Data filtering method and system based on LLM security protection system

Through the step-by-step data analysis method based on the LLM security protection system, combined with keyword, semantic and sentiment analysis, the problems of data filtering accuracy and efficiency in the prior art are solved, and high accuracy and efficient data filtering effect are achieved.

CN120407785AActive Publication Date: 2025-08-01GUANGDONG PLANNING & DESIGNING INST OF TELECOMM
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
CN202510905269.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-02
Publication Date
2025-08-01
Estimated Expiration
2045-07-02

AI Technical Summary

Technical Problem

In the prior art, data filtering methods based on large language models rely on manual evaluation, and there are problems of low accuracy, low efficiency and inconsistent results, making it difficult to effectively intercept malicious code and sensitive information.

Method used

The step-by-step data analysis method based on the LLM security protection system is adopted, including keyword analysis, semantic analysis and sentiment analysis, and the abnormal content analysis results are combined to determine whether the filtering conditions are met, and the corresponding data filtering operations are performed.

Benefits of technology

It improves the accuracy and efficiency of data filtering, reduces the false alarm rate, and enhances the response speed of the security protection system and the security of output data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120407785A_ABST
    Figure CN120407785A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data processing, and discloses a data filtering method and system based on an LLM security protection system, and the method comprises the steps: receiving target data content which needs to be subjected to data filtering analysis; performing stepped data analysis operation on the target data content to obtain an abnormal content analysis result; according to the abnormal content analysis result, judging whether the target data content meets an abnormal data filtering condition or not; and if yes, executing a corresponding data filtering operation on the target data content according to an abnormal content analysis result. Visibly, by implementing the method and the device, the anomaly detection accuracy and reliability of the target data content can be improved, the anomaly detection efficiency and convenience of the target data content are improved, the data filtering accuracy and efficiency of the target data content are further improved, and high accuracy and low false alarm rate of data content anomaly detection and filtering are realized; the response speed of the security protection system is improved, and the security and the suitability of the finally output / processed and filtered data content are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing technology, and in particular to a data filtering method and system based on an LLM security protection system. Background Art

[0002] As large-scale language models are increasingly used in various fields, their security issues are becoming increasingly prominent. Specifically, when generating text, large-scale language models may produce content containing malicious code, sensitive information, or inappropriate speech. It is necessary to monitor the data in real time and intercept these potential security risks to avoid losses to users and society.

[0003] Currently, most data filtering methods rely on staff members subjectively filtering and evaluating input data in the background. This subjective evaluation is affected by many factors, such as staff members' poor mental state during data filtering and evaluation, different staff members' different considerations and emphases when evaluating the same data, and the lack of a standardized and quantitative evaluation method. This can lead to deviations in the data filtering evaluation results even for the same data under the same conditions. Furthermore, staff members are required to manually filter and delete each data object, resulting in low data filtering accuracy and efficiency. Therefore, it is particularly important to provide a data filtering method that can improve data filtering accuracy and efficiency. Summary of the Invention

[0004] The present invention provides a data filtering method and system based on the LLM security protection system, which can improve the filtering accuracy and efficiency of data.

[0005] In order to solve the above technical problems, the first aspect of the present invention discloses a data filtering method based on the LLM security protection system, the method comprising: Receive target data content that requires data filtering and analysis; Performing corresponding step-by-step data analysis operations on the target data content to obtain abnormal content analysis results corresponding to the target data content; According to the abnormal content analysis result, determining whether the target data content meets the preset abnormal data filtering conditions; When it is determined that the target data content meets the abnormal data filtering condition, a corresponding data filtering operation is performed on the target data content according to the abnormal content analysis result.

[0006] As an optional implementation, in the first aspect of the present invention, performing corresponding step-by-step data analysis operations on the target data content to obtain abnormal content analysis results corresponding to the target data content may include: Perform corresponding keyword analysis operations on the target data content to obtain a first abnormal result; Perform corresponding semantic analysis operations on the target data content to obtain a second abnormal result; Perform corresponding sentiment analysis operations on the target data content to obtain a third abnormal result; According to the first abnormal result, the second abnormal result, and the third abnormal result, perform corresponding comprehensive abnormal analysis operations on the target data content to obtain an abnormal content analysis result corresponding to the target data content.

[0007] As an optional implementation manner, in the first aspect of the present invention, the performing corresponding keyword analysis operations on the target data content to obtain a first abnormal result includes: Perform corresponding character division operations on the target data content according to preset regular character collocation rules to obtain a character division result; Judge whether the target data content meets the preset keyword abnormal evaluation conditions according to the character division result and the preset abnormal keyword set; When it is determined that the target data content meets the keyword abnormal evaluation conditions, determine one or more target abnormal characters from the target data content according to the abnormal keyword set and the character division result; determine the first abnormal result according to all the target abnormal characters.

[0008] As an optional implementation manner, in the first aspect of the present invention, the performing corresponding semantic analysis operations on the target data content to obtain a second abnormal result includes: Perform corresponding semantic analysis operations on the target data content to obtain a text meaning result corresponding to the target data content; Determine the corresponding semantic abnormal level of the target data content according to the determined application scenario information of the target data content and the text meaning result; Judge whether the target data content meets the preset semantic abnormal lower limit conditions according to the application scenario information and the semantic abnormal level; When it is determined that the target data content meets the semantic abnormal lower limit conditions, determine a scenario semantic abnormal lower limit scheme according to the application scenario information; determine the abnormal semantic data object in the target data content according to the scenario semantic abnormal lower limit scheme and the text meaning result; determine the second abnormal result according to the abnormal semantic data object.

[0009] As an optional implementation manner, in the first aspect of the present invention, the performing corresponding sentiment analysis operations on the target data content to obtain a third abnormal result includes: Determine the emotional expression property corresponding to the target data content, where the emotional expression property includes a positive emotional expression property or a non-positive emotional expression property; When the emotional expression property includes the non-positive emotional expression property, determine the context data content corresponding to the target data content according to the target data content; Determine the lead-out application property corresponding to the target data content according to the context data content, where the lead-out application property includes a subjective thought application property or an objective logic application property; Determine the third abnormal result according to the target data content and the lead-out application property.

[0010] As an alternative implementation manner, in the first aspect of the present invention, the performing corresponding data filtering operations on the target data content according to the abnormal content analysis result includes: Determine the target abnormal object corresponding to the target data content according to the abnormal content analysis result, where the target abnormal object includes the overall content or partial content of the target data content; Determine the application importance and filtering influence degree of the target data content according to the associated data information corresponding to the target data content, and determine the filtering consideration requirement degree of the target data content according to the application importance and the filtering influence degree; Determine the target filtering method of the target data content according to the target abnormal object and the filtering consideration requirement degree; When the target filtering method is used to represent an overall filtering method, perform corresponding overall data filtering operations on the target data content; When the target filtering method is used to represent a partial filtering method, perform corresponding partial data filtering operations on the target data content according to the target abnormal object.

[0011] As an alternative implementation manner, in the first aspect of the present invention, the determining whether the target data content meets a preset abnormal data filtering condition according to the abnormal content analysis result includes: Judge whether the target data content meets a preset abnormal data existence condition according to the abnormal content analysis result; When it is judged that the target data content does not meet the abnormal data existence condition, determine that the target data content does not meet the preset abnormal data filtering condition; When it is judged that the target data content meets the abnormal data existence condition, determine the specific abnormal content corresponding to the target data content according to the abnormal content analysis result, and determine the abnormality universality and abnormality severity corresponding to the target data content according to the specific abnormal content. Based on the abnormality prevalence and the abnormality severity, determine whether the target data content meets a preset data filtering emergency condition; When it is determined that the target data content meets the data filtering emergency condition, determine that the target data content meets a preset abnormal data filtering condition; When it is determined that the target data content does not meet the data filtering emergency condition, determine that the target data content does not meet a preset abnormal data filtering condition.

