Target state estimation method and system based on differential privacy protection

Through multi-source data fusion decision-making and differential privacy protection technology, the privacy protection links in the state estimation of smart devices are identified and refined, and the problem of resource waste in the existing technology is solved and efficient and accurate privacy protection is achieved.

CN120234832APending Publication Date: 2025-07-01WUXI UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510520620.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

Existing privacy protection methods provide data privacy protection throughout the entire process of smart device status estimation, resulting in unnecessary and inefficient resource consumption.

Method used

Multi-source data fusion decision-making is adopted to rationally identify the privacy protection links in the target state estimation process, and differential privacy protection is carried out to avoid the entire process of protection, accurately identify the privacy protection links through the target portrait and event map, evaluate the utility value of additional links, plan the execution rhythm, and use differential privacy protection technology for refined protection.

Benefits of technology

It realizes more rational privacy protection in the state estimation of smart device, reduces resource consumption, improves privacy protection efficiency and accuracy, and avoids the risk of privacy leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120234832A_ABST
    Figure CN120234832A_ABST
Patent Text Reader

Abstract

The invention provides a target state estimation method and system based on differential privacy protection, and relates to the technical field of computer data processing, and the method comprises the steps: carrying out the rational recognition constraint of a multi-source data fusion decision; estimating a target state; identifying a privacy protection link in a target state estimation process based on the rational identification constraint; differential privacy protection is carried out on the privacy protection link; and outputting a final target state estimation result. The multi-source data fusion decision-making rational identification constraint is adopted, the privacy protection link in the target state estimation process is identified based on the constraint, differential privacy protection is performed, data privacy protection is prevented from being performed in the whole process of state estimation of the intelligent equipment, a more rational protection mode is realized, and the method is suitable for popularization and application. The unnecessary consumption of privacy protection resources is avoided, and the privacy protection efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer data processing, and particularly relates to a target state estimation method and system based on differential privacy protection. Background Art

[0002] At present, with the rapid development of industrial Internet technology, a large number of intelligent devices are interconnected with the control center. In order to ensure the operation stability of each intelligent device and its ability to cooperate with other intelligent devices in a timely manner, the control center needs to perform real-time state estimation on them.

[0003] In the process of real-time state estimation of intelligent devices, a large amount of privacy data will inevitably be involved, such as device operation data, user information, etc., and these privacy data need to be protected.

[0004] However, existing related privacy protection methods mostly perform data privacy protection throughout the entire process of state estimation of intelligent devices. The protection method is not rational enough, which may cause unnecessary consumption of privacy protection resources and reduce the privacy protection efficiency.

[0005] Therefore, a solution is urgently needed. Summary of the Invention

[0006] One of the purposes of the present invention is to provide a target state estimation method based on differential privacy protection, which rationally identifies and constrains multi-source data fusion decision-making, identifies the privacy protection links in the process of target state estimation based on it, and performs differential privacy protection, avoiding performing data privacy protection throughout the entire process of state estimation of intelligent devices, realizing a more rational protection method, avoiding unnecessary consumption of privacy protection resources, and improving the privacy protection efficiency.

[0007] A target state estimation method based on differential privacy protection provided by an embodiment of the present invention includes:

[0008] Rationally identifying and constraining multi-source data fusion decision-making;

[0009] Estimating the target state;

[0010] Based on the rational identification constraint, identifying the privacy protection links in the process of target state estimation;

[0011] Performing differential privacy protection on the privacy protection links;

[0012] Outputting the final target state estimation result.

[0013] Optionally, the rational identification and constraint of multi-source data fusion decision-making includes:

[0014] Match multi-source data based on the target portrait;

[0015] Map the multi-source data into the event graph;

[0016] Extract multiple independent first events and event groups of multiple second events that are mutually related in the event graph after the multi-source data is mapped in;

[0017] Generate a rational recognition constraint, including: when the possibility of any first event or all second events in the same event group occurring in the first sub-process during the target state estimation process exceeds the possibility threshold, the corresponding first sub-process is used as a privacy protection link.

