Large model training environment vulnerability management method and device

Through abstract syntax tree analysis and vulnerability reproduction and repair of the large model training environment, the problem of inefficient vulnerability management in the existing technology is solved, and more efficient and accurate vulnerability management is achieved, ensuring the security of the large model training environment.

CN120493262APending Publication Date: 2025-08-15VIVO MOBILE COMM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510573352.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

In the prior art, vulnerability management in large-model training environments is inefficient and may cause false detection, resulting in the inability to comprehensively repair vulnerabilities and pose operational risks.

Method used

By parsing the first program code, the abstract syntax tree is obtained, the security vulnerability set in the training environment is identified, and the vulnerability is reproduced in the sandbox environment. Finally, the vulnerability is reproduced after the vulnerability is reproduced, forming the second training large model.

Benefits of technology

It improves the accuracy and comprehensiveness of vulnerability detection in the large model training environment, ensures operational security, and improves vulnerability management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120493262A_ABST
    Figure CN120493262A_ABST
Patent Text Reader

Abstract

The invention discloses a large model training environment vulnerability management method and device, and belongs to the technical field of artificial intelligence. The method comprises the following steps: analyzing a first program code to obtain an abstract syntax tree; identifying a first security vulnerability set existing in a training environment of the first training large model; scanning the abstract syntax tree, and determining a second security vulnerability set existing in the first program code; respectively performing vulnerability reproduction on the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set to respectively obtain a first reproduction result and a second reproduction result; and under the condition that the first reproduction result indicates that the security vulnerabilities in the first security vulnerability set are reproduced and the second reproduction result indicates that the security vulnerabilities in the second security vulnerability set are reproduced, respectively performing vulnerability repair on the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set. And obtaining a second training large model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of artificial intelligence technology, and specifically relates to a method and device for managing vulnerabilities in a large model training environment. Background Art

[0002] With the rapid development of artificial intelligence (AI) technology, the security issues of AI systems have become increasingly prominent, especially during the training of large language models (LLMs). Due to the complex training environment, numerous code dependencies, and the difficulty in detecting security vulnerabilities, large models are easily targeted by hacker attacks.

[0003] Currently, when managing vulnerabilities in the LLM training environment, manual detection is usually used to find vulnerabilities in the large model training program code, then manually analyze the vulnerability impact, reproduce the vulnerability, and then manually develop a vulnerability repair plan to repair the vulnerability to ensure the security of the LLM training environment.

[0004] The above vulnerability management solution for the LLM training environment is inefficient and may cause false detection problems, which in turn leads to the inability to comprehensively repair existing vulnerabilities, resulting in operational risks in the LLM training environment. Summary of the Invention

[0005] The purpose of the embodiments of the present application is to provide a large-model training environment vulnerability management method and device, which can automatically manage the vulnerabilities of the large-model training environment, improve the efficiency and accuracy of the large-model training environment vulnerability management, and ensure the operational security of the large-model training environment.

[0006] In a first aspect, an embodiment of the present application provides a method for managing vulnerabilities in a large model training environment, the method comprising:

[0007] Parsing the first program code to obtain an abstract syntax tree, where the first program code is the program code used when the first training model is used to train the target project;

[0008] Identifying a first set of security vulnerabilities in a training environment of the first training large model;

[0009] Scanning the abstract syntax tree to determine a second set of security vulnerabilities present in the first program code;

[0010] Reproducing the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set, respectively, to obtain a first reproduction result and a second reproduction result;

[0011] When the first reproduction result indicates that all security vulnerabilities in the first security vulnerability set have been reproduced, and the second reproduction result indicates that all security vulnerabilities in the second security vulnerability set have been reproduced, the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set are repaired respectively to obtain a second large training model.

[0012] In a second aspect, an embodiment of the present application provides a large model training environment vulnerability management device, which includes:

[0013] A parsing module, configured to parse a first program code to obtain an abstract syntax tree, wherein the first program code is a program code used when the first training model is used to train the target project;

[0014] an identification module, configured to identify a first set of security vulnerabilities existing in a training environment of the first training large model;

[0015] The identification module is further configured to scan the abstract syntax tree to determine a second set of security vulnerabilities present in the first program code;

[0016] A reproduction module, configured to reproduce the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set, respectively, to obtain a first reproduction result and a second reproduction result;

[0017] A repair module is used to repair the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set respectively when the first reproduction result indicates that all security vulnerabilities in the first security vulnerability set have been reproduced, and the second reproduction result indicates that all security vulnerabilities in the second security vulnerability set have been reproduced, so as to obtain a second large training model.

[0018] In a third aspect, an embodiment of the present application provides an electronic device comprising a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the method described in the first aspect are implemented.

[0019] In a fourth aspect, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented.

[0020] In a fifth aspect, an embodiment of the present application provides a chip, which includes a processor and a communication interface, the communication interface and the processor are coupled, and the processor is used to run programs or instructions to implement the method described in the first aspect.

[0021] In a sixth aspect, an embodiment of the present application provides a computer program product, which is stored in a storage medium and executed by at least one processor to implement the method described in the first aspect.

[0022] In the embodiment of the present application, compared to the prior art which only detects vulnerabilities in the program code of the first training large model, the solution of the embodiment of the present application also detects security vulnerabilities in the training environment of the first training large model, thereby improving the accuracy and comprehensiveness of vulnerability detection of the first training large model and ensuring the operational security of the large model training environment. After detecting the security vulnerabilities in the program code and training environment of the first training large model, the security vulnerabilities are reproduced, and when it is determined that the security vulnerability reproduction is complete, the security vulnerabilities are repaired to obtain a second training large model. In this way, the security vulnerabilities of the first training large model are automatically managed through multiple levels such as detection, reproduction, and repair of security vulnerabilities in the training environment and program code of the first training large model, thereby improving the management efficiency of the security vulnerabilities of the first training large model. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 This is a schematic diagram of the structure of a large model training environment vulnerability management system provided by some embodiments of the present application;

[0024] Figure 2 This is a flowchart of a large model training environment vulnerability management method provided by some embodiments of the present application;

[0025] Figure 3 This is a flowchart of a large model training environment vulnerability management method provided by some embodiments of the present application;

[0026] Figure 4 This is a flowchart of a method for implementing a vulnerability management method for a large model training environment based on a vulnerability management system framework for a large model training environment, provided by some embodiments of the present application;

[0027] Figure 5 is a schematic diagram of the structure of a large model training environment vulnerability management device shown in some embodiments of the present application;

[0028] Figure 6 is a schematic structural diagram of an electronic device shown in some embodiments of the present application;

[0029] Figure 7 It is a schematic diagram of the hardware structure of an electronic device shown in some embodiments of the present application. DETAILED DESCRIPTION

[0030] The following will be combined with the accompanying drawings in the embodiments of the present application to clearly describe the technical solutions in the embodiments of the present application. Obviously, the embodiments described are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field are within the scope of protection of this application.

[0031] The terms "first," "second," and the like in the specification and claims of this application are used to distinguish similar objects, and are not used to describe a specific order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of this application can be implemented in an order other than that illustrated or described herein, and that the objects distinguished by "first," "second," and the like are generally of a class, and do not limit the number of objects; for example, the first object can be one or N. In addition, the term "and / or" in the specification and claims refers to at least one of the connected objects, and the character " / " generally indicates that the objects connected are in an "or" relationship.

[0032] The following explains the terms involved in the embodiments of the present invention.

[0033] An Abstract Syntax Tree (AST) is an abstract representation of the grammatical structure of source code. It represents the grammatical structure of a programming language in a tree-like format, with each node in the tree representing a structure in the source code. The syntax is called "abstract" because it doesn't represent every detail found in real-world syntax. For example, nested parentheses are implicitly represented in the tree structure and not as nodes; conditional jump statements like if-condition-then can be represented using nodes with two branches.

[0034] Each node in the AST represents a syntactic structure in the program code, such as an expression, statement, or function. Furthermore, relationships between nodes, such as parent-child and sibling relationships, reflect the hierarchical structure of the code. Node types are related to the grammatical rules of the programming language, with different elements having different node types, such as loop nodes and variable declaration nodes.

