Distributed differential privacy security parameter estimation method and device based on output disturbance, equipment and storage medium
A distributed differential privacy-preserving parameter estimation method with added Laplace noise and a decreasing step size strategy at the output is proposed to solve the problem of balancing data privacy and estimation accuracy in multi-agent systems, and to achieve stable parameter estimation and privacy protection in complex industrial environments.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIHANG UNIV
- Filing Date
- 2026-02-11
- Publication Date
- 2026-05-08
AI Technical Summary
In the collaborative estimation and control process of multi-agent systems, existing technologies struggle to maintain estimation accuracy and convergence efficiency while ensuring data privacy, and are ill-suited to the complex and variable observation conditions in industrial settings, especially when the observation matrix is unknown or time-varying.
By adding fixed-scale Laplace noise to the output and combining it with a decreasing step size strategy, a distributed differential privacy-preserving parameter estimation method is constructed to ensure the privacy protection of each output data. The mean square convergence is theoretically proven and it is applicable to industrial scenarios where the observation matrix is known or unknown.
It achieves stable and reliable parameter estimation results while ensuring data privacy, adapts to changing industrial environments, ensures the accuracy and real-time performance of system status and parameter estimation, and is applicable to scenarios such as multi-robot collaborative operation, environmental monitoring networks, and smart grids.
Smart Images

Figure CN122001771A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of automatic control and information security technology, and in particular to a distributed differential privacy security parameter estimation method, apparatus, device and storage medium based on output perturbation. Background Technology
[0002] Over the past few decades, network control and cooperative control technologies have been widely researched and applied. However, in the cooperative estimation and control of multi-agent systems, the privacy and security issues involving the local data of each agent have not received sufficient attention. In many scenarios, the output observation data of agents often contain sensitive information: for example, in target localization problems, the distance measurement output of an agent may expose its own position; in machine learning model training, the gradient information shared by each node may be used to reconstruct the original training data. Recent studies have shown that in distributed optimization and estimation algorithms, unprotected exchange of intermediate information can lead to privacy leaks (such as gradient leakage attacks). Therefore, ensuring data privacy while achieving parameter identification and state estimation in networked systems is of great significance for industrial IoT and cyber-physical systems.
[0003] Differential privacy, a rigorous mathematical definition of privacy proposed by Cynthia Dwork et al., has been successfully applied in numerous fields such as database querying, machine learning, and optimization control. In the fields of distributed control and the Industrial Internet of Things (IIoT), there have been attempts to introduce differential privacy into collaborative algorithms, such as adding noise to distributed optimization, consensus algorithms, game theory, and distributed estimation to protect the data of participating parties. However, existing technologies still have significant limitations in terms of privacy protection effectiveness, system estimation performance, and model adaptability in real-world industrial scenarios. In IIoT environments, such as multi-robot collaborative operation systems or wide-area sensor networks, the observation data of each node changes in real time and often contains sensitive information. Traditional methods often struggle to balance privacy and accuracy. While adding noise can improve privacy, it can lead to a decrease in the accuracy of system state or parameter estimation and slow convergence, affecting the real-time performance and accuracy of control and decision-making. Reducing noise can improve estimation efficiency, but it is insufficient to cope with potential eavesdropping and inference attacks in real-world systems, weakening privacy protection. Furthermore, the observation conditions in actual industrial settings are complex and variable. Sensing matrices may exhibit uncertainty and time-varying characteristics due to equipment features, communication interference, or missing information. Existing solutions lack sufficient flexibility and robustness when handling such incompletely known or randomly time-varying observation models. Therefore, it is necessary to propose a novel distributed estimation scheme that, while providing strict differential privacy guarantees, balances estimation accuracy and convergence efficiency, and can adapt to various real-world industrial scenarios, including those with known and unknown observation matrices. This will meet the dual requirements of networked control systems for data security and estimation performance. Summary of the Invention
[0004] This application provides a distributed differential privacy-preserving parameter estimation method, apparatus, device, and storage medium based on output perturbation, which is used to solve the problem of synergistic optimization between strict differential privacy protection and distributed parameter estimation accuracy and convergence efficiency in actual industrial scenarios where the observation matrix is known or unknown.
