Method for retraining posture estimation model for personal information protection

By employing homomorphic encryption and data distribution comparison, the method efficiently updates and deploys neural networks for personal information processing, addressing hardware disparities and privacy concerns.

WO2025143663A1PCT designated stage expired Publication Date: 2025-07-03SAFE AI CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/020456
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-29
Filing Date
2024-12-17
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

Existing federated learning methods for artificial neural networks face challenges in efficiently updating and deploying models for personal information processing due to hardware disparities and high computing resource requirements, while ensuring privacy protection.

Method used

A method involving homomorphic encryption and data distribution comparison is used to retrain a posture estimation model by generating encrypted data sets and distributions, updating models on devices with limited hardware, and improving performance through continuous learning.

Benefits of technology

The method efficiently renews the neural network model, enhancing its performance without decrypting data, thus maintaining privacy and reducing computational costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024020456_03072025_PF_FP_ABST
    Figure KR2024020456_03072025_PF_FP_ABST
Patent Text Reader

Abstract

According to an embodiment of the present disclosure, disclosed is a method performed by a computing apparatus to retrain a posture estimation model for personal information protection. Particularly, according to the present disclosure, a computing apparatus generates a first encrypted data set and a first data distribution representation on the basis of a first data set, performs training for a first artificial neural network model on the basis of the first encrypted data set, distributes the trained first artificial neural network model and the first data distribution representation to a device, receives a second encrypted data set generated on the basis of a second data set newly input into the device, updates the first encrypted data set on the basis of the second encrypted data set, and performs retraining of the first artificial neural network model on the basis of the updated first encrypted data set.
Need to check novelty before this filing date? Find Prior Art

Description

A method for retraining a pose estimation model for privacy protection

[0001] The present disclosure relates to a method for retraining a posture estimation model for personal information protection, and more particularly, to a method for retraining the first artificial neural network model by performing training of a first artificial neural network model based on a first encrypted data set, distributing the trained first artificial neural network model and the first data distribution representation to a device, and then comparing the first data distribution representation and the second data distribution representation.

[0002] With the advancement of cloud computing and artificial intelligence, many services are leveraging this technology to capture data from each user's device, transmit it to a server with an AI model for processing, and receive the results. For example, services could be implemented that recognize individuals in CCTV footage, estimate their posture, and generate alerts if they are identified as adopting a dangerous posture, thereby preventing accidents.

[0003] However, for data containing personal information, such as images containing human faces, transmitting such data over a network without separate processing, such as anonymization, to protect personal information may cause problems under the laws of each country.

[0004] To protect this privacy, the concept of federated learning has emerged in the field of artificial intelligence. Federated learning is a technology that intensively utilizes distributed data from multiple devices or locations to train models. A central server integrates model updates transmitted from each device, while each device maintains its own individual data while being protected. This approach maximizes overall learning effectiveness while strengthening privacy.

[0005] However, in the case of federated learning, the training of the artificial neural network model must be performed on each device. However, since the hardware suitable for training the artificial neural network model and the hardware suitable for inference are not the same, there is an additional cost for securing both, and there is a disadvantage in that a high level of computing resources must be secured for normal system operation.

[0006] Therefore, there is a need in the art for a method to efficiently update and deploy artificial neural network models at a relatively low cost while achieving privacy.

[0007] Korean Patent Publication No. KR 2023-0153448 A discloses a federated learning method, device, electronic device, and storage medium.

[0008] The present disclosure is conceived in response to the aforementioned background technology, and aims to efficiently retrain an artificial neural network model for processing data containing personal information through homomorphic encryption and comparison between data distributions.

[0009] Meanwhile, the technical task to be achieved by the present disclosure is not limited to the technical task mentioned above, and may include various technical tasks within a scope obvious to a person skilled in the art from the contents described below.

[0010] According to one embodiment of the present disclosure for realizing the above-described task, a method performed on a computing device for retraining a posture estimation model for personal information protection is disclosed. The method may include: generating a first encrypted data set and a first data distribution representation based on a first data set; performing training of a first artificial neural network model based on the first encrypted data set; distributing the trained first artificial neural network model and the first data distribution representation to a device; receiving a second encrypted data set generated based on a second data set newly input to the device; updating the first encrypted data set based on the second encrypted data set; and performing retraining of the first artificial neural network model based on the updated first encrypted data set.

[0011] In one embodiment, the first artificial neural network model may include an artificial neural network model that generates information related to pose estimation based on encrypted image data.

[0012] In one embodiment, the first data set may include offline data acquired for learning or verifying an artificial neural network model, and the first encrypted data set may include data encrypted based on homomorphic encryption of data included in the first data set.

[0013] In one embodiment, the second data set may include online data newly acquired from the device for inference of an artificial neural network model, and the second encrypted data set may include data encrypted based on homomorphic encryption of data included in the second data set.

[0014] In one embodiment, the step of receiving a second encrypted data set generated based on a second data set newly input to the device may include: generating, at the device, a second encrypted data set and a second data distribution representation based on the second data set; and receiving, at the device, the second encrypted data set based on comparing the first data distribution representation and the second data distribution representation.

[0015] In one embodiment, the step of receiving the second encrypted data set based on comparing the first data distribution representation and the second data distribution representation in the device may include: receiving the second encrypted data set if a difference between the first data distribution representation and the second data distribution representation is greater than or equal to a predetermined threshold.

[0016] In one embodiment, the step of generating a first encrypted data set and a first data distribution representation based on the first data set may include the step of generating a first skeleton data set based on the first data set and the step of generating a first encrypted data set and a first data distribution representation based on the first skeleton data set.

[0017] In one embodiment, the step of generating a second encrypted data set and a second data distribution representation based on the second data set in the device may include the step of generating a second skeleton data set based on the second data set and the step of generating a second encrypted data set and a second data distribution representation based on the second skeleton data set in the device.

[0018] In one embodiment, the method may further include the steps of: receiving the second data distribution representation from the device; updating the first data distribution representation based on the second data distribution representation; and deploying the updated first data distribution representation and the retrained first artificial neural network model to the device.

