Coal mine multi-mode business data dynamic desensitization system and method based on edge collaboration
The edge-collaborative dynamic desensitization system for multimodal business data in coal mines solves the problem of inconsistent centralized desensitization architecture and multimodal data desensitization by utilizing the collaborative mechanism of edge desensitization nodes and dynamic evaluation engine. It achieves high-precision data desensitization and business adaptability, and improves the efficiency and security of coal mine data security governance.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA COAL RES INST
- Filing Date
- 2025-12-29
- Publication Date
- 2026-05-15
AI Technical Summary
Existing coal mine data masking solutions suffer from the risk of sensitive data leakage due to centralized masking architecture, contradictions between static masking rules and dynamic security requirements, and security blind spots caused by inconsistent multimodal data masking standards. Furthermore, traditional methods are difficult to adapt to the dynamic changes in the underground coal mine environment and the masking requirements of multimodal data.
A dynamic desensitization system for multimodal business data in coal mines based on edge collaboration is adopted. Through edge desensitization nodes, dynamic evaluation engine and policy executor, combined with feature-preserving desensitization algorithm, LSTM and GAN model, multi-layer risk assessment model and cross-modal desensitization collaboration mechanism, local pre-desensitization and dynamic desensitization are achieved.
It improves the accuracy and business adaptability of data anonymization, reduces data distortion and security blind spots, enhances the efficiency of temporary business response, reduces manual operation costs, and ensures data security and business value.
Smart Images

Figure CN122045596A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of coal mine data security governance technology, and in particular to a dynamic desensitization system and method for multimodal business data in coal mines based on edge collaboration. Background Technology
[0002] With increasing demands for data security protection in coal mines, data anonymization has gradually become an important part of coal mine data governance. Among related technologies, data anonymization in coal mines mainly employs two modes: static anonymization and dynamic anonymization.
[0003] Static data masking processes data in batches according to pre-defined rules, which is simple to implement but cannot respond to real-time risk changes. Dynamic data masking can process data in real time, but existing solutions are mostly based on a single dimension of role and permission control and lack a multi-dimensional risk assessment mechanism for terminal environment, user behavior and business scenarios.
[0004] Therefore, the coal mine data anonymization schemes in related technologies have the following problems: First, the risk of sensitive data leakage caused by centralized anonymization architecture; second, the contradiction between static anonymization rules and dynamic security requirements; and third, the security blind spots caused by the lack of unified standards for multimodal data anonymization. Summary of the Invention
[0005] The purpose of this application is to at least partially solve one of the aforementioned technical problems.
[0006] Therefore, the first objective of this application is to propose a dynamic de-identification system for multimodal business data in coal mines based on edge collaboration. This system effectively preserves the business value of data while ensuring data security through edge-side time-series data conformal de-identification algorithm, three-dimensional dynamic risk assessment model and cross-modal de-identification collaboration mechanism. It solves problems such as data distortion and security blind spots after de-identification, and improves the accuracy and business adaptability of coal mine data de-identification.
[0007] The second objective of this application is to propose a dynamic desensitization method for multimodal business data in coal mines based on edge collaboration.
[0008] The third objective of this application is to propose an electronic device.
[0009] The fourth objective of this application is to provide a computer-readable storage medium.
[0010] To achieve the above objectives, the first aspect of this application proposes a dynamic de-identification system for multimodal business data in coal mines based on edge collaboration, comprising: edge de-identification nodes, a dynamic evaluation engine, and a policy executor; wherein, A communication connection is established between the edge desensitization node, the dynamic evaluation engine, and the policy executor; The edge desensitization node is deployed in the edge equipment of the coal mine. The edge desensitization node is used to perform local pre-desensitization on the original data collected by the edge equipment through the feature preservation desensitization algorithm to generate pre-desensitized data. The dynamic evaluation engine is deployed on the edge computing node of the mining area. The dynamic evaluation engine is used to process the data sent by the edge desensitization node using a three-layer risk assessment model. By integrating device security indicators, user behavior anomaly degree and business sensitivity level, dynamic desensitization coefficient is generated. The strategy executor is used to perform cross-modal collaborative desensitization operations based on the knowledge graph of multimodal data desensitization rules and the dynamic desensitization coefficients, so as to eliminate desensitization blind spots in multimodal business data.