[0018] Optionally, the matching of multi-source data based on the target portrait includes:

[0019] Determine the multi-source data matching mechanism corresponding to the target portrait from the multi-source data matching mechanism library;

[0020] Match multi-source data based on the multi-source data matching mechanism.

[0021] Optionally, the mapping of multi-source data into the event graph includes:

[0022] Search for the allowable mapping positions corresponding to each data in the multi-source data in the event graph, and map each data in the multi-source data to the corresponding allowable mapping positions.

[0023] Optionally, the target state estimation method based on differential privacy protection further includes:

[0024] When at least one additional link is temporarily derived in the privacy protection link during the differential privacy protection process of the privacy protection link, evaluate the utility value of the additional link for the target state estimation;

[0025] When the utility value exceeds the utility threshold, based on the rational recognition constraint, identify whether the additional link needs to be used as a new privacy protection link;

[0026] When it is yes, perform differential privacy protection on the additional link;

[0027] Otherwise, plan the execution rhythm of the additional link;

[0028] Execute the additional link based on the execution rhythm;

[0029] Whenever a new first sub-process in the additional link is executed, based on the execution results of the second sub-processes that have been executed in the additional link, determine whether the first sub-process needs to be used as a new privacy protection link;

[0030] When it is yes, perform differential privacy protection on the first sub-process;

[0031] Among them, the execution order of the first sub - link in the additional link is greater than or equal to two.

[0032] Optionally, the execution rhythm of the planned additional link includes:

[0033] Perform serialization processing on the additional link to obtain an execution link sequence;

[0034] Match each third sub - link in the execution link sequence with the fourth sub - link in the trigger link library respectively;

[0035] Describe the sequence position distribution of the third sub - links that match and the indication information corresponding to the fourth sub - links that match to obtain a first feature description vector;

[0036] Based on the first feature description vector, match sequence division knowledge;

[0037] Based on the sequence division knowledge, divide the execution link sequence into multiple local sequences and divide the execution rhythm type of each local sequence;

[0038] Traverse each local sequence in turn;

[0039] Each time during traversal, when the execution rhythm type of the traversed local sequence is active execution, generate the local execution rhythm of the traversed local sequence, including: when the second sub - process being executed in the target state estimation process is related to both the first and last third sub - links in the traversed local sequence, execute each third sub - link in the traversed local sequence in turn; and when the execution rhythm type of the traversed local sequence is passive execution, generate the local execution rhythm of the traversed local sequence, including: when the target state estimation process is completed, execute each third sub - link in the traversed local sequence in turn;

[0040] After traversing all local sequences, integrate the local execution rhythms of each local sequence to obtain the execution rhythm of the additional link.

[0041] Optionally, determining whether the first sub - link needs to be a new privacy protection link based on the execution result of the second sub - link already executed in the additional link includes:

[0042] Describe the execution result of the second sub - link already executed in the additional link to obtain a second feature description vector;

[0043] When the risk value corresponding to the second feature description vector in the risk value library exceeds the risk threshold, determine that the first sub - link needs to be a new privacy protection link.

[0044] Optionally, the matching sequence division knowledge based on the first feature description vector includes:

[0045] Determine the sequence division knowledge matching mechanism corresponding to the first feature description vector from the sequence division knowledge matching mechanism library;

[0046] Match the sequence division knowledge based on the sequence division knowledge matching mechanism.

[0047] Optionally, the target state estimation method based on differential privacy protection further includes:

[0048] When performing differential privacy protection on the first sub-link, obtain the target content of the first sub-link protected by differential privacy;

[0049] Obtain the non-standard privacy protection situations related to the target content; among them, the non-standard privacy protection situations include the first situation involving the target content and the second situation involving other target content;

[0050] Based on other target content, determine the historical time period and the joint target;

[0051] Verify whether the second situation occurs during the process of state estimation of the joint target within the historical time period;

[0052] When it occurs, stop executing the additional link based on the execution rhythm.

[0053] A target state estimation system based on differential privacy protection provided by an embodiment of the present invention includes:

[0054] A multi-source data fusion decision module for rationally identifying constraints for multi-source data fusion decision-making;

[0055] A target state estimation module for estimating the target state;

[0056] A privacy protection link identification module for identifying the privacy protection links in the target state estimation process based on the rational identification constraints;

[0057] A differential privacy protection module for performing differential privacy protection on the privacy protection links;

[0058] A target state estimation result output module for outputting the final target state estimation result.

