Risk control method and system based on differential privacy, electronic device, and storage medium
By adopting differential privacy-based methods in risk control technology, obfuscation values and accompanying probability are generated, obfuscation quotas are calculated and compared, the problem of difficulty in taking into account the accuracy of risk control services and user data privacy protection in the existing technology is solved, and efficient risk control data privacy protection is achieved.
Patent Information
- Application Number
- PCT/CN2024/127761
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-05
- Filing Date
- 2024-10-28
- Publication Date
- 2025-06-12
AI Technical Summary
It is difficult for existing risk control technologies to effectively protect users' risk control data privacy while providing accurate risk control services. Especially under the differential privacy protection mechanism, how to balance market demands and user data privacy protection needs is a challenge.
A risk control method based on differential privacy is used to generate obfuscation values and accompanying probability, based on the user's credit limit and query request, the obfuscation limit is calculated, and compared with the credit limit to be granted to generate a response. This method further ensures the security of user data through privacy budget supervision and the mixing of obfuscation values for multiple application scenarios.
It realizes that while providing risk control services, it effectively protects the privacy of user risk control data, complies with the differential privacy protection mechanism, takes into account market demand and user data privacy protection needs, and enhances the security of user data.
Smart Images

Figure CN2024127761_12062025_PF_FP_ABST
Abstract
Description
Risk control method, system, electronic device and storage medium based on differential privacy Technical Field
[0001] One or more embodiments of this specification relate to the field of risk control technology, and specifically to risk control methods, systems, electronic devices, and storage media based on differential privacy. Background Art
[0002] Differential privacy is a cryptographic technique designed to maximize the accuracy of data queries while minimizing the chance of identifying records when querying a database. The results of differential privacy scrambling require a trade-off between statistical accuracy and privacy protection. When the accuracy after scrambling is low, privacy protection is good, but data availability is poor. Conversely, when the accuracy after scrambling is high, privacy protection is poor, but data availability is high. Risk control refers to the process by which financial institutions, after identifying, assessing, and monitoring risks, take measures to reduce or avoid the occurrence of risk events, in order to maintain the stability of institutional assets and compensate for losses.
[0003] Summary of the Invention
[0004] The embodiments of this specification provide a risk control method based on differential privacy, which is executed by a risk control data provider, including: generating or receiving a risk control strategy, and obtaining a user's credit limit based on the risk control strategy; receiving a query request from a risk control data demander, wherein the query request includes a user identifier and a desired credit limit; generating an obfuscation value and an accompanying probability, and obtaining the obfuscated credit limit of the corresponding user based on the query request, the credit limit, the obfuscation value, and the accompanying probability; comparing the obfuscated credit limit with the desired credit limit, and generating a response to the query request based on the comparison result.
[0005] The embodiments of this specification provide a risk control method based on differential privacy, which is executed by a risk control data provider, including: generating or receiving a risk control strategy, and obtaining a user's credit limit based on the risk control strategy; receiving a query request from a risk control data demander, wherein the query request includes a user identifier; generating an obfuscation value and an accompanying probability, and generating an obfuscated credit limit corresponding to the user's credit limit based on the obfuscation value and the accompanying probability; and generating a response to the query request based on the obfuscated credit limit.
[0006] An embodiment of this specification provides a risk control system based on differential privacy, including: a policy component for generating or receiving a risk control policy, and obtaining a user's credit limit based on the risk control policy; a query receiving component for receiving a query request from a risk control data demander, wherein the query request includes a user identifier and a desired credit limit; a privacy protection component for generating an obfuscation value and an accompanying probability, and obtaining the obfuscated credit limit of the corresponding user based on the query request, credit limit, obfuscation value, and accompanying probability; and a response component for comparing the obfuscated credit limit with the desired credit limit, and generating a response to the query request based on the comparison result.
[0007] An embodiment of this specification provides an electronic device, including a processor and a memory; the processor is connected to the memory; the memory is used to store executable program code; the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to execute the method described in any of the above aspects.
[0008] An embodiment of this specification provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the method described in one or more embodiments of this specification is implemented.
[0009] The technical solutions provided in some embodiments of this specification provide at least the following beneficial effects: In one or more embodiments of this specification, the risk control methods provided can provide risk control services while ensuring the privacy of user risk control data, comply with differential privacy protection mechanisms, and take into account both market demand and the privacy protection needs of user risk control data. The security of user risk control data is further guaranteed through privacy budget monitoring and corresponding processing. Based on an improved obfuscation value mixing scheme, an obfuscation value mixing solution suitable for various application scenarios is provided.
[0010] Other features and advantages of one or more embodiments of this specification will be further disclosed in the following detailed description and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] In order to more clearly illustrate the technical solutions in the embodiments of this specification, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0012] FIG1 is a schematic diagram of an application scenario of an embodiment of this specification.
[0013] FIG2 is a schematic diagram of another application scenario of the embodiment of this specification.
[0014] FIG3 is a flow chart of the risk control method according to an embodiment of the present specification.
[0015] FIG4 is a flow chart of a method for obtaining privacy budget monitoring results according to an embodiment of this specification.
[0016] FIG5 is a schematic diagram of confusion values and accompanying probabilities according to an embodiment of this specification.
[0017] FIG6A is a schematic diagram of generating an obfuscated credit limit according to an embodiment of this specification.
[0018] FIG6B is another schematic diagram of generating an obfuscated credit limit according to an embodiment of this specification.
[0019] FIG6C is another schematic diagram of generating an obfuscated credit limit according to an embodiment of this specification.
[0020] FIG6D is another schematic diagram of generating an obfuscated credit limit according to an embodiment of this specification.
[0021] FIG7 is a schematic diagram of another application scenario of the embodiment of this specification.
[0022] FIG8 is a flow chart of another risk control method according to an embodiment of this specification.
[0023] FIG9 is a schematic diagram of a wind control system according to an embodiment of the present specification.
[0024] FIG10A is a schematic diagram of a privacy protection component according to an embodiment of the present specification.
[0025] FIG10B is a schematic diagram of another privacy protection component according to an embodiment of this specification.
[0026] FIG10C is a schematic diagram of another privacy protection component according to an embodiment of this specification.
[0027] FIG10D is a schematic diagram of another privacy protection component according to an embodiment of this specification.
[0028] FIG11 is a schematic diagram of an electronic device provided in an embodiment of this specification.
