Privacy protection enhanced machine learning method and system
By real-time monitoring and optimizing the privacy protection methods of data streams, drawing network diagrams, adjusting noise and encryption configurations, and simulating attack conditions, the problems of insufficient privacy protection and data security in traditional machine learning are solved, and efficient and secure data processing is achieved.
Patent Information
- Application Number
- CN202510464079.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2045-04-14
AI Technical Summary
Traditional machine learning methods have shortcomings in privacy protection and data security. They lack real-time dynamic data monitoring and immediate risk assessment, resulting in the inability to timely discover and respond to information leakage risks. In addition, the computing resource consumption and processing efficiency of homomorphic encryption are poor.
By monitoring data flows from multiple data sources in real time, drawing data association network diagrams, assessing information leakage risks and privacy sensitivity, adjusting noise types and intensity, matching homomorphic encryption configurations, simulating network attack conditions, optimizing encryption parameters, and monitoring the compatibility and consistency of encrypted data flows in real time.
It improves the security and privacy protection level in the data processing process, improves the efficiency and security of encryption processing, enhances the ability to respond to network attacks, and ensures the privacy and security of data.
Smart Images

Figure CN120337289B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to a machine learning method and system based on privacy protection enhancement. Background Art
[0002] The field of data processing technology involves everything from basic data input and output processing to complex information processing processes, including data cleaning, which is to eliminate duplicate and correct erroneous data points; data conversion, which is to convert data from one format or structure to another to adapt to different analytical tools or technical requirements; data loading, which is to store processed data in a data warehouse or other storage system for subsequent use, combined with data indexing and query optimization to ensure the efficiency and accuracy of data retrieval, aiming to extract valuable information and support decision making, including database management, data encoding, data encryption, and data conversion.
[0003] Among them, machine learning methods refer to the use of statistics, mathematics and algorithms to develop and optimize machine learning algorithms through the process of learning from data and making predictions or decisions. It involves automatically adjusting model parameters through algorithms to adapt to data changes, including the application of supervised learning, unsupervised learning and semi-supervised learning algorithms, such as decision trees, support vector machines and neural networks. It processes data through algorithmic logic and mathematical models, identifies patterns and associations, and ensures data security and privacy protection during the processing process to complete the target learning tasks.
[0004] Traditional methods have shortcomings in privacy protection and data security. They rely on static data cleaning and conversion processes, lack real-time dynamic data monitoring and immediate risk assessment, and are not ideal when processing information flows involving multiple data sources and high-speed changes. In terms of data privacy, conventional data processing technologies fail to fully consider the complex correlations between data, resulting in information leakage or privacy infringement. The lack of effective real-time data flow monitoring will result in the inability to timely discover and respond to data leakage risks. In the application of homomorphic encryption, the consumption of computing resources and processing efficiency cannot be optimized, which not only reduces the operating efficiency of the system, but also leads to a decrease in response speed and affects system performance. Summary of the Invention
[0005] To address the technical issues of insufficient privacy protection and data security in existing technologies, the present invention provides a machine learning method and system based on privacy protection enhancement. The technical solution is as follows:
[0006] On the one hand, a machine learning method based on privacy protection enhancement is provided, which includes:
[0007] S1. Based on real-time input data, monitor the real-time data flow of multiple data sources, analyze the relationship between multiple data, draw a data association network diagram, and evaluate the information leakage risk and privacy sensitivity of multiple data points by analyzing the interconnection density and path distribution of nodes in the network diagram, and generate sensitivity assessment indicators;
[0008] S2. Analyze the privacy requirement levels of the multiple data points based on the sensitivity assessment index and the privacy sensitivity of the multiple data points, adjust the type and intensity of noise added to the target data points, and generate a data noise addition record;
[0009] S3. Based on the data noise addition record, according to the data volume and security level requirements of the input data, by analyzing the computing resource consumption, encryption strength and processing efficiency of multiple homomorphic encryption configurations, matching homomorphic encryption configurations, and generating data homomorphic encryption parameters;
[0010] S4. Based on the data homomorphic encryption parameters, by simulating various network attack conditions, analyzing the response status and stability of the encrypted data under various loads and attack conditions, evaluating the actual performance of the target encryption parameters and making adjustments, and generating encryption performance analysis results;
[0011] S5. Based on the encryption performance analysis results, perform homomorphic encryption processing on various input data, monitor the encrypted data flow in real time, analyze the compatibility and correlation between the data, evaluate the consistency and integrity of the data in the encrypted state, and generate an encrypted record of the input data.
[0012] On the other hand, a privacy-enhanced machine learning system is provided, which is applied to a privacy-enhanced machine learning method, and the system includes:
[0013] The data flow monitoring module is used to monitor the real-time data flow of multiple data sources based on real-time input data, analyze the relationship between multiple data, draw data association network diagrams, and evaluate the information leakage risk and privacy sensitivity of multiple data points by analyzing the interconnection density and path distribution of nodes in the network diagram, and generate sensitivity assessment indicators;
[0014] a noise management module, configured to analyze the privacy requirement levels of the plurality of data points based on the sensitivity assessment index and the privacy sensitivity of the plurality of data points, adjust the type and intensity of noise added to the target data points, and generate a data noise addition record;
[0015] An encryption parameter configuration module is used to add records based on the data noise, analyze the computing resource consumption, encryption strength and processing efficiency of multiple homomorphic encryption configurations according to the data volume and security level requirements of the input data, match the homomorphic encryption configuration, and generate data homomorphic encryption parameters;
[0016] A network attack simulation module is used to simulate various network attack conditions based on the data homomorphic encryption parameters, analyze the response status and stability of encrypted data under various loads and attack conditions, evaluate the actual performance of target encryption parameters and make adjustments, and generate encryption performance analysis results;
[0017] The encrypted data monitoring module is used to perform homomorphic encryption processing on various input data based on the encryption performance analysis results, monitor the encrypted data flow in real time, analyze the compatibility and correlation between data, evaluate the consistency and integrity of the data in the encrypted state, and generate input data encryption records.
