User Information Purge in Learning Devices via Selective Forgetting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for protecting user privacy in systems processing user information, such as those in the 'Internet of Things' and healthcare, often result in loss of precision due to suppression or deletion of data, and existing anonymization techniques fail to effectively manage user information while maintaining privacy.

Innovation Solution

A method and device that purge user information from machine learners and user models by providing only data that adheres to predefined rules, allowing for selective deletion and retraining of models to suppress the influence of user information, using techniques like concept drift correction and ensemble methods to adapt machine learners and user models.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If user information is suppressed or deleted before processing by a machine learner, then user privacy is protected, but the precision and accuracy of the machine learner deteriorates

Engineering Contradiction:
Improveuser privacy protectionVSAvoidmachine learner precision
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The patent segments the machine learning process into multiple stages: initial training with user information, operation phase, and forgetting phase. The user information is processed in a controlled manner through these segments, allowing privacy protection at specific stages while maintaining learning precision during others. The forgetting process itself is segmented into identifying, training, and evaluating sub-stages.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by pre-training the machine learner with user information before actual operation, then preparing a forgetting mechanism in advance. The system pre-identifies which user information should be forgotten and pre-trains alternative models, so that when forgetting is needed, the transition is smooth and precision is maintained.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If user information is anonymized with random data, then user privacy is protected, but the ability to associate findings with users is lost

Engineering Contradiction:
Improveuser privacy protectionVSAvoiduser association capability
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The patent implements dynamic control over user information retention and forgetting. Instead of static anonymization, the system dynamically adjusts what user information is retained or forgotten based on user preferences, regulatory requirements, and operational context. This allows flexible association capability while maintaining privacy protection when needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes parameters of user information processing by adjusting the forgetting factor, training data composition, and model architecture parameters. These parameter changes allow the system to transition between states of high user association capability and high privacy protection without permanent loss of information.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If distributed machine learners are used to generate encrypted results, then user privacy is protected, but system complexity increases

Engineering Contradiction:
Improveuser privacy protectionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent introduces a central management unit as an intermediary that coordinates distributed machine learners. This intermediary handles the complex tasks of distributing forgetting instructions, collecting results, and managing the overall forgetting process, thereby reducing the complexity burden on individual distributed learners while maintaining privacy protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Object-affected harmful factors

If machine learners are completely retrained to remove user information influence, then user information is purged from models, but training time and computational resources increase

Engineering Contradiction:
Improveuser information removalVSAvoidretraining time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent applies partial action by implementing selective forgetting rather than complete retraining. The system identifies and forgets only the specific user information that needs to be removed, while retaining other useful learned patterns. This partial forgetting approach significantly reduces training time and computational resources compared to complete retraining, while still achieving the goal of purging unwanted user information.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system discards specific user information influences from the machine learner through targeted forgetting processes, while recovering and retaining other valuable learned patterns. This selective discarding and recovering mechanism allows efficient removal of unwanted information without losing overall model competence.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS11580252B2Method for controlling user information in an automatically learning device
Publication Date: 2023.02.14 ROBERT BOSCH GMBH
  • US11580252B2 patent drawing
  • US11580252B2 patent drawing

AI summary

A method in which user information is transmitted from at least one data source to a processing unit of a learning device. The user information is used, by the processing unit via a machine learner, to generate at least one user model. The at least one user model is adapted via an adaptation of parameters used by the at least one machine learner to generating the at least one user model. The parameters, used by the at least one machine learner for generating the at least one user model, are adapted as a function of at least one predefined rule. The user model generated on the basis of the adapted parameters is used to personalize at least one terminal.