[0011] In addition, the edge-collaboration-based dynamic desensitization system for multimodal business data in coal mines according to this application embodiment also has the following additional technical features: Optionally, in some embodiments, the edge desensitization node is specifically used to: learn data pattern features through a Long Short-Term Memory (LSTM) network for coal mine time-series data; and perform preliminary desensitization of the time-series data using a perturbation algorithm based on Gaussian noise injection.
[0012] Optionally, in some embodiments, the edge desensitization node is specifically used to: construct a data perturbation model based on a Generative Adversarial Network (GAN), and perform preliminary desensitization on the time-series data through the data perturbation model.
[0013] Optionally, in some embodiments, the three-layer risk assessment model includes: a terminal security assessment module, a user behavior analysis module, and a business sensitivity discrimination module; wherein, the terminal security assessment module is used to quantify environmental risk values through multiple device security indicators; the user behavior analysis module is used to establish a normal access baseline based on a hidden Markov model and detect user risky behaviors based on the normal access baseline; the business sensitivity discrimination module is used to automatically calibrate the data sensitivity of different business data according to a preset data classification standard.
[0014] Optionally, in some embodiments, the three-layer risk assessment model is specifically used to: fuse the assessment results output by each module through a fuzzy logic algorithm to generate the dynamic desensitization coefficient, wherein the dynamic desensitization coefficient ranges from 0 to 1, and when the dynamic desensitization coefficient is 0, it indicates that the business data is completely desensitized, and when the dynamic desensitization coefficient is 0, it indicates that the business data is the original data.
[0015] Optionally, in some embodiments, the policy executor is specifically used to: for devices in video data, automatically associate the dynamic operation data desensitization level of the device after identifying the static attribute information of the device; and for personnel outlines in the video data, perform dynamic blurring processing in combination with positioning system data.
[0016] To achieve the above objectives, the second aspect of this application proposes a dynamic de-identification method for multimodal business data in coal mines based on edge collaboration, applied to the dynamic de-identification system for multimodal business data in coal mines based on edge collaboration mentioned in the first aspect. The method includes: The raw multimodal business data collected by underground edge devices in coal mines is preprocessed locally through edge desensitization nodes, and various types of preprocessed data are sent to the dynamic evaluation engine. Based on the preprocessed data, the three-layer risk assessment model in the dynamic assessment engine is used to quantitatively assess the terminal security status, user access behavior and business data sensitivity, respectively, and generate a dynamic desensitization coefficient, which is then sent to the edge desensitization node. At the edge desensitization node, pre-desensitization processing is performed according to the dynamic desensitization coefficient, and the generated pre-desensitization data is sent to the policy executor; The policy executor performs cross-modal collaborative desensitization on the pre-desensitized data based on a multimodal data desensitization rule knowledge graph, so as to output desensitized secure data.
[0017] Optionally, before the strategy executor performs cross-modal collaborative desensitization on the pre-desensitized data based on the multimodal data desensitization rule knowledge graph, the method further includes: establishing the association relationship between multimodal business data based on graph neural network, and constructing the multimodal data desensitization rule knowledge graph by combining the association relationship between the multimodal business data and preset multiple business rules.
[0018] To achieve the above objectives, a third aspect of this application proposes an electronic device, including a dynamic desensitization system for multimodal business data in coal mines based on edge collaboration as described in any of the first aspect embodiments above.
[0019] To achieve the above objectives, a fourth aspect of this application provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the dynamic desensitization method for multimodal business data in coal mines based on edge collaboration as described in any one of the second aspects of the embodiment above.
[0020] The technical solutions provided by the embodiments of this application bring at least the following beneficial effects: This application, through the classification and sensitivity level assessment of coal mine business data, ensures that the data retains its business relevance after anonymization, improving the accuracy and business adaptability of data anonymization. Furthermore, based on a dynamic anonymization strategy across multiple scenarios, it avoids over- or under-anonymization of business data, optimizing the balance between anonymization granularity and data security, and improving the accuracy of business data anonymization selection. This application, through temporary authorization and anonymization mechanisms, eliminates the need for manual rule configuration, reducing temporary access request processing time from hours to minutes, significantly improving the efficiency of temporary business responses. This application also automatically matches sensitivity levels with anonymization algorithms, reducing the workload of manually selecting anonymization algorithms, thereby lowering the manual dependence and operational costs of the anonymization process. Therefore, this application provides a secure, efficient, and highly adaptable anonymization solution for multimodal business data in coal mines, which is beneficial for data security governance in the intelligent construction of coal mines.