[0035] Big models: are advanced AI algorithms trained on large amounts of data.

[0036] Artificial Intelligence: It is a new technical science that studies and develops theories, methods, technologies, and application systems for simulating, extending, and expanding human intelligence. Generally, AI refers to the technology of presenting human intelligence through ordinary computer programs.

[0037] Vulnerability reproduction: refers to verifying the existence and exploitability of known vulnerabilities in the target system or application by simulating hacker attacks.

[0038] A sandbox environment is a secure technology environment that simulates the operation of a real system through an isolation mechanism. It is mainly used in scenarios such as testing, development, and data circulation. Its core is to balance security and availability.

[0039] The technical solutions of the embodiments of the present application can be applied to scenarios where vulnerabilities in the training environment of a large model to be trained for a target project are detected. For example, a user wants to use a large model to train a speech-to-text process. When training the speech-to-text process based on the large model, the user does not know whether the large model has security vulnerabilities. The user wants to detect the security vulnerabilities of the large model and thus obtain a large model with a safe training environment and no security vulnerabilities.

[0040] Before introducing the large model training environment vulnerability management method provided by the embodiment of the present application, we first introduce the large model training environment vulnerability management system that implements the large model training environment vulnerability management method. Figure 1 As shown, the large model training environment vulnerability management system 100 may include a planning module 110 , an execution module 120 , a memory module 130 and a language module 140 .

[0041] The execution module 120 is configured to parse the first program code to obtain an abstract syntax tree; and identify a first set of security vulnerabilities in the training environment of the first training large model;

[0042] A planning module 110 is configured to scan the abstract syntax tree to determine a second set of security vulnerabilities present in the first program code;

[0043] The execution module 120 is also used to reproduce the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set, respectively, to obtain a first reproduction result and a second reproduction result, respectively; and when the first reproduction result indicates that the security vulnerabilities in the first security vulnerability set have all been reproduced, and the second reproduction result indicates that the security vulnerabilities in the second security vulnerability set have all been reproduced, respectively, to repair the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set, to obtain a second large training model.

[0044] The first program code may be the program code used when the first training model is used to train the target project. The first training model may be the model used to train the target project and is also the model used to perform security vulnerability detection in the embodiments of the present application. The target project may be the project that the first training model is used to train.

[0045] For example, a user wants to use a large model to train the speech-to-text process. When training the speech-to-text process based on the large model, the user does not know whether the large model has security vulnerabilities and wants to detect the security vulnerabilities of the large model to obtain a large model with a safe training environment and no security vulnerabilities. The large model used to train the speech-to-text process is the first training large model, speech-to-text is the target project, and the program code used to implement the training of the speech-to-text process in the large model is the first program code.

[0046] The training environment of the first training large model can be the environment in which the first training large model is used to train the target project. The training environment may include an operating system that integrates the first training large model and an external database called during the training process of the first training large model, that is, the training environment includes an operating system for executing the process of training the target project with the first training large model and an external database called during the training process of the first training large model.

[0047] Continuing with the above example, if the speech-to-text training process of the first training model is executed on a server, then the server is the operating system integrated with the first training model. If the training process of the first training model requires access to external databases, such as vulnerability databases or vulnerability repair databases, then the vulnerability databases or vulnerability repair databases are the external databases accessed during the training process of the first training model.

[0048] The first security vulnerability set may be a set of security vulnerabilities identified to exist in the training environment of the first large training model.

[0049] The second security vulnerability set may be a set of security vulnerabilities identified in the first program code.

[0050] The first reproduction result may be a result obtained by reproducing the security vulnerabilities in the first security vulnerability set, and the second reproduction result may be a result obtained by reproducing the security vulnerabilities in the second security vulnerability set.

[0051] The second large training model may be a large training model obtained after all vulnerabilities in the first large training model are repaired.

[0052] In an embodiment of the present application, a large model training environment vulnerability management system is provided to detect security vulnerabilities in the first training large model. Compared with the prior art that only detects vulnerabilities in the program code of the first training large model, the solution of the embodiment of the present application also detects security vulnerabilities in the training environment of the first training large model, thereby improving the accuracy and comprehensiveness of vulnerability detection of the first training large model and ensuring the operational security of the large model training environment. After detecting security vulnerabilities in the program code and training environment of the first training large model, the security vulnerabilities are reproduced. When it is determined that the security vulnerability reproduction is complete, the security vulnerabilities are repaired to obtain a second training large model. In this way, the security vulnerabilities of the first training large model are automatically managed through multiple levels such as detection, reproduction, and repair of security vulnerabilities in the training environment and program code of the first training large model, thereby improving the management efficiency of the security vulnerabilities of the first training large model.

[0053] In some embodiments of the present application, the planning module 110 can also be used to decompose the vulnerability management task of the first training large model. For example, the vulnerability management task can be divided into the following parts: converting the first program code into AST, detecting security vulnerabilities in the first program code, detecting security vulnerabilities in the training environment of the first training large model, reproducing the detected security vulnerabilities, and repairing the detected security vulnerabilities.

[0054] The planning module 110 may also be used to formulate a corresponding reproduction strategy before reproducing the detected security vulnerability, so as to ensure that the detected security vulnerability can be effectively verified.

[0055] The planning module 110 can also be used to formulate corresponding repair strategies before repairing the detected security vulnerabilities. Specifically, it can provide corresponding code or configuration modification suggestions to improve repair efficiency.

[0056] In some embodiments of the present application, the memory module 130 can be used to store the vulnerability database and vulnerability repair database used in the execution module 120, and to optimize the vulnerability database and vulnerability repair database based on previous security vulnerability detection results, so as to improve the vulnerability detection efficiency and vulnerability repair efficiency when security vulnerability detection is performed on the training large model in the future.

[0057] In some embodiments of the present application, the language module 140 can be used to generate a highly readable structured vulnerability detection result report after detecting security vulnerabilities in the first program code and detecting security vulnerabilities in the training environment of the first training model, and to generate corresponding vulnerability reproduction reports and vulnerability repair reports after reproducing the detected security vulnerabilities and repairing the detected security vulnerabilities. Among them, the vulnerability detection result report describes in detail the detection of each security vulnerability, as well as detailed information such as the type of each security vulnerability. The vulnerability reproduction report describes in detail the test steps, input and output data, and results of the test step execution performed during the vulnerability reproduction process. The vulnerability repair report can describe in detail the process of repairing each security vulnerability, specifically which content of the program code has been modified and which parameters of the training environment have been modified for each security vulnerability.

[0058] The file processing method provided in the embodiment of the present application is described in detail below through specific embodiments and their application scenarios in conjunction with the accompanying drawings.

[0059] Figure 2 This is a flow chart of a method for managing vulnerabilities in a large model training environment provided by an embodiment of the present application. The execution subject of the method for managing vulnerabilities in a large model training environment can be the above-mentioned Figure 1 The large model training environment vulnerability management system 100 is shown.

[0060] like Figure 2 As shown, the large model training environment vulnerability management method provided in the embodiment of the present application may include steps 210 to 250.

[0061] Step 210: Parse the first program code to obtain an abstract syntax tree.

[0062] Among them, the first program code is the program code when the first training model is used to train the target project.

[0063] In some embodiments of the present application, to improve the accuracy of converting the first program code into an abstract syntax tree, step 210 may specifically include:

[0064] preprocessing the first program code to obtain a preprocessed first program code;

[0065] The preprocessed first program code is parsed to obtain an abstract syntax tree.

[0066] The pre-processing may include removing comments, blank lines, and formatting symbols from the first program code. Formatting symbols may include, for example, book title marks, commas, and other formatting symbols.

[0067] In some embodiments of the present application, before performing security vulnerability detection on the first program code, the first program code must first be preprocessed. Specifically, the comments, blank lines and formatting symbols in the first program code can be removed. This prevents the comments, blank lines and formatting symbols in the first program code from affecting the subsequent execution module's detection of security vulnerabilities in the first program code.

