Information security risk control flow processing method and system and electronic equipment
By employing a collaborative analysis method combining a streaming processing engine and a large language model on recruitment platforms, the problem of lagging information security risk control on existing recruitment platforms has been solved. This enables real-time risk identification and processing of multimodal data, improving the identification rate and timeliness.
Patent Information
- Application Number
- CN202511523022.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-23
- Publication Date
- 2026-01-13
AI Technical Summary
Existing recruitment platforms suffer from passive, lagging, and single-dimensional problems in information security risk control, making it difficult to cope with new and hidden security threats. Furthermore, existing technologies rely on the platform's keyword database and manual processing, resulting in low risk identification rates and poor timeliness.
The system employs a streaming approach for information security risk control. It receives multimodal data in real time, uses a large language model for risk analysis and identification, and combines a streaming engine to achieve real-time risk control. This includes collaborative analysis of text, images, audio, and video, and improves identification accuracy through prompt word optimization and feedback mechanisms based on the large language model.
It has improved the identification rate and timeliness of information security risks, enabled real-time classification and rapid response to various risks, reduced the workload of manual review, and enhanced the security of the recruitment platform.
Smart Images

Figure CN121329360A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network data processing technology, and in particular to an information security risk control streaming processing method, system, and electronic device. Background Technology
[0002] With the rapid development of internet technology, online recruitment has become the mainstream channel for companies to attract talent and for job seekers to find career opportunities. Recruitment platforms, through digital and intelligent means, have effectively improved the efficiency and scope of talent matching, reduced recruitment costs, and built a vital bridge connecting hundreds of millions of companies and job seekers. However, precisely because of the important role of recruitment platforms in society and the massive amount of information they contain, recruitment platforms have become key targets for attacks, thus facing various severe information security risks.
[0003] Information security risks on recruitment platforms are diverse, including: the leakage of job seekers' and companies' personal information; phishing recruitment; fake recruiters; fake job seekers; fraudulent job postings; and the buying and selling of resumes. Currently, recruitment platforms proactively protect their data security in some security risk scenarios through measures such as encrypted data transmission, server firewalls, and account password authentication. However, for risks such as phishing recruitment, fake recruiters, fake job seekers, fraudulent job postings, and the buying and selling of resumes, they mostly adopt passive measures. For example, to monitor these security risks, recruitment platforms obtain relevant risk information through reporting mechanisms, typically using keyword matching and manual methods to identify risks from this information before taking appropriate blocking actions.
[0004] Currently, only text information processing is typically supported when processing reported information, meaning that only a single data type is processed. In addition, when identifying security risks based on text information, it relies on the platform's keyword database and manual intervention, which not only increases the workload for humans, but also makes it difficult for the platform's database and rule database to be updated quickly and adapt to various risks that emerge rapidly, thus leading to the omission of risks. On the other hand, this passive security measure has poor real-time performance, and many risks can only be dealt with after the fact.
[0005] In summary, existing recruitment platforms have significant shortcomings in information security risk control, such as being passive, lagging behind, and having a single dimension, making it difficult to cope with the increasingly emerging new and covert security threats. Summary of the Invention
[0006] In response to the technical problems existing in the prior art, this invention proposes an information security risk control streaming processing method, system, and electronic device, which can effectively improve the identification rate and timeliness of security risks.
[0007] To address the aforementioned technical problems, according to one aspect of the present invention, an information security risk control streaming processing method is provided. The method is applied to a recruitment platform, which includes multiple business systems. The method includes: Real-time reception of event messages driven by preset events from business data streams from business systems, the content of which includes multimodal data; Multimodal data in event messages is processed in real-time to obtain input content for a large language model; The input content is added to the prompt words, and the prompt words are provided to the large language model; wherein, the prompt words include at least the risk type and its characteristics; The large language model performs risk analysis and identification on the input content based on the risk type and its characteristics given in the prompt words, and outputs the content risk analysis results; Based on the content risk analysis results, a risk assessment quantification value is determined for the event message content, and a risk handling strategy matching the risk assessment quantification value is determined; and The risk handling strategy is executed in real time during the streaming real-time processing of data to achieve risk control of the event.
[0008] Optionally, when the multimodal data includes two or more modalities, when performing real-time streaming processing on the multimodal data, the multimodal data are processed separately in real-time streaming to obtain the input content of their respective large language models. Correspondingly, the input content of each large language model is added to the corresponding prompt words and provided to the corresponding large language model; each large language model performs risk analysis and identification on the corresponding input content based on the corresponding prompt words, and outputs the corresponding content risk analysis sub-results. The content risk analysis results are obtained by jointly analyzing multiple content risk analysis sub-results.
[0009] Optionally, the multimodal data includes one or more of the following formats: text, images, audio, and video.
[0010] Optionally, when receiving event messages driven by pre-defined events from the business data stream of the business system in real time, the method further includes: Obtain user behavior data from the event messages on the recruitment platform; Risk features are extracted and analyzed from user behavior data based on user behavior patterns to obtain behavioral risk analysis results; The results of content risk analysis and behavioral risk analysis are combined to obtain a comprehensive risk analysis result. Correspondingly, the risk level of the event message content is determined based on the comprehensive results of the risk analysis.
[0011] Optionally, the preset event is an online chat event between a recruiter and a job seeker, and the multimodal data of the corresponding event message includes one or more of the following: text data, voice data, image data, and video data of the online chat between the recruiter and the job seeker; and / or the preset event is a reporting event, and the multimodal data of the corresponding event message includes one or more of the following: text data, voice data, image data, and video data provided by the reporter.
