Data filtering method and system based on LLM security protection system

Through the step-by-step data analysis method based on the LLM security protection system, combined with keyword, semantic and sentiment analysis, the problems of low data filtering accuracy and efficiency in the prior art are solved, and data filtering effect with high accuracy and low false alarm rate is achieved.

CN120407785BActive Publication Date: 2025-09-02GUANGDONG PLANNING & DESIGNING INST OF TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510905269.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-02
Publication Date
2025-09-02
Estimated Expiration
2045-07-02

AI Technical Summary

Technical Problem

In the prior art, data filtering methods based on large language models rely on manual evaluation, which have problems of accuracy and low efficiency, and lack of standard quantitative evaluation methods, resulting in deviations in data filtering results.

Method used

The step-by-step data analysis method based on the LLM security protection system is adopted, including keyword analysis, semantic analysis and sentiment analysis. The target data content is evaluated at multiple levels, and whether abnormal data filtering conditions are met, and corresponding data filtering operations are performed.

Benefits of technology

It improves the accuracy and efficiency of data filtering, reduces the false alarm rate, and enhances the response speed of the security protection system and the security of output data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120407785B_ABST
    Figure CN120407785B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of data processing technology, and discloses a data filtering method and system based on an LLM security protection system, the method comprising: receiving target data content that needs to be subjected to data filtering analysis; performing a step-by-step data analysis operation on the target data content to obtain an abnormal content analysis result; judging whether the target data content meets an abnormal data filtering condition based on the abnormal content analysis result; and if so, performing a corresponding data filtering operation on the target data content based on the abnormal content analysis result. It can be seen that the implementation of the present invention can improve the accuracy and reliability of abnormality detection of target data content, improve the efficiency and convenience of abnormality detection of target data content, further improve the accuracy and efficiency of data filtering of target data content, achieve high accuracy and low false alarm rate of data content abnormality detection and filtering, improve the response speed of the security protection system, and improve the security and appropriateness of the final output / processed filtered data content.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing technology, and in particular to a data filtering method and system based on an LLM security protection system. Background Art

[0002] As large-scale language models are increasingly used in various fields, their security issues are becoming increasingly prominent. Specifically, when generating text, large-scale language models may produce content containing malicious code, sensitive information, or inappropriate speech. It is necessary to monitor the data in real time and intercept these potential security risks to avoid losses to users and society.

[0003] Currently, most data filtering methods rely on staff members subjectively filtering and evaluating input data in the background. This subjective evaluation is affected by many factors, such as staff members' poor mental state during data filtering and evaluation, different staff members' different considerations and emphases when evaluating the same data, and the lack of a standardized and quantitative evaluation method. This can lead to deviations in the data filtering evaluation results even for the same data under the same conditions. Furthermore, staff members are required to manually filter and delete each data object, resulting in low data filtering accuracy and efficiency. Therefore, it is particularly important to provide a data filtering method that can improve data filtering accuracy and efficiency. Summary of the Invention

[0004] The present invention provides a data filtering method and system based on the LLM security protection system, which can improve the filtering accuracy and efficiency of data.

[0005] In order to solve the above technical problems, the first aspect of the present invention discloses a data filtering method based on the LLM security protection system, the method comprising:

[0006] Receive target data content that requires data filtering and analysis;

[0007] Performing corresponding step-by-step data analysis operations on the target data content to obtain abnormal content analysis results corresponding to the target data content;

[0008] According to the abnormal content analysis result, determining whether the target data content meets the preset abnormal data filtering conditions;

[0009] When it is determined that the target data content meets the abnormal data filtering condition, a corresponding data filtering operation is performed on the target data content according to the abnormal content analysis result.

[0010] As an optional implementation, in the first aspect of the present invention, performing corresponding step-by-step data analysis operations on the target data content to obtain abnormal content analysis results corresponding to the target data content may include:

[0011] Performing a corresponding keyword analysis operation on the target data content to obtain a first abnormal result;

[0012] Performing a corresponding semantic analysis operation on the target data content to obtain a second abnormal result;

[0013] Performing a corresponding sentiment analysis operation on the target data content to obtain a third abnormal result;

[0014] According to the first abnormal result, the second abnormal result and the third abnormal result, a corresponding comprehensive abnormal analysis operation is performed on the target data content to obtain an abnormal content analysis result corresponding to the target data content.

[0015] As an optional implementation manner, in the first aspect of the present invention, performing a corresponding keyword analysis operation on the target data content to obtain a first abnormal result includes:

[0016] According to the preset conventional character collocation rules, a corresponding character segmentation operation is performed on the target data content to obtain a character segmentation result;

[0017] According to the character segmentation result and the preset abnormal keyword set, determining whether the target data content meets the preset keyword abnormality judgment condition;

[0018] When it is determined that the target data content meets the keyword abnormality judgment condition, one or more target abnormal characters are determined from the target data content according to the abnormal keyword set and the character segmentation result; and a first abnormal result is determined based on all the target abnormal characters.

[0019] As an optional implementation manner, in the first aspect of the present invention, performing a corresponding semantic analysis operation on the target data content to obtain a second abnormal result includes:

[0020] Performing corresponding semantic analysis operations on the target data content to obtain a text meaning result corresponding to the target data content;

[0021] Determining a semantic anomaly level corresponding to the target data content based on the determined application scenario information of the target data content and the text meaning result;

[0022] According to the application scenario information and the semantic anomaly level, determining whether the target data content meets a preset semantic anomaly lower limit condition;

[0023] When it is determined that the target data content meets the semantic anomaly lower limit condition, the scene semantic anomaly lower limit scheme is determined according to the application scenario information; the abnormal semantic data object in the target data content is determined according to the scene semantic anomaly lower limit scheme and the text meaning result; and the second abnormal result is determined according to the abnormal semantic data object.

[0024] As an optional implementation manner, in the first aspect of the present invention, performing a corresponding sentiment analysis operation on the target data content to obtain a third abnormal result includes:

[0025] Determining, based on the target data content, an emotional expression property corresponding to the target data content, the emotional expression property including a positive emotional expression property or a non-positive emotional expression property;

[0026] When the emotional expression property includes the non-positive emotional expression property, determining context data content corresponding to the target data content according to the target data content;

[0027] Determining, based on the context data content, an induced application property corresponding to the target data content, the induced application property including a subjective thought application property or an objective logic application property;

[0028] The third abnormal result is determined according to the target data content and the derived application property.

[0029] As an optional implementation manner, in the first aspect of the present invention, performing corresponding data filtering operations on the target data content according to the abnormal content analysis results includes:

[0030] Determine, based on the abnormal content analysis result, a target abnormal object corresponding to the target data content, wherein the target abnormal object includes the entire content or a portion of the target data content;

[0031] Determining the application importance and filtering impact of the target data content based on the associated data information corresponding to the target data content, and determining the filtering consideration requirement of the target data content based on the application importance and the filtering impact;

[0032] Determining a target filtering method for the target data content according to the target abnormal object and the filtering consideration requirement;

[0033] When the target filtering mode is used to represent an overall filtering mode, a corresponding overall data filtering operation is performed on the target data content;

[0034] When the target filtering mode is used to represent a partial filtering mode, a corresponding partial data filtering operation is performed on the target data content according to the target abnormal object.

