Vulnerability detection method based on differential privacy and related equipment
By introducing differential privacy technology into the vulnerability detection system, allocating privacy budgets and adding noise, the problem of privacy leakage in the existing technology is solved, and security protection and vulnerability detection of user data in a distributed environment is realized.
Patent Information
- Application Number
- CN202510535535.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-04-27
AI Technical Summary
Existing vulnerability mining technologies may lead to privacy leakage when processing important user data, especially in a distributed environment where multi-party collaboration is difficult to effectively protect the privacy of user data.
Vulnerability detection method based on differential privacy is adopted to protect the privacy of user behavior data by allocating privacy budgets in distributed nodes and adding noise according to query sensitivity. After each distributed node independently analyzes the data, the method summarizes and adds noise again through the central control node to generate a vulnerability detection report.
It effectively protects the privacy of user data, enhances the robustness of data query, promptly detects and reports security vulnerabilities, improves the proactive defense capabilities of network security, and ensures the secure use and privacy protection of user data in a distributed environment.
Smart Images

Figure CN120074956A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technologies, and in particular, to a vulnerability detection method and related devices based on differential privacy. Background Art
[0002] With the rapid development of the Internet and information technologies, network attacks and data leakage incidents occur frequently worldwide, and network security issues are becoming increasingly severe. In response to this challenge, vulnerability mining technology has become an important tool for ensuring the security of information systems. Vulnerability mining aims to identify potential security vulnerabilities by comprehensively analyzing a system, helping system administrators detect and repair security defects in a timely manner, and preventing malicious attackers from exploiting vulnerabilities to damage the system.
[0003] However, existing vulnerability mining technologies may lead to the problem of leakage of important user data and cannot guarantee network security. Summary of the Invention
[0004] In view of this, the purpose of this application is to propose a vulnerability detection method and related devices based on differential privacy to solve the above technical problems.
[0005] Based on the above purpose, the first aspect of this application provides a vulnerability detection method based on differential privacy, which is applied to a vulnerability detection system based on differential privacy. The system includes a central control node and multiple distributed nodes. Each distributed node is used to process different types of user behavior data. The method includes: Query user behavior data corresponding to a target user from each distributed node according to a preset query task corresponding to each distributed node, and determine an initial query result of the corresponding query task according to each user behavior data; For each distributed node, perform the following operations: obtain the trust level corresponding to the distributed node, and allocate the privacy budget of the distributed node by using the trust level corresponding to the distributed node; determine the query sensitivity corresponding to the query task of the distributed node, determine differential privacy noise based on the noise distribution mechanism according to the privacy budget and the query sensitivity, and add the differential privacy noise to the initial query result corresponding to the distributed node to obtain a query result after noise addition; in response to the query result after noise addition not being within the range of a preset query result threshold, determine that the vulnerability detection result corresponding to the distributed node is that there is a security vulnerability, and send the vulnerability detection result corresponding to the distributed node to the central control node; or, in response to the query result after noise addition being within the range of the preset query result threshold, determine that the vulnerability detection result corresponding to the distributed node is that there is no security vulnerability, and send the vulnerability detection result corresponding to the distributed node to the central control node; The vulnerability detection results corresponding to each distributed node are aggregated through a central control node to obtain an aggregated result. Preset differential privacy noise is added to the aggregated result to obtain an aggregated result with noise added, and a vulnerability detection report is generated based on the aggregated result with noise added for vulnerability repair according to the vulnerability detection report.
[0006] Based on the same inventive concept, a second aspect of the present application provides a vulnerability detection device based on differential privacy. The device is arranged in a vulnerability detection system based on differential privacy. The system includes a central control node and multiple distributed nodes, and each distributed node is used to process different types of user behavior data. The device includes: A query module, configured to query user behavior data corresponding to a target user from each distributed node according to a preset query task corresponding to each distributed node, and determine an initial query result of the corresponding query task according to each user behavior data; A vulnerability detection module, configured to perform the following operations for each distributed node: obtain the trust level corresponding to the distributed node, and allocate the privacy budget of the distributed node by using the trust level corresponding to the distributed node; determine the query sensitivity corresponding to the query task of the distributed node, determine differential privacy noise based on the privacy budget and the query sensitivity based on a noise distribution mechanism, and add the differential privacy noise to the initial query result corresponding to the distributed node to obtain a query result with noise added; in response to the query result with noise added not being within the range of a preset query result threshold, determine that the vulnerability detection result corresponding to the distributed node has a security vulnerability, and send the vulnerability detection result corresponding to the distributed node to the central control node; or, in response to the query result with noise added being within the range of the preset query result threshold, determine that the vulnerability detection result corresponding to the distributed node has no security vulnerability, and send the vulnerability detection result corresponding to the distributed node to the central control node; An aggregation module, configured to aggregate the vulnerability detection results corresponding to each distributed node through a central control node to obtain an aggregated result, add preset differential privacy noise to the aggregated result to obtain an aggregated result with noise added, and generate a vulnerability detection report based on the aggregated result with noise added for vulnerability repair according to the vulnerability detection report.
[0007] Based on the same inventive concept, a third aspect of the present application provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executed by the processor. When the processor executes the computer program, the method described in the first aspect above is implemented.
[0008] Based on the same inventive concept, a fourth aspect of the present application provides a non-transitory computer-readable storage medium storing computer instructions for causing a computer to execute the method described in the first aspect above.
[0009] As can be seen from the above, the vulnerability detection method and related devices based on differential privacy provided by the present application perform preset query tasks for each distributed node to ensure the pertinence and efficiency of data collection. Then, the privacy budget is allocated according to the node trust level, and differential privacy noise is added according to the query sensitivity. This mechanism not only protects the privacy of user data but also enhances the robustness of data queries. For the query results, through preset threshold verification, security vulnerabilities are promptly discovered and reported, realizing active defense against network security. Finally, the central control node aggregates the vulnerability detection results of each node and applies differential privacy protection again to further consolidate the security of the data aggregation stage, which can significantly improve the comprehensive efficiency of data query and network security protection, ensure the secure use and privacy protection of user data in a distributed environment, and provide strong support for network security reinforcement. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] In order to more clearly illustrate the technical solutions in the present application or related technologies, the following will briefly introduce the drawings required for use in the embodiments or related technology descriptions. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0011] Figure 1 It is a flowchart of the vulnerability detection method based on differential privacy according to an embodiment of the present application; Figure 2 It is a schematic structural diagram of the vulnerability detection system based on differential privacy according to an embodiment of the present application; Figure 3 It is a schematic data flow diagram of vulnerability detection according to an embodiment of the present application; Figure 4 It is a flowchart of adding noise to the differential privacy algorithm according to an embodiment of the present application; Figure 5 It is a block diagram of the structure of the vulnerability detection device based on differential privacy according to an embodiment of the present application; Figure 6 It is a schematic diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0012] To make the objectives, technical solutions, and advantages of the present application clearer, the following further elaborates on the present application in detail with reference to specific embodiments and the accompanying drawings.
[0013] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present application should have the ordinary meanings understood by those of ordinary skill in the field to which the present application belongs. The "first", "second" and similar terms used in the embodiments of the present application do not denote any order, quantity or importance, but are only used to distinguish different components. Words such as "including" or "comprising" mean that the elements or objects appearing before the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. Words such as "connected" or "linked" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. "Upper", "lower", "left", "right", etc. are only used to indicate relative position relationships, and when the absolute position of the object being described changes, the relative position relationship may also change accordingly.
[0014] It can be understood that before using the technical solutions of the various embodiments of the present application, the types, usage scopes, usage scenarios, etc. of the personal information involved will be informed to the user in an appropriate manner, and the user's authorization will be obtained.
