Security compliance detection method, device and equipment of data set, medium and product

By using the target knowledge base and compliant target fence in a generative model, the data set is subject to safety compliance inspection, which solves the problem that non-compliant fences cannot identify sensitive data in a timely manner and improves detection accuracy.

CN120197222AActive Publication Date: 2025-06-24NAT IND INFORMATION SECURITY DEV RES CENT
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510677374.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-06-24
Estimated Expiration
2045-05-26

AI Technical Summary

Technical Problem

In the prior art, non-compliant fences cannot identify and deal with sensitive data in a timely manner, resulting in a low accuracy of safety compliance detection of data sets by the generative model after the fence is configured.

Method used

By using the pre-constructed target model, the preset data set and the data set to be tested are respectively tested, and the target knowledge base and the target fence that evaluates compliant are used to determine whether the data set to be tested is compliant.

Benefits of technology

Ensure that compliant fences can identify and respond to sensitive data in a timely manner, thereby improving the accuracy of the generated model after configuring the fence to detect the data set's security compliance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120197222A_ABST
    Figure CN120197222A_ABST
Patent Text Reader

Abstract

The invention discloses a data set security compliance detection method, device and equipment, a medium and a product. The method comprises the following steps: respectively carrying out security compliance detection on a preset data set and a to-be-detected data set by utilizing a pre-constructed target model to obtain a first detection result corresponding to the preset data set and a second detection result corresponding to the to-be-detected data set; wherein the target model is configured with a target knowledge base and a target fence for assessment compliance; under the condition that the second detection result meets a preset condition, the to-be-detected data set rule is judged, and the preset condition includes that the deviation between the first detection result and the second detection result is smaller than a preset deviation range and the second detection result does not include a preset violation word. According to the embodiment of the invention, on the premise of ensuring that the compliant fence can identify and cope with the sensitive data in time, the detection precision of the generative model after the fence is configured on the security compliance of the data set is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the technical field of big data processing, and particularly relates to a method, device, equipment, medium and product for security and compliance detection of a data set. Background Art

[0002] During the training process of generative models, a large number of training data samples are usually used, which may include some sensitive information. For example, personal identity information, health records, financial data, etc. If such information is obtained by illegal users, it may have a serious impact on individuals or organizations. However, due to the characteristics of generative models, they can generate similar responses based on user inputs. Illegal users may indirectly obtain such sensitive data by asking questions to the model, resulting in data leakage. The leakage of sensitive data may bring a series of serious consequences, such as the infringement of personal privacy, economic losses, and damaged reputation.

[0003] To solve this problem, some technical means have been proposed in the industry to protect the security of generative models. For example, using fencing techniques such as NeMo Guardrails to control and limit the output of the model, aiming to prevent the model from generating sensitive information. These fencing techniques can reduce the risk of the model output containing sensitive data by filtering specific words or phrases. However, the evaluation of generative AI fences and the evaluation of data sets from this perspective have not been considered. Non-compliant fences may not be able to identify and respond to sensitive data in a timely manner, thus affecting the detection accuracy of the security and compliance of the data set by the generative model after configuring the fence. Summary of the Invention

[0004] Embodiments of this application provide a method, device, equipment, medium and product for security and compliance detection of a data set, so as to at least solve the problem in related technologies that non-compliant fences cannot identify and respond to sensitive data in a timely manner, resulting in low detection accuracy of the security and compliance of the data set by the generative model after configuring the fence.

[0005] In a first aspect, embodiments of this application provide a method for security and compliance detection of a data set, including: Using a pre-constructed target model to perform security and compliance detection on a preset data set and a to-be-tested data set respectively, obtaining a first detection result corresponding to the preset data set and a second detection result corresponding to the to-be-tested data set; wherein, the target model is configured with a target knowledge base and a target fence for evaluating compliance. When the second detection result meets a preset condition, determining that the to-be-tested data set is compliant, where the preset condition includes that the deviation between the first detection result and the second detection result is less than a preset deviation range and the second detection result does not include preset violation words.

[0006] Second aspect, an embodiment of the present application provides a security and compliance detection device for a data set, and the device includes: A detection module, configured to respectively perform security and compliance detection on a preset data set and a to-be-detected data set by using a pre-constructed target model, so as to obtain a first detection result corresponding to the preset data set and a second detection result corresponding to the to-be-detected data set; wherein, the target model is configured with a target knowledge base and a target fence for evaluating compliance. A determination module, configured to determine that the to-be-detected data set is compliant when the second detection result meets a preset condition, where the preset condition includes that the deviation between the first detection result and the second detection result is less than a preset deviation range and the second detection result does not include preset violation words.

[0007] Third aspect, an embodiment of the present application provides an electronic device, and the electronic device includes: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, the steps of the security and compliance detection method for a data set described in any one of the embodiments of the first aspect are implemented.

