Personalized differential privacy protection method, device and system based on user scoring strategy
The optimal dimension extraction parameters are determined by user scoring strategy and the expectation of minimizing estimated variance, which realizes personalized privacy protection of multidimensional data, solves the balance problem between privacy protection and data analysis accuracy in multidimensional data, and improves user participation and privacy protection effect.
Patent Information
- Application Number
- CN202510832014.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-20
- Publication Date
- 2025-10-17
Smart Images

Figure CN120805173A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of privacy data protection, and more particularly to a personalized differential privacy protection method, device and system based on user scoring strategy. BACKGROUND
[0002] Mean estimation is a commonly used statistical method, widely used in data analysis and inference, especially when understanding the trend of data set. However, when dealing with sensitive data, privacy protection becomes increasingly important. For example, in the fields of medical, financial, social network, etc., a large amount of personal privacy information is involved, so it is crucial to protect these information from being leaked. Traditional mean estimation method directly uses original data for calculation, which may lead to individual information leakage, thus increasing the privacy risk. Therefore, when performing mean estimation, it is essential to adopt appropriate privacy protection technology, which can ensure user privacy security without affecting the overall data analysis results. In summary, privacy protection is an important consideration in mean estimation, especially in sensitive information fields. Through effective privacy protection methods, not only the effectiveness of data analysis can be guaranteed, but also the security and legality of data can be ensured.
[0003] Currently, the research on privacy protection mean estimation mostly focuses on single-dimensional data, and the privacy protection is relatively simple. However, real-world data is usually multi-dimensional. With the increase of data dimensions, privacy protection becomes more complex, because multi-dimensional data contains multiple features, each of which may involve different types of sensitive information. In this case, how to balance privacy protection and data analysis accuracy becomes a big challenge. Too much noise may lead to a decrease in data analysis accuracy, while too little noise cannot effectively protect privacy. Local differential privacy technology provides an effective means to solve this problem. It adds noise to data at the source of each user's data to ensure that privacy leakage is effectively controlled. This technology is particularly important in some applications that require data collection from a large number of users, because it can prevent privacy leakage at the data collection stage. Therefore, when dealing with multi-dimensional data, using local differential privacy technology can not only ensure the privacy security of data, but also effectively solve the privacy protection problem without significantly affecting the analysis accuracy.
[0004] Compared with - Local Differential Privacy (LDP) mechanism, The scheme under the local differential privacy model has smaller error boundary and higher data utility. The existing The multi-dimensional data privacy protection mean value estimation method of the local differential privacy model is aimed at data probabilistic perturbation being one of two determined values, and there is a large error when the privacy protection strength is low, and the personalized privacy protection demand of the user for different dimensional data is not considered. SUMMARY
[0005] In view of the technical problems existing in the prior art, the present application proposes a privacy protection mean value estimation for multi-dimensional numerical data, and designs a personalized privacy protection mechanism based on local differential privacy. The optimal dimension extraction parameter is determined based on the expectation of minimizing the estimation variance, and part of the dimensional data is randomly extracted from all dimensions for perturbation and submission, so as to effectively improve the accuracy of the mean value estimation. Since the user has personalized privacy protection demand for different dimensional data, a user scoring strategy is adopted to determine the allocation strategy of the privacy budget, so as to realize personalized privacy protection at the user data level. In summary, the present application provides a new solution for personalized privacy protection mean value estimation of multi-dimensional data.
[0006] To achieve the above purpose, the first aspect of the present application provides a personalized differential privacy protection method based on a user scoring strategy, comprising: Determine the optimal dimension extraction parameter by minimizing the expectation of the estimation variance according to the privacy protection parameter; Aggregate and statistically analyze the personalized perturbation data sent by the user, wherein the personalized perturbation data is obtained after the user data level personalized privacy protection is performed by the user according to the user data level personalized privacy protection level, and the user data level personalized privacy protection level is obtained by the user based on the determined optimal dimension extraction parameter using the user scoring strategy.
