River trajectory data protection method based on differential privacy

By extracting the spatiotemporal features of river trajectories using graph convolutional networks and combining a dual decay factor and a dynamic Markov generation method, the problems of preserving the spatiotemporal characteristics and allocating the privacy budget for river trajectory data under differential privacy are solved, achieving an efficient balance between privacy protection and data utilization.

CN121479829APending Publication Date: 2026-02-06TIANJIN POLYTECHNIC UNIV
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511635011.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-10
Publication Date
2026-02-06

AI Technical Summary

Technical Problem

Existing differential privacy methods, when applied to river trajectory data, cannot effectively maintain spatiotemporal statistical characteristics and are difficult to adaptively allocate privacy budgets in differentiated regions, resulting in loss of data utility and the risk of privacy leakage.

Method used

Graph Convolutional Networks (GCNs) are used to extract the spatiotemporal features of river trajectories. A dual decay factor model is combined to allocate a differentiated privacy budget. Dynamic Markov generation and differential privacy mechanisms are used to generate synthetic trajectories. A balance between privacy protection and data utility is achieved through multi-index evaluation.

Benefits of technology

It effectively preserves the spatiotemporal statistical characteristics of river tracks, achieves strong privacy protection in high-frequency and high-density areas, and maintains high data availability in low-sensitivity areas, reduces noise errors, and improves the privacy and availability of data release.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121479829A_ABST
    Figure CN121479829A_ABST
Patent Text Reader

Abstract

The invention provides a river trajectory data protection method based on differential privacy, and belongs to the field of environmental data privacy protection. According to the method, river flow velocity and flow direction data are discretized into a two-dimensional grid, spatial-temporal characteristics are extracted by using a graph convolutional network (GCN), and a Markov transfer matrix is established; and according to the grid access frequency and the spatial density, privacy budget is adaptively allocated through a dual attenuation factor model, and differential privacy protection is realized. In the trajectory generation stage, dynamic privacy budget is combined, noise is injected into direction and time features by adopting an index mechanism and a Laplace mechanism, and a synthetic trajectory conforming to physical constraints is generated; and finally, evaluating and optimizing the track quality by using Savitzky-Golay filtering and multiple indexes (such as Frechet distance, access frequency error and KL divergence). According to the method, the privacy leakage risk is effectively reduced while the space-time continuity of the trajectory is kept, the data privacy and availability are considered, and the method is suitable for hydrological monitoring, ecological analysis and environmental data sharing.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the field of environmental data privacy protection and data publishing, and particularly relates to a differential privacy protection method for river trajectory (flow velocity and flow direction) data, and particularly relates to a synthetic trajectory generation and quality evaluation method combining a graph convolution network (GCN), adaptive privacy budget allocation and Markov generation. BACKGROUND

[0002] With the wide application of environmental monitoring and hydrological modeling, river flow velocity and flow direction trajectory data have important value in flood warning, water resource management and ecological research. However, such data often involve sensitive location information or exposure rate statistics for specific locations, and when the original trajectory data is published, there may be a risk of privacy or sensitive information leakage. Differential privacy (DP) as a theoretical privacy protection framework controls the probability of privacy leakage by injecting noise into published data or query results, and has been applied in the fields of location data and user trajectory. However, direct application of existing differential privacy methods to river trajectory data faces the following challenges: 1. River trajectory has obvious spatiotemporal dependence and physical constraints, and simple point-by-point perturbation can severely damage data utility; 2. River data has high-frequency access areas (such as river section hubs) and low-frequency areas in space, and a uniform noise strategy cannot meet the differentiated privacy needs; 3. In a dynamic environment, river flow direction and flow velocity change significantly over time, and privacy budget needs to be adaptively allocated over time and features to balance utility and privacy.

