculating privacy attribute weights using the analytic hierarchy process (AHP) and adjusting them based on user privacy preferences to generate personalized privacy weights; generating personalized privacy risks using weighted information entropy and periodically updating them according to a sliding time window mechanism; calculating the probability distribution of privacy leakage in time and space dimensions using gamma distribution and generating spatiotemporal privacy risks, which are also updated using a sliding time window mechanism; fusing personalized privacy risks and spatiotemporal privacy risks using a weighted average to generate a comprehensive privacy risk value, and verifying the accuracy of the measurement results using privacy assessment parameters. This application can effectively protect the privacy and security of intelligent connected vehicles, adaptively adjust privacy protection strategies according to user needs, and ensure the privacy and security of intelligent connected vehicles in different environments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular to a data privacy measurement method for intelligent connected vehicles. Background Technology

[0002] In existing technologies, the privacy measurement problem in intelligent connected vehicles mainly involves how to effectively measure and protect the privacy of vehicle data in highly dynamic environments. With the increasing data exchange between vehicles and between vehicles and infrastructure, privacy and security have become key challenges in intelligent connected vehicles. However, the dynamic changes, varied network topologies, and high real-time requirements faced by intelligent connected vehicles make traditional privacy measurement methods inadequate to address these challenges, especially in unreliable or weakly trusted environments, where effective privacy protection becomes even more complex.

[0003] In terms of data privacy measurement, existing research is largely based on information theory, primarily using methods such as information entropy. These methods can design various privacy measurement models based on the attacker's prior knowledge. Existing privacy protection technologies typically achieve privacy protection by perturbing the original data to obscure sensitive attributes. From the perspectives of both privacy protection strength and data availability, common privacy metrics include entropy, mutual information, differential privacy, and set pair analysis theory. These methods, combined with other mathematical tools such as graph theory, can quantify and model communication privacy leaks, demonstrating a relatively forward-looking impact. However, current technologies for privacy measurement of intelligent connected vehicle data do not consider the impact of vehicle dynamic changes on the risk of privacy leaks.

[0004] Personalized privacy risk measurement is gradually becoming an important direction in privacy measurement research. By combining mathematical models such as the analytic hierarchy process (AHP), privacy leakage can be calculated based on the different privacy preferences of users. In scenarios with user benefits, such as crowdsourcing, the timeliness of privacy preferences can be considered, and privacy preference thresholds and privacy measurement matrices can be dynamically adjusted to support personalized privacy measurement. In applications such as recommender systems and social networks, privacy protection based on personalized preferences can be optimized through customized algorithms. However, existing personalized privacy quantification methods are still too simplistic, often relying on manual specification, and the results are coarse-grained and lack flexibility.

[0005] In the area of ​​dynamic privacy measurement, existing research mainly focuses on how to perform privacy measurement in dynamically changing scenarios. For example, reinforcement learning-based mobile edge computing technology has been used for dynamic privacy measurement and protection in the Internet of Things (IoT). These methods consider various factors such as privacy attributes, attribute preferences, and timeliness. However, the data of intelligent connected vehicles is characterized by its large scale, unstructured nature, and dynamic changes, making traditional privacy measurement methods difficult to fully apply. Especially in the data privacy detection of vehicle ad hoc networks, the application of traditional static data privacy measurement methods has limitations. It is necessary to design specialized privacy measurement models that combine the dynamic characteristics of vehicle data and the real-time requirements.

[0006] In summary, current data privacy measurement technologies for intelligent connected vehicles have the following drawbacks:

[0007] (1) Existing data privacy measurement models do not take into account the dynamic changes of vehicles.

[0008] (2) Intelligent connected vehicles lack personalized privacy measures.

[0009] (3) Traditional privacy measurement methods for vehicles cannot meet the real-time requirements.

[0010] Therefore, in the face of the severe data security challenges brought about by large-scale intelligent connected vehicles, it is urgent to construct a practical and effective dynamic, precise, and fine-grained privacy measurement method for large-scale intelligent connected vehicles, addressing the needs of intelligent connected vehicles for accurate privacy detection, time sensitivity of measurement, and differences in user privacy protection strength requirements. This method should form personalized privacy protection measures based on node differences and data heterogeneity, protecting important data and ensuring the controllable and secure flow of privacy data. Summary of the Invention

[0011] This application aims to at least partially address one of the technical problems in the related art.

[0012] Therefore, the first objective of this application is to propose a data privacy measurement method for intelligent connected vehicles.

[0013] The second objective of this application is to propose a data privacy measurement device for intelligent connected vehicles.

[0014] The third objective of this application is to propose an electronic device.

[0015] The fourth objective of this application is to provide a computer-readable storage medium.

[0016] The fifth objective of this application is to provide a computer program product.

[0017] To achieve the above objectives, a first aspect of this application proposes a data privacy measurement method for intelligent connected vehicles, comprising:

[0018] A personalized dynamic privacy measurement model that integrates user privacy preferences is constructed. The privacy attribute weights are calculated using the analytic hierarchy process and then adjusted based on user privacy preferences to generate personalized privacy weights.

[0019] Based on the personalized privacy weight, the user's personalized privacy risk is calculated by weighted information entropy, and the personalized privacy risk is periodically updated by a sliding time window mechanism.

[0020] A spatiotemporally sensitive dynamic privacy measurement model is constructed. The probability distribution of privacy leakage in time and space dimensions is calculated using gamma distribution. Spatiotemporal privacy risks are generated through joint calculation, and the spatiotemporal privacy risks are periodically updated using a sliding time window mechanism.