[0021] Additional aspects and advantages of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this application. Attached Figure Description
[0022] The above and / or additional aspects and advantages of this application will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, wherein: Figure 1 This is a schematic diagram of the structure of a dynamic desensitization system for multimodal business data in coal mines based on edge collaboration, as proposed in an embodiment of this application. Figure 2 The flowchart is a method for dynamic desensitization of multimodal business data in coal mines based on edge collaboration, as proposed in an embodiment of this application. Figure 3 This is a schematic diagram illustrating the implementation principle of a dynamic desensitization method for multimodal business data in coal mines based on edge collaboration, as proposed in an embodiment of this application. Detailed Implementation
[0023] The embodiments of this application are described in detail below. Examples of these embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain this application, and should not be construed as limiting this application.
[0024] It should be noted that the coal mine data anonymization technology in the relevant embodiments faces three main technical bottlenecks: First, at the data processing level, existing systems mostly adopt a centralized anonymization architecture, requiring the complete transmission of raw data collected by edge devices to the cloud for processing, resulting in excessive exposure of sensitive data along the transmission link. Second, at the algorithm level, traditional static anonymization rules cannot adapt to the real-time risk adjustment needs brought about by dynamic changes in the underground coal mine environment (such as fluctuations in terminal safety status, abnormal access behavior, etc.). Third, at the data feature level, for industrial time-series data generated by SCADA systems (such as gas concentration curves and equipment vibration waveforms), existing anonymization methods struggle to balance data availability and security, often leading to severe data distortion after anonymization.
[0025] Furthermore, for the multimodal data unique to coal mines (such as the fusion analysis of video and sensor data), a unified dynamic desensitization framework has not yet been established in the relevant embodiments, which often leads to the omission of sensitive content such as equipment nameplate information and personnel facial features in the video stream.
[0026] Specifically, the defects in the coal mine data desensitization scheme in the relevant embodiments include, but are not limited to, the following: Existing systems lack local pre-desensitization mechanisms during data transmission, meaning that original sensitive data may be stolen when intermediate network nodes are compromised. Traditional dynamic desensitization only sets fixed rules based on user roles and cannot dynamically adjust desensitization strength according to environmental factors such as terminal authentication status and encryption strength. Statistical characteristics of industrial time-series data are distorted after desensitization, affecting the accuracy of analysis in critical business tasks such as "gas concentration trend prediction." The desensitization strategies for video data and equipment data are not coordinated, potentially allowing sensitive information to be recovered through multimodal data correlation analysis.
[0027] To address this, this application proposes a dynamic desensitization system and method for multimodal business data in coal mines based on edge collaboration. This application effectively preserves the business value of data while ensuring data security, and improves the accuracy and business adaptability of coal mine data desensitization.
[0028] The following describes, with reference to the accompanying drawings, an embodiment of the dynamic desensitization system and method for multimodal business data in coal mines based on edge collaboration.
[0029] Figure 1 This is a schematic diagram of the structure of a dynamic desensitization system for multimodal business data in coal mines based on edge collaboration, as proposed in an embodiment of this application. Figure 1 As shown, the system includes: edge desensitization node 10, dynamic evaluation engine 20, and policy executor 30.
[0030] Among them, a communication connection is established between the edge desensitization node 10, the dynamic evaluation engine 20 and the policy executor 30 to facilitate data interaction between the various parts.
[0031] Edge desensitization node 10 is deployed in the edge devices of the coal mine. Edge desensitization node 10 is used to perform local pre-desensitization on the original data collected by the edge devices through the feature retention desensitization algorithm to generate pre-desensitized data.
[0032] Specifically, such as Figure 1 As shown, this application first deploys edge desensitization nodes 10 on various edge devices (such as mine explosion-proof cameras, mine intrinsically safe terminals, and mine sensors) in the coal mine. The edge desensitization nodes 10 are lightweight desensitization agents that can use a "feature-preserving desensitization algorithm" to perform local preprocessing on the raw data (such as infrared video streams and industrial time-series data generated by SCADA systems) collected by various edge devices in the data acquisition layer.