[0012] A second aspect of the present invention discloses a data filtering system based on an LLM security protection system, and the system includes: A data receiving module, configured to receive target data content that needs to be analyzed for data filtering; An abnormal data analysis module, configured to perform corresponding step-by-step data analysis operations on the target data content to obtain an abnormal content analysis result corresponding to the target data content; A judgment module, configured to judge whether the target data content meets a preset abnormal data filtering condition according to the abnormal content analysis result; A data filtering module, configured to perform corresponding data filtering operations on the target data content according to the abnormal content analysis result when the judgment module determines that the target data content meets the abnormal data filtering condition.

[0013] As an optional implementation manner, in the second aspect of the present invention, the manner in which the abnormal data analysis module performs corresponding step-by-step data analysis operations on the target data content to obtain an abnormal content analysis result corresponding to the target data content specifically includes: Perform corresponding keyword analysis operations on the target data content to obtain a first abnormal result; Perform corresponding semantic analysis operations on the target data content to obtain a second abnormal result; Perform corresponding sentiment analysis operations on the target data content to obtain a third abnormal result; According to the first abnormal result, the second abnormal result, and the third abnormal result, perform corresponding comprehensive abnormal analysis operations on the target data content to obtain an abnormal content analysis result corresponding to the target data content.

[0014] As an optional implementation manner, in the second aspect of the present invention, the manner in which the abnormal data analysis module performs corresponding keyword analysis operations on the target data content to obtain a first abnormal result specifically includes: According to a preset regular character collocation rule, perform corresponding character division operations on the target data content to obtain a character division result; Based on the character division result and a preset set of abnormal keywords, determine whether the target data content meets the preset keyword abnormality judgment condition; When it is determined that the target data content meets the keyword abnormality judgment condition, based on the set of abnormal keywords and the character division result, determine one or more target abnormal characters from the target data content; determine a first abnormal result based on all the target abnormal characters.

[0015] As an optional implementation manner, in the second aspect of the present invention, the manner in which the abnormal data analysis module performs corresponding semantic analysis operations on the target data content to obtain a second abnormal result specifically includes: Perform corresponding semantic analysis operations on the target data content to obtain a text meaning result corresponding to the target data content; Based on the determined application scenario information of the target data content and the text meaning result, determine the semantic abnormality level corresponding to the target data content; Based on the application scenario information and the semantic abnormality level, determine whether the target data content meets the preset semantic abnormality lower limit condition; When it is determined that the target data content meets the semantic abnormality lower limit condition, based on the application scenario information, determine a scenario semantic abnormality lower limit solution; based on the scenario semantic abnormality lower limit solution and the text meaning result, determine the abnormal semantic data object in the target data content; determine a second abnormal result based on the abnormal semantic data object.

[0016] As an optional implementation manner, in the second aspect of the present invention, the manner in which the abnormal data analysis module performs corresponding sentiment analysis operations on the target data content to obtain a third abnormal result specifically includes: Based on the target data content, determine the sentiment expression property corresponding to the target data content, and the sentiment expression property includes a positive sentiment expression property or a non - positive sentiment expression property; When the sentiment expression property includes the non - positive sentiment expression property, based on the target data content, determine the context data content corresponding to the target data content; Based on the context data content, determine the lead - out application property corresponding to the target data content, and the lead - out application property includes a subjective thought application property or an objective logic application property; Based on the target data content and the lead - out application property, determine the third abnormal result.

[0017] As an alternative implementation, in the second aspect of the present invention, the manner in which the data filtering module performs corresponding data filtering operations on the target data content according to the abnormal content analysis result specifically includes: According to the abnormal content analysis result, determine the target abnormal object corresponding to the target data content, where the target abnormal object includes the entire content or part of the content of the target data content; According to the associated data information corresponding to the target data content, determine the application importance and filtering impact degree of the target data content, and according to the application importance and the filtering impact degree, determine the filtering consideration requirement degree of the target data content; According to the target abnormal object and the filtering consideration requirement degree, determine the target filtering method for the target data content; When the target filtering method is used to represent an overall filtering method, perform corresponding overall data filtering operations on the target data content; When the target filtering method is used to represent a partial filtering method, perform corresponding partial data filtering operations on the target data content according to the target abnormal object.

[0018] As an alternative implementation, in the second aspect of the present invention, the manner in which the judgment module determines whether the target data content meets the preset abnormal data filtering conditions according to the abnormal content analysis result specifically includes: According to the abnormal content analysis result, determine whether the target data content meets the preset abnormal data existence conditions; When it is determined that the target data content does not meet the abnormal data existence conditions, determine that the target data content does not meet the preset abnormal data filtering conditions; When it is determined that the target data content meets the abnormal data existence conditions, according to the abnormal content analysis result, determine the specific abnormal content corresponding to the target data content, and according to the specific abnormal content, determine the abnormality universality and abnormality severity corresponding to the target data content; According to the abnormality universality and the abnormality severity, determine whether the target data content meets the preset data filtering emergency conditions; When it is determined that the target data content meets the data filtering emergency conditions, determine that the target data content meets the preset abnormal data filtering conditions; When it is determined that the target data content does not meet the data filtering emergency conditions, determine that the target data content does not meet the preset abnormal data filtering conditions.

[0019] The third aspect of the present invention discloses another data filtering system based on an LLM security protection system, and the system includes: A memory storing executable program code; A processor coupled to the memory; The processor calls the executable program code stored in the memory and executes the data filtering method based on the LLM security protection system disclosed in the first aspect of the present invention.

[0020] The fourth aspect of the present invention discloses a computer storage medium storing computer instructions, which are used to execute the data filtering method based on the LLM security protection system disclosed in the first aspect of the present invention when the computer instructions are called.

[0021] Compared with the prior art, the embodiments of the present invention have the following beneficial effects: In the embodiments of the present invention, the target data content to be subjected to data filtering analysis is received; corresponding stepped data analysis operations are performed on the target data content to obtain an abnormal content analysis result corresponding to the target data content; according to the abnormal content analysis result, it is determined whether the target data content meets the preset abnormal data filtering condition; when it is determined that the target data content meets the abnormal data filtering condition, corresponding data filtering operations are performed on the target data content according to the abnormal content analysis result. It can be seen that the present invention can perform corresponding stepped data analysis operations on the target data content to obtain an abnormal content analysis result, and further perform corresponding data filtering operations on the target data content according to the abnormal content analysis result, which is beneficial to improving the comprehensiveness and integrity of the data filtering method based on the LLM security protection system, and is beneficial to improving the rationality and comprehensiveness of the data anomaly analysis method, and further is beneficial to improving the accuracy and reliability of the determined abnormal content analysis result, thereby being beneficial to improving the accuracy and reliability of the anomaly detection of the target data content, and being beneficial to improving the efficiency and convenience of the anomaly detection of the target data content, and further being beneficial to improving the accuracy and data filtering efficiency of the target data content, being beneficial to achieving high accuracy and low false alarm rate of data content anomaly detection and filtering, improving the response speed of the security protection system, and improving the security and appropriateness of the finally output / processed and filtered data content. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0023] Figure 1 It is a schematic flowchart of a data filtering method based on an LLM security protection system disclosed in an embodiment of the present invention; Figure 2 It is a schematic flowchart of another data filtering method for the LLM security protection system disclosed in the embodiments of the present invention; Figure 3 It is a schematic structural diagram of a data filtering system based on the LLM security protection system disclosed in the embodiments of the present invention; Figure 4 It is a schematic structural diagram of another data filtering system based on the LLM security protection system disclosed in the embodiments of the present invention. Detailed implementation manners

[0024] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the scope of protection of the present invention.

