Protection method and device for medical big language model

By detecting sensitive words and intentions for user input and judging their relevance with the medical field based on AI models, the problem of unrelated content in the application of traditional large language models in the medical field is solved, and high-quality and professional medical information output is achieved.

CN120015339APending Publication Date: 2025-05-16Artificial Intelligence and Robotics Innovation Center of Hong Kong Institute of Innovation, Chinese Academy of Sciences
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202411869945.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-18
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

There are problems with irrelevant dialogue content in the application of traditional large language models in the medical field, which leads to the large language models of medical large languages ​​that are prone to misleading information and cannot provide high-quality responses, which reduces their professionalism and effectiveness.

Method used

By performing sensitive word detection and intention detection on user input, we can determine whether it is related to the medical field. If relevant, input it into the medical language model for content production, and conduct sensitive word detection and intention detection after content production to ensure the relevance and safety of the output.

Benefits of technology

A dialogue framework specifically targeting medical scenarios is realized to ensure that the output content of the medical large language model closely revolves around the medical topic, provide accurate and reliable medical information, avoid irrelevant or potentially harmful topics, thereby improving its professionalism and effectiveness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120015339A_ABST
    Figure CN120015339A_ABST
Patent Text Reader

Abstract

The invention provides a medical large language model protection method and device, and relates to the technical field of artificial intelligence, and the method comprises the steps: carrying out the sensitive word detection and intention detection of user input; under the condition that the user input does not contain sensitive words and has no bad intention, whether the user input is related to the medical field or not is judged based on an AI model; and under the condition that the user input is related to the medical field, inputting the user input into the medical big language model for content production. According to the invention, the specialty and effectiveness of the medical big language model are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence technology, and in particular to a protection method and device for a large medical language model. Background Art

[0002] With the development of natural language processing technology, more and more studies are being conducted on applying large language models to the medical field.

[0003] Traditional large language models have the problem of irrelevant conversation content in medical applications, which makes the medical large language model (i.e., the large language model applied in the medical field) easily generate misleading information and fail to provide high-quality responses, reducing the professionalism and effectiveness of the medical large language model.

[0004] Therefore, it is necessary to provide a protection method for the medical large language model to improve the professionalism and effectiveness of the medical large language model. Summary of the invention

[0005] The present invention provides a protection method and device for a medical large language model, which are used to solve the defects of low professionalism and effectiveness of the medical large language model in the prior art, and to improve the professionalism and effectiveness of the medical large language model.

[0006] The present invention provides a method for protecting a large medical language model, comprising: Perform sensitive word detection and intent detection on user input; If the user input does not contain sensitive words and has no bad intentions, determine whether the user input is related to the medical field based on the AI ​​model; In the case where the user input is related to the medical field, the user input is input into a medical big language model for content production.

[0007] In some embodiments, the sensitive word detection and intent detection of the user input includes: Based on the AC automaton algorithm and the sensitive word library, sensitive word detection is performed on the user input; The user input is subjected to intent detection based on the LoRA fine-tuned protection model.

[0008] In some embodiments, before the LoRA-based fine-tuning protection model performs intent detection on the user input, it includes: Generating training data for protection scenarios and preprocessing the training data; Based on the preprocessed training data, the protection model is fine-tuned by LoRA.

[0009] In some embodiments, the determining whether the user input is related to the medical field based on the AI ​​model includes: Based on the AI ​​model, prompt engineering and state machine pipeline, determine whether the user input is related to the medical field.

[0010] In some embodiments, after inputting the user input into the medical big language model for content production, the process further includes: Perform sensitive word detection and intent detection on the production content of the medical large language model sentence by sentence.

[0011] In some embodiments, the guard model is a Llama Guard model.

[0012] The present invention also provides a protective device for a large medical language model, comprising: The first detection module is used to detect sensitive words and intentions of user input; A judgment module, used to judge whether the user input is related to the medical field based on the AI ​​model when the user input does not contain sensitive words and does not have bad intentions; The content production module is used to input the user input into the medical large language model for content production when the user input is related to the medical field.

[0013] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the protection method of the medical large language model as described in any one of the above is implemented.

[0014] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a method for protecting a large medical language model as described in any one of the above.

[0015] The present invention also provides a computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the protection method of the medical large language model as described in any one of the above is implemented.

