Vehicle data protection method, device and equipment

By using time series forecasting models to predict future data trends in vehicle data protection and dynamically adjusting the privacy budget, the problem of unreasonable privacy budget allocation in traditional methods is solved, achieving a more efficient balance between privacy protection and data utilization.

CN121125335APending Publication Date: 2025-12-12CHONGQING CHANGAN AUTOMOBILE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511567977.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-30
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

Traditional static differential privacy mechanisms cannot flexibly adjust privacy overhead according to dynamic changes in data, resulting in compromised data accuracy or excessive consumption of privacy budget. Furthermore, existing methods lack forward-looking modeling of future data change trends, leading to lagging privacy budget allocation and rigid protection strategies.

Method used

By acquiring device data for the current period, time series prediction models such as the Prophet model are used to predict the data change trend for the next period. Combining information on the intensity of change and the total privacy budget, the privacy budget for each vehicle device is dynamically adjusted to achieve fine-grained and adaptive privacy protection.

Benefits of technology

This approach achieves a more reasonable balance between privacy protection and data availability in vehicle data protection, improves data quality and security, and avoids resource waste and risk out of control in traditional methods.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125335A_ABST
    Figure CN121125335A_ABST
Patent Text Reader

Abstract

The invention discloses a vehicle data protection method, device and equipment, and the method comprises the steps: obtaining the current equipment data, collected in a current period, of different vehicle equipment, and the historical equipment data, collected in a historical period, of different vehicle equipment; based on the current historical device data, predicting prediction data of different vehicle devices collected in the next period; based on the prediction data of the different vehicle devices and the current device data of the different vehicle devices, determining change intensity information corresponding to the different vehicle devices; the change intensity information is used for representing the prediction reliability of the prediction data of the vehicle equipment; based on the change intensity information corresponding to the vehicle equipment and the privacy budget total amount corresponding to the next period, determining the equipment privacy budget of the vehicle equipment in the next current period; and performing data protection on the current real equipment data of the different vehicle equipment acquired in the next period based on the equipment privacy budgets corresponding to the different vehicle equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle technology, and specifically to a method, apparatus, and device for protecting vehicle data. Background Technology

[0002] With the rapid development of intelligent connected vehicles and vehicle-road cooperative systems, heterogeneous devices from multiple sources, including vehicles, roadside infrastructure, and the cloud, are continuously generating massive amounts of high-dimensional spatiotemporal data. This data is of significant value for traffic safety analysis, behavior prediction, and anomaly detection. However, the risk of privacy leakage increases significantly during data sharing and uploading, especially in scenarios involving sensitive information such as location and driving behavior. Traditional static differential privacy mechanisms struggle to balance privacy protection strength with data availability. On one hand, fixed budget allocation methods cannot flexibly adjust privacy costs based on dynamic data changes, easily leading to compromised accuracy of highly volatile data or excessive consumption of the privacy budget. On the other hand, existing privacy protection methods generally lack forward-looking modeling of future data trends, preventing the system from proactively identifying potentially high-risk phases before data collection, resulting in delayed privacy budget allocation and rigid protection strategies. Summary of the Invention

[0003] In view of this, embodiments of this application provide at least one method, apparatus, and device for protecting vehicle data.

[0004] The technical solution of this application embodiment is implemented as follows: In a first aspect, embodiments of this application provide a method for protecting vehicle data, the method comprising: Acquire current device data from different vehicle devices collected in the current period; Based on current equipment data, predict the forecast data for different vehicle equipment to be collected in the next cycle; Based on the prediction data and current equipment data of different vehicles and equipment, the change intensity information corresponding to different vehicles and equipment is determined; the change intensity information is used to characterize the prediction reliability of the prediction data of the vehicle and equipment. For each vehicle device, the device privacy budget for the next period is determined based on the change intensity information of the vehicle device and the total privacy budget for the next period. Based on the device privacy budget corresponding to different vehicles and devices, data protection is implemented for the real device data of different vehicles and devices collected in the next cycle.

[0005] Secondly, embodiments of this application provide a vehicle data protection device, which includes: The acquisition module is used to acquire current device data from different vehicle devices collected in the current period; The prediction module is used to predict the data collected from different vehicle devices in the next cycle based on the current device data. The first determining module is used to determine the change intensity information corresponding to different vehicle equipment based on the prediction data of different vehicle equipment and the current equipment data of different vehicle equipment; the change intensity information is used to characterize the prediction reliability of the prediction data of vehicle equipment. The second determining module is used to determine the device privacy budget for each vehicle device in the next cycle based on the change intensity information of the vehicle device and the total privacy budget for the next cycle. The protection module is used to protect the real device data of different vehicles and devices collected in the next cycle based on the device privacy budget corresponding to different vehicle devices.

[0006] Thirdly, embodiments of this application provide a vehicle data protection device, including a memory and a processor. The memory stores a computer program that can run on the processor, and the processor executes the program to implement some or all of the steps in the above method.

[0007] Fourthly, embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements some or all of the steps in the above-described method.

[0008] Fifthly, embodiments of this application provide a computer program product, including a computer program or instructions, which, when executed by a processor, implement some or all of the steps in the above-described method.

[0009] In this embodiment, the predicted data for the next period is first predicted based on the current device data collected in the current period. The intensity of change is then determined by combining the current device data with this information. This intensity of change reflects the reliability of future data change trends, thus providing a basis for privacy budget allocation. Subsequently, considering both the total privacy budget for the next period and the intensity of change information, the privacy budget for each vehicle device is dynamically adjusted to achieve fine-grained, adaptive privacy protection. Compared to existing privacy budget methods that control privacy with fixed or single parameters, this embodiment can more reasonably balance the intensity of privacy protection with data availability, improving the data quality and security of vehicle data.

[0010] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and are not intended to limit the technical solutions of this application. Attached Figure Description

[0011] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with this application and, together with the specification, serve to explain the technical solutions of this application.

[0012] Figure 1 A schematic diagram of the implementation process of a vehicle data protection method provided in this application embodiment. Figure 1 ; Figure 2 A schematic diagram of the implementation process of a vehicle data protection method provided in this application embodiment. Figure 2 ; Figure 3 A schematic diagram of the implementation process of a vehicle data protection method provided in this application embodiment. Figure 3 ; Figure 4 A schematic diagram of the composition structure of a vehicle data protection device provided in this application embodiment; Figure 5 A schematic diagram of a hardware entity of a vehicle data protection device provided in an embodiment of this application. Detailed Implementation

[0013] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application are further described in detail below with reference to the accompanying drawings and embodiments. The described embodiments should not be regarded as limitations on this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0014] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0015] The terms “first / second / third” are used merely to distinguish similar vehicles and do not represent a specific ordering of vehicles. It is understood that “first / second / third” may be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in a sequence other than that illustrated or described herein.

[0016] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains. The terminology used herein is for descriptive purposes only and is not intended to limit the scope of this application.

[0017] To address the technical problems in related technologies, embodiments of this application provide a method for protecting vehicle data. This method can be applied to electronic devices, which, exemplarily, include but are not limited to smartphones, tablets, wearable devices, personal computers (PCs), netbooks, etc. The implementation of this method is not fixed or limited in this application. Figure 1 As shown, the method includes the following steps S101 to S105: Step S101: Obtain current device data of different vehicle devices collected in the current cycle.