[0005] Firstly, this application provides a distributed differential privacy-preserving parameter estimation method based on output perturbation, applicable to multi-agent cooperative estimation and control scenarios in industrial IoT or cyber-physical systems. This method aims to protect the privacy of each agent's output observation data while achieving networked system parameter identification and state estimation. The method includes the following steps: S1. Construct a distributed network parameter estimation model consisting of multiple agents, and set initial parameter estimates for each agent; S2. In each iteration, each agent obtains its current output observation data, generates a Laplace noise vector and adds it to the output observation data to obtain the perturbed output data, so as to ensure that each iteration meets the ε-differential privacy requirement. S3. Based on the preset network topology, each agent sends its current parameter estimate and perturbed output data to neighboring agents and receives parameter estimates from neighboring agents. S4. Depending on whether the input matrix corresponding to the agent is completely known, update the estimated parameter value of the agent using the corresponding parameter update rule. S5. After each iteration, determine whether the change in the parameter estimates of all agents is lower than the preset threshold. If not, return to step S2 to enter the next iteration. If the threshold is met, terminate the iteration. S6. Output the parameter estimates that converge to a consensus among all agents as the estimation results of the unknown parameters of the target.
[0006] In one possible design, in step S1, the observation model for each agent is: in, This represents the set of vertices in the corresponding network graph. , The number of vertices; Number the intelligent agents; For a specific moment; For intelligent agents exist The measurement output vector at time; For intelligent agents exist Time-varying measurement or input matrix at any given moment; For intelligent agents exist The noise vector at time step; Let be the vector of unknown parameters to be estimated.
[0007] In one possible design, each element in the Laplace noise vector is independent and identically distributed, and follows a distribution with a mean of zero and a variance of . Laplace noise, Let the scale parameter of the Laplace noise satisfy: in Used to characterize the "degree of similarity" between two similar sensitive pieces of information, if for any , For a distance space, we have Then it is called and In distance metric In a sense, it means - Adjacent. To characterize the spatial distance of sensitive information, The measurable space corresponding to the opponent's observation. From arrive The random mapping, and Let be a probability space. If for any -Adjacency and any set All have , If it is a natural constant, then it is called a random mapping. yes -adjacent Differential privacy. The description of the opponent based on observation information (a certain Distinguish sensitive information Information about its neighbors The difficulty. The smaller the value, the more difficult it is for the opponent to distinguish these two sensitive pieces of information. Therefore, a smaller value... With larger This indicates that the system has a higher level of privacy protection capabilities.
[0008] In one possible design, depending on whether the input matrix corresponding to the agent is completely known, the agent updates its parameter estimates using corresponding parameter update rules, including: when When everything is known, the agent Update its estimate according to the following rules: in, Represents intelligent agents exist Parameter estimation at time 10:00 Represents intelligent agents exist Parameter estimation at time 10:00 Represents intelligent agents exist Parameter estimation at time 10:00 For matrix transpose, For intelligent agents The Laplacian noise vector, for The step size of time, For intelligent agents The neighbor set; when When some information is known, the agent Update its estimate according to the following rules: in, for The expectation matrix, , For expectation operators.
[0009] In one possible design, the step size is a step size that decreases with time, satisfying: in, for The step size of time.
[0010] In one possible design, ,and In the case of each iteration - Satisfies under adjacency property - Differential privacy, convergence rate satisfies: when hour, ; when hour, ; in, This represents the set of vertices in the corresponding network graph. The agent's ID number. For privacy parameters of differential privacy, For threshold parameters, The exponential parameter of the step size. The scale parameter for Laplace noise. The maximum value between adjacent output data sequences Sensitivity Let the square norm of the parameter estimation error be denoted as . It is the upper bound of the same order.
