Large model data processing method and device, equipment, medium and program product
Through orthogonal encryption processing between the client and the cloud, the problems of privacy leakage and high computing resource consumption during large-scale model training and inference are solved, and efficient and secure data processing is achieved, which is suitable for scenarios such as finance and biometric recognition.
Patent Information
- Application Number
- CN202511029168.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-24
- Publication Date
- 2025-09-05
AI Technical Summary
Existing technologies have the risk of privacy leakage and excessive consumption of computing resources during large-scale model training and inference, resulting in low usability and efficiency, making it difficult to adapt to actual application needs.
Orthogonal encryption is performed by combining different encryption matrices generated based on the same base matrix between the client and the cloud, and user data and model data are encrypted separately to ensure data privacy and security. The transmission and collaborative operation of encrypted data can reduce the amount of calculation and improve encryption efficiency.
On the basis of protecting privacy, it improves the efficiency and availability of large model processing, reduces the risk of privacy leakage during data transmission and calculation, and is suitable for sensitive data scenarios such as finance and biometric recognition.
Smart Images

Figure CN120602216A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of big data technology, and in particular to a large model data processing method, device, equipment, medium and program product. Background Art
[0002] With the deep integration of large-scale model technology and big data, data privacy and security have become a global trend. In practical applications, how to achieve multi-party collaboration to complete large-scale model training and inference while ensuring data and model privacy is a core focus of current industry research.
[0003] When users use large language models, there may be a risk of privacy leakage. Because the data contains sensitive information, relevant technologies need to encrypt the data before performing calculations on the large model to meet privacy protection requirements.
[0004] However, since the number of parameters in trained large models often reaches billions or tens of billions, the encryption methods provided in related technologies will consume a large amount of communication and computing resources when fine-tuning or inference based on data, resulting in low availability and inference efficiency of large models, making it difficult to adapt to actual application needs. Summary of the Invention
[0005] The present application provides a large model data processing method, device, equipment, medium and program product, so as to solve the technical problems of large model availability and low reasoning efficiency in the process of large model privacy processing.
[0006] In a first aspect, the present application provides a large model data processing method, wherein the large model includes a first part and a second part; the first part is deployed on a client and is used to process user data; the second part is deployed on a cloud and is used to process the model data; the method is applied to the first part or the second part;
[0007] The method comprises:
[0008] Obtaining a first encryption vector corresponding to local data and receiving a second encryption vector corresponding to remote data; wherein, when the local data is user data, the remote data is model data; and when the local data is model data, the remote data is user data;
[0009] The first encrypted vector and the second encrypted vector are obtained by orthogonally encrypting the first vector and the second vector, respectively; the first vector is an eigenvector corresponding to the local data, and the second vector is an eigenvector corresponding to the remote data; encryption matrices used in the orthogonal encryption of the first and second vectors are obtained by encrypting the same base matrix with different noise matrices;
[0010] An operation is performed on the first encryption vector and the second encryption vector to obtain a calculation result corresponding to the user data.
[0011] Orthogonal encryption is achieved by combining different encryption matrices generated based on the same base matrix between the client and the cloud, and user data and model data are encrypted separately. Under the premise of ensuring the privacy and security of user data and model data, the encrypted data is transmitted and operated collaboratively at both ends to reduce the risk of privacy leakage during data transmission and calculation. At the same time, relying on the characteristics of orthogonal encryption, the amount of calculation is reduced and the encryption efficiency is improved, thereby ensuring the efficiency and availability of large model processing while protecting privacy.
[0012] In an optional implementation, obtaining the first encryption vector corresponding to the local data includes:
[0013] Acquire the local data, and perform vector conversion processing on the local data to obtain a first vector;
[0014] Obtaining a first encryption matrix; wherein the first encryption matrix is generated based on a preset basis matrix and a first noise matrix;
[0015] The first vector is encrypted based on the first encryption matrix to obtain a first encrypted vector.
[0016] Through the above steps, the first part of the large model converts user data containing sensitive data into encrypted vectors. This ensures that the original user data always exists in encrypted form during the model transmission process, protecting data privacy, and ensures that the encrypted vectors can be directly used for subsequent model calculations without the need for decryption to achieve computational compatibility, thereby ensuring the efficiency and availability of large model processing while protecting privacy.
[0017] In an optional implementation, generating the first encryption matrix based on a preset basis matrix and a first noise matrix includes:
[0018] Based on the first noise matrix, encrypting the basis matrix to obtain a first initial encrypted matrix;
[0019] Performing orthogonal transformation on the first initial encryption matrix to obtain a first encryption matrix.
[0020] The above processing method not only improves the security of data encryption, but also enhances the compatibility and efficiency of computing.
[0021] In an optional implementation, encrypting the first vector based on the first encryption matrix to obtain the first encrypted vector includes:
[0022] Based on the first encryption matrix, performing an orthogonal transformation on the first vector to obtain a first initial encryption vector;
[0023] The first initial encrypted vector is encrypted based on a first noise vector corresponding to the local data to obtain a first encrypted vector.
[0024] Through the above implementation, the orthogonal characteristics of the first encryption matrix can be used to retain the core operational properties of the first vector while completing the encryption, ensuring that the encrypted first initial encryption vector can directly participate in cross-end collaborative computing, thereby ensuring the continuity and accuracy of large model processing; and secondary encryption can be performed based on the first noise vector bound to the local data, and the privacy protection strength of the data can be further enhanced through personalized encryption logic, thereby effectively resisting malicious cracking and preventing data leakage while taking into account the operational compatibility and personalized privacy protection of the encryption vector, and balancing privacy and usability.
[0025] In an optional implementation, receiving a second encryption vector corresponding to the remote data includes:
[0026] receiving a second encryption vector corresponding to remote data transmitted by another portion of the large model; wherein the second encryption vector is generated by encrypting the remote data by another portion of the large model;
[0027] The encryption process of the remote data includes:
[0028] Acquire the remote data, and perform vector conversion processing on the remote data to obtain a second vector;
[0029] Obtaining a second encryption matrix; wherein the second encryption matrix is generated based on a preset base matrix and a second noise matrix;
[0030] The second vector is encrypted based on the second encryption matrix to obtain a second encrypted vector.
[0031] Through the above steps, the second part of the large model converts the model data into an encrypted vector. Under the premise of ensuring that the original information of the model data is not leaked, it can realize cross-end collaborative operation of the encrypted vector and the first encrypted vector of the client, thereby achieving the efficiency and availability of large model processing while protecting privacy.
[0032] In an optional implementation, generating the second encryption matrix based on a preset base matrix and a second noise matrix includes:
[0033] Performing encryption processing on the base matrix based on the second noise matrix to obtain a second initial encrypted matrix;
[0034] Performing orthogonal transformation on the second initial encryption matrix to obtain a second encryption matrix.
[0035] The above steps not only improve the security of data encryption, but also enhance the compatibility and efficiency of computing.
[0036] In an optional implementation, encrypting the second vector based on the second encryption matrix to obtain the second encrypted vector includes:
[0037] performing an orthogonal transformation on the second vector based on the second encryption matrix to obtain a second initial encryption vector;
[0038] The second initial encryption vector is encrypted based on a second noise vector corresponding to the remote data to obtain a second encryption vector.
[0039] Through the above implementation, the orthogonal characteristics of the second encryption matrix can be used to retain the core operational properties of the second vector while completing the encryption, ensuring that the encrypted second initial encryption vector can directly participate in cross-end collaborative computing, thereby ensuring the continuity and accuracy of large model processing; it can also rely on the second noise vector bound to the local data for secondary encryption, and further enhance the privacy protection strength of the data through personalized encryption logic, thereby effectively resisting malicious cracking and preventing data leakage while taking into account the operational compatibility and personalized privacy protection of the encryption vector, and balancing privacy and usability.
[0040] In an optional implementation, the first noise matrix and the second noise matrix are random noise matrices; and the first noise vector and the second noise vector are random noise vectors.
[0041] Randomness is used to further enhance the unpredictability of encryption parameters, preventing attackers from cracking the encryption logic through pattern analysis. At the same time, the unbiased nature of random noise ensures that the computational deviation of the encrypted vector is controllable, balancing encryption security and the accuracy of calculation results.
[0042] In an optional embodiment, the matrix values of the first noise matrix and the second noise matrix are greater than a first matrix threshold and less than a second matrix threshold; the first matrix threshold and the second matrix threshold are determined based on the computational complexity and model safety performance of the large model;
[0043] The vector values of the first noise vector and the second noise vector are greater than a first vector threshold and less than a second vector threshold; the first vector threshold and the second vector threshold are determined based on the computational complexity and model safety performance of the large model.
[0044] In this way, the generated noise matrix not only provides the necessary security during the data encryption process, but also ensures that the model's calculation results remain within an acceptable accuracy range. This method effectively balances security and computational accuracy, ensuring the overall performance of the model.
[0045] In an optional implementation, the base matrix is generated by the first part and the second part by sharing a random seed or synchronizing information.