[0012] Optionally, the process of streaming real-time processing of multimodal data in event messages includes: Identify multimodal data types in event message content; When the multimodal data includes speech data, speech recognition is performed on the speech data to obtain text data; When the multimodal data includes video data, the video data is separated into audio and video to obtain speech data and video data; speech recognition is performed on the speech data to obtain text data; and frame extraction is performed on the video data to obtain one or more keyframe images.
[0013] Optionally, the risk assessment quantification value includes risk type and / or risk level; correspondingly, the risk handling strategy includes sending risk notifications to designated locations, real-time interception, and release.
[0014] Optionally, the method further includes: After executing the risk handling strategy, obtain feedback information on risk control of the event; Based on the feedback information, the risk assessment of the corresponding event is determined to be either a positive or negative case; wherein, when the feedback information indicates that the risk assessment of the corresponding event is incorrect or that a risk has been omitted, the risk assessment of the event is determined to be a negative case. Optimize prompt words for large language models based on negative cases.
[0015] Optionally, the prompt may also include judgment examples corresponding to the risk type, and / or exemption examples corresponding to the characteristics of the risk type.
[0016] According to another aspect of the present invention, an information security risk control streaming processing system is provided, the system comprising: The data input module is configured to receive event messages driven by preset events from the business data stream of the business system in real time, and the event message content includes multimodal data; The streaming computing module is configured to perform real-time streaming processing of multimodal data in event messages to obtain input content for the large language model; A risk perception module is configured to add the input content to prompt words and provide the prompt words to a large language model; wherein the prompt words include at least risk types and their characteristics; the large language model performs risk analysis and identification on the input content based on the risk types and characteristics given in the prompt words, and outputs the content risk analysis results; The risk decision-making module is configured to determine a quantitative risk assessment value for the event message content based on content risk analysis results, and to determine a risk handling strategy matching the quantitative risk assessment value; and The risk control processing module is configured to execute the risk processing strategy in real time during the streaming real-time data processing to achieve risk control of the event.
[0017] Optionally, the system further includes an optimization module configured to collect negative cases based on event risk control feedback information, wherein when the event risk control feedback information is a risk assessment error or risk omission, the risk assessment of the event is determined as a negative case; and the prompt words of the large language model are optimized based on the negative cases.
[0018] According to another aspect of the present invention, an electronic device is provided, including a processor and a memory, wherein a set of computer program instructions is stored in the memory, and the aforementioned information security risk control streaming processing method is implemented when the processor executes the set of computer program instructions in the memory.
[0019] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein a computer program instruction set is stored on the computer-readable storage medium, and the computer program instruction set, when executed by a processor, implements the aforementioned information security risk control streaming processing method.
[0020] According to another aspect of the present invention, a computer program product is provided, which includes a computer program instruction set, which, when executed by a processor, implements the aforementioned information security risk control streaming processing method.
[0021] In summary, this invention effectively improves the identification rate and timeliness of information security risks through the information security risk control streaming processing method and system, enables the classification and processing of various risks, and allows for real-time risk processing. Attached Figure Description
[0022] The preferred embodiments of the present invention will now be described in further detail with reference to the accompanying drawings, wherein: Figure 1 This is a flowchart of an information security risk control streaming processing method according to an embodiment of the present invention; Figure 2This is a flowchart of a method for real-time processing of multimodal data in event messages according to an embodiment of the present invention; Figure 3 This is a flowchart of a method for constructing risk types and their characteristics according to an embodiment of the present invention; Figure 4 This is a schematic diagram of the content structure of a large model prompt text according to an embodiment of the present invention; Figure 5 This is a flowchart of a method for determining risk using a large language model according to an embodiment of the present invention; Figure 6 This is a flowchart of a method for determining risk using a large language model according to another embodiment of the present invention; Figure 7 This is a flowchart of an optimization of prompt words for a large language model according to an embodiment of the present invention; Figure 8 This is a block diagram illustrating the principle of an information security risk control streaming processing system according to an embodiment of the present invention; and Figure 9 This is a schematic diagram of the hardware structure of an electronic device according to an embodiment of the present invention. Detailed Implementation
[0023] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0024] In the following detailed description, reference can be made to the accompanying drawings, which form part of this application and illustrate specific embodiments of the present application. In the drawings, similar reference numerals describe substantially similar components in different figures. Specific embodiments of the present application are described in sufficient detail below to enable those skilled in the art to implement the technical solutions of the present application. It should be understood that other embodiments may also be utilized, or structural, logical, or electrical changes may be made to the embodiments of the present application.
[0025] This invention provides an information security risk control streaming processing method and system applied to a recruitment platform. The recruitment platform includes various systems, such as an information security risk control streaming processing system for implementing the information security risk control streaming processing method, a business system for implementing different business operations, a data computing system for implementing various calculations, and a management and monitoring system, etc. These systems are connected through interfaces to transmit data or information as needed.
[0026] See Figure 1 , Figure 1 This is a flowchart of an information security risk control streaming processing method according to an embodiment of the present invention, the method comprising the following steps: Step S10: Receive event messages from the business data stream of the business system in real time, driven by preset events. The content of the event messages includes multimodal data.
[0027] Step S11: Perform real-time streaming processing on the multimodal data in the event message to obtain the input content provided to the large language model.