[0007] In one embodiment, the optimal dimension extraction parameter is determined by minimizing the expectation of the estimation variance according to the privacy protection level parameter as follows:
[0008] The optimal dimension extraction parameter is determined by minimizing the expectation of the estimation variance according to the privacy protection level parameter as follows: The dimension of the user data is determined by minimizing the expectation of the estimation variance according to the privacy protection level parameter as follows: The privacy protection budget, also known as the global privacy protection budget, is determined by minimizing the expectation of the estimation variance according to the privacy protection level parameter as follows:
[0009] Based on the same inventive concept, the second aspect of the present application provides a personalized differential privacy protection method based on a user scoring strategy, comprising: Receive the optimal dimension extraction parameter sent by the data aggregator, wherein the optimal dimension extraction parameter is determined by the data aggregator according to the privacy protection level parameter by minimizing the expectation of the estimation variance; Parameters are extracted based on the optimal dimension, and a user scoring strategy is used to allocate privacy protection parameters to determine the personalized privacy protection level at the user data level; According to the personalized privacy protection level at the user data level, personalized privacy protection is performed to obtain personalized disturbance data, which is then sent to the data aggregator so that the data aggregator can aggregate and perform statistical analysis on the personalized disturbance data sent by the user.
[0010] In one embodiment, parameters are extracted based on the optimal dimension, and a user scoring strategy is used to assign privacy protection parameters to determine the personalized privacy protection level at the user data level, including: Extract parameters based on the best dimension from the user d Random selection in dimensional data k dimensions, among which Extract parameters for the optimal dimension; Extraction based on data sensitivity The data of each dimension is scored for sensitivity, where the higher the sensitivity, the higher the score; The selected The sensitivity scores of each dimension are reverse normalized to construct the reverse normalized weight factor; The privacy protection parameters are personalized according to the inverse normalized weight factors to obtain the personalized privacy protection level at the user data level.
[0011] In one embodiment, the selected The sensitivity scores of each dimension are reverse normalized to construct the reverse normalized weight factors, which are as follows:
[0012] in, is the weight factor for the reverse normalization of the jth dimension among the selected k dimensions, Score the sensitivity of the jth dimension among the selected k dimensions, and i is the i-th dimension among the selected k dimensions.
[0013] In one embodiment, the privacy parameters are personalized according to the result of the direction normalization process to obtain a personalized privacy protection level at the user data level, including: According to the reverse normalized weight factor, the privacy protection parameters are personalized and the k The privacy protection parameters of each dimension in the dimensions serve as the personalized privacy protection level at the user data level, including personalized privacy budget and personalized relaxation factor, also known as local privacy protection parameters.
[0014] Based on the same inventive concept, the third aspect of the present application provides a personalized differential privacy protection device based on a user scoring strategy, the device being a data aggregator, comprising: An optimal dimension extraction parameter determination module is configured to determine an optimal dimension extraction parameter by minimizing the expectation of the estimation variance according to the privacy protection parameter. An aggregation module is configured to aggregate and statistically analyze the personalized perturbed data sent by the user, wherein the personalized perturbed data is obtained after the user performs personalized privacy protection according to the personalized privacy protection level at the user data level, and the personalized privacy protection level at the user data level is obtained by the user based on the determined optimal dimension extraction parameter using the user scoring strategy.
[0015] Based on the same inventive concept, the fourth aspect of the present application provides a personalized differential privacy protection device based on a user scoring strategy, the device being a user terminal, comprising: An optimal dimension extraction parameter receiving module is configured to receive the optimal dimension extraction parameter sent by the data aggregator, wherein the optimal dimension extraction parameter is determined by the data aggregator according to the privacy protection level parameter by minimizing the expectation of the estimation variance. A scoring module is configured to assign a privacy protection parameter based on the optimal dimension extraction parameter using the user scoring strategy to determine the personalized privacy protection level at the user data level. A personalized privacy protection module is configured to perform personalized privacy protection according to the personalized privacy protection level at the user data level to obtain personalized perturbed data and send the personalized perturbed data to the data aggregator, so that the data aggregator aggregates and statistically analyzes the personalized perturbed data sent by the user.
[0016] Based on the same inventive concept, the fifth aspect of the present application provides a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to realize the personalized differential privacy protection method based on the user scoring strategy in the first aspect and the second aspect.
[0017] Based on the same inventive concept, the sixth aspect of the present application provides a personalized differential privacy protection system based on a user scoring strategy, comprising the personalized differential privacy protection device based on the user scoring strategy in the third aspect and the personalized differential privacy protection device based on the user scoring strategy in the fourth aspect.
