无人机通信中的矩阵差分隐私保护方法
网络出版日期: 2025-03-19
基金资助
国家自然科学基金(62402302);上海市“科技创新行动计划”自然科学基金(24ZR1422200);上海市白玉兰人才计划浦江项目(24PJD032)
版权
Matrix differential privacy protection technology in UAV communications
Online published: 2025-03-19
Copyright
无人机(Unmanned Aerial Vehicle,UAV)在采集和传输感知数据时,面临数据泄露和恶意攻击的风险。差分隐私技术是一种能够在通信过程中提供隐私安全保护的方法。然而,传统的差分隐私机制在处理无人机通信中的高维或复杂数据时,存在隐私保护效果差和数据效用损失的问题。为了解决这些问题,提出了一种新型矩阵差分隐私保护方法——矩阵高斯机制(Matrix Gaussian Mechanism,MGM)。MGM通过引入结构化噪声,在矩阵数据中提供隐私保护,同时利用矩阵协方差结构控制噪声的添加方向,以最小化数据效用的损失。与传统方法相比,MGM能够更灵活地调节噪声分布,提高隐私保护效能,并在多维数据空间中保持数据的结构特征。实验结果证明,所提方法能够有效保护数据隐私,同时提升无人机的通信效率以及模型训练的适应性与可扩展性。
杨军港 , 孔浩 . 无人机通信中的矩阵差分隐私保护方法[J]. 网络空间安全科学学报, 2025 , 3(1) : 42 -51 . DOI: 10.20172/j.issn.2097-3136.250104
Unmanned aerial vehicle (UAV) faces the risk of data leakage and malicious attacks when collecting and transmitting data. Differential privacy technology can provide privacy protection in the communication process. However, the traditional differential privacy mechanism has the problem of poor privacy protection and data utility loss when dealing with the high dimensional or complex data in UAV communications. To solve these problems, a novel matrix differential privacy protection method named matrix Gaussian mechanism (MGM) was proposed. MGM provided privacy protection in matrix data by introducing structured noise, while using matrix covariance structure to control the direction of noise addition to minimize the data utility loss. Compared with the traditional methods, MGM could adjust the noise distribution more flexibly, improve the efficiency of privacy protection, and maintain the structural characteristics of data in the multidimensional data space. Experimental results showed that the proposed method could effectively protect data privacy with improving the efficiency of UAV communications as well as the adaptability and scalability of model training.
表 1 垂直联邦学习中的差分隐私保护设置Table 1 Differential privacy settings in vertical federated learning |
| 参数 | 数据集 | ||
| MNIST | CIFAR10 | IMDB | |
| 模型 | LeNet | ResNet-18 | LSTM |
| 训练集大小 | 55 000 | 50 000 | 25 000 |
| 测试集大小 | 5 000 | 10 000 | 25 000 |
| 限幅值 | 0.01 | 0.05 | 0.30 |
| 批大小 | 64 | 16 | 256 |
| 轮次 | 25 | 50 | 10 |
| 本地轮次 | 3 | 3 | 2 |
| 梯度形状 | 120×400 | 4 608×512 | 20 002×128 |
表 2 MGM与基线方法之间的理论误差比较Table 2 Comparison of theoretical errors between MGM and baselines |
| 方法 | Gaussian | MVG | UDN | IDN |
表 3 不同机制的运行时间Table 3 Runtime of different mechanisms |
| 方法 | 运行时间(s) |
| Gaussian | 0.001 64 |
| MVG | 0.511 46 |
| MM | 0.823 23 |
| UDN | 0.002 48 |
| IDN | 0.002 24 |
| 1 |
高骏峤, 周磊, 曹越, 等. 5G无人机安全研究综述[J]. 移动通信, 2023, 47 (1): 59- 64.
GAO J Q, ZHOU L, CAO Y, et al. A survey on 5G UAV security[J]. Mobile Communications, 2023, 47 (1): 59- 64.
|
| 2 |
SHOKRI R,STRONATI M,SONG C,et al. Membership inference attacks against machine learning models[C]//2017 IEEE Symposium on Security and Privacy (SP). Piscataway:IEEE,2017:3-18.
|
| 3 |
ZHANG Y,JIA R,PEI H,et al. The secret revealer:Generative model-inversion attacks against deep neural networks[C]//2020 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Piscataway:IEEE,2020:250-258.
|
| 4 |
DWORK C. A firm foundation for private data analysis[J]. Communications of the ACM, 2011, 54 (1): 86- 95.
|
| 5 |
KAKATI A,LI G. Enhancing secrecy with differential-based framework in UAV communications under dynamic eavesdroppers[C]//2024 9th International Conference on Computer and Communication Systems (ICCCS). Piscataway:IEEE,2024:248-253.
|
| 6 |
SHOKRI R,SHMATIKOV V. Privacy-preserving deep learning[C]//Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security. New York:ACM,2015:1310-1321.
|
| 7 |
ABADI M,CHU A,GOODFELLOW I,et al. Deep learning with differential privacy[C]//Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security. New York:ACM,2016:308-318.