[0029] Among them: 11. Obfuscation value, 12. Incidental probability, 21. Risk control data demander, 22. Query request, 23. Comparison result, 31. Risk control strategy, 32. Credit limit, 33. User, 34. User identification, 41. Obfuscation limit, 42. Response, 51. Privacy budget supervision result, 61. Policy component, 62. Query receiving component, 63. Privacy protection component, 64. Response component, 65. Supervision component, 631. Obfuscation value unit, 632. Persistence unit, 633. Obfuscation unit, 634. Query response unit, 635. Selection unit, 636. Query unit, 1100. Electronic device, 1101. Processor, 1102. Communication bus, 1103. User interface, 1104. Network interface, 1105. Memory. DETAILED DESCRIPTION
[0030] The following is an explanation and description of the technical solutions of the embodiments of this specification in conjunction with the drawings of the embodiments of this specification. However, the following embodiments are only preferred embodiments of this specification and are not exhaustive. Based on the embodiments in the implementation mode, other embodiments obtained by those skilled in the art without making any creative work are all within the scope of protection of this specification.
[0031] Throughout this specification, the claims, and the accompanying drawings, the terms "first," "second," "third," and the like are used to distinguish between different items, not to describe a particular order. Furthermore, the terms "including," "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or elements is not limited to the listed steps or elements but may optionally include steps or elements not listed, or may include other steps or elements inherent to the process, method, product, or apparatus.
[0032] In the following description, terms such as "inside", "outside", "up", "down", "left", "right", etc. that indicate directions or positional relationships are only used to facilitate the description of the embodiments and simplify the description. They do not indicate or imply that the devices or elements referred to must have a specific direction, be constructed and operate in a specific direction. Therefore, they should not be understood as limitations on this specification.
[0033] Before introducing the technical solutions of the embodiments of this specification, the application scenarios of one or more embodiments of this specification are introduced.
[0034] Glossary:
[0035] Risk Control Strategy
[0036] The risk control strategy 31 referred to in this specification involves a specific algorithm or rule for obtaining the credit limit 32 of user 33 based on the relevant data of user 33. The relevant data of user 33 involves the data of user 33 used to evaluate and obtain the credit limit 32 of user 33. Which data of user 33 is adopted to evaluate and obtain the credit limit 32 of user 33, as well as the method and approach for obtaining these data, can be determined by using the disclosed technology. This specification does not make any improvements to this and will not discuss it. It is worth noting that the data of user 33 involved in this application are all information and data authorized by user 33 or fully authorized by all parties, and the collection of relevant data complies with the relevant laws, regulations and standards of relevant countries and regions.
[0037] credit limit
[0038] The credit line 32 referred to in this specification refers to the credit line 32 that can be granted to user 33, obtained through risk control strategy 31 and based on the relevant data of user 33. If user 33's credit line 32 is greater than or equal to the credit line that risk control data demander 21 intends to grant to user 33, i.e., the intended credit line, risk control data demander 21 can ultimately grant user 33 the intended credit line, thereby achieving a certain degree of risk management effectiveness. If user 33's credit line 32 is less than the credit line that risk control data demander 21 intends to grant to user 33, risk control data demander 21 should refrain from ultimately granting user 33 the intended credit line, to avoid exposing assets to a higher risk of impairment.
[0039] User ID
[0040] The user identification 34 referred to in this specification refers to information that can identify the user 33. Examples include the unique ID of the user 33, the name of the user 33, and the login name of the user 33. One or more embodiments disclosed in this specification can also be implemented using information for identifying the user 33 that has been disclosed in the art.
[0041] Persistent Storage
[0042] The persistent storage referred to in this specification involves storing data in a persistent state. Exemplarily, persisting transient data (such as data in memory, which cannot be permanently saved) into persistent data (such as persisting it to a database, which can be saved for a long time) is a functional application of persistent storage. This specification involves storing data generated by the method provided in one or more embodiments of this specification in a persistent manner. Exemplarily, the relevant data is stored in a local database, a remote database, a server, a local file, etc.
[0043] Amount of confusion
[0044] The confusion amount referred to in this specification represents the modulus of the confusion value, that is, the distance between the confusion value and 0 on the number axis, which can be mathematically expressed as confusion amount = |confusion value|.
[0045] Application Scenario Introduction
[0046] One or more embodiments provided in this specification are applied to a scenario in which a risk control data provider provides risk control services to one or more risk control data demanders 21. Referring to FIG1 , the risk control data provider obtains a credit limit 32 of a user 33 based on relevant data and a risk control strategy 31. To ensure differential privacy protection for the credit limit 32 of user 33, the risk control data provider generates an obfuscation value 11 and an accompanying probability 12. The obfuscation value 11 introduces noise into the credit limit 32, thereby protecting the original value of the credit limit 32. Based on the accompanying probability 12, the noise is made to conform to a predetermined distribution pattern, thereby ensuring that the obfuscated credit limit 32, obfuscated by the obfuscation value 11, still has a certain degree of usability.
[0047] The risk control data provider receives a query request 22 from a risk control data demander 21. After comparing the obfuscated credit limit 41 with the information contained in the query request 22, the risk control data provider obtains a comparison result 23. Based on the comparison result 23, the provider generates a response 42 to the query request 22. For example, the query request 22 includes a user identifier 34 and a desired credit limit. If the obfuscated credit limit 41 found is greater than or equal to the desired credit limit, the response 42 to the query request 22 is positive. If the obfuscated credit limit 41 found is less than the desired credit limit, the response 42 to the query request 22 is negative.
[0048] Another application scenario introduction
[0049] One or more embodiments provided in this specification are applicable to scenarios where a risk control data provider provides risk control services to one or more risk control data demanders 21. Referring to FIG. 2 , the risk control data provider, while receiving and responding 42 to query requests 22 sent by risk control data demanders 21, records and counts the query requests 22. Based on the preset privacy budget and the counted query requests 22, a privacy budget monitoring result 51 is obtained. When the privacy budget monitoring result 51 indicates no privacy budget, a negative response 42 is generated to the query request 22.
[0050] First, this specification provides a risk control method based on differential privacy, which is performed by a risk control data provider. Please refer to Figure 3, which includes steps 102 to 108.
[0051] Step 102 : Generate or receive a risk control strategy 31 , and obtain the credit limit 32 of the user 33 based on the risk control strategy 31 .
[0052] Step 104: Receive a query request 22 from a risk control data demander 21, wherein the query request 22 includes a user identifier 34 and a desired credit limit.
[0053] Step 106 , generating an obfuscation value 11 and an accompanying probability 12 , and obtaining an obfuscation credit 41 corresponding to the user 33 based on the query request 22 , the credit limit 32 , the obfuscation value 11 and the accompanying probability 12 .
[0054] Step 108 : Compare the obfuscated credit limit 41 with the credit limit to be granted, and generate a response 42 to the query request 22 based on the comparison result 23 .