[0068] After obtaining the preprocessed first program code, the preprocessed first program code can be parsed to obtain an abstract syntax tree. Specifically, an AST parsing tool of the same programming language as the first program code can be used to convert the preprocessed first program code into an abstract syntax tree.

[0069] In an embodiment of the present application, by preprocessing the first program code, the subsequent process of converting the first program code into an abstract syntax tree can be avoided from being affected by comments, blank lines, and formatting symbols in the first program code, thereby improving the accuracy of converting the first program code into an abstract syntax tree.

[0070] In some embodiments of the present application, in order to accurately obtain an abstract syntax tree, parsing the preprocessed first program code to obtain an abstract syntax tree may specifically include:

[0071] performing word segmentation processing on the preprocessed first program code to obtain at least one word segmentation;

[0072] At least one word segment is converted into an abstract syntax tree with a tree structure according to the execution logic of the preprocessed first program code.

[0073] In some embodiments of the present application, the syntax analyzer in the AST parsing tool can be used to perform word segmentation on the characters in the preprocessed first program code to obtain at least one word segmentation, and then according to the execution logic of the preprocessed first program code, the at least one word segmentation can be converted into an abstract syntax tree with a tree structure.

[0074] In an embodiment of the present application, at least one word segmentation is obtained by performing word segmentation processing on the preprocessed first program code, and then the at least one word segmentation is converted into an abstract syntax tree with a tree structure according to the execution logic of the preprocessed first program code, so that the abstract syntax tree can be accurately obtained.

[0075] Step 220: Identify a first set of security vulnerabilities in the training environment of the first training large model.

[0076] In some embodiments of the present application, the training environment of the first training large model may include an operating system integrated with the first training large model and an external database called during the training process of the first training large model. If the parameters of the operating system integrated with the first training large model are improperly configured, it may lead to risks such as unauthorized access, sensitive data leakage, and malicious command execution. During the training process of the first training large model, many external databases will be called, such as open source databases or third-party components, and these components may contain known or unknown security vulnerabilities, such as malicious dependencies, code backdoors, etc. Attackers can endanger system security through supply chain attacks.

[0077] To solve the above problem, step 220 may specifically include:

[0078] According to the first attribute information of the operating system, searching a vulnerability database for a first reference vulnerability that matches the operating system of the first attribute information;

[0079] According to the second attribute information of the external database called during the training process of the first training large model, searching for a second reference vulnerability in the vulnerability database that matches the database of the second attribute information;

[0080] Based on the first reference vulnerability and the second reference vulnerability, a first security vulnerability set of the training environment of the first training large model is determined.

[0081] The first attribute information may be attribute information of the operating system integrated with the first training large model, such as the name, version information, and internal setting parameters of the operating system integrated with the first training large model.

[0082] The vulnerability database may be a database pre-stored in the memory module for identifying security vulnerabilities in the training environment of the first training large model. The vulnerability database may store vulnerabilities existing in operating systems with different attribute information and vulnerabilities existing in databases with different attribute information. Examples of the vulnerability database here may be Common Vulnerabilities & Exposures (CVE), NVD (National Vulnerability Database), or Open Source Vulnerability Database (OSV).

[0083] The first reference vulnerability may be a vulnerability found in a vulnerability database that matches the operating system of the first attribute information, that is, a possible security vulnerability found in the operating system of the first attribute information in the vulnerability database.

[0084] The second attribute information may be attribute information of an external database called during the training process of the first training large model, such as the name of the external database called during the training process of the first training large model, the framework used, version information, and internal setting parameters.

[0085] The second reference vulnerability may be a vulnerability found in the vulnerability database that matches the database of the second attribute information, that is, a possible security vulnerability in the external database of the second attribute information is found in the vulnerability database.

[0086] In some embodiments of the present application, since the operating system that integrates the first training large model and the external database called during the training process of the first training large model are generally open source operating systems and databases, the vulnerabilities of the operating system that integrates the first training large model and the vulnerabilities of the external database called during the training process of the first training large model can be detected based on a vulnerability database that includes a vulnerability set of existing open source operating systems and open source databases.

[0087] Specifically, the system version, kernel version and system configuration of the operating system that integrates the first training large model can be obtained, such as system setting parameter variables, system file permissions, system process management, etc., and then the security vulnerability database is called to check whether the operating system that integrates the first training large model contains known vulnerabilities to obtain the first reference vulnerability.

[0088] In addition, the framework used by the external database called during the training of the first large training model, such as Python, TensorFlow, PyTorch, and other frameworks, can also be obtained. Whether the external database called during the training of the first large training model calls other AI frameworks, for example, whether the external database called during the training of the first large training model uses AI frameworks such as TensorFlow, PyTorch, JAX, MXNet, and obtain the specific version. Then, the security vulnerability database is called to check whether the operating system integrated with the first large training model contains known vulnerabilities. For example, whether the external database called during the training of the first large training model contains unpatched security vulnerabilities (such as the remote code execution vulnerability in TensorFlow 1.x), weak encryption algorithms (such as Secure Hash Algorithm 1 (SHA-1) and Message Digest Algorithm (MD5), which are no longer recommended for use), and whether it contains untrusted third-party libraries that may introduce backdoors or supply chain attacks. This way, the second reference vulnerability is obtained.

[0089] Then, the identified first reference vulnerability and the second reference vulnerability are set together to obtain a first security vulnerability set.

[0090] It should be noted that when performing security vulnerability detection on the training environment of the first training large model, in addition to performing security vulnerability detection on the framework structure of the operating system that integrates the first training large model and the framework structure of the external database called during the training of the first training large model, it is also necessary to detect the files in the operating system that integrates the first training large model and the files in the external database called during the training of the first training large model. Specifically, it can be detected whether the file contains malicious instructions. Specifically, it can be detected based on the vulnerability database whether the files in the operating system that integrates the first training large model and the files in the external database called during the training of the first training large model contain malicious instructions.

[0091] In an embodiment of the present application, by utilizing a vulnerability database to identify a first set of security vulnerabilities existing in the training environment of the first training large model, there is no need for the user to develop other vulnerability detection algorithms to detect vulnerabilities in the training environment of the first training large model, thereby improving the efficiency of determining the first set of security vulnerabilities.

[0092] Step 230: Scan the abstract syntax tree to determine a second set of security vulnerabilities in the first program code.

[0093] The second security vulnerability set is the identified security vulnerabilities existing in the first program code.

[0094] In some embodiments of the present application, to improve the efficiency of determining the second security vulnerability set of the first program code, step 230 may specifically include:

[0095] Scanning the abstract syntax tree to obtain a syntax structure indicated by each tree node in the abstract syntax tree and a code logic of the first program code indicated by each tree node;

[0096] matching the grammatical structure indicated by each tree node with a reference vulnerability grammatical structure in the vulnerability database, and matching the code logic of the first program code indicated by each tree node with the reference vulnerability code logic in the vulnerability database;

[0097] The grammatical structure indicated by each tree node that matches the reference vulnerability grammatical structure, and the execution logic of the first program code indicated by each tree node that matches the reference vulnerability code logic are taken as the second security vulnerability set.

[0098] In some embodiments of the present application, the AST can be scanned using an existing AST scanning tool to obtain the grammatical structure indicated by each tree node in the abstract syntax tree and the code logic of the first program code indicated by each tree node. The structure and function of the first program code can be obtained based on the grammatical structure indicated by each tree node and the code logic of the first program code indicated by each tree node. The grammatical structure indicated by each tree node is then matched with the reference vulnerability grammatical structure in the vulnerability database, and the reference vulnerability grammatical structure that matches the grammatical structure indicated by each tree node in the vulnerability database is selected as the security vulnerability in the second security vulnerability set.

[0099] The code logic of the first program code indicated by each tree node is matched with the reference vulnerability code logic in the vulnerability database, and then the execution logic that matches the code logic of the first program code indicated by each tree node and the reference vulnerability code logic is selected as the security vulnerability in the second security vulnerability set.