[0003] Therefore, there is an urgent need for a method that can maintain the spatiotemporal statistical properties of river trajectory data while adaptively allocating privacy budget under differential privacy constraints and generating high-quality synthetic trajectory data. SUMMARY

[0004] The purpose of the present application is to provide a differential privacy-based river trajectory data protection method, which discretizes the original flow velocity and flow direction data into a two-dimensional grid, extracts spatiotemporal features based on a graph convolution network (GCN), allocates differentiated privacy budget using a double decay factor model, and generates synthetic trajectory data using dynamic Markov and exponential / Laplacian mechanisms to inject noise. Finally, the optimal balance between privacy protection and data utility is achieved through time domain / spatial domain smoothing and multi-index evaluation, thereby improving the privacy and usability of published data.

[0005] The specific steps are as follows: S1 discretize the river flow velocity and flow direction data into a two-dimensional grid, extract spatiotemporal features using a graph convolution network (GCN), and establish an initial transition matrix; S2 According to the access frequency and spatial density of each grid, a double decay factor model is used to dynamically allocate privacy budget, realizing differentiated privacy protection; S3 Based on the dynamic privacy budget, a Markov transition matrix is used to generate a synthetic trajectory, and differential privacy noise is injected into the direction and time characteristics through the exponential mechanism and the Laplace mechanism respectively; S4 Savitzky-Golay filter is used for time domain smoothing, and multiple indicators such as Fréchet distance and access frequency error are used to evaluate the quality, realizing the optimal balance between privacy protection and data utility.

[0006] Further, step S1 specifically includes: S11 Collect original flow rate and flow direction time series data from river monitoring stations, and perform time alignment, missing value interpolation, anomaly detection and normalization processing to form clean time series data set ; S12 Quantize data according to the preset discretization interval: flow rate is divided into 15 levels with a step size of , and flow direction is divided into 8 levels with a step size of , forming a state space composed of 120 discrete states; S13 Combine speed levels and direction levels into a 15x8 two-dimensional grid, each grid cell corresponds to a unique state identifier , and an adjacency matrix is constructed according to the spatial adjacency relationship ; map the cleaned sequence to this grid system to obtain the grid trajectory sequence; S14 Traverse the grid trajectory sequence, and count the access frequency , residence time (total continuous access time), and state transition times of each grid, and calculate the spatial density (the average access frequency of the neighborhood), thereby obtaining four key feature vectors for subsequent processing; S15 Take the initial feature matrix composed of access frequency, residence time, spatial density and other statistical indicators as input, and learn the spatio-temporal dependence features of nodes on the adjacency matrix through 2-3 layers of GCN; at the same time, normalize the state transition count matrix to obtain the Markov transition probability matrix , and output the high-dimensional GCN feature representation and transition probability matrix .

[0007] Further, step S2 specifically includes: S21 Based on the access frequency of each grid, a frequency inverse model

[0008] wherein, : the initial privacy budget of the i-th grid cell, representing the intensity of privacy protection allocated to this region in the differential privacy mechanism, the smaller the value, the stronger the protection; : the visit frequency of the grid, i.e., the proportion of the number of sampling points falling into this grid in the total number of trajectory points.

[0009] The privacy budget is initially allocated so that the grid with high visit frequency obtains a lower privacy budget (to enhance privacy protection) and the grid with low visit frequency obtains a higher budget (to maintain data utility).

[0010] S22 On the basis of the initial budget, a frequency decay factor

[0011] wherein, is the frequency decay factor, used to further suppress the privacy budget value of the high visit frequency region; : the natural logarithm function, used to moderate the difference amplitude between different visit frequencies; : as above, representing the visit frequency of the grid.