[0018] Here, the current period refers to the ongoing data acquisition phase. Device data refers to the raw data collected by various acquisition devices from vehicle equipment, including but not limited to location information, speed, acceleration, and environmental perception data. Device data is characterized by high dimensionality, temporal sequence, and dynamic changes, and it forms the basis for subsequent analysis, modeling, and privacy protection processing. For example, location information collected by an onboard GPS module can be used for traffic flow analysis, while real-time speed data collected by a vehicle speed sensor can be used for driving behavior analysis. Exemplarily, this device data may include vehicle driving safety data collected by the onboard sensing and control unit, roadside perception data collected by sensing devices installed on road infrastructure, and cloud data sourced from traffic management platforms or cloud data service interfaces.

[0019] Step S102: Based on the current device data, predict the predicted data of different vehicle devices to be collected in the next cycle.

[0020] In this embodiment of the application, a time series prediction model can be used to predict the data of different vehicles and devices collected in the next period based on the current device data. For example, this time series prediction model can be the Prophet model.

[0021] In practice, fitting the current device data to the Prophet model and outputting predicted data for the next data collection cycle helps to identify data change trends in advance, thus providing a forward-looking basis for privacy budget allocation. The technical effect of the above steps is that they achieve accurate prediction of data change trends, improving the adaptability and flexibility of privacy protection strategies.

[0022] Step S103: Based on the prediction data of different vehicles and equipment and the current equipment data of different vehicles and equipment, determine the change intensity information corresponding to different vehicles and equipment respectively; the change intensity information is used to characterize the prediction reliability of the prediction data of the vehicles and equipment.

[0023] Here, the intensity of change information can reflect the criticality of data changes in vehicle equipment and the reliability of prediction data.

[0024] In this embodiment, the number of data sampling points in the current period and the next period, as well as the time interval between two adjacent data sampling points, are the same. The predicted data corresponding to each data sampling point in the next period can be determined first, and the change between the current device data and the corresponding data sampling point in the current period can be determined. Then, the sum of the changes corresponding to each data sampling point is determined, and the change intensity information corresponding to different vehicles and devices is determined based on the sum of the changes corresponding to each data sampling point.

[0025] Step S104: For each vehicle device, based on the change intensity information corresponding to the vehicle device and the total privacy budget for the next period, determine the device privacy budget for the vehicle device in the next period.

[0026] Here, the privacy budget refers to the parameter used in differential privacy mechanisms to control the intensity of noise addition, typically denoted by ε (epsilon). The device privacy budget determines the strength of privacy protection during data release: a larger ε value results in weaker privacy protection but higher data availability; conversely, a smaller ε value results in stronger privacy protection but also higher data distortion. In this embodiment, the privacy budget is not fixed but adaptively adjusted based on the predicted data trend and task requirements to achieve a balance between privacy protection and data quality. The total privacy budget refers to the sum of the privacy budgets for all vehicle devices in the next cycle.

[0027] In this embodiment, the total change intensity information of all vehicle devices can be determined first, then the proportion of the change intensity information of each vehicle device to the total change intensity information can be determined, and then the device privacy budget of each vehicle device in the next period can be determined based on the proportion and the total privacy budget corresponding to the next period.

[0028] Step S105: Based on the device privacy budget corresponding to different vehicle devices, data protection is implemented for the real device data of different vehicle devices collected in the next cycle.

[0029] Here, data protection refers to the process of achieving privacy protection by adding noise to the real device data of different vehicles and devices collected in the next cycle under the differential privacy mechanism.

[0030] In this embodiment of the application, for each vehicle device, the statistical values ​​of multiple current device data collected by the vehicle device at multiple data sampling points in the next cycle can be determined first, and then the device privacy budget of the vehicle device can be injected into the statistical values ​​of multiple real device data to complete the protection of real device data.

[0031] In some embodiments, for each vehicle device, the device privacy budget of that vehicle device can be injected into the real device data collected at each data sampling point in the next cycle to complete the protection of the real device data.

[0032] It is understood that, in this embodiment of the application, after collecting device data for the current period and before collecting device data for the next period, the predicted device data for the next period is predicted based on the current period's device data. Then, the device privacy budget for the next period is pre-determined based on the predicted device data. Finally, after collecting the actual device data for the next period, the pre-determined device privacy budget is used to protect the actual device data. This allows for timely data protection of the collected device data using a pre-determined device privacy budget after data collection, thereby improving the efficiency of data protection.

[0033] In this embodiment, the predicted data for the next period is first predicted based on the current device data collected in the current period. The intensity of change is then determined by combining the current device data with this information. This intensity of change reflects the reliability of future data change trends, thus providing a basis for privacy budget allocation. Subsequently, considering both the total privacy budget for the next period and the intensity of change information, the privacy budget for each vehicle device is dynamically adjusted to achieve fine-grained, adaptive privacy protection. Compared to existing privacy budget methods that control privacy with fixed or single parameters, this embodiment can more reasonably balance the intensity of privacy protection with data availability, improving the data quality and security of vehicle data.

[0034] In some embodiments, the prediction data includes prediction device data and prediction confidence levels for the prediction device data; for each vehicle device, step S103 can be implemented by steps S1031 and S1032: Step S1031: Determine the data fluctuation information of the predicted equipment data of the vehicle equipment relative to the current equipment data of the vehicle equipment.

[0035] In this embodiment of the application, the change information of the predicted device data of each data collection point in the next period relative to the predicted device data of the corresponding data collection point in the current period is determined, and then the average change information of the change information corresponding to multiple data collection points is determined as the data fluctuation information of the vehicle equipment.

[0036] For example, both the next period and the current period include data acquisition point 1, data acquisition point 2, and data acquisition point 3. The prediction device data for the next period includes prediction device data 1 corresponding to data acquisition point 1, prediction device data 2 corresponding to data acquisition point 2, and prediction device data 3 corresponding to data acquisition point 3. The current device data for the current period includes current device data 1 corresponding to data acquisition point 1, current device data 2 corresponding to data acquisition point 2, and current device data 3 corresponding to data acquisition point 3. For data acquisition point 1, the change information 1 of prediction device data 1 relative to current device data 1 is determined; for data acquisition point 2, the change information 2 of prediction device data 2 relative to current device data 2 is determined; for data acquisition point 3, the change information 3 of prediction device data 3 relative to current device data 3 is determined. The average change information of change information 1, change information 2, and change information 3 is determined to obtain the data fluctuation information of the vehicle equipment.

[0037] Step S1032: Based on the data fluctuation information of the vehicle equipment and the prediction confidence level of the prediction equipment data, determine the change intensity information of the vehicle equipment.

[0038] Here, the prediction confidence of the prediction device data refers to the prediction confidence of the prediction device data corresponding to the data collection point in the next period. In other words, each prediction device data corresponding to a data collection point has a prediction confidence.

