A CPE anti-identification privacy protection system based on lightweight homomorphic encryption security model

Through the coordinated optimization of lightweight homomorphic encryption modules, scattering invariant neural networks, and quantization-aware training modules, the challenges of CPE identification technology in data privacy protection, anti-interference, and edge device adaptation are solved, achieving the unity of privacy protection strength, anti-attack capability, and operational efficiency, making it suitable for edge computing scenarios.

CN120408703BActive Publication Date: 2025-10-03BEIJING SHIXING TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510500694.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-10-03
Estimated Expiration
2045-04-21

AI Technical Summary

Technical Problem

Existing CPE identification technology faces difficulties in data privacy protection, anti-interference and edge device adaptation. Existing defense solutions cannot simultaneously meet the requirements of privacy protection, anti-interference and lightweight edge devices.

Method used

By adopting lightweight homomorphic encryption module, scattering invariant neural network recognition module and quantization perception training module, we build an encryption-defense-efficiency collaborative optimization system to realize the full-process encrypted data processing, integrate the geometric invariance characteristics of the scattering invariant network with the dynamic defense mechanism, and perform lightweight compression optimization of the model.

Benefits of technology

It achieves the organic unity of privacy protection strength, anti-attack capability and operational efficiency in edge computing scenarios, breaks through the bottleneck that traditional encryption technology cannot support ciphertext model training, and improves the model's anti-interference ability and adaptability to complex environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120408703B_ABST
    Figure CN120408703B_ABST
Patent Text Reader

Abstract

The present invention discloses a CPE anti-identification privacy protection system based on a lightweight homomorphic encryption security large model. The system relates to the interdisciplinary field of network security and privacy computing. It comprises: a lightweight homomorphic encryption module, a scattering-invariant neural network recognition module, and a quantization-aware training module; the lightweight homomorphic encryption module processes the acquired original CPE data into ciphertext, which is then input into the scattering-invariant neural network recognition module; the scattering-invariant neural network recognition module extracts and recognizes the ciphertext, which is then input into the quantization-aware training module as feature data; the quantization-aware training module quantizes the feature data, performs simulated quantization and training optimization based on the ciphertext in the lightweight homomorphic encryption module, and adjusts the model's parameters and quantization strategy. The present invention can achieve an organic unity of privacy security, anti-attack capability, and operational efficiency, providing a systematic solution for the secure deployment of CPE identification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the interdisciplinary field of network security and privacy computing, and more specifically to a CPE anti-identification privacy protection system based on a lightweight homomorphic encryption security model. Background Art

[0002] Common Platform Enumeration (CPE) technology is an internationally recognized software asset identification standard for software supply chain security management. It accurately locates software components and their versions, supporting vulnerability correlation analysis and improving vulnerability response and threat warning capabilities. However, existing CPE technology deployment faces three constraints: data privacy, malicious attack interference, and model complexity adaptation.

[0003] In recent years, deep learning technology has brought new opportunities to the field of software security. Automated feature learning mechanisms based on deep learning can uncover correlation patterns in software metadata and improve the accuracy of software version identification. Intelligent recognition systems based on large models also demonstrate the advantages of multimodal processing. However, CPE intelligent recognition technology faces severe security challenges. Attackers can construct malicious interference data, resulting in inaccurate recognition and delayed warnings. Existing defense solutions have limited effectiveness and increase model complexity and computational overhead, making it difficult to simultaneously meet the requirements of privacy protection, anti-interference, and edge device adaptability.

[0004] Adversarial defense technologies in the field of artificial intelligence offer a path forward for addressing privacy protection issues in CPE identification systems. Techniques such as adversarial training and data purification enhance the model's survivability against malicious attacks and offer advantages in CPE identification scenarios. However, existing defense solutions, when implemented, pose privacy risks and struggle to meet the lightweight requirements of edge nodes.

[0005] Therefore, it is an urgent problem for technical personnel in this field to propose a privacy protection defense system for CPE identification scenarios and achieve coordinated optimization of data security, anti-interference capability and computing efficiency through three-stage technological innovation. Summary of the Invention

[0006] In view of this, the present invention provides a CPE anti-identification privacy protection system based on a lightweight homomorphic encryption security model. The system overcomes the compatibility problem between encrypted computing and intelligent identification, and realizes the organic unity of privacy security, anti-attack capability and operational efficiency in scenarios such as the industrial Internet of Things, providing a systematic solution for the secure deployment of CPE identification.

