A federated learning marketing user privacy analysis method and system

CN122548768APending Publication Date: 2026-08-11SHANGHAI WANGMAI INFORMATION TECH GRP CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-16
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

未闭合标签、已反转标签及接口覆盖不完整的特征记录进入联邦训练后,会生成与真实用户行为不一致的加密模型更新,且聚合端无法直接读取原始数据以定位该类更新的失真来源

Benefits of technology

1、与现有仅依据跨平台身份关联结果进行联合训练的方式相比,本发明围绕广告点击事件建立触达锚点,在冻结的时间边界和版本边界内形成广告特征快照、会员特征快照及交易历史特征快照;再结合标签闭合状态和接口覆盖状态筛选训练快照。对于支付后退款、支付撤销、订单取消、接口补传、字段变化及时间偏差引起的样本状态变化,通过训练准入撤销和聚合前复核将关联更新包隔离,减少标签反转、时间范围不一致和接口数据不完整进入联邦聚合的情形,提高联合训练样本来源的一致性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122548768A_ABST
    Figure CN122548768A_ABST
Patent Text Reader

Abstract

This invention discloses a federated learning marketing user privacy analysis method and system. The federated analysis control terminal establishes a federated analysis session and reads time, window, protected associations, tag closure, interface coverage, field groups, and model version. The advertising platform forms reach anchors based on ad click events. The advertising, membership, and transaction service platforms form feature snapshots around these reach anchors and verify protected association tags. The transaction service platform verifies tag closure status based on orders, payments, refunds, and tag closure periods. Each platform verifies interface coverage status based on interface heartbeats, message sequences, and field integrity. Each platform performs training on the training snapshots, generating encrypted model update packages and training source credentials. Before aggregation, the federated analysis control terminal verifies changes in training source, tag status, and interface coverage, isolates update packages whose training scope has been revoked, and performs federated aggregation on the verified update packages.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of federated learning, privacy computing, and cross-platform data analysis, specifically a method and system for privacy analysis of marketing users in federated learning. Background Technology

[0002] Federated learning in advertising and marketing typically involves the advertising platform storing reach data such as impressions and clicks, the membership service platform storing member attributes and activity data, and the transaction service platform storing conversion data such as orders, payments, refunds, and retention. Without directly exchanging raw user data, participating platforms form joint samples through intersection of privacy sets, and then train an encrypted model based on these joint samples.

[0003] However, privacy set intersection can only confirm that each participating platform has a matching user identifier; it cannot confirm whether the feature snapshots and conversion tags generated by each platform for the same user correspond to the same observation time range. After an ad is clicked, events such as payment, refund, cancellation, and retention may occur at different times, and some feature interfaces may also have message delays, missing fields, or version changes. When feature records with unclosed tags, reversed tags, and incomplete interface coverage are entered into federated training, they will generate encrypted model updates that are inconsistent with real user behavior, and the aggregation end cannot directly read the original data to locate the source of such distortion in the updates. Summary of the Invention

[0004] To address the shortcomings of existing technologies, this invention provides a method and system for analyzing user privacy in federated learning marketing, in order to solve the problems mentioned in the background section.

[0005] To achieve the above objectives, the present invention provides the following technical solution: a method for analyzing user privacy in federated learning marketing, comprising the following steps: S1. The federated analysis control terminal establishes a federated analysis session and reads the time base version, observation window version, protected association version, tag closure version, interface coverage version, field group version, and basic model version. S2. The advertising platform forms reach anchors based on available ad click events within the time frame. The advertising platform, membership service platform, and transaction service platform form local feature snapshots based on the feature review window corresponding to the reach anchors, and verify the protected association markers corresponding to the same reach anchors based on the protected association version. S3. The transaction service platform verifies the tag closure status based on the order status, payment status, refund status, and tag closure period after reaching the anchor point. The advertising platform, membership service platform, and transaction service platform verify the interface coverage status based on the interface heartbeat, message sequence, and field integrity. S4. The advertising platform, membership service platform and transaction service platform perform local model training on training snapshots within the feature review window corresponding to the same feature time range, where the time is available, the protected association is established, the tag is closed, the interface is fully covered, the field group version of the advertising platform, membership service platform and transaction service platform is consistent with the frozen version combination, and the training snapshots are all within the same reach anchor point. S5. The federated analysis control terminal verifies the session version, training snapshot, label closure status, interface coverage status, and field group version of the encrypted model update package based on the training source credentials. Before aggregation, it reviews the label status changes and interface coverage changes. For encrypted model update packages that have not experienced training admission revocation, it performs protected aggregation according to the model block version to form candidate model versions.

[0006] Preferably, S1 includes: The time base version is determined based on the platform clock deviation records generated by the advertising platform, membership service platform, and transaction service platform. Each platform generates time inspection records at 60-second intervals. The most recent four consecutive time inspection records are valid. The most recent valid inspection record is no more than 90 seconds after the establishment of the federated analysis session, and the clock deviation is no more than 2 seconds. The time is considered available.

[0007] Preferably, S1 includes: The observation window version sets the ad click event occurrence time as the anchor point time, the 30-day closed interval before the anchor point time to one second before the anchor point time as the feature review window, the 72 hours from the anchor point time as the conversion observation window, the 14 days from the anchor point time as the tag closing window, the 15 minutes after the tag closing window ends as the interface retransmission window, the 10 minutes after the first encrypted model update package enters the federated analysis control terminal as the update package completion window, and the 10 minutes from the time the complete aggregation group is formed as the pre-aggregation review window.

[0008] Preferably, S2 includes: The advertising platform performs event number verification, exposure association verification, advertising element verification, page session verification, and event sequence verification for ad click events; After an ad click event is verified, an anchor number is generated based on the ad campaign number, anchor date number, click event number, and ad event sequence number, and the click time is set as the anchor time.

[0009] Preferably, S2 includes: The advertising platform, membership service platform and transaction service platform respectively form the association availability status based on the account association records that have been effective before the anchor time and remain valid at the anchor time, and form the session-level protected association mark in the local protected environment based on the federated analysis session number, anchor date number, advertising plan number and protected association version number. The advertising platform, membership service platform, and transaction service platform input the session-level protected association marker into the protected association verification process; the protected association verification process outputs the association verification result corresponding to the anchor number; when the association verification results for the three platforms are all in the established state, the federated analysis control terminal forms a joint association established state.

[0010] Preferably, S3 includes: The transaction service platform verifies the closure status of tags based on the order status sequence, payment status sequence, refund status sequence, and transaction interface coverage status. A positive closed state is formed when the payment success event is within the conversion observation window and meets the following conditions at the end of the label closing window: the order cancellation status is not effective, the order closure status is not effective, the payment revocation status is not effective, the refund success status has not been formed, the refund status is not in process, and the transaction interface coverage status is complete. A negative closed state is formed when no valid payment success event is generated within the conversion observation window, and the order status sequence, payment status sequence, refund status sequence, and transaction interface coverage status are all complete. After a payment success event, if any of the following states are in effect: successful refund, payment cancellation, order cancellation, or order closure, a reverse closed state is formed.

[0011] Preferably, S3 includes: The interface coverage status is formed based on the interface heartbeat status, message sequence status, and field integrity status; the interface forms a complete status when there are four consecutive valid heartbeats, a continuous message sequence, and all required fields are complete. When an interface has pending message transmission, pending message sequence verification, or pending field verification, it forms a pending verification state. When the ad click event interface, page visit completion interface, and ad feature output interface of the advertising platform, the member status interface, member behavior interface, and member feature output interface of the membership service platform, and the order event interface, payment event interface, refund event interface, transaction feature output interface, and tag closure output interface of the transaction service platform all form a complete state, the federated analysis control end forms a joint interface to cover the complete state.

[0012] Preferably, S4 includes: The federal analysis control terminal collects advertising feature source credentials, membership feature source credentials, transaction feature source credentials, tag closure credentials, and interface coverage credentials based on anchor point numbers; When the anchor number, protected association tag reference number and federated analysis session number in each credential are consistent, and the corresponding version referenced by each credential belongs to the frozen version combination of the current federated analysis session, a training range reference list is formed. When the label closure state corresponding to the training range reference list is within the trainable label range consisting of positive and negative closure states, and the joint interface coverage state is in the joint interface full coverage state, the federated analysis control terminal generates training admission credentials, and the training admission credentials are also written with the training admission time. When advertising platforms, membership service platforms, and transaction service platforms detect changes in feature time range, field group version, label closure status, interface coverage status, protected association status, inconsistent training range references, or changes in the basic model version during local review, they generate training admission revocation credentials.

[0013] Preferably, S5 includes: The federal analysis and control terminal collects encrypted model update packages from the advertising platform, membership service platform, and transaction service platform based on the training scope reference list number, basic model version number, and training access time. When the encrypted model update packages for the three platforms have all arrived, and the federated analysis session number, training range reference list number, base model version number, and training admission time are consistent, a complete aggregation group is formed. During the pre-aggregation review, when the federated analysis control receives the training admission revocation credential, it writes the complete aggregation group into the isolation update list; When the federated analysis control receives a pre-aggregation revocation credential sent by any participating platform during the pre-aggregation review, it will write the complete aggregation group corresponding to the training range reference list number in the pre-aggregation revocation credential into the isolation update list. In the complete aggregation group not written into the isolation update list, each encrypted model update package forms a candidate model block according to the corresponding model block version, and forms a candidate model version according to the base model version number and the training range reference list number.

