Method, device, equipment, medium and product for security compliance detection of data set

By building a target model and using the target knowledge base and fences to perform security compliance detection on the dataset, the problem of low detection accuracy caused by non-compliant fences is solved, and efficient security compliance detection of the generative model dataset is achieved.

CN120197222BActive Publication Date: 2025-10-21NAT IND INFORMATION SECURITY DEV RES CENT
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510677374.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-10-21
Estimated Expiration
2045-05-26

AI Technical Summary

Technical Problem

The non-compliant fences in existing technologies cannot identify and respond to sensitive data in a timely manner, resulting in low accuracy in data set security compliance detection by the generative model after fence configuration.

Method used

By using the pre-built target model to perform security compliance detection on the preset data set and the data set to be tested, the target fence configured with the target knowledge base and the compliance assessment is used to determine whether the data set to be tested is compliant, ensuring that the detection results meet the preset deviation range and do not contain preset violation words.

Benefits of technology

The accuracy of generative models in detecting data set security compliance has been improved, ensuring that compliance fences can identify and respond to sensitive data in a timely manner, reducing the risk of data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120197222B_ABST
    Figure CN120197222B_ABST
Patent Text Reader

Abstract

The application discloses a kind of security compliance detection methods, device, equipment, medium and product of data set.It is described as follows: using the target model constructed in advance, the preset data set and the data set to be measured are detected for security compliance, and the first detection result corresponding to the preset data set and the second detection result corresponding to the data set to be measured are obtained;Wherein, the target model is configured with target knowledge base and target fence for evaluating compliance;In the case where the second detection result meets the preset condition, the data set to be measured is determined to be compliant, and the preset condition includes that the deviation between the first detection result and the second detection result is less than the preset deviation range and the second detection result does not include the preset violation word.According to the embodiment of the application, under the premise that the compliance fence can identify and respond to sensitive data in time, the detection accuracy of the generated model after the fence configuration is ensured for the security compliance of the data set.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of big data processing technology, and in particular relates to a method, device, equipment, medium and product for security compliance detection of a data set. Background Art

[0002] Generative models typically use a large amount of training data during training, which may include sensitive information. For example, personal identification information, health records, and financial data. If this information is obtained by unauthorized users, it could have serious consequences for individuals or organizations. However, due to the nature of generative models, they can generate similar responses based on user input. Unauthorized users could indirectly obtain this sensitive data by asking the model questions, leading to data leaks. The leakage of sensitive data can have serious consequences, including the violation of personal privacy, financial losses, and damage to reputation.

[0003] To address this issue, the industry has proposed several technical measures to protect the security of generative models. For example, fencing technologies such as NeMo Guardrails can be used to control and restrict model outputs, preventing them from generating sensitive information. These fencing technologies can reduce the risk of model outputs containing sensitive data by filtering specific words or phrases. However, the evaluation of generative AI fencing, and the integration of this perspective into dataset assessment, have not yet been considered. Non-compliant fencing may fail to identify and address sensitive data in a timely manner, thus affecting the accuracy of dataset security compliance checks by fencing-enabled generative models. Summary of the Invention

[0004] The embodiments of the present application provide a method, apparatus, device, medium, and product for detecting security compliance of a data set, which are used to at least solve the problem in related technologies that non-compliant fences cannot promptly identify and respond to sensitive data, resulting in low accuracy in detecting security compliance of data sets by generative models after configuring fences.

[0005] In a first aspect, an embodiment of the present application provides a method for detecting security compliance of a data set, including:

[0006] Using a pre-built target model, a security compliance test is performed on a preset data set and a data set to be tested, respectively, to obtain a first test result corresponding to the preset data set and a second test result corresponding to the data set to be tested; wherein the target model is configured with a target knowledge base and a target fence for evaluating compliance;

[0007] If the second test result meets a preset condition, the test data set is determined to be compliant. The preset condition includes that the deviation between the first test result and the second test result is less than a preset deviation range and the second test result does not include a preset violation word.

[0008] In a second aspect, an embodiment of the present application provides a device for detecting security compliance of a data set, the device comprising:

[0009] A detection module, configured to perform security compliance detection on a preset dataset and a dataset to be tested, respectively, using a pre-built target model, to obtain a first detection result corresponding to the preset dataset and a second detection result corresponding to the dataset to be tested; wherein the target model is configured with a target knowledge base and a target fence for evaluating compliance;

[0010] and a determination module, configured to determine that the test data set is compliant if the second detection result satisfies a preset condition, wherein the preset condition includes that a deviation between the first detection result and the second detection result is less than a preset deviation range and the second detection result does not include a preset violation word.

[0011] In a third aspect, an embodiment of the present application provides an electronic device comprising: a processor and a memory storing computer program instructions; when the processor executes the computer program instructions, the steps of the data set security compliance detection method as described in any one of the embodiments of the first aspect are implemented.