[0035] As an optional implementation manner, in the first aspect of the present invention, judging whether the target data content meets a preset abnormal data filtering condition based on the abnormal content analysis result includes:

[0036] According to the abnormal content analysis result, determining whether the target data content meets the preset abnormal data existence condition;

[0037] When it is determined that the target data content does not satisfy the abnormal data existence condition, determining that the target data content does not satisfy a preset abnormal data filtering condition;

[0038] When it is determined that the target data content meets the abnormal data existence condition, determining the specific abnormal content corresponding to the target data content according to the abnormal content analysis result, and determining the abnormal prevalence and abnormal severity corresponding to the target data content according to the specific abnormal content;

[0039] Determining whether the target data content meets a preset data filtering emergency condition based on the anomaly prevalence and the anomaly severity;

[0040] When it is determined that the target data content meets the data filtering emergency condition, determining that the target data content meets the preset abnormal data filtering condition;

[0041] When it is determined that the target data content does not satisfy the data filtering emergency condition, it is determined that the target data content does not satisfy a preset abnormal data filtering condition.

[0042] A second aspect of the present invention discloses a data filtering system based on the LLM security protection system, the system comprising:

[0043] A data receiving module is used to receive target data content that needs to be filtered and analyzed;

[0044] An abnormal data analysis module is used to perform a corresponding step-by-step data analysis operation on the target data content to obtain an abnormal content analysis result corresponding to the target data content;

[0045] A judgment module, configured to judge whether the target data content satisfies a preset abnormal data filtering condition based on the abnormal content analysis result;

[0046] The data filtering module is configured to perform corresponding data filtering operations on the target data content according to the abnormal content analysis result when the judgment module determines that the target data content meets the abnormal data filtering condition.

[0047] As an optional embodiment, in the second aspect of the present invention, the abnormal data analysis module performs corresponding step-by-step data analysis operations on the target data content to obtain abnormal content analysis results corresponding to the target data content, specifically including:

[0048] Performing a corresponding keyword analysis operation on the target data content to obtain a first abnormal result;

[0049] Performing a corresponding semantic analysis operation on the target data content to obtain a second abnormal result;

[0050] Performing a corresponding sentiment analysis operation on the target data content to obtain a third abnormal result;

[0051] According to the first abnormal result, the second abnormal result and the third abnormal result, a corresponding comprehensive abnormal analysis operation is performed on the target data content to obtain an abnormal content analysis result corresponding to the target data content.

[0052] As an optional implementation, in the second aspect of the present invention, the abnormal data analysis module performs a corresponding keyword analysis operation on the target data content, and a manner of obtaining the first abnormal result specifically includes:

[0053] According to the preset conventional character collocation rules, a corresponding character segmentation operation is performed on the target data content to obtain a character segmentation result;

[0054] According to the character segmentation result and the preset abnormal keyword set, determining whether the target data content meets the preset keyword abnormality judgment condition;

[0055] When it is determined that the target data content meets the keyword abnormality judgment condition, one or more target abnormal characters are determined from the target data content according to the abnormal keyword set and the character segmentation result; and a first abnormal result is determined based on all the target abnormal characters.

[0056] As an optional implementation, in the second aspect of the present invention, the abnormal data analysis module performs a corresponding semantic analysis operation on the target data content, and a manner of obtaining the second abnormal result specifically includes:

[0057] Performing corresponding semantic analysis operations on the target data content to obtain a text meaning result corresponding to the target data content;

[0058] Determining a semantic anomaly level corresponding to the target data content based on the determined application scenario information of the target data content and the text meaning result;

[0059] According to the application scenario information and the semantic anomaly level, determining whether the target data content meets a preset semantic anomaly lower limit condition;

[0060] When it is determined that the target data content meets the semantic anomaly lower limit condition, the scene semantic anomaly lower limit scheme is determined according to the application scenario information; the abnormal semantic data object in the target data content is determined according to the scene semantic anomaly lower limit scheme and the text meaning result; and the second abnormal result is determined according to the abnormal semantic data object.

[0061] As an optional implementation, in the second aspect of the present invention, the abnormal data analysis module performs a corresponding sentiment analysis operation on the target data content, and a manner of obtaining the third abnormal result specifically includes:

[0062] Determining, based on the target data content, an emotional expression property corresponding to the target data content, the emotional expression property including a positive emotional expression property or a non-positive emotional expression property;

[0063] When the emotional expression property includes the non-positive emotional expression property, determining context data content corresponding to the target data content according to the target data content;

[0064] Determining, based on the context data content, an induced application property corresponding to the target data content, the induced application property including a subjective thought application property or an objective logic application property;

[0065] The third abnormal result is determined according to the target data content and the derived application property.

[0066] As an optional implementation, in the second aspect of the present invention, the data filtering module performs corresponding data filtering operations on the target data content according to the abnormal content analysis result, specifically including:

[0067] Determine, based on the abnormal content analysis result, a target abnormal object corresponding to the target data content, wherein the target abnormal object includes the entire content or a portion of the target data content;

[0068] Determining the application importance and filtering impact of the target data content based on the associated data information corresponding to the target data content, and determining the filtering consideration requirement of the target data content based on the application importance and the filtering impact;

[0069] Determining a target filtering method for the target data content according to the target abnormal object and the filtering consideration requirement;

[0070] When the target filtering mode is used to represent an overall filtering mode, a corresponding overall data filtering operation is performed on the target data content;

[0071] When the target filtering mode is used to represent a partial filtering mode, a corresponding partial data filtering operation is performed on the target data content according to the target abnormal object.

[0072] As an optional implementation, in the second aspect of the present invention, the judgment module determines whether the target data content meets the preset abnormal data filtering condition based on the abnormal content analysis result, specifically including:

[0073] According to the abnormal content analysis result, determining whether the target data content meets the preset abnormal data existence condition;

[0074] When it is determined that the target data content does not satisfy the abnormal data existence condition, determining that the target data content does not satisfy a preset abnormal data filtering condition;

[0075] When it is determined that the target data content meets the abnormal data existence condition, determining the specific abnormal content corresponding to the target data content according to the abnormal content analysis result, and determining the abnormal prevalence and abnormal severity corresponding to the target data content according to the specific abnormal content;

[0076] Determining whether the target data content meets a preset data filtering emergency condition based on the anomaly prevalence and the anomaly severity;

[0077] When it is determined that the target data content meets the data filtering emergency condition, determining that the target data content meets the preset abnormal data filtering condition;

[0078] When it is determined that the target data content does not satisfy the data filtering emergency condition, it is determined that the target data content does not satisfy a preset abnormal data filtering condition.

[0079] The third aspect of the present invention discloses another data filtering system based on the LLM security protection system, the system comprising:

[0080] a memory storing executable program code;

[0081] a processor coupled to the memory;

[0082] The processor calls the executable program code stored in the memory to execute the data filtering method based on the LLM security protection system disclosed in the first aspect of the present invention.

[0083] The fourth aspect of the present invention discloses a computer storage medium, which stores computer instructions. When the computer instructions are called, they are used to execute the data filtering method based on the LLM security protection system disclosed in the first aspect of the present invention.