[0016] The protection method and device of the medical big language model provided by the present invention realize a dialogue framework specifically for medical scenarios through sensitive word detection, intent detection and relevant judgments in the medical field, ensure that the output content of the medical big language model closely revolves around medical topics, provides accurate and reliable medical information, avoids irrelevant or potentially harmful topics, thereby improving the professionalism and effectiveness of the medical big language model. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0018] Figure 1 This is one of the flow charts of the protection method of the medical large language model provided by the present invention; Figure 2 This is the second flow chart of the protection method of the medical large language model provided by the present invention; Figure 3 It is a structural schematic diagram of the protective device of the medical large language model provided by the present invention; Figure 4 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION

[0019] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0020] Figure 1 This is one of the flow charts of the protection method of the medical large language model provided by the present invention, such as Figure 1 As shown, the present invention provides a method for protecting a large medical language model, comprising the following steps: Step 110, perform sensitive word detection and intent detection on the user input.

[0021] Specifically, in the medical field, a large amount of sensitive information is involved, such as patient privacy, drug names, medical ethics and medical procedures, etc. Therefore, it is necessary to detect sensitive words in user input to protect patient privacy and comply with industry regulations.

[0022] In addition, user input may have bad intentions, such as containing pornographic, political, violent, abusive words, etc. Therefore, it is also necessary to detect the user input's intention to determine whether the user input involves a protection scenario, which may include political scenarios, historical and celebrity evaluation scenarios, and non-medical scenarios. If the user output involves a protection scenario, it indicates that the user input has bad intentions; if the user output does not involve a protection scenario, it indicates that the user input does not have bad intentions.

[0023] Step 120, when the user input does not contain sensitive words and does not have bad intentions, determine whether the user input is related to the medical field based on the AI ​​model.

[0024] Specifically, when the user input does not contain sensitive words and has no bad intentions, the A1 model is used to determine whether the user input is related to the medical field, so as to limit the user input to medical scenarios. The AI ​​model refers to a language model based on the transformer architecture.

[0025] Step 130 , when the user input is related to the medical field, the user input is input into the medical big language model for content production.

[0026] Specifically, when the user input is related to the medical field, the user input is input into the medical big language model for content production, and the produced content is returned to the user.

[0027] The protection method of the medical big language model provided in the embodiment of the present invention realizes a dialogue framework specifically for medical scenarios through sensitive word detection, intent detection and relevant judgments in the medical field, ensures that the output content of the medical big language model closely revolves around medical topics, provides accurate and reliable medical information, avoids irrelevant or potentially harmful topics, thereby improving the professionalism and effectiveness of the medical big language model.

[0028] In some embodiments, sensitive word detection and intent detection are performed on user input, including: Based on the AC automaton algorithm and sensitive word library, sensitive word detection is performed on user input; The LoRA-based fine-tuned protection model performs intent detection on user input.

[0029] Specifically, existing protection technologies often introduce significant delays when performing content detection, affecting the user experience. Especially in medical scenarios, timely feedback is crucial.

[0030] Sensitive words are collected to build a sensitive word library. The AC automaton algorithm is used to perform multi-modal string matching between the user input and the sensitive word library to quickly retrieve whether the user input contains sensitive words.

[0031] The LoRA-fine-tuned protection model is used to detect the intent of user input to improve the ability to recognize protection scenarios.

[0032] In some embodiments, the protection model may be a Llama Guard model, which can provide protection against 14 risk categories, such as violent crime and code abuse.

[0033] The protection method of the medical large language model provided in the embodiment of the present invention optimizes the detection process through the AC automaton algorithm and the LoRA fine-tuned protection model, improves the detection processing speed, and makes it possible to quickly respond to user input and generate streaming output while ensuring security, thereby reducing unnecessary delays and providing a smoother interactive experience.

[0034] In some embodiments, before the LoRA-based fine-tuned protection model performs intent detection on user input, it includes: Generate training data for protection scenarios and preprocess the training data; Based on the preprocessed training data, the protection model is fine-tuned using LoRA.

[0035] Specifically, for protection scenarios, using artificial intelligence (AI) technology to generate training data, using AI technology to generate training data related to protection scenarios can improve the adaptability and accuracy of protection models. Preprocessing training data, such as screening, cleaning, translating, combining and formatting training data.

[0036] The protection model is fine-tuned using LoRA using the preprocessed training data. That is, the preprocessed training data is input into the protection model to impose a low-rank structure on the parameters of the protection model to enhance the protection model's ability to recognize protection scenarios.