[0033] In one embodiment of this application, the edge desensitization node is specifically used for: learning data pattern features through a Long Short-Term Memory (LSTM) network for coal mine time-series data; and performing preliminary desensitization of the time-series data using a perturbation algorithm based on Gaussian noise injection.
[0034] Specifically, in this embodiment, for coal mine time-series data, the lightweight desensitization agent learns data pattern features through a Long Short-Term Memory (LSTM) network and adopts a perturbation algorithm based on Gaussian noise injection, thereby achieving preliminary desensitization while maintaining the data trend, making the data irreversible in subsequent transmission processes and meeting differential privacy requirements.
[0035] In this embodiment, the LSTM network is well-suited for learning the trend characteristics of time series data (such as the variation pattern of coal mine gas concentration) for sequence prediction and data pattern learning, thereby obtaining the data characteristics and indicators in the original data.
[0036] In one embodiment of this application, the edge desensitization node is specifically used to: construct a data perturbation model based on a generative adversarial network (GAN), and perform preliminary desensitization on time-series data through the data perturbation model.
[0037] Specifically, the edge-side temporal data conformal desensitization algorithm in this embodiment can construct a data perturbation model through a generative adversarial network (GAN), thereby achieving effective desensitization while maintaining low error.
[0038] In this embodiment, the data generation and perturbation capabilities of the GAN model can be utilized to achieve privacy protection while maintaining data characteristics (such as conformal desensitization of time series data on coal mine gas concentration).
[0039] The dynamic evaluation engine 20 is deployed on the edge computing node of the mining area. The dynamic evaluation engine 20 is used to process the data sent by the edge de-identification node using a three-layer risk assessment model. By integrating device security indicators, user behavior anomalies and business sensitivity levels, dynamic de-identification coefficients are generated.
[0040] Specifically, the dynamic evaluation engine 20 is deployed on the edge computing nodes of the mining area to evaluate the data reported by the edge desensitization nodes 10 (such as data characteristics and environmental indicators of various business data), and generate real-time desensitization coefficients through a three-layer risk assessment model. In practice, the dynamic evaluation engine 20 first obtains a three-dimensional quantitative assessment of equipment security indicators, user behavior anomalies, and business sensitivity levels through the three-layer risk assessment model, and then integrates the three-dimensional quantitative assessment to obtain the dynamic desensitization coefficients.
[0041] In one embodiment of this application, the three-layer risk assessment model includes: a terminal security assessment module, a user behavior analysis module, and a business sensitivity discrimination module; wherein, the terminal security assessment module is used to quantify the environmental risk value through multiple device security indicators; the user behavior analysis module is used to establish a normal access baseline based on a hidden Markov model and detect user risky behaviors based on the normal access baseline; the business sensitivity discrimination module is used to automatically label the data sensitivity of different business data according to a preset data classification standard.
[0042] Specifically, the first layer of the three-layer risk assessment model is the terminal security assessment module, which quantifies environmental risk values through indicators such as device fingerprint authentication and encrypted channel strength detection. The second layer is the user behavior analysis module, which establishes a normal access baseline based on a Hidden Markov Model and then detects risky behaviors such as abnormal time access and high-frequency queries. The third layer is the business sensitivity discrimination module, which automatically calibrates data sensitivity according to data classification and grading standards (e.g., classifying gas data as L4 and production data as L2).
[0043] In one embodiment of this application, the three-layer risk assessment model is specifically used to: fuse the assessment results output by each module through a fuzzy logic algorithm to generate a dynamic desensitization coefficient, wherein the dynamic desensitization coefficient ranges from 0 to 1. When the dynamic desensitization coefficient is 0, it indicates that the business data is completely desensitized, and when the dynamic desensitization coefficient is 0, it indicates that the business data is the original data.
[0044] Specifically, the three-layer evaluation results are fused using a fuzzy logic algorithm to output a dynamic desensitization coefficient α∈[0,1], where α=0 represents complete desensitization and α=1 represents the original data.
[0045] The strategy executor 30 is used to perform cross-modal collaborative desensitization operations based on a knowledge graph of desensitization rules for multimodal data, using dynamic desensitization coefficients to eliminate desensitization blind spots in multimodal business data.