[0011] Secondly, this application provides a distributed differential privacy-preserving parameter estimation device based on output perturbation, applicable to multi-agent cooperative estimation and control scenarios in industrial IoT or cyber-physical systems, to protect the privacy of each agent's output observation data while achieving networked system parameter identification and state estimation. The device includes: The initial estimation module is configured to build a distributed network parameter estimation model consisting of multiple agents and set initial parameter estimates for each agent. The noise addition module is configured to, in each iteration, have each agent acquire its current output observation data, generate a Laplace noise vector, and add it to the output observation data to obtain perturbed output data, thus ensuring that each iteration satisfies the requirements. - Differential privacy requirements; The data communication module is configured to send its current parameter estimates and perturbed output data to neighboring agents based on a preset network topology, and receive parameter estimates from neighboring agents. The parameter update module is configured to update its own parameter estimates according to whether the input matrix of the agent is completely known, using the corresponding parameter update rules. The iteration judgment module is configured to determine whether the change in the parameter estimates of all agents is lower than a preset threshold after each iteration. If the threshold is not met, the module returns to the noise addition module to enter the next iteration. If the threshold is met, the iteration is terminated. The output module is configured to output the parameter estimates that converge to a consensus among the agents as the estimation results of the unknown parameters of the target.
[0012] Thirdly, embodiments of this application provide an electronic device, including: at least one processor and a memory; the memory stores computer-executable instructions; the at least one processor executes the computer-executable instructions stored in the memory, causing the at least one processor to perform the distributed differential privacy security parameter estimation method based on output perturbation as described in the first aspect and various possible designs of the first aspect.
[0013] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions. When a processor executes the computer-executable instructions, it implements the distributed differential privacy and security parameter estimation method based on output perturbation as described in the first aspect and various possible designs of the first aspect.
[0014] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the distributed differential privacy and security parameter estimation method based on output perturbation as described in the first aspect and various possible designs of the first aspect.
[0015] The distributed differential privacy-preserving parameter estimation method, apparatus, device, and storage medium based on output perturbation provided in this application have at least the following beneficial effects: This application achieves consistent output data publishing by adding fixed-scale Laplace noise to the output. - Differential privacy protection effectively addresses the risk of node data being eavesdropped on or inferred in industrial sensor networks; combined with a decreasing step size strategy, mean square convergence is theoretically proven, meaning that the estimated mean of each agent converges to the true parameters, and the estimation error variance is bounded. This ensures stable and reliable parameter estimation results under privacy protection in scenarios such as multi-robot cooperative localization or production line quality estimation; privacy parameters are given. Noise scale The quantitative relationship with convergence characteristics provides a clear design basis for practical system configuration. This application supports both known and unknown observation matrices. For unknown or randomly time-varying observation matrices, it remains applicable and convergent as long as certain statistical conditions (such as expected boundedness) are met. For example, in environmental monitoring networks, some sensor calibration parameters may be unknown; or in smart grid load identification, user electricity consumption pattern matrices may be time-varying. This method is applicable in both cases, thus enabling accurate parameter estimation while ensuring data transmission security in a wide range of practical industrial scenarios. Attached Figure Description
[0016] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0017] Figure 1 A flowchart of a distributed differential privacy-preserving parameter estimation device based on output perturbation provided in this application embodiment; Figure 2 Network topology diagram provided for embodiments of this application; Figure 3 The trajectory estimation map provided in the embodiments of this application has a completely known input matrix; Figure 4 The trajectory estimation map provided in the embodiments of this application has a partially known input matrix; Figure 5 This is a structural diagram of a distributed differential privacy-preserving parameter estimation device based on output perturbation, provided in an embodiment of this application.
[0018] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concepts of this application to those skilled in the art through reference to specific embodiments. Detailed Implementation
[0019] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0020] The collection, storage, use, processing, transmission, provision, and disclosure of financial data or user data involved in the technical solution of this application all comply with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0021] It should be noted that in the embodiments of this application, certain software, components, models and other existing solutions in the industry may be mentioned. These should be regarded as exemplary and are only intended to illustrate the feasibility of implementing the technical solution of this application. However, it does not mean that the applicant has used or necessarily used the solution.
[0022] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0023] This application provides a distributed differential privacy-preserving parameter estimation method based on output perturbation, which can be applied to multi-agent collaborative estimation and control scenarios in industrial IoT or cyber-physical systems to protect the privacy of each agent's output observation data while realizing networked system parameter identification and state estimation.
[0024] Specifically, the method provided in this application is applicable to various distributed physical systems or industrial IoT scenarios that require collaborative sensing, estimation, or control and have explicit requirements for data privacy. The following are descriptions of some specific application scenarios.