[0037] The protection method of the medical large language model provided in the embodiment of the present invention improves the recognition ability of the protection model for the protection scenario by performing LoRA fine-tuning on the protection model according to the training data of the protection scenario.

[0038] In some embodiments, determining whether the user input is related to the medical field based on the AI ​​model includes: Based on AI models, prompt engineering and state machine pipeline, determine whether user input is related to the medical field.

[0039] Specifically, using prompt engineering, the boundaries and definitions of medical questions are injected into user input as prompt words, thereby guiding the AI ​​model to determine whether the user input is related to the medical field. Through prompt engineering, the AI ​​model's ability to judge medical questions is optimized, and the accuracy and relevance of the response are improved.

[0040] Establish a state machine pipeline: Through the prompt project, the user input is passed to the AI ​​model for preliminary judgment to determine whether the user input content is related to the medical field; if it is judged to be relevant, the user input is passed to the AI ​​model again for judgment. By designing a multi-round self-detection mechanism, prompt word attacks and information misleading can be prevented.

[0041] The protection method of the medical large language model provided in the embodiment of the present invention enables the AI ​​model to intelligently judge the relevance of user input to the medical field through prompt engineering, and at the same time reduces the probability of prompt word injection and jailbreaking through the state machine pipeline, thereby facilitating the subsequent medical large language model to provide high-quality responses in medical-related dialogues and reduce the generation of misleading information.

[0042] In some embodiments, after inputting the user input into the medical big language model for content production, the method further includes: Perform sensitive word detection and intent detection on the production content of the medical large language model sentence by sentence.

[0043] Specifically, after the medical big language model produces content based on user input, the generated content of the medical big language model is subjected to sensitive word detection and intent detection sentence by sentence, that is, the content produced by the medical big language model is subjected to sensitive word detection and intent detection in a streaming output and segmented inspection manner. If the produced content does not contain sensitive words and does not have bad intentions, the produced content is output in a streaming output manner.

[0044] The protection method of the medical big language model provided in the embodiment of the present invention implements output control of the production content of the medical big language model by performing sensitive word detection and intent detection on the production content of the medical big language model sentence by sentence, thereby avoiding the outflow of misleading information.

[0045] Figure 2 This is the second flow chart of the protection method of the medical large language model provided by the present invention, such as Figure 2 As shown, the present invention provides a method for protecting a large medical language model, comprising: Based on the AC automaton algorithm and sensitive word library, the user input is detected for sensitive words to determine whether the user input contains sensitive words. Based on the LoRA fine-tuned protection model, the user input is detected for intent to determine whether the user input has bad intentions. If the user input contains sensitive words, an error is returned. If the user input has bad intentions, an error is returned.

[0046] If the user input does not contain sensitive words and has no bad intentions, the user input is input into the AI ​​model, and the AI ​​model determines whether it is related to the medical field. If the user input is not related to the medical field, an error is returned.

[0047] When the user input is related to the medical field, the user input is input into the medical large language model for content production, and the produced content is subjected to sensitive word detection and intent detection in a streaming output and segmented inspection manner. That is, sensitive word detection is performed on the produced content based on the AC automaton algorithm and sensitive word library to determine whether the produced content contains sensitive words; the intention detection is performed on the produced content based on the LoRA fine-tuned protection model to determine whether the produced content has bad intentions. If the produced content contains sensitive words, an error is returned. If the produced content has bad intentions, an error is returned.

[0048] When the produced content does not contain sensitive words and has no bad intentions, the produced content will be output in a streaming output manner.

[0049] The protective device for the medical large language model provided by the present invention is described below. The protective device for the medical large language model described below and the protective method for the medical large language model described above can be referenced to each other.

[0050] Figure 3 Schematic diagram of the structure of the protective device of the medical large language model provided by the present invention, such as Figure 3 As shown, the present invention provides a protective device for a large medical language model, comprising: The first detection module 310 is used to perform sensitive word detection and intention detection on user input; A judgment module 320, configured to judge whether the user input is related to the medical field based on the AI ​​model when the user input does not contain sensitive words and does not have bad intentions; The content production module 330 is used to input the user input into the medical big language model for content production when the user input is related to the medical field.

[0051] In some embodiments, the first detection module 310 has a function of: Based on the AC automaton algorithm and the sensitive word library, sensitive word detection is performed on the user input; The user input is subjected to intent detection based on the LoRA fine-tuned protection model.