[0019] According to one embodiment of the present disclosure for realizing the above-described task, a computer program stored in a computer-readable storage medium is disclosed that causes a computing device to perform operations for retraining a posture estimation model for personal information protection. The operations may include: generating a first encrypted data set and a first data distribution representation based on a first data set; performing training of a first artificial neural network model based on the first encrypted data set; distributing the trained first artificial neural network model and the first data distribution representation to a device; receiving a second encrypted data set generated based on a second data set newly input to the device; updating the first encrypted data set based on the second encrypted data set, and performing retraining of the first artificial neural network model based on the updated first encrypted data set.

[0020] According to one embodiment of the present disclosure for realizing the above-described task, a computing device for retraining a posture estimation model for personal information protection is disclosed. The computing device includes one or more processors and a memory, and the one or more processors are configured to generate a first encrypted data set and a first data distribution representation based on a first data set, perform training of a first artificial neural network model based on the first encrypted data set, distribute the trained first artificial neural network model and the first data distribution representation to a device, receive a second encrypted data set generated based on a second data set newly input to the device, update the first encrypted data set based on the second encrypted data set, and perform retraining of the first artificial neural network model based on the updated first encrypted data set.

[0021] The present disclosure effectively retrains an artificial neural network model for processing data containing personal information, thereby improving the performance of the artificial neural network model.

[0022] Meanwhile, the effects of the present disclosure are not limited to the effects mentioned above, and various effects may be included within a range apparent to those skilled in the art from the contents described below.

[0023] FIG. 1 is a block diagram of a computing device for retraining a posture estimation model for personal information protection according to one embodiment of the present disclosure.

[0024] FIG. 2 is a schematic diagram illustrating a network function according to one embodiment of the present disclosure.

[0025] FIG. 3 is a flowchart illustrating a retraining process of a posture estimation model for personal information protection according to one embodiment of the present disclosure.

[0026] FIG. 4 is a conceptual diagram illustrating a data encryption method according to one embodiment of the present disclosure.

[0027] FIG. 5 is a conceptual diagram illustrating the configuration of a server and a device for performing retraining of a posture estimation model for personal information protection according to one embodiment of the present disclosure.

[0028] FIG. 6 is a simplified, general schematic diagram of an exemplary computing environment in which embodiments of the present disclosure may be implemented.

[0029] The present disclosure is conceived in response to the aforementioned background technology and discloses a method for efficiently retraining an artificial neural network model for processing data containing personal information through homomorphic encryption and comparison between data distributions.

[0030] Various embodiments are now described with reference to the drawings. In this specification, various descriptions are provided to facilitate understanding of the present disclosure. However, it will be apparent that these embodiments may be practiced without these specific details.

[0031] As used herein, the terms "component," "module," "system," and the like refer to computer-related entities, hardware, firmware, software, a combination of software and hardware, or an execution of software. For example, a component may be, but is not limited to, a procedure running on a processor, a processor, an object, a thread of execution, a program, and / or a computer. For example, both an application running on a computing device and the computing device may be a component. One or more components may reside within a processor and / or a thread of execution. A component may be localized within a single computer. One or more components of the present disclosure may be distributed between two or more computers, i.e., execution environments. Furthermore, these components may execute from various computer-readable media having various data structures stored therein. Components may communicate via local and / or remote processes, for example, by signals comprising one or more data packets (e.g., data from one component interacting with another component in a local system, a distributed system, and / or data transmitted via signals to another system over a network such as the Internet).

[0032] Furthermore, the term "or" is intended to mean an inclusive "or" rather than an exclusive "or." That is, unless otherwise specified or clear from context, "X employs A or B" is intended to mean either of the natural inclusive permutations. That is, if X employs A; X employs B; or X employs both A and B, "X employs A or B" can apply to any of these cases. Furthermore, the term "and / or" as used herein should be understood to refer to and include all possible combinations of one or more of the associated items listed.

[0033] Additionally, the terms "comprises" and / or "comprising" should be understood to imply the presence of the features and / or components in question. However, it should be understood that the terms "comprises" and / or "comprising" do not exclude the presence or addition of one or more other features, components, and / or groups thereof. Furthermore, unless otherwise specified or clear from the context to refer to the singular form, the singular in the specification and claims should generally be construed to mean "one or more."

[0034] And, the term “at least one of A or B” should be interpreted to mean “if it includes only A”, “if it includes only B”, or “if it is combined in the composition of A and B”.

[0035] Those skilled in the art should further appreciate that the various illustrative logical blocks, configurations, modules, circuits, means, logics, and algorithm steps described in connection with the embodiments disclosed herein may be implemented as electronic hardware, computer software, or combinations of both. To clearly illustrate the interchangeability of hardware and software, various illustrative components, blocks, configurations, means, logics, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Skilled artisans may implement the described functionality in varying ways for each particular application. However, such implementation decisions should not be interpreted as causing a departure from the scope of the present disclosure.

[0036] The description of the disclosed embodiments is provided to enable a person skilled in the art to make or use the present disclosure. Various modifications to these embodiments will be apparent to those skilled in the art. The general principles defined herein may be applied to other embodiments without departing from the scope of the present disclosure. Thus, the present disclosure is not limited to the embodiments set forth herein. The present disclosure is to be construed in the widest scope consistent with the principles and novel features disclosed herein.

[0037]

[0038] FIG. 1 is a block diagram of a computing device for retraining a posture estimation model for personal information protection according to one embodiment of the present disclosure.

[0039] The configuration of the computing device (100) illustrated in FIG. 1 is merely a simplified example. In one embodiment of the present disclosure, the computing device (100) may include other configurations for performing the computing environment of the computing device (100), and only some of the disclosed configurations may constitute the computing device (100).

[0040] A computing device (100) may include a processor (110), memory (130), and network unit (150).

[0041] The processor (110) may be configured with one or more cores, and may include a processor for data analysis and deep learning, such as a central processing unit (CPU), a general purpose graphics processing unit (GPGPU), and a tensor processing unit (TPU) of a computing device. The processor (110) may read a computer program stored in the memory (130) and perform data processing for machine learning according to an embodiment of the present disclosure. According to an embodiment of the present disclosure, the processor (110) may perform operations for learning a neural network. The processor (110) may perform calculations for learning a neural network, such as processing input data for learning in deep learning (DL), extracting features from input data, calculating errors, and updating weights of a neural network using backpropagation.