[0008] Fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the steps of the security and compliance detection method for a data set described in any one of the embodiments of the first aspect are implemented.

[0009] Fifth aspect, an embodiment of the present application provides a computer program product, the program product is stored in a storage medium, and the program product is executed by at least one processor to implement the steps of the security and compliance detection method for a data set provided in the first aspect of the embodiments of the present application.

[0010] The security and compliance detection method, device, equipment, medium and product for a data set in the embodiments of the present application respectively perform security and compliance detection on a preset data set and a to-be-detected data set by using a target model configured with a target knowledge base and a target fence for evaluating compliance, and determine whether the to-be-detected data set is compliant through the detection results, ensuring that the configured fence can timely identify and respond to sensitive data, and guaranteeing the detection accuracy of the generative model for the security and compliance of the data set after configuring the fence. Description of the Drawings

[0011] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required to be used in the embodiments of the present application. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings without creative efforts.

[0012] Figure 1 It is a schematic flowchart of a security and compliance detection method for a data set provided by an embodiment of the present application; Figure 2 It is a schematic flowchart of the target fence evaluation method provided by an embodiment of the present application; Figure 3 It is a schematic flowchart of a more specific target fence evaluation method provided by an embodiment of the present application; Figure 4 It is a schematic structural diagram of a security compliance detection device for a dataset provided by an embodiment of the present application; Figure 5 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application.

[0013] Reference numerals: Security compliance detection device 400 for a dataset, detection module 401, determination module 402, Electronic device 500, processor 501, memory 502, communication interface 503, bus 510. Detailed implementation manners

[0014] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without some of these specific details. The following description of the embodiments is only intended to provide a better understanding of the present application by showing examples of the present application.

[0015] It should be noted that, in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover a non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, the elements defined by the statement "including..." do not exclude the presence of additional identical elements in the process, method, article or device including the said elements.

[0016] It should be noted that the acquisition, transmission, storage, use and processing of data in the embodiments of the present application all comply with the relevant regulations of national laws and regulations.

[0017] It should be noted that in the embodiments of the present application, some industry-existing solutions such as certain software, components, models, etc. may be mentioned. They should be regarded as exemplary, and their purpose is only to illustrate the feasibility in the implementation of the technical solution of the present application, but it does not mean that the applicant has already or necessarily used this solution.

[0018] During the training process of generative models, a large number of training data samples are usually used, which may include some sensitive information. For example, personal identity information, health records, financial data, etc. If this information is obtained by illegal users, it may have a serious impact on individuals or organizations. However, due to the characteristics of generative models, they can generate similar responses according to the user's input. Illegal users may indirectly obtain this sensitive data by asking questions to the model, resulting in data leakage. The leakage of sensitive data may bring a series of serious consequences, such as the infringement of personal privacy, economic losses, and damage to reputation.

[0019] To solve this problem, some technical means have been proposed in the industry to protect the security of generative models. For example, using fencing technologies such as NeMo Guardrails to control and limit the output of the model, aiming to prevent the model from generating sensitive information. These fencing technologies can reduce the risk of the model output containing sensitive data by filtering specific words or phrases.

[0020] However, the limitations of this method are also very obvious. First, existing fencing technologies can only filter the model output based on pre-set rules, which means they can only handle known sensitive words and phrases. If the expression of sensitive data changes or new sensitive words appear, existing fences may not be able to identify and respond in a timely manner, thus the risk of data leakage still exists.

[0021] In addition, due to the dynamic nature of sensitive data, the fences need to be continuously updated and adjusted to ensure that they can cope with new data leakage risks. As a result, the workload of maintaining the fencing system is very large, and it is easy to have situations of lagging or missing updates. Once the sensitive data in the fence is leaked or breached, it may lead to the exposure of all sensitive information, resulting in more serious consequences.

[0022] However, the evaluation of generative AI fences has not been considered currently. Non-compliant fences may not be able to identify and respond to sensitive data in a timely manner, thus affecting the detection accuracy of the security compliance of the dataset by the generative model after the fence is configured.

[0023] To solve the problems of related technologies, the embodiments of the present application provide a method, device, equipment, medium, and product for detecting the security compliance of a dataset.

[0024] The following will, in conjunction with the accompanying drawings, elaborate in detail on the method for detecting the security and compliance of a dataset provided by the embodiments of the present application through specific embodiments and their application scenarios.

