Trust-based crowd sensing distributed privacy protection method and system

By using reputation assessment and game theory models, user reputation is dynamically evaluated, and a global trust model is constructed. This solves the problem of malicious users in the crowd-sensing system, improves data quality and privacy protection, and enhances the system's security and stability. It is applicable to fields such as financial risk control, smart healthcare, and intelligent transportation.

CN121706141APending Publication Date: 2026-03-20GUIZHOU UNIVERSITY OF FINANCE AND ECONOMICS +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511935817.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-22
Publication Date
2026-03-20

AI Technical Summary

Technical Problem

Existing crowd-sensing systems lack effective user reputation assessment mechanisms, which may lead to malicious users providing false data or stealing privacy information, affecting the security and stability of the system and making it difficult to implement in sensitive areas.

Method used

We adopt a trust-based, distributed privacy protection approach based on collective intelligence perception. Through reputation assessment and game theory models, we dynamically evaluate user reputation, construct a global trust model, restrict malicious users, encourage honest behavior, and optimize the decision-making process through a multi-armed slot machine model to balance exploration and exploitation, thereby ensuring data quality and privacy protection.

Benefits of technology

Effectively identify and restrict malicious users, improve data quality and system stability, prevent privacy leaks, and enhance the security of system applications in fields such as financial risk control, smart healthcare, and intelligent transportation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121706141A_ABST
    Figure CN121706141A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of crowd sensing, and discloses a trust-based crowd sensing distributed privacy protection method and system, and the method comprises the steps: constructing a detailed reputation evaluation system, covering the calculation of a reputation value and the setting of a reputation threshold value of a participating user, and integrating a game model in an evaluation stage, the user is guided to avoid malicious behaviors through an income incentive mechanism so as to obtain higher income; a dobby machine model is introduced to dynamically balance the decision-making process of'exploring 'new users and'utilizing' high-reputation users, so that the cold start problem of insufficient reputation of the new users is effectively solved; and finally, verifying the security of the scheme through theoretical derivation of the security attribute of the scheme, verifying the validity of the scheme in the aspects of data credibility, privacy protection effect and the like in combination with experimental analysis, and providing support for credible operation and privacy protection of the crowd sensing system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to, but is not limited to, the field of crowd intelligence sensing technology, and particularly relates to a trust-based distributed privacy protection method and system for crowd intelligence sensing. Background Technology

[0002] Crowdsourcing sensing systems rely on large-scale data collection and sharing, typically involving a vast amount of users' personal information, such as location, health status, behavioral patterns, and consumption habits. While providing efficient services and accurate sensing, this data also exposes user privacy. Malicious users, by collecting others' personal data, may steal users' identity information. This data may involve users' daily behavior, communication records, hobbies, and so on. Once malicious users obtain sufficient information, they may engage in identity theft, impersonating users to commit financial fraud, loan fraud, and other acts, causing serious harm to users. This harm not only threatens users' personal lives but may also negatively impact the reputation, user participation, and long-term sustainable development of crowdsourcing sensing systems on a larger scale. For example, the Cambridge Analytica scandal in recent years revealed the illegal collection and misuse of millions of users' personal data on the Facebook platform. The key point of this incident was that Cambridge Analytica was able to collect a large amount of personal information from Facebook users through a seemingly harmless psychological testing application. Users provided basic personal information through the application, and using this information, Cambridge Analytica used data analysis technology to infer users' personality traits and behavioral patterns, and used this data for precise political advertising targeting and election campaigns, seriously violating users' privacy rights. Therefore, effectively protecting user privacy and preventing its leakage or misuse in a crowd-sensing system is crucial to ensuring the system's normal operation and maintaining user trust.

[0003] To address the security and privacy concerns of crowdsourced data sensing, most solutions rely on encryption algorithms as their core method. Encryption technology effectively protects data by transforming raw data into ciphertext that cannot be directly read, ensuring that even if data is intercepted during transmission, it cannot be illegally obtained or deciphered. Due to the large distribution area of ​​crowdsourced data sensing, existing privacy protection schemes typically employ a distributed architecture to avoid storing user information on a single server. This reduces the risk of data leakage because even if one node is attacked, the attacker cannot access all user data.

[0004] However, existing distributed architecture privacy protection schemes do not consider user reputation. In crowdsourced sensing scenarios, the lack of an effective user reputation assessment mechanism makes it difficult for the system to identify potentially malicious users. Such users may intentionally provide inaccurate data or attempt to obtain sensitive information from other users. Unregulated behavior may lead to a decrease in data quality and increase the potential risk of privacy breaches. Secondly, users often share data or participate in collaborative tasks. If the system cannot assess user reputation, it may lead to low-reputation users collecting, storing, or misusing the private data of other high-reputation users.

[0005] Current distributed privacy protection mechanisms widely used in crowdsourced sensing systems primarily rely on encryption algorithms and multi-node architectures to prevent centralized data leaks. However, in practical industrial applications, these mechanisms neglect dynamic assessment of user behavior reliability and lack a robust user reputation evaluation model. Because crowdsourced sensing systems heavily depend on user-uploaded data, the inability to identify malicious users or untrusted nodes makes it difficult to guarantee the credibility of data sources. This not only affects the accuracy and stability of the sensing services provided by the system but also allows malicious users to disrupt the normal operation of the entire sensing network by repeatedly submitting false data or performing abnormal interactive behaviors.

[0006] On the other hand, the widespread existence of data sharing and collaborative tasks among users leads to frequent and complex information interactions. In scenarios without a user reputation mechanism, the system struggles to restrict access to highly sensitive information for users with low reputations, easily leading to secondary leaks of user privacy. Furthermore, current solutions generally lack encrypted storage and trusted circulation mechanisms for reputation information, meaning that even with the initial introduction of reputation scoring in practical applications, its authenticity and security cannot be effectively guaranteed. This limits the deep implementation of crowdsourced sensing systems in sensitive areas such as financial risk control, smart healthcare, and intelligent transportation. Summary of the Invention

[0007] To address the problems existing in the prior art, this invention provides a trust-based, distributed privacy protection method for collective intelligence perception.