[0039] In this embodiment, the average prediction confidence level can be determined first based on the prediction confidence level corresponding to each data sampling point. Then, the product of the vehicle equipment's data fluctuation information and the average prediction confidence level is determined as the vehicle equipment's change intensity information. For example, step S1032 can be implemented using formula (1): Formula (1); in, This refers to the information on the intensity of changes in vehicle equipment J. This refers to the average prediction confidence level of vehicle equipment J. This refers to the data fluctuation information of vehicle equipment J.

[0040] In this embodiment, by determining the fluctuation information of the predicted device data relative to the current device data and combining it with the prediction confidence level to assess the intensity of change, the intensity of change information not only reflects the degree of data fluctuation but also embodies the reliability of the prediction results. This two-dimensional analysis method improves the accuracy of the intensity of change information and helps to make the subsequent allocation of privacy budgets more closely aligned with actual needs.

[0041] In some embodiments, such as Figure 2 As shown, step S104 can be achieved through steps S201 to S205: Step S201: Determine the data criticality of the vehicle equipment; data criticality is used to characterize the degree of importance of the equipment data of the vehicle equipment in the vehicle mission.

[0042] In this embodiment, the data criticality of the vehicle equipment can be determined based on the equipment weight and / or the data weight of the vehicle equipment. The equipment weight represents the importance of the vehicle equipment in the vehicle task, and the data weight represents the data attribute of the vehicle equipment's data.

[0043] In some embodiments, the sum of the device weight and the data weight of the vehicle device can be determined as the data criticality of the vehicle device. Alternatively, weight adjustment coefficients can be assigned to the device weight and the data weight of the vehicle device, and then the data criticality of the vehicle device can be determined based on their respective weight adjustment coefficients, as well as the device weight and the data weight.

[0044] Step S202: Determine the criticality percentage of vehicle equipment based on the data criticality of vehicle equipment.

[0045] In this embodiment of the application, the total data criticality corresponding to multiple vehicle devices can be determined first, and then the proportion of the data criticality of the vehicle devices in the total data criticality can be determined to obtain the criticality proportion.

[0046] In some embodiments, a temperature parameter can be assigned to each vehicle device to adjust the criticality percentage. A larger temperature parameter indicates a smaller impact of data criticality on the device's privacy budget, while a smaller temperature parameter indicates a larger impact of data criticality on the device's privacy budget. For example, the criticality percentage of the vehicle device can be achieved using formula (2): Formula (2); in, This refers to the criticality of data for vehicle equipment J, while M refers to the total number of vehicles and equipment. It is a smoothing constant. This refers to the temperature parameter.

[0047] Step S203: Based on the change intensity information corresponding to the vehicle equipment, determine the change intensity ratio of the vehicle equipment.

[0048] In this embodiment of the application, the sum of the change intensity information corresponding to multiple vehicle devices can be determined first, and then the proportion of the change intensity information of the vehicle devices in the sum of the change intensity information can be determined to obtain the change intensity proportion.

[0049] In some embodiments, a temperature parameter can be assigned to each vehicle device to adjust the percentage of change intensity. A larger temperature parameter indicates a smaller impact of the change intensity information on the device's privacy budget, while a smaller temperature parameter indicates a larger impact. For example, the percentage of change intensity for each vehicle device can be achieved using formula (3): Formula (3); in, This refers to the information on the intensity of changes in vehicle equipment J.

[0050] Step S204: Determine the privacy budget percentage for vehicle equipment based on the criticality percentage and the change intensity percentage.

[0051] In this embodiment of the application, the product of the criticality percentage and the change intensity percentage can be determined as the privacy budget percentage of the vehicle equipment.

[0052] Step S205: Based on the privacy budget percentage and total privacy budget of the vehicle equipment, determine the device privacy budget for the vehicle equipment in the next cycle.

[0053] In this embodiment of the application, the product of the privacy budget percentage and the total privacy budget can be determined as the device privacy budget for the vehicle device in the next cycle.

[0054] In this embodiment, by quantifying the criticality and variability of data, the privacy budget is allocated using both as weighting factors. This allows devices with high criticality and high volatility to receive more precise protection, while devices with low criticality or low volatility have their budget expenditures appropriately reduced. This approach achieves fine-grained resource allocation, avoiding the over-protection or under-protection problems caused by traditional static budget allocation, and improving overall data utilization efficiency and privacy protection levels.

[0055] In some embodiments, step S201 can be implemented by steps S2011 to S2013: Step S2011: Obtain the device weight of the vehicle equipment; the device weight is determined based on the device type of the vehicle equipment and / or the data sensitivity of the device data of the vehicle equipment.

[0056] Here, "device type" refers to the classification of vehicle equipment based on dimensions such as function, purpose, and data output format. "Data sensitivity" refers to the degree to which the equipment data contains user privacy or security-related information. For example, location data, driving behavior data (such as acceleration and emergency braking frequency), and passenger identification information are classified as high-sensitivity data, while data such as wheel speed and battery voltage are classified as low-sensitivity data. As the data sensitivity of vehicle equipment data increases, this indicates a greater need to add noise to differential privacy mechanisms to prevent the leakage of sensitive information within these mechanisms.

[0057] In this embodiment, the device weights of different vehicle devices can be determined in advance based on the device type and / or the data sensitivity of the device data. In actual implementation, there is a certain correlation between device type and data sensitivity. For example, certain types of vehicle devices typically generate data with high sensitivity. Therefore, when determining device weights, it is necessary to comprehensively consider both device type and data sensitivity to avoid bias in the final device weight evaluation result due to evaluation from only a single dimension.

[0058] Step S2012: Determine the data weight of the vehicle equipment based on the data attribute information of the current equipment data of the vehicle equipment.

[0059] Here, data attribute information refers to a set of metadata that describes the specific characteristics of the equipment data of the current vehicle equipment, including but not limited to data type (such as numerical, text, and image), sampling frequency, data update cycle, spatial resolution, timestamp, and data source identifier. Data attribute information can be used to determine the dynamics, volatility, reliability, and correlation between the data and other data.

[0060] Data weight refers to the quantitative assessment of the importance of vehicle equipment data within the current collection period, based on a comprehensive consideration of data attribute information. For example, if the equipment data of a certain vehicle equipment is updated frequently and fluctuates dramatically, then the data weight value of that vehicle equipment is higher, indicating that the trend of the data change in future collection periods is more valuable for reference. Therefore, the data of that vehicle equipment should be given a higher level of protection in the allocation of privacy budget.

[0061] Understandably, by introducing the concept of data weights, the data protection strategies for different vehicle devices can be dynamically adjusted. For example, when a vehicle device collects abnormally fluctuating data in the current period, the data weight of that vehicle device can be temporarily increased, thereby increasing the privacy budget allocation to avoid the loss of critical information due to noise disturbances.

[0062] Step S2013: Determine the data criticality of the vehicle equipment based on the equipment weight and data weight.

[0063] In this embodiment, the sum of the device weight and the data weight can be determined as the data criticality of the vehicle device. In some embodiments, the device weight and the data weight can be weighted and summed to obtain the data criticality of the vehicle device. For example, the above step S2013 can be implemented by formula (4): Formula (4): in, For device weights, For data weights, This is a weighting adjustment parameter used to balance the relative importance of device weights and data weights.