[0046] Specifically, the strategy executor 30 executes a cross-modal desensitization collaboration mechanism, which can achieve collaborative desensitization of multimodal data and eliminate desensitization blind spots through cross-modal correlation analysis.
[0047] In one embodiment of this application, the policy executor is specifically used to: for devices in video data, automatically associate the dynamic operation data desensitization level of the devices after identifying the static attribute information of the devices; and for personnel outlines in video data, perform dynamic blurring processing in combination with positioning system data.
[0048] Specifically, this embodiment uses the desensitization processing of video data as an example. When static attribute information of a device is identified in the video data, the desensitization level of the device's dynamic operating data is automatically associated. For personnel outlines in the video, dynamic blurring is performed in conjunction with positioning system data. The strategy executor 30 can have a built-in desensitization rule knowledge graph and store various business rules related to multimodal business data in coal mines, such as the vibration data business rule of "coal mining machine vibration data → associated video frame → requires synchronous desensitization", thereby ensuring the consistency of multi-source data desensitization strategies.
[0049] Based on the above embodiments, to further improve the practicality and applicability of the de-identification system in actual applications, the architecture of the dynamic de-identification system can be adjusted according to actual conditions. For example, the edge de-identification node 10 can use traditional AES encryption instead of the feature retention algorithm, which can improve security at the expense of data availability. The dynamic evaluation engine 20 can be simplified to a role-based static rule base, reducing computational complexity at the cost of data availability. The policy executor 30 can be replaced with an independently operating single-modal de-identification component, sacrificing collaboration for deployment flexibility. The necessary components of the dynamic de-identification system in this embodiment are at least one edge de-identification node and a dynamic evaluation engine.
[0050] In summary, the edge-collaboration-based dynamic de-identification system for multimodal business data in coal mines, as described in this application, maintains business relevance after de-identification by classifying and assessing the sensitivity levels of coal mine business data, thereby improving the accuracy and adaptability of data de-identification. Furthermore, the dynamic de-identification strategy based on multi-dimensional scenarios avoids over- or under-identification of business data, optimizing the balance between de-identification granularity and data security, and improving the accuracy of business data de-identification selection. This method, through temporary authorization and de-identification mechanisms, eliminates the need for manual rule configuration, reducing temporary access request processing time from hours to minutes, significantly improving temporary business response efficiency. The method also automatically matches sensitivity levels with de-identification algorithms, reducing the workload of manually selecting de-identification algorithms, thus lowering the manual dependence and operational costs of the de-identification process. Therefore, this method provides a secure, efficient, and highly adaptable de-identification solution for multimodal business data in coal mines, which is beneficial for data security governance in the intelligent construction of coal mines.
[0051] To more clearly illustrate the specific process of data desensitization in practical applications of the edge-collaboration-based dynamic desensitization system for multimodal business data in coal mines proposed in this application, a detailed description of an edge-collaboration-based dynamic desensitization method for multimodal business data in coal mines, as proposed in an embodiment of this application, is provided below. This method is applied to the edge-collaboration-based dynamic desensitization system for multimodal business data in coal mines in the above embodiments, that is, it performs relevant control on the system in the above embodiments to implement the method of this embodiment. The various devices involved in this method are as described in the above embodiments and will not be repeated here.
[0052] Figure 2 This is a flowchart of a dynamic desensitization method for multimodal business data in coal mines based on edge collaboration, as proposed in an embodiment of this application. Figure 2 As shown, the method includes the following steps: Step S101: The raw multimodal business data collected by the underground edge equipment in the coal mine is preprocessed locally through the edge desensitization node, and various types of preprocessed data are sent to the dynamic evaluation engine.
[0053] Specifically, the raw multimodal business data collected by underground edge devices in coal mines is preprocessed locally through edge desensitization nodes to obtain pre-processed data.
[0054] For example, when using a perturbation algorithm based on Gaussian noise injection to pre-de-identify industrial time-series data, the algorithm first learns data pattern features through an LSTM network to maintain data trends, so that the processed data meets differential privacy requirements.
[0055] As an example, such as Figure 3As shown, the data pattern features can be learned through the LSTM network to obtain the data features and environmental indicators in the original data, and then the data features and environmental indicators can be sent to the dynamic evaluation engine for further processing.