[0025] The terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, device, product or terminal that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products or terminals.

[0026] Referring to "embodiments" herein means that the specific features, structures or characteristics described in connection with the embodiments can be included in at least one embodiment of the present invention. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0027] The present invention discloses a data filtering method and system based on an LLM security protection system, which can perform corresponding stepped data analysis operations on target data content to obtain an abnormal content analysis result, and further perform corresponding data filtering operations on the target data content according to the abnormal content analysis result. This is beneficial to improving the comprehensiveness and integrity of the data filtering method based on the LLM security protection system, and is also beneficial to improving the rationality and comprehensiveness of the data anomaly analysis method. Furthermore, it is beneficial to improve the accuracy and reliability of the determined abnormal content analysis result, thereby being beneficial to improving the accuracy and reliability of the abnormal detection of the target data content, and being beneficial to improving the efficiency and convenience of the abnormal detection of the target data content. Further, it is beneficial to improve the data filtering accuracy and data filtering efficiency of the target data content, and is conducive to achieving high accuracy and low false alarm rate in data content anomaly detection and filtering, improving the response speed of the security protection system, and improving the security and appropriateness of the finally output / processed and filtered data content. The following will be described in detail respectively.

[0028] Embodiment 1 Please refer to Figure 1 , Figure 1 , which is a schematic flowchart of a data filtering method based on an LLM security protection system disclosed in an embodiment of the present invention. Among them, Figure 1 the described method can be applied to a data filtering system based on an LLM security protection system, where the system can include a server, and the server includes a local server or a cloud server, which is not limited in the embodiments of the present invention. As Figure 1 shown, the data filtering method based on the LLM security protection system includes the following operations: 101. Receive the target data content that needs to be analyzed for data filtering.

[0029] Optionally, the target data content can be text data content, language data content, other data content that can express meaning, etc.; further, other data content that can express meaning such as code, etc., is not limited in the embodiments of the present invention.

[0030] Further optionally, input the target data content into the intelligent data filtering module of the LLM security protection system for analysis and data filtering, and through advanced natural language processing technology, real-time detect and filter abnormal data content to ensure the security of the data output by the intelligent data filtering module, which is not limited in the embodiments of the present invention.

[0031] Optionally, the target data content that needs to be analyzed for data filtering can be understood as the data content input into the intelligent data filtering module of the LLM-based security protection system for analysis. This target data content may contain abnormal data and require data filtering, may contain abnormal data but not require data filtering, or may not contain abnormal data and not require data filtering. The embodiments of the present invention do not make any limitations in this regard.

[0032] 102. Perform corresponding step-by-step data analysis operations on the target data content to obtain the analysis result of abnormal content corresponding to the target data content.

[0033] Optionally, the analysis result of abnormal content corresponding to the target data content may include, but is not limited to, one or more of the information indicating whether there is abnormal content in the target data content, the specific abnormal data in the target data content and its corresponding abnormal type, and other information that can reflect the abnormal situation of the target data content. The embodiments of the present invention do not make any limitations in this regard.

[0034] Optionally, specific abnormal data, for example: inappropriate information such as violent speech, hate speech, and adult content. The embodiments of the present invention do not make any limitations in this regard.

[0035] Optionally, the step-by-step data analysis operation may include, but is not limited to, one or more of the data analysis operation based on keywords, the data analysis operation based on semantics, the data analysis operation based on sentiment, and the data analysis operation based on other aspect parameters. The embodiments of the present invention do not make any limitations in this regard.

[0036] 103. According to the analysis result of abnormal content, determine whether the target data content meets the preset abnormal data filtering conditions.

[0037] Further optionally, the method may further include the following operations: When it is determined that the target data content does not meet the preset abnormal data filtering conditions, determine the target data label of the target data content, and according to the target data label and the determined current filtering mode, determine whether the target data content meets the preset filtering label conditions; When it is determined that the target data content meets the filtering label conditions, perform corresponding data filtering operations on the target data content according to the target data label; When it is determined that the target data content does not meet the filtering label conditions, perform the above step of receiving the target data content that needs to be analyzed for data filtering again.

[0038] Further optionally, the above determination of whether the target data content meets the preset filtering label conditions according to the target data label and the determined current filtering mode may include: According to the determined current filtering mode, determine the additional attention data tags corresponding to the current filtering mode; Determine whether the additional attention data tags include the target data tags; When the judgment result is yes, determine that the target data content meets the preset filtering tag conditions; When the judgment result is no, determine that the target data content does not meet the preset filtering tag conditions.

[0039] 104. When it is determined that the target data content meets the abnormal data filtering conditions, perform corresponding data filtering operations on the target data content according to the abnormal content analysis results.

[0040] Further optionally, the above-mentioned performing corresponding data filtering operations on the target data content may be to filter and delete the entire target data content, or to filter and delete some data content in the target data content, which is not limited in the embodiments of the present invention.

[0041] Further optionally, after performing corresponding data filtering operations on the target data content, a data filtering result corresponding to the target data content is obtained; further, the data filtering result may be used to represent the target data content after data filtering, that is, the target data content that does not include abnormal data, that is, the abnormal data is deleted, or it may represent the data filtering situation of the target data content, which is not limited in the embodiments of the present invention.

[0042] It can be seen that the data filtering method based on the LLM security protection system described in the embodiments of the present invention can perform corresponding step-by-step data analysis operations on the target data content to obtain abnormal content analysis results, and further perform corresponding data filtering operations on the target data content according to the abnormal content analysis results, which is beneficial to improving the comprehensiveness and integrity of the data filtering method based on the LLM security protection system, and is beneficial to improving the rationality and comprehensiveness of the data anomaly analysis method, and further beneficial to improving the accuracy and reliability of the determined abnormal content analysis results, thereby being beneficial to improving the accuracy and reliability of the abnormal detection of the target data content, and being beneficial to improving the efficiency and convenience of the abnormal detection of the target data content, and further beneficial to improving the data filtering accuracy and data filtering efficiency of the target data content, being beneficial to achieving high accuracy and low false alarm rate of data content anomaly detection and filtering, improving the response speed of the security protection system, and improving the security and appropriateness of the finally output / processed filtered data content.

[0043] In an optional embodiment, the above-mentioned performing corresponding data filtering operations on the target data content according to the abnormal content analysis results may include: Based on the analysis result of the abnormal content, determine the target abnormal object corresponding to the target data content, where the target abnormal object includes the overall content or partial content of the target data content; Based on the associated data information corresponding to the target data content, determine the application importance and filtering influence degree of the target data content, and based on the application importance and filtering influence degree, determine the filtering consideration requirement degree of the target data content; Based on the target abnormal object and the filtering consideration requirement degree, determine the target filtering method for the target data content; When the target filtering method is used to represent the overall filtering method, perform the corresponding overall data filtering operation on the target data content; When the target filtering method is used to represent the partial filtering method, perform the corresponding partial data filtering operation on the target data content according to the target abnormal object.