[0025] Figure 1 The flowchart of a method for detecting the security and compliance of a dataset according to an embodiment of the present application is shown. As Figure 1 shown, the method for detecting the security and compliance of the dataset may specifically include the following steps: S101. Use a pre-constructed target model to respectively perform security and compliance detection on a preset dataset and a dataset to be tested, and obtain a first detection result corresponding to the preset dataset and a second detection result corresponding to the dataset to be tested; wherein, the target model is configured with a target knowledge base and a target fence for evaluating compliance; S102. When the second detection result meets the preset conditions, determine that the dataset to be tested is compliant. The preset conditions include that the deviation between the first detection result and the second detection result is less than a preset deviation range and the second detection result does not include preset violation words.

[0026] It should be noted that in this embodiment, the preset dataset is a compliant dataset; the preset violation words at least include pre-set sensitive information.

[0027] In this embodiment, multiple knowledge base data in the target knowledge base are all marked with knowledge base tags, and the knowledge base data in the target knowledge base are sufficient to cover possible queries. The target knowledge base is configured to be a knowledge base containing sensitive data or a knowledge base specifically for testing.

[0028] In this embodiment, the target fence runs based on multiple restriction rules. Specifically, the restriction rules include pre-defined sensitive data types to be filtered and a sensitive word list for each sensitive data type. The sensitive word list includes sensitive words and their corresponding variant words, where the variant words can be generated by a pre-constructed large language model. Optionally, for sensitive data types, such as but not limited to: personal privacy, trade secrets, taking personal privacy as an example of the sensitive data type, its corresponding sensitive word list may include ID numbers.

[0029] Thus, by using a target model configured with a target knowledge base and a target fence for evaluating compliance to respectively perform security and compliance detection on a preset dataset and a dataset to be tested, and judging whether the dataset to be tested is compliant through the detection results, while ensuring that the compliance fence can timely identify and respond to sensitive data, the detection accuracy of the generative model for the security and compliance of the dataset after configuring the fence is guaranteed.

[0030] It can be understood that before S101, it is necessary to evaluate whether the target fence is compliant, so as to determine whether the model obtained by adding the target fence to the target knowledge base is compliant, so as to ensure the detection accuracy of the target model configured with the target fence.

[0031] Reference Figure 2 , which is a schematic flowchart of the target fence evaluation method in the embodiments of the present application. As Figure 2 shown, the target fence evaluation method may specifically include the following steps: S201. When the preset model is not configured with the target knowledge base and / or the target fence, run the preset model according to the preset query text set to obtain a first reply text; S202. When the preset model is configured with the target knowledge base and not configured with the target fence, run the preset model according to the preset query text set to obtain a second reply text; S203. When the preset model is configured with the target knowledge base and the target fence, run the preset model according to the preset query text set to obtain a third reply text; S204. Evaluate whether the target fence is compliant according to the first reply text, the second reply text, and the third reply text.

[0032] The specific implementation manners of the above steps are introduced below.

[0033] In some embodiments, before S201, obtain a first query text; use a pre-constructed large language model to generate a plurality of second query texts that satisfy a second preset semantic similarity with the first query text; and determine the first query text and the plurality of second query texts as the preset query text set.

[0034] In this way, a high-quality query text set is constructed through the large model data augmentation technology, and the query text set is extended by using the large language model. Query instances are generated through the large model, which can increase the scale of the data set and balance the data set, and solve the problem of scarce query data.

[0035] Therefore, the first reply text includes: when the preset model is not configured with the target knowledge base and / or the target fence, respectively input the first query text and the plurality of second query texts in the preset query text set into the corresponding multiple outputs of the preset model; the second reply text includes: when the preset model is configured with the target knowledge base and not configured with the target fence, respectively input the first query text and the plurality of second query texts in the preset query text set into the corresponding multiple outputs of the preset model; the third reply text includes: when the preset model is configured with the target knowledge base and the target fence, respectively input the first query text and the plurality of second query texts in the preset query text set into the corresponding multiple outputs of the preset model.

[0036] That is to say, in S201, when the preset model is configured with the target knowledge base and not configured with the target fence, the first query text and multiple second query texts in the preset query text set are respectively input into the preset model, and multiple first output results of the preset model are obtained, and these first output results are used as the first reply text.

[0037] Similarly, in S202, when the preset model is configured with the target knowledge base and not configured with the target fence, the first query text and multiple second query texts in the preset query text set are respectively input into the preset model, and multiple second output results of the preset model are obtained, and these second output results are used as the second reply text.

[0038] In S203, when the preset model is configured with the target knowledge base and the target fence, the first query text and multiple second query texts in the preset query text set are respectively input into the preset model, and multiple third output results of the preset model are obtained, and these third output results are used as the third reply text.

[0039] In this way, after the user inputs the first query text, at least one second query text semantically similar to the first query text can be generated by the pre-constructed large language model according to the first query text. By inputting the first query text and the second query text into the target model not connected to the target knowledge base, the target model only connected to the target knowledge base, and the target model connected to both the target knowledge base and the target fence, the first reply text, the second reply text, and the third reply text are obtained. And, the reply text includes at least one model output result corresponding one by one to the first query text and the second query text.

