Cross-domain data security early warning method and system based on privacy calculation
By adopting a privacy-based computing method in cross-domain data collaboration, dynamically update the weights of each participant and weight the aggregation model parameters, the problem of low model warning accuracy caused by the differences in cross-domain data distribution is solved, and higher robustness and early warning accuracy are achieved, while protecting data privacy.
Patent Information
- Application Number
- CN202510653344.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-21
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2045-05-21
AI Technical Summary
In cross-domain data collaboration, due to the significant differences in data distribution among participants, existing methods are difficult to effectively solve the problem of low model warning accuracy, especially in large-scale heterogeneous data scenarios.
A cross-domain data security early warning method based on privacy computing is adopted. By training the local model on the local side and dynamically updating the weights of each participant, a global model update parameter is formed, and weighted aggregation is carried out to improve model adaptability.
It effectively solves the problem of inconsistent cross-domain data distribution, improves the robustness and early warning accuracy of the global model, and avoids the risk of privacy leakage of original data.
Smart Images

Figure CN120180451A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing, and particularly to a cross-domain data security warning method and system based on privacy computing. Background Art
[0002] With the acceleration of digital transformation and the popularization of data-driven decision-making, cross-domain data collaboration has become increasingly common. Cross-domain generally refers to the process of data interaction, resource sharing, or collaboration between different entities, systems, or organizations. These entities may be distributed in different physical locations, network environments, or management boundaries. However, cross-domain data collaboration is also accompanied by potential security risks and privacy leakage problems. Therefore, cross-domain data security warning based on privacy computing has become a necessary means, and its core purpose is to protect sensitive data while timely discovering and preventing potential security threats.
[0003] Federated learning is a machine learning paradigm aimed at jointly training a global model by multiple participating parties (such as devices, institutions, or organizations) without sharing the original data. The core goal of federated learning is to achieve efficient cross-domain collaboration while protecting data privacy. Using federated learning technology, without exposing the original data, through the sharing of model parameters, cross-domain data joint analysis and anomaly detection can be realized.
[0004] In cross-domain data security warning, the data distributions of participating parties are significantly different, and a single model is difficult to adapt to all distributions. Existing methods (such as simple aggregation or data resampling) cannot effectively solve this problem, especially in large-scale heterogeneous data scenarios. Summary of the Invention
[0005] To solve the technical problem of low model warning accuracy caused by the different data distributions of each participating party, this application provides a cross-domain data security warning method and system based on privacy computing.
[0006] In a first aspect, the present application provides a cross-domain data security warning method based on privacy computing, adopting the following technical solutions: training a local model based on local data at the local end to obtain model parameters; aggregating the model parameters and initial weights of each local model at the central server, calculating the model update parameters of the global model, and transmitting the model update parameters to each local model for the next round of model iterative training and dynamically updating the weights of each participating party; inputting new local data into the trained local model, outputting the risk value of the local data, and performing data security warning based on the risk value; the weight update method is as follows: calculating the difference score of the local data of each participating party at the client side; calculating the distribution difference of the model data between the participating parties at the central server; taking the mean of the data distribution differences between any participating party and other participating parties as the average similarity; receiving the difference score at the central server, taking the ratio of the data difference score of the participating party to the average similarity as the weight update parameter, and taking the product of the weight update parameter and the weight of the previous iteration as the updated weight.
[0007] The beneficial effects are as follows: aggregating the local model parameters of each participating party into global model update parameters can make full use of the training results of each participating party, while avoiding the risk of privacy leakage caused by directly sharing the original data. By dynamically adjusting the weights of each participating party, the global model can better adapt to local models with different data distributions. The combination of the difference score and the average similarity can comprehensively reflect the data quality of the participating party and the data distribution difference from other participating parties, so as to allocate weights more reasonably. This method effectively solves the problem of inconsistent cross-domain data distribution, and improves the robustness and warning accuracy of the global model.
