Vector retrieval method and device, medium, electronic equipment and program product

By performing linear transformation and dynamic encryption on vectors, the problem of privacy data leakage in vector retrieval is solved, and security and recall guarantees are achieved under vec2text attacks and known plaintext attacks.

CN120263399APending Publication Date: 2025-07-04BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510388360.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

In the process of vector retrieval, although it can resist vec2text attacks, it cannot effectively resist known plaintext attacks, resulting in a privacy data leakage in the knowledge vector library.

Method used

By linearly transforming the vectors using the transformation matrix generated based on the first orthogonal matrix and the second orthogonal matrix, a ciphertext vector is generated, and the vectors in the knowledge vector library are encrypted using the dynamically generated second transformation matrix to maintain the difference in the distance between vectors and the internal product, and the effectiveness of known plaintext attacks is reduced.

Benefits of technology

While supporting vector retrieval, it effectively resists vec2text attacks, avoids privacy data leakage, and keeps the recall rate basically unchanged, reducing the effectiveness of known plaintext attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263399A_ABST
    Figure CN120263399A_ABST
Patent Text Reader

Abstract

The invention discloses a vector retrieval method and device, a medium, electronic equipment and a program product. The method comprises the steps that a first vector corresponding to an input request is acquired, a first transformation matrix is acquired, and the first transformation matrix is generated based on a first orthogonal matrix and a second orthogonal matrix; performing linear transformation on the first vector by using the first transformation matrix to obtain a first ciphertext vector; sending the first ciphertext vector to a first server; the ciphertext vector in the knowledge vector library is obtained by performing linear transformation on a second vector by using a second transformation matrix, and the second transformation matrix is generated based on the first orthogonal matrix, the second orthogonal matrix and the second vector. Thus, on the premise of supporting vector retrieval, the vec2text attack in a language model service scene can be resisted, and leakage of privacy data in the knowledge vector library is avoided. The second transformation matrix is dynamically generated according to the second vector itself, so that differences of plaintext and ciphertext inner products of different vector pairs in the knowledge vector library are different, and the effectiveness of known plaintext attacks is remarkably reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technology, and in particular, to a vector retrieval method, device, medium, electronic device and program product. Background Art

[0002] Retrieval-Augmented Generation (RAG) is a technology that uses background knowledge to enhance the quality of answers given by large language models (LLMs). In RAG applications, users can upload their personal documents to the knowledge base in advance. When a user initiates a reasoning request to the LLM, the RAG application will first use the question to retrieve relevant text fragments in the knowledge base, and then combine these text fragments with the question and submit them to the LLM for reasoning.

[0003] RAG technology based on vector retrieval can better identify the semantic information of text and is therefore widely used. In the stage of uploading knowledge, the user document data as the knowledge base is first converted into a vector form db_embedding by the embedding model, such as Figure 1 As shown in the figure, after encrypting the knowledge text using traditional text encryption technology,<db_embedding,加密文本> In the inference phase, Figure 1 As shown in the figure, the user question is also converted into query_embedding in vector form by the embedding model. Query_embedding can be used to retrieve semantically relevant encrypted text from the vector database. After decryption, the semantically relevant encrypted text is submitted to LLM for reasoning together with the user question.

[0004] Generally speaking, embedding is considered to be indecipherable from the original plaintext, so it is not protected (otherwise it cannot be retrieved). Figure 1 and Figure 2 As shown in the figure, even if the attacker does not have an embedding model, he can still use the vector-to-text (vec2text) attack to decrypt the plaintext from the embedding (i.e., attack to restore the text). The similarity between the decrypted plaintext and the original text is close to 1, which may leak data privacy. Therefore, it is necessary to protect the embedding stored in the knowledge vector library while supporting vector retrieval. Summary of the invention

[0005] This Summary is provided to introduce a brief selection of concepts that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.

[0006] In a first aspect, the present disclosure provides a vector retrieval method, including:

[0007] Obtaining a first vector corresponding to an input request, and obtaining a first transformation matrix, where the first transformation matrix is generated based on a first orthogonal matrix and a second orthogonal matrix, and elements in the first orthogonal matrix and the second orthogonal matrix are random numbers generated with a preset key as a random seed;

[0008] Performing a linear transformation on the first vector by using the first transformation matrix to obtain a first ciphertext vector;

[0009] Sending the first ciphertext vector to a first server, where the first server is configured to retrieve at least one second ciphertext vector similar to the first ciphertext vector from a knowledge vector library; wherein the ciphertext vectors in the knowledge vector library are obtained by performing a linear transformation on second vectors by using a second transformation matrix, and the second transformation matrix is generated based on the first orthogonal matrix, the second orthogonal matrix, and the second vectors.

[0010] In a second aspect, the present disclosure provides a vector retrieval apparatus, including:

[0011] An obtaining module, configured to obtain a first vector corresponding to an input request, and obtain a first transformation matrix, where the first transformation matrix is generated based on a first orthogonal matrix and a second orthogonal matrix, and elements in the first orthogonal matrix and the second orthogonal matrix are random numbers generated with a preset key as a random seed;

[0012] A first linear transformation module, configured to perform a linear transformation on the first vector by using the first transformation matrix to obtain a first ciphertext vector;

[0013] A first sending module, configured to send the first ciphertext vector to a first server, where the first server is configured to retrieve at least one second ciphertext vector similar to the first ciphertext vector from a knowledge vector library; wherein the ciphertext vectors in the knowledge vector library are obtained by performing a linear transformation on second vectors by using a second transformation matrix, and the second transformation matrix is generated based on the first orthogonal matrix, the second orthogonal matrix, and the second vectors.

[0014] In a third aspect, the present disclosure provides a computer-readable medium having a computer program stored thereon, and when the computer program is executed by a processing device, the steps of the method provided in the first aspect of the present disclosure are implemented.

[0015] In a fourth aspect, the present disclosure provides an electronic device, including:

[0016] a storage device having a computer program stored thereon;

[0017] a processing device configured to execute the computer program in the storage device to implement the steps of the method provided in the first aspect of the present disclosure.

[0018] In a fifth aspect, the present disclosure provides a computer program product including a computer program, and when the computer program is executed by a processor, the steps of the method provided in the first aspect of the present disclosure are implemented.

[0019] In the above technical solution, before performing vector retrieval on the first vector, first, the first vector is linearly transformed by using a first transformation matrix to obtain a first ciphertext vector; then, the first ciphertext vector is sent to a first server, so that the first server retrieves at least one second ciphertext vector similar to the first ciphertext vector from a knowledge vector library, where the ciphertext vectors in the knowledge vector library are obtained by linearly transforming second vectors by using a second transformation matrix, and the second transformation matrix is generated based on a first orthogonal matrix, a second orthogonal matrix, and the second vectors. Since both the first transformation matrix and the second transformation matrix are generated based on the first orthogonal matrix and the second orthogonal matrix, in this way, the distance between different ciphertext vectors in the knowledge vector library can be made close to the distance between the original plaintext vectors, so as to approximately maintain the distance between the plaintext vectors, and the distance between the first ciphertext vector and the ciphertext vectors in the knowledge vector library can be made close to the distance between the original plaintext vectors, so as to approximately maintain the distance between the plaintext vectors. Thus, it is possible to support retrieval on ciphertext vectors like plaintext vectors support retrieval and ensure that the recall rate remains basically unchanged. In addition, encrypting the second vectors in the knowledge vector library by using the second transformation matrix can mask the information of the original plaintext vectors, so that it is possible to resist the vec2text attack in the language model service scenario and avoid the leakage of private data in the knowledge vector library on the premise of supporting vector retrieval. Furthermore, the second transformation matrix used to encrypt the second vectors is dynamically generated according to the second vectors themselves. In this way, different second transformation matrices can be generated for the second vectors corresponding to different knowledge texts, so that the differences in the inner products of the plaintext and ciphertext of different vector pairs in the knowledge vector library are different, thereby significantly reducing the effectiveness of the known plaintext attack.