[0055] As an example, risk control strategy 31 determines a credit limit 32 for user 33 based on their historical average annual spending. User 33A's historical average annual spending is 300,000 yuan, while user 33B's historical average annual spending is 50,000 yuan. Accordingly, based on risk control strategy 31, the risk control data provider grants user 33A a credit limit 32 of 1 million yuan and user 33B a credit limit 32 of 200,000 yuan. A risk control data requester 21 is processing a credit grant for user 33A and wants to know whether they can grant user 33A an 800,000 yuan credit line for a specific credit product. However, risk control data requester 21 does not have any relevant information about user 33A, nor does it have any credit limit data for user 33A. Therefore, risk control data requester 21 sends user 33A's user ID 34 and the desired credit limit of 800,000 yuan as a query request 22 to the risk control data provider. The risk control data provider generates an obfuscation value 11 and an accompanying probability 12, and then generates an obfuscated credit limit 41 for user 33. For example, if the obfuscated credit limit 41 generated by the risk control data provider for user 33A is 930,000 yuan, after comparison, a positive message is sent to the risk control data requester 21. Consequently, risk control data requester 21 grants user 33A a credit limit of 800,000 yuan for a certain credit product. It should be noted that the obfuscated credit limit 41 generated by the risk control data provider is different each time. For example, another risk control data requester 21 sends the user ID 33A and the desired credit limit of 800,000 yuan as a query request 22 to the risk control data provider. If the obfuscated credit limit 41 generated by the risk control data provider for user 33A is 700,000 yuan, after comparison, a negative message is sent to the risk control data requester 21. Although this results in a loss of a transaction opportunity for risk control data requester 21, the information of user 33A is effectively protected. Furthermore, the probability of generating an obfuscated credit limit 41 of 700,000 yuan for user 33A is relatively low. Therefore, the overall percentage of affected transactions is manageable. As another example, risk control data requester 21 sends a query request 22 to a risk control data provider, including the user ID 34 of user 33B and a desired credit limit of 250,000 yuan. The risk control data provider generates an obfuscated credit limit 41 of 300,000 yuan for user 33B. After comparison, the provider sends a confirmation message to risk control data requester 21. While risk control data requester 21 faces a relatively greater risk by completing this transaction, the probability of generating an obfuscated credit limit 41 of 300,000 yuan for user 33B is sufficiently low to ensure that the transaction's risks remain manageable.
[0056] On the other hand, in another embodiment, when generating a response 42 to the query request 22, the response 42 to the query request 22 is generated based on the comparison result 23 and the privacy budget supervision result 51; the method for obtaining the privacy budget supervision result 51 includes: reading the historical query request 22 corresponding to the user 33; and obtaining the privacy budget supervision result 51 based on the configured privacy budget and the historical query request 22.
[0057] The privacy budget refers to the total number of query requests 22 allowed for user 33. For example, if the privacy budget is set to 10 for user 33A, when the number of query requests 22 corresponding to user 33A reaches 8, a normal response 42 will be fed back. When the number of query requests 22 corresponding to user 33A reaches 10, a response 42 indicating no query results will be fed back for the 11th query.
[0058] On the other hand, in another embodiment, please refer to FIG. 4 , a method for obtaining a privacy budget monitoring result 51 based on a configured privacy budget and the historical query request 22 includes steps 202 to 208 .
[0059] Step 202 : Based on the configured inspection period and the historical query requests 22 , a statistical number of query requests 22 within the inspection period is obtained, which is recorded as the short-term query number.
[0060] Step 204 : Obtain the total number of queries of the corresponding user 33 based on the historical query request 22 .
[0061] Step 206 : When the number of short-term queries reaches a preset first threshold, the privacy budget monitoring result 51 is set to no privacy budget within a preset time period after the last query request 22 .
[0062] Step 208: When the total number of queries reaches a preset second threshold, the obfuscation value 11 and the incidental probability 12 are regenerated, and the obfuscation credit 41 of the corresponding user 33 is obtained based on the query request 22, the credit limit 32, the obfuscation value 11 and the incidental probability 12, and the total number of queries is reset.
[0063] In this embodiment, two privacy budgets are set: the number of short-term queries and the total number of queries. User 33 protects the data security of user 33. For example, the first threshold set for user 33A is 5 times, the second threshold is 20 times, and the observation period is 1 day. When the number of query requests 22 for user 33A reaches 5 on the same day, the privacy budget monitoring result 51 for user 33A will be set to no privacy budget for the next preset period of time, such as 6 hours. During this period, query requests 22 for user 33A will receive a response 42 with no query results. After 6 hours, normal responses 42 are restored. When the total number of query requests 22 for user 33A reaches 20, the obfuscation value 11 and the accompanying probability 12 are regenerated. Based on the query requests 22, the credit limit 32, the obfuscation value 11, and the accompanying probability 12, the obfuscation credit 41 for user 33 is obtained, and the total number of queries is reset.
[0064] On the other hand, in another embodiment, a confusion value 11 and an incidental probability 12 are generated. The smaller the confusion amount of the confusion value 11, the larger the corresponding incidental probability 12, as shown in FIG5. For example, FIG5 shows that when the confusion value 11 is 0, that is, when there is no confusion value 11, the incidental probability 12 is 25%. A more recommended embodiment is to take a number with a smaller confusion amount, rather than exactly 0, such as when the confusion value 11 is +3.5, +2.0, -0.5, or -1.5, the incidental probability 12 is 25%, which can better hide the true value. Methods for determining the incidental probability 12 include exponential mechanisms, Laplace mechanisms, Gaussian mechanisms, and the like. For example, when the exponential mechanism is used, the probability of generating the confusion value 11 is the same as is proportional to. Wherein, x represents the true value and r represents the obfuscation result. In this embodiment, the obfuscation result is equal to the sum of the true value and the obfuscation value 11. μ(x, r) is the set benefit function, and the output of the benefit function is the score given to the obfuscation result r. The higher the score, the higher the value of the obfuscation result. In this embodiment, the obfuscation result represents the obfuscation limit 41. The higher the obfuscation limit 41, the higher the credit limit that the corresponding user 33 may obtain, that is, the higher the value brought. ε represents the privacy budget parameter. When ε=1, there is a better privacy protection effect. Δμ represents the sensitivity of the configuration. The smaller the sensitivity value, the greater the distribution probability that the obfuscation result is close to the true value.
[0065] In this embodiment, the method for obtaining the obfuscation credit 41 corresponding to the user 33 based on the query request 22, the credit limit 32, the obfuscation value 11 and the incidental probability 12 includes: generating a plurality of obfuscation values 11 within a preconfigured numerical range, wherein the smaller the obfuscation amount of the obfuscation value 11, the larger the corresponding incidental probability 12; associating the credit limit 32, the obfuscation value 11 with the corresponding incidental probability 12 and the user identifier 34 and then storing them persistently; obtaining the corresponding credit limit 32, the obfuscation value 11 and the incidental probability 12 based on the user identifier 34 of the query request 22, and selecting an obfuscation value 11 from the plurality of obfuscation values 11 with the incidental probability 12 as the selection probability; and summing the credit limit 32 and the selected obfuscation value 11 as the obfuscation credit 41 obtained by the query request 22.