[0018] Compared with the prior art, the present application has the following innovative points and beneficial technical effects: 1. For the privacy protection mean estimation problem of multi-dimensional data, the individual privacy protection needs of the local user are fully considered, the accurate individual privacy protection is provided for the data of different dimensions of the user, the enthusiasm of the user in actively participating in data collection and sharing is effectively stimulated, and the participation and initiative of the user are significantly improved.
[0019] 2. In the present application, the data collector or aggregator knows the global privacy protection parameter, but does not know the individual privacy protection parameter of the user for the selected k dimensions, that is, the local privacy protection parameter is unknown. In other words, the specific privacy budget and relaxation factor allocation result of the k dimensions selected by the user is unknown to the data collector. In fact, the privacy protection parameter of the user for different data is also the privacy of the user, because the sensitive value weight of the user for the data also leaks the privacy information of the user from the side. Therefore, the present application further reduces the risk of user privacy leakage, while ensuring the individual privacy protection of the user data level.
[0020] 3. The present application is based on The individual privacy protection of multi-dimensional data is designed based on the local differential privacy protection model, which expands The mean estimation of multi-dimensional data under the local differential privacy protection model is considered, and the individual privacy protection needs of the user data level are considered, which is a more practical privacy protection model. That is: When The local differential privacy protection model is satisfied, and it is an individual privacy protection scheme, which shows that the present application technology is a more practical privacy protection model.
[0021] 4. The optimal dimension extraction parameter of the present application is derived based on the minimization of the expected estimation variance, which has a strict theoretical basis, so that each sub-population can select the optimal perturbation dimension parameter for data perturbation, effectively improving the accuracy of multi-dimensional data mean estimation, balancing privacy protection and data availability.
[0022] 5. The multi-dimensional data individual privacy protection mean estimation method proposed in the present application, in realizing the individual privacy protection of the data level, in order to measure the sensitivity of the selected dimension data, adopts the user scoring strategy, in principle, the more sensitive the data is, the higher the score is, and then the privacy budget and relaxation factor are segmented according to the inverse normalized weight factor, which provides a theoretical basis for the individual privacy protection of the user data level.
[0023] 6. The present application realizes the individual privacy protection of the user data level while ensuring good statistical estimation accuracy, which is a statistical and analytical method with great practical value, and has broad application prospect and important practical significance in actual application scenarios. BRIEF DESCRIPTION OF DRAWINGS
[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings described below are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor based on these drawings.
[0025] Figure 1 The flow chart of the personalized differential privacy protection method based on user scoring strategy for the data aggregator in the embodiment of the present application; Figure 2 The flow chart of the personalized differential privacy protection method based on user scoring strategy for the user terminal in the embodiment of the present application; Figure 3 The overall framework diagram of the personalized differential privacy protection method based on user scoring strategy in the embodiment of the present application. DETAILED DESCRIPTION
[0026] Embodiment one The embodiment provides a personalized differential privacy protection method based on a user scoring strategy, please refer to Figure 1 , comprising: S101: determining the optimal dimension extraction parameter according to the privacy protection parameter by minimizing the expectation of the estimated variance; S102: aggregating and statistically analyzing the personalized perturbation data sent by the user, wherein the personalized perturbation data is obtained after the user performs personalized privacy protection according to the personalized privacy protection level of the user data, and the personalized privacy protection level of the user data is obtained by the user based on the determined optimal dimension extraction parameter using the user scoring strategy.
[0027] Specifically, the execution subject of the present embodiment is a data aggregator, and S101 is to determine the optimal dimension extraction parameter by minimizing the expectation of the estimated variance according to the privacy protection parameter. The data aggregator determines the optimal dimension extraction parameter k by minimizing the expectation of the estimated variance according to the privacy protection level parameter , so that the user subsequently randomly selects k dimensions from the d-dimensional data for perturbation output.
[0028] S102 is the aggregation and statistical analysis of data. The data collector or aggregator aggregates and analyzes the d-dimensional data, and estimates the mean value of each dimension data.