[0025] In environmental monitoring sensor network scenarios, agents are widely deployed temperature, humidity, air quality, or water quality monitoring sensor nodes. Each sensor node continuously observes specific environmental indicators at its deployment location, constituting its output observation data. These nodes need to collaborate to estimate pollution diffusion model parameters or temperature field distribution across the entire monitoring area, i.e., unknown parameters of the target. However, the precise readings of a single node may expose its corresponding sensitive location information or details of exceedances in specific areas. Applying the method of this application, each node can add noise before sharing data, thereby protecting the specific readings and location privacy of individual nodes while jointly constructing a high-precision regional environmental model.
[0026] In non-intrusive load monitoring scenarios for smart grids, the intelligent agents are smart meters or home energy managers installed at different user terminals. These devices continuously observe real-time electricity consumption data such as current and voltage waveforms on the incoming bus, constituting their output observation data. They need to collaboratively estimate the operating modes or aggregated load curves of typical appliances in a region, i.e., the target unknown parameters. However, the electricity consumption details of each household directly reflect highly private information such as their living habits and whether they are at home. Applying the method of this application, each meter can perturb the waveform data before reporting the data for collaborative analysis, thereby achieving accurate regional load forecasting or fault identification while effectively preventing the leakage of users' personal privacy activities.
[0027] In collaborative process monitoring scenarios on industrial production lines, intelligent agents are visual sensors, vibration sensors, or spectrometers installed at various workstations along the assembly line. Each device collects images, vibration signals, or component spectra of the product, constituting its output observation data. They need to collaborate to estimate key parameters describing product quality, equipment health status, or process stability—i.e., target unknown parameters. However, the raw sensor data may contain core defect characteristics of the product or trade secrets related to equipment performance. Applying the method of this application, noise can be added to the equipment at each workstation before exchanging data for overall quality assessment, thereby achieving accurate estimation of the entire production line status and predictive maintenance while protecting the specific process details and data assets of each section.
[0028] In multi-robot cooperative search and mapping scenarios, the intelligent agent is the individual mobile robots in a robot swarm. Each robot acquires local distance or feature point information of its surrounding environment through its onboard LiDAR and visual sensors, forming its output observation data. They need to collaboratively estimate the global position coordinates of all robots or fuse them to generate a consistent global environment map, i.e., the unknown parameters of the target. However, the precise real-time position of a single robot and the details of its observed local environment are critical secrets when operating in military or sensitive areas. Applying the method of this application, each robot can perturb its own perception data during communication and coordination, thereby ensuring that the precise trajectory and reconnaissance information of the entire swarm are not leaked when any robot is captured, while successfully completing the cooperative localization and mapping tasks.
[0029] In the context of vehicle-to-everything (V2X) traffic flow state estimation, the intelligent agents are autonomous or intelligent connected vehicles on the road. Each vehicle acquires local traffic information such as its own speed and distance from the vehicle in front through onboard sensors, forming its output observation data. They need to collaborate to estimate macroscopic traffic flow parameters such as the average vehicle speed and traffic density of the entire road, i.e., the unknown parameters of the target. However, continuous high-precision trajectory data of a single vehicle is extremely sensitive personal information and could be used to track individual trips. By applying the method of this application, when vehicles participate in vehicle-to-cloud or vehicle-to-vehicle collaborative computing, the uploaded local motion data can be privatized, thereby protecting the travel privacy of vehicle owners while contributing data to obtain more accurate global traffic state services.
[0030] like Figure 1 As shown, the distributed differential privacy-preserving parameter estimation method based on output perturbation includes the following steps S1 to S6.
[0031] S1. Establish a multi-agent distributed parameter estimation model and initialize the parameters.
[0032] This embodiment considers a network consisting of N agents, where the observation model for each agent is as follows: in This represents the set of vertices in the corresponding network graph; For intelligent agents In time The measurement output vector at the location; This is a noise vector with zero mean and independent and identically distributed. It is an intelligent agent In time The time-varying measurement or input matrix at the given location may be fully known (e.g., under complete measurement or design conditions) or it may be a partially unknown random matrix sequence with well-defined statistical properties, i.e., for all... , ;and This is a vector of unknown parameters, i.e., the parameters to be estimated. At the initial time... Each agent's parameters Give an initial estimate These initial values can be different and do not need to be accurate. Globally used... This represents the stacked vector estimated by all agents. This represents the corresponding stacked vector of all outputs.
[0033] S2, Generate Laplace noise Constructing a perturbation output .