[0064] In this embodiment, data criticality is determined through multiple dimensions such as device type, data sensitivity, and current data attributes, making data criticality more applicable. This method can accurately reflect the importance of device data in specific tasks, providing a more reasonable basis for privacy budget allocation.

[0065] In some embodiments, the above method can also be implemented through steps S11 to S13: Step S11: Obtain the current remaining privacy budget for the current period.

[0066] Here, the current period refers to the ongoing data collection phase, typically defined as a data collection phase at fixed time intervals (e.g., every hour, every 10 minutes). A certain amount of privacy budget can be allocated within each data collection phase for differential privacy protection of the current device data. The current remaining privacy budget refers to the privacy budget remaining after data protection of the current device data collected within the current period. For example, if the privacy budget before data protection of the current device data is A, and data protection of the current device data is performed using privacy budget 1, then the current remaining privacy budget is A - privacy budget 1.

[0067] Step S12: Determine the basic privacy budget for the next previous period based on the current remaining privacy budget and the number of remaining collection periods.

[0068] Here, the number of remaining acquisition cycles refers to the total number of future cycles that have not yet been collected. For example, if it is planned to collect device data for 5 cycles, and the first and second cycles are historical cycles for which data has already been collected, then the number of remaining acquisition cycles would be 3.

[0069] In this embodiment of the application, the ratio of the current remaining privacy budget to the number of remaining collection cycles can be determined as the basic privacy budget for the next cycle.

[0070] In some embodiments, the difference between the current remaining privacy budget and the contingency buffer budget can be determined first, and then the ratio of the difference between the current remaining privacy budget and the contingency buffer budget to the number of remaining collection cycles can be used as the base privacy budget for the next cycle. For example, step S12 can be implemented using formula (5): Formula (5); in, For the current remaining privacy budget, This represents the number of remaining acquisition cycles. For emergency buffer budget.

[0071] Step S13: Determine the total privacy budget for the next cycle based on the basic privacy budget for the next cycle.

[0072] In this embodiment, a preset privacy budget can be added to the basic privacy budget for the next period to obtain the total privacy budget for the next period. This preset privacy budget can be determined based on the data fluctuation information of the predicted device data relative to the current device data of the vehicle device. If the data fluctuation information is greater than a preset value, indicating significant fluctuation in the predicted device data, a smaller preset privacy budget can be determined, resulting in a smaller total privacy budget. Because the total privacy budget is smaller, a smaller device privacy budget can be determined for the next period, thus providing stronger data protection for the significantly fluctuating real device data.

[0073] In this embodiment, a basic privacy budget is determined by the current remaining privacy budget and the remaining number of cycles, and the total privacy budget for the next cycle is derived based on this, ensuring that the overall budget allocation process has global constraints. This approach solves the problem of insufficient privacy budget in subsequent collection cycles due to excessive budget consumption in a certain cycle.

[0074] In some embodiments, such as Figure 3 As shown, step S13 above can be achieved through steps S301 to S303: Step S301: Based on the data fluctuation information corresponding to different vehicle devices, the historical data fluctuation information corresponding to different vehicle devices, and the basic privacy budget for the next period, determine the ideal increase in the privacy budget for the vehicle devices.

[0075] Here, data fluctuation information refers to the average change information of the predicted equipment data of each vehicle equipment relative to the current equipment data of the vehicle equipment. Historical data fluctuation information includes the fluctuation information of the current equipment data of each vehicle equipment relative to the historical equipment data, as well as the fluctuation information between equipment data in adjacent historical periods.

[0076] In this embodiment, the average fluctuation information of different vehicle devices can be determined first based on the data fluctuation information corresponding to different vehicle devices; then, the baseline fluctuation information of different vehicle devices can be determined based on the historical data fluctuation information corresponding to different vehicle devices; finally, the ideal increase in the privacy budget of the vehicle devices can be determined based on the ratio between the average fluctuation information and the baseline fluctuation information, and the basic privacy budget for the next period.

[0077] Step S302: Based on the basic privacy budget for the next cycle, determine the upper limit of the privacy budget for the next cycle.

[0078] In this embodiment, the product between the number of the second period to be executed, including the next period, and the basic privacy budget of the next period can be determined first, and then the difference between the current remaining privacy budget and the product can be determined as the upper limit of the privacy budget corresponding to the next period.

[0079] Understandably, we can first determine the total number of pending execution periods, then determine the total privacy budget for the pending execution periods, and subtract the total privacy budget from the current remaining privacy budget to obtain the upper limit of the privacy budget for the next period.

[0080] Step S303: Based on the minimum between the ideal increase and the upper limit of the privacy budget, and the basic privacy budget for the next period, determine the total amount of the privacy budget for the next period.

[0081] In this embodiment of the application, step S303 can be implemented by formula (6): Formula (6); in, This represents the total privacy budget for the next period, with the baseline being the basic privacy budget for the next period. To increase the quantity to the ideal, A privacy budget cap.

[0082] Understandably, the ideal increase is compared to the privacy budget ceiling, and the smaller of the two is taken as the actual privacy budget increment available for the next cycle. This is because the ideal increase may be a higher value based on predictions, but in practice, it must be constrained by the current cycle's budget ceiling. The final total privacy budget for the next cycle equals the base privacy budget for the current cycle plus this minimum value. This ensures that the privacy budget for the next cycle is neither too high, exceeding affordability, nor too low, impacting data quality. Simultaneously, this mechanism maintains the flexibility and foresight of privacy budget allocation, allowing for dynamic adjustments to protection intensity based on data trends.

[0083] In this embodiment, by comparing the ideal increase with the smaller value of the budget limit, the privacy budget for the next cycle is ensured to meet optimization needs without exceeding security boundaries, thus achieving dynamic adjustment while maintaining overall system controllability. This method effectively solves the problem of resource waste or risk out of control caused by unreasonable budget allocation.

[0084] In some embodiments, step S301 can be implemented by steps S3011 to S3013: Step S3011: Based on the data fluctuation information corresponding to different vehicles and equipment, determine the average fluctuation information of different vehicles and equipment.

[0085] In this embodiment of the application, the sum of data fluctuation information corresponding to different vehicle equipment can be determined first, and then the average fluctuation information of different vehicle equipment can be determined based on the sum of data fluctuation information corresponding to different vehicle equipment and the number of vehicle equipment.

[0086] Step S3012: Based on the historical data fluctuation information corresponding to different vehicles and equipment, determine the benchmark fluctuation information of different vehicles and equipment.

[0087] In this embodiment, the deviation information of the equipment data of two data sampling points corresponding to adjacent period groups of each vehicle equipment is first determined, then the average deviation information of adjacent period groups is determined, and finally the average of the average deviation information corresponding to multiple adjacent period groups is determined to obtain the reference fluctuation information of the vehicle equipment.