[0100] It should be noted that when using existing AST scanning tools to scan AST, you can use tools such as Bandit and Semgrep to perform static analysis on the first program code. In this way, you can identify whether there is Structured Query Language (SQL) injection, cross-site scripting (XSS), command execution vulnerabilities, path traversal attacks and other common security vulnerabilities in the first program code. In addition, you can also analyze whether the first program code contains high-risk function calls (such as eval(), exec(), pickle.loads(), etc.).

[0101] It should be noted that the second security vulnerability set of the first program code identified above is security vulnerabilities in information such as the calling relationship and data flow of the first program code.

[0102] In an embodiment of the present application, by scanning the abstract syntax tree, the grammatical structure indicated by each tree node in the abstract syntax tree and the code logic of the first program code indicated by each tree node are obtained, and then the grammatical structure indicated by each tree node and the code logic of the first program code indicated by each tree node are analyzed based on the vulnerability database to determine whether there are security vulnerabilities. In this way, there is no need to redevelop other vulnerability analysis algorithms to analyze whether there are security vulnerabilities in the grammatical structure indicated by each tree node and the code logic of the first program code indicated by each tree node, thereby improving the efficiency of determining the second security vulnerability set of the first program code.

[0103] Step 240: Reproduce the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set, respectively, to obtain a first reproduction result and a second reproduction result.

[0104] In some embodiments of the present application, step 240 can be implemented in a sandbox environment or a virtual machine, that is, a virtual environment that is the same as the training environment of the first training large model is constructed, and then the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set are reproduced in this environment respectively. In this way, the vulnerabilities can be reproduced safely, damage to the actual system can be avoided, and the controllability of vulnerability analysis can be improved.

[0105] In some embodiments of the present application, in order to improve the efficiency and accuracy of determining the reproduction strategy of the security vulnerabilities in the first security vulnerability set and the reproduction strategy of the security vulnerabilities in the second security vulnerability set, before step 240, the above method may further include:

[0106] Inputting the first security vulnerability set and the second security vulnerability set into a vulnerability reproduction database, obtaining a first vulnerability reproduction strategy for reproducing the security vulnerabilities in the first security vulnerability set, and a second vulnerability reproduction strategy for reproducing the security vulnerabilities in the second security vulnerability set;

[0107] Step 240 may specifically include:

[0108] Executing a corresponding operation in the first training large model based on the first operation instruction to obtain a third security vulnerability set;

[0109] Based on the second operation instruction, a corresponding operation is performed in the first training large model to obtain a fourth security vulnerability set.

[0110] Among them, the vulnerability reproduction database can be a model used to generate a vulnerability reproduction strategy. The vulnerability reproduction database can be a model obtained based on deep learning training. The vulnerability reproduction database can be but is not limited to a neural network model, a support vector machine model or a decision tree model.

[0111] The first vulnerability reproduction strategy may be a strategy for reproducing a security vulnerability in the first security vulnerability set. The first vulnerability reproduction strategy may include a first operation instruction on how to attack the training environment of the first training large model to cause a security vulnerability in the first security vulnerability set to appear.

[0112] The second vulnerability reproduction strategy may be a strategy for reproducing the security vulnerability in the second security vulnerability set. The second vulnerability reproduction strategy may include a second operation instruction on how to attack the first program code to cause the security vulnerability in the second security vulnerability set to appear.

[0113] The third set of security vulnerabilities may be a set of security vulnerabilities that appear in the first training model after the first operating instruction executes a corresponding operation in the first training model. Specifically, the third set of security vulnerabilities that appear in the first training model after the first operating instruction attacks the training environment of the first training model in the first training model. In other words, the first reproduction result may include the third set of security vulnerabilities.

[0114] The fourth set of security vulnerabilities may be a set of security vulnerabilities that appear in the first training model after the second operating instruction executes a corresponding operation in the first training model. Specifically, the fourth set of security vulnerabilities may be a set of security vulnerabilities that appear in the first training model after the second operating instruction attacks the first program code in the first training model. In other words, the second reproduction result may include the fourth set of security vulnerabilities.

[0115] In some embodiments of the present application, the first security vulnerability set and the second security vulnerability set can be input into a vulnerability reproduction database to obtain a first vulnerability reproduction strategy for reproducing the security vulnerabilities in the first security vulnerability set, and a second vulnerability reproduction strategy for reproducing the security vulnerabilities in the second security vulnerability set.

[0116] The above-mentioned inputting of the first security vulnerability set and the second security vulnerability set into the vulnerability reproduction database to obtain the first vulnerability reproduction strategy for reproducing the security vulnerabilities in the first security vulnerability set and the second vulnerability reproduction strategy for reproducing the security vulnerabilities in the second security vulnerability set can be executed in the planning module.

[0117] It should be noted that before inputting the first security vulnerability set and the second security vulnerability set into the vulnerability reproduction database to obtain the first vulnerability reproduction strategy for reproducing the security vulnerabilities in the first security vulnerability set, and the second vulnerability reproduction strategy for reproducing the security vulnerabilities in the second security vulnerability set, the first security vulnerability set and the second security vulnerability set may be preprocessed first. Specifically, the preprocessing may be text cleaning, formatting, etc., and then the preprocessed first security vulnerability set and second security vulnerability set are organized into a structured list, and then the list is input into the vulnerability reproduction database, so as to obtain the first vulnerability reproduction strategy for reproducing the security vulnerabilities in the first security vulnerability set, and the second vulnerability reproduction strategy for reproducing the security vulnerabilities in the second security vulnerability set.

[0118] Then, based on the first operation instruction, a corresponding operation is performed in the first training large model to obtain a third security vulnerability set. Based on the second operation instruction, a corresponding operation is performed in the first training large model to obtain a fourth security vulnerability set.

[0119] In an embodiment of the present application, a first vulnerability reproduction strategy for reproducing security vulnerabilities in a first security vulnerability set and a second vulnerability reproduction strategy for reproducing security vulnerabilities in a second security vulnerability set can be obtained through a vulnerability reproduction database. In this way, there is no need for the user to write a reproduction strategy for the security vulnerabilities in the first security vulnerability set and a reproduction strategy for the security vulnerabilities in the second security vulnerability set, thereby improving the efficiency and accuracy of determining the reproduction strategy for the security vulnerabilities in the first security vulnerability set and the reproduction strategy for the security vulnerabilities in the second security vulnerability set.

[0120] In some embodiments of the present application, in order to improve the comprehensiveness of security vulnerability detection in the first training large model, the above-mentioned method may further include:

[0121] updating at least one of the first operation instruction and the second operation instruction when at least one of the following is detected: the third security vulnerability set does not include all security vulnerabilities in the first security vulnerability set, and the fourth security vulnerability set does not include all security vulnerabilities in the second security vulnerability set;

[0122] Replace the updated first operation instruction with the first operation instruction, and replace the updated second operation instruction with the second operation instruction, return to execute the corresponding operation based on the first operation instruction in the first training large model to obtain the third security vulnerability set, and execute the corresponding operation based on the second operation instruction in the first training large model to obtain the third security vulnerability set, until the third security vulnerability set contains all the security vulnerabilities in the first security vulnerability set and the fourth security vulnerability set contains all the security vulnerabilities in the second security vulnerability set, it is determined that all the security vulnerabilities in the first security vulnerability set have been reproduced, and all the security vulnerabilities in the second security vulnerability set have been reproduced.

[0123] In some embodiments of the present application, when the third security vulnerability set does not include all the security vulnerabilities in the first security vulnerability set, and / or when the fourth security vulnerability set does not include all the security vulnerabilities in the second security vulnerability set, the first operation instruction and / or the second operation instruction are updated. That is, when the first operation instruction is used to reproduce the security vulnerabilities in the first security vulnerability set, if the security vulnerabilities in the first security vulnerability set are not completely reproduced, that is, the third security vulnerability set does not include all the security vulnerabilities in the first security vulnerability set, then the first operation instruction in the first vulnerability reproduction strategy needs to be updated, such as the need to re-modify the attack method or parameters for attacking the training environment of the first training large model. When the second operation instruction is used to reproduce the security vulnerabilities in the second security vulnerability set, if the security vulnerabilities in the second security vulnerability set are not completely reproduced, that is, the fourth security vulnerability set does not include all the security vulnerabilities in the second security vulnerability set, then the second operation instruction in the second vulnerability reproduction strategy needs to be updated, such as the need to re-modify the attack method or parameters for attacking the first program code.