[0008] This invention is implemented as follows: a trust-based, distributed privacy protection method for collective intelligence perception, comprising:

[0009] S1: In a swarm sensing system, let... For the set of participating users, each user is In each iteration, the primary user needs to randomly select two users to serve as the primary user for the next iteration. and alternate users The system performs a reputation assessment on randomly selected users to determine whether they are reliable and trustworthy enough to serve as the primary user. If a selected user is deemed malicious, the system will trigger a reselection mechanism to reselect the primary user, ensuring that the system's credibility and data security are not threatened.

[0010] S2: In addressing the cold start problem of new users struggling to acquire reputation points, a multi-armed slot machine model is designed to balance exploration and exploitation. Decisions are made based on the user's current reputation assessment, continuously balancing "exploration" by testing new user behavior and gathering more information with "exploitation." Based on existing information, the most likely option to succeed is selected, thereby helping new users gradually acquire reputation points.

[0011] Furthermore, S1 specifically includes:

[0012] (1) Credit score calculation:

[0013] For each user Its reputation value The calculation is performed by weighted averaging of trust assessments from multiple users; this method better reflects the overall reputation of users and reduces potential assessment bias from individual users; assuming there are... User-to-user The reputation of [the company / organization] was assessed, and the [number]th [item / company] was [evaluated The evaluation results given by individual users are as follows: Then the user Reputation value The weighted average can be calculated using the following formula:

[0014] (1)

[0015] User Voting weight, User right The evaluation results reflect the user's relative importance in the evaluation. Generally, when a user has a higher reputation, their weight in the evaluation results is also greater.

[0016] To further enhance the reliability of the evaluation, a weighted voting mechanism is introduced, giving each user's vote weight. Based on the user's credit rating This weighted voting mechanism ensures that when assessing user reputation, the system will give more consideration to the opinions of users with a better historical track record, thereby improving the accuracy of the assessment.

[0017] (2)

[0018] In multi-user systems, evaluating the overall reputation of the system requires considering the impact of individual user behaviors on the global reputation. In a multi-party interactive environment, each participant's decisions and behaviors have varying degrees of impact on the overall system's credibility. This impact is not only directly related to the quality of individual user behavior but also indirectly influenced by the behaviors of other users. Therefore, a global trust model is established to integrate the reputation data of all participants. This allows for a comprehensive assessment.

[0019] (3)

[0020] in, This represents the user's reputation score at time t. User Voting weight, It is the total number of participants in the system; the use of weighted averages ensures that when calculating global reputation, the contribution of each user to the global score can be adjusted according to the importance of each user in the system.

[0021] To prevent excessive interference from malicious users, the system sets a reputation score threshold. When a user's reputation score falls below this threshold, the system will restrict them, such as limiting access permissions or prohibiting them from participating in sensitive operations, in order to reduce the potential threat of malicious users to the system's security and stability.

[0022] (2) Calculation of reputation threshold:

[0023] If we assume that all users have a credit score of 1 Furthermore, the system is based on the average credit score of all users. The threshold is set by the score calculated by formula (4);

[0024] (4)

[0025] It is the first Each user's reputation score. Then, the standard deviation of the reputation score is calculated. This indicates the volatility of the rating:

[0026] (5)

[0027] Next, a threshold is set based on the mean and standard deviation. Set as a certain deviation from the average; where, Indicates the threshold. This is the threshold coefficient, used to represent the degree of deviation between the threshold and the average score; if more stringent screening is required, This can be increased, which will cause the threshold to deviate further from the average, filtering out more extreme scores;

[0028] (3) After calculating the user's reputation value, a game model is constructed so that all participating users can reach an optimal balance through strategy selection, thereby achieving a win-win situation and ensuring that the secret aggregation is completed by a trustworthy user within the framework of privacy protection.

[0029] Furthermore, step (3) specifically includes:

[0030] (1) The system has There are [number] users, each of whom can choose one of two strategies: honest user H who provides real data, or malicious user C who provides false data. Indicates the first Individual user strategies;

[0031] (2) The payoff function in a game determines the motivation for participants to choose honesty or cheating; the payoff function should be set based on the behavior provided by users and the overall behavior of the system; assuming that the payoff function for each user is... This function depends on the strategies of all participants; assuming each user's payment function takes the following form:

[0032] (6)

[0033] in, It is the reward users receive for choosing honesty. This is the punishment users receive for choosing to cheat; to encourage honest behavior, [the following is set]. In other words, honest behavior brings higher rewards, while cheating behavior leads to relatively larger penalties; if a player chooses a long-term honesty strategy, their overall payout will accumulate more, so players will tend to be honest in the long run.

[0034] (3) Dynamically update trust levels based on historical behavior; assuming the first The trust level of an individual user is Through interactions with other users, the trust level is updated based on the user's honesty; the trust level update formula can be set as follows: ,in It is the first individual users at any time Trust level It is an indicator function, representing The value is 1 for honest users, and 0 otherwise. It is a balancing factor that controls the impact of historical trust levels on current trust levels; data provided by users with higher trust levels are considered more reliable.

[0035] (4) Assumption If a game satisfies a Nash equilibrium, meaning that under this strategy configuration, no user is willing to unilaterally change their strategy, then the condition for a Nash equilibrium is: For all All of these hold true; that is, under Nash equilibrium, each participant chooses the optimal strategy while keeping the strategies of others constant.

[0036] The system continuously iterates and calculates trust levels and payoff functions, eventually converging to a stable state where all participants have chosen the optimal strategy without external intervention, achieving a game equilibrium. This ensures that the selected users are honest and trustworthy.

[0037] Furthermore, S2 specifically includes:

[0038] (1) By setting an exploration probability This balances the trade-off between exploration and exploitation. At each time step, the system... The probability is to randomly select one arm to explore, while... The arm with the highest expected reward is selected for use with a probability of probability; let... Indicates the deadline step opposite arm The expected reward is estimated, initially assuming that the expected reward of all arms is 0; each time an arm is pulled... When you receive a reward Then update the estimated value:

[0039] (7)

[0040] in, Indicates the deadline step Until then, arm The number of times it is selected; based on the above estimate, the system at each time step Select arm:

[0041] With probability Choose the arm with the highest estimated reward: ;

[0042] With probability Choose the arm with the highest estimated reward: ;

[0043] Initialize the expected reward of each arm to zero and set the number of selections for each arm to zero. At each time step, based on The value to choose is whether to explore or exploit;

[0044] (2) A balance between exploration and exploitation is achieved by introducing uncertainty into the expected reward estimation for each arm. By calculating the confidence bound for each arm, the system is encouraged to select arms with higher uncertainty, avoiding premature abandonment of certain arms and ensuring sufficient exploration. For each arm… The upper confidence limit is calculated using formula (8), and the largest upper confidence limit is selected.

