Large model response method and device based on permission awareness and electronic equipment
By introducing access control model and permission perception mechanism into the big model, the shortcomings of the big model in personalized response and permission management are solved, and refined processing and permission control of user requests are realized, and the security and personalized service capabilities of the system are improved.
Patent Information
- Application Number
- CN202510050884.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-13
- Publication Date
- 2025-05-23
AI Technical Summary
Existing large models have shortcomings in personalized response and permission management, lack of real-time flexibility and adaptability, resulting in high computational costs and difficulty in dealing with new task types or permission requirements.
By obtaining the access control method selected by the user and setting permission levels when receiving user requests, the trained access control model is called, the user request content and permission information is analyzed to evaluate and respond to requests, and the request and response are recorded for auditing.
It realizes refined processing and permission control of user requests, improves the system's security, accuracy and personalized service capabilities, reduces computing costs, and prevents data abuse and privacy leakage.
Smart Images

Figure CN120030527A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of large model technology, for example, to a large model response method and device based on authority perception, and electronic equipment. Background Art
[0002] Although existing general large models have made significant progress in providing rich and diverse responses, they still have shortcomings in personalized responses and permission management. These models often ignore the importance of individual differences, resulting in poor performance when processing sensitive information, providing professional consultation or personalized recommendations. The lack of effective access control mechanisms has made problems such as data abuse, content distortion and privacy infringement increasingly prominent. Therefore, large models need more accurate personalized responses to generate content that better meets user needs.
[0003] In order to achieve more accurate personalized responses, the relevant technology discloses a knowledge-controllable big model data processing method, including: based on the user's permissions and the type of data processing tasks, determining the target knowledge plug-in from the knowledge plug-ins pre-trained on the big model using data of different permissions and types; loading the target knowledge plug-in into the big model, changing the big model to a fine-tuned big model; and using the fine-tuned big model to respond to the user's data processing instructions.
[0004] In the process of implementing the embodiments of the present disclosure, it is found that there are at least the following problems in the related art:
[0005] Related technologies require that large models be trained in advance according to different permissions and task types to generate corresponding knowledge plug-ins. Knowledge plug-ins are created based on predefined permissions and task types, lacking real-time flexibility and adaptability. When new task types or permission requirements arise, large models may need to be retrained, increasing computational costs.
[0006] It should be noted that the information disclosed in the above background technology section is only used to enhance the understanding of the background of the present application, and therefore may include information that does not constitute the prior art known to ordinary technicians in the field. Summary of the invention
[0007] In order to provide a basic understanding of some aspects of the disclosed embodiments, a brief summary is given below. The summary is not an extensive review, nor is it intended to identify key / critical components or delineate the scope of protection of these embodiments, but rather serves as a prelude to the detailed description that follows.
[0008] The embodiments of the present disclosure provide a large model response method and device based on permission perception, and an electronic device, which can enhance the permission perception capability of the large model and greatly reduce the computing cost.
[0009] In some embodiments, the permission-aware large model response method includes: upon receiving a user request, obtaining the access control method selected by the user and setting the user's permission level; wherein the user's permission level corresponds to the access control method; calling a trained access control model and obtaining a response from the access control model; wherein the access control model corresponds to the user's permission level; and recording user requests and responses to the access control model for auditing.
[0010] Optionally, after receiving the user request, it also includes: verifying the user's password based on the password created by the user; if the password verification is successful, verifying the user's verification code based on the temporary verification code sent by the system; if the verification code verification is successful, determining that the user has logged in successfully to select an access control method.
[0011] Optionally, password verification is performed on the user based on the password created by the user, including: hashing the password created by the user to obtain a first password and storing it in a database; hashing the password in the user request to obtain a second password; and determining that the password verification is successful when the first password is the same as the second password.
[0012] Optionally, the access control model includes a mandatory access control model, a role-based access control model and an attribute-based access control model, and the access control model is trained in the following manner: obtain a data set for training; wherein the data set includes text content, pattern labels and permission labels; select an access control model according to the pattern label; and train the access control model using LoRA (Long Range Radio) technology based on the text content and the permission label.
[0013] Optionally, the access control model is trained using LoRA technology based on the text content and permission labels, including: updating the pre-trained weight matrix based on the first low-rank matrix and the second low-rank matrix; and adjusting some model parameters based on the updated weight matrix to train the access control model.