[0059] Other features and advantages of the present invention will be described in the following specification, and, in part, will be obvious from the specification, or will be understood by implementing the present invention. The objectives and other advantages of the present invention can be achieved and obtained by the structures specifically pointed out in the written specification and the drawings.

[0060] Next, through the drawings and embodiments, the technical solutions of the present invention will be further described in detail. Description of the Drawings

[0061] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation to the present invention. In the accompanying drawings:

[0062] Figure 1 It is a schematic diagram of a target state estimation method based on differential privacy protection in an embodiment of the present invention;

[0063] Figure 2 It is a schematic diagram of a target state estimation system based on differential privacy protection in an embodiment of the present invention. Detailed implementation manners

[0064] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention and are not used to limit the present invention.

[0065] Embodiment 1:

[0066] The embodiment of the present invention provides a target state estimation method based on differential privacy protection, as Figure 1 shown, including:

[0067] S1. Identify and constrain the rationality of multi-source data fusion decision-making;

[0068] S2. Estimate the target state;

[0069] S3. Based on the rationality identification constraint, identify the privacy protection link in the target state estimation process;

[0070] S4. Perform differential privacy protection on the privacy protection link;

[0071] S5. Output the final target state estimation result.

[0072] The target at least includes: intelligent devices connected to the control center, such as: intelligent manufacturing devices, industrial robots, intelligent transportation devices, etc.; the rationality identification constraint is used to constrain the privacy protection links that need to be protected during the rational identification of the target state estimation process in the system, perform multi-source data fusion decision-making, and improve the accuracy of its decision-making; when the privacy protection link is identified, based on the differential privacy protection technology, perform differential privacy protection on it; differential privacy is a technology that protects individual privacy by adding noise to the data. It can effectively prevent the leakage of sensitive information while retaining the overall statistical characteristics of the data. In the application scenario of this application, it can ensure the privacy while ensuring the accuracy of data analysis during target state estimation.

[0073] The embodiment of the present invention identifies and constrains the rationality of multi-source data fusion decision-making, identifies the privacy protection link in the target state estimation process based on it, and performs differential privacy protection, avoiding data privacy protection for the entire process of state estimation of intelligent devices, realizing a more rational protection method, avoiding unnecessary consumption of privacy protection resources, and improving the privacy protection efficiency.

[0074] Embodiment 2:

[0075] In one embodiment, the S1, multi-source data fusion decision rationality identification constraint, includes:

[0076] S11. Match multi-source data based on the target portrait;

[0077] In S11, the target portrait at least includes: device model, device usage, privacy leakage events that have occurred in the same type of devices in history, data generation type and storage method of the device, and device network connection method;

[0078] S12. Map the multi-source data into the event graph;

[0079] In S12, the event graph contains multiple event trees with a tree structure. Each event tree represents a demand event that requires privacy protection during the target state estimation process. The same event tree contains multiple nodes, and each node represents an event element of the demand event. When all nodes in the same event tree have successfully mapped data, the event tree can form the demand event it represents; each node will also mark the data type that allows data mapping; when at least two demand events need to be protected simultaneously, the event trees corresponding to the at least two demand events will be pre-associated and marked, and the at least two demand events will be mutually associated;

[0080] S13. Extract multiple independent first events and multiple groups of second events that are mutually associated in the event graph after the multi-source data is mapped in;

[0081] In S13, after the multi-source data is mapped into the event graph, if all nodes in the same event tree have successfully mapped data, obtain the demand event it represents. If there is no other event tree associated with this event tree, take the demand event it represents as the first event. Otherwise, if all nodes in the other event tree associated with this event tree have also successfully mapped data, take the demand events represented by both as multiple mutually associated second events to form an event group;

[0082] S14. Generate a rational recognition constraint, including: when the possibility that any first event occurs or all second events in the same event group occur during the first subprocess in the target state estimation process exceeds the possibility threshold, regarding the corresponding first subprocess as a privacy protection link;

