Electric vehicle privacy protection method and device

By adopting the energy consumption prediction model based on federated learning of neural network model and Gaussian noise training in electric vehicles, the problem of privacy data leakage of electric vehicle users is solved, and the coordinated development of vehicle and network with low communication burden and high privacy protection is achieved.

CN120744973APending Publication Date: 2025-10-03ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510871050.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-26
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

With existing technologies, user privacy data is easily leaked during the interaction between electric vehicles and power grids, and existing privacy protection methods require the participation of a trusted third party or increase the client's computing and communication burden, making it difficult to achieve vehicle-grid collaborative development with low communication burden and high privacy protection.

Method used

An energy consumption prediction model based on a neural network model is adopted, combined with a federated learning framework and Gaussian noise. The model parameters are trained through federated learning between the server and the client to reduce the communication burden and improve privacy protection capabilities.

Benefits of technology

It reduces the communication burden between the client and the server while protecting user privacy, improves the privacy protection capabilities of the federated learning framework, and supports the safe interaction between electric vehicles and the power grid.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120744973A_ABST
    Figure CN120744973A_ABST
Patent Text Reader

Abstract

The invention relates to an electric vehicle privacy protection method and device. The method comprises the following steps: acquiring current charging data of a target vehicle in a current use process; based on a pre-trained energy consumption prediction model, according to the current charging data of the target vehicle, predicting an energy consumption result of the target vehicle; wherein the energy consumption prediction model is obtained by training model parameters of the energy consumption prediction model based on a federated learning framework and Gaussian noise between the server and the client on the basis of a neural network model; in the training process of the energy consumption prediction model, model parameters of the energy consumption prediction model are transmitted between the server and the client; model parameters of the energy consumption prediction model are privacy data needing to be protected in the target vehicle. By adopting the method, the privacy protection capability of the federal learning framework can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of electric vehicles, and in particular to a privacy protection method and device for electric vehicles. Background Art

[0002] When electric vehicles (EVs) connect to the grid through charging stations and participate in vehicle-grid interactions, the complexity of multi-level data exchange within the vehicle-charging station-grid system exposes sensitive information such as user identity, charging location, and power profile to multiple leak risks. Charging times can be correlated with user sleep patterns (e.g., frequent nighttime charging reveals residential locations), charging station location data can map delivery routes for logistics vehicles, and real-time State-of-Charge (SOC) information can be used to reverse engineer commercial secrets such as battery health status. To enable EVs to more safely assist in grid dispatch, they must exchange location information and real-time battery SOC with the grid's operation monitoring and control center. This data, during transmission, can reveal users' travel habits and lifestyle preferences, posing the risk of malicious exploitation. Empirical evidence from the California Energy Commission shows that even with anonymized charging data, attackers can still identify users with 89% accuracy through spatiotemporal feature matching. These privacy risks significantly discourage users from participating in vehicle-grid interaction services. Therefore, how to fully unleash the flexible scheduling potential of EVs while protecting user privacy has become a core challenge in promoting the coordinated development of vehicle-grid services.

[0003] So far, approaches to protecting electric vehicle user privacy can be divided into two main categories. One approach focuses on perturbing or aggregating energy consumption data to obscure the traces of individual devices. The second approach protects privacy by anonymizing user identities, typically using cryptographic techniques such as blind signatures to conceal real identity information.

[0004] Both of the above methods require the participation of a trusted third party, which is vulnerable to malicious attacks and may lead to the leakage of private data. The general localized differential privacy method that does not require the participation of a third party inevitably increases the client's computational overhead and communication burden, and puts higher requirements on the real-time performance and resource consumption of the power grid operation and dispatching system. Therefore, there is an urgent need for a technical solution with low communication burden and high privacy protection. Summary of the Invention

[0005] Based on this, it is necessary to provide an electric vehicle privacy protection method and device with low communication burden and high privacy protection to address the above technical problems.

[0006] In a first aspect, the present application provides a privacy protection method for electric vehicles, which is applied to a client of any target vehicle connected to a server, and the method includes:

[0007] Obtain the current charging data of the target vehicle during its current use;

[0008] Based on the pre-trained energy consumption prediction model, the energy consumption result of the target vehicle is predicted according to the current charging data of the target vehicle;

[0009] Among them, the energy consumption prediction model is based on a neural network model. The model parameters of the energy consumption prediction model are trained based on the federated learning framework and Gaussian noise between the server and the client. During the training process of the energy consumption prediction model, the model parameters of the energy consumption prediction model are transmitted between the server and the client. The model parameters of the energy consumption prediction model are privacy data that need to be protected in the target vehicle.