[0021] By integrating the personalized privacy risks and the spatiotemporal privacy risks, a comprehensive privacy risk value is generated through weighted averaging, and the accuracy of the risk measurement results is verified by combining privacy assessment parameters.

[0022] Optionally, the construction of a personalized dynamic privacy measurement model that integrates user privacy preferences, calculating privacy attribute weights using the analytic hierarchy process and adjusting them based on user privacy preferences to generate personalized privacy weights, includes:

[0023] Vehicle nodes define a set of privacy attributes S = {AT1, AT2, AT3, ..., AT...} based on the data collection task. n The collected data is structured into a privacy matrix G using a non-negative numerical mapping function. m*n Where m is the number of samples and n is the number of privacy attributes;

[0024] By combining expert evaluation opinions, pairwise comparisons are performed on the n privacy attributes of the collected data to construct a judgment matrix M. n*n =[b ij ] n*n , where b ij This indicates the relative importance of the i-th privacy attribute relative to the j-th privacy attribute;

[0025] Divide each column of the judgment matrix by the sum of all its elements to obtain the normalized matrix M′. n*n The judgment matrix is ​​then subjected to a consistency check to ensure that its consistency ratio CR ≤ 0.1, where:

[0026]

[0027] In the formula, λ maxLet n be the largest eigenvalue of the judgment matrix, n be the number of privacy attributes, and RI be the random consistency index.

[0028] For the normalized matrix M′ that meets the conditions n*n Sum the elements in each row and take the average to obtain the initial privacy attribute weight w for each privacy attribute;

[0029] Based on user privacy preference weights w pref The initial privacy attribute weight w is modified to obtain a personalized privacy weight w that reflects the user's privacy preferences. final The formula is:

[0030] w final =θ1w+θ2w pref θ1+θ2=1

[0031]

[0032] In the formula, Co(w, w) pref ) represents the correction function, whose function value satisfies the normalization condition; θ1 and θ2 are proportionality coefficients.

[0033] Optionally, the step of calculating user personalized privacy risks based on the personalized privacy weight using weighted information entropy, and periodically updating the personalized privacy risks using a sliding time window mechanism, includes:

[0034] Based on the personalized privacy weights and privacy matrix, and through weighted information entropy H... p (w final G) Calculate the personalized privacy risks of the current window t. The formula is:

[0035]

[0036] In the formula, Let p(x) be the personalized privacy weight for the i-th privacy attribute. j Let be the probability distribution of the j-th sample;

[0037] The sliding time window mechanism is used to divide the privacy data into fixed-length time windows T1, T2, T3, ... T. m-1 T m Furthermore, the privacy risk weight within each time window is controlled by a time decay function, the expression of which is:

[0038]

[0039] If the privacy amount in each time slot is S = {s} 1 s 2 , ..., s m}, then the total personalized privacy risk at time t is:

[0040]

[0041] Where λ is the decay factor, t k Let s be the deadline for the k-th time slot. k This represents the amount of privacy within the k-th time slot.

[0042] Optionally, the constructed spatiotemporally sensitive dynamic privacy measurement model utilizes gamma distribution to calculate the privacy leakage probability distribution in both time and space dimensions, and generates spatiotemporal privacy risks through joint computation, including:

[0043] Define the vehicle communication radius R, allowed tracking time T′, allowed tracking distance D′, and maximum time T. max and maximum distance D max ;

[0044] This paper describes the privacy leakage of user location in the temporal and spatial dimensions from a probabilistic perspective based on the gamma distribution function. The formulas for the gamma distribution parameters in the temporal and spatial dimensions are as follows:

[0045]

[0046] The above distribution parameter α t β t α d β d Substituting these values ​​into the gamma distribution function, we obtain the privacy leakage probability distribution functions for the time and space dimensions, as shown in the formulas:

[0047]

[0048] In the formula, f t (t,α t ,β t Let f be the probability distribution function of privacy leakage over the time dimension. d (d, α) d ,β d ) is the probability distribution function of privacy leakage in the spatial dimension;

[0049] Combining the privacy leakage probability distribution functions of the time and space dimensions, the spatiotemporal privacy risk is calculated using the following formula:

[0050] L p =(1-∫0) T f t (x)dx)*(1-∫0 D f d (x)dx)

[0051] Where T and D are the upper limits of the time dimension and the space dimension, respectively.

[0052] Optionally, the process of integrating the personalized privacy risk and the spatiotemporal privacy risk to generate a comprehensive privacy risk value through a weighted average includes:

[0053] By incorporating personalized privacy risks through weighted average p and spatiotemporal privacy risks L p The formula for calculating the comprehensive privacy risk value is as follows:

[0054] P metric =μ1H p +μ2L p

[0055] Among them, P metric Let μ1 and μ2 be the comprehensive privacy risk value, and μ1 and μ2 be weighting factors, and μ1 and μ2 ∈ [0, 1].

[0056] Optionally, the verification of the accuracy of the risk measurement results by combining privacy assessment parameters includes:

[0057] A privacy information assessment parameter ρ is introduced to evaluate the accuracy of data privacy metrics, ΔH. p This represents the difference between the current privacy measurement result and the most recent one. The accuracy of the current privacy measurement result is ensured by limiting the difference to a controllable range of ε. The calculation formula is as follows:

[0058]

[0059] Combining the KL divergence of temporal and spatial privacy leakage distributions, the difference or distance between two probability distributions can be calculated using the following formula:

[0060]

[0061] In the formula, f t (i) and f d (i) are the temporal and spatial privacy leakage distribution functions, respectively.