[0020] Other features and advantages of the present disclosure will be described in detail in the subsequent specific implementation section. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In combination with the accompanying drawings and with reference to the following specific embodiments, the above and other features, advantages and aspects of the various embodiments of the present disclosure will become more apparent. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic and that the original and the elements are not necessarily drawn to scale. In the drawings:

[0022] Figure 1 is a schematic diagram of the process of the retrieval-augmented generation method in the related art.

[0023] Figure 2 is a schematic diagram of the vec2text attack in the related art.

[0024] Figure 3 is a flowchart of a vector retrieval method shown according to an exemplary embodiment.

[0025] Figure 4 is a flowchart of a vector retrieval method shown according to another exemplary embodiment.

[0026] Figure 5 is a block diagram of a vector retrieval device shown according to an exemplary embodiment.

[0027] Figure 6 is a schematic diagram of the structure of an electronic device shown according to an exemplary embodiment. Specific Embodiments

[0028] The embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not used to limit the protection scope of the present disclosure.

[0029] It should be understood that the various steps recited in the method embodiments of the present disclosure can be executed in a different order and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this regard.

[0030] As used herein, the term "including" and its variants are open-ended, i.e., "including but not limited to". The term "based on" is "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description.

[0031] It should be noted that concepts such as "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependent relationships.

[0032] It should be noted that the modifications of "one" and "multiple" mentioned in this disclosure are illustrative rather than restrictive. Those skilled in the art should understand that unless clearly specified otherwise in the context, it should be understood as "one or more".

[0033] The names of the messages or information exchanged between multiple devices in the embodiments of this disclosure are only for illustrative purposes and are not used to limit the scope of these messages or information.

[0034] It can be understood that before using the technical solutions disclosed in the embodiments of this disclosure, the types, usage scopes, usage scenarios, etc. of the personal information involved in this disclosure should be informed to users and the authorization of users should be obtained through appropriate means in accordance with relevant laws and regulations.

[0035] For example, when responding to receiving an active request from a user, a prompt message is sent to the user to clearly prompt the user that the operation requested by the user will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, an application program, a server or a storage medium that performs the operations of the technical solutions of this disclosure according to the prompt message.

[0036] As an optional but non-limiting implementation manner, the manner of sending a prompt message to the user in response to receiving an active request from the user can be, for example, in the form of a pop-up window. The prompt message can be presented in text in the pop-up window. In addition, the pop-up window can also carry selection controls for the user to choose "agree" or "disagree" to provide personal information to the electronic device.

[0037] It can be understood that the above process of notifying and obtaining user authorization is only illustrative and does not limit the implementation manners of this disclosure. Other manners that meet relevant laws and regulations can also be applied to the implementation manners of this disclosure.

[0038] At the same time, it can be understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of corresponding laws, regulations and related regulations.

[0039] In order to protect the embeddings stored in a knowledge vector library (i.e., a vector database) while supporting vector retrieval. In the related art, vector encryption in the knowledge vector library is achieved by means of orthogonal matrix transformation and random noise masking. Although this solution can resist vec2text attacks and take into account the retrieval effect, it cannot resist known plaintext attacks. In a known plaintext attack, the attacker obtains in advance a limited number of <plaintext db_embedding, ciphertext db_embedding> combinations stored in the vector database, and the attacker can use this background knowledge to try to restore the subsequent obtained ciphertext embeddings. Specifically, an effective known plaintext attack process is as follows:

[0040] The attacker pre-obtains M plaintext-ciphertext embeddings <g k ,c k >, k = 1, …, M. First, the attacker calculates the inner product d k = c·c k , k = 1, …, M, where c is the ciphertext embedding to be restored, g k is the k-th plaintext embedding among the M plaintext-ciphertext embeddings, and c k is the ciphertext embedding corresponding to g k ; then, according to an optimal transformation matrix g is fitted as the restored plaintext embedding, that is, the plaintext embedding corresponding to c.

[0041] In view of this, the present disclosure provides a vector retrieval method, apparatus, medium, electronic device, and program product.

[0042] Figure 3 is a flowchart of a vector retrieval method shown according to an exemplary embodiment. As Figure 3 shown, the vector retrieval method may include the following S101 to S103.

[0043] In S101, a first vector corresponding to an input request is obtained, and a first transformation matrix is obtained, where the first transformation matrix is generated based on a first orthogonal matrix and a second orthogonal matrix.

[0044] In the present disclosure, the above vector retrieval method may be applied to a client. The vector retrieval method may be applied to scenarios such as question answering and private cloud computing (PCC).

[0045] For the question-and-answer scenario, the user can initiate an input request to the client. In response to receiving the input request, the client can encode the input request to obtain a first vector corresponding to the input request, where the input request can be a question text. The first transformation matrix can be pre-generated by the client based on a first orthogonal matrix and a second orthogonal matrix.

[0046] Among them, both the first orthogonal matrix and the second orthogonal matrix are d*d square matrices, the first vector is a 1*d row vector, and the dimension of the first transformation matrix is d*2d, where d is the dimension of the first vector and d is a natural number greater than 0. The elements in the first orthogonal matrix and the second orthogonal matrix are random numbers generated with a preset key as the random seed. Specifically, the client can pre-generate the first orthogonal matrix and the second orthogonal matrix in the following manner: generate d*d first random numbers with the preset key as the random seed, and then generate the first orthogonal matrix according to the generated d*d first random numbers; at the same time, generate d*d second random numbers with the preset key as the random seed, and then generate the second orthogonal matrix according to the generated d*d second random numbers.

[0047] In S102, the first vector is linearly transformed using the first transformation matrix to obtain a first ciphertext vector.

[0048] In the present disclosure, the first vector can be encrypted using the first transformation matrix to obtain a ciphertext vector of the first vector, that is, the first ciphertext vector. Specifically, after obtaining the first vector and the first transformation matrix, the product of the first vector and the first transformation matrix can be determined as the first ciphertext vector.

[0049] In S103, the first ciphertext vector is sent to the first server, and the first server is used to retrieve at least one second ciphertext vector similar to the first ciphertext vector from the knowledge vector library. The ciphertext vectors in the knowledge vector library are obtained by linearly transforming the second vector using a second transformation matrix, and the second transformation matrix is generated based on the first orthogonal matrix, the second orthogonal matrix, and the second vector.

[0050] In the present disclosure, the second vector can be a 1*d row vector, that is, the first vector and the second vector have the same dimension, and the dimension of the second transformation matrix is the same as that of the first transformation matrix, which is also d*2d.

[0051] The knowledge vector library is stored on the first server. The knowledge vector library includes multiple ciphertext vectors and the ciphertext text corresponding to each ciphertext vector. Among them, the ciphertext vectors in the knowledge vector library are obtained by the client linearly transforming the second vector based on the second transformation matrix. The second vector can be the vector obtained by the client through word segmentation and encoding of the text in the corpus. The ciphertext text corresponding to the ciphertext vector is obtained by the client performing symmetric encryption on the corresponding text in the corpus. For example, the Advanced Encryption Standard (AES) is used for text encryption. After obtaining the ciphertext vector and its corresponding ciphertext text, the client stores them in the knowledge vector library.

