Large model security risk assessment method and system

By employing a dual-detector approach and component undirected graph matrix vectorization analysis, the problem of inaccurate security assessment of large language models and multimodal large models is solved, enabling dynamic and comprehensive risk assessment of large models and improving the accuracy and interpretability of risk detection.

CN120973564APending Publication Date: 2025-11-18BEIJING VOCATIONAL COLLEGE OF ECONOMICS & MANAGEMENT (BEIJING MANAGER COLLEGE) +1
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202511009693.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-22
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

The security assessment of large language models and multimodal large models in the existing technology lacks dynamism and comprehensiveness, and cannot accurately reflect their real-time risk status, resulting in inaccurate risk assessment.

Method used

A dual detector is used for dynamic and continuous detection. A real-time risk index is generated by combining a predetermined evaluation mechanism. The component risk coefficient is obtained through component undirected graph and matrix vectorization analysis. Finally, the real-time risk index is calibrated using the component risk coefficient.

Benefits of technology

It improves the accuracy and interpretability of risk detection for large models, enabling it to more accurately reflect the overall risk level of the model and ensure its safety in critical tasks and sensitive scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120973564A_ABST
    Figure CN120973564A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of model pre-diagnosis, and provides a security risk assessment method and system for a large model. The method comprises the following steps: activating a dual detector to dynamically detect a target model to obtain real-time detection information; analyzing the information according to an evaluation mechanism to obtain a real-time risk index; obtaining component set correlation information to form a component undirected graph; performing vectorization analysis on the component undirected graph to obtain a risk coefficient; and calibrating the real-time risk index by taking the risk coefficient as a weight to obtain a target risk index. The technical problem that in the prior art, security pre-diagnosis of a large model lacks dynamics and comprehensiveness, the risk state of the large model during operation cannot be accurately reflected, and the risk assessment of the large model is inaccurate is solved, and the effects that the association risk between the components is effectively quantified through the component undirected graph and matrix vectorization analysis, and the risk assessment accuracy is improved are achieved. And the accuracy and efficiency of large model security pre-diagnosis are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of model pre-diagnosis technology, specifically to a method and system for assessing the safety risks of large models. Background Technology

[0002] With artificial intelligence technology deeply integrated into all sectors of society, complex AI systems such as large-scale language models and multimodal models are being applied on an unprecedented scale in critical areas such as financial decision-making, autonomous driving, and medical diagnosis. As the number of parameters in these models exceeds trillions and their functional boundaries continue to expand, the coupling degree of their internal components and the complexity of their external interactions are also growing exponentially. This leads to the following shortcomings in traditional security assessment methods: on the one hand, single offline detection cannot capture real-time dynamic threats such as adversarial attacks and data drift; on the other hand, it ignores the risk transmission effect between internal components of the model, causing local vulnerabilities to be incorrectly assessed as low-risk. Therefore, to better ensure the security of large models, especially when they are applied to critical tasks or sensitive scenarios, a comprehensive, dynamic, and continuous risk assessment method is urgently needed to address the problems of lack of real-time performance and misjudgment of structural risks. Summary of the Invention

[0003] This application provides a method and system for assessing the security risks of large models, aiming to solve the technical problem that the existing technology lacks dynamism and comprehensiveness in the security pre-diagnosis of large models, and cannot accurately reflect the risk status of large models during operation, resulting in inaccurate risk assessment of large models.

[0004] The first aspect disclosed in this application provides a method for assessing the security risks of a large model. The method includes: activating a dual detector to perform dynamic and continuous detection on a target model to obtain real-time detection information; evaluating and analyzing the real-time detection information according to a predetermined evaluation mechanism to obtain a real-time risk index; acquiring the correlation information of the component set of the target model and forming an undirected graph of components based on the correlation information; performing matrix vectorization analysis on the undirected graph of components to obtain component risk coefficients; and calibrating the real-time risk index with the component risk coefficients as weights to obtain a target risk index.

[0005] Another aspect of this application discloses a security risk assessment system for a large model. The system includes: a dynamic detection module that activates dual detectors to perform dynamic and continuous detection of the target model, obtaining real-time detection information; an evaluation and analysis module that evaluates and analyzes the real-time detection information according to a predetermined evaluation mechanism, obtaining a real-time risk index; an undirected graph construction module that acquires the correlation information of the component set of the target model and forms an undirected graph of the components based on the correlation information; a vectorization module that performs matrix vectorization analysis on the undirected graph of the components, obtaining component risk coefficients; and an index calibration module that calibrates the real-time risk index using the component risk coefficients as weights, obtaining a target risk index.