[0062] To achieve the above objectives, a second aspect of this application provides a data privacy measurement device for intelligent connected vehicles, comprising:

[0063] The personalized privacy weight generation module is used to build a personalized dynamic privacy measurement model that integrates user privacy preferences. It calculates the privacy attribute weights through the analytic hierarchy process and corrects them in combination with user privacy preferences to generate personalized privacy weights.

[0064] The personalized privacy risk generation and update module is used to calculate the user's personalized privacy risk based on the personalized privacy weight by using weighted information entropy, and to periodically update the personalized privacy risk through a sliding time window mechanism.

[0065] The spatiotemporally sensitive dynamic privacy measurement module is used to construct a spatiotemporally sensitive dynamic privacy measurement model. It uses the gamma distribution to calculate the privacy leakage probability distribution in the time and space dimensions, generates spatiotemporal privacy risks through joint calculation, and uses a sliding time window mechanism to periodically update the spatiotemporal privacy risks.

[0066] The integrated privacy risk generation and verification module is used to integrate the personalized privacy risk and the spatiotemporal privacy risk, generate an integrated privacy risk value by weighted averaging, and verify the accuracy of the risk measurement result by combining privacy assessment parameters.

[0067] To achieve the above objectives, a third aspect of this application provides an electronic device, including: a processor, and a memory communicatively connected to the processor;

[0068] The memory stores computer-executed instructions;

[0069] The processor executes computer execution instructions stored in the memory to implement the method as described in any one of the first aspects.

[0070] To achieve the above objectives, a fourth aspect of this application provides a computer-readable storage medium storing computer-executable instructions that, when executed by a processor, are used to implement the method as described in any one of the first aspects.

[0071] To achieve the above objectives, a fifth aspect of this application provides a computer program product that, when executed by a processor, implements the method described in any one of the first aspects.

[0072] The technical solutions provided by the embodiments of this application bring at least the following beneficial effects:

[0073] (1) This invention introduces a personalized dynamic privacy measurement model, combines the analytic hierarchy process (AHP) to calculate the weights of sensitive attributes, and adjusts the weights according to the user's privacy preferences to generate a personalized privacy measurement value. This method can meet the differentiated privacy protection needs of different users, making privacy protection strategies more flexible and personalized, thereby improving user satisfaction with privacy protection.

[0074] (2) The spatiotemporally sensitive dynamic privacy model proposed in this invention assesses privacy risks by evaluating the time and communication distance of vehicle nodes during driving, and can dynamically capture changes in privacy risks when vehicles interact with surrounding facilities. This method effectively considers the dynamic changes of vehicle data in the spatiotemporal dimension, making privacy risk assessment more accurate and adaptable to the highly dynamic environment of intelligent connected vehicles.

[0075] (3) This invention introduces a sliding time window mechanism and combines it with a decay function to weight historical privacy risks, dynamically updating the privacy metric value. This method can comprehensively consider the impact of historical privacy risks while quickly responding to current privacy risks, meeting the real-time privacy measurement needs of intelligent connected vehicle nodes and providing vehicle users with accurate privacy assessment results.

[0076] (4) This invention can not only accurately measure the privacy leakage risk of vehicle nodes, but also achieve a balance between privacy protection and data availability through reasonable model design. The combination of personalized and spatiotemporally sensitive measurement methods ensures both the strength of privacy protection and the efficient flow of data in the vehicle network.

[0077] (5) This invention is specifically designed for the privacy measurement model of data dynamic characteristics and real-time requirements in intelligent connected vehicles. It is applicable to large-scale, unstructured, and dynamically changing data scenarios. It can effectively protect vehicle data privacy in weak trust environments and has good practicality and scalability.

[0078] In summary, this application can effectively solve the problems of insufficient personalization, weak spatiotemporal dynamic characteristic processing capability, and low real-time performance in the privacy measurement of intelligent connected vehicles in existing technologies, and provides a more accurate and efficient solution for privacy protection in intelligent connected vehicle scenarios.

[0079] Additional aspects and advantages of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this application. Attached Figure Description

[0080] The above and / or additional aspects and advantages of this application will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, wherein:

[0081] Figure 1 A flowchart illustrating a data privacy measurement method for intelligent connected vehicles provided in an embodiment of this application;

[0082] Figure 2 A schematic diagram illustrating the personalized dynamic privacy measurement method provided in the embodiments of this application;

[0083] Figure 3This is a schematic diagram illustrating the division of vehicle data privacy attributes as provided in an embodiment of this application;

[0084] Figure 4 The analytic hierarchy process attribute comparison scale diagram provided in the embodiments of this application;

[0085] Figure 5 This is a schematic diagram of a spatiotemporally sensitive vehicle node privacy measurement method provided in an embodiment of this application;

[0086] Figure 6 A schematic diagram illustrating the spatiotemporally sensitive personalized dynamic privacy measurement method provided in the embodiments of this application;

[0087] Figure 7 This is a schematic diagram of a data privacy measurement device for intelligent connected vehicles provided in an embodiment of this application. Detailed Implementation

[0088] The embodiments of this application are described in detail below. Examples of these embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain this application, and should not be construed as limiting this application.

[0089] To address the issue that vehicle data privacy measurement in intelligent connected vehicle scenarios is affected by user privacy preferences and dynamic changes in vehicle behavior, this application provides a data privacy measurement method for intelligent connected vehicles. Figure 1 This is a flowchart illustrating a data privacy measurement method for intelligent connected vehicles provided in an embodiment of this application. Figure 1 As shown, the method includes the following steps:

[0090] Step 101: Construct a personalized dynamic privacy measurement model that integrates user privacy preferences. Calculate the privacy attribute weights using the analytic hierarchy process and adjust them in conjunction with user privacy preferences to generate personalized privacy weights.

