Matrix decomposition recommendation method based on shuffling differential privacy
By combining shuffle differential privacy and random projection technology, the noise sensitivity and communication overhead are reduced, the data utility and privacy protection problems of the traditional matrix decomposition recommendation system are solved, and an efficient and secure recommendation system is realized.
Patent Information
- Application Number
- CN202511106570.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-08
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2045-08-08
AI Technical Summary
Traditional differential matrix factorization recommendation systems have low data utility, high communication and computational overhead, and local differential privacy models consume the privacy budget too quickly during iteration, resulting in difficulty in model convergence and high computing resource requirements.
A matrix decomposition recommendation method based on shuffle differential privacy is adopted, combined with random projection and multi-message shuffling model. By random dimensionality reduction and local perturbation gradient information, noise sensitivity is reduced, communication overhead is reduced, and the anonymization characteristics of the shuffle model are utilized to enhance privacy protection.
It significantly improves the privacy protection capability of the matrix decomposition recommendation system, reduces communication and computational overhead, ensures the efficiency and accuracy of the model, and achieves high-intensity privacy protection under low local noise conditions.
Smart Images

Figure CN120597334A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of differential privacy technology, and more specifically, to a matrix decomposition recommendation method based on shuffled differential privacy. Background Art
[0002] With the prevalence of mobile devices, consumers are increasingly relying on online marketplaces for their purchases. Faced with a wealth of choices, consumers' decision-making processes have become more complex, making the role of recommendation systems increasingly important. Recommendation systems not only help consumers discover products of interest but also provide personalized recommendations. By collecting and analyzing user behavior data, recommendation systems can optimize the user experience. However, this data often contains sensitive personal information, such as user rating patterns or item selection preferences, which can lead to the disclosure of private information such as gender and political leanings. Therefore, protecting user privacy has become a key issue in recommendation systems.
[0003] Among numerous privacy-preserving technologies, differential privacy (DP) has become a core standard in the data protection field. Traditional privacy-preserving methods are mostly based on centralized differential privacy (CentralizedDP), which assumes the existence of a trusted server that adds noise to aggregated data. However, in real-world applications, recommendation service providers may be untrustworthy, and a leak of centrally stored user data could have serious consequences. To mitigate this risk, local differential privacy (DP) has been proposed. In this approach, users perturb their data locally before uploading it, thus avoiding the risk of data leakage from centralized storage. However, local differential privacy typically requires a high amount of noise, which can significantly reduce model accuracy. Furthermore, in scenarios with multiple data interactions, the privacy budget is quickly depleted, limiting its application in big data analytics and machine learning.
[0004] To address this challenge, the DP Shuffle Model has been proposed as a promising alternative. In the Shuffle Model, a shuffler randomly arranges user information before publishing it to the server. Since the shuffler only rearranges the information without accessing its content, it is considered semi-trusted and can be implemented through anonymous channels or edge servers. By shuffling, users can inject less noise (low local privacy protection), thereby significantly amplifying the privacy protection effect. Recent studies have shown that from the server's perspective, the scrambled local ϵ-DP messages from n users can achieve . Thus, the utility of the shuffled model exceeds that of the local model and may approach that of the central model.
[0005] On the other hand, traditional content-based recommendation systems rely on collecting extensive user personal information and interaction data to provide personalized recommendations, which not only increases the risk of privacy breaches but also increases computing resource requirements. In contrast, collaborative filtering recommendation systems focus more on user evaluations and behavioral patterns, making them more adaptable to the addition of new users and products. Model-based collaborative filtering methods, in particular, can make recommendations by learning latent features of users and products, exhibiting strong generalization capabilities. However, applying local differential privacy (LDP) to matrix factorization faces two major challenges: First, the item dimensionality (typically tens of thousands to millions) causes gradient perturbation noise to grow linearly with dimensionality, severely impacting model effectiveness; second, the round-by-round allocation of the privacy budget during iterative optimization (e.g., when the total budget is ϵ, only ϵ / k is allocated per round) causes noise to amplify exponentially with the number of iterations, making it difficult for the model to converge.
[0006] In summary, the existing technologies still face the following problems and challenges: 1. The data utility of traditional differential matrix decomposition recommendation systems is low: Since the matrix decomposition process involves multiple iterative optimizations, the privacy budget needs to be divided. If the number of iterations is much larger than the privacy budget, the privacy budget of a single round will approach zero, resulting in the system being unable to obtain effective statistical information from the noise, resulting in low data utility. 2. High communication and computational overhead: The differential matrix decomposition recommendation system requires multiple interactions between users and the server, and users also need to perform complex calculations to meet differential privacy requirements. Due to privacy protection, the complete item feature matrix needs to be downloaded during the communication between the server and the user, which increases communication and computational overhead.