[0044] Optionally, the target abnormal object corresponding to the target data content can be understood as: the specific abnormal data content in the target data content, or the specific data content that causes data abnormality in the target data content, which is not limited in the embodiments of the present invention.

[0045] Optionally, the associated data information corresponding to the target data content, for example: can be other data information bundled and input with the target data content, can also be data information having a certain connection with the target data content, or can also be other information that can reflect the actual application situation of the target data content, which is not limited in the embodiments of the present invention.

[0046] Optionally, the application importance of the target data content can be understood as: the importance of the target data content in actual application; further, for example: if the target data content is text data, the application importance of the target data content can be determined by the role played by the target data content in the whole article, the role significance of the target data content for the coherence and meaning understanding of the article, etc., which is not limited in the embodiments of the present invention.

[0047] Optionally, the filtering influence degree of the target data content can be understood as: the influence degree of the data filtering result obtained after filtering the target data content on the actual application; further, for example: if the target data content is text data, after filtering the target data content, if the meaning of the whole article is opposite to the original meaning, it can be determined that the filtering influence degree of the target data content is relatively large, and the same applies to other situations, which is not limited in the embodiments of the present invention.

[0048] Optionally, the filtering consideration requirement for the target data content can be understood as the requirement degree that needs to be considered when performing a filtering operation on the target data content. Further, for example, when the filtering consideration requirement is higher, the filtered part of the target data content should be as concise as possible, and it should not be filtered randomly. The same applies to other situations, and the embodiments of the present invention do not make any limitations.

[0049] Further optionally, according to the application importance and the filtering impact degree, the filtering consideration requirement for the target data content is determined. For example, when the application importance indicates that the target data content is more important for the application and / or the filtering impact degree indicates that the filtering operation on the target data content has a greater impact on the actual situation, it can be determined that the filtering consideration requirement for the target data content is higher. The same applies to other situations, and the embodiments of the present invention do not make any limitations.

[0050] Further optionally, according to the target abnormal object and the filtering consideration requirement, the target filtering method for the target data content is determined. For example, when the target abnormal object represents the entire target data content, the target filtering method for the target data is determined as the overall filtering method; when the target abnormal object represents a part of the target data content and the filtering consideration requirement is relatively high, the target filtering method for the target data is determined as the partial filtering method; when the target abnormal object represents a part of the target data content and the filtering consideration requirement is relatively low, the target filtering method for the target data can be determined as the partial filtering method or the overall filtering method. The same applies to other situations, and the embodiments of the present invention do not make any limitations.

[0051] Further optionally, for example, when the target abnormal object is a part of the target data content and deleting the target abnormal object will not affect the meaning and function of the target data content, the partial filtering method can be adopted; or when the target abnormal object is a part of the target data content and the target data content is very important and cannot be filtered sentence by sentence, the partial filtering method can be adopted. The same applies to other situations, and the embodiments of the present invention do not make any limitations.

[0052] Further optionally, performing the corresponding overall data filtering operation on the target data content can be understood as filtering the entire target data content. The embodiments of the present invention do not make any limitations.

[0053] Further optionally, performing the corresponding partial data filtering operation on the target data content according to the target abnormal object may include: Determining the targeted data that needs to be filtered in the target data content according to the target abnormal object; Filtering the targeted data in the target data content.

[0054] It can be seen that the optional embodiment can determine the target filtering method according to the target abnormal object of the determined target data content and the filtering consideration requirement degree, and further perform corresponding data filtering operations according to the target filtering method. The target filtering method includes the overall filtering method or the partial filtering method, which is beneficial to improving the comprehensiveness and rationality of the method for determining the target filtering method of the target data content, and further beneficial to improving the diversity, flexibility and pertinence of the target filtering method, thus being beneficial to improving the execution accuracy and reliability of the data filtering operation, and further beneficial to improving the data filtering accuracy and reliability of the target data content.

[0055] In another optional embodiment, the above-mentioned judging whether the target data content meets the preset abnormal data filtering condition according to the abnormal content analysis result may include: Judging whether the target data content meets the preset abnormal data existence condition according to the abnormal content analysis result; When it is judged that the target data content does not meet the abnormal data existence condition, it is determined that the target data content does not meet the preset abnormal data filtering condition; When it is judged that the target data content meets the abnormal data existence condition, according to the abnormal content analysis result, the specific abnormal content corresponding to the target data content is determined, and according to the specific abnormal content, the abnormality universality and abnormality severity corresponding to the target data content are determined; Judging whether the target data content meets the preset data filtering emergency condition according to the abnormality universality and abnormality severity; When it is judged that the target data content meets the data filtering emergency condition, it is determined that the target data content meets the preset abnormal data filtering condition; When it is judged that the target data content does not meet the data filtering emergency condition, it is determined that the target data content does not meet the preset abnormal data filtering condition. [[ID=?]]

[0056] Further optionally, the above-mentioned judging whether the target data content meets the preset abnormal data existence condition according to the abnormal content analysis result may include: Judging whether there is abnormal data in the target data content according to the abnormal content analysis result; When the judgment result is yes, it is determined that the target data content meets the preset abnormal data existence condition; When the judgment result is no, it is determined that the target data content does not meet the preset abnormal data existence condition.

[0057] Optionally, the abnormality universality corresponding to the target data content can be understood as: the universality of the specific abnormal content appearing in this field or level of the target data content, which is not limited in the embodiments of the present invention.

[0058] Note: There seems to be an error in the original text where there is an unpaired tag

[0056] . It remains unchanged in the translation as per the requirements.Optionally, the severity of the exception corresponding to the target data content can be reflected by the degree of exception, the degree of influence, the degree of resulting damage, etc. of the specific exception content, which is not limited in the embodiments of the present invention.

[0059] Further optionally, determining whether the target data content meets the preset data filtering emergency condition according to the exception universality and the exception severity may include: Determining whether the exception universality is greater than or equal to a preset exception universality threshold, and determining whether the exception severity is greater than or equal to a preset exception severity threshold; When it is determined that the exception universality is less than the exception universality threshold and / or it is determined that the exception severity is greater than or equal to the exception severity threshold, it is determined that the target data content meets the preset data filtering emergency condition; When it is determined that the exception universality is greater than or equal to the exception universality threshold and it is determined that the exception severity is less than the exception severity threshold, it is determined that the target data content does not meet the preset data filtering emergency condition.

[0060] It can be seen that this optional embodiment can determine the result of meeting the exception data filtering condition from two levels of the existence condition of the exception data and the data filtering emergency condition, which is beneficial to improving the comprehensiveness, integrity, rationality and progressive nature of the method for determining the result of meeting the exception data filtering condition. Furthermore, it is beneficial to improve the accuracy and reliability of the determined result of meeting the exception data filtering condition, and thus beneficial to improving the execution timeliness, accuracy, reliability and efficiency of the subsequent data filtering operation based on the result of meeting the exception data filtering condition.

[0061] Embodiment 2 Please refer to Figure 2 , Figure 2 which is a schematic flowchart of another data filtering method based on the LLM security protection system disclosed in the embodiments of the present invention. Among them, Figure 2 The described method can be applied to a data filtering system based on the LLM security protection system, where the system may include a server, and the server includes a local server or a cloud server, which is not limited in the embodiments of the present invention. As Figure 2 shown, the data filtering method based on the LLM security protection system includes the following operations: 201. Receive the target data content that needs to be analyzed for data filtering.