[0091] The purpose of this step is to construct a personalized privacy measurement model, enabling intelligent connected vehicles to dynamically adjust privacy risk measurements based on different users' privacy preferences when processing vehicle data, thereby achieving personalized privacy protection. This step combines the Analytic Hierarchy Process (AHP) and user privacy preference correction, providing greater accuracy and flexibility for privacy measurement.

[0092] Reference Figure 2 First, the vehicle node defines a privacy attribute set S = {AT1, AT2, AT3, ..., AT...} based on the data collection task. n}, where AT iThis represents the i-th sensitive attribute, and the selection of these attributes all belong to... Figure 3 The definition of privacy attributes includes, for example, vehicle location, speed, and vehicle ID. By defining this set, sensitive attributes in vehicle data can be effectively segmented and identified, providing a foundation for privacy protection.

[0093] Next, the vehicle nodes perform structured processing on the collected data. To quantify the sensitivity of each privacy attribute, this embodiment employs a non-negative numerical mapping function f. j Its definition is:

[0094] f j =R + ∪{0},j∈{1,2,…,n}.

[0095] This mapping function maps the sensitivity of each privacy attribute to a non-negative value, where a larger mapping value indicates a higher sensitivity of the attribute. For example, vehicle location data may be more sensitive than vehicle speed data, and its corresponding mapping value will be larger.

[0096] After mapping is completed, the vehicle nodes will structure the collected data into a privacy matrix G. m*n Where m represents the number of data samples and n represents the number of privacy attributes. Privacy matrix G m*n The purpose of this matrix is ​​to transform the collected vehicle data into a unified, structured format, facilitating subsequent calculations of privacy weights and quantitative analysis of privacy risks. This matrix not only describes the sensitivity distribution of the collected vehicle data but also provides fundamental data support for personalized privacy measurements.

[0097] In the personalized dynamic privacy measurement model of this application, in order to quantify the impact of privacy attributes on the risk of privacy leakage, this embodiment uses the analytic hierarchy process (AHP) to obtain the initial privacy attribute weights, and then corrects the weights based on user privacy preferences to generate personalized privacy weights w with user privacy preferences. final The specific steps are as follows:

[0098] First, based on expert evaluations, pairwise comparisons are performed on the n privacy attributes of the collected data to construct a judgment matrix M. n*n =[b ij ] n*n , where b ij This represents the relative importance of the i-th privacy attribute relative to the j-th privacy attribute. The judgment matrix is ​​a symmetric matrix that satisfies b. ij =1 / b ji With b ii =1, by comparing pairs, the subjective judgment of experts on the importance of privacy attributes can be quantified into specific values, and a complete judgment matrix can be constructed.

[0099] Then, the judgment matrix M n*n Normalization is then performed. Specifically, each column of the judgment matrix is ​​divided by the sum of all elements in that column to obtain the normalized matrix M′. n*n Normalization makes the data in the judgment matrix more consistent, providing a standardized basis for subsequent weight calculations.

[0100] It should be noted that, to ensure the rationality and consistency of the judgment matrix, this embodiment performs a consistency check on the judgment matrix. Specifically, the consistency ratio CR is calculated to measure whether the judgment matrix has satisfactory consistency.

[0101]

[0102] In the formula, λ max is the largest eigenvalue of the judgment matrix; n is the number of privacy attributes, i.e., the order of the judgment matrix; RI is the random consistency index, whose value is related to the size of n and is derived from an empirical value table.

[0103] In this embodiment of the application, the consistency ratio is controlled at CR≤0.1. If CR≤0.1, it indicates that the judgment matrix has satisfactory consistency and meets the weight calculation requirements; otherwise, the judgment matrix needs to be readjusted until the consistency test passes.

[0104] Finally, for the normalized matrix M′ that passes the consistency test n*n The elements in each row are summed and averaged to obtain the initial privacy attribute weight w for each privacy attribute. The calculated w is the initial weight of each privacy attribute, reflecting the expert's subjective judgment on the relative importance of different privacy attributes.

[0105] It should be noted that in the personalized dynamic privacy measurement model, in order to generate personalized privacy weights w that reflect users' privacy preferences... final The initial privacy attribute weights w calculated using the analytic hierarchy process need to be corrected. This application uses user privacy preference weights w... pref The initial privacy weights are adjusted as follows:

[0106] First, a weighted formula is used to combine the initial privacy weight w and the user privacy preference weight w. pref This generates the final personalized privacy weight w. final The formula is:

[0107] w final =θ1w+θ2w pref

[0108] Where θ1 and θ2 are scaling coefficients, controlling the influence of the initial weight and the user privacy preference weight on the final weight, respectively. To ensure the rationality of the weight adjustment, the scaling coefficients must meet the following constraints:

[0109] θ1+θ2=1

[0110] To further determine the scaling factors θ1 and θ2, this application introduces a correction function Co(w, w) pref ), used to quantify the initial weight w and the user privacy preference weight w pref The difference between them is defined as follows:

[0111]

[0112] In the formula, Co(w, w) pref ) represents the correction function, whose function value satisfies the normalization condition.

[0113] It is understandable that the larger the value of the correction function, the stronger the initial weight w and the user privacy preference weight w. pref The greater the difference between them, the more dominant the influence of the initial weight becomes; conversely, when the value of the correction function is small, it indicates that the difference between the two is small, and the user preference weight has a stronger corrective effect on the final weight.