[0014] Optionally, when the pre-trained weight matrix is updated according to the first low-rank matrix and the second low-rank matrix, the forward propagation process of the data is modified according to the following formula:
[0015] h=W 0 x+ΔWx=W 0 X+M 2 M 1 x
[0016] Among them, h is the generated output data, x is the input data, W 0 is the pre-trained weight matrix, ΔW is the 0The low-rank correction, M 1 is the first low-rank matrix, M 2 is the second low-rank matrix, and the first low-rank matrix and the second low-rank matrix have smaller dimensions than the pre-trained weight matrix.
[0017] Optionally, the authority-aware large model response method also includes: calculating the gradients of the first low-rank matrix and the second low-rank matrix respectively according to a preset mean square error loss function; and optimizing the first low-rank matrix and the second low-rank matrix using a gradient descent method according to the gradients.
[0018] In some embodiments, the permission-aware big model response device includes: a permission management module, configured to obtain the access control method selected by the user and set the user's permission level when receiving a user request; wherein the user's permission level corresponds to the access control method; a big model module, configured to call a trained access control model and obtain a response from the access control model; wherein the access control model corresponds to the user's permission level; a log and audit module, configured to record user requests and responses to the access control model for auditing.
[0019] In some embodiments, the permission-aware large model response device includes: a processor and a memory storing program instructions, and the processor is configured to execute the permission-aware large model response method as described above when running the program instructions.
[0020] In some embodiments, the electronic device includes: an electronic device body; and a permission-aware large model response device as described above, installed on the electronic device body.
[0021] The permission-aware large model response method, device, and electronic device provided in the embodiments of the present disclosure can achieve the following technical effects:
[0022] The disclosed embodiment realizes the refined processing and permission control of user requests, thereby improving the security, accuracy and personalized service capabilities of the system. First, when receiving a user request, the access control method selected by the user is obtained and the corresponding permission level is set according to the user's selection. Next, the trained access control model is called, and the model corresponds to the user's permission level, and can evaluate and respond to the request according to the user's permission information. The access control model will analyze factors such as the user's request content, context environment, and the user's historical behavior to determine whether the user has the right to execute the request and generate a corresponding response result. Finally, the user request and the response of the access control model are recorded for post-audit. It provides important audit basis for system administrators, helps to discover potential security issues, analyze user behavior patterns and optimize permission management strategies. In this way, the permission-aware large model response method enhances the permission perception ability of the large model, can effectively prevent data abuse and privacy leakage, and ensure that users obtain the required services within the scope of their permissions.
[0023] The above general description and the following description are exemplary and explanatory only and are not intended to limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] One or more embodiments are exemplarily described by corresponding drawings, which do not limit the embodiments. Elements with the same reference numerals in the drawings are shown as similar elements, and the drawings do not constitute a scale limitation, and wherein:
[0025] Figure 1 It is a schematic diagram of an implementation environment of a permission-aware large model response provided by an embodiment of the present disclosure;
[0026] Figure 2 is a schematic diagram of a permission-aware large model response method provided by an embodiment of the present disclosure;
[0027] Figure 3 is a schematic diagram of another permission-aware large model response method provided by an embodiment of the present disclosure;
[0028] Figure 4 It is a schematic diagram of LoRA technology training provided by an embodiment of the present disclosure;
[0029] Figure 5 is a schematic diagram of a large model response device based on authority perception provided by an embodiment of the present disclosure;
[0030] Figure 6 It is a schematic diagram of another permission-aware large model response device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION
[0031] In order to be able to understand the features and technical contents of the embodiments of the present disclosure in more detail, the implementation of the embodiments of the present disclosure is described in detail below in conjunction with the accompanying drawings. The attached drawings are for reference only and are not used to limit the embodiments of the present disclosure. In the following technical description, for the convenience of explanation, a full understanding of the disclosed embodiments is provided through multiple details. However, one or more embodiments can still be implemented without these details. In other cases, to simplify the drawings, well-known structures and devices can be simplified for display.
[0032] The terms "first", "second", etc. in the technical solutions described in the embodiments of the present disclosure are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the terms used in this way can be interchanged where appropriate, so as to describe the embodiments of the present disclosure described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions.
[0033] Unless otherwise stated, the term "plurality" means two or more.
[0034] In the embodiment of the present disclosure, the character " / " indicates that the preceding and following objects are in an "or" relationship. For example, A / B indicates: A or B.
[0035] The term "and / or" is a description of the association relationship between objects, indicating that three relationships can exist. For example, A and / or B means: A or B, or, A and B.
[0036] The term "correspondence" may refer to an association relationship or a binding relationship. The correspondence between A and B means that there is an association relationship or a binding relationship between A and B.