[0007] To address these issues, this paper proposes a privacy-preserving matrix factorization framework that combines dimensionality reduction techniques with a multi-message shuffling model. Random projection is used to map high-dimensional gradients to a low-dimensional space, significantly reducing noise sensitivity. A sampling-based binary perturbation mechanism perturbs only randomly selected gradient dimensions on the user side, reducing communication overhead. Furthermore, by leveraging the anonymization properties of the shuffling model and combining it with a privacy amplification effect analysis method, this approach provides a tighter theoretical privacy bound for the privacy-preserving mechanism, thereby increasing the privacy budget for each iteration and further improving the effectiveness of the recommendation system. Summary of the Invention
[0008] The present invention aims to overcome at least one defect (shortcoming) of the above-mentioned prior art and provide a matrix decomposition recommendation method based on shuffled differential privacy, which is used to solve the problems of low data utility and high communication and computing overhead in traditional differential matrix decomposition recommendation systems.
[0009] The technical solution adopted by the present invention is a matrix decomposition recommendation method based on shuffled differential privacy. The method comprises the following steps: obtaining an interaction dataset between users and items, and inputting it into a matrix decomposition recommendation model for processing, thereby obtaining item recommendation results for users; The matrix decomposition recommendation model is obtained through training, and the training steps are as follows: S1: Preprocess model information on the server side, including setting system parameters, initializing system information, and setting optimization goals; S2: Calculate the user feature matrix on the user side based on the pre-processed model information, perform local perturbations on each message to generate a message set, and then upload the generated message set to the shuffling server; S3: The shuffling server receives the messages after local perturbation from the user, and uses the differential privacy shuffling model to shuffle the messages to obtain the shuffled message dataset, and transmits it to the server. S4: Aggregate and traverse the shuffled message dataset, then update the item feature matrix information on the server side and the user feature matrix information on the user side; S5: Perform privacy budget segmentation to ensure that each iteration of the model satisfies the differential privacy constraint. Finally, integrate the user feature matrix and the item feature matrix to construct a matrix decomposition recommendation model.
[0010] This application significantly improves the privacy protection capability of matrix decomposition recommendation by adopting a multi-message shuffled matrix decomposition recommendation mechanism, while ensuring the usability of this method, effectively solving the trade-off between privacy protection and model performance in the existing technology, and reducing the communication overhead during the model iteration process. Each user only needs to select two dimensions of single-bit data in the calculated project recommendation matrix for perturbation and transmission, without uploading the entire gradient, reducing the calculation and communication overhead on the user side. At the same time, the server uses a random dimensionality reduction matrix to project the feature gradient matrix into a low-rank space, so that the user only needs to download a low-rank update matrix with a smaller number of parameters to complete the feature vector update operation, further reducing the communication overhead between the user and the server. This application can also ensure privacy protection. By introducing the shuffling differential privacy model, users calculate and randomly sample the update information of the project matrix, disturb the data by adding a small amount of noise locally, and report the disturbed gradient information in the sampling dimension after anonymization processing by the multi-message shuffling protocol on the shuffling server side. The process of each user randomly selecting the data dimension is independent of each other. The shuffling process cuts off the association between the data and the original user by randomly permuting the order of user messages, so that the global privacy protection level from the server perspective is significantly higher than the local privacy budget of a single user, thereby achieving high-intensity privacy protection under low local noise conditions.
[0011] The step S2 includes: S21: Each user uses the local preference score to calculate the recommendation feature matrix update gradient; S22: Perform random sampling to constrain the gradient value to the expected data domain; S23: Perform local perturbation on the sampled data points; S24: Generate a message set by splitting the perturbed result into independent messages and then adding them to the message set. If the message set size is less than the number of messages generated by each user, , then repeat S22 and S23 until the size of the message set is equal to the number of messages generated by each user ; S25: Upload the generated message set to the shuffling server.
[0012] In this application, through operations such as gradient update, random sampling, local perturbation, message generation and uploading to the shuffling server, it is ensured that during the optimization process of the recommendation system, each uploaded message has been locally perturbed and does not contain the original data. The privacy of user data is effectively protected while maintaining the efficiency and accuracy of the system. When processing user data, the recommendation system can provide personalized recommendations while avoiding privacy leaks, ensuring that the system achieves a good balance between privacy and performance.
[0013] Preferably, the step S21 includes: S211: For each user Existing Projects Scoring record, set the marker variable The value of is 1, otherwise it is set to 0; S212: Calculate the gradient vector using the local score record data, and calculate the vector in the low-rank space using the random dimension reduction matrix.