[0052] In addition, the ciphertext vectors in the knowledge vector library can be generated in the following way: First, for each second vector, use the first orthogonal matrix, the second orthogonal matrix, and the second vector to generate the second transformation matrix corresponding to the second vector; then, use the second transformation matrix to linearly transform the second vector; finally, to avoid the influence of the second vector modulus length on the similarity distance during vector retrieval, a normalization operation can be performed on the second vector obtained after the linear transformation to obtain the ciphertext vector of the second vector, that is, the ciphertext vector in the knowledge vector library, so as to ensure the accuracy of vector retrieval.

[0053] In the above technical solution, before performing vector retrieval on the first vector, first perform a linear transformation on the first vector using the first transformation matrix to obtain a first ciphertext vector; then send the first ciphertext vector to the first server so that the first server retrieves at least one second ciphertext vector similar to the first ciphertext vector from the knowledge vector library, where the ciphertext vectors in the knowledge vector library are obtained by performing a linear transformation on the second vector using the second transformation matrix, and the second transformation matrix is generated based on the first orthogonal matrix, the second orthogonal matrix, and the second vector. Since both the first transformation matrix and the second transformation matrix are generated based on the first orthogonal matrix and the second orthogonal matrix, in this way, the distance between different ciphertext vectors in the knowledge vector library can be made close to the distance between the original plaintext vectors, so as to approximately maintain the distance between the plaintext vectors, and the distance between the first ciphertext vector and the ciphertext vectors in the knowledge vector library can be made close to the distance between the original plaintext vectors, so as to approximately maintain the distance between the plaintext vectors. Therefore, it is possible to support retrieval on ciphertext vectors in the same way as plaintext vectors support retrieval and ensure that the recall rate remains basically unchanged. In addition, encrypting the second vector in the knowledge vector library using the second transformation matrix can mask the information of the original plaintext vector, so that it is possible to resist the vec2text attack in the language model service scenario and avoid the leakage of privacy data in the knowledge vector library on the premise of supporting vector retrieval. Furthermore, the second transformation matrix used to encrypt the second vector is dynamically generated according to the second vector itself. In this way, different second transformation matrices can be generated for the second vectors corresponding to different knowledge texts, so that the differences in the inner products of the plaintext and ciphertext of different vector pairs in the knowledge vector library are different, thereby significantly reducing the effectiveness of the known plaintext attack.

[0054] The following will provide a detailed description of the generation method of the above second transformation matrix. Specifically, it can be implemented through the following steps (a1) to (a4):

[0055] Step (a1): For the j-th column element of the second vector, determine the sampling probability of the selection vector corresponding to the j-th column element according to the differential privacy budget and the j-th column element.

[0056] Exemplarily, according to the differential privacy budget and the j-th column element of the second vector, the sampling probability of the selection vector corresponding to the j-th column element of the second vector can be determined through the following equation (1):

[0057]

[0058] where p is the sampling probability of the selection vector corresponding to the j-th column element of the second vector; γ is the sampling threshold of differential privacy; ε is the differential privacy budget; the variable f j is the j-th column element of the second vector.

[0059] Step (a2): Randomly sample a selection vector from a Bernoulli distribution according to the sampling probability.

[0060] Among them, the Bernoulli distribution is a 0-1 distribution, the sampling probability is the probability of sampling 1 from the 0-1 distribution, and the values of the selection vector are 0 or 1.

[0061] Step (a3): Determine the concatenation order of the j-th row of the first orthogonal matrix and the j-th row of the second orthogonal matrix according to the selection vector.

[0062] Specifically, if the selection vector is 1, the concatenation order is that the j-th row of the second orthogonal matrix is concatenated before the j-th row of the first orthogonal matrix; if the selection vector is 0, the concatenation order is that the j-th row of the first orthogonal matrix is concatenated before the j-th row of the second orthogonal matrix.

[0063] Step (a4): Concatenate the j-th row of the first orthogonal matrix and the j-th row of the second orthogonal matrix according to the concatenation order to obtain the j-th row of the second transformation matrix.

[0064] Exemplarily, the second vector is a 1×4 row vector, the second transformation matrix is a 4×8 matrix, the selection vector corresponding to the first column of the second vector is 0, then the concatenation order of the first row of the first orthogonal matrix A and the first row of the second orthogonal matrix B is that the first row of the first orthogonal matrix A is concatenated before the first row of the second orthogonal matrix B. At this time, the first row of the second transformation matrix is "A[1],B[1]"; the selection vector corresponding to the second column of the second vector is 1, then the concatenation order of the second row of the first orthogonal matrix A and the second row of the second orthogonal matrix B is that the second row of the second orthogonal matrix B is concatenated before the second row of the first orthogonal matrix A. At this time, the second row of the second transformation matrix is "B[2],A[2]"; the selection vector corresponding to the third column of the second vector is 1, then the concatenation order of the third row of the first orthogonal matrix A and the third row of the second orthogonal matrix B is that the third row of the second orthogonal matrix B is concatenated before the third row of the first orthogonal matrix A. At this time, the third row of the second transformation matrix is "B[3],A[3]"; the selection vector corresponding to the fourth column of the second vector is 0, then the concatenation order of the fourth row of the first orthogonal matrix A and the fourth row of the second orthogonal matrix B is that the fourth row of the first orthogonal matrix A is concatenated before the fourth row of the second orthogonal matrix B. At this time, the fourth row of the second transformation matrix is "A[4],B[4]". Thus, the second transformation matrix can be obtained. Among them, A[l] is the l-th row of the first orthogonal matrix A, B[l] is the l-th row of the second orthogonal matrix B, and l = 1, 2, 3, 4.

[0065] The following will give a detailed description of the generation method of the above first transformation matrix. Specifically, the first transformation matrix can be generated in the following way:

[0066] Generate a first transformation matrix according to a first orthogonal matrix, a second orthogonal matrix, and a preset matrix through the following equation (2):

[0067]

[0068] where Q is the first transformation matrix; H 2d×d is a preset matrix of 2d*d, and H[i, i] = H[i + d, i] = 1, i = 1, …, d, H[i, i] is the element in the i-th row and i-th column of H 2d×d , and H[i + d, i] is the element in the (i + d)-th row and i-th column of H 2d×d ; all other elements in H 2d×d , except H[i, i] and H[i + d, i], are 0; (H 2d×d ) T is the transpose matrix of H 2d×d ; is the inverse matrix of ; is the transpose matrix of

[0069] To further enhance the privacy of the ciphertext vectors in the knowledge vector library, correspondingly, before linearly transforming the second vector using the second transformation matrix, the second vector can be masked using a random row vector. Specifically, the ciphertext vectors in the knowledge vector library can be generated through the following steps (b1) to (b4).

[0070] Step (b1): Generate a second random row vector.

[0071] where the second random row vector is a 1*d row vector, and the elements in the second random row vector follow a normal distribution, that is, each element in the first random row vector is randomly drawn from a normal distribution with a mean of 0 and a variance of .

[0072] Step (b2): Mask the second vector using the second random row vector to obtain a second masked vector.

[0073] Step (b3): Linearly transform the second masked vector using the second transformation matrix to obtain a third masked vector.

[0074] It can be signed that the product of the second masked vector and the second transformation matrix is determined as the third masked vector.

