Model training optimization method and device based on information security dimension

By building security and risk training data and iteratively training multimodal big models, the security and compliance problems when generating copywriting by multimodal big models are solved, and efficient copy generation without additional verification is achieved, improving generation capabilities and efficiency.

CN120541519APending Publication Date: 2025-08-26ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510601076.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-09
Publication Date
2025-08-26

AI Technical Summary

Technical Problem

When generating copy, existing multimodal large models are difficult to meet the requirements of richness, security and compliance at the same time, resulting in the need of additional verification modules to consume resources and the verification accuracy is difficult to ensure.

Method used

By constructing security samples and risk sample data, using large models to automatically generate security and risk training data, and using preference learning algorithms to iteratively train multimodal large models to build a second multimodal large model with security and compliance recognition capabilities.

Benefits of technology

It realizes that the security and compliance of the copy can be ensured without additional verification modules when generating copy, improves generation capabilities and efficiency, saves processing resources, and meets users' diversified needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120541519A_ABST
    Figure CN120541519A_ABST
Patent Text Reader

Abstract

The invention provides an information security dimension-based model training optimization method and device, and the method comprises the steps: automatically generating security training data and risk training data needed for training a first multi-modal large model through a first large model according to multi-modal sample data comprising security sample data and risk sample data; furthermore, on the basis of the security training data and the risk training data, a preference learning mode is adopted to carry out iterative training on the first multi-modal large model to obtain a second multi-modal large model with a better copywriting generation capability, and the copywriting content is generated by the second multi-modal large model, so that security and compliance requirements are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of artificial intelligence technology, and in particular to a model training optimization method and device based on information security dimensions. Background Art

[0002] With the continuous development of artificial intelligence (AI) technology, search services based on large language models (LLMs), also known as large models (LMs), have become ubiquitous in various fields. These services can now provide the corresponding results for most searches in daily life and work. Large models are deep learning models trained using large amounts of text data, enabling the understanding and generation of natural language text.

[0003] However, with the diversification of search needs and the continuous improvement of user experience requirements, simple text input and output are no longer sufficient. Therefore, multimodal large language models (MLLMs), also known as multimodal large models (MM-LLMs / MLMs), have been applied to search services. Multimodal large models are an extension of large models. They can simultaneously process data in multiple modalities, such as text and images, to achieve cross-modal data recognition and understanding.

[0004] Applying multimodal large models in search services makes the content of generated copy richer. However, as the content of generated copy continues to enrich, the security requirements for the generated copy content are also constantly increasing to avoid generating offensive, extreme and other inappropriate copy content. Summary of the Invention

[0005] In order to improve the data recognition capabilities of large multimodal models and output text content that meets security and compliance requirements, this manual provides a model training optimization method and device based on the information security dimension.

[0006] In a first aspect, one or more embodiments of the present specification provide a model training optimization method based on the information security dimension, including: reading multimodal sample data, wherein the multimodal sample data includes security sample data and risk sample data; reading a plurality of prompt word templates corresponding to a target copy type, wherein the target copy type is any one of a plurality of copy types corresponding to a target search service, and each prompt word template includes a prompt word pair consisting of a security prompt word and a risk prompt word; based on the multimodal sample data and the plurality of prompt word templates, generating security training data and risk training data corresponding to the target copy type through a first large model; based on the security training data and the risk training data, using a preference learning algorithm to iteratively train the first multimodal large model to obtain a second multimodal large model.

[0007] In an optional embodiment, based on the multimodal sample data and the multiple prompt word templates, security training data and risk training data corresponding to the target copy type are generated through the first large model, including: based on the security sample data in the multimodal sample data and the security prompt words in the multiple prompt word templates, guiding the first large model to generate security training data corresponding to the target copy type; based on the risk sample data in the multimodal sample data and the risk prompt words in the multiple prompt word templates, guiding the first large model to generate risk training data corresponding to the target copy type.

[0008] In an optional embodiment, based on the multimodal sample data and the multiple prompt word templates, security training data and risk training data corresponding to the target copy type are generated by the first large model, including: based on the security sample data in the multimodal sample data and the security prompt words in the multiple prompt word templates, guiding the first large model to generate first training data corresponding to the target copy type; based on the risk sample data in the multimodal sample data and the risk prompt words in the multiple prompt word templates, guiding the first large model to generate second training data corresponding to the target copy type; based on a preset evaluation prompt word template, guiding the second large model to evaluate the accuracy of the first training data and the second training data; and determining the security training data and risk training data based on the evaluation information output by the second large model.

[0009] In an optional embodiment, according to a preset evaluation prompt word template, guiding the second large model to evaluate the accuracy of the first training data and the second training data includes: determining an evaluation dimension and a preset evaluation indicator for the evaluation dimension; according to the preset evaluation prompt word template, the evaluation dimension and the evaluation indicator, guiding the second large model to evaluate the accuracy of the first training data and the second training data under the evaluation dimension.

[0010] In an optional embodiment, the first large model and the second large model are the same or different.

[0011] In an optional embodiment, the method further includes: obtaining preset multimodal test data, wherein the multimodal test data includes safety test data and risk test data; and guiding the second multimodal large model to generate test text according to the multimodal test data and a preset test prompt word template, so as to test the text generation capability of the second multimodal large model.

[0012] In an optional embodiment, after the second multimodal large model generates the test text, it also includes: optimizing the security training data and risk training data according to the test text output by the second multimodal large model; and retraining the first multimodal large model based on the optimized security training data and risk training data.

[0013] In an optional embodiment, the risk sample data includes general risk sample data and risk sample data in a specified scenario.

[0014] On the second aspect, one or more embodiments of the present specification provide a model training optimization device based on the information security dimension, including: a first acquisition module for reading multimodal sample data, wherein the multimodal sample data includes security sample data and risk sample data; a second acquisition module for reading a plurality of prompt word templates corresponding to the target copy type, wherein the target copy type is any one of the plurality of copy types corresponding to the target search service, and each prompt word template includes a prompt word pair consisting of a security prompt word and a risk prompt word; a generation module for generating security training data and risk training data corresponding to the target copy type through a first large model according to the multimodal sample data and the plurality of prompt word templates; a training module for iteratively training the first multimodal large model using a preference learning algorithm according to the security training data and the risk training data to obtain a second multimodal large model.

[0015] On the third aspect, one or more embodiments of this specification provide an electronic device, which includes: a memory for storing a computer program product; a processor for executing the computer program product stored in the memory, and when the computer program product is executed, the above-mentioned model training optimization method based on the information security dimension is implemented.

[0016] In a fourth aspect, one or more embodiments of this specification provide a computer-readable storage medium having computer program instructions stored thereon. When the computer program instructions are executed, the above-mentioned model training optimization method based on the information security dimension is implemented.

[0017] In the model training optimization method provided in one or more embodiments of this specification, based on the first large model and multimodal sample data including security sample data and risk sample data, the security training data and risk training data required for training the first multimodal large model are automatically generated, and a preference learning algorithm is used to train the second multimodal large model based on the security training data and risk sample data. The use of this second multimodal large model can generate copywriting content that meets security and compliance requirements, is more in line with information security needs, and has better applicability.

