Privacy protection decision tree model reasoning method and system based on partial homomorphic encryption

Through partial homomorphic encryption and secure multi-party computing technology, the calculation and communication bottlenecks of performance-constrained devices in decision tree model inference are solved, and efficient privacy protection decision tree model evaluation is achieved.

CN120297413APending Publication Date: 2025-07-11SHANDONG UNIV
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510367020.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

When the client is a performance-constrained device, there are problems with high computational and communication costs in the inference process of traditional decision tree model, especially in the feature selection and decision tree reasoning stages, and it is difficult for the prior art to complete the model inference task within constant rounds.

Method used

The privacy protection decision tree model reasoning method based on partial homomorphic encryption is adopted, combined with secure multi-party computing technology, and only allows participants to store node information related to the current split or classification. The threshold comparison is optimized through partial homomorphic encryption technology, which reduces communication costs and calculation overhead, and uses random arrangements and secret sharing matrices for data processing.

Benefits of technology

It effectively reduces the computing burden and communication overhead of the client, realizes decision tree model evaluation within constant rounds, and improves the efficiency of model inference and privacy protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120297413A_ABST
    Figure CN120297413A_ABST
Patent Text Reader

Abstract

The invention provides a privacy protection decision tree model reasoning method based on partial homomorphic encryption, and relates to the technical field of data privacy protection, and the method comprises the steps: obtaining to-be-predicted sample data, carrying out the preprocessing of each participant, and converting a ciphertext permutation matrix into a secret share matrix; performing bit decomposition on the to-be-predicted sample data to obtain a decomposition matrix, selecting an input sharing mode of the decomposition matrix according to the source of the to-be-predicted sample data, and then converting the input obtained decomposition matrix into a secret sharing share form; each participant performs comparative calculation by using the secret sharing share and the threshold share, evaluates Boolean functions of all leaf nodes to obtain indication result vectors, and randomly arranges the indication result vectors by using a secret share matrix to generate comparative result shares; and each participant constructs a vector pointing to a prediction output leaf node by using the comparison result share to obtain a prediction result, and outputs the prediction result to the sample data provider according to the to-be-predicted sample data source.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of data privacy protection, and particularly to a privacy protection decision tree model inference method and system based on partial homomorphic encryption. Background Art

[0002] The statements in this part merely provide background technical information related to the present disclosure and do not necessarily constitute prior art.

[0003] With the increase in the cost of model training due to the lack of data samples required for model training and the insufficient hardware computing power in the single-machine case, more and more organizations, enterprises or government agencies tend to cooperate and share sample data and computing resources. When the training sample data contains sensitive information, how to protect the security of privacy data has become a concern and worry of all participating parties. The concept of federated learning was thus proposed, which allows multiple participating parties to train a shared global model without directly uploading local data.

[0004] The decision tree model is composed of nodes, and its overall structure is an inverted tree shape; different nodes may be stored in different participating parties, which is determined by the training algorithm. Nodes can be divided into internal nodes and leaf nodes: internal nodes mainly store information related to splitting, such as features, threshold information, etc., and determine the direction of the decision path in the tree model; while leaf nodes mainly store information related to classification and regression, such as categories, weights, etc., and determine the final output result of the model. The training of the decision tree model is often carried out by recursively dividing the subset of sample data according to different algorithm metrics, and this metric is jointly determined by each participating party by continuously exchanging data. The privacy protection decision tree model training method needs to ensure that in the case of collusion among some participating parties, the privacy information of other participating parties cannot be deduced, and this method is generally achieved by encrypting the splitting information in the nodes and the data related to classification or regression in the leaf nodes. In addition, the privacy protection decision tree model inference still needs to ensure the privacy security of user sample data.

[0005] The privacy protection decision tree model inference process can be divided into three stages: feature selection, threshold comparison, and decision tree evaluation. In the feature selection stage, a mapping from the features of the input sample to the features of the internal nodes of the decision tree is established through the interaction between the user and the server; in the threshold comparison stage, the server compares the input sample features with the corresponding thresholds according to the mapping in the feature selection stage; the decision tree evaluation node evaluates the decision tree model according to the comparison result tree in the threshold comparison stage through the interaction between the user and the server and generates the final prediction output. Generally, privacy protection can be achieved by using existing two-party secure computing, but its communication cost and computing overhead are relatively large and the user needs to undertake certain computing tasks, making it difficult to complete the inference task within a constant number of rounds.