[0037] Although the existing general large models can provide a rich variety of responses, they ignore the importance of individual differences, resulting in inability to handle sensitive information, professional consultation, or personalized recommendations. More importantly, the lack of an effective access control mechanism can easily lead to problems such as data abuse, content distortion, and even privacy violations.
[0038] First, in terms of data abuse, unauthorized data access and improper use are frequent. For example, due to lax authority management, internal employees of an enterprise may illegally obtain and leak sensitive business information of other departments, such as financial data and research and development results, which may expose the enterprise to risks such as economic losses, loss of competitive advantage and reputation damage. In the medical field, if medical staff can arbitrarily view patient medical records that are not within the scope of their duties, they may use the information for illegal medical advertisements. Secondly, the problem of content distortion is also prominent. In news media and information publishing platforms, the lack of strict identity authentication and access control has led to the proliferation of false news and misleading information, affecting normal social order and public decision-making. In the field of scientific research, the illegal acquisition and dissemination of erroneous data will mislead subsequent research, cause waste of scientific research resources and distortion of scientific research results, and hinder scientific progress. Finally, the problem of privacy infringement is becoming increasingly serious. On e-commerce platforms, if user personal information is not properly protected, it may be illegally obtained and used for harassment, fraud or sold to other illegal organizations, seriously threatening the personal and property safety of users.
[0039] In summary, with the increasing use of large models, establishing a sound access control mechanism plays a vital role in maintaining data security, ensuring information authenticity, protecting personal privacy, and promoting social stability and development.
[0040] Figure 1 FIG. 1 is a schematic diagram of the implementation environment of the permission-aware large model response of the embodiment of the present disclosure. Figure 1 As shown, the implementation environment of the method may include a user 100 and a personalized response large model system 200. The personalized response large model system 200 includes a processor 201 and a plurality of access control models 202.
[0041] The processor 201 is used to control multiple access control models 202 to respond and reply to the request of the user 100. When receiving a user request, the processor 201 first checks the user's authority, determines the response level, and then calls the access control model 202 under the corresponding authority to generate a personalized reply.
[0042] Combination Figure 2 As shown, the embodiment of the present disclosure provides a large model response method based on permission awareness, including:
[0043] S201, upon receiving a user request, the processor obtains the access control method selected by the user and sets the user's authority level; wherein the user's authority level corresponds to the access control method.
[0044] S202, the processor calls the trained access control model and obtains a response of the access control model; wherein the access control model corresponds to the user's permission level.
[0045] S203, the processor records the user request and the response of the access control model for auditing.
[0046] By adopting the permission-aware large model response method provided by the embodiment of the present disclosure, the refined processing and permission control of user requests are realized, thereby improving the security, accuracy and personalized service capabilities of the system. First, when receiving a user request, the system will obtain the access control method selected by the user, such as mandatory access control, role-based access control or attribute-based access control, and set the corresponding permission level according to the user's choice. For example, users may be assigned different permission levels according to their roles or attributes in the organization, such as ordinary users, department heads or system administrators, and each level corresponds to different data access and operation permissions. Next, the system calls the trained access control model, which corresponds to the user's permission level and can evaluate and respond to the request according to the user's permission information. The access control model analyzes factors such as the user's request content, context environment, and the user's historical behavior, determines whether the user has the right to execute the request, and generates a corresponding response result. For example, for a request involving sensitive data, only users with high-level permissions can obtain detailed data content, while low-authority users may only see the summary of the data or be denied access. Finally, the system records the user request and the response of the access control model for post-audit. These records include the time, content, user information, permission level, and response results of the model, etc., which provide important audit basis for system administrators, help to discover potential security issues, analyze user behavior patterns, and optimize permission management strategies. Through these steps, the permission-aware large model response method can effectively prevent data abuse and privacy leakage, ensure that users obtain the required services within the scope of legal and compliant permissions, and provide strong support for the safe operation and continuous improvement of the system.
[0047] Optionally, after receiving the user request, it also includes: verifying the user's password based on the password created by the user; if the password verification is successful, verifying the user's verification code based on the temporary verification code sent by the system; if the verification code verification is successful, determining that the user has logged in successfully to select an access control method.
[0048] Combination Figure 3 As shown, the embodiment of the present disclosure provides another permission-aware large model response method, including:
[0049] S301: When receiving a user request, the processor verifies the user's password according to the password created by the user.
[0050] S302: When the password verification is successful, the processor performs a verification code verification on the user according to a temporary verification code sent by the system.
[0051] S303: When the verification code is successfully verified, the processor determines that the user has successfully logged in to select an access control method.
[0052] S304, the processor obtains the access control method selected by the user and sets the user's authority level; wherein the user's authority level corresponds to the access control method.