[0029] Embodiment two The embodiment provides a personalized differential privacy protection method based on a user scoring strategy, please refer to Figure 2 , comprising: S201: Receive optimal dimension extraction parameters sent by the data aggregator, where the optimal dimension extraction parameters are determined by the data aggregator by minimizing the expected estimated variance according to the privacy protection level parameter; S202: Extract parameters based on the optimal dimension, use a user scoring strategy to assign privacy protection parameters, and determine a personalized privacy protection level at the user data level; S203: Perform personalized privacy protection according to the personalized privacy protection level at the user data level, obtain personalized disturbance data, and send it to the data aggregator, so that the data aggregator can aggregate and perform statistical analysis on the personalized disturbance data sent by the user.
[0030] Specifically, the execution subject of this embodiment is the user terminal. S202 uses the user scoring strategy to allocate privacy parameters and determine the personalized privacy protection level at the user data level.
[0031] S202 can be achieved by: S2021: Extract parameters based on the best dimension, from the user d Random selection in dimensional data k dimensions, among which Extract parameters for the optimal dimension; S2022: Extraction based on data sensitivity The data of each dimension is scored for sensitivity, where the higher the sensitivity, the higher the score; S2023: will be selected The sensitivity scores of each dimension are reverse normalized to construct the reverse normalized weight factor; S2024: Personalize the allocation of privacy protection parameters based on the inverse normalized weight factors to obtain a personalized privacy protection level at the user data level.
[0032] During the specific implementation process, d Data of dimensions, randomly selected dimensions, satisfying: , users select the extracted The sensitivity of the data in each dimension is scored. The principle of scoring is that the higher the sensitivity of the data, the higher the score. The scores of each dimension are reverse normalized, and a personalized privacy parameter allocation strategy is determined based on this. The principle of reverse normalization is that if the user considers the data of a certain extracted dimension to be more sensitive, the privacy protection requirement is higher, and a lower privacy budget and relaxation factor are required to strengthen protection.
[0033] In S2024, the privacy parameters are personalized according to the results of the direction normalization processing, and the personalized privacy protection levels at the user data level are obtained, including: The privacy protection parameters in each dimension are personalized according to the reverse normalized weight factors, and the personalized privacy protection levels at the user data level are obtained, including the personalized privacy budget and the personalized relaxation factor, also known as the local privacy protection parameter. k
[0034] In S203, the personalized privacy protection levels at the user data level obtained according to the user personalized privacy budget allocation strategy are used to perform personalized privacy protection. Specifically, the user performs personalized data perturbation according to the personalized privacy parameter allocation strategy of the dimension determined in step S202, and sends the perturbed results to the data collector or aggregator. The data in the dimensions not selected for random selection is directly replaced with a value of 0 or output as empty.
[0035] In the specific implementation process, when performing data perturbation, not all data in the d dimension are perturbed and submitted, but dimension data are randomly selected for personalized perturbation and submission. Among them, is the dimension of the data, and . In the random selection of dimension data for perturbation, the value is derived based on the expectation of minimizing the estimation variance, satisfying: , which has a good theoretical basis.
[0036] Personalized privacy protection is based on the sensitivity of user data. The privacy protection requirements at the data level reflect the privacy protection requirements of users for their different sensitive attribute data. In order to measure the sensitivity of the selected dimension data, a user scoring strategy is adopted. In principle, the more sensitive the data, the higher the privacy protection requirement, and the higher the score. The user scores the sensitive data selected from the dimension, and performs reverse normalization processing to obtain k sensitivity weights: , … , satisfying: At this time, based on the reverse normalized sensitivity weight, the privacy budget and the relaxation factor are divided to achieve personalized privacy protection at the user data level, which can significantly improve the accuracy of the mean estimation of multi-dimensional personalized privacy protection.
[0037] The following analysis of the present application is made in combination with the drawings and specific examples, please see Figure 3 , for the overall framework diagram of the personalized differential privacy protection method based on user scoring strategy in the embodiment of the present application.
[0038] Given a data collector or aggregator and N users , assuming that the users are independent of each other, each user has a numerical data containing d dimensions, the d-dimensional data of user is defined as { , , }, without loss of generality, assuming that the numerical data of each dimension , the purpose of the data collector wants to obtain the mean estimate of each dimension data with high accuracy.
