Edge computing differential privacy industrial IoT data anonymization verification system and method

By using differential privacy initialization and adaptive mesh construction to dynamically adjust noise intensity, combined with a two-dimensional verification system, the problems of parameter mismatch and single verification of edge computing nodes are solved, achieving efficient and flexible data desensitization and verification in edge computing environments.

CN121530771BActive Publication Date: 2026-05-05LINGSHU TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
LINGSHU TECH CO LTD
Filing Date
2026-01-16
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

Existing industrial IoT data anonymization technologies suffer from several problems on edge computing nodes, including mismatch between parameter initialization and node characteristics, resource waste, insufficient or over-configuration of privacy protection, data distortion due to noise superposition effects, and a single verification system and lack of adjustment mechanisms. These issues make it difficult to adapt to complex industrial IoT scenarios.

Method used

By employing a differential privacy initialization module, an adaptive mesh construction module, a noise intensity correction module, and a node verification system construction module, and by dividing the system into terminal, gateway, and regional edge nodes, the noise intensity is dynamically adjusted and a two-dimensional cross-node verification system is constructed to achieve differentiated parameter initialization and closed-loop adjustment.

Benefits of technology

It achieves precise parameter adaptation and flexible collaborative desensitization of edge nodes, avoiding resource waste and data distortion, ensuring a balance between privacy protection and data availability, and quickly locating the root cause of problems through a two-dimensional verification system, adapting to the needs of industrial scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121530771B_ABST
    Figure CN121530771B_ABST
Patent Text Reader

Abstract

This invention relates to the field of industrial IoT data security technology, specifically to an edge computing differential privacy industrial IoT data anonymization verification system and method. This system and method divides edge nodes according to three dimensions: resource capabilities, functional positioning, and privacy requirements. It combines data attributes and the impact of leakage to formulate differentiated differential privacy parameters, and uses a dynamic adaptive mesh to achieve hierarchical alignment, scene binding, and elastic reconstruction, avoiding cross-level privacy risks and simplifying verification logic. Relying on the mesh to integrate multi-dimensional factors and dynamically correct noise intensity, it designs lightweight, medium, and deep hierarchical anonymization for three types of nodes, balancing privacy protection and data availability. It constructs a dual-dimensional verification chain of privacy security and data availability, and a three-level verification chain of terminal → gateway → region, to comprehensively evaluate the anonymization effect. Through hierarchical judgment and precise adjustment, it achieves closed-loop iteration, efficiently adapting to the needs of industrial scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial IoT data security technology, and more specifically, to an edge computing differential privacy industrial IoT data de-identification verification system and method. Background Technology

[0002] Against the backdrop of the rapid development of the Industrial Internet of Things (IIoT), edge computing architecture has been widely adopted due to its advantages of distributed deployment and low-latency processing. However, existing data anonymization technologies have significant limitations in adapting to edge nodes. Traditional solutions often fail to fully consider the differences in resource supply, functional positioning, and privacy requirements among different edge nodes, adopting a uniform parameter configuration mode. This leads to a mismatch between parameter initialization and the actual characteristics of the nodes, either causing data leakage risks due to insufficient privacy protection or wasting resources due to over-configuration, making it difficult to adapt to the complex node deployment scenarios of the IIoT. At the same time, the lack of an effective node collaborative management mechanism results in chaotic cross-level data flow, further exacerbating the difficulty of privacy protection and data governance.

[0003] In existing industrial IoT data anonymization technologies, noise intensity is often set to a fixed value, failing to dynamically adjust based on actual application scenarios, data characteristics, and grid resource status. This results in an inability to balance privacy and data usability in the anonymization effect. Some solutions lack differentiated anonymization strategies for edge nodes with different computing power levels, such as terminals, gateways, and regions. Low-power nodes may encounter efficiency bottlenecks due to complex anonymization operations, while highly sensitive data may face leakage risks due to insufficient anonymization strength. Furthermore, the noise superposition effect can easily cause data distortion, affecting the subsequent data analysis and decision-making value, and failing to meet the core requirement of data accuracy in industrial production.

[0004] Traditional data anonymization verification solutions generally suffer from a lack of comprehensive verification dimensions and adjustment mechanisms. Most focus solely on privacy and security verification, neglecting the usability assessment of whether the anonymized data can still support industrial production decisions, leading to one-sided verification results. Furthermore, the verification system lacks a cross-node collaborative architecture, making it difficult to comprehensively cover the entire anonymization process. Moreover, it lacks an effective problem identification and closed-loop adjustment mechanism. Even if the anonymization effect is found to be substandard, it is difficult to accurately pinpoint the root cause, resulting in blind adjustments that are not only inefficient but may also further decouple the anonymization strategy from the needs of industrial scenarios, failing to guarantee the continued adaptability of the anonymization solution. Summary of the Invention

[0005] To address the shortcomings of existing technologies, the present invention aims to provide an edge computing differential privacy industrial IoT data de-identification verification system and method.

[0006] To achieve the above objectives, the present invention provides the following technical solution:

[0007] Edge computing differential privacy industrial IoT data anonymization verification system includes:

[0008] The differential privacy initialization module is used to divide edge nodes into terminal edge nodes, gateway edge nodes, and regional edge nodes according to the edge architecture of the Industrial Internet of Things, and to initialize the differential privacy parameters of the terminal edge nodes, gateway edge nodes, and regional edge nodes.

[0009] The adaptive mesh building module is used to build dynamic adaptive meshes for edge nodes in industrial IoT.

[0010] The noise intensity correction and desensitization module corrects the basic noise intensity of each edge node based on a dynamic adaptive mesh to obtain the noise correction intensity of each edge node, and performs desensitization operation based on the noise correction intensity of each edge node.

[0011] The node verification system construction module builds a two-dimensional cross-node verification system.

[0012] The data anonymization verification module obtains the data anonymization verification index of each regional edge node based on the constructed two-dimensional cross-node verification system. When the data anonymization verification index is higher than the data anonymization verification threshold, the anonymization operation is deemed suitable. When the data anonymization verification index is not higher than the data anonymization verification threshold, the root cause of the problem is located and targeted adjustments are made.

