Platform privacy data processing method and system based on customer car use needs

By building a multi-modal demand data set and a real-time driving status data set, and dynamically adjusting privacy protection strategies using machine self-learning algorithms, the problem of privacy data leakage in the existing technology is solved, and the full-process privacy protection and customer experience improvement is achieved.

CN120387190BActive Publication Date: 2025-08-26GUANGDONG ICAR GUARD INFORMATION TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510886274.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2025-08-26
Estimated Expiration
2045-06-27

AI Technical Summary

Technical Problem

The existing vehicle service platform lacks in-depth privacy protection during data collection, transmission and processing, and cannot dynamically adjust its privacy protection policies, resulting in high risk of customer privacy data leakage and inability to provide highly targeted privacy protection, affecting customer experience.

Method used

By obtaining customers' multimodal demand data, analyzing the car demand categories using machine self-learning algorithms, a preliminary privacy protection strategy is generated, and a data set of actual driving status is constructed based on real-time driving behavior, environmental perception and iris tracking data, the privacy protection strategy is dynamically adjusted, and the adversarial noise pattern covers sensitive areas to achieve full-process privacy protection.

Benefits of technology

It enhances the comprehensiveness and dynamic nature of privacy protection, prevents sensitive information leakage, improves the customer's service platform experience, realizes joint analysis and model training of data from multiple service providers, and enhances data security and trust.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120387190B_ABST
    Figure CN120387190B_ABST
Patent Text Reader

Abstract

The present invention relates to a platform privacy data processing method based on customer vehicle use requirements. The method includes: obtaining preliminary customer application data and extracting features to construct a multimodal demand dataset; using a machine learning algorithm to analyze and generate preliminary vehicle use requirement categories and privacy protection strategies; collecting real-time driving behavior, environmental perception, and iris tracking data to construct an actual driving status dataset; analyzing and revising preliminary demand categories to actual vehicle use requirement data; and dynamically adjusting privacy protection strategies to protect real-time driving status data. This application effectively protects customer privacy, improves platform service quality, and thus enhances the customer experience with the service platform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data privacy protection, and in particular to a platform privacy data processing method and system based on customer vehicle usage needs. Background Art

[0002] With the development of the sharing economy, travel services such as ride-hailing and car rental platforms are becoming increasingly popular. While these platforms provide convenient travel services, they also collect and process a large amount of customer privacy data, including personal identity information, location data, driving habits, etc. How to effectively protect this privacy data has become a major issue.

[0003] Existing vehicle service platforms only perform simple desensitizing processing when collecting data, but this processing method is often not in-depth enough to prevent data leakage during transmission and processing. In addition, existing methods usually lack the ability to dynamically adjust privacy protection strategies and cannot provide targeted privacy protection based on different vehicle usage scenarios and customer needs, thereby reducing the customer experience when using the vehicle service platform, and therefore need to be improved. Summary of the Invention

[0004] In order to improve the customer experience when using the vehicle service platform, this application provides a platform privacy data processing method and system based on customer vehicle use needs.

[0005] In the first aspect, the above-mentioned invention object of the present application is achieved through the following technical solutions:

[0006] A platform privacy data processing method based on customer vehicle usage needs, the method comprising the steps of:

[0007] Obtain the preliminary application data submitted by the customer when submitting the car demand, and extract the demand features from the preliminary application data to build the customer's multimodal demand dataset;

[0008] The pre-set customer demand analysis model analyzes the multimodal demand data set based on a machine self-learning algorithm to generate a preliminary vehicle demand category for the customer;

[0009] Analyzing the preliminary vehicle demand category based on pre-set preliminary privacy protection rules to generate a preliminary privacy protection policy, wherein the preliminary privacy protection policy is used to protect the customer's preliminary application data;

[0010] Acquiring real-time driving behavior data of the customer, wherein the real-time driving behavior data includes steering wheel rotation frequency and corresponding rotation angle, and driving pedal and brake pedal switching frequency data;

[0011] Acquiring driving environment perception data, wherein the environment perception data includes visual monitoring data and radar data;

[0012] Acquire iris tracking data of people in the car, and when the on-board camera detects iris features, generate adversarial noise patterns to cover sensitive areas;

[0013] Associating the real-time driving behavior data, the environmental perception data, and the iris tracking data based on a preset common timeline to construct an actual driving state dataset;

[0014] The preset driving state analysis model analyzes the real-time driving state data based on a machine self-learning algorithm to generate driving state correction data, wherein the driving state correction data is used to correct the preliminary vehicle demand category;

[0015] The preset actual vehicle demand analysis model analyzes the driving state correction data and the preliminary vehicle demand category based on a machine self-learning algorithm to generate actual vehicle demand data;

[0016] The actual vehicle demand data is analyzed based on preset privacy protection rules to generate a revised privacy protection strategy, where the revised privacy protection strategy is used to protect the customer's real-time driving status data.

[0017] By adopting the above technical solution, a multimodal demand dataset is constructed by obtaining the customer's preliminary application data and extracting demand features. A machine self-learning algorithm is then used to analyze the customer's vehicle demand categories and generate a preliminary privacy protection strategy. Compared with existing technologies, this method not only protects the customer's preliminary application data but also further enhances the comprehensiveness and dynamism of privacy protection by obtaining the customer's driving behavior data, environmental perception data, and iris tracking data in real time. Existing technologies often only perform simple desensitization processing during the data collection phase, making it difficult to address the risk of data leakage during transmission and processing. The present invention, by constructing an actual driving state dataset and using a driving state analysis model to generate driving state correction data, dynamically adjusts the privacy protection strategy to ensure continuous protection of the customer's privacy throughout the vehicle use process. Furthermore, existing technologies have shortcomings in processing the biometric information of people in the vehicle. The present invention effectively prevents the leakage of sensitive information such as iris data by generating adversarial noise patterns to cover sensitive areas, further enhancing the strength of privacy protection.

[0018] In a preferred example, the present application may be further configured as follows: in the step of analyzing the multimodal demand data set based on the machine self-learning algorithm by the pre-set customer demand analysis model to generate the customer's preliminary vehicle demand category, the following steps are included:

[0019] Obtaining each demand feature in the multimodal demand dataset, wherein the demand features include driving mode parameters, trip purpose, and passenger status;

[0020] The pre-set customer demand profile construction model analyzes the multimodal demand data set based on a machine self-learning algorithm to construct a customer demand profile;

[0021] Perform a weighted score on the customer demand profile based on a preset profile scoring model to calculate a comprehensive score for the customer's needs;

[0022] Based on the comprehensive score of the customer's needs, a corresponding preliminary car demand category is generated, wherein the preliminary car demand category includes travel, business reception, shared car rental and emergency rescue.