[0006] One or more technical solutions provided in this application have at least the following technical effects or advantages:

[0007] The aforementioned method for assessing the security risks of large-scale models first involves continuously and dynamically monitoring the target model using dual detectors to obtain real-time detection information. Then, this information is analyzed using a predetermined evaluation mechanism to generate a real-time risk index. Next, the correlation information between the various components of the target model is acquired, and an undirected graph of the components is constructed based on this information. Then, matrix vectorization techniques are used to analyze this undirected graph to obtain the risk coefficient of each component. Finally, the real-time risk index is adjusted using these component risk coefficients as weights to obtain a more accurate target risk index, effectively improving the accuracy and interpretability of risk detection for large-scale models.

[0008] The above description is merely an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, specific embodiments of this application are given below. Attached Figure Description

[0009] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0010] Figure 1 This is a flowchart illustrating a security risk assessment method for a large model in one embodiment.

[0011] Figure 2 This is a diagram of a security risk assessment system architecture for a large model in one embodiment.

[0012] Figure labeling: Dynamic detection module 11, evaluation and analysis module 12, undirected graph construction module 13, vectorization module 14, exponential calibration module 15. Detailed Implementation

[0013] This application provides a method and system for assessing the security risks of large models, which solves the technical problem in the prior art that the security pre-diagnosis of large models lacks dynamism and comprehensiveness, cannot accurately reflect the risk status of large models during operation, and leads to inaccurate risk assessment of large models.

[0014] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0015] It should be noted that the terms “comprising” and “having”, and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or modules that are not explicitly listed or that are inherent to such process, method, product, or device.

[0016] Example 1, as Figure 1 As shown, this application provides a method for security risk assessment of large models, the method comprising:

[0017] Activate the dual detectors to perform dynamic and continuous detection on the target model and obtain real-time detection information.

[0018] In this embodiment, the dual detector consists of a code detector and a runtime detector working together. The code detector employs a static analysis engine based on Abstract Syntax Tree (AST) to scan the source code of the target model using a pre-built vulnerability pattern library (such as SQL injection and buffer overflow). The runtime detector deploys a lightweight monitoring agent (such as kernel-level eBPF hooks and framework-level Hook interfaces) to capture input data, intermediate layer activation values, and final output results during the model inference process at a preset sampling frequency (such as 1000 times per second). During the detection process, the code detection module generates static detection results including vulnerability type, line number, and original code snippet (usually stored in binary form); the runtime detection module records dynamic detection results including timestamps, resource consumption (CPU / memory usage), anomaly flags (such as the number of NaN values), abnormal input data, output data deviation, and calculation errors. Finally, by integrating these detection information to form real-time detection information, data support is provided for subsequent risk assessment, thereby ensuring that the target model will not exhibit unsafe behavior due to potential vulnerabilities or anomalies during actual operation.

[0019] The real-time detection information is evaluated and analyzed according to a predetermined evaluation mechanism to obtain a real-time risk index.

[0020] In one embodiment, after obtaining real-time detection information, code snippets and real-time runtime information are extracted from it. For the extracted code snippets, an image evaluation strategy within a predetermined evaluation mechanism is used to transform the code information and assess its risk level. For real-time runtime information related to the running status of the large model, a time evaluation strategy within the predetermined evaluation mechanism is used to analyze the performance of the large model at different time periods and assess its risk level. By weighting the analysis results of the code snippets and real-time runtime information, a comprehensive real-time risk index is obtained. This real-time risk index reflects the current overall risk level of the target model and can provide effective data support for subsequent risk management.

[0021] Furthermore, this application provides a method for evaluating and analyzing the real-time detection information according to a predetermined evaluation mechanism to obtain a real-time risk index, including:

[0022] Extract code information from the real-time detection information; invoke the image evaluation strategy in the predetermined evaluation mechanism to evaluate and analyze the code information to obtain a code risk coefficient; extract runtime information from the real-time detection information; invoke the time evaluation strategy in the predetermined evaluation mechanism to evaluate and analyze the runtime information to obtain a runtime risk coefficient; perform a variation-weighted calculation on the code risk coefficient and the runtime risk coefficient to obtain the real-time risk index.

[0023] Preferably, firstly, code snippets are extracted from the real-time detection data of the target model. These snippets can be partial source code, configuration files, runtime code segments, etc., of a large model. By storing these snippets separately, code information is obtained. Then, the image evaluation strategy in the predetermined evaluation mechanism is invoked. This strategy transforms the code information into a form suitable for image analysis, such as grayscale images or RGB images, through grayscale mapping and discrete wavelet transform. Risk features are extracted from the transformed images to calculate the code risk coefficient. In addition to code information, real-time operational information is extracted from the real-time detection data. This operational information includes multiple operational metrics of the target model during execution, such as timestamps, resource consumption, and anomaly flags, reflecting the model's performance in actual operation. Next, the time evaluation strategy in the predetermined evaluation mechanism is invoked. This strategy focuses on the model's behavior at different points in time or within a time period, assessing its stability and potential operational risks, thereby calculating the operational risk coefficient. Then, the calculated code risk coefficient is combined with the historical code risk coefficients within the most recent time window to calculate the standard deviation and mean of the code risk coefficient. The coefficient of variation for the code risk coefficient is obtained by dividing the standard deviation by the mean. The coefficient of variation for the operational risk coefficient is then calculated using the same method. Finally, the weights of the code risk coefficient and the operational risk coefficient are obtained by dividing the reciprocals of both coefficients by the sum of their reciprocals. These weights are then used to weight and sum the code risk coefficient and the operational risk coefficient to obtain the real-time risk index. This real-time risk index reflects the overall risk level of the target model in its current state, helping to determine the model's safety and providing a basis for subsequent risk management and decision-making.