[0084] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:

[0085] In an embodiment of the present invention, target data content that requires data filtering analysis is received; a corresponding step-by-step data analysis operation is performed on the target data content to obtain an abnormal content analysis result corresponding to the target data content; based on the abnormal content analysis result, it is determined whether the target data content meets a preset abnormal data filtering condition; when it is determined that the target data content meets the abnormal data filtering condition, a corresponding data filtering operation is performed on the target data content based on the abnormal content analysis result. It can be seen that the present invention can perform corresponding step-by-step data analysis operations on the target data content to obtain abnormal content analysis results, and further perform corresponding data filtering operations on the target data content according to the abnormal content analysis results, which is conducive to improving the comprehensiveness and integrity of the data filtering method based on the LLM security protection system, and is conducive to improving the rationality and comprehensiveness of the data anomaly analysis method, and thus is conducive to improving the accuracy and reliability of the determined abnormal content analysis results, thereby helping to improve the accuracy and reliability of anomaly detection of target data content, and is conducive to improving the efficiency and convenience of anomaly detection of target data content, and further helping to improve the data filtering accuracy and data filtering efficiency of target data content, and is conducive to achieving high accuracy and low false alarm rate of data content anomaly detection and filtering, improving the response speed of the security protection system, and improving the security and appropriateness of the final output / processed filtered data content. BRIEF DESCRIPTION OF THE DRAWINGS

[0086] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0087] Figure 1 This is a flow chart of a data filtering method based on the LLM security protection system disclosed in an embodiment of the present invention;

[0088] Figure 2This is a flow chart of another data filtering method for an LLM security protection system disclosed in an embodiment of the present invention;

[0089] Figure 3 This is a structural diagram of a data filtering system based on an LLM security protection system disclosed in an embodiment of the present invention;

[0090] Figure 4 This is a structural diagram of another data filtering system based on the LLM security protection system disclosed in an embodiment of the present invention. DETAILED DESCRIPTION

[0091] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0092] The terms "first," "second," and so on, in the description and claims of the present invention and the accompanying drawings are used to distinguish between different items, not to describe a specific order. Furthermore, the terms "including," "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, apparatus, product, or end comprising a series of steps or elements is not limited to the listed steps or elements but may optionally include steps or elements not listed therein, or may optionally include other steps or elements inherent to such process, method, product, or end.

[0093] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present invention. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute a separate or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0094] The present invention discloses a data filtering method and system based on an LLM security protection system, which can perform corresponding step-by-step data analysis operations on target data content to obtain abnormal content analysis results, and further perform corresponding data filtering operations on the target data content based on the abnormal content analysis results. This is conducive to improving the comprehensiveness and integrity of the data filtering method based on the LLM security protection system, as well as improving the rationality and comprehensiveness of the data abnormality analysis method, thereby facilitating improving the accuracy and reliability of the determined abnormal content analysis results, thereby facilitating improving the accuracy and reliability of abnormality detection of target data content, as well as improving the efficiency and convenience of abnormality detection of target data content, further facilitating improving the accuracy and efficiency of data filtering of target data content, facilitating achieving high accuracy and low false alarm rate of data content abnormality detection and filtering, improving the response speed of the security protection system, and improving the security and appropriateness of the final output / processed filtered data content. Detailed descriptions are given below.

[0095] Example 1

[0096] See also Figure 1 , Figure 1 This is a flow chart of a data filtering method based on the LLM security protection system disclosed in an embodiment of the present invention. Figure 1 The described method can be applied to a data filtering system based on an LLM security protection system, wherein the system may include a server, wherein the server includes a local server or a cloud server, which is not limited in the embodiment of the present invention. Figure 1 As shown, the data filtering method based on the LLM security protection system includes the following operations:

[0097] 101. Receive target data content that requires data filtering and analysis.

[0098] Optionally, the target data content may be text data content, language data content, other data content that can express meaning, etc.; further, other data content that can express meaning, such as code, etc., is not limited in the embodiment of the present invention.

[0099] Further optionally, the target data content is input into an intelligent data filtering module based on the LLM security protection system for analysis and data filtering. Through advanced natural language processing technology, abnormal data content is detected and filtered in real time to ensure the security of the data output by the intelligent data filtering module. This is not limited in the embodiments of the present invention.

[0100] Optionally, the target data content that requires data filtering analysis can be understood as the data content input into the intelligent data filtering module based on the LLM security protection system for analysis. The target data content may contain abnormal data and require data filtering, or may contain abnormal data but not require data filtering, or may not contain abnormal data and not require data filtering. The embodiment of the present invention does not limit this.

[0101] 102. Perform corresponding step-by-step data analysis operations on the target data content to obtain abnormal content analysis results corresponding to the target data content.

[0102] Optionally, the abnormal content analysis results corresponding to the target data content may include, but are not limited to, one or more of information used to indicate whether the target data content contains abnormal content, specific abnormal data of the target data content and its corresponding abnormal type, and other information that can reflect the abnormal situation of the target data content, etc., and the embodiments of the present invention do not limit this.

[0103] Specific abnormal data may be, for example, violent speech, hate speech, adult content, or other inappropriate information, which is not limited in this embodiment of the present invention.

[0104] Optionally, the step-by-step data analysis operation may include, but is not limited to, one or more of keyword-based data analysis operations, semantic-based data analysis operations, emotion-based data analysis operations, and data analysis operations based on other parameters, and is not limited in the embodiments of the present invention.

[0105] 103. Based on the abnormal content analysis results, determine whether the target data content meets the preset abnormal data filtering conditions.

[0106] Further optionally, the method may further include the following operations:

[0107] When it is determined that the target data content does not meet the preset abnormal data filtering conditions, the target data label of the target data content is determined, and based on the target data label and the determined current filtering mode, it is determined whether the target data content meets the preset filtering label conditions;

[0108] When it is determined that the target data content meets the filtering label conditions, the corresponding data filtering operation is performed on the target data content according to the target data label;

[0109] When it is determined that the target data content does not satisfy the filtering tag condition, the above step of receiving the target data content that needs to be subjected to data filtering analysis is performed again.

[0110] Further optionally, judging whether the target data content satisfies a preset filtering tag condition based on the target data tag and the determined current filtering mode may include:

[0111] Determine, based on the determined current filtering mode, an additional attention data label corresponding to the current filtering mode;

[0112] Determine whether the additional attention data label includes the target data label;

[0113] When the judgment result is yes, it is determined that the target data content meets the preset filtering label conditions;

[0114] When the judgment result is no, it is determined that the target data content does not meet the preset filtering label condition.

[0115] 104. When it is determined that the target data content meets the abnormal data filtering condition, a corresponding data filtering operation is performed on the target data content according to the abnormal content analysis result.

[0116] Further optionally, the above-mentioned corresponding data filtering operation performed on the target data content may be filtering and deleting the complete target data content, or filtering and deleting part of the target data content, which is not limited in the embodiment of the present invention.

[0117] Further optionally, after performing the corresponding data filtering operation on the target data content, a data filtering result corresponding to the target data content is obtained; further, the data filtering result can be used to represent the target data content after data filtering, that is, the target data content does not include abnormal data, that is, the abnormal data is deleted, and can also represent the data filtering status of the target data content, which is not limited in the embodiments of the present invention.

[0118] It can be seen that the data filtering method based on the LLM security protection system described in the embodiment of the present invention can perform corresponding step-by-step data analysis operations on the target data content to obtain abnormal content analysis results, and further perform corresponding data filtering operations on the target data content based on the abnormal content analysis results, which is conducive to improving the comprehensiveness and integrity of the data filtering method based on the LLM security protection system, and is conducive to improving the rationality and comprehensiveness of the data anomaly analysis method, and further is conducive to improving the accuracy and reliability of the determined abnormal content analysis results, thereby helping to improve the accuracy and reliability of anomaly detection of target data content, and is conducive to improving the efficiency and convenience of anomaly detection of target data content, and further is conducive to improving the data filtering accuracy and data filtering efficiency of target data content, and is conducive to achieving high accuracy and low false alarm rate of data content anomaly detection and filtering, improving the response speed of the security protection system, and improving the security and appropriateness of the final output / processed filtered data content.