[0006] Currently, traditional model inference requires the client to interact with the server and participate in a large amount of computation during the feature selection phase and the decision tree inference phase. The existing problems are as follows:

[0007] 1) When the client is a performance-limited device, the interaction between the client and the server and the participation in a large amount of computation during the feature selection phase and the decision tree inference phase will become a bottleneck in the model inference process;

[0008] 2) The data interaction with the server will increase the communication cost of the client during model inference. The inference process of the decision tree model needs to process the comparison operation between the sample data input by the client and the threshold information of its internal nodes. In this process, in order to achieve privacy protection and the comparison operation, it is necessary to use the fully homomorphic encryption technology that supports multiplication between ciphertexts to encrypt the user input and the threshold information of the internal nodes. This operation requires high computational overhead. Summary of the Invention

[0009] To solve the above problems, the present disclosure proposes a privacy protection decision tree model inference method and system based on partial homomorphic encryption. For the scenario where multiple parties participate in model deployment, the secure multi-party computing technology is applied in combination with the partial homomorphic encryption technology to reduce the difficulty of decision tree model inference. That is, during the model training process, only the parties related to the current split or classification hold the corresponding node information, and other parties only store empty nodes to maintain the model structure, and the threshold comparison is optimized in different situations, thereby reducing the communication cost and computational overhead.

[0010] According to some embodiments, the present disclosure adopts the following technical solutions:

[0011] A privacy protection decision tree model inference method based on partial homomorphic encryption, including:

[0012] Obtain the sample data to be predicted. Each party performs preprocessing, and uses the partial homomorphic encryption method to jointly generate a randomly permuted ciphertext permutation matrix, and convert the ciphertext permutation matrix into a secret share matrix;

[0013] Perform bit decomposition on the sample data to be predicted to obtain a decomposition matrix. Select the input sharing method of the decomposition matrix according to the source of the sample data to be predicted, and then convert the obtained input decomposition matrix into the form of secret sharing shares;

[0014] Each party uses the secret sharing shares and the threshold shares to perform comparison calculations, and evaluates the Boolean functions of all leaf nodes to obtain an indication result vector, and randomly permutes the indication result vector using the secret share matrix to generate comparison result shares;

[0015] Each participating party constructs a vector pointing to the predicted output leaf node using the comparison result share, obtains the prediction result, and outputs the prediction result to the sample data provider again according to the source of the sample data to be predicted.

[0016] According to some embodiments, the present disclosure adopts the following technical solutions:

[0017] A privacy-preserving decision tree model inference system based on partial homomorphic encryption, including:

[0018] A preprocessing module, configured to obtain the sample data to be predicted, perform preprocessing by each participating party, jointly generate a ciphertext permutation matrix with a random permutation using a partial homomorphic encryption method, and convert the ciphertext permutation matrix into a secret share matrix;

[0019] A threshold comparison module, configured to perform bit decomposition on the sample data to be predicted to obtain a decomposition matrix, select an input sharing method for the decomposition matrix according to the source of the sample data to be predicted, and then convert the obtained input decomposition matrix into the form of secret sharing shares;

[0020] A decision prediction module, configured to perform comparison calculations by each participating party using the secret sharing shares and the threshold shares, and evaluate the Boolean function of all leaf nodes to obtain an indication result vector, and randomly permute the indication result vector using the secret share matrix to generate a comparison result share;

[0021] A decision output module, configured to construct a vector pointing to the predicted output leaf node by each participating party using the comparison result share, obtain the prediction result, and output the prediction result to the sample data provider again according to the source of the sample data to be predicted.

[0022] According to some embodiments, the present disclosure adopts the following technical solutions:

[0023] A computer program product, including a computer program, where when the computer program is executed by a processor, it implements the privacy-preserving decision tree model inference method based on partial homomorphic encryption.

[0024] According to some embodiments, the present disclosure adopts the following technical solutions:

[0025] A non-transitory computer-readable storage medium, where the non-transitory computer-readable storage medium is used to store computer instructions, and when the computer instructions are executed by a processor, it implements the privacy-preserving decision tree model inference method based on partial homomorphic encryption.