[0075] Step (b4): Normalize the third masked vector to obtain the ciphertext vector of the second vector.

[0076] In the present disclosure, the second random row vector can be utilized to perform a masking process on the second vector in various ways to obtain a second masked vector.

[0077] In one implementation, the second random row vector can be utilized to perform a masking process on the second vector through the following equation (3) to obtain a second masked vector:

[0078] f′ = f + s (3)

[0079] where f′ is the second masked vector; f is the second vector; and s is the second random row vector.

[0080] In another implementation, the second random row vector can be utilized to perform a masking process on the second vector through the following equation (4) to obtain a second masked vector:

[0081] f′ = f + αs (4)

[0082] where α is a preset masking coefficient.

[0083] In this implementation, the user can control the magnitude of the noise added to the second vector through the preset masking coefficient, and thus can flexibly control the privacy of the ciphertext vectors in the knowledge vector library according to requirements. Among them, the smaller α is, the higher the recall rate of vector retrieval, but the worse the privacy protection of the original vector. The larger α is, the lower the recall rate of vector retrieval, but the better the privacy protection of the original vector. Therefore, by adjusting the magnitude of α, a balance can be achieved between the recall rate of approximate nearest neighbor search and the privacy protection of the original vector.

[0084] Correspondingly, in order to enhance the privacy of the first vector corresponding to the input request, after the first vector is obtained, it can be first masked using a random row vector, and then the masked first vector can be linearly transformed using a first transformation matrix to obtain a first ciphertext vector. Specifically, as Figure 4 shown, before the above S102, the above vector retrieval method may further include the following S104 and S105.

[0085] In S104, a first random row vector is generated.

[0086] In the present disclosure, the first random row vector is a 1*d row vector, and the elements in the first random row vector follow a normal distribution, that is, each element in the first random row vector is randomly drawn from a normal distribution with a mean of 0 and a variance of .

[0087] In S105, the first vector is masked using the first random row vector to obtain a first masked vector.

[0088] At this time, the above S102 may include: linearly transforming the first masking vector by using a first transformation matrix to obtain a first ciphertext vector. That is, determining the product of the first masking vector and the first transformation matrix as the first ciphertext vector.

[0089] In the present disclosure, a first random row vector can be used to perform a masking process on the first vector in various ways to obtain a first masking vector.

[0090] In one implementation, a first random row vector can be used to perform a masking process on the first vector through the following equation (5) to obtain a first masking vector:

[0091] f1′ = f1 + s1 (5)

[0092] Where, f1′ is the first masking vector; f1 is the first vector; s1 is the first random row vector.

[0093] In another implementation, a first random row vector can be used to perform a masking process on the first vector through the following equation (6) to obtain a first masking vector:

[0094] f1′ = f1 + αs1 (6)

[0095] In this implementation, the user can control the magnitude of the noise added to the first vector through a preset masking coefficient, and thus can flexibly control the privacy of the first vector corresponding to the input request according to the needs.

[0096] To ensure the retrieval effect, it is not only necessary to keep the order of the inner product magnitudes between the encrypted db_embedding (i.e., the ciphertext vector of the second vector) almost unchanged, so as to ensure that the process of building the index of the knowledge vector library is not affected, making the distance between different ciphertext vectors in the knowledge vector library close to the distance between the original plaintext vectors to approximately maintain the distance between the plaintext vectors, but also necessary to keep the order of the inner product magnitudes between the encrypted db_embedding (i.e., the ciphertext vector of the second vector) and the encrypted query_embedding (i.e., the first ciphertext vector) almost unchanged, so as to ensure that the comparison result of the inner product magnitudes between the encrypted query_embedding and the encrypted db_embedding during the retrieval process is not affected, making the distance between the first ciphertext vector and the ciphertext vectors in the knowledge vector library close to the distance between the original plaintext vectors to approximately maintain the distance between the plaintext vectors.

[0097] The above implementation provided by the present disclosure for performing a masking process on the second vector and the second vector by using a random vector before linearly transforming the first vector and the second vector can achieve the above retrieval effect, and the specific proof process is as follows:

[0098] For the second vector x and the second vector y, where the ciphertext vector of the second vector x is c x , and the ciphertext vector of the second vector y is c y , then there is an inner product where is the transpose vector of c y , s x is the second random row vector generated when generating the ciphertext vector c x of the second vector x, s y is the second random row vector generated when generating the ciphertext vector c y of the second vector y, K x is the second transformation matrix generated based on the first orthogonal matrix A, the second orthogonal matrix B, and the second vector x, K y is the second transformation matrix generated based on the first orthogonal matrix A, the second orthogonal matrix B, and the second vector y.

[0099] Since A[i]·A[j] = 0, and A[i]·B[j] ≈ 0, therefore, for j = 1, 2, …, d:

[0100] When σ x [i] = σ y [j], K x [i]·K y [j] = 2

[0101] When σ x [i] ≠ σ y [j], K x [i]·K y [j] ≈ 0

[0102] where A[i] is the i-th row of the first orthogonal matrix A, A[j] is the j-th row of the first orthogonal matrix A, B[j] is the j-th row of the second orthogonal matrix B, σ x [i] is the selection vector corresponding to the i-th column element of the second vector x, σ y [j] is the selection vector corresponding to the j-th column element of the second vector y, K x [i] is the i-th row of K x , K y [j] is the j-th row of K y .

[0103] For example, the selection vector σ x corresponding to the second vector x = {0, 0, 1, 0}, and the selection vector σ y corresponding to the second vector y = {0, 1, 1, 0}, then Therefore,

[0104] Among them, 0' represents a number close to 0. is the transpose matrix of K y .

[0105] Since the dimension d is usually large, and s x , s y are randomly selected from the normal distribution. Therefore, s x ·y T ≈ 0, where is the transpose vector of s y , y T is the transpose vector of the second vector y. Therefore,

[0106] For the second vector f and the first vector q, where the ciphertext vector of the second vector f is c f , and the ciphertext vector of the first vector q is c q , then there is an inner product where is the transpose vector of c q , s f is the second random row vector generated when generating the ciphertext vector c f of the second vector f, s q is the first random row vector generated when generating the ciphertext vector c q of the first vector q, K f is the second transformation matrix generated based on the first orthogonal matrix A, the second orthogonal matrix B, and the second vector f, Q T is the transpose matrix of Q.

[0107] Since H 2d×d satisfies H[i, i] = H[i + d, i] = 1, i = 1,..., d, and the remaining elements in H 2d×d except H[i, i] and H[i + d, i] are all 0. Therefore, K f *Q T = I, where I is the unit vector.

[0108] Since the dimension d is usually large, and s f , s q are randomly selected from the normal distribution. Therefore s f ·q T ≈ 0, is the transpose vector of s q , q T is the transpose vector of q. Thus,

[0109] Since the second transformation matrix is dynamically generated according to each DB embedding (the second vector) when encrypting it, for any three DB embeddings x, y, and z to be encrypted, although there is and where is the ciphertext vector c of the second vector z z is the transposed vector of z, and z T is the transposed vector of the second vector z, but due to the different dynamically generated second transformation matrices, the differences in the inner products of the plaintext and ciphertext are different, that is Thus, the effectiveness of the known-plaintext attack is significantly reduced.