[0015] For example, when responding to receiving an active request from the user, a prompt message is sent to the user to clearly prompt the user that the operation requested by the user will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, an application program, a server or a storage medium that executes the technical solution of the present application according to the prompt message.
[0016] As an optional but non-limiting implementation manner, the manner of sending a prompt message to the user in response to receiving an active request from the user can be, for example, in the form of a pop-up window, and the prompt message can be presented in text in the pop-up window. In addition, the pop-up window can also carry a selection control for the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0017] It can be understood that the above process of notifying and obtaining the user's authorization is only illustrative and does not limit the implementation manner of the present application, and other manners that meet relevant laws and regulations can also be applied to the implementation manner of the present application.
[0018] With the rapid development of the Internet and information technology, network attacks and data leakage incidents occur frequently globally, and network security issues are becoming increasingly severe. In response to this challenge, vulnerability mining technology has become an important tool to ensure the security of information systems. Vulnerability mining aims to identify potential security vulnerabilities through a comprehensive analysis of the system, helping system administrators discover and repair security defects in a timely manner, and preventing malicious attackers from exploiting vulnerabilities to damage the system. However, existing vulnerability mining technologies still face many challenges in practical applications, especially the issues in privacy protection are becoming more prominent.
[0019] Currently, vulnerability mining is mainly divided into two categories: static analysis and dynamic analysis. With the increase in system complexity, vulnerability mining in distributed systems and cloud computing environments has gradually become the focus. In these environments, the system involves multiple participants and there is a vast amount of user data. Since security detection requires access to important user data, how to protect the privacy of this data has become a key issue in vulnerability mining.
[0020] Vulnerability mining technology usually needs to obtain a large amount of system data for analysis, including log files, system calls, network traffic, and user input, etc. However, these data often contain a large amount of important information, such as users' personally identifiable information (PII), medical records, etc. Traditional vulnerability mining technologies may lead to privacy leakage when dealing with these important data. Especially in a distributed environment with multi-party collaboration, privacy protection becomes more complex. Therefore, conducting effective vulnerability mining without compromising user privacy is an urgent problem to be solved in this field currently.
[0021] This application applies differential privacy technology. Differential privacy ensures that query results on adjacent data sets are indistinguishable by introducing random noise during the data analysis process, thereby reducing the impact of individual data records on the overall analysis results. It guarantees that even if an attacker obtains the analysis results, they cannot infer specific user data. This mechanism balances privacy protection and data availability by controlling the "privacy budget". Differential privacy technology can be applied in various scenarios, such as data sharing, data analysis, and machine learning model training, to protect the privacy of data providers while ensuring the usefulness of data analysis results.
[0022] In the field of vulnerability mining, differential privacy can solve the following problems: Protect data privacy: During the vulnerability detection process, differential privacy can prevent external attackers or untrusted cooperation parties from inferring specific user information by protecting important data.
[0023] Enhancing the Security of Multi-Party Collaboration: In the scenario of vulnerability mining in a distributed or multi-party collaboration environment, differential privacy allows different organizations and platforms to share vulnerability mining results without sharing the original data, thereby improving the efficiency of collaboration while protecting privacy.
[0024] Existing vulnerability mining technologies mainly focus on the detection of system security vulnerabilities, but pay relatively limited attention to privacy protection. In the scenario of multi-party data sharing or distributed vulnerability mining, the main problems faced by traditional technologies include: Risk of Privacy Leakage: In multi-party vulnerability detection, traditional methods require different participants to share important data, leading to an increased risk of privacy leakage. For example, in a cloud computing environment, after users upload data, cloud service providers or external security auditing companies may obtain important user information through this data.
[0025] Challenges in Cross-Platform Vulnerability Mining: Mining security vulnerabilities between different systems and platforms requires a large amount of data exchange and collaboration, and traditional vulnerability mining technologies cannot guarantee that data leakage will not occur during these collaborations.
[0026] Limitations of Static and Dynamic Vulnerability Mining: Existing static analysis cannot detect vulnerabilities that depend on runtime conditions, and dynamic analysis is easily limited by test coverage. Especially in distributed systems, it is impossible to comprehensively detect all potential vulnerabilities.
[0027] To address the deficiencies in existing technologies, this application proposes a vulnerability detection method based on differential privacy, which is applied to a vulnerability detection system based on differential privacy. This system can perform distributed vulnerability mining while protecting user privacy and has the following technical advantages: Introduction of Differential Privacy Mechanism: Through differential privacy technology, important data is processed to ensure that user privacy is not leaked during the vulnerability detection process. Even if an attacker obtains the vulnerability mining results, it is still impossible to restore the original important data.
[0028] Distributed Vulnerability Mining: The system supports executing vulnerability mining in a distributed environment. Each node can independently analyze local data and simultaneously share the analysis results with other nodes through the differential privacy protection mechanism to ensure privacy security during the collaboration process.
[0029] Multi-Party Collaboration and Data Sharing: This system is particularly suitable for cross-organization and cross-platform data sharing and vulnerability mining scenarios, allowing multiple participants to collaborate on the vulnerability detection task of the system without sharing specific data.
[0030] Security Enhancement Function: Based on the vulnerability mining results, the system automatically evaluates risks and generates repair suggestions, thereby enhancing the overall security of the system.
[0031] This application aims to solve the problem of privacy leakage existing in the existing vulnerability mining technology, and proposes a vulnerability detection method based on differential privacy, which is applied to a vulnerability detection system based on differential privacy. When conducting vulnerability detection, traditional vulnerability mining technology usually needs to access a large amount of important data such as system logs, network traffic, and user inputs. Especially in the scenarios of distributed systems or multi-party collaborations, the privacy protection of data has become a major problem. However, the existing technology often fails to effectively conduct vulnerability mining while ensuring data privacy, resulting in the risk of privacy leakage when the system conducts security analysis.
[0032] To solve this problem, this application preprocesses important data by introducing differential privacy technology, ensuring that in the process of vulnerability detection, a single data point will not significantly affect the final detection result, thus effectively preventing external attackers from inferring specific user information through the analysis result. At the same time, this application is based on a distributed computing framework, supports vulnerability mining across multiple nodes. Each node can independently conduct vulnerability detection and share the analysis results while protecting privacy, thereby improving the efficiency and security of distributed vulnerability mining.
[0033] The objectives of this application are as follows: Protect data privacy: By using differential privacy technology, random noise is added to the data query results during the vulnerability mining process to ensure that important user information is not leaked. The system controls the privacy budget to adjust the intensity of the noise, so as to find the best balance between data accuracy and privacy protection. Especially in the environments of multi-party collaborations and distributed systems, it can effectively avoid privacy leakage.
[0034] Improve the efficiency of vulnerability mining: Utilize the distributed computing framework to allocate the vulnerability mining tasks to multiple nodes. Each node independently completes the detection task and shares the vulnerability detection results through the differential privacy mechanism, thereby accelerating the detection speed.
[0035] Multi-party collaboration and data sharing: Allow multiple organizations or platforms to conduct collaborative vulnerability detection without sharing the original data, ensuring the security of the data privacy of all parties.
[0036] Security enhancement and risk assessment: According to the vulnerability detection results, the system can automatically evaluate potential security risks and generate repair suggestions to help system administrators take measures in a timely manner and improve the overall security of the system.
[0037] This application mainly applies the following technologies: (1)The differential privacy technology is applied to distributed vulnerability mining for the first time. A comprehensive privacy protection mechanism is designed for the access problem of important data during the vulnerability mining process. In data analysis, by injecting random noise into the query results, it is ensured that the query results of adjacent datasets are difficult to distinguish, thus protecting the privacy of individual data records. Specifically for time series data (such as network logs, call traces, etc.), a time window partitioning method is proposed, and the balance between privacy protection and data accuracy is achieved by dynamically adjusting the noise intensity. In addition, Fourier transform and wavelet analysis techniques are used to retain the trends and periodic patterns of time series, avoiding the destruction of global characteristics by noise, which provides higher reliability for time-based vulnerability mining.