[0119] In an optional embodiment, performing corresponding data filtering operations on target data content based on abnormal content analysis results may include:

[0120] Determine the target abnormal object corresponding to the target data content based on the abnormal content analysis results, where the target abnormal object includes the entire content or part of the target data content;

[0121] Determine the application importance and filtering impact of the target data content based on the associated data information corresponding to the target data content, and determine the filtering consideration requirement of the target data content based on the application importance and filtering impact;

[0122] Determine the target filtering method for the target data content based on the target abnormal object and the filtering requirements;

[0123] When the target filtering mode is used to represent the overall filtering mode, the corresponding overall data filtering operation is performed on the target data content;

[0124] When the target filtering mode is used to represent a partial filtering mode, a corresponding partial data filtering operation is performed on the target data content according to the target exception object.

[0125] Optionally, the target abnormal object corresponding to the target data content can be understood as: specific abnormal data content in the target data content, or specific data content in the target data content that causes data abnormality, which is not limited in the embodiment of the present invention.

[0126] Optionally, the associated data information corresponding to the target data content can be, for example, other data information bundled with the target data content, data information that has some connection with the target data content, or other information that can reflect the actual application of the target data content, which is not limited in the embodiments of the present invention.

[0127] Optionally, the application importance of the target data content can be understood as: the importance of the target data content in practical applications; further, for example: for example, if the target data content is text data, the application importance of the target data content can be determined by the role played by the target data content in the entire article, the role and significance of the target data content in the coherence and meaning understanding of the article, etc., which is not limited in the embodiments of the present invention.

[0128] Optionally, the filtering influence of the target data content can be understood as: the influence of the data filtering result obtained after filtering the target data content on the actual application; further, for example: for example, if the target data content is text data, after filtering the target data content, the meaning of the entire article is opposite to the original meaning, then it can be determined that the filtering influence of the target data content is greater, and other situations are similar, and the embodiments of the present invention are not limited.

[0129] Optionally, the filtering consideration requirement of the target data content can be understood as: the need to consider the need to perform filtering operations on the target data content; further, for example: when the filtering consideration requirement is higher, it is necessary to streamline the filtering part of the target data content as much as possible, and try not to filter all of it as much as possible. The same applies to other situations, and the embodiments of the present invention do not limit this.

[0130] Further optionally, the above-mentioned requirement for filtering the target data content is determined based on the application importance and the filtering influence. For example: when the application importance is used to indicate that the target data content is more important to the application, and / or the filtering influence is used to indicate that the filtering operation of the target data content has a greater impact on the actual situation, then it can be determined that the requirement for filtering the target data content is higher. The same applies to other situations, and the embodiments of the present invention do not limit this.

[0131] Further optionally, the above-mentioned target filtering method of the target data content is determined based on the target abnormal object and the filtering consideration requirement. For example: when the target abnormal object is used to represent the entire target data content, the target filtering method of the target data is determined to be the overall filtering method; when the target abnormal object is used to represent part of the target data content and the filtering consideration requirement is high, the target filtering method of the target data is determined to be the partial filtering method; when the target abnormal object is used to represent part of the target data content and the filtering consideration requirement is low, the target filtering method of the target data can be determined to be the partial filtering method or the overall filtering method. Other situations are similar and are not limited in the embodiments of the present invention.

[0132] Further optionally, for example, when the target abnormal object is part of the target data content and deleting the target abnormal object will not affect the meaning of the target data content, a partial filtering method can be used; for example, when the target abnormal object is part of the target data content and the target data content is very important and cannot be filtered as a whole sentence, a partial filtering method can be used. The same applies to other situations, and the embodiments of the present invention are not limited thereto.

[0133] Further optionally, the above-mentioned performing of a corresponding overall data filtering operation on the target data content may be understood as filtering the entire target data content, which is not limited in the embodiment of the present invention.

[0134] Further optionally, performing a corresponding partial data filtering operation on the target data content according to the target abnormal object may include:

[0135] According to the target abnormal object, determine the targeted data that needs to be filtered in the target data content;

[0136] Filter targeted data in target data content.

[0137] It can be seen that this optional embodiment can determine the target filtering method based on the target abnormal object and filtering consideration requirement of the determined target data content, and further perform the corresponding data filtering operation according to the target filtering method. The target filtering method includes an overall filtering method or a partial filtering method, which is conducive to improving the comprehensiveness and rationality of the target filtering method determination method of the target data content, and thus is conducive to improving the diversity, flexibility and pertinence of the target filtering method, thereby helping to improve the execution accuracy and execution reliability of the data filtering operation, and further helping to improve the data filtering accuracy and reliability of the target data content.

[0138] In another optional embodiment, the above-mentioned determination of whether the target data content satisfies a preset abnormal data filtering condition based on the abnormal content analysis result may include:

[0139] Based on the abnormal content analysis results, determine whether the target data content meets the preset abnormal data existence conditions;

[0140] When it is determined that the target data content does not satisfy the abnormal data existence condition, determining that the target data content does not satisfy the preset abnormal data filtering condition;

[0141] When it is determined that the target data content meets the abnormal data existence conditions, the specific abnormal content corresponding to the target data content is determined based on the abnormal content analysis results, and the abnormal prevalence and severity of the abnormality corresponding to the target data content are determined based on the specific abnormal content;

[0142] Based on the prevalence and severity of the anomaly, determine whether the target data content meets the preset data filtering emergency conditions;

[0143] When it is determined that the target data content meets the data filtering emergency condition, determining that the target data content meets the preset abnormal data filtering condition;

[0144] When it is determined that the target data content does not satisfy the data filtering emergency condition, it is determined that the target data content does not satisfy the preset abnormal data filtering condition.

[0145] Further optionally, judging whether the target data content satisfies a preset abnormal data existence condition based on the abnormal content analysis result may include:

[0146] According to the abnormal content analysis results, determine whether there is abnormal data in the target data content;

[0147] When the judgment result is yes, it is determined that the target data content meets the preset abnormal data existence condition;

[0148] When the judgment result is no, it is determined that the target data content does not meet the preset abnormal data existence condition.

[0149] Optionally, the universality of the abnormality corresponding to the target data content can be understood as: the universality of the specific abnormal content in the field or level of the target data content, which is not limited in the embodiment of the present invention.

[0150] Optionally, the severity of the abnormality corresponding to the target data content may be reflected by the abnormality degree, impact degree, damage degree caused by the specific abnormal content, etc., which is not limited in the embodiment of the present invention.

[0151] Further optionally, judging whether the target data content meets the preset data filtering emergency conditions based on the anomaly prevalence and severity may include:

[0152] Determining whether the prevalence of the anomaly is greater than or equal to a preset prevalence threshold of the anomaly, and determining whether the severity of the anomaly is greater than or equal to a preset severity threshold of the anomaly;

[0153] When it is determined that the abnormality prevalence is less than the abnormality prevalence threshold and / or the abnormality severity is greater than or equal to the abnormality severity threshold, it is determined that the target data content meets the preset data filtering emergency condition;

[0154] When it is determined that the abnormality prevalence is greater than or equal to the abnormality prevalence threshold and the abnormality severity is determined to be less than the abnormality severity threshold, it is determined that the target data content does not meet the preset data filtering emergency condition.

[0155] It can be seen that this optional embodiment can determine the results of abnormal data filtering conditions being met from two levels: abnormal data existence conditions and data filtering emergency conditions. This is conducive to improving the comprehensiveness, integrity, rationality and progressiveness of the method for determining the results of abnormal data filtering conditions being met, and thus is conducive to improving the accuracy and reliability of the determined results of abnormal data filtering conditions being met, thereby helping to improve the timeliness, accuracy, reliability and efficiency of subsequent data filtering operations based on the results of abnormal data filtering conditions being met.