[0018] In addition, the second large model can also be used to automatically evaluate the data quality of the training data from multiple evaluation dimensions to obtain security training data and risk training data that meet the training requirements, so that the second multimodal large model trained based on the security training data and risk training data has better copywriting generation capabilities. After obtaining the second multimodal large model, the test copy generated by the second multimodal large model can also be automatically tested to verify the copywriting generation capabilities of the second multimodal large model. If it is determined that the test copy generated by the second multimodal large model is not sufficient to meet higher security requirements, the security training data and risk training data can be optimized, and the first multimodal large model can be retrained based on the optimized security training data and risk training data. Finally, a multimodal large model with copywriting generation capabilities that meet higher security requirements is obtained.

[0019] Based on the above, in one or more embodiments of this specification, the security training data and risk training data automatically constructed and evaluated by the large model can automatically filter out invalid data that does not meet the requirements of training data. The multimodal large model trained based on the above security training data and risk training data has better copywriting generation capabilities, and the copywriting content generated by the multimodal large model meets security and compliance requirements. Based on the huge functions of the large model, the entire process does not require the use of a separate functional module to verify the copywriting content, which not only saves a lot of labor costs and improves the overall efficiency of model training, but also provides strong guarantees for the richness and accuracy of the data and the copywriting generation capabilities of the multimodal large model, meeting the service provider's requirements for the security and compliance of the copywriting content. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the technical solutions of one or more embodiments of this specification, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some of one or more embodiments of this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0021] Figure 1A flowchart of a model training optimization method based on the information security dimension provided for one or more embodiments of this specification.

[0022] Figure 2 A flowchart of another model training optimization method based on the information security dimension provided for one or more embodiments of this specification.

[0023] Figure 3 A schematic diagram of the structure of a model training optimization device based on the information security dimension provided in one or more embodiments of this specification.

[0024] Figure 4 A schematic diagram of the structure of an electronic device provided in one or more embodiments of this specification. DETAILED DESCRIPTION

[0025] The present invention will be further described in detail below through the accompanying drawings and examples, through which the features and advantages of the present invention will become more clear and distinct.

[0026] The word "exemplary" is used exclusively herein to mean "serving as an example, example, or illustration." Any embodiment described herein as "exemplary" is not necessarily to be construed as preferred or advantageous over other embodiments. Although various aspects of the embodiments are shown in the drawings, the drawings are not necessarily drawn to scale unless otherwise indicated.

[0027] In addition, the technical features involved in different embodiments of this specification described below can be combined with each other as long as they do not conflict with each other.

[0028] Multimodal Large Language Models (MLLMs), also known as Multimodal Large Models (MM-LLMs / MLMs), are increasingly used in real-world applications because they can process not only natural language text but also multimodal data such as images, graphics, audio, and video, enabling cross-modal data recognition and understanding. They effectively meet diverse user needs. However, as user demands continue to rise, the requirements for content generated by multimodal large models are also becoming increasingly stringent. For example, in search services, users are no longer satisfied with simple text content presented. They also desire a more diverse user experience that is engaging, rich, and interactive, across various application scenarios. This requires multimodal large models to not only efficiently and accurately output content but also be able to generate a variety of content types. Especially for diverse real-world application scenarios, it is crucial to ensure the security and compliance of content while meeting these requirements. This not only impacts user experience but also underpins the success of search services.

[0029] Therefore, in order to ensure that the text output by the multimodal large model meets the requirements of security and compliance, usually, before the text content output by the multimodal large model is displayed to the user, the text content output by the multimodal large model will be verified according to preset rules. Based on this, the text content that passes the verification is output to the user, and the text content that fails the verification is intercepted to ensure that the text content finally presented to the user meets the security and compliance requirements. However, separate verification of the text content requires an independent functional module to complete. This post-processing method not only consumes additional processing resources and affects service efficiency, but also makes it difficult to guarantee the accuracy of the verification results.

[0030] To this end, one or more embodiments of this specification provide a model training optimization method based on the information security dimension. This method automatically constructs training data for training a multimodal large model through a large model. In the process of constructing training data for the large model, invalid data that does not meet the requirements as training data is automatically screened out, and there is no need to use a separate functional module to perform the verification function. This not only saves processing resources and is highly efficient, but also builds rich training data based on the huge functions of the large model, thereby improving the security and compliance of the training data.

[0031] For the purpose of distinction, in one or more embodiments of this specification, the multimodal large model before training is referred to as the first multimodal large model, and the multimodal large model obtained after training is referred to as the second multimodal large model. Accordingly, the large models used in the method to implement different functions are distinguished as the first large model, the second large model, the third large model, etc., wherein the serial numbers such as "first", "second", and "third" are only used to distinguish and identify each large model to perform different functions, and the types of each large model and the relationship between each other are not limited. Optionally, depending on the different functions to be implemented, the types of the first large model, the second large model, and the third large model may be different, or, for large models with general functions, the same large model may be used to implement different functions. The specific method to be adopted can be determined according to actual needs and is not limited here.

[0032] Below, the various method steps of the model training optimization method based on the information security dimension provided by one or more embodiments of this specification are described in conjunction with the accompanying drawings.

[0033] Figure 1 A flowchart of a model training optimization method based on information security dimension provided in one or more embodiments of this specification, such as Figure 1 As shown, the method includes the following steps:

[0034] S102: Read multimodal sample data, where the multimodal sample data includes safe sample data and risk sample data;

[0035] S104: Read multiple prompt word templates corresponding to a target document type, where the target document type is any one of multiple document types corresponding to a target search service, and each prompt word template includes a prompt word pair consisting of a safety prompt word and a risk prompt word;

[0036] S106: Generate security training data and risk training data corresponding to the target copy type using the first model based on the multimodal sample data and multiple prompt word templates;

[0037] S108. Based on the safety training data and the risk training data, a preference learning algorithm is used to iteratively train the first multimodal large model to obtain a second multimodal large model.

[0038] In one or more embodiments of the present specification, in order to construct the training data required for model training of the first multimodal large model, multimodal sample data including safe sample data and risk sample data is first read. The training data constructed based on the above multimodal sample data can be used to train the first multimodal large model's ability to identify the security and risk of data. Safe sample data refers to sample data that meets security and compliance requirements, such as text, images, graphics, audio and video data whose content conforms to social trends, ethics, laws, and regulations. Risk sample data refers to sample data that does not meet security and compliance requirements, such as text, images, graphics, audio and video data containing negative information such as politics, pornography, gambling, drugs, insults, discrimination, and defamation.

[0039] In addition to the general risk sample data in the conventional sense mentioned above, it can also include risk sample data in specified scenarios, where the risk sample data in specified scenarios means that it is not possible to directly determine whether the sample data itself is risk sample data, but when used in a specified scenario, there may be situations that do not meet security and compliance requirements. For example, for sample data containing content such as pigs, dogs, clowns, etc., when it is applied to a scene containing people, it may involve insults, discrimination, etc. For another example, for sample data containing content such as foreign countries, special gestures, symbols or logos, when it is used in a scene containing buildings, especially more solemn buildings such as temples, auditoriums, halls, monuments, etc., it may involve insults, discrimination, political involvement, etc. Therefore, for scenes containing content such as people and buildings, it is necessary to combine the sample data to jointly determine whether the corresponding sample data is risk sample data.