[0040] As an optional embodiment, the first reply text, the second reply text, and the third reply text are all structured data, including at least two columns: one column has the column name "query", which corresponds to the first query text or the second query text; the other column has the column name "reply", which corresponds to each output result of the model corresponding one by one to the first query text, the second query text in the first reply text, the second reply text, and the third reply text.

[0041] Optionally, the first reply text, the second reply text, and the third reply text may further include replies obtained by data augmentation according to each reply in the first reply text, the second reply text, and the third reply text.

[0042] Thus, through S201 to S203, the first response text output when the target model has not accessed sensitive data, the second response text output when accessing sensitive data, and the third response text output when accessing sensitive data with the target fence set can be obtained for the preset query text set. Thus, the differences in the content output by the large model in these three cases can be further compared during evaluation.

[0043] Further, in some embodiments, the specific implementation of S204 can refer to Figure 3 the steps shown, that is Figure 3 shows a more specific flowchart of the target fence evaluation method, including: S2041 to S2046.

[0044] S2041. Query the target labels in the multiple knowledge base labels of the target knowledge base that match the restriction rule according to the restriction rule.

[0045] S2042. Determine the knowledge base data corresponding to the target label in the target knowledge base as the target associated information.

[0046] In another embodiment, according to the target knowledge base, obtain the data labels of each item of knowledge base data in the target knowledge base; according to the target fence, obtain the restriction rules of the target fence; according to the data labels of each item of data in the target knowledge base and the restriction rules, screen out the data that conforms to the restriction rules as the target associated information.

[0047] Optionally, if the data labels of each item of data in the target knowledge base include unclassified, trade secret, secret-level secret, confidential-level secret, top-secret-level secret, etc., and the restriction rule of the target fence is to filter data at the secret-level secret and above, then the data that conforms to the restriction rules screened out as the target associated information is the data with the data labels of secret-level secret, confidential-level secret, and top-secret-level secret in the target knowledge base.

[0048] Optionally, the data labels of each item of data in the target knowledge base can be obtained by manual labeling or computer automatic labeling.

[0049] In this way, since the target knowledge base contains a lot of information, through the restriction of the target fence, specific sensitive information can be identified as the target associated information in the target knowledge base. Optionally, when the target knowledge base is a preset knowledge base specifically for testing, it can include a complete set of target fences and target information for testing.

[0050] S2043. Perform clause splitting on the first response text, the second response text, and the third response text respectively to obtain the clause-split first response text, second response text, and third response text.

[0051] S2044. Determine the sentences in the first reply text after clause processing that match the target associated information as the first associated text, determine the sentences in the second reply text after clause processing that match the target associated information as the second associated text, and determine the sentences in the third reply text after clause processing that match the target associated information as the third associated text.

[0052] In this embodiment, perform word segmentation on the first reply text after clause processing to obtain a plurality of candidate keywords; perform variant word reduction processing on each of the plurality of candidate keywords to obtain the plurality of candidate keywords after variant word reduction; according to the target associated information, search for target keywords in the plurality of candidate keywords after variant word reduction that satisfy the first preset semantic similarity with the target associated information; determine the sentence including the target keyword as the first associated text. Similarly, the above similar steps are adopted for the second associated text and the third associated text, so they will not be elaborated here.

[0053] Specifically, when implementing, label the plurality of candidate keywords after variant word reduction to determine their corresponding keyword tags; according to the target associated information, use the keyword tags corresponding to the target tags of the target associated information as the target keywords, that is, satisfy the first preset semantic similarity with the target associated information.

[0054] In this way, by performing data cleaning on the first reply text, the second reply text, and the third reply text to remove the content irrelevant to the target associated information, the accuracy of the subsequent evaluation results is further improved.

[0055] S2045. Calculate the first similarity between the first associated text and the second associated text, and the second similarity between the second associated text and the third associated text according to the first associated text, the second associated text, and the third associated text.

[0056] In this embodiment, the first word vector of the first associated text, the second word vector of the second associated text, and the third word vector of the third associated text can be obtained according to the first associated text, the second associated text, and the third associated text; calculate the first similarity between the first associated text and the second associated text according to the first word vector and the second word vector; calculate the second similarity between the third associated text and the second associated text according to the third word vector and the second word vector.

[0057] Specifically, when implementing, the first associated text can be defined , the second associated text and the third associated text The words in are respectively embedded as vectors , and , then the first similarity between the first associated text and the second associated text can be calculated according to the following formula (1): ; (1) Wherein, represents the first similarity between the first associated text and the second associated text , represents the th word vector in the first associated text, represents the th word vector in the second associated text, represents the number of word vectors in the text.

