Differential privacy protection method and system based on adaptive noise adjustment

By adopting adaptive noise adjustment and multimodal differential privacy protection methods in differential privacy protection, the shortcomings in the existing technology in noise design and attack model considerations are solved, and more efficient privacy protection and data query accuracy are achieved.

CN120068131APending Publication Date: 2025-05-30AEROSPACE NETWORK SECURITY TECH (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311614278.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-29
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing differential privacy protection methods have shortcomings in noise design and attack model considerations, and cannot fully meet the needs of document classification information data processing, especially on data sets of diversity and complexity.

Method used

The differential privacy protection method based on adaptive noise adjustment is adopted, and the amount and method of noise are adjusted adaptively, combined with the multimodal differential privacy protection method, and processed according to the specific characteristics of the data set and query requirements.

Benefits of technology

It improves the accuracy of data queries, reduces the possibility that attackers infer original data through query results, more effectively protects user privacy, and improves data processing efficiency and data quality.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The invention relates to a differential privacy protection method and system based on adaptive noise adjustment, and the method comprises the steps: intercepting first document data content, generating adjustment source data, correspondingly adding a first adjustment label, adding to-be-tested noise to the adjustment source data, generating adjustment test data, and outputting the adjustment test data; according to the method, whether the adjustment test data meets the data desensitization requirement or not is judged according to the first adjustment label, and according to the specific characteristics and query requirements of the data set, the privacy of a user can be better protected and a more accurate query result can be provided by adaptively adjusting the amount and mode of noise and adopting a multi-modal differential privacy protection method, so that the user experience is improved. The data processing efficiency and the data quality are improved, the accuracy of the query result is improved, the security and the reliability of the data are enhanced, and the sharing and the opening of the data are promoted.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of document classification information data processing and data security protection, and particularly relates to a differential privacy protection method and system based on adaptive noise adjustment. Background Art

[0002] In the process of document classification information data processing, differential privacy protection is a method for protecting personal privacy. Differential privacy is a privacy model in cryptography, aiming to provide a method that maximizes the accuracy of data query while minimizing the chance of identifying its records when querying from a statistical database.

[0003] In differential privacy protection, given a data set, the differential privacy system requires extracting a middleware from the database, injecting an appropriate amount of noise into the middleware using a specially designed random algorithm to obtain a noisy middleware; then deriving a noisy query result from the noisy middleware and feeding it back to the user. In this way, even if an attacker can reverse-derive the noisy middleware from the noisy result, he cannot accurately infer the noise-free middleware, let alone reason about the original database, thus achieving the purpose of privacy protection.

[0004] In document classification information processing, differential privacy protection can be applied to scenarios such as interactive statistical query interfaces, API interfaces, and user-side data statistics. By adding noise to the query result, it can protect the personal privacy and sensitive information of users, preventing data leakage and privacy leakage. At the same time, differential privacy protection can also provide rigorous definitions and quantitative evaluation methods to evaluate the degree and effect of privacy protection.

[0005] However, the execution methods of differential privacy protection in the prior art still have deficiencies and difficulties and cannot fully meet the usage requirements. First, the core of differential privacy is to add noise to the data set, but the amount and method of noise need to be reasonably designed according to the specific data set and query requirements. Excessive noise will affect the accuracy of the query result, while too little noise may not provide sufficient privacy protection; then, differential privacy protection assumes that the attacker has certain prior information and conducts inference attacks based on this information. Therefore, in differential privacy protection, it is necessary to focus on the attack model, including the attacker's capabilities, purposes, available information, etc.; finally, the document classification information data set has diversity and complexity, including various types of data such as text, images, and audio. These different types of data have different characteristics and attributes and require different processing and analysis. Summary of the Invention

[0006] To address the deficiencies in the prior art, the present invention proposes a differential privacy protection method and system based on adaptive noise adjustment. According to the specific characteristics of the data set and query requirements, by adaptively adjusting the amount and method of noise and adopting a multimodal differential privacy protection method, the user's privacy can be better protected and more accurate query results can be provided, which is conducive to improving data processing efficiency and data quality, improving the accuracy of query results, enhancing data security and reliability, and promoting data sharing and openness.