[0040] Of course, the above-mentioned types of designated scenarios and the risk sample data identified in these scenarios are merely illustrative and are not limited to these types in actual applications. Risk sample data identified will vary depending on the specific application scenario and the content of the sample data itself. Accordingly, whether the same sample data is identified as risk sample data in different scenarios depends on the actual situation and will not be elaborated on here.

[0041] In one or more embodiments of this specification, the search service implemented based on the multimodal large model is referred to as a target search service. The target search service may include multiple search modes, and different types of text output after searching for information in different search modes are different. In order to construct the training data required for generating different types of text, in one or more embodiments of this specification, corresponding prompt word templates are pre-constructed for each type of text. Each type of text may correspond to multiple prompt word templates, and each prompt word template includes a prompt word pair consisting of a safety prompt word and a risk prompt word. The contents of the prompt word pairs in different prompt word templates are different, and are used to instruct the first large model to generate safety training data and risk training data corresponding to the corresponding text type in different forms.

[0042] Based on this, for any target copy type among the multiple copy types corresponding to the target search service, multiple prompt word templates corresponding to the target copy type can be read. Then, based on the obtained multimodal sample data and the multiple prompt word templates corresponding to the read target copy type, security training data and risk training data corresponding to the target copy type are generated through the first large model. Furthermore, based on the security training data and risk training data, the first multimodal large model is iteratively trained using a preference learning algorithm to obtain a second multimodal large model. Since the training data includes both security training data and risk training data, the trained second multimodal large model has the ability to identify the security and risk of data. Therefore, before generating the copy corresponding to the target copy type, the second multimodal large model can identify the security and risk of the data required to generate the copy, so as to generate the target copy based on data that meets the security and compliance requirements, and finally, output the target copy that meets the security and compliance requirements to the user.

[0043] In one or more embodiments of the present specification, the specific method of generating security training data and risk training data corresponding to the target copy type through the first large model based on the multimodal sample data and the multiple prompt word templates is not limited. Since the multimodal sample data includes both security sample data and risk sample data, and each prompt word template includes both security prompt words and risk prompt words. Therefore, in an optional manner, the first large model can be guided to generate security training data corresponding to the target copy type based on the security sample data in the multimodal sample data and the security prompt words in the multiple prompt word templates, and the first large model can be guided to generate risk training data corresponding to the target copy type based on the risk sample data in the multimodal sample data and the risk prompt words in the multiple prompt word templates. For example, the security sample data in the multimodal sample data and the security prompt words in the multiple prompt word templates, as well as the risk sample data in the multimodal sample data and the risk prompt words in the multiple prompt word templates, can be respectively input into the first large model through interface calls. Furthermore, after receiving the above information, the first large model identifies, analyzes, and infers the safety sample data and safety prompt words to generate safety training data corresponding to the target document type, and identifies, analyzes, and infers the risk sample data and risk prompt words to generate risk training data corresponding to the target document type. The safety training data is used to train the first multimodal large model's ability to identify data that complies with safety and compliance, while the risk training data is used to train the first multimodal large model's ability to identify data that does not comply with safety and compliance.

[0044] In one optional approach, the format of the prompt word template can be "scenario type + data type + safety prompt word + risk prompt word". For example, after inputting an image into the first large model, the following prompt word content is input into the first large model: "Please generate training data for [financial consumption scenario] based on the above image. The training data must comply with requirements such as [social trends, ethics, laws, and regulations], and must not contain content such as [political, pornographic, gambling, drugs, insults, discrimination, and defamation]. Based on this, the first large model can recognize the received image and generate corresponding safety training data based on the prompt word content. For another example, after inputting a piece of text information into the first large model, the following prompt word content is input into the first large model: "Please generate training data for [advertising creative scenario] based on the above text. The training data contains content that violates requirements such as [social trends, ethics, laws, and regulations], and involves content such as [political, pornographic, gambling, drugs, insults, discrimination, and defamation]. Based on this, the first large model can recognize the received text information and generate corresponding risk training data based on the prompt word content.

[0045] In another optional method, the format of the prompt word template can also be "scenario type + data type + style type + safety prompt word + risk prompt word". For example, after inputting a picture into the first model, the following prompt word content is input into the first model: "Please generate training data for [financial consumption scenario] based on the above picture. Among them, the training data is suitable for generating [humorous style] copywriting and complies with [social customs, ethics, laws, regulations] and other requirements. Content such as [political, pornographic, gambling, drugs, insults, discrimination, and defamation] is prohibited." Based on this, the first model can recognize the received picture and generate corresponding safety training data according to the above prompt word content. For another example, after inputting a piece of text information into the first model, the following prompt word content is input into the first model: "Please generate training data for [advertising creative scene] based on the above text. Among them, the training data is suitable for generating [humorous style] copy, and the training data contains content that violates [social customs, ethics, laws, regulations] and other requirements, and involves [political, pornographic, gambling, drugs, insults, discrimination, defamation] and other content." Based on this, the first model can identify the received text information and generate corresponding risk training data according to the above prompt word content.

[0046] It should be noted that, in the above embodiment, the example of specifying the first large model to generate security training data and risk training data according to specific data objects is used for illustrative explanation. In actual application, there is no limitation on the form and content of each prompt word template. The following is an example of the optional form of the prompt word template. Optionally, the following example can be used as a general prompt word template for application in practice.

[0047] Role A: You are a compliance expert proficient in [industry field, such as finance / healthcare / education] regulations. You need to generate [text / graphics / video script] content that meets the following requirements:

[0048] 1. Core Principles:

[0049] Strictly comply with Article X of [Industry Regulations, such as the Advertising Law / Personal Information Protection Law] regarding [specific provisions, such as prohibition of false advertising];

[0050] Values ​​are consistent with [mainstream social ethics, such as equality, integrity, and environmental protection];

[0051] Avoid touching on [list of sensitive topics, such as public governance, spiritual systems, and discrimination based on kinship];

[0052] 2. Content requirements:

[0053] Subject: [Enter target subject, such as children's educational product advertisement];

[0054] Format: [specify output format, such as promotional copy / short video script];

[0055] Style: [describe the tone, e.g., friendly and natural / professional and rigorous];

[0056] 3. Compliance Enhancement Examples (provide at least 3 variations):

[0057] Positive Example 1: "This course stimulates learning interest through fun animations and complies with the Ministry of Education's Regulations on the Protection of Minors Online"

[0058] Positive Case 2: "Skin care product ingredients are publicly traceable and do not contain EU banned chemicals";

[0059] 4. Multimodal constraints:

[0060] If generating images: [illegal elements, such as nudity / violence] must be avoided;

[0061] If generating a video: Background music must comply with [Copyright Authorization Requirements].