[0024] Furthermore, this application provides a method for retrieving an image evaluation strategy from the predetermined evaluation mechanism to evaluate and analyze the code information, thereby obtaining a code risk coefficient, including:

[0025] The code information is converted into an unsigned integer matrix, wherein the code information is in binary code form; the unsigned integer matrix is ​​grayscale mapped to obtain a grayscale image; the grayscale image is subjected to discrete wavelet transform processing to obtain an RGB image; the RGB image is subjected to feature extraction analysis according to the image evaluation strategy to obtain image feature coefficients; the standardized result of the image feature coefficients is used as the code risk coefficient.

[0026] Optionally, when analyzing code information using an image evaluation strategy, the binary code stored in the target model is first extracted. Binary code is the basic form of computer processing programs. For further analysis and processing, the binary code is divided into groups of 8 bits, and the divided binary code is converted into unsigned decimal integers. For example, 01101001 is converted to 105. An unsigned integer matrix is ​​formed by arranging the integer sequence into a fixed-dimensional matrix (e.g., 256×256), where zeros are padded if the number of integers is insufficient. Subsequently, the unsigned integer matrix is ​​traversed to extract the largest and smallest integers. The difference between each integer and the smallest integer in the unsigned integer matrix is ​​divided by the difference between the largest and smallest integers, and the quotient is multiplied by 255 to obtain the grayscale value of each unsigned integer, thus converting the original code information into a grayscale image. Next, the obtained grayscale image is subjected to Discrete Wavelet Transform (DWT). Discrete Wavelet Transform is a signal processing method that helps extract important features and information from an image by decomposing it into low-frequency and high-frequency components. Specifically, a bioorthogonal wavelet (such as CDF 9 / 7 or db4) is used to perform a first-order wavelet decomposition on the grayscale image, obtaining approximation coefficients (LL), horizontal details (LH), vertical details (HL), and diagonal details (HH). The approximation coefficients are low-frequency components, while the horizontal, vertical, and diagonal details are high-frequency components. By mapping the approximation coefficients to the red channel, the horizontal details to the green channel, and the vertical details to the blue channel, an RGB image is formed to reveal potential patterns and anomalous features in the code. Then, feature extraction analysis is performed on the RGB image based on a predetermined image evaluation strategy. This strategy calculates an image feature coefficient by analyzing the pixel information of the RGB image and performing normalized mean processing. Finally, the standardized image feature coefficients obtained by normalizing the mean are standardized using Z-score, which transforms the image feature coefficients into standardized data with a mean of 0 and a variance of 1, forming a code risk coefficient. This code risk coefficient quantifies the potential risk level in the code, providing a basis for subsequent risk analysis.

[0027] Furthermore, this application provides a method for performing feature extraction and analysis on the RGB image according to the image evaluation strategy to obtain image feature coefficients, including:

[0028] Obtain the layering result of the RGB image; sequentially obtain the R feature value of the R layer image, the G feature value of the G layer image, and the B feature value of the B layer image in the layering result; calculate the normalized mean of the R feature value, G feature value, and B feature value according to the image evaluation strategy to obtain the image feature coefficient.

[0029] Optionally, firstly, the RGB image is decomposed into three color channels: red (R), green (G), and blue (B). This separates the red, green, and blue color components of each pixel in the RGB image, generating a separate image layer for each color channel, such as an R layer image, a G layer image, and a B layer image. These three image layers are then integrated to form a layered result, where each layer represents the intensity information of a specific color in the RGB image. Subsequently, R feature values, G feature values, and B feature values ​​are extracted from the R layer image, G layer image, and B layer image, respectively. These feature values ​​are the intensity values ​​of the corresponding colors. Next, the normalization formula in the image evaluation strategy is activated. This normalization formula corresponds to the maximum-minimum normalization method. By using the normalization formula, the dimensional differences between the R feature values, G feature values, and B feature values ​​are eliminated, making them comparable. Finally, the mean of the normalized R feature values, G feature values, and B feature values ​​is calculated to obtain the normalized feature value of each image layer. Finally, these normalized feature values ​​are weighted to calculate an image feature coefficient. This image feature coefficient represents the overall features of the RGB image, which can help assess the security of the image and provide useful information about the image structure and potential risks, and thus be used to assess the risk level of the target model.