[0026] According to some embodiments, the present disclosure adopts the following technical solutions:

[0027] An electronic device, comprising: a processor, a memory, and a computer program; wherein, the processor is connected to the memory, the computer program is stored in the memory, and when the electronic device runs, the processor executes the computer program stored in the memory so that the electronic device executes the privacy-preserving decision tree model inference method based on partial homomorphic encryption as described above.

[0028] Compared with the prior art, the beneficial effects of the present disclosure are as follows:

[0029] The privacy-preserving decision tree model inference method based on partial homomorphic encryption of the present disclosure uses the secure multi-party computing method to eliminate the requirement for relying on the computing power of the client in the decision tree model evaluation process in the traditional client-server mode, thereby avoiding the computing power of the client from becoming a bottleneck in model evaluation, reducing the communication overhead of the client, and considering the processing of sample data from different sources.

[0030] The privacy-preserving decision tree model inference method based on partial homomorphic encryption of the present disclosure does not use the fully homomorphic technology and the comparison protocol purely based on secure multi-party, but provides a simpler and lower communication overhead secure comparison scheme by combining the partial homomorphic encryption technology and the relevant technology and mathematical properties of secure multi-party.

[0031] The privacy-preserving decision tree model inference method based on partial homomorphic encryption of the present disclosure provides a method for evaluating the decision tree model with constant rounds by using the properties of the comparison results between the internal nodes of the decision tree model and the input, and encoding the leaf nodes by using the Lagrange polynomial interpolation method; the construction of the present disclosure depends on the input-independent randomness, so the existing preprocessing technology can be fully utilized to improve the efficiency of model evaluation. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] The accompanying drawings forming a part of the present disclosure are used to provide a further understanding of the present disclosure. The schematic embodiments and descriptions thereof of the present disclosure are used to explain the present disclosure and do not constitute an improper limitation to the present disclosure.

[0033] Figure 1 It is a system architecture diagram of an embodiment of the present disclosure;

[0034] Figure 2 It is a decision tree model inference flow chart of an embodiment of the present disclosure;

[0035] Figure 3 It is a schematic diagram of the principle of the comparison method of an embodiment of the present disclosure;

[0036] Figure 4 It is a schematic diagram of the principle of constructing the decision tree model inference indication vector of an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0037] The present disclosure will be further described below in conjunction with the accompanying drawings and embodiments.

[0038] It should be noted that the following detailed description is exemplary and is intended to provide further explanation of the present disclosure. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present disclosure belongs.

[0039] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present disclosure. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.

[0040] Embodiment 1

[0041] The privacy-preserving decision tree model inference method based on partial homomorphic encryption of the present disclosure is applicable to the scenario where the decision tree model is stored in multiple model training participants, that is, during the model training process, only the participants related to the current split or classification store the corresponding node information, and other participants only store empty nodes to maintain the model structure. The present disclosure considers two cases of decision tree models: 1) The data of the sample to be predicted is held by each training participant; 2) The data of the sample to be predicted is provided encrypted by other users, and this user only has a secure communication channel with the active participant. The specific steps are as follows: Step 1: Obtain the data of the sample to be predicted. Each participant performs preprocessing, and uses the partial homomorphic encryption method to jointly generate a ciphertext permutation matrix in random permutation, and convert the ciphertext permutation matrix into a secret share matrix.

[0042] Step 2: Perform bit decomposition on the data of the sample to be predicted to obtain a decomposition matrix. Select the input sharing method of the decomposition matrix according to the source of the data of the sample to be predicted, and then convert the obtained input decomposition matrix into the form of secret sharing shares.

[0043] Step 3: Each participant uses the secret sharing shares and threshold shares to perform comparison calculations, and evaluates the Boolean functions of all leaf nodes to obtain an indication result vector. Use the secret share matrix to randomly permute the indication result vector to generate comparison result shares.

[0044] Step 4: Each participant uses the comparison result shares to construct a vector pointing to the predicted output leaf node to obtain a prediction result, and then outputs the prediction result to the sample data provider again according to the source of the data of the sample to be predicted.

[0045] Step 5: Each participant uses the comparison result shares to construct a vector pointing to the predicted output leaf node to obtain a prediction result, and then outputs the prediction result to the sample data provider again according to the source of the data of the sample to be predicted.