[0007] To achieve the above objectives, the present invention adopts the following technical solutions: a CPE anti-identification privacy protection system based on a lightweight homomorphic encryption security large model, comprising: a lightweight homomorphic encryption module, a scattering invariant neural network recognition module, and a quantization perception training module;

[0008] The lightweight homomorphic encryption module processes the acquired original CPE data into ciphertext and inputs the ciphertext into the scattering invariant neural network recognition module;

[0009] The scattering invariant neural network recognition module extracts and recognizes the ciphertext and inputs it into the quantization perception training module as feature data;

[0010] The quantization-aware training module quantizes the feature data, and performs simulated quantization and training optimization based on the ciphertext in the lightweight homomorphic encryption module to adjust the parameters and quantization strategy of the model.

[0011] Preferably, the lightweight homomorphic encryption module includes a key generation layer, a key encryption layer, a homomorphic operation layer, a homomorphic decryption layer and a lightweight optimization layer connected in sequence;

[0012] The key generation layer is used to generate the public key, private key and evaluation key required for homomorphic encryption, and dynamically optimize the key parameter configuration;

[0013] The key encryption layer is used to introduce a block processing strategy to perform block encoding on the unstructured original CPE data and then encrypt it in parallel;

[0014] The homomorphic operation layer is used to perform addition and multiplication homomorphic operations in the ciphertext state;

[0015] The homomorphic decryption layer is used to decrypt the ciphertext calculation result into plaintext output, verify the data integrity, and decrypt the original CPE data;

[0016] The lightweight optimization layer constructs a sparse polynomial ring based on the Ring-LWE problem and protects the privacy of the sparse structure through random masking technology.

[0017] Preferably, the key generation layer generates a public key, a private key and an evaluation key based on Paillier encryption.

[0018] Preferably, the scattering invariance neural network recognition module includes a multi-scale scattering transformation layer, an invariance feature learning layer and a feature fusion enhancement layer connected in sequence;

[0019] The multi-scale scattering transform layer performs multi-scale decomposition on the input ciphertext, constructs a feature basis that is translationally and rotationally invariant, and obtains a multi-scale scattering coefficient. The multi-scale scattering coefficient provides a basic feature representation for the invariance feature learning layer.

[0020] The invariant feature learning layer learns and optimizes feature data according to the multi-scale scattering coefficient, and transmits the optimized feature data to the feature fusion enhancement layer;

[0021] The feature fusion enhancement layer fuses the optimized feature data at different levels based on the multi-scale scattering coefficient.

[0022] Preferably, the multi-scale scattering transformation layer uses a dynamic wavelet basis set to perform multi-scale decomposition on the input ciphertext to extract low-frequency features and high-frequency details with geometric invariance; and constructs a feature expression base with translation and rotation invariance through hierarchical scattering coefficient calculation;

[0023] The invariant feature learning layer introduces a geometric transformation data augmentation strategy to improve the model's robustness to input perturbations through adversarial training; a feature stability loss function is deployed to constrain the geometric invariance of the network output;

[0024] The feature fusion enhancement layer performs cross-scale fusion on the multi-scale scattering coefficients, strengthens the key feature channels through the attention weighting mechanism, and implements feature space orthogonalization processing to eliminate redundant features and improve feature discrimination.

[0025] Preferably, the quantization-aware training module includes a quantization strategy control layer and a quantization training optimization layer. The quantization strategy control layer is used to dynamically analyze the parameter distribution characteristics of each layer of the model, analyze the impact of quantization error on model accuracy based on gradient propagation, give priority to protecting the accuracy of key layers, and realize the compression of the progressive CPE identification model with controllable accuracy loss;

[0026] The quantization training optimization layer simulates quantization noise during the training phase, introduces dynamic quantization noise in back propagation, and enhances the model's adaptability to low-bitwidth calculations through pseudo-quantization operations; implements gradient rescaling and calibration technology, and maintains training stability through gradient amplitude normalization and direction correction.