[0110] The above implementation manner of directly performing linear transformation on the first vector and the second vector provided by the present disclosure can achieve the above retrieval effect, and the specific proof process is as follows:

[0111] For the second vector x and the second vector y, where the ciphertext vector of the second vector x is c x , and the ciphertext vector of the second vector y is c y , then there is an inner product

[0112] Since and A[i]·B[j]≈0, Therefore, for

[0113] When σ x [i] = σ y [j], K x [i]·K y [j] = 2

[0114] When σ x [i] ≠ σ y [j], K x [i]·K y [j]≈0

[0115] Therefore,

[0116] For the second vector f and the first vector q, where the ciphertext vector of the second vector f is c f , and the ciphertext vector of the first vector q is c q , then there is an inner product Since H 2d×d satisfies H[i,i] = H[i + d,i] = 1, i = 1,…,d, and the remaining elements in H 2d×d except H[i,i] and H[i + d,i] are all 0. Therefore, K f*Q T = I, thus,

[0117] Since the second transformation matrix is dynamically generated according to the second vector itself when encrypting each DB embedding (the second vector). Therefore, for any three DB embeddings x, y, z to be encrypted, although there are and where is the ciphertext vector c of the second vector z z transpose vector of, z T is the transpose vector of the second vector z, but due to the different dynamically generated second transformation matrices, therefore, the differences in the inner products of the plaintext and ciphertext are different, that is Thus, the effectiveness of the known-plaintext attack is significantly reduced.

[0118] When the above vector retrieval method is applied to the client, the first server is also used to obtain the ciphertext texts corresponding to at least one second ciphertext vector and send the at least one ciphertext text to the client; the above vector retrieval method may further include the following four steps:

[0119] In response to receiving the at least one ciphertext text sent by the first server, decrypt the at least one ciphertext text to obtain the plaintext text;

[0120] Concatenate the plaintext text with the input request to obtain a concatenated text;

[0121] Send the concatenated text to the large language model server, where the large language model server is used to generate the response text of the above input request according to the concatenated text and send the response text to the client;

[0122] Receive and display the response text sent by the large language model server.

[0123] In the present disclosure, a large language model is deployed on a large language model server. For a question-and-answer scenario, after the first server retrieves at least one second ciphertext vector similar to the first ciphertext vector from the knowledge vector library, it can obtain the ciphertext corresponding to the at least one second ciphertext vector; then, the first server can send the at least one ciphertext to the client; after receiving the at least one ciphertext sent by the first server, the client decrypts the at least one ciphertext using the encryption key used to generate the ciphertext in the knowledge vector library to obtain the plaintext; next, the first server splices the plaintext with the input request to obtain a spliced text, and sends the spliced text to the large language model server; after receiving the spliced text, the large language model server can generate a response text to the input request through a question-and-answer model (i.e., the large language model) based on the spliced text, and send the response text to the client; after receiving the response text, the client displays the response text.

[0124] Figure 5 is a block diagram of a vector retrieval device shown according to an exemplary embodiment. As Figure 5 shown, the vector retrieval device 200 includes:

[0125] An acquisition module 201, configured to acquire a first vector corresponding to an input request, and acquire a first transformation matrix, where the first transformation matrix is generated based on a first orthogonal matrix and a second orthogonal matrix, and the elements in the first orthogonal matrix and the second orthogonal matrix are random numbers generated with a preset key as a random seed;

[0126] A first linear transformation module 202, configured to perform a linear transformation on the first vector using the first transformation matrix to obtain a first ciphertext vector;

[0127] A first sending module 203, configured to send the first ciphertext vector to a first server, where the first server is configured to retrieve at least one second ciphertext vector similar to the first ciphertext vector from a knowledge vector library; where the ciphertext vectors in the knowledge vector library are obtained by performing a linear transformation on a second vector using a second transformation matrix, and the second transformation matrix is generated based on the first orthogonal matrix, the second orthogonal matrix, and the second vector.

[0128] In the above technical solution, before performing vector retrieval on the first vector, first linearly transform the first vector using the first transformation matrix to obtain the first ciphertext vector; then send the first ciphertext vector to the first server, so that the first server retrieves at least one second ciphertext vector similar to the first ciphertext vector from the knowledge vector library, where the ciphertext vectors in the knowledge vector library are obtained by linearly transforming the second vectors using the second transformation matrix, and the second transformation matrix is generated based on the first orthogonal matrix, the second orthogonal matrix, and the second vector. Since both the first transformation matrix and the second transformation matrix are generated based on the first orthogonal matrix and the second orthogonal matrix, in this way, the distance between different ciphertext vectors in the knowledge vector library can be made close to the distance between the original plaintext vectors, so as to approximately maintain the distance between the plaintext vectors, and the distance between the first ciphertext vector and the ciphertext vectors in the knowledge vector library can be made close to the distance between the original plaintext vectors, so as to approximately maintain the distance between the plaintext vectors. Thus, it is possible to support retrieval on ciphertext vectors in the same way as plaintext vectors support retrieval and ensure that the recall rate remains basically unchanged. In addition, encrypting the second vectors in the knowledge vector library using the second transformation matrix can mask the information of the original plaintext vectors, so that it is possible to resist the vec2text attack in the language model service scenario and avoid the leakage of private data in the knowledge vector library on the premise of supporting vector retrieval. Furthermore, the second transformation matrix used to encrypt the second vectors is dynamically generated according to the second vectors themselves. In this way, different second transformation matrices can be generated for the second vectors corresponding to different knowledge texts, so that the differences in the inner products of the plaintext and ciphertext of different vector pairs in the knowledge vector library are different, thereby significantly reducing the effectiveness of the known plaintext attack.

[0129] Optionally, the second transformation matrix is generated by a first matrix generation device, where the first matrix generation device includes:

[0130] A first determination module, configured to determine the sampling probability of the selection vector corresponding to the j-th column element of the second vector according to the differential privacy budget and the j-th column element, where the second vector is a row vector, j = 1,..., d, d is the dimension of the second vector and d is a natural number greater than 0;

[0131] A sampling module, configured to randomly sample the selection vector from the Bernoulli distribution according to the sampling probability;

[0132] A second determination module, configured to determine the splicing order of the j-th row of the first orthogonal matrix and the j-th row of the second orthogonal matrix according to the selection vector;

[0133] The first splicing module is used to splice the j-th row of the first orthogonal matrix and the j-th row of the second orthogonal matrix according to the splicing order to obtain the j-th row of the second transformation matrix.

[0134] Optionally, the first determination module is used to determine the sampling probability of the selection vector corresponding to the j-th column element according to the differential privacy budget and the j-th column element through the following formula:

[0135]

[0136] where p is the sampling probability; γ is the sampling threshold of differential privacy; ε is the differential privacy budget; the variable f j is the j-th column element.

[0137] Optionally, the second determination module includes:

[0138] The first determination sub-module is used to, if the selection vector is 1, splice the j-th row of the second orthogonal matrix before the j-th row of the first orthogonal matrix in the splicing order;

[0139] The second determination sub-module is used to, if the selection vector is 0, splice the j-th row of the first orthogonal matrix before the j-th row of the second orthogonal matrix in the splicing order.