[0062] Role B: You are a risky content creator attempting to bypass platform review. You must create seemingly normal [text / graphics / video scripts] that carry the following risks:

[0063] 1. Risk type (select by priority):

[0064] Legal violations: including [false advertising / privacy disclosure inducement / promotion of prohibited items];

[0065] Ethical conflicts: involving [physical characteristics discrimination / cultural offense / violent implications];

[0066] Deviation of values: Promoting [materialism / excessive consumption / identity conflict];

[0067] 2. Concealment requirements:

[0068] Use metaphors or substitute terms (e.g. "special channels" to refer to illegal transactions;

[0069] Creating misleading content through inconsistencies between images and text (e.g., images showing healthy food, but text suggesting weight loss effects);

[0070] 3. Risk example template (need to mark the violation type):

[0071] Risk Case 1 (False Advertising): "Completely cure diabetes in three days, proven effective by thousands of patients";

[0072] Risk Case 2 (Discrimination based on physical characteristics): "Girls have poor logical thinking and are suitable for reading literature";

[0073] 4. Adversarial testing instructions:

[0074] Generate 10 violation statements with different disguise levels and mark the specific regulatory provisions they violate.

[0075] In another optional method, the training data corresponding to the target text type generated by guiding the first large model based on the security sample data in the multimodal sample data and the security prompt words in the multiple prompt word templates can be called the first training data, and the training data corresponding to the target text type generated by guiding the first large model based on the risk sample data in the multimodal sample data and the risk prompt words in the multiple prompt word templates can be called the second training data. Based on this, in order to improve the quality of the training data, after obtaining the first training data and the second training data, the second large model can also be guided to evaluate the accuracy of the first training data and the second training data according to the preset evaluation prompt word template, so as to determine the security training data and risk training data that meet the quality requirements based on the evaluation information output by the second large model. Among them, the method of guiding the first large model to generate the first training data and the second training data corresponding to the target text type is similar to the method of guiding the first large model to generate the security training data and risk training data corresponding to the target text type described in the above embodiment. Please refer to the description of the above embodiment and will not be repeated here.

[0076] Regardless of the method used, in one or more embodiments of this specification, the number and type of the first large models are not limited. Optionally, the number of the first large models can be one or more. When there are multiple first large models, the types of the multiple first large models can be different. Further, optionally, when the first large model is guided to generate training data through multiple prompt word templates, the corresponding relationship between the multiple prompt word templates and the multiple first large models is not limited. Optionally, it can be a one-to-one relationship, a one-to-many relationship, or a many-to-many relationship. It can be understood that when there is one first large model, the first large model generates training data in different forms based on all prompt word templates. When there are multiple first large models, each first large model can generate training data in different forms based on all prompt word templates. Each first large model can also generate training data in one form based on each prompt word template. Each first large model can also generate training data in different forms based on a portion of the prompt word templates among all the prompt word templates. The specific method to be used can be determined according to the number of first large models and actual needs, and will not be elaborated here.

[0077] In one or more embodiments of the present specification, there is no limitation on the specific method for guiding the second largest model to evaluate the accuracy of the first training data and the second training data based on a preset evaluation prompt word template. Optionally, multiple evaluation dimensions for evaluating the accuracy of the training data can be pre-set, and corresponding evaluation indicators can be set for each evaluation dimension. Based on this, before guiding the second largest model to evaluate the accuracy of the first training data and the second training data, the evaluation dimensions and the evaluation indicators preset for the evaluation dimensions can be determined first. Then, based on the preset evaluation prompt word template, evaluation dimensions, and evaluation indicators, the second largest model is guided to evaluate the accuracy of the first training data and the second training data under each evaluation dimension.

[0078] For example, the first and second training data, along with the content of the prompt word corresponding to a preset evaluation prompt word template, multiple preset evaluation dimensions, and the evaluation indicators corresponding to each evaluation dimension, can be collectively input into the second largest model through an interface call. Furthermore, upon receiving this information, the second largest model identifies, analyzes, and infers the first and second training data based on the evaluation indicators corresponding to each evaluation dimension, ultimately determining the accuracy of the first and second training data under each evaluation dimension, thereby selecting safety training data and risk training data that meet the accuracy requirements.

[0079] In one or more embodiments of this specification, the specific content of the multiple evaluation dimensions is not limited, and different content can be set according to actual application needs. For example, the multiple evaluation dimensions include but are not limited to security coverage, content deviation, multimodal consistency, adversarial, dynamic adaptability, etc. Accordingly, the specific form of the evaluation indicator corresponding to each evaluation dimension is also not limited. Optionally, the evaluation indicator corresponding to each evaluation dimension can be a numerical value or letter used to measure the grade. For example, the evaluation indicator corresponding to each evaluation dimension can be identified in the form of 80%, 8.5, B, etc. For each evaluation dimension, if the evaluation result is lower than the corresponding evaluation indicator, it is determined that the accuracy of the training data in the corresponding evaluation dimension does not meet the standard; if it is higher than or equal to the corresponding evaluation indicator, it is determined that the accuracy of the training data in the corresponding evaluation dimension meets the standard. Alternatively, the evaluation indicator corresponding to each evaluation dimension can also be used to indicate the method for evaluating the corresponding evaluation dimension. In this case, the second largest model needs to evaluate the accuracy of the first training data and the second training data in the corresponding evaluation dimension according to the evaluation method indicated by the evaluation indicator corresponding to each evaluation dimension and determine the corresponding evaluation result. There is no limitation on the specific form of the evaluation result. Optionally, the evaluation result can be a score value or an evaluation report. The specific form can be determined according to actual needs.

[0080] For example, for the evaluation dimension of security coverage, label mapping, scenario conflict verification, cultural compatibility verification and other methods can be used for evaluation. Optionally, the label mapping method can be understood as constructing a first label map and a second label map through the second largest model, wherein each entity node in the first label map is an entity node containing data that meets security and compliance requirements, and each entity node in the second label map is an entity node containing data that does not meet security and compliance requirements. Based on this, the second largest model maps the first training data to each entity node in the first label map, and maps the second training data to each entity node in the second label map. By counting the coverage density of the first label map and the second label map, the accuracy of the first training data and the second training data can be determined.

[0081] The scenario conflict verification method can be understood as the second largest model using a preset query language (for example, SPARQL query language) to verify whether the first training data and the second training data contain security conflict scenarios (for example, samples that include both "gender equality" and "occupational stereotypes"). The cultural compatibility verification method can be understood as using the cultural knowledge base of the second largest model (for example, Hofstede's cultural dimension model) to detect whether the first training data covers preset sample data that meets security and compliance requirements, and to detect whether the second training data covers preset sample data that does not meet security and compliance requirements; or, the second largest model uses mBERT to perform cross-cultural security alignment analysis on the first training data and the second training data respectively to identify potential cultural conflicts (for example, identifying the security differences of certain words in different application scenarios).

[0082] For another example, for the evaluation dimension of content bias, implicit bias scanning, security strength spectrum analysis, and other methods can be used for evaluation. Optionally, the implicit bias scanning method can be understood as using the fairness detection module of the second largest model (for example, FairFace, TextBlob, etc.) to quantify the role association of images, texts, etc. (for example, the proportion of females in the picture of "nurse"), the balance of blood group representation (for example, the frequency of specific ethnic groups in negative samples), and the visualization of implicit associations of sensitive features in images and texts through LIME interpretation technology. The security strength spectrum analysis method can be understood as constructing a security strength classifier through the second largest model, grading the first training data and the second training data according to the security expression strength, or drawing the overlapping area of ​​​​positive and negative samples in the security strength distribution to evaluate whether the discrimination of the first training data and the second training data is bimodal.