[0038] (2)Based on trust-level collaboration optimization, to address the complexity of multi-party collaboration in the distributed vulnerability mining scenario, this application proposes a trust-level collaboration optimization mechanism. By assigning trust levels (high, medium, low) to each collaboration node, the system can dynamically adjust the privacy budget ( value) to meet the privacy requirements of different nodes. High-trust nodes are allocated less noise due to high data security to ensure data usability; while low-trust nodes protect their important data by increasing noise. This trust-level mechanism not only improves collaboration efficiency but also ensures privacy security in multi-party collaboration.
[0039] (3)To reduce the risk of privacy leakage caused by data transmission in distributed vulnerability mining, this application introduces edge computing technology. By performing differential privacy preprocessing at edge nodes close to the data source, the system realizes local data analysis while reducing the exposure risk of important data during transmission. After being protected by differential privacy, the edge nodes upload the analysis results to the central node for aggregation. In addition, in a distributed environment, the differential privacy mechanism is also used when sharing intermediate results between nodes, thus ensuring the privacy of node collaboration. This design combining edge computing makes vulnerability detection more efficient and secure.
[0040] (4)Regarding the problem that multiple queries in a distributed environment may lead to privacy leakage, this application proposes a dynamic privacy budget allocation mechanism. By comprehensively considering the trust level of nodes and the global privacy budget, the system realizes the dynamic allocation of the privacy budget and designs a sensitivity calculation method suitable for different data types. In important data scenarios such as time series data or user behavior logs, the system dynamically adjusts the noise intensity according to the query sensitivity, ensuring both the accuracy of data analysis results and avoiding excessive consumption of the privacy budget.
[0041] (5) In distributed vulnerability mining, the detection results of each node need to be aggregated to the central node. To avoid leaking important information in the aggregated results, this application designs a quadratic differential privacy protection mechanism. On the basis of injecting initial noise into the node detection results, the system injects global noise again during the aggregation process to ensure that attackers cannot infer the original data through multiple queries. In addition, the system adjusts the result aggregation strategy according to the node trust level. High-trust nodes directly participate in the aggregation, while the results of low-trust nodes are incorporated in a low-resolution form. This double-layer protection strategy strengthens the global privacy protection ability.
[0042] An embodiment of this application provides a vulnerability detection method based on differential privacy, which performs preset query tasks for each distributed node to ensure the pertinence and efficiency of data collection. Then, the privacy budget is allocated according to the node trust level, and differential privacy noise is added according to the query sensitivity. This mechanism not only protects the privacy of user data but also enhances the robustness of data queries. For the query results, security vulnerabilities are detected and reported in a timely manner through preset threshold verification, realizing active defense against network security. Finally, the central control node aggregates the vulnerability detection results of each node and applies differential privacy protection again, further consolidating the security of the data aggregation stage, significantly improving the comprehensive efficiency of data queries and network security protection, ensuring the secure use and privacy protection of user data in a distributed environment, and providing strong support for network security reinforcement.
[0043] As Figure 1 shown, the method of this embodiment is applied to a vulnerability detection system based on differential privacy. The system includes a central control node and multiple distributed nodes. Each distributed node is used to process different types of user behavior data. The method includes: Step 101, query the user behavior data corresponding to the target user from each distributed node according to the preset query task corresponding to each distributed node, and determine the initial query result of the corresponding query task according to each user behavior data.
[0044] In this step, specific query tasks are preset for each distributed node. These tasks define which types of user behavior data or which conditions are met to retrieve from the corresponding node.
[0045] Distributed nodes refer to different computing units or data storage locations distributed in the network. In a vulnerability detection system based on differential privacy, data is scattered and stored on these nodes to improve the efficiency, scalability, and fault tolerance of data access. Each node stores different parts or types of data related to user behavior.
[0046] According to the preset query task, the system retrieves user behavior data related to the target user from each distributed node. The target user may be determined based on specific user identifiers (such as user ID), user attributes (such as age, gender), or other business logics. User behavior data may include user click behavior, browsing history, etc.
[0047] The user behavior data collected from each node is used to generate the initial query result for the corresponding query task. This process may involve operations such as data aggregation, filtering, transformation, etc., to ensure that the result meets the requirements of the preset query task. The initial query result may be a direct summary of the original data or may have undergone a certain degree of processing or analysis.
[0048] Step 102, perform the following operations for each distributed node: obtain the trust level corresponding to the distributed node, and allocate the privacy budget of the distributed node using the trust level corresponding to the distributed node; determine the query sensitivity corresponding to the query task of the distributed node, determine the differential privacy noise based on the privacy budget and the query sensitivity according to the noise distribution mechanism, and add the differential privacy noise to the initial query result corresponding to the distributed node to obtain the query result after noise addition; in response to the query result after noise addition not being within the range of the preset query result threshold, determine that the vulnerability detection result corresponding to the distributed node is that there is a security vulnerability, and send the vulnerability detection result corresponding to the distributed node to the central control node; or, in response to the query result after noise addition being within the range of the preset query result threshold, determine that the vulnerability detection result corresponding to the distributed node is that there is no security vulnerability, and send the vulnerability detection result corresponding to the distributed node to the central control node.
[0049] In this step, each distributed node has a corresponding trust level. This trust level may be determined based on various factors such as the node's historical behavior, security, data processing ability, etc.
[0050] Based on this trust level, the system allocates a privacy budget for each node. The privacy budget is an indicator to measure the intensity of privacy protection. The higher the budget, the more data queries or analyses can be allowed while protecting privacy without revealing too much information.
[0051] For the query task of each distributed node, the system first determines the sensitivity of this query. The query sensitivity reflects the sensitivity of the query result to the change of a single data item in the dataset.
[0052] Based on the privacy budget and query sensitivity, the system determines the amount of differential privacy noise to be added using a noise distribution mechanism (such as Laplace noise or Gaussian noise). Differential privacy is a privacy protection technique that protects individual privacy by adding noise to query results while ensuring that the accuracy of query results is within an acceptable range.
[0053] The determined differential privacy noise is added to the initial query result to obtain a noise-processed query result.
[0054] The system presets a query result threshold range to evaluate the reasonableness of the noise-processed query result.
[0055] If the query result after adding noise is not within the preset threshold range, the system considers that there may be a security vulnerability in the distributed node. This may be because the amount of added noise is abnormal, reflecting that the data has been tampered with or there are abnormal behaviors in the system.
[0056] On the contrary, if the query result is within the preset threshold range, it is considered that there is no security vulnerability in the node.
[0057] Regardless of the detection result, the system will send the vulnerability detection result corresponding to each distributed node to the central control node. The central control node is responsible for collecting the detection results of all nodes, conducting comprehensive analysis, and may take further actions, such as notifying the administrator, isolating the affected nodes, etc.
[0058] This process combines differential privacy technology and security vulnerability detection, aiming to ensure the security and stability of the system while protecting the data privacy in the distributed system.
[0059] Step 103: Aggregate the vulnerability detection results corresponding to each distributed node through the central control node to obtain an aggregated result, add preset differential privacy noise to the aggregated result to obtain a noise-added aggregated result, and generate a vulnerability detection report based on the noise-added aggregated result for vulnerability repair according to the vulnerability detection report.
[0060] In this step, each distributed node independently conducts vulnerability detection. This means that each node will check its own security and look for possible vulnerabilities or weaknesses.
[0061] After all distributed nodes complete vulnerability detection, they send their respective detection results to the central control node. The central control node is responsible for collecting these results and aggregating them into a unified aggregated result. This aggregated result reflects the vulnerability detection situation of all nodes in the entire distributed system.