[0013] Furthermore, differential privacy parameters are initialized for the terminal edge node, gateway edge node, and regional edge node, including:

[0014] Select an edge node and obtain the importance score of the data properties corresponding to that edge node. And the impact of the leak on the score ;

[0015] Through formula The data sensitivity index was calculated. ,in , All are weighting coefficients;

[0016] Based on data sensitivity index The corresponding differential privacy parameter set is determined, and then the differential privacy parameters of the corresponding terminal edge nodes, gateway edge nodes and regional edge nodes are initialized based on the differential privacy parameter set.

[0017] Furthermore, the importance score of the data properties corresponding to edge nodes. The acquisition method is as follows: Obtain the property type of the data property corresponding to the edge node, determine the corresponding property score PR based on the property type, and then use the formula... =PR / PG calculation yields a score indicating the importance of the data properties corresponding to the edge nodes. Where PG is the property score threshold.

[0018] Furthermore, the impact of data leakage at edge nodes on the scoring. The acquisition method is as follows: Obtain the application scenario corresponding to the data properties of the edge node, determine the corresponding spillover score (DL) based on the application scenario, and calculate the leakage impact score of the data properties corresponding to the edge node using the formula Si=DL / DC. Where DC is the ripple score threshold.

[0019] Furthermore, the noise baseline intensity of each edge node is corrected based on the dynamic adaptive mesh, specifically as follows: An edge node is selected from the dynamic adaptive mesh; the application scenario bound to the mesh containing that edge node is identified; the scenario priority score for that application scenario is obtained; and the maximum data sensitivity index in the mesh containing that edge node is simultaneously obtained. Through formula The mesh privacy security baseline value Bs of the edge node is calculated, where L1 and L2 are weighting coefficients; then, the mesh resource carrying capacity baseline value Br of the mesh where the edge node is located is obtained, using the formula... The benchmark correction factor was calculated. Further, the data fusion requirement coefficient Kf and the link security status coefficient Kl of the grid where the edge node is located are obtained, and then the formula is used to obtain the data fusion requirement coefficient Kf and the link security status coefficient Kl of the grid where the edge node is located. The final correction coefficient was calculated. Obtain the base noise intensity of the edge node. Through formula The noise correction intensity was calculated. The noise baseline intensity of the edge nodes is corrected to the noise correction intensity. .

[0020] Furthermore, The average CPU utilization is obtained by collecting the arithmetic mean of the real-time CPU utilization of all edge nodes in the grid where the edge node is located. The average CPU utilization is obtained by collecting the arithmetic mean of the data transmission delay of each communication link in the grid where the edge node is located. P1 and P2 are both weighting coefficients.

[0021] Furthermore, the data fusion demand coefficient Kf is obtained by determining whether there is a data fusion request in the edge nodes of the area in the grid where the edge node is located, and then defining the fusion level. The data fusion demand coefficient Kf is calculated by the formula Kf=1+fusion level*f1, where f1 is the fusion impact coefficient.

[0022] Furthermore, the link security status coefficient Kl is obtained as follows: determine the average transmission delay fluctuation of the grid where the edge node is located, set an upper threshold and a lower threshold for delay fluctuation. When the average transmission delay fluctuation is lower than the lower threshold, the security level is defined as 0. When the average transmission delay fluctuation is between the upper and lower thresholds, the security level is defined as 1. When the average transmission delay fluctuation is higher than the upper threshold, the security level is defined as 2. The link security status coefficient Kl is calculated using the formula Kl = 1 + security level * g1, where g1 is the security risk coefficient.

[0023] Furthermore, the data anonymization verification index of a regional edge node is obtained as follows: the budget compliance score, anti-attack score, and decision effectiveness score of a regional edge node are obtained, and the data anonymization verification index of the regional edge node is calculated using the formula: Data anonymization verification index = (budget compliance score * q1 + anti-attack score * q2) * t1 + decision effectiveness score * t2; q1, q2, t1, and t2 are all weight coefficients.

[0024] Furthermore, the edge computing differential privacy industrial IoT data anonymization verification method has the following steps:

[0025] S1: Node partitioning and differential privacy parameter initialization: Based on the edge architecture of the Industrial Internet of Things, the edge nodes are divided into terminal edge nodes, gateway edge nodes and regional edge nodes, and differential privacy parameters are initialized for the terminal edge nodes, gateway edge nodes and regional edge nodes.

[0026] S2: Constructing a dynamic adaptive grid for industrial IoT;

[0027] S3: Dynamic noise intensity correction and hierarchical desensitization operation: Based on the dynamic adaptive mesh, the basic noise intensity of each edge node is corrected to obtain the noise correction intensity of each edge node, and the desensitization operation is performed based on the noise correction intensity of each edge node.

[0028] S4: Construct a two-dimensional cross-node verification system;

[0029] S5: Data anonymization verification and closed-loop adjustment: Based on the constructed two-dimensional cross-node verification system, obtain the data anonymization verification index of edge nodes in each region. When the data anonymization verification index is higher than the data anonymization verification threshold, determine the anonymization operation is suitable. When the data anonymization verification index is not higher than the data anonymization verification threshold, locate the root cause of the problem and make targeted adjustments.

[0030] Compared with the prior art, the present invention has the following beneficial effects:

[0031] The system and method of this invention divide edge nodes according to three dimensions: resource capabilities, functional positioning, and privacy requirements. It formulates differentiated privacy parameters by combining the inherent important attributes of data and the impact of leakage, ensuring that the parameter initialization is accurately adapted to the characteristics of different nodes. The dynamic adaptive mesh realizes the precise alignment of node hierarchy and mesh topology, strong binding of scene and mesh unit, and elastic reconstruction when nodes dynamically join and leave. It avoids the privacy risks caused by cross-level data turbulence and simplifies the de-identification verification logic, making the collaborative de-identification of edge nodes more targeted and flexible, perfectly matching the distributed architecture characteristics of the Industrial Internet of Things.

[0032] Based on a dynamic adaptive grid, this system integrates multiple factors such as scenario priority, data sensitivity, grid resource carrying capacity, data fusion requirements, and link security status to dynamically correct the basic noise intensity of each node. This allows the noise intensity to be flexibly adjusted according to the actual situation of the grid. At the same time, it designs lightweight, medium-intensity, and deep hierarchical desensitization operations to address the differences in computing power and functions among three types of nodes: terminals, gateways, and regions. This ensures the privacy protection strength of highly sensitive data, avoids efficiency losses caused by complex desensitization operations for low-computing-power nodes, and prevents data distortion caused by noise superposition, thus achieving a dynamic balance between privacy protection and data availability.