[0027] Through the above technical solutions, it can be seen that compared with the existing technology, the present invention discloses a CPE anti-identification privacy protection system based on a lightweight homomorphic encryption security large model. The advantages are: the present invention innovatively constructs a technical system for collaborative optimization of "encryption-defense-efficiency", and realizes the full-process confidential processing of data through lightweight homomorphic encryption, breaking through the bottleneck that traditional encryption technology cannot support ciphertext model training; integrating the geometric invariance characteristics of the scattering invariant network and the dynamic defense mechanism, significantly improving the model's anti-interference ability and adaptability to complex environments; and creating an original model lightweight compression optimization strategy based on a quantization-aware training framework to achieve a coordinated improvement in model volume compression and inference efficiency. This solution systematically solves the compatibility problem between encrypted computing and intelligent identification, achieves an organic unity of privacy protection strength, anti-attack capability and operational efficiency in edge computing scenarios, and provides feasible technical support for building a zero-trust security architecture. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.

[0029] Figure 1 A schematic diagram of the structure of the CPE anti-identification privacy protection system based on the lightweight homomorphic encryption security model provided by the present invention;

[0030] Figure 2 A schematic diagram of the structure of the lightweight homomorphic encryption module provided by the present invention;

[0031] Figure 3 This is a schematic diagram of the structure of the scattering invariance neural network recognition module provided by the present invention;

[0032] Figure 4 This is a structural diagram of the quantization perception training module provided by the present invention. DETAILED DESCRIPTION

[0033] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0034] like Figure 1 As shown, the embodiment of the present invention discloses a CPE anti-identification privacy protection system based on a lightweight homomorphic encryption security large model, including: a lightweight homomorphic encryption module, a scattering invariant neural network recognition module and a quantization perception training module;

[0035] The lightweight homomorphic encryption module processes the acquired original CPE data into ciphertext and inputs the ciphertext into the scattering invariant neural network recognition module;

[0036] The scattering invariant neural network recognition module extracts and recognizes the ciphertext and inputs it into the quantization perception training module as feature data;

[0037] The quantization-aware training module quantizes the feature data, and performs simulated quantization and training optimization based on the ciphertext in the lightweight homomorphic encryption module to adjust the parameters and quantization strategy of the model.

[0038] like Figure 2As shown, specifically, the lightweight homomorphic encryption module includes a key generation layer, a key encryption layer, a homomorphic operation layer, a homomorphic decryption layer and a lightweight optimization layer connected in sequence;

[0039] The key generation layer is used to generate the public key, private key and evaluation key required for homomorphic encryption, and dynamically optimize the key parameter configuration;

[0040] The key encryption layer is used to introduce a block processing strategy to perform block encoding on the unstructured original CPE data and then encrypt it in parallel;

[0041] The homomorphic operation layer is used to perform addition and multiplication homomorphic operations in the ciphertext state;

[0042] The homomorphic decryption layer is used to decrypt the ciphertext calculation result into plaintext output, verify the data integrity, and decrypt the original CPE data;

[0043] The lightweight optimization layer constructs a sparse polynomial ring based on the Ring-LWE problem and protects the privacy of the sparse structure through random masking technology.

[0044] Specifically, the key generation layer generates a public key, a private key and an evaluation key based on the Paillier encryption method.

[0045] In a specific embodiment, the specific steps for generating the public key, private key, and evaluation key based on the Paillier encryption method are as follows:

[0046] Select two large prime numbers p and q, and calculate n = p × q and λ = lcm(p-1,q-1), where lcm represents the least common multiple.

[0047] Choose a random integer g∈Z n * , i.e., select an element from the multiplicative group modulo n. Then, calculate the function f, which is usually related to g and n, for example, it can be f = g n mod n 2 The calculation result of this function will be used for subsequent decryption operations.

[0048] Let the private key be sk = (λ, f) and the public key be pk = (n, g). These two keys will be used for decryption and encryption operations respectively.

[0049] In another specific embodiment provided by the present invention, the key encryption layer uses the public key to encrypt plaintext data to generate ciphertext. The encryption process must ensure the security of the ciphertext during transmission and storage. Even if it is intercepted by an attacker, no useful information can be extracted from it. At the same time, to meet the characteristics of homomorphic encryption, the encryption process must preserve the ciphertext's closedness to specific mathematical operations. That is, the encrypted ciphertext can be directly used for certain operations without first decrypting it. The specific encryption process is as follows:

[0050] For the plaintext m∈Z to be encrypted n , first from Z n * A random integer r is randomly selected from the ciphertext as the random number in the encryption process. The introduction of this random number is to increase the unpredictability of the ciphertext and improve the security of the encryption scheme.

[0051] Calculate the ciphertext c=g m ×r n mod n 2 This formula utilizes the parameters g and n in the public key, combining the plaintext m and the random number r through modular exponential operation to generate the final ciphertext c. This ciphertext can directly participate in specific mathematical operations in the subsequent homomorphic operation layer.