[0007] To achieve the above objectives, the technical solutions adopted by the present invention include:

[0008] A differential privacy protection method based on adaptive noise adjustment, characterized by comprising:

[0009] S1, obtaining target document data, performing a preprocessing operation on the target document data, and generating first document data;

[0010] S2, intercepting the first document data content to generate adjustment source data, and adding a first adjustment tag to the corresponding adjustment source data;

[0011] S3, using a preset standard noise as the noise to be tested to add to the adjustment source data to generate adjustment test data, judging whether the adjustment test data meets the data desensitization requirement according to the first adjustment label, and when judging that the adjustment test data meets the data desensitization requirement, marking the noise to be tested as execution noise;

[0012] S4. When it is determined that the adjusted test data does not meet the data desensitization requirement, a noise adjustment operation is performed on the noise to be tested to generate a second noise;

[0013] S5, using the second noise as a new noise to be measured, and repeatedly executing steps S3 and S4 until an execution noise is obtained;

[0014] S6. Generate protection data by adding execution noise to the first document data content.

[0015] Further, the performing of the preprocessing operation includes performing any one or more combinations of the following:

[0016] Data cleaning operations;

[0017] Redundant data removal operation;

[0018] Target data format conversion operation;

[0019] Data verification operation.

[0020] Furthermore, the method further comprises:

[0021] A second adjustment tag is added to a portion of the first document data except for the adjustment source data.

[0022] Further, the method further includes:

[0023] Judging whether the protected data meets the data desensitization requirements according to the second adjustment label.

[0024] Further, the data desensitization requirements include:

[0025] Obtaining query data items;

[0026] Verifying whether the matching degree between the query data item and the data source is less than a preset threshold.

[0027] The present invention also relates to a differential privacy protection system based on adaptive noise adjustment, which is characterized by including:

[0028] A preprocessing module, configured to perform preprocessing operations on target document data to generate first document data;

[0029] An adjustment data management module, configured to intercept the content of the first document data to generate adjustment source data, and add a first adjustment label to the corresponding adjustment source data;

[0030] An adjustment test module, configured to add the noise to be tested to the adjustment source data to generate adjustment test data, and judge whether the adjustment test data meets the data desensitization requirements according to the first adjustment label. When it is judged that the adjustment test data meets the data desensitization requirements, mark the noise to be tested as the execution noise;

[0031] An adjustment execution module, configured to use the execution noise to be added to the content of the first document data to generate protected data.

[0032] The present invention also relates to a computer-readable storage medium, which is characterized in that a computer program is stored on the storage medium, and when the computer program is executed by a processor, the above-mentioned method is implemented.

[0033] The present invention also relates to an electronic device, which is characterized by including a processor and a memory;

[0034] The memory is used to store target document data, first document data, and adjustment source data;

[0035] The processor is configured to execute the above-mentioned method by calling the target document data, the first document data, and the adjustment source data.

[0036] The present invention also relates to a computer program product, including a computer program and / or instructions, which is characterized in that when the computer program and / or instructions are executed by a processor, the steps of the above-mentioned method are implemented.

[0037] The beneficial effects of the present invention are:

[0038] By adopting the differential privacy protection method and system based on adaptive noise adjustment according to the specific characteristics of the data set and query requirements, by adaptively adjusting the amount and manner of noise and adopting a multi-modal differential privacy protection method, the sensitivity and redundancy of the data set can be reduced, the accuracy of data query can be improved, the possibility for an attacker to infer the original data from the query results can be reduced, the privacy of users can be better protected and more accurate query results can be provided, which is beneficial to improving data processing efficiency and data quality, improving the accuracy of query results, enhancing the security and reliability of data, and promoting the sharing and opening of data. By applying the differential privacy protection method and system of the present invention, an appropriate amount of noise is injected into the middleware, making it impossible for an attacker to infer the original database, which can provide strict privacy protection and data security guarantee, improve the accuracy of data query and data processing efficiency, and promote the sharing and opening of data. Detailed implementation manners

[0039] For a clearer understanding of the content of the present invention, it will be described in detail in combination with embodiments.

[0040] The first aspect of the present invention relates to a differential privacy protection method based on adaptive noise adjustment, including:

[0041] S1. Obtain target document data, perform a preprocessing operation on the target document data to generate first document data.

[0042] Preferably, performing the preprocessing operation includes performing any one or a combination of the following: data cleaning operation; redundant data removal operation; target data format conversion operation; data verification operation.