[0088] For example, for vehicle equipment 1, the historical period includes period 1, period 2, and period 3. The equipment data in period 1 includes data 1 corresponding to data sampling point 1 and data 2 corresponding to data sampling point 2. The equipment data in period 2 includes data 3 corresponding to data sampling point 1 and data 4 corresponding to data sampling point 2. The equipment data in period 3 includes data 5 corresponding to data sampling point 1 and data 6 corresponding to data sampling point 2. For period 1 and period 2, the deviation information 1 between data 1 and data 3 is determined, the deviation information 2 between data 2 and data 4 is determined, and then the first average deviation information 1 between deviation information 1 and deviation information 2 is determined. For period 2 and period 3, the deviation information 3 between data 3 and data 5 is determined, the deviation information 4 between data 4 and data 6 is determined, and then the first average deviation information 2 between deviation information 3 and deviation information 4 is determined. Then, the average of the average deviation information 1 and the average deviation information 2 is determined to obtain the second average deviation information, and the second average deviation information is determined as the reference fluctuation information of vehicle equipment 1.

[0089] Step S3013: Based on the ratio between the average fluctuation information and the baseline fluctuation information, and the basic privacy budget for the current period, determine the ideal increase in the privacy budget of the vehicle equipment.

[0090] In this embodiment of the application, step S3013 can be implemented by formula (7): Formula (7); in, For average fluctuation information, This serves as the baseline fluctuation information.

[0091] In this embodiment, the ideal increase is dynamically calculated by comparing the ratio of the current average fluctuation information to the historical baseline fluctuation information, making the adjustment of the privacy budget more closely reflect the actual trend of data changes. This method can effectively capture changes in data fluctuation characteristics, providing a scientific basis for budget allocation in the next cycle, and further improving the system's adaptability and decision-making accuracy.

[0092] In some embodiments, step S302 can be implemented by steps S3021 and S3022: Step S3021: Based on the number of remaining collection cycles and the basic privacy budget for the next cycle, determine the total privacy budget for the remaining collection cycles.

[0093] Step S3022: The difference between the current remaining privacy budget and the total privacy budget for the remaining collection period is determined as the upper limit of the privacy budget for the current period.

[0094] In this embodiment of the application, the above steps S3021 and S3022 can be implemented by formula (8): Formula (8); Wherein, baseline is the base privacy budget for the next cycle, R buf R is the emergency buffer budget, and R is the number of remaining acquisition cycles.

[0095] In some embodiments, step S102 may include: inputting the current device data into a time series prediction model to obtain the predicted device data corresponding to each data sampling point in the next period, and the prediction confidence level corresponding to each predicted device data.

[0096] In some embodiments, step S105 can be achieved by formula (9): Formula (9); in, For vehicle equipment The data obtained after data protection is applied to the actual device data. For vehicle equipment The statistical values ​​of multiple real device data for the next period. This indicates that the value follows a mean of 0, and the scale parameter is... The Laplace distribution random noise. For example, this statistic can be one of the mean, sum, or variance of multiple real device data for the next period.

[0097] In this embodiment of the application, the scale parameter is implemented by formula (10): Formula (10); in, For vehicle equipment In the next cycle's device privacy budget, For vehicle equipment The maximum impact of a change in a single data point on the statistical results.

[0098] The following describes the application of the vehicle data protection method provided in this application in a real-world scenario: To address the technical problems existing in related technologies, such as the inability of fixed budget allocation methods to flexibly adjust privacy expenditures according to dynamic data changes, which can easily lead to loss of accuracy or excessive consumption of privacy budgets in highly volatile data, and the general lack of forward-looking modeling of future data change trends in existing privacy protection methods, which prevents the system from proactively detecting potential high-risk stages before data collection, resulting in lagging privacy budget allocation and rigid protection strategies, this application provides a method for protecting vehicle data, which can be implemented through steps S401 to S405: Step S401: In the multi-source data acquisition stage, heterogeneous vehicle data from different sources are acquired and recorded in real time according to the preset acquisition strategy.

[0099] In this embodiment, the data acquisition strategy includes parameters such as sampling frequency, triggering conditions, priority, and data caching and uploading methods to achieve an efficient, low-latency, and controllable data acquisition process. The multi-source heterogeneous data mainly includes three types of information: first, vehicle driving safety data, collected by onboard sensors and control units; second, roadside perception data, collected through sensing devices installed on road infrastructure; and third, cloud data, originating from traffic management platforms or cloud data service interfaces. All types of data are accompanied by timestamps, data source identifiers, and spatial location information during the acquisition process to support subsequent time synchronization and multi-source fusion processing.

[0100] Step S402: Perform data preprocessing on the original multi-source heterogeneous data.

[0101] In this embodiment, after acquiring raw multi-source heterogeneous data, it needs to be processed. Heterogeneous data fusion is used to preprocess and perform time synchronization fusion on the acquired raw data. Data preprocessing mainly includes three core steps: data cleaning, format conversion, and data calibration. Data cleaning aims to identify and remove noise, duplicates, and invalid records from the raw data to improve its accuracy and completeness. Format conversion converts the raw data from heterogeneous sensors into a standardized format for consistent execution of subsequent processing. Data calibration focuses on eliminating inherent systematic errors and biases of different sensors to ensure the reliability of the acquired data. After preprocessing, time synchronization fusion is performed. This process first systematically acquires the timestamp information corresponding to the data from each sensor. Then, using the maximum time coverage as a time reference benchmark, its timestamp is defined as the reference time point. For data sequences from other sensors, based on the time difference between their timestamps and the reference reference point, an interpolation algorithm is applied to reconstruct their equivalent data values ​​at the reference time point. Through the above interpolation operations, a strictly synchronized dataset of all sensors at the unified reference time point is finally generated.

[0102] Step S403: Analyze the historical data time series obtained after prediction processing using the Prophet model to obtain the future data time series within the future collection period.

[0103] In this embodiment, a Prophet model is constructed to predict collected data in future periods, effectively capturing seasonality, holiday effects, and long-term trends in the data. The Prophet model is a time series forecasting model based on additive trend model and decomposition method, which decomposes the time series into key components such as trend, seasonality, and holidays, thereby achieving high-precision forecasting. The process is represented by formula (11): Formula (11); in, This represents the trend term, used to characterize the inherent non-periodic long-term evolutionary pattern in the sequence; This indicates a seasonal term, used to capture predictable, recurring fluctuations caused by periodic factors such as day / night, week, or seasonal cycles. The holiday item is used to characterize transient effects associated with specific calendar events, such as statutory holidays or special events. This represents the residual term, used to capture random noise or irregular fluctuations that the structured components above cannot explain. The trend term... Seasonal items and holiday items Together, they constitute the key interpretable factors driving changes in historical data sequences.

[0104] In this embodiment of the application, the trend item The model is based on either a logistic regression function or a piecewise linear function. The logistic regression function simulates growth using an S-shaped curve, suitable for scenarios with physical limits or natural growth bottlenecks. For example, predicting the long-term operating temperature trend of a car engine: the engine temperature rises slowly during cold starts, rapidly increases to the ideal range after normal operation, and then significantly decreases due to the intervention of the cooling system when approaching the design threshold, generally conforming to the logic of S-shaped saturated growth. The piecewise linear function simulates the trend by connecting multiple linear segments, allowing for sudden changes in the growth rate at specific points in time, suitable for data affected by sudden events or external interventions. For example, predicting the traffic flow rate at highway toll stations: traffic flow is stable during normal periods, but when the roadside sensing system detects a traffic accident, control measures cause a sharp drop in traffic flow rate, and after the accident is resolved, traffic flow policies cause a rapid rebound. Such step changes require a piecewise linear model to accurately capture. The logistic regression function is expressed by formula (12): Formula (12); in, Indicates time The capacity for change represents the limit that a time series may reach when it tends to stabilize in the long run; Indicates the growth rate; This indicates the growth offset point.