[0042] At least one of the CPU, GPGPU, and TPU of the processor (110) can process network function learning. For example, the CPU and GPGPU can jointly process network function learning and data classification using the network function. Furthermore, in one embodiment of the present disclosure, processors of multiple computing devices can be used together to process network function learning and data classification using the network function. Furthermore, a computer program executed in a computing device according to one embodiment of the present disclosure may be a CPU, GPGPU, or TPU executable program.

[0043]

[0044] The processor (110) can generate a first encrypted data set and a first data distribution representation based on a first data set. In the present disclosure, the first data set may include offline data acquired for training or verifying an artificial neural network model. Specifically, the first data set may be a data set including image data including an area related to a human body.

[0045] In the present disclosure, the first encrypted data set may include data encrypted based on homomorphic encryption. Homomorphic encryption is an encryption technology that processes encrypted data without processing it, while maintaining the original data format. This technology enables secure information exchange between two entities, and allows computations to be performed on encrypted data without decrypting it. This enables privacy protection and secure data transmission, and is useful in environments such as cloud computing. Homomorphic encryption is recognized as an effective security method for safely handling sensitive information, as it allows computations to be performed even in an encrypted state. Specific examples of the first data set and the first encrypted data set are described below with reference to FIG. 4.

[0046] In the present disclosure, the first data distribution representation may be data that extracts features regarding the distribution of data included in the first data set. The first data distribution representation may be rule-based, but the data distribution representation may also be generated from the data set using various methods, such as an artificial neural network model.

[0047] The processor (110) may perform training of a first artificial neural network model based on a first encrypted data set. In an embodiment of the present disclosure, the first encrypted data set may be image data including an area corresponding to a person, encrypted by applying homomorphic encryption, and the first artificial neural network model may be an artificial neural network model that receives encrypted image data as input and performs a classification task. When applying homomorphic encryption, the form of the original data is maintained, so the first artificial neural network model trained with data encrypted by homomorphic encryption can generate a correct classification result for data encrypted by inputting image data in the inference step.

[0048] After the learning of the first artificial neural network model is completed, the processor (110) can distribute the learned first artificial neural network model and the first data distribution representation to the device.

[0049] In the present disclosure, the device may include hardware for inference of an artificial neural network and a computing device capable of receiving image data. For example, the device of the present disclosure may be a CCTV-type computing device including hardware such as an NPU for inference of an artificial neural network and a camera that acquires image data at regular intervals from a fixed location. When the device is in the form of a CCTV, the device may be a computing device that photographs image data including an area corresponding to a person and estimates the person's posture by photographing the image data. The device of the present disclosure may receive a first artificial neural network model and a first data distribution representation from a computing device (100) corresponding to a server, and may receive an input image by utilizing the first artificial neural network model to estimate the posture of the person included in the image.

[0050] The processor (110) may receive a second encrypted data set generated based on a second data set newly input to the device. The second data set may include online data newly acquired from the device for inference of an artificial neural network model. A specific method for generating a second encrypted data set based on the second data set will be described below with reference to FIG. 4.

[0051] The processor (110) may update the first encrypted data set based on the second encrypted data set. For example, the processor (110) may determine the union of the first encrypted data set and the second encrypted data set as a new first encrypted data set.

[0052] In another embodiment, the processor (110) may determine the second encrypted data set as a new first encrypted data set. However, it will be apparent to those skilled in the art that, in addition to the above example, a new training data set can be created by appropriately mixing a new online data set with an existing offline data set.

[0053] The processor (110) can retrain the first artificial neural network model based on the updated first encrypted data set. Since training is performed based on the updated training data set, the performance of the first artificial neural network model can be improved through retraining.

[0054] The processor (110) may receive a second data distribution representation from the device. Thereafter, the processor (110) may update the first data distribution representation based on the second data distribution representation. Specifically, when the processor (110) determines the second encrypted data set as a new first encrypted data set, the processor (110) may determine the second data distribution representation as the new first data distribution representation. As another example, when the processor (110) determines the union of the first encrypted data set and the second encrypted data set as the new first encrypted data set, the processor (110) may determine the new first data distribution representation by weighting the second data distribution representation and the first data distribution representation.

[0055] The processor (110) can distribute the updated first data distribution representation and the retrained first artificial neural network model to the device. Through the retraining cycle as described above, the first encrypted data set, which is offline data used for the initial training, is continuously updated based on data acquired from the device, and the artificial neural network model is continuously retrained according to the update of the training data, and the retrained artificial neural network model is distributed to the device again. Therefore, the performance of the model can be gradually improved without performing training of the artificial neural network model on a device with limited hardware, and at the same time, the data transmitted between the device and the computing device (100) of the server is encrypted data that does not contain personal information, so the purpose of personal information protection can also be achieved.

[0056]

[0057] According to one embodiment of the present disclosure, the memory (130) may include at least one type of storage medium among a flash memory type, a hard disk type, a multimedia card micro type, a card type memory (e.g., SD or XD memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a magnetic disk, and an optical disk. The computing device (100) may also operate in relation to web storage that performs the storage function of the memory (130) on the internet. The description of the above-described memory is merely an example, and the present disclosure is not limited thereto.

[0058] The network unit (150) according to one embodiment of the present disclosure can use various wired communication systems such as a public switched telephone network (PSTN), xDSL (x Digital Subscriber Line), RADSL (Rate Adaptive DSL), MDSL (Multi Rate DSL), VDSL (Very High Speed ​​DSL), UADSL (Universal Asymmetric DSL), HDSL (High Bit Rate DSL), and a local area network (LAN).

[0059] In addition, the network unit (150) presented in this specification can use various wireless communication systems such as CDMA (Code Division Multi Access), TDMA (Time Division Multi Access), FDMA (Frequency Division Multi Access), OFDMA (Orthogonal Frequency Division Multi Access), SC-FDMA (Single Carrier-FDMA) and other systems.

[0060] In the present disclosure, the network unit (150) can use any type of wired or wireless communication system.

[0061] The techniques described in this specification can be used in other networks as well as the networks mentioned above.

[0062]

[0063] FIG. 2 is a schematic diagram illustrating a network function according to one embodiment of the present disclosure.

[0064] Throughout this specification, the terms computational model, neural network, network function, and neural network may be used interchangeably. A neural network may be composed of a set of interconnected computational units, generally referred to as nodes. These nodes may also be referred to as neurons. A neural network comprises at least one node. The nodes (or neurons) comprising a neural network may be interconnected by one or more links.