[0056] Step S102: Based on the preprocessed data, the three-layer risk assessment model in the dynamic assessment engine is used to quantitatively assess the terminal security status, user access behavior and business data sensitivity, respectively, and generate dynamic desensitization coefficients. The dynamic desensitization coefficients are then distributed to the edge desensitization nodes.
[0057] Specifically, the three-layer risk assessment model of the dynamic assessment engine is used to quantitatively assess the terminal security status, user access behavior, and business data sensitivity, and then merge them to generate a dynamic desensitization coefficient. Among them, a normal user access baseline is established through a hidden Markov model, abnormal access behavior is identified and the behavior risk value is quantified, and the three-layer assessment results are fused by a fuzzy logic algorithm to output a dynamic desensitization coefficient α∈[0,1].
[0058] Furthermore, such as Figure 3 As shown, the generated dynamic desensitization coefficient α is sent down to the edge desensitization node.
[0059] Step S103: Perform pre-desensitization processing at the edge desensitization node according to the dynamic desensitization coefficient, and send the generated pre-desensitization data to the policy executor.
[0060] Specifically, the edge desensitization nodes perform local pre-desensitization on the raw multimodal business data collected by underground coal mine edge devices according to a dynamic desensitization coefficient, obtaining preliminary desensitized data corresponding to the dynamic desensitization coefficient. The generated pre-desensitized data is then sent to the strategy executor for subsequent collaborative desensitization processing.
[0061] Step S104: The policy executor performs cross-modal collaborative desensitization on the pre-desensitized data based on the multimodal data desensitization rule knowledge graph to output desensitized secure data.
[0062] Specifically, the strategy executor performs cross-modal collaborative desensitization on the initially desensitized data based on the dynamic desensitization coefficient and multimodal data association rules, thereby achieving... Figure 3 As shown, the final de-identified security data is output to the application layer for relevant applications, such as displaying blurred equipment nameplates to relevant personnel. Specifically, by combining business rules from the de-identification rule knowledge graph, collaborative de-identification of video data and industrial time-series data is achieved, eliminating security blind spots.
[0063] To facilitate a clear and intuitive description of the dynamic desensitization process for multimodal business data in coal mines as described in this application, a specific embodiment in a practical application will be used for illustration below.
[0064] In this embodiment, the dynamic desensitization system is applied to a large-scale intelligent coal mine. The mine is equipped with 120 mining sensors (including gas sensors, vibration sensors, etc.), 30 explosion-proof cameras, and 50 intrinsically safe mining terminals. The multimodal business data includes gas concentration time series data, coal mining machine vibration time series data, underground operation video data, and production statistics data.
[0065] First, deploy the system.
[0066] The edge desensitization nodes utilize explosion-proof edge computing terminals for mining, deployed in various underground working faces. They are connected to mining sensors, explosion-proof cameras, and intrinsically safe mining terminals via mining Ethernet. Each edge desensitization node is responsible for local pre-desensitization processing of multimodal data for its corresponding mining area. The dynamic evaluation engine is deployed at the mine's surface edge computing center, employing a dual-machine hot standby architecture to ensure operational stability. The policy executor and the dynamic evaluation engine are deployed on the same computing node, interacting via a high-speed bus.
[0067] Secondly, the process of edge desensitization nodes is carried out.
[0068] For time-series gas concentration data (sampling frequency 1Hz, data format JSON), the desensitization agent of the edge desensitization node first trains on 6 months of historical gas concentration data using an LSTM network to learn the data's trend characteristics (such as concentration fluctuation patterns during morning rush hours and upward trends during abnormal gas overflows). In real-time processing, a perturbation algorithm based on Gaussian noise injection is used to generate Gaussian noise with a variance of 0.02 based on the data distribution characteristics and inject it into the original gas concentration data to achieve pre-desensitization. Testing shows that the pre-desensitized gas concentration data has a low mean absolute error and a high degree of trend consistency with the original data, meeting the requirements of differential privacy. Even if the data is stolen during transmission, the original sensitive information cannot be recovered.
[0069] For the underground operation video data (1080P resolution, 25fps) collected by the explosion-proof camera, the edge desensitization node performs preliminary processing on the video frames, identifies static attribute information such as equipment nameplates and interface labels and performs blurring processing, and extracts personnel contour information in the video frames, marking key areas for subsequent collaborative desensitization. The compression ratio of the video data after preliminary processing is 1:3 to ensure transmission efficiency.