[0045] (8)

[0046] Through the above steps, in situations with high uncertainty, it can dynamically adjust the intensity of exploration by introducing confidence intervals; in the cold start phase, the system often has little understanding of each option, and can provide more exploration opportunities in the early stage, thereby gradually accumulating enough user data to optimize recommendations.

[0047] (3) Select the optimal action or arm through Bayesian inference; the core idea is to select an arm and conduct trials based on the probability distribution of each arm, and then update the probability distribution of this arm; assuming each arm There is a reward distribution, and the reward value is... It is drawn from a known probability distribution, and the goal is to find the optimal arm by selecting arms multiple times and obtaining rewards.

[0048] Assuming arm Rewards Following a Beta distribution, the reward distribution is typically used to model success or failure. Let the reward be a binary variable; the Beta distribution is a commonly used prior distribution, and its probability density function is:

[0049] (9)

[0050] in and These are the parameters of the Beta distribution. Initially, for each arm, the prior parameters of the Beta distribution are set. and Whenever choosing an arm Afterwards, rewards were observed. If the reward is 1, then update to If the reward is 0, then update to Each time an arm is selected, the mean reward sampled from the Beta distribution of each arm is used to determine which arm is selected, usually the maximum value.

[0051] Finally, the data collected from each user is preprocessed to remove obvious outliers and noise, aiming to improve data quality and ensure the accuracy of subsequent analysis. For example, if a user's uploaded data suddenly spikes to unreasonable values, it may need to be considered an outlier and removed to avoid negatively impacting subsequent data analysis and decision-making. Secondly, a user-environment variable matrix is ​​constructed, with... individual users and Environment variables, build for The similarity between users is calculated using the matrix (10). and Representing users respectively and users Detection values ​​under environmental conditions;

[0052] (10)

[0053] Furthermore, the correlation between users is calculated using formula (11) to assess whether they exhibit similar detection trends; where and Representing users respectively and users The average value of the detected values ​​in the environment; using known data and similarity information, collaborative filtering algorithms can be used to predict missing or inaccurate values;

[0054] (11).

[0055] Another objective of this invention is to provide a trust-based crowd-aware distributed privacy protection system based on the aforementioned trust-based crowd-aware distributed privacy protection method, the system specifically comprising:

[0056] The credit assessment module, in the group perception system, is set up... For the set of participating users, each user is In each iteration, the primary user needs to randomly select two users to serve as the primary user for the next iteration. and alternate users The system performs a reputation assessment on randomly selected users to determine whether they are reliable and trustworthy enough to serve as the primary user. If a selected user is deemed malicious, the system will trigger a reselection mechanism to reselect the primary user, ensuring that the system's credibility and data security are not threatened.

[0057] The slot machine model design module makes decisions based on the user's current credit assessment, continuously balancing "exploration," trying out new user behaviors, collecting more information and "utilization," and selecting the most likely successful option based on existing information, thereby helping new users gradually gain credit points.

[0058] Another object of the present invention is to provide a computer device including a memory and a processor, the memory storing a computer program, which, when executed by the processor, causes the processor to perform the steps of the trust-based crowd-aware distributed privacy protection method.

[0059] Another object of the present invention is to provide a computer-readable storage medium storing a computer program, which, when executed by a processor, causes the processor to perform the steps of the trust-based crowd-aware distributed privacy protection method.

[0060] Another objective of this invention is to provide an information data processing terminal for implementing the trust-based collective intelligence perception distributed privacy protection system.

[0061] Based on the above technical solutions and the technical problems solved, the advantages and positive effects of the technical solution to be protected by this invention are as follows:

[0062] First, to ensure user privacy in crowdsourced sensing scenarios, this invention utilizes a distributed privacy protection framework combined with a multi-party collaborative trust management mechanism to ensure proper protection of user privacy during data collection and processing, preventing malicious users from leaking sensitive information. Furthermore, by constructing a game theory model, it analyzes the competitive landscape among participating users, enabling each participant to achieve a win-win situation or optimal balance to a certain extent, thereby achieving the goal of privacy protection.

[0063] To address the cold start problem in the reputation assessment phase, which refers to the difficulty in assessing the reputation of new users due to insufficient historical behavioral data or contribution records, thus hindering the acquisition of trust points, a multi-armed slot machine model can be used. By balancing trial-and-error selection with exploitation to optimize the decision-making process, this approach effectively addresses the challenges of data scarcity or unknown environments, making it more suitable for real-world applications.

[0064] Secondly, most existing privacy protection technologies primarily address traditional privacy breaches. However, in crowdsourced sensing systems, the scenarios for information collection, sharing, and use are more complex, involving a large number of user devices and data. Therefore, this invention fills the technological gap in balancing data sharing and privacy protection within a crowdsourced sensing environment. Users with high credibility can be allowed to provide more sensitive data, while users with low credibility or unreliability require stricter data privacy protection measures. This mechanism ensures system security while avoiding efficiency losses due to over-protection. Simultaneously, by improving the multi-armed slot machine model, the balance between exploration and utilization allows the system to adapt to environmental changes. In dynamic environments, reward distributions may change, and relying solely on historical data may lead to suboptimal decisions. This invention enables the system to avoid over-reliance on specific options, reduce fluctuations caused by uncertainty, and enhance system stability.

[0065] Traditional privacy protection methods often focus on encrypting or anonymizing data, neglecting the issue of trust among participants. Trust management is a core element of crowdsourced sensing systems because the system relies on user-provided data to perform sensing tasks. Without an effective trust management mechanism, the system is vulnerable to false data or malicious behavior. This invention improves the overall system performance by jointly optimizing privacy protection and trust management. Considering the reputation of nodes, nodes with higher reputations can receive less protection for their personal data, allowing for more efficient data sharing; nodes with lower reputations will receive stronger data protection to prevent the leakage of sensitive information. The system can dynamically adjust data access permissions based on participants' reputations. Users with higher reputations can access more data, while users with lower reputations may be restricted from accessing certain sensitive data. Attached Figure Description

[0066] Figure 1 This is a flowchart of a trust-based, crowd-aware, distributed privacy protection method provided in an embodiment of the present invention.