[0124] Then, based on the updated first operating instructions, the corresponding operations are re-executed in the first training large model, i.e., the training environment of the first training large model is re-attacked using the updated first operating instructions, until the security vulnerabilities in the first security vulnerability set are completely reproduced. And based on the updated second operating instructions, the corresponding operations are re-executed in the first training large model, i.e., the first program code is re-attacked using the updated second operating instructions, until the security vulnerabilities in the second security vulnerability set are completely reproduced.

[0125] When it is determined that the security vulnerabilities in the first security vulnerability set are completely reproduced and the security vulnerabilities in the second security vulnerability set are completely reproduced, it can be determined that all the security vulnerabilities in the first security vulnerability set are completely reproduced and all the security vulnerabilities in the second security vulnerability set are completely reproduced.

[0126] In an embodiment of the present application, when the third security vulnerability set does not include all the security vulnerabilities in the first security vulnerability set, and / or the fourth security vulnerability set does not include all the security vulnerabilities in the second security vulnerability set, the first operation instruction and / or the second operation instruction can be updated, and then based on the updated first operation instruction and / or the second operation instruction, all the security vulnerabilities in the first security vulnerability set and / or all the security vulnerabilities in the second security vulnerability set can be reproduced again until all the security vulnerabilities in the first security vulnerability set are reproduced and all the security vulnerabilities in the second security vulnerability set are reproduced. This ensures that all the security vulnerabilities detected in the first training large model can be reproduced, thereby improving the comprehensiveness of security vulnerability detection in the first training large model.

[0127] Step 250: When the first reproduction result indicates that all security vulnerabilities in the first security vulnerability set have been reproduced, and the second reproduction result indicates that all security vulnerabilities in the second security vulnerability set have been reproduced, the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set are repaired respectively to obtain a second large training model.

[0128] In some embodiments of the present application, in order to improve the efficiency and accuracy of determining the remediation strategies for the security vulnerabilities in the first security vulnerability set and the remediation strategies for the security vulnerabilities in the second security vulnerability set, before step 250, the above-mentioned method may further include:

[0129] According to the first security vulnerability set, searching a reference vulnerability repair database for a repair strategy corresponding to a security vulnerability in the first security vulnerability set to obtain a first repair strategy;

[0130] According to the second security vulnerability set, searching for a repair strategy corresponding to the security vulnerability in the second security vulnerability set from a reference vulnerability repair database to obtain a second repair strategy;

[0131] Step 250 may specifically include:

[0132] The security vulnerabilities in the first security vulnerability set are repaired based on the first repair strategy, and the security vulnerabilities in the second security vulnerability set are repaired based on the second repair strategy to obtain a second large training model.

[0133] The reference vulnerability repair database may be a database for providing strategies for repairing security vulnerabilities, and the reference vulnerability repair database may store repair strategies for different security vulnerabilities.

[0134] The first repair strategy may be a strategy for repairing the security vulnerabilities in the first security vulnerability set. The first repair strategy may include the content that needs to be modified to repair the security vulnerabilities in the first security vulnerability set, as well as the modified content corresponding to the modified content. For example, if the security vulnerability in the first security vulnerability set is a vulnerability in the system parameter settings of the operating system that integrates the first large training model, the first repair strategy may include specific content on how to modify the system parameters of the operating system that integrates the first large training model.

[0135] The second repair strategy may be a strategy for repairing the security holes in the second security hole set. For example, if the security hole in the second security hole set is a vulnerability in a calling function in the first program code, the second repair strategy may include specific details on how to modify the calling function.

[0136] In some embodiments of the present application, based on the planning module, according to the first security vulnerability set, a repair strategy corresponding to the security vulnerabilities in the first security vulnerability set can be searched from the reference vulnerability repair database to obtain a first repair strategy, and according to the second security vulnerability set, a repair strategy corresponding to the security vulnerabilities in the second security vulnerability set can be searched from the reference vulnerability repair database to obtain a second repair strategy.

[0137] Then, based on the first repair strategy, the security vulnerabilities in the first security vulnerability set can be repaired, and based on the second repair strategy, the security vulnerabilities in the second security vulnerability set can be repaired, so that a second large training model without security vulnerabilities can be obtained.

[0138] In the implementation of the present application, by referring to the vulnerability repair database, a first repair strategy for repairing security vulnerabilities in the first security vulnerability set and a second repair strategy for repairing security vulnerabilities in the second security vulnerability set can be obtained. In this way, there is no need for the user to write the repair strategy for the security vulnerabilities in the first security vulnerability set and the repair strategy for the security vulnerabilities in the second security vulnerability set, which improves the efficiency and accuracy of determining the repair strategy for the security vulnerabilities in the first security vulnerability set and the repair strategy for the security vulnerabilities in the second security vulnerability set.

[0139] In some embodiments of the present application, in order to improve the comprehensiveness and accuracy of vulnerability repair, after step 250, the above method may further include:

[0140] The vulnerability reproduction strategies in the vulnerability reproduction database are updated according to the first vulnerability reproduction strategy and the second vulnerability reproduction strategy to obtain an updated vulnerability reproduction database.

[0141] In some embodiments of the present application, for any one of the first vulnerability reproduction strategy and the second vulnerability reproduction strategy, the reproduction strategy is modified based on the reproduction strategy provided by the vulnerability reproduction database. In this way, the reproduction strategy in the vulnerability reproduction database can be updated according to the first vulnerability reproduction strategy and the second vulnerability reproduction strategy to obtain an updated vulnerability reproduction database.

[0142] Similarly, when detecting security vulnerabilities in the first training large model, there may be security vulnerabilities that do not belong to the first security vulnerability set and the second security vulnerability set. In this way, the vulnerability database can be updated based on the reproduction and repair of the security vulnerability, which can facilitate subsequent more comprehensive vulnerability detection based on the vulnerability database.

[0143] In an embodiment of the present application, by updating the reproduction strategy in the vulnerability reproduction database according to the first vulnerability reproduction strategy and the second vulnerability reproduction strategy, an updated vulnerability reproduction database is obtained, which facilitates the subsequent comprehensive reproduction of the vulnerability and improves the comprehensiveness and accuracy of the vulnerability reproduction.

[0144] Figure 3 This is a flow chart of another large model training environment vulnerability management method provided by the embodiment of the present application. The execution subject of the large model training environment vulnerability management method can be the above Figure 1 The large model training environment vulnerability management system 100 is shown.

[0145] like Figure 3 As shown, the large model training environment vulnerability management method provided by the embodiment of the present application may include steps 310 to 330.

[0146] Step 310: Parse the first program code based on the execution module to obtain an abstract syntax tree; and identify a first set of security vulnerabilities in the training environment of the first training large model.

[0147] Among them, the first program code is the program code when the first training model trains the target project

[0148] Step 320: Scan the abstract syntax tree based on the planning module to determine a second set of security vulnerabilities in the first program code.

[0149] Step 330: Based on the execution module, the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set are respectively reproduced to obtain a first reproduction result and a second reproduction result, and when the first reproduction result indicates that the security vulnerabilities in the first security vulnerability set are all reproduced, and the second reproduction result indicates that the security vulnerabilities in the second security vulnerability set are all reproduced, the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set are respectively repaired to obtain a second large training model.

[0150] In the embodiment of the present application, compared to the prior art in which only the program code in the first training large model is detected for vulnerabilities, the solution of the embodiment of the present application also detects security vulnerabilities in the training environment of the first training large model based on the execution module, thereby improving the accuracy and comprehensiveness of vulnerability detection of the first training large model and ensuring the operational security of the large model training environment. After detecting the security vulnerabilities in the program code and training environment of the first training large model, the security vulnerabilities are also reproduced based on the execution module. When it is determined that the security vulnerability reproduction is complete, the security vulnerabilities are repaired to obtain the second training large model. In this way, the security vulnerabilities of the first training large model are automatically managed through multiple levels such as detection, reproduction, and repair of security vulnerabilities in the training environment and program code of the first training large model, thereby improving the management efficiency of the security vulnerabilities of the first training large model.