[0018] The beneficial effects brought about by the technical solution provided by the embodiment of the present invention include at least:
[0019] By identifying risk points in the data in real time and adjusting the noise level of data points in a targeted manner, the security and privacy protection levels in the data processing process are improved. By comprehensively considering data processing efficiency, security level requirements, and computing resource consumption, the efficiency and security of encryption processing are improved. By simulating network attack conditions to test the stability of encrypted data, the ability to respond to network attacks is enhanced, and the input data supports a variety of data analysis tasks, ensuring the privacy and security of the data. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0021] Figure 1 This is a flow chart of a machine learning method based on privacy protection enhancement provided by an embodiment of the present invention;
[0022] Figure 2 This is a block diagram of a machine learning system based on privacy protection enhancement provided by an embodiment of the present invention;
[0023] Figure 3 This is a structural diagram of a machine learning device based on privacy protection enhancement provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0024] The technical solution of the present invention is described below in conjunction with the accompanying drawings.
[0025] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as an "exemplary" in the present invention should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of the word "exemplary" is intended to present concepts in a concrete manner. Furthermore, in the embodiments of the present invention, "and / or" can mean both or either of the two.
[0026] In the embodiments of the present invention, the terms "image" and "picture" may sometimes be used interchangeably. It should be noted that, when the distinction is not emphasized, the meanings they convey are the same. The terms "of," "corresponding," and "corresponding" may sometimes be used interchangeably. It should be noted that, when the distinction is not emphasized, the meanings they convey are the same.
[0027] In the embodiments of the present invention, sometimes a subscript such as W1 may be written as a non-subscript such as W1. When the difference is not emphasized, the meanings to be expressed are the same.
[0028] In order to make the technical problems, technical solutions and advantages to be solved by the present invention clearer, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.
[0029] The embodiment of the present invention provides a machine learning method based on privacy protection enhancement, such as Figure 1 The flowchart of the privacy-enhanced machine learning method shown in FIG. 1 may include the following steps:
[0030] S1. Based on real-time input data, monitor the real-time data flow of multiple data sources, analyze the relationship between multiple data, draw a data association network diagram, and evaluate the information leakage risk and privacy sensitivity of multiple data points by analyzing the interconnection density and path distribution of nodes in the network diagram, and generate sensitivity assessment indicators.
[0031] Optionally, the sensitivity assessment indicators are specifically data point connectivity, data path distribution and data point risk level, the data noise addition record includes data point sensitivity, privacy requirement level and noise addition parameters, the data homomorphic encryption parameters specifically refer to the data processing efficiency of multiple configurations, the data security level of multiple encryption configurations and encryption configuration matching records, the encryption performance analysis results include data response status information, stability test results and encryption parameter adjustment records, and the input data encryption records are specifically data flow monitoring records, data compatibility analysis results and data integrity assessment results.
[0032] Optionally, the specific operation steps of S2 include the following S101-S103:
[0033] S101. Based on real-time input data, monitor the real-time data streams of multiple data sources in real time, record data changes, and generate data stream interaction analysis results by analyzing the relationships between the data.
[0034] In a feasible implementation method, the signals and data changes sent by each data source are captured in real time, and the target data stream is logged. The log content includes the timestamp, source, type and change details of the data. The data in the log is analyzed, and the interaction patterns and data transmission links between different data sources are associated. Graph theory analysis models and network flow analysis algorithms are used to process and parse the dependencies and correlations between data streams. Each data change will trigger an analysis process, which tracks the evolution of the data stream and reveals the potential dynamic relationship of the data. Through this data monitoring and dynamic analysis, data stream interaction analysis results are generated. The results record the interaction status and changes of the data stream at different time points, providing a basis for data processing and analysis.
[0035] S102. Based on the data flow interaction analysis results and according to the mutual relationships between the data, a data association network diagram is drawn to generate data network structure information.
[0036] In a feasible implementation, each data point in the data flow analysis results is regarded as a node in the network, and the interactive relationship between the data flows is converted into the connection between the nodes. The strength and direction of the connection reflect the degree of dependence between the data flows and the master-slave relationship of data transmission. Graphical software tools, including Gephi or Graphviz, are used to draw the network diagram. During the drawing process, the network topology characteristics such as the degree, centrality, and clustering coefficient of the node are calculated. The target calculation helps to reveal the core data sources and potential information flow bottlenecks in the data network. After the drawing is completed, the data network structure information is generated, and the target information is presented in the form of a visual chart, providing an intuitive structural reference and analysis basis for further privacy risk assessment.