[0023] By adopting the above technical solutions, preliminary vehicle demand categories are generated based on comprehensive demand scores. The platform can provide services that are more in line with customers' actual needs, while laying the foundation for targeted privacy protection strategies. Through the closed loop of multimodal feature extraction, portrait construction, dynamic scoring, and intelligent classification, accurate prediction of vehicle demand and efficient resource scheduling can be achieved, thereby improving customers' usage experience.

[0024] In a preferred example, the present application may be further configured as follows: after the pre-set customer demand profile building model analyzes the multimodal demand data set based on the machine self-learning algorithm to build the customer demand profile, the following steps are included:

[0025] Build a vertical federation model across service providers to align privacy across different user profiles.

[0026] Specifically, we identify overlapping users in each service provider's dataset as common samples for federated training, and extract detailed personal data of overlapping users as the initial common sample dataset;

[0027] Establishing a logical mapping relationship of feature fields across service providers, and processing the initial common sample dataset based on the logical mapping relationship to construct a standard common sample dataset;

[0028] The data with mapping relationship is used to calculate the cross-data features through homomorphic encryption algorithm to generate a joint feature vector;

[0029] User ID preprocessing is performed on user identifiers of different service providers in the standard common sample data set to unify them into hash values, thereby eliminating format differences.

[0030] By adopting the above technical solutions, joint analysis and model training of data from multiple service providers are achieved without leaking the original data. By calculating cross-features, the diversity and depth of features are increased, which helps to improve the predictive performance of the model. Homomorphic encryption ensures the confidentiality of data during the calculation process, enhances users' trust in data security, eliminates data format differences between users of different service providers, simplifies the data processing process, and hashed data is not easily reverse-cracking, further protecting user privacy. The unified format helps integrate data from multiple service providers and improve the efficiency and accuracy of federated learning.

[0031] In a preferred example, the present application may be further configured as follows: after performing user ID preprocessing on user identifiers of different service providers in the standard common sample data set to unify them into hash values, the following steps are included:

[0032] Adding Laplace noise to the feature bin boundaries of the standard common sample data set to confuse the statistical distribution;

[0033] Each service provider calculates the characteristic Shapley value of the standard common sample data set locally, and obtains the global importance ranking corresponding to each data in the standard common sample data through a secure aggregation algorithm, thereby avoiding direct sharing of characteristic data by each service provider to prevent inferring user behavior.

[0034] By adopting the above technical solution, each service provider only shares the encrypted Shapley value, the original feature distribution and user behavior patterns are completely hidden, and the global importance ranking guides resource allocation, making the decision explainable.

[0035] In a preferred example, the present application may be further configured as follows: after the step of analyzing the driving state correction data and the preliminary vehicle demand category based on a machine self-learning algorithm to generate actual vehicle demand data by a preset actual vehicle demand analysis model, the following steps are included:

[0036] Compare actual driving behavior with predicted values ​​through a federated learning algorithm to generate driving deviation;

[0037] Evaluating the driving deviation based on a machine self-learning algorithm to generate a corresponding abnormal behavior index;

[0038] Analyzing the environmental perception data based on a visual recognition algorithm to dynamically generate an environmental threat coefficient;

[0039] The preset driving dynamic risk assessment model comprehensively analyzes the abnormal behavior index and the environmental threat coefficient to generate a dynamic risk value for the customer, and the dynamic risk value is used to dynamically assess the priority level of privacy protection.

[0040] By adopting the above technical solutions, driving behavior and environmental factors are comprehensively considered to comprehensively assess driving risks. In high-risk driving situations, the privacy protection level is automatically improved to reduce the risk of data leakage, and the dynamic weighting mechanism is adapted to complex scenarios.

[0041] In a preferred example, the present application may be further configured as follows: after the step of analyzing the actual vehicle demand data based on the preset privacy protection rules to generate a revised privacy protection policy, the following steps are included:

[0042] Obtaining customer privacy-protected service feedback data, and associating the actual vehicle demand data, the revised privacy protection policy, and the service feedback data based on the public timeline to construct a privacy-related service feedback dataset;

[0043] The preset privacy service adjustment model analyzes the privacy service feedback-related data set based on a machine self-learning algorithm to generate a privacy leakage-service degradation correlation coefficient, which is used to adjust the weighted value of the dynamic risk value calculation.

[0044] By adopting the above technical solutions, by analyzing the privacy service feedback-related data sets and generating the privacy leakage-service degradation correlation coefficient, the platform can dynamically adjust the priority and intensity of the privacy protection strategy, better balance privacy protection and service quality, and improve customer satisfaction and trust.

[0045] In a preferred example, this application can be further configured as follows: after building a vertical federation model across service providers and performing privacy alignment on different user profile features, the following steps are included:

[0046] Obtain the real-time renewal status of the service provider. If the service provider's renewal status has expired, the historical session key will be automatically destroyed, blocking the ability to decrypt the real-time standard common sample data set.

[0047] Secondly, the above-mentioned invention objectives of this application are achieved through the following technical solutions:

[0048] A platform privacy data processing device based on customer vehicle use requirements, comprising: a multimodal demand dataset construction unit for obtaining preliminary application data submitted by a customer when submitting a vehicle use requirement, and extracting demand features from the preliminary application data to construct a multimodal demand dataset for the customer;

[0049] a preliminary vehicle demand category generating unit, configured to be pre-configured with a customer demand analysis model to analyze the multimodal demand dataset based on a machine self-learning algorithm to generate a preliminary vehicle demand category for the customer;

[0050] a preliminary privacy protection policy generating unit, configured to analyze the preliminary vehicle use demand category based on preset preliminary privacy protection rules to generate a preliminary privacy protection policy, wherein the preliminary privacy protection policy is used to protect the preliminary application data of the customer;

[0051] A real-time driving behavior data acquisition unit, used to acquire the customer's real-time driving behavior data;

[0052] An environmental perception data acquisition unit, used to acquire driving environmental perception data;

[0053] An iris tracking data acquisition unit, configured to acquire iris tracking data of a person in the vehicle and generate an adversarial noise pattern to cover the sensitive area when the vehicle-mounted camera detects iris features;

[0054] an actual driving state data set construction unit, configured to associate the real-time driving behavior data, the environment perception data, and the iris tracking data based on a preset common time axis to construct an actual driving state data set;

[0055] A driving state correction data generating unit, configured to analyze the real-time driving state data based on a machine self-learning algorithm using a pre-set driving state analysis model to generate driving state correction data;

[0056] an actual vehicle demand data generating unit, configured to be pre-configured with an actual vehicle demand analysis model to analyze the driving state correction data and the preliminary vehicle demand category based on a machine self-learning algorithm to generate actual vehicle demand data;

[0057] A modified privacy protection strategy generating unit is used to analyze the actual vehicle demand data based on preset privacy protection rules to generate a modified privacy protection strategy, wherein the modified privacy protection strategy is used to protect the customer's real-time driving status data.