[0105] In this embodiment, the piecewise linear function is represented by formula (13): Formula (13); in, This represents the transpose operator; Indicates time The variable point indicator vector; Represents the growth rate adjustment vector; This represents the offset compensation vector. The predictive performance of the logistic regression function or the piecewise linear function is compared using cross-validation. Based on the predictive performance, the logistic regression function or the piecewise linear function is selected for the trend term. calculate.

[0106] In this embodiment of the application, the seasonal term is represented by formula (14): Formula (14); in, The number of parameters; and The Fourier coefficients determine the amplitude and phase of seasonal fluctuations; Indicates the length of the seasonal cycle.

[0107] In this embodiment of the application, the holiday item is represented by formula (15): Formula (15); in, The initialization is , The standard deviation represents the normal distribution; the larger the value, the more pronounced the seasonal effect.

[0108] In this embodiment, after the Prophet model completes fitting and prediction, it outputs the future data time series and model confidence for each device in the historical data time series, respectively, to support the dynamic allocation of the subsequent privacy budget. Assume there are a total of... There are 1 data source (device), denoted as _____. For each device The Prophet model will be used in future data collection cycles. The internal output is a future data time series, which is represented by formula (16): Formula (16); in, Indicates equipment In time The predicted data values.

[0109] The Prophet model also outputs the model confidence score for each prediction point, which is expressed by formula (17): Formula (17); in, , respectively equipment In time The width of the upper and lower confidence intervals for prediction. To prevent extremely small constants with a denominator of zero, this confidence level is used to measure the reliability of the model's prediction results for that time point; a higher value indicates a more stable prediction. To obtain the overall prediction confidence level of the equipment, the confidence levels at each time point are averaged to obtain the overall confidence index, which is expressed by formula (18): Formula (18); in, This represents the predicted time steps within the future data collection period. Confidence level. The higher the value, the better the model is for the device. The more stable and reliable the future trend predictions, the better.

[0110] Step S404: Allocate differential privacy budgets for future collection cycles based on future data time series.

[0111] In this embodiment, differential privacy budgets are allocated to different data sources based on the future data time series within the future collection period, achieving an adaptive balance between privacy protection and data availability. The differential privacy budget can be obtained using formula (19): Formula (19); in, Indicates allocation to device The differential privacy budget value (i.e., the device privacy budget in the next cycle in the above embodiments); This refers to the change intensity factor (i.e., the change intensity information in the above embodiments). This is the global privacy constraint factor (i.e., the total privacy budget corresponding to the next cycle in the above embodiments). This is the data importance factor (i.e., the data criticality in the above embodiments). Represents the smoothing constant. As a temperature parameter, the concentration of budget allocation is controlled. When the system is at high risk, the following is set: <1. To concentrate the budget on key equipment. It can dynamically and adaptively adjust according to the cycle to achieve flexible and intelligent privacy protection.

[0112] In this embodiment of the application, the differential privacy budget value is determined by three main factors: First, the intensity of change factor The strength of future data fluctuations and the confidence level of the prediction are calculated together by the prediction model output to reflect the equipment's performance. The criticality of data changes and the reliability of predictions; Secondly, global privacy constraint factors This is used to limit the total amount of privacy budget available in future collection cycles, so as to avoid over-allocation leading to insufficient privacy budget in subsequent collection cycles. Third, data importance factor This is used to characterize the criticality of data from each acquisition device in the system task. Through this dynamic allocation mechanism, the privacy budget can be adaptively and optimally configured based on the future data change characteristics and task importance of each device, thereby improving the overall accuracy of data dissemination while ensuring privacy.

[0113] In this embodiment of the application, the change intensity factor can be achieved by the above formula (1).

[0114] In this embodiment, when the confidence level is high, the predicted volatility information is more reliable, and the change intensity factor is mainly dominated by volatility; when the confidence level is low, the prediction uncertainty is greater, and the change intensity factor will be weakened accordingly to reduce the interference of low-confidence predictions on privacy budget allocation. Ultimately, the change intensity factor... This comprehensively reflects the "reliable volatility" of data from various devices within the future collection cycle, providing basic input parameters for the dynamic privacy budget allocation algorithm. This ensures that the budget allocation process can both perceive future data change trends and take into account the reliability of the prediction results.

[0115] In this embodiment of the application, the global privacy constraint factor This can be achieved using the formula (6) above.

[0116] In this embodiment of the application, through the above mechanism, the system first determines the basic guarantee budget based on the remaining budget and the number of cycles in each data collection cycle. Then, the ideal increase is dynamically calculated based on the fluctuation ratio. and the available upper limit The smaller value is chosen to ensure that the allocation in the current period improves the data quality during critical periods without affecting the budget allocation balance in subsequent periods.

[0117] In this embodiment of the application, the data importance factor This is achieved through formula (4).

[0118] In this embodiment of the application, through the aforementioned dynamic privacy budget allocation mechanism based on multi-factor fusion, the system ultimately allocates privacy budgets to each data acquisition device. Output its unique, optimized differential privacy budget value for that collection period. .

[0119] Step S405: For the real data collected from each data source within the future collection period, perform differential privacy noise injection and secure release operations on the data statistics of the real data based on the dynamically allocated privacy budget value.

[0120] In this embodiment of the application, step S405 can be implemented by the above formula (9).

[0121] In some embodiments, after noise injection is completed, the resulting noise statistics are stored in an encrypted manner in a local database or cloud data center for subsequent data analysis, modeling, and anomaly detection. Simultaneously, the system records the budget usage and noise parameters for the current data collection period, providing feedback for dynamic adjustment of the privacy budget and model prediction in the next period.

[0122] Through the above steps, the system securely publishes real statistical data while ensuring differential privacy constraints. It effectively prevents privacy leaks while maximizing data availability, achieving an adaptive balance between privacy protection and data quality.

[0123] The vehicle data protection method provided in this application can achieve the following technical effects: 1. By introducing time series prediction models into the differential privacy budget allocation process, the Prophet model is constructed to decompose multi-source heterogeneous vehicle data into time series, dynamically decomposing features into trend term g(t), seasonal term s(t), and holiday term h(t), thus estimating data changes in future collection periods in advance and achieving "prediction-driven" privacy budget regulation.

[0124] 2. A privacy budget allocation mechanism based on multi-factor fusion comprehensively considers data volatility, prediction confidence, remaining privacy budget, and task criticality, achieving fine-grained dynamic optimal allocation. Specifically, the intensity of change factor reflects the future reliability and volatility of the data, the global constraint factor ensures a balanced allocation of the privacy budget across multiple periods, and the data importance factor introduces task-level weights, ensuring that resource allocation balances privacy security and task value. An interpretable, adjustable, and highly adaptive privacy budget allocation framework is constructed, significantly improving the dynamic coordination between data utilization efficiency and privacy protection.