[0010] In one embodiment, training model parameters of an energy consumption prediction model based on a federated learning framework and Gaussian noise between a server and a client includes:

[0011] Obtain the historical charging data of the target vehicle during its historical use, as well as the actual consumption results corresponding to the historical charging data;

[0012] For each iteration, in response to a first parameter sent by the server, if the first parameter is not a target parameter, updating the pre-trained energy consumption prediction model according to the first parameter; the first parameter is a model parameter used to update the energy consumption prediction model;

[0013] Based on the updated energy consumption prediction model and historical charging data, the predicted consumption result of the target vehicle is determined;

[0014] Determining a second parameter of the energy consumption prediction model based on the predicted consumption result, the actual consumption result corresponding to the historical charging data, and Gaussian noise; the Gaussian noise is used to perturb the model parameters of the energy consumption prediction model after the parameter adjustment; the second parameter is the model parameter after the perturbation processing of the model parameters of the energy consumption prediction model;

[0015] The second parameter is sent to the server so that the server can update the first parameter based on the second parameter based on federated learning, and the updated first parameter is fed back to the client until the current iteration process meets the preset iteration stop condition, and the updated first parameter in the last iteration process is sent to the client as the target parameter.

[0016] In one embodiment, determining a second parameter of the energy consumption prediction model based on the predicted consumption result, the actual consumption result corresponding to the historical charging data, and Gaussian noise includes:

[0017] Adjusting the model parameters of the energy consumption prediction model according to the predicted consumption results and the actual consumption results, and using the adjusted model parameters as the third parameter;

[0018] The third parameter is trimmed according to a preset parameter trimming threshold to obtain a fourth parameter;

[0019] Gaussian noise is injected into the fourth parameter to obtain the second parameter of the energy consumption prediction model.

[0020] In one embodiment, determining a fourth parameter of the energy consumption prediction model based on a preset parameter clipping threshold and the third parameter includes:

[0021] determining the Euclidean norm of the third parameter according to the third parameter;

[0022] When the Euclidean norm is greater than a preset parameter clipping threshold, clipping the third parameter according to the preset parameter clipping threshold to obtain a fourth parameter;

[0023] When the Euclidean norm is not greater than the preset parameter clipping threshold, the third parameter is no longer clipped and is directly used as the fourth parameter.

[0024] In one embodiment, the third parameter is trimmed according to a preset parameter trimming threshold to obtain the fourth parameter, including:

[0025] Determining a clipping value of the third parameter based on a preset parameter clipping threshold and a preset sensitivity; the sensitivity is used to represent the degree of clipping of the third parameter based on the preset parameter clipping threshold;

[0026] The product of the clipping value and the third parameter is used as the fourth parameter.

[0027] In one embodiment, injecting Gaussian noise into the fourth parameter to obtain the second parameter of the energy consumption prediction model includes:

[0028] The difference between the fourth parameter and the preset global parameter is used as the client's difference parameter;

[0029] The sum of the difference parameter and Gaussian noise is used as the second parameter of the energy consumption prediction model.

[0030] In a second aspect, the present application also provides an electric vehicle privacy protection device, comprising:

[0031] An acquisition module is used to obtain the current charging data of the target vehicle during its current use;

[0032] A prediction module, configured to predict the energy consumption result of a target vehicle based on the current charging data of the target vehicle based on a pre-trained energy consumption prediction model;

[0033] Among them, the energy consumption prediction model is based on a neural network model. The model parameters of the energy consumption prediction model are trained based on the federated learning framework and Gaussian noise between the server and the client. During the training process of the energy consumption prediction model, the model parameters of the energy consumption prediction model are transmitted between the server and the client. The model parameters of the energy consumption prediction model are privacy data that need to be protected in the target vehicle.

[0034] In a third aspect, the present application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0035] Obtain the current charging data of the target vehicle during its current use;

[0036] Based on the pre-trained energy consumption prediction model, the energy consumption result of the target vehicle is predicted according to the current charging data of the target vehicle;

[0037] Among them, the energy consumption prediction model is based on a neural network model. The model parameters of the energy consumption prediction model are trained based on the federated learning framework and Gaussian noise between the server and the client. During the training process of the energy consumption prediction model, the model parameters of the energy consumption prediction model are transmitted between the server and the client. The model parameters of the energy consumption prediction model are privacy data that need to be protected in the target vehicle.