[0058] Thirdly, the above-mentioned purpose of this application is achieved through the following technical solutions:

[0059] An electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the platform privacy data processing method based on customer vehicle usage needs are implemented.

[0060] Fourthly, the above-mentioned purpose of the present application is achieved through the following technical solutions:

[0061] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the above-mentioned platform privacy data processing method based on customer vehicle usage needs.

[0062] In summary, this application includes at least one of the following beneficial technical effects:

[0063] 1. By obtaining the customer's preliminary application data and extracting demand features, a multimodal demand data set is constructed, and then the customer's car demand category is analyzed using a machine self-learning algorithm, and a preliminary privacy protection strategy is generated. Compared with the existing technology, this method not only protects the customer's preliminary application data, but also further enhances the comprehensiveness and dynamism of privacy protection by obtaining the customer's driving behavior data, environmental perception data, and iris tracking data in real time. The existing technology can often only perform simple desensitization processing at the data collection stage, and it is difficult to deal with the risk of data leakage during transmission and processing. The present invention constructs an actual driving state data set and uses a driving state analysis model to generate driving state correction data, thereby dynamically adjusting the customer's privacy. The actual car-use needs of users are adjusted accordingly to the corresponding privacy protection strategy, ensuring that the customer's privacy is continuously protected throughout the car-use process while improving the customer's service platform experience. Traditional solutions only set a fixed privacy strength based on initial needs, resulting in insufficient protection of highly sensitive scenarios or excessive interference with the service experience in low-risk scenarios. The multi-source perception real-time correction mechanism of this solution can trigger dynamic adjustment of the privacy policy, thereby avoiding insufficient protection of highly sensitive scenarios or excessive interference with the service experience in low-risk scenarios. In addition, the existing technology has deficiencies in processing the biometric information of people in the car. The present invention effectively prevents the leakage of sensitive information such as iris data by generating adversarial noise patterns to cover sensitive areas, further improving the strength of privacy protection.

[0064] 2. By generating preliminary vehicle demand categories based on comprehensive demand scores, the platform can provide services more tailored to customers' actual needs while laying the foundation for targeted privacy protection strategies. Through a closed loop of multimodal feature extraction, profiling, dynamic scoring, and intelligent classification, it enables accurate prediction of vehicle demand and efficient resource scheduling, thereby improving the customer experience.

[0065] 3. Without leaking the original data, it enables joint analysis and model training of data from multiple service providers. By calculating cross-features, it increases the diversity and depth of features, which helps improve the predictive performance of the model. Homomorphic encryption ensures the confidentiality of data during the calculation process, enhances users' trust in data security, eliminates data format differences between users of different service providers, simplifies the data processing process, and makes hashed data less susceptible to reverse cracking, further protecting user privacy. The unified format helps integrate data from multiple service providers and improves the efficiency and accuracy of federated learning. BRIEF DESCRIPTION OF THE DRAWINGS

[0066] Figure 1 This is a flow chart of a platform privacy data processing method based on customer vehicle usage needs in one embodiment of the present application;

[0067] Figure 2 This is a principle block diagram of a platform privacy data processing device based on customer vehicle usage needs in one embodiment of the present application;

[0068] Figure 3 It is a schematic diagram of an electronic device in an embodiment of the present application.

[0069] Figure Number:

[0070] 1. Multimodal demand dataset construction unit; 2. Preliminary vehicle demand category generation unit; 3. Preliminary privacy protection strategy generation unit; 4. Real-time driving behavior data acquisition unit; 5. Environmental perception data acquisition unit; 6. Iris tracking data acquisition unit; 7. Actual driving status dataset construction unit; 8. Driving status correction data generation unit; 9. Actual vehicle demand data generation unit; 10. Corrected privacy protection strategy generation unit. DETAILED DESCRIPTION

[0071] The present application is further described in detail below with reference to the accompanying drawings.

[0072] In one embodiment, if Figure 1 As shown, this application discloses a platform privacy data processing method based on customer car use needs, which specifically includes the following steps:

[0073] S01: Obtain the preliminary application data when the customer submits the car demand, and extract the demand features from the preliminary application data to build the customer's multimodal demand dataset;

[0074] Specifically, taking a text requirement as an example, a customer submits a text requirement: "Send three business partners to Pudong Airport at 8 o'clock tomorrow morning, and a luxury car is required";

[0075] Extract features from preliminary application data:

[0076] Text semantics: business reception, luxury car models (NLP parsing)

[0077] Structured data: departure time (08:00), number of passengers (3), destination (airport)

[0078] Historical preference: This user selected silent mode air conditioning in 80% of their past orders. Build a multimodal dataset for this customer: {Demand type: Business, Time: 08:00, Number of passengers: 3, Vehicle preference: Luxury, Environment requirement: Silent}.

[0079] Integrate multi-dimensional data such as text, time, space, and behavior to improve the comprehensiveness of demand identification; construct data sets through non-sensitive features (such as the number of passengers rather than identity information) to comply with the principle of minimizing collection and protect customer identity privacy.

[0080] S02: A preset customer demand analysis model analyzes the multimodal demand dataset based on a machine self-learning algorithm to generate a preliminary vehicle demand category for the customer;

[0081] Specifically, in the embodiment of the present application, multimodal data is input into the pre-trained ResNet-Transformer hybrid model to output the preliminary car demand category: business reception category (for example, the confidence level is 92%). The labels corresponding to the business reception category include: high privacy sensitivity and need for comfort guarantee.

[0082] It should be noted that in the embodiment of the present application, the preliminary car demand categories include travel, business reception, shared car rental and emergency rescue. In other embodiments, the preliminary car demand categories can be classified according to different classification rules.

[0083] S03: Analyzing the preliminary car use demand category based on pre-set preliminary privacy protection rules to generate a preliminary privacy protection strategy;

[0084] Specifically, in the embodiment of the present application, the matching rules are: business reception triggers high-intensity privacy protection; travel triggers high-intensity privacy protection; shared car rental triggers low-intensity privacy protection; emergency rescue triggers the lowest-intensity privacy protection (providing vehicle usage data and customer information data according to rescue needs). The preliminary privacy protection strategy is used to protect the customer's preliminary application data, and the preliminary privacy protection strategy includes data desensitization, data obfuscation, and data encryption before storage.

[0085] In this embodiment of the present application, the preliminary privacy protection strategy includes vehicle position blur radius R = 100m (differential privacy noise injection), voiceprint instruction MFCC coefficient perturbation; biometric default masking (iris pixel retention rate ≤ 10%).

[0086] S04: Obtain real-time driving behavior data of customers;

[0087] S05: Acquire driving environment perception data;

[0088] S06: Acquire iris tracking data of people in the car, and when the onboard camera detects iris features, generate adversarial noise patterns to cover sensitive areas;

[0089] Specifically, for steps S04-S06, the real-time driving behavior data includes the steering wheel rotation frequency and the corresponding rotation angle, and the switching frequency data of the drive pedal and the brake pedal; the environmental perception data includes visual monitoring data and radar data.