[0037] S103. Based on the data network structure information, by calculating the interconnection density and path distribution of multiple nodes in the network, the information leakage risk of multiple nodes is identified, the privacy sensitivity of multiple data points is evaluated, and a sensitivity assessment index is generated.
[0038] Optionally, the specific formula for evaluating the privacy sensitivity of multiple data points is as follows (1):
[0039] (1)
[0040] in, is the total number of nodes in the network, is the number of direct connections between the i-th node and other nodes, is the average degree of all nodes in the network, is the standard deviation of node degrees in the network, is the clustering coefficient of the i-th node, represents the maximum clustering coefficient in the network, i is the index of the node, and S is the sensitivity score of each node.
[0041] The above formula (1) is explained by example, the process is as follows:
[0042] The formula is used to calculate the privacy sensitivity scores of multiple nodes in the network, and the results are used to assess the information leakage risk of the nodes;
[0043] Parameter meaning and setting value:
[0044] is the total number of nodes in the network, assuming it is 50, reflecting the size of the network;
[0045] For the The degree of a node, assuming it is 12, reflects the node Number of direct connections to other nodes;
[0046] is the average degree of all nodes in the network, assuming it is 10, reflecting the average connection density of the network;
[0047] is the standard deviation of node degrees in the network, which is assumed to be 2 and is used to measure the dispersion of node degrees;
[0048] is the clustering coefficient of the i-th node, assuming it is 0.5, reflecting the closeness between the neighbors of node i;
[0049] is the maximum clustering coefficient in the network, assumed to be 0.8, used for comparison of standardized clustering coefficients.
[0050] Substitute the parameters into the formula for calculation:
[0051] ;
[0052] ;
[0053] ;
[0054] ;
[0055] result It shows that the privacy sensitivity score of the node is low, indicating that the target node has a relatively small risk of information leakage compared with other nodes in the network. The calculation process is used to identify the privacy sensitivity of multiple data points and adjust the noise addition parameters.
[0056] S2. Analyze the privacy requirement levels of the multiple data points based on the sensitivity assessment index and the privacy sensitivity of the multiple data points, adjust the type and intensity of noise added to the target data points, and generate a data noise addition record.
[0057] Optionally, the specific operation steps of S2 include the following S201-S203:
[0058] S201. Evaluate the privacy protection requirements of multiple data points based on the sensitivity assessment index and the privacy sensitivity of the multiple data points, and generate a privacy requirement analysis result.
[0059] In a feasible implementation method, sensitivity scores are used to determine the privacy level of data points, and data classification algorithms, such as decision tree analysis, are used to classify data points. The sensitivity scores are converted into privacy protection requirements, such as high, medium, and low. During the process, each data point is assigned a different protection level based on its role in the network and the content of sensitive data. Data points with high sensitivity receive stricter protection measures. After the analysis is completed, the system generates privacy demand analysis results, lists the privacy protection requirements and recommended protection strategies for each data point, and provides accurate guidance for data protection operations.
[0060] S202: Based on the privacy requirement analysis results, analyze the types of noise that need to be added to multiple data points according to the types of data points, and generate noise type analysis results.
[0061] In one feasible implementation, probabilistic models and noise pattern analysis techniques, including Laplace noise and Gaussian noise addition models, are used to determine the noise type that is most suitable for various data sensitivity levels. The operation involves evaluating the balance between the potential information leakage risk of each type of data and the original accuracy of the data, and selecting the noise type that can effectively improve data privacy while minimizing the impact on data practicality. During the analysis process, the frequency of data usage and the user's privacy expectations are also taken into account to ensure that the selected noise addition strategy is both practical and meets user needs, thereby generating noise type analysis results.
[0062] S203. Based on the noise type analysis result, calculate the noise intensity that needs to be added to multiple data points, add noise to the target data points, and generate a data noise addition record.
[0063] In a feasible implementation, differential privacy technology is used to determine the noise value. The calculation takes into account the privacy requirement level of the data point and the characteristics of the selected noise type. Mathematical optimization methods, such as linear programming, are used to ensure that the noise addition can achieve the expected privacy protection effect while retaining the validity and accuracy of the data as much as possible. During the calculation process, the standard deviation, mean and distribution of the noise in the data set are calculated and adjusted in detail to adapt to different data application scenarios and privacy protection standards. After completing the target calculation, the system adds noise to the specified data point, records the details of each addition operation, and generates a data noise addition record. The target record details the type, intensity and addition time of the noise, providing a reliable record for subsequent data review and privacy verification.
[0064] S3. Add records based on data noise. According to the data volume and security level requirements of the input data, analyze the computing resource consumption, encryption strength and processing efficiency of multiple homomorphic encryption configurations, match the homomorphic encryption configuration, and generate data homomorphic encryption parameters.
[0065] Optionally, the specific operation steps of S3 include the following S301-S303:
[0066] S301. Add records based on data noise, identify the data volume and security level requirements of input data, and generate security requirement information.
[0067] Data analysis techniques, including statistical analysis and trend analysis methods, are used to identify the size and type of different data sets, including calculating the quantity and frequency of each data type, as well as the specific security protection requirements of the target data type. Data classification and data clustering techniques are used in the analysis process to group data according to sensitivity and usage. Each group of data is evaluated for its security level requirements based on its sensitivity and noise addition. The process ensures that the security requirements of all data points are accurately identified and recorded. The generated security requirement information provides a basis for the selection of subsequent encryption measures and ensures that the processing measures match the actual needs of the data.