[0038] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the following steps are implemented:

[0039] Obtain the current charging data of the target vehicle during its current use;

[0040] Based on the pre-trained energy consumption prediction model, the energy consumption result of the target vehicle is predicted according to the current charging data of the target vehicle;

[0041] Among them, the energy consumption prediction model is based on a neural network model. The model parameters of the energy consumption prediction model are trained based on the federated learning framework and Gaussian noise between the server and the client. During the training process of the energy consumption prediction model, the model parameters of the energy consumption prediction model are transmitted between the server and the client. The model parameters of the energy consumption prediction model are privacy data that need to be protected in the target vehicle.

[0042] In a fifth aspect, the present application further provides a computer program product, comprising a computer program, which, when executed by a processor, implements the following steps:

[0043] Obtain the current charging data of the target vehicle during its current use;

[0044] Based on the pre-trained energy consumption prediction model, the energy consumption result of the target vehicle is predicted according to the current charging data of the target vehicle;

[0045] Among them, the energy consumption prediction model is based on a neural network model. The model parameters of the energy consumption prediction model are trained based on the federated learning framework and Gaussian noise between the server and the client. During the training process of the energy consumption prediction model, the model parameters of the energy consumption prediction model are transmitted between the server and the client. The model parameters of the energy consumption prediction model are privacy data that need to be protected in the target vehicle.

[0046] The above-mentioned electric vehicle privacy protection method and device obtain the current charging data of the target vehicle during its current use; based on a pre-trained energy consumption prediction model, the target vehicle's energy consumption results are predicted according to the target vehicle's current charging data; wherein, the energy consumption prediction model is based on a neural network model, and the model parameters of the energy consumption prediction model are trained based on a federated learning framework and Gaussian noise between the server and the client; during the training of the energy consumption prediction model, the model parameters of the energy consumption prediction model are transmitted between the server and the client; the model parameters of the energy consumption prediction model are the privacy data that needs to be protected in the target vehicle. This embodiment utilizes a federated learning framework to overcome the problem of high communication burden of client localization, reduces the communication burden between the client and the server, and at the same time, trains the model parameters based on Gaussian noise, further enhancing the privacy protection capability of the federated learning framework. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0048] Figure 1 A diagram illustrating an application environment of a privacy protection method for electric vehicles provided in this embodiment;

[0049] Figure 2 A flowchart of a privacy protection method for electric vehicles provided in this embodiment;

[0050] Figure 3 A schematic diagram of a flow chart of the model training steps provided in this embodiment;

[0051] Figure 4A A schematic diagram of a flow chart of a step of determining a second parameter provided in this embodiment;

[0052] Figure 4B A schematic diagram of the structure of a federated learning solution provided in this embodiment;

[0053] Figure 5A A schematic diagram of model accuracy under different frameworks provided in this embodiment;

[0054] Figure 5B A schematic diagram of the impact of parameter clipping thresholds provided in this embodiment;

[0055] Figure 5C A performance evaluation diagram provided for this embodiment;

[0056] Figure 6 This is a structural block diagram of a privacy protection device for an electric vehicle provided in this embodiment;

[0057] Figure 7 This is a diagram of the internal structure of a computer device provided in this embodiment. DETAILED DESCRIPTION

[0058] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0059] The electric vehicle privacy protection method provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown, a server 101 communicates with clients 102 of at least two target vehicles; the clients 102 obtain current charging data of the target vehicles during their current use; based on a pre-trained energy consumption prediction model, the target vehicles' energy consumption is predicted according to their current charging data; the energy consumption prediction model is based on a neural network model, and its model parameters are trained using a federated learning framework and Gaussian noise between the server 101 and the client 102; during the training of the energy consumption prediction model, the model parameters of the energy consumption prediction model are transmitted between the server and the client; the model parameters of the energy consumption prediction model are privacy data in the target vehicles that need to be protected.

[0060] In an exemplary embodiment, Figure 2 As shown, a privacy protection method for electric vehicles is provided, which is applied to Figure 1 The client in the example is used to illustrate the process, including the following steps S201 to S202.

[0061] S201 obtains the current charging data of the target vehicle during its current use.

[0062] The current charging data may be understood as the charging data of the target vehicle during its current use, such as power data, current and voltage of the electric vehicle, for example.

[0063] In some embodiments, the client obtains current charging data of the target vehicle to which the client belongs during current use.

[0064] S202 predicts the energy consumption result of the target vehicle based on the pre-trained energy consumption prediction model and the current charging data of the target vehicle.