[0046] The above-mentioned method of generating the basis matrix ensures that the basis matrices of each part are highly unified in consistency and synchronization, avoiding inconsistency problems. It can also use the shared random seed as a security mechanism to further enhance the security of data generation.
[0047] In an optional implementation, the base matrix or the random seed is regenerated at intervals of a preset duration.
[0048] In an optional implementation, the first noise matrix or the second noise matrix is regenerated at intervals of a preset duration.
[0049] In order to reduce the risk of statistical attacks that may be caused by long-term use of the same encryption matrix, the present application provides a technical solution, that is, during implementation, the first encryption matrix and the second encryption matrix can be regenerated within a preset time interval.
[0050] Since the first encryption matrix and the second encryption matrix are generated by respectively combining the base matrix with the first noise matrix and the second noise matrix, and the base matrix is generated by sharing a random seed, in the above implementation process, it is possible to choose to regenerate the first noise matrix or the second noise matrix, or regenerate the base matrix or the random seed within a preset time interval.
[0051] In an optional embodiment, the operation includes a vector inner product operation;
[0052] Performing an operation on the first encryption vector and the second encryption vector to obtain a calculation result corresponding to the user data includes:
[0053] Obtaining a vector inner product operation expression corresponding to the vector inner product operation;
[0054] Based on the vector inner product operation expression, a vector inner product calculation is performed on the first encrypted vector and the second encrypted vector to obtain a calculation result corresponding to the user data.
[0055] Through the above process, the mathematical properties of vector inner product operations are utilized to complete the operation directly based on the encrypted vectors without decrypting the first and second encrypted vectors. This not only achieves the collaborative processing of user data and remote data, but also avoids the risk of privacy leakage caused by decryption of encrypted vectors during the operation process, ensuring data security and operation accuracy during large model processing.
[0056] In an optional embodiment, the method further includes:
[0057] Perform encryption processing or vector inner product operations through parallel processing.
[0058] The use of parallel processing can significantly improve the efficiency and performance of the system. Specifically, the data or vector to be processed is divided into multiple small blocks. Through parallel processing, multiple encryption operations or vector inner product operations can be performed simultaneously, and the respective results are summed to obtain the final result. This can greatly reduce the calculation time, not only improving the speed of data processing, but also making full use of the computing resources of the device where the large model is located and optimizing resource usage. In addition, parallel processing helps to improve the responsiveness of large models to user data, especially when processing large-scale data sets, which can significantly reduce latency and improve overall processing efficiency.
[0059] In an optional implementation, after obtaining the calculation result corresponding to the user data, the method further includes:
[0060] In the first part of the large model, text conversion processing is performed on the calculation result to obtain output data corresponding to the user data.
[0061] Because orthogonal encryption is used for data encryption, the calculation results of the first and second encrypted vectors are mathematically equivalent to the calculation results of the original vectors before encryption, that is, they satisfy the inner product consistency property of orthogonal matrices. Based on this, after obtaining the calculation results of the first part of the large model, the text conversion processing can be directly performed based on this encrypted result to obtain the corresponding output result without performing a decryption operation. In this way, while ensuring the output quality of the large model, the privacy protection of user data and model parameters is achieved throughout the lifecycle, which is particularly suitable for data privacy-sensitive scenarios such as medical consultations and financial consulting.
[0062] In a second aspect, the present application provides a large model data processing device, wherein the large model includes a first part and a second part; the first part is deployed on a client and is used to process user data; the second part is deployed on a cloud and is used to process the model data; the device is applied to the first part or the second part;
[0063] The device comprises:
[0064] an encryption vector acquisition module, configured to acquire a first encryption vector corresponding to local data and receive a second encryption vector corresponding to remote data; wherein, when the local data is user data, the remote data is model data; and when the local data is model data, the remote data is user data;
[0065] The first encrypted vector and the second encrypted vector are obtained by orthogonally encrypting the first vector and the second vector, respectively; the first vector is an eigenvector corresponding to the local data, and the second vector is an eigenvector corresponding to the remote data; encryption matrices used in the orthogonal encryption of the first and second vectors are obtained by encrypting the same base matrix with different noise matrices;
[0066] The encryption vector calculation module is configured to perform an operation on the first encryption vector and the second encryption vector to obtain a calculation result corresponding to the user data.
[0067] In a third aspect, the present application provides an electronic device, comprising: a processor, and a memory communicatively connected to the processor;
[0068] The memory stores computer-executable instructions;
[0069] The processor executes the computer-executable instructions stored in the memory to implement the method according to the first aspect.
[0070] In a fourth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are executed by a processor, they are used to implement the method described in the first aspect.
[0071] In a fifth aspect, the present application provides a computer program product, comprising a computer program, which implements the method described in the first aspect when executed by a processor.
[0072] The large model data processing technology provided in this application realizes orthogonal encryption by combining different encryption matrices generated based on the same base matrix between the client and the cloud, and encrypts user data and model data respectively. Under the premise of ensuring the privacy and security of user data and model data, it can reduce the risk of privacy leakage during data transmission and calculation by transmitting and coordinating the encrypted data at both ends. At the same time, relying on the characteristics of orthogonal encryption, it can reduce the amount of calculation and improve the encryption efficiency, thereby ensuring the efficiency and availability of large model processing on the basis of protecting privacy. BRIEF DESCRIPTION OF THE DRAWINGS
[0073] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0074] Figure 1 A schematic diagram of the structure of the large model provided for this application;
[0075] Figure 2 This is a diagram of the application scenario of the large model data processing method provided in this application when it is executed in the cloud;
[0076] Figure 3 This is a diagram of the application scenario of the large model data processing method provided in this application when it is executed on the client;
[0077] Figure 4 A schematic diagram of a large model data processing method provided in this application Figure 1 ;
[0078] Figure 5 A schematic diagram of a large model data processing method provided in this application Figure 2 ;
[0079] Figure 6 A schematic diagram of the structure of a large model data processing device provided in this application;
[0080] Figure 7 This is a block diagram of an electronic device provided by this application.
[0081] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0082] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0083] In the technical solution of this application, the collection, storage, use, processing, transmission, provision and disclosure of information such as financial data or user data involved comply with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0084] It should be noted that in the embodiments of the present application, certain software, components, models and other existing solutions in the industry may be mentioned. They should be regarded as exemplary. Their purpose is only to illustrate the feasibility of implementing the technical solution of the present application, but it does not mean that the applicant has or will necessarily use the solution.
[0085] As mentioned in the background, users may face the risk of privacy leakage when using large language models. Because the data contains sensitive information, related technologies must first encrypt the data before performing calculations to meet privacy protection requirements.
[0086] To meet privacy requirements during fine-tuning or inference of large models, relevant technologies can "split" large models, deploying them in a distributed environment with multi-party collaboration. Furthermore, during the fine-tuning and inference phases, multiple participants collaborate and perform joint operations, preventing any single party from holding all sensitive data and thus improving privacy protection.
[0087] However, the cryptographic techniques involved in these privacy-preserving computations (such as homomorphic encryption, secret sharing, and differential privacy) often require exponentially more communication overhead and computing resources when used with large models containing tens of billions of parameters. This high cost significantly reduces the usability and deployment efficiency of these solutions during the training and inference phases of large models.
[0088] For example, large models can employ homomorphic encryption to protect the privacy of sensitive data and the computational process. Specifically, when performing a vector inner product calculation in a large model, the data owner first encrypts each component of the vector using a homomorphic encryption algorithm, generating a ciphertext vector. The computational entity then receives the ciphertext vector and directly performs addition and multiplication operations on the ciphertext to obtain the vector inner product result in ciphertext form. Finally, the data owner decrypts the ciphertext result using their private key to obtain the final vector inner product value. Throughout this process, the data remains encrypted, preventing the computational entity from accessing the original data, thereby protecting data privacy.
[0089] However, due to the complexity of the homomorphic encryption algorithm, its operating speed on ciphertext is much lower than that on plaintext. Especially when processing large-scale data, the calculation delay increases significantly, so there is a technical problem of low computing efficiency.
[0090] For another example, large models can also employ multi-party secure computation schemes, such as secret sharing, to protect the privacy of sensitive data and the computation process. Specifically, in a large model's vector inner product computation, the data owner splits each vector component into multiple shares and distributes these shares to different computation parties. Each computation party only holds a partial share and lacks access to the complete vector information. Each computation party then performs an inner product operation on its local share and aggregates the results. Ultimately, by aggregating the share results from all computation parties, the complete vector inner product value is recovered.
[0091] However, multi-party secure computation schemes such as secret sharing require collaboration between multiple computing parties, placing high demands on communication and synchronization. This is especially true in scenarios with large models and large amounts of data, where large amounts of secret shares need to be transmitted, creating a significant communication performance bottleneck.
[0092] In summary, the encryption methods provided in related technologies consume a large amount of communication and computing resources, resulting in low availability and inference efficiency of large models, making it difficult to adapt to actual application needs.