[0008] Optionally, the calculation method of the difference score is as follows: calculating the first accuracy rate of the local data of the participating party in the local model, and calculating the second accuracy rate of the local data of the participating party in the global model; normalizing the absolute difference between the first accuracy rate and the second accuracy rate as the difference score of the local data of the participating party.
[0009] The beneficial effects are as follows: by comparing the accuracy rate differences between the local model and the global model on the local data of the participating party, the quality of the local data of the participating party can be quantified. A high first accuracy rate indicates that the local model performs well in processing local data. If the second accuracy rate is low, it means that the global model fails to adapt well to the local data distribution of this participating party, and the data distribution of this participating party is quite different from that of other participating parties. At this time, a higher weight needs to be assigned to this participating party to enhance the adaptability of the global model to this data distribution.
[0010] Optionally, the calculation formula for the distribution difference is: ; represents the participating party and the participating party of the model data distribution difference, The information entropy of the data of the participating party on the -th dimensional feature, The information entropy of the data of the participating party on the -th dimensional feature, represents the total number of feature dimensions, represents the normalization function.
[0011] The beneficial effect is that it is applicable to the case where the total number of feature dimensions of two participating parties is the same. By calculating the absolute difference of the information entropy on the feature dimensions between the participating parties and performing standardization processing on it, the distribution difference between the two sets of data in the feature space can be accurately reflected. This calculation method is simple and efficient and is applicable to the evaluation of distribution differences in large-scale heterogeneous data scenarios.
[0012] Optionally, ; represents the distribution difference of the model data between the participating party and the participating party , The information entropy of the data of the participating party on the -th dimensional feature, The information entropy of the data of the participating party on the -th dimensional feature, represents the total number of feature dimensions of the participating party , represents the total number of feature dimensions of the participating party , represents the normalization function, represents the maximum value function, represents the minimum value function The beneficial effect is that it is applicable to the case where the total number of feature dimensions of two participating parties is different. By comprehensively considering the information entropy difference and dimension difference between the two participating parties, the distribution difference can be evaluated more comprehensively.
[0013] Optionally, the calculation method of the information entropy is as follows: calculate the number of occurrences of any feature of the participating party in any dimension, and use the ratio of the number of occurrences to the total number of samples of the participating party in that dimension as the probability; calculate the product of the negative value of the natural logarithm of the probability and the probability, and use the sum of all products as the information entropy.
[0014] The beneficial effect is that the method of calculating the information entropy by counting the number of occurrences of features has the advantages of simplicity, intuitiveness, high efficiency, accuracy, and strong adaptability.
[0015] Optionally, the normalization method is standard normalization or maximum-minimum normalization.
[0016] The beneficial effects are as follows: The normalization process eliminates the influence caused by differences in data scale or feature distribution among different participating parties, ensuring the fairness and consistency of the weight update process.
[0017] Optionally, the expression for the model update parameter is: ; where represents the model update parameter, represents the local model parameter of the participating party , represents the weight of the participating party , represents the total number of participating parties.
[0018] The beneficial effects are as follows: The introduction of weights enables the global model to better adapt to the characteristics of different data distributions, improving the overall performance.
[0019] Optionally, the loss function for model training is the mean squared error loss function.
[0020] Optionally, the model parameters include the weight matrix and bias vector of each layer.
[0021] In a second aspect, the present application provides a cross-domain data security warning system based on privacy computing, adopting the following technical solutions: A cross-domain data security warning system based on privacy computing, comprising: a processor and a memory, the memory stores computer program instructions, and when the computer program instructions are executed by the processor, the cross-domain data security warning method based on privacy computing as described above is implemented.
[0022] Generate a computer program for the cross-domain data security warning method based on privacy computing as described above, and store it in the memory to be loaded and executed by the processor. Thus, a system is made according to the memory and the processor, which is convenient to use.
[0023] The present application has the following technical effects: The local model parameters of each participating party are weighted and aggregated into global model update parameters, and the global model then passes the model parameters back to the local model to adjust the local model, making full use of the training results of each participating party while avoiding the risk of privacy leakage caused by directly sharing the original local data.
