Ai learning system
The AI learning system addresses legal compliance issues by anonymizing and encrypting personal information, allowing secure and efficient AI learning with reduced computational processing.
Patent Information
- Application Number
- JP2023215135
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-20
- Publication Date
- 2025-07-02
- Estimated Expiration
- 2043-12-20
AI Technical Summary
Existing AI learning systems face difficulties in performing AI learning using personal information while complying with legal requirements such as the Personal Information Protection Law and GDPR, leading to limited AI utilization of personal data.
An AI learning system that includes a selection unit for anonymizing personal information, an encryption unit for encrypting the selected information, and an AI learning unit for secure computation on encrypted data, with the selection unit setting criteria to minimize computational processing based on the degree of encryption and anonymization needed.
Enables AI learning with personal information while adhering to legal requirements, reducing computational load and preventing personal information leakage, thus facilitating secure and efficient AI utilization.
Smart Images

Figure 2025098774000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of an AI learning system that performs AI learning based on AI learning data related to personal information while anonymizing the personal information.
Background Art
[0002] As such an AI learning system, in addition to traditional AI learning systems for automatic driving such as the so-called supervised learning method, unsupervised learning method, or reinforcement learning method, recently, systems for various applications such as generative AI have been developed and already put into practical use (see Patent Document 1). AI learning data used in such systems may include personal information depending on the field, and under the Personal Information Protection Law or GDPR (General Data Protection Regulation: General Data Protection Regulation in the EU), personal information needs to be encrypted or anonymized so that an individual cannot be easily identified.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, according to the above-described background art, although it is possible to improve the resource-driven efficiency of maintaining the blockchain network, it is difficult to perform AI learning while complying with the requirements of the Personal Information Protection Law and GDPR based on AI learning data including personal information in a state where the personal information is anonymized or concealed. For this reason, the AI utilization of personal information has not progressed much.
[0005] An object of the present invention is to provide an AI learning system that enables AI learning using AI learning data including personal information while complying with legal requirements related to personal information.
Means for Solving the Problems
[0006] One aspect of the AI learning system according to the present invention includes a selection unit that selects personal information to be anonymized when creating a desired AI model from the AI learning data according to a predetermined standard, an encryption unit that encrypts the selected personal information, a holding unit that holds the AI learning data in which the encrypted personal information is included in a blockchain, and an AI learning unit that learns the AI model by performing secret calculation on at least a data portion related to the encrypted personal information. The selection unit sets the predetermined standard so that the calculation processing amount is reduced according to the degree of increase or decrease in the calculation processing amount of the secret calculation by encrypting the personal information and the degree to which the personal information should be anonymized.
Effects of the Invention
[0007] According to one aspect of the AI learning system according to the present invention, AI learning using AI learning data including personal information is possible while complying with legal requirements such as GDPR related to personal information.
[0008] Such an operational effect of the present invention will be made clearer by the embodiments of the invention described below.
Brief Description of the Drawings
[0009]
Figure 1
Figure 2
Figure 3
Figure 4
Mode for Carrying Out the Invention
[0010] First, with reference to FIG. 1, the overall configuration of the AI learning system according to the embodiment will be described. This embodiment is constructed as a system that performs AI analysis based on AI learning data including personal information related to, for example, elderly drivers, disabled persons, patients, etc. Specifically, for example, it is constructed as a system that provides customized analysis results for those individuals, which are useful for decisions such as employment approval in their companies, selection of employment destinations, assignment destinations, working hours, determination of treatment and benefits, and determination of automobile accident insurance premiums. More generally, this embodiment is applicable to AI learning that needs to be carried out in accordance with legal requirements such as the Personal Information Protection Law and GDPR, and in any case, it is possible to enhance the protection of personal information.
[0011] As shown in FIG. 1, the AI learning system 10 is constructed as a system that performs centralized processing or distributed processing to input or provide "AI learning data" from a data provider (not shown) accommodated in the network and output or provide an "AI model" obtained as a result of AI learning or AI analysis to a model provider (not shown) accommodated in the network.
[0012] Note that the provider (not shown) is various computer-mounted devices and various computer devices that perform centralized processing or distributed processing, and the AI learning data input or collected there is provided to the AI learning system 10 via the network in its original form or in a data format subjected to a predetermined type of processing. The provider (not shown) is various computer-mounted devices and various computer devices that perform centralized processing or distributed processing, and the AI model output or provided thereto is configured to be used in various operations such as employment operations, personnel operations, and insurance operations.
