Model Encryption and Privacy Protection Method for Artificial Intelligence Algorithms
Through quantum feature extraction and multi-objective optimization, the privacy level mapping table is generated, combined with quantum optimization and dynamic noise injection, the parameter conflict and privacy protection problems caused by data heterogeneity in federated learning are solved, and the dynamic balance of model convergence efficiency and privacy protection is achieved, and the overall performance of federated learning is improved.
Patent Information
- Application Number
- CN202510541888.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-28
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-04-28
AI Technical Summary
When facing data heterogeneity, the existing federated learning framework has negative impacts on the convergence stability and accuracy of model convergence, especially the problem of parameter conflicts caused by non-independent and homogeneous data and the lack of dynamic privacy regulation mechanisms.
Quantum feature extraction and multi-objective optimization are used to generate a privacy level mapping table, and the subset of low-latency nodes is selected through quantum optimization and dynamic weight adjustment is performed. Combined with quantum all-homomorphic encryption and dynamic noise injection, and using quantum hash ratio and anomaly detection mechanisms, a quantum hybrid optimization framework is built for closed-loop feedback of encryption strength and noise strategies.
It effectively resolves parameter conflicts caused by data heterogeneity, improves model convergence efficiency, and realizes a dynamic balance between privacy protection intensity and model accuracy, forming a full-link adaptive collaboration, ensuring global optimal model aggregation efficiency and privacy-utility in non-independent and homogeneous data scenarios.
Smart Images

Figure CN120068123B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and particularly to a method for model encryption and privacy protection for artificial intelligence algorithms. Background Art
[0002] The model encryption and privacy protection technology for artificial intelligence algorithms aims to achieve efficient training and inference of models through cryptographic means and distributed cooperation mechanisms while ensuring data privacy. Among them, federated learning, as the mainstream privacy protection framework, stores data locally at distributed nodes and collaborates to update the global model, avoiding the centralized transmission of original data and effectively reducing the risk of privacy leakage. Differential privacy, on the other hand, injects controllable noise into model parameters or outputs to prevent individual information from being reverse-inferred. Such technologies are widely used in highly sensitive fields such as finance and healthcare to meet the increasingly strict data security regulatory requirements.
[0003] Existing federated learning frameworks face significant challenges in dealing with data heterogeneity. The non-independent and identically distributed characteristics of the participating parties' data lead to a deviation between the local model update direction and the global objective, and traditional static aggregation strategies are difficult to dynamically adjust the weight distribution, resulting in a slowdown in the model convergence speed or a decrease in accuracy. For example, the aggregation method using fixed weighted averaging cannot adapt to the dynamic changes in the data volume, feature distribution, or contribution degree of different nodes, exacerbating the conflict of local model parameters. In addition, the balance problem between privacy protection mechanisms and model performance in heterogeneous environments has not been effectively solved: over-reliance on noise injection or encryption layers will further weaken the convergence stability of the model, while simplifying protection measures may expose privacy vulnerabilities, forming a double contradiction between security and practicality. Summary of the Invention
[0004] Aiming at the deficiencies of the prior art, the present invention provides a method for model encryption and privacy protection for artificial intelligence algorithms, which solves the double contradiction formed by the decrease in model aggregation efficiency caused by data heterogeneity in the federated learning framework and the negative impact of privacy protection mechanisms on the convergence stability and accuracy of the model, and needs to solve the problem of parameter conflict caused by non-independent and identically distributed data between distributed nodes and the lack of a dynamic privacy regulation mechanism.
[0005] To solve the above technical problems, the specific technical solutions of the present invention are as follows:
[0006] The method for model encryption and privacy protection for artificial intelligence algorithms provided by the present invention includes:
[0007] Step S101, obtaining the original business data, identifying sensitive attributes through quantum feature extraction and dimensionality reduction processing, and generating a dimensionality-reduced feature vector;
[0008] Step S102, inputting the dimensionality-reduced feature vector into a multi-objective optimization and hierarchical algorithm to generate a privacy level mapping table including data sensitivity levels and cleaned structured data;
[0009] Step S103: Based on the privacy level mapping table, dynamically adjust the aggregation weights of participating nodes in the federated learning framework, select a subset of low-latency nodes through quantum optimization, and generate global model parameters.
[0010] Step S104: Perform quantum fully homomorphic encryption on the highly sensitive layers in the global model parameters according to the privacy level mapping table, and perform quantum sparse compression on the encrypted parameters.
[0011] Step S105: Inject dynamic noise generated based on reinforcement learning into the compressed encrypted parameters to generate noisy encrypted model parameters.
[0012] Step S106: Locate the incrementally updated part of the noisy encrypted model parameters through quantum hash comparison, generate an increment list, and update the global model.
[0013] Step S107: Receive a user inference request, use quantum anomaly detection to identify high-frequency query behaviors, and perform fuzzification processing on the output results of the updated global model.
[0014] Step S108: Intercept illegal transmissions according to compliance rules matched by data geographical area labels, and generate an audit chain through quantum secure hashing.
[0015] Step S109: Dynamically adjust the encryption intensity and noise injection strategy based on the risk indicators in the audit chain, and feedback the adjusted policy parameters to the federated learning node selection and encryption module.
[0016] Furthermore, for the model encryption and privacy protection method for artificial intelligence algorithms of the present invention, the step S101 includes:
[0017] Extract the feature covariance matrix in parallel through quantum principal component analysis, and extract the eigenvectors associated with sensitive attributes.
[0018] Input the eigenvectors into a multi-objective optimization and grading algorithm, and simultaneously use data sensitivity grading, service availability scoring, and GDPR compliance indicators as optimization objectives to generate a Pareto optimal solution set.
[0019] Generate a privacy level mapping table according to the optimal solutions in the Pareto optimal solution set. The privacy level mapping table includes encryption level markings for each data field, and is used to control the encryption intensity of the local training parameters of federated learning participating nodes.
[0020] Furthermore, for the model encryption and privacy protection method for artificial intelligence algorithms of the present invention, the step S103 includes:
[0021] Construct a Gaussian process model based on a Bayesian optimizer, and predict the weight values of each participating node in federated learning according to the historical aggregation contribution degrees of the participating nodes in federated learning;
[0022] Map the node communication delay and data distribution similarity to the Hamiltonian of the Ising model, and solve for the optimal federated node subset through a quantum annealing machine;
[0023] According to the predicted weight values of each participating node in federated learning and the optimal federated node subset, adjust the weighted average coefficient in the federated aggregation formula to generate global model parameters.
[0024] Furthermore, for the model encryption and privacy protection method for artificial intelligence algorithms of the present invention, the step S104 includes:
[0025] According to the global model parameters marked as the high-sensitivity level in the privacy level mapping table, apply the quantum fully homomorphic encryption algorithm for encryption;
[0026] Perform compression processing on the encrypted parameters through the sparse coding layer of the quantum neural network to generate compressed ciphertext parameters;
[0027] Input the compressed ciphertext parameters into the homomorphic operation interface of the differential privacy noise injection module to maintain noise superposition in the ciphertext state.
[0028] Furthermore, for the model encryption and privacy protection method for artificial intelligence algorithms of the present invention, the step S105 includes:
[0029] Through a deep deterministic policy gradient reinforcement learning model, use the privacy budget consumption rate and model accuracy loss as reward functions to generate the model layer position and variance intensity strategy for noise injection;
[0030] Use a quantum random number generator to generate a noise sequence that conforms to a Gaussian distribution;
[0031] Through the homomorphic addition operation of quantum fully homomorphic encryption, superimpose the noise sequence on the ciphertext of the encrypted parameters to generate encrypted model parameters with noise.
[0032] Furthermore, for the model encryption and privacy protection method for artificial intelligence algorithms of the present invention, the step S106 includes:
[0033] Based on the Grover algorithm, perform a quantum state comparison between the current global model parameters and the historical version, locate the newly added or modified parameters, and generate an incremental parameter list;
[0034] Perform quantum sparse coding processing on the incremental parameter list, and generate compressed ciphertext through the quantum fully homomorphic encryption algorithm;
[0035] Input the compressed ciphertext into the blockchain storage interface of the audit trail module, trigger the global model update, and generate the updated global model parameters.
[0036] Further, in the model encryption and privacy protection method for artificial intelligence algorithms of the present invention, the step S107 includes:
[0037] Perform quantum kernel mapping on the user request features through a quantum support vector machine. When it is detected that the number of requests within a unit time exceeds a preset threshold, it is determined as a high-frequency query abnormal behavior.
[0038] After triggering the defense mechanism, dynamically adjust the interval boundary value according to the ROC curve of the preset model validation set, and convert the probability value output by the updated global model into interval labels of high risk, medium risk, and low risk.
[0039] Input the abnormal behavior log into the rule matching module of the compliance routing engine to block the transmission of illegal data streams including sensitive fields.
[0040] Further, in the model encryption and privacy protection method for artificial intelligence algorithms of the present invention, the step S108 includes:
[0041] Perform digital signature on the federated learning node selection record and the noise injection operation log based on the lattice cryptography-based quantum secure hash algorithm.
[0042] Synchronize the signed log data to the permissioned blockchain node to generate an immutable audit chain including a timestamp.
[0043] Input the privacy leakage risk index in the audit chain into the optimization objective function of the quantum hybrid optimization framework to drive the dynamic adjustment of the encryption strength parameter.
[0044] Further, in the model encryption and privacy protection method for artificial intelligence algorithms of the present invention, the step S109 includes:
[0045] Search for the optimal combination of the key length of quantum fully homomorphic encryption and the differential privacy noise variance through the quantum approximate optimization algorithm.
[0046] Combine the classical gradient descent algorithm to locally optimize the weight allocation strategy for federated node selection, and generate the updated encryption strength parameter and noise injection rule.
[0047] Synchronize the encryption strength parameter and the noise injection rule to the aggregation controller and the differential privacy module of the federated learning framework in real time.
[0048] Further, the model encryption and privacy protection method for artificial intelligence algorithms of the present invention further includes:
[0049] According to the privacy leakage risk score in the audit chain, inversely adjust the selection priority of the participating nodes in federated learning;
[0050] Based on the model accuracy loss data monitored in real time, optimize the differential privacy noise variance and the geographical transmission constraints in the compliance routing rules;
[0051] Feed back the adjusted node selection priority, noise variance, and geographical transmission constraint parameters to the dimensionality reduction processing unit of the quantum feature extraction module and the key manager of the hierarchical encryption module.