[0012] and the spatial density decay factor

[0013] wherein, : the spatial density decay factor, used to adjust the privacy budget according to the crowdedness (neighborhood density) of the surrounding region; : the spatial density, representing the average or weighted average of visit frequency in the neighborhood of the grid; and the three are multiplied to determine the final privacy budget:

[0014] : the final privacy budget of the i-th grid; : the base privacy budget, which is the upper limit of the global initial budget set by the system, generally selected according to the data sensitivity; : the frequency decay factor, see formula (2); : the spatial density decay factor, see formula (3).​​

[0015] S23 KNN-based hierarchical clustering is adopted for 120 grids, and the optimal cluster number is determined by the weighted sum of Silhouette score and Calinski-Harabasz index ; In each cluster, the node with the highest average similarity to other nodes in the cluster is selected as the core point (Core Points), and the nodes with lower similarity are marked as the confuse set (Confuse-Set); S24 Real-time monitoring of direction change amplitude during trajectory generation , when the corresponding privacy budget is increased to reduce noise error when the direction change is gentle, the exponential mechanism is preferred to save the budget for critical moments, realizing dynamic optimization of privacy budget and accurate protection of flow characteristics change.

[0016] Further, step S3 specifically includes: S31 Based on a dynamic Markov trajectory generation model is constructed, and a transition probability matrix is used as the state transition kernel function; in each state transition, a differential privacy mechanism is called; S32 The direction change is disturbed by the exponential mechanism, and the disturbance probability is defined as:

[0017] wherein is the privacy parameter or disturbance intensity coefficient of the exponential mechanism, and U(D, Δθ_i) is the utility function of the direction transition; S33 The Laplace mechanism is used to inject noise for the residence time and flow rate, and the observation value disturbance form is:

[0018] wherein , is the sensitivity of the corresponding feature; S34 A set of trajectory sequences under differential privacy constraints is generated by multiple random sampling, so that the synthesized trajectory is approximately distributed as the original data in global statistics (average flow direction, transition probability, and access frequency); S35 The generated trajectory is post-processed to remove physically infeasible isolated states and reverse flow points, ensuring that the trajectory meets the physical constraints such as topological constraints.

[0019] Further, step S4 specifically includes: S41 In the time domain, Savitzky-Golay filter is used to smooth the synthesized trajectory to remove high-frequency noise and retain trend information; S42 Position smoothing in spatial domain using bidirectional neighborhood averaging method to ensure trajectory continuity and direction stability; S43 Multi-index evaluation of the quality of the synthesized trajectory, including but not limited to: a) Fréchet distance (FrD) - measures the similarity of spatio-temporal shapes; b) Access frequency error (AFE) - measures the deviation of spatial distribution; c) Transition matrix KL divergence (D_KL) - evaluates the consistency of state transition distribution; d) Privacy loss function - verify that the global privacy constraint meets the definition of differential privacy.

[0020] S44 Determine the output quality based on the multi-index comprehensive score; when the comprehensive score is lower than the threshold , automatically adjust the privacy budget allocation parameters and noise scale , and re-execute steps S2-S3 until the utility-privacy equilibrium condition is met; S45 Output the river trajectory dataset protected by differential privacy for safe use by downstream hydrological, ecological or prediction models.

[0021] Compared with the prior art, the present application has the following beneficial effects: 1. Combined with the spatio-temporal feature learning of GCN, the spatio-temporal statistical characteristics of river trajectory are effectively preserved, so that a higher data utility can be maintained after injecting differential privacy noise; 2. A double attenuation factor (frequency attenuation and density attenuation) and a dynamic budget adjustment mechanism are proposed to achieve stronger privacy protection in high-frequency and high-density sensitive areas, while preserving higher data availability in low-sensitive areas; 3. In the trajectory generation, a dynamic Markov and differential privacy mechanism (exponential mechanism for direction and Laplace for time / flow rate) is used to balance the privacy protection needs of probability structure and continuous features; 4. A closed-loop mechanism of filtering and multi-index quality evaluation is introduced to realize automatic adjustment of privacy-utility, enhancing the robustness and controllability of the method. BRIEF DESCRIPTION OF DRAWINGS

[0022] In order to facilitate the understanding of the embodiments of the present application, the drawings used in the description are briefly described as follows: Figure 1 is a schematic diagram of the overall architecture and flow of DiffRiver; Figure 2 is a comparison chart of trajectory length difference / length difference under different schemes; Figure 3 is a Frechet distance heat map; Figure 4 is a residence time difference heat map; Figure 5. Heatmap of access frequency error; Figure 6. Bar chart comparing the overall performance of the models; Figure 7. Privacy-utility balance analysis curve. Detailed Implementation

[0023] To make the technical solution of the present invention clearer and more complete, the present invention will be further described below with reference to preferred embodiments, but is not limited to these embodiments.