[0014] This invention also provides a federated learning marketing user privacy analysis system, comprising: The federated analysis control terminal is used to establish federated analysis sessions, read the time base version, observation window version, protected association version, label closure version, interface coverage version, field group version, and base model version, verify the session version, training snapshot, label closure status, interface coverage status, and field group version of the encrypted model update package based on the training source credentials, and review the label status changes and interface coverage changes before aggregation, and perform federated aggregation on encrypted model update packages that have not experienced training admission revocation. The advertising platform is used to form reach anchors based on available ad click events over time, form ad feature snapshots based on the feature review window corresponding to the reach anchors, form session-level protected association tags based on protected associated versions, and verify the ad interface coverage status based on interface heartbeats, message sequences, and field integrity. The member service platform is used to generate member feature snapshots based on the feature review window corresponding to the reach anchor, generate session-level protected association tags based on the protected association version, and verify the member interface coverage status based on interface heartbeat, message sequence and field integrity. The transaction service platform is used to form a snapshot of transaction history features based on the feature review window corresponding to the reach anchor point, form a session-level protected association tag based on the protected association version, verify the tag closure status based on the order status, payment status, refund status and tag closure period, and verify the transaction interface coverage status based on the interface heartbeat, message sequence and field integrity. The advertising platform, membership service platform, and transaction service platform are also used to perform local model training on training snapshots that are available in time, have established protected associations, closed tags, complete interface coverage, and whose field group versions are consistent with the frozen version combination, and whose feature time ranges are all within the feature review window corresponding to the same reach anchor point, thereby generating encrypted model update packages and training source credentials.

[0015] Compared with existing technologies, this invention provides a method and system for analyzing user privacy in federated learning marketing, which has the following beneficial effects: 1. Compared to existing methods that rely solely on cross-platform identity association results for joint training, this invention establishes reach anchors around ad click events, forming ad feature snapshots, member feature snapshots, and transaction history feature snapshots within frozen time and version boundaries; then, it combines tag closure status and interface coverage status to filter training snapshots. For sample status changes caused by post-payment refunds, payment cancellations, order cancellations, interface re-uploads, field changes, and time deviations, the associated update packages are isolated through training admission revocation and pre-aggregation review, reducing situations where tag reversals, inconsistent time ranges, and incomplete interface data enter the federated aggregation, thus improving the consistency of the joint training sample source.

[0016] 2. This invention completes feature snapshot creation, association verification, and model training locally on the advertising platform, membership service platform, and transaction service platform. It only transmits feature source credentials, tag closure credentials, interface coverage credentials, training source credentials, and encrypted model update packages to the federated analysis control terminal, without transmitting original advertising features, membership features, transaction features, or account-related base values. The candidate model version is bound to the training scope reference list, training snapshot, and training source credentials, facilitating the tracing of aggregation scope and isolation reasons. This reduces the cross-platform flow of original data while improving the verifiability of the federated training process. Attached Figure Description

[0017] Figure 1 This is a flowchart illustrating a method for analyzing user privacy in federated learning marketing according to the present invention. Figure 2 This is a schematic diagram of the structure of a federated learning marketing user privacy analysis system according to the present invention. Detailed Implementation

[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0019] Example 1: Figure 1 A federated learning marketing user privacy analysis method is presented, which performs the following steps: S1. The federated analysis control terminal establishes a federated analysis session and reads the time base version, observation window version, protected association version, tag closure version, interface coverage version, field group version, and basic model version. S2. The advertising platform forms reach anchors based on available ad click events within the time frame. The advertising platform, membership service platform, and transaction service platform form local feature snapshots based on the feature review window corresponding to the reach anchors, and verify the protected association markers corresponding to the same reach anchors based on the protected association version. S3. The transaction service platform verifies the tag closure status based on the order status, payment status, refund status, and tag closure period after reaching the anchor point. The advertising platform, membership service platform, and transaction service platform verify the interface coverage status based on the interface heartbeat, message sequence, and field integrity. S4. The advertising platform, membership service platform and transaction service platform perform local model training on training snapshots within the feature review window corresponding to the same feature time range, where the time is available, the protected association is established, the tag is closed, the interface is fully covered, the field group version of the advertising platform, membership service platform and transaction service platform is consistent with the frozen version combination, and the training snapshots are all within the same reach anchor point. S5. The federated analysis control terminal verifies the session version, training snapshot, label closure status, interface coverage status, and field group version of the encrypted model update package based on the training source credentials. Before aggregation, it reviews the label status changes and interface coverage changes. For encrypted model update packages that have not experienced training admission revocation, it performs protected aggregation according to the model block version to form candidate model versions.

[0020] S1 is specifically implemented as follows: The federated analysis control terminal establishes a federated analysis session after the start conditions are met during the predetermined training cycle. When the session is established, it reads the time base version, observation window version, protected association version, label closure version, interface coverage version, field group version, and basic model version.

[0021] The predetermined training period uses the anchor date number as the aggregation boundary. This implementation uses East Eighth Time Zone, grouping ad click events generated between 00:00:00 and 23:59:59 daily into the same anchor date number. The ad delivery platform retains the click event reference information that has passed event integrity verification within the current anchor date number. The transaction service platform completes conversion observation, tag closure, and interface retransmission verification around the anchor time of each click event. After the tag closure window and interface retransmission window corresponding to the last click event in the current anchor date number have ended, the federated analysis control terminal determines that anchor date number as the candidate training range.

[0022] The conditions for initiating a federated analysis session are as follows: the advertising platform, membership service platform, and transaction service platform are all in a time-available state; the label closing window and interface retransmission window within the candidate training range have all ended; each platform retains no unprocessed time-pending records; and there are no unconfirmed version changes in the current version combination. If any of the initiation conditions are not met, the federated analysis control terminal will write the anchor date number, the platform number to be verified, the reason for verification, the initial verification time, and the most recent review time into the session verification record, but will not establish the corresponding federated analysis session. After the platform to be verified regains time availability, the federated analysis control terminal will re-verify the candidate training range, window status, and version combination. Once the verification is successful, a federated analysis session will be established.

[0023] The time base version is determined by the platform clock deviation records generated by the advertising platform, membership service platform, and transaction service platform for seven consecutive days prior to the session establishment. Each platform sends a time synchronization request to the time synchronization service at a 60-second inspection interval, and records the local request time, local reception time, reference time in the time synchronization response, time source number, time source certificate version, and inspection sequence number. The platform generates a clock deviation record based on the reference time and the platform's local time, and the clock deviation record includes the inspection time, platform local time, reference time, clock deviation, inspection sequence number, and inspection validity status.

[0024] A platform is considered to be in a time-available state when all four most recent consecutive time inspection records are valid, and the most recent valid inspection record is no more than 90 seconds after the federated analysis session was established. A time-pending state is established when: no time synchronization response is returned; the time source certificate version expires; the inspection sequence number is interrupted; the clock deviation exceeds the time-available boundary; the most recent valid inspection record is more than 90 seconds old; or the same inspection sequence number corresponds to multiple inconsistent reference times. After a platform in a time-pending state re-establishes four consecutive valid inspection records with clock deviations not exceeding the time-available boundary, it generates time recovery credentials, which are then used by the federated analysis control terminal to re-verify the current candidate training range.

[0025] In this implementation, the available time boundary is set to two seconds. This two-second boundary is determined based on clock deviation records and message write buffer records generated during the online acceptance phase of the advertising platform, membership service platform, and transaction service platform. The federated analysis control terminal collects the clock deviation records from each platform and, in conjunction with the buffer durations corresponding to message writes, event sequence storage, and credential transmission, registers the available time boundary in the current time base version as two seconds.

[0026] After the time synchronization service is replaced, the platform log node is replaced, the event access channel is adjusted, or the time source certificate version is changed, each platform will re-form clock deviation records and message write buffer records. The federated analysis control terminal will form the subsequent time base version based on the re-collected records. The established federated analysis session will continue to perform time availability status verification based on the frozen time base version.

[0027] The observation window version is fixed, including the Reach Anchor Point Window, Feature Retrospective Window, Conversion Observation Window, Tag Closure Window, Interface Re-upload Window, and Pre-aggregation Review Window. The Reach Anchor Point Window uses the ad click event time as the anchor point, which is based on the time the ad click receipt is written into the ad event sequence. The Feature Retrospective Window covers the period from the 30-day period before the anchor point to one second before the anchor point. The Conversion Observation Window is 72 hours from the anchor point. The Tag Closure Window is 14 days from the anchor point. The Interface Re-upload Window is 15 minutes after the Tag Closure Window ends. The Update Package Completion Window is 10 minutes after the first encrypted model update package enters the federated analysis control. The Pre-aggregation Review Window is 10 minutes from the moment the complete aggregation group is formed.

[0028] The first 30-day feature review window is determined based on the retention period of member behavior before ad reach and the stability acceptance records of fields. The 72-hour conversion observation window is determined based on the historical duration records between the ad click event and the payment success event. The federated analytics control terminal collects the paid order records corresponding to the current advertising campaign, forms conversion duration records according to ad click time and payment success time, and excludes records corresponding to order association pending verification status, activity pending verification status, transaction event pending verification status, and event conflict status. The observation window version, based on the collected conversion duration records, registers the conversion observation window in the current implementation as 72 hours.

[0029] The 14-day tag closure window is formed based on refund completion records, payment cancellation records, order cancellation records, and order closure records under the current transaction rule version. The federated analysis control terminal collects tag closure duration records corresponding to anchor point numbers, excluding records corresponding to pending transaction events, conflicting events, and pending transaction interface states. Then, it forms a tag closure version based on the normal closure durations of refund completion, payment cancellation, order cancellation, and order closure. In this embodiment, the tag closure version registers the tag closure window as 14 days.

[0030] The 15-minute interface retransmission window is determined based on the normal retransmission duration records, message sorting and processing records, field verification records, and tag status recalculation records generated during the message channel's online acceptance period. The federated analysis control terminal registers the message retransmission reception duration, message sequence continuation duration, field integrity verification duration, and tag status recalculation duration in the observation window version, and registers the interface retransmission window in the current implementation as 15 minutes.

