Relational database fingerprint method based on local differential privacy

By adopting a fingerprint method based on local differential privacy in relational databases, combined with the inherent intrinsic conditional correlation between Tardos encoding and data, the problem of difficult to balance data privacy protection and responsibility tracking in the existing technology is solved, and efficient privacy protection and responsibility tracking are achieved, while reducing data utility losses.

CN120068144APending Publication Date: 2025-05-30NANJING UNIV OF AERONAUTICS & ASTRONAUTICS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510080024.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-19
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

While the existing technology realizes data privacy protection and responsibility tracking, it is difficult to achieve a good balance between privacy protection, responsibility tracking and data utility, resulting in large losses in data utility.

Method used

A relational database fingerprinting method based on local differential privacy is adopted to generate a specific fingerprint sequence through Tardos encoding, and a fingerprint is embedded in the relational database based on the inherent intrinsic conditional correlation of the data and the local differential privacy random response technology to realize privacy protection and responsibility tracking.

Benefits of technology

This method can not only effectively resist various fingerprint attacks, but also meet differential privacy requirements during the process of embedding fingerprints, thereby reducing data utility losses while ensuring data privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068144A_ABST
    Figure CN120068144A_ABST
Patent Text Reader

Abstract

The invention discloses a privacy protection probability fingerprint method for a relational database, and the method comprises the steps: firstly generating a specific fingerprint sequence through Tardos coding, and distributing a unique fingerprint for each service provider; secondly, embedding fingerprints in the relational database in combination with inherent condition relevance of data and a local differential privacy random response technology; then, when illegal redistribution of the database is found, fingerprints of the leaked database can be extracted through a high-credibility fingerprint extraction technology; and finally, comparing the extracted fingerprints of the leaked database with the fingerprints distributed by the service providers one by one, and instructing and controlling illegal service providers according to a tracking algorithm of Tardos coding. By adopting the method, each fingerprint bit can be embedded in a probability uniform manner, fingerprint attack algorithms such as random flipping attacks and collusion attacks can be effectively resisted, good fingerprint robustness is achieved, meanwhile, the differential privacy requirement is met in the fingerprint embedding process, and the data utility loss is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information security, and particularly relates to a relational database fingerprint method based on local differential privacy. Background Art

[0002] With the advent of the big data era, the collection of massive data and the wide application of relational databases have become important features of today's society. As a structured collection for storing data records with the same attributes, relational databases play an important role in scenarios such as enterprises, research institutions, and hospitals. The demand for data sharing is increasing day by day. For example, to achieve personalized advertising recommendations, social relationship analysis, or customized medical services, database owners need to share data with multiple service providers. However, such sharing behaviors have triggered a series of technical challenges, including data privacy protection, illegal distribution liability tracing, and the balance of data utility.

[0003] Databases usually contain sensitive and proprietary information, such as medical records, financial data, etc. The sharing of this information needs to meet strict privacy protection requirements to prevent unauthorized access or leakage. Illegal redistribution of data is another threat faced by data owners. In practical applications, dishonest recipients may sell or share data with third parties without authorization. Once a leak occurs, the data owner needs to be able to trace the source of the data to clarify responsibilities and prosecute violators. In addition, the core goal of data sharing is to support efficient data mining and analysis while maintaining the accuracy and usability of the data. However, under the intervention of privacy protection and liability tracing technologies, the utility of the data is often damaged. For example, adding privacy protection noise may reduce the analysis accuracy of the data, and the embedding of fingerprints may also cause data distortion. Therefore, how to minimize the loss of data utility while protecting privacy and tracing liability is an important research direction in the field of data sharing.

[0004] In data protection technologies, information hiding technologies (including watermarking and fingerprinting technologies) are widely used in data sharing scenarios. Watermarking technology is mainly used to prove the ownership of data. By embedding owner-specific marks in the data, these marks are detected in pirated data to claim data ownership. Fingerprinting technology is used to identify the recipients of illegally distributed data. By embedding unique digital marks for each recipient, the data owner can detect these marks in the leaked data to trace the source of the leak.