[0028] Step S12: Add the input content to the prompt words and provide the prompt words to the large language model; wherein the prompt words include at least the risk type and its characteristics.
[0029] Step S13: The large language model performs risk analysis and identification on the input content based on the risk type and its characteristics given in the prompt words, and outputs the content risk analysis results.
[0030] Step S14: Determine the risk assessment quantification value of the event message content based on the content risk analysis results, and determine the risk handling strategy that matches the risk assessment quantification value.
[0031] Step S15: During the real-time streaming processing of data, the risk handling strategy is executed in real time to achieve risk control of the event.
[0032] To improve the real-time performance of data processing, the recruitment platform of this invention employs a streaming engine for real-time data processing. Examples of streaming engines include Apache Flink (a streaming engine for distributed data processing), Apache Kafka Streams (a library for building streaming applications within Apache Kafka), Apache Spark (a streaming engine for large-scale data processing), Apache Storm (a streaming engine for distributed architectures), and Amazon Kinesis (a cloud-based streaming engine provided by Amazon). The streaming engine tracks and processes the business data streams of the business system. In this invention, to achieve information security risk control, a messaging mechanism is used to subscribe to messages in the business system requiring risk control. When a driving event set when the subscribed message occurs in the business system, a corresponding event message is generated, which serves as a type of data in the business data stream. In this invention, the format of the event message can be any format, such as JSON, XML, or a custom format.
[0033] Upon receiving an event message in step S10, the message content is extracted from the event message. The message content can be in the format of any one or more of text data, image data, audio data, and video data. The data processed by this invention is not limited to text data, but can process multimodal data such as images, audio, and video, thereby improving the identification rate of various risks.
[0034] In step S11, in order to facilitate the processing and understanding of the large language model, the multimodal data in the event message is processed accordingly.
[0035] See Figure 2 , Figure 2 This is a flowchart of a method for real-time processing of multimodal data in event messages according to an embodiment of the present invention. In this embodiment, the method for real-time processing of multimodal data includes the following steps: Step S110: Identify the multimodal data type in the event message content. For example, when the event message content is represented by text, symbols, etc., it is identified as text data, and step S111 is executed. When the event message content is represented by storage address, link, etc., the corresponding file is read according to the storage address or link, and the data type is determined according to the file extension. For example, when the file extension is jpg, bmp, png, tif, gif, etc., the multimodal data is identified as an image, and step S112 is executed. When the file extension is mp3, wav, aac, flac, ogg, etc., the multimodal data is identified as audio, and step S113 is executed. When the file extension is MP4, AVI, MOV, WMV, MKV, etc., the multimodal data is identified as video, and step S114 is executed.
[0036] Step S111: The text data is processed into text data in a preset format, and the preset format text data is used as input content for the large language model.
[0037] Step S112: Use the storage address of the image file as input to the large language model.
[0038] Step S113: Perform speech recognition on the audio data to obtain text data, and then execute step S111.
[0039] Step S114: Perform audio-visual separation on the video data to obtain audio data and video data. Then, proceed to step S113.
[0040] Step S115: Perform frame extraction on the video data to obtain one or more keyframe images.
[0041] Step S116: Store the keyframe image in a specified location and record the storage address. The storage address is then used as input content for the large language model.
[0042] The preset format in step S111 is an easily understandable or interpretable format, such as JSON or a custom format. For example, when the business system is an online chat system, the preset driving event is an online chat event between a recruiter and a job seeker. The corresponding event message includes the online chat text data between the recruiter and the job seeker. This text data is then processed into JSON format: {"hr_mail":"email address", "chat_content":[sender ID|chat content, sender ID|chat content, ...]}. The online chat text data includes two parts: the HR email address and the chat content. Each part is separated by a colon ":", with the name before the colon and the corresponding specific value after the colon. The first part is the HR email address, and the second part is the chat content. In the second part, "chat_content" is the name of the chat content, followed by the specific chat content, which includes multiple components. Each component represents the chat content sent by a participant. The participant and their content are separated by the symbol "|", with the sender ID before the separator and the specific chat content after the separator. In one embodiment, the sender ID represents job seekers and recruiters using different symbols. For example, the sender ID consists of a suffix or prefix that distinguishes the two identities and the sender's ID on the platform.
[0043] In step S113, during speech recognition of the audio data, the speech data is converted into text data using a speech recognition model. The speech recognition model can be based on any functional module of a speech recognition technology or a speech recognition service interface provided by a third-party system. For example, the speech recognition model could be a deep learning model deployed on a recruitment platform that uses neural networks for speech feature extraction and classification, or a large language model deployed on a recruitment platform. Those skilled in the art can choose any speech recognition model to obtain the chat text data as needed.
[0044] In step S115, when performing frame extraction processing on the video data, in one embodiment, video frames can be extracted frame by frame, and then frame-by-frame comparative analysis can be performed to filter out blurry or repetitive video frames, retaining clear video frames with different content as keyframes, and storing them as image files respectively. In another embodiment, video frames are extracted from the beginning of the video according to a set time window, for example, one video frame is extracted every 1 second, or two video frames are extracted every 1 second. In a further embodiment, the size of the time window and the number of video frames extracted in each time window are determined according to the video duration. For example, for a 5-second video, the relationship between the time window t and the video duration T can be t / T = 1 / 10 to 1 / 5, and one video frame is extracted in each time window.