[0090] It should be noted that after the on-board camera captures the driver's iris features, the system immediately generates a specific noise pattern to cover the iris area to prevent the iris data from being illegally collected and used. In the embodiment of the present application, the system calls the pre-trained generative adversarial network (GAN) model to generate adversarial noise patterns in real time to cover the sensitive areas of the eyes. The adversarial noise can effectively interfere with the illegal iris recognition algorithm, making it impossible to extract the real iris features; the noise only covers the iris texture, retaining non-sensitive features such as the eye contour, ensuring the accuracy of functions such as fatigue driving monitoring; the noise intensity is adjusted in real time with the risk level to dynamically adapt to the customer's actual driving conditions.

[0091] S07: Correlating the real-time driving behavior data, the environment perception data, and the iris tracking data based on a preset common timeline to construct an actual driving state dataset;

[0092] S08: The pre-set driving state analysis model analyzes the real-time driving state data based on a machine self-learning algorithm to generate driving state correction data;

[0093] The driving state correction data is used to correct the preliminary vehicle demand category. Specifically, the driving state analysis model may detect that the driver is driving fatigued and entering a school area. Based on historical data and real-time driving behavior (such as frequent direction adjustments and pedal switching), correction data is generated to prompt rest, thereby outputting a corrected vehicle demand category: the demand category is converted from "business" to "high safety priority" (due to fatigue driving + school area).

[0094] S09: A preset actual vehicle demand analysis model analyzes the driving state correction data and the preliminary vehicle demand category based on a machine self-learning algorithm to generate actual vehicle demand data;

[0095] Specifically, based on the demand type conversion mentioned in S08, the actual vehicle demand analysis model inputs: the revised demand label (high safety priority) + the original business demand, and outputs the corresponding actual vehicle demand: {Main type: Business, Sub-strategy: Safety enhancement, Specific measures: Activate assisted driving + Increase bio-shielding strength}.

[0096] S10: Analyzing the actual vehicle demand data based on pre-set privacy protection rules to generate a modified privacy protection policy, where the modified privacy protection policy is used to protect the customer's real-time driving status data;

[0097] Specifically, for example: the privacy protection strategy is modified as follows: the location blur radius is increased from 100m to 200m; the iris masking intensity is adjusted from 10% to 90%; and homomorphic encryption is enabled to transmit real-time behavior data.

[0098] What is needed is that, in the embodiment of the present application, the customer's car usage data is combined with the dual destruction conditions of the blockchain smart contract (such as automatically burning the voiceprint data 72 hours after the end of the trip and when there is no insurance claim) to achieve full life cycle management.

[0099] In summary, by obtaining the customer's preliminary application data and extracting demand features, a multimodal demand data set is constructed, and then the customer's car demand category is analyzed using a machine self-learning algorithm, and a preliminary privacy protection strategy is generated. Compared with the existing technology, this method not only protects the customer's preliminary application data, but also further enhances the comprehensiveness and dynamism of privacy protection by obtaining the customer's driving behavior data, environmental perception data and iris tracking data in real time. The existing technology can often only perform simple desensitization processing in the data collection stage, and it is difficult to deal with the risk of data leakage during transmission and processing. The present invention constructs an actual driving state data set and uses a driving state analysis model to generate driving state correction data, thereby dynamically adjusting The customer's actual car use needs and the corresponding privacy protection strategy are adjusted to ensure that the customer's privacy is continuously protected throughout the car use process while improving the customer's service platform usage experience. The traditional solution only sets a fixed privacy strength based on the initial needs, resulting in insufficient protection of highly sensitive scenarios or excessive interference with the service experience in low-risk scenarios; the multi-source perception real-time correction mechanism of this solution can trigger dynamic adjustment of the privacy policy, thereby avoiding insufficient protection of highly sensitive scenarios or excessive interference with the service experience in low-risk scenarios. In addition, the existing technology has deficiencies in processing the biometric information of people in the car. The present invention effectively prevents the leakage of sensitive information such as iris data by generating adversarial noise patterns to cover sensitive areas, thereby further improving the strength of privacy protection.

[0100] In step S02: the pre-set customer demand analysis model analyzes the multimodal demand dataset based on a machine self-learning algorithm to generate a preliminary vehicle demand category for the customer, the following steps are included:

[0101] S021: Obtaining each demand feature in the multimodal demand dataset, wherein the demand feature includes driving mode parameters, trip purpose, and passenger status;

[0102] Specifically, for example:

[0103] Driving mode parameters: When the user inputs "Turn on sports mode and avoid congested roads", the system extracts the keywords "sports mode" (power preference) and "avoid congestion" (road condition strategy).

[0104] Trip purpose: Text requirement: "Send three customers to Pudong Airport at 8:00 am tomorrow morning" → NLP parsed as "business transfer" (keywords: customer, airport).

[0105] Passenger status: The in-vehicle sensor detects pressure signals from four seats + the voice command "adjust the rear air conditioning to 24°C" → the comprehensive judgment is that the number of passengers is 3 (excluding the driver).

[0106] Step S021 integrates multi-source data such as voice, text, and sensors to achieve automated extraction of demand features, improving efficiency compared to traditional form filling. It also improves feature accuracy through multimodal complementary verification (such as cross-confirmation of passenger count through pressure sensors and voice commands).

[0107] S022: The pre-set customer demand profile construction model analyzes the multimodal demand dataset based on a machine self-learning algorithm to construct a customer demand profile;

[0108] Specifically, the input features are: {driving mode: sporty; trip purpose: business transfer; number of passengers: 3; historical preference: 80% of orders choose luxury models}.

[0109] Customer demand portrait construction model construction: In the embodiment of the present application, the customer demand portrait construction model adopts a clustering algorithm (K-means): users are classified into "high net worth business groups".

[0110] Preset labeling system: Generate portrait labels {demand intensity: 9.2 / 10, comfort demand: high, privacy sensitivity: high}.

[0111] Step S022 breaks through the limitations of single-dimensional classification (such as selecting only by car model) and uses multiple labels to three-dimensionally characterize user needs.

[0112] S023: Performing a weighted score on the customer demand profile based on a preset profile scoring model to calculate a comprehensive score of the customer's needs;

[0113] Specifically, the profile scoring model assigns a weighted score based on the different features within the customer demand profile. For example, the "business travel" feature is weighted higher, resulting in a high score for a customer who frequently travels for business; the "solo travel" feature is weighted lower, resulting in a lower score. Taking all these features into account, the customer's needs are scored 75 out of 100. This weighted scoring allows the platform to accurately quantify customer needs, providing a quantitative basis for subsequent service optimization and privacy protection strategies.