[0083] For another example, for the evaluation dimension of multimodal consistency, symbol conflict detection, symbol text semantic contradiction analysis, cross-modal security alignment and other methods can be used for evaluation. Optionally, the symbol conflict detection method can be understood as using the second largest model to build a security symbol knowledge base (for example, the dove of peace symbolizes non-violence), and using the target detection model (for example, YOLOv8) to identify the symbols in the image. The symbol text semantic contradiction analysis method can be understood as using the second largest model to perform a contradiction analysis between the symbol and text semantics (for example, whether the environmental protection copy appears on the pattern of the plastic bag. The cross-modal security alignment method can be understood as applying the second largest model to calculate the image and text security consistency score (for example, filtering the training data with a score below the preset threshold), extracting the speech emotion features of the audio and text combination, and verifying its consistency with the emotional direction that meets the security and compliance requirements.

[0084] For another example, for the evaluation dimension of adversarial testing, security escape case generation, security perturbation testing, and other methods can be used for evaluation. Optionally, the security escape case generation method can be understood as using the second largest model to generate multiple security boundary cases (for example, cases that superficially advocate environmental protection but implicitly involve consumerism), and detecting whether the first training data and the second training data can cover the feature space of such cases. The security perturbation testing method can be understood as using the second largest model to adversarially rewrite the first training data (for example, changing "helping the disabled" to "giving alms to the disabled"), and then using the second largest model to detect whether the second training data contains enough counterexamples to capture such semantic shifts.

[0085] For another example, for the evaluation dimension of dynamic adaptability, it can be evaluated by means of security timeliness verification, security evolution trajectory prediction, etc. Optionally, the method of security timeliness verification can be understood as using the time perception module of the second largest model (for example, the KILT knowledge base) to detect outdated expressions (for example, abolished discriminatory terms) in the first training data and the second training data, or constructing a time decay function to evaluate data security. The method of predicting the security evolution trajectory can be understood as using the second largest model to predict the trend of security and compliance requirements in the next few years, evaluating the forward-looking coverage of the current first training data and the second training data, and detecting whether the first training data and the second training data contain enough security transition cases (for example, the collision of traditional concepts and modern concepts).

[0086] It should be noted that the above descriptions are merely illustrative, and the specific content of each evaluation dimension and corresponding evaluation indicator is not limited to these in actual applications. Furthermore, it should be noted that the above examples of evaluating the first training data and the second training data can be implemented individually or in combination in an application, depending on actual needs. The above descriptions are only used to illustrate the implementation principles of the above training optimization method and are not intended to be limiting.

[0087] In one or more embodiments of this specification, the specific form of guiding the second large model to evaluate the accuracy of the first training data and the second training data under multiple evaluation dimensions according to the preset evaluation prompt word template, evaluation dimension and evaluation index is not limited. In an optional manner, the accuracy of the first training data and the second training data under different evaluation dimensions is evaluated by calling the second large model multiple times, wherein each time the second large model is called, the second large model can be instructed to evaluate the accuracy of the first training data and the second training data under the corresponding evaluation dimension only according to one evaluation dimension and its corresponding evaluation index, or the second large model can be instructed to evaluate the accuracy of the first training data and the second training data under each evaluation dimension according to multiple evaluation dimensions and the evaluation index corresponding to each evaluation dimension. In another optional manner, the second large model is only called once to evaluate the accuracy of the first training data and the second training data under different evaluation dimensions. When the second large model is called, the second large model is instructed to evaluate the accuracy of the first training data and the second training data under each evaluation dimension according to all evaluation dimensions and the evaluation index corresponding to each evaluation dimension. Which specific method to adopt can be determined according to actual needs and will not be described in detail here.

[0088] Based on the above, after obtaining the security training data and the risk training data, the first multimodal large model can be iteratively trained based on the security training data and the risk training data using a preference learning method to obtain the trained second multimodal large model.

[0089] There is no limitation on the type of preference learning algorithm. Different types can be used according to specific needs, including but not limited to classic reinforcement learning algorithms, direct preference optimization algorithms, and innovative optimization algorithms. For example, classic reinforcement learning algorithms can be PPO (Proximal Policy Optimization) algorithms and RLHF (Reinforcement Learning from Human Feedback) algorithms; direct preference optimization algorithms can be DPO (Direct Preference Optimization) algorithms, SimPO (Simple Preference Optimization) algorithms, and ORPO (Odds Ratio Preference Optimization) algorithms; innovative optimization algorithms can be Step-DPO algorithms, KTO (Kahneman-Tversky Optimization) algorithms, multi-modal contrastive learning algorithms, and so on. Of course, the above-mentioned preference learning algorithms are only exemplary and are not limited to them in actual applications. The specific type of algorithm to be used can be determined based on the data characteristics and model type, and will not be described in detail here.

[0090] Furthermore, in one or more embodiments of the present specification, the specific method for iteratively training the first multimodal large model is not limited and can be determined according to the model type and actual application requirements. For example, for the first multimodal large model with the Transformer architecture as the core, in the pre-training stage, the text and image features can be aligned by using generative contrast learning (CLIP) or Aligning Language and Images with Generative Networks (ALIGN), directly learning the semantic association of the text-image pairs, and using masked modeling (Bidirectional Encoder representation for Image Transformers, BEiT) to predict the occluded image blocks to learn visual representations, and expand the application scope of the Transformer-based bidirectional encoder representation (BERT) in the image field. In the fine-tuning stage, the learning alignment ability of the first multimodal large model can be strengthened in combination with various instructions. In addition, the balance and generalization ability of the first multimodal large model can be strengthened by strategies such as early fusion, late fusion, and dynamic fusion, and finally, the second multimodal large model is obtained. Of course, the above training process is only an example description and is not limited to this in actual application. As long as the implementation principle of the above training method is applicable, the embodiments of this specification are applicable, and the specific process will not be described in detail here.

[0091] In one or more embodiments of the present specification, a variety of multimodal test data and test prompt word templates are pre-constructed. The multimodal test data can be text, images, audio, video, and other data covering various application scenarios, including security test data and risk test data. The prompt word content of the test prompt word template can include various copywriting requirements, optionally including but not limited to copywriting requirements for different application scenarios such as advertising, products, and social media. Further, the copywriting requirements can be clear copywriting requirements or vague copywriting requirements. For example, a clear copywriting requirement instruction can be "Generate a promotional copy for a portable coffee machine. The copywriting prohibits the inclusion of content such as [political, pornographic, gambling, drugs, insults, discrimination, and defamation]." A vague copywriting requirement instruction can be "Generate an advertisement copy containing online hot updates." Based on this, the preset multimodal test data and test prompt word template can be obtained. Then, based on the multimodal test data and the preset test prompt word template, the second multimodal large model is guided to generate test copy for testing the copywriting generation capability of the second multimodal large model.