[0014] The method described in this application effectively reduces communication and computing overhead, improves the training efficiency and prediction accuracy of the recommendation system, reduces the risk of overfitting, and can handle large-scale data sets, especially the introduction of low-rank space. Users use local preference data to calculate gradient information, and convert the gradient information into sparse triples, upload the cropped and disturbed sparse triple set, and the server selects a latitude parameter that is much smaller than the number of recommended items, generates a random reduced-dimensional matrix based on the latitude parameter, and performs dimensionality reduction processing on the recommended item matrix, thereby reducing the computing and communication overhead between the user and the server, so that the system can significantly improve the computing efficiency and the generalization ability of the model when processing large-scale sparse matrices.
[0015] Further preferably, in step S212, the gradient vector calculation formula is:
[0016] in, represents the gradient vector; Indicates a tag variable; represents the user feature vector; Represents each user Own the project preference ratings; express The transpose of represents the item feature vector; Indicates the number of recommended items; The calculation formula of the vector in the low-rank space is:
[0017] in, represents a low-rank space vector; represents a random reduced-dimension matrix.
[0018] Preferably, the step S22 includes: S221: User samples two dimensional variables from a uniform distribution and ,in, The sampling set is , The sampling set is ,in Represents the low-rank space vector latitude; S222: Set and The low-rank gradient values corresponding to the two latitudes are ,like The value is out of range , then the data needs to be clipped to constrain the gradient value to the desired data domain.
[0019] Through uniform sampling and cropping, the model can avoid overfitting of a certain dimension during the learning process, while also ensuring that the updated gradient values during training are reasonable, avoiding overfitting, ensuring that the gradient values remain within a reasonable range, reducing large changes in calculation and storage, and improving the efficiency of the training process.
[0020] Preferably, in step S23, locally perturbing the sampled data points includes: Identifying variables from sampling symbols in a Bernoulli distribution ,if A value of 1 returns the perturbed gradient , otherwise return ,in Represents the latent vector data dimension; privacy parameter representing the user's perturbation mechanism; Indicates the total number of iterations of the algorithm.
[0021] Through this perturbation mechanism, the model can introduce randomness during gradient updates, increase the diversity of the training process, avoid falling into local optimal solutions, and thus enhance the generalization and robustness of the model. The adaptive perturbation intensity and directionality make this mechanism more efficient in the gradient optimization process, helping to improve the model's performance in complex tasks.
[0022] Preferably, the step S3 includes: S31: Summarize the noise data in the disturbance messages submitted by all users and integrate them into a temporary dataset in a unified format, eliminating the user's label information; S32: Perform random permutation of the temporary data set by reverse traversal, starting from the last data, and randomly selecting a data position in the front to exchange with the current position each time until the traversal is completed, ensuring that all data positions are uniformly and randomly disrupted; S33: Transmit the obfuscated message data set to the server.
[0023] The present invention effectively reduces the consumption of the privacy budget. By utilizing the shuffle differential privacy mechanism and combining it with a completely random tree structure, the data order is evenly disrupted through the random permutation operation of the reverse traversal, thus avoiding the correlation between the data and the dynamic splitting rule calculation, which significantly reduces the consumption of the privacy budget. At the same time, the privacy enhancement effect of the shuffle protocol is fully utilized, effectively enhancing the security and privacy of the data, while avoiding potential leakage risks and improving the privacy protection capability of the system.
[0024] Preferably, in step S4, the aggregation traversal of the shuffled message data set includes: the server traverses the shuffled global message set, calculates the mean of the disturbed gradient information of each data dimension, and first reconstructs the low-rank gradient matrix on the server side , for each latitude point , statistics include the gradient set of this latitude, the gradient set ,in, Represents the obfuscated message dataset; Represents a user The generated message collection; Represents a set union operation; express The disturbed gradient value at ; Representing a collection Index information in the triplet element; The server then calculates the mean of the messages at each data latitude, where the latitude point The element value is , express The gradient value in ; Represents a gradient set.
[0025] This step optimizes the processing and updating of gradient information by reconstructing the low-rank gradient matrix on the server side and averaging the perturbed gradients for each data dimension. Specifically, by shuffling the global message set, counting the gradient sets for each data dimension, and averaging them, it ensures that true gradient information can be effectively extracted when processing large amounts of perturbed data, reducing redundancy and interference in the data, thereby improving the training efficiency and stability of the model, ensuring the reliability and accuracy of the gradient information, and enhancing the stability and accuracy of model training. It also reduces computational complexity and storage requirements, enhances the generalization ability of the model, and ensures a more efficient and accurate training process.
[0026] Preferably, in step S4, the updating of the item feature matrix information on the server side includes: the server side first uses the pseudo-inverse random dimension reduction matrix Reconstructing the project gradient matrix ,in , and then use the reconstructed item gradient matrix to calculate the updated item feature matrix, which is calculated as follows:
[0027] in, represents the item feature matrix; is the learning rate in this round of update, Represents the item feature vector weight penalty parameter.