[0052] Advantages of the present invention;
[0053] Through the quantum optimization of node selection and multi-objective weighted aggregation strategy, the present invention effectively solves the parameter conflict problem caused by data heterogeneity in federated learning. The quantum annealing algorithm screens data complementary nodes to reduce parameter divergence, and the weight coefficients optimized by the NSGA-II algorithm balance the contribution differences of heterogeneous data, improving the model convergence efficiency; The hierarchical encryption and adaptive noise regulation mechanism, while protecting highly sensitive parameters with quantum fully homomorphic encryption, combines a dynamic noise injection strategy driven by reinforcement learning to achieve a dynamic balance between privacy protection intensity and model accuracy, reducing the negative impact of noise on convergence stability; The audit-driven closed-loop feedback system reversely optimizes node selection and noise rules through a quantum security audit chain, and the quantum hybrid optimization framework synchronously tunes the encryption intensity and noise parameters, forming a full-link adaptive collaboration from data preprocessing to model inference, and finally achieving the technical effect of global optimality of model aggregation efficiency and privacy-utility in the non-independent and identically distributed data scenario. Brief Description of the Drawings
[0054] In order to more clearly illustrate the technical solutions of the present invention, the accompanying drawings required for the embodiments will be briefly introduced below. Obviously, for those of ordinary skill in the art, other accompanying drawings can be obtained based on the accompanying drawings without creative efforts.
[0055] Figure 1 It is a flowchart of the model encryption and privacy protection method for artificial intelligence algorithms provided by the embodiments of the present invention. Detailed Embodiments
[0056] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below in conjunction with specific embodiments of the present invention and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention. The following will describe in detail the technical solutions provided by each embodiment of the present invention with reference to the drawings. To better understand the objectives of the present invention, the present invention will be further described in detail below.
[0057] Please refer to Figure 1 , the model encryption and privacy protection method for artificial intelligence algorithms provided by the present invention includes:
[0058] Step S101: Obtain the original business data, identify sensitive attributes through quantum feature extraction and dimensionality reduction processing, and generate a dimensionality-reduced feature vector.
[0059] After obtaining the original business data, perform standardized preprocessing on the data to eliminate the influence of dimensional differences and outliers. Specifically, perform word segmentation, entity recognition, and missing value imputation on unstructured data, and perform normalization and feature encoding conversion on structured data. The preprocessed data is loaded into the quantum computing unit through a quantum random access memory, and the classical feature vector is mapped into a quantum state superposition form by quantum amplitude encoding to form the input data of the quantum principal component analysis algorithm.
[0060] The quantum principal component analysis module calculates the eigenvalues and eigenvectors of the feature covariance matrix in parallel through the quantum phase estimation algorithm. In the quantum circuit, a quantum simulator of the covariance matrix is constructed through controlled rotation gate operations, and the matrix diagonalization process is accelerated using quantum parallelism. The eigenvectors are arranged in descending order of eigenvalues, and the feature dimensions with a correlation with sensitive attributes exceeding a preset threshold are selected to generate a low-dimensional feature subspace. Sensitive attribute recognition is based on the calculation of the Pearson correlation coefficient between the feature vector and the preset sensitive fields, and a white list of sensitive attributes is defined in combination with the business scenario to dynamically adjust the feature screening conditions.
[0061] The dimensionality-reduced feature vector is converted into a classical data format through quantum state measurement, retaining the key sensitive attribute correlation dimensions and removing redundant features. The dimension of the feature vector is dynamically determined according to the variance interpretation rate of the quantum principal component analysis, maximizing the information retention within the preset compression rate range. The output feature vector carries the key sensitive attribute distribution pattern of the original data, providing a structured input for subsequent privacy grading. This process accelerates the processing of high-dimensional data through quantum computing, identifying sensitive information at the feature space construction stage and reducing the computational complexity of the subsequent privacy protection module.
[0062] After the generation of the dimensionality-reduced feature vectors, format verification and data integrity verification are performed to prevent data distortion caused by quantum noise during the quantum computing process. The feature vectors that pass the verification are stored in a distributed database, and a data channel is established with the privacy level mapping table construction module to support the dynamic classification of sensitive levels by the multi-objective optimization algorithm. The collaborative design of preprocessing and feature extraction enables the identification of sensitive attributes and dimensionality compression of the original business data before it enters the federated learning framework, laying a data foundation for end-to-end privacy protection.
[0063] Step S102: Input the dimensionality-reduced feature vectors into a multi-objective optimization and classification algorithm to generate a privacy level mapping table including data sensitive levels and cleaned structured data.
[0064] After the dimensionality-reduced feature vectors are input into the multi-objective optimization and classification module, a multi-objective function set including data sensitivity scores, business availability weights, and compliance constraints is constructed to start the classification algorithm process. The data sensitivity scores are calculated based on the correlation strength between the feature vectors and the preset sensitive attributes. The business availability weights are determined by the contribution of the feature dimensions to the prediction of business metrics. The compliance constraints are dynamically loaded according to the data protection regulations in the target area. The module uses an improved NSGA-II algorithm to parallelly evaluate candidate solutions on the quantum computing unit to generate a set of Pareto front solutions covering different optimization objective balance points.
[0065] After generating the Pareto optimal solution set, a multi-criteria decision-making analysis process is executed. Through the preset data minimization principle and business priority rules, the optimal solutions that meet the privacy-utility balance point are screened from the solution set. The selected solutions drive the construction process of the privacy level mapping table, dividing the data fields into three sensitive levels: public level, internal level, and confidential level. The mapping table uses structured labels to mark the encryption levels and quantum key parameters of the fields. Among them, the confidential level fields are associated with high-dimensional sensitive attributes and bound to enhanced encryption policies. This table is distributed to each node through the federated learning control plane to guide subsequent differential encryption processing.
[0066] The generation process of the cleaned structured data is executed synchronously with the privacy classification. According to the sensitive level markings in the privacy level mapping table, field-level filtering and desensitization operations are performed on the original business data. The public level fields retain the original data format. The internal level fields are subjected to hash masking processing. The confidential level fields apply quantum homomorphic encryption algorithms to transform the data form. The cleaned data retains the business availability features and at the same time eliminates sensitive information that directly identifies personal identities, forming a structured data set that complies with the data compliance standards in the target area.
[0067] After receiving the cleaned data stream, the structured data storage module performs distributed sharding storage and access permission configuration. Public-level data is opened to the public storage area of the federated learning nodes. Internal-level data binds to node identity certificates to achieve fine-grained access control. Confidential-level data is transmitted to trusted nodes through the optical channel of quantum key distribution. The data storage format and the privacy level mapping table establish a dynamic association mechanism to support the on-demand invocation of data subsets at different sensitive levels during subsequent training processes. The hierarchical storage policy triggers the adaptive adjustment of encryption intensity during the data invocation phase, forming a data processing link linked to the privacy level.
[0068] The privacy level mapping table and the structured data are synchronously transmitted to the aggregation controller through the metadata interface of the federated learning framework. The field-level tags of the mapping table provide a basis for adjusting the encryption intensity of subsequent model parameters, and the cleaned structured data provides compliant inputs for local training of participating nodes. The collaborative design of the multi-objective optimization hierarchical module and the data cleaning module enables the dynamic adaptation of the feature space division and privacy protection strategy during the data preprocessing stage, laying a hierarchical control foundation for the privacy-utility balance of the entire federated learning process.
[0069] Step S103: Based on the privacy level mapping table, dynamically adjust the aggregation weights of participating nodes in the federated learning framework, select a subset of low-latency nodes through quantum optimization, and generate global model parameters.
[0070] After the privacy level mapping table is connected to the federated learning framework, the aggregation controller starts a dynamic weight adjustment mechanism. Based on the Gaussian process model constructed by the Bayesian optimizer, collect the historical aggregation contribution metrics of each participating node, including the parameter update amplitude, convergence stability, and data distribution representative parameters. The model fits the probability distribution characteristics of node contributions through a kernel function and predicts the weight allocation ratio for the next training cycle. The weight prediction results are updated to the federated aggregation control center in real time to form the decision basis for the dynamic weighting strategy.
[0071] The node selection optimization module synchronously receives the communication delay measurement data and the data distribution similarity matrix of participating nodes. The communication delay parameter is converted into the coupling strength coefficient in the Ising model after normalization processing, and the data distribution similarity is mapped into the spin interaction energy by calculating the KL divergence. The constructed Hamiltonian is input into the quantum annealing machine, and the quantum tunneling effect is used to break through the local optimal solution limit to solve the index list of the federated node subset that satisfies the delay constraint and has complementary data distribution. This process accelerates the search efficiency of the node combination space through quantum parallel computing and screens out a node cluster with low communication overhead and high data heterogeneity.
[0072] The federal aggregation controller synthesizes the dynamic weight prediction value and the quantum optimization node subset index to reconstruct the weighted strategy of the federated averaging algorithm. The weight coefficients are dynamically normalized according to the real-time contribution degrees of the members within the node subset, and a data volume proportion factor is introduced to balance the sample distribution deviation. The adjusted aggregation formula performs weighted summation operations in the ciphertext state, and combines with the sensitive levels marked in the privacy level mapping table to perform hierarchical aggregation on the local model parameters with different encryption strengths. The aggregation result is broadcast to all participating nodes through a quantum-secure channel to form a global parameter update quantity that takes into account both data privacy and model convergence efficiency.
[0073] After the global model parameters are generated, gradient verification and parameter legality verification are performed. The verification mechanism compares the integrity of the contribution parameters of each node based on the quantum-secure hash algorithm, identifies abnormal update quantities, and triggers the re-aggregation process. The parameter set that passes the verification is input into the model version management module to generate a global model snapshot with a timestamp and a node subset identifier. The snapshot data is synchronized to the federated learning network through a distributed storage interface to support participating nodes to call the latest model parameters as needed to start the next round of local training. The collaborative design of dynamic weight adjustment and quantum optimization node selection effectively alleviates the parameter drift caused by non-independent and identically distributed data and improves the model convergence stability in heterogeneous environments.
[0074] In the global parameter distribution phase, the aggregation controller enables the quantum key distribution optical channel transmission for the high-sensitivity layer parameters according to the encryption level label in the privacy level mapping table. The low-sensitivity layer parameters are transmitted using classical encryption protocols to reduce communication resource consumption. The coordinated implementation of the hierarchical transmission strategy and the dynamic aggregation mechanism realizes the adaptive balance of privacy protection intensity and communication efficiency in the federated learning process, forming a full-link optimization closed-loop from node selection, weight allocation to parameter generation.
[0075] Step S104, perform quantum fully homomorphic encryption on the high-sensitivity layer in the global model parameters according to the privacy level mapping table, and perform quantum sparse compression on the encrypted parameters;
[0076] After receiving the global model parameters, the privacy level mapping table parsing module identifies the high-sensitivity layer parameters based on the preset sensitive level labels, including key data such as the output layer weight matrix and user embedding vectors. The identification process uses a field-level label matching algorithm to divide the parameter tensor into data blocks of different sensitive levels, and the high-sensitivity layer data blocks trigger encryption processing instructions. The encryption instructions are distributed to the quantum fully homomorphic encryption engine through the federated learning control plane to start the parameter protection process.