[0052] In another specific embodiment provided by the present invention, the homomorphic operation layer performs specific mathematical operations, such as addition or multiplication, directly on the ciphertext without accessing the plaintext data. This feature enables meaningful calculations on encrypted data while protecting data privacy, expanding the application scenarios of data processing. The specific homomorphic addition operation is implemented as follows:

[0053] 1. Suppose there are two ciphertexts and The encryption results corresponding to plaintext m1 and m2 respectively.

[0054] 2. Directly multiply the two ciphertexts to obtain the new ciphertext c sum =c1×c2modn 2 According to the properties of Paillier encryption, this new ciphertext actually corresponds to the encryption result of plaintext m1+m2, that is, This shows that the multiplication operation in the ciphertext space is equivalent to the addition operation in the plaintext space, thus achieving homomorphic addition.

[0055] In another specific embodiment provided by the present invention, the homomorphic decryption layer converts the ciphertext after homomorphic operation back to the original plaintext data by using the private key. The decryption process must be accurate and efficient to ensure that the correct plaintext is recovered from the ciphertext, while also ensuring data security throughout the process and preventing system vulnerabilities caused by private key leakage. The specific decryption process is as follows:

[0056] For the ciphertext c to be decrypted, first calculate c λ mod n 2 , and then apply the function L(u)=u-1 / n to process it, and get L(c λ mod n 2 ).

[0057] Similarly, calculate g λ mod n 2 And apply the function L, we get L(g λ mod n 2 ).

[0058] Finally, by calculating The original plaintext m can be restored. This process uses the parameters λ and f in the private key to map the ciphertext back to the plaintext space through modular operations and function L.

[0059] In another specific embodiment provided by the present invention, the lightweight optimization layer optimizes the computing and storage resource requirements of the homomorphic encryption model, making it more suitable for running on devices with limited computing power. By simplifying the steps of the encryption and decryption algorithms, the operating efficiency and response speed of the system can be improved without significantly reducing security, thereby expanding the practical application scope of homomorphic encryption technology. When performing continuous homomorphic addition of multiple ciphertexts, a cumulative calculation method can be used to avoid performing a complete modular operation for each operation. For example, for multiple ciphertexts c1, c2, ..., c k , we can first perform addition accumulation in the integer domain:

[0060]

[0061] Then, when the final result is needed, perform the modular operation uniformly:

[0062] C final =C sum mod n 2

[0063] This reduces the number of intermediate modular operations and computational complexity. By applying these mathematical formulas, the lightweight optimization layer can effectively improve the computational efficiency and resource utilization of the lightweight homomorphic encryption model, making it more suitable for use in resource-constrained environments.

[0064] Specifically, the scattering invariant neural network recognition module includes a multi-scale scattering transformation layer, an invariant feature learning layer and a feature fusion enhancement layer connected in sequence;

[0065] The multi-scale scattering transform layer performs multi-scale decomposition on the input ciphertext, constructs a feature basis that is translationally and rotationally invariant, and obtains a multi-scale scattering coefficient. The multi-scale scattering coefficient provides a basic feature representation for the invariance feature learning layer.

[0066] The invariant feature learning layer learns and optimizes feature data according to the multi-scale scattering coefficient, and transmits the optimized feature data to the feature fusion enhancement layer;

[0067] The feature fusion enhancement layer fuses the optimized feature data at different levels based on the multi-scale scattering coefficient.

[0068] Specifically, the feature fusion enhancement layer fuses the features extracted by the "multi-scale scattering transform layer" and the "invariance feature learning layer" to form a more comprehensive and robust feature representation. This fused feature representation not only retains the global structure of the data, but is also invariant to various transformations, thereby enhancing the expressiveness and discriminative capabilities of the features.

[0069] Specifically, the multi-scale scattering transform layer uses a dynamic wavelet basis set to perform multi-scale decomposition on the input ciphertext, extracting low-frequency features and high-frequency details with geometric invariance; and constructing a feature expression basis with translation and rotation invariance through hierarchical scattering coefficient calculation.

[0070] The invariant feature learning layer introduces a geometric transformation data augmentation strategy to improve the model's robustness to input perturbations through adversarial training; a feature stability loss function is deployed to constrain the geometric invariance of the network output;

[0071] The feature fusion enhancement layer performs cross-scale fusion on the multi-scale scattering coefficients, strengthens the key feature channels through the attention weighting mechanism, and implements feature space orthogonalization processing to eliminate redundant features and improve feature discrimination.