[0062] 202. Perform corresponding keyword analysis operations on the target data content to obtain a first exception result.

[0063] Optionally, the above keyword analysis operation can be understood as quickly screening whether there is existing or potential harmful content in the target data content through keyword matching technology, which is not limited in the embodiments of the present invention.

[0064] 203. Perform a corresponding semantic analysis operation on the target data content to obtain a second abnormal result.

[0065] Optionally, the above-mentioned semantic analysis operation can be understood as deeply understanding the textual meaning of the target data content through semantic analysis technology and then determining whether the target data content is abnormal and harmful content, which is not limited in the embodiment of the present invention.

[0066] 204. Perform a corresponding sentiment analysis operation on the target data content to obtain a third abnormal result.

[0067] Optionally, the above sentiment analysis operation can be understood as combining sentiment classification technology to judge the text sentiment of the target data content to determine whether the target data content reflects abnormal and harmful content, which is not limited in the embodiment of the present invention.

[0068] 205. Perform corresponding comprehensive abnormality analysis operations on the target data content according to the first abnormality result, the second abnormality result, and the third abnormality result to obtain abnormal content analysis results corresponding to the target data content.

[0069] Further optionally, performing corresponding comprehensive abnormality analysis operations on the target data content based on the first abnormality result, the second abnormality result, and the third abnormality result to obtain abnormal content analysis results corresponding to the target data content may include: Determine whether there is an abnormal filtering conflict among the first abnormal result, the second abnormal result, and the third abnormal result; When the judgment result is no, the first abnormal result, the second abnormal result, and the third abnormal result are determined as abnormal content analysis results corresponding to the target data content; When the judgment result is yes, determine the abnormal weight scheme corresponding to the target data content for the keyword analysis level, semantic analysis level and sentiment analysis level; determine the abnormal content analysis result corresponding to the target data content based on the abnormal weight scheme, the first abnormal result, the second abnormal result and the third abnormal result.

[0070] 206. Based on the abnormal content analysis result, determine whether the target data content meets the preset abnormal data filtering conditions.

[0071] 207. When it is determined that the target data content meets the abnormal data filtering condition, a corresponding data filtering operation is performed on the target data content according to the abnormal content analysis result.

[0072] In the embodiment of the present invention, for other descriptions of steps 201 to 207, please refer to the other detailed descriptions of steps 101 to 104 in the first embodiment, which will not be repeated in the embodiment of the present invention.

[0073] It can be seen that the embodiments of the present invention can perform corresponding stepped data analysis operations on the target data content to obtain the analysis results of abnormal content, and further perform corresponding data filtering operations on the target data content according to the analysis results of abnormal content, which is beneficial to improving the comprehensiveness and integrity of the data filtering method based on the LLM security protection system, and is beneficial to improving the rationality and comprehensiveness of the data anomaly analysis method. Furthermore, it is beneficial to improve the accuracy and reliability of the determined analysis results of abnormal content, thereby being beneficial to improving the accuracy and reliability of the anomaly detection of the target data content, and being beneficial to improving the efficiency and convenience of the anomaly detection of the target data content. Further, it is beneficial to improve the accuracy and efficiency of data filtering of the target data content, being beneficial to achieving high accuracy and low false alarm rate of data content anomaly detection and filtering, improving the response speed of the security protection system, and improving the security and appropriateness of the finally output / processed and filtered data content; and, it can also determine the analysis results of abnormal content of the target data content from three levels of keyword analysis, semantic analysis, and sentiment analysis, which is beneficial to improving the comprehensiveness and integrity of the method for determining the analysis results of abnormal content of the target data content, and is beneficial to improving the diversity, flexibility, and comprehensiveness of the consideration levels for determining the analysis results of abnormal content. Furthermore, it is beneficial to improve the accuracy and reliability of the determined analysis results of abnormal content, thereby being beneficial to improving the timeliness and reliability of subsequent data filtering based on the analysis results of abnormal content.

[0074] In an optional embodiment, the above-mentioned performing corresponding keyword analysis operations on the target data content to obtain the first abnormal result may include: Performing corresponding character division operations on the target data content according to the preset regular character collocation rules to obtain the character division result; Judging whether the target data content meets the preset keyword anomaly judgment conditions according to the character division result and the preset abnormal keyword set; When it is judged that the target data content meets the keyword anomaly judgment conditions, one or more target abnormal characters are determined from the target data content according to the abnormal keyword set and the character division result; and the first abnormal result is determined according to all the target abnormal characters.

[0075] Optionally, the above-mentioned performing corresponding character division operations on the target data content is illustrated as follows: dividing the target data content into characters according to conventional words, phrases, sentences, expressions, etc., that is, analyzing the target data content in the form of characters. For example, if the target data content is "I love painting", then the character division result can be "I / love / painting", which is not limited in the embodiments of the present invention.

[0076] Further optionally, determining whether the target data content meets the preset keyword anomaly evaluation condition according to the character division result and the preset set of abnormal keywords may include: According to the character division result, determine one or more character combinations, where the character combination includes one or more characters; Determine whether there is at least one character combination in all character combinations that matches the abnormal keywords in the set of abnormal keywords; When the judgment result is yes, determine that the target data content meets the preset keyword anomaly evaluation condition; When the judgment result is no, determine that the target data content does not meet the preset keyword anomaly evaluation condition.

[0077] Optionally, the target abnormal character can be understood as the character in the target data content that matches one or more abnormal keywords in the set of abnormal keywords, which is not limited in the embodiments of the present invention.

[0078] Optionally, the first abnormal result can be used to indicate that there is an anomaly in the keyword analysis level of the target data content and / or to indicate the specific abnormal content, where the specific abnormal content is the target abnormal character, which is not limited in the embodiments of the present invention.

[0079] It can be seen that this optional embodiment can provide a method for determining the first abnormal result at the keyword analysis level. According to the set of abnormal keywords and the character division result, the target abnormal character is determined from the target data content, and then the first abnormal result at the keyword analysis level is determined, which is beneficial to improving the pertinence and rationality of the first abnormal result determination method, and further beneficial to improving the accuracy and reliability of the determined first abnormal result, thus being beneficial to improving the accuracy and reliability of the abnormal content analysis result determined based on the first abnormal result.

[0080] In another optional embodiment, performing the corresponding semantic analysis operation on the target data content to obtain the second abnormal result may include: Perform the corresponding semantic analysis operation on the target data content to obtain the text meaning result corresponding to the target data content; According to the determined application scenario information and text meaning result of the target data content, determine the semantic anomaly level corresponding to the target data content; According to the application scenario information and the semantic anomaly level, determine whether the target data content meets the preset semantic anomaly lower limit condition; When it is determined that the target data content meets the semantic anomaly lower limit condition, according to the application scenario information, determine the scenario semantic anomaly lower limit scheme; according to the scenario semantic anomaly lower limit scheme and the text meaning result, determine the abnormal semantic data object in the target data content; according to the abnormal semantic data object, determine the second abnormal result.

[0081] Optionally, for the application scenario information and the semantic anomaly lower limit condition, an example is given: the upper and lower limits of semantic anomalies in different application scenarios are different. Further, for example, the requirements for judging expression anomalies corresponding to the game combat scenario and the school scenario are different, and the same applies to other situations, which are not limited in the embodiments of the present invention.