[0034] In the At the start of the next iteration, each agent obtains its current output. Specifically, to protect the privacy of the output data, the intelligent agent... Generate a noise vector that follows a Laplace distribution. and will Add to the output to obtain the perturbed output. . Each element is independently and identically distributed, and follows a distribution with mean zero and variance . Laplace noise. To ensure that the condition is met in each iteration. - Differential privacy, only .if If it is a multi-dimensional vector, then Laplacian noise of the same scale is added independently to each component. It is important to emphasize that... This process remains constant throughout, meaning the same noise distribution is used in each iteration. This output perturbation step ensures that even if an attacker gains access to the published data... It is also impossible to reliably deduce the true output. This ensures data privacy.
[0035] S3, Send disturbance output to neighbors and current parameter estimation Receive parameter estimates from neighbors .
[0036] In this embodiment, in the network topology diagram In this system, there are multiple nodes, each node corresponding to an intelligent agent. The neighbor set is defined as ,in It is a set of edges. If the agent It is an intelligent agent Neighbor (record) ), then the intelligent agent It will estimate the current parameters and Send to the agent Receive from intelligent agents Parameter estimation .
[0037] like Figure 2 The diagram shown is a network topology diagram provided in this embodiment, where numbers 1 to 5 represent one agent. Taking agent 1 as an example, its neighboring agents are agent 2 and agent 4.
[0038] S4. Depending on whether the input matrix of the agent is completely known, update the estimated parameter value of the agent using the corresponding parameter update rule.
[0039] Specifically, step S4 is executed in the following two ways: Scenario 1: When When everything is known, the agent Update its estimate according to the following rules. .
[0040] Scenario 2: When When some information is known, the individual The update rules are as follows: .
[0041] in, Represents an individual In time When the unknown parameter vector to be estimated The estimated value, For the added Laplacian noise vector, The step size can be selected according to the convergence requirements, and it is preferred to set it to decrease with time, for example... To ensure algorithm convergence, and For any initial estimate.
[0042] S5. Determine whether the parameter estimates of each agent have reached a convergent and consistent value.
[0043] In this embodiment, after each iteration, it is determined whether a set termination condition is met. The set termination condition can be whether the estimated change in all agent parameters is lower than a threshold (convergence criterion). If the termination condition is not met, then... Then return to step S2 to proceed to the next iteration; if the condition is met, proceed to step S6.
[0044] S6. When the iteration ends, the parameter estimates of each agent have converged to a consistent value, which is the parameter to be identified. The estimation results. The final output can be provided by any agent or output through a preset aggregation node.
[0045] In step S2 The specific methods for obtaining it are as follows: In each iteration, the attacker obtains the following information: That is, the privacy protection mechanism at this time satisfy ,in For sets Random mapping.
[0046] set up and for - Adjacent. For ease of expression, the mapping relationship is defined as follows: The above mapping relationship is abbreviated as: .when When everything is fully known, to establish the corresponding differential privacy conditions, the probability density ratio needs to be examined in each iteration: when and Only and At different times, the same output is produced. The probability ratio. Note that... Based on the relationship between the probability of a continuous variable and its probability density function, we can obtain: in Indicates in -Indexes of individuals whose output vectors differ in the adjacency definition. and They are and The probability density function, for Time-based intelligent agent Added Laplacian noise vector, for Time-based intelligent agent The corresponding Laplacian noise vector in the case of adjacent datasets. for Time-based intelligent agent The original measurement output vector, for Time-based intelligent agent Measurement output vector in the case of adjacent datasets For probability, for Time-based intelligent agent Measurement output vector in the case of adjacent datasets for Time-based intelligent agent Noise vectors in the case of adjacent datasets for Time-based intelligent agent The parameter estimates, When the input is At that time, privacy protection mechanisms The output is The probability density, When the input is At that time, privacy protection mechanisms The output is The probability density, To and mutual - The set of adjacent output observation data.
[0047] In fact, when At that time, we can obtain from the equation: And for any measurable set ,have in, For random mapping (privacy protection mechanism) The range of values, When the input is At that time, privacy protection mechanisms The output is The probability density, When the input is At that time, privacy protection mechanisms The output is The probability density, When the input data is At that time, privacy protection mechanisms The output falls into the measurable set The probability, For integration variables, representing mechanisms Possible output results It is a natural constant.