[0072] In another specific embodiment of the present invention, the multiscale scattering transform layer, based on wavelet scattering transform theory, can extract multi-scale and multi-directional features from input signals. This layer simulates the signal's fluctuations and scattering behavior at different scales to capture both local and global signal characteristics. These features are invariant and robust to noise and geometric deformation of the target, providing a solid foundation for subsequent feature processing and classification.

[0073] Specifically, such as Figure 3As shown, the multi-scale scattering transformation layer includes a physical model-driven feature extraction module, a data-driven high-dimensional feature compression module and a pattern recognition module. The CPE data to be identified is input into the physical model-driven feature extraction module for convolution and filtering, and then global average pooling is performed in the data-driven high-dimensional feature compression module. Finally, the CPE data is input into the pattern recognition module to output the CPE identification result.

[0074] Specifically, the multi-scale scattering transform layer obtains scattering features at different scales by performing a series of convolution and modulus operations on the input signal. These features can effectively characterize the essential characteristics of the signal and remain relatively stable even in the presence of noise interference. The mathematical formula of the wavelet scattering transform is:

[0075] S j [f](t)=|f*ψ j |(t)

[0076] Among them, S j [f](t) represents the scattering characteristics at the jth scale, f is the input signal, ψ j is the wavelet function at the jth scale, * denotes the convolution operation, and || denotes taking the absolute value. This formula describes how to obtain the scattering characteristics at different scales by convolving the wavelet function with the input signal. Furthermore, the multi-scale scattering transform can be expressed as:

[0077]

[0078] Among them, j1, j2, …, j n Representing combinations of different scales, by performing convolution and modular operations layer by layer, we obtain multi-scale scattering features, i.e., feature data that is robust to local transformations. These features can capture the local fluctuations and structural information of the signal at different scales, providing rich basic data for subsequent feature fusion and classification.

[0079] In another specific embodiment of the present invention, the invariance feature learning layer leverages the learning capabilities of deep neural networks to further extract feature representations that are invariant to noise and target variations. This layer typically consists of multiple neural network layers, such as convolutional layers, pooling layers, and fully connected layers. Through nonlinear transformations and parameter learning, it gradually transforms the features extracted by the multi-scale scattering transform layer into higher-level abstract representations.

[0080] These representations can better capture the essential features of the target and are more robust to noise and geometric changes. Specifically, the network automatically adjusts parameters by learning a large number of noisy training samples so that the extracted features remain consistent under different noise conditions and target posture changes, thereby improving the model's noise resistance and recognition performance. Assume that the input feature is Fin , the output feature is F out , the parameters of the convolution layer are the weight matrix W and the bias vector b, then the convolution operation can be expressed as:

[0081] F out =σ(W·F in +b)

[0082] Where σ is the ReLU activation function. This formula describes how to extract nonlinear representations of features through convolution operations. During training, network parameters are optimized by minimizing the loss function. The corresponding cross entropy loss can be expressed as:

[0083]

[0084] Among them, y i is the true label, is the probability output of the network prediction, and N is the number of categories. The gradient is calculated by the backpropagation algorithm, and the Adam optimization algorithm is used to update the model parameters:

[0085]

[0086] Where η is the learning rate, and are the gradients of the loss function with respect to weights and biases, respectively. The above formulas together describe how to gradually optimize feature representation through deep learning methods to make it have stronger invariance and robustness of CPE features.

[0087] Specifically, the quantization-aware training module includes a quantization strategy control layer and a quantization training optimization layer. The quantization strategy control layer is used to dynamically analyze the parameter distribution characteristics of each layer of the model, analyze the impact of quantization error on model accuracy based on gradient propagation, prioritize the protection of key layer accuracy, and achieve progressive CPE identification model compression with controllable accuracy loss.

[0088] Specifically, the parameters of each layer refer to the weights and activation values ​​of each layer of the scattering invariant neural network recognition module.

[0089] In another specific embodiment provided by the present invention, Figure 4 As shown, the quantization training optimization layer simulates quantization noise in the training phase, introduces dynamic quantization noise in back propagation, and enhances the model's adaptability to low-bitwidth calculations through pseudo-quantization operations; implements gradient rescaling and calibration technology, and maintains training stability through gradient amplitude normalization and direction correction.