[0082] Further optionally, the above determination of whether the target data content meets the preset semantic anomaly lower limit condition according to the application scenario information and the semantic anomaly level may include: Determine the degree of semantic anomaly corresponding to the target data content according to the semantic anomaly level, and determine the threshold of the conventional semantic anomaly degree corresponding to this application scenario according to the application scenario information; Judge whether the degree of semantic anomaly is greater than or equal to the preset threshold of the conventional semantic anomaly degree; When the judgment result is yes, determine that the target data content meets the preset semantic anomaly lower limit condition; When the judgment result is no, determine that the target data content does not meet the preset semantic anomaly lower limit condition.

[0083] Further optionally, the method may further include the following operations: When it is determined that the target data content does not meet the semantic anomaly lower limit condition, determine a second anomaly result, and the second anomaly result is used to indicate that there is no data anomaly in the target data content at the semantic analysis level.

[0084] Optionally, the scenario semantic anomaly lower limit scheme can be understood as: the semantic situations that can be determined as anomalies in this application scenario, which are not limited in the embodiments of the present invention.

[0085] Optionally, the abnormal semantic data object in the target data content can be understood as: the data in the target data content that causes the target data content to be recognized as semantically abnormal, that is, the data that directly causes the target data content to have semantic anomalies, which are not limited in the embodiments of the present invention.

[0086] Further optionally, the above determination of the second anomaly result according to the abnormal semantic data object, for example: the second anomaly result includes the abnormal semantic data object and / or the second anomaly result is used to indicate that there is data anomaly in the target data content at the semantic analysis level, which are not limited in the embodiments of the present invention.

[0087] It can be seen that this optional embodiment can provide a method for determining the second abnormal result at the semantic analysis level, and determine the abnormal semantic data object and then determine the second abnormal result at the semantic analysis level by combining the application scenario information of the target data content, the scenario semantic abnormality lower limit scheme and the text meaning result, which is conducive to improving the pertinence and rationality of the method for determining the second abnormal result, and thus is conducive to improving the accuracy and reliability of the determined second abnormal result, thereby helping to improve the accuracy and reliability of the subsequent abnormal content analysis results determined based on the second abnormal result.

[0088] In yet another optional embodiment, performing the corresponding sentiment analysis operation on the target data content to obtain the third abnormal result may include: Determine, based on the target data content, the emotional expression properties corresponding to the target data content, where the emotional expression properties include positive emotional expression properties or non-positive emotional expression properties; When the emotional expression property includes a non-positive emotional expression property, determining context data content corresponding to the target data content according to the target data content; Determine the induced application properties corresponding to the target data content according to the context data content, where the induced application properties include subjective thought application properties or objective logic application properties; The third abnormal result is determined based on the target data content and the nature of the derived application.

[0089] Optionally, positive emotion expression properties include, for example, positive emotions, optimistic emotions, happy emotions, etc.; non-positive emotion expression properties include, for example, angry emotions, negative emotions, etc., which are not limited in the embodiment of the present invention.

[0090] Optionally, the above-mentioned determination of the induced application properties corresponding to the target data content is based on the context data content. For example: through the context data content, it can be known that, for example, the target data content is just a sentence cited as an example in the entire article, and the target data content does not have any emotional abnormalities (for example, the entire article is used to discuss the phenomenon of anger, then the target data content is a related example of anger expression, and it does not need to be filtered), then it can be determined that the induced application properties are objective logical application properties; for example, the full text emotion of the entire article and the target data content are consistent, and are used to carry over the context, and the target data content has emotional abnormalities (for example, the entire text is abusive, then it needs to be filtered), then it can be determined that the induced application properties are subjective thought application properties, and other situations can be obtained similarly, and the embodiments of the present invention are not limited thereto.

[0091] Optionally, the method may further include the following operations: When the nature of the emotional expression includes a positive emotional expression nature, a third abnormal result is determined to indicate that there is no data abnormality in the target data content at the emotional analysis level.

[0092] Optionally, determining the third abnormal result according to the target data content and the nature of the derived application may include: When the nature of the derived application includes a subjective thought application nature, according to the target data content, determining that the third abnormal result includes the target data content and / or the third abnormal result is used to indicate that there is data abnormality in the target data content at the emotional analysis level; When the nature of the derived application includes an objective logic application nature, determining the third abnormal result is used to indicate that there is no data abnormality in the target data content at the emotional analysis level.

[0093] It can be seen that this optional embodiment can provide a method for determining the third abnormal result at the emotional analysis level. According to the emotional expression nature of the determined target data content and the context data content, the corresponding nature of the derived application is determined, and then the third abnormal result at the emotional analysis level is further determined. This is beneficial to improving the pertinence and rationality of the method for determining the third abnormal result, and further beneficial to improving the accuracy and reliability of the determined third abnormal result, thus beneficial to improving the accuracy and reliability of the abnormal content analysis result determined based on the third abnormal result subsequently.

[0094] Embodiment III Please refer to Figure 3 , Figure 3 which is a schematic structural diagram of a data filtering system based on an LLM security protection system disclosed in an embodiment of the present invention. Among them, Figure 3 the described system may include a server, where the server includes a local server or a cloud server, which is not limited in the embodiments of the present invention. As Figure 3 shown, the data filtering system based on the LLM security protection system may include: A data receiving module 301, configured to receive target data content that needs to be analyzed for data filtering.

[0095] An abnormal data analysis module 302, configured to perform corresponding stepped data analysis operations on the target data content to obtain an abnormal content analysis result corresponding to the target data content.

[0096] A judgment module 303, configured to judge whether the target data content meets a preset abnormal data filtering condition according to the abnormal content analysis result.

[0097] A data filtering module 304, configured to perform corresponding data filtering operations on the target data content according to the abnormal content analysis result when the judgment module determines that the target data content meets the abnormal data filtering condition.

[0098] It can be seen that implementing Figure 3 the described data filtering system based on the LLM security protection system can perform corresponding stepped data analysis operations on the target data content to obtain the analysis result of abnormal content, and further perform corresponding data filtering operations on the target data content according to the analysis result of abnormal content, which is beneficial to improving the comprehensiveness and integrity of the data filtering method based on the LLM security protection system, and is beneficial to improving the rationality and comprehensiveness of the data anomaly analysis method. Furthermore, it is beneficial to improve the accuracy and reliability of the determined analysis result of abnormal content, thereby being beneficial to improving the accuracy and reliability of the anomaly detection of the target data content, and being beneficial to improving the efficiency and convenience of the anomaly detection of the target data content. Further, it is beneficial to improve the accuracy and efficiency of the data filtering of the target data content, which is beneficial to achieving high accuracy and low false alarm rate of the anomaly detection and filtering of the data content, improving the response speed of the security protection system, and improving the security and appropriateness of the finally output / processed and filtered data content.

[0099] In an alternative embodiment, the manner in which the abnormal data analysis module 302 performs corresponding stepped data analysis operations on the target data content to obtain the analysis result of abnormal content corresponding to the target data content specifically includes: Performing corresponding keyword analysis operations on the target data content to obtain a first abnormal result; Performing corresponding semantic analysis operations on the target data content to obtain a second abnormal result; Performing corresponding sentiment analysis operations on the target data content to obtain a third abnormal result; Performing corresponding comprehensive abnormal analysis operations on the target data content according to the first abnormal result, the second abnormal result, and the third abnormal result to obtain the analysis result of abnormal content corresponding to the target data content.