[0058] Similarly, the second similarity between the third associated text and the second associated text can be calculated according to the following formula (2): ; (2) Wherein, represents the second similarity between the third associated text and the second associated text , represents the th word vector in the third associated text, represents the th word vector in the second associated text, represents the number of word vectors in the text.

[0059] S2046. When the difference between the first similarity and the second similarity is greater than the first preset threshold and the second similarity is less than the second preset threshold, the evaluation result of the target fence is compliant.

[0060] It should be understood that if the first similarity (no knowledge base and with knowledge base) is significantly higher than the second similarity (with fence and knowledge base and only knowledge base), that is, the difference between the two is greater than the first preset threshold, it can be explained that the target fence effectively inhibits the leakage of sensitive information; and if the similarity between the third associated text and the second associated text drops by more than the second preset threshold, it can be determined that the target fence may over-filter. In this way, by judging the first similarity and the second similarity, the effectiveness of the target knowledge base and the constraint effect of the target fence can be evaluated.

[0061] That is to say, when the difference between the first similarity and the second similarity is greater than the first preset threshold and the second similarity is less than the second preset threshold, it can be concluded that: when the preset model is not configured with a target knowledge base and / or a target fence, the error rate of the model output is high; when the preset model is configured with a target knowledge base and not configured with a target fence, the accuracy of the model output is greatly improved, but contains sensitive information; when the preset model is configured with a target knowledge base and a target fence, after filtering sensitive information, the model output accuracy is high and there is no privacy leakage. Therefore, the evaluation result of the target fence can be obtained: the impact of the target fence on the accuracy of the answer is controllable under the premise of ensuring security, that is, the evaluation result of the target fence is compliant.

[0062] Therefore, by comparing the output of the target large model when it does not have access to sensitive data, the output when it has access to sensitive data, and the output when it has access to sensitive data with the target fence set, the impact of the target fence on the target large model can be evaluated. At least the problem of the industry's lack of an effective evaluation method for generative artificial intelligence fences in the prior art is solved. This ensures the accuracy of the generative model after the fence is configured to detect the security and compliance of the data set.

[0063] In addition, in the related art, it is generally only possible to simply evaluate whether the result of a single output of a generative model through a fence does not include sensitive data, but it is impossible to evaluate the possibility that the results of multiple outputs through the fence can be reverse cracked to restore sensitive data.

[0064] Therefore, in order to verify the effect of the target fence and prevent other users from reverse-engineering the content of the second reply text through the difference between the third reply text and the first reply text, that is, to prevent the third reply text from having regular features different from those of the first reply text relative to the second reply text, in this embodiment, the similarity between the third associated text and the first associated text is analyzed to determine the evaluation result of the target fence. This is also the reason why the reply text needs to be processed as associated text, so as to reduce the impact of content in the reply text that is not related to the target fence on the final evaluation result.

[0065] Specific steps may include: according to the first query text and the second query text, obtaining at least one third reply by inputting the first query text and the second query text at least once into a target large model that accesses a target knowledge base and a target fence; and according to the at least one third reply, obtaining a third reply text.

[0066] Further, when there are at least two third responses in the third response text, at least two fourth associated texts corresponding to the at least two third responses are obtained according to the third associated text, where the fourth associated text is the associated text corresponding to each third response in the third associated text; according to the first associated text and the second associated text, a first difference between the first associated text and the second associated text is obtained; according to the at least two fourth associated texts and the second associated text, a second difference between the at least two fourth associated texts and the second associated text is obtained; and an evaluation result of the target fence is obtained according to the distribution of the at least two second differences relative to the first difference.

[0067] In specific implementation, according to the first difference, a first feature vector corresponding to the first difference is obtained; according to the at least two second differences, at least two second feature vectors corresponding to the at least two second differences are obtained; an average vector of the at least two second feature vectors is obtained as a third feature vector; the similarity between the third feature vector and the first feature vector is calculated, and an evaluation result of the target fence is obtained according to the similarity between the third feature vector and the first feature vector.

[0068] In some alternative embodiments, an assignment is made according to the similarity between the third feature vector and the first feature vector to obtain a first eigenvalue, where the higher the similarity, the larger the first eigenvalue; according to the dispersion degree of the third feature vector, a second eigenvalue is obtained, where the lower the dispersion degree, the larger the second eigenvalue; and an evaluation result is obtained according to the first eigenvalue and the second eigenvalue. Specifically, the dispersion degree of the third feature vector can be calculated by variance, standard deviation, and covariance matrix.

[0069] In some alternative embodiments, when the first eigenvalue is less than a third preset threshold and the second eigenvalue is greater than a fourth preset threshold, the evaluation result is unqualified.