[0065] Within a neural network, one or more nodes connected via links can form a relationship between input nodes and output nodes. The concept of input nodes and output nodes is relative, meaning that any node that is in an output node relationship with one node can also be in an input node relationship with another node, and vice versa. As described above, the relationship between input nodes and output nodes can be created based on links. One input node can be connected to one or more output nodes via links, and vice versa.

[0066] In a relationship between input nodes and output nodes connected through a single link, the data of the output node can have its value determined based on the data input to the input node. Here, the link interconnecting the input nodes and output nodes can have a weight. The weight can be variable and can be varied by the user or an algorithm so that the neural network can perform a desired function. For example, when one or more input nodes are interconnected to one output node through each link, the output node can determine the output node value based on the values ​​input to the input nodes connected to the output node and the weight set on the link corresponding to each input node.

[0067] As described above, a neural network is a network in which one or more nodes are interconnected through one or more links, forming input and output node relationships within the network. The characteristics of a neural network can be determined based on the number of nodes and links within the network, the relationships between the nodes and links, and the weights assigned to each link. For example, if two neural networks have the same number of nodes and links but different weight values ​​for the links, the two neural networks can be perceived as different from each other.

[0068] A neural network can be composed of a set of one or more nodes. A subset of the nodes comprising the neural network can form a layer. Some of the nodes comprising the neural network can form a layer based on their distances from the initial input node. For example, a set of nodes that are n distances from the initial input node can form n layers. The distance from the initial input node can be defined by the minimum number of links required to reach the node from the initial input node. However, this definition of a layer is arbitrary for illustrative purposes, and the degree of a layer within a neural network can be defined in a different way than described above. For example, a layer of nodes can be defined by its distance from the final output node.

[0069] An initial input node may refer to one or more nodes within a neural network into which data is directly input without going through links with other nodes. Alternatively, within a neural network, it may refer to nodes that do not have other input nodes connected by links in the relationship between nodes based on links. Similarly, a final output node may refer to one or more nodes within a neural network that do not have output nodes in their relationship with other nodes. Furthermore, a hidden node may refer to nodes that constitute a neural network other than the initial input node and the final output node.

[0070] A neural network according to one embodiment of the present disclosure may be a neural network in which the number of nodes in an input layer may be the same as the number of nodes in an output layer, and the number of nodes decreases and then increases as it progresses from the input layer to the hidden layer. In addition, a neural network according to another embodiment of the present disclosure may be a neural network in which the number of nodes in an input layer may be less than the number of nodes in an output layer, and the number of nodes decreases as it progresses from the input layer to the hidden layer. In addition, a neural network according to another embodiment of the present disclosure may be a neural network in which the number of nodes in an input layer may be greater than the number of nodes in an output layer, and the number of nodes increases as it progresses from the input layer to the hidden layer. A neural network according to another embodiment of the present disclosure may be a neural network in a combined form of the neural networks described above.

[0071] A deep neural network (DNN) can refer to a neural network that includes multiple hidden layers in addition to input and output layers. Using DNNs, one can identify latent structures in data. For example, one can identify the latent structures of images, text, videos, audio, and music (e.g., what objects are in the image, what the content and emotion of the text are, what the content and emotion of the audio are, etc.). DNNs can include convolutional neural networks (CNNs), recurrent neural networks (RNNs), autoencoders, generative adversarial networks (GANs), restricted Boltzmann machines (RBMs), deep belief networks (DBNs), Q networks, U networks, Siamese networks, and generative adversarial networks (GANs). The description of the deep neural network described above is only an example and the present disclosure is not limited thereto.

[0072] In one embodiment of the present disclosure, the network function may include an autoencoder. An autoencoder may be a type of artificial neural network that outputs output data similar to input data. The autoencoder may include at least one hidden layer, and an odd number of hidden layers may be arranged between input and output layers. The number of nodes in each layer may be reduced from the number of nodes in the input layer to an intermediate layer called a bottleneck layer (encoding), and then expanded symmetrically from the bottleneck layer to the output layer (symmetrical to the input layer). The autoencoder may perform nonlinear dimensionality reduction. The number of input layers and output layers may correspond to the dimensionality after preprocessing of the input data. In the autoencoder structure, the number of nodes in the hidden layer included in the encoder may have a structure in which the number of nodes decreases as it moves away from the input layer. The number of nodes in the bottleneck layer (the layer with the fewest nodes between the encoder and decoder) may be kept above a certain number (e.g., more than half of the input layer), as too few nodes may not transmit enough information.

[0073] Neural networks can learn using at least one of the following methods: supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning. Neural network learning can be the process of applying knowledge to the neural network to perform a specific action.

[0074] Neural networks can be trained to minimize output errors. This process involves repeatedly inputting training data into the neural network, calculating the neural network output and target error for the training data, and backpropagating the neural network error from the output layer to the input layer to update the weights of each node in the neural network to reduce the error. Supervised learning uses training data with the correct answer labeled for each training data (i.e., labeled training data). Unsupervised learning, on the other hand, may not have the correct answer labeled for each training data. For example, in the case of supervised learning for data classification, the training data may be data with each category labeled. Labeled training data is input to the neural network, and the error can be calculated by comparing the output (category) of the neural network with the training data labels. Alternatively, in the case of unsupervised learning for data classification, the error can be calculated by comparing the input training data with the neural network output. The calculated error is backpropagated in the neural network in the backward direction (i.e., from the output layer to the input layer), and the connection weights of each node in each layer of the neural network can be updated according to the backpropagation. The amount of change in the connection weights of each node to be updated can be determined by the learning rate. The neural network's calculation of the input data and the backpropagation of the error can constitute a learning cycle (epoch). The learning rate can be applied differently depending on the number of iterations of the neural network's learning cycle. For example, a high learning rate can be used in the early stages of neural network training to quickly achieve a certain level of performance, thereby increasing efficiency. A lower learning rate can be used in the later stages of training to increase accuracy.

[0075] In neural network training, training data can typically be a subset of real-world data (i.e., the data to be processed using the trained neural network). Therefore, there can be a learning cycle where errors on the training data decrease but errors on the real-world data increase. Overfitting is a phenomenon where excessive training on the training data leads to increased errors on the real-world data. For example, a neural network trained on yellow cats may fail to recognize cats when shown non-yellow colors, a type of overfitting. Overfitting can increase errors in machine learning algorithms. Various optimization methods can be used to prevent overfitting. These methods include increasing the training data, regularization, dropout, which disables some nodes in the network during the learning process, and the use of batch normalization layers.