[0065] Among them, the energy consumption prediction model is based on a neural network model. The model parameters of the energy consumption prediction model are trained based on the federated learning framework and Gaussian noise between the server and the client. During the training process of the energy consumption prediction model, the model parameters of the energy consumption prediction model are transmitted between the server and the client. The model parameters of the energy consumption prediction model are privacy data that need to be protected in the target vehicle.

[0066] In some embodiments, the current charging data of the target vehicle is input into a pre-trained energy consumption prediction model, and the pre-trained energy consumption prediction model analyzes the current charging data to predict the energy consumption result of the target vehicle.

[0067] The above-mentioned electric vehicle privacy protection method and device obtain the current charging data of the target vehicle during its current use; based on a pre-trained energy consumption prediction model, the target vehicle's energy consumption results are predicted according to the target vehicle's current charging data; wherein, the energy consumption prediction model is based on a neural network model, and the model parameters of the energy consumption prediction model are trained based on a federated learning framework and Gaussian noise between the server and the client; during the training of the energy consumption prediction model, the model parameters of the energy consumption prediction model are transmitted between the server and the client; the model parameters of the energy consumption prediction model are the privacy data that needs to be protected in the target vehicle. This embodiment utilizes a federated learning framework to overcome the problem of high communication burden of client localization, reduces the communication burden between the client and the server, and at the same time, trains the model parameters based on Gaussian noise, further enhancing the privacy protection capability of the federated learning framework.

[0068] Figure 3 Schematic diagram of a flow chart of the model training steps in one embodiment. This embodiment provides an optional method of model training, including the following steps:

[0069] S301 obtains historical charging data of the target vehicle during its historical use, as well as actual consumption results corresponding to the historical charging data.

[0070] In some embodiments, the client obtains historical charging data of the target vehicle during its historical use; the client obtains actual consumption results corresponding to the historical charging data.

[0071] S302 , for each iteration process, responds to the first parameter sent by the server and, if the first parameter is not the target parameter, updates the pre-trained energy consumption prediction model according to the first parameter.

[0072] The first parameter is a model parameter used to update the energy consumption prediction model.

[0073] In some embodiments, for each iteration process, the client responds to the first parameter sent by the server and determines whether the first parameter carries a target parameter tag; if it carries the target parameter tag, the first parameter is determined to be the target parameter and the model training is completed; if it does not carry the target parameter tag, the first parameter is determined not to be the target parameter and the pre-trained energy consumption prediction model is updated according to the first parameter.

[0074] S303 determines the predicted consumption result of the target vehicle based on the updated energy consumption prediction model and historical charging data.

[0075] In some embodiments, the historical charging data is input into an updated energy consumption prediction model, and the updated energy consumption prediction model analyzes the historical charging data to obtain a predicted consumption result of the target vehicle.

[0076] S304 determines a second parameter of the energy consumption prediction model according to the predicted consumption result, the actual consumption result corresponding to the historical charging data, and Gaussian noise.

[0077] The Gaussian noise is used to perform perturbation processing on the model parameters of the energy consumption prediction model after parameter adjustment; and the second parameter is the model parameter after the perturbation processing is performed on the model parameters of the energy consumption prediction model.

[0078] In some embodiments, the model parameters of the energy consumption prediction model are adjusted according to the predicted consumption results and the actual consumption results corresponding to the historical charging data to obtain the adjusted model parameters; Gaussian noise is injected into the adjusted model parameters to determine the second parameters of the energy consumption prediction model.

[0079] S305 sends the second parameter to the server, so that the server can update the first parameter based on federated learning according to the second parameter, and feed back the updated first parameter to the client until the current iteration process meets the preset iteration stop condition, and send the updated first parameter in the last iteration process as the target parameter to the client.

[0080] In some embodiments, the client sends the second parameter to the server; the server updates the first parameter based on the second parameter based on federated learning, and feeds back the updated first parameter to the client until the current iteration process meets the preset iteration stop condition, and sends the updated first parameter in the last iteration process as the target parameter to the client.

[0081] It should be noted that the operation process of federated learning includes four core stages: model initialization, local model training, model parameter upload, and global model aggregation. The principle of the local model training stage is shown in the following formula (1); in the model aggregation stage, the server uses the FedAvg algorithm to aggregate client parameters and update the global model, as shown in the following (2);

[0082] (1)

[0083] Where L(∙) is the loss function, k represents the kth client, and D k is the local dataset of the kth client, x i ,y i are the input and output of the dataset respectively.