[0012] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium having computer program instructions stored thereon. When the computer program instructions are executed by a processor, the steps of the data set security compliance detection method as described in any one of the embodiments of the first aspect are implemented.

[0013] In a fifth aspect, an embodiment of the present application provides a computer program product, which is stored in a storage medium and executed by at least one processor to implement the steps of the security compliance detection method of a data set provided in the first aspect of the embodiment of the present application.

[0014] The security compliance detection method, device, equipment, medium and product of the data set in the embodiments of the present application use a target model configured with a target knowledge base and a target fence for evaluating compliance to perform security compliance detection on a preset data set and a data set to be tested respectively, and judge whether the data set to be tested is compliant based on the detection results. On the premise of ensuring that the compliant fence can timely identify and respond to sensitive data, the accuracy of the generative model after the fence is configured in detecting the security compliance of the data set is guaranteed. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0016] Figure 1 This is a flowchart of a method for detecting security compliance of a data set provided in an embodiment of the present application;

[0017] Figure 2 Schematic diagram of the target fence evaluation method provided in the embodiment of the present application;

[0018] Figure 3 is a flowchart of a more specific target fence evaluation method provided in an embodiment of the present application;

[0019] Figure 4 This is a schematic diagram of the structure of a data set security compliance detection device provided in an embodiment of the present application;

[0020] Figure 5 This is a structural diagram of an electronic device provided in an embodiment of the present application.

[0021] Reference numerals:

[0022] Data set security compliance detection device 400, detection module 401, determination module 402,

[0023] Electronic device 500 , processor 501 , memory 502 , communication interface 503 , bus 510 . DETAILED DESCRIPTION

[0024] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without the need for some of these specific details. The following description of the embodiments is merely to provide a better understanding of the present application by illustrating the examples of the present application.

[0025] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, the elements defined by the phrase "comprising..." do not exclude the presence of other identical elements in the process, method, article, or device comprising the elements.

[0026] It should be noted that the acquisition, transmission, storage, use and processing of data in the embodiments of this application are in compliance with the relevant provisions of national laws and regulations.

[0027] It should be noted that in the embodiments of the present application, certain software, components, models and other existing solutions in the industry may be mentioned. They should be regarded as exemplary. Their purpose is only to illustrate the feasibility of implementing the technical solution of the present application, but it does not mean that the applicant has or will necessarily use the solution.

[0028] Generative models typically use a large amount of training data during training, which may include sensitive information. For example, personal identification information, health records, and financial data. If this information is obtained by unauthorized users, it could have serious consequences for individuals or organizations. However, due to the nature of generative models, they can generate similar responses based on user input. Unauthorized users could indirectly obtain this sensitive data by asking the model questions, leading to data leaks. The leakage of sensitive data can have serious consequences, including the violation of personal privacy, financial losses, and damage to reputation.

[0029] To address this issue, the industry has proposed several technical measures to protect the security of generative models. For example, fencing technologies such as NeMo Guardrails can be used to control and restrict model outputs, preventing them from generating sensitive information. These fencing technologies can reduce the risk of model outputs containing sensitive data by filtering specific words or phrases.

[0030] However, this approach also has significant limitations. First, existing fence technology can only filter model output based on pre-set rules, meaning it can only process known sensitive words and phrases. If the expression of sensitive data changes or new sensitive words appear, existing fences may not be able to identify and respond in a timely manner, thus maintaining the risk of data leakage.

[0031] Furthermore, due to the dynamic nature of sensitive data, the fence needs to be constantly updated and adjusted to ensure it can address new data breach risks. This makes the maintenance of the fence system extremely labor-intensive and prone to updates being delayed or missed. If sensitive data within the fence is leaked or breached, all sensitive information could be exposed, leading to even more serious consequences.

[0032] However, the evaluation of generative AI fences is not currently considered. Non-compliant fences may not be able to identify and respond to sensitive data in a timely manner, thereby affecting the accuracy of the generative model after the fence is configured to detect the security compliance of the dataset.

[0033] In order to solve the problems of related technologies, embodiments of the present application provide a method, apparatus, device, medium, and product for security compliance detection of a data set.

[0034] The following describes in detail the security compliance detection method for a data set provided in the embodiment of the present application through specific embodiments and their application scenarios in conjunction with the accompanying drawings.

[0035] Figure 1 FIG. 1 is a flow chart showing a method for detecting security compliance of a data set according to an embodiment of the present application. Figure 1 As shown, the security compliance detection method of the data set may specifically include the following steps:

[0036] S101: Perform security compliance checks on a preset dataset and a dataset to be tested using a pre-built target model, obtaining a first test result corresponding to the preset dataset and a second test result corresponding to the dataset to be tested; wherein the target model is configured with a target knowledge base and a target fence for evaluating compliance;

[0037] S102: If the second test result satisfies a preset condition, determine that the test data set is compliant. The preset condition includes that a deviation between the first test result and the second test result is less than a preset deviation range and the second test result does not include a preset violation word.