[0045] In this embodiment, the prompt text is generated through prompt text engineering. The prompt text includes the following categories: role definition, given risk type and its characteristics, task requirement description, and output requirement description. Among these, the risk type and its characteristics are key components for the large language model to analyze the input content. This invention extracts various risk types and corresponding features from historical risk control events through feature engineering and adds these risk types and their features to the prompt text.
[0046] See Figure 3 , Figure 3 This is a flowchart illustrating a method for constructing risk types and their characteristics according to an embodiment of the present invention. It includes the following steps: Step S20: Collect historical data of pre-set events from the recruitment platform. Pre-set events include, for example, online chat events between recruiters and job seekers, and reports from job seekers. Historical data of pre-set events includes, for example, chat content data, report content data, and risk handling data of these events from online chat events that occurred within a certain historical period. The risk handling data includes, for example, the assessed risk type and a description of the risk's cause.
[0047] Step S21: Based on the risk handling results of the recruitment platform event content, the historical data is divided into risky datasets and risk-free datasets.
[0048] Step S22: Extract risk types from the risky dataset, and simultaneously extract risk feature descriptions, corresponding risk examples, and keywords from the risk cause descriptions and content data. For example, for online chat events, the risk types extracted from the content data might be "inducing users to follow a public account / join a QQ group / download an app / add a DingTalk account." Online chat events also include email risk types. Risk feature descriptions might include phrases like "join the group," "must follow the xx service account," and "uncommon app name." Risk examples might include "Hello, if you're interested, you can add the QQ group below to learn more: 622 375 807." Keywords might include "our company's QQ," "QQ group," "must follow," "must join the group," "video account," and "small shop." For reporting events, the risk types extracted from the content data might be "brushing orders," "charging xx fees," and "credit fraud." Risk feature descriptions might include phrases like "brushing performance," "requiring xx fees," "out-of-pocket expenses," and "loans." Risk examples might include "tricked into taking out a xx loan and then they collect the money." Risk characteristics of email risk types include, for example, text before the @ symbol consisting of a random mix of English letters and numbers.
[0049] Step S23: Based on the risk feature description, traverse the risk-free dataset and determine exemption examples that include risk features from the risk-free dataset. For example, for online chat events, exemption examples might be "I'll add you to the group to chat with the technical manager in detail" or "I'll explain the work content to everyone in the group." For whistleblowing events, exemption examples might be "Guiding you to add me on WeChat" or "Inducing you to participate in training and assessment."
[0050] Step S24 involves a comprehensive analysis of risk examples and exemption examples to derive risk definitions and exemption principle descriptions. For instance, regarding the risk type "inducing users to follow a public account / join a QQ group / download an app / add a DingTalk account" in online chat events, the risk definition is, for example, "only the four behaviors of requiring users to follow a public account, join a QQ group, download an app, or add a DingTalk account are considered risky." The exemption principle description is, for example, "requiring job seekers to add personal WeChat accounts multiple times or once, add personal (including customer service) QQ numbers, or provide specific QQ numbers or WeChat IDs for the purpose of establishing normal contact are all considered normal conversations."
[0051] Regarding the risk type "brushing" in the reported incidents, its risk definition is, for example, "explicitly mentioning brushing, boosting sales, or boosting positive reviews." The exemption principle is described, for example, as "only involving boosting performance or recruiting others does not fall under this risk type."
[0052] It should be understood that the aforementioned risk types, feature descriptions, keywords, risk examples, exemption examples, etc., are merely examples of mining types when performing feature mining on a certain type of risk in this embodiment. When applying the aforementioned method of this invention to perform feature mining, the art can obtain any one or more of the above-mentioned types of data, or other types of data not listed, depending on the circumstances.
[0053] Once data such as the risk type and characteristics of the pre-defined events, keywords, and exemption examples are obtained, a large-scale model of prompt words is constructed. (See also...) Figure 4 , Figure 4 This is a schematic diagram of the content structure of a large language model prompt text according to an embodiment of the present invention. The prompt text includes the following content modules: role definition, risk type, risk definition, risk example, exemption principle / example, task requirement description, input content, output requirement description, etc. The present invention includes risk type and risk definition (which describes the features used to define the risk type) in the prompt text, and provides risk examples, normal examples, and exemption principles / examples, thereby enabling the large language model to better complete the risk assessment task. In a better embodiment, the output requirement description provides output instructions for different risk assessment situations. For example, different fields are given in the output requirements, such as a risk field, a risk type field, and a judgment reason field. The risk field indicates whether a risk has been identified, usually represented by characters or numbers; for example, 0 indicates no risk, 1 indicates risk, and 2 indicates suspected risk. The content of the risk type field corresponds to the content of the risk field; when the risk field indicates no risk, the risk type field is blank. When the risk field indicates a risk, the risk type field specifies the exact risk type, such as "inducing followers to follow a public account / join a QQ group / download an app / add a DingTalk account" or "brushing orders," as mentioned earlier. Correspondingly, the judgment reason field provides the basis for determining the risk type. When the risk field indicates a suspected risk, the risk type field specifies the exact risk type, and the judgment reason field provides the basis for determining the risk type. This basis includes explanations for determining the risk type and explanations for situations where the determination is not entirely certain. The task requirement description section can include multiple sub-sections, such as work instructions, judgment rules, and thought processes.