[0062] To protect data privacy and prevent the leakage of important information, the central control node adds preset differential privacy noise to the aggregated results. By adding noise to the original data, the privacy of individual data records can be protected while ensuring the accuracy of the data query results.
[0063] The aggregated results after noise addition no longer directly reflect the original detection data, but they still retain sufficient information to generate a vulnerability detection report. This report is based on the statistics and analysis of the aggregated results and points out information such as the types, locations, and possible severities of vulnerabilities existing in the system.
[0064] Finally, the system administrator or security team will take necessary measures to fix the discovered vulnerabilities based on the information in the vulnerability detection report. This may include updating software, modifying configurations, enhancing access controls, etc.
[0065] The entire process not only achieves a comprehensive detection of the security of the distributed system but also effectively protects the privacy of important information in the system through the application of differential privacy technology, ensuring the security and compliance of the data.
[0066] Through the above solution, preset query tasks are executed for each distributed node to ensure the pertinence and efficiency of data collection. Then, the privacy budget is allocated according to the trust level of the nodes, and differential privacy noise is added according to the query sensitivity. This mechanism not only protects the privacy of user data but also enhances the robustness of data queries. For the query results, through preset threshold verification, security vulnerabilities are discovered and reported in a timely manner, realizing active defense against network security. Finally, the central control node aggregates the vulnerability detection results of each node and applies differential privacy protection again to further consolidate the security in the data aggregation stage, which can significantly improve the comprehensive efficiency of data query and network security protection, ensure the secure use and privacy protection of user data in a distributed environment, and provide strong support for network security reinforcement.
[0067] In some embodiments, in step 102, the allocating the privacy budget of the distributed node by using the trust level corresponding to the distributed node includes: Step A1, obtaining the privacy budgets of all distributed nodes.
[0068] Step A2, determining the privacy budget of the distributed node based on the privacy budgets of all distributed nodes and the weights of the trust levels corresponding to the distributed nodes through the following formula:
[0069] where, represents the privacy budget of the distributed node and represents the weight of the trust level of the distributed node and represents the privacy budget of all distributed nodes.
[0070] In the above solution, each distributed node is assigned a trust level, which reflects the degree to which the node is considered trustworthy. The trust level is usually represented in the form of a weight, and the higher the weight, the more trustworthy the node is.
[0071] Distributed nodes with a high trust level allocate less noise due to high data security to ensure data utility, so that more accurate or complex data processing can be performed while ensuring privacy.
[0072] By flexibly adjusting the privacy protection measures according to the credibility of the nodes, a balance can be found between privacy protection and data processing efficiency.
[0073] In some embodiments, in step 102, determining the query sensitivity corresponding to the query task of the distributed node includes: Step B1, obtaining the initial query result corresponding to the first user behavior data set in the current time window, and the initial query result corresponding to the second user behavior data set in the adjacent time window of the current time window.
[0074] Step B2, based on the initial query result corresponding to the first user behavior data set and the initial query result corresponding to the second user behavior data set, determining the query sensitivity through the following formula:
[0075] where represents the query sensitivity, represents the first user behavior data set corresponding initial query result, represents the second user behavior data set corresponding initial query result.
[0076] In the above solution, within the current time window, there is a first user behavior data set. After querying this data set, the corresponding initial query result is obtained. At the same time, within the adjacent time window of the current time window (which may be the previous or the next time window), there is a second user behavior data set. After querying this data set, the corresponding initial query result is also obtained.
[0077] The query sensitivity is an indicator used to measure the sensitivity of the query result to changes in the input data (here, the user behavior data set).
[0078] A high query sensitivity means that the query result is very sensitive to small changes in the user behavior data set, which may lead to instability or unpredictability of the query result.
[0079] A low query sensitivity means that the query results are less sensitive to changes in the user behavior dataset, which usually means that the query results are more stable and reliable.
[0080] In summary, this method evaluates the sensitivity of the query task by comparing the initial query results corresponding to the user behavior datasets in different time windows, thus helping to understand the stability and reliability of the query results.
[0081] In some embodiments, the noise distribution mechanism includes the Laplace mechanism.
[0082] In step 102, determining the differential privacy noise based on the privacy budget and query sensitivity according to the noise distribution mechanism includes: Step C1, performing a ratio process on the query sensitivity and the privacy budget to obtain a scale parameter.
[0083] Step C2, processing the scale parameter using the probability density function of the Laplace distribution to obtain the differential privacy noise.
[0084] In the above solution, differential privacy technology protects privacy by adding noise to the data query results. The distribution of the noise can be in various forms. The Laplace distribution is a continuous probability distribution, whose probability density function is symmetric about its mean and has heavier tails than the normal distribution, which means it allows larger noise values and helps to maintain the availability of the data while protecting privacy.
[0085] The privacy budget is a parameter measuring the degree of privacy protection. The query sensitivity is a parameter measuring the sensitivity of the query results to changes in individual data in the dataset.
[0086] In the Laplace mechanism, the magnitude of the noise is controlled by a scale parameter. This scale parameter is calculated by dividing the query sensitivity by the privacy budget.
[0087] Once the scale parameter is determined, the probability density function of the Laplace distribution can be used to generate the noise. In the Laplace distribution, the noise value is randomly drawn from a distribution centered at 0 with the scale parameter as the scale. This noise value is then added to the query results to ensure meeting the requirements of differential privacy.
[0088] In some embodiments, the noise distribution mechanism includes the Gaussian mechanism.
[0089] In step 102, determining the differential privacy noise based on the privacy budget and query sensitivity according to the noise distribution mechanism includes: Step D1, determine the variance of the probability density function of the Gaussian distribution, and based on the variance of the probability density function of the Gaussian distribution, the query sensitivity, and the privacy budget, determine the noise standard deviation through the following formula:
[0090] where, represents the noise standard deviation, represents the query sensitivity, represents the privacy budget, represents the variance of the probability density function of the Gaussian distribution.
[0091] Step D2, process the noise standard deviation using the probability density function of the Gaussian distribution to obtain differential privacy noise.
[0092] In the above solution, in differential privacy protection, a Gaussian distribution (normal distribution) can be used to generate the noise added to the query result. The Gaussian distribution is a common continuous probability distribution, and its shape is determined by the mean and variance.
[0093] When using the Gaussian mechanism, first, it is necessary to determine the variance of the probability density function of the Gaussian distribution . This variance determines the dispersion degree of the noise, that is, the possible fluctuation range of the noise value.
[0094] Determine the noise standard deviation based on the variance of the probability density function of the Gaussian distribution, the query sensitivity, and the privacy budget .
[0095] Once the noise standard deviation is determined, the probability density function of the Gaussian distribution can be used to generate specific noise values. This usually involves randomly drawing a value from the Gaussian distribution, and the distribution of this value is determined by the noise standard deviation.
[0096] Adding this randomly generated noise value to the query result can obtain a differential privacy query result that not only protects privacy but also retains the characteristics of the original data as much as possible.
[0097] In some embodiments, in step 102, adding differential privacy noise to the initial query result corresponding to the distributed node to obtain the query result after noise addition includes: Step E1, perform a summation process based on the initial query result corresponding to the distributed node and the differential privacy noise to determine the initial query result after noise addition.
[0098] Step E2, obtain the time window of the initial query result corresponding to the distributed node, and determine the data activity period of the time window, where the data activity period is used to indicate the activity status of the data within a specific time period.
[0099] Step E3, in response to the data activity period belonging to a preset first data activity period type, reduce the initially noise-added query result according to a preset noise threshold to obtain a noise-added query result. Or, Step E4, in response to the data activity period belonging to a preset second data activity period type, increase the initially noise-added query result according to a preset noise threshold to obtain a noise-added query result.