[0038] It should be noted that, in this embodiment, the preset data set is a compliance data set; the preset violation words at least include pre-set sensitive information.

[0039] In this embodiment, multiple knowledge base data in the target knowledge base are all marked with knowledge base tags, and the knowledge base data in the target knowledge base is sufficient to cover possible queries. The target knowledge base is configured as a knowledge base containing sensitive data or a knowledge base specifically used for testing.

[0040] In this embodiment, the target fence operates based on multiple restriction rules. Specifically, the restriction rules include predefined sensitive data types to be filtered and a sensitive word list for each sensitive data type. The sensitive word list includes sensitive words and their corresponding variant words, where the variant words can be generated by a pre-built large language model. Optionally, for sensitive data types, such as but not limited to: personal privacy and commercial secrets, taking the sensitive data type of personal privacy as an example, its corresponding sensitive word list can include ID card number.

[0041] Therefore, the target model configured with a target knowledge base and a target fence for compliance assessment is used to perform security compliance tests on the preset data set and the data set to be tested respectively. The compliance of the data set to be tested is judged by the test results. On the premise of ensuring that the compliant fence can identify and respond to sensitive data in a timely manner, the accuracy of the generative model after the fence is configured in detecting the security compliance of the data set is guaranteed.

[0042] It is understandable that before S101, it is necessary to evaluate whether the target fence is compliant, so as to determine whether the model obtained after adding the target fence to the target knowledge base is compliant, so as to ensure the detection accuracy of the target model configured with the target fence.

[0043] refer to Figure 2 , is a flow chart of the target fence evaluation method in the embodiment of the present application. Figure 2 As shown, the target fence evaluation method may specifically include the following steps:

[0044] S201: When a preset model is not configured with a target knowledge base and / or a target fence, the preset model is run according to a preset query text set to obtain a first reply text;

[0045] S202: When the preset model is configured with a target knowledge base and is not configured with a target fence, the preset model is run according to a preset query text set to obtain a second reply text;

[0046] S203: When the preset model is configured with a target knowledge base and a target fence, the preset model is run according to the preset query text set to obtain a third reply text;

[0047] S204. Evaluate whether the target fence is compliant based on the first reply text, the second reply text, and the third reply text.

[0048] The specific implementation methods of the above steps are introduced below.

[0049] In some embodiments, before S201, a first query text is obtained; a plurality of second query texts that meet a second preset semantic similarity with the first query text are generated using a pre-built large language model; and the first query text and the plurality of second query texts are determined as a preset query text set.

[0050] In this way, a high-quality query text set is constructed through large-model data enhancement technology, and the query text set is expanded using a large language model. Query instances are generated through the large model, which can increase the size of the data set and balance the data set, solving the problem of scarce query data.

[0051] Therefore, the first reply text includes: when the preset model is not configured with a target knowledge base and / or a target fence, the first query text and multiple second query texts in the preset query text set are respectively input into the multiple outputs corresponding to the preset model; the second reply text includes: when the preset model is configured with a target knowledge base and is not configured with a target fence, the first query text and multiple second query texts in the preset query text set are respectively input into the multiple outputs corresponding to the preset model; the third reply text includes: when the preset model is configured with a target knowledge base and a target fence, the first query text and multiple second query texts in the preset query text set are respectively input into the multiple outputs corresponding to the preset model.

[0052] That is to say, in S201, when the preset model is configured with a target knowledge base and no target fence is configured, the first query text and multiple second query texts in the preset query text set are respectively input into the preset model to obtain multiple first output results of the preset model, and these first output results are used as the first reply text.

[0053] Similarly, in S202, when the preset model is configured with a target knowledge base and no target fence is configured, the first query text and multiple second query texts in the preset query text set are respectively input into the preset model to obtain multiple second output results of the preset model, and these second output results are used as the second reply text.

[0054] In S203, when the preset model is configured with a target knowledge base and a target fence, the first query text and multiple second query texts in the preset query text set are respectively input into the preset model to obtain multiple third output results of the preset model, and these third output results are used as third reply texts.

[0055] In this way, after a user enters a first query, a pre-built large language model can be used to generate at least one second query with similar semantics to the first query. By inputting the first and second query texts into a target model without access to the target knowledge base, a target model with access only to the target knowledge base, and a target model with access to both the target knowledge base and the target fence, a first response text, a second response text, and a third response text are generated. Furthermore, the response text includes at least one model output result that corresponds one-to-one with the first and second query texts.

[0056] As an optional embodiment, the first reply text, the second reply text and the third reply text are all structured data, including at least two columns: one of the columns is named query, which corresponds to the first query text or the second query text; the other column is named reply, which corresponds to each output result of the model in the first reply text, the second reply text and the third reply text that corresponds one to one to the first query text and the second query text.

[0057] Optionally, the first reply text, the second reply text and the third reply text may also include replies obtained by performing data enhancement on each reply in the first reply text, the second reply text and the third reply text.