[0140] Optionally, the first transformation matrix is generated by a second matrix generation device, and the second matrix generation device includes a first generation module. The first generation module is used to generate the first transformation matrix according to the first orthogonal matrix, the second orthogonal matrix, and a preset matrix through the following formula:

[0141]

[0142] where Q is the first transformation matrix; A is the first orthogonal matrix; B is the second orthogonal matrix; H 2d×d is the preset matrix, and H[i, i] = H[i + d, i] = 1, i = 1,..., d, d is the dimension of the second vector and d is a natural number greater than 0, H[i, i] is the element in the i-th row and i-th column of H 2d×d and H[i + d, i] is the element in the (i + d)-th row and i-th column of H 2d×d ; the remaining elements of H 2d×d except H[i, i] and H[i + d, i] are all 0; (H 2d×d ) T is the transpose matrix of H 2d×d ; is 's inverse matrix; is The transposed matrix of

[0143] Optionally, the vector retrieval device 200 further includes:

[0144] A second generation module, configured to generate a first random row vector before the first linear transformation module 202 linearly transforms the first vector by using the first transformation matrix to obtain a first ciphertext vector, where the first random row vector is a 1*d row vector, and the elements in the first random row vector obey a normal distribution, d is the dimension of the second vector, and d is a natural number greater than 0;

[0145] A first masking processing module, configured to mask the first vector by using the first random row vector to obtain a first masked vector;

[0146] The first linear transformation module 202 is configured to linearly transform the first masked vector by using the first transformation matrix to obtain the first ciphertext vector.

[0147] Optionally, the first masking processing module is configured to mask the first vector by using the first random row vector through the following formula to obtain a first masked vector:

[0148] f1′ = f1 + αs1

[0149] where f1′ is the first masked vector; f1 is the first vector; α is a preset masking coefficient; s1 is the first random row vector.

[0150] Optionally, the ciphertext vector in the knowledge vector library is generated by a ciphertext generation device, and the ciphertext generation device includes:

[0151] A third generation module, configured to generate a second random row vector, where the second random row vector is a 1*d row vector, and the elements in the second random row vector obey a normal distribution;

[0152] A second masking processing module, configured to mask the second vector by using the second random row vector to obtain a second masked vector;

[0153] A second linear transformation module, configured to linearly transform the second masked vector by using the second transformation matrix to obtain a third masked vector;

[0154] A normalization processing module, configured to perform normalization processing on the third masked vector to obtain the ciphertext vector of the second vector.

[0155] Optionally, the second masking processing module is configured to use the second random row vector to perform masking processing on the second vector through the following formula to obtain a second masked vector:

[0156] f′ = f + αs

[0157] where f′ is the second masked vector; f is the second vector; α is a preset masking coefficient; and s is the second random row vector.

[0158] Optionally, the vector retrieval device 200 is applied to the client;

[0159] The first server is further configured to obtain ciphertext texts corresponding to at least one of the second ciphertext vectors, and send at least one of the ciphertext texts to the client;

[0160] The vector retrieval device 200 further includes:

[0161] A decryption module, configured to decrypt at least one of the ciphertext texts in response to receiving at least one of the ciphertext texts sent by the first server to obtain plaintext texts;

[0162] A second splicing module, configured to splice the plaintext texts with the input request to obtain a spliced text;

[0163] A second sending module, configured to send the spliced text to a large language model server, and the large language model server is configured to generate a response text for the input request according to the spliced text and send the response text to the client;

[0164] A display module, configured to receive and display the response text sent by the large language model server.

[0165] It should be noted that the above first matrix generation device may be provided independently of the vector retrieval device 200, or may be integrated in the vector retrieval device 200. The above second matrix generation device may be provided independently of the vector retrieval device 200, or may be integrated in the vector retrieval device 200. The above ciphertext generation device may be provided independently of the vector retrieval device 200, or may be integrated in the vector retrieval device 200. The present disclosure does not make specific limitations.

[0166] In addition, the present disclosure further provides a computer-readable medium, on which a computer program is stored, and when the computer program is executed by a processing device, the steps of the above vector retrieval method provided by the present disclosure are implemented.

[0167] Furthermore, the present disclosure further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the above vector retrieval method provided by the present disclosure are implemented.

[0168] Reference is made below to Figure 6 , which shows a schematic structural diagram of an electronic device (such as a terminal device) 600 suitable for implementing the embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 6 The electronic device shown is merely an example and should not impose any limitations on the functions and scope of use of the embodiments of the present disclosure.

[0169] As Figure 6 shown, the electronic device 600 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 601, which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage device 608 into a random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the electronic device 600 are also stored. The processing device 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.

[0170] Generally, the following devices may be connected to the I / O interface 605: an input device 606 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 608 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 609. The communication device 609 may allow the electronic device 600 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 6 the electronic device 600 with various devices is shown, it should be understood that it is not required to implement or include all the shown devices. Instead, more or fewer devices may be implemented or included.

[0171] Specifically, according to the embodiments of the present disclosure, the processes described above with reference to the flowcharts may be implemented as computer software programs. For example, the embodiments of the present disclosure include a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program may be downloaded and installed from a network through the communication device 609, or installed from the storage device 608, or installed from the ROM 602. When the computer program is executed by the processing device 601, the above-mentioned functions defined in the methods of the embodiments of the present disclosure are executed.

[0172] It should be noted that the above-mentioned computer-readable medium in the present disclosure may be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. In the present disclosure, the computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which the computer-readable program code is carried. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable signal medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any suitable medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0173] In some embodiments, the client can communicate using any currently known or future-developed network protocol such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communication in any form or medium (for example, a communication network). Examples of communication networks include local area networks ("LAN"), wide area networks ("WAN"), the Internet (for example, the Internet), and end-to-end networks (for example, ad hoc end-to-end networks), as well as any currently known or future-developed networks.

[0174] The above-mentioned computer-readable medium may be included in the above-mentioned electronic device; or it may exist separately without being assembled into the electronic device.

[0175] The above computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: obtain a first vector corresponding to an input request, and obtain a first transformation matrix, wherein the first transformation matrix is generated based on a first orthogonal matrix and a second orthogonal matrix, and the elements in the first orthogonal matrix and the second orthogonal matrix are random numbers generated with a preset key as a random seed; perform a linear transformation on the first vector by using the first transformation matrix to obtain a first ciphertext vector; send the first ciphertext vector to a first server, wherein the first server is configured to retrieve at least one second ciphertext vector similar to the first ciphertext vector from a knowledge vector library; wherein the ciphertext vectors in the knowledge vector library are obtained by performing a linear transformation on second vectors by using a second transformation matrix, and the second transformation matrix is generated based on the first orthogonal matrix, the second orthogonal matrix, and the second vectors.

[0176] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0177] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that, in some alternative implementations, the functions denoted by the blocks may occur in an order different from that denoted in the drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system that performs the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.

[0178] The modules involved in the embodiments of the present disclosure can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation on the module itself in some cases. For example, the acquisition module can also be described as "the module that acquires the first vector corresponding to the input request and acquires the first transformation matrix".

[0179] The functions described above herein can be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that can be used include: Field Programmable Gate Array (FPGA), Application Specific Integrated Circuit (ASIC), Application Specific Standard Product (ASSP), System on Chip (SOC), Complex Programmable Logic Device (CPLD), and so on.

[0180] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media would include electrical connections based on one or more wires, portable computer disks, hard disks, Random Access Memory (RAM), Read Only Memory (ROM), Erasable Programmable Read Only Memory (EPROM or Flash Memory), optical fibers, portable compact disc read only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0181] According to one or more embodiments of the present disclosure, Example 1 provides a vector retrieval method, including:

[0182] acquiring a first vector corresponding to an input request and acquiring a first transformation matrix, wherein the first transformation matrix is generated based on a first orthogonal matrix and a second orthogonal matrix, and the elements in the first orthogonal matrix and the second orthogonal matrix are random numbers generated with a preset key as a random seed;

[0183] performing a linear transformation on the first vector by using the first transformation matrix to obtain a first ciphertext vector;

[0184] Send the first ciphertext vector to a first server, where the first server is configured to retrieve at least one second ciphertext vector similar to the first ciphertext vector from a knowledge vector library; wherein the ciphertext vectors in the knowledge vector library are obtained by linearly transforming second vectors using a second transformation matrix, and the second transformation matrix is generated based on the first orthogonal matrix, the second orthogonal matrix, and the second vectors.