[0033] The dual-dimensional cross-node verification system prioritizes privacy and data availability, constructing a three-tiered verification chain from terminal to gateway to region. Through cumulative privacy budget verification, anti-attack verification, and decision support effectiveness verification, it comprehensively covers key evaluation dimensions of de-identification effectiveness, ensuring the comprehensiveness and reliability of verification results. Furthermore, the tiered judgment and precise adjustment mechanism based on the verification index can quickly pinpoint the root causes of problems in parameter configuration and de-identification strategies. Closed-loop iteration is achieved through local fine-tuning or deep optimization, avoiding the drawbacks of traditional de-identification solutions' singular verification and blind adjustments, ensuring that de-identification operations are always adapted to the needs of industrial scenarios. Attached Figure Description

[0034] Figure 1 This is a flowchart illustrating the principle of the method of the present invention;

[0035] Figure 2 A schematic diagram illustrating the operational principle of the adaptive mesh construction module;

[0036] Figure 3 A flowchart for constructing a two-dimensional cross-node verification system. Detailed Implementation

[0037] Example 1: Refer to Figures 1 to 3 Edge computing differential privacy industrial IoT data anonymization verification system, including:

[0038] The differential privacy initialization module, based on the edge architecture of the Industrial Internet of Things (IIoT), divides edge nodes into terminal edge nodes, gateway edge nodes, and regional edge nodes. This division is based on three dimensions: resource capability gradient, functional positioning, and privacy requirement hierarchy. According to the resource capability gradient: computing power, bandwidth, and storage capacity are the core indicators, showing a progressively increasing trend; terminal edge nodes: weakest resources (low computing power, narrow bandwidth, small storage), suitable for sensors, smart meters, and other terminal devices; gateway edge nodes: medium resources (basic computing power, medium bandwidth, moderate storage), suitable for industrial gateways and edge controllers; regional edge nodes: strongest resources (high computing power, wide bandwidth, large storage capacity), suitable for edge servers and edge cloud nodes. According to the functional positioning: based on the core role in data flow, a closed loop of collection-aggregation-integration is formed; terminal edge nodes: data... The data acquisition end is responsible for raw data acquisition and lightweight preprocessing; the gateway edge node is the data hub, responsible for multi-terminal data aggregation, format standardization, and medium-intensity processing; the regional edge node is the data core, responsible for multi-gateway data fusion, deep processing, and storage. Based on privacy requirements, the requirements increase progressively according to the sensitivity of the processed data: terminal edge nodes have the lowest privacy requirements, processing only low / medium sensitive data from a single device; gateway edge nodes have medium privacy requirements, processing multi-device associated data, including some highly sensitive data; and regional edge nodes have the highest privacy requirements, processing multi-source highly sensitive data across the entire region (such as core process and global scheduling data). Differential privacy parameter initialization is performed on the terminal edge nodes, gateway edge nodes, and regional edge nodes (i.e., the privacy budget for the terminal edge nodes, gateway edge nodes, and regional edge nodes). Noise base strength (Perform differentiated initialization).

[0039] Differential privacy parameter initialization is performed for terminal edge nodes, gateway edge nodes, and regional edge nodes, as follows: Select one edge node (one of the terminal edge node, gateway edge node, and regional edge node), and obtain the importance score of the data properties corresponding to that edge node. And the impact of the leak on the score (For example, if terminal edge node a is responsible for collecting humidity and temperature data from an environmental humidity sensor, then the data type corresponding to terminal edge node a is humidity data and temperature data.) This is achieved through the formula... The data sensitivity index was calculated. ; , All are weighting coefficients. Because it is necessary to focus on the inherently important attributes of the data, with the impact of leakage as a secondary consideration, and to match the privacy protection priorities of industrial scenarios, it is crucial to ensure the accuracy and stability of the differential privacy parameter initialization. The value can be 0.7. The value can be 0.3; set each data sensitivity index. The range corresponds to a differential privacy parameter set, and the range of the data sensitivity index is... , … The differential privacy parameter set includes differential privacy parameter set 1, differential privacy parameter set 2, ..., differential privacy parameter set A. The privacy budget of differential privacy parameter set 1 is higher than that of differential privacy parameter set 2, the noise basis strength of differential privacy parameter set 1 is lower than that of differential privacy parameter set 2, and so on. Example: Privacy budget of differential privacy parameter set 1 The noise base strength is 1.5. The privacy budget is 0.4; Differential privacy parameter set 2 The noise level is 0.8, and the basic noise intensity is... It is 0.8.

[0040] The importance score of the data properties corresponding to edge nodes The acquisition method is as follows: Obtain the property type of the data corresponding to the edge node (property types are divided into three categories: core data, ordinary data, and public data. Core data includes data such as process formulas, equipment keys, and production scheduling instructions; ordinary data includes data such as daily equipment temperature, energy consumption, and operating time; public data includes data such as workshop humidity, lighting, and air quality; the importance of core data > the importance of ordinary data > the importance of public data. If there are multiple property types corresponding to the data of an edge node, the property type with the highest importance is selected; for example, if edge node b corresponds to core data, ordinary data, and public data, then the property type of edge node b is core data). Determine the corresponding property score PR based on the property type (based on the industrial data sensitivity level quantification convention, in this embodiment, the property score of core data is 3, the property score of ordinary data is 2, and the property score of public data is 1. The purpose is to standardize SS to a unified range of 0.33-1, facilitating subsequent linear gradient mapping of differential privacy parameters and improving the accuracy of parameter initialization). Then, use the formula... =PR / PG calculation yields a score indicating the importance of the data properties corresponding to the edge nodes. Wherein, PG is the property score threshold (in this embodiment, the property score threshold is the highest property score, i.e., 3 points).