[0070] In this way, it is possible to avoid the situation where the difference between the third response text and the first response text is large and concentrated. When such a situation occurs, it is easy to reverse-crack and restore the second response text, that is, the problem of the possibility of reverse-cracking and restoring sensitive data from the results of multiple outputs passing through the fence is solved.

[0071] Further, the present application also provides another method for security and compliance detection of a dataset, which may specifically include the following steps: Inputting multiple data samples in the dataset to be tested into a pre-constructed target model respectively to obtain multiple output results corresponding to the multiple data samples, where the target model is configured with a target knowledge base and a target fence for evaluating compliance; Comparing the multiple output results to determine whether the detection result of the dataset to be tested is compliant; In the case where the detection result of the dataset to be tested is non-compliant, sending the detection result to the object under inspection corresponding to the dataset to be tested.

[0072] In this way, by comparing multiple output results of the target model, a score can be obtained, and the directly given comparison result can be shielded from the object under inspection, effectively preventing the object under inspection from testing out the sensitive word library, evaluation rules, and stealing / leaking sensitive information through repeated evaluations.

[0073] It should be noted that some embodiments of the present application have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than in the above embodiments and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily require the specific order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0074] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present application also provides a security and compliance detection device 400 for a dataset.

[0075] As Figure 4 shown, the security and compliance detection device 400 for the dataset may include: A detection module 401, configured to perform security and compliance detection on a preset dataset and a dataset to be tested respectively by using a pre-constructed target model, to obtain a first detection result corresponding to the preset dataset and a second detection result corresponding to the dataset to be tested; wherein, the target model is configured with a target knowledge base and a target fence for evaluating compliance; A determination module 402, configured to determine that the dataset to be tested is compliant when the second detection result meets a preset condition, where the preset condition includes that the deviation between the first detection result and the second detection result is less than a preset deviation range and the second detection result does not include a preset violation word.

[0076] In some embodiments, the security and compliance detection device 400 for the dataset further includes an evaluation module ( Figure 4not shown in [the figure], for: when the preset model is not configured with the target knowledge base and / or the target fence, running the preset model according to the preset query text set to obtain a first reply text; when the preset model is configured with the target knowledge base and not configured with the target fence, running the preset model according to the preset query text set to obtain a second reply text; when the preset model is configured with the target knowledge base and the target fence, running the preset model according to the preset query text set to obtain a third reply text; and evaluating whether the target fence is compliant according to the first reply text, the second reply text, and the third reply text.

[0077] Optionally, multiple knowledge base data in the target knowledge base are each marked with a knowledge base label, and the target fence operates based on multiple restriction rules.

[0078] Optionally, the evaluating whether the target fence is compliant according to the first reply text, the second reply text, and the third reply text includes: querying, according to the restriction rules, target labels in multiple knowledge base labels of the target knowledge base that match the restriction rules; determining knowledge base data in the target knowledge base corresponding to the target labels as target associated information; respectively performing clause splitting processing on the first reply text, the second reply text, and the third reply text to obtain the clause-split first reply text, second reply text, and third reply text; determining a sentence in the clause-split first reply text that matches the target associated information as a first associated text, determining a sentence in the clause-split second reply text that matches the target associated information as a second associated text, and determining a sentence in the clause-split third reply text that matches the target associated information as a third associated text; calculating a first similarity between the first associated text and the second associated text, and a second similarity between the second associated text and the third associated text according to the first associated text, the second associated text, and the third associated text; and when a difference between the first similarity and the second similarity is greater than a first preset threshold and the second similarity is less than a second preset threshold, the evaluation result of the target fence is compliant.

[0079] Optionally, the determining a sentence in the clause-split first reply text that matches the target associated information as a first associated text includes: performing word segmentation processing on the clause-split first reply text to obtain multiple candidate keywords; performing variant word restoration processing on the multiple candidate keywords respectively to obtain the multiple candidate keywords after variant word restoration; searching, according to the target associated information, for target keywords in the multiple candidate keywords after variant word restoration that satisfy a first preset semantic similarity with the target associated information; and determining a sentence including the target keywords as the first associated text.

[0080] Optionally, when the preset model is not configured with a target knowledge base and / or a target fence, before running the preset model according to the preset query text set to obtain a first response text, the method further includes: obtaining a first query text; generating, by using a pre-constructed large language model, a plurality of second query texts that satisfy a second preset semantic similarity with the first query text; and determining the first query text and the plurality of second query texts as the preset query text set.

[0081] Optionally, the third response text includes: when the preset model is configured with a target knowledge base and a target fence, respectively inputting the first query text and the plurality of second query texts in the preset query text set into a plurality of outputs corresponding to the preset model.

[0082] It should be noted that for the convenience of description, when describing the above device, various modules are described separately according to their functions. Of course, when implementing the present application, the functions of each module can be implemented in the same or multiple software and / or hardware.