[0185] According to one or more embodiments of the present disclosure, Example 2 provides the method of Example 1, and the second transformation matrix is generated in the following manner:

[0186] For the j-th column element of the second vector, determine the sampling probability of the selection vector corresponding to the j-th column element according to the differential privacy budget and the j-th column element, where the second vector is a row vector, j = 1, …, d, d is the dimension of the second vector and d is a natural number greater than 0;

[0187] Randomly sample the selection vector from a Bernoulli distribution according to the sampling probability;

[0188] Determine the splicing order of the j-th row of the first orthogonal matrix and the j-th row of the second orthogonal matrix according to the selection vector;

[0189] Splice the j-th row of the first orthogonal matrix and the j-th row of the second orthogonal matrix according to the splicing order to obtain the j-th row of the second transformation matrix.

[0190] According to one or more embodiments of the present disclosure, Example 3 provides the method of Example 2, and determining the sampling probability of the selection vector corresponding to the j-th column element according to the differential privacy budget and the j-th column element includes:

[0191] Determine the sampling probability of the selection vector corresponding to the j-th column element according to the differential privacy budget and the j-th column element through the following formula:

[0192]

[0193] where p is the sampling probability; γ is the sampling threshold of differential privacy; ε is the differential privacy budget; the variable f j is the j-th column element.

[0194] According to one or more embodiments of the present disclosure, Example 4 provides the method of Example 2, and determining the splicing order of the j-th row of the first orthogonal matrix and the j-th row of the second orthogonal matrix according to the selection vector includes:

[0195] If the selection vector is 1, the splicing order is that the j-th row of the second orthogonal matrix is spliced before the j-th row of the first orthogonal matrix;

[0196] If the selection vector is 0, the splicing order is that the j-th row of the first orthogonal matrix is spliced before the j-th row of the second orthogonal matrix.

[0197] According to one or more embodiments of the present disclosure, Example 5 provides the method of Example 1, and the first transformation matrix is generated by the following method:

[0198] According to the first orthogonal matrix, the second orthogonal matrix, and a preset matrix, the first transformation matrix is generated by the following formula:

[0199]

[0200] where Q is the first transformation matrix; A is the first orthogonal matrix; B is the second orthogonal matrix; H 2d×d is the preset matrix, and H[i, i] = H[i + d, i] = 1, i = 1, …, d, d is the dimension of the second vector and d is a natural number greater than 0, H[i, i] is the element at the i-th row and i-th column of H 2d×d and H[i + d, i] is the element at the (i + d)-th row and i-th column of H 2d×d ; all other elements of H 2d×d except H[i, i] and H[i + d, i] are 0; (H 2d×d ) T is the transpose matrix of H 2d×d ; is 's inverse matrix; is 's transpose matrix.

[0201] According to one or more embodiments of the present disclosure, Example 6 provides the method of Example 1. Before the step of linearly transforming the first vector with the first transformation matrix to obtain a first ciphertext vector, the method further includes:

[0202] generating a first random row vector, where the first random row vector is a 1×d row vector and the elements in the first random row vector follow a normal distribution, d is the dimension of the second vector and d is a natural number greater than 0;

[0203] using the first random row vector to perform a masking process on the first vector to obtain a first masked vector;

[0204] The step of linearly transforming the first vector with the first transformation matrix to obtain a first ciphertext vector includes:

[0205] The first masked vector is linearly transformed using the first transformation matrix to obtain the first ciphertext vector.

[0206] According to one or more embodiments of the present disclosure, Example 7 provides the method of Example 6. The masking the first vector using the first random row vector to obtain a first masked vector includes:

[0207] Using the first random row vector, the first vector is masked through the following formula to obtain a first masked vector:

[0208] f1′ = f1 + αs1

[0209] where f1′ is the first masked vector; f1 is the first vector; α is a preset masking coefficient; and s1 is the first random row vector.

[0210] According to one or more embodiments of the present disclosure, Example 8 provides the method of Example 6. The ciphertext vector in the knowledge vector library is generated by the following method:

[0211] Generate a second random row vector, where the second random row vector is a 1*d row vector and the elements in the second random row vector follow a normal distribution;

[0212] Mask the second vector using the second random row vector to obtain a second masked vector;

[0213] Linearly transform the second masked vector using the second transformation matrix to obtain a third masked vector;

[0214] Normalize the third masked vector to obtain the ciphertext vector of the second vector.

[0215] According to one or more embodiments of the present disclosure, Example 9 provides the method of Example 8. The masking the second vector using the second random row vector to obtain a second masked vector includes:

[0216] Using the second random row vector, the second vector is masked through the following formula to obtain a second masked vector:

[0217] f′ = f + αs

[0218] where f′ is the second masked vector; f is the second vector; α is a preset masking coefficient; and s is the second random row vector.

[0219] According to one or more embodiments of the present disclosure, Example 10 provides the method of any one of Examples 1-9, and the method is applied to a client;

[0220] The first server is further configured to obtain ciphertext texts corresponding to at least one of the second ciphertext vectors, and send at least one of the ciphertext texts to the client;

[0221] The method further includes:

[0222] In response to receiving at least one of the ciphertext texts sent by the first server, decrypt at least one of the ciphertext texts to obtain plaintext texts;

[0223] Concatenate the plaintext texts with the input request to obtain a concatenated text;

[0224] Send the concatenated text to a large language model server, and the large language model server is configured to generate a response text for the input request according to the concatenated text, and send the response text to the client;

[0225] Receive and display the response text sent by the large language model server.

[0226] According to one or more embodiments of the present disclosure, Example 11 provides a vector retrieval device, including:

[0227] An acquisition module, configured to acquire a first vector corresponding to an input request, and acquire a first transformation matrix, where the first transformation matrix is generated based on a first orthogonal matrix and a second orthogonal matrix, and elements in the first orthogonal matrix and the second orthogonal matrix are random numbers generated with a preset key as a random seed;

[0228] A first linear transformation module, configured to perform a linear transformation on the first vector by using the first transformation matrix to obtain a first ciphertext vector;

[0229] A first sending module, configured to send the first ciphertext vector to a first server, where the first server is configured to retrieve at least one second ciphertext vector similar to the first ciphertext vector from a knowledge vector library; wherein, the ciphertext vectors in the knowledge vector library are obtained by performing a linear transformation on second vectors by using a second transformation matrix, and the second transformation matrix is generated based on the first orthogonal matrix, the second orthogonal matrix, and the second vectors.

[0230] According to one or more embodiments of the present disclosure, Example 12 provides a computer-readable medium, on which a computer program is stored, and when the computer program is executed by a processing device, the steps of the method of any one of Examples 1-10 are implemented.

[0231] According to one or more embodiments of the present disclosure, Example 13 provides an electronic device, including:

[0232] A storage device on which a computer program is stored;

[0233] A processing device configured to execute the computer program in the storage device to implement the steps of the method according to any one of Examples 1-10.