[0093] The large model data processing method provided in this application is intended to solve the above technical problems of the prior art. Specifically, orthogonal encryption is achieved by combining different encryption matrices generated based on the same base matrix between the client and the cloud, and user data and model data are encrypted separately. Under the premise of ensuring the privacy security of user data and model data, the encrypted data can be transmitted and operated collaboratively at both ends to reduce the risk of privacy leakage during data transmission and calculation. At the same time, relying on the characteristics of orthogonal encryption, the amount of calculation can be reduced and the encryption efficiency can be improved, thereby ensuring the efficiency and availability of large model processing on the basis of protecting privacy.
[0094] The large model data processing method provided in this application can be widely used in sensitive data scenarios that require both data privacy protection and efficient large model processing, including but not limited to the following scenarios:
[0095] Optionally, in the financial sector, when large models are used to process digitally sensitive data, for example, when banks, securities companies, and other institutions use large models to conduct risk assessments, intelligent recommendations, or compliance audits on user account information, transaction records, credit data, etc., this solution can be used to achieve collaborative processing between the client and the cloud. Specifically, the client performs orthogonal encryption on the user's financially sensitive data (such as transaction flows, credit scores, etc.), and the cloud performs orthogonal encryption on the model parameter data of the financial risk control model generated based on the large model. Calculations are performed based on the orthogonally encrypted vectors. This can prevent financial data from being leaked during transmission and calculation, meeting the privacy compliance requirements of the financial industry, while also reducing the amount of computation, improving encryption efficiency, and ensuring the efficiency of large models in processing financial data.
[0096] Optionally, in biometric data processing scenarios, when large models are used to verify and intelligently identify data containing biometric features such as faces, fingerprints, and irises, for example, when security systems use large models to compare and infer facial images, or when large models are used in the medical field to predict disease risks based on biometric data, this solution can be used to protect biometric privacy. Specifically, the client orthogonally encrypts the vectors corresponding to the collected biometric data (such as the feature vectors of facial images), and the cloud orthogonally encrypts the vectors corresponding to the large model's biometric recognition parameters, feature extraction network structure, and other model data. Both parties perform collaborative operations based on the resulting encrypted vectors, avoiding direct exposure of sensitive biometric data, ensuring the recognition accuracy of the large model, and balancing the needs of privacy protection and response efficiency.
[0097] In addition, this solution can also be extended to other large-model application scenarios involving sensitive data, such as government data processing, medical and health data modeling, etc. Any scenario that requires data processing while protecting the privacy of user data and model data can achieve dual protection of privacy security and processing efficiency through this solution.
[0098] In order to more clearly understand the large model data processing method provided by this application, the following Figure 1 A brief description of the large model in this application is given to facilitate easier understanding and application of the large model data processing method proposed in this application.
[0099] See also Figure 1 The large model includes a first part and a second part; the first part is deployed on the client and is used to process user data; the second part is deployed on the cloud and is used to process model data; the data processing method can be applied to the first part or the second part.
[0100] In this application, the large model adopts a distributed deployment architecture, specifically dividing it into the first part and the second part based on the model function, and deploying them on the client and the cloud respectively, so as to achieve local encryption of sensitive data and model parameters and cross-end collaborative computing processing.
[0101] Specifically, the first part of the large model serves as the front-end and back-end processing module for user interaction. Its core function is to encrypt the client's local data (i.e., user data). It should be noted that user data can include two types of data: first, fine-tuning data that users input into the large model based on their needs (such as user preference data and scenario adaptation data for personalized model training); second, inference data provided by users when initiating inference requests (such as text to be recognized, image features, etc.). The first part uses a built-in noise matrix to convert this user data into an encrypted feature vector and performs operations on the encrypted vector and the received encrypted vector.
[0102] The second part of the large model serves as the core computing and storage module, primarily responsible for encrypting local data (i.e., model data) stored in the cloud. This model data primarily consists of the model's parameters (such as the neural network's weight matrix, bias terms, and activation function parameters, which directly determine the model's reasoning capabilities and output accuracy). This second part encrypts the model parameter data using its corresponding noise matrix and supports computational processing on the encrypted vectors.
[0103] It should also be noted that, in some cases, the encrypted model data in the cloud also includes the structural data of the large model and the intermediate layer calculation data.
[0104] It is worth noting that any part of the large model has the ability to receive encrypted data and perform operations on encrypted data. Therefore, the large model data processing method provided in this application can be flexibly applied to any of the above parts. Specifically, when the data processing method is applied to the first part of the client, the client will take the lead in encrypting the user data and, in combination with the encrypted model data transmitted by the cloud, collaboratively generate the operation results; when the data processing method is applied to the second part of the cloud, the cloud will take the lead in encrypting the model data and, in combination with the encrypted user data transmitted by the client, collaboratively complete the operation.
[0105] Both of the above-mentioned application methods rely on the encryption processing and computing capabilities of the client and the cloud, and avoid the risk of data leakage for user data and model parameter data during model data calculation, thereby improving the level of privacy protection.
[0106] For ease of understanding, the following combination Figure 2 and Figure 3 The application scenarios to which this application is applicable are described in detail. Figure 2 This is a diagram of the application scenario of the large model data processing method provided in this application when it is executed in the cloud. Figure 3 This is a diagram of the application scenario when the large model data processing method provided in this application is executed on the client.
[0107] exist Figure 2 In the cloud-based execution scenario shown, the cloud, acting as the executor of the large model data processing method of this application, first encrypts its locally stored data (i.e., model data) to obtain a first encryption vector. Simultaneously, it also receives a second encryption vector corresponding to the encrypted remote data (i.e., user data) transmitted from the client. The cloud then operates on these first and second encryption vectors to obtain a calculation result corresponding to the user data. Furthermore, the cloud transmits this calculation result to the client for conversion and output.
[0108] exist Figure 3In the client execution scenario shown, the client, as the executor of the large model data processing method of this application, first encrypts its acquired local data (i.e., user data) to obtain a first encryption vector. Simultaneously, it also receives a second encryption vector corresponding to the encrypted remote data (i.e., model data) transmitted from the cloud. The client then performs operations on the first and second encryption vectors to obtain a calculation result corresponding to the user data. The calculation result is then converted and output.
[0109] In this application, both the cloud and the client can serve as the executors of the large-model data processing method, that is, to realize the encrypted collaborative operation of local data and remote data during the large-model data processing process, to ensure data privacy and security, and to flexibly adapt to different processing needs.
[0110] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.
[0111] Figure 4 A schematic diagram of a large model data processing method provided in this application Figure 1 The method in this embodiment can be implemented by software, hardware, or a combination of software and hardware. Figure 4 As shown, the method includes the following steps:
[0112] S401: Obtain a first encryption vector corresponding to local data, and receive a second encryption vector corresponding to remote data.
[0113] In this application, when the local data is user data, the remote data is model data; when the local data is model data, the remote data is user data; the first encryption vector and the second encryption vector are obtained by orthogonally encrypting the first vector and the second vector respectively; the first vector is the eigenvector corresponding to the local data, and the second vector is the eigenvector corresponding to the remote data; the encryption matrix used for the orthogonal encryption processing of the first vector and the second vector is obtained by encrypting the same base matrix with different noise matrices.
[0114] It should be noted that the specific content of the local data and remote data in this embodiment is uncertain and will change dynamically depending on the execution entity of this solution. In other words, when the execution entity is the first part deployed on the client, the local data is the client's user data, and the corresponding remote data is the cloud-based model data. Conversely, when the execution entity is the second part deployed on the cloud, the local data is the cloud-based model data, and the corresponding remote data is the client's user data.
[0115] On this basis, in different parts, the vectors corresponding to their respective data are orthogonally encrypted through the same basis matrix and the noise matrix generated by each part to obtain the encrypted vectors corresponding to their respective data, that is, the first vector corresponding to the local data and the second vector corresponding to the remote data.
[0116] Orthogonal encryption can be understood as an encryption method that introduces an orthogonal transformation during the encryption process. Specifically, a series of operations can be performed on the first or second vector to be encrypted, the first or second encryption matrix generated by encrypting the base matrix and performing an orthogonal transformation on the noise matrix, to achieve the encryption process.
[0117] During the above implementation process, the privacy and security of user data and model data can be guaranteed by encrypting the data. Furthermore, orthogonal encryption based on the same basis matrix not only ensures the correlation of the encryption process, but also reduces the amount of calculation and improves encryption efficiency. In addition, through different noise matrices, the independence and security of data encryption are achieved, thereby ensuring the efficiency and availability of large model processing while protecting privacy.
[0118] S402: Perform calculation on the first encryption vector and the second encryption vector to obtain a calculation result corresponding to the user data.