[0067] Figure 2 This is a system framework diagram provided in an embodiment of the present invention;

[0068] Figure 3 This refers to the credibility of normal users provided in the embodiments of the present invention;

[0069] Figure 4 This refers to the credibility of malicious users provided in the embodiments of the present invention;

[0070] Figure 5 The combined attack provided in the embodiments of this invention affects the present invention;

[0071] Figure 6 This refers to the computational overhead provided by the embodiments of the present invention;

[0072] Figure 7 This is the robustness of malicious user logout provided by the embodiments of the present invention. Detailed Implementation

[0073] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0074] like Figure 1 , 2 As shown, this embodiment of the invention provides a trust-based distributed privacy protection method for crowd-aware intelligence, the method comprising:

[0075] S1: In a swarm sensing system, let... For the set of participating users, each user is In each iteration, the primary user needs to randomly select two users to serve as the primary user for the next iteration. and alternate users The system performs a reputation assessment on randomly selected users to determine whether they are reliable and trustworthy enough to serve as the primary user. If a selected user is deemed malicious, the system will trigger a reselection mechanism to reselect the primary user, ensuring that the system's credibility and data security are not threatened.

[0076] S2: In addressing the cold start problem of new users struggling to acquire reputation points, a multi-armed slot machine model is designed to balance exploration and exploitation. Decisions are made based on the user's current reputation assessment, continuously balancing "exploration" by testing new user behavior and gathering more information with "exploitation." Based on existing information, the most likely option to succeed is selected, thereby helping new users gradually acquire reputation points.

[0077] S1 specifically includes:

[0078] (1) Credit score calculation:

[0079] For each user Its reputation value The calculation is performed by weighted averaging of trust assessments from multiple users; this method better reflects the overall reputation of users and reduces potential assessment bias from individual users; assuming there are... User-to-user The reputation of [the company / organization] was assessed, and the [number]th [item / company] was [evaluated The evaluation results given by individual users are as follows: Then the user Reputation value The weighted average can be calculated using the following formula:

[0080] (1)

[0081] User Voting weight, User right The evaluation results reflect the user's relative importance in the evaluation. Generally, when a user has a higher reputation, their weight in the evaluation results is also greater.

[0082] To further enhance the reliability of the evaluation, a weighted voting mechanism is introduced, giving each user's vote weight. Based on the user's credit rating This weighted voting mechanism ensures that when assessing user reputation, the system will give more consideration to the opinions of users with a better historical track record, thereby improving the accuracy of the assessment.

[0083] (2)

[0084] In multi-user systems, evaluating the overall reputation of the system requires considering the impact of individual user behaviors on the global reputation. In a multi-party interactive environment, each participant's decisions and behaviors have varying degrees of impact on the overall system's credibility. This impact is not only directly related to the quality of individual user behavior but also indirectly influenced by the behaviors of other users. Therefore, a global trust model is established to integrate the reputation data of all participants. This allows for a comprehensive assessment.

[0085] (3)

[0086] in, This represents the user's reputation score at time t. User Voting weight, It is the total number of participants in the system; the use of weighted averages ensures that when calculating global reputation, the contribution of each user to the global score can be adjusted according to the importance of each user in the system.

[0087] To prevent excessive interference from malicious users, the system sets a reputation score threshold. When a user's reputation score falls below this threshold, the system will restrict them, such as limiting access permissions or prohibiting them from participating in sensitive operations, in order to reduce the potential threat of malicious users to the system's security and stability.

[0088] (2) Calculation of reputation threshold:

[0089] If we assume that all users have a credit score of 1 Furthermore, the system is based on the average credit score of all users. The threshold is set by the score calculated by formula (4);

[0090] (4)

[0091] It is the first Each user's reputation score. Then, the standard deviation of the reputation score is calculated. This indicates the volatility of the rating:

[0092] (5)

[0093] Next, a threshold is set based on the mean and standard deviation. Set as a certain deviation from the average; where, Indicates the threshold. This is the threshold coefficient, used to represent the degree of deviation between the threshold and the average score; if more stringent screening is required, This can be increased, which will cause the threshold to deviate further from the average, filtering out more extreme scores;

[0094] (3) After calculating the user's reputation value, a game model is constructed so that all participating users can reach an optimal balance through strategy selection, thereby achieving a win-win situation and ensuring that the secret aggregation is completed by a trustworthy user within the framework of privacy protection.

[0095] Step (3) specifically includes:

[0096] (1) The system has There are [number] users, each of whom can choose one of two strategies: honest user H who provides real data, or malicious user C who provides false data. Indicates the first Individual user strategies;

[0097] (2) The payoff function in a game determines the motivation for participants to choose honesty or cheating; the payoff function should be set based on the behavior provided by users and the overall behavior of the system; assuming that the payoff function for each user is... This function depends on the strategies of all participants; assuming each user's payment function takes the following form:

[0098] (6)

[0099] in, It is the reward users receive for choosing honesty. This is the punishment users receive for choosing to cheat; to encourage honest behavior, [the following is set]. In other words, honesty brings higher rewards, while cheating results in relatively larger penalties; if a player chooses a long-term honesty strategy, their overall payout will accumulate more, so players will tend to be honest in the long run.

[0100] (3) Dynamically update trust levels based on historical behavior; assuming the first The trust level of an individual user is Through interactions with other users, the trust level is updated based on the user's honesty; the trust level update formula can be set as follows: ,in It is the first individual users at any time Trust level It is an indicator function, representing The value is 1 for honest users, and 0 otherwise. It is a balancing factor that controls the impact of historical trust levels on current trust levels; data provided by users with higher trust levels are considered more reliable.

[0101] (4) Assumption If a game satisfies a Nash equilibrium, meaning that under this strategy configuration, no user is willing to unilaterally change their strategy, then the condition for a Nash equilibrium is: For all All of these hold true; that is, under Nash equilibrium, each participant chooses the optimal strategy while keeping the strategies of others constant.