[0031] The update packet completion window is determined based on the encryption model update packet transmission record, update packet arrival delay record, and complete aggregate group formation record. The federated analysis control terminal registers the arrival time of the first update packet, the arrival times of the remaining update packets, and the complete aggregate group formation time in the observation window version. In this embodiment, the observation window version registers the update packet completion window as ten minutes.

[0032] The pre-aggregation review window is formed based on the training source credential verification record, the pre-aggregation confirmation record, and the pre-aggregation withdrawal record. The federated analysis control terminal records the credential verification time, the credential confirmation return time, and the credential withdrawal processing time in the observation window version. In this embodiment, the observation window version records the pre-aggregation review window as ten minutes.

[0033] Advertising interaction events, member behavior events, and transaction events that occur after the anchor point time are not included in the feature snapshot corresponding to the current anchor point. When a payment success event occurs after the conversion observation window ends, the transaction service platform will create an out-of-window payment status for the corresponding anchor point number. The out-of-window payment status is not converted into a positive or negative closed state and is not included in the training snapshot corresponding to the current base model version.

[0034] The protected association version specifies the source range of the fixed account association base value, the association source numbering rules, the session-level protected association tag formation rules, and the association verification credential field rules. The tag closure version specifies the formation rules for order status, payment status, refund status, out-of-window payment status, positive closure status, negative closure status, reverse closure status, and tag pending verification status. The interface coverage version specifies the interface number, heartbeat rules, message sequence rules, field integrity rules, and interface certificate version for each event interface.

[0035] The field group version specifies the field number, field source, valid time range, and required status for the advertising feature field, member feature field, transaction history feature field, and tag field. The basic model version specifies the advertising code block version, member code block version, transaction code block version, fusion block version, input field group version, output tag definition version, and model access certificate version.

[0036] The federated analysis control terminal reads the version number, effective time, expiration time, configuration checksum, and platform read confirmation credentials for each version. The platform read confirmation credentials are written with the platform number, version number, read time, configuration checksum, and read confirmation status. If the read confirmation statuses of all three platforms are valid, and the version number and configuration checksum match the results read by the federated analysis control terminal, the federated analysis control terminal uses the current version combination as the frozen version combination for the federated analysis session and generates federated analysis session credentials.

[0037] The federated analysis session credentials are written with the federated analysis session number, anchor date number, session establishment time, time base version number, observation window version number, protected association version number, tag closure version number, interface coverage version number, ad field group version number, member field group version number, transaction field group version number, base model version number, version checksum, and session validity status. The federated analysis session credentials are sent to the ad delivery platform, member service platform, and transaction service platform, serving as a unified time and version boundary for subsequent reach anchors, feature snapshots, tag closure status, interface coverage status, training snapshots, training source credentials, and encrypted model update packages.

[0038] When advertising platforms, membership service platforms, and transaction service platforms receive field group configuration release records, interface certificate update receipts, time synchronization service switch receipts, tag closure rule release records, or basic model version release records during a federated analysis session, they generate version change credentials. The version change credentials include the change time, the previous version number, the new version number, the reason for the change, the affected platform number, the affected anchor date number, and the configuration verification value.

[0039] The federated analysis control end does not write the changed version to the current federated analysis session. When the version change affects the anchor number before the training admission credential is formed, the training admission credential is not sent to that anchor number; when the version change affects the anchor number for which a training admission credential has already been formed, the anchor number is checked in subsequent training source credential verification and pre-aggregation review to see if it still conforms to the frozen version combination. Anchor numbers that do not conform to the frozen version combination are not included in the training snapshot formation process, and the already formed encrypted model update package is written to the isolated update list.

[0040] S2 is specifically implemented as follows: The ad delivery platform reads ad click events that are in a time-available state in the current federated analysis session and forms reach anchors based on the ad click events. The ad delivery platform, membership service platform and transaction service platform form feature snapshots on their respective local systems around the same reach anchor and complete session-level protected association tag verification based on the protected association version.

[0041] Ad click events are generated by writing ad click receipts into the ad event sequence. Ad click receipts record the click event number, corresponding exposure event number, click time, ad campaign number, ad unit number, creative number, ad placement number, page session number, ad event sequence number, and ad account associated base value reference number.

[0042] The base value associated with the ad account is retained locally on the ad delivery platform, and the ad click receipt only retains the reference number that can locate the locally associated record. The click time is based on the time when the ad event access channel confirms the click receipt and completes the event sequence writing, and is not replaced by the ad display time, page load time, or retransmission message reception time.

[0043] The advertising platform performs the following checks on ad click events sequentially, based on the current time base version of the federated analytics session freeze: event number verification, impression association verification, ad element verification, page session verification, and event sequence verification. Event number verification checks whether the click event number has a unique corresponding record within the current ad event sequence.

[0044] Exposure association verification checks whether the corresponding exposure event number exists and whether the ad campaign number, ad unit number, creative number, and ad placement number are consistent between the click event and the exposure event. Page session verification checks whether the page session number validly corresponds to the current click event. Event sequence verification checks whether the ad event sequence number can be consecutively connected with the sequence number of the preceding event within the same ad event partition.

[0045] When a click event has an empty click event number, an empty corresponding exposure event number, a non-existent corresponding exposure event, inconsistent ad elements, an empty page session number, a missing ad event sequence number, ad event sequence numbers that cannot be consecutively linked, conflicting click times corresponding to the same click event number, or a click time that is in a pending verification state, the ad delivery platform will write the click event into the ad event pending verification record. The ad event pending verification record records the click event number, the reason for pending verification, the formation time, the corresponding exposure event number, the page session number, and the ad event sequence number.

[0046] Ad event pending verification records are not included in the reach anchor range of the current federated analytics session. If a late-written click receipt has the following conditions: its original click time is within the current anchor date number, the event number is not duplicated, the ad event sequence number can be added to the existing event sequence, and the corresponding exposure event verification passes, the ad delivery platform will re-execute the aforementioned verification; if a late-written click receipt does not meet the aforementioned conditions, the ad event remains in the pending verification state, and a new reach anchor will not be formed based on the rewritten event reception time.

[0047] After an ad click event is verified, the ad delivery platform generates an anchor number using the ad campaign number, anchor date number, click event number, and ad event sequence number, and fixes the click time as the anchor moment. The anchor record includes the anchor number, anchor moment, ad campaign number, ad unit number, creative number, ad placement number, page session number, ad event sequence number, ad time availability status, ad field group version number, and ad account associated base value reference number. An anchor number corresponds to only one verified ad click event within the current federated analytics session; the same ad click event cannot generate multiple anchor numbers.

[0048] The advertising platform, membership service platform, and transaction service platform each read local account association records based on the anchor point time. The base value for advertising account association is derived from the binding records of advertising account login status and advertising click sessions; the base value for membership account association is derived from membership account login status and membership account status records; and the base value for transaction account association is derived from transaction account authorization status, order account ownership records, and payment account ownership records. Each platform only uses account association records that were effective before the anchor point time and were not canceled, frozen, or revoked at the anchor point time. Account binding, unbinding, cancellation, freezing, and authorization revocation records generated after the anchor point time do not change the account association judgment corresponding to the currently reached anchor point.

[0049] Each platform performs field standardization processing on local account association records based on the protected association version. Field standardization processing sequentially checks the existence of the account association base value, the existence of the association source number, the validity of the account activation status, the ineffectiveness of the account freeze status, the ineffectiveness of the account cancellation status, and the validity of the identity verification completion status. When the account association base value exists, the association source number exists, the account activation status is valid, the account freeze status is ineffective, the account cancellation status is ineffective, and the identity verification completion status is valid, the corresponding platform establishes an association available status. When the account association base value is empty, the association source number is missing, the account freeze status is effective, the account cancellation status is effective, the identity verification completion status is invalid, or the same account association base value corresponds to conflicting account statuses at the anchor point, the corresponding platform establishes an association pending verification status.

[0050] The advertising platform, membership service platform, and transaction service platform read the federated analysis session number, anchor date number, advertising plan number, and protected association version number within their respective local protected environments to form a session-level protected association tag based on the account association base value corresponding to the associated availability status.

[0051] The input range for session-level protected association tags is limited to the local account association base value and current session parameters within the current federated analysis session. They are not used as the basis for association in subsequent federated analysis sessions and are not written into the raw data exchange messages between advertising, membership and trading platforms.

[0052] The advertising platform, membership service platform, and transaction service platform each submit protected association verification input credentials corresponding to the current anchor number to the protected association verification process. The protected association verification input credentials record the anchor number, protected association tag reference number, participating platform number, association source number, federated analysis session number, anchor date number, advertising plan number, and protected association version number, but do not record the account association base value, account identifier, device identifier, order identifier, payment identifier, or session-level protected association tag text.

[0053] The Federated Analytics control terminal invokes the Protected Association Verification Process based on the Protected Association Version. The Protected Association Verification Process receives the session-level Protected Association tag corresponding to the current anchor number from the advertising platform, membership service platform, and transaction service platform, and reads the Federated Analytics Session Number, Anchor Date Number, Advertising Campaign Number, and Protected Association Version Number as session constraint information.

[0054] The protected association verification process performs protected correspondence verification under the same session constraint on the three session-level protected association tags, generating only the protected association verification result. The protected association verification result records the anchor number, protected association tag reference number, participating platform number, association verification status, and verification time, but does not record the account association base value, account identifier, device identifier, order identifier, payment identifier, or session-level protected association tag text.

[0055] When the association verification status for the current anchor point number is established on all three platforms, the federated analysis control terminal establishes a joint association established status. When the association verification status for any platform is pending verification, the federated analysis control terminal establishes a joint association pending verification status. When any platform fails to generate a session-level protected association marker, or when the protected association verification process fails to generate an established status for all three platforms, the federated analysis control terminal establishes a joint association invalid status. Joint association pending verification and joint association invalid statuses do not qualify for subsequent training.