[0090] Furthermore, the quantization strategy control layer is mainly responsible for inserting fake quantization nodes (FakeQuantize Nodes) during the model training process. These nodes simulate the quantization process, allowing the model to gradually adapt to low-precision representation. By counting the data range of input and output during training, the quantization strategy control layer can help determine the quantization parameters, thereby maintaining the privacy protection performance of the CPE identification security large model as much as possible after quantization. Specifically, it will perform range statistics on key data such as activation values ​​and weights during the forward propagation of the model, providing the necessary parameter basis for subsequent quantization operations. Assuming the floating-point value range is r min ,r max , the quantization target is an n-bit integer (usually n = 8), then the quantization formula is:

[0091]

[0092] Where S is the scaling factor, which determines the floating-point span of each quantization step. Quantization is achieved by mapping the floating-point value range to the integer range. Z is the zero offset, which ensures that floating-point zero values ​​are accurately mapped to integer values, thereby reducing quantization errors. Q is the quantized integer value, and R is the original floating-point value.

[0093] In the quantization training optimization layer, the main focus is on how to optimize the quantization parameters and model weights during the training process to minimize the accuracy loss caused by quantization. The optimization strategies at this layer include adjusting the learning rate, using mixed precision training and other methods. Through a reasonable learning rate scheduling strategy, it can be ensured that the quantization parameters and model weights are stably updated during the training process, thereby gradually improving the performance of the model after quantization. In addition, the mixed precision training method can balance the accuracy and computational efficiency of the model during the training process. By using different precision representations for data in different layers or different parts, the model can be trained and inferred more efficiently while maintaining high accuracy. In order to stabilize the learning of quantization parameters, a phased learning rate scheduling strategy is adopted. The specific scheduling strategy is as follows:

[0094] Initial stage (0-30%): The learning rate is set to a low value, such as η1 = 1 × 10 -5 At this time, the model has just begun to adapt to quantization, and a low learning rate helps to stabilize the update of quantization parameters.

[0095] Mid-term stage (30% to 70%): The learning rate gradually increases to the basic value Right now Speed ​​up model convergence.

[0096] Late stage (70% to 100%): Use the cosine decay formula to adjust the learning rate, so that the learning rate gradually decreases to help fine-tune the model:

[0097]

[0098] Among them, η base is the basic learning rate, t is the current training round, T mid is the end round of the mid-term stage, T end is the total number of training rounds.

[0099] In addition, in mixed precision training, FP16 precision is retained for sensitive layers, and other layers are quantized to balance accuracy and computational efficiency. The corresponding weight update formula is:

[0100]

[0101] Among them, θ t is the model weight of the tth round, η is the learning rate, is the gradient of the loss function with respect to the weights. During the training process, quantization parameters (such as the scaling factor S and the zero offset Z) also need to be updated. Taking the scaling factor S as an example, its update formula is:

[0102]

[0103] Where α is the learning rate, and is the maximum and minimum estimate of the current batch of data, and n is the number of quantization bits. This formula adjusts the scaling factor by minimizing the quantization error so that the quantized data more accurately represents the original floating-point data.

[0104] This strategy is based on the different sensitivities of different layers to quantization errors. By retaining higher precision for sensitive layers, it protects the model's key information from being destroyed by excessive quantization. At the same time, it quantizes relatively less sensitive layers to reduce overall computing resource consumption and improve the efficiency of training and inference.

[0105] The core innovations of this invention lie in: 1. Building a collaborative architecture for encrypted computing and intelligent recognition, achieving simultaneous optimization of feature analysis and attack defense in the encrypted state; 2. Designing a geometrically invariant feature extraction network to suppress adversarial perturbations through multi-scale scattering transforms; and 3. Developing a lightweight model adapted for encrypted domain computing to overcome resource constraints on edge devices. Compared to traditional solutions, this invention achieves a synergistic improvement in privacy protection, attack resistance, and operational efficiency.

[0106] It should be noted that the implementation details of this invention can be adjusted according to specific application scenarios, including but not limited to encryption algorithm parameter configuration, neural network layer design, and quantization strategy selection. The combination and optimization of the above technical features are all within the scope of protection of this invention, and any improvement scheme based on the core architecture of this invention should be included in the scope of the claims.

[0107] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Reference can be made to the common and similar parts between the various embodiments. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method description.