[0084] (2)

[0085] in, For the total data volume, the weighted average mechanism ensures that clients with large data volumes have a greater impact on the global model.

[0086] It should be noted that after the client completes n rounds of local training, it does not directly upload the model parameter difference. Instead, an adaptive noise injection strategy should be used to Perform noise processing and then use the noise-added model parameters And the evaluation results are sent back to the server.

[0087] It should be noted that the model hyperparameter settings in this embodiment are as follows: the total number of federated training rounds T is 50, the number of local training rounds n is 10, the global learning rate is 0.8, the local learning rate r is 0.01, the batch size is 32, and the number of hidden layers is 48.

[0088] On the one hand, this embodiment utilizes the distributed computing of the federated learning algorithm to overcome the high communication burden of the general localized differential privacy method. On the other hand, it utilizes the differential privacy method to further enhance the privacy protection capability of the federated learning algorithm.

[0089] Figure 4A Schematic diagram of a flow chart of the step of determining the second parameter in one embodiment. This embodiment provides an optional method for determining the second parameter, including the following steps:

[0090] S401 adjusts the model parameters of the energy consumption prediction model according to the predicted consumption result and the actual consumption result, and uses the adjusted model parameters as the third parameters.

[0091] In some embodiments, a loss value of the energy consumption prediction model is determined based on the predicted consumption result and the actual consumption result; based on the loss value, the model parameters of the energy consumption prediction model are adjusted using the following formula (3); and the adjusted model parameters are used as the third parameter.

[0092] (3)

[0093] Among them, D k is the local database of the kth client, F k is the local model loss function of the k-th client.

[0094] S402 performs trimming processing on the third parameter according to a preset parameter trimming threshold to obtain a fourth parameter.

[0095] In some embodiments, the Euclidean norm of the third parameter is determined based on the third parameter; when the Euclidean norm is greater than a preset parameter clipping threshold, the third parameter is clipped according to the preset parameter clipping threshold to obtain a fourth parameter; when the Euclidean norm is not greater than the preset parameter clipping threshold, the third parameter is no longer clipped and is directly used as the fourth parameter.

[0096] Exemplarily, based on the Euclidean norm to determine the model, the Euclidean norm of the third parameter is determined according to the third parameter; when the Euclidean norm is greater than the preset parameter clipping threshold, the third parameter is clipped according to the preset parameter clipping threshold to obtain the fourth parameter; when the Euclidean norm is not greater than the preset parameter clipping threshold, the third parameter is no longer clipped and the third parameter is directly used as the fourth parameter.

[0097] In some embodiments, the third parameter is clipped according to a preset parameter clipping threshold to obtain a fourth parameter, including: determining a clipping value of the third parameter according to the preset parameter clipping threshold and a preset sensitivity; the sensitivity is used to characterize the clipping degree of the third parameter based on the preset parameter clipping threshold; taking the product value between the clipping value and the third parameter as the fourth parameter.

[0098] Exemplarily, before injecting noise into the model parameters, the client also needs to perform a clipping process on the model parameters. The purpose is to limit the maximum influence of a single client on the global model and improve the training stability. Therefore, before noise injection, L2 norm clipping needs to be performed on the model parameter update, as shown in the following formula (4):

[0099] (4)

[0100] Where, represents the clipped model parameters, represents the model parameters before clipping, represents the scaling factor.

[0101] It should be noted that, the sensitivity of can be expressed as: . Where, is the adjacent dataset of D k They have the same size but differ by only one sample; C is the threshold for parameter clipping.

[0102] It should be noted that in this embodiment, the global sensitivity of the model parameter uplink is defined as: . In order to achieve a smaller global sensitivity and ensure that the noise of all clients meets the worst-case privacy protection, that is, the client with the smallest amount of data has the maximum sensitivity, the smallest local dataset size among the K clients participating in each training is defined as m, then there is , due to the randomness of client selection, it can be known that varies dynamically with the client data volume. This mechanism ensures that all client updates meet strict privacy requirements while avoiding excessive noise addition, thereby preventing the client with the smallest amount of data from becoming a vulnerability for privacy leakage; assuming that each client participating in a federated training has a risk of privacy exposure, and each client participates in at most L times of training (L < T), then the maximum number of privacy exposure times is L. Compared with the centralized calculation and the federated learning framework without differential privacy, the setting of L limits the number of times each client participates in federated training, thus directly avoiding the privacy exposure risk brought by multiple data interactions.