[0077] The quantum fully homomorphic encryption engine performs lattice-cryptography-based encryption operations on high-sensitivity layer parameters. In the encryption process, the public key generated by the quantum key distribution protocol is used to perform homomorphic transformation on the parameters, supporting addition and multiplication operations in the ciphertext state. After the parameter tensor completes the encryption operation in the quantum state, it retains its mathematical operation characteristics, forming an encrypted parameter set that can directly participate in the calculation during the federated learning aggregation process. The encrypted parameters are transmitted to the sparse compression module through the quantum communication channel, avoiding the risk of privacy leakage caused by plaintext transmission.
[0078] After receiving the encrypted parameters, the quantum sparse compression module uses the encoder unit of the quantum variational autoencoder to perform low-dimensional manifold projection on the ciphertext data. The encoder quantum circuit maps the high-dimensional parameter matrix to a low-dimensional sparse space by optimizing the sparse basis vector combination, and the volume of the compressed ciphertext is significantly reduced. During the compression process, the continuity of the encryption state is maintained, so that the ciphertext data is compatible with the subsequent homomorphic operation interface before and after compression. The sparse coding parameters are temporarily stored in the quantum random access memory, waiting to be input into the differential privacy noise injection module.
[0079] Before the compressed ciphertext parameters are output, format compatibility verification and data integrity verification are performed. The verification mechanism compares the data fingerprints before and after compression based on the quantum secure hash algorithm to identify data distortion caused by quantum noise or transmission errors. The verified compressed ciphertext parameters are transmitted to the noise injection module through the homomorphic operation interface, and at the same time, the compression log is recorded in the audit tracking database. The collaborative design of the compression module and the encryption module reduces the communication overhead while maintaining data privacy, forming a closed-loop protection mechanism for the high-sensitivity parameter processing link.
[0080] The compressed encrypted parameters are stored in the distributed ciphertext database and dynamically associated with the privacy level mapping table. The storage module configures access permissions according to the sensitive level label, and the high-sensitivity layer compressed ciphertext is only allowed to be called by authorized nodes through the quantum secure channel. The storage strategy is connected with the subsequent model update process, supporting quick positioning of the encrypted and compressed data blocks during incremental parameter replacement, and improving the global model iteration efficiency. The dual processing mechanism of encryption and compression provides a full-process privacy protection foundation for the transmission, storage, and calculation of high-sensitivity data in the federated learning framework.
[0081] Step S105, injecting dynamic noise generated based on reinforcement learning into the compressed encrypted parameters to generate noisy encrypted model parameters;
[0082] After the compressed encrypted parameter is input into the noise injection module, the deep deterministic policy gradient reinforcement learning model starts the dynamic noise policy generation process. The model receives the real-time monitoring data stream of the federated learning system, including the remaining privacy budget, the accuracy loss of the model validation set, and the amplitude of the parameter update gradient. The state space is constructed as the time series features of the privacy-utility balance metric, and the action space is defined as the set of hierarchical position indices and variance intensity parameters of noise injection. The reward function combines the negative constraint of the privacy budget consumption rate and the weight combination of the model accuracy loss, driving the policy network to generate a dynamic noise configuration scheme.
[0083] The quantum random number generator is based on the physical entropy source of quantum randomness of a single photon detector, and performs Gaussian distribution fitting on the original random sequence through a post-processing algorithm. After the generated noise sequence is verified for its distribution characteristics by the Kolmogorov-Smirnov test, it is input into the buffer queue of the noise injection controller. The dimension of the noise sequence is automatically aligned with the tensor structure of the encrypted parameter, realizing the one-to-one mapping relationship between the noise element and the target parameter, and avoiding the model accuracy perturbation caused by the injection position deviation.
[0084] After receiving the encrypted parameter and the noise sequence, the homomorphic noise superposition interface performs the homomorphic addition gate operation defined by the quantum fully homomorphic encryption protocol. The encrypted parameter is linearly superposed with the noise sequence in the quantum state, and the integrity of the ciphertext format is verified through the quantum Fourier transform during the superposition process. The injected noisy parameter retains the homomorphic operation ability and satisfies the differential privacy constraint condition after decryption, forming a set of encrypted noise parameters that takes into account both privacy protection and model usability. The noise injection log is recorded in the audit tracking database in real time, providing a data basis for subsequent policy optimization.
[0085] After the noisy encrypted parameter is generated, the noise impact assessment and model convergence monitoring are performed. The assessment module compares the amplitude of the model gradient change before and after the noise injection, identifies abnormal parameter fluctuations, and triggers the dynamic calibration of the noise variance. The calibration signal is fed back to the reinforcement learning policy network to optimize the noise configuration parameters in the next training cycle. The monitoring data is synchronously input into the federated learning aggregation controller, providing a noise compensation reference value for the global model parameter update and reducing the negative impact of noise injection on the model convergence rate.
[0086] The noise parameter is transmitted to the distributed storage node through a quantum secure channel and associated with the privacy level mapping table. The storage module configures multi-version noise parameter snapshots according to the sensitive level label, supporting the on-demand loading of historical noise configurations when the model is rolled back. The collaborative design of the dynamic noise injection mechanism and the encryption compression module realizes the adaptive balance between the privacy protection intensity and the model utility while maintaining the continuity of ciphertext operations, providing data integrity guarantee for subsequent incremental updates and audit tracing.
[0087] Step S106: Locate the incrementally updated part of the encrypted model parameters with noise through quantum hashing comparison, generate an increment list, and update the global model.
[0088] After the encrypted model parameters with noise are input into the quantum hashing comparison module, quantum state encoding and data difference location with the historical version parameters are performed. The quantum circuit constructed by the Grover algorithm is used to perform parallel comparison between the current parameters and the historical version, and the quantum amplitude amplification principle is utilized to accelerate the search for parameter differences. When it is detected that the parameter value deviation exceeds the preset threshold, it is marked as an incrementally updated item, and an increment matrix containing the parameter index and the difference value is generated. This process significantly improves the comparison efficiency of large-scale parameter sets through quantum parallel computing.
[0089] After the increment matrix is input into the sparse coding module, the quantum variational autoencoder performs low-rank approximation decomposition on the difference data. The encoder quantum circuit learns the sparse representation pattern of the increment parameters and projects the high-dimensional difference matrix onto the low-dimensional space spanned by the orthogonal basis vectors. The compressed sparse representation data is re-encrypted through a quantum fully homomorphic encryption scheme based on learning with errors on rings, generating a compressed ciphertext data packet that meets the data security standard. The compression process maintains the ciphertext operation characteristics and supports the homomorphic processing requirements in the subsequent aggregation stage.
[0090] After the compressed ciphertext data packet is transmitted to the blockchain storage interface of the audit trail module, a smart contract is called to generate an audit transaction request containing the timestamp and the operator identifier. The transaction request triggers the permissioned blockchain consensus node to execute the zero-knowledge proof verification process to verify the legality of the increment parameter modification and the compliance of the operation permissions. The verified increment parameters are decrypted and merged into the global model copy, generating an updated model parameter set with a version identifier. The update log generates a digital fingerprint through the quantum secure hash algorithm and is synchronously written into the blockchain to form an immutable audit chain record.
[0091] After the global model update is completed, the version management module performs the presetting of the parameter rollback ability. A rollback index table is established through the multi-version parameter snapshots stored in the blockchain. When it is detected that the model accuracy drops abnormally, the smart contract is triggered to load the historical parameter versions in chronological order. The rollback mechanism and the incremental update process form a closed loop, providing fault tolerance guarantee for model iteration. The updated parameter set is synchronized to the federated learning participating nodes through the quantum key distribution optical channel, supporting each node to start the local training task based on the latest model.
[0092] The collaborative design of the incremental update process and the quantum hashing comparison module reduces the communication overhead while maintaining data integrity. The connection between the compression and encryption mechanism and the blockchain verification link realizes the full-process traceability from difference location to model update. The dynamic parameter replacement strategy combined with the version rollback ability improves the robustness and iteration efficiency of the federated learning framework in the non-i.i.d. data scenario, forming a continuous optimization link for privacy protection and model utility.
[0093] Step S107, receiving a user reasoning request, using quantum anomaly detection to identify high-frequency query behaviors, and performing fuzzification processing on the output results of the updated global model;
[0094] After the user's reasoning request is connected to the federated learning framework, the quantum anomaly detection module starts the real-time request feature analysis process. The request feature vector is mapped to the high-dimensional Hilbert space by the quantum kernel function, and the query behavior pattern is determined by the classification boundary constructed by the quantum support vector machine. When the request frequency in the unit time window exceeds the dynamic threshold, the abnormal behavior marking mechanism is triggered. The dynamic threshold is dynamically adjusted according to the historical access pattern baseline and the compliance constraints preset by the target area data protection regulations to meet the detection sensitivity requirements of different business scenarios.
[0095] After detecting high-frequency query anomalies, the model output adaptation module performs fuzzification processing on the global model inference results. The probability value output is converted into discrete risk interval labels through quantum fuzzy logic operations, including high risk, medium risk and low risk levels. The interval boundary values are dynamically calibrated based on the ROC curve of the model verification set to balance the detection sensitivity and false alarm rate indicators. The converted interval labels are returned to the user terminal through the quantum secure channel, hiding the original probability distribution details to reduce the possibility of privacy leakage.
[0096] Abnormal behavior logs are input into the rule matching module of the compliance routing engine in real time, and the preset list of sensitive fields and cross-border data transmission policies are loaded. When abnormal requests are identified to contain user ID numbers, biometrics and other tag fields, the traffic filtering rule set is activated. The interception instruction triggers the quantum secure hash engine to generate an operation fingerprint, which is bound to the abnormal event log and written into the blockchain audit chain to provide reverse data flow for subsequent model optimization and policy adjustment. The blocked data flow is redirected to the isolated storage area, waiting for the manual review process to process.
[0097] The compliance routing engine matches the transmission rule base according to the data regional label, and generates interception instructions for requests that violate the data localization requirements of the target area. The transmission rule base integrates geo-fence parameters and real-time policy update data, and dynamically loads applicable terms through the semantic parsing engine. The interception operation record generates a verifiable credential through the quantum security signature algorithm, which is synchronized to the permission chain node to form an unalterable audit evidence chain. The collaborative design of the routing strategy and the anomaly detection module superimposes transmission control on the basis of output fuzzification to form a multi-level privacy protection system.