[0056] The advertising platform generates an ad feature snapshot from the closed period of thirty days prior to the anchor time to one second prior to the anchor time. The sources of the ad feature snapshot are limited to ad impression events, ad display completion receipts, ad interaction completion receipts, and page visit completion receipts. The ad campaign reach frequency status is generated based on the ad campaign impression events within the feature review window, using the base value reference number associated with the same ad account.

[0057] The ad placement reach frequency status is based on the ad placement exposure events within the feature review window, using the base value reference number associated with the same ad account. The creative reach status is based on the creative ID and ad display completion receipt. The pre-click ad interaction status is based on the ad expansion completion receipt, creative interaction completion receipt, and page dwell completion receipt generated before the anchor point time. The ad page visit completion status is based on the page session ID, page visit completion time, and page load completion status. The ad device environment status is based on the device system type, network access type, and ad display environment version.

[0058] The membership service platform generates a member feature snapshot within the same feature review window. The sources of these member feature snapshots are limited to successful login events, page access completion events, browsing completion events, successful collection receipts, successful add-to-cart receipts, benefit redemption completion receipts, and member account status change records. The number of valid login days in the past thirty days is calculated by deduplicating successful login events by calendar day; failed login events, session refresh events, and automatic renewal events are not included in the valid login days count.

[0059] The number of valid visits in the past seven days is calculated based on page visit completion events with a page session number and a visit completion status. Page loading failure events, repeated refresh events, and abnormal redirect events are not included in the valid visit count. The number of valid browsing category sets in the past seven days is calculated based on the product category code in the browsing completion event. Browsing completion events with empty product category codes are not included in the browsing category set status. The number of valid favorites in the past seven days is calculated based on successful favorite receipts. The number of valid add-to-cart statuses in the past seven days is calculated based on successful add-to-cart receipts. The number of benefits redemption statuses is calculated based on benefits redemption completion receipts.

[0060] The transaction service platform creates a snapshot of transaction history features within the same feature review window. This snapshot only uses order records, payment records, refund records, and fulfillment completion records created before the anchor point. Order creation events, payment events, refund events, and fulfillment events created after the anchor point are not included in the transaction history snapshot.

[0061] The status of valid payment orders within the past 30 days in the transaction history snapshot is based on payment success receipts, order completion status, and the product code to which the order belongs. Orders that have already been refunded, cancelled, cancelled, or closed after successful payment are not included in the valid payment order status. The status of valid refunds within the past 30 days is based on refund success receipts and order association relationships. The status of fulfilled orders within the past 30 days is based on fulfillment completion receipts. The status of valid shopping carts within the past 7 days is based on shopping cart records where products are still in a valid sales status. The status of used benefits within the past 7 days is based on successful benefit redemption receipts.

[0062] When creating local feature snapshots, advertising platforms, membership service platforms, and transaction service platforms all verify the occurrence time of the source event, the field group version number, and the status of required fields. If the source event time is later than the anchor point time, earlier than the feature review window start time, required fields are empty, conflicting field contents correspond to the same event number, or the field group version number is inconsistent with the frozen field group version in the federated analysis session, the corresponding platform will enter a feature pending verification status. The feature pending verification status will not be replaced by default values, historical values, or subsequent event content. Advertising feature snapshots, membership feature snapshots, and transaction history feature snapshots are all frozen after local completion, and the frozen feature snapshots will not be changed by events occurring after the anchor point time.

[0063] The advertising platform, membership service platform, and transaction service platform each generate feature source credentials. Feature source credentials record the anchor number, protected association tag reference number, corresponding field group version number, feature time range, time availability status, field integrity status, feature pending verification status, and local snapshot number.

[0064] The three platforms only send feature source credentials to the federated analysis control terminal, and do not send advertising features, membership features, transaction history features, or local account association records. The federated analysis control terminal uses the anchor number, protected association tag reference number, feature time range, field group version number, and status information from the three feature source credentials as the sample boundaries for S3 to perform label closure verification, interface coverage verification, and joint anonymized sample range verification.

[0065] S3 is specifically implemented as follows: The transaction service platform verifies the order status, payment status, refund status, and transaction interface coverage status within the conversion observation window, tag closure window, and interface retransmission window, based on the anchor point number and protected association tag reference number formed by S2, thus forming a tag closure status. The advertising platform, membership service platform, and transaction service platform form an interface coverage status based on the interface heartbeat, message sequence, and field integrity status within the time range corresponding to the current anchor point number.

[0066] The transaction service platform reads the following events within 72 hours after the anchor point time: order creation event, payment initiation event, payment success event, payment failure event, payment cancellation event, refund application event, refund review event, refund success event, refund rejection event, refund closure event, order cancellation event, order closure event, and fulfillment completion event.

[0067] The order creation event records the order's associated base value, order creation time, order activity code, order status, order event sequence number, and order source channel number. The payment event records the order's associated reference number, payment event time, payment status, payment event sequence number, and payment source channel number. The refund event records the order's associated reference number, refund event time, refund status, refund event sequence number, and refund source channel number.

[0068] The local association between the order association base value and the protected association marker reference number is formed based on the transaction account authorization status, order account ownership record, and payment account ownership record that have taken effect on the transaction service platform before the anchor time. When the transaction account authorization status is valid, the order account ownership record is valid, and the payment account ownership record is valid, and all three records correspond to the same account association base value, the transaction service platform establishes an order association status.

[0069] When a transaction account authorization is revoked, an order account ownership record is missing, a payment account ownership record is missing, or there are conflicting account ownership records corresponding to the same order's associated base value, the transaction service platform will establish an order association pending verification status. Account authorization, account deassociation, and account status changes that occur after the anchor point time will not change the order association judgment corresponding to the current anchor point number.

[0070] The correspondence between order activity codes and advertising campaign numbers is established based on the activity attribution records stored locally on the transaction service platform. These records consist of the activity code, advertising campaign number, effective time, expiration time, and activity status, all written to the transaction service platform before the advertising campaign is launched. When the order creation time falls between the effective and expiration times in the activity attribution record, the order activity code matches the advertising campaign number in the reach anchor, and the activity status is valid, the transaction service platform establishes a corresponding activity status. When the order activity code is empty, the activity attribution record does not exist, the activity status is invalid, the order creation time exceeds the valid time range of the activity attribution record, or the order activity code corresponds to multiple advertising campaign numbers, the transaction service platform establishes an activity pending verification status.

[0071] The transaction service platform uses the original event occurrence time and event sequence number to form order status sequences, payment status sequences, and refund status sequences. Multiple events with the same original event occurrence time are arranged according to their event sequence number. When the field content corresponding to the same original event number is identical, the transaction service platform retains the event written earlier and does not write it again into the status sequence.

[0072] When the same original event number corresponds to different event times, status content, order-related reference numbers, or source channel numbers, the transaction service platform enters an event conflict state. When the event sequence number cannot be consecutive, the event time is empty, the event occurrence time is earlier than the anchor point time but is written into the conversion observation window, or the event source channel number is invalid, the transaction service platform enters a transaction event pending verification state. Before the event conflict state and the transaction event pending verification state are resolved, the corresponding anchor point number cannot form a label closure state that can be used for training.

[0073] When the order association establishment status, activity matching status, and payment success event are all established simultaneously, and the payment success event occurs within the conversion observation window, the transaction service platform forms a positive candidate status. When the conversion observation window ends, and both the order association establishment status and activity matching status are valid, but the order status sequence, payment status sequence, and refund status sequence have not yet reached a transaction event pending verification status, and no valid payment success event has occurred, the transaction service platform forms a negative candidate status. After a payment success event occurs, if a refund success event, payment cancellation event, order cancellation event, or order closure event occurs within the label closing window, the transaction service platform forms a reverse candidate status.

[0074] When a refund application event and a refund review event have occurred, but a successful refund event, a rejected refund event, or a refund closure event have not yet occurred, the transaction service platform will maintain the current anchor point number in a "pending verification" state and will not prematurely form a positive closure state. When an order association pending verification state, an activity pending verification state, a transaction event pending verification state, an event conflict state, a transaction interface coverage pending verification state, or a transaction interface incomplete coverage state occurs, the transaction service platform will establish a "pending verification" state.

[0075] When the label closing window ends, the transaction service platform performs a closure verification on the order status sequence, payment status sequence, refund status sequence, and transaction interface coverage status. A positive closed status is formed when the positive candidate status meets the following conditions: payment success status is valid, order cancellation status is not effective, order closure status is not effective, payment reversal status is not effective, refund success status has not been formed, refund application status is not in process, and transaction interface coverage status is complete.

[0076] A negative candidate state is formed when, within the conversion observation window, no valid payment success event has occurred, the order status sequence is complete, the payment status sequence is complete, the refund status sequence is complete, and the transaction interface coverage status is complete. A reverse candidate state is formed when the label closure window ends. Reversed closure states remain independent and are not translated into positive or negative closure states. When a payment success event occurs after the conversion observation window ends, the transaction service platform forms an out-of-window payment state. Out-of-window payment states are not included in the training range corresponding to positive, negative, and reverse closure states.

[0077] After the tag closure window ends, the pending verification status enters a 15-minute interface retransmission window. The transaction service platform receives order retransmission messages, payment retransmission messages, and refund retransmission messages, and verifies the original event number, original event occurrence time, original event sequence number, retransmission reception time, and message source channel number in the retransmission messages. If the original event number is not written into the existing status sequence, the original event occurrence time is within the tag closure window, the original event sequence number can continue from the existing status sequence, and the message source channel number is valid, the transaction service platform writes the retransmission message into the corresponding status sequence and then re-executes the tag closure verification.

[0078] If the retransmitted message conflicts with the existing state sequence, the original event occurrence time is empty, the original event occurrence time exceeds the label closing window, the message source channel number is invalid, or the label pending verification status is not eliminated after the interface retransmission window ends, the transaction service platform will maintain the label pending verification status and will not write the corresponding anchor number into the training admission range.