[0234] According to one or more embodiments of the present disclosure, Example 14 provides a computer program product including a computer program, which when executed by a processor, implements the steps of the method according to any one of Examples 1-10.

[0235] The above description is only a preferred embodiment of the present disclosure and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions disclosed in the present disclosure.

[0236] In addition, although the operations are depicted in a particular order, this should not be construed as requiring that the operations be performed in the particular order shown or in sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, although a number of specific implementation details are included in the above discussion, these should not be construed as limiting the scope of the present disclosure. Certain features described in the context of separate embodiments may also be implemented combinatorially in a single embodiment. Conversely, the various features described in the context of a single embodiment may also be implemented separately or in any suitable sub-combination in multiple embodiments.

[0237] Although the subject matter has been described in language specific to structural features and / or methodological acts, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are merely example forms for implementing the claims. Regarding the device in the above embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method, and will not be elaborated here.

Claims

1. A vector retrieval method, characterized in that, Including: Obtain a first vector corresponding to an input request, and obtain a first transformation matrix, where the first transformation matrix is generated based on a first orthogonal matrix and a second orthogonal matrix, and the elements in the first orthogonal matrix and the second orthogonal matrix are random numbers generated with a preset key as a random seed; Perform a linear transformation on the first vector using the first transformation matrix to obtain a first ciphertext vector; Send the first ciphertext vector to a first server, where the first server is used to retrieve at least one second ciphertext vector similar to the first ciphertext vector from a knowledge vector library; where the ciphertext vectors in the knowledge vector library are obtained by performing a linear transformation on second vectors using a second transformation matrix, and the second transformation matrix is generated based on the first orthogonal matrix, the second orthogonal matrix, and the second vectors.

2. The method according to claim 1, characterized in that The second transformation matrix is generated in the following manner: For the j-th column element of the second vector, determine the sampling probability of the selection vector corresponding to the j-th column element according to the differential privacy budget and the j-th column element, where the second vector is a row vector, j = 1, …, d, d is the dimension of the second vector and d is a natural number greater than 0; Randomly sample the selection vector from the Bernoulli distribution according to the sampling probability; Determine the concatenation order of the j-th row of the first orthogonal matrix and the j-th row of the second orthogonal matrix according to the selection vector; Concatenate the j-th row of the first orthogonal matrix and the j-th row of the second orthogonal matrix in accordance with the concatenation order to obtain the j-th row of the second transformation matrix.

3. The method according to claim 2, wherein The determining the sampling probability of the selection vector corresponding to the j-th column element according to the differential privacy budget and the j-th column element includes: Determine the sampling probability of the selection vector corresponding to the j-th column element according to the differential privacy budget and the j-th column element through the following formula: where p is the sampling probability; γ is the sampling threshold of differential privacy; ε is the differential privacy budget; the variable 4. The method according to claim 2, wherein The determining the concatenation order of the j-th row of the first orthogonal matrix and the j-th row of the second orthogonal matrix according to the selection vector includes: If the selection vector is 1, the concatenation order is that the j-th row of the second orthogonal matrix is concatenated before the j-th row of the first orthogonal matrix; If the selection vector is 0, the concatenation order is that the j-th row of the first orthogonal matrix is concatenated before the j-th row of the second orthogonal matrix.

5. The method according to claim 1, wherein The first transformation matrix is generated in the following manner: Generate the first transformation matrix according to the first orthogonal matrix, the second orthogonal matrix, and a preset matrix through the following formula: Wherein, Q is the first transformation matrix; A is the first orthogonal matrix; B is the second orthogonal matrix; H 2d×d is the preset matrix, and H[i,i] = H[i+d,i] = 1, i = 1, …, d, where d is the dimension of the second vector and d is a natural number greater than 0, H[i,i] is the element in the i-th row and i-th column of H 2d×d , and H[i+d,i] is the element in the (i+d)-th row and i-th column of H 2d×d ; the remaining elements in H2d × d except H[i,i] and H[i+d,i] are all 0; (H 2d×d ) T is the transpose matrix of H2d × d; is the inverse matrix of ; the transpose matrix of 6. The method according to claim 1, wherein Before the step of performing a linear transformation on the first vector using the first transformation matrix to obtain a first ciphertext vector, the method further includes: Generate a first random row vector, where the first random row vector is a 1*d row vector, and the elements in the first random row vector follow a normal distribution, d is the dimension of the second vector and d is a natural number greater than 0; Perform a masking process on the first vector using the first random row vector to obtain a first masked vector; The performing a linear transformation on the first vector using the first transformation matrix to obtain a first ciphertext vector includes: Perform a linear transformation on the first masked vector using the first transformation matrix to obtain the first ciphertext vector.

7. The method according to claim 6, wherein Performing a masking process on the first vector using the first random row vector to obtain a first masked vector, includes: Performing a masking process on the first vector using the first random row vector according to the following formula to obtain a first masked vector: f1′ = f1 + αs1 Where f1′ is the first masked vector; f1 is the first vector; α is a preset masking coefficient; s1 is the first random row vector.

8. The method according to claim 6, characterized in that, The ciphertext vectors in the knowledge vector library are generated in the following manner: Generate a second random row vector, where the second random row vector is a 1*d row vector and the elements in the second random row vector follow a normal distribution; Performing a masking process on the second vector using the second random row vector to obtain a second masked vector; Performing a linear transformation on the second masked vector using the second transformation matrix to obtain a third masked vector; Performing a normalization process on the third masked vector to obtain the ciphertext vector of the second vector.

9. The method according to claim 8, wherein Performing a masking process on the second vector using the second random row vector to obtain a second masked vector, includes: Performing a masking process on the second vector using the second random row vector according to the following formula to obtain a second masked vector: f′ = f + αs Where f′ is the second masked vector; f is the second vector; α is a preset masking coefficient; s is the second random row vector.

10. The method according to any one of claims 1-9, characterized in that, The method is applied to a client; The first server is further configured to obtain at least one ciphertext text corresponding to the second ciphertext vector, and send at least one ciphertext text to the client; The method further includes: In response to receiving at least one ciphertext text sent by the first server, decrypting at least one ciphertext text to obtain a plaintext text; Concatenating the plaintext text with the input request to obtain a concatenated text; Sending the concatenated text to a large language model server, where the large language model server is configured to generate a response text for the input request according to the concatenated text, and send the response text to the client; Receiving and displaying the response text sent by the large language model server.

11. A vector retrieval device, characterized in that, Includes: An acquisition module, configured to acquire a first vector corresponding to an input request, and acquire a first transformation matrix, where the first transformation matrix is generated based on a first orthogonal matrix and a second orthogonal matrix, and the elements in the first orthogonal matrix and the second orthogonal matrix are random numbers generated with a preset key as a random seed; A first linear transformation module, configured to perform a linear transformation on the first vector using the first transformation matrix to obtain a first ciphertext vector; A first sending module, configured to send the first ciphertext vector to a first server, where the first server is configured to retrieve at least one second ciphertext vector similar to the first ciphertext vector from a knowledge vector library; where the ciphertext vectors in the knowledge vector library are obtained by performing a linear transformation on a second vector using a second transformation matrix, and the second transformation matrix is generated based on the first orthogonal matrix, the second orthogonal matrix, and the second vector.

12. A computer-readable medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processing device, it implements the steps of the method according to any one of claims 1-10.

13. An electronic device, characterized in that, Includes: A storage device, on which a computer program is stored; A processing device for executing the computer program in the storage device to implement the steps of the method according to any one of claims 1-10.

14. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1-10 are implemented.