[0068] S302. Based on the security requirement information, analyze the encryption strength, computing resource consumption, and data processing efficiency of multiple homomorphic encryption configurations to generate configuration comparison analysis results.
[0069] An encryption strength assessment algorithm and resource consumption model are used. The target algorithm and model help evaluate the performance of each encryption configuration in actual operation. For example, the computing resource consumption of a configuration can be quantified by measuring the time required for encryption operations and CPU usage. A comprehensive scoring system is used to comprehensively consider encryption efficiency, cost, and maintenance complexity to ensure that the recommended configuration not only meets security standards but also optimizes the economy and practicality of operations. The generated configuration comparison analysis results list in detail the scores and advantages and disadvantages of each configuration, providing a scientific basis for selecting the encryption configuration that best suits current data processing needs.
[0070] S303. Based on the configuration comparison analysis results, taking into account security requirements and processing efficiency, match the homomorphic encryption configuration and generate data homomorphic encryption parameters.
[0071] Optionally, the specific formula for matching homomorphic encryption configuration is as follows (2):
[0072] (2)
[0073] Among them, F is the score of the target encryption parameter configuration, j is the index of the configuration factor, represents the weight of the j-th configuration factor, represents the performance value of the jth configuration factor in the current environment, and m is the number of evaluation factors.
[0074] The above formula (2) is explained by example, the process is as follows:
[0075] The formula is used to calculate the comprehensive scores of different homomorphic encryption configurations, and the results are used to select the optimal encryption configuration;
[0076] Parameter meaning and setting value:
[0077] is the weight of the jth configuration factor, assuming that they are encryption strength, computing resource consumption, and processing efficiency, with corresponding values of 0.6, 0.3, and 0.1; is the performance value of the jth configuration factor in the current environment, assuming it is 0.9, 0.7, and 0.5, representing the actual performance of encryption strength, resource consumption, and efficiency; m is the total number of evaluation factors, assuming it is 3;
[0078] Substitute the parameters into the formula for calculation:
[0079] ;
[0080] ;
[0081] ;
[0082] ;
[0083] result It shows that the target configuration can effectively control resource consumption and maintain moderate processing efficiency while ensuring high encryption strength. The calculation process is used to help strike a balance between multiple important factors and optimize the security of the encryption configuration and data processing efficiency.
[0084] S4. Based on data homomorphic encryption parameters, by simulating various network attack conditions, analyze the response status and stability of encrypted data under various loads and attack conditions, evaluate the actual performance of the target encryption parameters and make adjustments, and generate encryption performance analysis results.
[0085] Optionally, the specific operation steps of S4 include the following S401-S403:
[0086] S401. Based on data homomorphic encryption parameters, simulate network attack scenarios, test the response status of encrypted data, record the response time and data loss rate under various conditions, and generate performance test results.
[0087] In the network attack simulation sub-step, based on the determined data homomorphic encryption parameters, different network attack scenarios are set to test the response capability of the encrypted data. A multi-condition stress test method is used to simulate common network threats such as DDoS attacks and SQL injections, and the response time T and data loss rate D of the encrypted data under various attacks are monitored. According to the formula , calculate the response efficiency in various scenarios and generate performance test results;
[0088] Where T represents the average response time, D represents the data loss rate, e is the base of the natural logarithm, and R represents the response efficiency;
[0089] The detailed explanation of the formula and the formula calculation derivation process are as follows:
[0090] Assume that in the target DDoS attack test, the average response time for encrypted data is 2 seconds. , the data loss rate is 0.05, , calculate R:
[0091] ;
[0092] The result of 0.475 indicates that under the preset attack scenario, the response efficiency score of the target encryption configuration is 0.475. The calculation process is used to evaluate the performance of data homomorphic encryption under different network attack conditions. The response efficiency value is obtained to help determine the adaptability of the current encryption settings and the effectiveness of security protection.
[0093] S402: Analyze the performance test results, detect the stability and security of encrypted data under various load and attack conditions, and generate data stability information.
[0094] Use data analysis software, such as MATLAB or Python's Pandas library, to process performance test data and analyze the statistical characteristics of the data, including the average response time of encrypted data, the distribution of the longest and shortest response times, and the data integrity retention rate. This analysis helps determine which encryption configurations are most stable in specific network environments and which configurations can still maintain high data security under high attack risks. This generates data stability information. This target information indicates the security and stability performance of encrypted data under various environmental conditions, providing key data for further adjustment of encryption policies.
[0095] S403. Based on the data stability information, taking into account the data security requirements and processing efficiency, adjust the parameter settings of the homomorphic encryption algorithm to generate encryption performance analysis results.
[0096] Based on the data stability information, the existing homomorphic encryption algorithm parameters are evaluated, and the configuration parameters are adjusted to match the security requirements of the data and optimize processing efficiency. The priority of data protection and the resource consumption of encryption operations are considered in the process. Decision analysis methods, including cost-benefit analysis, are used to compare the security and efficiency performance under different parameter settings. The key length, number of encryption rounds and computational complexity of the encryption algorithm are adjusted in the process to ensure that the encryption processing does not excessively consume computing resources while meeting security standards, and generate encryption performance analysis results. The target results describe in detail the adjusted parameter settings and their expected impact on encryption performance, ensuring that the encryption strategy is both secure and efficient.
