Question processing method and device and electronic equipment
By determining the label and level of the question from multiple protection risk dimensions and content risk dimensions in the generative artificial intelligence big model, protection decisions and content decisions are made, the security problems brought about by confrontational questions are solved, and the security and harmlessness of the content generated by the big model are improved.
Patent Information
- Application Number
- CN202510373674.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2045-03-27
AI Technical Summary
The existing generative artificial intelligence model has security problems when dealing with adversarial questions, making it difficult to effectively protect against adversarial questions, making it difficult to guarantee the harmlessness of generated content.
When accepting questions entered by users, the protection labels and content labels of the question are determined from multiple protection risk dimensions and content risk dimensions, and the protection decisions and content decisions are made based on these tags and levels, and the answer acquisition strategy is determined, and the safe answer is obtained and returned.
Effectively protect against confrontational questions, improve the security and harmlessness of content generated by large-scale models, and reduce the risks brought by confrontational questions.
Smart Images

Figure CN119917635A_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of data processing technology, and specifically relates to a method, device and electronic equipment for question processing. Background Art
[0002] Generative AI (Artificial Intelligence Generated Content, AIGC) refers to the technology based on artificial intelligence technical methods such as generative adversarial networks and large pre-trained models, which generates relevant content with appropriate generalization capabilities by learning and identifying existing data. With the rise of generative AI, many large models and their applications have emerged, forming a situation of a hundred schools of thought.
[0003] The huge data sets behind these large models provide them with powerful content generation capabilities, but at the same time, the content generated by large models also brings many security issues. The sources of these security issues usually include two aspects: on the one hand, it comes from the pollution of data with value bias, privacy leakage and other issues, and on the other hand, it comes from the creative (illusion) content generation ability of large models.
[0004] To address the above issues, after pre-training, large models can rely on supervised fine-tuning (SFT) and reinforcement learning from human feedback (RLHF) to align HHH (Helpful, Honest, Harmless), thereby improving the security of content generated by large models. However, more and more complex adversarial questions (prompts) further expose and exploit the security issues of content generated by large models. Therefore, it is necessary to provide a better question processing solution to protect against adversarial questions and align the harmlessness of large models. Summary of the invention
[0005] The embodiments of this specification provide a method, device and electronic device for question processing, so as to provide a solution for question processing.
[0006] In a first aspect, an embodiment of the present specification provides a method for question processing, the method comprising: upon receiving a question input by a user into a target macro model, determining, from multiple protection risk dimensions, a protection risk dimension to which the question belongs and a protection label and a protection level of the question under the protection risk dimension to which it belongs; determining a protection decision according to the protection label and the protection level of the question under the protection risk dimension to which it belongs; determining, from multiple content risk dimensions, a content risk dimension to which the question belongs and a content label and a content level of the question under the content risk dimension to which it belongs; determining a content decision according to the content label and the content level of the question under the content risk dimension to which it belongs; determining an answer acquisition strategy based on the target macro model according to the protection decision and / or the content decision, executing the answer acquisition strategy, and returning the answer obtained after executing the answer acquisition strategy to the user.
[0007] In a second aspect, an embodiment of the present specification provides a device for question processing, comprising: a protection dimension module, for determining, from multiple protection risk dimensions, the protection risk dimension to which the question belongs and the protection label and protection level of the question under the protection risk dimension to which it belongs, upon receiving a question of a target macro model input by a user; a protection decision module, for determining a protection decision according to the protection label and protection level of the question under the protection risk dimension to which it belongs; a content dimension module, for determining, from multiple content risk dimensions, the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension to which it belongs; a content decision module, for determining a content decision according to the content label and content level of the question under the content risk dimension to which it belongs; an answer acquisition module, for determining an answer acquisition strategy based on the target macro model according to the protection decision and / or the content decision, executing the answer acquisition strategy, and returning to the user the answer obtained after executing the answer acquisition strategy.
[0008] In a third aspect, an embodiment of the present specification provides an electronic device, comprising: a processor, and a memory arranged to store computer executable instructions, wherein when the executable instructions are executed, the processor is enabled to: upon receiving a question input by a user into a target macro model, determine, from multiple protection risk dimensions, the protection risk dimension to which the question belongs and the protection label and protection level of the question under the protection risk dimension to which it belongs; determine a protection decision based on the protection label and protection level of the question under the protection risk dimension to which it belongs; determine, from multiple content risk dimensions, the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension to which it belongs; determine a content decision based on the content label and content level of the question under the content risk dimension to which it belongs; determine an answer acquisition strategy based on the target macro model based on the protection decision and / or the content decision, execute the answer acquisition strategy, and return the answer obtained after executing the answer acquisition strategy to the user.
[0009] In a fourth aspect, an embodiment of the present specification provides a storage medium for storing a computer program, which can be executed by a processor to implement the following process: when a question of a target macro model input by a user is received, determining from multiple protection risk dimensions the protection risk dimension to which the question belongs and the protection label and protection level of the question under the protection risk dimension to which it belongs; determining a protection decision based on the protection label and protection level of the question under the protection risk dimension to which it belongs; determining from multiple content risk dimensions the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension to which it belongs; determining a content decision based on the content label and content level of the question under the content risk dimension to which it belongs; determining an answer acquisition strategy based on the target macro model based on the protection decision and / or the content decision, executing the answer acquisition strategy, and returning the answer obtained after executing the answer acquisition strategy to the user.