[0066] Referring to FIG. 6A , after generating obfuscated value 11 and associated probability 12, user 33's credit limit 32, user ID 34, and several obfuscated values 11 and associated probabilities 12 are stored together. During a query, the credit limit 32, user ID 34, and all obfuscated values 11 and associated probabilities 12 are retrieved. Based on the associated probability 12, one obfuscated value 11 is selected from the multiple obfuscated values 11, and the sum of the obfuscated value 11 and the credit limit 32 is used as the obfuscated credit limit 41 obtained for this query request 22. For example, if user 33A's credit limit 32 is 500,000 yuan, the generated obfuscated values 11 and associated probabilities 12 are: -150,000 yuan (5%), -100,000 yuan (15%), -50,000 yuan (30%), 50,000 yuan (30%), 100,000 yuan (15%), and 150,000 yuan (5%). The user ID 34 of user 33A, the credit limit of 32.5 million yuan, and -150,000 yuan (5%), -100,000 yuan (15%), -50,000 yuan (30%), 50,000 yuan (30%), 100,000 yuan (15%), and 150,000 yuan (5%) are stored. During a query, an obfuscated value 11 is randomly selected from -150,000 yuan, -100,000 yuan, -50,000 yuan, 50,000 yuan, 100,000 yuan, and 150,000 yuan according to the incidental probability 12. For example, the obfuscated value 11 selected is -50,000 yuan. The sum of the credit limit of 32.5 million yuan and -50,000 yuan is 450,000 yuan. The obfuscated limit 41 obtained as the result of this query request 22 is 450,000 yuan.
[0067] On the other hand, in another embodiment, a method for generating a confusion value 11 and an accompanying probability 12, and obtaining a confusion credit 41 corresponding to a user 33 based on the query request 22, the credit limit 32, the confusion value 11, and the accompanying probability 12 includes: generating a plurality of confusion values 11 within a preconfigured numerical range, wherein the smaller the confusion amount of the confusion value 11, the larger the corresponding accompanying probability 12; summing the credit limit 32 and the plurality of confusion values 11 as the confusion credit 41, associating the confusion credit 41 with the corresponding accompanying probability 12 and the user identifier 34, and then persistently storing the sum; obtaining the corresponding confusion credit 41 and the accompanying probability 12 based on the user identifier 34 of the query request 22, and selecting a confusion credit 41 from the plurality of confusion credits 41 using the accompanying probability 12 as the selection probability as the confusion credit 41 obtained for the query request 22.
[0068] Referring to FIG. 6B , after generating obfuscation values 11 and associated probabilities 12, user 33's credit limit 32 is summed with the corresponding obfuscation values 11 to obtain an obfuscated credit limit 41. User 33's user ID 34, the multiple obfuscated credit limits 41, and the associated probabilities 12 are stored together. During a query, the user ID 34, the multiple obfuscated credit limits 41, and the associated probabilities 12 are retrieved. Based on the associated probabilities 12, one of the multiple obfuscated credit limits 41 is selected as the obfuscated credit limit 41 obtained for this query request 22. For example, if user 33A's credit limit 32 is 500,000 yuan, the generated obfuscation values 11 and associated probabilities 12 are: -150,000 yuan (5%), -100,000 yuan (15%), -50,000 yuan (30%), 50,000 yuan (30%), 100,000 yuan (15%), and 150,000 yuan (5%). The credit limit of user 33A, RMB 32.5 million, is summed with several confusion values 11 respectively to obtain the confusion limit 41 and the accompanying probability 12: RMB 350,000 (5%), RMB 400,000 (15%), RMB 450,000 (30%), RMB 550,000 (30%), RMB 600,000 (15%), and RMB 650,000 (5%).
[0069] The user ID 34 of user 33A and 350,000 yuan (5%), 400,000 yuan (15%), 450,000 yuan (30%), 550,000 yuan (30%), 600,000 yuan (15%), and 650,000 yuan (5%) are stored. During a query, an obfuscated amount 41 is randomly selected from 350,000 yuan, 400,000 yuan, 450,000 yuan, 550,000 yuan, 600,000 yuan, and 650,000 yuan according to the incidental probability 12. For example, the selected obfuscated value 11 is 600,000 yuan, and the obfuscated amount 41 ultimately obtained for this query request 22 is 600,000 yuan. Compared to the solution shown in FIG. 6A , this embodiment can reduce one computational step when responding to 42 the query request 22.
[0070] On the other hand, in another embodiment, a method for generating a confusion value 11 and an accompanying probability 12, and obtaining a confusion credit 41 corresponding to a user 33 based on the query request 22, the credit limit 32, the confusion value 11, and the accompanying probability 12 includes: generating a plurality of confusion values 11 within a preconfigured numerical range, wherein the smaller the confusion amount of the confusion value 11, the larger the corresponding accompanying probability 12; selecting a confusion value 11 from the plurality of confusion values 11 using the accompanying probability 12 as the selection probability; summing the credit limit 32 and the selected confusion value 11 as the confusion credit 41, associating the confusion credit 41 with the user identifier 34 and storing them persistently; and obtaining a corresponding confusion credit 41 based on the user identifier 34 of the query request 22 as the confusion credit 41 obtained for the query request 22.
[0071] Referring to FIG. 6C , after generating an obfuscated value 11 and associated probability 12, one of several obfuscated values 11 is selected based on the associated probability 12. The selected obfuscated value 11 is then summed with the credit limit 32 of the user 33 to form an obfuscated credit limit 41. This obfuscated credit limit 41 is associated with the user identifier 34 and stored. During a query, the obfuscated credit limit 41 is retrieved and used as the obfuscated credit limit 41 for the current query request 22.
[0072] For example, if user 33A's credit limit 32 is 500,000 yuan, the generated obfuscation values 11 and associated probabilities 12 are: -150,000 yuan (5%), -100,000 yuan (15%), -50,000 yuan (30%), 50,000 yuan (30%), 100,000 yuan (15%), and 150,000 yuan (5%). During a query, based on associated probabilities 12, an obfuscation value 11 is randomly selected from -150,000 yuan, -100,000 yuan, -50,000 yuan, 50,000 yuan, 100,000 yuan, and 150,000 yuan. For example, the selected obfuscation value 11 is -100,000 yuan.