[0079] The advertising platform, membership service platform, and transaction service platform each establish an interface coverage state based on the time range corresponding to the current anchor number. The advertising platform verifies the ad click event interface, ad feature output interface, and page visit completion interface. The membership service platform verifies the member status interface, member behavior interface, and member feature output interface. The transaction service platform verifies the order event interface, payment event interface, refund event interface, transaction feature output interface, and tag closure output interface. The verification time range for each interface starts from the start time of the feature review window for the corresponding anchor number and continues until the end of the tag closure window and interface retransmission window.

[0080] The interface heartbeat cycle, the number of consecutive valid heartbeats, and the message delay boundary are registered under the interface overlay version. The federated analysis and control terminal forms the interface heartbeat cycle, the number of consecutive valid heartbeats, and the message delay boundary based on the service level agreement under the current interface certificate version, gateway inspection records, interface heartbeat recovery records, message middleware stable operation records, and arrival delay records of order, payment, and refund message channels.

[0081] The interface heartbeat period is used to limit the sending interval of adjacent heartbeat requests, the number of consecutive valid heartbeats is used to verify whether a continuous and stable response is formed after the interface recovers, and the message delay boundary is used to verify the effective arrival time of the original event from message generation to interface reception. In this embodiment, the interface coverage version registers the interface heartbeat period as 30 seconds, the number of consecutive valid heartbeats as four, and the message delay boundary as 300 seconds.

[0082] When the interface certificate version, message middleware version, service node list, or transaction message channel changes, the federated analysis control terminal re-collects the corresponding operation records and forms the subsequent interface coverage version; the established federated analysis session continues to perform interface coverage verification based on the frozen interface coverage version.

[0083] The interface heartbeat records the interface number, heartbeat initiation time, heartbeat response time, interface certificate version, service node number, message queue partition number, and heartbeat response status. A valid heartbeat is formed when the heartbeat response status is successful, the heartbeat response time is within 300 seconds, the interface certificate version matches the interface overriding version, the service node number is in the list of valid nodes, and the message queue partition number is valid. Four consecutive valid heartbeats constitute an established interface heartbeat status.

[0084] The message sequence status is formed by the message topic number, partition number, message sequence number, previous message sequence number, message reception time, and original event number. A continuous message sequence status is formed when the current message sequence number is consecutive to the previous message sequence number within the same message topic and partition, the original event number does not conflict, and the message reception time is within 300 seconds. A pending message sequence status is formed when the message sequence number is interrupted, the message reception time exceeds 300 seconds, the content corresponding to the same original event number is inconsistent, or the message topic number is inconsistent with the interface coverage version.

[0085] The field completeness status is determined based on the list of required fields corresponding to the current interface number in the interface coverage version. A field completeness status occurs when all required fields in the interface output exist, the field code matches the corresponding field group version, and the field time range matches the observation window corresponding to the current anchor number. A field pending verification status occurs when required fields are missing, field codes are inconsistent, or the field time range exceeds the current observation window.

[0086] An interface is considered complete when its heartbeat, message sequence continuity, and field completeness are all simultaneously enabled. An interface is considered pending verification when it has pending message retransmissions, pending message sequence verification, or pending field verification. An interface is considered incomplete when it has fewer than four consecutive valid heartbeats, a message sequence interruption exceeding the interface retransmission window, a required field missing exceeding the interface retransmission window, an expired interface certificate, or a service node not being in the valid node list.

[0087] When all the necessary interfaces of the advertising platform, membership service platform, and transaction service platform are in a complete state, the federated analysis control terminal forms a joint interface to cover the complete state. If any platform has a pending verification state, the federated analysis control terminal forms a joint interface to cover the pending verification state. If any platform has an incomplete state, the federated analysis control terminal forms a joint interface to cover the incomplete state.

[0088] The transaction service platform writes the anchor number, protected association tag reference number, tag candidate status, tag closure status, transaction interface coverage status, tag closure version number, feature time range, and tag formation time into the tag closure credential. The advertising platform, membership service platform, and transaction service platform respectively write the anchor number, interface number, interface coverage status, interface coverage version number, verification time range, and credential formation time into the interface coverage credential. The tag closure credential and interface coverage credential are sent to the federated analysis control terminal for S4 to filter training snapshots around the same anchor number.

[0089] S4 is specifically implemented as follows: The federated analysis control terminal uses the advertising feature source credentials, membership feature source credentials, and transaction feature source credentials formed by S2, as well as the label closure credentials and interface coverage credentials formed by S3, to verify the training source boundary of the joint anonymized samples around the anchor number; the advertising platform, membership service platform, and transaction service platform establish training snapshots for the local feature snapshots that have passed the training access verification, perform local model training, and form encrypted model update packages and training source credentials.

[0090] The federated analytics control unit aggregates advertising feature source credentials, membership feature source credentials, transaction feature source credentials, tag closure credentials, and interface coverage credentials according to anchor point numbers, forming joint anonymization sample candidate records. Each joint anonymization sample candidate record records the federated analytics session number, anchor point number, advertising campaign number, protected association tag reference number, time base version number, observation window version number, protected association version number, tag closure version number, interface coverage version number, advertising field group version number, membership field group version number, transaction field group version number, base model version number, time availability status, joint association verification status, tag closure status, joint interface coverage status, field completeness status, and joint anonymization sample range status.

[0091] The joint anonymization sample range status is formed based on the anchor number, protected association tag reference number, federated analysis session number, version number, and feature time range among the five types of credentials. The joint anonymization sample range consistency status is achieved when the anchor number, protected association tag reference number, federated analysis session number, time base version number, observation window version number, protected association version number, tag closure version number, and interface coverage version number are consistent with the frozen version of the current federated analysis session; the version numbers of the advertising field group, membership field group, and transaction field group are consistent with the version numbers of the advertising field group, membership field group, and transaction field group in the frozen version combination of the current federated analysis session, respectively; and all three feature time ranges are within the feature review window at the corresponding anchor time.

[0092] If any credential is missing, anchor point numbers are inconsistent, protected association tag reference numbers are inconsistent, federated analysis session numbers are inconsistent, version numbers are inconsistent, feature time ranges are earlier than the feature review window start time, feature time ranges are later than the anchor point time, or the same anchor point number corresponds to multiple conflicting label closure states, the federated analysis control terminal will enter a joint anonymization sample range pending verification state. The joint anonymization sample range pending verification state will not be replaced by historical snapshots, subsequent snapshots, or default field content, and will not be included in the training admission range.

[0093] When the advertising time availability status, membership time availability status, and transaction time availability status are all valid, the joint association verification status is that the joint association is established, the label closure status is either positive or negative closure, the joint interface coverage status is that the joint interface is fully covered, the advertising feature field complete status, the membership feature field complete status, and the transaction feature field complete status are all complete, and the joint anonymized sample range status is consistent, the federated analysis control terminal forms a training admission status.

[0094] The federated analysis control terminal generates a training range reference list based on the anchor point numbers corresponding to the training admission status. The training range reference list is arranged in ascending order of anchor point numbers and includes the following reference numbers: anchor point number set reference number, protected association tag reference number set reference number, advertising feature snapshot reference number, membership feature snapshot reference number, transaction history feature snapshot reference number, tag closure status set reference number, interface coverage status set reference number, time base version number, observation window version number, field group version combination, and base model version number. The field group version combination includes the advertising field group version number, membership field group version number, and transaction field group version number.

[0095] The anchor point number set reference is only used to identify the set of anchor point numbers within the current training range and is not included in the ad click event content. The tag closure state set reference is only used to identify the anchor point range corresponding to the positive and negative closure states and is not included in the order, payment, and refund event content. The interface coverage state set reference is only used to identify the anchor point range corresponding to the complete coverage state of the joint interface and is not included in the interface log body.

[0096] The federated analysis control terminal generates training admission credentials based on the training scope reference list and sends them to the advertising platform, membership service platform, and transaction service platform respectively. The training admission credentials record the federated analysis session number, anchor number set reference number, protected association tag reference number set reference number, training scope reference list number, tag closure status set reference number, interface coverage status set reference number, advertising field group version number, membership field group version number, transaction field group version number, base model version number, training admission time, and training admission status.

[0097] When the label closure status is reverse closure, label pending verification, or out-of-window payment status; the joint interface coverage status is joint interface coverage pending verification or joint interface coverage incomplete status; the joint association verification status is joint association pending verification or joint association not established status; the time availability status is pending verification status; the field complete status is pending verification status; or the joint anonymized sample range status is pending verification status, the federated analysis control terminal does not generate training admission credentials.

[0098] After receiving the training access credentials, the advertising platform reads the ad feature snapshot reference number, ad field group version number, ad time availability status, ad interface coverage status, protected association tag reference number, and base model version number, and verifies whether these match the corresponding content in the training access credentials. The membership service platform verifies the member feature snapshot reference number, member field group version number, member time availability status, member interface coverage status, protected association tag reference number, and base model version number in the same way. The transaction service platform verifies the transaction history feature snapshot reference number, tag closure status, transaction field group version number, transaction time availability status, transaction interface coverage status, protected association tag reference number, and base model version number.

[0099] If any platform discovers changes in feature time range, field group version, field integrity status, interface coverage status, label closure status, protected association status, or base model version during local review, or if the anchor number in the training range reference list does not correspond to the local feature snapshot reference number, it will stop creating the training snapshot with the corresponding anchor number and generate a training admission revocation credential.

[0100] The training admission revocation credential records the federated analysis session number, anchor number, revocation platform number, revocation time, revocation reason code, feature snapshot reference number, training range reference list number, and corresponding version number. The revocation reason code is limited to changes in time boundaries, changes in field group versions, changes in label closure status, changes in interface coverage status, changes in protected association status, missing snapshot fields, inconsistent training range references, and inconsistent base model versions.