[0010] In a fifth aspect, an embodiment of the present specification provides a computer program product, including a computer program, which implements the following process when executed by a processor: when a question of a target big model input by a user is received, determining from multiple protection risk dimensions the protection risk dimension to which the question belongs and the protection label and protection level of the question under the protection risk dimension to which it belongs; determining a protection decision based on the protection label and protection level of the question under the protection risk dimension to which it belongs; determining from multiple content risk dimensions the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension to which it belongs; determining a content decision based on the content label and content level of the question under the content risk dimension to which it belongs; determining an answer acquisition strategy based on the target big model based on the protection decision and / or the content decision, executing the answer acquisition strategy, and returning the answer obtained after executing the answer acquisition strategy to the user. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] In order to more clearly illustrate one or more embodiments of this specification or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in one or more embodiments of this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0012] Figure 1 It is a flowchart of a method for question processing provided in an embodiment of this specification; Figure 2 This is a schematic diagram of the use process of a protection engine provided in an embodiment of this specification; Figure 3 This is a schematic diagram of the use process of a content risk engine provided by an embodiment of this specification; Figure 4 It is a schematic diagram of the architecture of a question processing system provided in an embodiment of this specification; Figure 5 It is a flowchart of the operation of a question processing system provided in an embodiment of this specification; Figure 6 A schematic diagram of an application scenario of a method for question processing provided in an embodiment of this specification; Figure 7 It is a structural diagram of a protection risk dimension provided by an embodiment of this specification; Figure 8 It is a flow chart of a content risk control engine provided by an embodiment of this specification; Fig. 9It is a schematic diagram of an interception and blocking process for high-risk questions provided in an embodiment of this specification; Fig.10 This is a schematic diagram of a process for enhancing prompts for question content provided by an embodiment of this specification; Fig.11 This is a schematic diagram of a process for performing a security proxy on a large model provided by an embodiment of this specification; Fig.12 It is a structural diagram of a device for question processing provided in an embodiment of this specification; Fig.13 It is a structural diagram of an electronic device provided in an embodiment of this specification. DETAILED DESCRIPTION
[0013] The following will be combined with the drawings in the embodiments of this specification to clearly and completely describe the technical solutions in the embodiments of this specification. Obviously, the described embodiments are part of the embodiments of this specification, not all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0014] The terms "first", "second", etc. in the specification and claims of this application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable under appropriate circumstances, so that the embodiments of this specification can be implemented in an order other than those illustrated or described here, and the objects distinguished by "first", "second", etc. are generally of one type, and the number of objects is not limited. For example, the first object can be one or more. In addition, "and / or" in the specification and claims represents at least one of the connected objects, and the character " / " generally indicates that the objects associated with each other are in an "or" relationship.
[0015] Adversarial questions are challenging or misleading questions asked by users when they are trying to test the capabilities of the big model or find the weaknesses of the big model. Table 1 is a specific example of adversarial questions. As shown in Table 1, Table 1 shows two types of adversarial questions, one is target hijacking (or interception, hostage, etc.) questions, and the other is reverse induction (or guidance, persuasion, etc.) questions. There are many other sample types of adversarial questions like the above, such as: positive and negative views, role-playing, variant confrontation, etc. As can be seen from Table 1, the big model itself has no subject consciousness. Although it has been aligned by SFT+RLHF, it is still easily exploited and deceived by adversarial questions.
[0016] Table 1 shows specific examples of adversarial questioning.
[0017] Among them, Supervised Fine-Turning (SFT) is a common deep learning strategy, which is usually used on pre-trained large language models. The specific approach is to use labeled data to fine-tune the large model to adapt it to specific tasks or fields.
[0018] The role of Reinforcement Learning from Human Feedback (RLHF) is to provide machines with a natural, humane, interactive learning process by incorporating human feedback into the training process. This is just like the way humans learn expertise from another professional. By building a bridge between humans, RLHF enables AI to quickly master human experience. In RLHF, reinforcement learning is combined with human feedback, and human preferences are used as reward signals to guide the training of large models (including large models), thereby enhancing the model's understanding and satisfaction of human intentions. In generative models, RLHF can also fully align the generated images with text prompts.
[0019] The question processing method, device and electronic device provided in the embodiments of this specification are described in detail below with reference to the accompanying drawings through specific embodiments and their application scenarios.
[0020] Figure 1 A method for question processing provided by an embodiment of the present invention is shown. The method can be executed by an electronic device, and the electronic device may include: a server and / or a terminal device, wherein the terminal device may be, for example, a vehicle-mounted terminal or a mobile phone terminal. In other words, the method can be executed by software or hardware installed in the aforementioned electronic device, and the method for question processing includes the following steps: Step S102: When receiving a question input by the user into the target macro model, determine the protection risk dimension to which the question belongs and the protection label and protection level of the question under the protection risk dimension from multiple protection risk dimensions.
[0021] The target large model is a machine learning model with ultra-large-scale parameters (usually more than one billion) and complex computing structure. The target large model can be any type of large model. The type of the target large model is not specifically limited in this specification and can be determined according to actual conditions. The question initiated by the user to the target large model can be a unimodal text.
[0022] The Guardrails risk dimension is a dimension for understanding and performing risk protection on questions input by users into the target big model in the big model usage scenario. It can be an intention dimension, a historical dimension, a legal and / or regulatory dimension, a social merit and / or ethical dimension, etc. The Guardrails risk dimension can be obtained by analyzing and classifying the collected historical confrontation questions. The process of determining the Guardrails risk dimension to which a question belongs can be: extracting the features of the question, and comparing the extracted features with the features corresponding to each protection type under the Guardrails risk dimension. If the two are similar, it means that the question belongs to the Guardrails risk dimension, otherwise it does not.
[0023] Since the user's intention to ask a question is the purpose of the user asking the question, by understanding the user's intention to ask a question, it is possible to filter out adversarial questions with harmful intentions (or high-risk intentions), greatly reducing the risks generated by the user's questioning process. Therefore, among these protection risk dimensions, the intention dimension that represents the user's intention to ask a question can be used as an indispensable protection risk dimension. In addition to the intention dimension, other protection risk dimensions can be used to supplement the intention dimension. The number and content of the protection risk dimensions are not specifically limited in this specification and can be determined based on actual conditions.
[0024] In order to achieve refined protection of questions, for each protection risk dimension, there are multiple protection labels and multiple protection levels. For example, the protection labels corresponding to each protection type under the intention dimension may include: target hijacking, reverse induction, positive and negative views, role-playing, variant confrontation, etc., and the protection level corresponding to each protection label may include high risk, low risk, medium risk, etc. This manual does not specifically limit the protection labels and protection levels contained in different protection risk dimensions, and can be determined according to actual conditions.
[0025] Figure 2 The figure shows the use process of the protection engine. Figure 2 As shown, a protection engine (a system for taking precautionary measures against the risks of questions asked) can be set up to determine the protection risk dimensions of questions entered by users into the target large model. Figure 2 The protection engine in contains three protection risk dimensions. The input question hits the target hijacking label in the intent dimension, and the risk level is high risk.