[0046] As an embodiment, for the privacy-preserving decision tree model inference method based on partial homomorphic encryption of the present disclosure, the solution of the present disclosure uses (T, M)-thresholded partial homomorphic Paillier encryption and secure multi-party computation based on secret sharing as technical support and sets the threshold value T to M, that is, correct decryption requires all participating parties to complete together. It is characterized in that:

[0047] 1) Each participating party realizes the conversion of the node information in the tree model from ciphertext to password sharing shares to fill its empty nodes;

[0048] 2) Based on feature 1), the comparison protocol executed in the threshold comparison stage is designed as a preprocessing stage and a secure comparison stage to amortize the overhead caused by directly using the corresponding secure multi-party computation technology;

[0049] 3) Provide a constant-round decision tree evaluation method at the cost of sacrificing additional space and communication overhead.

[0050] Now assume that [n] represents {0,..., n - 1}; for Fixed-point numbers are represented using l bits; the non-participating user is The sample data to be predicted held is x = (x0,..., x n-1 ), which are sample feature values; the tree model structure is where are internal nodes, storing the index of the splitting feature and the corresponding splitting threshold are leaf nodes, storing classification label information or regression weight information Each training participating party is where is the active participating party, and the others are passive participating parties; The nodes in are stored in the i server; each participating party holds the public key PK and its private key SK ; the non-user participating parties hold the public key and its private key

[0051] The sample features and the node features have been de-privatized and the matching has been completed (which can be done through a hash function). The specific process of the privacy-preserving decision tree model inference method based on partial homomorphic encryption of the present disclosure is as follows:

[0052] Specifically, step 1.1: The active participating party Construct the identity matrix \(E\). l×l And pack the elements of the identity matrix column by column into a single plaintext space, that is where and the selection of offset should be at least consistent with the bit size of the modulus used in secure multi-party computation; then Use the public key \(PK\) to encrypt each of them to obtain the corresponding ciphertext set Without considering the case of overflowing the plaintext space. When overflow occurs, we can pack and encrypt this column vector in multiple plaintexts.

[0053] Step 1.2: The participating parties Generate a random permutation sequence \(\pi\) of \(\{0, \ldots, l - 1\}\) locally i and rearrange the ciphertexts in according to this sequence, that is Then, the participating parties need to use the partially homomorphic property to refresh the ciphertext values while keeping the plaintext unchanged, that is Finally, the participating parties Forward to the participating party

[0054] Step 1.3: Each participating party executes Step 1.2 in turn, that is By Broadcast the final permutation matrix to the other participating parties.

[0055] Step 1.4: The participating party Randomly generate a mask matrix \(Mask\) i l×l And pack the column vectors of this matrix in the way described in 1.1; then, encrypt it using the public key \(PK\) to obtain Each participating party Calculate And forward it to Calculate And complete decryption and unpacking under its coordination to obtain the masked random permutation matrix \(P\) * ; then Calculate 0 is P * - Mask0, Calculate i For - Mask i 。

[0056] Step 2: Input stage of the sample data to be predicted. The execution of this stage depends on the source of the sample data to be predicted: 1) If the sample data is from a certain participating party, it can use the zero - sum masking technology to share the input without interaction; 2) If the sample data is from other non - participating parties, it encrypts its input using the public keys of each participating party and sends it to the active participating party; then, each participating party converts this input into the form of secret - sharing shares. The sample data from any of the above sources needs to perform bit - decomposition on its input as the final input before input; in addition, non - participating parties can pack their multiple input bits into a single plaintext space and then encrypt them to reduce communication overhead.

[0057] Specifically, Step 2.1: First, perform bit - decomposition on the input sample data, that is, convert x=(x0,...,x n-1 ) into x n×l , where the row vector x[i] of x satisfies

[0058] Furthermore, if the sample data to be predicted is from a certain participating party it can use the existing zero - sum masking technology to convert the decomposition matrix x into its secret - sharing form <x>, each participating party holds <x> i 。

[0059] Furthermore, if the sample data to be predicted is from a non-participating party it needs to pack its decomposition matrix in the manner described in Step 1.1 and encrypt it using the public key PK to obtain Then, forward it to the participating party

[0060] In Step 2.2, each participating party converts the encrypted decomposition matrix into its secret sharing form <x>, each participating party holds <x> i 。