[0097] S5. Based on the results of encryption performance analysis, perform homomorphic encryption on various input data, monitor the encrypted data flow in real time, analyze the compatibility and correlation between data, evaluate the consistency and integrity of the data in the encrypted state, and generate encrypted records of the input data.
[0098] Optionally, the specific operation steps of S5 include the following S501-S503:
[0099] S501. Use the encryption performance analysis results to perform homomorphic encryption on various input data to generate an encrypted processing data set.
[0100] Use RSA or ElGamal, adjust the configuration of the encryption algorithm according to the type and sensitivity of the data, including selecting the appropriate key length and complexity, setting security protocols and standards in the encryption process, applying the encryption algorithm to each type of data, and recording and verifying each encryption operation to ensure encryption quality. The process ensures that all input data is fully protected before storage or transmission, and generates a processed data set containing various types of encrypted data.
[0101] S502: Based on the encrypted data set, monitor the encrypted data flow in real time, record the interaction and data transmission status between multiple data sources, and generate an encrypted data flow monitoring log.
[0102] Use network monitoring tools, such as Wireshark and data monitoring scripts, to track and record the transmission status of encrypted data in the network and the interaction between multiple data sources, record data transmission speed, access frequency and packet loss, including any abnormal data flow monitored will trigger a security alert. Target monitoring logs help identify possible data leakage points or security weaknesses, provide real-time data support for the network security team, generate encrypted data flow monitoring logs, and provide basic data for subsequent security analysis and optimization.
[0103] S503: Analyze the encrypted data flow monitoring log, analyze the compatibility and correlation between the encrypted data, evaluate the consistency and integrity of the encrypted data, and generate an encrypted record of the input data.
[0104] Use data analysis tools, such as Python's data processing libraries NumPy and Pandas, to analyze the encrypted data streams recorded in the monitoring logs and evaluate the consistency and integrity of the data during the encryption process. During the analysis, calculate the rate of change and error range of the data before and after encryption to ensure that the data retains its original data structure and association after encryption. The operation results reveal whether the encryption processing has changed the data content or the relationship between the data, ensuring that the output of all data processing remains highly consistent and complete. Based on the target analysis, generate input data encryption records, record the encryption effect and the consistency status of the data, and provide accurate records for the further use and protection of the data.
[0105] In an embodiment of the present invention, risk points in the data are identified in real time, the noise level of the data points is adjusted in a targeted manner, and the security and privacy protection levels in the data processing process are improved. By comprehensively considering data processing efficiency, security level requirements, and computing resource consumption, the efficiency and security of encryption processing are improved. By simulating network attack conditions to test the stability of encrypted data, the ability to respond to network attacks is enhanced, and the input data supports a variety of data analysis tasks, ensuring the privacy and security of the data.
[0106] Figure 2 This is a block diagram of a machine learning system based on privacy protection enhancement provided by an embodiment of the present invention, which is used for a machine learning method based on privacy protection enhancement. Figure 2 The device includes a data flow monitoring module 210, a noise management module 220, an encryption parameter configuration module 230, a network attack simulation module 240 and an encrypted data monitoring module 250.
[0107] Data flow monitoring module 210 is used to monitor the real-time data flow of multiple data sources based on real-time input data, analyze the relationship between multiple data, draw a data association network diagram, and evaluate the information leakage risk and privacy sensitivity of multiple data points by analyzing the interconnection density and path distribution of nodes in the network diagram to generate sensitivity assessment indicators;
[0108] a noise management module 220 for analyzing the privacy requirement levels of the plurality of data points based on the sensitivity assessment index and the privacy sensitivity of the plurality of data points, adjusting the type and intensity of noise added to the target data points, and generating a data noise addition record;
[0109] An encryption parameter configuration module 230 is configured to add records based on the data noise, analyze the computing resource consumption, encryption strength, and processing efficiency of multiple homomorphic encryption configurations according to the data volume and security level requirements of the input data, match the homomorphic encryption configuration, and generate data homomorphic encryption parameters;
[0110] A network attack simulation module 240 is configured to simulate various network attack conditions based on the data homomorphic encryption parameters, analyze the response status and stability of encrypted data under various loads and attack conditions, evaluate the actual performance of target encryption parameters and make adjustments, and generate encryption performance analysis results;
[0111] The encrypted data monitoring module 250 is used to perform homomorphic encryption processing on various input data based on the encryption performance analysis results, monitor the encrypted data flow in real time and analyze the compatibility and correlation between data, and evaluate the consistency and integrity of the data in the encrypted state, and generate input data encryption records.
[0112] Optionally, the sensitivity assessment indicators are specifically data point connectivity, data path distribution and data point risk level, the data noise addition records include data point sensitivity, privacy requirement level and noise addition parameters, the data homomorphic encryption parameters specifically refer to the data processing efficiency of multiple configurations, the data security level of multiple encryption configurations and encryption configuration matching records, the encryption performance analysis results include data response status information, stability test results and encryption parameter adjustment records, and the input data encryption records are specifically data flow monitoring records, data compatibility analysis results and data integrity assessment results.