[0030] Furthermore, this application provides a time-based evaluation strategy for retrieving the predetermined evaluation mechanism to evaluate and analyze the operational information, thereby obtaining an operational risk coefficient, including:

[0031] Obtain any operational metric and iterate through the operational information to obtain any operational data corresponding to the arbitrary operational metric; generate an arbitrary operational sequence based on the arbitrary operational data and segment the arbitrary operational sequence to obtain a set of time segments, wherein the set of time segments includes a first time segment; compare the first time segment with a predetermined arbitrary time segment to obtain a comparison deviation; if the comparison deviation reaches a predetermined deviation limit, add the first time segment to an abnormal time segment list; obtain the operational risk coefficient based on the abnormal time segment list and the set of time segments.

[0032] Optionally, when using a time-based evaluation strategy to analyze real-time operational information, a single operational indicator is first extracted sequentially from a set of operational indicators. This set of indicators includes, but is not limited to, resource usage, memory consumption, anomaly flags, response time, number of input data anomalies, output data deviation, and calculation error. The operational indicator can be any one of the indicators in the set. Then, based on the acquired operational indicator, the real-time operational information is traversed to extract the corresponding operational data. For example, if resource usage is selected as the operational indicator, resource usage information will be extracted from the operational information. Next, from the extracted operational data, this resource usage information is arranged into a runtime sequence according to time order. Then, the runtime sequence is segmented according to a preset time window (e.g., per hour, per minute), thus dividing the time-series data into multiple time segments, forming a time-series set. This time-series set includes a first time segment, a second time segment, etc., and each time segment contains operational data over a period of time, which can be used to describe the model's behavior within a specific time period. Then, the first time series segment is compared with a predetermined arbitrary time series segment. This predetermined arbitrary time series segment is the reference time series data under normal model operation, representing the expected and normal model behavior. Typically, the selected arbitrary time series segment has the same time as the time series segment to be analyzed. The difference between the two is calculated using Frazer spatial distance, yielding the comparison deviation, which measures the degree of difference between the first time series segment and the predetermined time series segment. When the comparison deviation exceeds the predetermined deviation limit, it indicates that the first time series segment exhibits an abnormal state or potential safety hazard. In this case, the first time series segment is added to the abnormal time series segment list as a marker of abnormal model behavior. Finally, the operational risk coefficient is obtained by calculating the ratio of the number of abnormal time series segments in the abnormal time series segment list to the total number of time series segments in the time series segment set. This operational risk coefficient reflects the frequency of abnormal behavior of the model during operation. A high ratio indicates that the model frequently experiences abnormalities during operation, posing a significant risk; a low ratio indicates that the model's operation is relatively stable, with a lower risk.

[0033] Furthermore, this application provides a comparison deviation degree obtained by comparing the first time segment with any predetermined time segment, including:

[0034] The first time segment and the predetermined arbitrary time segment are sequentially scatter plotted to obtain a first scatter plot and a predetermined scatter plot, respectively; the first scatter plot and the predetermined scatter plot are sequentially curve plotted to obtain a first curve and a predetermined curve, respectively; the first curve and the predetermined curve are subjected to Frazer spatial distance calculation to obtain a first Frazer distance; the first Frazer distance is normalized to obtain the comparison deviation.

[0035] Optionally, firstly, the first time series segment and the predetermined arbitrary time series segment are scatter plotted. The goal of scatter plotting is to transform the time series data into a scatter plot, so that each data point corresponds to a time point and value in the time series data. For the first time series segment, the data value of each time point is mapped to a scatter plot, resulting in the first scatter plot. Similarly, for the predetermined time series segment, it is also transformed into a scatter plot, resulting in the predetermined scatter plot. Each scatter plot represents the distribution of the time series data, which can help identify the fluctuations and trends of the time series. Subsequently, based on each scatter plot, the corresponding polynomial order is determined through cross-validation or error minimization, and the first polynomial function and the predetermined polynomial function are constructed. Then, the least squares method is used to fit the first time series segment and the predetermined arbitrary time series segment respectively, and the polynomial coefficients are solved. During the solution process, the sum of squared errors between the actual data and the fitted curve is minimized as much as possible. Through calculation, two specific polynomial curves are obtained, namely the first curve and the predetermined curve, which represent the overall trends of the first time series segment and the predetermined time series segment, respectively. Next, the Frazer distance is calculated between the first curve and the predetermined curve. Frazer distance is a method for measuring the similarity between two curves; it assesses their differences by calculating the shortest distance between them. Specifically, Euclidean distance is used to calculate the distance between two points on the curve at the same time point, and the shortest distance between all points is found, resulting in a comprehensive distance value, which serves as the first Frazer distance. This first Frazer distance reflects the similarity between the overall behavior of the first time segment and the predetermined time segment. Finally, the calculated first Frazer distance is normalized. Normalization aims to transform the Frazer distance into a standard range so that different comparison results can be compared uniformly. Normalization is typically performed by dividing the Frazer distance by the maximum possible distance. The normalized result is the comparison bias, which represents the degree of difference between the first time segment and the predetermined time segment. A higher comparison bias indicates a greater difference, potentially suggesting abnormal or unexpected model behavior; a lower comparison bias indicates a higher similarity, indicating normal model operation, thus helping to further evaluate the model's stability and safety.