[0061] Step 3: Threshold comparison phase. In this phase, each party calculates corresponding statistical information using the shares of the sample input and the threshold share as inputs, such as the Hamming distance between the two inputs at the i-th bit and the indication result vector based on this distance; if and only if there is a 0 in this vector, it indicates that the input sample is less than the threshold information. This indication result vector will directly expose the comparison result of the two inputs and their difference positions. Each party needs to randomly permute this indication result vector using the ciphertext permutation matrix generated in the preprocessing phase; in addition, each party generates a random bit, which controls whether to swap the positions of the inputs to randomize the comparison result. Finally, each party uses this random bit to derandomize the comparison result to obtain the correct comparison result share.

[0062] Specifically, assume that when the sample data input to be compared and the threshold information are <α> = (<α0>, <α1>,..., <α l-1 >) and <β> = (<β0>, <β1>,..., <β l-1 >), specifically as follows:

[0063] Step 3.1: Each party P i randomly generates a secret-sharing bit and random secret sharing vectors <r> =(<r -1 >, <r0>,...,<r l-1 >), each participant holds i and <r> i 。

[0064] Step 3.2: Each participant Calculate Wherein

[0065] Step 3.3: Each participant Calculate the vector <c> =(<c -1 >, <c0>,...,<c l-1 >), where and

[0066] Step 3.4: Each participating party to <c>The elements of are randomly permuted column by column, that is

[0067] Step 3.5: Each participant Discloses <c * > and checks whether there exists an i ∈ {-1} ∪ [l] such that Is 0: If so, each participant Sets <result> ←1- ; Otherwise, set <result> ← 。

[0068] Step 3.6: Each participant parallelly or hierarchically according to the tree structure, perform Steps 3.1 to 3.6 on all internal nodes in the decision tree model and the corresponding inputs to obtain all comparison result shares

[0069] Step 4: Decision tree evaluation phase. In this phase, each participant constructs a vector pointing to the final output leaf node using the comparison results in Step 3. First, each participant initializes the label of the root node of the decision tree model to 1; then recursively updates the label of the current node using the label of the parent node and the comparison results in Step 3 until reaching the leaf node; finally, calculate the inner product of the vector composed of leaf node information and this indicator vector to obtain the prediction result.

[0070] The specific steps of Step 4 are as follows:

[0071] Step 4.1: Each participant locally calculates the sum of the comparison information of the internal nodes on each path from the root node to the leaf node in the decision tree model, that is j ∈ [t]; then, calculate where node the height of the decision tree at the location.

[0072] Step 4.2: Each participant for each calculate that is and where is a random secret share and each participant P i publicly

[0073] Step 4.3: Each participant uses the Lagrange interpolation method to define a Boolean function such that each participant can calculate Thus, each participant can construct an indicator vector and calculate the final result as

[0074] Step 5: Decision Output Phase. In this phase, each participating party outputs the prediction result to the sample data provider: 1) If the sample is from a certain participating party, this participating party only needs to collect the prediction results from other participating parties and reconstruct them; 2) If the sample is from a non-participating party Each participating party needs to use the public key of this user to encrypt its share and send it to the active participating party which forwards the encrypted share

[0075] Specifically, if the sample data is from a certain participating party then the other participating parties only need to send their shares to who reconstructs them, that is

[0076] Furthermore, if the sample data is from a non-participating party the participating party needs to use the user's public key to encrypt its share, that is and forward it to who calculates and forwards it to the user The user uses its private key to decrypt to obtain the final model output output

[0077] Embodiment 2

[0078] In an embodiment of the present disclosure, a privacy-preserving decision tree model inference system based on partial homomorphic encryption is provided, including:

[0079] A preprocessing module, configured to obtain the sample data to be predicted. Each participating party performs preprocessing, and uses the partial homomorphic encryption method to jointly generate a randomly permuted ciphertext permutation matrix, and converts the ciphertext permutation matrix into a secret share matrix;

[0080] A threshold comparison module, configured to perform bit decomposition on the sample data to be predicted to obtain a decomposition matrix, select the input sharing method of the decomposition matrix according to the source of the sample data to be predicted, and then convert the obtained input decomposition matrix into the form of secret sharing shares;

[0081] A decision prediction module, configured to perform comparison calculations by each participating party using the secret sharing shares and the threshold shares, and evaluate the Boolean functions of all leaf nodes to obtain an indication result vector, and randomly permute the indication result vector using the secret share matrix to generate a comparison result share;

[0082] A decision output module for each participant to construct a vector pointing to the predicted output leaf node using the comparison result share, obtain the prediction result, and then output the prediction result to the sample data provider according to the source of the sample data to be predicted.