[0100] It can be seen that implementing Figure 3 the described system can also determine the analysis result of abnormal content of the target data content from three levels of keyword analysis, semantic analysis, and sentiment analysis, which is beneficial to improving the comprehensiveness and integrity of the method for determining the analysis result of abnormal content of the target data content, and is beneficial to improving the diversity, flexibility, and comprehensiveness of the consideration levels for determining the analysis result of abnormal content. Furthermore, it is beneficial to improve the accuracy and reliability of the determined analysis result of abnormal content, thereby being beneficial to improving the timeliness and reliability of subsequent data filtering based on the analysis result of abnormal content.

[0101] In another alternative embodiment, the manner in which the abnormal data analysis module 302 performs corresponding keyword analysis operations on the target data content to obtain a first abnormal result specifically includes: Perform corresponding character division operations on the target data content according to the preset conventional character collocation rules to obtain a character division result; Judge whether the target data content meets the preset keyword anomaly evaluation conditions according to the character division result and the preset set of abnormal keywords; When it is judged that the target data content meets the keyword anomaly evaluation conditions, determine one or more target abnormal characters from the target data content according to the set of abnormal keywords and the character division result; determine the first anomaly result according to all the target abnormal characters.

[0102] It can be seen that implementing Figure 3 The described system can also provide a method for determining the first anomaly result at the keyword analysis level. According to the set of abnormal keywords and the character division result, determine the target abnormal characters from the target data content and then determine the first anomaly result at the keyword analysis level, which is beneficial to improving the pertinence and rationality of the method for determining the first anomaly result, and thus beneficial to improving the accuracy and reliability of the determined first anomaly result, and thereby beneficial to improving the accuracy and reliability of the subsequent anomaly content analysis result determined based on the first anomaly result.

[0103] In another optional embodiment, the specific manner in which the abnormal data analysis module 302 performs corresponding semantic analysis operations on the target data content to obtain a second anomaly result includes: Perform corresponding semantic analysis operations on the target data content to obtain a text meaning result corresponding to the target data content; Determine the semantic anomaly level corresponding to the target data content according to the determined application scenario information and text meaning result of the target data content; Judge whether the target data content meets the preset semantic anomaly lower limit condition according to the application scenario information and the semantic anomaly level; When it is judged that the target data content meets the semantic anomaly lower limit condition, determine the scenario semantic anomaly lower limit scheme according to the application scenario information; determine the abnormal semantic data object in the target data content according to the scenario semantic anomaly lower limit scheme and the text meaning result; determine the second anomaly result according to the abnormal semantic data object.

[0104] It can be seen that implementing Figure 3The described system is also capable of providing a second abnormal result determination method for the semantic analysis level. By combining the application scenario information of the target data content, the scenario semantic abnormality lower limit scheme, and the text meaning result, abnormal semantic data objects are determined, and then the second abnormal result for the semantic analysis level is determined. This is beneficial to improving the pertinence and rationality of the second abnormal result determination method, and further beneficial to improving the accuracy and reliability of the determined second abnormal result. Thus, it is beneficial to improve the accuracy and reliability of the abnormal content analysis result determined based on the second abnormal result subsequently.

[0105] In yet another alternative embodiment, the abnormal data analysis module 302 performs corresponding sentiment analysis operations on the target data content. The specific manner of obtaining the third abnormal result includes: Based on the target data content, determine the sentiment expression property corresponding to the target data content. The sentiment expression property includes a positive sentiment expression property or a non - positive sentiment expression property; When the sentiment expression property includes a non - positive sentiment expression property, based on the target data content, determine the context data content corresponding to the target data content; Based on the context data content, determine the lead - out application property corresponding to the target data content. The lead - out application property includes a subjective thought application property or an objective logic application property; Based on the target data content and the lead - out application property, determine the third abnormal result.

[0106] It can be seen that implementing Figure 3 The described system is also capable of providing a third abnormal result determination method for the sentiment analysis level. By determining the sentiment expression property of the target data content and the context data content, the corresponding lead - out application property is determined, and further the third abnormal result for the sentiment analysis level is determined. This is beneficial to improving the pertinence and rationality of the third abnormal result determination method, and further beneficial to improving the accuracy and reliability of the determined third abnormal result. Thus, it is beneficial to improve the accuracy and reliability of the abnormal content analysis result determined based on the third abnormal result subsequently.

[0107] In yet another alternative embodiment, the data filtering module 304 performs corresponding data filtering operations on the target data content according to the abnormal content analysis result. The specific manner includes: Based on the abnormal content analysis result, determine the target abnormal object corresponding to the target data content. The target abnormal object includes the overall content or partial content of the target data content; Based on the associated data information corresponding to the target data content, determine the application importance and filtering influence degree of the target data content, and according to the application importance and filtering influence degree, determine the filtering consideration requirement degree of the target data content; Determine the target filtering method for the target data content according to the target exception object and the filtering consideration requirement degree; When the target filtering method is used to represent the overall filtering method, perform the corresponding overall data filtering operation on the target data content; When the target filtering method is used to represent the partial filtering method, perform the corresponding partial data filtering operation on the target data content according to the target exception object.

[0108] It can be seen that implementing Figure 3 The described system can also determine the target filtering method according to the target exception object and the filtering consideration requirement degree of the determined target data content, and further perform the corresponding data filtering operation according to the target filtering method. The target filtering method includes the overall filtering method or the partial filtering method, which is beneficial to improving the comprehensiveness and rationality of the method for determining the target filtering method of the target data content, and further beneficial to improving the diversity, flexibility and pertinence of the target filtering method, thereby being beneficial to improving the execution accuracy and execution reliability of the data filtering operation, and further being beneficial to improving the data filtering accuracy and reliability of the target data content.

[0109] In another optional embodiment, the manner in which the judgment module 303 determines whether the target data content meets the preset abnormal data filtering condition according to the abnormal content analysis result specifically includes: According to the abnormal content analysis result, determine whether the target data content meets the preset abnormal data existence condition; When it is determined that the target data content does not meet the abnormal data existence condition, determine that the target data content does not meet the preset abnormal data filtering condition; When it is determined that the target data content meets the abnormal data existence condition, according to the abnormal content analysis result, determine the specific abnormal content corresponding to the target data content, and according to the specific abnormal content, determine the abnormality universality and abnormality severity corresponding to the target data content; According to the abnormality universality and abnormality severity, determine whether the target data content meets the preset data filtering emergency condition; When it is determined that the target data content meets the data filtering emergency condition, determine that the target data content meets the preset abnormal data filtering condition; When it is determined that the target data content does not meet the data filtering emergency condition, determine that the target data content does not meet the preset abnormal data filtering condition.

[0110] It can be seen that implementing Figure 3The described system can also determine the satisfaction result of the abnormal data filtering condition from two levels: the existence condition of abnormal data and the emergency condition of data filtering, which is beneficial to improving the comprehensiveness, integrity, rationality, and progressive nature of the method for determining the satisfaction result of the abnormal data filtering condition. Furthermore, it is beneficial to improve the accuracy and reliability of the determined satisfaction result of the abnormal data filtering condition, thereby facilitating the timeliness, accuracy, reliability, and efficiency of the subsequent data filtering operation based on the satisfaction result of the abnormal data filtering condition.

[0111] Embodiment 4 Please refer to Figure 4 , Figure 4 which is a schematic structural diagram of another data filtering system based on the LLM security protection system disclosed in the embodiments of the present invention. Among them, Figure 4 the described device may include a server, where the server includes a local server or a cloud server, which is not limited in the embodiments of the present invention. As Figure 4 shown, the device may include: a memory 401 storing executable program code; a processor 402 coupled to the memory 401; Furthermore, it may further include an input interface 403 and an output interface 404 coupled to the processor 402; wherein, the processor 402 calls the executable program code stored in the memory 401 to execute the steps in the data filtering method based on the LLM security protection system described in Embodiment 1 or Embodiment 2.