[0076]

[0077] FIG. 3 is a flowchart illustrating a retraining process of a posture estimation model for personal information protection according to one embodiment of the present disclosure. According to one embodiment of the present disclosure, the retraining process of a posture estimation model for personal information protection may include a step of generating a first encrypted data set and a first data distribution representation based on a first data set (S110), a step of performing training of a first artificial neural network model based on the first encrypted data set (S120), a step of distributing the trained first artificial neural network model and the first data distribution representation to a device (S130), a step of receiving a second encrypted data set generated based on a second data set newly input to the device (S140), a step of updating the first encrypted data set based on the second encrypted data set (S150), and a step of performing retraining of the first artificial neural network model based on the updated first encrypted data set.

[0078] In step S110, the processor (110) can generate a first encrypted data set and a first data distribution representation based on the first data set. The first encrypted data set and the first data distribution representation have been described above with reference to FIG. 1.

[0079] In step S120, the processor (110) can perform learning of the first artificial neural network model based on the first encrypted data set.

[0080] In step S130, the processor (110) can distribute the learned first artificial neural network model and the first data distribution representation to the device.

[0081] In step S140, the processor (110) can receive a second encrypted data set generated based on a second data set newly input to the device.

[0082] In step S150, the processor (110) can update the first encrypted data set based on the second encrypted data set.

[0083] In step S160, the processor (110) can perform retraining of the first artificial neural network model based on the updated first encrypted data set.

[0084]

[0085] FIG. 4 is a conceptual diagram illustrating a data encryption method according to one embodiment of the present disclosure.

[0086] In the present disclosure, the first data set may include image data (410) including an area corresponding to a person. The processor (110) may obtain encrypted data (430) corresponding to the image data based on homomorphic encryption of the image data (410) included in the first data set. For each image data, the processor (110) may obtain encrypted data and determine a set of encrypted data as the first encrypted data set.

[0087] In another embodiment of the present disclosure, the processor (110) may generate a first skeleton data set based on the first data set. In the present disclosure, the skeleton data set may be data including skeleton data abstracted in the form of a plurality of straight lines that simplify the torso and limbs of a human.

[0088] The processor (110) can input image data (410) included in the first data set into an artificial neural network or use a rule-based method to generate skeleton data (420). In this way, skeleton data (420) can be generated for the entire image data (410), and a first skeleton data set can be configured.

[0089] The processor (110) can generate a first encrypted data set and a first data distribution representation based on the first skeleton data set. When only skeleton data, rather than image data, is used, the model's computation speed and data distribution extraction speed are dramatically increased.

[0090]

[0091] FIG. 5 is a conceptual diagram illustrating the configuration of a server and a device for performing retraining of a posture estimation model for personal information protection according to one embodiment of the present disclosure.

[0092] In the present disclosure, a system for performing retraining of a posture estimation model for privacy protection may include a server (510) and a device (520). Training and retraining of the model are performed on the server (510), and the inference process of the model is performed on the device (520).

[0093] A processor included in the server (510) can generate a first encrypted data set (512) and a first data distribution representation (513) from a first data set (511) which is offline image data.

[0094] A processor included in the server (510) can train a first artificial neural network model (514) using a first encrypted data set (512) as training data.

[0095] Thereafter, the processor included in the server (510) can transmit the first artificial neural network model (514) learned with the initial data and the first data distribution representation (513) to the device (520).

[0096] The processor included in the device (520) can receive a second data set (530) including online data obtained through a camera or the like, and generate a second data distribution representation (523) and a second encrypted data set (524). The first artificial neural network model (522) can be implemented to receive encrypted image data from the device and perform a pose estimation task, as learned from the server.

[0097] The monitoring module (521) included in the device (520) can continuously compare the first data distribution representation and the second data distribution representation at regular time intervals. The processor included in the device (520) can compare the data distribution representations, and if the difference in the representations is greater than or equal to a predetermined threshold, the encrypted data set can be included in the training data set for retraining the neural network model. That is, the processor included in the device (520) can update the second encrypted data set to the server (510) if the difference in the representations is greater than or equal to the predetermined threshold. At this time, the second distribution representation (523) can also be updated to the server (510) like the second encrypted data set.

[0098] The performance of an artificial neural network model trained in the future server (510) can be improved by the first data set updated based on the second encrypted data set and the first distribution representation updated based on the second distribution representation.

[0099]

[0100] Meanwhile, a computer-readable medium storing a data structure according to an embodiment of the present disclosure is disclosed.

[0101] A data structure can refer to the organization, management, and storage of data to enable efficient access and modification. A data structure can refer to the organization of data to solve a specific problem (e.g., data retrieval, data storage, or data modification in the shortest possible time). A data structure can also be defined as the physical or logical relationships between data elements designed to support specific data processing functions. Logical relationships between data elements can include connections between user-defined data elements. Physical relationships between data elements can include actual relationships between data elements physically stored on a computer-readable storage medium (e.g., persistent storage). Specifically, a data structure can include a collection of data, relationships between data, and functions or commands applicable to the data. An effectively designed data structure allows a computing device to perform operations while minimizing the use of its resources. Specifically, a computing device can improve the efficiency of operations, reading, inserting, deleting, comparing, exchanging, and searching through an effectively designed data structure.

[0102] Data structures can be categorized as linear or nonlinear, depending on their form. A linear data structure can be a structure in which only one data item is linked to the next. Linear data structures can include lists, stacks, queues, and deques. A list can refer to a series of data sets with an internal order. Lists can also include linked lists. A linked list is a data structure in which data is linked in a single line, each item having a pointer. In a linked list, a pointer can contain information about the next or previous item. Linked lists can be expressed as singly linked lists, doubly linked lists, or circular linked lists, depending on their form. A stack can be a data listing structure with limited data access. A stack can be a linear data structure in which data operations (e.g., insertion or deletion) can only be performed at one end of the data structure. Data stored in a stack can be a Last-in-First-out (LIFO) data structure. A queue is a data structure with limited access to data. Unlike a stack, it can be a first-in, first-out (FIFO) data structure, with later data being retrieved later. A deck can be a data structure that can process data at both ends.