[0013] As AI learning data related to such personal information, it includes general personal information to special personal information, such as an individual's age, gender, date of birth, height and weight, blood type, various vital data, pre-existing medical history of the individual and their relatives, family composition, educational background, work history, job experience, skills, awards, arrest record, address, place of origin, place of registered permanent residence, asset status, identification photo, driver's license number, My Number, etc., on the premise of obtaining the consent of the individual. In any case, the effects of the present embodiment described below will be correspondingly achieved. Such personal information may be in a predetermined format, texturized or coded, or handwritten or by mark sheet, or even imaged or videoed, as long as it can be analyzed by existing or future-developed AI.
[0014] The AI learning system 10 includes a memory, a processor, etc., and is configured as a centralized system that performs centralized processing or a distributed system that performs distributed processing, and includes a selection unit 12, an encryption unit 13, a holding unit 14, and an AI learning unit 15.
[0015] The selection unit 12 is configured to select personal information data Dp to be anonymized when creating a desired AI model (for example, an AI model for personnel evaluation, etc.) from the AI learning data according to a predetermined criterion. Specifically, the selection unit 12 sets a predetermined criterion so that the amount of computational processing decreases according to the degree of increase or decrease in the amount of computational processing of the secret calculation by encrypting the personal information and the degree to which the personal information should be anonymized.
[0016] At this time, the setting of the predetermined criterion by the criterion setting unit 12a may be set, for example, by manual input by an operator or input of a function determined empirically in advance (that is, input of a function that takes the degree of increase or decrease in the amount of computational processing of the secret calculation and the degree to which the personal information should be anonymized as inputs and outputs the amount of computational processing), or by referring to a map that defines the three-party relationship of the degree of increase or decrease in the amount of computational processing of the secret calculation, the degree to which the personal information should be anonymized, and the amount of computational processing, or may be set by AI learning.
[0017] When setting by AI learning, for example, first, an operator inputs one or more hyperparameters related to the computational workload of secure computation and the confidentiality of personal information for setting the predetermined criteria, and the AI is configured to tune the previously set hyperparameters, that is, adjust the types and combinations of parameters, during the learning process. In particular, the computational workload of secure computation increases or decreases complexly according to the specific method and content of the computation. On the other hand, the degree to which personal information should be anonymized also changes complexly, such as depending on the combination of individual elements that make up the personal information and whether an individual can be identified. Furthermore, the allowable range that each individual may use for AI analysis may also vary among individuals. Therefore, it is effective to perform hyperparameter tuning by AI learning rather than simply inputting a function input or hyperparameters with the computational workload as the output.
[0018] The AI learning in such a criteria setting unit 12a may be configured to perform AI learning such as supervised learning, unsupervised learning, semi-supervised learning, reinforcement learning, generative AI, etc., and update the set criteria. Alternatively, the criteria setting unit 12a that performs AI learning may be configured using a neural network that performs efficient AI learning through representation learning, transfer learning, feature selection, fine-tuning or hyperparameter tuning, ensemble learning, etc., or may be configured as a generative AI that generates reference data.
[0019] The encryption unit 13 is configured to encrypt the personal information data Dp selected by the selection unit 12 (in other words, the personal information data to be encrypted) using various existing or future-developed encryption technologies (for example, secure computation such as homomorphic encryption method, secret sharing method, etc.), and output it as the encrypted personal information data Dpe.
[0020] The holding unit 14 includes the memories of a plurality of computers housed in the network, and is configured using existing or future-upgraded blockchain technology. The holding unit 14 holds, sequentially or at appropriate timings, AI learning data including encrypted personal information data Dpe, that is, two types of data: encrypted personal information data Dpe and unencrypted personal information data Dn (i.e., data that may be treated as "non-personal information data") in the blockchain.
[0021] The AI learning unit 15 is configured to learn an AI model by performing secret calculations on at least the data portion related to the encrypted personal information Dpe from the AI learning data (i.e., encrypted personal information data Dpe and unencrypted personal information data Dn) held in the blockchain by the holding unit 14, using its secret calculation unit 15a.
[0022] Such an AI learning unit 15 may be configured to perform AI learning such as supervised learning, unsupervised learning, semi-supervised learning, reinforcement learning, generative AI, etc., and sequentially or collectively provide the learned AI model to a destination via the network. The AI learning unit 15 may be configured using a neural neural network that performs efficient AI learning through representation learning, transfer learning, feature selection, fine-tuning or hyperparameter tuning, ensemble learning, etc., or may be configured as a generative AI that learns the patterns and relationships of the AI learning data and generates content data different from the AI learning data. In any case, since the criterion setting by the criterion setting unit 12a is performed in the selection unit 12, the amount of computational processing in the secret calculation unit 15a can be reduced compared to the case where such criterion setting is not performed. Here, the secret calculation is performed as secret calculation such as fully homomorphic encryption or homomorphic encryption method, secret sharing method, etc. In particular, when the criterion setting unit 12a in the selection unit 12 sets the criterion by AI learning, the amount of computational processing for secret calculation decreases as the learning progresses, which is practically advantageous.