[0058] Thus, through S201 to S203, we can obtain, for a preset query text set, the first response text output when the target model does not encounter sensitive data, the second response text output when it encounters sensitive data, and the third response text output when it encounters sensitive data while the target fence is set. Thus, we can further compare the differences in the output content of the large model in these three situations during evaluation.

[0059] Furthermore, in some embodiments, the specific implementation of S204 can be referred to Figure 3 The steps shown are Figure 3 A more specific flowchart of the target fence evaluation method is shown, including: S2041 to S2046.

[0060] S2041 . According to the restriction rule, query a target tag in a plurality of knowledge base tags of the target knowledge base for a target tag that matches the restriction rule.

[0061] S2042: Determine the knowledge base data corresponding to the target tag in the target knowledge base as target association information.

[0062] In another embodiment, based on the target knowledge base, data labels of each knowledge base data in the target knowledge base are obtained; based on the target fence, restriction rules of the target fence are obtained; based on the data labels of each data in the target knowledge base and the restriction rules, data that meets the restriction rules are filtered out as target association information.

[0063] Optionally, if the data labels of various data in the target knowledge base include non-confidential, commercial secret, secret-level secret, confidential-level secret, top secret-level secret, etc., and the restriction rule of the target fence is to filter out data of secret-level secret and above, then the data that meets the restriction rule is filtered out as the target associated information, which is the data in the target knowledge base with data labels of secret-level secret, confidential-level secret, and top secret-level secret.

[0064] Optionally, the data labels of each data item in the target knowledge base may be obtained by manual labeling or automatic labeling by a computer.

[0065] In this case, since the target knowledge base contains a lot of information, through the restriction of the target fence, specific sensitive information in the target knowledge base can be identified as target-related information. Optionally, when the target knowledge base is a pre-set knowledge base specifically for testing, a set of target fences and target information can be included for testing.

[0066] S2043. Perform sentence segmentation processing on the first reply text, the second reply text and the third reply text respectively to obtain the sentence segmented first reply text, the second reply text and the third reply text.

[0067] S2044. Determine the sentence in the first reply text after the sentence processing that matches the target association information as the first associated text, determine the sentence in the second reply text after the sentence processing that matches the target association information as the second associated text, and determine the sentence in the third reply text after the sentence processing that matches the target association information as the third associated text.

[0068] In this embodiment, the first reply text after sentence segmentation is subjected to word segmentation processing to obtain multiple candidate keywords; variant word restoration processing is performed on each of the multiple candidate keywords to obtain multiple candidate keywords after variant word restoration; based on the target association information, a target keyword is searched among the multiple candidate keywords after variant word restoration that meets a first preset semantic similarity with the target association information; and the sentence including the target keyword is determined as the first associated text. Similarly, similar steps are used for the second and third associated texts, and are not further described here.

[0069] During specific implementation, multiple alternative keywords after the variant words are restored are marked to determine their corresponding keyword labels; according to the target association information, the keyword label that matches the target label of the target association information is used as the target keyword, that is, it meets the first preset semantic similarity with the target association information.

[0070] In this way, by performing data cleaning on the first reply text, the second reply text, and the third reply text and removing content irrelevant to the target-related information, the accuracy of subsequent evaluation results can be further improved.

[0071] S2045 : Calculate, based on the first associated text, the second associated text, and the third associated text, a first similarity between the first associated text and the second associated text, and a second similarity between the second associated text and the third associated text.

[0072] In this embodiment, a first word vector of the first associated text, a second word vector of the second associated text, and a third word vector of the third associated text can be obtained based on the first associated text, the second associated text, and the third associated text; a first similarity between the first associated text and the second associated text is calculated based on the first word vector and the second word vector; and a second similarity between the third associated text and the second associated text is calculated based on the third word vector and the second word vector.

[0073] In specific implementation, the first associated text can be defined , Second related text and the third associated text The words in are embedded as vectors 、 and , the first similarity between the first associated text and the second associated text can be calculated according to the following formula (1):

[0074] ; (1)

[0075] in, Indicates the first associated text With the second associated text The first similarity between Indicates the first associated text word vectors, Indicates the second associated text word vectors, Represents the number of word vectors in the text.

[0076] Similarly, the second similarity between the third associated text and the second associated text can be calculated according to the following formula (2):

[0077] ; (2)

[0078] in, Indicates the third associated text With the second associated text The second similarity between Indicates the third related text word vectors, Indicates the second associated text word vectors, Represents the number of word vectors in the text.

[0079] S2046: When the difference between the first similarity and the second similarity is greater than a first preset threshold and the second similarity is less than a second preset threshold, the evaluation result of the target fence is compliance.

[0080] It should be understood that if the first similarity (without a knowledge base vs. with a knowledge base) is significantly higher than the second similarity (with a fence and knowledge base vs. with only a knowledge base), that is, the difference between the two is greater than a first preset threshold, it can be concluded that the target fence has effectively suppressed the leakage of sensitive information. Conversely, if the similarity between the third associated text and the second associated text drops by more than a second preset threshold, it can be determined that the target fence may be over-filtering. In this way, by evaluating the first and second similarities, the effectiveness of the target knowledge base and the restrictive effect of the target fence can be evaluated.