[0054] In one embodiment, the prompt text can be stored as a template, with different templates corresponding to different events. After receiving the input content, the corresponding prompt template is invoked, and the input content is added to the input content section of the template. By pre-setting the prompt templates, the prompt text can be quickly obtained and provided to the large language model during real-time streaming processing.
[0055] The large language model in this invention can be either a large language model that has been trained and deployed to a recruitment platform, or a large language model provided by a third-party platform, such as the GPT series (OpenAI), the Claude series (Anthropic) model, the Llama series (Meta) model, Wenxin Yiyan (Baidu), Tongyi Qianwen (Alibaba Cloud), the Gemini series (Google DeepMind), and DeepSeek-R1 (DeepSeek), etc. Those skilled in the art can choose any model according to actual needs and usage habits.
[0056] In one embodiment, before being deployed, the large language model of this invention undergoes adversarial training using sample data, which includes both positive and negative samples. This invention balances the positive and negative samples and reduces risky data within the positive samples, thereby improving the model's accuracy through adversarial training. Furthermore, during training, the return result format of the large model can be optimized to ensure the accuracy and consistency of parsing.
[0057] When put into use, the large language model analyzes and logically infers from the prompt word text to obtain content risk analysis results.
[0058] See you again Figure 1After obtaining the content risk analysis results for the preset events, in order to improve the readability of the content risk analysis results and facilitate the matching of risk handling strategies, in step S14, the risk judgment quantification value of the event message content is determined based on the content risk analysis results. In one embodiment, the risk judgment quantification value is, for example, a specific risk type; in another embodiment, the risk judgment quantification value includes not only the risk type but also the risk level. The configuration file matches corresponding risk levels for different risk types or combinations of risk types. In one embodiment, the risk level is divided into three levels, from low to high, corresponding to "normal," "suspected," and "high risk." Corresponding risk handling strategies are matched for different risk levels. For example, the risk handling strategies include sending risk notifications to designated locations, real-time interception, and release. The lowest risk level, representing "normal," corresponds to release (i.e., no processing); the risk level, representing "suspected," corresponds to sending risk notifications to designated locations, such as sending emails, SMS messages, or system notifications to designated risk assessment staff to prompt manual review; and the risk level, representing "high risk," corresponds to real-time interception, such as synchronously linking with the business system, which then implements the corresponding real-time interception function. For example, when monitoring the information risk of an HR's online chat, if it is determined that there is a risk type of "inducing people to follow public accounts / join QQ groups / download apps", and this risk type corresponds to a high-risk level, the online chat system will stop the online chat and freeze the HR's member account to prevent security issues from occurring.
[0059] This invention enables collaborative analysis of multimodal risk data, including text, images, audio, and video, and accurate identification of security risk types, overcoming the limitations of single-modal processing in traditional systems. Through a streaming processing framework and messaging mechanism, this invention achieves real-time processing of pre-defined events, controlling risk handling delays to the second level, meeting real-time interception requirements, and reversing the "passive defense" situation in existing technologies. Utilizing the semantic understanding, context awareness, and dynamic adaptation capabilities of large language models, this invention can quickly identify fraudulent rhetoric and image-based risk traces.
[0060] To reduce the illusion of large language models, in addition to giving specific restrictions in the prompt text, such as "only identification and judgment according to the given risk type is allowed, and the generation of risk types outside the given range is absolutely not allowed", in another embodiment, the same number of large language models are used to process the corresponding modal data for the number of modalities in the event message content.
[0061] See Figure 5 , Figure 5This is a flowchart of a method for risk assessment using large language models according to an embodiment of the present invention. In this embodiment, the system provides four large language models, which are used to analyze and identify risks in text, image, audio, and video event content, respectively. The method specifically includes the following steps: Step S310: Identify the multimodal data type in the event message content. When the event message content is represented by text, symbols, etc., it is identified as text data, and step S311 is executed. When the event message content is represented by storage address, link, etc., the corresponding file is read according to the storage address or link, and the data type is determined according to the file extension. When the file extension indicates an image storage format, the multimodal data is identified as an image, and step S331 is executed. When the file extension is an audio storage format, the multimodal data is identified as audio, and step S341 is executed. When the file extension is a video storage format, the multimodal data is identified as video, and step S351 is executed.
[0062] Step S311: The text data is processed into text data in a preset format, and the preset format text data is used as input content for the large language model.
[0063] Step S312: Generate the first prompt word. For example, call the prompt word template that provides text input, add the input content to the prompt word template, and thus obtain the first prompt word.
[0064] Step S313: The first prompt word is provided to the first large language model. The first large language model performs risk analysis and identification on the input content based on the first prompt word and obtains the first analysis sub-result.
[0065] Step S331: Use the storage address of the image file as input to the large language model.
[0066] Step S332: Generate a second prompt word. For example, call the prompt word template that provides image input, and add the input to the prompt word template to obtain the second prompt word.
[0067] Step S333: The second prompt word is provided to the second language model. The second language model performs risk analysis and identification on the input content based on the second prompt word and obtains the second analysis sub-result.
[0068] Step S341: Use the storage address of the audio file as input to the large language model.
[0069] Step S342: Generate a third prompt word. For example, call the prompt word template that provides audio input, and add the input to the prompt word template to obtain the third prompt word.
[0070] Step S343: The third prompt word is provided to the third language model. The third language model performs risk analysis and identification on the input content based on the third prompt word and obtains the third analysis sub-result.
[0071] Step S351: Use the storage address of the video file as input to the large language model.