[0119] In this application, if the computation is performed by the first component deployed on the client, the second component deployed on the cloud encrypts the model data to obtain the corresponding encrypted vector, which is then transmitted as the second encrypted vector to the first component of the large model. Simultaneously, the first component can also obtain local user data and encrypt it to obtain the corresponding first encrypted vector. Subsequently, based on its own computing power, the first component performs a preset computation on the two encrypted vectors, avoiding exposure of plaintext data through computation of the encrypted vectors and obtaining an inference result or fine-tuning feedback result corresponding to the user data.
[0120] Optionally, if the computation is performed by the second component deployed in the cloud, the first component deployed in the client encrypts the user data and transmits the resulting encryption vector as the second encryption vector to the second component in the cloud. The second component receives the second encryption vector, obtains the local model data, and encrypts it to obtain the first encryption vector. Similarly, the second component performs a preset computation on the two encryption vectors and feeds the computation result back to the first component corresponding to the user data, allowing data conversion and output in the first component. This allows the response to user needs to be completed without accessing the plaintext user data or model data.
[0121] It should be noted that no matter in which entity the operation is performed, since the first encryption vector and the second encryption vector are orthogonally encrypted based on different encryption parameters generated by the same basis matrix, the operation process satisfies the mathematical compatibility of the encryption vector. Therefore, the above encryption method can ensure the accuracy and effectiveness of the final operation result, and achieve the efficiency and availability of large model processing while protecting privacy.
[0122] Optionally, operations include but are not limited to vector inner product, norm calculation, etc., and the specific operation method is determined according to the task type of the large model.
[0123] In an optional embodiment, the operation includes a vector inner product operation; accordingly, the process of performing the operation on the first encrypted vector and the second encrypted vector to obtain a calculation result corresponding to the user data may include: obtaining a vector inner product operation expression corresponding to the vector inner product operation; and performing a vector inner product calculation on the first encrypted vector and the second encrypted vector based on the vector inner product operation expression to obtain a calculation result corresponding to the user data.
[0124] Specifically, the vector inner product operation expression corresponding to the vector inner product operation is obtained; wherein, the expression is a mathematical operation formula preset in the execution body, and its form is the sum of the multiplication of the corresponding elements of the two vectors, that is, for vectors of dimension n and vector , the vector inner product operation expression is .
[0125] Subsequently, the vector inner product calculation is performed on the first and second encrypted vectors based on the vector inner product expression. Specifically, the generated first encrypted vector and the received second encrypted vector are called, and elements at corresponding positions in the two vectors are sequentially extracted according to the vector inner product expression. The extracted elements are multiplied pairwise, and all the products are accumulated. The resulting sum is the vector inner product value of the first and second encrypted vectors, which is also the calculation result corresponding to the user data.
[0126] Through the above process, the mathematical properties of vector inner product operations are utilized to complete the operation directly based on the encrypted vectors without decrypting the first and second encrypted vectors. This not only achieves the collaborative processing of user data and remote data, but also avoids the risk of privacy leakage caused by decryption of encrypted vectors during the operation process, ensuring data security and operation accuracy during large model processing.
[0127] On the basis of the above implementation manner, the technical solution of the present application further includes, after obtaining the calculation result corresponding to the user data: on the client side, performing text conversion processing on the calculation result to obtain output data corresponding to the user data.
[0128] In the technical solution of this application, since orthogonal encryption is used for data encryption, the calculation results of the first encrypted vector and the second encrypted vector are mathematically equivalent to the calculation results of the original vector before encryption, that is, they meet the consistency characteristics of the inner product and norm of the orthogonal matrix. Based on this, after obtaining the calculation results, the first part of the large model can directly perform text conversion processing based on the encrypted state results to obtain the corresponding output results without performing decryption operations. In this way, while ensuring the output quality of the large model, the privacy protection of user data and model parameters throughout the entire life cycle is achieved, which is particularly suitable for scenarios sensitive to data privacy, such as medical consultations and financial consulting.
[0129] In the above technical solution, orthogonal encryption is achieved by combining different encryption matrices generated based on the same base matrix between the client and the cloud, and user data and model data are encrypted separately. Under the premise of ensuring the privacy and security of user data and model data, the encrypted data can be transmitted and operated collaboratively at both ends to reduce the risk of privacy leakage in the data transmission and calculation process. At the same time, relying on the characteristics of orthogonal encryption, the amount of calculation can be reduced and the encryption efficiency can be improved, thereby ensuring the efficiency and availability of large model processing on the basis of protecting privacy.
[0130] Next, the process of performing orthogonal encryption on local data and remote data to obtain their respective corresponding encryption vectors is introduced in detail.
[0131] Based on this, the process of orthogonally encrypting local data to obtain a first encrypted vector may include: obtaining local data, performing vector conversion processing on the local data to obtain a first vector; obtaining a first encryption matrix; wherein the first encryption matrix is generated based on a preset basis matrix and a first noise matrix; and encrypting the first vector based on the first encryption matrix to obtain the first encrypted vector.
[0132] For ease of understanding, the following example illustrates the relevant process using the first part deployed on the client as the execution entity, and correspondingly limiting local data to the client's user data. It should be emphasized that this example is only to help understand the technical solution and does not constitute a limitation on the local data processing process in this solution.
[0133] Specifically, when the user inputs user data into the big model through the client, the first part of the big model deployed on the client will receive the above user data and perform local encryption processing in the first part of the big model. That is, the entire encryption process of the user data is completed locally on the client, avoiding the transmission or exposure of user data in plain text, and ensuring the privacy and security of user data from the source.
[0134] Specifically, before encryption, the first part of the large model can perform vector conversion on the user data based on its pre-configured text encoding model or image encoding model, etc., so as to map the input original data into the first vector in the high-dimensional feature space.
[0135] During this period, a pre-generated first encryption matrix is called; wherein the first encryption matrix is generated based on a preset base matrix and a first noise matrix.
[0136] It should be explained that the basis matrix can be understood as the basic encryption benchmark shared by the first and second parts of the large model.
[0137] Optionally, the base matrix can be generated by the first part and the second part by sharing a random seed or synchronizing information.
[0138] Among them, the shared random seed can be understood as the same initial random value (or random sequence) pre-agreed between the first and second parts of the large model or transmitted through a secure communication link. This value serves as the starting point for generating a random number sequence, allowing both parties to generate completely consistent random numbers or derivative matrices, namely, the base matrix, based on the same algorithm.
[0139] It should also be explained that information synchronization can be understood as the first and second parts of the large model interacting with each other through data, so that the basis matrices held by both parties, or the generation parameters of the basis matrices, are kept consistent, so as to achieve a completely consistent basis matrix as above.
[0140] The above-mentioned method of generating the basis matrix ensures that the basis matrices of each part are highly unified in consistency and synchronization, avoiding inconsistency problems. It can also use the shared random seed as a security mechanism to further enhance the security of data generation.
[0141] In order to prevent data leakage caused by inverse deduction of the basis matrix, the first part and the second part use independent parameters to perturb the basis matrix respectively. That is, the first part and the second part can independently generate their own corresponding encryption matrices based on their respective encryption parameters when performing orthogonal encryption on the basis matrix, and introduce them into the orthogonalization processing link of the basis matrix respectively to realize orthogonal encryption of the basis matrix.
[0142] Specifically, before processing the local data, the first part of the large model may perform orthogonal encryption processing on the pre-acquired basis matrix using the first noise matrix corresponding thereto to generate a corresponding first encryption matrix.
[0143] It should be noted that the generated first encryption matrix can be cached and reused continuously within a preset validity period (such as 1 hour or processing 1,000 data records). During this period, all local data encryption operations use the same matrix, thereby avoiding resource consumption caused by repeated calculations.
[0144] When a preset time threshold or processing number threshold is reached, the client automatically triggers the matrix update process, that is, re-encrypting the base matrix based on the newly generated first noise matrix, or re-encrypting the newly generated base matrix based on the first noise matrix to generate a new first encryption matrix and replace the old matrix, ensuring the long-term security of the encryption system.
[0145] On this basis, when processing local data, the first vector corresponding to the local data is operated through the first encryption matrix. Specifically, the characteristic dimension and numerical distribution of the first vector can be encrypted and transformed to generate a first encrypted vector corresponding to the first vector.
[0146] Through the above steps, the first part of the large model converts user data containing sensitive data into encrypted vectors. This ensures that the original user data always exists in encrypted form during the model transmission process, protecting data privacy, and ensures that the encrypted vectors can be directly used for subsequent model calculations without the need for decryption to achieve computational compatibility, thereby ensuring the efficiency and availability of large model processing while protecting privacy.
[0147] In the above implementation process, the first part of the large model processes the basis matrix based on the first noise matrix to obtain the first encryption matrix. An optional implementation method may include: encrypting the basis matrix based on the first noise matrix to obtain the first initial encryption matrix; and performing orthogonal transformation on the first initial encryption matrix to obtain the first encryption matrix.
[0148] Specifically, the first part of the large model obtains a first noise matrix corresponding to the pre-generated user data. Using this encryption parameter, the base matrix is encrypted. This is done by fine-tuning the values in the base matrix to achieve preliminary encryption of the base matrix and generate a first initial encryption matrix corresponding to the user data.