[0156] Example 2

[0157] See also Figure 2 , Figure 2 This is a flow chart of another data filtering method based on the LLM security protection system disclosed in an embodiment of the present invention. Figure 2 The described method can be applied to a data filtering system based on an LLM security protection system, wherein the system may include a server, wherein the server includes a local server or a cloud server, which is not limited in the embodiment of the present invention. Figure 2 As shown, the data filtering method based on the LLM security protection system includes the following operations:

[0158] 201. Receive target data content that requires data filtering and analysis.

[0159] 202. Perform a corresponding keyword analysis operation on the target data content to obtain a first abnormal result.

[0160] Optionally, the above-mentioned keyword analysis operation can be understood as quickly screening the target data content for the presence or potential harmful content through keyword matching technology, which is not limited in the embodiment of the present invention.

[0161] 203. Perform corresponding semantic analysis operations on the target data content to obtain a second abnormal result.

[0162] Optionally, the above-mentioned semantic analysis operation can be understood as deeply understanding the textual meaning of the target data content through semantic analysis technology and then determining whether the target data content is abnormal and harmful content, which is not limited in the embodiment of the present invention.

[0163] 204. Perform a corresponding sentiment analysis operation on the target data content to obtain a third abnormal result.

[0164] Optionally, the above sentiment analysis operation can be understood as combining sentiment classification technology to judge the text sentiment of the target data content to determine whether the target data content reflects abnormal and harmful content, which is not limited in the embodiment of the present invention.

[0165] 205. Perform corresponding comprehensive abnormality analysis operations on the target data content according to the first abnormality result, the second abnormality result, and the third abnormality result to obtain abnormal content analysis results corresponding to the target data content.

[0166] Further optionally, performing corresponding comprehensive abnormality analysis operations on the target data content based on the first abnormality result, the second abnormality result, and the third abnormality result to obtain abnormal content analysis results corresponding to the target data content may include:

[0167] Determine whether there is an abnormal filtering conflict among the first abnormal result, the second abnormal result, and the third abnormal result;

[0168] When the judgment result is no, the first abnormal result, the second abnormal result, and the third abnormal result are determined as abnormal content analysis results corresponding to the target data content;

[0169] When the judgment result is yes, determine the abnormal weight scheme corresponding to the target data content for the keyword analysis level, semantic analysis level and sentiment analysis level; determine the abnormal content analysis result corresponding to the target data content based on the abnormal weight scheme, the first abnormal result, the second abnormal result and the third abnormal result.

[0170] 206. Based on the abnormal content analysis result, determine whether the target data content meets the preset abnormal data filtering conditions.

[0171] 207. When it is determined that the target data content meets the abnormal data filtering condition, a corresponding data filtering operation is performed on the target data content according to the abnormal content analysis result.

[0172] In the embodiment of the present invention, for other descriptions of steps 201 to 207, please refer to the other detailed descriptions of steps 101 to 104 in the first embodiment, which will not be repeated in the embodiment of the present invention.

[0173] It can be seen that the embodiment of the present invention can perform corresponding step-by-step data analysis operations on the target data content to obtain abnormal content analysis results, and further perform corresponding data filtering operations on the target data content according to the abnormal content analysis results, which is conducive to improving the comprehensiveness and integrity of the data filtering method based on the LLM security protection system, and is conducive to improving the rationality and comprehensiveness of the data abnormality analysis method, and further is conducive to improving the accuracy and reliability of the determined abnormal content analysis results, thereby helping to improve the accuracy and reliability of abnormality detection of target data content, and is conducive to improving the efficiency and convenience of abnormality detection of target data content, and further is conducive to improving the data filtering accuracy and data filtering efficiency of target data content. It is conducive to achieving high accuracy and low false alarm rate in data content anomaly detection and filtering, improving the response speed of the security protection system, and improving the security and appropriateness of the final output / processed filtered data content; and it can also determine the abnormal content analysis results of the target data content from three levels: keyword analysis, semantic analysis, and sentiment analysis, which is conducive to improving the comprehensiveness and integrity of the method for determining the abnormal content analysis results of the target data content, and is conducive to improving the diversity, flexibility and comprehensiveness of the consideration levels used to determine the abnormal content analysis results, and thus is conducive to improving the accuracy and reliability of the determined abnormal content analysis results, thereby helping to improve the timeliness and reliability of subsequent data filtering based on the abnormal content analysis results.

[0174] In an optional embodiment, performing the corresponding keyword analysis operation on the target data content to obtain the first abnormal result may include:

[0175] According to the preset conventional character collocation rules, the corresponding character segmentation operation is performed on the target data content to obtain the character segmentation result;

[0176] Based on the character segmentation results and the preset abnormal keyword set, determine whether the target data content meets the preset keyword abnormality judgment conditions;

[0177] When it is determined that the target data content meets the keyword anomaly judgment condition, one or more target abnormal characters are determined from the target data content according to the abnormal keyword set and the character segmentation result; and a first abnormal result is determined based on all the target abnormal characters.

[0178] Optionally, the above-mentioned corresponding character segmentation operation is performed on the target data content. For example: the target data content is segmented into characters according to conventional words, phrases, sentences, expressions, etc., that is, the target data content is analyzed in the form of characters. For example: the target data content is "I love painting", then the character segmentation result can be "I / love / painting", which is not limited in the embodiment of the present invention.

[0179] Further optionally, judging whether the target data content meets a preset keyword abnormality judgment condition based on the character segmentation result and the preset abnormal keyword set may include:

[0180] Determine one or more character combinations based on the character segmentation result, where the character combination includes one or more characters;

[0181] Determine whether there is at least one character combination among all character combinations that matches an abnormal keyword in the abnormal keyword set;

[0182] If the result of the judgment is yes, it is determined that the target data content meets the preset keyword abnormality judgment condition;

[0183] When the judgment result is no, it is determined that the target data content does not meet the preset keyword abnormality judgment condition.

[0184] Optionally, the target abnormal character may be understood as a character in the target data content that matches one or more abnormal keywords in the abnormal keyword set, which is not limited in the embodiment of the present invention.

[0185] Optionally, the first abnormal result can be used to indicate that there is an abnormality in the target data content at the keyword analysis level and / or to indicate specific abnormal content, where the specific abnormal content is also the target abnormal character, which is not limited in the embodiment of the present invention.

[0186] It can be seen that this optional embodiment can provide a method for determining the first abnormal result at the keyword analysis level. According to the abnormal keyword set and the character division result, the target abnormal character is determined from the target data content and then the first abnormal result at the keyword analysis level is determined. This is conducive to improving the pertinence and rationality of the method for determining the first abnormal result, and thus is conducive to improving the accuracy and reliability of the determined first abnormal result, thereby helping to improve the accuracy and reliability of the subsequent abnormal content analysis results determined based on the first abnormal result.

[0187] In another optional embodiment, performing the corresponding semantic analysis operation on the target data content to obtain the second abnormal result may include:

[0188] Perform corresponding semantic analysis operations on the target data content to obtain the text meaning results corresponding to the target data content;

[0189] Determine the semantic anomaly level corresponding to the target data content based on the determined application scenario information and text meaning results of the target data content;

[0190] Based on the application scenario information and semantic anomaly level, determine whether the target data content meets the preset semantic anomaly lower limit conditions;

[0191] When it is determined that the target data content meets the semantic anomaly lower limit condition, the scene semantic anomaly lower limit scheme is determined based on the application scenario information; based on the scene semantic anomaly lower limit scheme and the text meaning result, the abnormal semantic data object in the target data content is determined; based on the abnormal semantic data object, the second abnormal result is determined.