[0072] Step S352: Generate the fourth prompt word. For example, call the prompt word template that provides video input, and add the input to the prompt word template to obtain the fourth prompt word.
[0073] Step S353: The fourth prompt word is provided to the fourth language model. The fourth language model performs risk analysis and identification on the input content based on the fourth prompt word and obtains the fourth analysis sub-result.
[0074] If the multimodal data includes only one modality, the analysis sub-result obtained from the corresponding large language model is used as the final content risk analysis result. If the multimodal data includes two or more modalities, the analysis sub-results obtained from each large language model are jointly analyzed. For example, in this embodiment, four modalities are included, so in step S360, the analysis sub-results obtained from each large language model are jointly analyzed to obtain the content risk analysis result. This embodiment, by designing prompt word templates for different data types, can effectively reduce the steps in generating prompt words and fully utilize the processing advantages of different large language models for different types of data. The large model directly processes various modalities, reducing intermediate processing steps and further improving processing speed.
[0075] In another embodiment, multimodal data processing can be applied to text-type input content and image-type input content, such as... Figure 2 As shown, after Figure 2 The system processes audio into text and video into text and images. It pre-stores prompt templates for text input and image input. The system calls the corresponding templates, adds input content, and then provides these templates to the large language models processing text and images, respectively. This results in two sub-analysis results, which are then jointly analyzed to obtain the final content risk analysis result. This embodiment only requires designing two types of prompt templates, reducing the design task and avoiding the impact of improper prompt content design on the accuracy of audio and video data processing.
[0076] See Figure 6 , Figure 6This is a flowchart of a method for determining risk using a large language model according to another embodiment of the present invention. In this embodiment, in addition to risk analysis of the event content, risk analysis of the behavior of the users involved in the event is also performed. Steps S40, S411, S421, and S431 are respectively related to... Figure 1 Steps S10, S11, S12, and S13 are similar and will not be repeated here. After obtaining the event message in step S40, while processing the multimodal data in the event message in step S411, step S412 is executed to obtain the user behavior data in the event message from the recruitment platform. For example, based on the HR user ID in the online chat event message, one or more user behaviors during that period are obtained based on a preset time window, and a user behavior sequence is established in chronological order. The user behaviors include logging into the recruitment platform, enterprise authentication, posting job information, and the number of times online communication invitations are sent to job seekers. Alternatively, based on the user ID involved in the reported event (such as the user ID of the enterprise HR), the number of times the user has been reported, the number of invitations submitted, the active IP city, the number of times the mobile phone number has been viewed, etc., can be queried. This embodiment has preset user behavior patterns with security risks, such as: the number of times online communication invitations to job seekers are sent to job seekers exceeding a threshold within a preset time period, the number of job information posted exceeding a threshold within a preset time period, the number of invitations submitted exceeding a threshold, etc. These behavior patterns indicate certain risks, such as fake recruitment and illegal collection of job seekers' resumes. In step S422, when extracting and analyzing risk features from user behavior data, the risk features include, for example, the number of job postings and the number of invitations submitted. Based on these features, the user behavior sequence is compared with preset risky user behavior patterns. If the user's behavior matches these risky behavior patterns, it is determined to be risky; otherwise, it is confirmed to be risk-free. Alternatively, if a user's behavior does not match a certain risky behavior pattern but has multiple behaviors that are close to the risky behavior pattern, it is confirmed as a suspected risk. The behavioral risk analysis results include a risk description, such as "risky," "no risk," or "suspected risk," along with a description of the reasons for identifying these risks. For example, when the risk description is "risky," the corresponding behavior is recorded in the reason description, such as the aforementioned risky behavior pattern of exceeding a threshold in the number of invitations submitted.
[0077] Then, in step S44, the content risk analysis results and behavioral risk analysis results are jointly analyzed to obtain a comprehensive risk analysis result. The joint analysis in this embodiment, as well as in the aforementioned embodiments, typically refers to statistically analyzing, merging, and combining the risk types obtained to obtain further analysis results. For example, for an online chat event, the content risk analysis result is no risk because the online chat duration is short and no suspicious keywords were found. However, the behavioral risk analysis result shows that the HR user invited more than the threshold number of applications within a short period, and the duration of each online chat event was less than the threshold, thus determining that the user's behavior poses a risk. Therefore, combining these two analysis results still confirms that the event has a certain risk. In one embodiment, when neither type of analysis result indicates risk, the event is confirmed to be risk-free; if only one type of analysis result indicates risk, it is confirmed as a suspected risk; if both types of analysis results indicate risk, the event is confirmed to be risky.
[0078] In analyzing whether an event poses a risk, this embodiment also references user behavior data, making full use of the abundant data in the recruitment platform to supplement the security risk analysis of independent events, thereby improving the risk identification rate.
[0079] See Figure 7 , Figure 7 This is a flowchart of an optimization process for prompt words in a large language model according to an embodiment of the present invention. In this embodiment, after executing the risk handling strategy for an event, the following processing is performed: Step S50: Obtain feedback information for risk control of the event. This invention records the risk analysis results and implemented control strategies for each event, and establishes feedback channels. For example, a list of event risk control results is stored in a database, recording each event, its corresponding risk assessment, implemented control strategies, and feedback data. Relevant personnel provide feedback information on these events periodically or irregularly. For example, for cases initially deemed risk-free but actually identified as risky, an error in assessment is marked, and the specific risk type and reason are recorded. For events where real-time interception has been implemented but confirmed to be risk-free, an error in assessment is marked, and the specific reason is recorded. Furthermore, for suspected risks, after manual review to determine their risk level, specific risk information is marked.