[0103] S403 injects Gaussian noise into the fourth parameter to obtain the second parameter of the energy consumption prediction model.

[0104] In some embodiments, the difference between the fourth parameter and the preset global parameter is used as the difference parameter of the client; and the sum of the difference parameter and Gaussian noise is used as the second parameter of the energy consumption prediction model.

[0105] For example, Figure 4B The schematic diagram of the federated learning scheme structure shown in FIG. 1 determines the second parameter of the energy consumption prediction model through the following formula (5).

[0106] (5)

[0107] in, The local model parameters after adding noise to the k-th client.

[0108] For example, the Gaussian noise injected in this embodiment can be expressed as follows:

[0109] (6)

[0110] in, is the standard deviation of Gaussian noise. That is, the noise injected by the client .

[0111] In this embodiment, differential privacy is used to enhance data privacy. Compared with homomorphic encryption privacy protection schemes, differential privacy does not require a complex key management mechanism, and significantly reduces communication and computing overhead while ensuring strong privacy.

[0112] In one embodiment of the present invention, the raw data used is the actual charging data of electric vehicles. After screening and classification, the raw data is divided into 15 regions according to the geographical location of the charging stations. Each region is regarded as an independent client computing node. There are 500-800 user data in total. The size of each data set is measured by the amount of data. The privacy protection level of the present invention is considered from the perspective of algorithm architecture and privacy budget. The paper discusses the size of the network, and compares the three modes of centralized training, federated learning (FL), and differential privacy improved federated learning (DPFL) horizontally, and vertically compares different privacy protection levels. The impact on the DPFL model reveals the quantitative trade-off between privacy protection strength and model performance. Since the centralized training method does not have privacy protection, in order to eliminate the interference caused by different data structures and model parameters, the data set is input in the centralized training method, and the data sets of 15 clients are merged into a single data set format for processing during training. At the same time, the number of training rounds is set to 50, and the learning rate is the same as the local learning rate of distributed training, which is 0.01. For the DPFL algorithm, the parameter clipping threshold C is set to 1, and the privacy budget is set to 0. =2, the noise added to the client is the largest, and the model privacy protection capability is the strongest. The loss value functions and model accuracy under the three training frameworks are shown in the attached figure. Figure 5A As shown in the figure, it can be seen that the three algorithms all converged and the accuracy gradually increased and finally stabilized. Finally, after concentrated training, the accuracy of FL and DPFL were 96.79%, 96.51% and 92.81% respectively.

[0113] It can be seen that the model accuracy under centralized training and FL methods is close, but the model convergence effect of centralized training is significantly better than that of the FL framework; while the DPFL algorithm with differential privacy protection has decreased in both model convergence and accuracy, but considering its strong protection of data privacy and security and the final accuracy of more than 90%, this sacrifice in model performance is considered to be within an acceptable range. Three representative privacy budget values ​​were selected ( =2, 4, 6), while fixing the gradient parameter clipping threshold C = 1, and verifying the impact of privacy budget on DPFL performance separately, as shown in the attached figure. Figure 5B As shown in the figure, it can be seen that as the privacy budget increases, the model accuracy shows an upward trend. = 6, the convergence speed is the fastest and the model accuracy is the highest. This phenomenon is in line with the basic law of the differential privacy mechanism, that is, there is a certain trade-off between the strength of privacy protection and the loss of model performance. That is, relaxing the privacy level restriction of the model will lead to improved accuracy, but at the same time, a larger value also means a higher risk of privacy exposure.

[0114] For example, the parameter clipping threshold C can prevent unstable oscillations in the training process by limiting the maximum range of model parameter updates, and can also affect the global sensitivity. This affects the amount of noise injected into the model parameters. Three representative parameter trimming thresholds (C=1, 2, 4) are selected, while the privacy protection budget is fixed. =6, that is, excluding the additional noise interference caused by the privacy budget, the performance evaluation of the DPFL model is performed by performing gradient parameter clipping threshold. The results are shown in the attached figure. Figure 5CAs shown in the figure. When C is large (C=4), the range of client model parameter updates is loosely restricted. The data distribution of certain clients has an excessive impact on the global model, making the model easily dominated by a small number of clients, increasing training curve fluctuations and reducing stability. Therefore, it can be seen that the parameter clipping threshold is positively correlated with the scale of injected noise. To meet the requirements of differential privacy, a larger parameter clipping threshold will result in larger noise injections, thus affecting model accuracy. When C is small (C=1), each client's parameter update is strictly restricted, and extreme updates are suppressed. In this case, training is more stable. However, overly strict clipping discards some gradient information, resulting in smaller updates in each round and relatively slow convergence. According to the Gaussian mechanism, under the same privacy budget, the smaller C, the lower the injected noise and the higher the model utility. This conclusion is also consistent with the general principle of differential privacy algorithms.