[0041] Impact of data leakage at edge nodes on score The acquisition method is as follows: Obtain the application scenarios corresponding to the data properties of the edge nodes (application scenarios are divided into three types: core production scenarios, routine operation scenarios, and auxiliary support scenarios. Core production scenarios directly serve key production links, such as chemical reaction workshops, intelligent manufacturing core production lines, and energy grid dispatch centers, which rely on data-driven decision-making. Routine operation scenarios serve ordinary production and operation links, such as general assembly lines, daily workshop monitoring, and non-core equipment maintenance. Auxiliary support scenarios serve non-core production links, such as office area environmental monitoring, employee attendance data statistics, and equipment idle status monitoring. The impact of leakage in core production scenarios > the impact of leakage in routine operation scenarios > the impact of leakage in auxiliary support scenarios. If there are multiple application scenarios corresponding to the data properties of the edge nodes, then the impact of leakage in the application scenarios corresponding to the data properties of the edge nodes is determined by the data properties of the edge nodes. The scenario is selected based on the application scenario with the greatest impact from leakage. For example, if edge node c corresponds to the core production scenario, the regular operation scenario, and the auxiliary support scenario, then the application scenario of edge node c is the core production scenario. The corresponding impact score DL is determined based on the application scenario (based on the scenario leakage impact gradient; in this embodiment, the impact score of the core production scenario is 3, the impact score of the regular operation scenario is 2, and the impact score of the auxiliary support scenario is 1; for example, if edge node d is used to collect temperature data of a critical precision production line, then the application scenario of edge node d is the core production scenario, and the impact score is 3; if edge node e is used to collect temperature data of the office area environment, then the application scenario of edge node e is the auxiliary support scenario, and the impact score is 1). The leakage impact score of the data nature corresponding to the edge node is calculated by the formula Si=DL / DC. Wherein, DC is the ripple score threshold (in this embodiment, the ripple score threshold is the highest ripple score, i.e., 3 points).

[0042] The adaptive mesh building module constructs a dynamic adaptive mesh for edge nodes in the Industrial Internet of Things.

[0043] To construct a dynamic adaptive mesh for edge nodes in the Industrial Internet of Things (IIoT), the following principles are defined: The core design principles of the mesh are clarified (hierarchical alignment principle: the mesh topology corresponds one-to-one with the edge node hierarchy (terminal edge node → gateway edge node → regional edge node), avoiding cross-hierarchical data turbulence and protecting privacy parameters). , Unified management and control; Scenario binding principle: Strong binding between grid units and application scenarios (core production / routine operation / auxiliary support), ensuring consistent data nature and privacy requirements for edge nodes within the same grid unit, simplifying desensitization verification logic; Dynamic elasticity principle: Supporting real-time access / exit of edge nodes, load migration, and grid reconstruction triggered by scenario switching, avoiding resource waste or desensitization interruption caused by static grids), dividing basic geographical boundaries according to the actual layout of the industrial site (such as workshops, production lines, and office areas), ensuring close physical distance and low data transmission latency for edge nodes within the same grid unit, and further subdividing each physical area into sub-units according to application scenarios (core production / routine operation / auxiliary support), ensuring that nodes within the unit serve the same type of scenario (such as "Workshop 1 Core Production Line - Core Production Scenario Grid Unit"); Each grid unit must contain "1 The system consists of "regional edge nodes (core control) + N gateway edge nodes (data hubs) + M terminal edge nodes (data acquisition)," forming a local closed loop of "acquisition-aggregation-de-identification-verification" to avoid privacy risks caused by cross-unit data flow. Centered on the regional edge nodes, gateway edge nodes within the jurisdiction are connected via industrial buses (such as Modbus, Profinet) or wireless communications (such as 5G, LoRa). The gateway edge nodes then connect to the corresponding terminal edge nodes, forming a star + chain hybrid physical topology. Logical connection rules are established based on node tags: only nodes within the same grid unit and in the same scenario are allowed to communicate with each other (e.g., terminals in the core production scenario grid can only transmit data to the gateway of their own unit and cannot connect to the gateway of the regular operation scenario across units; cross-grid data collaboration can only be initiated by the regional edge nodes of each grid).

[0044] The noise intensity correction and desensitization module corrects the basic noise intensity of each edge node based on a dynamic adaptive mesh to obtain the noise correction intensity of each edge node, and performs desensitization operation based on the noise correction intensity of each edge node.

[0045] The noise baseline intensity of each edge node is corrected based on a dynamic adaptive grid, specifically as follows: An edge node is selected from the dynamic adaptive grid. The application scenario bound to the grid of that edge node is identified, and the scenario priority score of that application scenario is obtained (scenario priority score: core production scenario = 3, regular operation scenario = 2, auxiliary support scenario = 1 (consistent with the DL value acquisition logic above, ensuring continuity)). Simultaneously, the maximum value of the data sensitivity index in the grid where that edge node is located is obtained. (That is, the maximum value of the data sensitivity index Sa among all edge nodes (terminals / gateways / regions) within the grid cell), obtained through the formula The grid privacy security baseline value Bs of the edge node is calculated, where L1 and L2 are weighting coefficients, and L1 + L2 = 1. Since the scene is an inherent attribute of the grid, it determines the "basic level" of privacy protection and has a higher priority. Data sensitivity is dynamically changing (e.g., data nature upgrades), and is used to "fine-tune the baseline value" to adapt to sensitive fluctuations at the data level. Therefore, the value of L1 can be 0.6, and the value of L2 can be 0.4. Next, the grid resource carrying capacity baseline value Br of the grid where the edge node is located is obtained. The average CPU utilization is obtained by collecting the arithmetic mean of the real-time CPU utilization of all edge nodes (terminal edge nodes, gateway edge nodes, and regional edge nodes) in the grid where the edge node is located. The average data transmission latency is obtained by collecting the arithmetic mean of the data transmission latency of each communication link in the grid where the edge node is located (terminal → gateway, gateway → regional edge node). The average data transmission latency is obtained by collecting the arithmetic mean of the data transmission latency of each communication link in the grid where the edge node is located. The data transmission latency threshold is determined as a critical latency value to ensure data real-time performance in industrial scenarios. It is a reference standard for judging whether the link is congested. Based on the common requirements of industrial IoT data transmission, the default value can be 100ms. P1 and P2 are both weighting coefficients. Because CPU utilization and data transmission latency have equally important effects on the grid resource carrying capacity benchmark value Bᵣ, the values ​​of P1 and P2 can both be 0.5. The benchmark correction factor was calculated. ( The goal is to standardize it to the 0-1 range. Further, the data fusion requirement coefficient Kf and link security status coefficient Kl of the grid where the edge node is located are obtained. (The data fusion requirement coefficient Kf is obtained by determining whether there is a data fusion request (multi-node data integration within the grid / cross-grid data collaboration) among the edge nodes in the grid where the edge node is located. If there is no data fusion request among the edge nodes in the area, the fusion level is defined as 0. If there is fusion within the same grid but no cross-grid fusion, the fusion level is defined as 1. If there is cross-grid fusion, the fusion level is defined as 2. This is achieved through the formula Kf.) =1 + Fusion Level * f1, calculate the data fusion requirement coefficient Kf, where f1 is the fusion impact coefficient (the value can be 0.1, as a gentle increase of 0.1 can avoid excessive desensitization leading to data distortion when the fusion level is increased, while also meeting the privacy enhancement requirements of cross-mesh fusion); the link security status coefficient Kl is obtained by determining the average transmission delay fluctuation of the mesh where the edge node is located (the arithmetic mean of the link transmission delay fluctuation of each communication link in the mesh, link transmission delay fluctuation = (real-time transmission delay - delay baseline value) / delay baseline value, taking the communication link within the last 10 seconds). The average transmission delay is used as the baseline value for delay. Upper and lower thresholds for delay fluctuation are set (the upper threshold can be set to 30%, and the lower threshold to 20%; 20%: the upper limit for normal fluctuations in industrial links (e.g., occasional fluctuations in normal 5G / LoRa transmission ≤ 20%), below which data availability is not affected; 30%: the critical value for abnormal fluctuations in industrial scenarios (exceeding 30% may be accompanied by link congestion / interference / potential attacks), requiring an alert to strengthen privacy protection). When the average transmission delay fluctuation is lower than the lower threshold, the security level is defined as 0 (secure). When the average transmission delay fluctuation is between the upper and lower thresholds of delay fluctuation, the security level is defined as 1. When the average transmission delay fluctuation is higher than the upper threshold of delay fluctuation, the security level is defined as 2 (risk). The link security status coefficient Kl is calculated using the formula Kl = 1 + security level * g1, where g1 is the security risk coefficient (its value can be 0.15 to adapt to the security level gradient; for level 2 risk, Kl = 1.3 (balancing privacy enhancement and data availability), which is higher than the fusion impact coefficient (0.1), highlighting the higher priority of link security for privacy protection). The final correction coefficient was calculated. Obtain the base noise intensity of the edge node. Through formula The noise correction intensity was calculated. The noise baseline intensity of the edge nodes is corrected to the noise correction intensity. .