[0024] By dynamically adjusting the weights of each participating party, the global model can better adapt to the local models with different data distributions. The combination of the difference score and the average similarity can comprehensively reflect the data quality of the participating party and the data distribution difference from other participating parties, thereby more reasonably allocating weights. This method effectively solves the problem of inconsistent cross-domain data distributions and improves the robustness and warning accuracy of the global model. Description of the Drawings
[0025] Figure 1 It is a flowchart of a cross - domain data security warning method based on privacy computing in an embodiment of the present application.
[0026] Figure 2 It is a flowchart of step S2 in a cross - domain data security warning method based on privacy computing in an embodiment of the present application. Detailed implementation manner
[0027] An embodiment of the present application discloses a cross - domain data security warning method based on privacy computing. Referring to Figure 1 , it includes steps S1 - S3, specifically as follows: S1: Train a local model according to local data at the local end to obtain model parameters.
[0028] Each participant (such as different enterprises or institutions) independently trains a local model using its local data. Since the data distributions of each participant may be different, the local models will learn different patterns. During the training process, only local data is used to ensure that privacy is not leaked.
[0029] Exemplarily, assume there are two banks, Bank A and Bank B, which have respectively collected the savings behaviors of users. Bank A mainly faces more high - net - worth customers, and Bank B mainly faces more medium - and low - net - worth customers. By jointly building a model, the accuracy of savings prediction can be improved, while ensuring that user data privacy is not leaked, and data security warnings can be made according to the risk values of local data to prevent possible abnormal behaviors.
[0030] S2: Aggregate the model parameters and initial weights of each local model at the central server, calculate the model update parameters of the global model, and transmit the model update parameters to each local model for the next round of model iterative training and dynamically update the weights of each participant.
[0031] Referring to Figure 2 , the weight update method includes steps S20 - S22, specifically as follows: S20: Calculate the difference scores of the local data of each participant at the client side.
[0032] The calculation method of the difference score is: calculate the first accuracy of the local data of the participant in the local model, calculate the second accuracy of the local data of the participant in the global model; normalize the absolute difference between the first accuracy and the second accuracy according to a normalization function as the difference score of the local data of the participant.
[0033] By comparing the accuracy differences between the local model and the global model on the local data of the participating parties, the quality of the local data of the participating parties can be quantified. A high first accuracy indicates that the local model performs well in processing local data. If the second accuracy is low, it means that the global model fails to adapt well to the local data distribution of this participating party, and the data distribution of this participating party is quite different from that of other participating parties. At this time, a higher weight needs to be assigned to this participating party to enhance the adaptability of the global model to this data distribution.
[0034] S21: Calculate the distribution difference of the model data among the participating parties at the central server; take the mean of the data distribution differences between any participating party and other participating parties as the average similarity.
[0035] When the total number of data dimensions of two participating parties is the same, the calculation formula for the distribution difference is: ; represents the participating party and the participating party of the model data distribution difference, represents the participating party of the data in the th - dimensional feature of the information entropy, represents the participating party of the data in the th - dimensional feature of the information entropy, represents the total number of feature dimensions, represents the normalization function.
[0036] The information entropy reflects the data richness of the local data. When the difference in data richness between two participating parties is smaller, it indicates a higher similarity in data distribution between the two participating parties, and at this time the distribution difference is smaller.
[0037] Multi - dimensional means describing data from the perspectives of multiple features or attributes. In the bank savings scenario, multi - dimensional can include account balance, transaction frequency, transaction amount distribution, geographical information, credit score, etc.
[0038] The calculation method of information entropy can be: calculate the occurrence times of any feature of the participating party in any dimension, take the ratio of the occurrence times to the total number of samples of the participating party in this dimension as the probability; calculate the product of the negative value of the natural logarithm of the probability and the probability, and take the sum of all products as the information entropy.