[0112] Embodiment 5 The embodiments of the present invention disclose a computer storage medium that stores a computer program for electronic data exchange, where the computer program causes the computer to execute the steps in the data filtering method based on the LLM security protection system described in Embodiment 1 or Embodiment 2.

[0113] Embodiment 6 The embodiments of the present invention disclose a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to cause the computer to execute the steps in the data filtering method based on the LLM security protection system described in Embodiment 1 or Embodiment 2.

[0114] The device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.

[0115] Through the above specific descriptions of the embodiments, those skilled in the art can clearly understand that each implementation can be achieved by means of software plus a necessary general hardware platform, and of course, it can also be achieved by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, and the storage medium includes read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc memories, magnetic disk memories, tape memories, or any other computer-readable medium that can be used to carry or store data.

[0116] Finally, it should be noted that: The data filtering method and system based on the LLM security protection system disclosed in the embodiments of the present invention only disclose the preferred embodiments of the present invention, which are only used to illustrate the technical solutions of the present invention and are not intended to limit them; Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; And these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A data filtering method for an LLM-based security protection system, characterized in that, The method includes: Receiving target data content that needs to be analyzed for data filtering; Performing corresponding stepped data analysis operations on the target data content to obtain an analysis result of abnormal content corresponding to the target data content; Judging whether the target data content meets a preset abnormal data filtering condition according to the analysis result of abnormal content; When it is judged that the target data content meets the abnormal data filtering condition, performing corresponding data filtering operations on the target data content according to the analysis result of abnormal content.

2. The data filtering method based on the LLM security protection system according to claim 1, characterized in that The performing corresponding stepped data analysis operations on the target data content to obtain an analysis result of abnormal content corresponding to the target data content includes: Performing corresponding keyword analysis operations on the target data content to obtain a first abnormal result; Performing corresponding semantic analysis operations on the target data content to obtain a second abnormal result; Performing corresponding sentiment analysis operations on the target data content to obtain a third abnormal result; Performing corresponding comprehensive abnormal analysis operations on the target data content according to the first abnormal result, the second abnormal result, and the third abnormal result to obtain an analysis result of abnormal content corresponding to the target data content.

3. The data filtering method based on the LLM security protection system according to claim 2, wherein, The performing corresponding keyword analysis operations on the target data content to obtain a first abnormal result includes: Performing corresponding character division operations on the target data content according to a preset regular character collocation rule to obtain a character division result; Judging whether the target data content meets a preset keyword abnormal judgment condition according to the character division result and a preset abnormal keyword set; When it is judged that the target data content meets the keyword abnormal judgment condition, determining one or more target abnormal characters from the target data content according to the abnormal keyword set and the character division result; and determining a first abnormal result according to all the target abnormal characters.

4. The data filtering method based on the LLM security protection system according to claim 2, wherein The performing corresponding semantic analysis operations on the target data content to obtain a second abnormal result includes: Performing corresponding semantic analysis operations on the target data content to obtain a text meaning result corresponding to the target data content; Determining a semantic abnormal level corresponding to the target data content according to the determined application scenario information of the target data content and the text meaning result; Judging whether the target data content meets a preset semantic abnormal lower limit condition according to the application scenario information and the semantic abnormal level; When it is judged that the target data content meets the semantic abnormal lower limit condition, determining a scenario semantic abnormal lower limit scheme according to the application scenario information; determining an abnormal semantic data object in the target data content according to the scenario semantic abnormal lower limit scheme and the text meaning result; and determining a second abnormal result according to the abnormal semantic data object.

5. The data filtering method based on the LLM security protection system according to claim 2, characterized in that, The performing corresponding sentiment analysis operations on the target data content to obtain a third abnormal result includes: Determining a sentiment expression property corresponding to the target data content according to the target data content, where the sentiment expression property includes a positive sentiment expression property or a non-positive sentiment expression property; When the emotional expression property includes the non-positive emotional expression property, determine the context data content corresponding to the target data content according to the target data content; Determine the leading application property corresponding to the target data content according to the context data content, where the leading application property includes a subjective thought application property or an objective logic application property; Determine the third abnormal result according to the target data content and the leading application property.

6. The data filtering method based on the LLM security protection system according to any one of claims 1-5, characterized in that, The performing corresponding data filtering operations on the target data content according to the abnormal content analysis result includes: Determine the target abnormal object corresponding to the target data content according to the abnormal content analysis result, where the target abnormal object includes the overall content or partial content of the target data content; Determine the application importance and filtering influence degree of the target data content according to the associated data information corresponding to the target data content, and determine the filtering consideration requirement degree of the target data content according to the application importance and the filtering influence degree; Determine the target filtering method of the target data content according to the target abnormal object and the filtering consideration requirement degree; When the target filtering method is used to represent an overall filtering method, perform corresponding overall data filtering operations on the target data content; When the target filtering method is used to represent a partial filtering method, perform corresponding partial data filtering operations on the target data content according to the target abnormal object.

7. The data filtering method based on the LLM security protection system according to any one of claims 1-5, characterized in that The judging whether the target data content meets the preset abnormal data filtering conditions according to the abnormal content analysis result includes: Judge whether the target data content meets the preset abnormal data existence condition according to the abnormal content analysis result; When it is judged that the target data content does not meet the abnormal data existence condition, determine that the target data content does not meet the preset abnormal data filtering condition; When it is judged that the target data content meets the abnormal data existence condition, determine the specific abnormal content corresponding to the target data content according to the abnormal content analysis result, and determine the abnormality universality and abnormality severity corresponding to the target data content according to the specific abnormal content; Judge whether the target data content meets the preset data filtering emergency condition according to the abnormality universality and the abnormality severity; When it is judged that the target data content meets the data filtering emergency condition, determine that the target data content meets the preset abnormal data filtering condition; When it is judged that the target data content does not meet the data filtering emergency condition, determine that the target data content does not meet the preset abnormal data filtering condition.

8. A data filtering system for an LLM security protection system, characterized in that, The system includes: A data receiving module, configured to receive target data content that needs to be analyzed for data filtering; An abnormal data analysis module, configured to perform corresponding stepped data analysis operations on the target data content to obtain an abnormal content analysis result corresponding to the target data content; A judging module, configured to judge whether the target data content meets the preset abnormal data filtering conditions according to the abnormal content analysis result; A data filtering module, configured to perform corresponding data filtering operations on the target data content according to the abnormal content analysis result when the judgment module determines that the target data content meets the abnormal data filtering condition.

9. A data filtering system for an LLM security protection system, characterized in that, The system includes: A memory storing executable program code; A processor coupled to the memory; The processor calls the executable program code stored in the memory and executes the data filtering method of the LLM-based security protection system according to any one of claims 1-7.

10. A computer storage medium, characterized in that, The computer storage medium stores computer instructions, which are used to execute the data filtering method of the LLM-based security protection system according to any one of claims 1-7 when the computer instructions are called.

Citation Information

Patent Citations

  • Data filtering and mining method

    CN109783619A

  • LLM model-based alarm log analysis method and system

    CN117539666A

  • Black bear abnormity monitoring method and device based on multi-modal information

    CN118296528A

  • LLM-driven industrial network intrusion detection method and response system

    CN118381627A

  • Report generation method and device, equipment, medium and product

    CN119293184A