[0046] The desensitization process differs for different edge nodes.

[0047] For terminal edge nodes (lightweight desensitization), the operation steps are as follows: Perform basic denoising on the raw data collected by the terminal edge nodes (such as temperature, humidity, and equipment operating status codes) (removing sensor outliers, such as extreme values ​​exceeding the reasonable range of the process) to avoid invalid data consuming desensitization resources; consistently use Laplace noise (lowest computational cost, suitable for low computing power), performing a single round of noise injection only on valid data, without adding additional complex perturbation logic; for continuous data (temperature, energy consumption): the noise intensity is directly equal to... The formula is: (Laplace parameter) Position parameter μ=0); Discrete data (device status codes, switch signals): based on The formula for determining the mask ratio is: ( For discrete data adaptation coefficients, since discrete data is mostly structured coding (such as device status codes), a 30% mask of non-critical bits can hide sensitive information while retaining core identification features. Therefore, the value of z1 can be 0.3 to avoid excessive masking leading to data failure. Random masking is applied to the non-critical bits of discrete values ​​(e.g., status code "1011" → "10×1", where × is a randomly generated 0 / 1); pre-calculate " -Noise value" mapping dictionary (overlay) Common values), during data masking, the table is directly looked up and called to avoid real-time calculation overhead; the masked data is output to the corresponding gateway edge node, and the data masking log (including the original data, ...) is recorded synchronously. Values, noise levels, and desensitized timestamps). The cumulative noise intensity ≤ the maximum threshold corresponding to the initial privacy budget ε (e.g., when ε=1.5, the cumulative...). (Total ≤ 3.0).

[0048] For gateway edge nodes (medium-intensity data masking), the operation steps are as follows: receive masked data from multiple terminal edge nodes, perform format standardization (unify data units and sampling frequency), deduplication and merging (remove duplicate data collection) to form a structured dataset; adopt a combination strategy of "Laplace noise + data trend preservation perturbation" (balancing privacy and data correlation). Tiered adaptation: Low-sensitivity aggregated data (such as average humidity in a multi-terminal workshop): (lc is the noise attenuation coefficient for low-sensitivity converged data, in order to retain both...) The baseline privacy level (without excessively weakening privacy protection) and the gentle attenuation to avoid data distortion caused by noise superposition align with the gateway's "medium-intensity desensitization" positioning. The value of lc can be 0.8; this attenuation ratio reduces noise interference with data statistical characteristics (mean, trend), ensuring effective subsequent analysis. Medium-sensitivity aggregated data (such as the total energy consumption of multiple devices): (Baseline intensity); The standardized data are grouped according to sensitivity level, and Laplace noise of corresponding intensity is injected into each group. Simultaneously, the trend slope of the data sequence (e.g., energy consumption increase / decrease trend) is fine-tuned. To avoid noise disrupting data correlation, the processed and desensitized data is uploaded to the regional edge node, and the log is updated with "aggregated data volume, sensitivity level grouping, and outlier handling records".

[0049] For edge nodes of a region (deep desensitization), the operation steps are as follows:

[0050] It receives data from multiple gateways, performs deep cleaning (removing redundant fields and repairing missing data values), and data fusion (such as associating core process parameters with production scheduling data) to form a high-value dataset. It adopts a dual strategy of "Gaussian noise + data fragmentation and obfuscation" (Gaussian noise is adapted to highly sensitive continuous data, and fragmentation and obfuscation enhance the privacy of discrete core data). Dynamic optimization and adaptation:

[0051] Continuous core data (such as process formulation parameters, global energy consumption peak): ( To enhance the privacy of highly sensitive core data, a small increase of 1.0 to 1.1 is used to avoid excessive desensitization that could disrupt data trends (such as the changing patterns of process parameters), ensuring that core data can still support production decisions. The value of em can be 1.1. The formula is as follows: ( (mean = 0); discrete core data (such as equipment key fragments, production instruction codes): first, according to... Granularity of segmentation ( The larger the size, the finer the fragmentation, such as The time is divided into 4 pieces. The time is divided into 6 pieces), and then random rearrangement and partial masking are performed on the pieces to ensure that the original encoding cannot be restored; for the multi-source fused dataset (such as process parameters + equipment status data), based on Recalculate the cumulative noise intensity; if it does not reach the privacy budget threshold, inject a small amount of additional noise. Based on differential privacy serial combination rules, calculate the end-to-end cumulative privacy budget. ( / / (These are the initial privacy budgets for the endpoint / gateway / regional node, respectively), ensuring... ≤Preset safety threshold (e.g., in core production scenarios) ≤3.0); Output and Logs: Output the anonymized data to the industrial cloud platform or local storage. The logs include the end-to-end privacy budget calculation results, double anonymization details, and fused data processing records.