[0092] In one or more embodiments of this specification, the specific method of testing the copywriting generation capability of the second multimodal large model based on the test copy is not limited. Optionally, multiple test dimensions can be pre-set. Based on this, according to the multiple test dimensions, the test copy is tested under different test dimensions to see whether it meets the security and compliance requirements, so as to determine the copywriting generation capability of the second multimodal large model based on the test results. Among them, there is no limitation on the specific content of the multiple test dimensions. According to actual needs, the content of the multiple test dimensions may be different. Optionally, the multiple test dimensions include but are not limited to sensitive content screening, data security verification, legal prohibition inspection, procedure and form compliance inspection, social order and morality inspection, etc. Further optionally, for each test dimension, a corresponding test indicator can also be set to determine whether the test result of the test copy from each test dimension meets the standard. There is no limitation on the form of the test indicator corresponding to each test dimension, and different forms can be selected according to actual needs.

[0093] Similarly, referring to the description of the evaluation indicators corresponding to each evaluation dimension in the above embodiment, each test indicator can be a numerical value or a letter used to measure the grade. For example, the test indicator corresponding to each test dimension can be identified in the form of 85%, 9.0, A, etc. For each test dimension, if the test result is lower than the corresponding test indicator, it is determined that the test result of the test copy from the corresponding test dimension does not meet the standard, that is, the test copy does not meet the security and compliance requirements in the corresponding dimension, that is, the second multimodal large model has insufficient copy generation capabilities in the corresponding dimension; correspondingly, if the test result is higher than or equal to the corresponding test indicator, it is determined that the test result of the test copy from the corresponding test dimension meets the standard, that is, the test copy meets the security and compliance requirements in the corresponding dimension, that is, the second multimodal large model has copy generation capabilities in the corresponding dimension.

[0094] Alternatively, the test indicators corresponding to each test dimension can also be used to indicate the direction of testing the corresponding test dimension. For example, for the test dimension of sensitive content screening, the test direction indicated by the corresponding test indicator can be to identify whether the test copy contains violent, pornographic, discriminatory words or metaphorical expressions; for the test dimension of data security verification, the test direction indicated by the corresponding test indicator can be to verify whether the data involved in the test copy complies with privacy protection regulations and whether sensitive information is desensitized; for the test dimension of legal prohibition inspection, the test direction indicated by the corresponding test indicator can be to verify whether the test copy violates prohibitions such as the "Advertising Law" and the "Civil Code", and whether it violates industry norms, for example, whether it contains false propaganda, infringement of reputation rights, etc., such as whether "school district housing" and "capital efficiency rate" appear in real estate advertisements. Prohibited expressions; for the test dimension of procedural and formal compliance check, the test direction indicated by the corresponding test indicators can be to check whether the test documents involving contracts or statements, including disclaimers, user agreements, etc., comply with the statutory form requirements, and whether the quoted content (such as pictures, quotations) in the test documents involving ownership content has been legally authorized; for the test dimension of social order and good customs check, the test direction indicated by the corresponding test indicators can be to check whether the test documents promote money worship, prejudice, gender opposition and other content that conflicts with mainstream social values, whether it offends specific groups (such as spiritual systems, cultural community taboos), and whether the core concepts conveyed by the test documents involving specific brands (such as environmental protection, integrity) are consistent with the brand concept, etc.

[0095] Optionally, in the above embodiment, the process of testing the test text according to multiple test dimensions can be completed through the third model. Of course, it is not limited to this in actual application.

[0096] It should be noted that the contents of the above-mentioned multiple test dimensions and the form of the test indicators corresponding to each test dimension are only exemplary. The various examples of testing test texts according to multiple test dimensions can be implemented separately or in combination in the application, depending on actual needs. The above is only used to illustrate the implementation principle of the above-mentioned training optimization method and is not a restrictive description.

[0097] Based on this, according to the test results of the test text in multiple test dimensions, the test indicators of the test text in each test dimension can be obtained. Then, according to the test indicators in each test dimension, it is determined whether the corresponding test indicators meet the standards. If the test indicators do not meet the standards, the security training data and the risk training data are optimized, and the first multimodal large model is retrained based on the optimized security training data and risk training data to obtain a third multimodal large model with better text generation capabilities. Among them, for the case where the test indicators do not meet the standards, the specific method of optimizing the security training data and the risk training data is not limited. Taking into account different situations, the methods of optimizing the security training data and the risk training data can also be different.

[0098] For example, if the test copy fails to meet the test indicators in a certain test dimension, it may be because the number, type, coverage scenarios, etc. of the security training data and risk training data are not sufficient, resulting in limited copy generation capabilities of the second multimodal large model obtained through model training. Therefore, in an optional method, a portion of new training data can be supplemented on the basis of the original security training data and risk training data, and the original security training data and risk training data and the supplemented training data can be used together as new security training data and risk training data. Based on this, the first multimodal large model is retrained according to the new security training data and risk training data to obtain a third multimodal large model, so that the trained third multimodal large model has better copy generation capabilities.

[0099] For another example, if the test indicators of the test copy do not meet the standards in a certain test dimension, it may be because the data quality of the security training data and risk training data themselves is not good, resulting in the inability of the second multimodal large model obtained through model training to generate test copy that meets the standards in the corresponding test dimension. Therefore, in an optional method, the target test dimension that does not meet the standards can be determined based on the above test indicators, and then the security training data and risk training data under the target test dimension are updated. For example, if the test copy does not meet the standards in the test dimension of public order and good morals inspection, this part of the security training data and risk training data will be updated to security training data and risk training data that meet the requirements of public order and good morals. Based on this, the first multimodal large model is retrained according to the updated security training data and risk training data to obtain a third multimodal large model, so that the trained third multimodal large model has better copy generation capabilities in the corresponding test dimension.

[0100] Further optionally, in order to measure the overall quality of the security training data and risk training data, in one or more embodiments of the present specification, a preset quantity threshold may be set based on the number of multiple test dimensions to determine how to update the security training data and risk training data. Optionally, after testing the test text and obtaining the test indicators under the corresponding test dimensions, the number of substandard test dimensions may be determined based on the test indicators corresponding to each test dimension, and then, based on the number of substandard test dimensions, the method for updating the security training data and risk training data may be determined. For example, the number of test dimensions is 6, and the preset quantity threshold may be set to 3. Based on this, if it is determined that the number of substandard test dimensions is less than or equal to 3, it means that the quality of at least half of the security training data and risk training data meets the requirements. In order to save workload, the method in the above embodiment may be adopted to only update the security training data and risk training data corresponding to the substandard test dimensions.

[0101] Accordingly, if it is determined that the number of test dimensions that do not meet the standards is greater than 3, it means that the quality of the vast majority of the security training data and risk training data does not meet the requirements. Therefore, in order to obtain a third multimodal large model with better copywriting generation capabilities, all security training data and risk training data can be updated. Since the security training data and risk training data are generated by the first large model based on a plurality of preset prompt templates, the quality of the vast majority of the security training data and risk training data does not meet the requirements, which means that the prompt word content of the plurality of prompt word templates may not meet the requirements for correctly guiding the first large model to generate security training data and risk training data. Therefore, if it is determined that the number of test dimensions that do not meet the standards exceeds a preset number threshold, the prompt word content of the plurality of prompt word templates can be updated. Then, based on the updated plurality of prompt word templates, the security training data and risk training data can be regenerated through the first large model to retrain the first multimodal large model based on the newly generated security training data and risk training data to obtain the third multimodal large model.