[0115] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0116] Based on the same inventive concept, the present application also provides an electric vehicle privacy protection device for implementing the electric vehicle privacy protection method described above. The solution provided by this device is similar to the solution described in the above method. Therefore, the specific limitations of one or more electric vehicle privacy protection device embodiments provided below can be found in the above-mentioned limitations of the electric vehicle privacy protection method and will not be repeated here.

[0117] In an exemplary embodiment, Figure 6 As shown, a privacy protection device for an electric vehicle is provided, comprising: an acquisition module 10 and a prediction module 11, wherein:

[0118] An acquisition module 10 is used to obtain current charging data of the target vehicle during its current use;

[0119] The prediction module 11 is used to predict the energy consumption result of the target vehicle based on the current charging data of the target vehicle based on the pre-trained energy consumption prediction model;

[0120] Among them, the energy consumption prediction model is based on a neural network model. The model parameters of the energy consumption prediction model are trained based on the federated learning framework and Gaussian noise between the server and the client. During the training process of the energy consumption prediction model, the model parameters of the energy consumption prediction model are transmitted between the server and the client. The model parameters of the energy consumption prediction model are privacy data that need to be protected in the target vehicle.

[0121] In some embodiments, the electric vehicle privacy protection device further includes: a model training module for obtaining historical charging data of the target vehicle during historical use, and actual consumption results corresponding to the historical charging data; for each iteration process, in response to the first parameter sent by the server, if the first parameter is not the target parameter, updating the pre-trained energy consumption prediction model according to the first parameter; the first parameter is a model parameter for updating the energy consumption prediction model; based on the updated energy consumption prediction model, the predicted consumption result of the target vehicle is determined according to the historical charging data; the second parameter of the energy consumption prediction model is determined according to the predicted consumption result, the actual consumption result corresponding to the historical charging data and Gaussian noise; Gaussian noise is used to perturb the model parameters of the energy consumption prediction model after parameter adjustment; the second parameter is the model parameter after perturbation of the model parameters of the energy consumption prediction model; the second parameter is sent to the server for the server to update the first parameter based on federated learning according to the second parameter, and the updated first parameter is fed back to the client until the current iteration process meets the preset iteration stop condition, and the updated first parameter in the last iteration process is sent to the client as the target parameter.

[0122] In some embodiments, the model training module is also used to adjust the model parameters of the energy consumption prediction model based on the predicted consumption results and the actual consumption results, and use the adjusted model parameters as the third parameter; trim the third parameter according to the preset parameter trimming threshold to obtain the fourth parameter; inject Gaussian noise into the fourth parameter to obtain the second parameter of the energy consumption prediction model.

[0123] In some embodiments, the model training module is further used to determine the Euclidean norm of the third parameter based on the third parameter; when the Euclidean norm is greater than a preset parameter clipping threshold, the third parameter is clipped according to the preset parameter clipping threshold to obtain a fourth parameter; when the Euclidean norm is not greater than the preset parameter clipping threshold, the third parameter is no longer clipped and the third parameter is directly used as the fourth parameter.

[0124] In some embodiments, the model training module is also used to determine the trimming value of the third parameter based on a preset parameter trimming threshold and a preset sensitivity; the sensitivity is used to characterize the degree of trimming of the third parameter based on the preset parameter trimming threshold; and the product value between the trimming value and the third parameter is used as the fourth parameter.

[0125] In some embodiments, the model training module is further used to use the difference between the fourth parameter and the preset global parameter as the difference parameter of the client; and use the sum of the difference parameter and Gaussian noise as the second parameter of the energy consumption prediction model.

[0126] Each module in the above-mentioned electric vehicle privacy protection device can be implemented in whole or in part through software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in a computer device in hardware form, or can be stored in a memory in the computer device in software form, so that the processor can call and execute the corresponding operations of each module.

[0127] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Figure 7 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O) and a communication interface. The processor, memory and input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store data. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a method for protecting privacy of an electric vehicle is implemented.

[0128] Those skilled in the art will understand that Figure 7 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0129] In one embodiment, a computer device is further provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above method embodiments when executing the computer program.

[0130] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0131] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.

[0132] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.