[0125] In some embodiments, such as Figure 4 As shown, this application embodiment provides a vehicle data protection device 400, which includes an acquisition module 401, a prediction module 402, a first determination module 403, a first determination module 404, and a protection module 405; wherein: The acquisition module 401 is used to acquire current device data of different vehicle devices collected in the current period; Prediction module 402 is used to predict the predicted data of different vehicle equipment collected in the next cycle based on the current equipment data; The first determining module 403 is used to determine the change intensity information corresponding to different vehicle equipment based on the prediction data of different vehicle equipment and the current equipment data of different vehicle equipment; the change intensity information is used to characterize the prediction reliability of the prediction data of vehicle equipment. The second determining module 404 is used to determine the device privacy budget of each vehicle device in the next cycle based on the change intensity information of the vehicle device and the total privacy budget of the next cycle. The protection module 405 is used to protect the real device data of different vehicle devices collected in the next cycle based on the device privacy budget corresponding to different vehicle devices.

[0126] In some embodiments, the prediction data includes prediction device data and prediction confidence for the prediction device data; for each vehicle device, the first determining module 403 is further configured to determine data fluctuation information of the prediction device data of the vehicle device relative to the current device data of the vehicle device; and based on the data fluctuation information of the vehicle device and the prediction confidence for the prediction device data, determine the change intensity information of the vehicle device.

[0127] In some embodiments, the second determining module 404 is further configured to determine the data criticality of the vehicle equipment; the data criticality is used to characterize the criticality of the equipment data of the vehicle equipment in the vehicle task; based on the data criticality of the vehicle equipment, determine the criticality percentage of the vehicle equipment; based on the change intensity information corresponding to the vehicle equipment, determine the change intensity percentage of the vehicle equipment; based on the criticality percentage and the change intensity percentage, determine the privacy budget percentage of the vehicle equipment; based on the privacy budget percentage of the vehicle equipment and the total privacy budget, determine the equipment privacy budget of the vehicle equipment in the next cycle.

[0128] In some embodiments, the second determining module 404 is further configured to obtain the device weight of the vehicle device; the device weight is determined based on the device type of the vehicle device and / or the data sensitivity of the device data of the vehicle device; the data weight of the vehicle device is determined based on the data attribute information of the current device data of the vehicle device; and the data criticality of the vehicle device is determined based on the device weight and the data weight.

[0129] In some embodiments, the vehicle data protection device 400 further includes a third determining module 405, which is used to obtain the current remaining privacy budget corresponding to the current period; determine the basic privacy budget for the next period based on the current remaining privacy budget and the number of remaining collection periods; and determine the total privacy budget corresponding to the next period based on the basic privacy budget for the next period.

[0130] In some embodiments, the third determining module 405 is further configured to determine the ideal increase in the privacy budget of the vehicle equipment based on the data fluctuation information corresponding to different vehicle equipment, the historical data fluctuation information corresponding to different vehicle equipment, and the basic privacy budget for the next period; determine the upper limit of the privacy budget for the next period based on the basic privacy budget for the next period; and determine the total amount of the privacy budget for the next period based on the minimum value between the ideal increase and the upper limit of the privacy budget, and the basic privacy budget for the next period.

[0131] In some embodiments, the third determining module 405 is further configured to determine the average fluctuation information of different vehicle devices based on the data fluctuation information corresponding to different vehicle devices; determine the baseline fluctuation information of different vehicle devices based on the historical data fluctuation information corresponding to different vehicle devices; and determine the ideal increase in the privacy budget of the vehicle devices based on the ratio between the average fluctuation information and the baseline fluctuation information, and the basic privacy budget for the next period.

[0132] In some embodiments, the third determining module 405 is further configured to determine the total privacy budget for the period to be executed based on the number of remaining collection periods and the basic privacy budget for the next period; and to determine the difference between the current remaining privacy budget and the total privacy budget for the period to be executed as the upper limit of the privacy budget for the next period.

[0133] The descriptions of the apparatus embodiments above are similar to those of the method embodiments above, and have similar beneficial effects. In some embodiments, the functions or modules included in the apparatus provided in this disclosure can be used to perform the methods described in the method embodiments above. For technical details not disclosed in the apparatus embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0134] It should be noted that, in the embodiments of this application, if the above-described data processing method is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of this application, or the part that contributes to the related technology, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, mobile hard drives, read-only memory (ROM), magnetic disks, or optical disks. Thus, the embodiments of this application are not limited to any specific hardware, software, or firmware, or any combination of hardware, software, and firmware.

[0135] This application provides a computer device including a memory and a processor. The memory stores a computer program that can run on the processor. When the processor executes the program, it implements some or all of the steps in the above-described method.

[0136] This application provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements some or all of the steps in the above-described method. The computer-readable storage medium can be transient or non-transient.

[0137] This application provides a computer program including computer-readable code. When the computer-readable code is run in a computer device, the processor in the computer device performs some or all of the steps for implementing the above-described method.

[0138] This application provides a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program. When the computer program is read and executed by a computer, it implements some or all of the steps in the above-described method. This computer program product can be implemented specifically through hardware, software, or a combination thereof. In some embodiments, the computer program product is specifically embodied as a computer storage medium; in other embodiments, the computer program product is specifically embodied as a software product, such as a software development kit (SDK), etc.

[0139] It should be noted that the descriptions of the various embodiments above tend to emphasize the differences between them, while their similarities or commonalities can be referred to interchangeably. The descriptions of the above embodiments of the device, storage medium, computer program, and computer program product are similar to the descriptions of the above method embodiments and have similar beneficial effects. For technical details not disclosed in the embodiments of the device, storage medium, computer program, and computer program product of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0140] Figure 5 A schematic diagram of the composition structure of a vehicle data protection device 500 provided in this application embodiment is shown below. Figure 5 As shown, the device includes: a processor 501, a communication interface 502, and a memory 503, wherein: The processor 501 typically controls the overall operation of the vehicle data protection device 500, which may implement the vehicle data protection method provided in the embodiments of this application.

[0141] The communication interface 502 enables the vehicle data protection device 500 to communicate with other terminals or servers via a network.

[0142] The memory 503 is configured to store instructions and applications executable by the processor 501, and can also cache data to be processed or already processed (e.g., image data, audio data, voice communication data, and video communication data) from various modules in the processor 501 and the vehicle data protection device 500. It can be implemented using flash memory or random access memory (RAM). Data transfer between the processor 501, the communication interface 502, and the memory 503 can be performed via bus 504.

[0143] This application provides a computer program product or computer program that includes computer instructions stored in a readable storage medium. A processor of a computer device reads the computer instructions from the readable storage medium and executes the computer instructions, causing the computer device to perform the vehicle data protection method described above in this application.

[0144] This application provides a readable storage medium storing executable instructions, wherein the executable instructions, when executed by a processor, will cause the processor to execute the vehicle data protection method provided in this application.