[0005] In addition, with the wide application of differential privacy technology, it provides a new technical means for data privacy protection. Differential privacy makes the data analysis results independent of individual data by adding noise, thus effectively protecting user privacy. Introducing differential privacy into fingerprint technology can achieve privacy protection during the embedding process. However, current research has not fully explored how to effectively combine differential privacy with the fingerprint embedding process. Most studies independently handle the data privacy protection problem and the responsibility tracing problem, embedding fingerprints in the data after differential privacy processing to achieve privacy protection and tracing functions. However, this method will significantly reduce the data utility and has not yet achieved a good balance among privacy protection, responsibility tracing, and data utility. Summary of the Invention

[0006] In view of the above problems, the present invention aims to provide a privacy protection probability fingerprint method for relational databases, which can not only effectively resist various fingerprint attacks, but also meet the requirements of differential privacy during the process of embedding fingerprints, thereby protecting data privacy while reducing the loss of data utility.

[0007] To achieve the above invention purpose, the technical method adopted by the present invention is as follows:

[0008] A fingerprint method for relational databases based on local differential privacy uses Tardos coding to generate a specific fingerprint sequence and assigns a unique fingerprint to each service provider; then combines the inherent internal conditional relevance of the data with the local differential privacy random response technology to embed fingerprints in the relational database; then, when it is found that the database is illegally redistributed, the fingerprints of the leaked database can be extracted through a highly reliable fingerprint extraction technology; finally, the fingerprints of the leaked database extracted are compared one by one with the fingerprints assigned to each service provider, and the illegal service providers are accused according to the tracing algorithm of Tardos coding. By adopting the above method, each fingerprint bit can be embedded with uniform probability, effectively resisting fingerprint attack algorithms such as random flipping attacks and collusion attacks, having good fingerprint robustness, while meeting the requirements of differential privacy during the process of embedding fingerprints and reducing the loss of data utility.

[0009] Furthermore, the method includes the following steps:

[0010] S1. Use Tardos coding to generate a specific fingerprint sequence and assign a unique fingerprint to each service provider;

[0011] S2. Combine the inherent internal conditional relevance of the data with the local differential privacy random response technology to embed fingerprints in the relational database;

[0012] S3. When it is found that the database is illegally redistributed, extract the fingerprints of the leaked database through a highly reliable fingerprint extraction technology;

[0013] S4. Compare the fingerprints of the extracted leakage database with the fingerprints assigned to each service provider one by one, and accuse the illegal service provider according to the tracing algorithm of Tardos coding.

[0014] In step S1, the generation of the fingerprint sequence includes the following process:

[0015] S11. Set the total number of service providers n, the maximum number of colluding service providers c, and the upper limit of the error rate e of the tracing algorithm, and generate parameters m = 100c 2 k,t = 1 / (300c);

[0016] S12. Generate a random number sequence u of length m, and its values are distributed in the interval [0,1];

[0017] S13. According to the probability distribution function Sample to obtain the fingerprint parameter q;

[0018] S14. Conduct n Bernoulli experiments according to the parameter q to generate a fingerprint sequence matrix of n rows and m columns, where each row corresponds to the fingerprint of a service provider.

[0019] In step S2, the fingerprint embedding includes the following process:

[0020] S21. Traverse the database and set the random number seed where is the key of the database owner, r.PmyKey is the primary key of the data tuple, i represents the i-th data tuple of the database, j represents the j-th attribute of each data tuple, N is the total number of database tuples, and M is the number of attributes of each data tuple;

[0021] S22. Generate the first random number where is a pseudo-random number generator, and set the fingerprint embedding probability p. If is divisible by then embed the fingerprint into the database;

[0022] S23. Generate the second random number If is divisible by 2, set the mask bit x = 0, otherwise set x = 1;

[0023] S24. Generate the third random number Set the fingerprint position where L is the length of the fingerprint; let the fingerprint bit f be the l-th bit of the fingerprint F;

[0024] S25. Calculate the marker bit If B = 1, sample a new value different from the current value according to the conditional probability of privacy protection and embed it into the data;

[0025] S26. The calculation method of the conditional probability of privacy protection is as follows:

[0026] Let r[i,j]=a, r[i,j - 1]=b, where r[i,j] represents the value corresponding to the j-th attribute of the i-th data tuple in the database. Set P(x j =a)=1 - p, and then allocate the remaining probability p proportionally to Among them where M j is the set of domain values of the j-th attribute of the data tuple; if j = 1, directly allocate the remaining probability according to P(x j =a);

[0027] At the same time, given the privacy budget ε, check the condition If the condition is not satisfied, increase Reduce other probabilities proportionally until the condition is satisfied;

[0028] S27. Definition of ε-local differential privacy: For any two possible inputs x and x′, and any possible output y, if a randomized algorithm satisfies the following conditions:

[0029]

[0030] Among them, ε is the privacy budget, indicating the strength of privacy protection, then the algorithm satisfies ε-local differential privacy.