[0103] A nonlinear data structure can be a structure in which multiple pieces of data are connected behind a single piece of data. Nonlinear data structures can include graph data structures. A graph data structure can be defined by vertices and edges, and an edge can include a line connecting two different vertices. Graph data structures can include tree data structures. A tree data structure can be a data structure in which there is only one path connecting two different vertices among multiple vertices included in the tree. In other words, it can be a data structure that does not form a loop in a graph data structure.

[0104] Throughout this specification, the terms computational model, neural network, network function, and neural network may be used interchangeably. Hereinafter, they are collectively referred to as neural networks. The data structure may include a neural network. And the data structure including the neural network may be stored on a computer-readable medium. The data structure including the neural network may also include preprocessed data for processing by the neural network, data input to the neural network, weights of the neural network, hyperparameters of the neural network, data obtained from the neural network, activation functions associated with each node or layer of the neural network, loss functions for learning the neural network, etc. The data structure including the neural network may include any of the components disclosed above. That is, the data structure including the neural network may be configured to include all or any combination of preprocessed data for processing by the neural network, data input to the neural network, weights of the neural network, hyperparameters of the neural network, data obtained from the neural network, activation functions associated with each node or layer of the neural network, loss functions for learning the neural network, etc. In addition to the aforementioned configurations, a data structure including a neural network may include any other information that determines the characteristics of the neural network. Furthermore, the data structure may include any form of data used or generated in the computational process of the neural network, and is not limited to the aforementioned. The computer-readable medium may include a computer-readable recording medium and / or a computer-readable transmission medium. A neural network may be composed of a set of interconnected computational units, which may generally be referred to as nodes. These nodes may also be referred to as neurons. A neural network is composed of at least one node.

[0105] The data structure may include data input to a neural network. The data structure including the data input to the neural network may be stored on a computer-readable medium. The data input to the neural network may include training data input during the neural network training process and / or input data input to the neural network after training has been completed. The data input to the neural network may include data that has undergone preprocessing and / or data that is the target of preprocessing. Preprocessing may include a data processing process for inputting data to the neural network. Accordingly, the data structure may include data that is the target of preprocessing and data generated by the preprocessing. The above-described data structure is merely an example, and the present disclosure is not limited thereto.

[0106] The data structure may include weights of a neural network. The data structure including the weights of the neural network may be stored on a computer-readable medium. The neural network may include a plurality of weights. The weights may be variable and may be varied by a user or an algorithm so that the neural network can perform a desired function. For example, when one or more input nodes are interconnected to an output node by respective links, the output node may determine a data value output from the output node based on the values ​​input to the input nodes connected to the output node and the weights set for the links corresponding to each input node. The above-described data structure is merely an example, and the present disclosure is not limited thereto.

[0107] By way of example and not limitation, the weights may include weights that vary during the neural network training process and / or weights that have completed neural network training. The weights that vary during the neural network training process may include weights at the start of the training cycle and / or weights that vary during the training cycle. The weights that have completed neural network training may include weights that have completed the training cycle. Accordingly, a data structure including the weights of a neural network may include a data structure including weights that vary during the neural network training process and / or weights that have completed neural network training. Therefore, the above-described weights and / or combinations of each weight are included in the data structure including the weights of a neural network. The above-described data structures are merely examples and the present disclosure is not limited thereto.

[0108] A data structure including neural network weights can be stored in a computer-readable storage medium (e.g., memory, hard disk) after going through a serialization process. Serialization can be a process of converting a data structure into a form that can be stored on the same or different computing devices and later reconstructed and used. A computing device can serialize the data structure to transmit and receive data over a network. The serialized data structure including neural network weights can be reconstructed on the same or different computing devices through deserialization. The data structure including neural network weights is not limited to serialization. Furthermore, the data structure including neural network weights can include a data structure that increases computational efficiency while minimizing the use of computing device resources (e.g., a B-Tree, a Trie, an m-way search tree, an AVL tree, a Red-Black Tree in nonlinear data structures). The foregoing is merely an example, and the present disclosure is not limited thereto.

[0109] The data structure may include hyperparameters of a neural network. Furthermore, the data structure including the hyperparameters of the neural network may be stored on a computer-readable medium. The hyperparameters may be variables that can be varied by the user. The hyperparameters may include, for example, a learning rate, a cost function, the number of learning cycle repetitions, weight initialization (e.g., setting a range of weight values ​​to be subject to weight initialization), and the number of hidden units (e.g., the number of hidden layers, the number of nodes in the hidden layer). The above-described data structure is merely an example, and the present disclosure is not limited thereto.

[0110]

[0111] FIG. 6 is a simplified, general schematic diagram of an exemplary computing environment in which embodiments of the present disclosure may be implemented.

[0112] Although the present disclosure has been described above as being generally implemented by a computing device, those skilled in the art will appreciate that the present disclosure may be implemented in combination with computer-executable instructions and / or other program modules that may be executed on one or more computers and / or as a combination of hardware and software.

[0113] Generally, program modules include routines, programs, components, data structures, and the like that perform particular tasks or implement particular abstract data types. Furthermore, those skilled in the art will appreciate that the methods of the present disclosure can be implemented with other computer system configurations, including single-processor or multiprocessor computer systems, minicomputers, mainframe computers, as well as personal computers, handheld computing devices, microprocessor-based or programmable consumer electronics, and the like, each of which may be operatively connected to one or more associated devices.

[0114] The described embodiments of the present disclosure can also be practiced in distributed computing environments, where certain tasks are performed by remote processing devices that are linked through a communications network. In a distributed computing environment, program modules may be located in both local and remote memory storage devices.

[0115] Computers typically include a variety of computer-readable media. Computer-readable media can be any media that can be accessed by a computer, and includes both volatile and nonvolatile media, transitory and non-transitory media, removable and non-removable media. By way of example, and not limitation, computer-readable media can include computer-readable storage media and computer-readable transmission media. Computer-readable storage media includes both volatile and nonvolatile media, transitory and non-transitory media, removable and non-removable media implemented in any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. Computer-readable storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital video disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be accessed by a computer and used to store the desired information.