[0036] Obtain the correlation information of the component set of the target model, and form an undirected graph of components based on the correlation information.

[0037] In one embodiment, firstly, the correlation information of each component in the target model is obtained. The target model typically includes multiple sub-components, such as network layers, data processing modules, and training modules. To evaluate the interactions and dependencies between these components, the correlation information between each component and other components is obtained by analyzing the data flow between components. If data is passed from component A to component B, it indicates that component A and component B are related. Subsequently, based on this correlation information, an undirected graph of the components is constructed. An undirected graph is a mathematical model in which each node represents a component, and edges represent the relationships between components. In an undirected graph, edges have no direction, meaning that the relationships are symmetric; that is, if component A is related to component B, component B is also related to component A. Ultimately, the resulting undirected graph of components not only shows the interrelationships between the components in the model but also provides important structural information for subsequent risk analysis, thereby effectively improving the model's security and stability.

[0038] Furthermore, this application provides a method for obtaining correlation information of the component set of the target model and forming an undirected graph of components based on the correlation information, including:

[0039] Extract the first component and the second component from the component set; determine whether the first component and the second component have a correlation relationship based on the correlation information; if they do, form the component undirected graph with the first component and the second component as vertices and the connecting line between the first component and the second component as edges.

[0040] Preferably, firstly, a first component and a second component are randomly extracted from the component set of the target model. Then, correlation information is used to determine the relationship between the components. If the correlation information shows that the output of the first component is used as the input of the second component, or vice versa, it indicates that there is data interaction between the two components, and thus a correlation can be determined. In this case, the first and second components are treated as two vertices, and an edge is added between them to represent their correlation. In this way, an undirected component graph can be constructed, where each node represents a component, and each edge represents the correlation between two components. This undirected component graph not only helps to understand the interaction relationships between components within the model but also provides a clear structural basis for subsequent risk assessment.

[0041] The component risk coefficient is obtained by performing matrix vectorization analysis on the undirected graph of the component.

[0042] In one embodiment, firstly, the degree matrix and adjacency matrix of the undirected graph of components are obtained. The degree matrix is ​​a diagonal matrix, where each diagonal element represents the degree of the corresponding component, i.e., the number of other components connected to that component. The adjacency matrix describes the direct connections between components, with each element indicating whether two components are connected. Next, a new matrix is ​​obtained by subtracting the degree matrix and the adjacency matrix. This matrix is ​​then subjected to eigenvalue decomposition, and the component risk index is obtained by calculating the eigenvalues. This component risk index reflects the importance and influence of the component in the undirected graph, providing a quantitative basis for subsequent risk assessment.

[0043] Furthermore, this application provides matrix-vectorized analysis of the undirected graph of the component to obtain the component risk coefficient, including:

[0044] Obtain the degree matrix and adjacency matrix of the undirected graph of the component respectively; calculate the difference between the degree matrix and the adjacency matrix to obtain the Laplacian matrix; perform eigenvalue decomposition on the Laplacian matrix to obtain the component risk coefficient.

[0045] Preferably, the degree matrix and adjacency matrix of the undirected graph of the components are first obtained. The degree matrix is ​​a diagonal matrix, where each diagonal element represents the degree of the corresponding component in the graph, that is, the number of edges that directly connect that component to other components. For example, if component A has 3 connections (associated with 3 other components), then the element corresponding to A in the degree matrix is ​​3. The adjacency matrix represents the connection relationship between the components in the graph. Each element in the matrix indicates whether there is an edge connection between two components. If there is a direct connection between component A and component B, then the element in the corresponding row and column of the adjacency matrix is ​​1; otherwise, it is 0. Next, the degree matrix and adjacency matrix are calculated to obtain the Laplacian matrix. Then, the Laplacian matrix is ​​subjected to eigenvalue decomposition, and the decomposition results are combined with vulnerability information to calculate the component risk coefficient. This provides a basis for subsequent risk assessment and security analysis, helping the system accurately identify potential risks in the model.

[0046] Furthermore, this application provides an eigenvalue decomposition of the Laplace matrix to obtain the component risk coefficient, including:

[0047] The first relevant feature value of the first component is obtained based on the Laplace matrix; the first vulnerability information in the first security defect report of the first component is extracted, wherein the first vulnerability information includes a first vulnerability type and a first vulnerability frequency; a first risk coefficient is obtained according to the first vulnerability type and the first vulnerability frequency; the product of the first relevant feature value and the first risk coefficient is recorded as the first risk index; the mean of the first risk index is taken as the component risk coefficient.