[0023] Next, in addition to the block diagram of FIG. 1, an example of the processing in the AI learning system according to the present embodiment will be described with reference to the flowcharts of FIGS. 2, 3, and 4.
[0024] In FIG. 2, first, in the AI learning system 10 (see FIG. 1), AI learning data related to personal information in a texturized or coded form in a predetermined format is input from a data provider accommodated in the network (step S11). Such AI learning data may include image data or video data.
[0025] Next, in the selection unit 12 (see FIG. 1), personal information data Dp to be anonymized in creating a desired AI model is selected from the AI learning data according to a predetermined criterion (step S12). Here, in particular, the predetermined criterion is set so that the amount of calculation processing is reduced according to the degree of increase or decrease in the amount of calculation processing of the secret calculation by encrypting personal information and the degree to which personal information should be anonymized. The setting of such a criterion is preferably set by AI learning as described later (see FIGS. 3 and 4).
[0026] Next, in the encryption unit 13 (see FIG. 1), the selected personal information data Dp to be encrypted is encrypted by various encryption techniques and output as encrypted personal information data Dpe (step S13).
[0027] Next, in the holding unit 14 (see FIG. 1), the AI learning data including the encrypted personal information data Dpe and the non-encrypted personal information data Dn is held in the blockchain (step S14).
[0028] Next, in the AI learning unit 15 (see FIG. 1), the AI learning data held in the blockchain is used to train the AI model (step S15) by performing secret calculations on at least the data portion related to the encrypted personal information Dpe using the secret calculation unit 15a (see FIG. 1). The secret calculation here may employ a secret calculation method using fully homomorphic encryption or somewhat homomorphic encryption that performs operations while keeping the encrypted personal information data Dpe encrypted, or alternatively, a secret calculation method using a secret sharing method that divides the encrypted personal information data Dpe into several meaningless random number fragments (shares) for concealment. Further, the processing by such an AI learning unit 15 is preferably executed by AI learning as described later (see FIGS. 3 and 4).
[0029] Next, the predicted or created AI model is output to the destination (step S16), and a series of processes ends.
[0030] The above sorting process (step S12) and AI learning (step S15) are each executed by, for example, traditional AI learning that is not generative AI as shown in an example in FIG. 3, or AI learning using generative AI as shown in another example in FIG. 4.
[0031] That is, as shown in FIG. 3, in an example of the sorting process (step S12), various types of AI learning data related to personal information are input (step S17), storage (step S18) and knowledge conversion (step S19) of these data are executed, an AI model that is an appropriate answer is predicted (step S20), and existing content is output. Here, in particular, a predetermined standard is predicted as an AI model so that the amount of calculation processing is reduced according to the degree of increase or decrease in the amount of calculation processing of secure calculation by encrypting personal information and the degree to which personal information should be anonymized. In this case, for example, the target of encryption is selected so that a combination of personal information that can identify an individual does not occur, or personal information that can be permitted without encryption from the perspective of the AI learning system 10 is input as teacher data, and encryption that causes an extremely large amount of calculation processing for secure calculation is avoided as much as possible. Conversely, the rule-making when setting a predetermined standard may be performed, such as preferentially permitting encryption that leads to a reduction in the amount of calculation processing for secure calculation.
[0032] On the other hand, as shown in FIG. 3, in an example of AI learning (step S15), encrypted personal information data Dpe and unencrypted personal information data Dn are input as AI learning data (step S17), storage (step S18) and knowledge conversion (step S19) of these data are executed, an AI model that is an appropriate answer is predicted (step S20), and the output of existing content is executed in step S16 of FIG. 2. The calculations related to the storage, knowledge conversion, and prediction of the AI model of the data in steps S18 to S20 are processed by secure calculation while encrypted for the encrypted personal information data Dpe.
[0033] Alternatively, as shown in FIG. 4, in another example of the sorting process (step S12), various types of AI learning data related to personal information are input (step S17), the storage of these data (step S18), as well as the learning of oneself through knowledgeization and deep learning (step S29) are executed, an AI model that is an appropriate answer is created (step S30), and output of original content that is not existing content is performed. Here, in particular, a predetermined criterion is created as an AI model so that the amount of computational processing is reduced according to the degree of increase or decrease in the amount of computational processing of secure computation by encrypting personal information and the degree to which personal information should be anonymized. For example, deep learning related to avoiding combinations of personal information that can identify an individual or preferentially allowing encryption that leads to a reduction in the amount of computational processing of secure computation may be performed.