[0102] The system continuously iterates and calculates trust levels and payoff functions, eventually converging to a stable state where all participants have chosen the optimal strategy without external intervention, achieving a game equilibrium. This ensures that the selected users are honest and trustworthy.

[0103] S2 specifically includes:

[0104] (1) By setting an exploration probability This balances the trade-off between exploration and exploitation. At each time step, the system... The probability is to randomly select one arm to explore, while... The arm with the highest expected reward is selected for use with a probability of probability; let... Indicates the deadline step opposite arm The expected reward is estimated, initially assuming that the expected reward of all arms is 0; each time an arm is pulled... When you receive a reward Then update the estimated value:

[0105] (7)

[0106] in, Indicates the deadline step Until then, arm The number of times it is selected; based on the above estimate, the system at each time step Select arm:

[0107] With probability Choose the arm with the highest estimated reward: ;

[0108] With probability Choose the arm with the highest estimated reward: ;

[0109] Initialize the expected reward of each arm to zero and set the number of selections for each arm to zero. At each time step, based on The value to choose is whether to explore or exploit;

[0110] (2) A balance between exploration and exploitation is achieved by introducing uncertainty into the expected reward estimation for each arm. By calculating the confidence bound for each arm, the system is encouraged to select arms with higher uncertainty, avoiding premature abandonment of certain arms and ensuring sufficient exploration. For each arm… The upper confidence limit is calculated using formula (8), and the largest upper confidence limit is selected.

[0111] (8)

[0112] Through the above steps, in situations with high uncertainty, it can dynamically adjust the intensity of exploration by introducing confidence intervals; in the cold start phase, the system often has little understanding of each option, and can provide more exploration opportunities in the early stage, thereby gradually accumulating enough user data to optimize recommendations.

[0113] (3) Select the optimal action or arm through Bayesian inference; the core idea is to select an arm and conduct trials based on the probability distribution of each arm, and then update the probability distribution of this arm; assuming each arm There is a reward distribution, and the reward value is... It is drawn from a known probability distribution, and the goal is to find the optimal arm by selecting arms multiple times and obtaining rewards.

[0114] Assuming arm Rewards Following a Beta distribution, the reward distribution is typically used to model success or failure. Let the reward be a binary variable; the Beta distribution is a commonly used prior distribution, and its probability density function is:

[0115] (9)

[0116] in and These are the parameters of the Beta distribution. Initially, for each arm, the prior parameters of the Beta distribution are set. and Whenever choosing an arm Afterwards, rewards were observed. If the reward is 1, then update to If the reward is 0, then update to Each time an arm is selected, the mean reward sampled from the Beta distribution of each arm is used to determine which arm is selected, usually the maximum value.

[0117] Finally, the data collected from each user is preprocessed to remove obvious outliers and noise, aiming to improve data quality and ensure the accuracy of subsequent analysis. For example, if a user's uploaded data suddenly spikes to unreasonable values, it may need to be considered an outlier and removed to avoid negatively impacting subsequent data analysis and decision-making. Secondly, a user-environment variable matrix is ​​constructed, with... individual users and Environment variables, build for The similarity between users is calculated using the matrix (10). and Representing users respectively and users Detection values ​​under environmental conditions;

[0118] (10)

[0119] Furthermore, the correlation between users is calculated using formula (11) to assess whether they exhibit similar detection trends; where and Representing users respectively and users The average value of the detected values ​​in the environment; using known data and similarity information, collaborative filtering algorithms can be used to predict missing or inaccurate values;

[0120] (11).

[0121] This invention provides a trust-based distributed privacy protection system based on the aforementioned trust-based crowd-aware perception method. The system specifically includes:

[0122] The credit assessment module, in the group perception system, is set up... For the set of participating users, each user is In each iteration, the primary user needs to randomly select two users to serve as the primary user for the next iteration. and alternate users The system performs a reputation assessment on randomly selected users to determine whether they are reliable and trustworthy enough to serve as the primary user. If a selected user is deemed malicious, the system will trigger a reselection mechanism to reselect the primary user, ensuring that the system's credibility and data security are not threatened.

[0123] The slot machine model design module makes decisions based on the user's current credit assessment, continuously balancing "exploration," trying out new user behaviors, collecting more information and "utilization," and selecting the most likely successful option based on existing information, thereby helping new users gradually gain credit points.

[0124] This invention provides a computer device, which includes a memory and a processor. The memory stores a computer program, and when the computer program is executed by the processor, the processor performs the steps of the trust-based crowd-aware distributed privacy protection method.

[0125] This invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, causes the processor to perform the steps of the trust-based crowd-aware distributed privacy protection method.

[0126] This invention provides an information data processing terminal, which is used to implement the trust-based collective intelligence perception distributed privacy protection system.

[0127] Evidence related to the technical effects obtained by the embodiments of the present invention.

[0128] 1. Theoretical Analysis

[0129] The security properties of the proposed scheme will be analyzed to demonstrate its robustness.

[0130] Theorem 4-1. The proposed solution is resistant to attacks.

[0131] Proof: First, the trust level in a crowd-sensing system is a dynamic variable that continuously adjusts based on changes in participants' historical behavior, current performance, and feedback from others. If a participating user consistently exhibits malicious behavior, their trust level will gradually decrease. Through this dynamic update mechanism, the influence of malicious participants will be gradually weakened. Therefore, malicious behavior cannot affect the overall outcome of the system in the long term.

[0132] Secondly, the interaction and trust propagation among multiple participating users effectively prevents a single malicious actor from influencing the entire system. This propagation can be described using a graph theory model. Let the trust network consist of... The system consists of 10 participating users, who trust each other through edges. The propagation rule of trust is shown in formula (12):

[0133] (12)

[0134] The system adjusts trust levels by incorporating user feedback. When multiple neighboring users provide consistent feedback, the system can identify and lower the trust level of malicious users. In this way, even if a malicious user manages to disrupt the system through a small number of users, their misconduct will be suppressed by the legitimate feedback from other users, thus reducing the negative impact on the system.