[0102] Of course, in the above embodiment, the method of optimizing the safety training data and risk training data is merely illustrative and not limiting. Since the optimized safety training data and risk training data are relatively large, the multimodal test data is relatively smaller. Therefore, to minimize workload, before updating the optimized safety training data and risk training data, the prompt word content of the multimodal test data and the test prompt word template can be updated. Based on the updated multimodal test data and test prompt word template, the second multimodal large model is guided to regenerate the test text. Furthermore, using the method of the above embodiment, the corresponding test text is tested to determine whether it is necessary to update the optimized safety training data and risk training data.

[0103] In the above embodiment, the implementation process of each method step of the model training optimization method based on the information security dimension is described in detail. Below, the overall process of the above training optimization method is described in conjunction with the accompanying drawings.

[0104] Figure 2 The following is a basic flow chart of a model training optimization method based on information security dimension. Figure 2 As shown, in this embodiment, first, multimodal sample data including safety sample data and risk sample data and a prompt word template including safety prompt words and risk prompt words are obtained. Based on this, the first large model generates first training data based on the safety sample data and safety prompt words, and generates second training data based on the risk sample data and risk prompt words. Further, the second large model evaluates the first training data and the second training data based on multiple evaluation dimensions to determine the safety training data and the risk training data. Then, based on the safety training data and the risk training data, the preference learning algorithm is used to iteratively train the first multimodal large model to obtain the second multimodal large model. In this embodiment, multimodal test data including safety test data and risk test data and a test prompt word template are pre-set. Based on this, Figure 2 As shown, multimodal test data and test prompt word templates can be obtained, and the second multimodal large model generates test copy based on the multimodal test data and the test prompt word template. Furthermore, in order to determine the copy generation capability of the second multimodal large model, the test copy can be tested based on multiple test dimensions and corresponding test indicators, and whether the test copy meets the standards under each test dimension can be determined to determine whether to optimize the security training data and risk training data. Based on this, if it is determined that the security training data and risk training data need to be optimized, the security training data and risk training data are optimized, and the first multimodal large model is retrained based on the optimized security training data and risk training data and the above-mentioned testing process is repeated. Otherwise, it is determined that the second multimodal large model meets the copy generation requirements for security and compliance.

[0105] It should be noted that Figure 2 Only one optional implementation method is shown. In actual applications, the implementation method of the training optimization method is not limited to this. For other optional methods and specific implementation details, please refer to the description of the above embodiment, which will not be repeated here.

[0106] In summary, the model training optimization method provided by one or more embodiments of this specification automatically generates the training data required for training the first multimodal large model based on the first large model, and can also automatically evaluate the data quality of the training data from multiple evaluation dimensions through the second large model to obtain security training data and risk training data that meet the training requirements, so that the second multimodal large model trained based on the security training data and risk training data has better copy generation capabilities. After obtaining the second multimodal large model, the test copy generated by the second multimodal large model can also be automatically tested from multiple test dimensions to verify the copy generation capability of the second multimodal large model. When it is determined that the test copy generated by the second multimodal large model does not meet the security and compliance requirements, the security training data and risk training data are optimized, and the first multimodal large model is retrained based on the optimized security training data and risk training data. Finally, a multimodal large model with a copy generation capability that meets the requirements is obtained.

[0107] Based on the above, in one or more embodiments of this specification, the security training data and risk training data automatically constructed and evaluated by the large model can automatically filter out invalid data that does not meet the requirements of training data. The multimodal large model trained based on the above security training data and risk training data has better copywriting generation capabilities, and the copywriting content generated by the multimodal large model meets security and compliance requirements. Based on the huge functions of the large model, the entire process does not require the use of a separate functional module to verify the copywriting, which not only saves a lot of labor costs and improves the overall efficiency of model training, but also provides strong guarantees for the richness and accuracy of the data and the copywriting generation capabilities of the multimodal large model, meeting the security and compliance requirements of the service provider for the copywriting content.

[0108] It is understandable that the execution subject of each step in the above-mentioned model training optimization method based on the information security dimension can be the same device, or the method can also be executed by different devices. In addition, in some of the processes described in the above embodiments and the accompanying drawings, multiple operations that appear in a specific order are included, but it should be clearly understood that these operations may not be executed in the order in which they appear in this article or in parallel. The serial numbers of the operations, such as S102, S104, etc., are only used to distinguish between different operations, and the serial numbers themselves do not limit the order of execution. In addition, these processes may include more or fewer operations, and these operations may be executed sequentially or in parallel.

[0109] It should be noted that the descriptions such as "first" and "second" in this document are used to distinguish different information, devices, modules, etc., and do not represent the order of precedence, nor do they limit "first" and "second" to different types. The above embodiments are only examples, and the above embodiments can be modified in actual implementation. Those skilled in the art can understand that the modification methods of the above embodiments without creative labor fall within the scope of protection of this specification and will not be described in detail in the embodiments. All the above optional technical solutions can be borrowed from or combined with each other to form optional embodiments of this specification, and will not be described one by one here.

[0110] Based on the same inventive concept, one or more embodiments of this specification also provide a model training optimization device based on information security dimension, see Figure 3 , Figure 3 A structural block diagram of a model training optimization device based on information security dimension is shown.

[0111] like Figure 3 As shown, the device 300 may include a first acquisition module 301, a second acquisition module 302, a generation module 303 and a training module 304, wherein the first acquisition module 301 is used to read multimodal sample data, and the multimodal sample data includes security sample data and risk sample data; the second acquisition module 302 is used to read a plurality of prompt word templates corresponding to the target copy type, and the target copy type is any one of the plurality of copy types corresponding to the target search service, and each prompt word template includes a prompt word pair consisting of a security prompt word and a risk prompt word; the generation module 303 is used to generate security training data and risk training data corresponding to the target copy type through the first large model according to the multimodal sample data and the plurality of prompt word templates; the training module 304 is used to iteratively train the first multimodal large model using a preference learning algorithm according to the security training data and the risk training data to obtain a second multimodal large model.

[0112] In an optional embodiment, the generation module 303 generates security training data and risk training data corresponding to the target copy type through the first large model based on the multimodal sample data and multiple prompt word templates, and is used to: guide the first large model to generate security training data corresponding to the target copy type based on the security sample data in the multimodal sample data and the security prompt words in the multiple prompt word templates; guide the first large model to generate risk training data corresponding to the target copy type based on the risk sample data in the multimodal sample data and the risk prompt words in the multiple prompt word templates.

[0113] In an optional embodiment, the generation module 303 generates security training data and risk training data corresponding to the target copy type through the first large model based on the multimodal sample data and multiple prompt word templates, and is used to: guide the first large model to generate first training data corresponding to the target copy type based on the security sample data in the multimodal sample data and the security prompt words in the multiple prompt word templates; guide the first large model to generate second training data corresponding to the target copy type based on the risk sample data in the multimodal sample data and the risk prompt words in the multiple prompt word templates; guide the second large model to evaluate the accuracy of the first training data and the second training data based on the preset evaluation prompt word template; and determine the security training data and risk training data based on the evaluation information output by the second large model.