[0101] Upon receiving the training admission revocation credential, the federated analysis control terminal maintains the anchor number set, version combination, and training scope reference list number of the corresponding training scope reference list unchanged, and marks the training scope reference list as having been revoked. The federated analysis control terminal writes the revocation anchor number, revocation platform number, revocation time, revocation reason code, training admission credential reference number, and training scope reference list number into the training scope revocation record.

[0102] If a training snapshot has not yet been generated for a corresponding anchor number, the federated analysis control terminal will no longer send the training admission credentials corresponding to that anchor number to the three participating platforms; the remaining anchor numbers that have not been revoked will be re-formed into a training scope reference list, and a new training scope reference list number will be generated. The new training scope reference list includes the revision source list number, the set reference number of the removed anchor numbers, and the revision formation time.

[0103] When the corresponding anchor point number has already formed a training snapshot, encrypted model update package, or training source credential, the federated analysis control terminal does not rewrite the original training scope reference list, but writes the associated encrypted model update package, training source credential, and aggregation group that reference the original training scope reference list number into the isolated update list.

[0104] When any one of the advertising platform, membership service platform, and transaction service platform generates a training access revocation credential, the other two platforms will no longer create a new training snapshot for the same anchor point number.

[0105] When the corresponding anchor number has generated an encrypted model update package but has not yet entered the pre-aggregation review queue, the federated analysis control terminal will write the associated encrypted model update package into the isolation update list; when it has entered the pre-aggregation review queue, the federated analysis control terminal will stop the pre-aggregation review of the corresponding anchor number and write the associated encrypted model update package formed by the advertising platform, membership service platform and transaction service platform into the isolation update list.

[0106] The advertising platform creates advertising training snapshots for training access statuses that have not been revoked. Each advertising training snapshot records the training snapshot number, anchor number set reference number, advertising feature snapshot reference number, advertising field group version number, training access credential reference number, base model version number, and snapshot creation time. The membership service platform creates member training snapshots, which record the training snapshot number, anchor number set reference number, member feature snapshot reference number, member field group version number, training access credential reference number, base model version number, and snapshot creation time.

[0107] The transaction service platform establishes a transaction training snapshot, which records the training snapshot number, anchor number set reference number, transaction history feature snapshot reference number, label closure state set reference number, transaction field group version number, training admission credential reference number, basic model version number, and snapshot formation time.

[0108] Advertising training snapshots, member training snapshots, and transaction training snapshots remain frozen after they are created locally. Once a training snapshot is frozen, advertising events, member behavior events, order events, payment events, refund events, and field version change records generated after the anchor time are not written to the current training snapshot. If a change in tag closure state, interface coverage state, time availability state, inconsistency in field group versions, or inconsistency in the base model version is detected after a training snapshot is frozen, the corresponding platform will generate a training admission revocation credential and will not rewrite the frozen training snapshot.

[0109] The advertising platform encodes the advertising training snapshot into an encrypted intermediate representation based on the advertising encoding block version, and the membership service platform encodes the membership training snapshot into an encrypted intermediate representation based on the membership encoding block version. Both intermediate representations are bound to the federated analysis session number, training range reference list number, training snapshot number, and model block version number, and sent to the protected training environment of the transaction service platform.

[0110] The transaction service platform forms a transaction intermediate representation based on the transaction code block version, and inputs the encrypted advertising intermediate representation, the encrypted membership intermediate representation, and the transaction intermediate representation into the fusion block in a protected training environment. It forms a fusion training error based on the label closure state of the corresponding anchor number, and generates the encrypted feedback quantities corresponding to the advertising code block, membership code block, transaction code block, and fusion block. The encrypted feedback quantities corresponding to the advertising code block and membership code block are sent to the advertising platform and the membership service platform, respectively.

[0111] The advertising platform, membership service platform, and transaction service platform update the advertising code block, membership code block, transaction code block, and fusion block respectively based on the local training snapshot and the corresponding encrypted feedback volume, and form the encrypted model update package of the corresponding model block; after the federated analysis control terminal verifies the training source, it performs model block-level federated merging according to the model block version number to form candidate model versions.

[0112] The advertising platform reads only local snapshots of ad features, the membership service platform reads only local snapshots of membership features, and the transaction service platform reads only local snapshots of transaction history features and tag closure status. No platform sends original ad features, original membership features, original transaction features, original conversion tags, account-associated base values, order numbers, payment numbers, or refund numbers to other platforms. The federated analytics control terminal does not receive the encrypted intermediate representations of ads, memberships, or transactions.

[0113] After local model training is completed, the advertising platform generates parameter updates for the advertising encoding block, the membership service platform generates parameter updates for the membership encoding block, and the transaction service platform generates parameter updates for the transaction encoding block and the fusion block. These parameter updates correspond to the parameter positions of the respective model blocks in the current base model version and do not include advertising features, membership features, transaction features, label closure status, account association base values, order numbers, payment numbers, or refund numbers.

[0114] The advertising platform, membership service platform, and transaction service platform each encrypt the corresponding parameter updates locally based on the model access certificate version, forming encrypted model update packages. The advertising encrypted model update package records the advertising encoding block version number and the encrypted update amount of the advertising encoding block parameters; the membership encrypted model update package records the membership encoding block version number and the encrypted update amount of the membership encoding block parameters; the transaction encrypted model update package records the transaction encoding block version number, the fusion block version number, the encrypted update amount of the transaction encoding block parameters, and the encrypted update amount of the fusion block parameters. Each encrypted model update package also records the federated analysis session number, the base model version number, the training snapshot number, the training range reference list number, the training access credential reference number, the update package number, the update generation time, the encryption protection status, and the update validity status.

[0115] The encryption protection status is formed based on the model access certificate version, the protected aggregate environment identifier, and the aggregate certificate version corresponding to the base model version. When the model access certificate version is invalid, the aggregate certificate version is invalid, the training snapshot number is empty, the training range reference list number is empty, the training admission credential reference number is empty, the training admission status is revoked, or the base model version number is inconsistent with the frozen version of the current federated analysis session, the corresponding encrypted model update package will be in an update pending state and will not be sent to the federated analysis control terminal.

[0116] Once the update validity status is established, each platform generates training source credentials. These credentials record the federated analysis session number, training scope reference list number, anchor number set reference number, training snapshot number set reference number, label closure status set reference number, interface coverage status set reference number, time base version number, observation window version number, protected association version number, label closure version number, interface coverage version number, field group version combination, base model version number, training generation time, and training source validity status. The encrypted model update package and training source credentials are simultaneously sent to the federated analysis control terminal for S5 to perform training source credential verification and pre-aggregation review.

[0117] S5 is implemented as follows: After receiving the encrypted model update package and training source credentials generated by S4, the federated analysis control terminal first forms an aggregation group based on the same training scope reference list number, the same basic model version number, and the same training admission time. Then, it performs training source verification, pre-aggregation review, and federated aggregation on the aggregation group.

[0118] The federated analysis control unit categorizes encrypted model update packages sent by the advertising platform, membership service platform, and transaction service platform into corresponding aggregation groups. An aggregation group is determined by the training scope reference list number, the base model version number, and the training admission time. A complete aggregation group is formed when the encrypted advertising model update package, the encrypted membership model update package, and the encrypted transaction model update package corresponding to the same training scope reference list number have all arrived, and the federated analysis session number, training scope reference list number, base model version number, and training admission time are consistent across all three update packages.

[0119] If the encrypted model update package from any platform fails to arrive, the training range reference list number in the update package is inconsistent, the base model version number is inconsistent, the training admission time is inconsistent, or the same platform repeatedly sends multiple update packages with inconsistent content for the same training range reference list number, the federated analysis control terminal will form an aggregation group pending verification status.

[0120] The aggregation group's pending verification status is established when the first encrypted model update package arrives. When the advertising platform, membership service platform, and transaction service platform complete valid update packages before the update package completion window closes, the federated analysis control terminal re-executes the aggregation group verification. If a complete aggregation group is not formed by the end of the update package completion window, the federated analysis control terminal adds the arrived encrypted model update packages to the isolated update list, without replacing the complete aggregation group with a single platform update package, and without merging update packages corresponding to different training range reference list numbers.

[0121] The federated analysis control terminal performs training source verification on the encrypted model update package and training source credentials in the complete aggregation group. Training source verification includes session version verification, training snapshot verification, label closure status verification, interface coverage status verification, field group version verification, and training admission revocation verification.

[0122] The session version verification checks whether the Federated Analysis Session Number, Base Model Version Number, Model Block Version Number, and Training Admission Credential Reference Number in the encrypted model update package correspond to the Federated Analysis Session Number, Base Model Version Number, Time Base Version Number, Observation Window Version Number, Protected Association Version Number, Tag Closure Version Number, Interface Coverage Version Number, and Field Group Version Number in the Training Source Credentials. A valid session version is established when the Ad Encoding Block Version, Membership Encoding Block Version, Transaction Encoding Block Version, and Fusion Block Version all match the base model version frozen in the Federated Analysis Session.

[0123] The training snapshot verification checks the correspondence between the training snapshot number set reference number, the anchor number set reference number, the training range reference list number, and the protected association marker reference number set reference number. A valid training snapshot is considered valid if all training snapshot numbers correspond to valid training access credentials, all anchor numbers are consistent with the joint anonymization sample range, all protected association marker reference numbers are in a jointly associated state, and the training range reference list number is not in a revoked state.

[0124] The tag closure state verification checks whether the tag closure state set reference number corresponds only to positive and negative closure states. The interface coverage state verification checks whether the interface coverage state set reference number corresponds only to the federated interface coverage complete state. The field group version verification checks whether the version numbers of the advertising field group, membership field group, and transaction field group are consistent with the version numbers of the advertising field group, membership field group, and transaction field group in the frozen version combination of the federated analysis session, respectively. The training admission revocation verification checks whether the anchor number, training snapshot number, training scope reference list number, and version combination associated with the current aggregation group have training admission revocation credentials or version change credentials.