[0073] The credit limit of user 33A, 32.5 million yuan, is summed with the obfuscation values 110,000 yuan to 100,000 yuan, resulting in an obfuscated credit limit 41 of 400,000 yuan. The obfuscated credit limit 41, 41.4 million yuan, is associated with the user ID 34 of user 33A and stored. During a query, the obfuscated credit limit 41, 41.4 million yuan, is used as the obfuscated credit limit 41 obtained for this query request 22. Compared to the solution shown in Figures 6A and 6B, this embodiment utilizes fewer calculation steps when responding to query request 22, but requires periodic updating of the obfuscated credit limit 41.
[0074] On the other hand, in another embodiment, a method for generating a confusion value 11 and an accompanying probability 12, and obtaining a confusion credit 41 corresponding to a user 33 based on the query request 22, the credit limit 32, the confusion value 11, and the accompanying probability 12 includes: associating the credit limit 32 and the user identifier 34 and storing them persistently; obtaining the corresponding credit limit 32 based on the user identifier 34 of the query request 22; generating several confusion values 11 within a preconfigured numerical range, the smaller the confusion amount of the confusion value 11, the larger the corresponding accompanying probability 12; selecting a confusion value 11 from several of the confusion values 11 with the accompanying probability 12 as the selection probability; and summing the credit limit 32 and the selected confusion value 11 as the confusion credit 41 obtained by the query request 22.
[0075] Referring to FIG. 6D , during storage, only the credit limit 32 of user 33 is associated with the user identifier 34 and stored. During query, the credit limit 32 of user 33 is retrieved. Simultaneously, several obfuscated values 11 and associated probabilities 12 are temporarily generated. Based on the associated probability 12, one of the obfuscated values 11 is selected. The sum of the obfuscated value 11 and the credit limit 32 is used as the obfuscated credit limit 41 obtained for this query request 22.
[0076] For example, the credit limit 32 of user 33A is RMB 500,000, and the credit limit 32.5 million is associated with the user ID 34 of user 33A and stored.
[0077] During the query, the credit limit 32 of user 33A is obtained as 500,000 yuan, and then the temporary generated obfuscation value 11 and the accompanying probability 12 are: -150,000 yuan (5%), -100,000 yuan (15%), -50,000 yuan (30%), 50,000 yuan (30%), 100,000 yuan (15%), and 150,000 yuan (5%). According to the accompanying probability 12, an obfuscation value 11 is randomly selected from -150,000 yuan, -100,000 yuan, -50,000 yuan, 50,000 yuan, 100,000 yuan, and 150,000 yuan. The exemplary obfuscation value 11 is -50,000 yuan. The sum of the credit limit 32.5 million yuan and -50,000 yuan is 450,000 yuan. The final obfuscation limit 41 obtained as this query request 22 is 450,000 yuan. Compared with the solutions shown in Figures 6A, 6B, and 6C, this embodiment can have higher storage efficiency, but the query efficiency is relatively low.
[0078] Application Scenario Introduction
[0079] In some application scenarios, risk control data requester 21 does not provide a desired credit limit, but instead wishes to directly query user 33's credit limit 32, as shown in Figure 7. For example, when multiple credit products are presented to user 33, user 33's credit limit 32 is obtained by querying the risk control data provider. Based on user 33's credit limit 32, the display area for credit products that user 33 does not meet the threshold is hidden, thereby improving user 33's experience.
[0080] To be applied to this application scenario, this specification provides a risk control method based on differential privacy, which is performed by the risk control data provider. Please refer to Figure 8, which includes steps 302 to 308.
[0081] Step 302 : Generate or receive a risk control strategy 31 , and obtain the credit limit 32 of the user 33 based on the risk control strategy 31 .
[0082] Step 304 : Receive a query request 22 from a risk control data demander 21 , where the query request 22 includes a user identifier 34 .
[0083] Step 306 : Generate an obfuscation value 11 and an accompanying probability 12 , and generate an obfuscation credit limit 41 corresponding to the credit limit 32 of the user 33 based on the obfuscation value 11 and the accompanying probability 12 .
[0084] Step 308 : Generate a response 42 to the query request 22 based on the obfuscation credit 41 .
[0085] In this embodiment, when risk control data demander 21 sends a query request 22 to a risk control data provider, it only needs to provide a user identifier 34. The risk control data provider uses a differential privacy mechanism to generate an obfuscated value 11 based on user 33's credit limit 32, and then feeds the obfuscated credit limit 41 back to risk control data demander 21 as a response 42.
[0086] On the other hand, in another embodiment, when generating a response 42 to the query request 22, the response 42 to the query request 22 is generated based on the obfuscation amount 41 and the privacy budget supervision result 51; the method for obtaining the privacy budget supervision result 51 includes the steps of: reading the historical query request 22 corresponding to the user 33; and obtaining the privacy budget supervision result 51 based on the configured privacy budget and the historical query request 22.
[0087] On the other hand, in another embodiment, a method for obtaining a privacy budget supervision result 51 based on a configured privacy budget and the historical query request 22 includes: based on the configured inspection period and the historical query request 22, obtaining a statistical number of query requests 22 within the inspection period, recorded as the number of short-time queries; obtaining a total number of queries corresponding to the user 33 based on the historical query request 22; when the number of short-time queries reaches a preset first threshold, setting the privacy budget supervision result 51 to no privacy budget within a preset time after the last query request 22; when the total number of queries reaches a preset second threshold, regenerating the confusion value 11 and the incidental probability 12, generating a confusion limit 41 for the credit limit 32 of the corresponding user 33 based on the confusion value 11 and the incidental probability 12, and resetting the total number of queries.
[0088] On the other hand, this specification provides a risk control method based on differential privacy, which is executed by a risk control data demander 21, and includes the steps of: sending a query request 22 to a risk control data provider, wherein the query request 22 includes a user identifier 34; receiving a response 42 from the risk control data provider to the query request 22; and generating a credit limit for the corresponding user 33 based on the response 42.
[0089] On the other hand, this specification provides a risk control method based on differential privacy, which is executed by a risk control data demander 21, and includes the steps of: sending a query request 22 to a risk control data provider, wherein the query request 22 includes a user identifier 34 and a desired credit limit; receiving a response 42 from the risk control data provider to the query request 22; and obtaining the effective result of the desired credit limit of the corresponding user 33 based on the response 42.
[0090] On the other hand, this specification provides a risk control system based on differential privacy, please refer to Figure 9, including: a strategy component 61, used to generate or receive a risk control strategy 31, and obtain the credit limit 32 of a user 33 based on the risk control strategy 31; a query receiving component 62, used to receive a query request 22 from a risk control data demander 21, and the query request 22 includes a user identifier 34 and a desired credit limit; a privacy protection component 63, used to generate an obfuscation value 11 and an accompanying probability 12, and obtain the obfuscation limit 41 of the corresponding user 33 based on the query request 22, the credit limit 32, the obfuscation value 11 and the accompanying probability 12; a response component 64, used to compare the obfuscation limit 41 with the desired credit limit, and generate a response 42 to the query request 22 based on the comparison result 23.