[0081] That is, if the difference between the first and second similarities is greater than a first preset threshold and the second similarity is less than a second preset threshold, it can be concluded that: when the preset model is not configured with a target knowledge base and / or a target fence, the model output has a high error rate; when the preset model is configured with a target knowledge base but not a target fence, the model output accuracy is significantly improved, but contains sensitive information; when the preset model is configured with a target knowledge base and a target fence, after filtering sensitive information, the model output has a high accuracy rate and no privacy leakage. Therefore, the target fence evaluation result can be obtained: while ensuring security, the target fence's impact on answer accuracy is controllable, that is, the target fence evaluation result is compliant.

[0082] By comparing the output of the target large model when it has no access to sensitive data, when it has access to sensitive data, and when it has access to sensitive data with the target fence in place, we can assess the impact of the target fence on the target large model. This solves the existing problem of the industry's lack of an effective evaluation method for generative AI fences. This ensures the accuracy of the fenced generative model in detecting data set security and compliance.

[0083] In addition, in the related art, it is generally only possible to simply evaluate whether the result of a single output of the generative model through the fence does not include sensitive data, but it is impossible to evaluate the possibility that the results of multiple outputs through the fence can be reverse cracked to restore sensitive data.

[0084] Therefore, in order to verify the effect of the target fence and prevent other users from reverse-engineering and restoring the content of the second reply text through the difference between the third reply text and the first reply text, that is, to avoid the third reply text having different regular features from the first reply text relative to the second reply text, in this embodiment, the similarity between the third associated text and the first associated text is analyzed to determine the evaluation result of the target fence. This is also the reason why the reply text needs to be processed as associated text, so as to reduce the impact of content in the reply text that is not related to the target fence on the final evaluation result.

[0085] The specific steps may include: according to the first query text and the second query text, obtaining at least one third reply by inputting the first query text and the second query text at least once into the target large model connected to the target knowledge base and the target fence; and obtaining a third reply text according to the at least one third reply.

[0086] Further, when the third reply text includes at least two third replies, at least two fourth associated texts corresponding to the at least two third replies are obtained based on the third associated text, and the fourth associated text is the associated text corresponding to each third reply in the third associated text; based on the first associated text and the second associated text, the first difference between the first associated text and the second associated text is obtained; based on the at least two fourth associated texts and the second associated text, the second difference between the at least two fourth associated texts and the second associated text is obtained; and based on the distribution of the at least two second differences relative to the first difference, an evaluation result of the target fence is obtained.

[0087] During specific implementation, based on the first difference, a first eigenvector corresponding to the first difference is obtained; based on the at least two second differences, at least two second eigenvectors corresponding to the at least two second differences are obtained; based on the at least two second eigenvectors, an average vector of the at least two second eigenvectors is obtained as a third eigenvector; the similarity between the third eigenvector and the first eigenvector is calculated, and based on the similarity between the third eigenvector and the first eigenvector, an evaluation result of the target fence is obtained.

[0088] In some optional embodiments, a first eigenvalue is obtained by assigning a value based on the similarity between the third eigenvector and the first eigenvector, where the higher the similarity, the larger the first eigenvalue; a second eigenvalue is obtained based on the degree of dispersion of the third eigenvector, where the lower the degree of dispersion, the larger the second eigenvalue; and an evaluation result is obtained based on the first eigenvalue and the second eigenvalue. Specifically, the degree of dispersion of the third eigenvector can be calculated using the variance, standard deviation, and covariance matrix.

[0089] In some optional embodiments, when the first characteristic value is less than a third preset threshold and the second characteristic value is greater than a fourth preset threshold, the evaluation result is unqualified.

[0090] In this way, the problem of large and concentrated differences between the third reply text and the first reply text can be avoided. When this happens, it is easy to reverse crack and restore the second reply text. That is, the problem of being unable to evaluate the possibility of multiple outputs passing through the fence being reverse cracked to restore sensitive data is solved.

[0091] Furthermore, the present application also provides another method for security compliance detection of a data set, which may specifically include the following steps: inputting multiple data samples in the data set to be tested into a pre-built target model to obtain multiple output results corresponding to each of the multiple data samples, wherein the target model is configured with a target knowledge base and a target fence for evaluating compliance; comparing the multiple output results to determine whether the detection result of the data set to be tested is compliant; if the detection result of the data set to be tested is non-compliant, sending the detection result to the inspected object corresponding to the data set to be tested.

[0092] In this way, a score can be obtained by comparing multiple output results of the target model, and the comparison results directly given to the inspected object can be shielded, effectively preventing the inspected object from testing sensitive vocabulary and evaluation rules through repeated evaluation and obtaining / leaking sensitive information.