[0083] In S14, the occurrence of the first event or the second event has multiple occurrence conditions. The sum of the proportion of conditions that the first subprocess meets the occurrence conditions of the first event and the proportion of conditions that the first subprocess meets the occurrence conditions of all second events can be used as the possibility. The possibility is a threshold representing a relatively high possibility of occurrence. When the possibility that any first event occurs or all second events in the same event group occur during the first subprocess exceeds the possibility threshold, then regarding the corresponding first subprocess as a privacy protection link. This rational recognition constraint is used to constrain the system to rationally identify the privacy protection links that need privacy protection during the target state estimation process;

[0084] Among them, S11. Match multi-source data based on the target portrait, including:

[0085] S111. Determine the multi-source data matching mechanism corresponding to the target portrait from the multi-source data matching mechanism library; the multi-source data matching mechanism includes: matching the event elements related to the multi-source data that can be used as the above-mentioned demand events;

[0086] S112. Match multi-source data based on the multi-source data matching mechanism;

[0087] S12. Map the multi-source data into the event graph, including:

[0088] S121. Search for the allowed mapping positions corresponding to each data in the multi-source data from the event graph, and map each data in the multi-source data to the corresponding allowed mapping positions.

[0089] In S121, when mapping the multi-source data, based on the type of each data, find the corresponding node on the event tree, and this node is the allowed mapping position, and map the corresponding data to this allowed mapping position.

[0090] When the present invention performs rational recognition constraint for multi-source data fusion decision-making, it matches multi-source data using the target portrait. The rational recognition constraint for decision-making using the matched multi-source data can accurately adapt to the recognition of the privacy protection links in the target state estimation process, improving the decision-making accuracy; secondly, an event graph is introduced, and it is used to quickly and efficiently determine the first event and the second event, and generate a rational recognition constraint based on these two, improving the decision-making efficiency. Overall, it improves the accuracy, comprehensiveness, and efficiency of multi-source data fusion decision-making.

[0091] Embodiment 3:

[0092] In the actual application of this application, a special problem will occur: the operating environment and communication environment of the target may change at any time. Therefore, when performing state estimation, privacy protection measures may temporarily derive additional links. Specifically, for example, when evaluating the state of a heart rate sensor for health monitoring of a user, the heart rate sensor fails, resulting in the inability to obtain accurate heart rate data. Therefore, an additional link for estimating whether the heart rate sensor can use motion tracking data to estimate heart rate changes is temporarily derived.

[0093] Due to the complexity and particularity of the additional link, it is not always possible to accurately determine whether privacy protection is required for it solely based on rational identification constraints. At the same time, the additional link may have a greater effect on the target state estimation. In this case, directly executing the additional link may lead to the risk of privacy leakage, and performing differential privacy protection on its entire process may cause excessive consumption of privacy protection resources. Therefore, to solve the above special problem, in one embodiment, the target state estimation method based on differential privacy protection further includes:

[0094] S6. When at least one additional link is temporarily derived during the differential privacy protection of the privacy protection link, evaluate the utility value of the additional link for the target state estimation;

[0095] In S6, the utility value represents the degree of utility of the additional link for the target state estimation. Specifically, it can be determined based on the derived type of the attachment link. For example, if the heart rate sensor fails and an additional link for estimating whether the heart rate sensor can use motion tracking data to estimate heart rate changes is temporarily derived, the derived type is replacement, and the utility value is a relatively large value; the utility values of different attachment link types can also be set in advance by technicians;

[0096] S7. When the utility value exceeds the utility threshold, based on rational identification constraints, identify whether the additional link needs to be used as a new privacy protection link; S8. When the answer is yes, perform differential privacy protection on the additional link;

[0097] S9. Otherwise, plan the execution rhythm of the additional link;

[0098] S10. Execute the additional link based on the execution rhythm;

[0099] S11. Whenever the first sub-link in the additional link is newly executed, based on the execution result of the second sub-link that has been executed in the additional link, determine whether the first sub-link needs to be used as a new privacy protection link;

[0100] S12. When the answer is yes, perform differential privacy protection on the first sub-link;

[0101] Among them, the execution order of the first sub-link in the additional link is greater than or equal to two.