[0083] The device in the above embodiment is used to implement the security and compliance detection method for the corresponding data set in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated herein.

[0084] Based on the same technical concept, corresponding to the method in any of the foregoing embodiments, the present application further provides an electronic device.

[0085] Figure 5 FIG. shows a more specific schematic diagram of the hardware structure of the electronic device provided in this embodiment.

[0086] The electronic device 500 may include a processor 501 and a memory 502 storing computer program instructions.

[0087] Specifically, the above-mentioned processor 501 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured as one or more integrated circuits for implementing the embodiments of the present application.

[0088] The memory 502 may include a mass storage for data or instructions. By way of example and not limitation, the memory 502 may include a hard disk drive (HDD), a floppy disk drive, flash memory, an optical disc, a magneto-optical disc, magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, the memory 502 may include removable or non-removable (or fixed) media. Where appropriate, the memory 502 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, the memory 502 is a non-volatile solid-state memory.

[0089] In a particular embodiment, the memory may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk storage media device, an optical storage media device, a flash memory device, an electrical, optical, or other physical / tangible memory storage device. Thus, in general, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to one aspect of the present application.

[0090] The processor 501 implements the security compliance detection method for any one of the data sets in the above embodiments by reading and executing the computer program instructions stored in the memory 502.

[0091] In some examples, the electronic device 500 may further include a communication interface 503 and a bus 510. Among them, as Figure 5 shown, the processor 501, the memory 502, and the communication interface 503 are connected through the bus 510 and complete communication with each other.

[0092] The communication interface 503 is mainly used to implement communication between the various modules, devices, units, and / or devices in the embodiments of the present application.

[0093] The bus 510 includes hardware, software, or both, and couples the components of the online data flow metering device to each other. By way of example and not limitation, the bus 510 may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a MicroChannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or a combination of two or more of these. Where appropriate, the bus 510 may include one or more buses. Although the embodiments of the present application describe and illustrate specific buses, the present application contemplates any suitable bus or interconnect.

[0094] Exemplarily, the electronic device 500 may be a mobile phone, a tablet computer, a laptop computer, a handheld computer, an in-vehicle electronic device, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA), etc.

[0095] Based on the same inventive concept, corresponding to any of the above-described embodiment methods, the present application also provides a non-transitory computer-readable storage medium. Computer program instructions are stored on the computer-readable storage medium; when the computer program instructions are executed by a processor, the security compliance detection method of any one of the above-described embodiments is implemented. Examples of the computer-readable storage medium include non-transitory computer-readable storage media, such as a portable disk, a hard disk, a Random Access Memory (RAM), a Read-Only Memory (ROM), an Erasable Programmable Read-Only Memory (EPROM or Flash Memory), a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, etc.

[0096] Based on the same inventive concept, corresponding to any of the above-described embodiment methods, the present application also provides a computer program product, which includes computer program instructions. In some embodiments, the computer program instructions may be executed by one or more processors of a computer to cause the computer and / or the processor to execute the security compliance detection method of the dataset. Corresponding to the execution subject of each step in each embodiment of the security compliance detection method of the dataset, the processor that executes the corresponding step may belong to the corresponding execution subject.

[0097] It should be clear that the present application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order between steps after understanding the spirit of the present application.

[0098] The functional blocks shown in the above-described structural block diagrams can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application-specific integrated circuit (ASIC), appropriate firmware, a plug-in, a function card, and so on. When implemented in software, the elements of the present application are programs or code segments used to perform the required tasks. The program or code segment can be stored in a machine-readable medium or transmitted via a data signal carried in a carrier wave over a transmission medium or a communication link. A "machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical discs, hard disks, fiber optic media, radio frequency (RF) links, and so on. The code segment can be downloaded via a computer network such as the Internet, an intranet, and so on.

[0099] It should also be noted that the exemplary embodiments mentioned in the present application describe some methods or systems based on a series of steps or devices. However, the present application is not limited to the order of the above steps, that is, the steps can be executed in the order mentioned in the embodiments, or different from the order in the embodiments, or several steps can be executed simultaneously.

[0100] The various aspects of the present application have been described above with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present application. It should be understood that each block in the flowchart and / or block diagram, and the combinations of blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing devices to produce a machine such that the instructions executed by the processor of the computer or other programmable data processing devices enable the implementation of the functions / actions specified in one or more blocks of the flowchart and / or block diagram. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagram and / or flowchart, and the combinations of blocks in the block diagram and / or flowchart, can also be implemented by dedicated hardware that performs the specified functions or actions, or by a combination of dedicated hardware and computer instructions.

[0101] As described above, this is only the specific implementation manner of the present application. Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, modules, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein. It should be understood that the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present application.