[0114] S024: Generating corresponding preliminary vehicle demand categories based on the comprehensive demand scores of the customer, wherein the preliminary vehicle demand categories include travel, business reception, shared car rental, and emergency rescue;

[0115] Specifically, in the example of step S023, the customer's comprehensive demand score is 75 points. According to the preset scoring rules, 70-80 points correspond to the "Business Reception" category. Therefore, the platform classifies the customer's initial car demand as "Business Reception."

[0116] By generating preliminary car demand categories based on comprehensive demand scores, the platform can provide services that are more in line with customers' actual needs, while laying the foundation for targeted privacy protection strategies.

[0117] In summary, through the closed loop of multimodal feature extraction, portrait construction, dynamic scoring, and intelligent classification, accurate prediction of vehicle demand and efficient resource scheduling can be achieved, thereby improving customer experience.

[0118] After the step S022: the pre-set customer demand profile construction model analyzes the multimodal demand data set based on the machine self-learning algorithm to construct the customer demand profile, the following steps are included:

[0119] S0221: Build a cross-provider vertical federation model to align privacy across different user profiles.

[0120] For example, suppose multiple travel service providers participate in federated learning. Each provider has its own user profile. For example, travel service provider A may have characteristics such as user ride frequency and trip distance, while travel service provider B may have characteristics such as user booking habits and vehicle preferences. Through vertical federated learning, these different user profile characteristics are privacy-aligned, allowing each provider to build a joint user profile model without leaking their own user data.

[0121] In the embodiment of the present application, a cross-industry service provider scenario is also included: car company A has user driving behavior data, insurance company B holds user credit records, and bank C has consumption capacity data. The three parties establish a federal channel through an encrypted channel and agree on the overlapping user range (such as the user group with car insurance renewal records in the past three months).

[0122] Service providers do not need to share original data, avoiding the risk of user data leakage. The integration of characteristics of multiple service providers makes user portraits more comprehensive, improves the predictive ability of the model, promotes cooperation between different service providers, and jointly improves service quality without worrying about data privacy issues. It also breaks down data silos, allowing car companies to integrate insurance / banking characteristics without exposing original data; and reduces compliance risks compared to traditional data transaction service platforms.

[0123] It should be noted that the real-time renewal status of the service provider is obtained. If the renewal status of the service provider has expired, the historical session key will be automatically destroyed, blocking the ability to decrypt the real-time standard common sample data set.

[0124] S0222: Identify overlapping users in each service provider's dataset as common samples for federated training, and extract detailed personal data of overlapping users as the initial common sample dataset;

[0125] Specifically, using Proven Secure Intersection (PSI) technology, based on identifiers such as user IDs and mobile phone numbers, we identify overlapping users from multiple travel service providers' datasets who have used all three services simultaneously. For example, if user A has registered and used travel service providers A, B, and C, then user A is identified as an overlapping user. Detailed personal data (such as ride frequency, trip distance, booking habits, and vehicle model preferences) is then extracted from these overlapping users to form the initial common sample dataset.

[0126] This step ensures that federated training is based on the same user group, improving the consistency and accuracy of model training. The detailed data of overlapping users provides rich information, which helps to build a high-quality joint model, provides a basis for data collaboration between different service providers, and enhances the feasibility and effectiveness of federated learning.

[0127] S0223: Establishing a logical mapping relationship of feature fields across service providers, and processing the initial common sample dataset based on the logical mapping relationship to construct a standard common sample dataset;

[0128] Specifically, the dataset for travel provider A includes the feature "ride frequency," while the dataset for travel provider B includes the feature "number of trips." These two features are essentially the same, so a logical mapping relationship is established, mapping "ride frequency" to "number of trips," with unified units and definitions. The initial common sample dataset is then processed based on this mapping relationship, converting the corresponding features for all providers into a unified standard format, thereby constructing a standard common sample dataset.

[0129] Step S0223 has the following technical effects: feature unification: eliminates feature differences between different service providers, improves data comparability and model training efficiency; model generalization: unified feature fields help the model better generalize to user groups of different service providers; data integration: provides a unified data foundation for further integration of data from multiple service providers, enhancing the effect of federated learning.

[0130] S0224: Calculate cross-data features of the data with mapping relationships through a homomorphic encryption algorithm to generate a joint feature vector;

[0131] Specifically, for the "number of trips" feature in the standard common sample dataset, suppose that user A has made 10 trips in the data from travel provider A, and 8 trips in the data from travel provider B. Using a homomorphic encryption algorithm (such as Paillier encryption), these two data sets are first encrypted, and then their cross-features are calculated, such as their sum, difference, or product. The resulting encrypted result is a portion of the joint feature vector, which can be used to train the joint model without decrypting the original data.

[0132] Without leaking the original data, joint analysis and model training of data from multiple service providers are achieved. By calculating cross-features, the diversity and depth of features are increased, which helps to improve the predictive performance of the model. Homomorphic encryption ensures the confidentiality of data during the calculation process and enhances users' trust in data security.

[0133] S0225: Performing user ID preprocessing on user identifiers of different service providers in the standard common sample data set to unify them into hash values, thereby eliminating format differences;

[0134] Specifically, in the standard common sample dataset, the user ID for travel service provider A is "123456789," the user ID for travel service provider B is "user_987654321," and the user ID for travel service provider C is "T3_111222333." Using a hashing algorithm (such as MD5 or SHA-256), these user IDs of varying formats are converted into a unified hash value. For example, "123456789" is converted to "abc123def456," "user_987654321" is converted to "def456abc123," and "T3_111222333" is converted to "ghi789jkl345." This way, all user IDs are unified into hash values ​​of the same length and format, facilitating subsequent data processing and model training.

[0135] It eliminates format differences among user IDs of different service providers and simplifies the data processing process. The hashed user ID is not easily reverse-crackered, further protecting user privacy. The unified user ID format helps integrate data from multiple service providers and improve the efficiency and accuracy of federated learning.

[0136] After the step S0225 of performing user ID preprocessing on user identifiers of different service providers in the standard common sample data set to unify them into hash values, the following steps are included:

[0137] Adding Laplace noise to the feature bin boundaries of the standard common sample data set to confuse the statistical distribution;

[0138] Each service provider calculates the characteristic Shapley value of the standard common sample data set locally, and obtains the global importance ranking corresponding to each data in the standard common sample data through a secure aggregation algorithm, thereby avoiding direct sharing of characteristic data by each service provider to prevent inferring user behavior.

[0139] Based on differential privacy protection, Laplace noise is added to the feature binning boundaries of the standard common sample data set. A specific example is: in the joint modeling of banks and travel service platforms, it is necessary to bin user income features and calculate the boundary sensitivity (the maximum offset of the boundaries of adjacent data sets); Laplace noise is generated to determine the noise value, and the user income feature bins are adjusted based on the noise value to confuse the statistical distribution. The noise injection causes the binning boundaries to shift randomly, blocking the path of inferring individuals through distribution statistics, making it impossible for attackers to infer individual income through statistical distribution.