[0026] In the protection engine, multiple multi-classification protection dimension models can be set up, and each protection risk dimension corresponds to a protection dimension model. The protection dimension model improves the generalization ability of adversarial questions based on a rich vocabulary and keywords. When a question is received from a user input into the target large model, the question can be input into each protection dimension model at the same time to determine the protection risk dimension to which the question belongs, as well as the protection label and protection level of the question under the protection risk dimension to which it belongs. It should be noted that a question can belong to one or more protection risk dimensions. The structure of the protection dimension model is not specifically limited in this specification and can be determined according to actual conditions.
[0027] Step S104: Determine a protection decision based on the protection label and protection level of the question under the protection risk dimension.
[0028] Among them, the protection decision is a risk strategy determined based on the protection risk dimension for the question, which is used to obtain specific decision actions and cooperate with the target large model for security defense. Protection decisions can be roughly divided into two categories: pass and fail. The former is used to indicate that you can enter the next link (i.e., determine the content risk dimension), and the latter is used to indicate that you cannot enter the next link, and directly return relevant information of the refusal to answer to the user who asked the question as the answer to the question. Furthermore, the two types of pass and fail decisions can be further subdivided. For example, the former can include transaction suggestions, question interaction, etc., and the latter can include refusal to answer, termination of the session, etc.
[0029] In one example, a protection decision can be determined through a policy tree. Specifically, the policy tree may contain N tree nodes, each of which may consist of 1-N policies; each policy may contain a rule and multiple actions, where the rule may contain: left value, comparison operator, right value, and the actions may contain: pass, reject, full review, only hit review, transaction suggestion, etc. By inputting the protection label and protection level of the question under the protection risk dimension to the policy tree, the protection decision corresponding to the question can be obtained.
[0030] Step S106: Determine, from among the multiple content risk dimensions, the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension to which it belongs.
[0031] Among them, the content risk dimension is a risk dimension determined based on the content of the question, which may include the content bottom line dimension (such as relevant legal bottom line), scientific and technological ethics dimension, data privacy dimension, etc.
[0032] In order to achieve refined control over the content of questions, for each content risk dimension, there are multiple content labels (corresponding to the content risk type) and multiple content levels. For the content risk dimension of the compliance dimension, the content labels may include: labor, environment, etc. The content level corresponding to each content label may include high risk, low risk, medium risk, etc. This specification does not specifically limit the content labels and content levels contained in different content risk dimensions, and they can be determined based on actual conditions.
[0033] In one example, a content risk engine (a system that identifies, evaluates, and manages risks based on the content of questions) can be set up to determine the content risk dimension of questions input by users into the target large model. In the content risk engine, a 1-N policy tree can be set for each content risk dimension (the number of policy trees is related to the number of labels of the content risk dimension), and each policy tree can contain N tree nodes, and each node can be composed of 1-N policies. The policy tree can refer to the policy tree corresponding to the aforementioned protection decision. In addition, the left value of each content risk dimension can also cover rich data sources such as models, databases, caches, etc. The content risk engine and the protection engine can be independent of each other, or the two can be merged into a new engine. The relationship between the content risk engine and the protection engine is not specifically limited in this specification, and can be determined based on actual conditions.
[0034] When a question input by a user into the target macro model is received, the question may be input into a content risk engine to determine the content risk dimension to which the question belongs, as well as the content label and content level of the question under the content risk dimension.
[0035] In one example, determining the content risk dimension to which the question belongs can be performed after the protection decision is determined (i.e., the question should be input into the protection engine first and then into the content risk engine). In this way, if the protection decision is not passed, the process of determining the content risk dimension to which the question belongs can be avoided, thereby improving the efficiency of question processing.
[0036] Step S108: Determine the content decision according to the content label and content level of the question under the content risk dimension.
[0037] Among them, content decision is a risk strategy determined for questions based on the content risk dimension, which is used to obtain specific decision actions. Content decisions can be roughly divided into two categories: pass and fail. The former is used to indicate that you can enter the next link (that is, determine the answer acquisition strategy based on the target large model), and the latter is used to indicate that you cannot enter the next link, and directly return relevant information of refusing to answer to the user who asked the question as the answer to the question. Furthermore, these two types of decisions, pass and fail, can be further subdivided. For example, the former can include transaction suggestions, question interaction, etc., and the latter can include refusing to answer, terminating the session, etc.
[0038] Similar to the aforementioned process of determining the protection decision, the content decision can be determined through a decision tree using the content label and content level of the question under the content risk dimension.
[0039] Figure 3 The following is a schematic diagram showing the usage process of the content risk engine. Figure 3 As shown, the content risk engine can include a content qualitative layer and a comprehensive decision layer. After the user inputs the question of the target large model into the content risk engine, the content qualitative layer can understand the content risk dimension and obtain the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension. The comprehensive qualitative layer can obtain the content decision based on the obtained content label and content level. In the case of obtaining multiple content decisions, these content decisions can be merged to obtain the final content decision.
[0040] In addition to the content qualitative layer and the comprehensive strategy layer, in order to reduce the pressure on the content risk control engine, such as Figure 3 As shown, a quick decision layer can also be set up in the content risk control engine. The quick decision layer is provided with multiple sample libraries such as a list library, a keyword library, a link library, etc. as a whitelist or a blacklist. The obtained labels of the intent dimension are compared with the data in these sample libraries. When the comparison result indicates that the question has a high risk, the high-risk question can be quickly intercepted and handled, and the content decision can be directly obtained, reducing the pressure on the content risk prevention and control engine.
[0041] Step S110: According to the protection decision and / or content decision, determine the answer acquisition strategy based on the target large model, execute the answer acquisition strategy, and return the answer obtained after executing the answer acquisition strategy to the user.
[0042] Among them, the answer acquisition strategy is a strategy for using a large model to obtain the answer corresponding to the question. Since the protection label and protection level are the labels and levels of the questions determined from the protection risk dimension, and the content label and content level are the labels and levels of the questions determined from the content risk dimension, the protection decision corresponding to the former and the content decision corresponding to the latter can be combined to obtain the answer acquisition strategy. The answer acquisition strategy can be to refuse to answer, input the large model to obtain the answer, etc. Table 2 shows some answer acquisition strategies corresponding to different adversarial questions.