[0114] In this process, the correction function Co(w, w) is modified. pref The normalization property of ) ensures the scientific and reasonable calculation of the proportional coefficient. In this way, objective initial weights w and user privacy preference weights w can be determined. pref Achieving a balance between them.

[0115] Ultimately, the generated personalized privacy weight w final This approach not only reflects users' privacy preferences but also maintains the rationality and scientific nature of the weight distribution. When the difference between the initial weights and user preference weights is large (i.e., the correction function value is large), the influence of user preferences on the final weights is weak, making it suitable for scenarios where user preferences have little impact on the sensitivity of privacy attributes. Conversely, when the difference between the initial weights and user preference weights is small (i.e., the correction function value is small), the influence of user preferences on the final weights is strong, making it more suitable for scenarios where users have significant subjective privacy needs.

[0116] Through the above correction process, the final personalized privacy weight w is generated. final It can provide more accurate data support for personalized privacy measurement, laying the foundation for the formulation of user privacy protection strategies in intelligent connected vehicles.

[0117] Step 102: Based on personalized privacy weights, calculate the user's personalized privacy risks using weighted information entropy, and periodically update the personalized privacy risks using a sliding time window mechanism.

[0118] In the personalized dynamic privacy measurement method, the embodiments of this application first measure the privacy risk result of the current window t. Specifically, based on the personalized privacy weight w final And the privacy matrix G, through weighted information entropy H p (w final G) Calculate the personalized privacy risks of the current window t. The formula is:

[0119]

[0120] In the formula, Let p(x) be the personalized privacy weight for the i-th privacy attribute. j Let be the probability distribution of the j-th sample.

[0121] In the above formula, the inner summation calculates the privacy risk value p(x) for each sample. j log2p(x) j Then, combine the privacy attribute weights. Perform a weighted summation to obtain the personalized privacy risks of the current time window t. This calculation method can simultaneously reflect the importance of privacy attributes and users' personalized privacy preferences, thereby generating accurate personalized privacy risk assessment results.

[0122] To dynamically measure privacy risks at the current moment, while also considering the impact of historical data on current privacy risks, this application further introduces a sliding time window mechanism, dividing the privacy data into fixed-length time windows T1, T2, T3, ... T m-1 T m This allows for the dynamic calculation of the overall privacy risk at the current time t. The time window slides at fixed intervals over time, and the privacy risk weight within each time window is determined by a time decay function R. d (t) is used for control, and its expression is:

[0123]

[0124] Where λ is the decay factor and λ∈[0,1], t k This is the deadline for the k-th time slot.

[0125] This time decay function measures the weight of historical time slots on current privacy risks. The further back in time the historical data, the lower its weight on current privacy risks. This effectively reduces the interference of data from earlier time windows on current privacy measurement results, thus dynamically balancing the impact of real-time and historical privacy risks.

[0126] Assume the privacy amount within each time slot is S = {s} 1 s 2 , ..., s m}, then the total personalized privacy risk at the current time t is:

[0127]

[0128] Among them, s k This represents the amount of privacy within the k-th time slot. This represents the time decay weight for the k-th time slot.

[0129] Using the formula above, the total personalized privacy risk S at current time t H (t) represents the privacy risk s for all historical time slots. k The result of weighted summation. The sliding time window mechanism introduces a time decay function R. d (t) dynamically controls the weight of privacy risks in historical time slots, thereby ensuring the real-time nature of privacy risk measurement.

[0130] Overall, this step, by combining personalized privacy risk calculation with a sliding time window mechanism, achieves a dynamic and comprehensive analysis of current and historical privacy risks. It not only reflects users' personalized privacy needs but also effectively addresses the dynamic changes and real-time requirements of privacy data in intelligent connected vehicles.

[0131] Step 103: Construct a time- and space-sensitive dynamic privacy measurement model, use gamma distribution to calculate the privacy leakage probability distribution in time and space dimensions, generate time- and space-based privacy risks through joint calculation, and use a sliding time window mechanism to periodically update the time- and space-based privacy risks.

[0132] It is understandable that high-speed moving vehicle nodes face the risk of privacy leakage during interactions with surrounding facilities due to the dynamic changes in interaction time and communication distance. Therefore, this application proposes a time- and space-sensitive dynamic privacy measurement model to quantify the risk of privacy leakage from both temporal and spatial dimensions. (See reference...) Figure 5 and Figure 6 .

[0133] First, define the following parameters:

[0134] Vehicle communication radius R: The communication range of the vehicle node;

[0135] Allowed tracking time T′: The maximum time a user is allowed to be tracked;

[0136] Allowed tracking distance D′: The maximum distance that the user allows to be tracked;

[0137] Maximum time T max The maximum traceable time specified by the system;

[0138] Maximum distance D max The maximum traceable distance specified by the system.

[0139] Among them, the values ​​of allowed tracking time and distance reflect the user's subjective preference for privacy sensitivity; the higher the value, the lower the user's sensitivity to privacy.

[0140] To describe the privacy leakage risks in the time and space dimensions from a probabilistic perspective, embodiments of this application establish privacy leakage probability distribution models in the time and space dimensions based on the gamma distribution function, with the following parameter formulas:

[0141] Time-dimensional gamma distribution parameters:

[0142]

[0143] Spatial dimension gamma distribution parameters:

[0144]

[0145] Then, the gamma distribution parameter α mentioned above... t β t α d β d Substituting these values ​​into the gamma distribution function, we obtain the privacy leakage probability distribution functions for the time and space dimensions, as shown in the formulas:

[0146] Time-dimensional privacy leakage probability distribution function:

[0147]

[0148] Spatial dimension privacy leakage probability distribution function:

[0149]

[0150] In the formula, f t (t,α t ,β t Let f be the probability distribution function of privacy leakage over the time dimension. d (d, α) d ,β dΓ is the probability distribution function of privacy leakage in the spatial dimension, and Γ() is the gamma function.