[0080] Step S51: Determine the category of the risk assessment case for the corresponding event based on the feedback information. Cases where the feedback information matches the assessment result are positive; otherwise, they are negative. If the risk assessment for the corresponding event is incorrect or omitted, the risk assessment for that event is a negative case.
[0081] Step S52: Determine if it is a negative case. If it is, proceed to step S53. If not, end the current optimization process.
[0082] Step S53: Optimize the prompt words of the large language model based on negative cases, and end the optimization process after optimization. During the optimization of prompt words, for example, the risk characteristics of the prompt words are modified based on the content of the feedback information, exemption examples are added, risk examples are added, and judgment rules are revised, etc., enabling rapid iteration of the rules.
[0083] Although this embodiment is an optimization performed after risk control of an event has been completed, it is understood that the optimization can be performed at any time, and multiple negative cases can be used during the optimization. In one embodiment, negative cases are collected in real time, and the prompt words are dynamically adjusted and optimized periodically. In a further embodiment, before the prompt words are optimized and submitted for use, they are manually reviewed by relevant personnel to ensure the accuracy of the optimized prompt words.
[0084] This invention achieves closed-loop optimization feedback for risk control, feeding negative cases back into the prompt words and judgment rule system. Through incremental learning and prompt word iteration, the system achieves dynamic evolution, thereby improving the accuracy of risk identification and reducing the workload of manual review.
[0085] See Figure 8 , Figure 8 This is a block diagram illustrating the principle of an information security risk control streaming processing system according to an embodiment of the present invention. The system includes a data input module 100, a streaming computing module 200, a risk perception module 300, a risk decision module 400, and a risk control processing module 500. The data input module 100 receives event messages driven by preset events from the business data stream of the business system in real time. The event message content includes multimodal data. The streaming computing module 200 performs real-time streaming processing on the multimodal data in the event messages to obtain input content for a large language model. The risk perception module 300 adds the input content to prompts and provides the prompts to the large language model; wherein the prompts include at least risk types and their characteristics; the large language model performs risk analysis and identification on the input content based on the risk types and characteristics given in the prompts, and outputs the content risk analysis results. The risk decision module 400 determines the risk assessment quantification value of the event message content based on the content risk analysis results, and determines a risk handling strategy matching the risk assessment quantification value. The risk control processing module 500 executes the risk handling strategy in real time during the streaming real-time data processing to achieve risk control of the event. The specific processing procedures and details of each module are described in the corresponding descriptions of the aforementioned method, and will not be repeated here.
[0086] Figure 9 This is a schematic diagram of the hardware structure of an electronic device according to an embodiment of the present invention. The electronic device can be implemented as a server or other various terminal devices, such as desktop personal computers, tablet computers, laptop computers, mobile phones, etc., including a processor 601 and a memory 602. The memory 602 stores a program instruction set, and the aforementioned information security risk control streaming processing method is implemented when the processor 601 executes the program instruction set in the memory 602.
[0087] Specifically, the processor 601 may include a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of the present invention.
[0088] Memory 602 may include mass storage for data or instructions. For example, and not limitingly, memory 602 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 602 may include removable or non-removable (or fixed) media. Where appropriate, memory 602 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 602 is non-volatile solid-state memory.
[0089] The memory may include read-only memory (ROM), random access memory (RAM), disk storage media devices, optical storage media devices, flash memory devices, and electrical, optical, or other physical / tangible memory storage devices. Therefore, typically, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the information security risk control streaming processing method provided by this invention.
[0090] In one example, the electronic device may also include a communication interface 603 and a bus 604. The processor 601, memory 602, and communication interface 603 are connected via the bus 604 and communicate with each other.
[0091] The communication interface 603 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of the present invention.
[0092] Bus 604 includes hardware, software, or both, that couples components of an online data traffic metering device together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 604 may include one or more buses. While specific buses are described and illustrated in embodiments of the invention, the invention contemplates any suitable bus or interconnect.
[0093] The present invention also provides a computer-readable storage medium storing computer program instructions thereon, which, when executed by a processor, implement any of the information security risk control streaming processing methods described in the foregoing embodiments. The computer-readable storage medium can be any tangible medium that contains or stores computer-executable instructions for use by or in conjunction with an instruction execution system, apparatus, or device. The storage medium can be a transient computer-readable storage medium or a non-transitory computer-readable storage medium. Non-transitory computer-readable storage media may include, but are not limited to, magnetic storage devices, optical storage devices, and / or semiconductor storage devices. Examples of such storage devices include, for example, magnetic disks, optical discs based on CD, DVD, or Blu-ray technology, and persistent solid-state storage such as flash memory and solid-state drives.
[0094] This invention also provides a computer program product, comprising a set of computer program instructions, which, when executed by a processor, implement any of the information security risk control streaming processing methods described in the foregoing embodiments. The computer program product includes, but is not limited to, application installation packages published on websites and in app stores, application plugins, and mini-programs that can run within certain applications.
[0095] It should be clarified that the present invention is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present invention is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of the present invention.
[0096] The above embodiments are for illustrative purposes only and are not intended to limit the invention. Those skilled in the art can make various changes and modifications without departing from the scope of the invention. Therefore, all equivalent technical solutions should also fall within the scope of the invention.