[0116] Computer-readable transmission media typically includes any information delivery media that embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal, such as a carrier wave or other transport mechanism. The term modulated data signal means a signal that has one or more of its characteristics set or changed so as to encode information in the signal. By way of example, and not limitation, computer-readable transmission media includes wired media, such as a wired network or direct-wired connection, and wireless media, such as acoustic, RF, infrared, or other wireless media. Combinations of any of the above are also intended to be included within the scope of computer-readable transmission media.

[0117] An exemplary environment (1100) implementing various aspects of the present disclosure is illustrated, including a computer (1102) comprising a processing unit (1104), system memory (1106), and a system bus (1108). The system bus (1108) connects system components, including but not limited to the system memory (1106), to the processing unit (1104). The processing unit (1104) may be any of a variety of commercially available processors. Dual processors and other multiprocessor architectures may also be utilized as the processing unit (1104).

[0118] The system bus (1108) may be any of several types of bus structures that may be additionally interconnected to a memory bus, a peripheral bus, and a local bus using any of a variety of commercial bus architectures. The system memory (1106) includes read-only memory (ROM) (1110) and random access memory (RAM) (1112). A basic input / output system (BIOS) is stored in non-volatile memory (1110), such as ROM, EPROM, or EEPROM, and includes basic routines that help transfer information between components within the computer (1102), such as during start-up. The RAM (1112) may also include high-speed RAM, such as static RAM, for caching data.

[0119] The computer (1102) also includes an internal hard disk drive (HDD) (1114) (e.g., EIDE, SATA) - which may also be configured for external use within a suitable chassis (not shown), a magnetic floppy disk drive (FDD) (1116) (e.g., for reading from or writing to a removable diskette (1118)), and an optical disk drive (1120) (e.g., for reading from or writing to a CD-ROM disk (1122) or other high-capacity optical media such as a DVD). The hard disk drive (1114), the magnetic disk drive (1116), and the optical disk drive (1120) may be connected to the system bus (1108) by a hard disk drive interface (1124), a magnetic disk drive interface (1126), and an optical drive interface (1128), respectively. The interface (1124) for implementing an external drive includes at least one or both of Universal Serial Bus (USB) and IEEE 1394 interface technologies.

[0120] These drives and their associated computer-readable media provide non-volatile storage of data, data structures, computer-executable instructions, and the like. In the case of the computer (1102), the drives and media correspond to storing any data in a suitable digital format. While the description of computer-readable media above refers to HDDs, removable magnetic disks, and removable optical media such as CDs or DVDs, those skilled in the art will appreciate that other types of media readable by a computer, such as zip drives, magnetic cassettes, flash memory cards, cartridges, and the like, may also be used in the exemplary operating environment, and that any such media may contain computer-executable instructions for performing the methods of the present disclosure.

[0121] A number of program modules, including an operating system (1130), one or more application programs (1132), other program modules (1134), and program data (1136), may be stored in the drive and RAM (1112). All or portions of the operating system, applications, modules, and / or data may also be cached in RAM (1112). It will be appreciated that the present disclosure may be implemented in various commercially available operating systems or combinations of operating systems.

[0122] A user may enter commands and information into the computer (1102) via one or more wired / wireless input devices, such as a keyboard (1138) and a pointing device such as a mouse (1140). Other input devices (not shown) may include a microphone, an IR remote control, a joystick, a game pad, a stylus pen, a touch screen, and the like. These and other input devices are often connected to the processing unit (1104) via an input device interface (1142) that is connected to the system bus (1108), but may be connected by other interfaces such as a parallel port, an IEEE 1394 serial port, a game port, a USB port, an IR interface, and the like.

[0123] A monitor (1144) or other type of display device is also connected to the system bus (1108) via an interface, such as a video adapter (1146). In addition to the monitor (1144), the computer typically includes other peripheral output devices (not shown), such as speakers, a printer, and so on.

[0124] The computer (1102) may operate in a networked environment using logical connections to one or more remote computers, such as remote computer(s) (1148), via wired and / or wireless communications. The remote computer(s) (1148) may be a workstation, a computing device computer, a router, a personal computer, a portable computer, a microprocessor-based entertainment device, a peer device, or other conventional network node, and generally include many or all of the components described for the computer (1102), although for simplicity, only the memory storage device (1150) is shown. The logical connections shown include wired / wireless connections to a local area network (LAN) (1152) and / or a larger network, such as a wide area network (WAN) (1154). Such LAN and WAN networking environments are common in offices and companies and facilitate enterprise-wide computer networks, such as intranets, all of which may be connected to a worldwide computer network, such as the Internet.

[0125] When used in a LAN networking environment, the computer (1102) is connected to a local network (1152) via a wired and / or wireless communication network interface or adapter (1156). The adapter (1156) may facilitate wired or wireless communications to the LAN (1152), which may also include a wireless access point installed therein for communicating with the wireless adapter (1156). When used in a WAN networking environment, the computer (1102) may include a modem (1158), be connected to a communications computing device on the WAN (1154), or have other means of establishing communications over the WAN (1154), such as via the Internet. The modem (1158), which may be internal or external and wired or wireless, is connected to the system bus (1108) via a serial port interface (1142). In a networked environment, program modules or portions thereof described for the computer (1102) may be stored in a remote memory / storage device (1150). It will be appreciated that the network connections depicted are exemplary and other means of establishing a communications link between the computers may be used.

[0126] The computer (1102) operates to communicate with any wireless device or object that is arranged and operates via wireless communication, such as a printer, a scanner, a desktop and / or portable computer, a portable data assistant (PDA), a communication satellite, any equipment or location associated with a radio-detectable tag, and a telephone. This includes at least Wi-Fi and Bluetooth wireless technologies. Accordingly, the communication may be a predefined structure as in a conventional network, or may simply be an ad hoc communication between at least two devices.

[0127] Wi-Fi (Wireless Fidelity) enables connections to the Internet and other devices without wires. Wi-Fi is a wireless technology that allows devices, such as computers, to send and receive data anywhere within the coverage area of ​​a base station, both indoors and outdoors, similar to cell phones. Wi-Fi networks use wireless technologies called IEEE 802.11 (a, b, g, etc.) to provide secure, reliable, and high-speed wireless connections. Wi-Fi can be used to connect computers to each other, to the Internet, and to wired networks (using IEEE 802.3 or Ethernet). Wi-Fi networks can operate in the unlicensed 2.4 and 5 GHz radio bands, at data rates of, for example, 11 Mbps (802.11a) or 54 Mbps (802.11b), or in products that include both bands (dual-band).