[0149] Next, to ensure the accuracy of subsequent encryption calculations and optimize computational complexity, an orthogonal transformation is performed on the first initial encryption matrix to generate a corresponding orthogonal matrix, the first encryption matrix. This process not only improves the security of data encryption but also enhances the compatibility and efficiency of the calculations.
[0150] On this basis, the first part of the large model encrypts the first vector based on the first encryption matrix to obtain the first encrypted vector. An optional implementation method may include: performing an orthogonal transformation on the first vector based on the first encryption matrix to obtain a first initial encrypted vector; and encrypting the first initial encrypted vector based on the first noise vector corresponding to the local data to obtain the first encrypted vector.
[0151] Specifically, as can be seen from the above implementation process, since the first encryption matrix has an orthogonal characteristic, the process of using it to encrypt the first vector can essentially be understood as a process of orthogonalizing the first vector, that is, through the multiplication operation of the first encryption matrix and the first vector, an orthogonal vector corresponding to the first vector, i.e., the first initial encryption vector, is generated.
[0152] This orthogonal matrix-based encryption method can preserve the vector's operational properties (such as the inner product and norm) while performing an encryption transformation on the first vector, thereby ensuring that the encrypted vector can directly participate in cross-end collaborative computing between the client and the cloud, effectively avoiding processing failures caused by encryption operations destroying data operational characteristics. Ultimately, on the basis of protecting user data privacy, it ensures the availability and accuracy of the large model processing process.
[0153] To further enhance encryption security, the first part of the large model uses a first noise vector corresponding to the user data. This noise vector is then used to encrypt the first initial encryption vector, further enhancing encryption complexity and security, ultimately yielding the first encryption vector.
[0154] Through the above implementation, the orthogonal characteristics of the first encryption matrix can be used to retain the core operational properties of the first vector while completing the encryption, ensuring that the encrypted first initial encryption vector can directly participate in cross-end collaborative computing, thereby ensuring the continuity and accuracy of large model processing; and secondary encryption can be performed based on the first noise vector bound to the local data, and the privacy protection strength of the data can be further enhanced through personalized encryption logic, thereby effectively resisting malicious cracking and preventing data leakage while taking into account the operational compatibility and personalized privacy protection of the encryption vector, and balancing privacy and usability.
[0155] During this period, the current execution entity also receives a second encryption vector corresponding to the remote data. Optionally, the second encryption vector corresponding to the remote data transmitted by another portion of the large model is received; wherein the second encryption vector is generated by encrypting the remote data by the other portion of the large model; wherein encrypting the remote data includes: obtaining the remote data, performing vector conversion on the remote data to obtain a second vector; obtaining a second encryption matrix; wherein the second encryption matrix is generated based on a preset basis matrix and a second noise matrix; and encrypting the second vector based on the second encryption matrix to obtain the second encrypted vector.
[0156] Continuing with the example of the first part deployed on the client as the execution body, the other part of the large model is the second part deployed on the cloud, and the remote data is correspondingly limited to the model data on the cloud.
[0157] Specifically, the first part of the large model receives the second encryption vector corresponding to the model data transmitted by the second part of the large model through a preset secure communication link.
[0158] It should be noted that a data verification mechanism can be pre-integrated into the secure communication link. In this way, hash value comparison and other methods can be used to ensure that the second encryption vector has not been tampered with during transmission, thereby ensuring data security during data transmission.
[0159] Before transmitting the second encrypted vector, the second part of the large model deployed in the cloud first retrieves the model data from the local cloud storage unit and performs local encryption on the model data. In other words, the entire encryption process for the model data is completed within the cloud environment. This prevents model data leakage during the encryption stage at the source of the data processing chain, ensuring the security of the model data.
[0160] Specifically, during the model data encryption process, the second part of the large model can vectorize the model data using a built-in feature conversion model. Optionally, since model data is typically matrix-type parameters, the vector conversion can first be performed by performing a matrix flattening operation, then mapping the values to a preset interval to generate a fixed-dimensional numerical vector, i.e., the second vector.
[0161] During this period, the second part calls a preset second encryption matrix; wherein the second encryption matrix is generated based on the base matrix and the second noise matrix. It can be explained that the base matrix is the initial encryption reference shared with the first part of the large model.
[0162] Before processing the model data, the second part of the large model can pre-process the base matrix with its corresponding second noise matrix to perform orthogonal encryption processing to generate a corresponding second encryption matrix.
[0163] On this basis, the second vector is operated through the second encryption matrix, specifically, the characteristic dimension and numerical distribution of the second vector can be encrypted and transformed to generate a second encrypted vector corresponding to the second vector.
[0164] In this way, through the above steps, the second part of the large model converts the model data into an encrypted vector. Under the premise of ensuring that the original information of the model data is not leaked, it can realize cross-end collaborative operation of the encrypted vector and the first encrypted vector of the client, thereby achieving the efficiency and availability of large model processing while protecting privacy.
[0165] In the above implementation process, the second part of the large model processes the basis matrix based on the second noise matrix to obtain the second encrypted matrix. An optional implementation method includes: encrypting the basis matrix based on the second noise matrix to obtain the second initial encrypted matrix; and performing orthogonal transformation on the second initial encrypted matrix to obtain the second encrypted matrix.
[0166] Specifically, the second part of the large model obtains a pre-generated second noise matrix corresponding to the model data. Using this parameter, the diagnosis is encrypted, that is, the values in the basis matrix are fine-tuned to achieve preliminary encryption of the basis matrix, generating a second initial encryption matrix corresponding to the model data.
[0167] Next, to ensure the accuracy of subsequent encryption calculations and optimize computational complexity, an orthogonal transformation is performed on the second initial encryption matrix to generate a corresponding orthogonal matrix, the second encryption matrix. This process not only improves the security of data encryption but also enhances the compatibility and efficiency of the calculations.
[0168] On this basis, the second part of the large model encrypts the second vector based on the second encryption matrix to obtain an optional implementation of the second encrypted vector, which includes: performing an orthogonal transformation on the second vector based on the second encryption matrix to obtain a second initial encrypted vector; and encrypting the second initial encrypted vector based on the second noise vector corresponding to the remote data to obtain a second encrypted vector.
[0169] Specifically, as can be seen from the above implementation process, since the second encryption matrix has an orthogonal property, the process of using it to encrypt the second vector can essentially be understood as a process of orthogonalizing the second vector, that is, through the multiplication operation of the second encryption matrix and the second vector, an orthogonal vector corresponding to the second vector, i.e., the second initial encryption vector, is generated.
[0170] This orthogonal matrix-based encryption method can preserve the vector's operational properties (such as inner product, norm, and other features) while performing an encryption transformation on the second vector, thereby ensuring that the encrypted vector can directly participate in cross-end collaborative computing between the client and the cloud, effectively avoiding processing failures caused by encryption operations destroying data computational characteristics. Ultimately, while protecting user data privacy, it ensures the availability and accuracy of large model processing.
[0171] To further enhance encryption security, the second part of the large model uses a second noise vector corresponding to the user data. This noise vector is then used to encrypt the second initial encryption vector, further enhancing encryption complexity and security, ultimately yielding the second encryption vector.
[0172] Through the above implementation, the orthogonal characteristics of the second encryption matrix can be used to retain the core operational properties of the second vector while completing the encryption, ensuring that the encrypted second initial encryption vector can directly participate in cross-end collaborative computing, thereby ensuring the continuity and accuracy of large model processing; it can also rely on the second noise vector bound to the local data for secondary encryption, and further enhance the privacy protection strength of the data through personalized encryption logic, thereby effectively resisting malicious cracking and preventing data leakage while taking into account the operational compatibility and personalized privacy protection of the encryption vector, and balancing privacy and usability.
[0173] In the above implementation process, the first encryption parameter and the third encryption parameter are exclusive encryption parameters generated by the first part.
[0174] Specifically, the first noise matrix of the first encryption parameter can adopt the first noise matrix pre-generated in the first part. This noise matrix is generated by a random number generation algorithm, such as a Gaussian noise matrix, a Gamma noise matrix, a Poisson noise matrix, etc. Correspondingly, the first noise vector is also the first noise vector generated in the first part. This noise vector is also generated by a random algorithm, such as a Gaussian noise vector, a Gamma noise vector, a Poisson noise vector, etc. To achieve efficient calculation, the dimension of the noise matrix should be adapted to the base matrix to provide a dynamic perturbation basis for the encryption processing of the base matrix; the dimension of the noise vector should be adapted to the first initial encryption vector to facilitate its encryption processing.
[0175] Corresponding to the first noise matrix and the first noise vector, the second noise matrix and the second noise vector are exclusive encryption parameters generated for the second part.