[0039] It should be noted that: in practice, the value range of numerical data may not be the interval [-1, 1], as long as it is mapped to the interval [-1, 1] by linear normalization method, and then the mean estimate result is restored, so the method in the present application is applicable to the mean estimate of any value range.
[0040] The embodiment of the present application is based on - The local differential privacy protection model designs personalized privacy protection of multi-dimensional data, and realizes personalized privacy protection at the user data level. First, the perturbation mechanism of single-dimensional data is described: (1) satisfies - The interval perturbation mechanism of single-dimensional data of local differential privacy Assuming that the input data of the user is , the perturbed output is , and , wherein is the output domain, is a function related to the privacy protection parameter , once the privacy protection parameter is given, C is a certain constant. The user divides the output domain into three intervals: left interval, middle interval and right interval, and the data is perturbed to the three intervals with different probabilities. The privacy protection level is measured by the differential privacy budget and the relaxation factor , the perturbation mechanism satisfying (- ) local differential privacy is designed, for numerical data , the perturbation strategy is:
[0041] , wherein represents the probability density function, [ ) is the left interval, is the middle interval, is the right interval, and b is a function of the privacy protection parameter , once the privacy protection parameter is given, and b are specific constants, t is a numerical intermediate variable, p and q are functions of , satisfying . According to the above perturbation mechanism, the probability of the perturbed data falling in the middle interval is , that is, the probability of the perturbed output data falling in each point of the middle interval is ; the probability of the perturbed data falling in the left interval and the right interval is , that is, the probability of the perturbed data falling in each point of the left interval and the right interval is . The specific parameter settings are as follows:
[0042]
[0043]
[0044]
[0045]
[0046] Each end user executes the above perturbation strategy and sends the perturbed data to the data collector for aggregation, and the estimated mean value is:
[0047] where N is the data volume.
[0048] According to the definition of expectation, the expectation of the perturbed data is
[0049] According to the definition of variance, the variance of the perturbed data is described as:
[0050]
[0051]
[0052] The variance of the estimated mean is:
[0053] (2) satisfies - Interval perturbation mechanism for multi-dimensional data of local personalized differential privacy a. Privacy parameter segmentation based on user scoring strategy For ease of description, - The privacy protection parameter in local differential privacy is called a global privacy protection parameter. Existing - The local differential privacy scheme perturbs the data of the selected dimensions, and the global privacy protection parameter is averaged and segmented, such as , , which does not take into account the personalized privacy protection needs of users in different dimensions of data, i.e., the sensitivity of different dimensions of data of users is different, and of course the privacy protection needs are different. The sensitivity of personal data is one of the most important factors in determining personal privacy perception, and the sensitivity of data will affect the willingness of users to disclose personal information. Different users may have different sensitivities to the same data, and individual differences can be captured through a user scoring strategy, so that a more personalized privacy protection strategy can be developed. Based on this, in order to measure the sensitivity of the selected dimensions of data, the user scoring strategy is used to measure the personalized privacy protection needs of the user data level. In principle, the more sensitive the data, the higher the privacy protection needs, and the higher the score.
[0054] To solve the problem of user's sensitivity perception deviation, we can start from two aspects of user guidance and data calibration, the specific operation is as follows: (1) User guidance. Before the user starts scoring, define the sensitivity in simple and easy-to-understand language. For example, for health data, it can be explained as "sensitivity refers to the degree to which the data, if leaked, may affect your personal life and rights, such as information related to your private illness, which is high-sensitivity data". Design a step-by-step scoring process to avoid confusion when users face too much dimensional data at once. For example, first show one dimension of data, guide the user to understand and score, and then enter the next dimension.
[0055] (2) Multi-round scoring and consistency check. Ask the user to score the same group of data at different time points, and evaluate the stability of the user's perception by comparing the consistency of the scoring results. If the difference between the multi-round scoring results is large, it means that the user's perception of sensitivity is fluctuating, and the user can be prompted to re-examine the scoring criteria. Use algorithms to analyze the multi-round scoring results, for example, calculate the Pearson correlation coefficient. If the correlation coefficient is lower than the set threshold, it is determined that the scoring results are inconsistent, triggering the re-scoring process.
[0056] The above user guidance for sensitivity scoring, as well as the multiple rounds of scoring and consistency checking, are not necessarily mandatory operations, and in practice, whether to perform the above operations can be selected according to needs.