[0151] Assuming an initial privacy threshold of 1, this application combines privacy leakage probability distribution functions of the time and space dimensions to calculate spatiotemporal privacy risks, using the following formula:

[0152] L p =(1-∫0) T f t (x)dx)*(1-∫0 D f d (x)dx)

[0153] Where T and D are the upper limits of the time dimension and the space dimension, respectively.

[0154] Using the above formula, the spatiotemporal privacy risk L p It is a joint result of the probability of privacy leakage in the time dimension and the probability of privacy leakage in the spatial dimension. The gamma distribution model in the time and spatial dimensions can reflect the dynamic changes of the probability of privacy leakage in the time and space ranges. Combined with users' preferences for the sensitivity of time and space privacy, the privacy risks of vehicle nodes can be assessed more accurately.

[0155] In addition, similar to the measurement of personalized privacy risks, this application introduces a sliding time window mechanism to periodically analyze the results of spatiotemporally sensitive privacy measurements in order to dynamically analyze these risks. This sliding time window mechanism allows for dynamic updates to privacy risks, comprehensively considering both the data within the current time window and the privacy information from historical time slots.

[0156] Specifically, the spatiotemporally sensitive privacy data is divided into fixed-length time windows T1, T2, T3, ... T m-1 T m The privacy risk weight within each time window is determined by a time decay function R. d (t) is used for control, and its expression is:

[0157]

[0158] Where λ is the decay factor and λ∈[0,1], t k This is the deadline for the k-th time slot.

[0159] This time decay function measures the weight of historical time slots on current privacy risks. The further back in time the historical data, the lower its weight on current privacy risks. This effectively reduces the interference of data from earlier time windows on current privacy measurement results, thus dynamically balancing the impact of real-time and historical privacy risks.

[0160] Assume that the spatiotemporal sensitive privacy quantities in each time slot were previously S = {s} 1 s 2 , ..., s m Then, the spatiotemporal sensitive privacy metric result at the current time t is calculated by the following formula:

[0161]

[0162] Among them, s k This represents the amount of spatiotemporally sensitive privacy within the k-th time slot. This represents the time decay weight for the k-th time slot.

[0163] Using the above formula, the total spatiotemporal sensitive privacy metric S at current time t is obtained. L (t) represents the privacy amount s within all historical time slots. k The result is a weighted sum. The time decay function ensures that the impact of privacy values ​​in earlier time windows on current privacy risks gradually weakens, while the impact of privacy values ​​in the current time window on the measurement result is more significant.

[0164] Furthermore, the introduction of the sliding time window mechanism into spatiotemporally sensitive privacy metrics not only improves the dynamism and real-time nature of privacy risk measurement, but also allows for a reasonable balance of the impact of historical data through a time decay function, avoiding interference from outdated data on current privacy risk measurement, thereby further enhancing the effectiveness of privacy protection.

[0165] Step 104: Integrate personalized privacy risks and spatiotemporal privacy risks, generate a comprehensive privacy risk value through weighted averaging, and verify the accuracy of the risk measurement results by combining privacy assessment parameters.

[0166] In the privacy measurement method of this application, personalized privacy risk H p and spatiotemporal privacy risks L p These are two independent privacy measurement results. In order to generate a comprehensive privacy risk value that can more fully assess the privacy risks of vehicle nodes under personalized privacy preferences and spatiotemporal dynamic changes, this application proposes a method to fuse the two privacy risks by weighted averaging.

[0167] The formula for calculating the comprehensive privacy risk score is:

[0168] P metric =μ1H p +μ2L p

[0169] Among them, P metric For the comprehensive privacy risk value, μ1 and μ2 are weighting factors, and μ1 and μ2 ∈ [0, 1].

[0170] Using the weighted average formula described above, the two privacy measurement strategies can be adaptively selected based on user privacy preferences. When users are more concerned about personalized privacy protection, μ1 can be set to a larger value, in which case the weight of personalized privacy risk Hp is higher; when users are more concerned about spatiotemporal privacy protection, μ2 can be set to a larger value, thereby enhancing the weight of spatiotemporal privacy risk L. p Impact on overall privacy risk. When one of the weighting factors is zero, such as μ1 = 0 or μ2 = 0, it indicates that the overall privacy risk value is determined solely by another privacy risk value.

[0171] In addition, to verify the comprehensive privacy risk value P metric To assess the accuracy of data privacy metrics, this application further introduces a privacy information assessment parameter ρ.

[0172] The formula for calculating the privacy information assessment parameter ρ is:

[0173]

[0174] In the formula, ΔH p This represents the difference from the most recent privacy measurement result. Personalized privacy risks for the current time window t. This relates to personalized privacy risks in the previous time window.

[0175] This application embodiment sets a controllable range ε, which is set according to the actual scenario, and if the following conditions are met:

[0176] ρ=|ΔH p |<ε

[0177] This indicates that the privacy risk measurement results have sufficient accuracy and stability; conversely, if ρ exceeds ε, it indicates that the accuracy of the privacy risk measurement results may be insufficient, and the privacy risk calculation process needs further verification and adjustment.

[0178] To further verify the accuracy of the spatiotemporal privacy measurement results, this application proposes using Kullback-Leibler divergence (KL divergence) to measure the distance between the temporal and spatial privacy measurement results. KL divergence is a classic method for measuring the difference or distance between two probability distributions. It works by analyzing the temporal and spatial privacy leakage probability distributions fi. d The differences between them can be used to assess the reasonableness and accuracy of the spatiotemporal awareness privacy measurement results.