[0091] In this embodiment, the policy component 61, query receiving component 62, privacy protection component 63, and response component 64 can be deployed on the same device, system, platform, or server, or they can be deployed in a distributed manner across different devices, systems, platforms, or servers, exchanging data with each other via network communication. When the volume of query requests 22 is high, the policy component 61, query receiving component 62, privacy protection component 63, and response component 64 can also be deployed in a server cluster.
[0092] On the other hand, in another embodiment, when the response component 64 generates a response 42 to the query request 22, it generates a response 42 to the query request 22 based on the comparison result 23 and the privacy budget supervision result 51; the risk control system also includes a supervision component 65, which is used to read the historical query requests 22 corresponding to the user 33, and obtain the privacy budget supervision result 51 based on the configured privacy budget and the historical query requests 22.
[0093] The supervisor component 65 obtains historical query requests 22 from the query receiving component 62 through data subscription. The query receiving component 62 periodically pushes new historical query requests 22, or writes new historical query requests 22 to a configured database, which the supervisor component 65 then accesses to obtain. The former requires direct data exchange between the supervisor component 65 and the query receiving component 62, while the latter does not.
[0094] On the other hand, in another embodiment, please refer to Figure 10A, the privacy protection component 63 includes: an obfuscation value unit 631, which is used to generate several obfuscation values 11 within a preconfigured numerical range, and the smaller the obfuscation amount of the obfuscation value 11, the larger the corresponding incidental probability 12; a persistence unit 632, which is used to associate the credit limit 32, the obfuscation value 11 with the corresponding incidental probability 12 and the user identification 34 and then store them persistently; an obfuscation unit 633, which is used to obtain the corresponding credit limit 32, the obfuscation value 11 and the incidental probability 12 based on the user identification 34 of the query request 22, and select an obfuscation value 11 from several of the obfuscation values 11 with the incidental probability 12 as the selection probability; a query response unit 634, which is used to obtain the corresponding credit limit 32, the obfuscation value 11 and the incidental probability 12 based on the user identification 34 of the query request 22, and select an obfuscation value 11 from several of the obfuscation values 11 with the incidental probability 12 as the selection probability.
[0095] On the other hand, in another embodiment, please refer to Figure 10B, the privacy protection component 63 includes: an obfuscation value unit 631, which is used to generate a number of obfuscation values 11 within a preconfigured numerical range, and the smaller the obfuscation amount of the obfuscation value 11, the larger the corresponding incidental probability 12; a persistence unit 632, which is used to sum the credit limit 32 and the number of the obfuscation values 11 as the obfuscation limit 41, and associate the obfuscation limit 41 with the corresponding incidental probability 12 and the user identification 34 and then store them persistently; a query response unit 634, which is used to obtain the corresponding obfuscation limit 41 and incidental probability 12 based on the user identification 34 of the query request 22, and select a obfuscation limit 41 from the number of the obfuscation limits 41 with the incidental probability 12 as the selection probability as the obfuscation limit 41 obtained by the query request 22.
[0096] On the other hand, in another embodiment, please refer to Figure 10C, the privacy protection component 63 includes: an obfuscation value unit 631, which is used to generate a number of obfuscation values 11 within a preconfigured numerical range, and the smaller the obfuscation amount of the obfuscation value 11, the larger the corresponding incidental probability 12; a selection unit 635, which is used to select an obfuscation value 11 from the several obfuscation values 11 with the incidental probability 12 as the selection probability; a persistence unit 632, which is used to sum the credit limit 32 and the selected obfuscation value 11 as the obfuscation limit 41, and persistently store the obfuscation limit 41; a query response unit 634, which is used to obtain a corresponding obfuscation limit based on the user identifier 34 of the query request 22, as the obfuscation limit 41 obtained by the query request 22.
[0097] On the other hand, in another embodiment, please refer to Figure 10D, the privacy protection component 63 includes: a persistence unit 632, which is used to persistently store the credit limit 32; a query unit 636, which is used to obtain the corresponding credit limit 32 based on the user identifier 34 of the query request 22; an obfuscation value unit 631, which is used to generate a number of obfuscation values 11 within a preconfigured numerical range, and the smaller the obfuscation amount of the obfuscation value 11, the larger the corresponding incidental probability 12; a selection unit 635, which is used to select an obfuscation value 11 from the several obfuscation values 11 with the incidental probability 12 as the selection probability; a query response unit 634, which is used to sum the credit limit 32 and the selected obfuscation value 11 as the obfuscation limit 41 obtained by the query request 22.
[0098] In some application scenarios, the risk control data demander 21 does not provide the credit limit to be granted, but hopes to directly query the credit limit 32 of the user 33. To this end, this specification provides another risk control system based on differential privacy, including: a policy module for generating or receiving a risk control policy 31, and obtaining the credit limit 32 of the user 33 based on the risk control policy 31; a query receiving module for receiving a query request 22 from the risk control data demander 21, wherein the query request 22 includes a user identifier 34; a privacy protection module for generating an obfuscation value 11 and an accompanying probability 12, and generating an obfuscated limit 41 corresponding to the credit limit 32 of the user 33 based on the obfuscation value 11 and the accompanying probability 12; and a response 42 module for generating a response 42 to the query request 22 based on the obfuscated limit 41.
[0099] On the other hand, in another embodiment, when the response 42 module generates a response 42 to the query request 22 based on the obfuscation amount 41, the response 42 to the query request 22 is generated based on the obfuscation amount 41 and the privacy budget supervision result 51; the risk control system also includes a supervision module, which is used to read the historical query requests 22 corresponding to the user 33, and obtain the privacy budget supervision result 51 based on the configured privacy budget and the historical query requests 22.
[0100] Please refer to FIG11 , which shows a schematic structural diagram of an electronic device provided in an embodiment of this specification.
[0101] As shown in Figure 11, the electronic device 1100 may include: at least one processor 1101, at least one network interface 1104, a user interface 1103, a memory 1105, and at least one communication bus 1102. The communication bus 1102 may be used to implement connection and communication between the above-mentioned components. The user interface 1103 may include buttons, and the optional user interface may also include a standard wired interface or a wireless interface. The network interface 1104 may include, but is not limited to, a Bluetooth module, an NFC module, a Wi-Fi module, etc. The processor 1101 may include one or more processing cores. The processor 1101 uses various interfaces and lines to connect the various parts of the entire electronic device 1100, and executes various functions and processes data of the routing device 1100 by running or executing instructions, programs, code sets, or instruction sets stored in the memory 1105, and calling data stored in the memory 1105. Optionally, the processor 1101 may be implemented in the form of at least one hardware component selected from DSP, FPGA, and PLA. The processor 1101 may integrate one or a combination of CPU, GPU, modem, etc. Among them, the CPU mainly processes the operating system, user interface and application programs; the GPU is responsible for rendering and drawing the content that needs to be displayed on the display; and the modem is used to handle wireless communication.