[0151] In order to better understand the large model training environment vulnerability management method in the embodiment of the present application, the process of implementing the large model training environment vulnerability management method based on the large model training environment vulnerability management system framework is described in detail below. Figure 4 , Figure 4 A flowchart for implementing a large model training environment vulnerability management method based on the large model training environment vulnerability management system framework.

[0152] Step 1: Convert the first program code into an abstract syntax tree.

[0153] Step 2: Detection of the training environment.

[0154] This step 2 is to identify the first set of security vulnerabilities in the training environment of the first training large model in the above embodiment.

[0155] In step 2, it is first necessary to obtain the training environment of the first training large model, and then use the vulnerability database to detect security vulnerabilities in the training environment of the first training large model to obtain a first security vulnerability set.

[0156] Step 3: Code logic detection.

[0157] This step 3 is to scan the abstract syntax tree in the above embodiment to identify the second set of security vulnerabilities in the first program code.

[0158] In step 3, the abstract syntax tree may be scanned to obtain the code structure and function of the first program code, and then a second set of security vulnerabilities in the first program code may be identified based on the vulnerability database.

[0159] Step 4: Reproduce the vulnerability.

[0160] The process of step 4 is the process of respectively reproducing the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set in the above embodiment to obtain the first reproduction result and the second reproduction result respectively.

[0161] In this step 4, a first vulnerability reproduction strategy for reproducing the security vulnerabilities in the first security vulnerability set and a second vulnerability reproduction strategy for reproducing the security vulnerabilities in the second security vulnerability set can be generated based on the planning module, and then the first vulnerability reproduction strategy and the second vulnerability reproduction strategy are sent to the planning module. The planning module can perform a corresponding operation in the first training large model based on the first operation instruction to obtain a first reproduction result, and perform a corresponding operation in the first training large model based on the second operation instruction to obtain a second reproduction result.

[0162] The planning module then sends the first reproduction result and the second reproduction result to the planning module, and the planning model determines whether all the security vulnerabilities in the first security vulnerability set have been reproduced, and whether all the security vulnerabilities in the second security vulnerability set have been reproduced. If so, a vulnerability reproduction report is generated. If not, the first operation instruction and the second operation instruction are updated, and the corresponding operation based on the first operation instruction is returned to be executed in the first training large model again, and the corresponding operation based on the second operation instruction is executed in the first training large model again, until all the security vulnerabilities in the first security vulnerability set are reproduced, and all the security vulnerabilities in the second security vulnerability set are reproduced.

[0163] Step 5: Vulnerability Fix

[0164] This step 5 is the process of repairing the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set respectively in the above embodiment to obtain the second large training model.

[0165] In this step 5, the planning module can generate a vulnerability repair strategy based on the vulnerability reproduction report, that is, according to the first security vulnerability set, the reference vulnerability repair database is searched for the repair strategy corresponding to the security vulnerability in the first security vulnerability set to obtain the first repair strategy in the above embodiment; and according to the second security vulnerability set, the reference vulnerability repair database is searched for the repair strategy corresponding to the security vulnerability in the second security vulnerability set to obtain the second repair strategy.

[0166] The execution module can then repair the security vulnerabilities in the first security vulnerability set according to the first repair strategy, and repair the security vulnerabilities in the second security vulnerability set based on the second repair strategy to obtain a second training large model.

[0167] After obtaining the second large training model, a vulnerability repair report can be generated, and the vulnerability repair report can be fed back to the memory module to update the reference vulnerability repair database, and the vulnerability database can be updated based on the vulnerability reproduction report.

[0168] Compared with traditional security vulnerability detection methods, the embodiments of the present application have the following advantages:

[0169] The embodiments of this application combine multiple detection methods such as reliance security detection, logical vulnerability analysis, and dynamic vulnerability reproduction to discover security vulnerabilities from multiple levels such as code, operating environment, and interactive behavior, ensuring comprehensive detection. Through the collaboration of the planning module, execution module, memory module, and language module, a complete detection closed loop is formed to ensure the accuracy and consistency of the detection results. Through comparative analysis of the vulnerability database, known vulnerabilities can be quickly discovered, and combined with static and dynamic analysis techniques, potential vulnerabilities can be identified to improve detection accuracy.

[0170] Using the vulnerability reproduction database, we can automatically select appropriate vulnerability reproduction strategies, verify vulnerability exploitability, and assess the vulnerability's impact. During the vulnerability reproduction process, the planning module automatically adjusts the reproduction strategy based on the results, improving the success rate of vulnerability reproduction. Combined with sandbox environments or virtual machine technology, vulnerabilities can be reproduced safely, avoiding damage to the actual system and improving the controllability of vulnerability analysis.

[0171] Based on the vulnerability reproduction results, vulnerability remediation strategies are automatically generated to improve vulnerability remediation efficiency. Combined with code patch generation technology, affected code can be directly modified and static / dynamic verification is performed to ensure the effectiveness of the remediation plan. Repaired project files can be versioned to ensure historical version tracking, preventing accidental fixes or the introduction of secondary vulnerabilities.

[0172] The memory module stores newly discovered vulnerabilities and their fixes in the vulnerability database, enabling the system to acquire long-term learning capabilities. After each vulnerability detection and fix, the system analyzes the results, adjusts the fix strategy, and optimizes future vulnerability discovery. By combining historical vulnerability data, it trains vulnerability detection models, optimizes the vulnerability database, and improves its ability to identify new vulnerability attack methods.

[0173] By automating the detection and repair of security vulnerabilities, manual workload is significantly reduced, labor costs are lowered, and the automation level of security vulnerability detection is improved. In addition, the solution of the embodiment of the present application significantly reduces the time cost of security vulnerability detection and speeds up the cycle of vulnerability discovery and repair.

[0174] The embodiment of the present application provides a method for managing vulnerabilities in a large model training environment, and the execution subject can be a large model training environment vulnerability management device. In the embodiment of the present application, an information processing device is used to execute the method for managing vulnerabilities in a large model training environment as an example to illustrate the large model training environment vulnerability management device provided in the embodiment of the present application.

[0175] Figure 5 This is a schematic diagram of a large model training environment vulnerability management device according to an exemplary embodiment. The large model training environment vulnerability management device can be applied to Figure 1 Large model training environment vulnerability management system in . Figure 5 As shown, the large model training environment vulnerability management device 500 may include:

[0176] A parsing module 510 is configured to parse a first program code to obtain an abstract syntax tree, wherein the first program code is the program code used when the first training model is used to train the target project;

[0177] An identification module 520 is configured to identify a first set of security vulnerabilities present in the training environment of the first training large model;

[0178] The identification module 520 is further configured to scan the abstract syntax tree to determine a second set of security vulnerabilities present in the first program code;

[0179] A reproduction module 530 is configured to reproduce the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set, respectively, to obtain a first reproduction result and a second reproduction result;

[0180] The repair module 540 is used to repair the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set respectively when the first reproduction result indicates that all security vulnerabilities in the first security vulnerability set have been reproduced, and the second reproduction result indicates that all security vulnerabilities in the second security vulnerability set have been reproduced, so as to obtain a second large training model.

[0181] In the embodiment of the present application, compared to the prior art which only detects vulnerabilities in the program code of the first training large model, the solution of the embodiment of the present application also detects security vulnerabilities in the training environment of the first training large model, thereby improving the accuracy and comprehensiveness of vulnerability detection of the first training large model and ensuring the operational security of the large model training environment. After detecting the security vulnerabilities in the program code and training environment of the first training large model, the security vulnerabilities are reproduced, and when it is determined that the security vulnerability reproduction is complete, the security vulnerabilities are repaired to obtain a second training large model. In this way, the security vulnerabilities of the first training large model are automatically managed through multiple levels such as detection, reproduction, and repair of security vulnerabilities in the training environment and program code of the first training large model, thereby improving the management efficiency of the security vulnerabilities of the first training large model.