[0135] The robustness of this system is demonstrated by the fact that even if a certain number of malicious users exist within the system, the overall system can still continue to operate. Assuming the system contains... One malicious user and Among the honest users, Let be the total number of users. Assume the quality of malicious users' behavior is negative, and the quality of honest users' behavior is positive. Next, we need to prove that the system can tolerate the existence of malicious users without being completely compromised. To ensure the overall security of the system, the trust level of each user will not fall below a certain minimum value to prevent excessively lowering the trust level of some participating users, which could lead to system crashes. For each time step, the system can tolerate a maximum of [missing value]. The impact of a malicious user, as long as the remaining... The trust level of honest users is high enough that they can compensate for the impact of malicious users through mutual cooperation. Let the average trust level of all honest users in the system be , then the overall system trust level should satisfy the following condition:

[0136] (13)

[0137] Therefore, as long as the trust level of honest users remains above the minimum threshold... In this way, the overall trust level of the system can be maintained within a safe range, resisting the impact of malicious attacks.

[0138] Finally, the outlier detection feature of this invention aims to identify malicious users who upload abnormal values. For example, if at a certain moment the system detects that a user's behavior is significantly lower than expected, the system can determine that the user is malicious and take appropriate measures, such as removing the user's influence or minimizing their trust level. In this way, the system can effectively isolate malicious behavior and ensure overall security.

[0139] Based on the above steps and assumptions, we conclude that this solution can avoid security problems caused by malicious users.

[0140] Theorem 4-2. This invention is convergent.

[0141] Proof: Convergence means that within a finite time period, through continuously updated trust values, the system will stabilize to a certain state without infinite fluctuations or instability. To analyze the convergence of this trust update process, we first represent the trust value update process as a matrix multiplication model. Let... This is a column vector representing the trust values ​​of all users. Trust weights are also defined. Let be an m*m matrix, describing the propagation of trust among users in the entire trust network. In this way, trust value updates can be iteratively performed using matrix multiplication. To ensure that the trust values ​​eventually converge, the matrix needs to be analyzed. The eigenvalues ​​of a matrix are obtained by solving the equations. We obtain the spectral radius, which is the absolute value of the largest eigenvalue of the matrix. If the spectral radius satisfies... If the spectral radius is less than 1, the system's trust value will gradually stabilize. This condition ensures that the iterative process of the trust value will converge to a fixed value within a finite time, without producing unstable oscillations or divergences.

[0142] When calculating the spectral radius, if only a multi-party collaborative trust management approach is adopted, the spectral radius is often greater than 1, which may lead to an explosive increase or decrease in user trust, affecting system stability. To address this issue, the proposed solution calculates a reputation threshold to prevent users' reputation values ​​from drastically increasing or decreasing. This is equivalent to adjusting the trust weight. Scaling the matrix reduces the spectral radius, but it's still not stable enough. To ensure the spectral radius continues to approach 1, the proposed game theory model ensures that participating users maximize their profit by avoiding malicious behavior. This, in turn, modifies the matrix... After regularization, the system is nearly stable, with the spectral radius reduced to 1, ensuring that user reputation remains stable. To further improve system stability, the solution addresses the cold start problem by modifying the matrix... After symmetry adjustment, the spectral radius stabilizes at 1. The system stability is fully guaranteed, meeting the stability requirements in crowdsourced sensing scenarios.

[0143] Based on the above steps and assumptions, we can conclude that the scheme has a certain degree of convergence.

[0144] 2. Experimental Analysis

[0145] 2.1 Experimental Environment and Setup

[0146] To evaluate the performance of this invention, the proposed incentive mechanism environment, experimental hardware environment (CPU: Intel Core i5-8300H, memory: 8192MB RAM), and experimental software environment (operating system: Windows 11 64-bit, system kernel: Windows 11 Professional 21H2, runtime environment: Python 3.7.8) were used. This invention uses an artificially generated dataset, and the participating users are set as follows: The reputation score of each participating user Each data source contains Each timestamp data point has a value within the specified range. Between. For each participating user, assume their normal observations follow an expected value of y=5 and a variance of... The Gaussian distribution, where The value is in the interval Independent and uniform sampling is performed. To ensure the validity of normal data, it is limited to within two standard deviations of the expected value. That is, every normal data point meets this condition.

[0147] In terms of experimental comparison, this invention uses the CRH algorithm and PPTD algorithm as the basic algorithms for comparison, and compares the effectiveness of the three schemes in terms of credibility assessment, anti-attack ability, and computational cost.

[0148] 2.2 Experimental Results and Analysis

[0149] (1) Credibility assessment

[0150] This invention involved multiple rounds of experiments to analyze the differences in credibility exhibited by normal users and malicious users within the system. Each round of experiments included two key operations: First, for normal users, positive feedback was provided to increase their credibility score in the system, thereby enhancing their trustworthiness in subsequent tasks; simultaneously, for users identified as malicious, negative feedback was applied to reduce their credibility, ultimately leading to the removal of these malicious users from the system. This experimental design not only effectively assesses the behavioral patterns of different user types but also improves the system's overall credibility management capabilities by optimizing the feedback mechanism, thus ensuring the system can more accurately identify and respond to malicious behavior.

[0151] Figure 3 The figure illustrates the process by which participating users' credibility, starting from an initial value of 0.5, gradually increases over time and eventually stabilizes. The figure shows the significant differences in growth rates among the three schemes, with the proposed model exhibiting a relatively slow growth trend. In contrast, the CRH model, due to the long-term accumulation of honest behavior, rapidly increases the weight of honest behavior, driving a rapid increase in credibility and exhibiting the fastest-rising growth curve. Meanwhile, the PPTD scheme's credibility updates are relatively slow, with a lower growth rate than the CRH model. The proposed scheme, relying on a multi-party collaborative reputation assessment method, employs a more robust and gradual growth mechanism, thus exhibiting the slowest growth rate. This growth characteristic is more consistent with the process of user credibility accumulation in real-world applications, as user credibility typically accumulates gradually and tends towards stability rather than fluctuating rapidly. Therefore, this invention is more in line with practical application scenarios.