[0102] It is understandable that the above-mentioned modem may not be integrated into the processor 1101, but may be implemented by a separate chip.
[0103] Among them, the memory 1105 may include RAM or ROM. Optionally, the memory 1105 includes a non-transitory computer-readable medium. The memory 1105 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 1105 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store data involved in the above-mentioned various method embodiments, etc. The memory 1105 may also be at least one storage device located away from the aforementioned processor 1101. The memory 1105 as a computer storage medium may include an operating system, a network communication module, a user interface module and an application. The processor 1101 can be used to call the application stored in the memory 1105 and execute the method in one or more of the above-mentioned embodiments.
[0104] The embodiments of this specification also provide a computer-readable storage medium having instructions stored therein that, when executed on a computer or processor, cause the computer or processor to perform one or more steps of the above embodiments. If the components of the electronic device described above are implemented as software functional units and sold or used as independent products, they may be stored in the computer-readable storage medium.
[0105] In the absence of conflict, the technical features in this embodiment and implementation scheme can be combined arbitrarily.
[0106] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiments of this specification is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted via the computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a digital versatile disc (DVD)), or a semiconductor medium (eg, a solid state disk (SSD)).
[0107] When implemented through hardware or firmware, the aforementioned method flow is programmed into the hardware circuit to obtain the corresponding hardware circuit structure and realize the corresponding function. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit, whose logical function is determined by the user 33 programming the device. Designers can "integrate" a digital system on a PLD by programming themselves, eliminating the need to hire a chip manufacturer to design and manufacture a dedicated integrated circuit chip. Moreover, today, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. This is similar to the software compiler used in program development. Before compilation, the original code must also be written in a specific programming language, called a hardware description language (HDL). There are not just one HDL, but many types. Those skilled in the art will also understand that by simply programming the method flow using one of the aforementioned hardware description languages and programming it into the integrated circuit, a hardware circuit that implements the logical method flow can be easily obtained.
[0108] The embodiments described above are descriptions of the implementation methods of this specification and are not intended to limit the scope of this specification. Without departing from the design spirit of this specification, various modifications and improvements made to the technical solutions of this specification by ordinary technicians in this field should fall within the scope of protection determined by the claims of this specification.
Claims
1. A risk control method based on differential privacy, performed by a risk control data provider, comprising: Generate or receive a risk control strategy, and obtain a user's credit limit based on the risk control strategy; Receive a query request from a risk control data demander, the query request including a user identifier and a desired credit limit; Generate an obfuscation value and an accompanying probability, and obtain an obfuscation credit of a corresponding user based on the query request, the credit limit, the obfuscation value and the accompanying probability; The obfuscated credit limit is compared with the desired credit limit, and a response to the query request is generated based on the comparison result.
2. The risk control method based on differential privacy according to claim 1, wherein: When generating a response to the query request, generating a response to the query request based on the comparison result and the privacy budget supervision result; Methods for obtaining privacy budget monitoring results include: Read the historical query requests corresponding to the user; A privacy budget supervision result is obtained based on the configured privacy budget and the historical query request.
3. The risk control method based on differential privacy according to claim 2, wherein: The method for obtaining the privacy budget supervision result based on the configured privacy budget and the historical query request includes: Based on the configured inspection period and the historical query requests, obtain the statistical number of query requests within the inspection period, which is recorded as the short-term query number; Obtaining the total number of queries of the corresponding user based on the historical query requests; When the number of short-term queries reaches a preset first threshold, within a preset time period after the last query request, setting the privacy budget supervision result to no privacy budget; When the total number of queries reaches a preset second threshold, the confusion value and the accompanying probability are regenerated, the confusion credit of the corresponding user is obtained based on the query request, the credit limit, the confusion value and the accompanying probability, and the total number of queries is reset.
4. The risk control method based on differential privacy according to any one of claims 1 to 3, wherein: The method of generating a confusion value and an accompanying probability, and obtaining a confusion credit of a corresponding user based on the query request, the credit line, the confusion value and the accompanying probability, comprises: Generate several obfuscation values in a pre-configured numerical range. The smaller the obfuscation amount of the obfuscation value, the greater the corresponding incidental probability; Associating the credit limit, the obfuscation value with the corresponding incidental probability and the user identifier and storing them persistently; Obtaining a corresponding credit limit, an obfuscation value, and an incidental probability based on a user identifier of a query request, and selecting an obfuscation value from a plurality of obfuscation values using the incidental probability as a selection probability; summing the credit limit and the selected obfuscation value as the obfuscation limit obtained by the query request; or The method of generating a confusion value and an accompanying probability, and obtaining a confusion credit of a corresponding user based on the query request, the credit limit, the confusion value and the accompanying probability includes: Generate several obfuscation values in a pre-configured numerical range. The smaller the obfuscation amount of the obfuscation value, the greater the corresponding incidental probability; The credit limit and a plurality of the obfuscation values are summed as the obfuscation limit, and the obfuscation limit is associated with the corresponding incidental probability and user identification and then stored persistently; Obtaining a corresponding obfuscation amount and an accompanying probability based on a user identifier of the query request, taking the accompanying probability as a selection probability, and selecting a obfuscation amount from a plurality of the obfuscation amounts as the obfuscation amount obtained by the query request; or, The method of generating a confusion value and an accompanying probability, and obtaining a confusion credit of a corresponding user based on the query request, the credit limit, the confusion value and the accompanying probability includes: Generate several obfuscation values in a pre-configured numerical range. The smaller the obfuscation amount of the obfuscation value, the greater the corresponding incidental probability; Taking the incidental probability as the selection probability, selecting an obfuscation value from the plurality of obfuscation values; The credit limit and the selected obfuscation value are summed as the obfuscation limit, and the obfuscation limit is associated with the user identifier and stored persistently; Obtaining a corresponding obfuscation amount based on the user identifier of the query request as the obfuscation amount obtained by the query request; or, The method of generating a confusion value and an accompanying probability, and obtaining a confusion credit of a corresponding user based on the query request, the credit limit, the confusion value and the accompanying probability includes: Associating the credit limit and the user identification and storing them persistently; Obtaining a corresponding credit limit based on the user ID of the query request; Generate several obfuscation values in a pre-configured numerical range. The smaller the obfuscation amount of the obfuscation value, the greater the corresponding incidental probability; Taking the incidental probability as the selection probability, selecting an obfuscation value from the plurality of obfuscation values; The credit limit and the selected obfuscation value are summed to obtain the obfuscation limit obtained by the query request.