[0113] Optionally, the data flow monitoring module 210 is configured to:
[0114] S101. Based on real-time input data, monitor the real-time data streams of multiple data sources in real time, record data changes, and generate data stream interaction analysis results by analyzing the relationships between the data;
[0115] S102. Based on the data flow interaction analysis results, draw a data association network diagram according to the mutual relationships between the data to generate data network structure information;
[0116] S103. Based on the data network structure information, by calculating the interconnection density and path distribution of multiple nodes in the network, identifying the information leakage risk of multiple nodes, evaluating the privacy sensitivity of multiple data points, and generating a sensitivity assessment index.
[0117] Optionally, the specific formula for evaluating the privacy sensitivity of multiple data points is as follows:
[0118] (1)
[0119] in, is the total number of nodes in the network, is the number of direct connections between the i-th node and other nodes, is the average degree of all nodes in the network, is the standard deviation of node degrees in the network, is the clustering coefficient of the i-th node, represents the maximum clustering coefficient in the network, i is the index of the node, and S is the sensitivity score of each node.
[0120] Optionally, the noise management module 220 is configured to:
[0121] S201, evaluating the privacy protection requirements of multiple data points based on the sensitivity assessment index and the privacy sensitivity of multiple data points, and generating a privacy requirement analysis result;
[0122] S202: Based on the privacy requirement analysis result, analyze the type of noise that needs to be added to the multiple data points according to the type of data points, and generate a noise type analysis result;
[0123] S203. Based on the noise type analysis result, calculate the noise intensity that needs to be added to multiple data points, add noise to the target data points, and generate a data noise addition record.
[0124] Optionally, the encryption parameter configuration module 230 is configured to:
[0125] S301, based on the data noise addition record, identifying the data volume and security level requirements of the input data, and generating security requirement information;
[0126] S302: Based on the security requirement information, analyze the encryption strength, computing resource consumption, and data processing efficiency of multiple homomorphic encryption configurations to generate a configuration comparison analysis result;
[0127] S303. Based on the configuration comparison and analysis results, taking into account security requirements and processing efficiency, match the homomorphic encryption configuration and generate data homomorphic encryption parameters.
[0128] Optionally, the specific formula for matching homomorphic encryption configuration is as follows (2):
[0129] (2)
[0130] Among them, F is the score of the target encryption parameter configuration, j is the index of the configuration factor, represents the weight of the j-th configuration factor, represents the performance value of the jth configuration factor in the current environment, and m is the number of evaluation factors.
[0131] Optionally, the network attack simulation module 240 is configured to:
[0132] S401. Based on the data homomorphic encryption parameters, simulate a network attack scenario, test the response status of the encrypted data, record the response time and data loss rate under various conditions, and generate performance test results;
[0133] S402: Analyze the performance test results, detect the stability and security of encrypted data under various load and attack conditions, and generate data stability information;
[0134] S403. Based on the data stability information, taking into account the security requirements and processing efficiency of the data, adjust the parameter settings of the homomorphic encryption algorithm to generate encryption performance analysis results.
[0135] Optionally, the encrypted data monitoring module 250 is configured to:
[0136] S501. Using the encryption performance analysis result, perform homomorphic encryption on a variety of input data to generate an encrypted processing data set;
[0137] S502: Based on the encrypted processed data set, monitor the encrypted data flow in real time, record the interaction and data transmission status between multiple data sources, and generate an encrypted data flow monitoring log;
[0138] S503: Analyze the encrypted data flow monitoring log, analyze the compatibility and correlation between the encrypted data, evaluate the consistency and integrity of the encrypted data, and generate an encrypted record of the input data.
[0139] In an embodiment of the present invention, risk points in the data are identified in real time, the noise level of the data points is adjusted in a targeted manner, and the security and privacy protection levels in the data processing process are improved. By comprehensively considering data processing efficiency, security level requirements, and computing resource consumption, the efficiency and security of encryption processing are improved. By simulating network attack conditions to test the stability of encrypted data, the ability to respond to network attacks is enhanced, and the input data supports a variety of data analysis tasks, ensuring the privacy and security of the data.
[0140] Figure 3 is a structural diagram of a machine learning device based on privacy protection enhancement provided by an embodiment of the present invention, such as Figure 3 As shown, the machine learning device based on privacy protection enhancement may include the above Figure 2 Optionally, the machine learning device 310 based on privacy protection enhancement may include a first processor 2001.
[0141] Optionally, the privacy protection-enhanced machine learning device 310 may further include a memory 2002 and a transceiver 2003 .
[0142] The first processor 2001, the memory 2002 and the transceiver 2003 may be connected via a communication bus.
[0143] The following combination Figure 3 The components of the privacy-enhanced machine learning device 310 are described in detail.
[0144] The first processor 2001 is the control center of the privacy-enhanced machine learning device 310 and can be a single processor or a collective term for multiple processing elements. For example, the first processor 2001 can be one or more central processing units (CPUs), or application-specific integrated circuits (ASICs), or one or more integrated circuits configured to implement embodiments of the present invention, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).
[0145] Optionally, the first processor 2001 can perform various functions of the privacy protection enhanced machine learning device 310 by running or executing software programs stored in the memory 2002 and calling data stored in the memory 2002.
[0146] In a specific implementation, as an embodiment, the first processor 2001 may include one or more CPUs, such as Figure 3 CPU0 and CPU1 are shown in FIG.