[0152] Furthermore, the credibility of malicious users was explored in depth, such as... Figure 4As shown, the credibility of participating users gradually decreases over time due to their continuous malicious behavior. This change reflects the impact of malicious behavior on the reputation system. It is noteworthy that all three schemes exhibit a decrease in credibility when participating users begin malicious behavior, eventually reaching a low and stable level. However, although the CRH scheme's credibility growth is slower than the PPTD scheme, its credibility decline rate after a malicious attack remains relatively slow. In contrast, the scheme of [Scheme Name] exhibits a significantly faster credibility decline when encountering malicious attacks. The core reason for this difference lies in the multi-party collaborative trust management mechanism introduced in the scheme. This mechanism prioritizes the current user's reputation rather than relying on historical reputation data when assessing malicious behavior. This means that when a user engages in malicious behavior, the system can quickly identify and adjust their reputation score, thereby rapidly weakening the malicious user's credibility. This approach ensures that the system can react more promptly to malicious behavior, enhancing the defense effect. This design not only improves the efficiency of malicious behavior identification but also enhances the system's robustness against malicious users. Therefore, compared to other schemes, [Scheme Name]'s model demonstrates higher sensitivity and a faster credibility decline when dealing with malicious attacks.

[0153] (2) Resistance to attack

[0154] To address potential coordinated attacks, a joint anomaly detection mechanism was designed. This mechanism forms a collective judgment by sharing trust assessment results among users, effectively addressing this issue. For example... Figure 5 As shown, without collective judgment, participating users performed well in the first 22 evaluation periods, with their credibility rising to 0.526. After the attack, the credibility of participating users dropped rapidly, but recovered to 0.5258 after only one evaluation period. With the collective judgment mechanism applied, the credibility of participating users plummeted in the 22nd evaluation period, and although it slowly recovered afterward, it remained below the previous credibility level. This means that malicious users need a longer time to restore their credibility to its original level, further validating the effectiveness of the invention.

[0155] (4) Calculate the cost

[0156] In evaluating the computational overhead of the solution, a series of experiments were conducted with varying numbers of users, ranging from 10 to 50. In each experiment, the time consumption of each operation process for different functional modules was evaluated in detail. The computational overhead comprises the following core components:

[0157] Data acquisition overhead: This part of the overhead mainly involves the data acquisition process during the task execution by participating users. By estimating the amount of data collected by each participating user per instance and combining it with the sampling frequency, the total amount of data collected by each participating user per unit time is calculated.

[0158] Local computing overhead: After data collection is complete, each participating user typically performs certain data processing tasks, such as data filtering. This overhead reflects the computing resources required for each participating user to perform data processing locally.

[0159] Transmission overhead: When data is transmitted to the server platform via a wireless network, a certain amount of bandwidth is consumed. The assessment of transmission overhead mainly considers packet size, transmission frequency, and network bandwidth limitations. The total amount of data that each participating user needs to transmit over the network was analyzed to estimate the overall transmission overhead.

[0160] Collaboration overhead: In a crowdsourced sensing system, participating users need to exchange data and perform collaborative computation. The overhead incurred in this process is called collaboration overhead. It encompasses the computational resource consumption required for information sharing, data synchronization, and collaborative decision-making among participating users.

[0161] like Figure 6 As shown, the method exhibits excellent performance in terms of computational overhead as the number of users participating in the task changes, especially with the computational overhead remaining within a reasonable range as the number of users increases. This indicates that regardless of the scale of the task, the present invention can effectively handle more user participation without excessive waste of computational resources. A comparison with other solutions demonstrates that the method improves system processing power while fully ensuring computational efficiency and optimizing resource allocation.

[0162] (3) Robustness of malicious user logout

[0163] To verify the robustness of this invention in the event of malicious user logout, this experiment statistically analyzed the relationship between the number of users participating in the sensing task and the number of system failures. Specific results can be found in [link to results]. Figure 7 During the experiment, if a malicious user exits during runtime, causing the task to be unable to continue and requiring a restart, this situation is considered a system failure. According to the design of this invention, the task will only fail to continue execution and be judged as a failure if the number of online users falls below a preset threshold. Experimental results show that the number of system failures increases with the number of users participating in the task. However, as long as the number of malicious users who exit does not exceed the predetermined threshold, the system can still maintain high robustness, ensuring that the task can proceed normally under a wide range of conditions.

[0164] Based on the above experimental results, this invention demonstrates good resistance to attacks and superior computational efficiency in practical applications, and can maintain stable performance in multi-user environments. This means that regardless of increased task load or number of users, this invention can effectively handle complex and dynamic task requirements, providing reliable and efficient support. This makes the invention more adaptable to changing real-world application scenarios, and while improving system performance, it maintains the rational utilization of computing resources, demonstrating high practical application value.

[0165] It should be noted that embodiments of the present invention can be implemented in hardware, software, or a combination of both. The hardware portion can be implemented using dedicated logic; the software portion can be stored in memory and executed by a suitable instruction execution system, such as a microprocessor or dedicated-design hardware. Those skilled in the art will understand that the above-described devices and methods can be implemented using computer-executable instructions and / or included in processor control code, for example, such code provided on a carrier medium such as a disk, CD, or DVD-ROM, a programmable memory such as read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. The devices and modules of the present invention can be implemented by hardware circuitry such as very large-scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, or programmable hardware devices such as field-programmable gate arrays, programmable logic devices, etc., or by software executed by various types of processors, or by a combination of the above-described hardware circuitry and software, such as firmware.

[0166] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications, equivalent substitutions, and improvements made by those skilled in the art within the scope of the technology disclosed in the present invention, and within the spirit and principles of the present invention, should be covered within the scope of protection of the present invention.

Claims

1. A trust-based, distributed privacy protection method for crowd-based intelligent perception, characterized in that, The method includes: S1: In a swarm sensing system, let... For the set of participating users, each user is In each iteration, the primary user needs to randomly select two users to serve as the primary user for the next iteration. and alternate users The system performs a reputation assessment on randomly selected users to determine whether they are reliable and trustworthy enough to serve as the primary user. If a selected user is deemed malicious, the system will trigger a reselection mechanism to re-select the primary user, ensuring that the system's credibility and data security are not threatened. S2: By designing a multi-armed slot machine model to balance exploration and exploitation, decisions are made based on the user's current credit assessment, and the option most likely to succeed is selected based on available information.