[0176] Specifically, the second noise matrix can be a second noise matrix pre-generated in the second part, which is generated by a random number generation algorithm, such as a Gaussian noise matrix, a Gamma noise matrix, a Poisson noise matrix, etc. Correspondingly, the second noise vector can also be a second noise vector generated in the second part, which is also generated by a random algorithm, such as a Gaussian noise vector, a Gamma noise vector, a Poisson noise vector, etc. To achieve efficient calculation, the dimension of the noise matrix should be adapted to the base matrix to provide a dynamic perturbation basis for the encryption processing of the base matrix; the dimension of the noise vector should be adapted to the second initial encrypted vector to facilitate encryption processing thereof.
[0177] It should be noted that in some scenarios, the first and second noise matrices can use Gaussian noise matrices, and the first and second noise vectors can use Gaussian noise vectors. Because Gaussian noise follows a normal distribution with a mean of 0, its distribution curve exhibits a "tall and thin" characteristic. This results in random values of the noise matrix and noise vector being concentrated near the mean, and the standard deviation of this normal distribution is small. This randomness provides a perturbation basis for the encryption process while preventing significant impacts on the accuracy of matrix and vector operations due to excessive noise amplitude.
[0178] Based on the above, it should also be noted that the matrix values of the first noise matrix and the second noise matrix are greater than the first matrix threshold and less than the second matrix threshold; the first matrix threshold and the second matrix threshold are determined based on the computational complexity of the large model and the model safety performance.
[0179] In this application, although the first noise matrix and the second noise matrix are composed of different matrix values, their matrix values must be between the first matrix threshold and the second matrix threshold. This ensures the effectiveness of the noise, that is, it enhances data security without affecting the calculation accuracy.
[0180] It's important to note that the settings for the first and second matrix thresholds are based on the computational complexity of the large model and the model's safety performance requirements. Specifically, these thresholds need to ensure model computational accuracy while providing sufficient noise to mitigate potential security threats. Therefore, when selecting the values of the noise matrix, it's important to consider: too small a value may reduce safety, while too large a value may affect computational accuracy. Therefore, selecting an appropriate range for determining these two matrix thresholds is crucial. Within this range, the values of the first and second noise matrices can be arbitrary.
[0181] For example, in a financial risk control scenario with high requirements for calculation accuracy, the calculation of the noise matrix can be pre-set to allow a calculation error of ≤0.1%. Based on this, the first matrix threshold can be set to 0.001 and the second matrix threshold can be set to 0.009. At this time, the matrix values of the first noise matrix can be selected as 0.005, 0.008, etc., and the matrix values of the second noise matrix can be selected as 0.0015, 0.0012, etc., all of which are in the interval [0.001, 0.009].
[0182] In this way, the generated noise matrix not only provides the necessary security during the data encryption process, but also ensures that the model's calculation results remain within an acceptable accuracy range. This method effectively balances security and computational accuracy, ensuring the overall performance of the model.
[0183] Similar to the noise matrix, it should be noted that the vector values of the first noise vector and the second noise vector are greater than the first vector threshold and less than the second vector threshold. The first vector threshold and the second vector threshold are determined based on the computational complexity of the large model and the model safety performance.
[0184] Exemplarily, the calculation of the noise vector can be pre-set to allow the calculation error to be ≤0.2%, then the first vector threshold can be set to 0.02, the second vector threshold can be set to 0.15, the vector data of the first noise vector can be selected from values such as 0.05 and 0.08, and the vector value of the second noise vector can be selected from values such as 0.1 and 0.12.
[0185] In this application, although the first noise vector and the second noise vector are composed of different vector values, their vector values must be between the first vector threshold and the second vector threshold. This ensures the effectiveness of the noise, that is, it enhances data security without affecting calculation accuracy.
[0186] It should be noted that the setting of the first vector threshold and the second vector threshold is determined based on the computational complexity of the large model and the security performance requirements of the model. Specifically, these thresholds need to provide sufficient noise to resist potential security threats while ensuring the computational accuracy of the model. Based on this, when selecting the value of the noise vector, it is necessary to consider that too small a value may lead to reduced security, while too large a value may affect the computational accuracy. Therefore, it is crucial to select an appropriate range to determine the two vector thresholds. Within this range, the values of the first noise vector and the second noise vector can be arbitrary. In this way, the generated noise vector can not only provide the necessary security guarantees during the data encryption process, but also ensure that the calculation results of the model remain within an acceptable accuracy range. This method effectively balances security and computational accuracy, ensuring the overall performance of the large model.
[0187] In order to reduce the risk of statistical attacks that may be caused by long-term use of the same encryption matrix, the present application provides a technical solution, that is, during implementation, the first encryption matrix and the second encryption matrix can be regenerated within a preset time interval.
[0188] Since the first encryption matrix and the second encryption matrix are generated by respectively combining the base matrix with the first noise matrix and the second noise matrix, and the base matrix is generated by sharing a random seed, in the above implementation process, it is possible to choose to regenerate the first noise matrix or the second noise matrix, or regenerate the base matrix or the random seed within a preset time interval.
[0189] Specifically, the preset time interval in the above embodiment may be regenerated at fixed intervals, or may be regenerated after completing a preset number of calculations, without specific limitation.
[0190] It should also be noted that in the above-mentioned process of vector conversion and encryption of local data and model data, as well as the process of operation on the encrypted vector, encryption processing or vector inner product operation can be performed through parallel processing.
[0191] The use of parallel processing can significantly improve the efficiency and performance of the system. Specifically, the data or vector to be processed is divided into multiple small blocks. Through parallel processing, multiple encryption operations or vector inner product operations can be performed simultaneously, and the respective results are summed to obtain the final result. This can greatly reduce the calculation time, not only improving the speed of data processing, but also making full use of the computing resources of the device where the large model is located and optimizing resource usage. In addition, parallel processing helps to improve the responsiveness of large models to user data, especially when processing large-scale data sets, which can significantly reduce latency and improve overall processing efficiency.
[0192] On the basis of the above-mentioned implementation manner, the present application also provides an exemplary embodiment, and the large model data processing process of the present application is explained based on the exemplary embodiment. Figure 5 A schematic diagram of a large model data processing method provided in this application Figure 2 .
[0193] In this application, the first and second parts of the large model are deployed on the cloud and client, respectively.
[0194] Specifically, on the client side, the first part of the large model performs vector conversion on the received user data to obtain a first vector, which is represented as: u=[1.0,2.0,3.0];
[0195] Get the basis matrix H of the large model, which is expressed as: H=[[0.4967 -0.1383 0.6477], [1.523 -0.2342 -0.2341], [-0.4695 -0.2341 1.5792]];
[0196] In the first part, noise is added and orthogonal transformation is performed to obtain the corresponding orthogonal matrix, namely the first encryption matrix; its expression is: Q A =[[-0.2783 0.8319,0.4801],[-0.9368 -0.3483 -0.0318],[0.2117 -0.4325 0.8766]];
[0197] Optionally, before encrypting the first vector, the generated first encryption matrix may be pre-verified for orthogonality to ensure that it satisfies the matrix orthogonality property and to ensure the accuracy of subsequent calculation results. Specifically, the verification process includes: Q A T Q A =[[1.0000 -0.0000 -0.0000],[-0.0000 1.0000 -0.0000],[-0.0000 -0.00001.0000]]=I, which satisfies the matrix orthogonality property.
[0198] Subsequently, the first encryption matrix is used to encrypt the first vector to obtain an encrypted first encryption vector; the expression form of the encrypted first encryption vector is: u'=[-0.134008, 2.231992, 4.964003].
[0199] During this period, in the cloud, the second part of the large model performs vector conversion on the model data stored in itself to obtain the second vector, which is expressed as: v=[4.0,5.0,6.0];
[0200] Get the basis matrix H of the large model, which is expressed as: H=[[0.4967 -0.1383 0.6477], [1.523 -0.2342 -0.2341], [-0.4695 -0.2341 1.5792]];
[0201] In the second part, noise is added and orthogonal transformation is performed to obtain the corresponding orthogonal matrix, namely the second encryption matrix; its expression is: Q B =[[-0.2578 0.8491 0.4618],[-0.9628 -0.2699 -0.012],[0.0838 -0.4541, 0.8869]];
[0202] Optionally, before encrypting the second vector, the generated second encryption matrix may be pre-verified for orthogonality to ensure that it satisfies the matrix orthogonality property, thereby ensuring the accuracy of subsequent calculation results. Specifically, the verification process includes: B T Q B =[[1.0000 0.0000 0.0000],[0.0000 1.0000 0.0000],[0.0000 0.0000 1.0000]]=I, which satisfies the matrix orthogonality property.
[0203] In some cases, verification can also be performed using two encryption matrices, namely Q B=[[0.992 0.023 -0.03],[0.025 0.973 -0.027],[-0.025 -0.024 0.998]], we can see that the diagonal elements are: 0.992, 0.973, 0.998 (the ideal value should be 1), and the off-diagonal elements have a maximum deviation of 0.03 (the ideal value should be 0). A With Q B Generated by different noises, there is a certain error in the complementarity. A With Q B Mutual orthogonality is approximately satisfied, and the magnitude of the deviation (≤0.03) is acceptable in orthogonal basis applications. At the same time, the error can be reduced by adjusting the noise.