[0102] In S7 to S12, the utility threshold is a threshold representing a relatively large utility degree of the additional link for the target state estimation. For example, the utility threshold is set to 8. When the utility value exceeds the utility threshold, it means that the utility degree of the additional link for the target state estimation is relatively large and it must be executed. At this time, the privacy security during its execution needs to be considered. First, based on the rational identification constraint, it is identified whether the additional link needs to be a new privacy protection link. When it is yes, differential privacy protection is directly performed on the additional link. Otherwise, its execution rhythm is planned so that it is executed according to the execution rhythm to avoid direct execution of all at once. Then, whenever the first sub-link is newly executed, based on the execution result of the second sub-link, it is determined whether it needs to be a new privacy protection link. When it is yes, differential privacy protection is performed on the first sub-link. Setting the condition that the execution order of the first sub-link in the additional link is greater than or equal to two is to ensure that the second sub-link is not empty.

[0103] In the embodiment of the present invention, when encountering the situation of a temporarily derived additional link, first, its utility value is evaluated. When the utility value exceeds the utility threshold, subsequent operations are performed to reduce system processing resources. Then, the additional link is first identified using the rational identification constraint to determine whether it needs to be a new privacy protection link. If so, differential privacy protection is directly performed. If not, its execution rhythm is planned to avoid direct execution of all at once. Every time the first sub-link is newly executed, based on the execution result of the second sub-link, it is determined whether it needs to be a new privacy protection link. If so, differential privacy protection is performed on the first sub-link, realizing refined differential privacy protection. Overall, it accurately and effectively solves the above special problems that will be encountered in the actual application of this application, avoids the risk of privacy leakage that may be caused by directly executing the additional link, and avoids the excessive consumption of privacy protection resources that may be caused by performing differential privacy protection on the entire process of the additional link, greatly improving the applicability of the system.

[0104] Embodiment 4:

[0105] In one embodiment, in S9, planning the execution rhythm of the additional link includes:

[0106] S91. Serialize the additional link to obtain an execution link sequence;

[0107] In S91, when performing serialization processing, multiple sub-links that need to be executed in the additional link are sorted according to the execution sequence to obtain an execution link sequence;

[0108] S92. Match each third sub - link in the execution link sequence with the fourth sub - link in the trigger link library respectively; S93. Characterize the sequence position distribution of the third sub - links that match and the indication information corresponding to the fourth sub - links that match, and obtain the first feature description vector;

[0109] S94. Based on the first feature description vector, match the sequence division knowledge;

[0110] S95. Based on the sequence division knowledge, divide the execution link sequence into multiple local sequences and divide the execution rhythm type of each local sequence;

[0111] S96. Traverse each local sequence in turn;

[0112] S97. Each time when traversing, when the execution rhythm type of the traversed local sequence is active execution, generate the local execution rhythm of the traversed local sequence, including: when the second sub - process being executed in the target state estimation process is related to both the first and last third sub - links in the traversed local sequence, execute each third sub - link in the traversed local sequence in turn; and when the execution rhythm type of the traversed local sequence is passive execution, generate the local execution rhythm of the traversed local sequence, including: when the target state estimation process is completed, execute each third sub - link in the traversed local sequence in turn;

[0113] In S92 to S95, when the third sub - link matches the fourth sub - link, based on the sequence position distribution of the third sub - links that match and the indication information corresponding to the fourth sub - links that match, the sequence division knowledge applicable to how to locally divide the execution link sequence and divide its execution rhythm type can be comprehensively determined; when the local execution rhythm of the local sequence is active execution, it is necessary that the second sub - process being executed in the target state estimation process is related to both the first and last third sub - links in the traversed local sequence to execute the third sub - links therein in turn; when the local execution rhythm of the local sequence is passive execution, it is necessary that when the target state estimation process is completed, execute each third sub - link in the traversed local sequence in turn;