[0100] In the above solution, each distributed node generates an initial query result. To protect privacy, differential privacy noise is added to the initial query result of each distributed node. Differential privacy noise is a carefully designed random noise, and the amount of addition depends on the requirements of privacy protection and the sensitivity of the data.
[0101] By performing a summation process on the initial query result and the differential privacy noise, a preliminary noise-added query result is obtained.
[0102] For the query result of each distributed node, the system also considers its corresponding time window. The time window refers to the time range covered by the query result.
[0103] Within this time window, the system further determines the data activity period. The data activity period is used to indicate the activity status of the data within a specific time period, such as frequent updates, access, or operations of the data.
[0104] According to the type of the data activity period, the system further adjusts the preliminary noise-added query result.
[0105] If the data activity period belongs to a preset first data activity period type (which may indicate relatively frequent data activities, for example, during high-traffic periods with a large amount of data transmission, or during periods with multiple abnormal behaviors), then reduce the preliminary noise-added query result according to a preset noise threshold. This is done to reduce noise injection when data activities are frequent and improve the accuracy of the detection results.
[0106] If the data activity period belongs to a preset second data activity period type (which may indicate relatively sparse data activities), then increase the preliminary noise-added query result according to a preset noise threshold. This is done to appropriately increase the noise intensity when data activities are sparse to enhance privacy protection.
[0107] In this way, the system can dynamically adjust the amount of noise addition according to the activity status of the data while protecting user privacy, thereby finding a balance between privacy protection and statistical accuracy.
[0108] In some embodiments, in step 103, adding preset differential privacy noise to the summary result to obtain the noise-added summary result includes: Step F1, based on the summary result and the preset differential privacy noise, obtaining the noise-added summary result through the following formula:
[0109] Wherein, represents the noise-added summary result, represents the preset differential privacy noise, represents the query sensitivity, represents the privacy budget of all distributed nodes, represents the summary result, represents the vulnerability detection result corresponding to the distributed node represents the order of the distributed nodes, represents the number of distributed nodes.
[0110] In the above solution, the noise-added summary result is obtained by adding the preset differential privacy noise to the summary result.
[0111] The size and distribution of the noise are determined based on the query sensitivity, the privacy budget, and the specific noise addition mechanism.
[0112] In this way, even if an attacker obtains the noise-added summary result, it is difficult to infer the original data of a single distributed node from it, thereby protecting personal privacy.
[0113] In some embodiments, the present application can perform efficient vulnerability mining in a distributed system while ensuring that data privacy is not leaked. The system consists of multiple computing nodes, each node independently executes the vulnerability detection task, shares the analysis results among the nodes through differential privacy technology, and finally generates a global vulnerability report. The system is applicable to security vulnerability detection scenarios of multi-party collaboration and cross-platform, especially in cases involving important data, and can ensure the security and privacy of the data.
[0114] Figure 2 The present application provides a vulnerability detection method based on differential privacy, which is applied to a vulnerability detection system based on differential privacy. The architecture of the system is as Figure 2As shown, it includes multiple distributed nodes (Distributed Node 1, Distributed Node 2, ……, Distributed Node N) and a system control and summarization module (i.e., the central control node). Each distributed node can perform differential privacy processing and use a vulnerability detection module to detect vulnerabilities, and then send the vulnerability detection results to the system control and summarization module respectively. The system control and summarization module includes a report generation and visualization module, a result summarization and differential privacy protection module, and a security enhancement and repair suggestion module.
[0115] A vulnerability detection method based on differential privacy provided by this application includes the following steps: Step 1: Data preprocessing and differential privacy protection: Before the vulnerability detection starts, the system performs differential privacy processing on the important data of each node. By adding noise to the data, it ensures that attackers cannot infer the original data by analyzing the results.
[0116] The core of the differential privacy algorithm is to control the privacy budget to adjust the noise intensity, ensuring that while guaranteeing the analysis accuracy, it maximally protects data privacy. For the processing of time series data, the system optimizes the dynamic noise distribution strategy and dynamically adjusts the noise intensity according to the importance of time periods. At the same time, the Fourier transform method is used to retain the global time series pattern to ensure that the noise does not affect the key timing characteristics.
[0117] Step 2: Distributed vulnerability mining: After the data undergoes differential privacy processing, the system distributes the data to multiple nodes for distributed computing. Each node independently runs the vulnerability mining algorithm to perform security analysis on the local data and find potential vulnerabilities in the system.
[0118] The vulnerability mining algorithm includes static analysis, dynamic analysis, and comprehensive analysis combining the two, and can detect code structure vulnerabilities, network communication vulnerabilities, and security vulnerabilities that may occur during the dynamic execution process.
[0119] Step 3: Result summarization and differential privacy protection: After each node completes the vulnerability detection, it returns the detection results to the central control module. To prevent privacy leakage caused by cumulative queries during the summarization process, the system adds differential privacy noise again during the result summarization. This mechanism ensures that no matter how many times the query is made, attackers still cannot infer the original data content by setting a global privacy budget, so as to prevent attackers from reverse inferring the specific data of each node by analyzing the summarization results.
[0120] In distributed collaboration, the system allocates differential privacy budgets to nodes based on a trust evaluation model. Nodes with a higher trust level are allocated less noise to improve the result accuracy, and nodes with a lower trust level increase the noise to enhance privacy protection.
[0121] Combined with edge computing technology, each edge node completes differential privacy protection processing locally and only shares the protected analysis results.
[0122] The aggregated detection results include the types of vulnerabilities existing in the system, the severity levels, the occurrence locations, and the relevant security risk assessments.
[0123] Step 4: Generation of vulnerability detection report: The aggregated detection results are used to generate a global vulnerability detection report. The system further evaluates the accuracy of the detection data based on the noise amplitude in the detection results, and quantifies the risks of the vulnerabilities involved in the report to ensure that effective risk assessments can still be provided under the premise of privacy protection. The report includes the following contents: The types of detected vulnerabilities (such as buffer overflow, unauthorized access, SQL injection, etc.).
[0124] The severity assessment of each vulnerability (such as high risk, medium risk, low risk).
[0125] The occurrence locations of the vulnerabilities and their related system components.
[0126] Analysis of the potential risks that the vulnerabilities may bring.
[0127] Step 5: Security enhancement and repair suggestions: Based on the vulnerability detection report, the system conducts an automated risk assessment and generates corresponding security enhancement suggestions. The suggestions include repair solutions, vulnerability patching methods, and specific code modification examples.
[0128] System administrators can quickly repair the vulnerabilities according to the report and suggestions to improve the security of the system.
[0129] Step 6: System communication and collaboration: The system connects distributed edge nodes through a secure communication channel. While ensuring communication security, it protects the intermediate results through differential privacy to ensure the data privacy during the node collaboration process.
[0130] System architecture: 1. Data preprocessing module: Responsible for preprocessing the original data, adding a differential privacy protection mechanism to ensure that important information of users will not be leaked during the data analysis and vulnerability detection processes.
[0131] Randomize the input data using differential privacy techniques (such as the Laplace noise mechanism or the exponential mechanism). During the processing, control the intensity of the noise according to the set privacy budget ( ) to ensure data security without significantly affecting the accuracy of vulnerability detection.
[0132] Introduce a time - series optimization mechanism, dynamically allocate differential privacy budgets according to time periods, combine Fourier transform to retain key time - series patterns, and prevent noise from affecting the global trend of data.
[0133] Introduce a dynamic optimization mechanism for differential privacy algorithms. According to data types and uses, select the optimal privacy budget and noise distribution method. For example, for time - series data, use a dynamic noise distribution strategy.
[0134] Distribute the data processed by differential privacy to different distributed nodes, and each node independently executes the vulnerability detection task.