[0083] Embodiment 3

[0084] In an embodiment of the present disclosure, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the privacy protection decision tree model inference method based on partial homomorphic encryption is implemented.

[0085] Embodiment 4

[0086] In an embodiment of the present disclosure, a non-transitory computer-readable storage medium is provided, and the non-transitory computer-readable storage medium is used to store computer instructions, and when the computer instructions are executed by a processor, the privacy protection decision tree model inference method based on partial homomorphic encryption is implemented.

[0087] Embodiment 5

[0088] In an embodiment of the present disclosure, an electronic device is provided, including: a processor, a memory, and a computer program; wherein, the processor is connected to the memory, the computer program is stored in the memory, and when the electronic device runs, the processor executes the computer program stored in the memory so that the electronic device executes the privacy protection decision tree model inference method based on partial homomorphic encryption.

[0089] The present disclosure is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present disclosure. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the specified function in one or more flows and / or blocks. Figure 1 one or more flows and / or blocks Figure 1 in one or more blocks.

[0090] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for realizing the specified function in one or more flows and / or blocks. Figure 1 one or more flows and / or blocks Figure 1 in one or more blocks.

[0091] Although the specific embodiments of the present disclosure have been described above in conjunction with the accompanying drawings, they are not intended to limit the scope of protection of the present disclosure. Those skilled in the art should understand that, based on the technical solutions of the present disclosure, various modifications or variations that can be made by those skilled in the art without creative efforts are still within the scope of protection of the present disclosure. < / result> < / result> < / c> < / c> < / r> < / r> < / x> < / x> < / x> < / x>

Claims

1. A privacy-preserving decision tree model inference method based on partial homomorphic encryption, characterized in that Including: Obtain the sample data to be predicted. Each participating party performs preprocessing, and uses the partially homomorphic encryption method to jointly generate a ciphertext permutation matrix with a random permutation, and converts the ciphertext permutation matrix into a secret share matrix; Perform bit decomposition on the sample data to be predicted to obtain a decomposition matrix. Select the input sharing method of the decomposition matrix according to the source of the sample data to be predicted, and then convert the obtained decomposition matrix into the form of secret sharing shares; Each participating party uses the secret sharing shares and threshold shares to perform comparison calculations, and evaluates the Boolean function of all leaf nodes to obtain an indication result vector. Use the secret share matrix to randomly permute the indication result vector to generate comparison result shares; Each participating party uses the comparison result shares to construct a vector pointing to the predicted output leaf node to obtain the prediction result, and then outputs the prediction result to the sample data provider again according to the source of the sample data to be predicted.

2. The privacy-preserving decision tree model inference method based on partial homomorphic encryption according to claim 1, wherein, Each participating party performs preprocessing, and uses the partially homomorphic encryption method to jointly generate a ciphertext permutation matrix with a random permutation, and converting the ciphertext permutation matrix into a secret share matrix includes: The active participating party constructs an identity matrix and packs the elements of the identity matrix into a single plaintext space column by column, and then encrypts them respectively using the public key to obtain the corresponding ciphertext set; The participating party generates a random permutation sequence locally and rearranges the ciphertexts in the ciphertext set according to the random permutation sequence. Then, the participating party uses the partially homomorphic property to refresh the ciphertext value while keeping the plaintext unchanged, and finally broadcasts the final permutation matrix to other participating parties. The participating party randomly generates a mask matrix and packs the column vectors of the mask matrix; Then use the public key to encrypt. Finally, each participating party completes decryption under coordination and obtains a masked random permutation matrix, and converts it into a secret share matrix.

3. The privacy-preserving decision tree model inference method based on partial homomorphic encryption according to claim 1, wherein Select the input sharing method of the decomposition matrix according to the source of the sample data to be predicted, including: If the sample data to be predicted comes from a certain participating party, it uses the existing zero-sum masking technology to convert the decomposition matrix into its secret sharing form, which each participating party holds; If the sample data to be predicted comes from a non-participating party, it needs to pack its decomposition matrix and encrypt it using the public key; Then, forward the encrypted ciphertext to the participating party.