[0028] Preferably, in step S4, the updating of user feature matrix information at the user end includes: user Download the reconstructed low-rank gradient matrix , and complete the reconstruction operation of the project gradient matrix locally, and then calculate the updated gradient of the user feature vector. The calculation formula is:
[0029] in, Represents user feature vector The updated gradient of Indicates a tag variable; represents the item feature vector; Represents each user Own the project preference ratings; Represents user feature vector The transpose of Indicates the number of recommended items; And use this gradient information to update the user feature vector, we can get
[0030] in, represents the updated user feature vector; is the learning rate in this round of update; Represents the user feature vector weight penalty parameter.
[0031] This step improves the update efficiency and accuracy of the project feature matrix by using a pseudo-inverse random dimensionality reduction matrix on the server side to reconstruct the project gradient matrix, project the feature gradient matrix into a low-rank space, and use the reconstructed matrix to update the project feature matrix, so that the user only needs to download a low-rank update matrix with a smaller number of parameters to complete the feature vector update operation, further reducing the communication overhead between the user and the server; at the same time, the user side optimizes the calculation and update process of the user feature matrix by downloading the reconstructed low-rank gradient matrix and performing local updates, effectively reducing the amount of data transmission, reducing the calculation and communication overhead on the user side, and maintaining good computational stability and convergence in a distributed environment, improving the generalization ability of the model, avoiding overfitting, and reducing computational overhead, thereby improving the overall performance of the system.
[0032] Compared with the prior art, the present invention has the following beneficial effects: (1) Reducing privacy budget consumption: This paper utilizes the shuffle differential privacy mechanism and combines it with a completely random tree structure to avoid dynamic splitting rule calculation, significantly reducing privacy budget consumption while fully utilizing the privacy enhancement effect of the shuffle protocol.
[0033] (2) Reduce communication and computational overhead: Users use their local preference data to calculate gradient information, convert the gradient information into sparse triples, and upload the pruned and perturbed sparse triples. The server selects a dimension parameter that is much smaller than the number of recommended items, generates a random dimension reduction matrix based on this dimension parameter, and performs dimensionality reduction on the recommended item matrix, thereby reducing the computational and communication overhead between the user and the server. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 This is a flow chart of the model training method provided in this embodiment.
[0035] Figure 2 This is a schematic diagram of the experimental test results provided in this embodiment. DETAILED DESCRIPTION
[0036] The accompanying drawings are for illustrative purposes only and are not to be construed as limiting the present invention. To better illustrate the following embodiments, some components in the accompanying drawings may be omitted, enlarged, or reduced in size, and do not represent actual product dimensions. Those skilled in the art will appreciate that some well-known structures and their descriptions may be omitted from the accompanying drawings.
[0037] Example 1 The technical solution adopted in this embodiment is a matrix decomposition recommendation method based on shuffled differential privacy. The method comprises the following steps: obtaining a dataset of interactions between users and items and inputting it into a matrix decomposition recommendation model for processing, thereby obtaining item recommendation results for the user; Preferably, the method further comprises training the matrix decomposition recommendation model, such as Figure 1 As shown, the training steps are: Step S1: Preprocessing model information on the server side, including setting system parameters, initializing system information, and setting optimization targets; Preferably, the setting of system parameters includes: setting system parameters. The amount of user data in the recommendation system is , the number of recommended items is , the number of messages generated by each user is , the privacy parameter of the user perturbation mechanism is , the implicit vector data dimension is (generally ), the low-rank space vector latitude is (generally ), the random dimension reduction matrix is , the user feature matrix is , the item feature matrix is .
[0038] The initialization system information includes: assuming that each element in the random dimension reduction matrix has a mean of 0 and a standard deviation of At the same time, the parameters in the user feature matrix and the item feature matrix are initialized to 0.
[0039] The optimization goal setting includes: setting each user Own the project Preference score , the user feature vector is , the item feature vector is ,The specific optimization goal of the matrix decomposition recommendation model is as follows:
[0040] in, is the set of preference ratings for all users on items, For collection The number of elements included, and are the penalty parameters for user feature vectors and item feature vectors, respectively, used to prevent overfitting during model training.
[0041] Step S2: Calculate the user feature matrix on the user side based on the pre-processed model information, perform local perturbations on each message to generate a message set, and then upload the generated message set to the shuffling server; Preferably, the step S2 includes the following steps: Step S21: To optimize the objective function , each user uses the local preference score to calculate the recommendation feature matrix update gradient; Preferably, the step S21 includes: Step S211: For each user Existing Projects Scoring record, set the marker variable The value of is 1, otherwise it is set to 0; Step S212: Calculate the gradient vector using the local score record data, and calculate the vector in the low-rank space using the random dimension reduction matrix.