[0048] Therefore, when When it is known that it satisfies - Differential privacy.
[0049] when When the information is not fully known, simply put In Replace with This can be obtained by repeating the above argument.
[0050] The following is a simulation example.
[0051] This simulation example illustrates a conflicting scenario in an Industrial Internet of Things (IIoT) environment: the need for both collaboration and confidentiality. Assume a residential community or industrial park with five main electricity-consuming units, each equipped with a smart meter (smart agent). These meters need to collaborate in a distributed manner to identify the operating parameters of shared equipment within the area, such as a large central air conditioning system or an energy storage power station, so that the power control center can make accurate load-side responses. The network... Each agent represents five distributed sensor nodes (smart meters) located in an industrial field; the actual parameters to be estimated. The power factor, inductance / capacitance characteristic vector, or unknown scaling factor in the load model representing the shared load within the area; in the simulation data, This is a time-varying observation matrix, representing the known operating characteristics or sensitivity matrix of electrical equipment under different operating conditions, such as peak and off-peak periods and voltage fluctuations; system noise. This refers to random physical interference caused by sensor accuracy limitations, harmonic interference, or meter sampling errors; smart meters Real-time observation data This means that the smart meter is in The voltage and current waveforms or active / reactive power readings are collected in real time; each smart meter acquires the raw readings. Then, it will be based on the preset privacy parameters. Generate and add fixed-scale Laplace noise ; Represents the maximum value between adjacent power consumption sequences Sensitivity, in a power scenario, corresponds to the upper limit of the measurement jump caused by a user turning a standard power device on or off, such as a 500W appliance; step size. The selection of the frequency simulates the dynamic response of the power grid load change, and the step size decreases over time to simulate the process of the system from the initial large-scale search to the later precise locking. Each smart meter only exchanges "disturbed data" and "parameter estimates" with its physical neighbors, without uploading the original privacy data to the central server.
[0052] This simulation example demonstrates that in a smart grid, by adding local controls to each meter to meet the requirements... - Laplace noise with differential privacy requirements, combined with distributed parameter update rules, enables the entire community to collaboratively complete complex load model identification tasks without exposing the real-time electricity consumption details of individual households. Even under harsh conditions where the observation matrix is partially unknown or there is environmental interference, the parameter estimates of each node can still stably converge to the true values, achieving a dual synergistic optimization of privacy protection and industrial estimation accuracy.
[0053] This embodiment retrieves individual data from the network. Adjacency matrix Actual parameters and system noise ( )for: Specifically, such as Figure 2 As shown.
[0054] When the input matrix is completely known, the input matrix can be selected as follows: , , , , When the input matrix is not fully known, the input matrix is selected in the following manner: in And they are independent of each other. Therefore: ,and .
[0055] First, this embodiment takes the step size. Privacy parameters and Initial estimate ( ), noise parameters When the input matrix is completely known, there is an update rule according to step S4. The simulation results are as follows Figure 3 As shown.
[0056] When the input matrix is not fully known, there is an update rule according to step S4. The simulation results are as follows Figure 4 As shown. Among them, Represents an individual right The The estimated trajectory of each component Represents an individual right The The estimated trajectories of each component are obtained. It can be seen that the estimated trajectories in both cases converge to the true parameters, thus verifying the main convergence conclusion.
[0057] This application also provides a distributed differential privacy-preserving parameter estimation device based on output perturbation, applicable to multi-agent cooperative estimation and control scenarios in industrial IoT or cyber-physical systems. This device aims to protect the privacy of each agent's output observation data while achieving networked system parameter identification and state estimation. Figure 5 As shown, the device includes: The initial estimation module 501 is configured to construct a distributed network parameter estimation model consisting of multiple agents and to set initial parameter estimates for each agent. The noise addition module 502 is configured to, in each iteration, each agent obtains its current output observation data, generates a Laplace noise vector and adds it to the output observation data to obtain the perturbed output data, so as to ensure that each iteration meets the ε-differential privacy requirement; The data communication module 503 is configured to send its current parameter estimates and perturbed output data to neighboring agents based on a preset network topology, and to receive parameter estimates from neighboring agents. The parameter update module 504 is configured to update its own parameter estimates according to whether the input matrix of the agent is completely known, using the corresponding parameter update rules. The iteration judgment module 505 is configured to determine whether the change in the parameter estimates of all agents is lower than a preset threshold after each iteration. If the threshold is not met, the module returns to the noise addition module to enter the next iteration. If the threshold is met, the iteration is terminated. The output module 506 is configured to output the parameter estimates that converge to a consensus among the agents as the estimation results of the unknown parameters of the target.