[0043] Table 2 Answer acquisition strategies for different adversarial questions
[0044] After obtaining the answer acquisition strategy, the answer acquisition strategy can be executed, and the answer obtained after the execution is returned to the user. Figure 4 FIG. 1 shows a schematic diagram of the architecture of a question processing system. Figure 4 As shown, the system includes a protection engine, a content risk engine and a decision center. The decision center is used to determine the answer acquisition strategy based on the protection decision and the content decision.
[0045] Figure 5 Shows Figure 4 The flowchart of the question processing system in FIG. Figure 5 As shown, after the user inputs a question, the question is first input into the protection engine, and the question is understood through multiple protection risk dimensions to obtain the protection risk dimension to which the question belongs and the protection label and protection level of the question under the protection risk dimension to which it belongs. Then, a protection decision can be obtained based on the obtained protection label and protection level; if the protection decision is passed, the question is input into the content risk engine to obtain the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension to which it belongs. Then, a content decision can be obtained based on the obtained content label and content level; if the content decision is passed, the decision center determines and executes the answer acquisition strategy, which is to obtain the answer without using a large model and return a rejected answer to the user.
[0046] In the embodiment of the present specification, the protection label and protection level of the question under the protection risk dimension to which it belongs are obtained, and the protection decision corresponding to the obtained protection label and protection level is obtained, the content label and content level of the question under the content risk dimension to which it belongs are obtained, and the content decision corresponding to the obtained content label and content level is obtained, the risk label and risk level of the content risk dimension, and the protection decision and the content decision are combined to determine the answer acquisition strategy, and then the answer acquisition strategy is executed, and the answer obtained by executing the answer acquisition strategy is returned to the user. This process combines the protection risk dimension and the content risk dimension to obtain the answer acquisition strategy. By adding the protection risk dimension, the protection against adversarial questions against the large model can be improved, thereby aligning the harmlessness of the large model.
[0047] Figure 6 A schematic diagram of an application scenario of a question processing method is provided, such as Figure 6 As shown, the user sends a service request to the server through a terminal such as a mobile phone, and the service request includes: executing a question processing task for a target question initiated by the user to the target large model. After receiving the service request, the server uses the question processing method in this specification to obtain the answer corresponding to the question, and sends the answer to the terminal for the user's reference.
[0048] As mentioned above, the intention dimension is an important risk protection dimension. Adversarial questions are complex and varied, and the intention dimension covers a wide range. In order to better understand the intention of the question, it is necessary to divide the intention dimension into fine-grained levels. In one implementation, the risk protection dimension includes the intention dimension. Step S102 can be executed as the following steps A1-A2: Step A1, when receiving a question, determining the protection risk dimension to which the question belongs from multiple protection risk dimensions; Step A2, when the protection risk dimension to which the question belongs includes the intention dimension, determine the sub-intention dimension to which the question belongs and the protection label and protection level of the question under the sub-intention dimension from the sub-intention dimension included in the intention dimension.
[0049] Figure 7 The structural diagram of the protection risk dimension is shown in FIG. Figure 7 As shown in Figure 3, the protection risk dimension can include topic dimension, intention dimension, and domain dimension. The broad intention dimension is divided into fine-grained categories, and the attack sub-dimension, emotion sub-dimension, and other sub-dimensions are obtained. Tables 3 to 5 show the protection types included in the three sub-intention dimensions.
[0050] Table 3 Protection types included in the attack sub-dimension of the intention dimension
[0051] As shown in Table 3, the attack sub-dimension in the intention dimension mainly focuses on three types of confrontation questions: target hijacking, reverse induction, and variant confrontation.
[0052] Table 4 Protection types included in the emotion sub-dimension of the intention dimension
[0053] As shown in Table 4, the emotion sub-dimension in the intention dimension mainly focuses on the following four types of questions: fact description-positive, fact description-negative, subject emotion-positive, and subject emotion-negative.
[0054] In addition to the question types in Table 3 and Table 4, the remaining question types are considered as other sub-intention dimensions. The types included in other sub-intention dimensions can be found in Table 5.
[0055] Table 5 Protection types included in other sub-dimensions of the intention dimension
[0056] Similar to the protection risk dimension, each intention sub-dimension also contains multiple protection labels and protection levels. Since the intention dimension contains multiple sub-intention dimensions, when receiving a question from a user input into the target macro model, the protection risk dimension to which the question belongs can be determined first. If the protection risk dimension to which the question belongs contains the intention dimension, the intention sub-dimension to which the question belongs can be further determined, and the protection label and protection level of the question under the intention sub-dimension can be determined.
[0057] In the embodiments of the present specification, when the protection risk dimension to which the question belongs includes the intention dimension, it is necessary to further determine the intention sub-dimension to which the question belongs in order to better identify the protection risk dimension of the question, thereby reducing the risk of the answer obtained in the question processing process.
[0058] Determining the protection label and protection level of the question under the protection risk type can be considered as a type classification of the question, which can be used to facilitate the subsequent determination of the content risk dimension. In one implementation, when the protection risk dimension includes the domain dimension, step S106 can be executed as the following steps B1-B2: Step B1, based on the protection label of the question under the domain dimension, determine the target content risk dimension corresponding to the question from the content risk dimension; Step B2: Determine, from the target content risk dimension, the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension to which it belongs.
[0059] The domain dimension is used to indicate the scope or area to which the question belongs. When collecting historical adversarial questions, adversarial questions can be divided into domains to obtain multiple domain dimensions. Table 6 shows some of the protection types included in the domain dimension. As shown in Table 6, adversarial questions can be related to the political, medical and government fields.
[0060] Table 6 Protection types included in the domain dimension
[0061] The target content risk dimension is the content risk dimension to which the question may belong based on the domain dimension. In one example, a mapping relationship between the domain dimension and the content risk dimension can be set, so that when the protection risk dimension determination process hits at least one preset domain dimension, the multiple content risk dimensions (i.e., target content risk dimensions) to which the question may belong can be determined through the obtained protection labels and mapping relationships.
[0062] Furthermore, the content risk dimension to which the question specifically belongs can be determined from the target content risk dimension, and the content label and content level of the question under the content risk dimension can be determined.
[0063] Figure 8 The flowchart of the content risk control engine is shown in FIG. Figure 8 As shown, determining the target content risk dimension based on the hit domain dimensions (domain 1 and domain 2) can avoid the execution of irrelevant policies.