Claims
1. A streaming method for information security risk control, the method being applied to a recruitment platform, the recruitment platform comprising multiple business systems, characterized in that, The method includes: Real-time reception of event messages driven by preset events from business data streams from business systems, the content of which includes multimodal data; Multimodal data in event messages is processed in real-time to obtain input content for a large language model; The input content is added to the prompt words, and the prompt words are provided to the large language model; wherein, the prompt words include at least the risk type and its characteristics; The large language model performs risk analysis and identification on the input content based on the risk type and its characteristics given in the prompt words, and outputs the content risk analysis results; Based on the content risk analysis results, a risk assessment quantification value is determined for the event message content, and a risk handling strategy matching the risk assessment quantification value is determined; and The risk handling strategy is executed in real time during the streaming real-time processing of data to achieve risk control of the event.
2. The method according to claim 1, characterized in that, When the multimodal data includes two or more modalities, during the real-time streaming processing of the multimodal data, the multimodal data are processed separately in real-time streaming to obtain the input content of the corresponding large language model. Correspondingly, the input content of each large language model is added to the corresponding prompt words and provided to the corresponding large language model; each large language model performs risk analysis and identification on the corresponding input content based on the corresponding prompt words, and outputs the corresponding content risk analysis sub-results. The content risk analysis results are obtained by jointly analyzing multiple content risk analysis sub-results.
3. The method according to claim 1 or 2, characterized in that, The multimodal data includes one or more of the following formats: text, image, audio, and video.
4. The method according to claim 1 or 2, characterized in that, When receiving event messages driven by pre-defined events in real-time from the business data stream from the business system, it further includes: Obtain user behavior data from the event messages on the recruitment platform; Risk features are extracted and analyzed from user behavior data based on user behavior patterns to obtain behavioral risk analysis results; The results of content risk analysis and behavioral risk analysis are combined to obtain a comprehensive risk analysis result. Correspondingly, the risk level of the event message content is determined based on the comprehensive results of the risk analysis.
5. The method according to claim 1, characterized in that, The preset event is an online chat event between a recruiter and a job seeker, and the multimodal data of the corresponding event message includes one or more of the following: text data, voice data, image data, and video data of the online chat between the recruiter and the job seeker; and / or the preset event is a reporting event, and the multimodal data of the corresponding event message includes one or more of the following: text data, voice data, image data, and video data provided by the reporter.
6. The method according to claim 3, characterized in that, The process of streaming real-time processing of multimodal data in event messages includes: Identify multimodal data types in event message content; When the multimodal data includes speech data, speech recognition is performed on the speech data to obtain text data; When the multimodal data includes video data, the video data is separated into audio and video to obtain speech data and video data; speech recognition is performed on the speech data to obtain text data; and frame extraction is performed on the video data to obtain one or more keyframe images.
7. The method according to claim 1 or 2, characterized in that, The risk assessment quantification value includes risk type and / or risk level; correspondingly, the risk handling strategy includes sending risk notifications to designated locations, real-time interception, and release.
8. The method according to claim 1, characterized in that, Further includes: After executing the risk handling strategy, obtain feedback information on risk control of the event; Based on the feedback information, the risk assessment of the corresponding event is determined to be either a positive or negative case; wherein, when the feedback information indicates that the risk assessment of the corresponding event is incorrect or that a risk has been omitted, the risk assessment of the event is determined to be a negative case. Optimize prompt words for large language models based on negative cases.
9. The method according to claim 1, characterized in that, The prompt also includes judgment examples corresponding to the risk type, and / or exemption examples corresponding to the characteristics of the risk type.
10. An information security risk control streaming processing system, characterized in that, include: The data input module is configured to receive event messages driven by preset events from the business data stream of the business system in real time, the content of which includes multimodal data; The streaming computing module is configured to perform real-time streaming processing of multimodal data in event messages to obtain input content for the large language model; A risk perception module is configured to add the input content to prompt words and provide the prompt words to a large language model; wherein the prompt words include at least risk types and their characteristics; the large language model performs risk analysis and identification on the input content based on the risk types and characteristics given in the prompt words, and outputs the content risk analysis results; The risk decision-making module is configured to determine a quantitative risk assessment value for the event message content based on content risk analysis results, and to determine a risk handling strategy matching the quantitative risk assessment value; and The risk control processing module is configured to execute the risk processing strategy in real time during the streaming real-time data processing to achieve risk control of the event.
11. The system according to claim 10, characterized in that, The system further includes an optimization module, configured to collect negative cases based on event risk control feedback information. When the event risk control feedback information indicates an error in risk assessment or omission of risk, the risk assessment of the event is determined as a negative case. The system also optimizes the prompt words of the large language model based on the negative cases.
12. An electronic device comprising a processor and a memory, wherein the memory stores a set of computer program instructions, characterized in that, The information security risk control streaming processing method according to any one of claims 1-9 is implemented when the processor executes the computer program instruction set on the memory.
13. A computer-readable storage medium, wherein, The computer-readable storage medium stores a set of computer program instructions, characterized in that, when the set of computer program instructions is executed by a processor, it implements the information security risk control streaming processing method according to any one of claims 1-9.
14. A computer program product comprising a computer program instruction set, characterized in that, When the computer program instruction set is executed by the processor, it implements the information security risk control streaming processing method according to any one of claims 1-9.