[0098] The output data after fuzzification is temporarily stored through the distributed cache interface, and access frequency monitoring and data life cycle management are performed. The cache module configures different retention periods according to the sensitive level tags, and a short-term automatic erasure mechanism is enabled for data with high-risk tags. A dynamic association is established between the data flow path and the privacy level mapping table to maintain business continuity while reducing storage risks. The closed-loop design of anomaly detection and output processing enables the inference service on the user side to build a full-link privacy protection network from request access to result feedback while meeting low-latency response requirements.
[0099] Step S108, intercept the illegal transmission according to the compliance rules matched by the data geographical area tag, and generate an audit chain through quantum-secure hashing;
[0100] After receiving the transmission request, the data geographical area tag matching module calls the geofence policy library to load the data compliance rules for the target area. The geofence parameters are dynamically generated based on the data storage location, transmission destination, and governing regulations, and the natural language clauses are converted into executable policy instructions through the semantic parsing engine. The policy library integrates region-specific data protection regulations updated in real time, including data localization requirements and cross-border transmission whitelists, to form a multi-dimensional set of compliance constraints.
[0101] The transmission request parsing engine extracts the geographical area tag and content features in the packet metadata and performs multi-level matching with the compliance rule library. The matching process uses a rule determination algorithm based on a finite state machine. When it detects that the data flow is to a non-whitelist area or contains restricted sensitive fields, a hierarchical interception mechanism is triggered. The primary interception performs packet filtering at the protocol layer, and the advanced interception activates the application layer session termination instruction to form a multi-level transmission control system. After the interception instruction is generated, the audit log recording process is started synchronously.
[0102] The quantum-secure hash engine performs quantum-resistant digital signatures on the intercepted operation logs. The hash function based on lattice cryptography converts the operation type, timestamp, and data fingerprint into a fixed-length digest, and uses the private key generated by the quantum key distribution protocol for signing. The signed log data is submitted through the permissioned chain node consensus interface, and after being verified by the practical Byzantine fault tolerance mechanism, it is appended to the blockchain data structure to generate an immutable audit chain with a time series. The audit chain block header information contains a forward hash pointer and a quantum-secure signature, forming a cross-block data integrity verification link.
[0103] The audit chain storage module distributes and stores the signed logs in the encrypted database of the permissioned chain nodes, and establishes access permission control based on the sensitive level. The quantum key distribution optical channel transmission protocol is enabled for high-sensitivity operation records, and only authorized audit nodes can access the complete log data through the quantum-secure proxy. A dynamic association index is established between the storage architecture and the privacy level mapping table to support multi-dimensional rapid retrieval of audit information according to geographical area tags, operation types, etc.
[0104] The audit chain analysis module periodically scans the blockchain ledger to extract risk indicators such as the frequency of illegal transmission events and the exposure duration of sensitive data. The indicator data is input into the objective function of the quantum hybrid optimization framework to drive the dynamic tuning of subsequent encryption strength and node selection strategies. The reverse feedback mechanism of the illegal log is connected to the real-time update interface of the policy library to form a closed-loop optimization link from transmission control to rule iteration. The collaborative design of the regional compliance policy and the quantum audit chain constructs a verifiable data governance system throughout the life cycle while blocking illegal transmissions.
[0105] Step S109: Based on the risk indicators in the audit chain, dynamically adjust the encryption strength and noise injection strategy, and feedback the adjusted policy parameters to the federated learning node selection and encryption module to form a closed-loop iteration.
[0106] The audit chain risk indicator extraction module periodically scans the blockchain ledger and analyzes quantitative parameters such as the frequency of illegal transmission events, the exposure duration of sensitive data, and the node trustworthiness score. After normalization, the risk indicators are input into the quantum hybrid optimization framework to construct a multi-objective optimization function centered on the balance between privacy protection strength and model utility. The quantum approximate optimization algorithm parallelly searches for the optimal combination of the key length of quantum fully homomorphic encryption and the differential privacy noise variance on the quantum processor to generate a candidate parameter set that meets the current risk level.
[0107] The classical optimization module extracts the feasible solution interval from the quantum optimization results, and combines the real-time communication efficiency and data distribution characteristics of the federated learning nodes to iteratively adjust the node selection weight allocation strategy through the gradient descent algorithm. The weight update signal is fed back to the quantum optimization module through the quantum-classical hybrid interface to dynamically shrink the boundary of the parameter search space and improve the convergence speed of the hybrid optimization process. The optimized encryption strength parameters and noise rules form a policy update package, which is pushed to the federated learning control plane after digital signature verification.
[0108] After receiving the update package, the policy distribution engine starts the parameter hot loading process. The encryption strength parameters are written into the key scheduler of the quantum fully homomorphic encryption module, triggering key rotation and encryption protocol version update. The noise injection rules are updated to the policy cache area of the differential privacy module to reconfigure the noise variance threshold and injection position priority. The node selection weight parameters are synchronized to the federated aggregation controller to reconstruct the weighted aggregation formula for the next training cycle. The parameter update log generates an audit fingerprint through the quantum secure hash algorithm and is appended to the blockchain to form a policy iteration traceability link.
[0109] The closed-loop feedback mechanism inputs the optimized policy parameters back into the data preprocessing stage. The dimensionality reduction unit of the quantum feature extraction module receives the updated regional transmission constraint parameters and dynamically adjusts the weight coefficients of geographical labels in feature screening. The key manager of the hierarchical encryption module updates the quantum key distribution policy according to the node priority table and enables an enhanced anti-quantum attack protocol for high-priority communication links. The collaborative tuning of all-link parameters enables the data preprocessing, model training, and inference links to form a dynamically linked privacy-utility balance system.
[0110] The policy iteration verification module monitors the actual effects of the encryption intensity and noise policy in the new cycle of federated learning. By comparing the newly generated privacy risk metrics in the audit chain with the historical baseline data, it evaluates the impact of parameter adjustment on the model convergence speed and the probability of privacy leakage. The evaluation results are input as feedback signals into the quantum hybrid optimization framework to drive the dynamic tuning of the next round of policy parameters. The closed-loop iteration mechanism maintains the privacy protection intensity and model availability of the federated learning system in the data heterogeneous scenario through continuous risk perception and policy response.
[0111] In the data processing stage, the original business data is input into the quantum feature extraction module. The feature covariance matrix is calculated in parallel through the quantum principal component analysis algorithm to identify sensitive attributes including user identity information and location coordinates, and the dimensionality-reduced feature vector is output. This process uses the parallel computing characteristics of quantum bits to accelerate the diagonalization of the covariance matrix, and the dimensionality of the extracted feature vector is reduced by more than 60% compared with the classical algorithm, providing an input basis for subsequent privacy grading.
[0112] The dimensionality-reduced feature vector is input into the multi-objective optimization grading module. With the data sensitivity score, business availability metrics, and GDPR compliance requirements as the optimization objectives, the Pareto front solution set is generated through the NSGA-II algorithm. A privacy level mapping table is constructed based on the solution set to divide the data fields into public, internal, and confidential layers, and at the same time, the cleaned structured data is output. The privacy level mapping table labels the sensitive levels through field-level tags to guide the differential encryption policies of federated learning nodes.
[0113] After receiving the privacy level mapping table, the federated learning framework constructs a Gaussian process model based on the Bayesian optimizer during the local training process of participating nodes to predict the aggregation weights according to the historical contribution degree of the nodes. At the same time, the node communication delay and data distribution similarity parameters are mapped to the Hamiltonian of the Ising model, and the optimal node subset is solved through a quantum annealer. The dynamically adjusted aggregation weights and the selected low-latency nodes are jointly input into the aggregation formula to generate global model parameters.
[0114] The global model parameters enter the hierarchical encryption module. According to the confidential levels marked in the privacy level mapping table, the quantum fully homomorphic encryption algorithm is applied to the output layer parameters. The encrypted parameters are input into the quantum neural network compression module, and the ciphertext volume is compressed by more than 70% through sparse coding. The compressed ciphertext parameters are transmitted to the noise injection interface while remaining encrypted, avoiding the risk of data leakage in the intermediate decryption process.
[0115] After the noise injection module receives the encrypted parameters, the deep deterministic policy gradient model generates the model layer position and variance intensity policy for noise injection based on the real-time privacy budget consumption rate and model accuracy loss data. The quantum random number generator generates a true random noise sequence that conforms to the Gaussian distribution, and the noise is superimposed on the ciphertext parameters through quantum homomorphic addition operation. The parameters after injecting noise still satisfy the differential privacy constraint after decryption processing, forming encrypted model parameters with noise.
[0116] Based on the Grover algorithm, the incremental update module compares the parameters with noise and the historical version in the quantum state to locate the newly added or modified parameters and generate an incremental list. After being compressed by quantum sparse coding, the incremental list is re-encrypted through the quantum fully homomorphic encryption algorithm and input into the blockchain storage node. The global model replaces the parameters according to the incremental list, generates an updated model version, and synchronizes it to each federated learning node.
[0117] When a user initiates an inference request, the quantum support vector machine performs a quantum kernel space mapping on the request features to detect high-risk queries whose request frequency exceeds the preset threshold within a unit time. After the defense mechanism is triggered, the exact probability value output by the model is converted into high, medium, and low-risk interval labels through quantum fuzzy logic. The abnormal query log is input into the compliance routing engine in real time to block the cross-regional transmission of illegal data including sensitive fields.
[0118] The compliance routing engine matches the preset transmission rules according to the data geographical region label and generates an interception instruction for requests that violate the data localization requirements in Region A. All operation logs are digitally signed through a quantum-secure hash algorithm based on lattice cryptography to generate an audit chain data block including a timestamp. The audit chain data is stored on the chain in real time to form an immutable operation trace record.
[0119] The audit chain data is input into the quantum hybrid optimization framework. The quantum approximate optimization algorithm takes the privacy leakage risk score and model accuracy index as the optimization objectives to search for the optimal combination of the encryption key length and noise variance. The classical gradient descent algorithm synchronously optimizes the weight distribution parameters in the federated node selection strategy. The updated encryption intensity parameters and noise rules are synchronously updated to the dimensionality reduction unit of the feature extraction module and the key manager of the encryption module in real time, forming a technical closed-loop from data input to policy iteration.
[0120] Specifically, for the model encryption and privacy protection method for artificial intelligence algorithms, step S101 includes:
[0121] Extract the eigenvector associated with sensitive attributes by parallel computing the feature covariance matrix through quantum principal component analysis;
[0122] Input the eigenvector into the multi-objective optimization and grading algorithm, and generate a Pareto optimal solution set with data sensitivity grading, business availability scoring, and GDPR compliance indicators as optimization objectives;
[0123] Generate a privacy level mapping table according to the optimal solution in the Pareto optimal solution set. The privacy level mapping table includes encryption level marks for each data field, and is used to control the encryption intensity of local training parameters of federated learning participating nodes.
