A Cross-Domain Data Security Early Warning Method and System Based on Privacy Computing
By adopting the privacy calculation method in cross-domain data collaboration and dynamically adjusting the weight update parameters, the problem of low model warning accuracy caused by the differences in cross-domain data distribution is solved, achieving higher robustness and accuracy, while protecting data privacy.
Patent Information
- Application Number
- CN202510653344.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-21
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-05-21
AI Technical Summary
In cross-domain data collaboration, due to the significant differences in data distribution among participants, existing methods are difficult to effectively solve the problem of low model warning accuracy, especially in large-scale heterogeneous data scenarios.
Using a method based on privacy calculation, the local model is trained on the local side and the model parameters are summarized on the central server side. The weight update parameters are calculated through differential scores and average similarity, the weights of each participant are dynamically adjusted, the global model update parameters are generated, and the local model is returned to iterative training, and the risk value is output for early warning.
It effectively solves the problem of inconsistent cross-domain data distribution, improves the robustness and early warning accuracy of the global model, and avoids the risk of privacy leakage caused by the direct sharing of original data.
Smart Images

Figure CN120180451B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing, and particularly to a cross-domain data security warning method and system based on privacy computing. Background Art
[0002] With the acceleration of digital transformation and the popularization of data-driven decision-making, cross-domain data collaboration has become increasingly common. Cross-domain generally refers to the process of data interaction, resource sharing, or collaboration between different entities, systems, or organizations. These entities may be distributed in different physical locations, network environments, or management boundaries. However, cross-domain data collaboration is also accompanied by potential security risks and privacy leakage problems. Therefore, cross-domain data security warning based on privacy computing has become a necessary means, and its core purpose is to protect sensitive data while timely discovering and preventing potential security threats.
[0003] Federated learning is a machine learning paradigm aimed at jointly training a global model by allowing multiple participants (such as devices, institutions, or organizations) without sharing raw data. The core goal of federated learning is to achieve efficient cross-domain collaboration while protecting data privacy. Using federated learning technology, without exposing the raw data, through the sharing of model parameters, cross-domain data joint analysis and anomaly detection are realized.
[0004] In cross-domain data security warning, the data distributions of participants are significantly different, and a single model is difficult to adapt to all distributions. Existing methods (such as simple aggregation or data resampling) cannot effectively solve this problem, especially in large-scale heterogeneous data scenarios. Summary of the Invention
[0005] To solve the technical problem of low model warning accuracy caused by the differences in the data distributions of each participating data, this application provides a cross-domain data security warning method and system based on privacy computing.
[0006] In a first aspect, the present application provides a cross - domain data security warning method based on privacy computing, adopting the following technical solutions: training a local model according to local data at the local end to obtain model parameters; aggregating the model parameters and initial weights of each local model at the central server, calculating the model update parameters of the global model, and transmitting the model update parameters to each local model for the next round of model iterative training and dynamically updating the weights of each participating party; inputting new local data into the trained local model, outputting the risk value of the local data, and performing data security warning according to the risk value; the weight update method is as follows: calculating the difference score of the local data of each participating party at the client; calculating the distribution difference of the model data between the participating parties at the central server; taking the mean of the data distribution differences between any participating party and other participating parties as the average similarity; receiving the difference score at the central server, taking the ratio of the data difference score of the participating party to the average similarity as the weight update parameter, and taking the product of the weight update parameter and the weight of the previous iteration as the updated weight.
[0007] The beneficial effects are as follows: aggregating the local model parameters of each participating party into global model update parameters can make full use of the training results of each participating party, and at the same time avoid the risk of privacy leakage caused by directly sharing the original data. By dynamically adjusting the weights of each participating party, the global model can better adapt to local models with different data distributions. The combination of the difference score and the average similarity can comprehensively reflect the data quality of the participating party and the data distribution difference from other participating parties, so as to allocate weights more reasonably. This method effectively solves the problem of inconsistent cross - domain data distribution, and improves the robustness and warning accuracy of the global model.