[0024] Overall process and module logic description like Figure 1 As shown, the overall structure of the river trajectory data protection system based on differential privacy proposed in this invention includes five main modules: ① Data preprocessing and gridding module; ② Graph Convolutional Network (GCN) feature extraction module; ③ Dual decay factor privacy budget allocation module; ④ Dynamic Markov trajectory generation module; ⑤ Smoothing and multi-indicator evaluation module.

[0025] The modules are connected through data flow and parameter closed loop to form an adaptive privacy protection process, realizing end-to-end privacy optimization and quality assessment of river trajectory data.

[0026] 1. Data Acquisition and Preprocessing like Figure 2 As shown, this invention first collects flow velocity data from river monitoring stations. Flow direction With time Time series data. The raw data undergoes time alignment, missing value imputation, and outlier detection.

[0027] flow rate Flow direction To discretize the step size, form A discrete state node.

[0028] Construct an adjacency matrix based on geographical adjacency relationships. The original trajectory sequence is then mapped to this grid system to obtain a gridded trajectory sequence, providing a unified structure for subsequent feature extraction and privacy budget allocation.

[0029] 2. Feature Statistics and GCN Feature Extraction like Figure 3 As shown, the system traverses the gridded trajectory sequence and counts the access frequency of each grid. Duration of stay Number of state transitions and spatial density .

[0030] with constitute the initial feature matrix , input into two or three layers of graph convolution network (GCN), realize feature propagation and spatio-temporal dependence modeling on the adjacency matrix .

[0031] output node embedding representation and the row-normalized Markov transition probability matrix .

[0032] This module enables the system to learn the global and local dependence structure of river trajectories, laying the foundation for subsequent adaptive allocation of privacy budget.

[0033] 3. Double decay factor privacy budget allocation As shown in Figure 4 , the core of this module is to consider both access frequency and spatial density dimensions to achieve differential privacy protection.

[0034] First, according to the access frequency , an inverse model is used to allocate the initial budget , the higher the access frequency, the smaller the allocated budget.

[0035] Then introduce the frequency decay factor and the spatial density decay factor , calculate the final budget:

[0036] Use the KNN-based hierarchical clustering method to automatically determine the number of clusters , and determine the optimal grouping through the weighted combination of Silhouette score and Calinski-Harabasz index.

[0037] In each cluster, select the node with the highest intra-class similarity as the core point (Core Points), and the remaining nodes are recorded as the confusion set (Confuse Set).

[0038] In the trajectory generation process, when the detected direction change amplitude exceeds the set threshold, the system automatically increases the current budget to reduce noise error, realizing dynamic adjustment of privacy budget.

[0039] 4. Trajectory generation and differential privacy noise injection As shown in Figure 5 , the privacy budget matrix obtained in step S2 is used to generate the Markov transition matrix For input, a dynamic Markov trajectory generation model is established.

[0040] When the trajectory state transition occurs: The direction feature is disturbed by an exponential mechanism, and its probability is defined as:

[0041] where is the utility function of the direction; The residence time and flow rate features are disturbed by a Laplace mechanism to inject noise, and the output disturbance value is:

[0042] By multiple sampling, a set of pseudo-tracks satisfying the differential privacy constraint is generated, and isolated states and reverse flow points are removed to ensure that the trajectory is reasonable in physics and topology.

[0043] 5. Smoothing and multi-index evaluation As shown in Figure 6 , the generated trajectory data is first filtered by a Savitzky-Golay filter in the time domain to remove high-frequency noise, and then smoothed by a bidirectional neighborhood average in the spatial domain to maintain flow direction and continuity.