[0043] S2. Intercept the content of the first document data to generate adjustment source data, and add a first adjustment label corresponding to the adjustment source data.

[0044] Preferably, add a second adjustment label to the part of the first document data other than the adjustment source data.

[0045] S3. Use a preset standard noise as the noise to be measured and add it to the adjustment source data to generate adjustment test data. Determine whether the adjustment test data meets the data desensitization requirements according to the first adjustment label. When it is determined that the adjustment test data meets the data desensitization requirements, mark the noise to be measured as the executed noise.

[0046] Preferably, the data desensitization requirements include: obtaining query data items; verifying whether the matching degree between the query data items and the data source is less than a preset threshold. In specific implementation, it can be evaluated by comparing the differences between the original data set and the desensitized data set, the possibility for an attacker to infer the original data, etc.

[0047] S4. When it is determined that the adjusted test data does not meet the data desensitization requirements, perform a noise adjustment operation on the to-be-tested noise to generate a second noise.

[0048] S5. Use the second noise as the new to-be-tested noise, and repeat steps S3 and S4 until an execution noise is obtained.

[0049] S6. Add the execution noise to the first document data content to generate protected data.

[0050] Preferably, determine whether the protected data meets the data desensitization requirements according to the second adjustment label.

[0051] After differential privacy protection is performed, the desensitized data set can be provided for querying and analysis. Since differential privacy protection has been performed, it can be ensured that users cannot infer the specific information of the original data through the query results, thereby protecting the privacy of users.

[0052] On the other hand, the present invention also relates to a differential privacy protection system based on adaptive noise adjustment, including:

[0053] A preprocessing module for performing a preprocessing operation on the target document data to generate first document data;

[0054] An adjustment data management module for intercepting the first document data content to generate adjustment source data, and adding a first adjustment label corresponding to the adjustment source data;

[0055] An adjustment test module for adding the to-be-tested noise to the adjustment source data to generate adjustment test data, and determining whether the adjustment test data meets the data desensitization requirements according to the first adjustment label. When it is determined that the adjustment test data meets the data desensitization requirements, mark the to-be-tested noise as the execution noise;

[0056] An adjustment execution module for adding the execution noise to the first document data content to generate protected data.

[0057] By using this system, the above-mentioned arithmetic processing method can be executed and the corresponding technical effects can be achieved.

[0058] An embodiment of the present invention also provides a computer-readable storage medium capable of implementing all the steps in the method in the above embodiment. A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, all the steps in the method in the above embodiment are implemented.

[0059] An embodiment of the present invention further provides an electronic device for executing the above method. As an implementation device of the method, the electronic device at least includes a processor and a memory. In particular, the memory stores data and related computer programs required for executing the method, such as target document data, first document data, and adjustment source data, etc. And all steps of the method are implemented by the processor calling the data and programs in the memory, and corresponding technical effects are obtained.

[0060] Preferably, the electronic device may include a bus architecture. The bus may include any number of interconnected buses and bridges, and the bus links various circuits including one or more processors and memories together. The bus may also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, etc., which are well known in the art, so they will not be further described herein. The bus interface provides an interface between the bus and the receiver and transmitter. The receiver and transmitter may be the same element, i.e., a transceiver, which provides a unit for communicating with various other systems on the transmission medium. The processor is responsible for managing the bus and general processing, while the memory may be used to store data used by the processor when executing operations.

[0061] Additionally, the electronic device may further include components such as a communication module, an input unit, an audio processor, a display, a power supply, etc. The processor (or controller, operation control) used therein may include a microprocessor or other processor devices and / or logic devices, which receive inputs and control the operations of the various components of the electronic device; the memory may be one or more of a buffer, a flash memory, a hard drive, a removable medium, a volatile memory, a non-volatile memory, or other suitable devices, capable of storing the above relevant data information, and may also store programs for executing relevant information, and the processor may execute the programs stored in the memory to implement information storage or processing, etc.; the input unit is used to provide inputs to the processor, for example, it may be a key or a touch input device; the power supply is used to provide power to the electronic device; the display is used to display display objects such as images and texts, for example, it may be an LCD display. The communication module is a transmitter / receiver that sends and receives signals via an antenna. The communication module (transmitter / receiver) is coupled to the processor to provide input signals and receive output signals, which may be the same as in the case of a conventional mobile communication terminal. Based on different communication technologies, multiple communication modules may be provided in the same electronic device, such as a cellular network module, a Bluetooth module, and / or a wireless local area network module, etc. The communication module (transmitter / receiver) is also coupled to the speaker and the microphone via the audio processor to provide audio output via the speaker and receive audio input from the microphone, thereby implementing the usual telecommunication functions. The audio processor may include any suitable buffer, decoder, amplifier, etc. Additionally, the audio processor is also coupled to the central processor, so that it is possible to record on the device through the microphone and play the sounds stored on the device through the speaker.