[0064] In the above process, the target content risk dimension is determined based on the protection label under the domain dimension, the scope of the content risk dimension to which the question belongs is delineated, the execution of irrelevant strategies is reduced, the size of the decision flow is reduced, the routing function of the content strategy in the content risk dimension and the refined prevention and control of adversarial questions are realized, various costs such as machines, models, and storage are reduced, and cost reduction and efficiency improvement are better achieved.
[0065] Furthermore, the protection label and protection level of the question under the protection risk dimension can also be used to assist the determination process of the content risk dimension and / or the determination process of the content decision. In one implementation, step B2 can be executed as the following step C1: Step C1, based on the protection label and protection level of the question under the protection risk dimension, determine the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension from the target content risk dimension; And / or step S108 may be executed as the following step C2: Step C2, determining the content decision according to the protection label and protection level of the question under the protection risk dimension to which it belongs, and the content label and content level of the question under the content risk dimension to which it belongs.
[0066] Since the protection label and protection level of the question under the protection risk dimension are the understanding of the question in the protection risk dimension, in one example, the protection label and protection level of the question under the protection risk dimension can be used in the determination process of the content risk dimension to which the question belongs. Similarly, the protection label and protection level of the question under the protection risk dimension can also be used in the determination process of content decision.
[0067] like Figure 8 As shown, the protection engine is externally mounted on the content risk control engine. The protection label and protection level obtained by the protection engine enter the content risk control engine. The protection label and protection level of the question under the protection risk dimension to which it belongs are input into the content qualitative layer. This can improve the accuracy of the content risk dimension to which the question belongs as determined by the content qualitative layer, as well as the content label and content level of the question under the content risk dimension to which it belongs; the protection label and protection level of the question under the protection risk dimension to which it belongs are input into the comprehensive decision-making layer. This can improve the accuracy of the content decision determined by the comprehensive decision-making layer.
[0068] Since the protection engine includes time-consuming capacity pre-calculation and parallel calculation of tree strategies, the protection engine can be set to process questions less than or equal to 100ms to ensure the timeliness of the question processing process. In addition to the content qualitative layer and the comprehensive strategy layer, in order to reduce the pressure on the content risk control engine, Figure 8 As shown, a quick decision layer can also be set up in the content risk control engine. The quick decision layer is provided with multiple sample libraries such as a list library, a keyword library, and a link library as a whitelist or a blacklist. The labels of the obtained intent dimension are compared with the data in these sample libraries. When the comparison result indicates that the question has a high risk, the high-risk question can be quickly intercepted and handled, and a content decision that is not passed can be directly obtained, thereby reducing the pressure on the content risk prevention and control engine.
[0069] In the embodiments of the present specification, by using the protection label and protection level of the question under the protection risk dimension to which it belongs in the process of determining the content risk dimension to which the question belongs and / or the process of determining the content decision, the accuracy of the process of determining the content risk dimension to which the question belongs and / or the process of determining the content decision can be improved.
[0070] In one implementation, step S110 may be performed as the following steps D1-D2: Step D1, when the protection decision or the content decision is not passed, the answer acquisition strategy is determined to not use the target large model to obtain the answer; Step D2, when both the protection decision and the content decision are passed, the answer acquisition strategy is determined to use the target large model to obtain the answer.
[0071] Specifically, when the protection decision or content decision is not passed, it is usually indicated that the questions asked by the user to the target large model are high-risk adversarial questions, and such questions need to be directly intercepted and blocked. Fig. 9 The figure shows the process of intercepting and blocking high-risk questions. Fig. 9 As shown, if the protection decision or content decision is not passed, the decision center will make a rejection answer.
[0072] When both the protection decision and the content decision are passed, the answer acquisition strategy can be to use the target large model to obtain the answer. In the question, the topic is the subject of the question. During the training process of the target large model, the detailed information of some topics is not open to the public for special purposes. In this way, for questions under these topics, if the questions are directly input into the target large model, the simple answers obtained may not satisfy the user. In one implementation, the protection risk dimension includes the topic dimension, and step S110 can be executed as the following steps E1-E2: Step E1, when the protection risk dimension to which the question belongs includes a topic dimension, obtaining supplementary information corresponding to the question from a data source corresponding to the topic dimension to which the question belongs; Step E2, when the answer acquisition strategy is to use the target large model to obtain the answer, the question and the supplementary information source corresponding to the question are input into the target large model to obtain the answer.
[0073] The topic dimension is the dimension of the subject of the question, and the topic dimension is the dimension that supplements the information of the question in addition to the intention dimension. The topic dimension can be determined based on the collected historical questions and their corresponding answers. Table 7 shows some of the protection types included in the topic dimension.
[0074] Table 7 Protection types included in the topic dimension
[0075] Supplementary information is information that supplements questions. Since the target big model does not have enough knowledge of some topic dimensions, it is necessary to find relevant supplementary information to improve the user experience in the big model application scenario. Generally, the supplementary information corresponding to different topic dimensions can be obtained in different ways. For example, the supplementary information can be obtained from a database, a specific big model (different from the big model used by the user), etc.
[0076] In one example, the data source for obtaining supplementary information can be determined based on the topic dimension to which the question belongs, and then the supplementary information can be obtained from the data source. Specifically, it can be determined first whether the protection dimension to which the question belongs includes the topic dimension. If it does, the data source can be obtained based on the topic dimension, and the supplementary information can be obtained from the data source. In one implementation, the process of obtaining supplementary information can be performed as follows: Steps F1-F2: Step F1, when the data source is a database, extract keywords from the question, and obtain supplementary information corresponding to the question from the database based on the keywords; Step F2, when the data source is the supplementary information big model, the question is input into the supplementary information big model, and the answer corresponding to the question output by the supplementary information big model is used as the supplementary information corresponding to the question.
[0077] Specifically, when the data source of the supplementary information is a database, the supplementary information can be obtained from the database (such as a knowledge base, etc.) according to the keywords in the question, so as to enhance the prompt of the question content. Fig.10 FIG. 1 shows a schematic diagram of the process of enhancing the prompt of the question content. Fig.10 As shown, a knowledge base can be used to obtain supplementary information.
[0078] When the data source of the supplementary information is the supplementary information big model, the questions can be input into the supplementary information big model, and the answers can be used as the supplementary information to achieve secure answering of the big model. Fig.11 The schematic diagram of the process of performing security proxy on a large model is shown. Fig.11 As shown, supplementary information can be obtained using a supplementary information macro model.