[0145] It should be noted that the descriptions of the storage medium and device embodiments above are similar to the descriptions of the method embodiments above, and have similar beneficial effects. For technical details not disclosed in the storage medium and device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0146] The aforementioned processor can be at least one of the following: Application Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array (FPGA), Central Processing Unit (CPU), Controller, Microcontroller, and Microprocessor. It is understood that other electronic devices can also implement the functions of the aforementioned processor, and this application does not specifically limit the specific implementation.

[0147] The aforementioned computer storage media / memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM), etc.; or it can be various terminals that include one or any combination of the above-mentioned memories, such as mobile phones, computers, tablet devices, personal digital assistants, etc.

[0148] It should be understood that the phrase "one embodiment" or "an embodiment" throughout the specification means that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of this application. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. It should be understood that in the various embodiments of this application, the sequence numbers of the above steps / processes do not imply a sequential order of execution; the execution order of each step / process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application. The sequence numbers of the above embodiments of this application are merely descriptive and do not represent the superiority or inferiority of the embodiments.

[0149] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0150] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or units can be electrical, mechanical, or other forms.

[0151] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units. They may be located in one place or distributed across multiple network units. Some or all of the units may be selected to achieve the purpose of this embodiment according to actual needs.

[0152] In addition, each functional unit in the various embodiments of this application can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in hardware or in the form of hardware plus software functional units.

[0153] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media that can store program code, such as mobile storage devices, read-only memory (ROM), magnetic disks, or optical disks.

[0154] Alternatively, if the integrated units described above are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, or the part that contributes to related technologies, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROM, magnetic disks, or optical disks.

[0155] The above description is merely an embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application.

Claims

1. A method for protecting vehicle data, characterized in that, The method for protecting the vehicle data includes: Acquire current device data from different vehicle devices collected in the current period; Based on the current device data, predict the predicted data for different vehicle devices to be collected in the next cycle; Based on the predicted data of the different vehicle equipment and the current equipment data of the different vehicle equipment, the change intensity information corresponding to the different vehicle equipment is determined; the change intensity information is used to characterize the prediction reliability of the predicted data of the vehicle equipment. For each of the vehicle devices, the device privacy budget for the vehicle device in the next period is determined based on the change intensity information corresponding to the vehicle device and the total privacy budget corresponding to the next period. Based on the device privacy budget corresponding to the different vehicle devices, data protection is implemented for the real device data of the different vehicle devices collected in the next cycle.

2. The method for protecting vehicle data according to claim 1, characterized in that, The prediction data includes prediction device data and prediction confidence levels for the prediction device data; for each vehicle device, determining the change intensity information corresponding to each vehicle device based on the prediction data of the different vehicle devices and the current device data of the different vehicle devices includes: Determine the data fluctuation information of the predicted equipment data of the vehicle equipment relative to the current equipment data of the vehicle equipment; Based on the data fluctuation information of the vehicle equipment and the prediction confidence level of the prediction equipment data, the change intensity information of the vehicle equipment is determined.

3. The method for protecting vehicle data according to claim 1 or 2, characterized in that, The process of determining the device privacy budget for the vehicle equipment in the next period based on the change intensity information corresponding to the vehicle equipment and the total privacy budget for the next period includes: Determine the data criticality of the vehicle equipment; the data criticality is used to characterize the degree of importance of the equipment data of the vehicle equipment in the vehicle mission; Based on the data criticality of the vehicle equipment, the criticality percentage of the vehicle equipment is determined; Based on the change intensity information corresponding to the vehicle equipment, the change intensity ratio of the vehicle equipment is determined; Based on the criticality percentage and the change intensity percentage, the privacy budget percentage of the vehicle equipment is determined; Based on the privacy budget percentage of the vehicle equipment and the total privacy budget, the device privacy budget for the vehicle equipment in the next cycle is determined.

4. The method for protecting vehicle data according to claim 3, characterized in that, Determining the data criticality of the vehicle equipment includes: Obtain the device weight of the vehicle equipment; the device weight is determined based on the device type of the vehicle equipment and / or the data sensitivity of the device data of the vehicle equipment. Based on the data attribute information of the current equipment data of the vehicle equipment, the data weight of the vehicle equipment is determined; The data criticality of the vehicle equipment is determined based on the device weight and the data weight.

5. The method for protecting vehicle data according to claim 2, characterized in that, The method further includes: Obtain the current remaining privacy budget corresponding to the current period; Based on the current remaining privacy budget and the number of remaining collection cycles, the basic privacy budget for the next cycle is determined; Based on the basic privacy budget for the next cycle, determine the total privacy budget for the next cycle.

6. The method for protecting vehicle data according to claim 5, characterized in that, The determination of the total privacy budget for the next period based on the basic privacy budget for the next period includes: Based on the data fluctuation information corresponding to different vehicle devices, the historical data fluctuation information corresponding to different vehicle devices, and the basic privacy budget for the next period, the ideal increase in the privacy budget of the vehicle device is determined. Based on the basic privacy budget for the next cycle, determine the upper limit of the privacy budget for the next cycle; The total privacy budget for the next period is determined based on the minimum between the ideal increase and the upper limit of the privacy budget, and the base privacy budget for the next period.

7. The method for protecting vehicle data according to claim 6, characterized in that, The determination of the ideal increase in the privacy budget for each vehicle device, based on the data fluctuation information corresponding to different vehicle devices, the historical data fluctuation information corresponding to different vehicle devices, and the basic privacy budget for the next period, includes: Based on the data fluctuation information corresponding to different vehicle equipment, the average fluctuation information of the different vehicle equipment is determined. Based on the historical data fluctuation information corresponding to different vehicle equipment, the baseline fluctuation information of the different vehicle equipment is determined. Based on the ratio between the average fluctuation information and the baseline fluctuation information, and the basic privacy budget for the next period, the ideal increase in the privacy budget of the vehicle equipment is determined.

8. The method for protecting vehicle data according to claim 6, characterized in that, The determination of the upper limit of the privacy budget for the next period based on the basic privacy budget for the next period includes: Based on the number of remaining collection cycles and the basic privacy budget for the next cycle, the total privacy budget for the remaining collection cycles is determined. The difference between the current remaining privacy budget and the total privacy budget for the remaining collection period is determined as the upper limit of the privacy budget for the next period.

9. A vehicle data protection device, characterized in that, The vehicle data protection device includes: The acquisition module is used to acquire current device data from different vehicle devices collected in the current period; The prediction module is used to predict the predicted data of different vehicle devices collected in the next cycle based on the current device data; The first determining module is used to determine the change intensity information corresponding to different vehicle equipment based on the prediction data of the different vehicle equipment and the current equipment data of the different vehicle equipment; the change intensity information is used to characterize the prediction reliability of the prediction data of the vehicle equipment. The second determining module is used to determine the device privacy budget of each vehicle device in the next cycle based on the change intensity information corresponding to the vehicle device and the total privacy budget corresponding to the next cycle. The protection module is used to protect the real device data of different vehicle devices collected in the next cycle based on the device privacy budget corresponding to the different vehicle devices.

10. A vehicle data protection device, the protection device comprising a processor and a memory storing instructions executable by the processor; characterized in that, When the instructions are executed by the processor, the method described in any one of claims 1 to 8 is implemented.