| CPC G06F 21/602 (2013.01) [G06N 20/00 (2019.01)] | 20 Claims | 

| 
               1. A data protection method, wherein the method comprises: 
            obtaining a specified batch of reference samples of an active participant of a joint training model, wherein the specified batch of reference samples of the active participant includes a first reference sample and a second reference sample, target encryption identification information corresponding to the first reference sample is not target encryption identification information of the active participant, target encryption identification information corresponding to the second reference sample is the target encryption identification information of the active participant, and the target encryption identification information is obtained by encrypting according to a key of the active participant and a key of a passive participant of the joint training model; 
                determining generation gradient information of the first reference sample, wherein the generation gradient information is determined according to at least one of the following information items: actual gradient information of the second reference sample, generation label information of the first reference sample, and feature information of a specified batch of reference samples of the passive participant; 
                determining target gradient information sent to the passive participant according to the generation gradient information, and sending the target gradient information to the passive participant, to update, by the passive participant, parameters of the joint training model according to the target gradient information. 
               |