[0079] Furthermore, the supplementary information and the question can be input into the target macro model together to obtain the answer which is fed back to the user.
[0080] The above process, by providing additional information to enhance prompts and / or answer questions safely, can improve the safety level of large model application scenarios while reducing the refusal rate of large models and meet special prevention and control demands in large model application scenarios.
[0081] Before feeding back the answer to the user, the answer can be checked for safety to determine whether the answer displayed to the user is safe, so as to further improve the risk prevention and control capabilities of large model application scenarios. In one implementation, step S110 can be executed as the following steps G1-G3: Step G1, determining the content risk dimension to which the answer belongs and the content label and content level of the answer under the content risk dimension from among the multiple content risk dimensions; Step G2, determining the risk identification result of the answer according to the content label and content level of the answer under the content risk dimension to which it belongs; Step G3: When the risk identification result of the answer is a preset risk level, the answer is returned to the user.
[0082] Among them, the risk identification result is the risk level of the question determined based on the protection dimension and the content risk dimension, which can be a specific risk value.
[0083] Specifically, different risk values can be set for different content labels and content levels. In this way, after obtaining the content label and content level of the answer under the content risk dimension, the risk value of the question can be determined, and then the risk identification result corresponding to the question can be determined according to the risk value. The risk identification result can be high risk, low risk and medium risk.
[0084] When the risk identification result is high risk, it means that the answer has a high risk and it is not appropriate to return the answer to the user directly. The answer can be processed to eliminate the risk. When the processed answer is converted to the preset risk level, the answer can be returned to the user. When the risk identification result is the preset risk level (such as low risk and / or medium risk), the answer can be returned to the user directly.
[0085] In the embodiments of this specification, by determining the risk identification results of the answers, the risk of the answers reaching the user can be reduced, thereby improving the risk prevention and control capabilities of large model application scenarios.
[0086] It can be understood that the above-mentioned various method embodiments mentioned in this specification can be combined with each other to form a combined embodiment without violating the principle logic. Due to space limitations, they will not be repeated in this specification. Those skilled in the art can understand that in the above-mentioned method of the specific implementation method, the specific execution order of each step should be determined according to its function and possible internal logic.
[0087] It should be noted that the question processing method provided in the embodiments of this specification may be executed by a question processing device or a control module in the question processing device for executing the question processing method. In the embodiments of this specification, the question processing device provided in the embodiments of this specification is described by taking the question processing method executed by the question processing device as an example.
[0088] Fig.12 is a schematic diagram of the structure of a device for question processing according to an embodiment of the present invention. Fig.12 As shown, the apparatus 1200 for question processing includes: The protection dimension module 1210 is used to determine the protection risk dimension to which the question belongs and the protection label and protection level of the question under the protection risk dimension from multiple protection risk dimensions when receiving a question of the target macro model input by the user; The protection decision module 1220 is used to determine the protection decision according to the protection label and protection level of the question under the protection risk dimension; The content dimension module 1230 is used to determine the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension from multiple content risk dimensions; Content decision module 1240, used to determine content decision according to the content label and content level of the question under the content risk dimension; The answer acquisition module 1250 is used to determine the answer acquisition strategy based on the target large model according to the protection decision and / or content decision, and execute the answer acquisition strategy, and return the answer obtained after executing the answer acquisition strategy to the user.
[0089] In one embodiment, the answer acquisition module 1250 includes: A first answer acquisition unit is used to determine the answer acquisition strategy as not using the target large model to acquire the answer when the protection decision or the content decision is not passed; The second answer acquisition unit is used to determine the answer acquisition strategy as using the target large model to obtain the answer when both the protection decision and the content decision are passed.
[0090] In one embodiment, the protection risk dimension includes a topic dimension, and the answer acquisition module 1250 includes: A supplementary information acquisition unit, configured to acquire supplementary information corresponding to the question from a data source corresponding to the topic dimension to which the question belongs, when the protection risk dimension to which the question belongs includes a topic dimension; The answer acquisition unit is used to input the question and the supplementary information source corresponding to the question into the target large model to obtain the answer when the answer acquisition strategy is to use the target large model to obtain the answer.
[0091] In one embodiment, the process of obtaining the supplementary information includes: When the data source is a database, keywords are extracted from the question, and supplementary information corresponding to the question is obtained from the database based on the keywords; When the data source is the supplementary information big model, the question is input into the supplementary information big model, and the answer corresponding to the question output by the supplementary information big model is used as the supplementary information corresponding to the question.
[0092] In one embodiment, the content dimension module 1230 includes: A target unit, used to determine a target content risk dimension corresponding to the question from the content risk dimension based on the protection label of the question under the domain dimension, when the protection risk dimension includes the domain dimension; The dimension unit is used to determine, from the target content risk dimension, the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension to which it belongs.
[0093] In one embodiment, determining the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension from the target content risk dimension includes: Based on the protection label and protection level of the question under the protection risk dimension, determine the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension from the target content risk dimension; and / or content decision module 1240, comprising: The content decision unit is used to determine the content decision according to the protection label and protection level of the question under the protection risk dimension to which it belongs, and the content label and content level of the question under the content risk dimension to which it belongs.
[0094] In one embodiment, the protection risk dimension includes the intention dimension, and the protection dimension module 1210 includes: A protection risk dimension unit is used to determine, when receiving a question, the protection risk dimension to which the question belongs from among multiple protection risk dimensions; The sub-intention dimension unit is used to determine the sub-intention dimension to which the question belongs and the protection label and protection level of the question under the sub-intention dimension from the sub-intention dimension included in the intention dimension when the protection risk dimension to which the question belongs includes the intention dimension.
[0095] In one embodiment, the answer acquisition module 1250 includes: A content risk dimension unit, used to determine, from a plurality of content risk dimensions, the content risk dimension to which the answer belongs and the content label and content level of the answer under the content risk dimension to which it belongs; A risk identification result unit, used to determine the risk identification result of the answer according to the content label and content level of the answer under the content risk dimension to which it belongs; The answer returning unit is used to return the answer to the user when the risk identification result of the answer is a preset risk level.