5. A risk control method based on differential privacy, performed by a risk control data provider, comprising: Generate or receive a risk control strategy, and obtain a user's credit limit based on the risk control strategy; Receive a query request from a risk control data demander, where the query request includes a user identifier; Generate an obfuscation value and an accompanying probability, and generate an obfuscation credit limit corresponding to the user's credit limit based on the obfuscation value and the accompanying probability; A response to the query request is generated based on the obfuscation amount.
6. The risk control method based on differential privacy according to claim 5, wherein: When generating a response to the query request, generating a response to the query request based on the obfuscation amount and the privacy budget supervision result; Methods for obtaining privacy budget monitoring results include: Read the historical query requests corresponding to the user; A privacy budget supervision result is obtained based on the configured privacy budget and the historical query request.
7. The risk control method based on differential privacy according to claim 6, wherein: The method for obtaining the privacy budget supervision result based on the configured privacy budget and the historical query request includes: Based on the configured inspection period and the historical query requests, obtain the statistical number of query requests within the inspection period, which is recorded as the short-term query number; Obtaining the total number of queries of the corresponding user based on the historical query requests; When the number of short-term queries reaches a preset first threshold, within a preset time period after the last query request, setting the privacy budget supervision result to no privacy budget; When the total number of queries reaches a preset second threshold, the confusion value and the accompanying probability are regenerated, a confusion credit limit corresponding to the user's credit limit is generated based on the confusion value and the accompanying probability, and the total number of queries is reset.
8. A risk control method based on differential privacy, performed by a risk control data demander, comprising: Sending a query request to a risk control data provider, wherein the query request includes a user identifier; Receiving a response from a risk control data provider to the query request; A credit limit for the corresponding user is generated based on the response.
9. A risk control method based on differential privacy, performed by a risk control data demander, comprising: Sending a query request to the risk control data provider, the query request including the user ID and the credit limit to be granted; Receiving a response from a risk control data provider to the query request; Based on the response, a validation result of the credit limit to be granted to the corresponding user is obtained.
10. A risk control system based on differential privacy, comprising: A strategy component, used to generate or receive a risk control strategy, and obtain a user's credit limit based on the risk control strategy; A query receiving component, used to receive a query request from a risk control data demander, wherein the query request includes a user identifier and a desired credit limit; A privacy protection component, used to generate an obfuscation value and an accompanying probability, and obtain an obfuscation credit of a corresponding user based on the query request, the credit limit, the obfuscation value and the accompanying probability; A response component is used to compare the obfuscated credit limit with the desired credit limit, and generate a response to the query request based on the comparison result.
11. The risk control system based on differential privacy according to claim 10, wherein: When the response component generates a response to the query request, the response to the query request is generated based on the comparison result and the privacy budget supervision result; The risk control system also includes a monitoring component, which is used to read historical query requests corresponding to users and obtain privacy budget monitoring results based on the configured privacy budget and the historical query requests.
12. The risk control system based on differential privacy according to claim 10, wherein: The privacy protection component includes: A confusion value unit, used to generate a number of confusion values in a pre-configured value range, wherein the smaller the confusion amount of the confusion value, the greater the corresponding incidental probability; A persistence unit, used for persistently storing the credit limit, the confusion value, the corresponding incidental probability and the user identifier after association; The obfuscation unit is used to obtain a corresponding credit limit, an obfuscation value and an accompanying probability based on a user identifier of a query request, and select an obfuscation value from a plurality of obfuscation values using the accompanying probability as a selection probability; A query response unit, configured to obtain a corresponding credit limit, a confusion value and an incidental probability based on a user identifier of a query request, and select a confusion value from a plurality of the confusion values using the incidental probability as a selection probability; or, The privacy protection component includes: A confusion value unit, used to generate a number of confusion values in a pre-configured value range, wherein the smaller the confusion amount of the confusion value, the greater the corresponding incidental probability; A persistence unit, used for summing the credit limit and a plurality of the obfuscation values as an obfuscation limit, associating the obfuscation limit with a corresponding incidental probability and a user identifier, and then storing the resultant obfuscation limit persistently; A query response unit, configured to obtain a corresponding obfuscation amount and an accompanying probability based on a user identifier of a query request, and select a obfuscation amount from a plurality of obfuscation amounts using the accompanying probability as a selection probability as the obfuscation amount obtained by the query request; or, The privacy protection component includes: A confusion value unit, used to generate a number of confusion values in a pre-configured value range, wherein the smaller the confusion amount of the confusion value, the greater the corresponding incidental probability; A selection unit, configured to select an obfuscation value from a plurality of obfuscation values by taking the incidental probability as a selection probability; A persistence unit, configured to sum the credit limit and the selected obfuscation value as an obfuscation limit, and persistently store the obfuscation limit; A query response unit, configured to obtain a corresponding obfuscation amount based on a user identifier of a query request as the obfuscation amount obtained by the query request; or, The privacy protection component includes: A persistence unit, used for persistently storing the credit limit; A query unit, used to obtain a corresponding credit limit based on a user identifier of a query request; A confusion value unit, used to generate a number of confusion values in a pre-configured value range, wherein the smaller the confusion amount of the confusion value, the greater the corresponding incidental probability; A selection unit, configured to select an obfuscation value from a plurality of obfuscation values by taking the incidental probability as a selection probability; The query response unit is used to sum the credit limit and the selected obfuscation value as the obfuscation limit obtained by the query request.
13. A risk control system based on differential privacy, comprising: A policy module, used to generate or receive a risk control policy, and obtain a user's credit limit based on the risk control policy; A query receiving module, used to receive a query request from a risk control data demander, wherein the query request includes a user identifier; A privacy protection module, used to generate an obfuscation value and an accompanying probability, and generate an obfuscation limit corresponding to the credit limit of the user based on the obfuscation value and the accompanying probability; A response module is used to generate a response to the query request based on the obfuscation amount.
14. The risk control system based on differential privacy according to claim 13, wherein: When the response module generates a response to the query request based on the obfuscation quota, the response module generates a response to the query request based on the obfuscation quota and the privacy budget supervision result; The risk control system also includes a supervision module, which is used to read historical query requests corresponding to users and obtain privacy budget supervision results based on the configured privacy budget and the historical query requests.
15. An electronic device comprising a processor and a memory; The processor is connected to the memory; The memory is used to store executable program code; The processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to execute the method according to any one of claims 1 to 9.
16. A computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Differential privacy protection method and system based on sampling
CN110727957A
Risk control method and system based on differential privacy, electronic equipment and storage medium
CN117708875A
Credit exposure limit management method and system
KR1020120134849A
Detecting first party fraud abuse
US20090222308A1