[0042] Further preferably, in step S212, the gradient vector calculation formula is:
[0043] in, represents the gradient vector; Indicates a tag variable; represents the user feature vector; Represents each user Own the project preference ratings; express The transpose of represents the item feature vector; Indicates the number of recommended items; The calculation formula of the vector in the low-rank space is:
[0044] in, represents a low-rank space vector; represents a random reduced-dimension matrix.
[0045] Therefore, in this embodiment, the above operations effectively reduce communication and computing overheads, improve the training efficiency and prediction accuracy of the recommendation system, reduce the risk of overfitting, and can process large-scale data sets, especially the introduction of low-rank space. Users use local preference data to calculate gradient information, and convert the gradient information into sparse triples, upload the cropped and disturbed sparse triple set, and the server selects a latitude parameter that is much smaller than the number of recommended items, generates a random reduced-dimensional matrix based on the latitude parameter, and performs dimensionality reduction processing on the recommended item matrix, thereby reducing the computing and communication overhead between the user and the server, so that the system can significantly improve the computing efficiency and the generalization ability of the model when processing large-scale sparse matrices.
[0046] Step S22: Perform random sampling to constrain the gradient value within the expected data domain; Preferably, the step S22 includes: Step S221: In order to reduce communication costs, the user samples two dimensional variables from a uniform distribution and ,in, The sampling set is , The sampling set is ,in Represents the low-rank space vector latitude; Step S222: Set and The low-rank gradient values corresponding to the two latitudes are ,like The value is out of range , then the data needs to be clipped to constrain the gradient value to the desired data domain.
[0047] Therefore, through uniform sampling and cropping, the model can avoid overfitting to a certain dimension during the learning process, while also ensuring that the gradient values updated during training are reasonable, avoiding overfitting, ensuring that the gradient values remain within a reasonable range, reducing large changes in calculation and storage, and improving the efficiency of the training process.
[0048] Step S23: performing local perturbation on the sampled data points; Preferably, in order to protect privacy, the user needs to use a perturbation mechanism to clean the sampled data points. In step S23, the local perturbation of the sampled data points includes: Identifying variables from sampling symbols in a Bernoulli distribution ,Right now ,if A value of 1 returns the perturbed gradient , otherwise return ,in Represents the latent vector data dimension; privacy parameter representing the user's perturbation mechanism; Indicates the total number of iterations of the algorithm.
[0049] Therefore, in this embodiment, through this perturbation mechanism, the model can introduce randomness during gradient updates, increase the diversity of the training process, avoid falling into local optimal solutions, and thus enhance the generalization ability and robustness of the model. The adaptive perturbation intensity and directionality make this mechanism more efficient in the gradient optimization process, which helps to improve the performance of the model in complex tasks.
[0050] Step S24: Generate message set ; In order to optimize the effectiveness of the recommendation system, the gradient error rate is reduced by splitting the perturbed results into independent messages, where the format of each message is , and then add the generated message to the message collection. If the message collection size is less than the number of messages generated by each user , then repeat S22 and S23 until the size of the message set meets the requirement; S25: User generates a message collection Upload to the shuffling server. Each uploaded message has been locally perturbed and does not contain the original data.
[0051] Through operations such as gradient updates, random sampling, local perturbations, message generation, and uploading to shuffling servers, it is ensured that during the optimization process of the recommendation system, each uploaded message has been locally perturbed and does not contain the original data. The privacy of user data is effectively protected while maintaining the efficiency and accuracy of the system. This allows the recommendation system to provide personalized recommendations while avoiding privacy leaks when processing user data, ensuring that the system achieves a good balance between privacy and performance.
[0052] Step S3: The shuffling server receives the messages after local perturbation by the user end. These messages have been locally added with a certain amount of noise, and uses the differential privacy shuffling model to shuffle these messages to obtain the shuffled message dataset, and transmits it to the server end; Preferably, the step S3 includes: S31: Summarize the noise data in the disturbance messages submitted by all users and integrate them into a temporary dataset in a unified format, eliminating the user's label information; S32: Perform random permutation of the temporary data set by reverse traversal, starting from the last data, and randomly selecting a data position in the front to exchange with the current position each time until the traversal is completed, ensuring that all data positions are uniformly and randomly disrupted; S33: Obfuscated message dataset The data is transmitted to the server, eliminating the arrangement correlation between the data, making it impossible for the server to infer the correspondence between the data and the user through features such as sequence and context, and can only be mined based on overall statistical features.
[0053] This effectively reduces the privacy budget consumption. By utilizing the shuffle differential privacy mechanism, combined with the completely random tree structure, the data order is evenly disrupted through the random permutation operation of the reverse traversal, avoiding the correlation between the data and the dynamic splitting rule calculation, significantly reducing the privacy budget consumption. At the same time, the privacy enhancement effect of the shuffle protocol is fully utilized, effectively enhancing the security and privacy of the data, while avoiding potential leakage risks and improving the privacy protection capabilities of the system.