[0008] Optionally, the calculation method of the difference score is: calculating the first accuracy rate of the local data of the participating party in the local model, and calculating the second accuracy rate of the local data of the participating party in the global model; normalizing the absolute difference between the first accuracy rate and the second accuracy rate as the difference score of the local data of the participating party.
[0009] The beneficial effects are as follows: by comparing the accuracy rate differences between the local model and the global model on the local data of the participating party, the quality of the local data of the participating party can be quantified. A high first accuracy rate indicates that the local model performs well in processing local data. If the second accuracy rate is low, it means that the global model fails to adapt well to the local data distribution of this participating party, and the data distribution of this participating party is quite different from that of other participating parties. At this time, a higher weight needs to be assigned to this participating party to enhance the adaptability of the global model to this data distribution.
[0010] Optionally, the calculation formula for the distribution difference is: ; represents the participating party and the participating party of the model data distribution difference, The information entropy of the data of the participating party on the -dimensional feature, The information entropy of the data of the participating party on the -dimensional feature, represents the total number of feature dimensions, represents the normalization function.
[0011] The beneficial effect is that it is applicable to the case where the total number of feature dimensions of two participating parties is the same. By calculating the absolute difference of the information entropy on the feature dimensions between the participating parties and normalizing it, the distribution difference between the two sets of data in the feature space can be accurately reflected. This calculation method is simple and efficient and is applicable to the evaluation of distribution differences in large-scale heterogeneous data scenarios.
[0012] Optionally, ; represents the distribution difference of the model data between the participating party and the participating party , The information entropy of the data of the participating party on the -dimensional feature, The information entropy of the data of the participating party on the -dimensional feature, represents the total number of feature dimensions of the participating party , represents the total number of feature dimensions of the participating party , represents the normalization function, represents the maximum value function, represents the minimum value function
[0013] The beneficial effect is that it is applicable to the case where the total number of feature dimensions of two participating parties is different. By comprehensively considering the information entropy difference and dimension difference between the two participating parties, the distribution difference can be evaluated more comprehensively.
[0014] Optionally, the calculation method of the information entropy is as follows: calculate the number of occurrences of any feature of the participating party in any dimension, and use the ratio of the number of occurrences to the total number of samples of the participating party in that dimension as the probability; calculate the product of the negative value of the natural logarithm of the probability and the probability, and use the sum of all products as the information entropy.
[0015] The beneficial effect is that the method of calculating the information entropy by counting the number of occurrences of features has the advantages of simplicity, intuitiveness, high efficiency, accuracy, and strong adaptability.
[0016] Optionally, the normalization method is standard normalization or maximum-minimum normalization.
[0017] The beneficial effects are as follows: The normalization process eliminates the influence brought by differences in data scale or feature distribution among different participating parties, ensuring the fairness and consistency of the weight update process.
[0018] Optionally, the expression of the model update parameter is: ; where represents the model update parameter, represents the local model parameter of the participating party and represents the weight of the participating party , and
[0019] represents the total number of participating parties.
[0020] Optionally, the loss function for model training is the mean squared error loss function.
[0021] Optionally, the model parameters include the weight matrix and bias vector of each layer.
[0022] In the second aspect, the present application provides a cross-domain data security warning system based on privacy computing, adopting the following technical solution:
[0023] A cross-domain data security warning system based on privacy computing includes: a processor and a memory, and the memory stores computer program instructions, which, when executed by the processor, implement the cross-domain data security warning method based on privacy computing as described above.
[0024] Generate a computer program for the cross-domain data security warning method based on privacy computing as described above, and store it in the memory to be loaded and executed by the processor. Thus, a system is made according to the memory and the processor, which is convenient to use.
[0025] The present application has the following technical effects:
[0026] Weighted aggregation of the local model parameters of each participating party into global model update parameters, and then the global model transmits the model parameters back to the local model to adjust the local model, making full use of the training results of each participating party while avoiding the risk of privacy leakage caused by directly sharing the original local data.