[0048] Optionally, after obtaining the Laplace matrix, the eigenvalues ​​λ and eigenvectors v of the Laplace matrix L are calculated using L·v = λ·v. Then, the eigenvalues ​​of the first component are extracted from all eigenvalues ​​as the first relevant eigenvalues. These first relevant eigenvalues ​​reflect the connection strength and stability of the component in the graph. Subsequently, the first vulnerability information related to the first component is extracted from the first security defect report of the first component, including the first vulnerability type and the first vulnerability frequency discovered during actual use. The first vulnerability type represents the type of vulnerability in the first component, such as data leakage, access control issues, buffer overflows, etc.; the first vulnerability frequency represents the frequency of a certain vulnerability in the first component occurring within a specific time period, reflecting the severity or prevalence of the vulnerability. Afterwards, the risk weight of the extracted vulnerability type is matched. Generally, the more severe the vulnerability type, the greater the risk weight. The risk weight and the first vulnerability frequency are normalized separately, and then the normalized results are multiplied to obtain the first risk coefficient. Then, the first relevant feature value is multiplied by the first risk coefficient to obtain the first risk index. This first risk index comprehensively considers the structural importance of the component in the graph and the impact of security vulnerabilities, and can accurately reflect the overall risk level of the component. If the first component has multiple types of vulnerabilities, multiple risk indices will be calculated. By adding the first risk index to other risk indices and then dividing by the number of risk indices, the component risk coefficient is obtained. This component risk coefficient represents the comprehensive risk level of the component, which can quantify its risk degree in the entire model and provide data support for subsequent risk management.

[0049] The real-time risk index is calibrated using the component risk coefficient as a weight to obtain the target risk index.

[0050] In one embodiment, the calculated real-time risk index reflects the current safety status of the model, but it does not take into account the actual importance and potential risk differences of each component within the model. To improve the accuracy of risk assessment, component risk coefficients are used as weights to calibrate the real-time risk index. This process involves weighting the real-time risk index using these component risk coefficients to obtain a target risk index. This target risk index more accurately reflects the overall safety risk level of the target model because it considers not only the model's real-time operating status but also calibrates the assessment results based on the actual importance and potential risks of each component. This allows for a more precise assessment of the model's overall risk, helping to identify and address key risk points and ensure the model's safety and stability.

[0051] In summary, the embodiments of this application have at least the following technical effects:

[0052] This application embodiment first activates a dual detector to dynamically and continuously detect the target model, obtaining real-time detection information. Then, it evaluates and analyzes the real-time detection information according to a predetermined evaluation mechanism to obtain a real-time risk index. Next, it acquires the correlation information of the component set of the target model and forms an undirected graph of the components based on this correlation information. Then, it performs matrix vectorization analysis on the undirected graph of the components to obtain component risk coefficients. Finally, it calibrates the real-time risk index using the component risk coefficients as weights to obtain the target risk index. These technical effects collectively solve the technical problems in the prior art where the safety pre-diagnosis of large models lacks dynamism and comprehensiveness, and cannot accurately reflect the risk status of large models during operation, leading to inaccurate risk assessment of large models. It achieves the technical effect of effectively quantifying the correlation risk between components through component undirected graphs and matrix vectorization analysis, improving the accuracy and efficiency of safety pre-diagnosis of large models.

[0053] Example 2, based on the same inventive concept as the large-scale model security risk assessment method in the aforementioned examples, such as... Figure 2 As shown, this application provides a security risk assessment system for a large model. The system includes: a dynamic detection module 11: activating dual detectors to perform dynamic and continuous detection on the target model to obtain real-time detection information; an evaluation and analysis module 12: evaluating and analyzing the real-time detection information according to a predetermined evaluation mechanism to obtain a real-time risk index; an undirected graph construction module 13: acquiring the correlation information of the component set of the target model and forming an undirected graph of components based on the correlation information; a vectorization module 14: performing matrix vectorization analysis on the undirected graph of components to obtain component risk coefficients; and an index calibration module 15: calibrating the real-time risk index with the component risk coefficients as weights to obtain a target risk index.

[0054] Furthermore, the evaluation and analysis module 12 is also used to perform the following methods:

[0055] Extract code information from the real-time detection information; invoke the image evaluation strategy in the predetermined evaluation mechanism to evaluate and analyze the code information to obtain a code risk coefficient; extract runtime information from the real-time detection information; invoke the time evaluation strategy in the predetermined evaluation mechanism to evaluate and analyze the runtime information to obtain a runtime risk coefficient; perform a variation-weighted calculation on the code risk coefficient and the runtime risk coefficient to obtain the real-time risk index.