[0192] Optionally, for application scenario information and semantic anomaly lower limit conditions, examples are given: the upper and lower limits of semantic anomalies are different for different application scenarios. Furthermore, for example, the expression anomaly evaluation requirements corresponding to the application scenario of a game battle scenario and the application scenario of a school scenario are different. The same applies to other situations, and the embodiments of the present invention do not limit this.

[0193] Further optionally, judging whether the target data content meets a preset semantic anomaly lower limit condition based on the application scenario information and the semantic anomaly level may include:

[0194] Determine the semantic anomaly level corresponding to the target data content based on the semantic anomaly level, and determine the conventional semantic anomaly level threshold corresponding to the application scenario based on the application scenario information;

[0195] Determining whether the degree of semantic abnormality is greater than or equal to a preset conventional semantic abnormality threshold;

[0196] When the judgment result is yes, it is determined that the target data content meets the preset semantic anomaly lower limit condition;

[0197] When the judgment result is no, it is determined that the target data content does not meet the preset semantic anomaly lower limit condition.

[0198] Further optionally, the method may further include the following operations:

[0199] When it is determined that the target data content does not meet the semantic anomaly lower limit condition, a second anomaly result is determined, and the second anomaly result is used to indicate that there is no data anomaly in the target data content at the semantic analysis level.

[0200] Optionally, the scenario semantic anomaly lower limit solution can be understood as: a semantic situation that can be determined as abnormal in the application scenario, which is not limited in the embodiment of the present invention.

[0201] Optionally, the abnormal semantic data object in the target data content can be understood as: data in the target data content that causes the target data content to be identified as semantically abnormal, that is, data that directly causes semantic abnormality in the target data content, which is not limited in the embodiment of the present invention.

[0202] Further optionally, the above-mentioned second abnormal result is determined based on the abnormal semantic data object. For example, the second abnormal result includes the abnormal semantic data object and / or the second abnormal result is used to indicate that there is a data anomaly in the target data content at the semantic analysis level, which is not limited in the embodiment of the present invention.

[0203] It can be seen that this optional embodiment can provide a method for determining the second abnormal result at the semantic analysis level, and determine the abnormal semantic data object and then determine the second abnormal result at the semantic analysis level by combining the application scenario information of the target data content, the scenario semantic abnormality lower limit scheme and the text meaning result, which is conducive to improving the pertinence and rationality of the method for determining the second abnormal result, and thus is conducive to improving the accuracy and reliability of the determined second abnormal result, thereby helping to improve the accuracy and reliability of the subsequent abnormal content analysis results determined based on the second abnormal result.

[0204] In yet another optional embodiment, performing the corresponding sentiment analysis operation on the target data content to obtain the third abnormal result may include:

[0205] Determine, based on the target data content, the emotional expression properties corresponding to the target data content, where the emotional expression properties include positive emotional expression properties or non-positive emotional expression properties;

[0206] When the emotional expression property includes a non-positive emotional expression property, determining context data content corresponding to the target data content according to the target data content;

[0207] Determine the induced application properties corresponding to the target data content according to the context data content, where the induced application properties include subjective thought application properties or objective logic application properties;

[0208] The third abnormal result is determined based on the target data content and the nature of the derived application.

[0209] Optionally, positive emotion expression properties include, for example, positive emotions, optimistic emotions, happy emotions, etc.; non-positive emotion expression properties include, for example, angry emotions, negative emotions, etc., which are not limited in the embodiment of the present invention.

[0210] Optionally, the above-mentioned determination of the induced application properties corresponding to the target data content is based on the context data content. For example: through the context data content, it can be known that, for example, the target data content is just a sentence cited as an example in the entire article, and the target data content does not have any emotional abnormalities (for example, the entire article is used to discuss the phenomenon of anger, then the target data content is a related example of anger expression, and it does not need to be filtered), then it can be determined that the induced application properties are objective logical application properties; for example, the full text emotion of the entire article and the target data content are consistent, and are used to carry over the context, and the target data content has emotional abnormalities (for example, the entire text is abusive, then it needs to be filtered), then it can be determined that the induced application properties are subjective thought application properties, and other situations can be obtained similarly, and the embodiments of the present invention are not limited thereto.

[0211] Further optionally, the method may further include the following operations:

[0212] When the emotional expression property includes a positive emotional expression property, determining the third abnormal result is used to indicate that there is no data abnormality in the target data content at the emotional analysis level.

[0213] Optionally, the above-mentioned determination of the third abnormal result based on the target data content and the nature of the induced application may include:

[0214] When the elicited application property includes a subjective thought application property, determining, based on the target data content, that the third abnormal result includes the target data content and / or that the third abnormal result is used to indicate that the target data content has a data abnormality at a sentiment analysis level;

[0215] When the derived application properties include objective logical application properties, determining the third abnormal result is used to indicate that there is no data abnormality in the target data content at the sentiment analysis level.

[0216] It can be seen that this optional embodiment can provide a method for determining the third abnormal result at the sentiment analysis level, and further determine the third abnormal result at the sentiment analysis level based on the determined emotional expression properties of the target data content and the corresponding induced application properties of the context data content, which is conducive to improving the pertinence and rationality of the method for determining the third abnormal result, and thus is conducive to improving the accuracy and reliability of the determined third abnormal result, thereby helping to improve the accuracy and reliability of the subsequent abnormal content analysis results determined based on the third abnormal result.

[0217] Example 3

[0218] See also Figure 3 , Figure 3 This is a schematic diagram of the structure of a data filtering system based on the LLM security protection system disclosed in an embodiment of the present invention. Figure 3The described system may include a server, wherein the server includes a local server or a cloud server, which is not limited in the embodiment of the present invention. Figure 3 As shown, the data filtering system based on the LLM security protection system may include:

[0219] The data receiving module 301 is used to receive target data content that needs to be subjected to data filtering analysis.

[0220] The abnormal data analysis module 302 is used to perform corresponding step-by-step data analysis operations on the target data content to obtain abnormal content analysis results corresponding to the target data content.

[0221] The judgment module 303 is used to judge whether the target data content meets the preset abnormal data filtering conditions according to the abnormal content analysis result.

[0222] The data filtering module 304 is configured to perform corresponding data filtering operations on the target data content according to the abnormal content analysis result when the judgment module determines that the target data content meets the abnormal data filtering condition.

[0223] It can be seen that implementation Figure 3 The described data filtering system based on the LLM security protection system can perform corresponding step-by-step data analysis operations on the target data content to obtain abnormal content analysis results, and further perform corresponding data filtering operations on the target data content based on the abnormal content analysis results, which is conducive to improving the comprehensiveness and integrity of the data filtering method based on the LLM security protection system, and is conducive to improving the rationality and comprehensiveness of the data anomaly analysis method, and thus is conducive to improving the accuracy and reliability of the determined abnormal content analysis results, thereby helping to improve the accuracy and reliability of anomaly detection of target data content, and is conducive to improving the efficiency and convenience of anomaly detection of target data content, and further helping to improve the data filtering accuracy and data filtering efficiency of target data content, and is conducive to achieving high accuracy and low false alarm rate of data content anomaly detection and filtering, improving the response speed of the security protection system, and improving the security and appropriateness of the final output / processed filtered data content.

[0224] In an optional embodiment, the abnormal data analysis module 302 performs corresponding step-by-step data analysis operations on the target data content to obtain abnormal content analysis results corresponding to the target data content, specifically including:

[0225] Performing a corresponding keyword analysis operation on the target data content to obtain a first abnormal result;

[0226] Performing a corresponding semantic analysis operation on the target data content to obtain a second abnormal result;

[0227] Perform corresponding sentiment analysis operations on the target data content to obtain a third abnormal result;

[0228] According to the first abnormal result, the second abnormal result and the third abnormal result, a corresponding comprehensive abnormal analysis operation is performed on the target data content to obtain an abnormal content analysis result corresponding to the target data content.