[0114] Specifically, for example: if the additional step is to estimate whether the heart rate sensor can use the motion tracking data to estimate the heart rate change, the execution step sequence is to test the motion tracking data collection, test the matching of the motion data with the historical motion data, test the retrieval of the user's historical heart rate corresponding to the matched historical motion data, and test the estimation of the current heart rate by combining the retrieved historical heart rate. The fourth sub-steps are set as testing the motion tracking data collection and testing the estimation of the current heart rate by combining the retrieved historical heart rate, and the corresponding indication information is to perform data collection and to perform heart rate estimation respectively. After matching, the sequence position distribution is at the head and tail of the sequence. The sequence position distribution and the indication information are represented as a first feature description vector in vector form. The matching sequence division knowledge indicates that the first three sub-steps in the execution step sequence are divided into a local sequence, and its execution rhythm type is active execution (there will be relevant second sub-processes executed for the motion tracking data collection and the subsequent data retrieval. If the relevant second sub-processes are executed, it means that the possibility of data tampering and the like in the sequential execution of the third sub-step in the local sequence is relatively small. For example, if the relevant second sub-process is the collection of the positioning information of the heart rate sensor and the retrieval of its historical positioning information, then there is a synchronous recording between the positioning information and the motion tracking data in terms of time, and thus it is possible to immediately verify whether the collected motion tracking data is correct). The last sub-step is divided into a local sequence, and its execution rhythm type is passive execution (testing the estimation of the current heart rate by combining the retrieved historical heart rate is an unconventional process and will generate new data. Therefore, it needs to be executed after the target state estimation process is completed to ensure safety);

[0115] S98. After traversing each local sequence, integrate the local execution rhythms of each local sequence to obtain the execution rhythm of the additional step;

[0116] Among them, in the above-mentioned S11, based on the execution result of the second sub-step already executed in the additional step, determine whether the first sub-step needs to be used as a new privacy protection step, including:

[0117] S111. Perform feature description on the execution result of the second sub-step already executed in the additional step to obtain a second feature description vector;

[0118] S112. When the risk value corresponding to the second feature description vector in the risk value library exceeds the risk threshold, determine that the first sub-step needs to be used as a new privacy protection step;

[0119] In S111 to S112, the execution result is represented as a second feature description vector in vector form; there are risk values corresponding to different second feature description vectors in the risk value library, and the risk value represents the degree of the privacy leakage risk that may occur in the execution of the first sub-link reflected by the execution result of the second sub-link. For example, if the execution result is to extract some features of user-sensitive data, then the first sub-link may utilize these features, and thus it needs to be regarded as a new privacy protection link, and the risk value corresponding to the second feature description vector is 20; the risk threshold is the threshold representing a relatively large degree of the privacy leakage risk that may occur in the execution of the first sub-link reflected by the execution result of the second sub-link. For example, the risk threshold is set to 10.

[0120] Among them, the S94, based on the first feature description vector, matching sequence partitioning knowledge, includes:

[0121] S941. Determine the sequence partitioning knowledge matching mechanism corresponding to the first feature description vector from the sequence partitioning knowledge matching mechanism library;

[0122] In S941, the sequence partitioning knowledge matching mechanism is a mechanism for matching the sequence partitioning knowledge corresponding to the first feature description vector;

[0123] S942. Based on the sequence partitioning knowledge matching mechanism, match the sequence partitioning knowledge.

[0124] In the embodiment of the present invention, when planning the execution rhythm of the additional link, a trigger link library is introduced, the third sub-link is matched with the fourth sub-link, and based on the sequence position distribution of the third sub-link that meets the match in the execution link sequence and the indication information corresponding to the fourth sub-link that meets the match, the sequence partitioning knowledge applicable to how to locally partition the execution link sequence and the type of its execution rhythm is comprehensively determined, so as to quickly and accurately perform corresponding partitioning on the execution link sequence. According to different types of the divided execution rhythm, the local execution rhythm is set respectively, and finally the local execution rhythms of each local sequence are integrated to complete the planning of the execution rhythm of the additional link, which greatly improves the accuracy, comprehensiveness and execution efficiency of the execution rhythm planning of the additional link; secondly, when determining whether the first sub-link needs to be regarded as a new privacy protection link based on the execution result of the second sub-link already executed in the additional link, a risk value library is introduced to quickly determine the risk value, which improves the accuracy and efficiency of determining whether the first sub-link needs to be regarded as a new privacy protection link. Overall, the safety and stability of executing the additional link according to the planned execution rhythm are improved.