[0058] This application provides an electronic device. The electronic device may include a processor and a memory, wherein the processor and the memory can communicate; exemplarily, the processor and the memory communicate via a communication bus.
[0059] The processor executes computer execution instructions stored in memory, causing the processor to perform the scheme in the above embodiments. The processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0060] The communication bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The system bus can be divided into address bus, data bus, control bus, etc. Transceivers are used to enable communication between database access devices and other computers (e.g., clients, read-write libraries, and read-only libraries). Memory may include random access memory (RAM) and may also include non-volatile memory.
[0061] The electronic device provided in this application embodiment can be the terminal device described in the above embodiments.
[0062] This application also provides a computer-readable storage medium storing computer instructions. When the computer instructions are executed on a computer, the computer performs the technical solution of the distributed differential privacy and security parameter estimation method based on output perturbation described in the above embodiments.
[0063] This application also provides a computer program product, which includes a computer program stored in a computer-readable storage medium. At least one processor can read the computer program from the computer-readable storage medium. When the at least one processor executes the computer program, it can implement the technical solution of the distributed differential privacy security parameter estimation method based on output perturbation in the above embodiments.
[0064] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or modules, and may be electrical, mechanical, or other forms.
[0065] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to implement the solution of this embodiment according to actual needs.
[0066] Furthermore, the functional modules in the various embodiments of this application can be integrated into one processing unit, or each module can exist physically separately, or two or more modules can be integrated into one unit. The unit composed of the above modules can be implemented in hardware or in the form of hardware plus software functional units.
[0067] The integrated modules described above, implemented as software functional modules, can be stored in a computer-readable storage medium. These software functional modules, stored in a storage medium, include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute some steps of the methods of the various embodiments of this application.
[0068] It should be understood that the aforementioned processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly manifested as execution by a hardware processor, or execution by a combination of hardware and software modules within the processor.
[0069] The memory may include high-speed RAM, and may also include non-volatile storage (NVM), such as at least one disk storage device, and may also be a USB flash drive, external hard drive, read-only memory, disk or optical disc, etc.
[0070] Buses can be Industry Standard Architecture (ISA) buses, Peripheral Component Interconnect (PCI) buses, or Extended Industry Standard Architecture (EISA) buses, etc. Buses can be categorized into address buses, data buses, control buses, etc.
[0071] The aforementioned storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0072] An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Alternatively, the storage medium can be an integral part of the processor. The processor and storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and storage medium can exist as discrete components in an electronic control unit or main control device.
[0073] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0074] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
Claims
1. A distributed differential privacy-preserving parameter estimation method based on output perturbation, applied to multi-agent cooperative estimation and control scenarios in industrial IoT or cyber-physical systems, to protect the privacy of each agent's output observation data while achieving networked system parameter identification and state estimation, characterized in that... The method includes the following steps: S1. Construct a distributed network parameter estimation model consisting of multiple agents, and set initial parameter estimates for each agent; S2. In each iteration, each agent acquires its current output observation data, generates a Laplace noise vector, and adds it to the output observation data to obtain the perturbed output data, ensuring that each iteration satisfies the condition. - Differential privacy requirements; S3. Based on the preset network topology, each agent sends its current parameter estimate and perturbed output data to neighboring agents and receives parameter estimates from neighboring agents. S4. Depending on whether the input matrix corresponding to the agent is completely known, update the estimated parameter value of the agent using the corresponding parameter update rule. S5. After each iteration, determine whether the change in the parameter estimates of all agents is lower than the preset threshold. If not, return to step S2 to enter the next iteration. If the threshold is met, terminate the iteration. S6. Output the parameter estimates that converge to a consensus among all agents as the estimation results of the unknown parameters of the target.