[0031] S28. Definition of the K-level randomized response mechanism: For any input R, R has K possible results, and its output R′ is:

[0032]

[0033] That is, responds to the true result with probability and responds to any one of the other K - 1 results with probability

[0034] Among them, ε is the privacy budget, then it satisfies ε-local differential privacy.

[0035] S31. Traverse the leakage database and set the random number seed

[0036] S32. Generate the first random number Set the fingerprint embedding probability p. If is divisible by then embed the fingerprint into the database;

[0037] S33. Generate the second random number If is divisible by 2, set the mask bit x = 0; otherwise, set x = 1;

[0038] S34. Generate the third random number Set the fingerprint position where L is the length of the fingerprint;

[0039] S35. Calculate the flag bit represents the leaked data, extract the l-th bit of the fingerprint Count the values of F l extracted multiple times, and restore the original F through majority voting l , and finally restore the complete fingerprint F.

[0040] In step S4, the tracing algorithm includes the following process:

[0041] S41. For the fingerprint F' extracted from the leaked data and the service providers with public IDs, calculate the accusation score S ID for each service provider, and the calculation method is as follows:

[0042]

[0043] where F l is the l-th bit of the fingerprint, and q is the Tardos coding parameter.

[0044] S42. If S ID is greater than the threshold Z, then accuse the service provider of guilt.

[0045] Beneficial effects: Compared with the prior art, the substantial progress and remarkable feature of the present invention is that the fingerprint embedding and differential privacy noise addition are combined into one operation. In view of the fact that fingerprint embedding will cause data perturbation, and the differential privacy technology also perturbs the data by adding noise, the present invention combines the fingerprint embedding and differential privacy noise addition into one operation, so that the embedded fingerprint can simultaneously realize the function of differential privacy noise, thereby enabling the generated fingerprint database to not only effectively resist fingerprint attack algorithms such as random flipping attacks and collusion attacks, but also achieve comprehensive protection of data privacy and minimize the loss of data utility to the greatest extent. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] Figure 1 is a framework diagram of the privacy protection probability fingerprint method for the relational database of the present invention.

[0047] Figure 2 It is a flow chart of fingerprint embedding and fingerprint extraction for a typical relational database. Specific implementation manner

[0048] In order to illustrate in detail the technical solution provided by the present invention, the technical method of the present invention will be further described below with reference to the accompanying drawings.

[0049] The prior art needs to be implemented in two steps for database privacy and copyright protection. First, the database is cleaned to obtain a privacy-protected database, and then fingerprints are embedded in it. However, since both steps will perturb the data, the data utility will be greatly reduced, and the number of embedded fingerprints is insufficient, resulting in difficulty in resisting fingerprint attacks such as random flipping attacks and collusion attacks. In view of the fact that fingerprint embedding will cause data perturbation, and differential privacy technology also perturbs data by adding noise, the present invention, through careful design, combines fingerprint embedding and differential privacy noise addition into one operation, so that the embedded fingerprints can simultaneously achieve the function of differential privacy noise, which can minimize the loss of database utility. At the same time, a large number of fingerprints are embedded, effectively improving the robustness of the fingerprints. At the same time, conventional fingerprint methods are difficult to resist collusion attacks. Since the present invention extracts fingerprints using a majority voting mechanism, each fingerprint will be embedded multiple times. Only when more than half of the embedded copies are damaged will the fingerprint fail to be successfully extracted. Considering the short codeword characteristics of Tardos coding, combined with Tardos digital coding, while resisting collusion attacks, the number of embeddings of each fingerprint is increased, thereby further improving the robustness of the fingerprints.

[0050] The present invention aims to provide a relational database fingerprint method based on local differential privacy, which generates fingerprints through Tardos coding, embeds fingerprints in the relational database by combining the inherent internal conditional correlation of the data and the local differential privacy random response technology. When it is found that the database is illegally redistributed, the fingerprints of the leaked database are extracted according to the fingerprint extraction technology, and finally the illegal service provider is accused based on the tracing algorithm. This method evenly embeds fingerprint bits, can effectively resist random flipping and collusion attacks, and at the same time meets the requirements of differential privacy and reduces utility loss.