[0054] In the privacy amplification analysis, based on the latitude sampling and mechanism characteristics, the privacy analysis of the machine is reduced to the privacy analysis problem of the random response mechanism. Combined with the privacy amplification effect analysis technology, the privacy level of the matrix decomposition recommendation system construction process is analyzed, and the privacy protection level is effectively enhanced. The global privacy protection level after shuffling derived in this embodiment can reach -DP tight bounds (where is the number of users, for , (where is the desired privacy leakage risk parameter) compared to traditional local differential privacy (LDP) methods, the global privacy leakage risk is significantly reduced under the same local budget. This theoretical result provides a strict guarantee for the balance between privacy and utility, ensuring that user privacy is protected while still supporting large-scale data analysis and model building with high utility.
[0055] In the differential privacy shuffling model, the communication overhead is reduced by adopting dimensionality sampling and random projection dimensionality reduction techniques, and the data is anonymized and counted in combination with the multi-message shuffling protocol. The introduction of multiple messages can effectively alleviate the data bias problem caused by differential privacy noise and optimize the effectiveness of the system model. Specifically, by proposing an efficient matrix decomposition recommendation mechanism, user data is randomly responded to locally, uploaded through multiple messages, and shuffled and counted on the server side, to achieve efficient estimation of the user feature matrix and the project feature matrix, thereby constructing a privacy-protected recommendation mechanism. In addition, the present invention derives the privacy amplification limit for the multi-message protocol, further optimizing the effectiveness of the recommendation mechanism, so that under the same privacy budget, the error of the present invention is reduced by 50%-80% compared with the traditional local differential privacy method.
[0056] Step S4: Aggregate and traverse the shuffled message data set, and then update the project feature matrix information on the server side and the user feature matrix information on the user side; Preferably, in step S4, the aggregation traversal of the shuffled message data set includes: the server traverses the shuffled global message set, calculates the mean of the disturbed gradient information of each data dimension, and since the client performs a dimensionality reduction operation, it is necessary to reconstruct the low-rank gradient matrix on the server side. , for each latitude point , statistics include the gradient set of this latitude, the gradient set ,in, Represents the obfuscated message dataset; Represents a user The generated message collection; Represents a set union operation; express The disturbed gradient value at ; Representing a collection Index information in the triplet element; The server then calculates the mean of the messages at each data latitude, where the latitude point The element value is , express The gradient value in ; Represents a gradient set.
[0057] This step optimizes the processing and updating of gradient information by reconstructing the low-rank gradient matrix on the server side and averaging the perturbed gradients for each data dimension. Specifically, by shuffling the global message set, counting the gradient sets for each data dimension, and averaging them, it ensures that true gradient information can be effectively extracted when processing large amounts of perturbed data, reducing redundancy and interference in the data, thereby improving the training efficiency and stability of the model, ensuring the reliability and accuracy of the gradient information, and enhancing the stability and accuracy of model training. It also reduces computational complexity and storage requirements, enhances the generalization ability of the model, and ensures a more efficient and accurate training process.
[0058] Preferably, in step S4, the updating of the item feature matrix information on the server side includes: the server side first uses the pseudo-inverse random dimension reduction matrix Reconstructing the project gradient matrix ,in , and then use the reconstructed item gradient matrix to calculate the updated item feature matrix, which is calculated as follows:
[0059] in, represents the item feature matrix; is the learning rate in this round of update, Represents the item feature vector weight penalty parameter.
[0060] Preferably, in step S4, the updating of the user feature matrix information at the user end includes: in order to reduce the communication overhead in this process, the user Download the reconstructed low-rank gradient matrix , and complete the reconstruction operation of the project gradient matrix locally, and then calculate the updated gradient of the user feature vector. The calculation formula is:
[0061] in, Represents user feature vector The updated gradient of Indicates a tag variable; represents the item feature vector; Represents each user Own the project preference ratings; Represents user feature vector The transpose of Indicates the number of recommended items; And use this gradient information to update the user feature vector, we can get
[0062] in, represents the updated user feature vector; is the learning rate in this round of update; Represents the user feature vector weight penalty parameter.
[0063] This step improves the update efficiency and accuracy of the project feature matrix by using a pseudo-inverse random dimensionality reduction matrix on the server side to reconstruct the project gradient matrix, project the feature gradient matrix into a low-rank space, and use the reconstructed matrix to update the project feature matrix, so that the user only needs to download a low-rank update matrix with a smaller number of parameters to complete the feature vector update operation, further reducing the communication overhead between the user and the server; at the same time, the user side optimizes the calculation and update process of the user feature matrix by downloading the reconstructed low-rank gradient matrix and performing local updates, effectively reducing the amount of data transmission, reducing the calculation and communication overhead on the user side, and maintaining good computational stability and convergence in a distributed environment, improving the generalization ability of the model, avoiding overfitting, and reducing computational overhead, thereby improving the overall performance of the system.