2. The distributed differential privacy-preserving parameter estimation method based on output perturbation according to claim 1, characterized in that, In step S1, the observation model for each agent is as follows: in, This represents the set of vertices in the corresponding network graph. , The number of vertices; Number the intelligent agents; For a specific moment; For intelligent agents exist The measurement output vector at time; For intelligent agents exist Time-varying measurement or input matrix at any given moment; For intelligent agents exist The noise vector at time step; Let be the vector of unknown parameters to be estimated.
3. The distributed differential privacy-preserving parameter estimation method based on output perturbation according to claim 1, characterized in that, Each element in the Laplace noise vector is independent and identically distributed, and follows a distribution with a mean of zero and a variance of . Laplace noise, Let the scale parameter of the Laplace noise satisfy: in Used to characterize the degree of similarity between two similar sensitive pieces of information, if for any , For a distance space, we have but and In distance metric In a sense, it means - Adjacent; To characterize the spatial distance of sensitive information, The measurable space corresponding to the opponent's observation. From arrive The random mapping, and Let be a probability space; if for any -Adjacency and any set All have , If it is a natural constant, then it is a random mapping. yes -adjacent Differential privacy; Describes how adversaries differentiate sensitive information based on observational data. Information about its neighbors The difficulty.
4. The distributed differential privacy-preserving parameter estimation method based on output perturbation according to claim 2, characterized in that, Depending on whether the input matrix corresponding to the agent is completely known, the agent updates its own parameter estimates using the corresponding parameter update rules, including: when When everything is known, the agent Update its estimate according to the following rules: in, Represents intelligent agents exist Parameter estimation at time 10:00 Represents intelligent agents exist Parameter estimation at time 10:00 Represents intelligent agents exist Parameter estimation at time 10:00 For matrix transpose, For intelligent agents The Laplacian noise vector, for The step size of time, For intelligent agents The neighbor set; when When some information is known, the agent Update its estimate according to the following rules: in, for The expectation matrix, , For expectation operators.
5. The distributed differential privacy-preserving parameter estimation method based on output perturbation according to claim 4, characterized in that, The step size is a step size that decreases with time, satisfying: in, for The step size of time.
6. The distributed differential privacy-preserving parameter estimation method based on output perturbation according to claim 4, characterized in that, exist ,and In the case of each iteration - Satisfies under adjacency property - Differential privacy, convergence rate satisfies: when hour, ; when hour, ; in, This represents the set of vertices in the corresponding network graph. The agent's ID number. For privacy parameters of differential privacy, For threshold parameters, The exponential parameter of the step size. The scale parameter for Laplace noise. The maximum value between adjacent output data sequences Sensitivity Let the square norm of the parameter estimation error be denoted as . It is the upper bound of the same order.
7. A distributed differential privacy-preserving parameter estimation device based on output perturbation, applied to multi-agent cooperative estimation and control scenarios in industrial IoT or cyber-physical systems, to protect the privacy of each agent's output observation data while achieving networked system parameter identification and state estimation, characterized in that... The device includes: The initial estimation module is configured to build a distributed network parameter estimation model consisting of multiple agents and set initial parameter estimates for each agent. The noise addition module is configured to, in each iteration, have each agent acquire its current output observation data, generate a Laplace noise vector, and add it to the output observation data to obtain perturbed output data, thus ensuring that each iteration satisfies the requirements. - Differential privacy requirements; The data communication module is configured to send its current parameter estimates and perturbed output data to neighboring agents based on a preset network topology, and receive parameter estimates from neighboring agents. The parameter update module is configured to update its own parameter estimates according to whether the input matrix of the agent is completely known, using the corresponding parameter update rules. The iteration judgment module is configured to determine whether the change in the parameter estimates of all agents is lower than a preset threshold after each iteration. If the threshold is not met, the module returns to the noise addition module to enter the next iteration. If the threshold is met, the iteration is terminated. The output module is configured to output the parameter estimates that converge to a consensus among the agents as the estimation results of the unknown parameters of the target.
8. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes the computer execution instructions stored in the memory to implement the distributed differential privacy security parameter estimation method based on output perturbation as described in any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the distributed differential privacy-preserving parameter estimation method based on output perturbation as described in any one of claims 1-6.
10. A computer program product, characterized in that, The method includes a computer program that, when executed by a processor, implements the distributed differential privacy-preserving parameter estimation method based on output perturbation as described in any one of claims 1-6.