[0140] Each service provider calculates the Shapley value of feature i locally , measuring its marginal contribution to the prediction, where The calculation formula is:

[0141]

[0142] , N is the full set of features, S is the feature subset, f is the model prediction function, and i is the i-th feature in the dataset.

[0143] Aggregate the data of each service provider based on a secure aggregation algorithm (through Paillier homomorphic encryption or secret sharing technology) , after decryption, only the global importance ranking is exposed.

[0144] Each service provider calculates the Shapley value of a feature locally. For example, if the Shapley value of a feature like "travel frequency" is 0.3, it means that this feature contributes 30% to the model's prediction on average. Using a secure aggregation algorithm, the Shapley values ​​of all service providers are aggregated to create a global importance ranking, with "travel frequency" ranked first and "vehicle type preference" ranked third.

[0145] Zero exposure of effect data: all parties only share encrypted Shapley values ​​(scalars), the original feature distribution and user behavior patterns are completely hidden, and decision interpretability: global importance ranking guides resource allocation.

[0146] After the step S09 of analyzing the driving state correction data and the preliminary vehicle demand category based on a machine self-learning algorithm to generate actual vehicle demand data by using a preset actual vehicle demand analysis model, the following steps are included:

[0147] S091: Compare actual driving behavior and predicted values ​​through a federated learning algorithm to generate driving deviation;

[0148] Specifically, each vehicle terminal locally calculates the difference between the actual driving behavior (such as steering wheel angle and acceleration) and the output value of the prediction model, uploads the gradient through Paillier homomorphic encryption, and the central server aggregates the encrypted gradient to update the global model and output the driving deviation (such as trajectory deviation rate and speed fluctuation variance).

[0149] S092: Evaluate the driving deviation based on a machine self-learning algorithm to generate a corresponding abnormal behavior index;

[0150] Specifically, in the embodiment of the present application, based on the Isolation Forest and LOF (Local Outlier Factor) algorithms, the spatiotemporal distribution characteristics of the deviation are analyzed; and an abnormal behavior index (0-1.0 in this application) is output, where a higher value indicates a greater behavioral risk.

[0151] For example: Scenario: On a nighttime highway, the driver has not rested for two hours and the frequency of steering wheel fine-tuning increases sharply. Evaluation process:

[0152] Input: steering wheel fine-tuning frequency (0.8Hz→2.3Hz), blink interval (3s→1.2s);

[0153] Isolation Forest Identification: Fine-tuning frequency at abnormal branch depth = 3 (normal branch depth > 8) → index = 0.86; Beneficial effect:

[0154] Early warning: When the index exceeds the preset threshold, a fatigue reminder is triggered (earlier than traditional DMS systems);

[0155] Anti-interference: Robust to sensor noise.

[0156] S093: Analyze the environmental perception data based on a visual recognition algorithm to dynamically generate an environmental threat coefficient;

[0157] Specifically, we dynamically detect road targets (pedestrians and vehicles) based on YOLOv5 and combine it with the spatiotemporal convolutional network (STCNN) to predict the probability of trajectory conflict.

[0158] Threat coefficient = number of targets × motion entropy × inverse of collision time. By enhancing image recognition through GAN, the error of threat coefficient is reduced.

[0159] S094: A preset driving dynamic risk assessment model comprehensively analyzes the abnormal behavior index and the environmental threat coefficient to generate a dynamic risk value for the customer, wherein the dynamic risk value is used to dynamically assess the priority level of privacy protection;

[0160] Specifically, for example: the driving dynamic risk assessment model combines the abnormal behavior index of 85 and the environmental threat coefficient of 0.8, and calculates the customer's dynamic risk value as 0.75 (out of 1.0) through a preset formula. Based on the risk value, the system will increase the priority level of privacy protection, limit unnecessary data sharing, and prioritize protecting the customer's privacy in high-risk situations.

[0161] To sum up, by comprehensively considering driving behavior and environmental factors, driving risks are comprehensively assessed. In high-risk driving situations, the privacy protection level is automatically improved to reduce the risk of data leakage, and the dynamic weight mechanism is adapted to complex scenarios.

[0162] After the step S10 of analyzing the actual vehicle demand data based on the preset privacy protection rules to generate a revised privacy protection strategy, the following steps are included:

[0163] S101: Obtain customer privacy-protected service feedback data, and associate the actual vehicle demand data, the revised privacy protection policy, and the service feedback data based on the public timeline to construct a privacy-related service feedback dataset;

[0164] Specifically, after using platform services, customers provide privacy-related service feedback through questionnaires or rating systems. For example, after using the platform's services, Customer A rated the platform's privacy protection measures 4 out of 5 and expressed concerns about how the platform handles their driving behavior data. The platform uses a public timeline to link Customer A's actual vehicle usage data (e.g., for business trips), revised privacy protection policies (e.g., encrypted driving behavior data), and service feedback data to construct a privacy-related service feedback dataset.

[0165] By associating customers' privacy protection service feedback with actual vehicle usage demand data and revised privacy protection strategies, the platform can better understand customers' satisfaction and concerns about privacy protection measures, and provide data support for subsequent optimization of privacy protection strategies.

[0166] S102: A preset privacy service adjustment model analyzes the privacy service feedback-related data set based on a machine self-learning algorithm to generate a privacy leakage-service degradation correlation coefficient, which is used to adjust the weighted value of dynamic risk value calculation;

[0167] Specifically, the platform's privacy service adjustment model uses machine learning algorithms (such as logistic regression or neural networks) to analyze data sets related to privacy service feedback. For example, the privacy service adjustment model found that when customer satisfaction with privacy protection measures falls below 3 points, the risk of privacy leakage increases by 20%. Based on this, the model generates a privacy leakage-service degradation correlation coefficient of 0.2, indicating a moderately negative correlation between privacy leakage risk and service satisfaction. This coefficient is used to adjust the weighting in the dynamic risk value calculation to reflect the impact of privacy protection measures on overall risk.

[0168] By analyzing privacy service feedback-related data sets and generating a privacy leakage-service degradation correlation coefficient, the platform can dynamically adjust the priority and intensity of privacy protection policies, better balance privacy protection and service quality, and improve customer satisfaction and trust.