[0053] S305, the processor calls the trained access control model and obtains a response of the access control model; wherein the access control model corresponds to the user's permission level.
[0054] S306, the processor records the user request and the response of the access control model for auditing.
[0055] After receiving the user's request, the system will first verify the password based on the password created by the user. When registering, the user will set a password that meets security requirements, such as containing uppercase and lowercase letters, numbers and special characters, and the length is not less than 8 characters. When logging in, after the user enters the password, the system will compare the entered password with the password stored in the database. If the password verification is successful, the system will further verify the verification code based on the temporary verification code sent to the user. The temporary verification code is usually sent through the user's reserved mobile phone number or email address. It has the characteristics of timeliness and one-time use to prevent it from being intercepted and abused by others. After the user receives the verification code, enter the verification code on the login interface. The system will match the entered verification code with the sent verification code. If the verification code verification is successful, the user is deemed to have logged in successfully. At this point, the user can choose the access control method according to their needs, such as mandatory access control, role-based access control, or attribute-based access control. Through this series of steps, the system implements strict verification of user identity and precise control of permissions, effectively preventing illegal user login and abuse of permissions, and ensuring the security of system resources and confidentiality of data. At the same time, it also provides users with flexible access control options to meet the personalized needs of different users in different scenarios, improving user experience and the overall security of the system.
[0056] Optionally, password verification is performed on the user based on the password created by the user, including: hashing the password created by the user to obtain a first password and storing it in a database; hashing the password in the user request to obtain a second password; and determining that the password verification is successful when the first password is the same as the second password.
[0057] In the disclosed embodiment, after the user sets the password, the system will perform hash processing on the password, that is, convert the password into a hash value of fixed length through a hash algorithm, and this hash value is called the first password. The hash algorithm is unidirectional, and the original password cannot be deduced from the hash value. Therefore, even if the database is illegally accessed, the attacker cannot directly obtain the user's password. After obtaining the first password, the system stores the first password in the database for subsequent password verification. When the user tries to log in to the system, he needs to enter the password, and the system will hash the password in the user's request again to obtain the second password. Then, the system compares the second password with the first password stored in the database. If the two are the same, it means that the password entered by the user is consistent with the password set during registration. The system determines that the password verification is successful and allows the user to log in and access system resources. This process realizes the security verification of the user's password and effectively prevents the risk of password leakage and illegal login. Through hash processing, the system does not need to store the user's original password, which reduces the security risk of data storage. At the same time, the rapidity and consistency of the hash algorithm ensure the efficiency and accuracy of the password verification process, providing users with a safe and reliable login verification method, and enhancing the overall security of the system.
[0058] Optionally, the access control model includes a mandatory access control model, a role-based access control model and an attribute-based access control model, and the access control model is trained in the following manner: obtain a data set for training; wherein the data set includes text content, pattern labels and permission labels; select an access control model according to the pattern label; and train the access control model using LoRA technology according to the text content and the permission label.
[0059] The access control model allows users to choose the appropriate access control method when using it, including the MAC (Mandatory Access Control) model, the RBAC (Role-Based Access Control) model, and the ABAC (Attribute-Based Access Control) model.
[0060] The MAC model is a strict security measure that limits the flow of information by establishing a permission hierarchy to ensure that lower-level subjects cannot access higher-level objects. The MAC model focuses on the security level of information and the security level of the visitor. Each text sample is labeled with a corresponding security level. Each instance in the dataset should contain the following fields:
[0061] test: text content, which can be a paragraph, a question or a conversation.
[0062] type: MAC.
[0063] Security level: indicates the security level of the sample. For example, the five-level permissions can be set as Visitor\Regular, Advanced, Expert, and Super.
[0064] Access condition: identifies users with security levels above the specified level who can access the information, such as VisitorUser, Regular User, Advanced User, Expert User, and Super User.
[0065] In the RBAC model, permissions are not granted directly to users, but indirectly through roles. Each user can have multiple roles, and each role has a fixed set of permissions. Let the user set be U, the role set be R, the permission set be P, and the matrix M be UR Represents the association between users and roles, matrix M PR Indicates the relationship between roles and permissions. i Belongs to the role j , then M UR (i,j)=1, otherwise 0. Similarly, if the role r j With permission p k , then M RP (j,k)=1, otherwise 0. i , the permission set P it actually possesses u The calculation is as follows:
[0066]
[0067] Among them, “*” represents matrix multiplication, “:” represents selecting a column of the matrix, and U represents the union operation of sets.