[0051] A complete privacy protection probability fingerprint method for a relational database, as Figure 1 shown, mainly includes four steps: fingerprint generation, fingerprint embedding, fingerprint extraction and tracing the illegal service provider.

[0052] In step S1, a specific fingerprint sequence is generated using Tardos coding, and then a unique fingerprint is assigned to each service provider. The generation of the fingerprint sequence includes the following process:

[0053] S11. Set the total number n of service providers, the maximum number c of colluding service providers, and the upper limit e of the error rate of the tracking algorithm, and generate parameters

[0054] S12. Generate a random number sequence u of length m, whose values are distributed in the interval [0, 1];

[0055] S13. Sample the fingerprint parameter q according to the probability distribution function

[0056] S14. Conduct n Bernoulli experiments according to the parameter q to generate a fingerprint sequence matrix of n rows and m columns, where each row corresponds to the fingerprint of a service provider.

[0057] In step S2, combine the inherent internal conditional relevance of the data with the local differential privacy random response technology to embed fingerprints in the relational database. The fingerprint embedding algorithm is as Figure 2 shown, including the following process:

[0058] S21. Traverse the database and set the random number seed where is the key of the database owner, r.PmyKey is the primary key of the data tuple, i represents the i-th data tuple of the database, j represents the j-th attribute of each data tuple, N is the total number of database tuples, and M is the number of attributes of each data tuple;

[0059] S22. Generate the first random number where is the pseudo-random number generator, and set the fingerprint embedding probability p. If is divisible by then embed the fingerprint in the database;

[0060] S23. Generate the second random number If is divisible by 2, set the mask bit x = 0, otherwise set x = 1;

[0061] S24. Generate the third random number Set the fingerprint position where L is the length of the fingerprint; let the fingerprint bit f be the l-th bit of the fingerprint F;

[0062] S25. Calculate the flag bit If B = 1, then sample a new value different from the current value according to the conditional probability of privacy protection and embed it in the data;

[0063] S26. The calculation method of the conditional probability of privacy protection is as follows:

[0064] ​Let r[i, j] = a and r[i, j - 1] = b, where r[i, j] represents the value corresponding to the j-th attribute of the i-th data tuple in the database. Set P(x j = a) = 1 - p, and then proportionally distribute the remaining probability p to where where M j is the set of domain values of the j-th attribute of the data tuple; if j = 1, then directly distribute the remaining probability according to ;

[0065] At the same time, given the privacy budget ε, check the condition If the condition is not satisfied, then increase and proportionally reduce other probabilities until the condition is satisfied;

[0066] S27. Definition of ε-local differential privacy: For any two possible inputs x and x′, and any possible output y, if a randomized algorithm satisfies the following conditions:

[0067]

[0068] where ε is the privacy budget, representing the strength of privacy protection, then the algorithm is said to satisfy ε-local differential privacy.

[0069] S28. Definition of the K-level randomized response mechanism: For any input R, R has K possible results, and its output R′ is:

[0070]

[0071] That is, with probability respond to the true result, and with probability respond to any one of the other K - 1 results, where ε is the privacy budget, then it satisfies ε-local differential privacy.

[0072] In step S3, when it is found that the database is illegally redistributed, extract the fingerprint of the leaked database through the fingerprint extraction algorithm, including the following process:

[0073] S31. Traverse the leaked database and set the random number seed

[0074] S32. Generate the first random number Set the fingerprint embedding probability p. If is divisible by then embed the fingerprint into the database;

[0075] S33. Generate the second random number If it can be divided evenly by 2, set the mask bit x = 0, otherwise set x = 1;

[0076] S34. Generate the third random number Set the fingerprint position where L is the length of the fingerprint;

[0077] S35. Calculate the flag bit indicating the leaked data, extract the l-th bit of the fingerprint Count the values of F l extracted multiple times, and restore the original F by majority voting l , and finally restore the complete fingerprint F.

[0078] In step S4, compare the fingerprint of the extracted leaked database with the fingerprints assigned to each service provider one by one, and accuse the illegal service provider according to the tracing algorithm of Tardos coding. The tracing algorithm includes the following process:

[0079] S41. For the fingerprint F' extracted from the leaked data and the service provider with a public ID, calculate the accusation score S ID of each service provider, and the calculation method is as follows:

[0080]

[0081] where F l is the l-th bit of the fingerprint, and q is the Tardos coding parameter.

[0082] S42. If S ID is greater than the threshold Z, accuse the service provider of being guilty.