[0125] Embodiment 5:

[0126] In one embodiment, the target state estimation method based on differential privacy protection further includes:

[0127] S13. When performing differential privacy protection on the first sub-link, obtain the target content protected by differential privacy for the first sub-link;

[0128] In S13, the target content is the content protected by differential privacy. For example, it is the user privacy data generated when the first sub-link is executed;

[0129] S14. Obtain the non-standard privacy protection situations related to the target content; among them, the non-standard privacy protection situations include the first situation involving the target content and the second situation involving other target content;

[0130] In S14, the non-standard privacy protection situations are preset. The non-standard privacy protection situations refer to the unconventional situations that need privacy protection. The first situation involving the target content means the first situation that includes protecting the target content from privacy leakage. Correspondingly, the non-standard privacy protection situations will also include the second situation involving other target content;

[0131] S15. Based on other target content, determine the historical time period and the combined target;

[0132] In S15, the first situation occurs during the process of performing differential privacy protection on the first sub-link; the target content will reflect when and what combined target will jointly generate the second situation with the process of performing differential privacy protection on the first sub-link. For example, the second situation is that the payment device of a certain store and the smart watch worn by the user are maliciously invaded and want to jointly steal the privacy information of the user's consumption habits when running; then the target content is the running trajectory that the user often passes by historically, the other target content is the consumption information of the stores passed by the running trajectory, the historical time period is the time period when the user generates the running trajectory on the same day, and the combined target is the payment device of the store passed by the running trajectory;

[0133] S16. Verify whether the second situation appears during the process of performing state estimation on the combined target within the historical time period;

[0134] S17. When it appears, stop executing the additional link based on the execution rhythm.

[0135] In S17, when it appears, it means that the non-standard privacy protection situation is triggered, and stop executing the additional link based on the execution rhythm.

[0136] The embodiment of the present invention obtains the non-standard privacy protection situations related to the target content, and based on other target content, determines the historical time period and the combined target, and determines whether to stop executing the additional link based on the execution rhythm by verifying whether the second situation appears during the process of performing state estimation on the combined target within the historical time period, which greatly improves the comprehensiveness and accuracy of privacy protection during the state estimation process, and further improves the applicability of the system.

[0137] Example 6:

[0138] An embodiment of the present invention provides a target state estimation system based on differential privacy protection, as Figure 2 shown, including:

[0139] A multi-source data fusion decision-making module 1 for rationally identifying constraints in multi-source data fusion decision-making;

[0140] A target state estimation module 2 for estimating the target state;

[0141] A privacy protection link identification module 3 for identifying privacy protection links in the target state estimation process based on rational identification constraints;

[0142] A differential privacy protection module 4 for performing differential privacy protection on privacy protection links;

[0143] A target state estimation result output module 5 for outputting the final target state estimation result.

[0144] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these changes and modifications.

Claims

1. A target state estimation method based on differential privacy protection, characterized in that: include: Multi-source data fusion decision-making rational identification constraints; Estimate the target state; Based on rational identification constraints, the privacy protection links in the target state estimation process are identified; Perform differential privacy protection on the privacy protection link; Output the final target state estimation result.

2. The target state estimation method based on differential privacy protection according to claim 1, characterized in that: The multi-source data fusion decision rational identification constraints include: Match multi-source data based on target portrait; Map multi-source data into event graphs; Extracting multiple independent first events and multiple groups of mutually related second events from the event graph after the multi-source data is mapped; Generate rational identification constraints, including: when the probability of any first event occurring in the first sub-process of the target state estimation process or all second events in the same event group occurring exceeds a probability threshold, use the corresponding first sub-process as a privacy protection link.

3. The target state estimation method based on differential privacy protection according to claim 2, characterized in that: The target portrait-based matching of multi-source data includes: Determine the multi-source data matching mechanism corresponding to the target profile from the multi-source data matching mechanism library; Match multi-source data based on multi-source data matching mechanism.