[0057] Suppose the user scores the data sensitivity of the selected dimension, and the scoring results are recorded in turn as , … The reverse normalized weight factor of the jth dimension in the selected k dimensions is designed as .
[0058] Through the above formula, the k sensitivity weights can be obtained: , … , which satisfy: . At this time, the privacy protection parameters of the selected dimension data are respectively: , … , that is, the weight factor is constructed based on the sensitivity, and then the personalized privacy budget and the relaxation privacy segmentation strategy are determined, to realize the personalized privacy protection at the user data level, and for the multi-dimensional data of the user, satisfy -LDP. Specifically: Define the personalized privacy budget of the jth dimension data in the selected k dimensions as , then = , which is closely related to the sensitivity of the jth dimension data in the selected k dimensions of the user; define the personalized relaxation factor of the jth dimension data in the selected k dimensions as , then = , which is also closely related to the sensitivity of the jth dimension data in the selected k dimensions of the user. In the privacy parameter segmentation strategy, the total privacy budget consumed by the k dimension data selected by the user is , and the total relaxation factor consumed is . For the jth dimension data selected by the user in the k dimensions, the perturbation mechanism needs to satisfy -LDP. For ease of description, -LDP is also called local privacy protection parameter.
[0059] In principle, the higher the sensitivity of the user's certain dimension data, the higher the privacy protection requirement, and the smaller privacy budget and relaxation factor need to be allocated. The above weight factor construction method meets this principle.
[0060] It is worth noting that in the present application, the data collector does not know the global privacy protection parameter of each user data level, i.e. the specific privacy budget and relaxation factor allocation result of the k dimensions selected by each user is unknown to the data collector, which further protects the privacy information of the user and reduces the risk of user privacy leakage.
[0061] b. Personalized privacy protection and data aggregation According to the above privacy budget and relaxation privacy segmentation strategy, the user selects k dimensions Adopt -LDP for disturbance (j=1, 2, …, k). That is, the above interval disturbance mechanism that meets -LDP is replaced by , is replaced by , , and the disturbance output is .
[0062] Since the multi-dimensional data mean estimation mechanism under -LDP is that the user randomly selects dimensions from d dimensions for disturbance output, in order to ensure the unbiased estimation characteristics of the estimated mean, the disturbance output result of the above single-dimensional data needs to be corrected. The corrected disturbance output is described as:
[0063] The unselected dimensions are directly replaced by =0 when submitting data, then The estimated mean of the jth dimension data under -LDP is described as:
[0064] Where, is the number of users.
[0065] c. Optimal dimension parameter determination According to the definition of expectation, the expectation of disturbed data is
[0066] According to the definition of variance, the variance of disturbed data is described as:
[0067] wherein each parameter is described as follows:
[0068]
[0069]
[0070]
[0071]
[0072] Since the allocation strategy of the privacy parameter is unknown to the data collector, that is, the data collector only knows the global privacy protection parameter and does not know the local privacy protection parameter of each user, it is impossible to infer the data privacy information from the personalized privacy protection at the user data level, thereby reducing the risk of privacy leakage. However, the personalized privacy budget and the personalized relaxation factor used by the data collector when performing data perturbation on each dimension selected by each user are unknown, and it is impossible to directly perform theoretical analysis according to the specific allocated privacy budget and relaxation factor when performing error evaluation. Therefore, the expectation of the estimated variance is used for error evaluation in the embodiment:
[0073] wherein
[0074]
[0075] Let = , = , the known parameters and k, and the parameter , are known, then
[0076]
[0077]
[0078] Since the specific distribution of is unknown, without loss of generality, it is assumed that is uniformly distributed in the interval of -1 to 1, then
[0079] The expectation of the variance of the above mean estimate is described as:
[0080] In Under LDP, each user randomly selects k dimensions of data for perturbation. In order to ensure that the error of the estimated mean is minimized, the optimal dimension extraction parameter is determined based on minimizing the expectation of the estimated variance (i.e., minimizing ).
[0081] wherein, It can be seen that the optimal number of dimension extraction is closely related to the global privacy budget and the number of dimensions.