[0096] It should be noted that the embodiments of the apparatus for question processing in this specification and the embodiments of the method for question processing in this specification are based on the same inventive concept, so the specific implementation of this embodiment can refer to the implementation of the corresponding method for question processing mentioned above, and the repeated parts will not be repeated.
[0097] Each module in the above-mentioned question processing device can be implemented in whole or in part by software, hardware and a combination thereof. Each of the above-mentioned modules can be embedded in or independent of the processor in the terminal device or the processor on the server in the form of hardware, or can be stored in the memory in the terminal device or the memory on the server in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.
[0098] Further, corresponding to the question processing method described above, based on the same technical concept, one or more embodiments of this specification also provide an electronic device, which is used to execute the question processing method described above. Fig.13 A schematic diagram of the structure of an electronic device provided for one or more embodiments of this specification.
[0099] Based on the same idea, one or more embodiments of this specification also provide an electronic device, such as Fig.13 As shown. The electronic device may have relatively large differences due to different configurations or performances, and may include one or more processors 1301 and memory 1302, and the memory 1302 may store one or more storage applications or data. Among them, the memory 1302 may be a short-term storage or a permanent storage. The application stored in the memory 1302 may include one or more modules (not shown in the figure), and each module may include a series of computer executable instructions in the electronic device. Furthermore, the processor 1301 can be configured to communicate with the memory 1302 to execute a series of computer executable instructions in the memory 1302 on the electronic device. The electronic device may also include one or more power supplies 1303, one or more wired or wireless network interfaces 1304, one or more input and output interfaces 1305, and one or more keyboards 1306.
[0100] In a specific embodiment, the electronic device includes a memory and one or more programs, wherein the one or more programs are stored in the memory, and the one or more programs may include one or more modules, and each module may include a series of computer executable instructions for the electronic device, and the one or more programs configured to be executed by one or more processors include the following computer executable instructions: When receiving a question input by a user into the target large model, determining the protection risk dimension to which the question belongs and the protection label and protection level of the question under the protection risk dimension from multiple protection risk dimensions; Determine the protection decision based on the protection label and protection level of the question under the protection risk dimension; From multiple content risk dimensions, determine the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension to which it belongs; Determine content decisions based on the content label and content level of the question under the content risk dimension. According to the protection decision and / or content decision, determine the answer acquisition strategy based on the target large model, execute the answer acquisition strategy, and return the answer obtained after executing the answer acquisition strategy to the user.
[0101] It should be noted that the embodiment of the electronic device in this specification and the embodiment of the method for question processing in this specification are based on the same inventive concept, so the specific implementation of this embodiment can refer to the implementation of the aforementioned corresponding method for question processing, and the repeated parts will not be repeated.
[0102] Furthermore, corresponding to the question processing method described above, based on the same technical concept, one or more embodiments of this specification further provide a storage medium for storing computer executable instructions. In a specific embodiment, the storage medium may be a USB flash drive, an optical disk, a hard disk, etc. When the computer executable instructions stored in the storage medium are executed by the processor, the following process can be implemented: When receiving a question input by a user into the target large model, determining the protection risk dimension to which the question belongs and the protection label and protection level of the question under the protection risk dimension from multiple protection risk dimensions; Determine the protection decision based on the protection label and protection level of the question under the protection risk dimension; From multiple content risk dimensions, determine the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension to which it belongs; Determine content decisions based on the content label and content level of the question under the content risk dimension. According to the protection decision and / or content decision, determine the answer acquisition strategy based on the target large model, execute the answer acquisition strategy, and return the answer obtained after executing the answer acquisition strategy to the user.
[0103] It should be noted that the embodiment of the storage medium in this specification and the method of question processing in this specification are based on the same inventive concept, so the specific implementation of this embodiment can refer to the implementation of the corresponding question processing method mentioned above, and the repeated parts will not be repeated.
[0104] Furthermore, corresponding to the question processing method described above, based on the same technical concept, one or more embodiments of this specification also provide a computer program product, the computer program product includes a computer program, and when the computer program is executed by a processor, the following process can be implemented: When receiving a question input by a user into the target large model, determining the protection risk dimension to which the question belongs and the protection label and protection level of the question under the protection risk dimension from multiple protection risk dimensions; Determine the protection decision based on the protection label and protection level of the question under the protection risk dimension; From multiple content risk dimensions, determine the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension to which it belongs; Determine content decisions based on the content label and content level of the question under the content risk dimension. According to the protection decision and / or content decision, determine the answer acquisition strategy based on the target large model, execute the answer acquisition strategy, and return the answer obtained after executing the answer acquisition strategy to the user.
[0105] It should be noted that the embodiment of the computer program product in this specification and the embodiment of the question processing method in this specification are based on the same inventive concept, so the specific implementation of this embodiment can refer to the implementation of the aforementioned corresponding question processing method, and the repeated parts will not be repeated.
[0106] The above is a description of a specific embodiment of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0107] In the 1990s, it was very clear whether the improvement of a technology was hardware improvement (for example, improvement of the circuit structure of diodes, transistors, switches, etc.) or software improvement (improvement of the method flow). However, with the development of technology, many improvements of the method flow today can be regarded as direct improvements of the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that the improvement of a method flow cannot be implemented with a hardware entity module. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit whose logical function is determined by the user's programming of the device. Designers can "integrate" a digital system on a PLD by programming themselves, without having to ask chip manufacturers to design and make dedicated integrated circuit chips. Moreover, nowadays, instead of manually making integrated circuit chips, this kind of programming is mostly implemented by "logic compiler" software, which is similar to the software compiler used when developing and writing programs, and the original code before compilation must also be written in a specific programming language, which is called hardware description language (HDL). There is not only one kind of HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also know that it is only necessary to program the method flow slightly in the above-mentioned hardware description languages and program it into the integrated circuit, and then it is easy to obtain the hardware circuit that implements the logic method flow.
[0108] The controller may be implemented in any suitable manner, for example, the controller may take the form of a microprocessor or processor and a computer-readable medium storing a computer-readable program code (e.g., software or firmware) executable by the (micro)processor, a logic gate, a switch, an application-specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller, examples of which include but are not limited to the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320, and the memory controller may also be implemented as part of the control logic of the memory. It is also known to those skilled in the art that, in addition to implementing the controller in a purely computer-readable program code manner, the controller may be implemented in the form of a logic gate, a switch, an application-specific integrated circuit, a programmable logic controller, and an embedded microcontroller by logically programming the method steps. Therefore, such a controller may be considered as a hardware component, and the devices for implementing various functions included therein may also be considered as structures within the hardware component. Or even, the devices for implementing various functions may be considered as both software modules for implementing the method and structures within the hardware component.