[0068] The RBAC model focuses on user roles and their corresponding permissions. Each sample is associated with one or more role labels, such as "Manager", "Employee", and "Visitor". In addition, the permission set for each role is defined to ensure that the model only provides relevant information to users with specific roles. For example, "Financial Report" may only be open to "Finance Director". Each instance in the dataset should contain the following fields:
[0069] test: text content, which can be a paragraph, a question or a conversation.
[0070] type: RBAC.
[0071] roles required: The roles that must be possessed to access this information. This can be an array of one or more role names.
[0072] default access: users who can view this information by default.
[0073] In the ABAC model, access decisions not only rely on the user's identity, but also comprehensively consider a series of attributes, including but not limited to the user's location, time, department, task status and other factors, making permission control more detailed and dynamic.
[0074] The ABAC model dynamically determines access rights based on user attributes and environment variables. The dataset needs to contain enough information to support this dynamic decision-making process. Each instance in the dataset should contain the following fields:
[0075] test: text content, which can be a paragraph, a question or a conversation.
[0076] type: ABAC.
[0077] attributes: describes the properties required to access data under ideal conditions, such as {"location":"office","time of day":"work hours"}.
[0078] access condition: The access rule determined by the current context attributes. Only users who meet the rule can access the sample.
[0079] In the disclosed embodiment, in the process of training the access control model, it is first necessary to obtain a data set for training, which contains key information such as text content, mode tags and permission tags. The text content covers user requests, conversation history, document fragments, etc., providing rich training materials for the model. The mode tag identifies which access control model the entry is applicable to, helping the model to identify access control requirements in different scenarios. The permission tag is accompanied by specific permission information, such as permission level or attributes, which clarifies the user's access rights in different scenarios. According to the mode tag, the corresponding access control model can be selected. For example, for scenarios that require strict control of the direction of information flow, the MAC model is selected. For scenarios involving role permission allocation, the RBAC model is selected. For scenarios that require comprehensive consideration of user attributes and environmental variables, the ABAC model is selected. After the model is selected, the access control model is trained using LoRA technology. LoRA technology adjusts the weights of the pre-trained model by adding a trainable low-rank matrix, without the need to fully retrain the model, thereby improving the utilization efficiency of parameters and reducing the computational cost. During the training process, the model learns the access control rules of different users in different scenarios based on the text content and permission tags, and optimizes the reasoning ability and decision accuracy of the model. The access control model trained in this way can accurately identify the permission requirements in user requests, and generate response results that meet security requirements according to the user's permission level and access control mode, thereby achieving strict control and refined management of user access. This not only ensures the security of system resources and the confidentiality of data, but also improves the intelligence level of the system and user experience, enabling the system to better adapt to complex and changing access control requirements and provide users with safe and reliable services.
[0080] Optionally, the access control model is trained using LoRA technology based on the text content and permission labels, including: updating the pre-trained weight matrix based on the first low-rank matrix and the second low-rank matrix; and adjusting some model parameters based on the updated weight matrix to train the access control model.
[0081] like Figure 4As shown, specifically, LoRA technology will introduce two low-rank matrices, namely the first low-rank matrix and the second low-rank matrix. The dimensions of these two matrices are relatively small, but they can effectively capture and express the complex relationship between model parameters. By training and adjusting these two low-rank matrices, the pre-trained weight matrix can be updated to better adapt to the current training data and task requirements. The updated weight matrix will be used to adjust some parameters of the model, which are usually closely related to the key functions and performance of the model, such as activation functions and connection weights in neural networks. By adjusting these parameters, the access control model can more accurately learn and master the access control rules of different users at different permission levels, and improve the reasoning ability and decision accuracy of the model. Finally, the access control model trained by LoRA technology can quickly and accurately generate response results that meet security requirements based on the user's request content and permission information, and realize strict control and refined management of user access. This process not only improves the training efficiency and performance of the model, but also reduces the consumption of computing resources, enabling the model to better adapt to complex and changeable access control scenarios and provide users with a safe and reliable service experience.
[0082] Optionally, when the pre-trained weight matrix is updated according to the first low-rank matrix and the second low-rank matrix, the forward propagation process of the data is modified according to the following formula:
[0083] h=W 0 x+ΔWx=W 0 X+M 2 M 1 x
[0084] Among them, h is the generated output data, x is the input data, W 0 is the pre-trained weight matrix, ΔW is the 0 The low-rank correction, M 1 is the first low-rank matrix, M 2 is the second low-rank matrix, and the first low-rank matrix and the second low-rank matrix have smaller dimensions than the pre-trained weight matrix.