[0062] Those skilled in the art should understand that the embodiments of the present invention may be provided as a method, a system, or a computer program product. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.

[0063] The present invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each flow and / or block in the flowchart illustrations and / or block diagrams, and combinations of flows and / or blocks in the flowchart illustrations and / or block diagrams, can be realized by computer program instructions. These computer program instructions may be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions executed by the processor of the computer or other programmable data processing apparatus create a system for realizing the functions specified in one or more flows of the flowchart and / or one or more blocks of the block diagram.

[0064] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means that realize the functions specified in one or more flows of the flowchart and / or one or more blocks of the block diagram.

[0065] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable apparatus provide steps for realizing the functions specified in one or more flows of the flowchart and / or one or more blocks of the block diagram. Although the preferred embodiments of the present invention have been described, additional changes and modifications can be made by those skilled in the art once they learn of the basic inventive concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0066] The above are only the preferred specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A differential privacy protection method based on adaptive noise adjustment, characterized in that, it includes: S1. Obtain target document data, perform preprocessing operations on the target document data to generate first document data; S2. Intercept the content of the first document data to generate adjustment source data, and add a first adjustment label corresponding to the adjustment source data; S3. Use preset standard noise as the noise to be tested and add it to the adjustment source data to generate adjustment test data. Determine whether the adjustment test data meets the data desensitization requirements according to the first adjustment label. When it is determined that the adjustment test data meets the data desensitization requirements, mark the noise to be tested as the executed noise; S4. When it is determined that the adjustment test data does not meet the data desensitization requirements, perform a noise adjustment operation on the noise to be tested to generate a second noise; S5. Use the second noise as the new noise to be tested, and repeat steps S3 and S4 until the executed noise is obtained; S6. Use the executed noise to be added to the content of the first document data to generate protected data.

2. The method according to claim 1, characterized in that, the preprocessing operation includes performing any one or more combinations of the following: Data cleaning operation; Redundant data removal operation; Target data format conversion operation; Data verification operation.

3. The method according to claim 1, characterized in that, the method further includes: Adding a second adjustment label to the part of the first document data other than the adjustment source data.

4. The method according to claim 1, characterized in that, the method further includes: Determine whether the protected data meets the data desensitization requirements according to the second adjustment label.

5. The method according to claim 1, characterized in that, the data desensitization requirements include: Obtain query data items; Verify whether the matching degree between the query data items and the data source is less than a preset threshold.

6. A differential privacy protection system based on adaptive noise adjustment, characterized in that, it includes: A preprocessing module for performing preprocessing operations on target document data to generate first document data; An adjustment data management module for intercepting the content of the first document data to generate adjustment source data, and adding a first adjustment label corresponding to the adjustment source data; An adjustment test module for adding the noise to be tested to the adjustment source data to generate adjustment test data, and determining whether the adjustment test data meets the data desensitization requirements according to the first adjustment label. When it is determined that the adjustment test data meets the data desensitization requirements, mark the noise to be tested as the executed noise; An adjustment execution module for using the executed noise to be added to the content of the first document data to generate protected data.

7. A computer-readable storage medium, characterized in that, a computer program is stored on the storage medium, and when the computer program is executed by a processor, the method described in any one of claims 1 to 5 is implemented.

8. An electronic device, characterized in that, it includes a processor and a memory; the memory is used to store target document data, first document data, and adjustment source data; the processor is used to execute the method described in any one of claims 1 to 5 by calling the target document data, first document data, and adjustment source data.

9. A computer program product, including a computer program and / or instructions, characterized in that, When the computer program and / or instructions are executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.