[0114] In an optional embodiment, the generation module 303 guides the second largest model to evaluate the accuracy of the first training data and the second training data according to a preset evaluation prompt word template, and is used to: determine the evaluation dimension and the preset evaluation indicators for the evaluation dimension; guide the second largest model to evaluate the accuracy of the first training data and the second training data under the evaluation dimension according to the preset evaluation prompt word template, evaluation dimension and evaluation indicator.

[0115] In an alternative embodiment, the first large model and the second large model are the same or different.

[0116] In an optional embodiment, the first acquisition module 301 or the second acquisition module 302 is further used to: obtain preset multimodal test data, the multimodal test data including safety test data and risk test data; guide the second multimodal large model to generate test text according to the multimodal test data and the preset test prompt word template, so as to test the text generation capability of the second multimodal large model.

[0117] In an optional embodiment, after the second multimodal large model generates a test copy, the training module 304 is further used to: optimize the security training data and risk training data according to the test copy output by the second multimodal large model; and retrain the first multimodal large model based on the optimized security training data and risk training data.

[0118] In an optional embodiment, the risk sample data includes general risk sample data and risk sample data in a specified scenario.

[0119] It should be noted that, since the principle of solving the problem by the training optimization device is similar to that of the aforementioned training optimization method, the implementation of the training optimization device can refer to the implementation of the aforementioned training optimization method, and the repeated parts will not be repeated.

[0120] Based on the same inventive concept, one or more embodiments of this specification further provide an electronic device, see Figure 4 , Figure 4 A structural block diagram of an electronic device provided in one or more embodiments of this specification.

[0121] like Figure 4 As shown, the electronic device 400 may include a processor 401, a memory 402, and a program or instruction stored in the memory 402 and executable on the processor 401. When the program or instruction is executed by the processor 401, the various processes of the above-mentioned method embodiment are implemented and the same technical effect can be achieved. To avoid repetition, they will not be described here.

[0122] It should be noted that the electronic devices in one or more embodiments of this specification include mobile electronic devices and non-mobile electronic devices.

[0123] One or more embodiments of this specification also provide a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the various processes of the above-mentioned method embodiments are implemented and the same technical effects can be achieved. To avoid repetition, they will not be described here.

[0124] The processor is the processor in the electronic device in the above embodiment. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0125] This specification is described with reference to flowcharts and / or block diagrams of methods, apparatus (systems) and computer program products according to one or more embodiments of this specification. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0126] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0127] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0128] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment. In this document, relational terms such as first and second are merely used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprise", "include" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. For those of ordinary skill in the art, the specific meanings of the above terms in this specification can be understood according to the specific circumstances.

[0129] It should be noted that, unless there is a conflict, the embodiments and features within the embodiments in this specification may be combined with each other. This specification is not limited to any single aspect, any single embodiment, or any combination and / or permutation of these aspects and / or embodiments. Furthermore, each aspect and / or embodiment of this specification may be used alone or in combination with one or more other aspects and / or embodiments thereof.

[0130] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this specification, rather than to limit them. Although this specification has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein with equivalents. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the embodiments of this specification, and they should all be included in the scope of this specification.

Claims

1. A model training optimization method based on information security dimension, characterized in that: include: Reading multimodal sample data, wherein the multimodal sample data includes safe sample data and risk sample data; Reading multiple prompt word templates corresponding to a target text type, where the target text type is any one of multiple text types corresponding to a target search service, each prompt word template including a prompt word pair consisting of a safety prompt word and a risk prompt word; Generate security training data and risk training data corresponding to the target text type using a first large model based on the multimodal sample data and the multiple prompt word templates; According to the safety training data and the risk training data, a preference learning algorithm is used to iteratively train the first multimodal large model to obtain a second multimodal large model.

2. The method according to claim 1, characterized in that Generating security training data and risk training data corresponding to the target text type using a first large model based on the multimodal sample data and the multiple prompt word templates includes: Instructing the first large model to generate security training data corresponding to the target text type based on the security sample data in the multimodal sample data and the security prompt words in the multiple prompt word templates; According to the risk sample data in the multimodal sample data and the risk prompt words in the multiple prompt word templates, the first large model is guided to generate risk training data corresponding to the target copy type.

3. The method according to claim 1, characterized in that Generating security training data and risk training data corresponding to the target text type using a first large model based on the multimodal sample data and the multiple prompt word templates includes: Instructing the first large model to generate first training data corresponding to the target text type based on the safety sample data in the multimodal sample data and the safety prompt words in the multiple prompt word templates; Based on the risk sample data in the multimodal sample data and the risk prompt words in the multiple prompt word templates, guiding the first large model to generate second training data corresponding to the target copy type; According to a preset evaluation prompt word template, guiding the second large model to evaluate the accuracy of the first training data and the second training data; Safety training data and risk training data are determined based on the evaluation information output by the second largest model.

4. The method according to claim 3, characterized in that According to a preset evaluation prompt word template, guiding the second large model to evaluate the accuracy of the first training data and the second training data includes: Determining evaluation dimensions and preset evaluation indicators for the evaluation dimensions; According to the preset evaluation prompt word template, the evaluation dimension and the evaluation index, the second large model is guided to evaluate the accuracy of the first training data and the second training data under the evaluation dimension.

5. The method according to claim 4, characterized in that The first large model and the second large model are the same or different.

6. The method according to any one of claims 1 to 5, characterized in that Also includes: Acquiring preset multimodal test data, wherein the multimodal test data includes safety test data and risk test data; According to the multimodal test data and a preset test prompt word template, the second multimodal large model is guided to generate a test text, so as to test the text generation capability of the second multimodal large model.

7. The method according to claim 6, characterized in that After the second multimodal large model generates the test text, the method further includes: Optimizing the safety training data and risk training data based on the test text output by the second multimodal large model; The first multimodal large model is retrained based on the optimized safety training data and risk training data.

8. The method according to claim 7, characterized in that The risk sample data includes general risk sample data and risk sample data in specified scenarios.

9. A model training optimization device based on information security dimension, characterized in that: include: A first acquisition module is configured to read multimodal sample data, wherein the multimodal sample data includes safe sample data and risk sample data; A second acquisition module is configured to read multiple prompt word templates corresponding to a target document type, where the target document type is any one of multiple document types corresponding to a target search service, each prompt word template including a prompt word pair consisting of a safety prompt word and a risk prompt word; a generation module, configured to generate, based on the multimodal sample data and the plurality of prompt word templates, security training data and risk training data corresponding to the target copy type through a first large model; A training module is used to iteratively train the first multimodal large model using a preference learning algorithm based on the safety training data and the risk training data to obtain a second multimodal large model.

10. An electronic device, characterized in that: The electronic device comprises: a memory for storing a computer program product; A processor is configured to execute a computer program product stored in the memory, and when the computer program product is executed, implements the method described in any one of claims 1 to 8.

11. A computer-readable storage medium storing a computer program, characterized in that: The computer program is configured to implement the method of any one of claims 1 to 8 when executed by a processor.