4. The privacy-preserving decision tree model inference method based on partial homomorphic encryption according to claim 1, wherein Each participating party uses the secret sharing shares and threshold shares for comparison calculations, evaluates the Boolean functions of all leaf nodes to obtain an indication result vector, and randomly permutes the indication result vector using the secret share matrix to generate comparison result shares, including: Each participating party constructs a vector pointing to the predicted output leaf node using the comparison result shares to obtain a prediction result, and then outputs the prediction result to the sample data provider according to the source of the sample data to be predicted, including: Each participating party randomly generates secret sharing bits and a random secret sharing vector, calculates the corresponding statistical information using the shares of the sample data to be predicted input and the threshold shares as inputs, and based on the Hamming distance between the two inputs and the indication result vector based on this Hamming distance; When and only when there is a 0 in the indication result vector, it indicates that the input sample data to be predicted is less than the threshold information, and each participating party needs to randomly permute this vector using the permutation matrix generated in the preprocessing stage; Each participating party generates random bits, and these random bits control whether to exchange the positions of the inputs to randomize the comparison result; Finally, each participating party uses the random bits to derandomize the comparison result to obtain the correct comparison result shares.

5. The privacy-preserving decision tree model inference method based on partial homomorphic encryption according to claim 1, wherein Each participating party constructs a vector pointing to the predicted output leaf node using the comparison result shares to obtain a prediction result, and then outputs the prediction result to the sample data provider according to the source of the sample data to be predicted, including: Each participating party constructs a vector pointing to the final output leaf node using the comparison result shares. First, each participating party initializes the label of the root node of the decision tree model to 1; Then recursively update the label of the current node using the label of the parent node and the comparison result shares until the leaf node; Finally, calculate the inner product of the vector composed of the leaf node information and the indication vector to obtain the prediction result.

6. The privacy-preserving decision tree model inference method based on partial homomorphic encryption according to claim 5, wherein, Each participating party outputs the prediction result to the sample data provider, including: 1) If the sample is from a certain participating party, this participating party only needs to collect the prediction results from other participating parties and reconstruct them; 2) If the sample is from a non-participating party, each participating party needs to encrypt the shares it holds using the public key of the non-participating party and send them to the active participating party, which forwards the encrypted shares.

7. A privacy-preserving decision tree model inference system based on partial homomorphic encryption, characterized in that Including: A preprocessing module, used to obtain the sample data to be predicted, each participating party performs preprocessing, uses a partially homomorphic encryption method to jointly generate a randomly permuted ciphertext permutation matrix, and converts this ciphertext permutation matrix into a secret share matrix; A threshold comparison module, used to perform bit decomposition on the sample data to be predicted to obtain a decomposition matrix, select the input sharing method of the decomposition matrix according to the source of the sample data to be predicted, and then convert the obtained input decomposition matrix into the form of secret sharing shares; A decision prediction module, used for each participating party to perform comparison calculations using the secret sharing shares and threshold shares, evaluate the Boolean functions of all leaf nodes to obtain an indication result vector, and randomly permute the indication result vector using the secret share matrix to generate comparison result shares; A decision output module, used for each participating party to construct a vector pointing to the predicted output leaf node using the comparison result shares to obtain a prediction result, and then output the prediction result to the sample data provider according to the source of the sample data to be predicted.

8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method for reasoning about a privacy-preserving decision tree model based on partially homomorphic encryption according to any one of claims 1-6.

9. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium is used to store computer instructions, which, when executed by a processor, implement the method for reasoning about a privacy-preserving decision tree model based on partially homomorphic encryption according to any one of claims 1-6.

10. An electronic device, characterized in that, Comprising: A processor, a memory, and a computer program; wherein, the processor is connected to the memory, the computer program is stored in the memory, and when the electronic device runs, the processor executes the computer program stored in the memory so that the electronic device implements the method for reasoning about a privacy-preserving decision tree model based on partially homomorphic encryption according to any one of claims 1-6.

Citation Information

Cited By

  • New energy station power prediction method and system based on longitudinal federated decision tree

    CN121786465A