[0093] It should be noted that the above description is limited to some embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in an order different from that described in the above embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0094] Based on the same technical concept, corresponding to any of the above-mentioned embodiments and methods, the present application also provides a data set security compliance detection device 400.

[0095] like Figure 4 As shown, the data set security compliance detection device 400 may include:

[0096] A detection module 401 is configured to perform security compliance detection on a preset dataset and a dataset to be tested using a pre-built target model, obtaining a first detection result corresponding to the preset dataset and a second detection result corresponding to the dataset to be tested; wherein the target model is configured with a target knowledge base and a target fence for evaluating compliance;

[0097] The determination module 402 is configured to determine that the test data set is compliant if the second detection result satisfies a preset condition. The preset condition includes that the deviation between the first detection result and the second detection result is less than a preset deviation range and the second detection result does not include a preset violation word.

[0098] In some embodiments, the data set security compliance detection device 400 further includes an evaluation module ( Figure 4 ), used for: when the preset model is not configured with a target knowledge base and / or a target fence, running the preset model according to a preset query text set to obtain a first reply text; when the preset model is configured with a target knowledge base and is not configured with a target fence, running the preset model according to the preset query text set to obtain a second reply text; when the preset model is configured with a target knowledge base and a target fence, running the preset model according to the preset query text set to obtain a third reply text; and evaluating whether the target fence is compliant based on the first reply text, the second reply text and the third reply text.

[0099] Optionally, multiple knowledge base data in the target knowledge base are all marked with knowledge base tags, and the target fence is operated based on multiple restriction rules.

[0100] Optionally, the evaluation of whether the target fence is compliant based on the first reply text, the second reply text and the third reply text includes: according to the restriction rule, querying the target tag that matches the restriction rule among the multiple knowledge base tags of the target knowledge base; determining the knowledge base data corresponding to the target tag in the target knowledge base as target association information; performing sentence processing on the first reply text, the second reply text and the third reply text respectively to obtain the first reply text, the second reply text and the third reply text after sentence processing; determining the sentence that matches the target association information in the first reply text after sentence processing as the first association text, and determining the target association information as the first association text. The sentence in the second reply text after the sentence processing that matches the target association information is determined as the second associated text, and the sentence in the third reply text after the sentence processing that matches the target association information is determined as the third associated text; based on the first associated text, the second associated text and the third associated text, the first similarity between the first associated text and the second associated text, and the second similarity between the second associated text and the third associated text are calculated; when the difference between the first similarity and the second similarity is greater than a first preset threshold and the second similarity is less than a second preset threshold, the evaluation result of the target fence is compliance.

[0101] Optionally, the sentence in the first reply text after the sentence segmentation processing that matches the target association information is determined as the first associated text, including: performing word segmentation processing on the first reply text after the sentence segmentation processing to obtain multiple alternative keywords; performing variant word restoration processing on the multiple alternative keywords respectively to obtain multiple alternative keywords after variant word restoration; according to the target association information, searching for the target keyword in the multiple alternative keywords after variant word restoration that meets the first preset semantic similarity with the target association information; and determining the sentence including the target keyword as the first associated text.

[0102] Optionally, when the preset model is not configured with a target knowledge base and / or a target fence, before running the preset model according to the preset query text set to obtain the first reply text, the method also includes: obtaining a first query text; using a pre-built large language model to generate multiple second query texts that meet a second preset semantic similarity with the first query text; and determining the first query text and the multiple second query texts as a preset query text set.

[0103] Optionally, the third reply text includes: when the preset model is configured with a target knowledge base and a target fence, inputting the first query text and multiple second query texts in the preset query text set into multiple outputs corresponding to the preset model respectively.

[0104] It should be noted that, for the convenience of description, the above devices are described as being divided into various modules according to their functions. Of course, when implementing this application, the functions of each module can be implemented in the same or multiple software and / or hardware.

[0105] The apparatus of the above embodiment is used to implement the security compliance detection method of the corresponding data set in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be described in detail here.

[0106] Based on the same technical concept, corresponding to any of the above-mentioned embodiment methods, the present application also provides an electronic device.

[0107] Figure 5 A more specific hardware structure diagram of an electronic device provided by this embodiment is shown.

[0108] The electronic device 500 may include a processor 501 and a memory 502 storing computer program instructions.

[0109] Specifically, the processor 501 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.

[0110] Memory 502 may include a large-capacity memory for data or instructions. By way of example and not limitation, memory 502 may include a hard disk drive (HDD), a floppy disk drive, flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 502 may include removable or non-removable (or fixed) media. Where appropriate, memory 502 may be internal or external to the integrated gateway disaster recovery device. In a specific embodiment, memory 502 is a non-volatile solid-state memory.

[0111] In certain embodiments, the memory may include read-only memory (ROM), random access memory (RAM), magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical, or other physical / tangible memory storage devices. Thus, generally, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to an aspect of the present application.

[0112] The processor 501 reads and executes computer program instructions stored in the memory 502 to implement any one of the data set security compliance detection methods in the above embodiments.