[0085] In the disclosed embodiment, by training and adjusting these two low-rank matrices, the pre-trained weight matrix can be updated to better adapt to the current training data and task requirements. Therefore, the objective function of the training using the LoRA method is:
[0086]
[0087] Different from updating the model parameters Φ comprehensively, the embodiment of the present disclosure only adjusts a small part of the parameters θ, which indirectly affect the model parameters Φ through ΔΦ. 0Represents the parameters of the pre-trained model, and the goal of the update is to optimize θ to find the optimal ΔΦ, thereby improving the performance of the model on a specific task.
[0088] Optionally, the authority-aware large model response method also includes: calculating the gradients of the first low-rank matrix and the second low-rank matrix respectively according to a preset mean square error loss function; and optimizing the first low-rank matrix and the second low-rank matrix using a gradient descent method according to the gradients.
[0089] In the disclosed embodiment, the specific steps are as follows: First, define a mean square error loss function, which is used to measure the difference between the model output and the true label, and is the target that needs to be minimized during the model training process. Then, through the back propagation algorithm, according to the dependence of the loss function on the model parameters, the gradients of the first low-rank matrix and the second low-rank matrix are calculated respectively. The gradient represents the rate of change of the loss function at the current parameter value, that is, along the gradient direction, the loss function value will increase, and along the opposite direction of the gradient, the loss function value will decrease. Next, the first low-rank matrix and the second low-rank matrix are updated using the gradient descent method. In each iteration, according to the calculated gradient, according to a certain learning rate, the parameters of the low-rank matrix are adjusted along the opposite direction of the gradient, thereby gradually reducing the value of the loss function, so that the output of the model is closer to the true label. In this way, the model can better learn and master the access control rules under different permission levels, and improve the accuracy and security of the response to user requests. Since the dimension of the low-rank matrix is small, the computational cost of the optimization process is relatively low, which helps to speed up the training speed of the model and shorten the training time of the model.
[0090] The form of the loss function L is as follows:
[0091]
[0092] Here, y is the desired output.
[0093] The first low-rank matrix M 1 and the second low-rank matrix M 2 The gradients of are calculated as follows:
[0094]
[0095] Finally, the gradient descent method is used to update the low-rank matrix. The update formula is as follows:
[0096]
[0097] Optionally, logging user requests and responses to the access control model includes logging all interaction details, monitoring compliance and security posture.
[0098] Logging is no longer just a routine technical practice, but has become a key link connecting user behavior analysis, model optimization, system operation and maintenance, and even legal compliance. The primary task of the logging strategy is to capture and retain every moment of the system operation process, whether it is every interaction between the front-end user and the model, or every turning point of the back-end model decision, all need to be recorded.
[0099] The purpose and principle of logging is comprehensive coverage and privacy priority. While ensuring that all user requests, permission changes, model responses, and abnormal conditions are traceable, we strictly comply with data protection laws, minimize the recording of sensitive information, and adopt anonymization processing methods.
[0100] In terms of recorded content, it is specifically divided into user behavior logs, permission change logs, model decision logs, and exception and security logs. User behavior logs include detailed records of user identity information, request time, request content, permission level, received model responses, etc. Permission change logs include tracking the granting, revocation, upgrade or downgrade of permissions, including status comparisons before and after the change. Model decision logs refer to saving the intermediate steps when the model processes requests, including reasoning paths, weight distributions, activation function status, etc., for subsequent audits. Exception and security logs pay special attention to abnormal events such as unauthorized access attempts, system failures, performance bottlenecks, etc.
[0101] Log auditing is not only a tool for post-event accountability, but also a key link in preventing problems, improving system performance, and enhancing security defense. First, define clear audit objectives and scope, including compliance verification, which is to check whether the system always complies with the latest requirements of data protection, privacy, and industry regulations. Security assessment, which is to evaluate the system's ability to resist attacks, such as data encryption and firewall effectiveness. Performance monitoring, which is to continuously monitor system health, including model response speed, resource utilization, and fault tolerance.
[0102] Log auditing specifically includes permission flow and data access auditing, model decision transparency auditing, and data security and compliance checking. In terms of permission flow and data access auditing, a distributed tracing system is used to record the full path of each request, including all service calls and permission judgment nodes involved, so as to facilitate the subsequent analysis of the rationality of permission allocation. Through the big data platform, massive log data is aggregated and analyzed to identify common access patterns and detect whether there is any abuse of permissions. In terms of model decision transparency auditing, a fairness assessment framework is introduced to analyze the performance differences of the model between different groups to prevent unfair services caused by algorithmic bias. In terms of data security and compliance checking, the encryption level of data during transmission and the security protocol used are detected to confirm whether they meet industry security standards. At the same time, relying on the data governance platform, each stage of data collection to destruction is reviewed to ensure that the entire process complies with the requirements of relevant laws and regulations on data protection.