[0082] Embodiment Three Based on the same inventive concept, the embodiment discloses a personalized differential privacy protection device based on a user scoring strategy. The device is a data aggregator and comprises: An optimal dimension extraction parameter determination module is configured to determine an optimal dimension extraction parameter by minimizing the expectation of the estimated variance according to a privacy protection parameter. An aggregation module is configured to aggregate and statistically analyze personalized perturbation data sent by a user, wherein the personalized perturbation data is obtained after the user performs personalized privacy protection according to a personalized privacy protection level at the user data level, and the personalized privacy protection level at the user data level is obtained by the user based on the determined optimal dimension extraction parameter using a user scoring strategy.
[0083] Since the device introduced in Embodiment Three of the present application is a device used to implement the method in Embodiment One of the present application, the specific structure and modifications of the device can be understood by those skilled in the art based on the method introduced in Embodiment Three of the present application, and therefore will not be described here. Any device used in the method in Embodiment Three of the present application belongs to the scope of the present application.
[0084] Embodiment Four Based on the same inventive concept, the embodiment discloses a personalized differential privacy protection device based on a user scoring strategy. The device is a user end and comprises: An optimal dimension extraction parameter receiving module is configured to receive an optimal dimension extraction parameter sent by a data aggregator, wherein the optimal dimension extraction parameter is determined by the data aggregator according to a privacy protection level parameter by minimizing the expectation of the estimated variance. A scoring module is configured to assign a privacy protection parameter based on the optimal dimension extraction parameter using a user scoring strategy to determine a personalized privacy protection level at the user data level. The personalized privacy protection module is configured to perform personalized privacy protection according to a personalized privacy protection level of the user data, to obtain personalized perturbed data, and to send the personalized perturbed data to the data aggregator, so that the data aggregator performs aggregation and statistical analysis on the personalized perturbed data sent by the user.
[0085] Since the device introduced in the fourth embodiment of the present application is the device used for implementing the method in the second embodiment of the present application, the specific structure and variations of the device can be understood by those skilled in the art based on the method introduced in the second embodiment of the present application, and thus will not be described here again. Any device used for the method in the second embodiment of the present application belongs to the scope of the present application.
[0086] Embodiment Five Based on the same inventive concept, the present application further provides a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method in the first or second embodiment when executing the program.
[0087] Since the computer device introduced in the fifth embodiment of the present application is the computer device used for implementing the personalized differential privacy protection method based on the user scoring strategy in the first or second embodiment of the present application, the specific structure and variations of the computer device can be understood by those skilled in the art based on the method introduced in the first embodiment of the present application, and thus will not be described here again. Any computer device used for the method in the first embodiment of the present application belongs to the scope of the present application.
[0088] Embodiment Six Based on the same inventive concept, the present application further provides a personalized differential privacy protection system based on a user scoring strategy, comprising the personalized differential privacy protection device based on a user scoring strategy in the third embodiment and the personalized differential privacy protection device based on a user scoring strategy in the fourth embodiment.
[0089] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can be in the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can be in the form of a computer program product implemented on one or more computer usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer usable program code.
[0090] The computer program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other processing device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other processing device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions specified in the flowchart block or blocks. Figure 1 one or more functions specified in the flowchart block or blocks and Figure 1 one or more functions specified in the flowchart block or blocks and
[0091] While the preferred embodiments of the application have been described, additional variations and modifications can be made to the embodiments by those skilled in the art once they learn of the basic inventive concepts. Such additional variations and modifications have been provided for by the above description of the preferred embodiments, which are intended to be illustrative only. Accordingly, it is not intended that the application be limited as described above but rather that it is intended to be limited only by the scope of the appended claims, including all equivalents of the subject matter of the claims. Obviously, many modifications and variations of the present embodiments are possible in light of the above teachings. It is, therefore, to be understood that within the scope of the claims, the application can be practiced otherwise than as specifically described. For that reason, the following claims should be studied to determine the true scope and content of the application.
Claims
1. A personalized differential privacy protection method based on user scoring strategy, characterized by: include: According to the privacy protection parameters, the optimal dimension extraction parameters are determined by minimizing the expected estimated variance; The personalized disturbance data sent by users is aggregated and statistically analyzed, where the personalized disturbance data is obtained by users after performing personalized privacy protection according to the personalized privacy protection level at the user data level. The personalized privacy protection level at the user data level is obtained by users using a user scoring strategy based on the determined optimal dimension extraction parameters.