[0135] The data distribution adopts a weighted random allocation strategy. High - risk data is preferentially allocated to high - performance nodes for pre - processing; less important data is allocated to edge nodes to reduce the load on the main nodes.
[0136] 2. Distributed Vulnerability Detection Module: Parallelly execute vulnerability detection tasks on multiple distributed nodes, mainly performing security analysis on the local data of different nodes or systems. Static analysis is used to detect code - structure problems such as buffer overflows and Structured Query Language (SQL) injections; dynamic analysis identifies runtime vulnerabilities that depend on user input by simulating running behaviors.
[0137] Utilize edge - computing technology to perform local analysis and privacy protection on data at nodes close to the data source, reducing the privacy risk of data transmission. In node collaborative analysis, allocate differential privacy budgets according to the trust model to improve cross - platform collaboration efficiency. After local data pre - processing using edge - computing technology, share the results of differential privacy processing to reduce the privacy leakage risk brought by data transmission between nodes.
[0138] Ensure that different nodes can share vulnerability detection information through the differential privacy mechanism without revealing specific data content. Collaboration between nodes can better cover vulnerabilities across platforms and systems.
[0139] 3. Result Summarization and Report Generation Module: Summarize the vulnerability detection results independently completed by each distributed node and generate a global vulnerability detection report.
[0140] To prevent attackers from reverse - inferring the specific data of nodes through the summarized results, continue to use the differential privacy mechanism to add noise protection during the summarization process. Even if an attacker obtains the summarized results, they cannot restore the original data through reverse analysis.
[0141] The summarized vulnerability detection information includes the following: The detected vulnerability types and their occurrence locations.
[0142] The risk level assessment of vulnerabilities is divided into three levels: low, medium, and high.
[0143] The system threats and potential attack paths that vulnerabilities may cause.
[0144] Repair suggestions and security enhancement solutions.
[0145] The vulnerability detection reports generated by the system are presented to the system administrator in a visual way to help the operators more intuitively understand the vulnerability distribution and security status in the system.
[0146] When summarizing the detection results of each node, the system injects global noise into the cumulative query results to avoid privacy leakage caused by multiple queries and protect the privacy of the final summary results at the same time.
[0147] 4. Security Enhancement Module: Based on the vulnerability detection report, the system automatically generates risk assessments and security enhancement suggestions to help the administrator quickly repair vulnerabilities and improve system security.
[0148] According to the detected vulnerability types and risk levels, the system provides automated repair suggestions. For example: For SQL injection problems, it is recommended to use parameterized queries or an Object-Relational Mapping (ORM) framework. For buffer overflow problems, it is recommended to use secure string manipulation functions.
[0149] The system can be integrated with automated repair tools to directly mark repair suggestions at the code locations where vulnerabilities are detected and generate a change report for code review.
[0150] 5. Differential Privacy Mechanism: The differential privacy mechanism runs through all stages of the system to ensure the privacy protection of important data during the entire vulnerability detection process.
[0151] Privacy Budget Control: By setting the privacy budget ε, the system can adjust the intensity of the noise according to needs. A lower privacy budget value means stronger privacy protection, but may sacrifice some data accuracy. A higher privacy budget allows for more accurate vulnerability detection, but the privacy protection intensity is relatively weaker.
[0152] The system limits the privacy consumption in multiple query scenarios by dynamically adjusting the privacy budget ( ). For example, setting the maximum budget allocation limit for each query to ensure that the total privacy budget is not exhausted.
[0153] During the vulnerability detection process executed at each node, random noise is injected into the intermediate results of the output to prevent attackers from inferring the original data through the output of a single node.
[0154] The differential privacy mechanism automatically adjusts the noise during multiple data queries to prevent attackers from inferring important data content through multiple analyses. The system dynamically adjusts the noise level according to the privacy budget consumed by each query to maintain the effectiveness of overall privacy protection.
[0155] For various data types (such as time series data, user behavior logs, etc.), an adaptive sensitivity calculation method is used. The sensitivity calculation for dynamic analysis is based on the maximum change amplitude of system calls or behavior patterns.
[0156] 6. System Communication and Collaboration: In a distributed system, each node needs to exchange data through a secure communication channel. During the communication process, differential privacy technology can prevent data leakage between nodes. Even if the communication channel is attacked, the important data of the nodes cannot be recovered.
[0157] The system ensures that the intermediate results of vulnerability detection can be shared between different nodes through the differential privacy mechanism, and collaboratively analyzes cross-system vulnerabilities without revealing important information.
[0158] Implementation Steps: (1) Differential Privacy Algorithm Design: By introducing noise, ensure the privacy of each data point is protected. For time series data (such as network logs, call traces), adopt the time window partitioning method to dynamically adjust the noise intensity and ensure the data accuracy during high-activity periods. Specifically, differential privacy ensures that the query results on two adjacent data sets are difficult to distinguish by adding noise to the query results. The most commonly used noise distribution mechanisms are the Laplace mechanism and the Gaussian mechanism. The Laplace mechanism adds noise to the query results, and its distribution is:
[0159] where, is the global sensitivity of the query, is the privacy budget.
[0160] The Gaussian mechanism uses normally distributed noise and is applicable to scenarios that satisfy ( , ) differential privacy:
[0161] where, : the standard deviation of the noise, related to the query sensitivity and the privacy budget, and the formula is:
[0162] This protection mechanism is particularly important for vulnerability mining scenarios because important data (such as user identities, browsing records, etc.) may be accessed during the vulnerability detection process.
[0163] (2) Definition of differential privacy: By adding noise to the query results, it provides a mathematical definition of privacy protection. For a query , given adjacent data sets and (which differ by only one data point), differential privacy requires the following formula to hold:
[0164] is the privacy budget, which controls the trade-off between privacy and accuracy. A smaller provides stronger privacy protection but may sacrifice the accuracy of the query results.
[0165] is the probabilistic failure term, usually set to a very small value to ensure that privacy protection is effective in most cases.
[0166] is an arbitrary subset of the query results, representing the possible results that the query may return.
[0167] (3) Optimization of time series data processing: The system first identifies the type of input data. If it is time series data (such as network traffic logs, call traces, etc.), the system uses the time window partitioning method to process the data in segments.
[0168] For the data within each time window, the noise intensity is dynamically adjusted: During high data activity periods (such as high traffic, abnormal behavior prone periods), the noise injection is reduced to improve the accuracy of the detection results.
[0169] During low data activity periods, the noise intensity is increased to enhance privacy protection.
[0170] Using Fourier transform or wavelet analysis techniques, the trends and periodic patterns of the time series are retained to ensure that the noise does not destroy the global time series characteristics.
[0171] Fourier transform formula:
[0172] is used to extract the frequency characteristics of the time series.
[0173] (4) Privacy budget allocation based on trust level: For the multi-party collaboration scenario, the system allocates different privacy budgets according to the trust levels of the participants ( ) High trust level: Reduce the noise intensity and enhance the analysis value of the data.
[0174] Medium trust level: Maintain the conventional noise intensity and balance privacy and data usability.
[0175] Low trust level: Increase the noise intensity and strengthen data protection.
[0176] Dynamic allocation formula:
[0177] Where: : The privacy budget of node . : The trust weight of the node. High-trust nodes have a larger weight.
[0178] (5) Edge node localization processing: In a distributed environment, edge nodes close to the data source perform differential privacy preprocessing. This step processes important data locally to reduce the privacy risks that the data may face during transmission.
[0179] Application process of differential privacy in vulnerability mining: Step 1: Data preprocessing: On each distributed node, first query the local dataset . For example, the query can be "the number of abnormal function calls triggered by users" or "the occurrence frequency of a certain type of access behavior".
[0180] Step 2: Calculate the query sensitivity: Calculate the sensitivity of the query , such as the maximum possible change in the frequency of a certain function call on adjacent datasets.