[0113] In some examples, the electronic device 500 may further include a communication interface 503 and a bus 510. Figure 5 As shown, the processor 501, the memory 502, and the communication interface 503 are connected via a bus 510 and communicate with each other.

[0114] The communication interface 503 is mainly used to implement communication between various modules, devices, units and / or equipment in the embodiments of the present application.

[0115] Bus 510 includes hardware, software, or both, and couples the components of the online data traffic metering device to each other. By way of example, and not limitation, bus 510 may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industrial Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industrial Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local Area Network (VLB) bus, or other suitable buses, or a combination of two or more of these. Where appropriate, bus 510 may include one or more buses. Although the embodiments of the present application describe and illustrate specific buses, the present application contemplates any suitable bus or interconnect.

[0116] Illustratively, the electronic device 500 may be a mobile phone, a tablet computer, a laptop computer, a PDA, an in-vehicle electronic device, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA).

[0117] Based on the same technical concept, corresponding to any of the above-mentioned embodiments and methods, the present application also provides a non-transitory computer-readable storage medium. Computer program instructions are stored on the computer-readable storage medium; when the computer program instructions are executed by the processor, any of the security compliance detection methods for the data set in the above-mentioned embodiments is implemented. Examples of computer-readable storage media include non-transitory computer-readable storage media, such as portable disks, hard disks, random access memories (RAMs), read-only memories (ROMs), erasable programmable read-only memories (EPROMs or flash memories), portable compact disk read-only memories (CD-ROMs), optical storage devices, magnetic storage devices, etc.

[0118] Based on the same technical concept, corresponding to any of the above-mentioned embodiments and methods, the present application also provides a computer program product comprising computer program instructions. In some embodiments, the computer program instructions can be executed by one or more processors of a computer to cause the computer and / or the processor to perform the data set security compliance detection method. For the execution entities corresponding to the steps in each embodiment of the data set security compliance detection method, the processors that execute the corresponding steps can belong to the corresponding execution entities.

[0119] It should be understood that the present application is not limited to the specific configurations and processes described above and illustrated in the figures. For the sake of brevity, a detailed description of known methods is omitted here. In the above embodiments, several specific steps are described and illustrated as examples. However, the method process of the present application is not limited to the specific steps described and illustrated. Those skilled in the art can make various changes, modifications, and additions, or change the order of the steps after understanding the spirit of the present application.

[0120] The functional blocks shown in the block diagrams described above can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they may be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, and the like. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments may be stored in a machine-readable medium or transmitted via a data signal carried in a carrier wave over a transmission medium or communication link. "Machine-readable medium" may include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROMs, flash memory, erasable ROMs (EROMs), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, and the like. Code segments may be downloaded via a computer network such as the Internet or an intranet.

[0121] It should also be noted that the exemplary embodiments mentioned in this application describe some methods or systems based on a series of steps or devices. However, this application is not limited to the order of the above steps. In other words, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0122] Aspects of the present application have been described above with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present application. It should be understood that each block in the flowcharts and / or block diagrams, as well as combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to produce a machine such that execution of these instructions by the processor of the computer or other programmable data processing device enables the implementation of the functions / actions specified in one or more blocks in the flowcharts and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field programmable logic circuit. It should also be understood that each block in the block diagrams and / or flowcharts, as well as combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by dedicated hardware that performs the specified functions or actions, or by a combination of dedicated hardware and computer instructions.

[0123] The above description is only a specific embodiment of the present application. Those skilled in the art will clearly understand that for the convenience and brevity of description, the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. It should be understood that the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily think of various equivalent modifications or replacements within the technical scope disclosed in the present application, and these modifications or replacements should be included in the scope of protection of the present application.

Claims

1. A data set security compliance detection method, characterized in that: include: Using a pre-built target model, a security compliance test is performed on a preset data set and a data set to be tested, respectively, to obtain a first test result corresponding to the preset data set and a second test result corresponding to the data set to be tested; wherein the target model is configured with a target knowledge base and a target fence for evaluating compliance; If the second test result satisfies a preset condition, determining that the test data set is compliant, wherein the preset condition includes that a deviation between the first test result and the second test result is less than a preset deviation range and the second test result does not include a preset violation word; Before using the pre-built target model to perform security compliance testing on the preset data set and the data set to be tested, the method further includes: When the preset model is not configured with a target knowledge base and / or a target fence, running the preset model according to a preset query text set to obtain a first reply text; When the preset model is configured with a target knowledge base and is not configured with a target fence, running the preset model according to a preset query text set to obtain a second reply text; When the preset model is configured with a target knowledge base and a target fence, the preset model is run according to the preset query text set to obtain a third reply text; Assess whether the target fence complies with regulations based on the first reply text, the second reply text, and the third reply text; The plurality of knowledge base data in the target knowledge base are all marked with knowledge base tags, and the target fence is operated based on a plurality of restriction rules; The evaluating whether the target fence is compliant based on the first reply text, the second reply text, and the third reply text includes: According to the restriction rule, querying a target tag among multiple knowledge base tags of the target knowledge base that matches the restriction rule; Determining the knowledge base data corresponding to the target tag in the target knowledge base as target association information; Determine, according to the target association information, the first associated text, the second associated text, and the third associated text corresponding to the first reply text, the second reply text, and the third reply text, respectively; Calculating, based on the first associated text, the second associated text, and the third associated text, a first similarity between the first associated text and the second associated text, and a second similarity between the second associated text and the third associated text; When the difference between the first similarity and the second similarity is greater than a first preset threshold and the second similarity is less than a second preset threshold, the evaluation result of the target fence is compliance.