[0125] If the session version is valid, the training snapshot is valid, the label closure status verification is successful, the interface coverage status verification is successful, and the field group version verification is successful, and no revocation status is found in the training admission revocation verification, the federated analysis control terminal will write the complete aggregation group to the pre-aggregation review queue. If any verification fails, the federated analysis control terminal will write the complete aggregation group to the isolation update list.

[0126] The isolation update list records the aggregation group number, training range reference list number, anchor number set reference number, training snapshot number set reference number, update package number set reference number, training source credential reference number, isolation time, isolation reason, and base model version number. Encrypted model update packages in the isolation update list are not included in the current federated aggregation task, are not written back to the local training snapshot, and are not used as training sources for subsequent candidate models.

[0127] The Federated Analytics control unit sends pre-aggregation review requests to the advertising platform, membership service platform, and transaction service platform for aggregation groups that have entered the pre-aggregation review queue. The pre-aggregation review request records the Federated Analytics session number, aggregation group number, training range reference list number, anchor number set reference number, training snapshot number set reference number, training generation time, review start time, review end time, and base model version number. The review start time is based on the complete aggregation group formation time, and the review end time is ten minutes after the review start time; the review time range is determined based on the version of the observation window frozen in the current Federated Analytics session.

[0128] Between the training generation time and the review completion time, the advertising platform reads the ad event retransmission records, page session binding records, ad interface heartbeat records, ad message sequence records, ad field group version change records, and ad clock deviation records corresponding to the current anchor point number set. If the advertising platform does not detect click event cancellation, page session binding conflicts, ad event sequence conflicts, ad interface coverage status changes from complete to pending or incomplete, ad field group version changes, or ad time availability status changes from valid to pending, it generates a pre-aggregation confirmation credential.

[0129] Within the same review scope, the member service platform reads member account status change records, member event retransmission records, member interface heartbeat records, member message sequence records, member field group version change records, and member clock deviation records corresponding to the current anchor point number set. The member service platform generates a pre-aggregation confirmation credential when it does not detect any account freeze status, account cancellation status, identity verification completion status failure, member event time exceeding the feature review window, member interface coverage status changing from complete to pending or incomplete, member field group version changes, or member time availability status changing from valid to pending.

[0130] Within the same review scope, the transaction service platform reads the order retransmission records, payment retransmission records, refund retransmission records, transaction interface heartbeat records, transaction message sequence records, tag status change records, transaction field group version change records, and transaction clock deviation records corresponding to the current anchor point number set.

[0131] The transaction service platform generates a pre-aggregation withdrawal credential when the anchor number corresponding to the positive closure state experiences events such as successful refund, payment cancellation, order cancellation, order closure, payment status conflict, order association conflict, transaction interface coverage status changing from complete to pending or incomplete, transaction time availability status changing from valid to pending, or transaction field group version change.

[0132] The transaction aggregation pre-aggregation withdrawal credentials record the federated analysis session number, aggregation group number, anchor number, training snapshot number, withdrawal time, withdrawal reason code, original label closure status, current label status, transaction interface coverage status, transaction time availability status, and transaction field group version number. The withdrawal reason code is limited to label reversal retransmission, payment status conflict, order association conflict, refund status retransmission, interface coverage degradation, time boundary change, and field group version change.

[0133] When the advertising platform and membership service platform discover during the review that the corresponding anchor number no longer meets the requirements of advertising feature snapshot, membership feature snapshot, association status, or interface coverage status, they will generate pre-aggregation withdrawal credentials for advertising and pre-aggregation for membership respectively. The credential fields are consistent with the pre-aggregation withdrawal credentials for transaction. The withdrawal reason codes are limited to advertising event cancellation, page session conflict, advertising interface coverage degradation, advertising field group version change, membership account status invalidation, membership event time out of bounds, membership interface coverage degradation, and membership field group version change, respectively.

[0134] Upon receiving any pre-aggregation withdrawal credential, the Federated Analysis Control System writes the entire corresponding aggregation group into the segregated update list. The advertising encryption model update package, member encryption model update package, and transaction encryption model update package within the aggregation group simultaneously cease subsequent processing; the Federated Aggregation will not continue with the encryption model update package from the unwithdrawn platform. If the pre-aggregation withdrawal credential arrives after the review end time, and the corresponding aggregation group has not yet executed the Federated Aggregation, the Federated Analysis Control System will still write the aggregation group into the segregated update list.

[0135] The confirmation credentials for ad aggregation, membership aggregation, and transaction aggregation all record the federated analysis session number, aggregation group number, training range reference list number, training snapshot number set reference number, review time range, interface coverage status, time availability status, field group version number, base model version number, and confirmation status.

[0136] If all three confirmation credentials reach a confirmed status before the review deadline, and the Federated Analysis Control System has not received the training admission revocation credential and the pre-aggregation withdrawal credential, the corresponding aggregation group will enter an aggregation allowed status. If confirmation credentials are missing, confirmation status is pending review, interface coverage status is pending review, time availability status is pending review, field group versions are inconsistent, or base model versions are inconsistent, the corresponding aggregation group will enter an aggregation pending review status. If the aggregation pending review status has not changed to an aggregation allowed status after the review deadline, the Federated Analysis Control System will add the corresponding aggregation group to the isolation update list.

[0137] The federated analysis control terminal executes model block-level protected aggregations only on aggregation groups that are in an aggregation-allowed state. The federated analysis control terminal inputs the encrypted model update package from the complete aggregation group into the protected aggregation environment corresponding to the current base model version. The protected aggregation environment processes the encrypted parameter update amount only within the protected execution area based on the aggregation certificate version; the session management module, training source verification module, and isolated update list of the federated analysis control terminal do not read the plaintext parameter update amount.

[0138] The protected aggregation environment reads the version numbers of the advertising code block, the member code block, the transaction code block, and the fusion block, respectively, and verifies that the version number of each model block is consistent with the corresponding model block version in the current basic model version, and verifies that the parameter position of the parameter update quantity is consistent with the parameter position of the corresponding model block.

[0139] After verification, the protected aggregation environment applies the update amount of the advertising coding block parameters to the advertising basic coding block, the update amount of the membership coding block parameters to the membership basic coding block, the update amount of the transaction coding block parameters to the transaction basic coding block, and the update amount of the fusion block parameters to the fusion basic block, thereby forming advertising candidate coding blocks, membership candidate coding blocks, transaction candidate coding blocks, and candidate fusion blocks, respectively.

[0140] When the advertising candidate coding block, membership candidate coding block, transaction candidate coding block, and candidate fusion block correspond to the same federated analysis session number, training range reference list number, training admission time, and base model version number, the protected aggregation environment assembles the four candidate model blocks into a candidate model version. The candidate model version records the candidate model number, aggregation group number, base model version number, participating update package number set reference number, training source credential set reference number, aggregation time, candidate model status, and model source validity status.

[0141] The candidate model version is bound to its corresponding aggregation group, training range reference list, training snapshot number set reference number, and training source credential set reference number. The candidate model version does not change the current base model version, which continues to be used in subsequent federated analysis sessions.

[0142] Example 2: Figure 2 A schematic diagram of the structure of a federated learning marketing user privacy analysis system according to the present invention is provided. The federated learning marketing user privacy analysis system includes: The federated analysis control terminal is used to establish federated analysis sessions, read the time base version, observation window version, protected association version, label closure version, interface coverage version, field group version, and base model version, verify the session version, training snapshot, label closure status, interface coverage status, and field group version of the encrypted model update package based on the training source credentials, and review the label status changes and interface coverage changes before aggregation, and perform federated aggregation on encrypted model update packages that have not experienced training admission revocation. The advertising platform is used to form reach anchors based on available ad click events over time, form ad feature snapshots based on the feature review window corresponding to the reach anchors, form session-level protected association tags based on protected associated versions, and verify the ad interface coverage status based on interface heartbeats, message sequences, and field integrity. The member service platform is used to generate member feature snapshots based on the feature review window corresponding to the reach anchor, generate session-level protected association tags based on the protected association version, and verify the member interface coverage status based on interface heartbeat, message sequence and field integrity. The transaction service platform is used to form a snapshot of transaction history features based on the feature review window corresponding to the reach anchor point, form a session-level protected association tag based on the protected association version, verify the tag closure status based on the order status, payment status, refund status and tag closure period, and verify the transaction interface coverage status based on the interface heartbeat, message sequence and field integrity. The advertising platform, membership service platform, and transaction service platform are also used to perform local model training on training snapshots that are available in time, have established protected associations, closed tags, complete interface coverage, and whose field group versions are consistent with the frozen version combination, and whose feature time ranges are all within the feature review window corresponding to the same reach anchor point, thereby generating encrypted model update packages and training source credentials.

[0143] In this embodiment, the Federated Analytics Control Terminal establishes credential communication connections with the advertising platform, membership service platform, and transaction service platform, respectively. After establishing a Federated Analytics session, the Federated Analytics Control Terminal sends Federated Analytics session credentials to the three participating platforms. After the advertising platform forms an anchor point, it sends the anchor point credentials to the Federated Analytics Control Terminal; the Federated Analytics Control Terminal sends anchor point range notifications to the membership service platform and the transaction service platform. The anchor point range notification includes the anchor point number, anchor point time, advertising campaign number, and Federated Analytics session number, but does not include the account-associated base value, ad click content, order identifier, payment identifier, or refund identifier.

[0144] Upon receiving the anchor point range notification, each of the three participating platforms generates a session-level protected association marker locally and submits protected association verification input credentials. The advertising platform generates ad feature source credentials, ad protected association verification input credentials, and ad interface coverage credentials; the membership service platform generates member feature source credentials, member protected association verification input credentials, and member interface coverage credentials; and the transaction service platform generates transaction feature source credentials, transaction protected association verification input credentials, tag closure credentials, and transaction interface coverage credentials. The federated analysis control terminal performs protected association verification based on the protected association verification input credentials submitted by the three participating platforms. After establishing a joint association status, it generates a training range reference list and training access credentials based on each credential.