[0181]
[0182] Step 3: Add differential privacy noise: Use the Laplace mechanism to add noise to the query result . The noise is generated according to the sensitivity of the query and the set privacy budget. Calculate the sensitivity of the query , that is, the maximum possible change in the query result on adjacent datasets. For example, in vulnerability mining, it may be to analyze the frequency of calls to a specific module. The query sensitivity is the maximum change in the call frequency when adding or removing a user's data. Set the privacy budget according to the system requirements. A smaller It means stronger privacy protection, but the accuracy of query results may decrease. For each query result, the node performs the following operations:
[0183] Where: is the query result of the data set is the global sensitivity of the query indicating the maximum change in the query result on adjacent data sets:
[0184] is the privacy budget.
[0185] is the noise term of the Laplace distribution with a scale parameter of
[0186] Step 4: Distributed vulnerability mining: Divide the distributed node tasks by functional modules or regions, such as "Module A is responsible for network request log analysis" and "Module B is responsible for system call log analysis" to optimize the computing load. Each node executes the vulnerability detection algorithm by querying the local data. The differential privacy mechanism ensures that the query results of each node on the local data do not disclose important information, and even if the detection results are accessed by other nodes, the true values of any single data point will not be exposed.
[0187] Step 5: Result aggregation: Each node aggregates the processed query results (i.e., the vulnerability detection results with noise) to the central control node. Differential privacy guarantees the privacy security of the data of each node. The central control node aggregates the results of each node and injects noise into the aggregated data again to protect privacy:
[0188] Noise is added again during aggregation to ensure that attackers cannot infer the information of any single data point from multiple results.
[0189] In addition, the data flow of vulnerability detection is as Figure 3 As shown, each distributed node (distributed node 1, distributed node 2, …, distributed node N) performs differential privacy processing and uses a vulnerability detection module to detect vulnerabilities, and then sends the vulnerability detection results to the system control and aggregation module (i.e., the local detection results are sent to the system control module for aggregation). The result aggregation and differential privacy protection module in the system control and aggregation module is used for data aggregation and differential privacy noise processing, and noise injection is performed during the data processing and differential privacy process, so that the aggregation result obtained by the system control and aggregation module by aggregating each local detection result is added with noise again to ensure that attackers cannot infer the information of any single data point through multiple results.
[0190] The process of adding noise to the differential privacy algorithm is as Figure 4 shown, including a data preprocessing stage, calculating the sensitivity of the query, selecting the noise distribution (Laplace mechanism), and adding noise to the query result.
[0191] Among them, in the data preprocessing stage: the system receives a query request and extracts the relevant data set ; calculating the sensitivity of the query: calculating the maximum change amount of the query on the data set to determine the sensitivity ; selecting the noise distribution (Laplace mechanism): according to the sensitivity and the privacy budget calculate the noise intensity; adding noise to the query result: adding the calculated noise value to the query result to generate a noisy output and returning the noisy query result .
[0192] It should be noted that the method of the embodiment of the present application can be executed by a single device, such as a computer or a server, etc. The method of this embodiment can also be applied to a distributed scenario and completed by multiple devices cooperating with each other. In this case of a distributed scenario, one of these multiple devices can only execute one or more steps of the method of the embodiment of the present application, and these multiple devices will interact with each other to complete the described method.
[0193] It should be noted that some embodiments of the present application have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order than in the above embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the specific order or continuous order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0194] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present application further provides a vulnerability detection device based on differential privacy.
[0195] Reference Figure 5 , for the vulnerability detection device based on differential privacy, the device is disposed in a vulnerability detection system based on differential privacy, the system includes a central control node and a plurality of distributed nodes, each distributed node is used to process different types of user behavior data, and the device includes: A query module 501, configured to query user behavior data corresponding to a target user from each distributed node according to a preset query task corresponding to each distributed node, and determine an initial query result of the corresponding query task according to each user behavior data; A vulnerability detection module 502, configured to perform the following operations for each distributed node: obtain a trust level corresponding to the distributed node, and allocate a privacy budget for the distributed node by using the trust level corresponding to the distributed node; determine a query sensitivity corresponding to the query task of the distributed node, determine a differential privacy noise based on a noise distribution mechanism according to the privacy budget and the query sensitivity, and add the differential privacy noise to the initial query result corresponding to the distributed node to obtain a query result after noise addition; in response to the query result after noise addition not being within the range of a preset query result threshold, determine that the vulnerability detection result corresponding to the distributed node is that there is a security vulnerability, and send the vulnerability detection result corresponding to the distributed node to the central control node; or, in response to the query result after noise addition being within the range of the preset query result threshold, determine that the vulnerability detection result corresponding to the distributed node is that there is no security vulnerability, and send the vulnerability detection result corresponding to the distributed node to the central control node; A summarization module 503, configured to summarize the vulnerability detection results corresponding to each distributed node through the central control node to obtain a summary result, add a preset differential privacy noise to the summary result to obtain a summary result after noise addition, and generate a vulnerability detection report based on the summary result after noise addition for vulnerability repair according to the vulnerability detection report.
[0196] For the convenience of description, when describing the above device, it is divided into various modules according to functions and described separately. Of course, when implementing the present application, the functions of each module can be implemented in the same or multiple software and / or hardware.
[0197] The device of the above embodiment is used to implement the corresponding vulnerability detection method based on differential privacy in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0198] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present application further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the method for detecting vulnerabilities based on differential privacy described in any of the above embodiments is implemented.
[0199] Figure 6 FIG. shows a more specific schematic diagram of the hardware structure of the electronic device provided in this embodiment. The device may include: a processor 601, a memory 602, an input / output interface 603, a communication interface 604, and a bus 605. Among them, the processor 601, the memory 602, the input / output interface 603, and the communication interface 604 are communicatively connected to each other inside the device through the bus 605.
[0200] The processor 601 may be implemented in a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.
[0201] The memory 602 may be implemented in the form of a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 602 may store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 602 and are called and executed by the processor 601.
[0202] The input / output interface 603 is used to connect to an input / output module to implement information input and output. The input / output module may be configured as a component in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Among them, the input device may include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device may include a display, a speaker, a vibrator, an indicator light, etc.
[0203] The communication interface 604 is used to connect to a communication module (not shown in the figure) to implement communication interaction between this device and other devices. Among them, the communication module may implement communication in a wired manner (such as USB, network cable, etc.) or in a wireless manner (such as mobile network, WIFI, Bluetooth, etc.).
[0204] The bus 605 includes a path for transmitting information between various components of the device, such as the processor 601, the memory 602, the input / output interface 603, and the communication interface 604.
[0205] It should be noted that although only the processor 601, the memory 602, the input / output interface 603, the communication interface 604, and the bus 605 are shown in the above device, in the specific implementation process, the device may also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device may also only include the components necessary to implement the solution of the embodiments of this specification, and do not necessarily include all the components shown in the figure.
[0206] The electronic device of the above embodiment is used to implement the corresponding differential privacy-based vulnerability detection method in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated here.
[0207] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present application also provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to execute the differential privacy-based vulnerability detection method as described in any of the foregoing embodiments.
[0208] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.
[0209] The computer instructions stored in the storage medium of the above embodiment are used to cause the computer to execute the differential privacy-based vulnerability detection method as described in any of the foregoing embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be elaborated here.
[0210] Those of ordinary skill in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of the present application is limited to these examples; under the concept of the present application, the technical features in the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations in different aspects of the embodiments of the present application as described above, and for the sake of brevity, they are not provided in detail.