[0179] The formula for calculating the KL divergence is as follows:

[0180]

[0181] In the formula, D KL (f t ||f d f represents the probability distribution of privacy leakage over time. t Spatial dimension privacy leakage probability distribution f d KL divergence between them; f t (i) and f d (i) represent the temporal and spatial privacy leakage distribution functions, respectively; i represents the discrete point of the privacy leakage probability in the distribution.

[0182] By calculating the time dimension distribution f t and spatial dimension distribution f d The KL divergence can quantitatively assess the difference between two privacy measurement results, thereby ensuring the accuracy and reliability of privacy measurement results based on spatiotemporal awareness. Furthermore, when the KL divergence value is small, it can be considered that the privacy leakage risk measurements in the temporal and spatial dimensions have high consistency and complementarity, which provides a more reliable basis for calculating comprehensive privacy risk.

[0183] To achieve the above embodiments, this application also proposes a data privacy measurement device for intelligent connected vehicles. Figure 7 This is a schematic diagram of a data privacy measurement device for intelligent connected vehicles provided in an embodiment of this application. Figure 7 As shown, the device includes:

[0184] The personalized privacy weight generation module 100 is used to construct a personalized dynamic privacy measurement model that integrates user privacy preferences. It calculates the privacy attribute weights through the analytic hierarchy process and corrects them in combination with user privacy preferences to generate personalized privacy weights.

[0185] The personalized privacy risk generation and update module 200 is used to calculate the user's personalized privacy risk based on the personalized privacy weight and through weighted information entropy, and to periodically update the personalized privacy risk through a sliding time window mechanism.

[0186] The Spatiotemporally Sensitive Dynamic Privacy Measurement Module 300 is used to construct a spatiotemporally sensitive dynamic privacy measurement model. It uses the gamma distribution to calculate the privacy leakage probability distribution in the time and space dimensions, generates spatiotemporal privacy risks through joint calculation, and uses a sliding time window mechanism to periodically update the spatiotemporal privacy risks.

[0187] The integrated privacy risk generation and verification module 400 is used to integrate personalized privacy risks and spatiotemporal privacy risks, generate an integrated privacy risk value through weighted averaging, and verify the accuracy of the risk measurement results by combining privacy assessment parameters.

[0188] To implement the above embodiments, this application also proposes an electronic device, including: a processor and a memory communicatively connected to the processor; the memory stores computer execution instructions; the processor executes the computer execution instructions stored in the memory to implement the method provided in the foregoing embodiments.

[0189] To implement the above embodiments, this application also proposes a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the methods provided in the foregoing embodiments.

[0190] To implement the above embodiments, this application also proposes a computer program product, including a computer program that, when executed by a processor, implements the methods provided in the foregoing embodiments.

[0191] The collection, storage, use, processing, transmission, provision, and disclosure of user personal information involved in this application all comply with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0192] It should be noted that personal information collected from users should be used for legitimate and reasonable purposes and should not be shared or sold outside of these legitimate uses. Furthermore, such collection / sharing should only be conducted after receiving the user's informed consent, including but not limited to notifying the user to read the user agreement / user notice and sign an agreement / authorization that includes authorization of relevant user information before the user uses the function. In addition, any necessary steps must be taken to protect and safeguard access to such personal information data and ensure that others with access to personal information data comply with their privacy policies and procedures.

[0193] This application is intended to provide an implementation scheme for users to selectively prevent the use or access to their personal information data. Specifically, this disclosure is intended to provide hardware and / or software to prevent or block access to such personal information data. Once personal information data is no longer needed, risks can be minimized by restricting data collection and deleting data. Furthermore, where applicable, such personal information is de-identified to protect user privacy.

[0194] In the foregoing descriptions of the embodiments, the terms "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0195] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this application, "multiple" means at least two, such as two, three, etc., unless otherwise explicitly specified.

[0196] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing custom logic functions or processes, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as should be understood by those skilled in the art to which embodiments of this application pertain.

[0197] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include: an electrical connection having one or more wires (electronic device), a portable computer disk drive (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Alternatively, the computer-readable medium may be paper or other suitable media on which the program can be printed, since the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in a computer memory.

[0198] It should be understood that various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0199] Those skilled in the art will understand that all or part of the steps of the methods described in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it includes one or a combination of the steps of the method embodiments.

[0200] Furthermore, the functional units in the various embodiments of this application can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.

[0201] The storage medium mentioned above can be a read-only memory, a disk, or an optical disk, etc. Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of this application.

[0202] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this application can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this application can be achieved, and this is not limited herein.