[0039] When the total number of data dimensions of two participating parties is different, the calculation formula for the distribution difference is: ; represents the participating party and the participating party of the model data distribution difference, Indicates the participating party The information entropy of the data of on the Indicates the participating party The information entropy of the data of on the Indicates the participating party The total number of feature dimensions of Indicates the participating party The total number of feature dimensions of Indicates the normalization function Indicates the maximum value function Indicates the minimum value function
[0040] The closer it is to 1, the higher the similarity of the total data dimensions of the two participating parties. Conversely, the lower the similarity of the total data dimensions of the two participating parties. Considering the information entropy difference and dimension difference of the two participating parties comprehensively can evaluate the distribution difference more comprehensively
[0041] The normalization function in this application is standard normalization or maximum-minimum normalization, which will not be elaborated in the prior art
[0042] Calculate the model update parameters of the global model, transmit the model update parameters to each local model for the next round of model iterative training, and dynamically update the weights of each participating party. Perform a weighted sum of the local model parameters of each participating party to generate the update parameters of the global model
[0043] The expression of the model update parameter is ; where Indicates the parameters of the global model Indicates the participating party The local model parameters of Indicates the participating party The weight of Indicates the total number of participating parties is not a fixed value and is calculated by a dynamic adjustment method
[0044] S22: Receive the difference score at the central server, use the ratio of the data difference score of the participating party to the average similarity as the weight update parameter, and use the product of the weight update parameter and the weight of the previous iteration as the updated weight
[0045] The model parameters and initial weights of each local model are aggregated at the central server. The model parameters include the weight matrix and bias vector of each layer. For example, in a fully connected layer, the weight matrix determines the relationship between the input features and the output features, while the bias vector provides additional adjustment capabilities. The central server calculates the global model parameters and sends them back to each local model for the next round of iterative training. This process does not involve the transmission of local data, but only the transmission of model parameters, in order to protect local data and reduce the risk of leakage.
[0046] In one embodiment, all initial weights are set to 0.5. The initial model parameters can be set using the Kaiming initialization method, which will not be elaborated in the prior art.
[0047] The model can use the BP (Backpropagation) model, or select a neural network model in the prior art that is applicable to this application. The loss function for model training is the mean squared error loss function. The model and model training are prior art and will not be elaborated here.
[0048] S3: Input the new local data into the trained local model, output the risk value of the local data, and perform data security warning based on the risk value.
[0049] Two companies train local models on their respective local data. After the model training is completed, Bank A and Bank B input the new local data into the trained local models and output the risk values of each user's savings behavior.
[0050] The labels for the local data are low risk, medium risk, and high risk. The risk value output by the model is a vector composed of three probability values. The probability values are numbers between 0 and 1. The three probability values respectively represent the probability of low risk, medium risk, and high risk of the risk value. Select the label with the highest probability value as the risk detection result of the data at this time.
[0051] For example, Bank A discovers that there are frequent small transfers in the accounts of some high-net-worth customers, which may be abnormal fund flows. Bank B discovers that there are large inflows and outflows in the accounts of some medium and low-net-worth customers, which may be signals of abnormal transfer behaviors. For example, a high-net-worth customer has recently transferred funds to multiple unfamiliar accounts frequently, and the amount of each transfer is close to the regulatory limit. The risk value output by the model is high risk, triggering a high-risk alarm. Bank A immediately freezes the account and notifies the relevant departments for investigation.
[0052] The embodiment of the present application also discloses a cross-domain data security warning system based on privacy computing, including a processor and a memory. The memory stores computer program instructions, and when the computer program instructions are executed by the processor, a cross-domain data security warning method based on privacy computing according to the present application is implemented.
[0053] The above system further includes other components well-known to those skilled in the art, such as a communication bus and a communication interface. Their settings and functions are known in the art, so they will not be described herein again.
[0054] In this application, the aforementioned memory can be any tangible medium that contains or stores a program, and this program can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, a computer-readable storage medium can be any suitable magnetic storage medium or magneto-optical storage medium, such as a resistive random access memory, a dynamic random access memory, a static random access memory, and so on, or any other medium that can be used to store the required information and can be accessed by an application program, a module, or both. Any such computer storage medium can be part of the device or accessible or connectable to the device.