[0211] In addition, for simplicity of explanation and discussion, and in order not to make the embodiments of the present application difficult to understand, the well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Further, the devices may be shown in block diagram form in order to avoid making the embodiments of the present application difficult to understand, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform on which the embodiments of the present application are to be implemented (i.e., these details should be fully within the understanding of those skilled in the art). In cases where specific details (such as circuits) are set forth to describe exemplary embodiments of the present application, it will be apparent to those skilled in the art that the embodiments of the present application may be implemented without these specific details or with variations of these specific details. Therefore, these descriptions should be considered illustrative rather than restrictive.
[0212] Although the present application has been described in connection with specific embodiments of the present application, many alternatives, modifications, and variations of these embodiments will be apparent to those of ordinary skill in the art based on the foregoing description. For example, other memory architectures (such as dynamic RAM (DRAM)) may be used with the embodiments discussed.
[0213] The embodiments of the present application are intended to cover all such alternatives, modifications, and variations that fall within the broad scope of the present application. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of the embodiments of the present application shall be included within the protection scope of the present application.
Claims
1. A vulnerability detection method based on differential privacy, characterized in that: Applied to a vulnerability detection system based on differential privacy, the system includes a central control node and multiple distributed nodes, each distributed node is used to process different types of user behavior data, and the method includes: Querying user behavior data corresponding to the target user from each distributed node according to the preset query task corresponding to each distributed node, and determining the initial query result of the corresponding query task according to each user behavior data; The following operations are performed for each distributed node: the trust level corresponding to the distributed node is obtained, and the privacy budget of the distributed node is allocated using the trust level corresponding to the distributed node; the query sensitivity corresponding to the query task of the distributed node is determined, the differential privacy noise is determined based on the noise distribution mechanism according to the privacy budget and the query sensitivity, and the differential privacy noise is added to the initial query result corresponding to the distributed node to obtain the query result after the noise is added; in response to the query result after the noise is added not being within the range of the preset query result threshold, the vulnerability detection result corresponding to the distributed node is determined to be the existence of a security vulnerability, and the vulnerability detection result corresponding to the distributed node is sent to the central control node; or, in response to the query result after the noise is added being within the range of the preset query result threshold, the vulnerability detection result corresponding to the distributed node is determined to be the absence of a security vulnerability, and the vulnerability detection result corresponding to the distributed node is sent to the central control node; The vulnerability detection results corresponding to each distributed node are summarized through the central control node to obtain a summary result, and preset differential privacy noise is added to the summary result to obtain a summary result with noise added, and a vulnerability detection report is generated based on the summary result with noise added, so that the vulnerability can be repaired according to the vulnerability detection report.
2. The method according to claim 1, characterized in that The allocating the privacy budget of the distributed nodes by using the trust level corresponding to the distributed nodes includes: Obtain the privacy budget of all distributed nodes; Based on the privacy budget of all distributed nodes and the weight of the trust level corresponding to the distributed node, the privacy budget of the distributed node is determined by the following formula: in, Represents a distributed node privacy budget, Represents a distributed node The weight of the trust level, Represents the privacy budget of all distributed nodes.
3. The method according to claim 1, characterized in that The determining of the query sensitivity corresponding to the query task of the distributed node includes: Obtaining an initial query result corresponding to a first user behavior data set in a current time window, and an initial query result corresponding to a second user behavior data set in a time window adjacent to the current time window; Based on the initial query result corresponding to the first user behavior dataset and the initial query result corresponding to the second user behavior dataset, the query sensitivity is determined by the following formula: in, Indicates the query sensitivity, Represents the first user behavior dataset The corresponding initial query results, Represents the second user behavior dataset The corresponding initial query results.
4. The method according to claim 1, characterized in that: The noise distribution mechanism includes a Laplace mechanism; The step of determining the differential privacy noise based on the noise distribution mechanism according to the privacy budget and the query sensitivity includes: The query sensitivity and privacy budget are ratioed to obtain the scale parameter: The scale parameter is processed using the probability density function of the Laplace distribution to obtain differential privacy noise.
5. The method according to claim 1, characterized in that The noise distribution mechanism includes a Gaussian mechanism; The step of determining the differential privacy noise based on the noise distribution mechanism according to the privacy budget and the query sensitivity includes: The variance of the probability density function of the Gaussian distribution is determined, and based on the variance of the probability density function of the Gaussian distribution, the query sensitivity, and the privacy budget, the noise standard deviation is determined by the following formula: in, represents the noise standard deviation, Indicates the query sensitivity, represents the privacy budget, represents the variance of the probability density function of the Gaussian distribution; The noise standard deviation is processed using the probability density function of the Gaussian distribution to obtain differential privacy noise.
6. The method according to claim 1, characterized in that The adding of differential privacy noise to the initial query result corresponding to the distributed node to obtain the query result after the noise is added includes: Based on the summation of the initial query results corresponding to the distributed nodes and the differential privacy noise, the initial query results after noise addition are determined: Obtaining a time window of an initial query result corresponding to a distributed node, and determining a data activity period of the time window, wherein the data activity period is used to indicate an activity status of data within a specific time period; In response to the data activity period belonging to a preset first data activity period type, the initial noise-added query result is reduced according to a preset noise threshold to obtain the noise-added query result; or, In response to the data activity period belonging to a preset second data activity period type, the initial noise-added query result is increased according to a preset noise threshold to obtain a noise-added query result.
7. The method according to claim 1, characterized in that The adding of preset differential privacy noise to the summary result to obtain the summary result after the noise is added includes: Based on the summary result and the preset differential privacy noise, the summary result after noise addition is obtained by the following formula: in, represents the summary result after noise addition, represents the preset differential privacy noise, Indicates the query sensitivity, represents the privacy budget of all distributed nodes, Indicates the summary results, Representation and distributed nodes The corresponding vulnerability detection results, Indicates the order of distributed nodes, Indicates the number of distributed nodes.
8. A vulnerability detection device based on differential privacy, characterized in that: The device is arranged in a vulnerability detection system based on differential privacy, the system comprising a central control node and a plurality of distributed nodes, each distributed node being used to process different types of user behavior data, the device comprising: A query module is configured to query user behavior data corresponding to a target user from each distributed node according to a preset query task corresponding to each distributed node, and determine an initial query result corresponding to the query task according to each user behavior data; The vulnerability detection module is configured to perform the following operations for each distributed node: obtain the trust level corresponding to the distributed node, and allocate the privacy budget of the distributed node using the trust level corresponding to the distributed node; determine the query sensitivity corresponding to the query task of the distributed node, determine the differential privacy noise based on the noise distribution mechanism according to the privacy budget and the query sensitivity, and add the differential privacy noise to the initial query result corresponding to the distributed node to obtain the query result after the noise is added; in response to the query result after the noise is added not being within the range of the preset query result threshold, determine that the vulnerability detection result corresponding to the distributed node is that there is a security vulnerability, and send the vulnerability detection result corresponding to the distributed node to the central control node; or, in response to the query result after the noise is added being within the range of the preset query result threshold, determine that the vulnerability detection result corresponding to the distributed node is that there is no security vulnerability, and send the vulnerability detection result corresponding to the distributed node to the central control node. The aggregation module is configured to aggregate the vulnerability detection results corresponding to each distributed node through a central control node to obtain an aggregation result, add preset differential privacy noise to the aggregation result to obtain an aggregation result with noise added, and generate a vulnerability detection report based on the aggregation result with noise added, so as to perform vulnerability repair according to the vulnerability detection report.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the program, the method according to any one of claims 1 to 7 is implemented.
10. A non-transitory computer-readable storage medium storing computer instructions, characterized in that: The computer instructions are used to enable a computer to execute the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Privacy budget allocating and data publishing method and privacy budget allocating and data publishing system for protecting data query privacy
CN108537055A
Computer-implemented privacy engineering system and method
CN109716345A
Efficiently querying databases while providing differential privacy
US20190156057A1