[0083] Embodiment

[0084] The method provided by the present invention is used for experiments. The Adult dataset is used in the experiments. This dataset contains 32,561 records, recording users' personal information, including age, work situation, education level, salary, etc. The present invention obtains a fingerprint dataset by embedding fingerprints into the original dataset. This dataset can effectively resist fingerprint attack algorithms such as random flipping attack and collusion attack, and at the same time provide privacy protection for the data. In the experiment, the Tardos coding parameters are set as follows: the total number of service providers is 1000, the maximum number of colluding service providers is 6, and the upper limit of the error rate of the tracing algorithm is 0.05. At the same time, different privacy budgets are set for testing. The privacy budget ε is set to 2, 3, 4, 5, 6 in turn. To consider the correlation of the dataset, the embedding probability of the fingerprint Where k is the domain value size of the dataset, and in the Adult dataset, k is set to 16.

[0085] The server evaluates the robustness of fingerprints through random flipping attack experiments and collusion attack experiments on the fingerprint dataset, and evaluates the utility of the fingerprint dataset through classification experiments using a support vector machine (SVM).

[0086] In the random flipping attack experiment, first, a random flipping attack is performed on the original dataset to generate leaked data, and the random flipping probabilities are set to 0.1, 0.2, 0.3, 0.4, and 0.5 in sequence. Subsequently, fingerprint extraction algorithms are used to extract fingerprint information from the leaked data, and it is matched with the original fingerprint to calculate the accuracy of fingerprint extraction. At the same time, illegal service providers are identified through a tracing algorithm, and the accuracy of accusation is calculated to comprehensively evaluate the robustness of the method in the random flipping attack scenario.

[0087] In the collusion attack experiment, a majority collusion attack is performed on the original dataset to generate leaked data, and the number of colluding service providers is set to 2, 3, 4, 5, 6, 7, and 8 in sequence. The tracing algorithm is used to identify illegal service providers from the leaked data, and the probability of successfully accusing all illegal service providers and the probability of accusing at least one illegal service provider are calculated to comprehensively evaluate the robustness of the method in the collusion attack scenario.

[0088] In the SVM classification experiment, an SVM classifier is adopted, and 80% of the data records are used as the training set, and 20% of the data records are used as the test set. The utility of the fingerprint database is evaluated by comparing the fingerprint test accuracy (training the SVM classifier on the fingerprint training data and then testing on the original test data) with the original test accuracy (training the SVM classifier on the original training data and then testing on the original test data). To ensure the reliability and accuracy of the experimental results, five-fold cross-validation is adopted in the experiment. The smaller the difference between the fingerprint test accuracy and the original test accuracy, the smaller the impact of the fingerprint dataset on the data utility, and the higher the utility.

[0089] The experimental results of the privacy protection probability fingerprint method on the Adult dataset are shown in Table 1, Table 2, Table 3, Table 4, and Table 5 respectively, comprehensively demonstrating the robustness and utility performance of this method in various fingerprint attack scenarios.

[0090] Table 1 Accuracy of fingerprint extraction under random flipping attack

[0091]

[0092] Table 2 Accuracy of accusing illegal service providers under random flipping attack

[0093]

[0094] Table 3 Probability of accusing all illegal service providers under the collusive attack

[0095]

[0096] Table 4 Probability of accusing at least one illegal service provider under the collusive attack

[0097]

[0098] Table 5 SVM classification results under different privacy budgets

[0099]

[0100] As can be seen from Table 1 and Table 2, in the scenario of the random flipping attack, with the increase of the random flipping rate, the accuracy of fingerprint extraction gradually decreases. When the privacy budget is small, the accuracy of fingerprint extraction remains above 95%. When the privacy budget ε = 6, even when the random flipping rate is as high as 50%, the accuracy of fingerprint extraction is still higher than 75%, which is sufficient to correctly accuse illegal service providers, proving the robustness of this method against the random flipping attack.

[0101] As can be seen from Table 3 and Table 4, in the scenario of the collusive attack, when the number of actual collusive service providers does not exceed the maximum number of collusive service providers, this method can successfully accuse all illegal service providers; when the number of actual collusive service providers exceeds the maximum number of collusive service providers, it can still successfully accuse at least one illegal service provider, proving the robustness of this method against the collusive attack.