[0103] Combination Figure 5 As shown, the embodiment of the present disclosure provides a big model response device 500 based on permission perception, including: the permission management module 501 is configured to obtain the access control method selected by the user and set the user's permission level when receiving a user request; wherein the user's permission level corresponds to the access control method; the big model module 502 is configured to call the trained access control model and obtain the response of the access control model; wherein the access control model corresponds to the user's permission level; the log and audit module 503 is configured to record the user request and the response of the access control model for auditing.
[0104] By adopting the permission-aware large model response device 500 provided by the embodiment of the present disclosure, the user can independently choose the access control method, such as mandatory access control, role-based access control, and attribute-based access control. First, the user submits basic information and selects the access control method. Then the permission management module 501 verifies the user's identity, automatically sets the permission level according to the user's choice, and stores and updates the user permission information at the same time. The large model module 502 first needs to perform personalized fine-tuning and training. First, a reasonable permission level is set, and the training data is sorted and organized, and the basic model is fine-tuned and trained using data at different permission levels. When the fine-tuned model receives a user request, it first checks the user's permission, determines the response level, and then calls the model under the corresponding permission to generate a personalized reply. The log and audit module 503 is mainly responsible for recording user requests and system responses for post-audit. In addition, the audit process will be started regularly or on demand to check the logs to ensure that the system operation meets security and compliance requirements.
[0105] Combination Figure 6 As shown, the embodiment of the present disclosure provides a large model response device 60 based on permission perception, including a processor (processor) 201 and a memory (memory) 601. Optionally, the device 60 may also include a communication interface (Communication Interface) 602 and a bus 603. Among them, the processor 201, the communication interface 602, and the memory 601 can communicate with each other through the bus 603. The communication interface 602 can be used for information transmission. The processor 201 can call the logic instructions in the memory 601 to execute the large model response method based on permission perception of the above embodiment.
[0106] In addition, the logic instructions in the memory 601 described above can be implemented in the form of software functional units and can be stored in a computer-readable storage medium when sold or used as an independent product.
[0107] The memory 601 is a computer-readable storage medium that can be used to store software programs and computer executable programs, such as program instructions / modules corresponding to the method in the embodiment of the present disclosure. The processor 201 executes the function application and data processing by running the program instructions / modules stored in the memory 601, that is, the large model response method based on permission perception in the above embodiment is implemented.
[0108] The memory 601 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and an application required for at least one function; the data storage area may store data created according to the use of the terminal device, etc. In addition, the memory 601 may include a high-speed random access memory and may also include a non-volatile memory.
[0109] The disclosed embodiments provide an electronic device, including: a product body, and the above-mentioned large model response device based on permission perception. The large model response device based on permission perception is installed in the electronic device body. The installation relationship described here is not limited to placement inside the electronic device body, but also includes installation connections with other components of the electronic device, including but not limited to physical connections, electrical connections or signal transmission connections, etc. Those skilled in the art can understand that the large model response device based on permission perception can be adapted to a feasible electronic device body, thereby realizing other feasible embodiments.
[0110] The technical solution of the embodiment of the present disclosure can be embodied in the form of a software product, which is stored in a storage medium and includes one or more instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in the embodiment of the present disclosure. The aforementioned storage medium may be a non-transient storage medium, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a disk or an optical disk, and other media that can store program codes.
[0111] The above description and the accompanying drawings fully illustrate the embodiments of the present disclosure so that those skilled in the art can practice them. Other embodiments may include structural, logical, electrical, process and other changes. The embodiments represent only possible changes. Unless explicitly required, separate components and functions are optional, and the order of operation may vary. The parts and features of some embodiments may be included in or replace the parts and features of other embodiments. Moreover, the words used in this application are only used to describe the embodiments and are not used to limit the claims. As used in the description of the embodiments and the claims, unless the context clearly indicates, the singular forms of "a", "an" and "the" are intended to include plural forms as well. Similarly, the term "and / or" as used in this application refers to any and all possible combinations of listings containing one or more associated ones. In addition, when used in the present application, the term "comprise" and its variants "comprises" and / or comprising refer to the presence of stated features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or groups thereof. In the absence of further restrictions, the elements defined by the sentence "comprising a ..." do not exclude the presence of other identical elements in the process, method or device comprising the elements. In this article, each embodiment may focus on the differences from other embodiments, and the same and similar parts between the various embodiments may refer to each other. For the methods, products, etc. disclosed in the embodiments, if they correspond to the method part disclosed in the embodiments, then the relevant parts can refer to the description of the method part.