[0169] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0170] In one embodiment, a platform privacy data processing device based on customer car use needs is provided. The platform privacy data processing device based on customer car use needs corresponds to the platform privacy data processing method based on customer car use needs in the above embodiment. Figure 2 As shown, the platform privacy data processing device based on customer car use needs includes:

[0171] The multimodal demand data set construction unit 1 is used to obtain the preliminary application data when the customer submits the vehicle demand, and extract the demand features from the preliminary application data to construct the customer's multimodal demand data set;

[0172] A preliminary vehicle demand category generating unit 2 is configured to be pre-configured with a customer demand analysis model to analyze the multimodal demand dataset based on a machine self-learning algorithm to generate a preliminary vehicle demand category for the customer;

[0173] a preliminary privacy protection policy generating unit 3, configured to analyze the preliminary vehicle demand category based on pre-set preliminary privacy protection rules to generate a preliminary privacy protection policy, wherein the preliminary privacy protection policy is used to protect the preliminary application data of the customer;

[0174] A real-time driving behavior data acquisition unit 4 is used to acquire the real-time driving behavior data of the customer;

[0175] Environmental perception data acquisition unit 5, used to acquire driving environmental perception data;

[0176] an iris tracking data acquisition unit 6, configured to acquire iris tracking data of a person in the vehicle and, when the vehicle-mounted camera detects iris features, generate an adversarial noise pattern to cover the sensitive area;

[0177] an actual driving state data set construction unit 7, configured to associate the real-time driving behavior data, the environment perception data, and the iris tracking data based on a preset common time axis to construct an actual driving state data set;

[0178] A driving state correction data generating unit 8 is configured to analyze the real-time driving state data based on a machine self-learning algorithm and generate driving state correction data.

[0179] an actual vehicle demand data generating unit 9, configured to be pre-configured with an actual vehicle demand analysis model to analyze the driving state correction data and the preliminary vehicle demand category based on a machine self-learning algorithm to generate actual vehicle demand data;

[0180] The modified privacy protection strategy generating unit 10 is configured to analyze the actual vehicle demand data based on preset privacy protection rules to generate a modified privacy protection strategy, wherein the modified privacy protection strategy is used to protect the customer's real-time driving status data.

[0181] Regarding the specific definition of the platform privacy data processing device based on customer car use needs, please refer to the definition of the platform privacy data processing method based on customer car use needs above, which will not be repeated here. The various modules in the above-mentioned platform privacy data processing device based on customer car use needs can be implemented in whole or in part by software, hardware, and a combination thereof. The above-mentioned modules can be embedded in or independent of the processor in the electronic device in hardware form, or can be stored in the memory of the electronic device in software form, so that the processor can call and execute the operations corresponding to the above modules.

[0182] In one embodiment, an electronic device is provided. The electronic device may be a server, and its internal structure diagram may be as follows: Figure 3 As shown. The electronic device includes a processor, a memory, a network interface and a database connected via a system bus. The processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the electronic device is used to store a database. The network interface of the electronic device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, a platform privacy data processing method based on customer vehicle use needs is implemented.

[0183] In one embodiment, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the following steps are performed:

[0184] Obtain the preliminary application data submitted by the customer when submitting the car demand, and extract the demand features from the preliminary application data to build the customer's multimodal demand dataset;

[0185] The pre-set customer demand analysis model analyzes the multimodal demand data set based on a machine self-learning algorithm to generate a preliminary vehicle demand category for the customer;

[0186] Analyzing the preliminary vehicle demand category based on pre-set preliminary privacy protection rules to generate a preliminary privacy protection policy, wherein the preliminary privacy protection policy is used to protect the customer's preliminary application data;

[0187] Acquiring real-time driving behavior data of the customer, wherein the real-time driving behavior data includes steering wheel rotation frequency and corresponding rotation angle, and driving pedal and brake pedal switching frequency data;

[0188] Acquiring driving environment perception data, wherein the environment perception data includes visual monitoring data and radar data;

[0189] Acquire iris tracking data of people in the car, and when the on-board camera detects iris features, generate adversarial noise patterns to cover sensitive areas;

[0190] Associating the real-time driving behavior data, the environmental perception data, and the iris tracking data based on a preset common timeline to construct an actual driving state dataset;

[0191] The preset driving state analysis model analyzes the real-time driving state data based on a machine self-learning algorithm to generate driving state correction data, wherein the driving state correction data is used to correct the preliminary vehicle demand category;

[0192] The preset actual vehicle demand analysis model analyzes the driving state correction data and the preliminary vehicle demand category based on a machine self-learning algorithm to generate actual vehicle demand data;

[0193] The actual vehicle demand data is analyzed based on preset privacy protection rules to generate a revised privacy protection strategy, where the revised privacy protection strategy is used to protect the customer's real-time driving status data.

[0194] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0195] Obtain the preliminary application data submitted by the customer when submitting the car demand, and extract the demand features from the preliminary application data to build the customer's multimodal demand dataset;

[0196] The pre-set customer demand analysis model analyzes the multimodal demand data set based on a machine self-learning algorithm to generate a preliminary vehicle demand category for the customer;

[0197] Analyzing the preliminary vehicle demand category based on pre-set preliminary privacy protection rules to generate a preliminary privacy protection policy, wherein the preliminary privacy protection policy is used to protect the customer's preliminary application data;

[0198] Acquiring real-time driving behavior data of the customer, wherein the real-time driving behavior data includes steering wheel rotation frequency and corresponding rotation angle, and driving pedal and brake pedal switching frequency data;

[0199] Acquiring driving environment perception data, wherein the environment perception data includes visual monitoring data and radar data;

[0200] Acquire iris tracking data of people in the car, and when the on-board camera detects iris features, generate adversarial noise patterns to cover sensitive areas;

[0201] Associating the real-time driving behavior data, the environmental perception data, and the iris tracking data based on a preset common timeline to construct an actual driving state dataset;

[0202] The preset driving state analysis model analyzes the real-time driving state data based on a machine self-learning algorithm to generate driving state correction data, wherein the driving state correction data is used to correct the preliminary vehicle demand category;

[0203] The preset actual vehicle demand analysis model analyzes the driving state correction data and the preliminary vehicle demand category based on a machine self-learning algorithm to generate actual vehicle demand data;

[0204] The actual vehicle demand data is analyzed based on preset privacy protection rules to generate a revised privacy protection strategy, where the revised privacy protection strategy is used to protect the customer's real-time driving status data.

[0205] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0206] Those skilled in the art will clearly understand that for the sake of convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.

[0207] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the scope of protection of the present application.