[0044] The following four indicators are used in the evaluation stage: Fréchet distance (FrD): reflects the similarity of the shape of the trajectory in time and space; Access frequency error (AFE): measures the deviation of spatial distribution; Transition matrix KL divergence (D_KL): reflects the consistency of state transition distribution; Privacy loss function L(ε): verifies whether the global budget meets the differential privacy constraint.

[0045] As shown in Figure 7 , the system automatically judges the quality of the trajectory according to the comprehensive score, and when the score is lower than the threshold , the privacy budget parameters and noise scale are adjusted, and the S2-S3 steps are repeated to realize the closed-loop optimization of privacy-utility.

[0046] Parameter setting and experimental verification 1. Model parameter setting The GCN adopts a two-layer structure, the input dimension is 6, the hidden layer dimension is 128, the activation function is ReLU, the optimizer is Adam, and the learning rate is 0.001.

[0047] KNN clustering neighbor number k = 5, cluster number K is searched in the range of [2, 15], and the optimal cluster is evaluated by Silhouette and Calinski-Harabasz index weighted evaluation.

[0048] The privacy budget ε range is set to [0.4, 2.0], and the sensitivity Δf takes the flow rate discrete step of 5 m / s. The Savitzky-Golay filter window width w = 7. 2. Experimental index and result analysis

[0049] Verification is performed on real river monitoring data sets. The results show that the DiffRiver method reduces the Fréchet distance by about 52.9% compared with the MPTD model, the access frequency error decreases by about 60%, and the KL divergence decreases by about 45%.

[0050] When ε = 0.8, the model can still maintain high data utility under the condition of AFE < 0.05, proving the practicability and robustness of the present application in the low budget scenario. 3. Application scenarios and expansibility

[0051] The present method is suitable for fields such as environmental monitoring, hydrological modeling, ecological research and flood warning that require trajectory data sharing.

[0052] The system can be deployed on the cloud or edge computing nodes, support parameter self-adaptation and visual output, and can be further extended to urban water system management and water quality monitoring tasks.

[0053] Summary of experimental results As Figure 7 shown, on several real hydrological data sets (based on historical observation data of monitoring stations in a certain river basin), the differential privacy trajectory protection method proposed by the present application is verified.

[0054] Under the premise of meeting the differential privacy constraint, the present method is significantly better than traditional baseline methods (such as point-by-point Laplace perturbation, global random sampling, etc.) in terms of Fréchet distance, access frequency error (AFE) and transition matrix KL divergence (D_KL).

[0055] Among them, the Fréchet distance is reduced by about 50% on average compared with the baseline model, the access frequency error is reduced by about 60%, and the KL divergence is reduced by about 45%, proving that the present method can effectively maintain the spatio-temporal continuity and statistical characteristics of trajectory data while ensuring privacy, achieving a balance between high privacy and high utility.

[0056] In addition, the trajectory generation result of the present application is verified after visualization, which shows that the disturbed trajectory still accurately reflects the river flow direction and the water system structure characteristics, the noise introduction does not destroy the physical rationality of the data, and has good explainability and practicability.

[0057] Correspondence of claims The steps S1-S4 described in the specification and their sub-steps correspond to each other as technical features in the claims.

[0058] Claim 1 defines the overall structure and function modules of the system, which corresponds to the system framework in Figure 1 Example 1; Claims 2-4 correspond to the technical details of the data preprocessing and feature extraction, privacy budget allocation, trajectory generation and evaluation modules, respectively. Claim 5 corresponds to the parameter setting and performance optimization part in Example 2.

[0059] All technical features related to the above claims have been specifically disclosed in the specification, and feasible implementation modes are given.

[0060] In practical applications, parameters such as the range of ε, the number of clusters K, and the noise sensitivity Δf can be adjusted or replaced modularly according to different basin scales, sensor deployment densities, privacy demand levels, etc., but all belong to equivalent implementation forms within the protection scope of the present application.

