节点文献

基于BP神经网络的双重差分隐私保护算法

Double Differential Privacy Protection Algorithm Based on BP Neural Network

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 张晓琴; 琚晓颖; 米子川; 李师毅;

【Author】 Zhang Xiaoqin;Ju Xiaoying;Mi Zichuan;Li Shiyi;School of Statistics, Shanxi University of Finance & Economics;School of Mathematics and Statistics, Shanxi University;School of Computer and Information Technology, Shanxi University;

【通讯作者】 米子川;

【机构】 山西财经大学统计学院; 山西大学数学与统计学院; 山西大学计算机与信息技术学院;

【摘要】 随着数据挖掘技术的不断发展,数据中潜藏的信息可以给各个领域带来巨大的价值,但利用模型进行预测时往往存在用户敏感信息泄露的风险.针对神经网络在训练过程中所存在的敏感数据泄露问题,提出了一种具有双重差分隐私保护的BP神经网络改进算法BP-DDP.该算法在网络训练过程中引入差分隐私理论,对损失函数添加符合一定隐私预算的高斯噪声,并在对梯度进行修正后添加Laplace噪声,从而实现隐私保护,最后与传统的BP神经网络进行对比实验.实验结果表明,当添加噪声规模较小时,BP神经网络在保护隐私前提下仍然具有较好的多分类性能.

【Abstract】 With the continuous development of data mining, the information hidden within data can bring immense value across various fields, but there is always the risk of user sensitive information leakage when using the model for prediction. Aiming at the problem of sensitive data leakage in the training process of neural networks, this paper proposed an improved BP neural network algorithm with differential and dual privacy protection, named BP-DDP. In this method, the difference privacy theory was introduced in the process of network training, and Gaussian noise conforming to a certain privacy budget was added to the loss function, and Laplace noise was added after the gradient is corrected, so as to achieve privacy protection. Finally, the experiment is compared with the traditional BP neural network. The experimental results show that the BP neural network still has good multi-classification performance under the premise of privacy protection when the added noise scale is small.

【基金】 国家社会科学基金重大项目(24&ZD183);国家自然科学基金项目(82274360);教育部人文社会科学研究项目(22YJAZH092);山西省基础研究计划项目(202303021221054,202403021211086);山西省回国留学人员科研资助项目(2024-002)
  • 【文献出处】 信息安全研究 ,Journal of Information Security Research , 编辑部邮箱 ,2025年09期
  • 【分类号】TP183;TP309
  • 【下载频次】144
节点文献中: 

本文链接的文献网络图示:

本文的引文网络