2. The method according to claim 1, characterized in that The determining, according to the target association information, the first associated text, the second associated text, and the third associated text corresponding to the first reply text, the second reply text, and the third reply text, respectively, includes: Performing sentence processing on the first reply text, the second reply text, and the third reply text respectively to obtain the sentence-processed first reply text, the second reply text, and the third reply text; The sentence in the first reply text after the sentence processing that matches the target association information is determined as the first associated text, the sentence in the second reply text after the sentence processing that matches the target association information is determined as the second associated text, and the sentence in the third reply text after the sentence processing that matches the target association information is determined as the third associated text.

3. The method according to claim 2, characterized in that The step of determining the sentence in the first reply text after the sentence segmentation processing that matches the target association information as the first associated text includes: Performing word segmentation on the first reply text after the sentence segmentation process to obtain a plurality of candidate keywords; Perform variant word restoration processing on multiple candidate keywords respectively to obtain multiple candidate keywords after variant word restoration; According to the target association information, searching for a target keyword among the multiple candidate keywords restored from the variant words, which has a first preset semantic similarity with the target association information; A sentence including the target keyword is determined as a first associated text.

4. The method according to claim 2, characterized in that In the case where the preset model is not configured with a target knowledge base and / or a target fence, before running the preset model according to a preset query text set and obtaining a first answer text, the method further includes: Get the first query text; Generate a plurality of second query texts that meet a second preset semantic similarity with the first query text using a pre-built large language model; The first query text and a plurality of second query texts are determined as a preset query text set.

5. The method according to claim 4, characterized in that The third reply text includes: when the preset model is configured with a target knowledge base and a target fence, the first query text and multiple second query texts in the preset query text set are input into multiple outputs corresponding to the preset model respectively.

6. A data set security compliance detection device, characterized in that: The device comprises: A detection module, configured to perform security compliance detection on a preset dataset and a dataset to be tested, respectively, using a pre-built target model, to obtain a first detection result corresponding to the preset dataset and a second detection result corresponding to the dataset to be tested; wherein the target model is configured with a target knowledge base and a target fence for evaluating compliance; a determination module, configured to determine that the test data set is compliant if the second test result satisfies a preset condition, wherein the preset condition includes that a deviation between the first test result and the second test result is less than a preset deviation range and the second test result does not include a preset violation word; An evaluation module is used for, before using a pre-built target model to perform security compliance detection on a preset data set and a data set to be tested respectively: when the preset model is not configured with a target knowledge base and / or a target fence, running the preset model according to a preset query text set to obtain a first reply text; when the preset model is configured with a target knowledge base and not configured with a target fence, running the preset model according to the preset query text set to obtain a second reply text; when the preset model is configured with a target knowledge base and a target fence, running the preset model according to the preset query text set to obtain a third reply text; and evaluating whether the target fence is compliant based on the first reply text, the second reply text, and the third reply text; The plurality of knowledge base data in the target knowledge base are all marked with knowledge base tags, and the target fence is operated based on a plurality of restriction rules; The evaluation module is specifically used to query the target tag that matches the restriction rule among the multiple knowledge base tags of the target knowledge base according to the restriction rule; determine the knowledge base data corresponding to the target tag in the target knowledge base as target association information; determine the first associated text, second associated text and third associated text corresponding to the first reply text, the second reply text and the third reply text respectively according to the target association information; calculate the first similarity between the first associated text and the second associated text, and the second similarity between the second associated text and the third associated text according to the first associated text, the second associated text and the third associated text; when the difference between the first similarity and the second similarity is greater than a first preset threshold and the second similarity is less than a second preset threshold, the evaluation result of the target fence is compliance.

7. An electronic device, characterized in that: The device includes: a processor and a memory storing computer program instructions; when the processor calls the computer program instructions, it implements the security compliance detection method for a data set according to any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer program instructions, which, when called by a processor, implement the data set security compliance detection method according to any one of claims 1 to 5.

9. A computer program product, characterized in that When the instructions in the computer program product are executed by a processor of an electronic device, the electronic device executes the security compliance detection method for a data set according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Text detection method and device, equipment and storage medium

    CN117332039A

  • Multi-modal security fence method based on vector matching

    CN119646874A