[0027] By dynamically adjusting the weights of each participant, the global model can better adapt to local models with different data distributions. The combination of the difference score and the average similarity can comprehensively reflect the data quality of the participants and the data distribution differences from other participants, thus more reasonably allocating weights. This method effectively solves the problem of inconsistent cross-domain data distributions and improves the robustness and warning accuracy of the global model. Brief Description of the Drawings
[0028] Figure 1 is a flowchart of a cross-domain data security warning method based on privacy computing according to an embodiment of the present application.
[0029] Figure 2 is a flowchart of step S2 in a cross-domain data security warning method based on privacy computing according to an embodiment of the present application. Detailed Description of the Embodiment
[0030] An embodiment of the present application discloses a cross-domain data security warning method based on privacy computing. Referring to Figure 1 , it includes steps S1 - S3, specifically as follows:
[0031] S1: Train a local model according to local data at the local end to obtain model parameters.
[0032] Each participant (such as different enterprises or institutions) independently trains a local model using its local data. Since the data distributions of each participant may be different, the local models will learn different patterns. During the training process, only local data is used to ensure that privacy is not leaked.
[0033] Exemplarily, assume there are two banks, Bank A and Bank B, which have respectively collected the savings behaviors of users. Bank A mainly faces more high-net-worth customers, and Bank B mainly faces more medium- and low-net-worth customers. By jointly building a model, the accuracy of savings prediction can be improved, while ensuring that user data privacy is not leaked. At the same time, data security warnings can be made based on the risk values of local data to prevent possible abnormal behaviors.
[0034] S2: Aggregate the model parameters and initial weights of each local model at the central server, calculate the model update parameters of the global model, and transmit the model update parameters to each local model for the next round of model iterative training and dynamically update the weights of each participant.
[0035] Referring to Figure 2 , the weight update method includes steps S20 - S22, specifically as follows:
[0036] S20: Calculate the difference scores of the local data of each participant at the client side.
[0037] The calculation method of the difference score is as follows: calculate the first accuracy rate of the local data of the participating party in the local model, and calculate the second accuracy rate of the local data of the participating party in the global model; the absolute difference between the first accuracy rate and the second accuracy rate is normalized by the normalization function as the difference score of the local data of the participating party.
[0038] By comparing the accuracy rate differences between the local model and the global model on the local data of the participating party, the quality of the local data of the participating party can be quantified. A high first accuracy rate indicates that the local model performs well in processing local data. If the second accuracy rate is low, it means that the global model fails to adapt well to the local data distribution of this participating party, and the data distribution of this participating party is quite different from that of other participating parties. At this time, a higher weight needs to be assigned to this participating party to enhance the adaptability of the global model to this data distribution.
[0039] S21: Calculate the distribution difference of the model data between the participating parties at the central server; use the mean of the data distribution differences between any participating party and other participating parties as the average similarity.
[0040] When the total number of data dimensions of two participating parties is the same, the calculation formula for the distribution difference is:
[0041] ; represents the participating party and the participating party of the model data distribution difference, represents the participating party of the data in the th-dimensional feature of the information entropy, represents the participating party of the data in the th-dimensional feature of the information entropy, represents the total number of feature dimensions, represents the normalization function.
[0042] The information entropy reflects the data richness of the local data. When the difference in data richness between two participating parties is smaller, it indicates that the similarity of the data distribution between the two participating parties is high, and at this time the distribution difference is relatively small.
[0043] Multi-dimensional means describing data from the perspectives of multiple features or attributes. In the bank savings scenario, multi-dimensional can include account balance, transaction frequency, transaction amount distribution, geographical information, credit score, etc.
[0044] The calculation method of the information entropy can be: calculate the occurrence times of any feature of the participating party in any dimension, use the ratio of the occurrence times to the total number of samples of the participating party in this dimension as the probability; calculate the product of the negative value of the natural logarithm of the probability and the probability, and use the sum of all products as the information entropy.