[0052] The node verification system construction module builds a two-dimensional cross-node verification system.

[0053] The dual-dimensional cross-node verification system is constructed as follows: Define the verification subject and collaborative architecture: core verification node: regional edge node; distributed verification node: gateway edge node; support node: terminal edge node; collaborative logic: form a three-level verification chain of "terminal → gateway → region". The gateway edge node first performs "lightweight verification" on the desensitized data of the terminal edge node, and then synchronizes the verification result with its own desensitized log to the regional edge node. The regional node integrates the full-link data to perform "deep verification" to ensure comprehensive and efficient verification. The core content of dual-dimensional verification: (1) First dimension: privacy security verification: ① Cumulative privacy budget verification (core indicator): The regional edge node reviews the full-link cumulative privacy budget based on the differential privacy serial combination rule. The system determines whether the cumulative privacy budget across the entire chain is less than or equal to the scenario security threshold (the scenario security threshold varies depending on the scenario; for example, the scenario security threshold for core production scenarios can be set to 3.0, for regular operation scenarios to 4.0, and for auxiliary support scenarios to 5.0; these are just examples. If the entire chain involves multiple scenarios, the lowest scenario security threshold among the involved scenarios is selected; for example, if the entire chain involves both core production and regular operation scenarios, the scenario security threshold is set to 3.0). If the score is ≤ the scenario security threshold, the budget compliance score is 100. For every 1% exceeding the scenario's safety threshold, 10 points will be deducted (i.e., ...). (Deduct points until 0 is reached).

[0054] ② Anti-attack effectiveness verification: At the edge nodes of the grid, a reconstruction attack simulation is performed on highly sensitive, de-identified data (e.g., reverse derivation of the original formula based on de-identified process parameters). If the attack success rate is ≤ the success rate threshold, the anti-attack verification is considered successful; if the success rate is > the success rate threshold, privacy protection is deemed insufficient (the success rate threshold is preset; the following is an example: the higher the privacy requirements of the corresponding scenario (the more sensitive the data, the greater the harm of leakage), the lower the success rate threshold, forming a gradient adaptation: core production scenario (highly sensitive data: process formula, equipment keys): success rate threshold ≤ 5% (e.g., 3%~5%), because data leakage in this scenario may lead to the leakage of trade secrets). For production accidents, the effective probability of reconstruction attacks must be strictly limited; for routine operation scenarios (medium-sensitivity data: global energy consumption, multi-device associated data): the success rate threshold ≤ 10% (e.g., 8%~10%), the impact of leakage is limited to operational efficiency, and the threshold can be appropriately relaxed; for auxiliary support scenarios (low-sensitivity data: cross-grid collaborative environmental data): the success rate threshold ≤ 15% (e.g., 12%~15%), the privacy requirements are the lowest, and data availability is prioritized); when the success rate ≤ the success rate threshold, the anti-attack score is 100 points, and 10 points are deducted for every 1% of the success rate exceeding the success rate threshold (success rate - success rate threshold) / success rate threshold × 100%), until 0 points are deducted.

[0055] (2) Second dimension: Data availability verification (adapting to industrial production decisions and avoiding data distortion).

[0056] ① Decision Support Effectiveness Verification: Regional edge nodes input anonymized core data (such as process parameters and scheduling instructions) into the industrial production decision model. The deviation rate between the output of the industrial production decision model and the original data-driven decision results is calculated (i.e., the deviation rate between the pure data (without anonymization) and the decision results generated by the same industrial production decision model as the anonymized data). The industrial production decision model is an automated decision-making tool built for industrial IoT scenarios, based on core data from the entire production process (process parameters, equipment status, scheduling instructions, etc.), through mathematical modeling, machine learning, or rule engines. Its core function is to receive input data (original data or anonymized core data) and output decision results directly related to production operations. Results (such as product quality prediction, equipment failure early warning, capacity scheduling plan, process parameter optimization suggestions, etc.) are essentially a fusion of industrial production experience, business rules, and data algorithms; they usually reuse existing mature models of enterprises, so the examples will not elaborate on existing mature models of enterprises; the decision result deviation rate is divided into quantitative decision results and categorical decision results; the calculation process of the decision result deviation rate of quantitative decision results is as follows: Calculation formula: Decision result deviation rate = |Anonymized data decision result - Original data decision result| / Original data decision result × 100%; Example: The product quality score driven by the original data is 90 points, and the score driven by the anonymized data is 85.5 points, then the deviation rate = |85.5 points|.5-90| / 90×100%=5%; Explanation: If the original data decision result is 0 (e.g., no fault risk), then "absolute deviation + threshold correction" is used (e.g., decision result deviation rate = min(absolute deviation / safety threshold, 100%)) to avoid the logical loophole of the denominator being 0; The calculation process of the decision result deviation rate for classification decision results is as follows: If the classification label of the desensitized data decision result is completely consistent with that of the original data decision result, it is recorded as "consistent"; otherwise, it is recorded as "inconsistent"; ② Decision result deviation rate = number of inconsistent samples / total number of validation samples × 100%; Example: Validating the quality grade of 100 production batches, there are 3 cases where the desensitized data and the original data decision results are inconsistent, then the decision result deviation rate = 3 / 100×100%=3%), and thus obtain the decision effectiveness score. When the deviation rate of the decision result is less than or equal to the deviation rate threshold (the deviation rate threshold is a quantitative boundary for the "acceptability of decision results" in industrial scenarios, determined through industrial scenario risk assessment: Quantitative decisions (such as capacity forecasting, quality scoring): If the deviation rate exceeds the threshold, it will lead to production plan imbalance (e.g., capacity forecast deviation > 5% leading to raw material waste) or quality control failure, so the threshold is locked at "the maximum deviation without substantial loss" (e.g., ≤ 5% for core production scenarios); Classification decisions (such as fault type, scheduling priority): If the deviation rate exceeds the threshold, it will lead to misjudgment (e.g., fault type judgment deviation > 3% may delay maintenance), so the threshold is set as the boundary of "misjudgment rate does not affect normal business operation" (e.g., ≤ 3% for core production scenarios)), the decision effectiveness score is 100 points, and 10 points are deducted for each 1% exceeding the threshold, until 0 points are reached.