[0145] The advertising platform generates encrypted intermediate representations for the ads based on the ad training snapshots, and the membership service platform generates encrypted intermediate representations for the members based on the member training snapshots. Both are then sent to the protected training environment of the transaction service platform. The transaction service platform generates transaction intermediates based on the transaction training snapshots and inputs the three intermediate representations into a fusion block within its protected training environment. Based on the tag closure state, it generates encrypted feedback quantities. The encrypted feedback quantities corresponding to the ad encoding block are sent to the advertising platform, and the encrypted feedback quantities corresponding to the member encoding block are sent to the membership service platform.

[0146] The advertising platform, membership service platform, and transaction service platform update their respective model blocks based on local training snapshots and corresponding encrypted feedback volumes, and send encrypted model update packages and training source credentials to the federated analysis control terminal. After pre-aggregation review and approval, the federated analysis control terminal inputs the encrypted model update packages from the three participating platforms into the protected aggregation environment, forms candidate model blocks according to the corresponding model block versions, and generates candidate model versions. When any participating platform sends training admission revocation credentials or pre-aggregation withdrawal credentials, the federated analysis control terminal writes the corresponding aggregation group into the isolated update list.

[0147] The above content is only a specific embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for analyzing user privacy in federated learning marketing, characterized in that, Perform the following steps: S1. The federated analysis control terminal establishes a federated analysis session and reads the time base version, observation window version, protected association version, tag closure version, interface coverage version, field group version, and basic model version. S2. The advertising platform forms reach anchors based on available ad click events within the time frame. The advertising platform, membership service platform, and transaction service platform form local feature snapshots based on the feature review window corresponding to the reach anchors, and verify the protected association markers corresponding to the same reach anchors based on the protected association version. S3. The transaction service platform verifies the tag closure status based on the order status, payment status, refund status, and tag closure period after reaching the anchor point. The advertising platform, membership service platform, and transaction service platform verify the interface coverage status based on the interface heartbeat, message sequence, and field integrity. S4. The advertising platform, membership service platform and transaction service platform perform local model training on training snapshots within the feature review window corresponding to the same feature time range, where the time is available, the protected association is established, the tag is closed, the interface is fully covered, the field group version of the advertising platform, membership service platform and transaction service platform is consistent with the frozen version combination, and the training snapshots are all within the same reach anchor point. S5. The federated analysis control terminal verifies the session version, training snapshot, label closure status, interface coverage status, and field group version of the encrypted model update package based on the training source credentials. Before aggregation, it reviews the label status changes and interface coverage changes. For encrypted model update packages that have not experienced training admission revocation, it performs protected aggregation according to the model block version to form candidate model versions.

2. The method for analyzing user privacy in federated learning marketing according to claim 1, characterized in that, S1 includes: The time base version is determined based on the platform clock deviation records generated by the advertising platform, membership service platform, and transaction service platform. Each platform generates time inspection records at 60-second intervals. The most recent four consecutive time inspection records are valid. The most recent valid inspection record is no more than 90 seconds after the establishment of the federated analysis session, and the clock deviation is no more than 2 seconds. The time is considered available.

3. The method for analyzing user privacy in federated learning marketing according to claim 1, characterized in that, S1 includes: The observation window version sets the ad click event occurrence time as the anchor point time, the 30-day closed interval before the anchor point time to one second before the anchor point time as the feature review window, the 72 hours from the anchor point time as the conversion observation window, the 14 days from the anchor point time as the tag closing window, the 15 minutes after the tag closing window ends as the interface retransmission window, the 10 minutes after the first encrypted model update package enters the federated analysis control terminal as the update package completion window, and the 10 minutes from the time the complete aggregation group is formed as the pre-aggregation review window.

4. The method for analyzing user privacy in federated learning marketing according to claim 1, characterized in that, S2 include: The advertising platform performs event number verification, exposure association verification, advertising element verification, page session verification, and event sequence verification for ad click events; After an ad click event is verified, an anchor number is generated based on the ad campaign number, anchor date number, click event number, and ad event sequence number, and the click time is set as the anchor time.

5. The method for analyzing user privacy in federated learning marketing according to claim 1, characterized in that, S2 include: The advertising platform, membership service platform and transaction service platform respectively form the association availability status based on the account association records that have been effective before the anchor time and remain valid at the anchor time, and form the session-level protected association mark in the local protected environment based on the federated analysis session number, anchor date number, advertising plan number and protected association version number. The advertising platform, membership service platform, and transaction service platform input the session-level protected association marker into the protected association verification process; the protected association verification process outputs the association verification result corresponding to the anchor number; when the association verification results for the three platforms are all in the established state, the federated analysis control terminal forms a joint association established state.

6. The method for analyzing user privacy in federated learning marketing according to claim 1, characterized in that, S3 includes: The transaction service platform verifies the closure status of tags based on the order status sequence, payment status sequence, refund status sequence, and transaction interface coverage status. A positive closed state is formed when the payment success event is within the conversion observation window and meets the following conditions at the end of the label closing window: the order cancellation status is not effective, the order closure status is not effective, the payment revocation status is not effective, the refund success status has not been formed, the refund status is not in process, and the transaction interface coverage status is complete. A negative closed state is formed when no valid payment success event is generated within the conversion observation window, and the order status sequence, payment status sequence, refund status sequence, and transaction interface coverage status are all complete. After a payment success event, if any of the following states are in effect: successful refund, payment cancellation, order cancellation, or order closure, a reverse closed state is formed.

7. A method for analyzing user privacy in federated learning marketing according to claim 1, characterized in that, S3 include: The interface coverage status is formed based on the interface heartbeat status, message sequence status, and field integrity status; the interface forms a complete status when there are four consecutive valid heartbeats, a continuous message sequence, and all required fields are complete. When an interface has pending message transmission, pending message sequence verification, or pending field verification, it forms a pending verification state. When the ad click event interface, page visit completion interface, and ad feature output interface of the advertising platform, the member status interface, member behavior interface, and member feature output interface of the membership service platform, and the order event interface, payment event interface, refund event interface, transaction feature output interface, and tag closure output interface of the transaction service platform all form a complete state, the federated analysis control end forms a joint interface to cover the complete state.

8. A method for analyzing user privacy in federated learning marketing according to claim 1, characterized in that, S4 include: The federal analysis control terminal collects advertising feature source credentials, membership feature source credentials, transaction feature source credentials, tag closure credentials, and interface coverage credentials based on anchor point numbers; When the anchor number, protected association tag reference number and federated analysis session number in each credential are consistent, and the corresponding version referenced by each credential belongs to the frozen version combination of the current federated analysis session, a training range reference list is formed. When the label closure state corresponding to the training range reference list is within the trainable label range consisting of positive and negative closure states, and the joint interface coverage state is in the joint interface full coverage state, the federated analysis control terminal generates training admission credentials, and the training admission credentials are also written with the training admission time. When advertising platforms, membership service platforms, and transaction service platforms detect changes in feature time range, field group version, label closure status, interface coverage status, protected association status, inconsistent training range references, or changes in the basic model version during local review, they generate training admission revocation credentials.

9. A method for analyzing user privacy in federated learning marketing according to claim 1, characterized in that, S5 include: The federal analysis and control terminal collects encrypted model update packages from the advertising platform, membership service platform, and transaction service platform based on the training scope reference list number, basic model version number, and training access time. When the encrypted model update packages for the three platforms have all arrived, and the federated analysis session number, training range reference list number, base model version number, and training admission time are consistent, a complete aggregation group is formed. During the pre-aggregation review, when the federated analysis control receives the training admission revocation credential, it writes the complete aggregation group into the isolation update list; When the federated analysis control receives a pre-aggregation revocation credential sent by any participating platform during the pre-aggregation review, it will write the complete aggregation group corresponding to the training range reference list number in the pre-aggregation revocation credential into the isolation update list. In the complete aggregation group not written into the isolation update list, each encrypted model update package forms a candidate model block according to the corresponding model block version, and forms a candidate model version according to the base model version number and the training range reference list number.

10. A federated learning marketing user privacy analysis system, used to implement the federated learning marketing user privacy analysis method according to any one of claims 1-9, characterized in that, include: The federated analysis control terminal is used to establish federated analysis sessions, read the time base version, observation window version, protected association version, label closure version, interface coverage version, field group version, and base model version, verify the session version, training snapshot, label closure status, interface coverage status, and field group version of the encrypted model update package based on the training source credentials, and review the label status changes and interface coverage changes before aggregation, and perform federated aggregation on encrypted model update packages that have not experienced training admission revocation. The advertising platform is used to form reach anchors based on available ad click events over time, form ad feature snapshots based on the feature review window corresponding to the reach anchors, form session-level protected association tags based on protected associated versions, and verify the ad interface coverage status based on interface heartbeats, message sequences, and field integrity. The member service platform is used to generate member feature snapshots based on the feature review window corresponding to the reach anchor, generate session-level protected association tags based on the protected association version, and verify the member interface coverage status based on interface heartbeat, message sequence and field integrity. The transaction service platform is used to form a snapshot of transaction history features based on the feature review window corresponding to the reach anchor point, form a session-level protected association tag based on the protected association version, verify the tag closure status based on the order status, payment status, refund status and tag closure period, and verify the transaction interface coverage status based on the interface heartbeat, message sequence and field integrity. The advertising platform, membership service platform, and transaction service platform are also used to perform local model training on training snapshots that are available in time, have established protected associations, closed tags, complete interface coverage, and whose field group versions are consistent with the frozen version combination, and whose feature time ranges are all within the feature review window corresponding to the same reach anchor point, thereby generating encrypted model update packages and training source credentials.