[0056] Furthermore, the evaluation and analysis module 12 is also used to perform the following methods:

[0057] The code information is converted into an unsigned integer matrix, wherein the code information is in binary code form; the unsigned integer matrix is ​​grayscale mapped to obtain a grayscale image; the grayscale image is subjected to discrete wavelet transform processing to obtain an RGB image; the RGB image is subjected to feature extraction analysis according to the image evaluation strategy to obtain image feature coefficients; the standardized result of the image feature coefficients is used as the code risk coefficient.

[0058] Furthermore, the evaluation and analysis module 12 is also used to perform the following methods:

[0059] Obtain the layering result of the RGB image; sequentially obtain the R feature value of the R layer image, the G feature value of the G layer image, and the B feature value of the B layer image in the layering result; calculate the normalized mean of the R feature value, G feature value, and B feature value according to the image evaluation strategy to obtain the image feature coefficient.

[0060] Furthermore, the evaluation and analysis module 12 is also used to perform the following methods:

[0061] Obtain any operational indicator and iterate through the operational information to obtain any operational data corresponding to the arbitrary operational indicator; generate an arbitrary operational sequence based on the arbitrary operational data and segment the arbitrary operational sequence to obtain a time sequence set, wherein the time sequence set includes a first time sequence; compare the first time sequence with a predetermined arbitrary time sequence to obtain a comparison deviation; if the comparison deviation reaches a predetermined deviation limit, add the first time sequence to the abnormal time sequence list; obtain the operational risk coefficient based on the abnormal time sequence list and the time sequence set.

[0062] Furthermore, the evaluation and analysis module 12 is also used to perform the following methods:

[0063] The first time segment and the predetermined arbitrary time segment are sequentially scatter plotted to obtain a first scatter plot and a predetermined scatter plot, respectively; the first scatter plot and the predetermined scatter plot are sequentially curve plotted to obtain a first curve and a predetermined curve, respectively; the first curve and the predetermined curve are subjected to Frazer spatial distance calculation to obtain a first Frazer distance; the first Frazer distance is normalized to obtain the comparison deviation.

[0064] Furthermore, the undirected graph construction module 13 is also used to perform the following method:

[0065] Extract the first component and the second component from the component set; determine whether the first component and the second component have a correlation relationship based on the correlation information; if they do, form the component undirected graph with the first component and the second component as vertices and the connecting line between the first component and the second component as edges.

[0066] Furthermore, the vectorization module 14 is also used to perform the following method:

[0067] Obtain the degree matrix and adjacency matrix of the undirected graph of the component respectively; calculate the difference between the degree matrix and the adjacency matrix to obtain the Laplacian matrix; perform eigenvalue decomposition on the Laplacian matrix to obtain the component risk coefficient.

[0068] Furthermore, the vectorization module 14 is also used to perform the following method:

[0069] The first relevant feature value of the first component is obtained based on the Laplace matrix; the first vulnerability information in the first security defect report of the first component is extracted, wherein the first vulnerability information includes a first vulnerability type and a first vulnerability frequency; a first risk coefficient is obtained according to the first vulnerability type and the first vulnerability frequency; the product of the first relevant feature value and the first risk coefficient is recorded as the first risk index; the mean of the first risk index is taken as the component risk coefficient.

[0070] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, the above description focuses on specific embodiments of this specification. The processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing are possible or may be advantageous.

[0071] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

[0072] This specification and accompanying drawings are merely illustrative examples of this application and are intended to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from its scope. Therefore, if such modifications and modifications fall within the scope of this application and its equivalents, this application intends to include such modifications and modifications.

Claims

1. A method for security risk assessment of a large model, characterized in that, include: Activate dual detectors to perform dynamic and continuous detection of the target model and obtain real-time detection information; The real-time detection information is evaluated and analyzed according to a predetermined evaluation mechanism to obtain a real-time risk index; Obtain the correlation information of the component set of the target model, and form an undirected graph of components based on the correlation information; Matrix vectorization analysis is performed on the undirected graph of the component to obtain the component risk coefficient; The real-time risk index is calibrated using the component risk coefficient as a weight to obtain the target risk index.

2. The safety risk assessment method for a large model as described in claim 1, characterized in that, The real-time detection information is evaluated and analyzed according to a predetermined evaluation mechanism to obtain a real-time risk index, including: Extract the code information from the real-time detection information; The image evaluation strategy in the predetermined evaluation mechanism is invoked to evaluate and analyze the code information, thereby obtaining the code risk coefficient; Extract the operational information from the real-time detection information; The time assessment strategy in the predetermined assessment mechanism is retrieved to assess and analyze the operational information, thereby obtaining the operational risk coefficient. The real-time risk index is obtained by performing a variation-weighted calculation on the code risk coefficient and the runtime risk coefficient.