[0124] In the quantum feature extraction stage, after receiving the original business data, the quantum principal component analysis module diagonalizes the feature covariance matrix using the quantum bit parallel computing mechanism. This process accelerates the eigenvalue decomposition through the quantum phase estimation algorithm, identifies the sensitive attribute dimensions related to user identity information and location trajectory, and generates a set of low-dimensional eigenvectors. The parallel nature of quantum computing improves the high-dimensional data processing efficiency by two orders of magnitude compared to classical algorithms, providing a high-precision feature space representation for subsequent privacy grading.
[0125] After receiving the dimensionality-reduced eigenvector, the multi-objective optimization and grading module constructs a multi-objective function including data sensitivity scoring, business availability weight, and compliance constraints in Region A. The data sensitivity scoring is calculated based on the Pearson correlation coefficient between the eigenvector and sensitive attributes, and the business availability weight is determined by the regression contribution degree of the feature dimension to the business indicators. The improved NSGA-II algorithm is used to parallelly evaluate the solution set on the quantum computing unit to generate a Pareto front solution set covering different optimization objective balance points. Each Pareto solution corresponds to a specific privacy-utility balance strategy.
[0126] The privacy level mapping table construction module conducts multi-criteria decision analysis on the Pareto optimal solution set, and selects the optimal solution plan that meets the data minimization principle in Region A. According to the selected plan, the data fields are divided into three sensitive levels: public level, internal level, and confidential level. The confidential level fields include the feature dimensions that directly identify personal identity. The mapping table is stored in XML structured format, and each field is marked with an encryption level label and the corresponding quantum key length parameter. This table is distributed to each participating node through the federated learning control plane to guide the differential encryption processing of different sensitive level parameters during local training.
[0127] Specifically, for the model encryption and privacy protection method for artificial intelligence algorithms, step S103 includes:
[0128] Construct a Gaussian process model based on a Bayesian optimizer, and predict the weight values of each participating node in federated learning according to the historical aggregation contribution degrees of each participating node in federated learning;
[0129] Map the node communication delay and data distribution similarity to the Hamiltonian of the Ising model, and solve for the optimal federated node subset through a quantum annealing machine;
[0130] According to the predicted weight values of each participating node in federated learning and the optimal federated node subset, adjust the weighted average coefficient in the federated aggregation formula to generate global model parameters.
[0131] In the federated learning node weight prediction stage, the Bayesian optimizer collects the model update contribution degree data of each participating node in the previous training rounds, including the parameter update amplitude and the convergence stability index. The Gaussian process model uses the historical contribution degrees as training samples, fits the probability distribution characteristics of the node contribution degrees through a kernel function, and outputs the expected weight values for future training rounds. The weight prediction results are updated to the federated aggregation control center in real time to provide a prior knowledge base for dynamic adjustment.
[0132] The node selection optimization module synchronously receives the communication delay measurement data and the data distribution similarity matrix of the participating nodes. The communication delay data is transformed into the coupling strength coefficient in the Ising model after normalization processing, and the data distribution similarity is mapped to the spin interaction energy through KL divergence calculation. The constructed Ising model Hamiltonian is input into the quantum annealing machine, and with the assistance of the quantum tunneling effect, it quickly converges to the ground state, and outputs an optimal node subset index list that satisfies the delay constraint and has complementary data distributions.
[0133] The federated aggregation controller synthesizes the weight prediction value and the node subset index to improve the traditional federated averaging algorithm. The weighted average coefficient is dynamically normalized according to the real-time weight values of each member in the node subset, and at the same time, a data volume ratio factor is introduced to balance the sample distribution deviation. The adjusted aggregation formula performs a weighted summation operation in the ciphertext state to generate global model parameters that meet the data compliance requirements of Region A. These parameters are broadcast to all participating nodes through a quantum secure channel to start the next round of federated training cycle.
[0134] Specifically, for the model encryption and privacy protection method for artificial intelligence algorithms, the step S104 includes:
[0135] Encrypt the global model parameters marked as the high-sensitivity level in the privacy level mapping table by applying the quantum fully homomorphic encryption algorithm;
[0136] Compress the encrypted parameters through the sparse coding layer of the quantum neural network to generate compressed ciphertext parameters;
[0137] Input the compressed ciphertext parameters into the homomorphic operation interface of the differential privacy noise injection module to keep the noise superposition in the ciphertext state.
[0138] In the model parameter encryption stage, the privacy level mapping table parsing module identifies the model parameter levels marked as confidential, including the user portrait embedding vector and the output layer weight matrix. The quantum fully homomorphic encryption engine adopts an encryption scheme based on lattice cryptography, assigns independent quantum key pairs to each confidential parameter, and performs addition and multiplication homomorphic operations in the ciphertext space. The encrypted parameters maintain the tensor data structure and are transmitted to the compression processing module through the quantum channel.
[0139] After receiving the encrypted parameters, the sparse coding layer in the quantum neural network learns the low-dimensional manifold representation of the ciphertext data through the quantum variational autoencoder structure. This layer uses a quantum circuit to construct an encoder-decoder architecture, and projects the high-dimensional parameter matrix to the sparse basis vector space while keeping the ciphertext state unchanged. The volume of the compressed ciphertext parameters is reduced to less than 30% of the original data, while retaining the homomorphic operation compatibility.
[0140] The compressed ciphertext parameters are input into the differential privacy noise injection interface, which performs a protocol handshake with the quantum homomorphic operation unit to verify the ciphertext format compatibility. The noise generator generates a true random noise sequence based on the principle of quantum random walk, and superimposes the noise on the compressed ciphertext parameters through the homomorphic addition operation. The superimposition process is completed entirely in the ciphertext space, avoiding the risk of information leakage caused by parameter decryption, and meeting the requirements of the data security regulations in Region A for the processing of sensitive information.
[0141] Specifically, for the model encryption and privacy protection method for artificial intelligence algorithms, step S105 includes:
[0142] Through the deep deterministic policy gradient reinforcement learning model, using the privacy budget consumption rate and the model accuracy loss as the reward function, generate the model layer position and variance intensity policy for noise injection;
[0143] Use a quantum random number generator to generate a noise sequence that conforms to the Gaussian distribution;
[0144] Through the homomorphic addition operation of quantum fully homomorphic encryption, superimpose the noise sequence on the ciphertext of the encrypted parameters to generate encrypted model parameters with noise.
[0145] In the noise strategy generation stage, the deep deterministic policy gradient reinforcement learning model receives the real-time monitoring data of the federated learning system, including the remaining privacy budget, the accuracy of the model validation set, and the magnitude of the parameter update gradient. The state space of the model is defined as the time series characteristics of the privacy-accuracy balance metric, and the action space is the position index and variance parameter of the noise injection layer. The reward function is designed as a weighted combination of the negative logarithmic function of the privacy budget consumption rate and the model accuracy loss, driving the policy network to generate a dynamic noise configuration scheme.
[0146] The quantum random number generation module is based on the physical entropy source of quantum randomness of a single photon detector, and performs Gaussian distribution fitting on the original random sequence through a post-processing algorithm. After the generated noise sequence is verified for its distribution characteristics by the Kolmogorov-Smirnov test, it is input into the buffer of the noise injection controller. This sequence is automatically aligned with the dimension of the encrypted parameter tensor to ensure a one-to-one correspondence between the noise elements and the parameters to be processed.
[0147] After receiving the encrypted parameters and the noise sequence, the homomorphic noise superposition interface performs the homomorphic addition gate operation defined by the quantum fully homomorphic encryption protocol. The encrypted parameters are linearly superposed with the noise sequence in the quantum state, and the integrity of the ciphertext format is verified through the quantum Fourier transform. The parameters after injecting noise retain the homomorphic operation ability and satisfy the (ε, δ)-differential privacy constraint condition after decryption, meeting the data anonymization processing standard in Region A. The noise injection log is recorded in real time in the audit tracking database for the subsequent policy optimization module to evaluate the effect.
[0148] Specifically, for the model encryption and privacy protection method for artificial intelligence algorithms, the step S106 includes:
[0149] Based on the Grover algorithm, perform a quantum state comparison between the current global model parameters and the historical versions, locate the newly added or modified parameters, and generate an incremental parameter list;
[0150] Perform quantum sparse coding processing on the incremental parameter list and generate compressed ciphertext through the quantum fully homomorphic encryption algorithm;
[0151] Input the compressed ciphertext into the blockchain storage interface of the audit tracking module, trigger the global model update, and generate the updated global model parameters.
[0152] In the quantum hash comparison stage, the Grover's algorithm quantum circuit receives the current global model parameters and the quantum state encoded data of the historical version, and accelerates the search for parameter differences through the principle of quantum amplitude amplification. The algorithm compares all parameter components in parallel in the quantum superposition state. When it detects that the parameter value deviation exceeds the preset threshold, it marks it as a modified item, and generates an index list of incremental parameters and a numerical difference matrix. This process improves the efficiency by a square root factor compared to the classical comparison algorithm, and is applicable to the rapid difference location of large-scale model parameters.
[0153] The incremental parameter list is input into the quantum sparse coding module, and the quantum variational autoencoder is used to perform a low-rank approximation decomposition on the difference matrix. The encoder quantum circuit learns the sparse representation pattern of the parameter differences, and projects the high-dimensional incremental data into the low-dimensional space spanned by the orthogonal basis vectors. The compressed sparse representation data is re-encrypted through a quantum fully homomorphic encryption scheme based on learning with errors on rings, and a compressed ciphertext data packet that meets the data security standards of Region A is generated.
[0154] After the blockchain interface of the audit trail module verifies the compliance of the compressed ciphertext format, it calls the smart contract to generate an audit transaction request including a timestamp. The transaction request triggers the permissioned blockchain consensus node to execute the model update verification process, and verifies the legality of the modification of the incremental parameters through zero-knowledge proof. The verified incremental parameters are decrypted and merged into the global model copy, and an updated model parameter set with a version identifier is generated. The updated parameter set is synchronized to the federated learning participating nodes through the quantum key distribution optical channel, completing the closed-loop management of the model iteration cycle.
[0155] Specifically, for the model encryption and privacy protection method for artificial intelligence algorithms, step S107 includes:
[0156] Perform quantum kernel mapping on the user request features through a quantum support vector machine. When it detects that the number of requests within a unit time exceeds the preset threshold, it is determined as a high-frequency query abnormal behavior;
[0157] After triggering the defense mechanism, convert the probability value output by the updated global model into interval labels of high risk, medium risk, and low risk;
[0158] Input the abnormal behavior log into the rule matching module of the compliance routing engine to block the transmission of illegal data streams including sensitive fields.