[0108] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not limited to the embodiments shown herein but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A CPE anti-identification privacy protection system based on a lightweight homomorphic encryption security model, characterized by: include: Lightweight homomorphic encryption module, scattering invariant neural network recognition module, and quantization-aware training module; The lightweight homomorphic encryption module processes the acquired original CPE data into ciphertext and inputs the ciphertext into the scattering invariant neural network recognition module; The scattering invariant neural network recognition module extracts and recognizes the ciphertext and inputs it into the quantization perception training module as feature data; The quantization-aware training module quantizes the feature data, and performs simulated quantization and training optimization based on the ciphertext in the lightweight homomorphic encryption module to adjust the parameters and quantization strategy of the model.

2. A CPE anti-identification privacy protection system based on a lightweight homomorphic encryption security model according to claim 1, characterized in that: The lightweight homomorphic encryption module includes a key generation layer, a key encryption layer, a homomorphic operation layer, a homomorphic decryption layer and a lightweight optimization layer connected in sequence; The key generation layer is used to generate the public key, private key and evaluation key required for homomorphic encryption, and dynamically optimize the key parameter configuration; The key encryption layer is used to introduce a block processing strategy to perform block encoding on the unstructured original CPE data and then encrypt it in parallel; The homomorphic operation layer is used to perform addition and multiplication homomorphic operations in the ciphertext state; The homomorphic decryption layer is used to decrypt the ciphertext calculation result into plaintext output, verify the data integrity, and decrypt the original CPE data; The lightweight optimization layer constructs a sparse polynomial ring based on the Ring-LWE problem and protects the privacy of the sparse structure through random masking technology.

3. A CPE anti-identification privacy protection system based on a lightweight homomorphic encryption security model according to claim 2, characterized in that: The key generation layer generates public keys, private keys and evaluation keys based on Paillier encryption.

4. A CPE anti-identification privacy protection system based on a lightweight homomorphic encryption security model according to claim 1, characterized in that: The scattering invariant neural network recognition module includes a multi-scale scattering transformation layer, an invariant feature learning layer and a feature fusion enhancement layer connected in sequence; The multi-scale scattering transform layer performs multi-scale decomposition on the input ciphertext, constructs a feature basis that is translationally and rotationally invariant, and obtains a multi-scale scattering coefficient. The multi-scale scattering coefficient provides a basic feature representation for the invariance feature learning layer. The invariant feature learning layer learns and optimizes feature data according to the multi-scale scattering coefficient, and transmits the optimized feature data to the feature fusion enhancement layer; The feature fusion enhancement layer fuses the optimized feature data at different levels based on the multi-scale scattering coefficient.

5. A CPE anti-identification privacy protection system based on a lightweight homomorphic encryption security model according to claim 4, characterized in that: The multi-scale scattering transform layer uses a dynamic wavelet basis set to perform multi-scale decomposition on the input ciphertext to extract low-frequency features and high-frequency details with geometric invariance; By calculating the hierarchical scattering coefficient, a feature expression base with translation and rotation invariance is constructed; The invariant feature learning layer introduces a geometric transformation data augmentation strategy to improve the robustness of the model to input perturbations through adversarial training; Deploy a feature stability loss function to constrain the geometric invariance of the network output; The feature fusion enhancement layer performs cross-scale fusion on the multi-scale scattering coefficients and strengthens the key feature channels through the attention weighting mechanism; Implement feature space orthogonalization processing to eliminate redundant features and improve feature discrimination.

6. A CPE anti-identification privacy protection system based on a lightweight homomorphic encryption security model according to claim 1, characterized in that: The quantization-aware training module includes a quantization strategy control layer and a quantization training optimization layer. The quantization strategy control layer is used to dynamically analyze the parameter distribution characteristics of each layer of the model, analyze the impact of quantization error on model accuracy based on gradient propagation, prioritize the accuracy of key layers, and achieve progressive CPE identification model compression with controllable accuracy loss. The quantization training optimization layer simulates quantization noise during the training phase, introduces dynamic quantization noise in back propagation, and enhances the model's adaptability to low-bitwidth calculations through pseudo-quantization operations; Implement gradient rescaling and calibration techniques to maintain training stability by normalizing gradient magnitudes and correcting their directions.

Citation Information

Patent Citations

  • Longitudinal federated learning privacy protection method and system based on multi-key homomorphic encryption

    CN115455476A

  • Adversarial sample recovery method and system based on wavelet transform and attention mechanism

    CN116452918A