[0064] Step S5: Perform privacy budget segmentation to ensure that each iteration of the model satisfies the differential privacy constraint. Finally, integrate the user feature matrix and the item feature matrix to construct a matrix decomposition recommendation model.
[0065] Preferably, in step S5, when performing privacy budget segmentation, the matrix decomposition algorithm needs to complete model convergence in multiple rounds of iterations. Suppose the number of iterations required by the model is , according to the basic differential privacy combination mechanism, the privacy budget of each round needs to be set to To ensure that the final algorithm satisfies -DP constraints.
[0066] In the matrix decomposition recommendation model constructed by integrating the user feature matrix and the item feature matrix, the calculation of the user feature matrix is completed on the local device in order to protect the user's privacy. In order to allow the server to complete the prediction process independently, after the algorithm iteration is completed, each user needs to convert the local feature vector Upload to the server. Since the entire algorithm mechanism follows differential privacy constraints, this step does not threaten the user's privacy.
[0067] Preferably, if Figure 2 As shown in the figure, in this embodiment, to further verify the effectiveness of the present invention, experiments were conducted on two real-world datasets (MovieLens 1M and 10M) to compare the model prediction error rates under different privacy budgets. The MovieLens dataset includes users’ preference ratings for different movies, and the rating values are located in In terms of parameter setting, the penalty parameter and All set to In particular, in the MovieLens 1M dataset, the latent vector data dimension is set to , the low-rank space vector latitude is , learning rate ; In the MovieLens10M dataset, the latent vector data latitude is set to , the low-rank space vector latitude is , learning rate The set of privacy budget parameters tested is , the root mean square error (RMSE) is used to evaluate the model performance, and its formula is as follows:
[0068] in, For the real result, is the prediction result of the model. The test results of the experiment are shown in Figure 2. The experimental results show that compared with the traditional local differential privacy matrix decomposition mechanism, the method provided by this embodiment reduces the classification error rate by 15%-50% while ensuring privacy security and significantly reduces the privacy budget. More specifically: Strong privacy protection environment (privacy budget ), the RMSE of the traditional local differential privacy method on the MovieLens 1M dataset was 0.51, while the RMSE of this embodiment was 0.43, a 15% improvement. When processing a larger dataset (MovieLens 10M), the RMSE of the traditional local differential privacy method was 0.21, while the RMSE of this embodiment was 0.11, an approximately 16% improvement.
[0069] Under weak privacy protection environment (privacy budget ), the RMSE of the traditional local differential privacy method on the MovieLens 1M dataset was 0.455, while the RMSE of this embodiment was 0.425, a significant improvement. When processing a larger dataset (MovieLens 10M), the RMSE of the traditional local differential privacy method was 0.21, while the RMSE of this invention was 0.11, an improvement of approximately 50%.
[0070] At the same time, it can be observed that when the amount of data used to train the model is relatively large, the method provided by this embodiment has a stable improvement compared to the traditional local differential privacy method, that is, there are visible differences under different budgets.
[0071] Obviously, the above embodiments of the present invention are merely examples for the purpose of clearly illustrating the technical solutions of the present invention, and are not intended to limit the specific implementation methods of the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the claims of the present invention shall be included within the scope of protection of the claims of the present invention.
Claims
1. A matrix factorization recommendation method based on shuffled differential privacy, which involves obtaining a dataset of user-item interactions and inputting it into a matrix factorization recommendation model for processing, thereby obtaining item recommendations for the user. It is characterized by: The matrix decomposition recommendation model is obtained through training, and the training steps are as follows: S1: Preprocess model information on the server side, including setting system parameters, initializing system information, and setting optimization goals; S2: Calculate the user feature matrix on the user side based on the pre-processed model information, perform local perturbations on each message to generate a message set, and then upload the generated message set to the shuffling server; S3: The shuffling server receives the messages after local perturbation from the user, and uses the differential privacy shuffling model to shuffle the messages to obtain the shuffled message dataset, and transmits it to the server. S4: Aggregate and traverse the shuffled message dataset, then update the item feature matrix information on the server side and the user feature matrix information on the user side; S5: Perform privacy budget segmentation to ensure that each iteration of the model satisfies the differential privacy constraint. Finally, integrate the user feature matrix and the item feature matrix to construct a matrix decomposition recommendation model.