[0045] When the total number of data dimensions of the two participating parties is different, the calculation formula for the distribution difference is as follows:
[0046] ; represents the participating party and the participating party of the model data distribution difference, represents the participating party of the data in the first dimensional feature of the information entropy, represents the participating party of the data in the first dimensional feature of the information entropy, represents the participating party of the total number of feature dimensions, represents the participating party of the total number of feature dimensions, represents the normalization function, represents the maximum value function, represents the minimum value function.
[0047] The closer it is to 1, the higher the similarity of the total data dimensions of the two participating parties. On the contrary, it indicates that the similarity of the total data dimensions of the two participating parties is lower. Considering the information entropy difference and dimension difference of the two participating parties comprehensively can evaluate the distribution difference more comprehensively.
[0048] The normalization function in this application is standard normalization or maximum-minimum normalization, which will not be elaborated in the prior art.
[0049] Calculate the model update parameters of the global model, transmit the model update parameters to each local model for the next round of model iterative training, and dynamically update the weights of each participating party. Perform a weighted sum of the local model parameters of each participating party to generate the update parameters of the global model.
[0050] The expression of the model update parameter is: ; where, represents the parameters of the global model, represents the participating party of the local model parameters, represents the participating party of the weight, represents the total number of participating parties. is not a fixed value and is calculated by a dynamic adjustment method.
[0051] S22: Receive the difference score at the central server, use the ratio of the data difference score of the participating party to the average similarity as the weight update parameter, and use the product of the weight update parameter and the weight of the previous iteration as the updated weight.
[0052] The central server aggregates the model parameters and initial weights of each local model. The model parameters include the weight matrix and bias vector of each layer. For example, in a fully connected layer, the weight matrix determines the relationship between the input features and the output features, while the bias vector provides additional adjustment capabilities. The central server calculates the global model parameters and sends them back to each local model for the next round of iterative training. This process does not involve the transmission of local data, but only the transmission of model parameters, so as to protect local data and reduce the risk of leakage.
[0053] In one embodiment, all initial weights are set to 0.5, and the initial model parameters can be set using the Kaiming initialization method. The prior art will not be elaborated here.
[0054] The model can use the BP (Backpropagation) model, or select a neural network model in the prior art that is applicable to this application. The loss function for model training is the mean squared error loss function. The model and model training are prior art and will not be elaborated here.
[0055] S3: Input the new local data into the trained local model, output the risk value of the local data, and perform data security warning according to the risk value.
[0056] Two companies train local models on their respective local data. After the model training is completed, Bank A and Bank B input the new local data into the trained local model and output the risk value of each user's savings behavior.
[0057] The labels for the local data are low risk, medium risk, and high risk. The risk value output by the model is a vector composed of three probability values. The probability values are numbers between 0 and 1. The three probability values respectively represent the probability of low risk, medium risk, and high risk of the risk value. Select the label with the highest probability value as the risk detection result of the data at this time.
[0058] For example, Bank A discovers that there are frequent small - amount transfers in the accounts of some high - net - worth customers, which may be abnormal fund flows. Bank B discovers that there are large - amount fund inflows and outflows in the accounts of some medium - and low - net - worth customers, which may be signals of abnormal transfer behaviors. For example, a high - net - worth customer has recently transferred money to multiple unfamiliar accounts frequently, and the amount of each transfer is close to the regulatory limit. The risk value output by the model is high risk, triggering a high - risk alarm. Bank A immediately freezes the account and notifies the relevant departments for investigation.
[0059] An embodiment of the present application also discloses a cross - domain data security early warning system based on privacy computing, including a processor and a memory. The memory stores computer program instructions, and when the computer program instructions are executed by the processor, a cross - domain data security early warning method based on privacy computing according to the present application is implemented.
[0060] The above - mentioned system also includes other components well - known to those skilled in the art, such as a communication bus and a communication interface. Their settings and functions are known in the art, so they will not be elaborated here.