[0147] In a specific implementation, as an embodiment, the privacy protection-enhanced machine learning device 310 may also include multiple processors, such as Figure 3 1 and 2. The first processor 2001 and the second processor 2004 are shown in FIG. Each of these processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). A processor herein can refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0148] The memory 2002 is used to store the software program for executing the solution of the present invention, and is controlled by the first processor 2001 to execute. The specific implementation method can refer to the above method embodiment and will not be repeated here.
[0149] Optionally, the memory 2002 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 2002 may be integrated with the first processor 2001 or exist independently and accessed through the interface circuit ( Figure 3 (not shown) is coupled to the first processor 2001, which is not specifically limited in this embodiment of the present invention.
[0150] The transceiver 2003 is used to communicate with a network device or a terminal device.
[0151] Optionally, the transceiver 2003 may include a receiver and a transmitter ( Figure 3 The receiver is used to implement a receiving function, and the transmitter is used to implement a sending function.
[0152] Optionally, the transceiver 2003 may be integrated with the first processor 2001 or may exist independently and communicate with the first processor 2001 through the interface circuit ( Figure 3 (not shown) is coupled to the first processor 2001, which is not specifically limited in this embodiment of the present invention.
[0153] It should be noted that Figure 3 The structure of the privacy-enhanced machine learning device 310 shown in the figure does not constitute a limitation on the router. The actual knowledge structure recognition device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0154] In addition, the technical effects of the privacy protection-enhanced machine learning device 310 can refer to the technical effects of the privacy protection-enhanced machine learning device method described in the above method embodiment, and will not be repeated here.
[0155] It should be understood that the first processor 2001 in the embodiment of the present invention may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor, or the processor may be any conventional processor, etc.
[0156] It should also be understood that the memory in the embodiments of the present invention may be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory may be random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0157] The above embodiments can be implemented in whole or in part via software, hardware (e.g., circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product comprises one or more computer instructions or computer programs. When loaded or executed on a computer, the processes or functions described in accordance with the embodiments of the present invention are fully or partially performed. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired means (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server or data center that contains a collection of one or more available media. The available medium can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.
[0158] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.
[0159] In this disclosure, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, "at least one of a, b, or c" can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.
[0160] It should be understood that in various embodiments of the present invention, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0161] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.
[0162] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described equipment, devices and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0163] In the several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0164] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0165] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0166] If the functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or the portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage media include various media that can store program code, such as USB flash drives, mobile hard drives, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical disks.
[0167] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.
Claims
1. A machine learning method based on privacy protection enhancement, characterized in that: The method comprises: S1. Based on real-time input data, monitor the real-time data flow of multiple data sources, analyze the relationship between multiple data, draw a data association network diagram, and evaluate the information leakage risk and privacy sensitivity of multiple data points by analyzing the interconnection density and path distribution of nodes in the network diagram, and generate sensitivity assessment indicators; S2. Analyze the privacy requirement levels of the multiple data points based on the sensitivity assessment index and the privacy sensitivity of the multiple data points, adjust the type and intensity of noise added to the target data points, and generate a data noise addition record; S3. Based on the data noise addition record, according to the data volume and security level requirements of the input data, by analyzing the computing resource consumption, encryption strength and processing efficiency of multiple homomorphic encryption configurations, matching homomorphic encryption configurations, and generating data homomorphic encryption parameters; S4. Based on the data homomorphic encryption parameters, by simulating various network attack conditions, analyzing the response status and stability of the encrypted data under various loads and attack conditions, evaluating the actual performance of the target encryption parameters and making adjustments, and generating encryption performance analysis results; S5. Based on the encryption performance analysis results, perform homomorphic encryption processing on various input data, monitor the encrypted data flow in real time, analyze the compatibility and correlation between data, evaluate the consistency and integrity of the data in the encrypted state, and generate input data encryption records.
2. The privacy-enhanced machine learning method according to claim 1, wherein: The sensitivity assessment indicators of S1 are specifically data point connectivity, data path distribution and data point risk level. The data noise addition record includes data point sensitivity, privacy requirement level and noise addition parameters. The data homomorphic encryption parameters specifically refer to the data processing efficiency of multiple configurations, the data security level of multiple encryption configurations and encryption configuration matching records. The encryption performance analysis results include data response status information, stability test results and encryption parameter adjustment records. The input data encryption records are specifically data flow monitoring records, data compatibility analysis results and data integrity assessment results.
3. The privacy-enhanced machine learning method according to claim 1, wherein: S1 monitors the real-time data streams from multiple data sources based on real-time input data, analyzes the relationships between multiple data, draws a data association network diagram, and evaluates the information leakage risk and privacy sensitivity of multiple data points by analyzing the interconnection density and path distribution of nodes in the network diagram. The specific steps for generating sensitivity assessment indicators are as follows: S101. Based on real-time input data, monitor the real-time data streams of multiple data sources in real time, record data changes, and generate data stream interaction analysis results by analyzing the relationships between the data; S102. Based on the data flow interaction analysis results, draw a data association network diagram according to the mutual relationships between the data to generate data network structure information; S103. Based on the data network structure information, by calculating the interconnection density and path distribution of multiple nodes in the network, identifying the information leakage risk of multiple nodes, evaluating the privacy sensitivity of multiple data points, and generating a sensitivity assessment index.
4. The privacy-enhanced machine learning method according to claim 3, wherein: The specific formula for evaluating the privacy sensitivity of multiple data points is as follows (1): (1) in, is the total number of nodes in the network, is the number of direct connections between the i-th node and other nodes, is the average degree of all nodes in the network, is the standard deviation of node degrees in the network, is the clustering coefficient of the i-th node, represents the maximum clustering coefficient in the network, i is the index of the node, and S is the sensitivity score of each node.