[0055] The above are all preferred embodiments of this application. The protection scope of this application is not limited thereby. Therefore, any equivalent changes made according to the structure, shape, and principle of this application shall be covered within the protection scope of this application.
Claims
1. A cross-domain data security early warning method based on privacy computing, characterized in that: The method comprises the following steps: training a local model based on local data at the local end to obtain model parameters; aggregating the model parameters and initial weights of each local model at the central server end, calculating the model update parameters of the global model, transmitting the model update parameters to each local model for the next round of model iteration training and dynamically updating the weights of each participant; Input new local data into the trained local model, output the risk value of the local data, and issue data security warnings based on the risk value; The weight updating method is as follows: the difference score of each participant's local data is calculated on the client; the distribution difference of the model data between the participants is calculated on the central server; the mean of the data distribution difference between any participant and other participants is taken as the average similarity; the difference score is received on the central server, and the ratio of the participant's data difference score to the average similarity is taken as the weight updating parameter, and the product of the weight updating parameter and the weight of the previous iteration is taken as the updated weight.
2. According to claim 1, the cross-domain data security early warning method based on privacy computing is characterized in that: The calculation method of the difference score is: calculate the first accuracy of the local data of the participant in the local model, and calculate the second accuracy of the local data of the participant in the global model; the absolute difference between the first accuracy and the second accuracy is normalized according to the normalization function as the difference score of the local data of the participant.
3. According to claim 1, the cross-domain data security early warning method based on privacy computing is characterized in that: The distribution difference is calculated as: ; Indicates the participants With the participants The difference in model data distribution, Indicates the participants The data in Information entropy on dimensional features, Indicates the participants The data in Information entropy on dimensional features, represents the total number of feature dimensions, Represents the normalization function.
4. The cross-domain data security early warning method based on privacy computing according to claim 1 is characterized in that: ; Indicates the participants With the participants The difference in model data distribution, Indicates the participants The data in Information entropy on dimensional features, Indicates the participants The data in Information entropy on dimensional features, Indicates the participants The total number of feature dimensions, Indicates the participants The total number of feature dimensions, represents the normalization function, represents the maximum value function, Represents the minimum function.
5. The cross-domain data security early warning method based on privacy computing according to claim 3 or 4 is characterized in that: The calculation method of information entropy is: calculate the number of occurrences of any feature of the participant on any dimension, and take the ratio of the number of occurrences to the total number of samples of the participant on that dimension as the probability; Calculate the product of the negative value of the natural logarithm of the probability and the probability, and take the sum of all products as the information entropy.
6. The cross-domain data security early warning method based on privacy computing according to any one of claims 2 to 4, characterized in that: The normalization function is standard normalization or maximum and minimum normalization.
7. The cross-domain data security early warning method based on privacy computing according to claim 1 is characterized in that: The expression of the model update parameter is: ;in, represents the parameters of the global model, Indicates the participants The local model parameters, Indicates the participants The weight of Indicates the total number of parties.
8. The cross-domain data security early warning method based on privacy computing according to claim 1 is characterized in that: The loss function for model training is the mean square error loss function.
9. The cross-domain data security early warning method based on privacy computing according to claim 1 is characterized in that: Model parameters include the weight matrix and bias vector of each layer.
10. A cross-domain data security early warning system based on privacy computing, characterized in that: include: A processor and a memory, wherein the memory stores computer program instructions, and when the computer program instructions are executed by the processor, a cross-domain data security warning method based on privacy computing is implemented according to any one of claims 1-9.
Citation Information
Patent Citations
Self-adaptive personalized federal learning method supporting heterogeneous model
CN115271099A
Heterogeneous federated learning method based on contribution weighted aggregation
CN119783758A
Urban traffic detection system and method based on bidirectional memory federated learning, medium and electronic equipment
CN119989111A
Computer-Implemented Data Structure, Method and System for Operating a Technical Device with a Model Based on Federated Learning
US20250094843A1