3. The safety risk assessment method for a large model as described in claim 2, characterized in that, The image evaluation strategy in the predetermined evaluation mechanism is invoked to evaluate and analyze the code information, resulting in a code risk coefficient, including: The code information is converted into an unsigned integer matrix, wherein the code information is in binary code form; Perform grayscale mapping on the unsigned integer matrix to obtain a grayscale image; Perform discrete wavelet transform on the grayscale image to obtain an RGB image; The RGB image is subjected to feature extraction and analysis according to the image evaluation strategy to obtain image feature coefficients; The standardized result of the image feature coefficients is used as the code risk coefficient.

4. The safety risk assessment method for a large model as described in claim 3, characterized in that, The RGB image is subjected to feature extraction and analysis according to the image evaluation strategy to obtain image feature coefficients, including: Obtain the layering results of the RGB image; The R feature value of the R layer image, the G feature value of the G layer image, and the B feature value of the B layer image are obtained sequentially in the layering result. The image feature coefficients are obtained by normalizing the mean values ​​of the R, G, and B feature values ​​according to the image evaluation strategy.

5. The method for assessing the safety risks of a large model as described in claim 2, characterized in that, The operational information is evaluated and analyzed by retrieving the time evaluation strategy from the predetermined evaluation mechanism to obtain the operational risk coefficient, including: Obtain any operational metric, and iterate through the operational information to obtain any operational data corresponding to the arbitrary operational metric; An arbitrary runtime sequence is generated based on the arbitrary runtime data, and the arbitrary runtime sequence is segmented to obtain a set of time sequence segments, wherein the set of time sequence segments includes a first time sequence segment. The comparison deviation is obtained by comparing the first time segment with any predetermined time segment; If the comparison deviation reaches the predetermined deviation limit, the first time segment is added to the list of abnormal time segments; The operational risk coefficient is obtained based on the list of abnormal time segments and the set of time segments.

6. The method for assessing the safety risks of a large model as described in claim 5, characterized in that, The comparison deviation is obtained by comparing the first time segment with any predetermined time segment, including: The first time segment and the predetermined arbitrary time segment are sequentially scattered to obtain a first scatter plot and a predetermined scatter plot, respectively. The first scatter plot and the predetermined scatter plot are sequentially processed into curves to obtain the first curve and the predetermined curve, respectively. The first Fraser distance is obtained by calculating the Fraser spatial distance between the first curve and the predetermined curve. The contrast bias is obtained by normalizing the first Fraser distance.

7. The safety risk assessment method for a large model as described in claim 1, characterized in that, Obtaining the correlation information of the component set of the target model, and forming an undirected graph of components based on the correlation information, includes: Extract the first component and the second component from the component set; Based on the correlation information, it is determined whether the first component and the second component have a correlation relationship; If so, an undirected graph of the components is formed, with the first component and the second component as vertices and the connecting line between the first component and the second component as edges.

8. The method for assessing the safety risks of a large model as described in claim 7, characterized in that, Matrix vectorization analysis is performed on the undirected graph of the component to obtain the component risk coefficient, including: Obtain the degree matrix and adjacency matrix of the undirected graph of the component, respectively; The difference between the degree matrix and the adjacency matrix is ​​calculated to obtain the Laplace matrix; The component risk coefficient is obtained by performing eigenvalue decomposition on the Laplace matrix.

9. The method for assessing the safety risks of a large model as described in claim 8, characterized in that, The component risk coefficient is obtained by performing eigenvalue decomposition on the Laplace matrix, including: The first relevant feature value of the first component is obtained based on the Laplacian matrix; Extract the first vulnerability information from the first security defect report of the first component, wherein the first vulnerability information includes the first vulnerability type and the first vulnerability frequency; A first risk coefficient is obtained based on the first vulnerability type and the first vulnerability frequency; The product of the first relevant feature value and the first risk coefficient is denoted as the first risk index; The average value of the first risk index is taken as the risk coefficient of the component.

10. A large-scale model security risk assessment system, characterized in that, The system is used to execute the security risk assessment method for a large model according to any one of claims 1-9, including: Dynamic detection module: Activates dual detectors to perform dynamic and continuous detection of the target model and obtain real-time detection information; Evaluation and analysis module: Evaluates and analyzes the real-time detection information according to a predetermined evaluation mechanism to obtain a real-time risk index; Undirected graph construction module: Obtains the correlation information of the component set of the target model, and forms an undirected graph of components based on the correlation information; Vectorization module: Performs matrix vectorization analysis on the undirected graph of the component to obtain the component risk coefficient; Index calibration module: The real-time risk index is calibrated using the component risk coefficient as a weight to obtain the target risk index.

Citation Information

Patent Citations

  • Method for automatically detecting core characteristics of malicious code

    CN107908963A

  • Data security risk assessment and management system based on large language model

    CN118194358A

  • Open source software code security and compliance control method

    CN120162794A

  • System and method for predictive risk assessment and intervention

    US20250210204A1

  • Method and system for dynamic risk assessment of software systems

    US6219805B1