[0229] It can be seen that implementation Figure 3 The described system can also determine the abnormal content analysis results of the target data content from three levels: keyword analysis, semantic analysis, and sentiment analysis, which is conducive to improving the comprehensiveness and integrity of the method for determining the abnormal content analysis results of the target data content, and is conducive to improving the diversity, flexibility and comprehensiveness of the consideration levels used to determine the abnormal content analysis results, and thus is conducive to improving the accuracy and reliability of the determined abnormal content analysis results, thereby helping to improve the timeliness and reliability of subsequent data filtering based on the abnormal content analysis results.

[0230] In another optional embodiment, the abnormal data analysis module 302 performs a corresponding keyword analysis operation on the target data content, and obtains the first abnormal result in the following manner:

[0231] According to the preset conventional character collocation rules, the corresponding character segmentation operation is performed on the target data content to obtain the character segmentation result;

[0232] Based on the character segmentation results and the preset abnormal keyword set, determine whether the target data content meets the preset keyword abnormality judgment conditions;

[0233] When it is determined that the target data content meets the keyword anomaly judgment condition, one or more target abnormal characters are determined from the target data content according to the abnormal keyword set and the character segmentation result; and a first abnormal result is determined based on all the target abnormal characters.

[0234] It can be seen that implementation Figure 3 The described system can also provide a method for determining the first abnormal result at the keyword analysis level. Based on the abnormal keyword set and character segmentation results, the target abnormal characters are determined from the target data content and then the first abnormal result at the keyword analysis level is determined. This is conducive to improving the pertinence and rationality of the method for determining the first abnormal result, and thus is conducive to improving the accuracy and reliability of the determined first abnormal result, thereby helping to improve the accuracy and reliability of subsequent abnormal content analysis results determined based on the first abnormal result.

[0235] In another optional embodiment, the abnormal data analysis module 302 performs corresponding semantic analysis operations on the target data content to obtain the second abnormal result in the following manner:

[0236] Perform corresponding semantic analysis operations on the target data content to obtain the text meaning results corresponding to the target data content;

[0237] Determine the semantic anomaly level corresponding to the target data content based on the determined application scenario information and text meaning results of the target data content;

[0238] Based on the application scenario information and semantic anomaly level, determine whether the target data content meets the preset semantic anomaly lower limit conditions;

[0239] When it is determined that the target data content meets the semantic anomaly lower limit condition, the scene semantic anomaly lower limit scheme is determined based on the application scenario information; based on the scene semantic anomaly lower limit scheme and the text meaning result, the abnormal semantic data object in the target data content is determined; based on the abnormal semantic data object, the second abnormal result is determined.

[0240] It can be seen that implementation Figure 3 The described system can also provide a method for determining a second abnormal result at the semantic analysis level, which combines the application scenario information of the target data content, the scenario semantic abnormality lower limit scheme and the text meaning result to determine the abnormal semantic data object and then determine the second abnormal result at the semantic analysis level, which is conducive to improving the pertinence and rationality of the method for determining the second abnormal result, and thus is conducive to improving the accuracy and reliability of the determined second abnormal result, thereby helping to improve the accuracy and reliability of the subsequent abnormal content analysis results determined based on the second abnormal result.

[0241] In another optional embodiment, the abnormal data analysis module 302 performs a corresponding sentiment analysis operation on the target data content, and the manner in which the third abnormal result is obtained specifically includes:

[0242] Determine, based on the target data content, the emotional expression properties corresponding to the target data content, where the emotional expression properties include positive emotional expression properties or non-positive emotional expression properties;

[0243] When the emotional expression property includes a non-positive emotional expression property, determining context data content corresponding to the target data content according to the target data content;

[0244] Determine the induced application properties corresponding to the target data content according to the context data content, where the induced application properties include subjective thought application properties or objective logic application properties;

[0245] The third abnormal result is determined based on the target data content and the nature of the derived application.

[0246] It can be seen that implementation Figure 3The described system can also provide a method for determining the third abnormal result at the sentiment analysis level, and further determine the third abnormal result at the sentiment analysis level based on the determined emotional expression properties of the target data content and the corresponding induced application properties of the context data content. This is conducive to improving the pertinence and rationality of the method for determining the third abnormal result, and thus is conducive to improving the accuracy and reliability of the determined third abnormal result, thereby helping to improve the accuracy and reliability of the subsequent abnormal content analysis results determined based on the third abnormal result.

[0247] In another optional embodiment, the data filtering module 304 performs corresponding data filtering operations on the target data content according to the abnormal content analysis result, specifically including:

[0248] Determine the target abnormal object corresponding to the target data content based on the abnormal content analysis results, where the target abnormal object includes the entire content or part of the target data content;

[0249] Determine the application importance and filtering impact of the target data content based on the associated data information corresponding to the target data content, and determine the filtering consideration requirement of the target data content based on the application importance and filtering impact;

[0250] Determine the target filtering method for the target data content based on the target abnormal object and the filtering requirements;

[0251] When the target filtering mode is used to represent the overall filtering mode, the corresponding overall data filtering operation is performed on the target data content;

[0252] When the target filtering mode is used to represent a partial filtering mode, a corresponding partial data filtering operation is performed on the target data content according to the target exception object.

[0253] It can be seen that implementation Figure 3 The described system can also determine the target filtering method based on the target abnormal objects and filtering consideration requirements of the determined target data content, and further perform corresponding data filtering operations based on the target filtering method. The target filtering method includes an overall filtering method or a partial filtering method, which is conducive to improving the comprehensiveness and rationality of the target filtering method determination method of the target data content, and thus is conducive to improving the diversity, flexibility and pertinence of the target filtering method, thereby helping to improve the execution accuracy and execution reliability of the data filtering operation, and further helping to improve the data filtering accuracy and reliability of the target data content.

[0254] In another optional embodiment, the judgment module 303 judges whether the target data content meets the preset abnormal data filtering condition according to the abnormal content analysis result, specifically including:

[0255] Based on the abnormal content analysis results, determine whether the target data content meets the preset abnormal data existence conditions;

[0256] When it is determined that the target data content does not satisfy the abnormal data existence condition, determining that the target data content does not satisfy the preset abnormal data filtering condition;

[0257] When it is determined that the target data content meets the abnormal data existence conditions, the specific abnormal content corresponding to the target data content is determined based on the abnormal content analysis results, and the abnormal prevalence and severity of the abnormality corresponding to the target data content are determined based on the specific abnormal content;

[0258] Based on the prevalence and severity of the anomaly, determine whether the target data content meets the preset data filtering emergency conditions;

[0259] When it is determined that the target data content meets the data filtering emergency condition, determining that the target data content meets the preset abnormal data filtering condition;

[0260] When it is determined that the target data content does not satisfy the data filtering emergency condition, it is determined that the target data content does not satisfy the preset abnormal data filtering condition.

[0261] It can be seen that implementation Figure 3 The described system can also determine the results of abnormal data filtering condition satisfaction from two levels: abnormal data existence conditions and data filtering emergency conditions, which is conducive to improving the comprehensiveness, integrity, rationality and progressiveness of the method for determining the results of abnormal data filtering condition satisfaction, and thus is conducive to improving the accuracy and reliability of the determined abnormal data filtering condition satisfaction results, thereby helping to improve the timeliness, accuracy, reliability and efficiency of subsequent data filtering operations based on the abnormal data filtering condition satisfaction results.