5. The privacy-enhanced machine learning method according to claim 1, wherein: S2 analyzes the privacy requirement levels of the multiple data points based on the sensitivity assessment index and the privacy sensitivity of the multiple data points, and adjusts the type and intensity of noise added to the target data points to generate a data noise addition record. Specifically, the steps are as follows: S201, evaluating the privacy protection requirements of multiple data points based on the sensitivity assessment index and the privacy sensitivity of multiple data points, and generating a privacy requirement analysis result; S202: Based on the privacy requirement analysis result, analyze the type of noise that needs to be added to the multiple data points according to the type of data points, and generate a noise type analysis result; S203. Based on the noise type analysis result, calculate the noise intensity that needs to be added to multiple data points, add noise to the target data points, and generate a data noise addition record.
6. The privacy-enhanced machine learning method according to claim 1, wherein: S3 adds records based on the data noise, analyzes the computing resource consumption, encryption strength, and processing efficiency of various homomorphic encryption configurations according to the data volume and security level requirements of the input data, matches the homomorphic encryption configuration, and generates data homomorphic encryption parameters in the following steps: S301, based on the data noise addition record, identifying the data volume and security level requirements of the input data, and generating security requirement information; S302: Based on the security requirement information, analyze the encryption strength, computing resource consumption, and data processing efficiency of multiple homomorphic encryption configurations to generate a configuration comparison analysis result; S303. Based on the configuration comparison and analysis results, taking into account security requirements and processing efficiency, match the homomorphic encryption configuration and generate data homomorphic encryption parameters.
7. The privacy-enhanced machine learning method according to claim 6, wherein: The specific formula for matching homomorphic encryption configuration is as follows (2): (2) Among them, F is the score of the target encryption parameter configuration, j is the index of the configuration factor, represents the weight of the j-th configuration factor, represents the performance value of the jth configuration factor in the current environment, and m is the number of evaluation factors.
8. The privacy-enhanced machine learning method according to claim 1, wherein: S4, based on the data homomorphic encryption parameters, simulates various network attack conditions, analyzes the response status and stability of encrypted data under various loads and attack conditions, evaluates the actual performance of the target encryption parameters and makes adjustments, and generates encryption performance analysis results in the following steps: S401. Based on the data homomorphic encryption parameters, simulate a network attack scenario, test the response status of the encrypted data, record the response time and data loss rate under various conditions, and generate performance test results; S402: Analyze the performance test results, detect the stability and security of encrypted data under various load and attack conditions, and generate data stability information; S403. Based on the data stability information, taking into account the security requirements and processing efficiency of the data, adjust the parameter settings of the homomorphic encryption algorithm to generate encryption performance analysis results.
9. The privacy-enhanced machine learning method according to claim 1, wherein: Based on the encryption performance analysis results, S5 performs homomorphic encryption on various input data, monitors the encrypted data stream in real time, analyzes the compatibility and correlation between the data, and evaluates the consistency and integrity of the data in the encrypted state. The specific steps for generating encrypted records of the input data are as follows: S501. Using the encryption performance analysis result, perform homomorphic encryption on a variety of input data to generate an encrypted processing data set; S502: Based on the encrypted processed data set, monitor the encrypted data flow in real time, record the interaction and data transmission status between multiple data sources, and generate an encrypted data flow monitoring log; S503: Analyze the encrypted data flow monitoring log, analyze the compatibility and correlation between the encrypted data, evaluate the consistency and integrity of the encrypted data, and generate an encrypted record of the input data.
10. A machine learning system based on privacy protection enhancement, characterized in that: The machine learning system based on privacy protection enhancement is used to implement the machine learning method based on privacy protection enhancement according to any one of claims 1 to 9, characterized in that the system includes: The data flow monitoring module is used to monitor the real-time data flow of multiple data sources based on real-time input data, draw relationship diagrams between data, analyze the connection density and path distribution of nodes in the diagram, evaluate the leakage risk and privacy sensitivity of multiple data points, and generate sensitivity assessment indicators; a noise management module, configured to add noise to a plurality of data points according to the sensitivity assessment index, adjust the noise type and intensity according to the privacy requirement levels of the plurality of data points, and generate a data noise addition record; An encryption parameter configuration module is used to add records using the data noise, analyze the data volume and security level requirements of the input data, calculate the data processing efficiency, computing resource consumption and encryption strength of multiple encryption configurations, match the data homomorphic encryption configuration, and generate data homomorphic encryption parameters; A network attack simulation module is used to use the data homomorphic encryption parameters to simulate various network attack conditions, analyze the response and stability of encrypted data under various loads and attack conditions, adjust encryption parameters, and generate encryption performance analysis results; The encrypted data monitoring module is used to perform homomorphic encryption processing on various input data based on the encryption performance analysis results, monitor the encrypted data flow in real time, analyze the compatibility and correlation between data, evaluate the consistency and integrity of data, and generate input data encryption records.
Citation Information
Patent Citations
Distributed machine learning privacy protection method and system based on homomorphic encryption and signature algorithm
CN118396080A
Private data protection method and system based on homomorphic encryption and federated learning
CN119513919A