[0070] Furthermore, the engine's working process is dynamically evaluated.
[0071] The parameters of the three-layer risk assessment model of the dynamic assessment engine are configured as follows: The terminal security assessment module sets the device fingerprint authentication threshold and the encryption channel strength threshold. The device fingerprint authentication adopts a dual authentication mechanism based on hardware serial number + firmware version. The encryption channel strength uses the transmission rate and bit error rate of the relevant encryption algorithm as evaluation indicators. The environmental risk value quantification range is [0,10]. The user behavior analysis module is based on the Hidden Markov Model and is trained on the access data of underground workers, managers and maintenance personnel in the past 3 months to establish a normal access baseline. The normal access period is set to 6:00-22:00. The daily query frequency threshold for a single user is 50 times. The abnormal behavior risk value quantification range is [0,10]. The business sensitivity discrimination module adopts the coal mine data classification and grading standard, classifying gas concentration data and personnel positioning data as L4 level (extremely high sensitivity), coal mining machine vibration data and equipment operating parameters as L3 level (high sensitivity), production statistics data as L2 level (medium sensitivity), and operation log data as L1 level (low sensitivity). The data sensitivity quantification range is [0,10].
[0072] During real-time evaluation, the terminal security assessment module detected a bit error rate of 0.8% (threshold 1%) in the encrypted channel of a certain intrinsically safe terminal used in mining. Device fingerprint authentication passed, and the quantified environmental risk value was 1.2. The user behavior analysis module detected that a maintenance personnel initiated high-frequency queries (30 queries within 10 minutes) at 2:30 AM (outside normal access hours), with a quantified behavioral risk value of 8.5. The business sensitivity judgment module determined that the coal mining machine vibration data accessed by the maintenance personnel was at level L3, with a quantified data sensitivity of 7.0. The three-layer evaluation results were fused using a fuzzy logic algorithm, with a triangular membership function used. The fused result output a dynamic desensitization coefficient α = 0.65.
[0073] Finally, the working process of the strategy executor is performed.
[0074] The knowledge graph of the desensitization rules of the strategy executor stores 120 business association rules for the coal mine, among which "coal mining machine vibration data (Level 3) → associated operation video frame → synchronous desensitization" is one of the core rules. When the strategy executor receives the dynamic desensitization coefficient α=0.65 and the initially desensitized coal mining machine vibration data and operation video data, it first confirms the operation video frame corresponding to the currently accessed coal mining machine vibration data (timestamp matching error ≤0.1s) through cross-modal association analysis. For the personnel outline information marked in the video frame, combined with the underground personnel positioning system data, if the personnel are in the coal mining machine operation area, the blur intensity of the personnel outline is adjusted to 65% (the blur intensity corresponding to α=0.65), and if the personnel are in the non-operation area, the blur intensity is adjusted to 40%. At the same time, the dynamic operating area of the equipment associated with the coal mining machine in the video frame (such as the hydraulic support movement part) is locally blurred to ensure consistency with the desensitization level of the vibration data.
[0075] Tests showed that the vibration data of the coal mining machine processed by the system was consistent with the trend of the original data, and the accuracy of blurring sensitive information in the video data was high, with no omission of sensitive information.
[0076] In summary, the edge-collaboration-based dynamic de-identification method for multimodal business data in coal mines in this application embodiment, through edge-side time-series data conformal de-identification algorithm, three-dimensional dynamic risk assessment model and cross-modal de-identification collaboration mechanism, effectively preserves data business value while ensuring data security, solves problems such as data distortion and security blind spots after de-identification, and improves the accuracy and business adaptability of coal mine data de-identification. To implement the above embodiments, this application also proposes an electronic device, including a dynamic desensitization system for multimodal business data in coal mines based on edge collaboration as described in any of the first aspect embodiments above.
[0077] To implement the above embodiments, this application also proposes a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the dynamic desensitization method for multimodal business data in coal mines based on edge collaboration as described in any one of the second aspects of the embodiments above.
[0078] It should be noted that various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0079] Furthermore, in the description of this application, the terms "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limiting the present invention.
[0080] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise explicitly specified.
[0081] In this invention, unless otherwise explicitly specified and limited, the terms "installation," "connection," "linking," and "fixing," etc., should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral part; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components, unless otherwise explicitly limited. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.