[0057] The data anonymization verification module obtains the data anonymization verification index of each regional edge node based on the constructed two-dimensional cross-node verification system. When the data anonymization verification index is higher than the data anonymization verification threshold, the anonymization operation is determined to be appropriate. When the data anonymization verification index is not higher than the data anonymization verification threshold, the root cause of the problem is located and targeted adjustments are made.

[0058] The data anonymization verification index for a regional edge node is obtained as follows: The budget compliance score, anti-attack score, and decision effectiveness score of a regional edge node are obtained. The data anonymization verification index is then calculated using the formula: Data Anonymization Verification Index = (Budget Compliance Score * q1 + Anti-Attack Score * q2) * t1 + Decision Effectiveness Score * t2. q1, q2, t1, and t2 are all weighting coefficients, q1 + q2 = 1, t1 + t2 = 1, because budget compliance is the "mathematical bottom line" for privacy security. Based on the differential privacy serial combination rule... Directly quantifying the risk of privacy breaches across the entire value chain is an insurmountable fundamental constraint (such as...). Exceeding the limit means that privacy protection has failed, and its priority is higher than anti-attack verification. Therefore, the value of q1 can be 0.6 and the value of q2 can be 0.4. Since privacy and security are the "prerequisites" for industrial desensitization, the leakage of highly sensitive industrial data (such as process formulas and equipment keys) may lead to the leakage of trade secrets, production accidents, and compliance penalties. Its harm is far greater than the slight unusability of data (such as a decision bias rate of 3%, which can be optimized by fine-tuning the desensitization parameters). Decision effectiveness is the "bottom line requirement". Therefore, the value of t1 can be 0.6 and the value of t2 can be 0.4.

[0059] When the data anonymization verification index is not higher than the data anonymization verification threshold, locate the root cause of the problem and make targeted adjustments, as follows:

[0060] Based on the specific performance of budget compliance score, anti-attack score, and decision effectiveness score, identify optimization directions (avoiding blind adjustments): If the budget compliance score is low (e.g.... Exceeding the limit): The problem stems from an unreasonable allocation of privacy budgets (such as regional edge nodes). (The proportion is too high) or the scene safety threshold calibration is incorrect.

[0061] If the anti-attack score is low (e.g., the attack success rate exceeds the standard): the problem stems from insufficient noise strength (e.g., noise correction strength). Or final correction factor (Small)

[0062] If the decision effectiveness score is low (e.g., the decision result deviation rate exceeds the standard): the problem stems from excessive desensitization (e.g., the privacy enhancement coefficient em of highly sensitive core data is too large) or inconsistent data preprocessing logic (e.g., the noise reduction rules for the original data and the desensitized data are different).

[0063] Targeted adjustment measures (minor adjustments to local parameters, without changing the core logic):

[0064] Insufficient budget compliance: Reallocate end-to-end privacy budget (e.g., reduce regional edge node requirements) Improve the terminal / gateway / ,make sure ); or fine-tune the security threshold for the scenario (e.g., relax the core production scenario from 3.0 to 3.2, and simultaneously verify that the anti-attack capability has not decreased).

[0065] Weak resistance to attacks: Increase the noise intensity of highly sensitive data (e.g., adjust the regional node em from 1.1 to 1.15), optimize the g1 of the link security state coefficient Kl (from 0.15 to 0.2, strengthening privacy protection in high-risk scenarios); or implement encrypted fragmentation obfuscation rules (e.g.) The number of slices per hour increased from 4 to 5.

[0066] Insufficient decision-making effectiveness: Reduce parameters for excessive desensitization (e.g., adjust the noise attenuation coefficient lc of low-sensitivity data in the gateway from 0.8 to 0.9), optimize the proportion of discrete data masking (z1 from 0.3 to 0.25); or unify the preprocessing logic of the original data and the desensitized data (e.g., use Kalman filtering for noise reduction simultaneously).

[0067] Example 2: Edge computing differential privacy industrial IoT data anonymization verification method, the steps of which are as follows:

[0068] S1: Node partitioning and differential privacy parameter initialization: Based on the edge architecture of the Industrial Internet of Things, the edge nodes are divided into terminal edge nodes, gateway edge nodes and regional edge nodes, and differential privacy parameters are initialized for the terminal edge nodes, gateway edge nodes and regional edge nodes.

[0069] S2: Constructing a dynamic adaptive grid for industrial IoT;

[0070] S3: Dynamic noise intensity correction and hierarchical desensitization operation: Based on the dynamic adaptive mesh, the basic noise intensity of each edge node is corrected to obtain the noise correction intensity of each edge node, and the desensitization operation is performed based on the noise correction intensity of each edge node.

[0071] S4: Construct a two-dimensional cross-node verification system;

[0072] S5: Data anonymization verification and closed-loop adjustment: Based on the constructed two-dimensional cross-node verification system, obtain the data anonymization verification index of edge nodes in each region. When the data anonymization verification index is higher than the data anonymization verification threshold, determine the anonymization operation is suitable. When the data anonymization verification index is not higher than the data anonymization verification threshold, locate the root cause of the problem and make targeted adjustments.

[0073] The above formulas are all dimensionless calculations, and the preset parameters in the formulas should be set by those skilled in the art according to the actual situation.