[0182] In some embodiments of the present application, the parsing module is specifically used to:

[0183] Preprocessing the first program code to obtain preprocessed first program code, wherein the preprocessing includes: removing comments, blank lines, and formatting symbols in the first program code;

[0184] The preprocessed first program code is parsed to obtain an abstract syntax tree.

[0185] In some embodiments of the present application, the parsing module is specifically used to:

[0186] performing word segmentation processing on the preprocessed first program code to obtain at least one word segmentation;

[0187] At least one word segment is converted into an abstract syntax tree with a tree structure according to the execution logic of the preprocessed first program code.

[0188] In some embodiments of the present application, the training environment of the first training large model includes an operating system integrated with the first training large model and an external database called during the training process of the first training large model;

[0189] The identification module is specifically used for:

[0190] searching, from a vulnerability database, for a first reference vulnerability that matches the operating system with the first attribute information according to the first attribute information of the operating system;

[0191] According to the second attribute information of the external database called during the training process of the first training large model, searching the vulnerability database for a second reference vulnerability that matches the database of the second attribute information;

[0192] Determining a first security vulnerability set of a training environment of the first training large model based on the first reference vulnerability and the second reference vulnerability;

[0193] The vulnerability database stores vulnerabilities existing in operating systems with different attribute information and vulnerabilities existing in databases with different attribute information.

[0194] In some embodiments of the present application, the identification module is specifically used to:

[0195] Scanning the abstract syntax tree to obtain a syntax structure indicated by each tree node in the abstract syntax tree and a code logic of the first program code;

[0196] Matching the grammatical structure indicated by each tree node with the reference vulnerability grammatical structure in the vulnerability database, and matching the code logic of the first program code indicated by each tree node with the reference vulnerability code logic in the vulnerability database;

[0197] The grammatical structure indicated by each tree node that matches the reference vulnerability grammatical structure, and the code logic of the first program code indicated by each tree node that matches the reference vulnerability code logic are taken as the second security vulnerability set.

[0198] The large model training environment vulnerability management device in the embodiment of the present application can be an electronic device or a component in an electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal or other device other than a terminal. Exemplarily, the electronic device can be a mobile phone, a tablet computer, a laptop computer, a PDA, a car-mounted electronic device, a mobile Internet device (Mobile Internet Device, MID), an augmented reality (augmented reality, AR) / virtual reality (virtual reality, VR) device, a robot, a wearable device, an ultra-mobile personal computer (ultra-mobile personal computer, UMPC), a netbook or a personal digital assistant (personal digital assistant, PDA), etc. It can also be a server, a network attached storage (Network Attached Storage, NAS), a personal computer (personal computer, PC), a television (television, TV), a teller machine or a self-service machine, etc., and the embodiment of the present application is not specifically limited.

[0199] The large model training environment vulnerability management device in the embodiment of the present application can be a device with an operating system. The operating system can be an Android operating system, an iOS operating system, or other possible operating systems, which are not specifically limited in the embodiment of the present application.

[0200] The large model training environment vulnerability management device provided in the embodiment of the present application can achieve Figure 2 To avoid repetition, the various processes implemented in the method embodiment are not described here.

[0201] Alternatively, as Figure 6 As shown, an embodiment of the present application also provides an electronic device 600, including a processor 601 and a memory 602, wherein the memory 602 stores a program or instruction that can be run on the processor 601. When the program or instruction is executed by the processor 601, each step of the above-mentioned large model training environment vulnerability management method embodiment is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0202] It should be noted that the electronic devices in the embodiments of the present application include the mobile electronic devices and non-mobile electronic devices mentioned above.

[0203] Figure 7 A schematic diagram of the hardware structure of an electronic device implementing an embodiment of the present application.

[0204] The electronic device 700 includes but is not limited to components such as a radio frequency unit 701 , a network module 702 , an audio output unit 703 , an input unit 704 , a sensor 705 , a display unit 706 , a user input unit 707 , an interface unit 708 , a memory 709 , and a processor 710 .

[0205] Those skilled in the art will understand that the electronic device 700 may also include a power source (such as a battery) to power each component, and the power source may be logically connected to the processor 710 through a power management system, thereby implementing functions such as charging, discharging, and power consumption management through the power management system. Figure 7 The electronic device structure shown in the figure does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently, which will not be repeated here.

[0206] Among them, the processor 710 is used to parse the first program code to obtain an abstract syntax tree, where the first program code is the program code when the first training large model trains the target project; identify the first security vulnerability set existing in the training environment of the first training large model; scan the abstract syntax tree to determine the second security vulnerability set existing in the first program code; reproduce the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set respectively, and obtain a first reproduction result and a second reproduction result respectively; when the first reproduction result indicates that the security vulnerabilities in the first security vulnerability set have all been reproduced, and the second reproduction result indicates that the security vulnerabilities in the second security vulnerability set have all been reproduced, the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set are repaired respectively to obtain a second training large model.

[0207] Thus, compared to the prior art which only detects vulnerabilities in the program code of the first training large model, the solution of the embodiment of the present application also detects security vulnerabilities in the training environment of the first training large model, thereby improving the accuracy and comprehensiveness of vulnerability detection of the first training large model and ensuring the operational security of the large model training environment. After detecting security vulnerabilities in the program code and training environment of the first training large model, the security vulnerabilities are reproduced, and when it is determined that the security vulnerability reproduction is complete, the security vulnerabilities are repaired to obtain a second training large model. Thus, the security vulnerabilities of the first training large model are automatically managed through multiple levels such as detection, reproduction, and repair of security vulnerabilities in the training environment and program code of the first training large model, thereby improving the management efficiency of the security vulnerabilities of the first training large model.

[0208] Optionally, the processor 710 is further used to preprocess the first program code to obtain a preprocessed first program code, wherein the preprocessing includes: removing comments, blank lines, and formatting symbols in the first program code; and parsing the preprocessed first program code to obtain an abstract syntax tree.

[0209] In this way, by preprocessing the first program code, the subsequent conversion of the first program code into an abstract syntax tree can be avoided from being affected by comments, blank lines, and formatting symbols in the first program code, thereby improving the accuracy of converting the first program code into an abstract syntax tree.

[0210] Optionally, the processor 710 is further configured to perform word segmentation processing on the preprocessed first program code to obtain at least one word segmentation; and convert the at least one word segmentation into an abstract syntax tree with a tree structure according to the execution logic of the preprocessed first program code.

[0211] In this way, by performing word segmentation processing on the preprocessed first program code, at least one word segment is obtained, and then according to the execution logic of the preprocessed first program code, the at least one word segment is converted into an abstract syntax tree with a tree structure, so that the abstract syntax tree can be accurately obtained.

[0212] Optionally, the training environment of the first training large model includes an operating system that integrates the first training large model and an external database called during the training process of the first training large model; the processor 710 is further used to search for a first reference vulnerability that matches the operating system of the first attribute information from a vulnerability database based on the first attribute information of the operating system; search for a second reference vulnerability that matches the database of the second attribute information from the vulnerability database based on the second attribute information of the external database called during the training process of the first training large model; determine the first security vulnerability set of the training environment of the first training large model based on the first reference vulnerability and the second reference vulnerability; wherein, the vulnerability database stores vulnerabilities existing in operating systems with different attribute information and vulnerabilities existing in databases with different attribute information.

[0213] In this way, by utilizing the vulnerability database to identify the first set of security vulnerabilities existing in the training environment of the first training large model, there is no need for users to develop other vulnerability detection algorithms to detect vulnerabilities in the training environment of the first training large model, thereby improving the efficiency of determining the first set of security vulnerabilities.

[0214] Optionally, the processor 710 is further used to scan the abstract syntax tree to obtain the syntax structure indicated by each tree node in the abstract syntax tree and the code logic of the first program code; match the syntax structure indicated by each tree node with the reference vulnerability syntax structure in the vulnerability database, and match the code logic of the first program code indicated by each tree node with the reference vulnerability code logic in the vulnerability database; and use the syntax structure in the syntax structure indicated by each tree node that matches the reference vulnerability syntax structure, and the code logic of the first program code indicated by each tree node that matches the reference vulnerability code logic as the second security vulnerability set.