[0061] Conclusion In summary, the present application constructs a river trajectory data protection method that takes into account privacy and data utility and has self-adaptive adjustment capability through grid modeling, GCN spatiotemporal feature extraction, double attenuation factor privacy budget allocation, dynamic Markov trajectory generation, differential privacy noise injection, and closed-loop quality evaluation.

[0062] The method theoretically solves the problem of high trajectory data distortion under differential privacy constraints and has the advantages of modularity, portability, and high parallelism in engineering implementation.

[0063] The present application is not only applicable to environmental data sharing, flood warning model training, hydrological simulation and ecological analysis, etc., but also can be extended to other privacy protection tasks of spatial and temporal data, and has significant promotion and application value.

Claims

1. A method for protecting river trajectory data based on differential privacy, characterized in that, Includes the following steps: S1 discretizes the river flow velocity and direction data into a grid, uses a graph convolutional network to extract spatiotemporal features, and establishes an initial transition matrix; S2 dynamically allocates the privacy budget based on the access frequency and spatial density of each grid, using a dual decay factor model to achieve differentiated privacy protection; S3 is based on a dynamic privacy budget and uses Markov transition matrices to generate synthetic trajectories. It also injects differential privacy noise into the orientation and time features through exponential and Laplace mechanisms, respectively. S4 employs a Savitzky-Golay filter for time-domain smoothing and evaluates its quality using multiple metrics such as Fréchet distance and access frequency error, achieving an optimal balance between privacy protection and data utility.

2. The method for protecting river trajectory data based on differential privacy according to claim 1, characterized in that, Step S1 specifically includes: S11 collects raw time-series data on flow velocity and direction from river monitoring stations, performs time alignment, missing value interpolation, outlier detection, and normalization on the data to obtain a clean data sequence with a uniform format. ; S12 quantizes the continuous data according to the preset discretization interval, where the flow velocity is divided into 15 levels with a step size of Δv=5m / s and the flow direction is divided into 8 directional levels with a step size of Δθ=45°, thus forming a complete state space composed of 120 discrete states. S13 combines the discretized velocity and direction levels into a 15×8 two-dimensional grid, with each grid cell (i,j) corresponding to a unique state identifier. And construct an adjacency matrix A based on the spatial adjacency relationship of each unit; map the cleaned trajectory sequence to this grid system to generate a gridded trajectory sequence; S14 Iterates through the gridded trajectory sequence, counts the access frequency, dwell time, and state transition number of each grid, and calculates its spatial density to obtain four key feature vectors for subsequent privacy budget allocation and feature learning. S15 takes an initial feature matrix composed of access frequency, dwell time, spatial density and other statistical indicators as input, and extracts the spatiotemporal dependency features of nodes on the adjacency matrix A through a 2 to 3 layer graph convolutional network. Simultaneously, row normalization is performed on the state transition counting matrix C to obtain the Markov transition probability matrix P; The final output is a high-dimensional GCN feature representation and the corresponding transition probability matrix, providing basic data for subsequent privacy budget allocation and trajectory generation.