[0204] Subsequently, the second vector is encrypted using the second encryption matrix to obtain an encrypted second encrypted vector; the expression form of the encrypted second vector is: v'=[5.597995,2.463999,-0.750002].
[0205] On this basis, the inner product calculation of the first encryption vector and the second encryption vector can be performed on the client or in the cloud. .
[0206] Compared with the true inner product value 32, the relative error is 0.0004%. It can be seen that even with the addition of noise (σ=1e-3), Q A T Q B ≈I, error <3% (meets safety calculation requirements).
[0207] Verification of the impact of different noise levels on inner product accuracy. After testing, the results of the impact of different noise levels on inner product accuracy are as follows:
[0208] σ=0.001:|| Q A T Q B -I||=0.0002; very low noise approximate unit matrix;
[0209] σ=0.010:|| Q A T Q B -I||=0.0051; slight deviation
[0210] σ=0.100:|| Q A T Q B -I||=0.1523; obvious deviation
[0211] σ=1.000:|| Q A T Q B-I||=1.8937; serious deviation
[0212] σ=10.00:|| Q A T Q B -I||=2.0149; completely irrelevant basis
[0213] Based on the above verification results, it is recommended that: 0<σ< 0.01;
[0214] In other words, when matrix noise σ ≤ 1e-3, the inner product calculation error is less than 0.01%, and vector-level noise (σ = 1e-5) has a negligible impact on the result. This dual noise injection (matrix-level + vector-level) effectively hides the original data while simultaneously destroying the original vector structure through orthogonal transformation, preventing reverse engineering.
[0215] Figure 6 This is a schematic diagram of the structure of a large model data processing device provided by this application. Figure 6 The large model data processing device 60 includes: an encryption vector acquisition module 601 and an encryption vector calculation module 602; wherein,
[0216] The encryption vector acquisition module 601 is used to acquire a first encryption vector corresponding to local data and receive a second encryption vector corresponding to remote data; wherein, when the local data is user data, the remote data is model data; when the local data is model data, the remote data is user data;
[0217] The first encrypted vector and the second encrypted vector are obtained by orthogonally encrypting the first vector and the second vector, respectively; the first vector is the eigenvector corresponding to the local data, and the second vector is the eigenvector corresponding to the remote data; the encryption matrix used in the orthogonal encryption of the first vector and the second vector is obtained by encrypting the same base matrix with different noise matrices;
[0218] The encryption vector calculation module 602 is configured to perform operations on the first encryption vector and the second encryption vector to obtain a calculation result corresponding to the user data.
[0219] In an optional implementation, the encryption vector acquisition module 601 includes:
[0220] A first vector determination submodule is used to obtain local data, perform vector conversion processing on the local data, and obtain a first vector;
[0221] A first encryption matrix acquisition submodule is configured to acquire a first encryption matrix, wherein the first encryption matrix is generated based on a preset basis matrix and a first noise matrix;
[0222] The first encryption vector determination submodule is configured to perform encryption processing on the first vector based on the first encryption matrix to obtain the first encryption vector.
[0223] In an optional implementation, the first encryption matrix determination submodule includes:
[0224] A first initial encryption matrix determining unit is configured to perform encryption processing on the base matrix based on the first noise matrix to obtain a first initial encryption matrix;
[0225] The first encryption matrix determining unit is configured to perform an orthogonal transformation on the first initial encryption matrix to obtain a first encryption matrix.
[0226] In an optional embodiment, the first encryption vector determination submodule,
[0227] A first initial encryption vector determining unit, configured to perform an orthogonal transformation on the first vector based on a first encryption matrix to obtain a first initial encryption vector;
[0228] The first encryption vector determining unit is configured to encrypt the first initial encryption vector based on the first noise vector corresponding to the local data to obtain a first encryption vector.
[0229] In an optional implementation, the encryption vector acquisition module 601 includes:
[0230] a second encryption vector receiving module, configured to receive a second encryption vector corresponding to remote data transmitted by another portion of the large model; wherein the second encryption vector is generated by encrypting the remote data by the other portion of the large model;
[0231] The second encryption vector receiving module includes:
[0232] A second vector determination submodule is used to obtain local data, perform vector conversion processing on the local data, and obtain a second vector;
[0233] A second encryption matrix acquisition submodule is configured to acquire a second encryption matrix; wherein the second encryption matrix is generated based on a preset base matrix and a second noise matrix;
[0234] The second encryption vector determination submodule is configured to perform encryption processing on the second vector based on the second encryption matrix to obtain a second encryption vector.
[0235] In an optional implementation, the second encryption matrix determination submodule includes:
[0236] A second initial encryption matrix determining unit is configured to perform encryption processing on the base matrix based on the second noise matrix to obtain a second initial encryption matrix;
[0237] The second encryption matrix determining unit is used to perform orthogonal transformation processing on the second initial encryption matrix to obtain a second encryption matrix.
[0238] In an optional embodiment, the second encryption vector determination submodule,
[0239] A second initial encryption vector determining unit, configured to perform an orthogonal transformation on the second vector based on a second encryption matrix to obtain a second initial encryption vector;
[0240] The second encryption vector determining unit is configured to encrypt the second initial encryption vector based on a second noise vector corresponding to the local data to obtain a second encryption vector.
[0241] In an optional implementation, the first noise matrix and the second noise matrix are random noise matrices; and the first noise vector and the second noise vector are random noise vectors.
[0242] In an optional embodiment, the matrix values of the first noise matrix and the second noise matrix are greater than the first matrix threshold and less than the second matrix threshold; the first matrix threshold and the second matrix threshold are determined based on the computational complexity and model safety performance of the large model;
[0243] The vector values of the first noise vector and the second noise vector are greater than the first vector threshold and less than the second vector threshold; the first vector threshold and the second vector threshold are determined based on the computational complexity and model safety performance of the large model.
[0244] In an optional implementation, the base matrix is generated by the first part and the second part by sharing a random seed or synchronizing information.
[0245] In an optional implementation, the base matrix or random seed is regenerated at intervals of a preset duration.
[0246] In an optional implementation manner, the first noise matrix or the second noise matrix is regenerated at intervals of a preset duration.
[0247] In an optional embodiment, the operation includes a vector inner product operation; the encrypted vector calculation module 602 includes:
[0248] The expression acquisition submodule is used to obtain the vector inner product operation expression corresponding to the vector inner product operation;
[0249] The calculation result acquisition submodule is used to perform vector inner product calculation on the first encrypted vector and the second encrypted vector based on the vector inner product operation expression to obtain the calculation result corresponding to the user data.
[0250] In an optional embodiment, the device includes:
[0251] The parallel computing module is used to perform encryption processing or vector inner product operations through parallel processing.
[0252] In an optional embodiment, the device further comprises:
[0253] The data conversion module is used to perform text conversion on the calculation results in the first part of the large model to obtain output data corresponding to the user data.
[0254] Figure 7 This is a block diagram of an electronic device provided by this application. The device can be a client terminal device or a cloud server. Figure 7 , device 700 may include one or more of the following components: a processing component 702 , a memory 704 , a power component 706 , a multimedia component 708 , an audio component 710 , an input / output interface 712 , a sensor component 714 , and a communication component 716 .
[0255] The processing component 702 generally controls the overall operation of the device 700, such as operations associated with display, phone calls, data communications, camera operation, and recording operations. The processing component 702 may include one or more processors 720 to execute instructions to perform all or part of the steps of the above-described method. In addition, the processing component 702 may include one or more modules to facilitate interaction between the processing component 702 and other components. For example, the processing component 702 may include a multimedia module to facilitate interaction between the multimedia component 708 and the processing component 702.
[0256] The memory 704 is configured to store various types of data to support operations on the device 700. Examples of such data include instructions for any application or method operating on the device 700, contact data, phone book data, messages, pictures, videos, etc. The memory 704 can be implemented by any type of volatile or non-volatile memory device, or a combination thereof, such as static random-access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disk.
[0257] The power supply component 706 provides power to the various components of the device 700. The power supply component 706 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the device 700.
[0258] The multimedia component 708 includes a screen that provides an output interface between the device 700 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, it may be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, slides, and gestures on the touch panel. The touch sensors can detect not only the boundaries of a touch or slide action, but also the duration and pressure associated with the touch or slide action. In some embodiments, the multimedia component 708 includes a front-facing camera and / or a rear-facing camera. When the device 700 is in an operating mode, such as a capture mode or a video mode, the front-facing camera and / or the rear-facing camera can receive external multimedia data. Each front-facing camera and the rear-facing camera can have a fixed optical lens system or have variable focal length and optical zoom capabilities.