2. The personalized differential privacy protection method based on user scoring strategy according to claim 1, characterized in that: According to the privacy protection level parameter, the optimal dimension extraction parameter is determined by minimizing the expected estimated variance: is the optimal dimension extraction parameter, is the dimension of user data, is a privacy protection parameter.
3. A personalized differential privacy protection method based on user scoring strategy, characterized by: include: Receive the optimal dimension extraction parameters sent by the data aggregator, where the optimal dimension extraction parameters are determined by the data aggregator by minimizing the expected estimated variance according to the privacy protection level parameter; Parameters are extracted based on the optimal dimension, and a user scoring strategy is used to allocate privacy protection parameters to determine the personalized privacy protection level at the user data level; According to the personalized privacy protection level at the user data level, personalized privacy protection is performed to obtain personalized disturbance data, which is then sent to the data aggregator so that the data aggregator can aggregate and perform statistical analysis on the personalized disturbance data sent by the user.
4. The personalized differential privacy protection method based on user scoring strategy according to claim 3, characterized in that: Parameters are extracted based on the optimal dimension, and a user scoring strategy is used to allocate privacy protection parameters to determine the personalized privacy protection level at the user data level, including: Extract parameters based on the best dimension from the user d Random selection in dimensional data k dimensions, among which Extract parameters for the optimal dimension; Extraction based on data sensitivity The data of each dimension is scored for sensitivity, where the higher the sensitivity, the higher the score; The selected The sensitivity scores of each dimension are reverse normalized to construct the reverse normalized weight factor; The privacy protection parameters are personalized according to the inverse normalized weight factors to obtain the personalized privacy protection level at the user data level.
5. The personalized differential privacy protection method based on user scoring strategy according to claim 4, characterized in that: The selected The sensitivity scores of each dimension are reverse normalized to construct the reverse normalized weight factors, which are as follows: in, is the weight factor for the reverse normalization of the jth dimension among the selected k dimensions, Score the sensitivity of the jth dimension among the selected k dimensions, and i is the i-th dimension among the selected k dimensions.
6. The personalized differential privacy protection method based on user scoring strategy according to claim 5, characterized in that: Based on the results of the directional normalization process, the privacy parameters are personalized and assigned to obtain the personalized privacy protection level at the user data level, including: According to the reverse normalized weight factor, the privacy protection parameters are personalized and the k The privacy protection parameters of each dimension in the three dimensions serve as the personalized privacy protection level at the user data level, including personalized privacy budget and personalized relaxation factor.
7. A personalized differential privacy protection device based on user scoring strategy, characterized in that: The device is a data aggregator and includes: An optimal dimension extraction parameter determination module is used to determine the optimal dimension extraction parameter by minimizing the expected estimated variance according to the privacy protection parameter; The aggregation module is used to aggregate and statistically analyze the personalized disturbance data sent by users. The personalized disturbance data is obtained by users after performing personalized privacy protection according to the personalized privacy protection level at the user data level. The personalized privacy protection level at the user data level is obtained by users using a user scoring strategy based on the determined optimal dimension extraction parameters.
8. A personalized differential privacy protection device based on user scoring strategy, characterized in that: The device is a user terminal, including: An optimal dimension extraction parameter receiving module is used to receive the optimal dimension extraction parameters sent by the data aggregator, wherein the optimal dimension extraction parameters are determined by the data aggregator by minimizing the expected estimated variance according to the privacy protection level parameter; The scoring module is used to extract parameters based on the optimal dimension, allocate privacy protection parameters using a user scoring strategy, and determine the personalized privacy protection level at the user data level; The personalized privacy protection module is used to perform personalized privacy protection according to the personalized privacy protection level at the user data level, obtain personalized disturbance data, and send it to the data aggregator so that the data aggregator can aggregate and perform statistical analysis on the personalized disturbance data sent by the user.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, it implements the personalized differential privacy protection method based on the user scoring strategy as described in any one of claims 1 to 6.
10. A personalized differential privacy protection system based on user scoring strategy, characterized by: It includes the personalized differential privacy protection device based on user scoring strategy as described in claim 7 and the personalized differential privacy protection device based on user scoring strategy as described in claim 8.