[0109] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0110] For the convenience of description, the above devices are described in terms of functions and are divided into various units. Of course, when implementing the embodiments of this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0111] It should be understood by those skilled in the art that one or more embodiments of the present specification may be provided as a method, system or computer program product. Therefore, one or more embodiments of the present specification may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0112] This specification is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of this specification. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0113] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0114] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0115] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0116] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0117] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined in this article, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0118] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0119] One or more embodiments of the present specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. One or more embodiments of the present specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0120] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0121] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.
Claims
1. A method for question processing, comprising: When receiving a question input by a user into the target macro model, determining, from multiple protection risk dimensions, the protection risk dimension to which the question belongs and the protection label and protection level of the question under the protection risk dimension to which it belongs; Determine a protection decision based on the protection label and protection level of the question under the protection risk dimension to which it belongs; Determining, from a plurality of content risk dimensions, the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension to which it belongs; Determine a content decision according to the content label and content level of the question under the content risk dimension; According to the protection decision and / or the content decision, an answer acquisition strategy based on the target macro model is determined, and the answer acquisition strategy is executed, and the answer obtained after executing the answer acquisition strategy is returned to the user.
2. The method according to claim 1, wherein determining the answer acquisition strategy based on the target macro model according to the protection decision and / or the content decision comprises: When the protection decision or the content decision is not passed, determining the answer acquisition strategy to not use the target large model to acquire the answer; When both the protection decision and the content decision are passed, the answer acquisition strategy is determined to use the target large model to acquire the answer.
3. According to the method of claim 2, the protection risk dimension includes a topic dimension, and the execution of the answer acquisition strategy comprises: In a case where the protection risk dimension to which the question belongs includes the topic dimension, obtaining supplementary information corresponding to the question from a data source corresponding to the topic dimension to which the question belongs; When the answer acquisition strategy is to use the target macro model to acquire the answer, the question and the supplementary information source corresponding to the question are input into the target macro model to obtain the answer.
4. The method according to claim 3, wherein the process of obtaining the supplementary information comprises: When the data source is a database, extracting keywords from the question, and acquiring supplementary information corresponding to the question from the database based on the keywords; In the case where the data source is a supplementary information macromodel, the question is input into the supplementary information macromodel, and the answer corresponding to the question output by the supplementary information macromodel is used as the supplementary information corresponding to the question.
5. According to the method of claim 1, when the protection risk dimension includes a domain dimension, determining the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension from multiple content risk dimensions comprises: Based on the protection label of the question under the domain dimension, determining the target content risk dimension corresponding to the question from the content risk dimension; From the target content risk dimension, the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension are determined.
6. The method according to claim 5, wherein determining, from the target content risk dimension, the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension to which the question belongs comprises: Based on the protection label and protection level of the question under the protection risk dimension, determine the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension from the target content risk dimension; and / or determining a content decision according to the content label and content level of the question under the content risk dimension, including: The content decision is determined according to the protection label and protection level of the question under the protection risk dimension and the content label and content level of the question under the content risk dimension.
7. The method according to claim 1, wherein the protection risk dimension includes an intention dimension, and when a question of the target macro model is received from a user, determining the protection risk dimension to which the question belongs and the protection label and protection level of the question under the protection risk dimension from multiple protection risk dimensions, comprises: When receiving the question, determining the protection risk dimension to which the question belongs from the plurality of protection risk dimensions; In the case that the protection risk dimension to which the question belongs includes the intention dimension, the sub-intention dimension to which the question belongs and the protection label and protection level of the question under the sub-intention dimension are determined from the sub-intention dimension included in the intention dimension.
8. According to the method of claim 1, the step of returning to the user the answer obtained after executing the answer acquisition strategy comprises: Determining, from the plurality of content risk dimensions, the content risk dimension to which the answer belongs and the content label and content level of the answer under the content risk dimension to which it belongs; Determining a risk identification result of the answer according to the content label and content level of the answer under the content risk dimension to which it belongs; When the risk identification result of the answer is a preset risk level, the answer is returned to the user.
9. A device for question processing, comprising: A protection dimension module is used to determine, from multiple protection risk dimensions, the protection risk dimension to which the question belongs and the protection label and protection level of the question under the protection risk dimension to which it belongs, when receiving a question input by a user into the target macro model; A protection decision module, used to determine a protection decision according to the protection label and protection level of the question under the protection risk dimension; A content dimension module, used to determine, from a plurality of content risk dimensions, the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension to which it belongs; A content decision module, used to determine a content decision according to the content label and content level of the question under the content risk dimension; An answer acquisition module is used to determine an answer acquisition strategy based on the target large model according to the protection decision and / or the content decision, execute the answer acquisition strategy, and return the answer obtained after executing the answer acquisition strategy to the user.
10. An electronic device comprising: processor, and a memory arranged to store computer executable instructions which, when executed, cause the processor to: When receiving a question input by a user into the target macro model, determining, from multiple protection risk dimensions, the protection risk dimension to which the question belongs and the protection label and protection level of the question under the protection risk dimension to which it belongs; Determine a protection decision based on the protection label and protection level of the question under the protection risk dimension to which it belongs; Determining, from a plurality of content risk dimensions, the content risk dimension to which the question belongs and the content label and content level of the question under the content risk dimension to which it belongs; Determine a content decision according to the content label and content level of the question under the content risk dimension; According to the protection decision and / or the content decision, an answer acquisition strategy based on the target macro model is determined, and the answer acquisition strategy is executed, and the answer obtained after executing the answer acquisition strategy is returned to the user.
Citation Information
Patent Citations
Large model security evaluation method and device, computer equipment and storage medium
CN117874177A
Question reply system, question reply method, storage medium, and program product
CN118627620A
Power knowledge question-answering system construction method and system in combination with engineering ethical analysis
CN119293185A
Safety evaluation method based on large language model and related device
CN119357021A
Apparatus and method for automated risk assessment
US12039612B1