[0082] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0083] Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of this invention.
Claims
1. A dynamic data anonymization system for multimodal business data in coal mines based on edge collaboration, characterized in that, include: Edge-desensitization nodes, dynamic evaluation engine, and policy executor; among them, A communication connection is established between the edge desensitization node, the dynamic evaluation engine, and the policy executor; The edge desensitization node is deployed in the edge equipment of the coal mine. The edge desensitization node is used to perform local pre-desensitization on the original data collected by the edge equipment through the feature preservation desensitization algorithm to generate pre-desensitized data. The dynamic evaluation engine is deployed on the edge computing node of the mining area. The dynamic evaluation engine is used to process the data sent by the edge desensitization node using a three-layer risk assessment model. By integrating device security indicators, user behavior anomaly degree and business sensitivity level, dynamic desensitization coefficient is generated. The strategy executor is used to perform cross-modal collaborative desensitization operations based on the knowledge graph of multimodal data desensitization rules and the dynamic desensitization coefficients, so as to eliminate desensitization blind spots in multimodal business data.
2. The system according to claim 1, characterized in that, The edge desensitization node is specifically used for: For coal mine time-series data, the data pattern features are learned through the Long Short-Term Memory (LSTM) network. The time-series data is initially desensitized using a perturbation algorithm based on Gaussian noise injection.
3. The system according to claim 2, characterized in that, The edge desensitization node is specifically used for: A data perturbation model is constructed based on Generative Adversarial Network (GAN), and the time-series data is initially de-identified using the data perturbation model.
4. The system according to claim 1, characterized in that, The three-layer risk assessment model includes: a terminal security assessment module, a user behavior analysis module, and a business sensitivity determination module; wherein, The terminal security assessment module is used to quantify environmental risk values through multiple device security indicators; The user behavior analysis module is used to establish a normal access baseline based on a hidden Markov model and to detect risky user behaviors based on the normal access baseline. The business sensitivity discrimination module is used to automatically determine the data sensitivity of different business data according to a preset data classification standard.
5. The system according to claim 4, characterized in that, The three-tiered risk assessment model is specifically used for: The dynamic desensitization coefficient is generated by fusing the evaluation results from various modules using a fuzzy logic algorithm. The dynamic desensitization coefficient ranges from 0 to 1. When the dynamic desensitization coefficient is 0, it indicates that the business data is completely desensitized. When the dynamic desensitization coefficient is 0, it indicates that the business data is the original data.
6. The system according to claim 1, characterized in that, The policy executor is specifically used for: For devices in video data, once the static attribute information of the device is identified, the dynamic operation data desensitization level of the device is automatically associated. The silhouettes of people in the video data are dynamically blurred using the positioning system data.
7. A dynamic desensitization method for multimodal business data in coal mines based on edge collaboration, characterized in that, The method for applying the edge-collaboration-based dynamic data desensitization system for coal mine multimodal business data as described in any one of claims 1-6 includes the following steps: The raw multimodal business data collected by underground edge devices in coal mines is preprocessed locally through edge desensitization nodes, and various types of preprocessed data are sent to the dynamic evaluation engine. Based on the preprocessed data, the three-layer risk assessment model in the dynamic assessment engine is used to quantitatively assess the terminal security status, user access behavior and business data sensitivity, respectively, and generate a dynamic desensitization coefficient, which is then sent to the edge desensitization node. At the edge desensitization node, pre-desensitization processing is performed according to the dynamic desensitization coefficient, and the generated pre-desensitization data is sent to the policy executor; The policy executor performs cross-modal collaborative desensitization on the pre-desensitized data based on a multimodal data desensitization rule knowledge graph, so as to output desensitized secure data.
8. The method according to claim 7, characterized in that, Before the cross-modal collaborative desensitization operation is performed on the pre-desensitized data by the policy executor based on the multimodal data desensitization rule knowledge graph, the method further includes: The association between multimodal business data is established based on graph neural networks. The association between the multimodal business data and the preset business rules are combined to construct a knowledge graph of multimodal data anonymization rules.
9. An electronic device, characterized in that, Including the dynamic desensitization system for multimodal business data in coal mines based on edge collaboration as described in any one of claims 1-6.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the dynamic desensitization method for multimodal business data in coal mines based on edge collaboration as described in any one of claims 7-8.