4. The target state estimation method based on differential privacy protection according to claim 2, characterized in that: Mapping multi-source data into an event graph includes: The allowed mapping position corresponding to each data in the multi-source data is searched from the event graph, and each data in the multi-source data is mapped to the corresponding allowed mapping position.

5. The target state estimation method based on differential privacy protection according to claim 1, characterized in that: Also includes: When the privacy protection link temporarily derives at least one additional link during the differential privacy protection process of the privacy protection link, evaluating the utility value of the additional link for the target state estimation; When the utility value exceeds the utility threshold, based on rational identification constraints, identify whether additional links need to be used as new privacy protection links; When it is yes, differential privacy protection is performed on the additional links; Otherwise, plan the execution rhythm of the additional links; Execute additional steps based on execution rhythm; Whenever the first sub-stage in the additional stage is newly executed, based on the execution result of the second sub-stage that has been executed in the additional stage, it is determined whether the first sub-stage needs to be used as a new privacy protection stage; When it is yes, differential privacy protection is performed on the first sub-link; Among them, the execution order of the first sub-link in the additional link is greater than or equal to two.

6. The target state estimation method based on differential privacy protection according to claim 5, characterized in that: The execution rhythm of the additional planning steps includes: Serialize the additional links to obtain the execution link sequence; Match each third sub-link in the execution link sequence with the fourth sub-link in the trigger link library; Performing feature description on the sequence position distribution of the matched third sub-link in the execution link sequence and the indication information corresponding to the matched fourth sub-link to obtain a first feature description vector; Based on the first feature description vector, matching sequence partition knowledge; Based on the sequence division knowledge, the execution link sequence is divided into multiple local sequences, and the execution rhythm type of each local sequence is divided; Traverse each local sequence in turn; During each traversal, when the execution rhythm type of the traversed local sequence is active execution, a local execution rhythm of the traversed local sequence is generated, including: when the second sub-process being executed in the target state estimation process is related to the first and last third sub-links in the traversed local sequence, each third sub-link in the traversed local sequence is executed in sequence; and when the execution rhythm type of the traversed local sequence is passive execution, a local execution rhythm of the traversed local sequence is generated, including: when the target state estimation process is completed, each third sub-link in the traversed local sequence is executed in sequence; After traversing each local sequence, the local execution rhythm of each local sequence is integrated to obtain the execution rhythm of the additional link.

7. The target state estimation method based on differential privacy protection according to claim 5, characterized in that: The step of determining whether the first sub-step needs to be used as a new privacy protection step based on the execution result of the second sub-step that has been executed in the additional step includes: Performing feature description on the execution result of the second sub-link executed in the additional link to obtain a second feature description vector; When the risk value corresponding to the second feature description vector in the risk value library exceeds the risk threshold, it is determined that the first sub-link needs to be used as a new privacy protection link.

8. The target state estimation method based on differential privacy protection according to claim 6, characterized in that: The matching sequence partitioning knowledge based on the first feature description vector includes: Determine the sequence partitioning knowledge matching mechanism corresponding to the first feature description vector from the sequence partitioning knowledge matching mechanism library; Based on the sequence partition knowledge matching mechanism, the sequence partition knowledge is matched.

9. The target state estimation method based on differential privacy protection according to claim 5, characterized in that: Also includes: When performing differential privacy protection on the first sub-phase, obtaining target content protected by differential privacy in the first sub-phase; Acquire non-standard privacy protection situations related to target content; wherein the non-standard privacy protection situations include a first situation involving the target content and a second situation involving other target content; Determine historical time periods and joint goals based on other goal content; Verify whether the second situation occurs during the state estimation of the joint target in the historical time period; When overdue, stop executing additional links based on the execution rhythm.

10. A target state estimation system based on differential privacy protection, characterized in that: include: Multi-source data fusion decision module, used for rational identification constraints of multi-source data fusion decision; A target state estimation module, used for estimating the target state; The privacy protection link identification module is used to identify the privacy protection links in the target state estimation process based on rational identification constraints; The differential privacy protection module is used to perform differential privacy protection on the privacy protection link; The target state estimation result output module is used to output the final target state estimation result.