[0215] In this way, by scanning the abstract syntax tree, the grammatical structure indicated by each tree node in the abstract syntax tree and the code logic of the first program code indicated by each tree node are obtained, and then based on the vulnerability database, the grammatical structure indicated by each tree node and the code logic of the first program code indicated by each tree node are analyzed to see whether there are security vulnerabilities. In this way, there is no need to redevelop other vulnerability analysis algorithms to analyze whether there are security vulnerabilities in the grammatical structure indicated by each tree node and the code logic of the first program code indicated by each tree node, thereby improving the efficiency of determining the second security vulnerability set of the first program code.

[0216] It should be understood that in an embodiment of the present application, the input unit 704 may include a graphics processing unit (GPU) 7041 and a microphone 7042, and the graphics processor 7041 processes the image data of a static picture or video obtained by an image capture device (such as a color camera) in a video capture mode or an image capture mode. The display unit 706 may include a display panel 7061, and the display panel 7061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc. The user input unit 707 includes a touch panel 7071 and at least one of other input devices 7072. The touch panel 7071 is also called a touch screen. The touch panel 7071 may include two parts: a touch detection device and a touch controller. Other input devices 7072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and an operating stick, which will not be repeated here.

[0217] The memory 709 can be used to store software programs and various data. The memory 709 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, applications or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 709 may include a volatile memory or a non-volatile memory, or the memory 709 may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDRSDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchronous link dynamic random access memory (SLDRAM), and a direct memory bus random access memory (DRRAM). The memory 709 in the embodiment of the present application includes but is not limited to these and any other suitable types of memory.

[0218] Processor 710 may include one or more processing units. Optionally, processor 710 integrates an application processor and a modem processor. The application processor primarily handles operations related to the operating system, user interface, and application programs, while the modem processor primarily processes wireless communication signals, such as a baseband processor. It is understood that the modem processor may not be integrated into processor 710.

[0219] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the above-mentioned large model training environment vulnerability management method embodiment are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0220] The processor is the processor in the electronic device described in the above embodiment. The readable storage medium includes a computer readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0221] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned large model training environment vulnerability management method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0222] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.

[0223] An embodiment of the present application provides a computer program product, which is stored in a storage medium. The program product is executed by at least one processor to implement the various processes of the above-mentioned large model training environment vulnerability management method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0224] It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the statement "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, it should be noted that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the opposite order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may also be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0225] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art can be embodied in the form of a computer software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), including a number of instructions for enabling a terminal (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in each embodiment of the present application.

[0226] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.

Claims

1. A method for managing vulnerabilities in a large model training environment, characterized in that: The method comprises: Parsing the first program code to obtain an abstract syntax tree, where the first program code is the program code used when the first training model is used to train the target project; Identifying a first set of security vulnerabilities in a training environment of the first training large model; Scanning the abstract syntax tree to determine a second set of security vulnerabilities present in the first program code; Reproducing the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set, respectively, to obtain a first reproduction result and a second reproduction result; When the first reproduction result indicates that all security vulnerabilities in the first security vulnerability set have been reproduced, and the second reproduction result indicates that all security vulnerabilities in the second security vulnerability set have been reproduced, the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set are repaired respectively to obtain a second large training model.

2. The method according to claim 1, characterized in that The step of parsing the first program code to obtain an abstract syntax tree includes: Preprocessing the first program code to obtain a preprocessed first program code, wherein the preprocessing includes: removing comments, blank lines, and formatting symbols in the first program code; The preprocessed first program code is parsed to obtain the abstract syntax tree.

3. The method according to claim 2, characterized in that The step of parsing the preprocessed first program code to obtain an abstract syntax tree includes: performing word segmentation processing on the preprocessed first program code to obtain at least one word segmentation; According to the execution logic of the preprocessed first program code, at least one word segment is converted into an abstract syntax tree with a tree structure.

4. The method according to claim 1, wherein The training environment of the first training large model includes an operating system integrated with the first training large model and an external database called during the training process of the first training large model; The identifying a first set of security vulnerabilities in the training environment of the first training large model includes: searching, from a vulnerability database, for a first reference vulnerability that matches the operating system with the first attribute information according to the first attribute information of the operating system; According to the second attribute information of the external database called during the training process of the first training large model, searching the vulnerability database for a second reference vulnerability that matches the database of the second attribute information; Determining a first security vulnerability set of a training environment of the first training large model based on the first reference vulnerability and the second reference vulnerability; The vulnerability database stores vulnerabilities existing in operating systems with different attribute information and vulnerabilities existing in databases with different attribute information.

5. The method according to claim 1, characterized in that Scanning the abstract syntax tree to identify a second set of security vulnerabilities in the first program code includes: Scanning the abstract syntax tree to obtain a syntax structure indicated by each tree node in the abstract syntax tree and a code logic of the first program code; Matching the grammatical structure indicated by each tree node with a reference vulnerability grammatical structure in a vulnerability database, and matching the code logic of the first program code indicated by each tree node with a reference vulnerability code logic in the vulnerability database; The grammatical structure indicated by each tree node that matches the reference vulnerability grammatical structure, and the code logic of the first program code indicated by each tree node that matches the reference vulnerability code logic are taken as the second security vulnerability set.

6. A large model training environment vulnerability management device, characterized in that: The device comprises: A parsing module, configured to parse a first program code to obtain an abstract syntax tree, wherein the first program code is a program code used when the first training model is used to train the target project; an identification module, configured to identify a first set of security vulnerabilities existing in a training environment of the first training large model; The identification module is further configured to scan the abstract syntax tree to determine a second set of security vulnerabilities present in the first program code; A reproduction module, configured to reproduce the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set, respectively, to obtain a first reproduction result and a second reproduction result; A repair module is used to repair the security vulnerabilities in the first security vulnerability set and the security vulnerabilities in the second security vulnerability set respectively when the first reproduction result indicates that all security vulnerabilities in the first security vulnerability set have been reproduced, and the second reproduction result indicates that all security vulnerabilities in the second security vulnerability set have been reproduced, so as to obtain a second large training model.

7. The device according to claim 6, characterized in that The parsing module is specifically used for: Preprocessing the first program code to obtain a preprocessed first program code, wherein the preprocessing includes: removing comments, blank lines, and formatting symbols in the first program code; The preprocessed first program code is parsed to obtain the abstract syntax tree.

8. The device according to claim 7, characterized in that The parsing module is specifically used for: performing word segmentation processing on the preprocessed first program code to obtain at least one word segmentation; According to the execution logic of the preprocessed first program code, at least one word segment is converted into an abstract syntax tree with a tree structure.

9. The device according to claim 6, characterized in that The training environment of the first training large model includes an operating system integrated with the first training large model and an external database called during the training process of the first training large model; The identification module is specifically used for: searching, from a vulnerability database, for a first reference vulnerability that matches the operating system with the first attribute information according to the first attribute information of the operating system; According to the second attribute information of the external database called during the training process of the first training large model, searching the vulnerability database for a second reference vulnerability that matches the database of the second attribute information; Determining a first security vulnerability set of a training environment of the first training large model based on the first reference vulnerability and the second reference vulnerability; The vulnerability database stores vulnerabilities existing in operating systems with different attribute information and vulnerabilities existing in databases with different attribute information.

10. The device according to claim 6, characterized in that The identification module is specifically used for: Scanning the abstract syntax tree to obtain a syntax structure indicated by each tree node in the abstract syntax tree and a code logic of the first program code; Matching the grammatical structure indicated by each tree node with a reference vulnerability grammatical structure in a vulnerability database, and matching the code logic of the first program code indicated by each tree node with a reference vulnerability code logic in the vulnerability database; The grammatical structure indicated by each tree node that matches the reference vulnerability grammatical structure, and the code logic of the first program code indicated by each tree node that matches the reference vulnerability code logic are taken as the second security vulnerability set.