[0203] The specific embodiments described above do not constitute a limitation on the scope of protection of this application. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A data privacy measurement method for intelligent connected vehicles, characterized in that, Includes the following steps: A personalized dynamic privacy measurement model that integrates user privacy preferences is constructed. The privacy attribute weights are calculated using the analytic hierarchy process and then adjusted based on user privacy preferences to generate personalized privacy weights. Based on the personalized privacy weight, the user's personalized privacy risk is calculated by weighted information entropy, and the personalized privacy risk is periodically updated by a sliding time window mechanism. A spatiotemporally sensitive dynamic privacy measurement model is constructed. The probability distribution of privacy leakage in time and space dimensions is calculated using gamma distribution. Spatiotemporal privacy risks are generated through joint calculation, and the spatiotemporal privacy risks are periodically updated using a sliding time window mechanism. By integrating the personalized privacy risks and the spatiotemporal privacy risks, a comprehensive privacy risk value is generated through weighted averaging, and the accuracy of the risk measurement results is verified by combining privacy assessment parameters. The process of calculating user personalized privacy risks based on the personalized privacy weights using weighted information entropy, and periodically updating the personalized privacy risks using a sliding time window mechanism, includes: Based on the personalized privacy weights and privacy matrix, weighted information entropy is used. Calculate the current window Personalized privacy risks The formula is: In the formula, For the first Personalized privacy weights for each privacy attribute. For the first The probability distribution of each sample; Using a sliding time window mechanism to divide privacy data into fixed-length time windows Furthermore, the privacy risk weight within each time window is controlled by a time decay function, the expression of which is: If the privacy amount in each time slot is respectively Then in time The overall personalized privacy risks are: in, As the attenuation factor, For the first The deadline for each time slot. Indicates the first Privacy amount within each time slot; The constructed spatiotemporally sensitive dynamic privacy measurement model utilizes the gamma distribution to calculate the privacy leakage probability distribution in both time and space dimensions, and generates spatiotemporal privacy risks through joint computation, including: Define vehicle communication radius Allowed tracking time Permissible tracking distance Maximum time and maximum distance ; This paper describes the privacy leakage of user location in the temporal and spatial dimensions from a probabilistic perspective based on the gamma distribution function. The formulas for the gamma distribution parameters in the temporal and spatial dimensions are as follows: The above distribution parameters , , , Substituting these values ​​into the gamma distribution function, we obtain the privacy leakage probability distribution functions for the time and space dimensions, as shown in the formulas: In the formula, Let be the privacy leakage probability distribution function over time. Let be the probability distribution function for privacy leaks in the spatial dimension; Combining the privacy leakage probability distribution functions of the time and space dimensions, the spatiotemporal privacy risk is calculated using the following formula: in, and These are the upper limits for the time dimension and the space dimension, respectively.

2. The method according to claim 1, characterized in that, The construction of a personalized dynamic privacy measurement model that integrates user privacy preferences involves calculating privacy attribute weights using the analytic hierarchy process (AHP) and then adjusting them based on user privacy preferences to generate personalized privacy weights. This includes: Vehicle nodes define a set of privacy attributes based on the data collection task. The collected data is structured into a privacy matrix using a non-negative numerical mapping function. ,in, For the sample size, Number of privacy attributes; The collected data were evaluated in conjunction with expert opinions. Each privacy attribute is compared pairwise to construct a judgment matrix. ,in, Indicates the first The privacy attribute is relative to the first The relative importance of each privacy attribute; Divide each column of the judgment matrix by the sum of all elements in that column to obtain the normalized matrix. The consistency of the judgment matrix is ​​then checked to ensure its consistency ratio. ,in: In the formula, The largest eigenvalue of the judgment matrix is... The number of privacy attributes. It is a random consistency indicator; For the normalized matrix that meets the conditions Sum the elements in each row and take the average to obtain the initial privacy attribute weight for each privacy attribute. ; Weighted by user privacy preferences Adjust the initial privacy attribute weights The adjustments are made to obtain a personalized privacy weight that reflects the user's privacy preferences. The formula is: In the formula, This represents the correction function, whose function value satisfies the normalization condition; and This is the proportionality coefficient.

3. The method according to claim 2, characterized in that, The integration of personalized privacy risks and spatiotemporal privacy risks, and the generation of a comprehensive privacy risk value through a weighted average, includes: Incorporating personalized privacy risks through weighted averaging and temporal privacy risks The formula for calculating the comprehensive privacy risk value is as follows: in, The comprehensive privacy risk value is... As a weighting factor, and .

4. The method according to claim 3, characterized in that, The verification of the accuracy of the risk measurement results by incorporating privacy assessment parameters includes: Introducing privacy information assessment parameters To assess the accuracy of data privacy metrics, This represents the difference from the most recent privacy measurement result, defined by the range of the two values. To ensure the accuracy of this privacy measurement result within a controllable range, the calculation formula is as follows: Combining the distribution of privacy breaches in time and space Divergence, which calculates the difference or distance between two probability distributions, is given by the following formula: In the formula, and These are the temporal and spatial privacy leakage distribution functions, respectively.

5. A data privacy measurement device for intelligent connected vehicles based on the method of any one of claims 1-4, characterized in that, include: The personalized privacy weight generation module is used to build a personalized dynamic privacy measurement model that integrates user privacy preferences. It calculates the privacy attribute weights through the analytic hierarchy process and corrects them in combination with user privacy preferences to generate personalized privacy weights. The personalized privacy risk generation and update module is used to calculate the user's personalized privacy risk based on the personalized privacy weight by using weighted information entropy, and to periodically update the personalized privacy risk through a sliding time window mechanism. The spatiotemporally sensitive dynamic privacy measurement module is used to construct a spatiotemporally sensitive dynamic privacy measurement model. It uses the gamma distribution to calculate the privacy leakage probability distribution in the time and space dimensions, generates spatiotemporal privacy risks through joint calculation, and uses a sliding time window mechanism to periodically update the spatiotemporal privacy risks. The integrated privacy risk generation and verification module is used to integrate the personalized privacy risk and the spatiotemporal privacy risk, generate an integrated privacy risk value by weighted averaging, and verify the accuracy of the risk measurement result by combining privacy assessment parameters.

6. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1-4.

7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-4.

8. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1-4.

Citation Information

Patent Citations

  • Vehicle real-time track privacy protection method and device and storage medium

    CN116975903A

  • Using privacy budget to train models for controlling autonomous vehicles

    US20230385441A1