2. A matrix decomposition recommendation method based on shuffled differential privacy according to claim 1, characterized in that: The step S2 includes: S21: Each user uses the local preference score to calculate the recommendation feature matrix update gradient; S22: Perform random sampling to constrain the gradient value to the expected data domain; S23: Perform local perturbation on the sampled data points; S24: Generate a message set by splitting the perturbed result into independent messages and then adding them to the message set. If the message set size is less than the number of messages generated by each user, , then repeat steps S22 and S23 until the size of the message set is equal to the number of messages generated by each user ; S25: Upload the generated message set to the shuffling server.
3. A matrix decomposition recommendation method based on shuffled differential privacy according to claim 2, characterized in that: The step S21 includes: S211: For each user Existing Projects Scoring record, set the marker variable The value of is 1, otherwise it is set to 0; S212: Calculate the gradient vector using the local score record data, and calculate the vector in the low-rank space using the random dimension reduction matrix.
4. A matrix decomposition recommendation method based on shuffled differential privacy according to claim 3, characterized in that: In step S212, the gradient vector calculation formula is: in, represents the gradient vector; Indicates a tag variable; represents the user feature vector; Represents each user Own the project preference ratings; express The transpose of represents the item feature vector; Indicates the number of recommended items; The calculation formula of the vector in the low-rank space is: in, represents a low-rank space vector; represents a random reduced-dimension matrix.
5. A matrix decomposition recommendation method based on shuffled differential privacy according to claim 2, characterized in that: The step S22 includes: S221: User samples two dimensional variables from a uniform distribution and ,in, The sampling set is , The sampling set is ,in Represents the low-rank space vector latitude; S222: Set and The low-rank gradient values corresponding to the two latitudes are ,like The value is out of range , then the data needs to be clipped to constrain the gradient value to the desired data domain.
6. A matrix decomposition recommendation method based on shuffled differential privacy according to claim 5, characterized in that: In step S23, locally disturbing the sampled data points includes: Identifying variables from sampling symbols in a Bernoulli distribution ,if A value of 1 returns the perturbed gradient , otherwise return ,in Represents the latent vector data dimension; privacy parameter representing the user's perturbation mechanism; Indicates the total number of iterations of the algorithm.
7. A matrix decomposition recommendation method based on shuffled differential privacy according to claim 1, characterized in that: The step S3 includes: S31: Summarize the noise data in the disturbance messages submitted by all users and integrate them into a temporary dataset in a unified format, eliminating the user's label information; S32: Perform random permutation of the temporary data set by reverse traversal, starting from the last data, and randomly selecting a data position in the front to exchange with the current position each time until the traversal is completed, ensuring that all data positions are uniformly and randomly disrupted; S33: Transmit the obfuscated message data set to the server.
8. A matrix decomposition recommendation method based on shuffled differential privacy according to claim 1, characterized in that: In step S4, the aggregation traversal of the shuffled message data set includes: the server traverses the shuffled global message set, calculates the mean of the disturbed gradient information of each data dimension, and first reconstructs the low-rank gradient matrix on the server side , for each latitude point , statistics include the gradient set of this latitude, the gradient set ,in, Represents the obfuscated message dataset; Represents a user The generated message collection; Represents a set union operation; express The disturbed gradient value at ; Representing a collection Index information in the triplet element; The server then calculates the mean of the messages at each data latitude, where the latitude point The element value is , express The gradient value in ; Represents a gradient set.
9. A matrix decomposition recommendation method based on shuffled differential privacy according to claim 8, characterized in that: In step S4, the updating of the item feature matrix information on the server side includes: the server side first uses the pseudo-inverse random dimension reduction matrix Reconstructing the project gradient matrix ,in , and then use the reconstructed item gradient matrix to calculate the updated item feature matrix, which is calculated as follows: in, represents the item feature matrix; is the learning rate in this round of update, Represents the item feature vector weight penalty parameter.
10. A matrix decomposition recommendation method based on shuffled differential privacy according to claim 8, characterized in that: In step S4, the updating of user feature matrix information at the user end includes: Download the reconstructed low-rank gradient matrix , and complete the reconstruction operation of the project gradient matrix locally, and then calculate the updated gradient of the user feature vector. The calculation formula is: in, Represents user feature vector The updated gradient of Indicates a tag variable; represents the item feature vector; Represents each user Own the project preference ratings; Represents user feature vector The transpose of Indicates the number of recommended items; And use this gradient information to update the user feature vector, we can get in, represents the updated user feature vector; is the learning rate in this round of update; Represents the user feature vector weight penalty parameter.
Citation Information
Patent Citations
Matrix decomposition recommendation method based on shuffler federated differential privacy
CN117743690A
Distributed differential privacy matrix decomposition recommendation method based on secret sharing
CN118332596A
Gradient perturbation optimization method for implicit matrix factorization based on differential privacy
CN120105467A