Claims

1. A method for detecting the security and compliance of a dataset, characterized in that Including: Using a pre - constructed target model to perform security and compliance detection on a preset data set and a data set to be tested respectively, obtaining a first detection result corresponding to the preset data set and a second detection result corresponding to the data set to be tested; wherein, the target model is configured with a target knowledge base and a target fence for evaluating compliance. When the second detection result meets the preset conditions, it is determined that the data set to be tested is compliant. The preset conditions include that the deviation between the first detection result and the second detection result is less than a preset deviation range and the second detection result does not include preset violation words.

2. The method according to claim 1, wherein Before using the pre - constructed target model to perform security and compliance detection on the preset data set and the data set to be tested respectively, the method further includes: When the preset model is not configured with a target knowledge base and / or a target fence, running the preset model according to a preset query text set to obtain a first reply text. When the preset model is configured with a target knowledge base and not configured with a target fence, running the preset model according to a preset query text set to obtain a second reply text. When the preset model is configured with a target knowledge base and a target fence, running the preset model according to a preset query text set to obtain a third reply text. Evaluating whether the target fence is compliant according to the first reply text, the second reply text and the third reply text.

3. The method according to claim 2, wherein Multiple knowledge base data in the target knowledge base are all marked with knowledge base tags, and the target fence runs based on multiple restriction rules. The evaluating whether the target fence is compliant according to the first reply text, the second reply text and the third reply text includes: Querying target tags in multiple knowledge base tags of the target knowledge base that match the restriction rules according to the restriction rules. Determining the knowledge base data in the target knowledge base corresponding to the target tags as target associated information. Performing clause - splitting processing on the first reply text, the second reply text and the third reply text respectively to obtain the clause - split first reply text, second reply text and third reply text. Determining the sentences in the clause - split first reply text that match the target associated information as the first associated text, determining the sentences in the clause - split second reply text that match the target associated information as the second associated text, and determining the sentences in the clause - split third reply text that match the target associated information as the third associated text. Calculating a first similarity between the first associated text and the second associated text, and a second similarity between the second associated text and the third associated text according to the first associated text, the second associated text and the third associated text. When the difference between the first similarity and the second similarity is greater than a first preset threshold and the second similarity is less than a second preset threshold, the evaluation result of the target fence is compliant.

4. The method according to claim 3, characterized in that The determining the sentences in the clause - split first reply text that match the target associated information as the first associated text includes: Performing word - splitting processing on the clause - split first reply text to obtain multiple candidate keywords. Perform lemmatization processing on multiple alternative keywords respectively to obtain multiple alternative keywords after lemmatization; According to the target association information, search for a target keyword in the multiple alternative keywords after lemmatization that satisfies the first preset semantic similarity with the target association information; Determine the sentence including the target keyword as the first associated text.

5. The method according to claim 2, characterized in that, Before running the preset model according to the preset query text set to obtain the first reply text when the target knowledge base and / or target fence are not configured in the preset model, the method further includes; Obtain the first query text; Use a pre-constructed large language model to generate multiple second query texts that satisfy the second preset semantic similarity with the first query text; Determine the first query text and the multiple second query texts as the preset query text set.

6. The method according to claim 3, characterized in that The third reply text includes: when the preset model is configured with a target knowledge base and a target fence, input the first query text and the multiple second query texts in the preset query text set into the corresponding multiple outputs of the preset model respectively.

7. A security and compliance detection device for a dataset, characterized in that The device includes: A detection module for using a pre-constructed target model to perform security and compliance detection on a preset data set and a data set to be tested respectively, to obtain a first detection result corresponding to the preset data set and a second detection result corresponding to the data set to be tested; wherein, the target model is configured with a target knowledge base and a target fence for evaluating compliance; A determination module for determining that the data set to be tested is compliant when the second detection result meets the preset conditions, and the preset conditions include that the deviation between the first detection result and the second detection result is less than a preset deviation range and the second detection result does not include preset violation words.

8. An electronic device, characterized in that, The device includes: a processor and a memory storing computer program instructions; when the processor calls the computer program instructions, the security and compliance detection method of the data set as described in any one of claims 1-6 is implemented.

9. A computer-readable storage medium, characterized in that, Computer program instructions are stored on the computer-readable storage medium, and when the computer program instructions are called by the processor, the security and compliance detection method of the data set as described in any one of claims 1-6 is implemented.

10. A computer program product, characterized in that, When the instructions in the computer program product are executed by the processor of the electronic device, the electronic device is caused to execute the security and compliance detection method of the data set as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Model training method and device, storage medium and electronic equipment

    CN115238826A

  • Text detection method and device, equipment and storage medium

    CN117332039A

  • Model training method and device, text detection method and device, storage medium and equipment

    CN117744837A

  • Security evaluation method for large language model generation content

    CN118839206A

  • Multi-modal security fence method based on vector matching

    CN119646874A