[0061] In the present application, the foregoing memory can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, device, or device. For example, a computer - readable storage medium can be any suitable magnetic storage medium or magneto - optical storage medium, such as a resistive - random - access memory, a dynamic random - access memory, a static random - access memory, etc., or any other medium that can be used to store the required information and can be accessed by an application program, a module, or both. Any such computer storage medium can be part of the device or accessible or connectable to the device.
[0062] The above are all the preferred embodiments of the present application. The protection scope of the present application is not limited thereby. Therefore, all equivalent changes made according to the structure, shape, and principle of the present application should be covered within the protection scope of the present application.
Claims
1. A cross - domain data security early warning method based on privacy computing, characterized in that, It includes the steps of: training a local model based on local data at the local end to obtain model parameters; aggregating the model parameters and initial weights of each local model at the central server, calculating the model update parameters of the global model, and transmitting the model update parameters to each local model for the next round of model iterative training and dynamically updating the weights of each participant; Inputting new local data into the trained local model, outputting the risk value of the local data, and performing data security early warning based on the risk value; The weight update method is as follows: Calculate the first accuracy of the local data of the participating parties in the local model on the client side, and calculate the second accuracy of the local data of the participating parties in the global model; Use the absolute difference between the first accuracy and the second accuracy as the difference score of the local data of the participating parties after normalization according to the normalization function; Calculate the distribution difference of the model data between the participating parties on the central server side; When the total number of data dimensions of two participating parties is the same, the calculation formula for the distribution difference is: ; represents the participating party and the participating party of the model data distribution difference, represents the participating party of the data in the th dimension feature of the information entropy, represents the participating party of the data in the th dimension feature of the information entropy, represents the total number of feature dimensions, represents the normalization function; When the total number of data dimensions of two participating parties is different, the calculation formula for the distribution difference is: ; represents the participating party and the participating party of the model data distribution difference, represents the participating party of the data in the th dimension feature of the information entropy, represents the participating party of the data in the th dimension feature of the information entropy, represents the participating party of the total number of feature dimensions, represents the participating party of the total number of feature dimensions, represents the normalization function, represents the maximum value function, represents the minimum value function; Taking the mean of the data distribution differences between any participant and other participants as the average similarity; receiving the difference scores at the central server, taking the ratio of the data difference score of the participant to the average similarity as the weight update parameter, and taking the product of the weight update parameter and the weight of the previous iteration as the updated weight.
2. The cross-domain data security warning method based on privacy computing according to claim 1, wherein The calculation method of information entropy is: calculating the occurrence times of any feature of any participant in any dimension, and taking the ratio of the occurrence times to the total number of samples of the participant in that dimension as the probability; Calculating the product of the negative value of the natural logarithm of the probability and the probability, and taking the cumulative sum of all products as the information entropy.
3. The cross-domain data security warning method based on privacy computing according to claim 2, characterized in that The normalization function is standard normalization or maximum-minimum normalization.
4. The cross-domain data security warning method based on privacy computing according to claim 1, characterized in that The expression for the model update parameter is as follows: ; where represents the parameters of the global model, represents the local model parameters of the participant , represents the weight of the participant , represents the total number of participants.
5. The cross-domain data security warning method based on privacy computing according to claim 1, characterized in that The loss function for model training is the mean squared error loss function.
6. The cross-domain data security warning method based on privacy computing according to claim 1, characterized in that The model parameters include the weight matrix and bias vector of each layer.
7. A cross-domain data security early warning system based on privacy computing, characterized in that, It includes: A processor and a memory, where the memory stores computer program instructions, and when the computer program instructions are executed by the processor, the cross-domain data security early warning method based on privacy computing according to any one of claims 1-6 is implemented.
Citation Information
Patent Citations
Heterogeneous federated learning method based on contribution weighted aggregation
CN119783758A
Urban traffic detection system and method based on bidirectional memory federated learning, medium and electronic equipment
CN119989111A