[0259] The audio component 710 is configured to output and / or input audio signals. For example, the audio component 710 includes a microphone (MIC) that is configured to receive external audio signals when the device 700 is in an operating mode, such as a call mode, a recording mode, or a voice recognition mode. The received audio signals may be further stored in the memory 704 or transmitted via the communication component 716. In some embodiments, the audio component 710 also includes a speaker for outputting audio signals.
[0260] The input / output interface 712 provides an interface between the processing component 702 and peripheral interface modules, such as a keyboard, a click wheel, buttons, etc. These buttons may include but are not limited to: a home button, a volume button, a start button, and a lock button.
[0261] Sensor assembly 714 includes one or more sensors for providing various status assessments of device 700. For example, sensor assembly 714 can detect the open / closed state of device 700, the relative positioning of components, such as the display and keypad of device 700. Sensor assembly 714 can also detect changes in the position of device 700 or a component of device 700, the presence or absence of user contact with device 700, the orientation or acceleration / deceleration of device 700, and changes in the temperature of device 700. Sensor assembly 714 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. Sensor assembly 714 may also include an optical sensor, such as a Complementary Metal Oxide Semiconductor (CMOS) sensor or a Charge-Coupled Device (CCD) sensor, for use in imaging applications. In some embodiments, sensor assembly 714 may also include an accelerometer, a gyroscope, a magnetic sensor, a pressure sensor, or a temperature sensor.
[0262] The communication component 716 is configured to facilitate wired or wireless communication between the device 700 and other devices. The device 700 can access a wireless network based on a communication standard, such as WiFi, 4G or 5G, or a combination thereof. In an exemplary embodiment, the communication component 716 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 716 also includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra wide band (UWB) technology, Bluetooth (BT) technology and other technologies.
[0263] In an exemplary embodiment, the device 700 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the above method.
[0264] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 704 including instructions. The instructions are executable by the processor 720 of the device 700 to perform the above method. For example, the non-transitory computer-readable storage medium may be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, or the like.
[0265] A non-transitory computer-readable storage medium, when the instructions in the storage medium are executed by a processor of a server, enables the server to perform the above-mentioned large model data processing method.
[0266] An embodiment of the present application also provides a chip for running instructions, which is used to execute the technical solution of the large model data processing method in the above embodiment.
[0267] An embodiment of the present application also provides a computer-readable storage medium, which stores computer execution instructions. When the computer execution instructions are run on a computer, the computer executes the technical solution of the large model data processing method of the above embodiment.
[0268] An embodiment of the present application also provides a computer program product, which includes a computer program stored in a computer-readable storage medium. At least one processor can read the computer program from the computer-readable storage medium. When at least one processor executes the computer program, it can implement the technical solution of the large model data processing method in the above embodiment.
[0269] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, and the true scope and spirit of the present application are indicated by the following claims.
[0270] It should be understood that the present application is not limited to the exact structure described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.
[0271] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, and the true scope and spirit of the present application are indicated by the following claims.
[0272] It should be understood that the present application is not limited to the exact structure described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.
Claims
1. A large model data processing method, characterized in that: The large model includes a first part and a second part; the first part is deployed on the client and is used to process user data; The second part is deployed in the cloud and is used to process the model data; The method is applied to the first portion or the second portion; The method comprises: Obtaining a first encryption vector corresponding to local data and receiving a second encryption vector corresponding to remote data; wherein, when the local data is user data, the remote data is model data; and when the local data is model data, the remote data is user data; The first encrypted vector and the second encrypted vector are obtained by orthogonally encrypting the first vector and the second vector, respectively; the first vector is an eigenvector corresponding to the local data, and the second vector is an eigenvector corresponding to the remote data; encryption matrices used in the orthogonal encryption of the first and second vectors are obtained by encrypting the same base matrix with different noise matrices; An operation is performed on the first encryption vector and the second encryption vector to obtain a calculation result corresponding to the user data.
2. The method according to claim 1, characterized in that Obtaining a first encryption vector corresponding to the local data includes: Acquire the local data, and perform vector conversion processing on the local data to obtain a first vector; Obtaining a first encryption matrix; wherein the first encryption matrix is generated based on a preset basis matrix and a first noise matrix; The first vector is encrypted based on the first encryption matrix to obtain a first encrypted vector.
3. The method according to claim 2, characterized in that Generating the first encryption matrix based on a preset basis matrix and a first noise matrix includes: Based on the first noise matrix, encrypting the basis matrix to obtain a first initial encrypted matrix; Performing orthogonal transformation on the first initial encryption matrix to obtain a first encryption matrix.
4. The method according to claim 2, characterized in that Encrypting the first vector based on the first encryption matrix to obtain a first encrypted vector includes: Based on the first encryption matrix, performing an orthogonal transformation on the first vector to obtain a first initial encryption vector; The first initial encrypted vector is encrypted based on a first noise vector corresponding to the local data to obtain a first encrypted vector.
5. The method according to claim 1, characterized in that Receiving a second encryption vector corresponding to the remote data includes: receiving a second encryption vector corresponding to remote data transmitted by another portion of the large model; wherein the second encryption vector is generated by encrypting the remote data by another portion of the large model; The encryption process of the remote data includes: Acquire the remote data, and perform vector conversion processing on the remote data to obtain a second vector; Obtaining a second encryption matrix; wherein the second encryption matrix is generated based on a preset base matrix and a second noise matrix; The second vector is encrypted based on the second encryption matrix to obtain a second encrypted vector.
6. The method according to claim 5, characterized in that Generating the second encryption matrix based on a preset base matrix and a second noise matrix includes: Performing encryption processing on the base matrix based on the second noise matrix to obtain a second initial encrypted matrix; Performing orthogonal transformation on the second initial encryption matrix to obtain a second encryption matrix.
7. The method according to claim 5, characterized in that Encrypting the second vector based on the second encryption matrix to obtain a second encrypted vector includes: performing an orthogonal transformation on the second vector based on the second encryption matrix to obtain a second initial encryption vector; The second initial encryption vector is encrypted based on a second noise vector corresponding to the remote data to obtain a second encryption vector.
8. The method according to any one of claims 3 to 7, characterized in that The first noise matrix and the second noise matrix are random noise matrices; the first noise vector and the second noise vector are random noise vectors.
9. The method according to claim 8, characterized in that The matrix values of the first noise matrix and the second noise matrix are greater than a first matrix threshold and less than a second matrix threshold; the first matrix threshold and the second matrix threshold are determined based on the computational complexity and model safety performance of the large model; The vector values of the first noise vector and the second noise vector are greater than a first vector threshold and less than a second vector threshold; the first vector threshold and the second vector threshold are determined based on the computational complexity and model safety performance of the large model.
10. The method according to any one of claims 1 to 7, characterized in that The base matrix is generated by the first part and the second part by sharing a random seed or synchronizing information.
11. The method according to claim 10, characterized in that The method further comprises: The base matrix or the random seed is regenerated at every preset time interval.
12. The method according to claim 8, characterized in that The method further comprises: The first noise matrix or the second noise matrix is regenerated at every preset time interval.
13. The method according to claim 1, wherein The operation includes a vector inner product operation; Performing an operation on the first encryption vector and the second encryption vector to obtain a calculation result corresponding to the user data includes: Obtaining a vector inner product operation expression corresponding to the vector inner product operation; Based on the vector inner product operation expression, a vector inner product calculation is performed on the first encrypted vector and the second encrypted vector to obtain a calculation result corresponding to the user data.
14. The method according to any one of claims 1 to 7 and 13, characterized in that The method further comprises: Perform encryption processing or vector inner product operations through parallel processing.
15. The method according to claim 1, wherein After obtaining the calculation result corresponding to the user data, the method further includes: In the first part of the large model, text conversion processing is performed on the calculation result to obtain output data corresponding to the user data.
16. A large model data processing device, characterized in that: The large model includes a first part and a second part; the first part is deployed on the client and is used to process user data; The second part is deployed in the cloud and is used to process the model data; The device is applied to the first part or the second part; The device comprises: an encryption vector acquisition module, configured to acquire a first encryption vector corresponding to local data and receive a second encryption vector corresponding to remote data; wherein, when the local data is user data, the remote data is model data; and when the local data is model data, the remote data is user data; The first encrypted vector and the second encrypted vector are obtained by orthogonally encrypting the first vector and the second vector, respectively; the first vector is an eigenvector corresponding to the local data, and the second vector is an eigenvector corresponding to the remote data; encryption matrices used in the orthogonal encryption of the first and second vectors are obtained by encrypting the same base matrix with different noise matrices; The encryption vector calculation module is configured to perform an operation on the first encryption vector and the second encryption vector to obtain a calculation result corresponding to the user data.
17. An electronic device, characterized in that: include: a processor and a memory communicatively connected to the processor; The memory stores computer-executable instructions; When executing the computer-executable instructions, the processor is used to implement the large model data processing method according to any one of claims 1 to 15.
18. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the large model data processing method according to any one of claims 1 to 15.
19. A computer program product, characterized in that The method comprises a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 15.