[0128] Those skilled in the art will appreciate that information and signals may be represented using any of a variety of different technologies and techniques. For example, the data, instructions, commands, information, signals, bits, symbols, and chips referenced in the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.

[0129] Those skilled in the art will appreciate that the various illustrative logical blocks, modules, processors, means, circuits, and algorithm steps described in connection with the embodiments disclosed herein may be implemented as electronic hardware, various forms of programs or design code (referred to herein, for convenience, as software), or a combination of both. To clearly illustrate this interchangeability of hardware and software, various illustrative components, blocks, modules, circuits, and steps have been described above generally in terms of their functionality. Whether such functionality is implemented as hardware or software depends upon the particular application and design constraints imposed on the overall system. Those skilled in the art may implement the described functionality in varying ways for each particular application, but such implementation decisions should not be interpreted as causing a departure from the scope of the present disclosure.

[0130] The various embodiments presented herein can be implemented as a method, apparatus, or article of manufacture using standard programming and / or engineering techniques. The term article of manufacture includes a computer program, carrier, or media accessible from any computer-readable storage device. For example, computer-readable storage media include, but are not limited to, magnetic storage devices (e.g., hard disks, floppy disks, magnetic strips, etc.), optical disks (e.g., CDs, DVDs, etc.), smart cards, and flash memory devices (e.g., EEPROMs, cards, sticks, key drives, etc.). Furthermore, various storage media presented herein include one or more devices and / or other machine-readable media for storing information.

[0131] It should be understood that the specific order or hierarchy of steps in the presented processes is merely an example of exemplary approaches. It should be understood that the specific order or hierarchy of steps in the processes may be rearranged within the scope of the present disclosure based on design priorities. The appended method claims provide elements of various steps in a sample order, but are not intended to be limited to the specific order or hierarchy presented.

[0132] The description of the disclosed embodiments is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments without departing from the scope of the present disclosure. Therefore, the present disclosure is not intended to be limited to the embodiments disclosed herein, but is to be construed in the broadest scope consistent with the principles and novel features disclosed herein.

[0133] As described above, the relevant contents have been described in the best form for carrying out the invention.

Claims

1. A method performed on a computing device for retraining a detailed estimation model for privacy protection, A step of generating a first encrypted data set and a first data distribution representation based on the first data set; A step of performing learning of a first artificial neural network model based on the first encrypted data set; A step of distributing the learned first artificial neural network model and the first data distribution representation to a device; A step of receiving a second encrypted data set generated based on a second data set newly input to the device; a step of updating the first encrypted data set based on the second encrypted data set; and A step of performing retraining of the first artificial neural network model based on the updated first encrypted data set; Including, method.

2. In paragraph 1, The above first artificial neural network model includes an artificial neural network model that generates information related to pose estimation based on encrypted image data. method.

3. In paragraph 1, The above first data set includes offline data acquired for learning or verifying an artificial neural network model, The above first encrypted data set includes data encrypted based on homomorphic encryption of data included in the first data set. method.

4. In paragraph 1, The second data set includes online data newly acquired from the device for inference of an artificial neural network model, The second encrypted data set includes data encrypted based on homomorphic encryption of data included in the second data set. method.

5. In paragraph 1, The step of receiving a second encrypted data set generated based on a second data set newly input to the above device comprises: In the above device, a step of generating a second encrypted data set and a second data distribution representation based on the second data set; and A step of receiving the second encrypted data set based on comparing the first data distribution representation and the second data distribution representation in the device; Including, method.

6. In paragraph 5, The step of receiving the second encrypted data set based on comparing the first data distribution representation and the second data distribution representation in the device comprises: A step of receiving the second encrypted data set when the difference between the first data distribution representation and the second data distribution representation is greater than or equal to a predetermined threshold value; Including, method.

7. In paragraph 5, The step of generating a first encrypted data set and a first data distribution representation based on the first data set comprises: A step of generating a first skeleton data set based on the first data set; and A step of generating a first encrypted data set and a first data distribution representation based on the first skeleton data set; Including, method.

8. In paragraph 7, In the above device, a step of generating a second encrypted data set and a second data distribution representation based on the second data set is; In the above device, a step of generating a second skeleton data set based on the second data set; and A step of generating a second encrypted data set and a second data distribution representation based on the second skeleton data set; Including, method.

9. In paragraph 5, The method comprises the steps of: receiving the second data distribution representation from the device; A step of updating the first data distribution representation based on the second data distribution representation; and A step of deploying the updated first data distribution representation and the retrained first artificial neural network model to the device; Including more, method.

10. A computer program stored in a computer-readable storage medium that causes a computing device to perform operations for retraining a posture estimation model for personal information protection, the operations comprising: An operation of generating a first encrypted data set and a first data distribution representation based on the first data set; An operation of performing learning of a first artificial neural network model based on the first encrypted data set; An operation of deploying the learned first artificial neural network model and the first data distribution representation to a device; An operation of receiving a second encrypted data set generated based on a second data set newly input to the device; An operation of updating the first encrypted data set based on the second encrypted data set; and An operation of performing retraining of the first artificial neural network model based on the updated first encrypted data set; Including, A computer program stored on a computer-readable storage medium.

11. As a computing device for retraining a detailed estimation model for privacy protection. one or more processors; and memory; Including, One or more of the above processors, Generate a first encrypted data set and a first data distribution representation based on the first data set, Training of a first artificial neural network model is performed based on the first encrypted data set, Deploying the learned first artificial neural network model and the first data distribution representation to the device, Receive a second encrypted data set generated based on a second data set newly input to the device, Update the first encrypted data set based on the second encrypted data set, and Based on the updated first encrypted data set, retraining of the first artificial neural network model is performed. Computing device.

Citation Information

Patent Citations

  • federated learning method and device for statistical model

    KR102485748B1

  • Fence for preventing suicide

    KR102578426B1

  • Adaptive distributed learning model optimization for performance prediction under data privacy constraints

    US20220101178A1

  • Privacy-preserving machine learning training based on homomorphic encryption using executable file packages in an untrusted environment

    US20230025754A1

  • Information processing apparatus, information processing method, program and information processing terminal

    US20230182747A1