[0262] Example 4

[0263] See also Figure 4 , Figure 4 This is a structural diagram of another data filtering system based on the LLM security protection system disclosed in an embodiment of the present invention. Figure 4 The described device may include a server, wherein the server includes a local server or a cloud server, which is not limited in the embodiment of the present invention. Figure 4 As shown, the device may include:

[0264] A memory 401 storing executable program code;

[0265] a processor 402 coupled to the memory 401;

[0266] Furthermore, it may also include an input interface 403 and an output interface 404 coupled to the processor 402;

[0267] The processor 402 calls the executable program code stored in the memory 401 to execute the steps of the data filtering method based on the LLM security protection system described in the first or second embodiment.

[0268] Example 5

[0269] An embodiment of the present invention discloses a computer storage medium storing a computer program for electronic data exchange, wherein the computer program enables a computer to execute the steps of the data filtering method based on the LLM security protection system described in the first or second embodiment.

[0270] Example 6

[0271] An embodiment of the present invention discloses a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to enable a computer to execute the steps of the data filtering method based on the LLM security protection system described in Example 1 or Example 2.

[0272] The device embodiments described above are merely illustrative, wherein the modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules, i.e., they may be located in one place or distributed across multiple network modules. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Those skilled in the art can understand and implement the present invention without inventive effort.

[0273] Through the detailed description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus the necessary general hardware platform, or of course, by means of hardware. Based on this understanding, the above technical solution, in essence, or the portion that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, including a read-only memory (ROM), a random access memory (RAM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), a one-time programmable read-only memory (OTPROM), an electronically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, magnetic disk storage, magnetic tape storage, or any other computer-readable medium capable of carrying or storing data.

[0274] Finally, it should be noted that the data filtering method and system based on the LLM security protection system disclosed in the embodiment of the present invention are only preferred embodiments of the present invention, which are only used to illustrate the technical solution of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, ordinary technicians in this field should understand that it is still possible to modify the technical solutions recorded in the aforementioned embodiments, or to make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A data filtering method based on LLM security protection system, characterized in that: The method comprises: Receive target data content that requires data filtering and analysis; Performing a corresponding keyword analysis operation on the target data content to obtain a first abnormal result; Performing a corresponding semantic analysis operation on the target data content to obtain a second abnormal result; Performing a corresponding sentiment analysis operation on the target data content to obtain a third abnormal result; performing corresponding comprehensive abnormality analysis operations on the target data content according to the first abnormality result, the second abnormality result, and the third abnormality result to obtain abnormal content analysis results corresponding to the target data content; According to the abnormal content analysis result, determining whether the target data content meets the preset abnormal data filtering conditions; When it is determined that the target data content meets the abnormal data filtering condition, the target abnormal object corresponding to the target data content is determined according to the abnormal content analysis result, and the target abnormal object includes the entire content or partial content of the target data content; according to the associated data information corresponding to the target data content, the application importance and filtering influence of the target data content are determined, and according to the application importance and the filtering influence, the filtering consideration requirement of the target data content is determined; according to the target abnormal object and the filtering consideration requirement, the target filtering mode of the target data content is determined; when the target filtering mode is used to represent the overall filtering mode, the corresponding overall data filtering operation is performed on the target data content; when the target filtering mode is used to represent the partial filtering mode, the corresponding partial data filtering operation is performed on the target data content according to the target abnormal object.

2. The data filtering method based on the LLM security protection system according to claim 1 is characterized in that: The performing of a corresponding keyword analysis operation on the target data content to obtain a first abnormal result includes: According to the preset conventional character collocation rules, a corresponding character segmentation operation is performed on the target data content to obtain a character segmentation result; According to the character segmentation result and the preset abnormal keyword set, determining whether the target data content meets the preset keyword abnormality judgment condition; When it is determined that the target data content meets the keyword abnormality judgment condition, one or more target abnormal characters are determined from the target data content according to the abnormal keyword set and the character segmentation result; and a first abnormal result is determined based on all the target abnormal characters.

3. The data filtering method based on the LLM security protection system according to claim 1 is characterized in that: The performing a corresponding semantic analysis operation on the target data content to obtain a second abnormal result includes: Performing corresponding semantic analysis operations on the target data content to obtain a text meaning result corresponding to the target data content; Determining a semantic anomaly level corresponding to the target data content based on the determined application scenario information of the target data content and the text meaning result; According to the application scenario information and the semantic anomaly level, determining whether the target data content meets a preset semantic anomaly lower limit condition; When it is determined that the target data content meets the semantic anomaly lower limit condition, the scene semantic anomaly lower limit scheme is determined according to the application scenario information; the abnormal semantic data object in the target data content is determined according to the scene semantic anomaly lower limit scheme and the text meaning result; and the second abnormal result is determined according to the abnormal semantic data object.

4. The data filtering method based on the LLM security protection system according to claim 1 is characterized in that: The performing a corresponding sentiment analysis operation on the target data content to obtain a third abnormal result includes: Determining, based on the target data content, an emotional expression property corresponding to the target data content, the emotional expression property including a positive emotional expression property or a non-positive emotional expression property; When the emotional expression property includes the non-positive emotional expression property, determining context data content corresponding to the target data content according to the target data content; Determining, based on the context data content, an induced application property corresponding to the target data content, the induced application property including a subjective thought application property or an objective logic application property; The third abnormal result is determined according to the target data content and the derived application property.

5. The data filtering method based on the LLM security protection system according to any one of claims 1 to 4, characterized in that: The step of determining whether the target data content satisfies a preset abnormal data filtering condition based on the abnormal content analysis result includes: According to the abnormal content analysis result, determining whether the target data content meets the preset abnormal data existence condition; When it is determined that the target data content does not satisfy the abnormal data existence condition, determining that the target data content does not satisfy a preset abnormal data filtering condition; When it is determined that the target data content meets the abnormal data existence condition, determining the specific abnormal content corresponding to the target data content according to the abnormal content analysis result, and determining the abnormal prevalence and abnormal severity corresponding to the target data content according to the specific abnormal content; Determining whether the target data content meets a preset data filtering emergency condition based on the anomaly prevalence and the anomaly severity; When it is determined that the target data content meets the data filtering emergency condition, determining that the target data content meets the preset abnormal data filtering condition; When it is determined that the target data content does not satisfy the data filtering emergency condition, it is determined that the target data content does not satisfy a preset abnormal data filtering condition.

6. A data filtering system based on the LLM security protection system, characterized in that: The data filtering system is used to execute the data filtering method based on the LLM security protection system according to any one of claims 1 to 5, and the data filtering system includes: A data receiving module is used to receive target data content that needs to be filtered and analyzed; An abnormal data analysis module is used to perform a corresponding step-by-step data analysis operation on the target data content to obtain an abnormal content analysis result corresponding to the target data content; A judgment module, configured to judge whether the target data content satisfies a preset abnormal data filtering condition based on the abnormal content analysis result; The data filtering module is configured to perform corresponding data filtering operations on the target data content according to the abnormal content analysis result when the judgment module determines that the target data content meets the abnormal data filtering condition.

7. A data filtering system based on the LLM security protection system, characterized in that: The data filtering system includes: a memory storing executable program code; a processor coupled to the memory; The processor calls the executable program code stored in the memory to execute the data filtering method based on the LLM security protection system as described in any one of claims 1 to 5.

8. A computer storage medium, characterized in that The computer storage medium stores computer instructions, and when the computer instructions are called, they are used to execute the data filtering method based on the LLM security protection system according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Data filtering and mining method

    CN109783619A

  • LLM-driven industrial network intrusion detection method and response system

    CN118381627A