[0112] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software may depend on the specific application and design constraints of the technical solution. The technicians may use different methods for each specific application to implement the described functions, but such implementations should not be considered to exceed the scope of the embodiments of the present disclosure. The technicians may clearly understand that, for the convenience and simplicity of description, the specific working processes of the systems, devices and units described above may refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here.
[0113] In the embodiments disclosed herein, the disclosed methods and products (including but not limited to devices, equipment, etc.) can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units can be only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between each other shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms. The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the units may be selected according to actual needs to implement this embodiment. In addition, each functional unit in the embodiment of the present disclosure may be integrated in a processing unit, or each unit may exist physically alone, or two or more units may be integrated in one unit.
[0114] The flowchart and block diagram in the accompanying drawings show the possible architecture, function and operation of the system, method and computer program product according to the embodiment of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of the code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. In some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, which can depend on the functions involved. In the description corresponding to the flowchart and the block diagram in the accompanying drawings, the operations or steps corresponding to different boxes can also occur in a different order from the order disclosed in the description, and sometimes there is no specific order between different operations or steps. For example, two consecutive operations or steps can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, which can depend on the functions involved. Each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented by a dedicated hardware-based system that performs the specified functions or actions, or may be implemented by a combination of dedicated hardware and computer instructions.
Claims
1. A large model response method based on authority perception, characterized in that: include: Upon receiving a user request, obtaining the access control method selected by the user and setting the user's authority level; wherein the user's authority level corresponds to the access control method; Calling a trained access control model and obtaining a response from the access control model, wherein the access control model corresponds to the user's permission level; Log user requests and responses of access control models for auditing purposes.
2. The large model response method according to claim 1, characterized in that: After receiving the user request, it also includes: Password verification of users based on the passwords they created; If the password verification is successful, the user will be verified by the temporary verification code sent by the system; If the verification code is successfully verified, the user is determined to have logged in successfully to select an access control method.
3. The large model response method according to claim 2, characterized in that: Password verification for users based on the passwords they create, including: Hash the password created by the user to obtain the first password and store it in the database; Hash the password in the user request to obtain a second password; When the first password and the second password are the same, it is determined that the password verification is successful.
4. The large model response method according to any one of claims 1 to 3, characterized in that: The access control model includes mandatory access control model, role-based access control model and attribute-based access control model. The access control model is trained as follows: Obtain a data set for training; wherein the data set includes text content, mode labels, and permission labels; Select the access control model based on the mode label; The access control model is trained using long-range radio LoRA technology based on text content and permission labels.
5. The large model response method according to claim 4, characterized in that: Based on the text content and permission labels, the access control model is trained using LoRA technology, including: Updating the pre-trained weight matrix according to the first low-rank matrix and the second low-rank matrix; Based on the updated weight matrix, some model parameters are adjusted to train the access control model.
6. The large model response method according to claim 5, characterized in that: When the pre-trained weight matrix is updated according to the first low-rank matrix and the second low-rank matrix, the forward propagation process of the data is modified according to the following formula: h=W0x+ΔWx=W0X+M2M1x Among them, h is the generated output data, x is the input data, W0 is the pre-trained weight matrix, ΔW is the low-rank correction to W0, M1 is the first low-rank matrix, M2 is the second low-rank matrix, and the first low-rank matrix and the second low-rank matrix have smaller dimensions than the pre-trained weight matrix.
7. The large model response method according to claim 5, characterized in that: Also includes: According to a preset mean square error loss function, respectively calculate the gradients of the first low-rank matrix and the second low-rank matrix; According to the gradient, the first low-rank matrix and the second low-rank matrix are optimized using a gradient descent method.
8. A large model response device based on authority perception, characterized in that: include: The authority management module is configured to obtain the access control mode selected by the user and set the user's authority level when receiving a user request; wherein the user's authority level corresponds to the access control mode; The large model module is configured to call a trained access control model and obtain a response of the access control model; wherein the access control model corresponds to a permission level of the user; The logging and auditing module is configured to log user requests and responses of the access control model for auditing purposes.
9. A large model response device based on authority perception, comprising a processor and a memory storing program instructions, characterized in that: The processor is configured to execute the permission-aware large model response method according to any one of claims 1 to 7 when running the program instructions.
10. An electronic device, characterized in that: include: Electronic device body; The permission-aware large model response device as described in claim 8 or 9 is installed on the electronic device body.