[0052] In some embodiments, the apparatus further comprises: A processing module, used to generate training data for protection scenarios and pre-process the training data; A fine-tuning module is used to perform LoRA fine-tuning on the protection model based on the preprocessed training data.

[0053] In some embodiments, the determination module 320 is configured to: Based on the AI ​​model, prompt engineering and state machine pipeline, determine whether the user input is related to the medical field.

[0054] In some embodiments, the apparatus further comprises: The second detection module is used to perform sensitive word detection and intent detection on the production content of the medical large language model sentence by sentence.

[0055] In some embodiments, the guard model is a Llama Guard model.

[0056] It should be noted here that the protection device of the above-mentioned medical large language model provided by the present invention can implement all the method steps implemented by the above-mentioned method embodiment, and can achieve the same technical effect. The parts and beneficial effects that are the same as the method embodiment in this embodiment will not be described in detail here.

[0057] Figure 4 is a schematic diagram of the structure of the electronic device provided by the present invention, such as Figure 4 As shown, the electronic device may include: a processor 410, a communication interface 420, a memory 430 and a communication bus 440, wherein the processor 410, the communication interface 420 and the memory 430 communicate with each other through the communication bus 440. The processor 410 may call the logic instructions in the memory 430 to execute the protection method of the medical large language model, which includes: performing sensitive word detection and intention detection on the user input; if the user input does not contain sensitive words and does not have bad intentions, judging whether the user input is related to the medical field based on the AI ​​model; if the user input is related to the medical field, inputting the user input into the medical large language model for content production.

[0058] In addition, the logic instructions in the above-mentioned memory 430 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when it is sold or used as an independent product. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.

[0059] On the other hand, the present invention also provides a computer program product, which includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the protection method of the medical big language model provided by the above methods, which method includes: performing sensitive word detection and intention detection on user input; when the user input does not contain sensitive words and does not have bad intentions, judging whether the user input is related to the medical field based on the AI ​​model; when the user input is related to the medical field, inputting the user input into the medical big language model for content production.

[0060] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a method for protecting the medical big language model provided by the above-mentioned methods, the method comprising: performing sensitive word detection and intent detection on user input; when the user input does not contain sensitive words and does not have bad intentions, determining whether the user input is related to the medical field based on an AI model; when the user input is related to the medical field, inputting the user input into the medical big language model for content production.

[0061] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.

[0062] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0063] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for protecting a large medical language model, characterized in that: include: Perform sensitive word detection and intent detection on user input; If the user input does not contain sensitive words and has no bad intentions, determine whether the user input is related to the medical field based on the AI ​​model; In the case where the user input is related to the medical field, the user input is input into a medical big language model for content production.

2. The method for protecting a large medical language model according to claim 1, characterized in that: The sensitive word detection and intention detection of user input includes: Based on the AC automaton algorithm and the sensitive word library, sensitive word detection is performed on the user input; The user input is subjected to intent detection based on the LoRA fine-tuned protection model.

3. The method for protecting a large medical language model according to claim 2, characterized in that: Before the LoRA-based fine-tuning protection model performs intent detection on the user input, it includes: Generating training data for protection scenarios and preprocessing the training data; Based on the preprocessed training data, the protection model is fine-tuned by LoRA.

4. The method for protecting a large medical language model according to claim 1, characterized in that: The determining whether the user input is related to the medical field based on the AI ​​model includes: Based on the AI ​​model, prompt engineering and state machine pipeline, determine whether the user input is related to the medical field.

5. The method for protecting a large medical language model according to claim 1, characterized in that: After inputting the user input into the medical large language model for content production, the method further includes: Perform sensitive word detection and intent detection on the production content of the medical large language model sentence by sentence.

6. The method for protecting a large medical language model according to claim 2 or 3, characterized in that: The protection model is the Llama Guard model.

7. A protective device for a large medical language model, characterized in that: include: The first detection module is used to detect sensitive words and intentions of user input; A judgment module, used to judge whether the user input is related to the medical field based on the AI ​​model when the user input does not contain sensitive words and does not have bad intentions; The content production module is used to input the user input into the medical large language model for content production when the user input is related to the medical field.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the protection method of the medical large language model as described in any one of claims 1 to 6 is implemented.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the protection method of the medical large language model as claimed in any one of claims 1 to 6 is implemented.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the protection method of the medical large language model as claimed in any one of claims 1 to 6 is implemented.

Citation Information

Cited By

  • Medical question and answer risk control method and device

    CN120767013A