|
| 8 |
PAPERNOT N,ABADI M,ERLINGSSON U,et al. Scalable private learning with PATE[C]//Proceedings of the 6th International Conference on Learning Representations. Vancouver:ICLR,2018:1-34.
|
| 9 |
GENG Q, VISWANATH P. Optimal noise adding mechanisms for approximate differential privacy[J]. IEEE Transactions on Information Theory, 2016, 62 (2): 952- 969.
|
| 10 |
LI C, MIKLAU G, HAY M, et al. The matrix mechanism: Optimizing linear counting queries under differential privacy[J]. The VLDB Journal, 2015, 24 (6): 757- 781.
|
| 11 |
AHMADI S. An overview of next-generation mobile WiMAX technology[J]. IEEE Communications Magazine, 2009, 47 (6): 84- 98.
|
| 12 |
CAO J, MA M, LI H, et al. A survey on security aspects for LTE and LTE-A networks[J]. IEEE Communications Surveys & Tutorials, 2013, 16 (1): 283- 302.
|
| 13 |
ZOHOURIAN A, DADKHAH S, NETO E C P, et al. IoT zigbee device security: A comprehensive review[J]. Internet of Things, 2023, 22, 100791.
|
| 14 |
VAHIDI V,SABERINIA E. A low complexity and bandwidth efficient procedure for OFDM data reconstruction in DSC 5G networks[C]//2018 15th IEEE Annual Consumer Communications & Networking Conference (CCNC). Piscataway:IEEE,2018:1-4.
|
| 15 |
SUDHEESH P G, MOZAFFARI M, MAGARINI M, et al. Sum-rate analysis for high altitude platform (HAP) drones with tethered balloon relay[J]. IEEE Communications Letters, 2017, 22 (6): 1240- 1243.
|
| 16 |
SOMARAJU R, TRUMPF J. Degrees of freedom of a communication channel: Using DOF singular values[J]. IEEE Transactions on Information Theory, 2010, 56 (4): 1560- 1573.
|
| 17 |
BU Z,MAO J,XU S. Scalable and efficient training of large convolutional neural networks with differential privacy[C]//Advances in Neural Information Processing Systems 35. San Diego:NeurIPS,2022:1-12.
|
| 18 |
TRAMÈR F,BONEH D. Differentially private learning needs better features (or much more data)[C]//9th International Conference on Learning Representations. Vienna:ICLR,2021:1-21.
|
| 19 |
WANG B,WU F,LONG Y,et al. DataLens:Scalable privacy preserving training via gradient compression and aggregation[C]//Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. New York:ACM,2021:2146-2168.
|
| 20 |
YU D,ZHANG H,CHEN W,et al. Large scale private learning via low-rank reparametrization[C]//Proceedings of the 38th International Conference on Machine Learning. New York:PMLR,2021:12208-12218.
|
| 21 |
DING J, ERRAPOTU S M, GUO Y, et al. Private empirical risk minimization with analytic gaussian mechanism for healthcare system[J]. IEEE Transactions on Big Data, 2022, 8 (4): 1107- 1117.
|
| 22 |
DE CRISTOFARO E. A critical overview of privacy in machine learning[J]. IEEE Security & Privacy, 2021, 19 (4): 19- 27.
|
| 23 |
YANG J, XIANG L, YU J, et al. Matrix gaussian mechanisms for differentially-private learning[J]. IEEE Transactions on Mobile Computing, 2021, 22 (2): 1036- 1048.
|
| 24 |
CHANYASWAD T,DYTSO A,POOR H V,et al. MVG mechanism:Differential privacy under matrix-valued query[C]//Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security. New York:ACM,2018:230-246.
|
| 25 |
BOYD S,VANDENBERGHE L. Convex optimization[M]. Cambridge:Cambridge University Press,2004.
|
| 26 |
LECUN Y, BOTTOU L, BENGIO Y, et al. Gradient-based learning applied to document recognition[J]. Proceedings of the IEEE, 1998, 86 (11): 2278- 2324.
|
| 27 |
KRIZHEVSKY A,HINTON G,SALAKHUTDINOV R. Learning multiple layers of features from tiny images[R]. Toronto:University of Toronto Technical Report,2009.
|
| 28 |
MAAS A L,DALY R E,PHAM P T,et al. Learning word vectors for sentiment analysis[C]//Proceedings of the 49th Annual Meeting of the Association for Computational Linguistics:Human Language Technologies. Stroudsburg:ACL,2011:142-150.
|
| 29 |
KAIROUZ P, OH S, VISWANATH P. The composition theorem for differential privacy[J]. IEEE Transactions on Information Theory, 2017, 63 (6): 4037- 4049.
|
| 30 |
BEIMEL A,KASIVISWANATHAN S P,NISSIM K. Bounds on the sample complexity for private learning and private data release[C]//Proceedings of the 7th Theory of Cryptography Conference. Berlin:Springer,2010:437-454.
|
| 31 |
DWORK C, ROTH A. The algorithmic foundations of differential privacy[J]. Foundations and Trends in Theoretical Computer Science, 2014, 9 (3-4): 211- 407.
|
/
| 〈 |
|
〉 |