Claims

1. A platform privacy data processing method based on customer car use needs, characterized by: The method comprises the steps of: obtaining preliminary application data when a customer submits a vehicle demand, and extracting demand features from the preliminary application data to construct a multimodal demand dataset of the customer; The pre-set customer demand analysis model analyzes the multimodal demand data set based on a machine self-learning algorithm to generate a preliminary vehicle demand category for the customer; Analyzing the preliminary vehicle demand category based on pre-set preliminary privacy protection rules to generate a preliminary privacy protection policy, wherein the preliminary privacy protection policy is used to protect the customer's preliminary application data; Acquiring real-time driving behavior data of the customer, wherein the real-time driving behavior data includes steering wheel rotation frequency and corresponding rotation angle, and driving pedal and brake pedal switching frequency data; Acquiring driving environment perception data, wherein the environment perception data includes visual monitoring data and radar data; Acquire iris tracking data of people in the car, and when the on-board camera detects iris features, generate adversarial noise patterns to cover sensitive areas; Associating the real-time driving behavior data, the environmental perception data, and the iris tracking data based on a preset common timeline to construct an actual driving state dataset; The preset driving state analysis model analyzes the real-time driving state data based on a machine self-learning algorithm to generate driving state correction data, wherein the driving state correction data is used to correct the preliminary vehicle demand category; The preset actual vehicle demand analysis model analyzes the driving state correction data and the preliminary vehicle demand category based on a machine self-learning algorithm to generate actual vehicle demand data; Specifically, the actual driving behavior and the predicted value are compared through the federated learning algorithm to generate the driving deviation; Evaluating the driving deviation based on a machine self-learning algorithm to generate a corresponding abnormal behavior index; Analyzing the environmental perception data based on a visual recognition algorithm to dynamically generate an environmental threat coefficient; A preset driving dynamic risk assessment model comprehensively analyzes the abnormal behavior index and the environmental threat coefficient to generate a dynamic risk value for the customer, and the dynamic risk value is used to dynamically assess the priority level of privacy protection; Analyzing the actual vehicle demand data based on preset privacy protection rules to generate a revised privacy protection strategy, wherein the revised privacy protection strategy is used to protect the customer's real-time driving status data; Obtaining customer privacy-protected service feedback data, and associating the actual vehicle demand data, the revised privacy protection policy, and the service feedback data based on the public timeline to construct a privacy-related service feedback dataset; The preset privacy service adjustment model analyzes the privacy service feedback-related data set based on a machine self-learning algorithm to generate a privacy leakage-service degradation correlation coefficient, which is used to adjust the weighted value of the dynamic risk value calculation.

2. A platform privacy data processing method based on customer vehicle use needs according to claim 1, characterized in that: In the step of analyzing the multimodal demand data set based on the machine self-learning algorithm by the preset customer demand analysis model to generate the customer's preliminary vehicle demand category, the following steps are included: Obtaining each demand feature in the multimodal demand dataset, wherein the demand features include driving mode parameters, trip purpose, and passenger status; The pre-set customer demand profile construction model analyzes the multimodal demand data set based on a machine self-learning algorithm to construct a customer demand profile; Perform a weighted score on the customer demand profile based on a preset profile scoring model to calculate a comprehensive score for the customer's needs; Based on the comprehensive score of the customer's needs, a corresponding preliminary car demand category is generated, wherein the preliminary car demand category includes travel, business reception, shared car rental and emergency rescue.

3. A platform privacy data processing method based on customer vehicle use needs according to claim 2, characterized in that: After the pre-set customer demand profile building model analyzes the multimodal demand data set based on the machine self-learning algorithm to build the customer demand profile, the following steps are included: Build a vertical federation model across service providers to align privacy across different user profiles. Specifically, we identify overlapping users in each service provider's dataset as common samples for federated training, and extract detailed personal data of overlapping users as the initial common sample dataset; Establishing a logical mapping relationship of feature fields across service providers, and processing the initial common sample dataset based on the logical mapping relationship to construct a standard common sample dataset; The data with mapping relationship is used to calculate the cross-data features through homomorphic encryption algorithm to generate a joint feature vector; User ID preprocessing is performed on user identifiers of different service providers in the standard common sample data set to unify them into hash values, thereby eliminating format differences.

4. A platform privacy data processing method based on customer vehicle use needs according to claim 3, characterized in that: After pre-processing the user identifiers of different service providers in the standard common sample data set to unify them into hash values, the following steps are included: Adding Laplace noise to the feature bin boundaries of the standard common sample data set to confuse the statistical distribution; Each service provider calculates the characteristic Shapley value of the standard common sample data set locally, and obtains the global importance ranking corresponding to each data in the standard common sample data through a secure aggregation algorithm, thereby avoiding direct sharing of characteristic data by each service provider to prevent inferring user behavior.

5. The platform privacy data processing method based on customer vehicle use needs according to claim 3 is characterized in that: After building a cross-provider vertical federation model and aligning the privacy of different user profile features, the following steps are involved: Obtain the real-time renewal status of the service provider. If the service provider's renewal status has expired, the historical session key will be automatically destroyed, blocking the ability to decrypt the real-time standard common sample data set.

6. A platform privacy data processing device based on customer car use needs, applied to a platform privacy data processing method based on customer car use needs according to any one of claims 1 to 5, characterized in that: The device comprises: A multimodal demand data set construction unit (1) is used to obtain preliminary application data submitted by a customer when submitting a vehicle demand, and to extract demand features from the preliminary application data to construct a multimodal demand data set of the customer; A preliminary vehicle demand category generating unit (2) is configured to be pre-configured with a customer demand analysis model to analyze the multimodal demand data set based on a machine self-learning algorithm to generate a preliminary vehicle demand category for the customer; A preliminary privacy protection strategy generating unit (3) is used to analyze the preliminary vehicle demand category based on a preset preliminary privacy protection rule to generate a preliminary privacy protection strategy, wherein the preliminary privacy protection strategy is used to protect the preliminary application data of the customer; A real-time driving behavior data acquisition unit (4), configured to acquire the customer's real-time driving behavior data; An environmental perception data acquisition unit (5), used for acquiring driving environmental perception data; An iris tracking data acquisition unit (6) is used to acquire iris tracking data of a person in the vehicle, and when an onboard camera detects an iris feature, generate an adversarial noise pattern to cover a sensitive area; an actual driving state data set construction unit (7), configured to associate the real-time driving behavior data, the environment perception data, and the iris tracking data based on a preset common time axis to construct an actual driving state data set; A driving state correction data generating unit (8) is configured to be pre-configured with a driving state analysis model to analyze the real-time driving state data based on a machine self-learning algorithm to generate driving state correction data; an actual vehicle use demand data generating unit (9), configured to be pre-configured with an actual vehicle use demand analysis model to analyze the driving state correction data and the preliminary vehicle use demand category based on a machine self-learning algorithm to generate actual vehicle use demand data; A modified privacy protection strategy generating unit (10) is used to analyze the actual vehicle demand data based on preset privacy protection rules to generate a modified privacy protection strategy, wherein the modified privacy protection strategy is used to protect the real-time driving status data of the customer.

7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of a platform privacy data processing method based on customer vehicle usage needs as described in any one of claims 1 to 5 are implemented.

8. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by the processor, the steps of a platform privacy data processing method based on customer vehicle usage needs as described in any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Customer privacy protection method and system, computer equipment and storage medium

    CN116776381A

  • Vehicle intelligent service method and device based on big data analysis and intelligent terminal

    CN117390647A