[0159] In the quantum anomaly detection phase, after receiving the feature vectors requested by the user, the quantum support vector machine maps the features to a high-dimensional Hilbert space through the quantum kernel trick. The quantum kernel function is constructed using a radial basis function based on the quantum Fourier transform, and the quantum parallelism is utilized to accelerate the calculation of the kernel matrix. When the detection engine statistically discovers that the request frequency of a specific user session within a fixed time window exceeds the dynamic threshold (which is set according to the historical access pattern and the data protection regulations in Region A), an abnormal behavior flag is triggered and a security alert event is generated.
[0160] After the defense mechanism is triggered, the model output adaptation module performs a fuzzification process on the global model inference result. The probability values are mapped to discrete intervals through quantum fuzzy logic operations, where the high-risk interval corresponds to the distribution area of the top 10% of the probability values, the medium-risk interval covers the middle 30% of the numerical range, and the low-risk interval includes the remaining 60% of the data. The interval boundary values are dynamically adjusted according to the ROC curve of the model validation set to maintain the balance between detection sensitivity and false alarm rate.
[0161] After receiving the abnormal behavior log, the compliance routing engine's rule matching module loads the preset list of sensitive fields and the data cross-border transmission constraint policy. When it detects that the abnormal request includes marked fields such as the user's ID card number and biometric features, the traffic filtering rules are activated in real time. The interception operation triggers the quantum secure hash engine to generate an operation fingerprint, which is bound to the abnormal event log and written into the blockchain audit log, providing a feedback data stream for subsequent model optimization. The blocked data flow is redirected to the isolation storage area through a secure channel and waits for the manual review process to handle.
[0162] Specifically, for the model encryption and privacy protection method for artificial intelligence algorithms, the step S108 includes:
[0163] Based on the lattice cryptography-based quantum secure hash algorithm, digitally sign the federated learning node selection record and the noise injection operation log;
[0164] Synchronize the signed log data to the permissioned blockchain nodes to generate an immutable audit chain including timestamps;
[0165] Input the privacy leakage risk indicators in the audit chain into the optimization objective function of the quantum hybrid optimization framework to drive the dynamic adjustment of the encryption strength parameters.
[0166] In the audit chain generation phase, the lattice cryptography-based quantum secure hash algorithm receives the data streams of the federated learning node selection record and the noise injection operation log. This algorithm constructs a quantum-resistant hash function using the learning with errors (LWE) problem and digitally signs the node identifier, timestamp, and operation type fields in the log. The signing process is completed on a quantum co-processor to generate a verifiable credential that binds the operation content and the operator's identity, meeting the electronic evidence storage standards in Region A.
[0167] The signed log data is formatted and packaged into an audit transaction unit, and submitted to the blockchain network through the consensus protocol interface of the permissioned blockchain. The permissioned blockchain adopts the Practical Byzantine Fault Tolerance (PBFT) consensus mechanism, and the authorized verification nodes perform timestamp sorting and legality verification on the transaction unit. The verified audit transactions are appended to the blockchain data structure in chronological order to form an immutable audit chain with forward hash pointer links, and stored in the distributed ledger nodes.
[0168] The privacy leakage risk indicator extraction module in the audit chain periodically scans the blockchain ledger, and statistically analyzes the abnormal node selection event frequency and the noise injection deviation index. The quantified risk indicator values are input into the multi-objective function of the quantum hybrid optimization framework, which together with the model accuracy loss constitute the constraint conditions of the Pareto optimization frontier. The optimization results dynamically adjust the key update period and the noise variance threshold of the quantum fully homomorphic encryption, and send the adjusted parameters to the federated learning aggregator and the noise injection engine through the control plane to complete the adaptive tuning of the privacy protection intensity.
[0169] Specifically, for the model encryption and privacy protection method for artificial intelligence algorithms, the step S109 includes:
[0170] Search for the optimal combination of the key length of the quantum fully homomorphic encryption and the differential privacy noise variance through the quantum approximate optimization algorithm;
[0171] Combined with the classical gradient descent algorithm, locally optimize the weight allocation strategy for federated node selection to generate updated encryption intensity parameters and noise injection rules;
[0172] Synchronize the encryption intensity parameters and the noise injection rules to the aggregation controller and the differential privacy module of the federated learning framework in real time.
[0173] In the initialization stage of the quantum hybrid optimization framework, the quantum approximate optimization algorithm receives the privacy risk indicators from the audit chain and the federated learning performance monitoring data. The quantum circuit constructs the Hamiltonian of the key length parameter and the noise variance parameter, and searches for the Pareto optimal solution space through the quantum variational optimization loop. The optimization process parallelly evaluates the privacy-utility balance of different parameter combinations on the quantum processor, and outputs a candidate parameter set that meets the compliance standards of Region A to form an initial optimization strategy library.
[0174] The classical optimization module extracts the feasible solution interval from the quantum optimization results and constructs the constraint condition space for the federated node weight allocation. The gradient descent algorithm takes the node data distribution uniformity and communication efficiency as the optimization objectives, and iteratively adjusts the node selection weight coefficients within the feasible solution interval. The weight update amount of each iteration is fed back to the quantum optimization module through the quantum-classical interface, dynamically shrinking the parameter search range to achieve the collaborative acceleration of the hybrid optimization process.
[0175] After receiving the finally optimized key length, noise variance, and node weight parameters, the parameter synchronization engine writes the encryption strength parameters into the key scheduler of the quantum fully homomorphic encryption module through the policy distribution channel of the federated learning control plane. After the digital signature verification of the noise injection rule update package, it is pushed to the policy buffer of the differential privacy module to trigger real-time configuration hot loading. The aggregation controller synchronously receives the node weight parameters, enables the updated weighted aggregation formula in the next round of federated training cycle, and completes the closed-loop update of the full-link policy.
[0176] Specifically, the model encryption and privacy protection method for artificial intelligence algorithms further includes:
[0177] According to the privacy leakage risk score in the audit chain, reversely adjust the selection priority of the federated learning participating nodes;
[0178] Based on the real-time monitored model accuracy loss data, optimize the geographical transmission constraints in the differential privacy noise variance and compliance routing rules;
[0179] Feed back the adjusted node selection priority, noise variance, and geographical transmission constraint parameters to the dimensionality reduction processing unit of the quantum feature extraction module and the key manager of the hierarchical encryption module to achieve full-link adaptive tuning from data preprocessing to model inference.
[0180] In the closed-loop iterative node priority adjustment stage, the privacy leakage risk scoring engine analyzes the abnormal event frequency, sensitive data exposure duration, and compliance / non-compliance records in the audit chain, and generates a node trustworthiness indicator through a weighted scoring algorithm. The trustworthiness indicator is input into the federated learning scheduler to dynamically calculate the priority weights of the participating nodes, demote the nodes with historical violation records, and at the same time increase the weights of the nodes with high data distribution diversity to optimize the global model convergence efficiency of federated learning.
[0181] The noise variance optimization module receives the real-time model accuracy monitoring data stream, including the F1 value decline rate of the validation set and the fluctuation range of the training loss function. Based on the gradient descent algorithm, search for the optimal noise variance on the privacy-utility Pareto curve, and combine the geographical fence parameters in the cross-border data transmission rules of Region A to dynamically adjust the whitelist threshold of the compliance routing engine. The optimized noise variance updates the base value parameters through the configuration interface of the quantum random number generator, and the geographical transmission constraints are written into the routing rule database.
[0182] The parameter feedback channel encapsulates the node priority table, the updated noise variance, and the geographical constraint parameters into a policy update instruction set, and distributes them to the data preprocessing and encryption module through the control plane. The dimensionality reduction unit of the quantum feature extraction module receives the new geographical constraint parameters and dynamically adjusts the weight coefficients of the geographical labels in the feature selection algorithm. The key manager of the hierarchical encryption module updates the key rotation policy according to the node priority, enables the enhanced quantum key distribution protocol for the communication links of high-priority nodes, and completes the collaborative optimization of all-link parameters from data input to model output.
[0183] The following explains the technical features in the technical solution of the present invention:
[0184] Quantum feature extraction: It refers to the technology of reducing the dimensionality of high-dimensional data by using the parallel processing ability of quantum computing. The covariance matrix diagonalization is accelerated through the quantum phase estimation algorithm, and low-dimensional feature vectors strongly correlated with sensitive attributes (such as user identity, location information) are extracted. Its core lies in the parallel computing characteristics of the superposition state of quantum bits, which significantly improves the computing efficiency compared with classical algorithms.
[0185] Multi-objective optimization hierarchical algorithm: A decision-making method that takes data sensitivity, service availability, and regulatory compliance as optimization goals and generates a Pareto optimal solution set through the NSGA-II algorithm. Data sensitivity is scored based on the correlation between features and sensitive attributes, service availability is based on the contribution of features to model prediction, and compliance matches the regulatory constraints of the target area (such as GDPR). Finally, a privacy level mapping table for guiding encryption policies is generated.
[0186] Dynamic adjustment in the federated learning framework: A Gaussian process model based on a Bayesian optimizer is used to predict the aggregation weights of federated nodes; combined with the quantum annealing algorithm, the node selection problem is mapped to the Hamiltonian of the Ising model to screen a subset of nodes with low latency and complementary data distributions. The dynamic adjustment mechanism balances the sample distribution deviation through weight normalization and the data volume factor, and alleviates the parameter conflicts caused by non-independent and identically distributed (Non-IID) data.
[0187] Quantum fully homomorphic encryption: An encryption scheme based on lattice cryptography that supports direct addition and multiplication operations on ciphertext data. It is applied to highly sensitive hierarchical parameters (such as output layer weights), maintains the encrypted state during the federated aggregation process, avoids information leakage caused by plaintext transmission, and is also compatible with subsequent noise injection and compression operations.
[0188] Quantum sparse compression: The encrypted parameters are projected onto a low-dimensional manifold through a quantum variational autoencoder, and the volume of ciphertext data is reduced by using a combination of sparse basis vectors. The compression process retains the homomorphic operation ability, reduces the communication overhead while maintaining data privacy, and the compressed parameters are transmitted to the downstream module through a quantum secure channel.
[0189] Dynamic Noise Injection Strategy: The Deep Deterministic Policy Gradient (DDPG) reinforcement learning model uses the privacy budget consumption rate and the model accuracy loss as feedback signals to dynamically generate the noise variance and injection position parameters. The quantum random number generator generates a true random noise sequence, which is superimposed on the encrypted parameter ciphertext through quantum homomorphic addition to achieve the balance between differential privacy protection and model utility.