3. The method for protecting river trajectory data based on differential privacy according to claim 1, characterized in that, Step S2 specifically includes: S21 Based on the access frequency of each grid Using the inverse frequency model in, : No. The initial privacy budget for each grid cell represents the strength of privacy protection allocated to that area in the differential privacy mechanism; the smaller the value, the stronger the protection. The access frequency of this grid, i.e., the proportion of the number of sampling points in the trajectory data that fall into this grid out of the total number of trajectory points; The privacy budget is initially allocated so that grids with high access frequency receive a lower privacy budget and grids with low access frequency receive a higher budget. S22 introduces a frequency attenuation factor based on the initial budget. in, This is a frequency attenuation factor used to further suppress the privacy budget value in high-access frequency areas; The natural logarithm function is used to mitigate the difference in amplitude between different access frequencies. Same as above, indicating grid access frequency; With spatial density attenuation factor in, Spatial density attenuation factor, used to adjust the privacy budget based on the crowding level of the surrounding area; Spatial density represents the average or weighted average of the access frequencies in the neighborhood of this grid. The final privacy budget is determined by multiplying these three factors: : No. The grid's final privacy budget; The basic privacy budget is the global initial budget limit set for the system, which is generally selected based on the sensitivity of the data. : Frequency attenuation factor, see formula (2); : Spatial density attenuation factor, see formula (3); This enables differentiated privacy protection in both frequency and density dimensions, providing the strongest privacy constraints to high-frequency and high-density areas. S23 uses a hierarchical clustering algorithm based on KNN to dynamically cluster all grids, and automatically determines the optimal number of clusters K by weighted combination of silhouette coefficient and Calinski-Harabasz exponent; In each cluster, the node with the highest average similarity to other grids within the cluster is selected as the core point, and nodes with low similarity are marked as the confusion set, so as to facilitate sample selection and privacy enhancement in the subsequent trajectory generation stage; During trajectory generation, S24 monitors the trajectory direction change magnitude Δθ in real time. When a significant direction change is detected, the system dynamically increases the privacy budget at that moment to reduce noise error. When the direction change is relatively gentle, the exponential mechanism is used first for light perturbation, and the remaining budget is reserved for subsequent high-sensitivity transfers; This adaptive budget adjustment mechanism enables dynamic optimization of the privacy budget and precise protection against changes in river flow characteristics.

4. The method for protecting river trajectory data based on differential privacy according to claim 1, characterized in that, Step S3 specifically includes: S31 Based on the final privacy budget allocation matrix ε_grid_final generated in step S2, construct a dynamic Markov trajectory generation model, use the transition probability matrix P as the state transition kernel function, and call the differential privacy mechanism in each state transition with privacy budget as constraint. S32 When the trajectory state transitions, the direction change characteristic is perturbed using an exponential mechanism, and the perturbation probability is defined as follows: Where U(D, ) is the utility function for the direction of the transfer; S33 uses the Laplace mechanism to inject noise into the residence time and flow velocity characteristics, and the observed values ​​after injection are... in = / Based on privacy budget and sensitivity The noise scale; S34 Generates a set of trajectory sequences under differential privacy protection based on the above noise injection mechanism, and obtains the distribution of fake trajectories through multiple random samplings, so that its global statistical features are... - Similar to the original data under differential privacy constraints; S35 performs post-processing on the trajectory generation results, eliminating unreasonable isolated states and countercurrent points to ensure that the generated trajectory is feasible under physical constraints.

5. The method for protecting river trajectory data based on differential privacy according to claim 1, characterized in that, Step S4 specifically includes: S41 smooths the generated trajectory data in the time domain using a Savitzky-Golay filter to remove high-frequency noise and preserve the trend of flow velocity changes. S42 performs position smoothing in the spatial domain through bidirectional neighborhood averaging, ensuring the continuity of the trajectory curve and the stability of the flow direction; S43 performs a multi-metric evaluation on the generated privacy-protected trajectory data and the original data, the metrics including: a) Fréchet distance: measures the similarity of two trajectories in terms of their spatiotemporal shape; b) Access frequency error: reflects the deviation between the generated data and the original data in terms of spatial distribution; c) KL divergence of the transition matrix: used to evaluate the consistency of the state transition distribution; d) Privacy loss function: Verify that the global privacy budget conforms to differential privacy constraints; S44 determines the model output quality by combining multiple indicators. When the combined score is lower than the threshold T, the privacy budget allocation parameters and noise scale λ_i are automatically adjusted, and steps S2–S3 are re-executed until the utility-privacy balance condition is met. S45 ultimately outputs a differentially privacy-preserving river trajectory dataset, providing a secure and usable data foundation for downstream hydrological analysis, ecological monitoring, or predictive models.

Citation Information

Cited By

  • Land space partition planning-oriented spatial heterogeneous differential privacy calculation method and system

    CN122174276A