[0133] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned embodiments. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), data processing logic devices based on quantum computing, and the like.

[0134] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0135] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A privacy protection method for electric vehicles, characterized in that: Applied to a client of any target vehicle connected to a server, the method includes: Obtain the current charging data of the target vehicle during its current use; Based on a pre-trained energy consumption prediction model, the energy consumption result of the target vehicle is predicted according to the current charging data of the target vehicle; Among them, the energy consumption prediction model is based on a neural network model, and the model parameters of the energy consumption prediction model are trained based on a federated learning framework and Gaussian noise between the server and the client; during the training process of the energy consumption prediction model, the model parameters of the energy consumption prediction model are transmitted between the server and the client; the model parameters of the energy consumption prediction model are privacy data that need to be protected in the target vehicle.

2. The method according to claim 1, characterized in that The training of model parameters of the energy consumption prediction model based on the federated learning framework and Gaussian noise between the server and the client includes: Obtaining historical charging data of the target vehicle during its historical use, and actual consumption results corresponding to the historical charging data; For each iteration, in response to a first parameter sent by the server, if the first parameter is not a target parameter, updating a pre-trained energy consumption prediction model according to the first parameter; Determining a predicted consumption result of the target vehicle based on the updated energy consumption prediction model and the historical charging data; determining a second parameter of the energy consumption prediction model based on the predicted consumption result, the actual consumption result corresponding to the historical charging data, and the Gaussian noise; The second parameter is sent to the server, so that the server updates the first parameter based on the second parameter based on federated learning, and feeds back the updated first parameter to the client until the current iteration process meets the preset iteration stop condition, and sends the updated first parameter in the last iteration process as the target parameter to the client.

3. The method according to claim 2, characterized in that The determining of the second parameter of the energy consumption prediction model according to the predicted consumption result, the actual consumption result corresponding to the historical charging data, and the Gaussian noise includes: adjusting the model parameters of the energy consumption prediction model according to the predicted consumption result and the actual consumption result, and using the adjusted model parameters as the third parameters; trimming the third parameter according to a preset parameter trimming threshold to obtain a fourth parameter; The Gaussian noise is injected into the fourth parameter to obtain a second parameter of the energy consumption prediction model.

4. The method according to claim 3, characterized in that Determining the fourth parameter of the energy consumption prediction model according to the preset parameter clipping threshold and the third parameter includes: determining the Euclidean norm of the third parameter according to the third parameter; When the Euclidean norm is greater than a preset parameter clipping threshold, clipping the third parameter according to the preset parameter clipping threshold to obtain a fourth parameter; When the Euclidean norm is not greater than the preset parameter clipping threshold, the third parameter is no longer clipped and is directly used as the fourth parameter.

5. The method according to claim 3 or 4, characterized in that The step of trimming the third parameter according to a preset parameter trimming threshold to obtain a fourth parameter includes: determining a clipping value of the third parameter according to a preset parameter clipping threshold and a preset sensitivity; the sensitivity being used to characterize the degree of clipping of the third parameter based on the preset parameter clipping threshold; The product value of the clipping value and the third parameter is used as the fourth parameter.

6. The method according to claim 3, characterized in that The injecting the Gaussian noise into the fourth parameter to obtain the second parameter of the energy consumption prediction model includes: Using the difference between the fourth parameter and the preset global parameter as the difference parameter of the client; The sum of the difference parameter and the Gaussian noise is used as the second parameter of the energy consumption prediction model.

7. The method according to claim 2, characterized in that The first parameter is a model parameter used to update the energy consumption prediction model.

8. The method according to claim 2, characterized in that The Gaussian noise is used to perform disturbance processing on the model parameters of the energy consumption prediction model after parameter adjustment.

9. The method according to claim 2, characterized in that The second parameter is a model parameter obtained by performing disturbance processing on the model parameter of the energy consumption prediction model.

10. An electric vehicle privacy protection device, characterized in that: The device comprises: An acquisition module is used to obtain the current charging data of the target vehicle during its current use; A prediction module, configured to predict the energy consumption result of the target vehicle based on the current charging data of the target vehicle based on a pre-trained energy consumption prediction model; Among them, the energy consumption prediction model is based on a neural network model, and the model parameters of the energy consumption prediction model are trained based on a federated learning framework and Gaussian noise between the server and the client; during the training process of the energy consumption prediction model, the model parameters of the energy consumption prediction model are transmitted between the server and the client; the model parameters of the energy consumption prediction model are privacy data that need to be protected in the target vehicle.