2. The trust-based distributed privacy protection method for crowd-aware perception according to claim 1, characterized in that, S1 specifically includes: (1) Credit score calculation: For each user Its reputation value The calculation is performed by weighted averaging of trust assessments from multiple users; assuming there are... User-to-user The reputation of [the company / organization] was assessed, and the [number]th [item / company] was [evaluated The evaluation results given by individual users are as follows: Then the user Reputation value The weighted average can be calculated using the following formula: (1), User Voting weight, User right The evaluation results reflect the user's relative importance in the evaluation. Generally, when a user has a higher reputation, their weight in the evaluation results is also greater. To further enhance the reliability of the evaluation, a weighted voting mechanism is introduced, giving each user's vote weight. Based on the user's credit rating To determine, that is: (2), Establish a global trust model to integrate the reputation data of all participants. This allows for a comprehensive assessment. (3), in, This indicates the user's reputation score at a given time step. User Voting weight, It is the total number of participants in the system; the use of weighted averages ensures that when calculating global reputation, the contribution of each user to the global score can be adjusted according to the importance of each user in the system. (2) Calculation of reputation threshold: All users' credit rating is Furthermore, the system is based on the average credit score of all users. The threshold is set by the score calculated by formula (4); (4), It is the first The user's reputation score is calculated; then, the standard deviation of the reputation score is calculated. This indicates the volatility of the rating: (5), Next, a threshold is set based on the mean and standard deviation. Set as a certain deviation from the average; where, Indicates the threshold. This is the threshold coefficient, used to represent the degree of deviation between the threshold and the average score; more stringent screening is required. You can increase it, which will make the threshold deviate further from the average value and filter out more extreme scores.

3. The trust-based distributed privacy protection method for crowd-aware perception as described in claim 2, characterized in that, Step (3) specifically includes: (1) The system has There are [number] users, each of whom can choose one of two strategies: honest user H who provides real data, or malicious user C who provides false data. Indicates the first Individual user strategies; (2) Assume that the payment function for each user is This function depends on the strategies of all participants; assuming each user's payment function takes the following form: (6), in, It is the reward users receive for choosing honesty. This is the punishment users receive for choosing to cheat; to encourage honest behavior, [the following is set]. In other words, honest behavior leads to higher rewards, while cheating behavior results in relatively higher penalties; (3) Update the trust level dynamically based on historical behavior; the trust level update formula can be set as follows: ,in It is the first individual users at any time Trust level It is an indicator function, when The value is 1 if the user is honest, and 0 otherwise. It is a balancing factor that controls the impact of historical trust levels on current trust levels; (4) Assumption If a game satisfies a Nash equilibrium, meaning that under this strategy configuration, no user is willing to unilaterally change their strategy, then the condition for a Nash equilibrium is: For all All are true; The system continuously iterates and calculates trust levels and payoff functions, eventually converging to a stable state where all participants have chosen the optimal strategy without external intervention, achieving a game equilibrium. This ensures that the selected users are honest and trustworthy.

4. The trust-based distributed privacy protection method for crowd-aware perception as described in claim 1, characterized in that, S2 specifically includes: (1) By setting an exploration probability At each time step, the system uses The probability is to randomly select one arm to explore, while... The arm with the highest expected reward is selected for use with a probability of probability; let... Indicates the deadline step opposite arm The expected reward is estimated, initially assuming that the expected reward of all arms is 0; each time an arm is pulled... When you receive a reward Then update the estimated value: (7), in, Indicates the deadline step Until then, arm The number of times it is selected; based on the above estimate, the system at each time step Select arm: With probability Choose the arm with the highest estimated reward: ; With probability Choose the arm with the highest estimated reward: ; Initialize the expected reward of each arm to zero, and set the number of choices for each arm to zero; at each time step, based on The value to choose is whether to explore or exploit; (2) For each arm The upper confidence limit is calculated using formula (8), and the largest upper confidence limit is selected. (8), (3) Assume each arm There is a reward distribution, and the reward value is... It is drawn from a known probability distribution; Assuming arm Rewards Following a Beta distribution, the reward distribution is typically used to model success or failure. Let the reward be a binary variable; the Beta distribution is a commonly used prior distribution, and its probability density function is: (9), in and These are the parameters of the Beta distribution. Initially, for each arm, the prior parameters of the Beta distribution are set. and Whenever choosing an arm Afterwards, rewards were observed. If the reward is 1, then update to If the reward is 0, then update to Each time an arm is selected, the mean reward sampled from the Beta distribution of each arm is used to determine which arm is selected, usually the maximum value. Finally, the data collected from each user is preprocessed, and a set of... individual users and Environment variables, build for The similarity between users is calculated using the matrix (10). and Representing users respectively and users Detection values ​​under environmental conditions; (10), Furthermore, the correlation between users is calculated using formula (11) to assess whether they exhibit similar detection trends; where and Representing users respectively and users The average value of the detected values ​​in the environment; (11)。 5. A trust-based distributed privacy protection system based on the trust-based crowd-aware perception method as described in claims 1-4, characterized in that, The system specifically includes: The credit assessment module, in the group perception system, is set up... For the set of participating users, each user is In each iteration, the primary user needs to randomly select two users to serve as the primary user for the next iteration. and alternate users The system performs a reputation assessment on randomly selected users to determine whether they are reliable and trustworthy enough to serve as the primary user. If a selected user is deemed malicious, the system will trigger a reselection mechanism to re-select the primary user, ensuring that the system's credibility and data security are not threatened. The slot machine model design module makes decisions based on the user's current credit assessment, continuously balancing "exploration," trying out new user behaviors, collecting more information and "utilization," and selecting the most likely successful option based on existing information, thereby helping new users gradually gain credit points.

6. A computer device, characterized in that, The computer device includes a memory and a processor. The memory stores a computer program that, when executed by the processor, causes the processor to perform the steps of the trust-based crowd-aware distributed privacy protection method as described in any one of claims 1-4.

7. A computer-readable storage medium, characterized in that, The system contains a computer program that, when executed by a processor, causes the processor to perform the steps of the trust-based crowd-aware distributed privacy protection method as described in any one of claims 1-4.

8. An information data processing terminal, characterized in that, The information data processing terminal is used to implement the trust-based, crowd-aware, distributed privacy protection system as described in claim 5.

Citation Information

Cited By

  • A scene-aware and zero-click transmission agent privacy protection test method

    CN122389048A