[0190] Quantum Hash Comparison: The Grover algorithm is used to construct a quantum circuit, and the parameter difference positioning is accelerated through the principle of quantum state amplitude amplification. It is used to detect the incremental update part of the noisy encrypted parameters, generate a difference matrix and trigger the compression encryption process, significantly improving the comparison efficiency of large-scale parameter sets.
[0191] Incremental Update and Blockchain Verification: After the differential parameters are sparsely compressed and re-encrypted, the zero-knowledge proof is called through a smart contract to verify the legality of the modification. The verified incremental data is merged into the global model, and the update log is written into the blockchain through a quantum-secure hash signature to form an immutable audit chain, supporting version rollback and operation traceability.
[0192] Quantum Anomaly Detection: The quantum support vector machine maps the user request features to a high-dimensional space through a quantum kernel function to identify abnormal behaviors such as high-frequency queries. The dynamic threshold is adjusted according to the historical access pattern and compliance requirements, triggering the output fuzzification process (such as converting the probability value to a risk interval label) to block the illegal transmission of sensitive data.
[0193] Audit Chain Generation and Feedback Optimization: The quantum-secure hash algorithm based on lattice cryptography signs the operation log to generate a blockchain audit chain with a timestamp. Risk metrics (such as the frequency of privacy leakage) are input into the quantum hybrid optimization framework to drive the dynamic tuning of encryption intensity and noise rules, forming a closed-loop feedback link from data transmission, model training to policy iteration.
[0194] Closed-loop Iterative Mechanism: The quantum-classical hybrid optimization framework continuously adjusts the encryption key length, noise variance, and node selection weights, and feeds the parameters back to the data preprocessing module (such as the feature reduction weight). The model convergence speed and risk metrics in the audit chain reverse-optimize the full-link strategy to maintain the global optimum of privacy protection and model utility.
[0195] The above technical features collaborate through quantum computing acceleration, dynamic policy optimization, and hierarchical encryption mechanisms to solve the parameter conflict and privacy leakage problems in the federated learning in the non-independent and identically distributed data scenario, and achieve the full-link privacy-utility balance from data input, model training to inference output.
[0196] Quantum Principal Component Analysis (Quantum PCA): A dimensionality reduction algorithm based on quantum computing. It accelerates the diagonalization of the covariance matrix through quantum phase estimation and controlled rotation gate operations, and extracts the low-dimensional eigenvectors with the strongest correlation with sensitive attributes (such as user identity, location information) in high-dimensional data. Compared with classical PCA, quantum parallelism significantly improves the efficiency of eigen-decomposition, providing efficient feature screening capabilities for subsequent privacy grading.
[0197] Non-dominated Sorting Genetic Algorithm-II (NSGA-II): An improved non-dominated sorting genetic algorithm. With the data sensitivity score, business availability weight, and GDPR compliance constraints as optimization objectives, it parallelly evaluates the candidate solution set on the quantum computing unit, generating Pareto front solutions covering different privacy-utility balance points. It selects the optimal grading strategy through multi-criteria decision analysis, constructs a field-level privacy level mapping table, and guides the differential encryption and noise injection rules.
[0198] Bayesian Optimizer: A hyperparameter tuning method based on the Gaussian process model. It fits the historical contribution data (such as parameter update amplitude, convergence stability) of federated learning nodes through kernel functions, and predicts the aggregation weight allocation ratio in future training cycles. This optimizer dynamically adjusts the weight coefficients to mitigate the negative impact of non-independent and identically distributed data on the convergence of the global model.
[0199] Quantum Annealing: Maps the federated node selection problem to the Hamiltonian of the Ising model (the node communication delay is mapped to the coupling strength, and the data distribution similarity is mapped to the spin interaction energy). It uses the quantum tunneling effect to break through the local optimal solution limit and quickly screen a subset of nodes with low latency and complementary data distribution. This algorithm optimizes the search efficiency of node combinations and reduces the parameter deviation caused by heterogeneous data.
[0200] Deep Deterministic Policy Gradient (DDPG) Model: A reinforcement learning model that combines policy gradient and Q-learning. With the privacy budget consumption rate and model accuracy loss as the joint reward function, it generates the position index and variance intensity strategy of noise injection. It dynamically adjusts the noise configuration through the Actor-Critic network structure to balance the differential privacy protection strength and model availability.
[0201] Quantum Support Vector Machine (Quantum SVM): Uses the quantum kernel trick to map the user request features to a high-dimensional Hilbert space and constructs a non-linear classification boundary through quantum Fourier transform. It is used to real-time detect high-frequency query abnormal behaviors, combines dynamic thresholds (based on historical access patterns and compliance requirements) to trigger output fuzzification processing, and blocks potential privacy leakage risks.
[0202] Quantum Approximate Optimization Algorithm (QAOA): A hybrid quantum-classical optimization algorithm that constructs a Hamiltonian containing encryption key length and noise variance parameters, and searches for the privacy-utility Pareto optimal solution through quantum variational optimization loops. The algorithm works in conjunction with classical gradient descent to dynamically adjust the federated node weight allocation strategy to form a global optimal parameter combination.
[0203] Lattice-based Cryptography: A quantum-resistant encryption scheme based on lattice mathematical problems, used to build quantum fully homomorphic encryption protocols. Public and private keys are generated through the ring learning with errors (RLWE) problem, and addition and multiplication operations in the ciphertext state are supported to ensure the computational privacy of highly sensitive parameters during federated aggregation and noise injection.
[0204] Quantum Variational Autoencoder: A quantum-classical hybrid neural network. The encoder quantum circuit learns the sparse representation mode of encryption parameters and projects high-dimensional ciphertext data into a low-dimensional sparse space. The decoder reconstructs the original data distribution, and the compression process maintains homomorphic operation compatibility, significantly reducing the ciphertext transmission and storage overhead.
[0205] Quantum-safe Hash: A quantum-resistant hash function based on lattice cryptography that digitally signs operation logs and generates tamper-proof summary information. Combined with permissioned blockchain technology, it builds an audit chain with a timestamp to support operation traceability and compliance verification, and resist the risk of data forgery under quantum computing attacks.
[0206] Multi-objective optimization classification model (NSGA-II): Using an improved non-dominated sorting genetic algorithm, with data sensitivity score, business availability weight and GDPR compliance constraints as optimization objectives, the candidate solution set is evaluated in parallel on the quantum computing unit to generate Pareto frontier solutions covering different privacy-utility balance points. The optimal classification strategy is selected through multi-criteria decision analysis, and a field-level privacy level mapping table is constructed to guide differentiated encryption and noise injection rules.
[0207] Bayesian Optimization Model (Gaussian Process): A federated node weight prediction model based on Gaussian process regression, which uses kernel functions to fit the node's historical contribution data (such as parameter update amplitude and convergence stability) to predict the aggregate weight distribution ratio in future training cycles. The model dynamically adjusts the weight coefficient to alleviate the negative impact of non-independent and identically distributed data on the convergence of the global model.
[0208] Quantum Annealing Model (Ising Model Mapping): Transforms the federated node selection problem into an Ising model Hamiltonian, where the node communication delay is mapped to the coupling strength coefficient, and the data distribution similarity is calculated by KL divergence and mapped to the spin interaction energy. Through the quantum tunneling effect of the quantum annealer, it breaks through the local optimal solution limit and quickly screens a subset of nodes with low latency and complementary data distribution.
[0209] Deep Deterministic Policy Gradient Model (DDPG): A reinforcement learning model that generates a noise injection policy through an Actor-Critic network structure. The Actor network uses the privacy budget consumption rate and the model accuracy loss as a joint reward function to output the noise position and variance parameters; the Critic network evaluates the policy effect and feedbacks the gradient signal to dynamically optimize the privacy-utility balance of the noise configuration.
[0210] Quantum-Secure Hash Model (Lattice-based Hash):
[0211] A quantum-resistant hash function constructed based on lattice cryptography performs digital signatures on operation logs to generate tamper-proof digest information. Combining with the permissioned chain blockchain technology, it constructs a timestamped audit chain to support operation traceability and compliance verification, and resist the risk of data forgery under quantum computing attacks.
[0212] Quantum Approximate Optimization Model (QAOA):
[0213] A hybrid quantum-classical optimization framework constructs a Hamiltonian containing the encryption key length and noise variance parameters, and searches for the privacy-utility Pareto optimal solution through quantum variational optimization cycles. This model collaborates with classical gradient descent to dynamically adjust the federated node weight allocation strategy to form a globally optimal parameter combination.
[0214] Lattice Cryptography Fully Homomorphic Encryption Model (RLWE-based FHE):
[0215] A fully homomorphic encryption scheme based on the Ring-Learning with Errors (RLWE) problem generates public and private key pairs to encrypt highly sensitive parameters and supports addition and multiplication operations in the ciphertext state. This model ensures the privacy of parameter calculations during the federated aggregation process and is also compatible with noise injection and sparse compression operations.
[0216] The model encryption and privacy protection method for artificial intelligence algorithms of the present invention aims at the data heterogeneity and privacy-utility balance problems faced by the federated learning framework in high-sensitive data scenarios, and constructs a full-link collaborative privacy protection system through the integration of quantum computing and dynamic optimization technologies. The specific implementation methods are as follows:
[0217] In the data preprocessing stage, the original business data undergoes feature dimensionality reduction by the quantum principal component analysis module. The quantum phase estimation algorithm is used to accelerate the diagonalization of the covariance matrix, and low-dimensional feature vectors strongly correlated with sensitive attributes are extracted. During the dimensionality reduction process, the number of features to be retained is dynamically determined based on the variance explanation rate, eliminating redundant features while preserving the data distribution pattern. After receiving the dimensionality-reduced features, the multi-objective optimization hierarchical algorithm uses the data sensitivity score, business availability weight, and GDPR compliance metrics as optimization objectives, and generates a Pareto optimal solution set through an improved NSGA-II algorithm to construct a field-level privacy level mapping table. This table divides the data into public, internal, and confidential levels, guiding subsequent hierarchical encryption strategies. For example, confidential-level fields are bound with quantum fully homomorphic encryption and a dynamic noise injection mechanism.
[0218] In the federated learning framework, the aggregation weights of participating nodes are dynamically adjusted through a Gaussian process model constructed by a Bayesian optimizer, predicting the weight coefficients by combining the node's historical contribution degree and real-time communication delay data. The quantum annealing machine maps the node selection problem to an Ising model Hamiltonian to solve for a subset of nodes with low latency and complementary data distribution. The dynamic weights and the optimized node subset are input into an improved federated aggregation formula to perform a hierarchical weighted summation operation in the ciphertext state, generating global model parameters. For the parameters of the highly sensitive layer, a quantum fully homomorphic encryption algorithm based on lattice cryptography is applied for ciphertext conversion, and the ciphertext volume is compressed through the sparse coding layer of the quantum neural network to reduce the transmission overhead.