[0074] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. An edge computing differential privacy industrial IoT data anonymization verification system, characterized in that, include: The differential privacy initialization module is used to divide edge nodes into terminal edge nodes, gateway edge nodes, and regional edge nodes according to the edge architecture of the Industrial Internet of Things, and to initialize the differential privacy parameters of the terminal edge nodes, gateway edge nodes, and regional edge nodes. The adaptive mesh building module is used to build dynamic adaptive meshes for edge nodes in industrial IoT. The noise intensity correction and desensitization module corrects the basic noise intensity of each edge node based on a dynamic adaptive mesh to obtain the noise correction intensity of each edge node, and performs desensitization operation based on the noise correction intensity of each edge node. The noise baseline intensity of each edge node is corrected based on a dynamic adaptive mesh, specifically as follows: An edge node is selected from the dynamic adaptive mesh; the application scenario bound to the mesh containing that edge node is identified; the scenario priority score for that application scenario is obtained; and simultaneously, the maximum data sensitivity index of the mesh containing that edge node is obtained. Through formula The mesh privacy security baseline value Bs of the edge node is calculated, where L1 and L2 are weighting coefficients; then, the mesh resource carrying capacity baseline value Br of the mesh where the edge node is located is obtained, using the formula... The benchmark correction factor was calculated. Further, the data fusion requirement coefficient Kf and the link security status coefficient Kl of the grid where the edge node is located are obtained, and then the formula is used to obtain the data fusion requirement coefficient Kf and the link security status coefficient Kl of the grid where the edge node is located. The final correction coefficient was calculated. Obtain the base noise intensity of the edge node. Through formula The noise correction intensity was calculated. The noise baseline intensity of the edge nodes is corrected to the noise correction intensity. ; The node verification system construction module builds a two-dimensional cross-node verification system. The data anonymization verification module obtains the data anonymization verification index of each regional edge node based on the constructed two-dimensional cross-node verification system. When the data anonymization verification index is higher than the data anonymization verification threshold, the anonymization operation is deemed suitable. When the data anonymization verification index is not higher than the data anonymization verification threshold, the root cause of the problem is located and targeted adjustments are made.

2. The edge computing differential privacy industrial IoT data anonymization verification system according to claim 1, characterized in that, Differential privacy parameter initialization is performed on terminal edge nodes, gateway edge nodes, and regional edge nodes, including: Select an edge node and obtain the importance score of the data properties corresponding to that edge node. And the impact of the leak on the score ; Through formula The data sensitivity index was calculated. ,in , All are weighting coefficients; Based on data sensitivity index The corresponding differential privacy parameter set is determined, and then the differential privacy parameters of the corresponding terminal edge nodes, gateway edge nodes and regional edge nodes are initialized based on the differential privacy parameter set.

3. The edge computing differential privacy industrial IoT data anonymization verification system according to claim 2, characterized in that, The importance score of the data properties corresponding to edge nodes The acquisition method is as follows: Obtain the property type of the data property corresponding to the edge node, determine the corresponding property score PR based on the property type, and then use the formula... =PR / PG calculation yields a score indicating the importance of the data properties corresponding to the edge nodes. Where PG is the property score threshold.

4. The edge computing differential privacy industrial IoT data anonymization verification system according to claim 2, characterized in that, Impact of data leakage at edge nodes on score The acquisition method is as follows: Obtain the application scenario corresponding to the data properties of the edge node, determine the corresponding spillover score (DL) based on the application scenario, and calculate the leakage impact score of the data properties corresponding to the edge node using the formula Si=DL / DC. Where DC is the ripple score threshold.

5. The edge computing differential privacy industrial IoT data anonymization verification system according to claim 1, characterized in that, The average CPU utilization is obtained by collecting the arithmetic mean of the real-time CPU utilization of all edge nodes in the grid where the edge node is located. The average CPU utilization is obtained by collecting the arithmetic mean of the data transmission delay of each communication link in the grid where the edge node is located. P1 and P2 are both weighting coefficients.

6. The edge computing differential privacy industrial IoT data anonymization verification system according to claim 1, characterized in that, The data fusion demand coefficient Kf is obtained by determining whether there is a data fusion request in the edge nodes of the area in the grid where the edge node is located, and then defining the fusion level. The data fusion demand coefficient Kf is calculated by the formula Kf=1+fusion level*f1, where f1 is the fusion impact coefficient.

7. The edge computing differential privacy industrial IoT data anonymization verification system according to claim 1, characterized in that, The link security status coefficient Kl is obtained by determining the average transmission delay fluctuation of the grid where the edge node is located, setting an upper threshold and a lower threshold for delay fluctuation. When the average transmission delay fluctuation is lower than the lower threshold, the security level is defined as 0. When the average transmission delay fluctuation is between the upper and lower thresholds, the security level is defined as 1. When the average transmission delay fluctuation is higher than the upper threshold, the security level is defined as 2. The link security status coefficient Kl is calculated using the formula Kl = 1 + security level * g1, where g1 is the security risk coefficient.

8. The edge computing differential privacy industrial IoT data anonymization verification system according to claim 1, characterized in that, The data anonymization verification index of a regional edge node is obtained as follows: the budget compliance score, anti-attack score, and decision effectiveness score of a regional edge node are obtained, and the data anonymization verification index of the regional edge node is calculated using the formula: Data anonymization verification index = (budget compliance score * q1 + anti-attack score * q2) * t1 + decision effectiveness score * t2; q1, q2, t1, and t2 are all weight coefficients.

9. An edge computing differential privacy industrial IoT data anonymization verification method, applied to the edge computing differential privacy industrial IoT data anonymization verification system described in claim 1, characterized in that, The steps are as follows: S1: Node partitioning and differential privacy parameter initialization: Based on the edge architecture of the Industrial Internet of Things, the edge nodes are divided into terminal edge nodes, gateway edge nodes and regional edge nodes, and differential privacy parameters are initialized for the terminal edge nodes, gateway edge nodes and regional edge nodes. S2: Constructing a dynamic adaptive grid for industrial IoT; S3: Dynamic noise intensity correction and hierarchical desensitization operation: Based on the dynamic adaptive mesh, the basic noise intensity of each edge node is corrected to obtain the noise correction intensity of each edge node, and the desensitization operation is performed based on the noise correction intensity of each edge node. S4: Construct a two-dimensional cross-node verification system; S5: Data anonymization verification and closed-loop adjustment: Based on the constructed two-dimensional cross-node verification system, obtain the data anonymization verification index of edge nodes in each region. When the data anonymization verification index is higher than the data anonymization verification threshold, determine the anonymization operation is suitable. When the data anonymization verification index is not higher than the data anonymization verification threshold, locate the root cause of the problem and make targeted adjustments.

Citation Information

Patent Citations

  • Cross-platform education data privacy protection analysis system

    CN120781380A

  • Static database self-adaptive fuzzification desensitization implementation method for highly sensitive data

    CN121278774A