[0102] As can be seen from Table 5, in the SVM classification experiment, with the increase of the privacy budget, the difference between the fingerprint test accuracy and the original test accuracy gradually decreases. When the privacy budget ε > 3, the accuracy loss is less than 10%. At the same time, although there are certain differences in the results of the 5 experiments, the overall fluctuation is small, indicating that this fingerprint method has a small impact on the database utility and has high stability and practicality.

Claims

1. A relational database fingerprint method based on local differential privacy, characterized in that the steps include: S1. Generate fingerprint sequence using Tardos encoding and assign unique fingerprint to each service provider; The generation of the fingerprint sequence includes the following process: S11. Set the total number of service providers n, the maximum number of colluding service providers c, and the upper limit of the error rate of the tracking algorithm e, and generate parameters m=100c 2 k,t=1 / (300c); S12, generate a random number sequence u of length m, whose values ​​are distributed in the interval [0,1]; S13. According to the probability distribution function Sampling to obtain fingerprint parameter q; S14, performing n Bernoulli experiments according to parameter q, generating a fingerprint sequence matrix of n rows and m columns, wherein each row corresponds to a fingerprint of a service provider; S2, embedding fingerprints in relational databases by combining the inherent conditional correlation of data with local differential privacy random response technology; The fingerprint embedding is specifically as follows: S21. Traverse the database and set the random number seed i∈[1,N],j∈[1,M], where K is the database owner's key, r.PmyKey is the primary key of the data tuple, i represents the i-th data tuple in the database, j represents the j-th attribute of each data tuple, N is the total number of database tuples, and M is the number of attributes of each data tuple; S22. Generate the first random number in is a pseudo-random number generator, and sets the fingerprint embedding probability p. If Divisible Then embed the fingerprint into the database; S23. Generate a second random number if If it is divisible by 2, set the mask bit x=0, otherwise set x=1; S24. Generate the third random number Set fingerprint location Where L is the length of the fingerprint; let fingerprint bit f be the lth bit of fingerprint F; S25, calculate the mark position If B = 1, a new value different from the current value is sampled and embedded into the data according to the privacy-preserving conditional probability; S26. The conditional probability calculation method for privacy protection is as follows: Assume r[i,j] = a, r[i,j-1] = b, where r[i,j] represents the value corresponding to the jth attribute of the i-th data tuple in the database, and set P(x j =a) = 1-p, then according to Distribute the remaining probability p equally to in M j is the domain value set of the jth attribute of the data tuple; if j = 1, then directly follow Assign residual probabilities; Given a privacy budget ε, check the condition If the condition is not met, increase Reduce other probabilities in equal proportion until the conditions are met; S27, ε-local differential privacy definition: For any two possible inputs x and x′, and any possible output y, if a randomized algorithm The following conditions are met: Among them, ε is the privacy budget, which indicates the strength of privacy protection. The algorithm is called Satisfies ε-local differential privacy; S28, K-level random response mechanism definition: For any input R, R has K possible results, and its output R′ is: That is The probability of responding to the true result is The probability of responding to any of the other K-1 results, where ε is the privacy budget, satisfies ε-local differential privacy; S3. When illegal redistribution of the database is discovered, the fingerprint of the leaked database is extracted through fingerprint extraction technology. Each fingerprint is embedded multiple times, so that when more than half of the embedded copies are destroyed, the fingerprint cannot be successfully extracted. S4. Compare the extracted fingerprint of the leaked database with the fingerprint assigned to each service provider one by one, and accuse the illegal service provider according to the tracking algorithm encoded by Tardos; The tracking algorithm is as follows: S41. For the fingerprint F′ extracted from the leaked data and the service providers with public IDs, calculate the accusation score S of each service provider. ID , calculated as follows: where F l is the lth bit of the fingerprint, and q is the Tardos encoding parameter; S42, if S ID If it is greater than the threshold Z, the service provider is accused of leaking data privacy.

2. The relational database fingerprint method based on local differential privacy according to claim 1, characterized in that: The fingerprint extraction method of step S3 is as follows: S31. Traverse the leaked database and set the random number seed i∈[1,N], j∈[1,M]; S32, generate the first random number Set the fingerprint embedding probability p if Divisible Then embed the fingerprint into the database; S33, generate the second random number if If it is divisible by 2, set the mask bit x=0, otherwise set x=1; S34. Generate the third random number Set fingerprint location Where L is the length of the fingerprint; S35, calculate the mark position Indicates leaked data, extract the lth bit of the fingerprint For the F extracted multiple times l The value counts and restores the original F by majority voting l , and finally restore the complete fingerprint F.