[0034] On the other hand, as shown in FIG. 4, in another example of AI learning (step S15), the encrypted personal information data Dpe and the unencrypted personal information data Dn are input as AI learning data (step S17), the storage of these data (step S18), as well as the learning of oneself through knowledgeization and deep learning (step S29) are executed, an AI model that is an appropriate answer is created (step S30), and output of original content that is not existing content is executed in step S16 of FIG. 2. The calculations related to the storage, knowledgeization, deep learning, and creation of the AI model in these steps S18 to S30 are processed by secure computation while encrypted for the encrypted personal information data Dpe.
[0035] As described in detail above, personal information to be anonymized among the AI learning data is selected and encrypted, the data retention is executed using blockchain technology, and AI learning is executed using secret computing technology. Therefore, even for personal information data in an environment where it is difficult to inherently maintain confidentiality because it is retained for a relatively long period of time, it is prevented that staff members of a corporation or the like using the AI learning system 10 view the personal information data Dpe or the AI model as information that can identify an individual related to the personal information. Furthermore, it becomes extremely difficult to view it in a form of information that can identify an individual related to the personal information. As a result, it is possible to effectively prevent the leakage of personal information to a third party, and at the same time, it is possible to provide value customized by AI learning using the personal information mainly to the owner of the personal information.
[0036] Supplementary Note Regarding the embodiments described above, the following additional notes are further disclosed.
[0037] [Supplementary Note 1] The AI learning system according to Supplementary Note 1 of the present invention includes a selection unit that selects personal information to be anonymized among the AI learning data according to a predetermined standard when creating a desired AI model, an encryption unit that encrypts the selected personal information, a holding unit that holds the AI learning data in which the encrypted personal information is included in a blockchain, and an AI learning unit that learns the AI model by performing secret computing on at least a data portion related to the encrypted personal information. The selection unit sets the predetermined standard so that the amount of computational processing decreases according to the degree of increase or decrease in the amount of computational processing of the secret computing by encrypting the personal information and the degree to which the personal information should be anonymized.
[0038] According to the AI learning system described in Supplementary Note 1, personal information to be anonymized among the AI learning data is selected and encrypted. Further, the AI learning data in a state including the encrypted personal information is held in a blockchain. The AI model is learned by performing secure computation on at least the data portion related to the encrypted personal information of the thus-held AI learning data. The above selection is performed by setting a predetermined criterion so that the amount of computation decreases according to the degree of increase or decrease in the amount of computation processing of the secure computation by encrypting the personal information and the degree to which the personal information should be anonymized. By these means, while effectively preventing the leakage of personal information to a third party, it becomes possible to provide a value customized by AI learning using the personal information mainly to the owner of the personal information.
[0039] [Supplementary Note 2] The AI learning system described in Supplementary Note 2 according to the present invention is the AI learning system according to Supplementary Note 1, wherein the selection unit sets the predetermined criterion and selects the personal information by AI learning using the AI learning data of the degree of increase or decrease in the amount of computation processing and the degree to which the personal information should be anonymized.
[0040] According to the AI learning system described in Supplementary Note 2 according to the present invention, in the selection unit, a predetermined criterion as described above is set by AI learning. Therefore, as the AI learning in the selection unit progresses, the number of samples or the scale of learning of the AI learning data related to the amount of computation processing in the secure computation and the AI learning data related to the confidentiality of the personal information increases, and it becomes possible to set a more appropriate predetermined criterion. This is very advantageous for reducing the amount of computation processing while ensuring confidentiality.
[0041] The present invention can be appropriately modified within a range not contrary to the gist or idea of the invention that can be read from the claims and the entire specification, and an AI learning system involving such a modification is also included in the technical idea of the present invention.
Explanation of Reference Numerals
[0042] AI learning system... 10 Selection unit... 12 Encryption unit... 13 Retention unit... 14 AI learning unit... 15
Claims
1. Among the data for AI learning, a screening unit that screens personal information to be anonymized when creating a desired AI model according to a predetermined standard, An encryption unit that encrypts the screened personal information, A holding unit that holds the AI learning data in which the encrypted personal information is included in a blockchain, An AI learning unit that learns the AI model by performing secure computation on at least the data portion related to the encrypted personal information of the held AI learning data And comprising, The screening unit sets the predetermined standard so that the amount of computation is reduced according to the degree of increase or decrease in the amount of computation processing of the secure computation by encrypting the personal information and the degree of anonymization of the personal information. An AI learning system characterized by
2. The screening unit sets the predetermined standard by AI learning using the degree of increase or decrease in the amount of computation processing and the degree of anonymization of the personal information as data for AI learning, and screens the personal information. The AI learning system according to claim 1.
Citation Information
Patent Citations
Machine learning system and machine learning method
JP2023105909A
Method and apparatus for deidentifying driver image dataset
US20230058530A1
Autonomous vehicle environmental perception software management
WO2023141702A1
Dispersion type machine learning system
JP2019212248A