[0219] The noise injection module dynamically generates a noise configuration strategy through a deep deterministic policy gradient reinforcement learning model, using the privacy budget consumption rate and the model accuracy loss as feedback signals to optimize the noise injection position and variance intensity. The quantum random number generator generates a true random noise sequence conforming to a Gaussian distribution, and uses quantum homomorphic addition to superimpose the noise on the encrypted parameter ciphertext. The parameter after noise injection undergoes quantum hash comparison by the Grover algorithm to locate the incrementally updated part and generate a compressed ciphertext increment list, which triggers a global model version iteration after verification by the blockchain smart contract.
[0220] In the user inference stage, the anomaly detection model constructed by the quantum support vector machine analyzes the request features in real time, triggering an output fuzzification process when the high-frequency queries exceed the dynamic threshold. The probability value is mapped to discrete risk labels through quantum fuzzy logic, and combined with the geographical rules matching of the compliance routing engine to intercept illegal transmission requests. All operation logs are signed by the quantum secure hash algorithm and written into the permissioned chain to form an immutable audit chain. The risk metrics in the audit chain drive the quantum hybrid optimization framework to dynamically adjust the encryption strength and noise rules. For example, the optimal combination of the key length and noise variance is searched through the quantum approximate optimization algorithm, and the optimized parameters are fed back to the federated node selection and encryption module.
[0221] The closed-loop iterative mechanism continuously monitors the model convergence speed and privacy leakage risk, and reversely tunes the feature dimension reduction weights and encryption strategies in the data preprocessing stage. For example, abnormal node behavior data in the audit chain triggers the reallocation of the federal participation priority, and the model accuracy loss signal drives the dynamic calibration of the noise variance threshold. The full-link parameters are collaboratively updated under the quantum-classical hybrid optimization framework to achieve the global optimum of privacy-utility from data input, model training to inference output, effectively solving the parameter conflict and privacy leakage risk in the non-independent and identically distributed data scenario.
[0222] The technical solution of the present invention systematically solves the dual contradictions of data heterogeneity and privacy protection in federated learning by constructing a dynamic collaborative optimization system. First, for the parameter conflict caused by non-independent and identically distributed data, a quantum optimization node selection and multi-objective weighted aggregation strategy is adopted. The quantum annealing algorithm is used to analyze the node data distribution similarity matrix, dynamically screen the subset of participating nodes with strong data complementarity, and reduce the divergence of the parameter update direction; at the same time, the aggregation weight allocation is optimized based on the NSGA-II algorithm, and the Pareto optimal weight coefficient is established under the privacy budget constraint to balance the contribution degree difference of data heterogeneous nodes and alleviate model oscillation.
[0223] Secondly, for the deterioration of convergence stability caused by the privacy protection mechanism, a collaborative mechanism of hierarchical encryption and adaptive noise regulation is designed. Quantum fully homomorphic encryption is implemented for highly sensitive parameters according to the privacy level mapping table, and the aggregation operation is performed in the ciphertext state to avoid the leakage risk of plaintext transmission; combined with the deep deterministic policy gradient model, the noise injection intensity and position are dynamically adjusted, and the model accuracy loss is used as the feedback signal to adaptively optimize the noise variance parameter during the training process to achieve the dynamic balance between the privacy protection intensity and the model convergence rate.
[0224] Furthermore, the full-link parameter collaboration is achieved through an audit-driven closed-loop feedback mechanism. Based on the privacy leakage risk indicators recorded by the quantum security audit chain, the federal node selection strategy and noise injection rules are reversely optimized; the quantum hybrid optimization framework is used to synchronously adjust the encryption key length and noise distribution parameters, and the optimization results are fed back to the feature dimension reduction unit of the data preprocessing module to form a full-cycle adaptive tuning from data input, model training to inference output, and finally achieve efficient aggregation and the global optimum of privacy-utility in the data heterogeneous environment.
Claims
1. A method for model encryption and privacy protection for artificial intelligence algorithms, characterized in that, Including: Step S101: Obtain the original business data, identify sensitive attributes through quantum feature extraction and dimensionality reduction processing, and generate a dimensionality-reduced feature vector. Step S102: Input the dimensionality-reduced feature vector into a multi-objective optimization and grading algorithm to generate a privacy level mapping table including data sensitivity levels and the cleaned structured data. Step S103: Based on the privacy level mapping table, dynamically adjust the aggregation weights of participating nodes in the federated learning framework, select a subset of low-latency nodes through quantum optimization, and generate global model parameters. Step S104: Perform quantum fully homomorphic encryption on the highly sensitive layer in the global model parameters according to the privacy level mapping table, and perform quantum sparse compression on the encrypted parameters. Step S105: Inject dynamic noise generated based on reinforcement learning into the compressed encrypted parameters to generate noisy encrypted model parameters. Step S106: Locate the incrementally updated part of the noisy encrypted model parameters through quantum hash comparison, generate an increment list and update the global model. Step S107: Receive a user inference request, identify high-frequency query behaviors using quantum anomaly detection, and perform fuzzification processing on the output result of the updated global model. Step S108: Intercept illegal transmissions according to compliance rules matched by data geographical region labels, and generate an audit chain through quantum secure hashing. Step S109: Dynamically adjust the encryption strength and noise injection strategy based on the risk indicators in the audit chain, and feedback the adjusted policy parameters to the federated learning node selection and encryption module.
2. The model encryption and privacy protection method for artificial intelligence algorithms according to claim 1, wherein The step S101 includes: Parallelly calculate the feature covariance matrix through quantum principal component analysis, and extract the feature vectors associated with sensitive attributes. Input the feature vectors into a multi-objective optimization and grading algorithm, and generate a Pareto optimal solution set with data sensitivity grading, business availability scoring, and GDPR compliance indicators as optimization objectives. Generate a privacy level mapping table according to the optimal solution in the Pareto optimal solution set. The privacy level mapping table includes encryption level markings for each data field, which are used to control the encryption strength of local training parameters of federated learning participating nodes.
3. The model encryption and privacy protection method for artificial intelligence algorithms according to claim 1, characterized in that The step S103 includes: Construct a Gaussian process model based on a Bayesian optimizer, and predict the weight values of each federated learning participating node according to the historical aggregation contribution degrees of each federated learning participating node. Map the node communication delay and data distribution similarity to the Hamiltonian of the Ising model, and solve the optimal subset of federated nodes through a quantum annealing machine. Adjust the weighted average coefficient in the federated aggregation formula according to the predicted weight values of each federated learning participating node and the optimal subset of federated nodes, and generate global model parameters.
4. The method for model encryption and privacy protection for artificial intelligence algorithms according to claim 1, wherein The step S104 includes: Encrypt the global model parameters marked as the highly sensitive level in the privacy level mapping table using a quantum fully homomorphic encryption algorithm. Perform compression processing on the encrypted parameters through the sparse coding layer of a quantum neural network to generate compressed ciphertext parameters. Input the compressed ciphertext parameters into the homomorphic operation interface of the differential privacy noise injection module to maintain noise superposition in the ciphertext state.
5. The method for model encryption and privacy protection for artificial intelligence algorithms according to claim 1, characterized in that The step S105 includes: Through the deep deterministic policy gradient reinforcement learning model, with the privacy budget consumption rate and the model accuracy loss as the reward functions, generate the model layer positions and variance intensity policies for noise injection; Use a quantum random number generator to generate a noise sequence that conforms to a Gaussian distribution; Through the homomorphic addition operation of quantum fully homomorphic encryption, superimpose the noise sequence on the ciphertext of the encryption parameter to generate a noisy encrypted model parameter.
6. The method for model encryption and privacy protection for artificial intelligence algorithms according to claim 1, characterized in that The step S106 includes: Based on the Grover algorithm, perform a quantum state comparison between the current global model parameter and the historical version, locate the newly added or modified parameters, and generate an incremental parameter list; Perform quantum sparse coding processing on the incremental parameter list, and generate a compressed ciphertext through the quantum fully homomorphic encryption algorithm; Input the compressed ciphertext into the blockchain storage interface of the audit tracking module, trigger the global model update, and generate the updated global model parameter.
7. The method for model encryption and privacy protection for artificial intelligence algorithms according to claim 1, wherein The step S107 includes: Perform a quantum kernel mapping on the user request features through a quantum support vector machine. When it is detected that the number of requests within a unit time exceeds a preset threshold, it is determined as a high-frequency query abnormal behavior; After triggering the defense mechanism, dynamically adjust the interval boundary value according to the ROC curve of the preset model validation set, and convert the probability value output by the updated global model into interval labels of high risk, medium risk, and low risk; Input the abnormal behavior log into the rule matching module of the compliance routing engine to block the transmission of the illegal data stream including sensitive fields.
8. The method for model encryption and privacy protection for artificial intelligence algorithms according to claim 1, wherein, The step S108 includes: Based on the quantum-secure hash algorithm of lattice cryptography, digitally sign the federated learning node selection record and the noise injection operation log; Synchronize the signed log data to the permissioned blockchain node to generate an immutable audit chain including timestamps; Input the privacy leakage risk indicator in the audit chain into the optimization objective function of the quantum hybrid optimization framework to drive the dynamic adjustment of the encryption strength parameter.
9. The method for model encryption and privacy protection for artificial intelligence algorithms according to claim 1, characterized in that The step S109 includes: Search for the optimal combination of the key length of quantum fully homomorphic encryption and the differential privacy noise variance through the quantum approximate optimization algorithm; Combined with the classical gradient descent algorithm, locally optimize the weight allocation strategy for federated node selection to generate the updated encryption strength parameter and noise injection rule; Synchronize the encryption strength parameter and the noise injection rule to the aggregation controller and the differential privacy module of the federated learning framework in real time.
10. The method for model encryption and privacy protection for artificial intelligence algorithms according to claim 9, characterized in that, It also includes: According to the privacy leakage risk score in the audit chain, reversely adjust the selection priority of the federated learning participating nodes; Based on the real-time monitored model accuracy loss data, optimize the differential privacy noise variance and the geographical transmission constraint in the compliance routing rule; Feed back the adjusted node selection priority, noise variance, and geographical transmission constraint parameters to the dimensionality reduction processing unit of the quantum feature extraction module and the key manager of the hierarchical encryption module.
Citation Information
Patent Citations
Quantum encryption communication method based on multi-party security computing
CN114257314A
Private data protection method and system based on homomorphic encryption and federated learning
CN119513919A