A large model-based privacy information protection system and method

By analyzing user behavior and scenario information through large-scale modeling, constructing behavioral pattern models and conducting real-time evaluations, the problems of false alarms and false negatives in privacy information leakage in existing technologies are solved, and efficient abnormal behavior identification and early warning are achieved.

CN121561899BActive Publication Date: 2026-04-07EAST CHINA NORMAL UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-22
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing technologies are unable to effectively cope with complex user behaviors and changing usage scenarios, leading to false alarms or missed alarms about privacy information leaks, which affects user experience and trust.

Method used

By analyzing behavioral data and scenario information on user devices using large-scale models, behavioral pattern models are constructed to identify abnormal behaviors and conduct risk assessments, and early warnings are issued in conjunction with real-time scenario information.

Benefits of technology

It significantly reduces false alarm and false negative rates, improves the accuracy of privacy risk assessment, and can effectively identify abnormal behavior in different scenarios to prevent information leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121561899B_ABST
    Figure CN121561899B_ABST
Patent Text Reader

Abstract

The application discloses a privacy information guarantee system and method based on a large model, and relates to the technical field of privacy guarantee, the guarantee method comprises the following steps: collecting scene information and behavior data of a user, identifying the guarantee situation of privacy information, and generating information browsing records of the user; dividing the scene types in which the user is located; identifying and dividing the behavior data, establishing a behavior mode model of the user; obtaining the behavior data containing situation of any scene type, obtaining the abnormal association situation between the behavior data and the scene types; analyzing the distribution situation of any behavior data, obtaining the abnormal characteristic values of each behavior data; comprehensively evaluating the risks in any information browsing record; obtaining the scene information and behavior data in which the user is currently located in real time, and performing preliminary evaluation; predicting the expected behavior data of the user, and performing risk early warning on the abnormal behavior.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of privacy protection technology, specifically a privacy information protection system and method based on a large model. Background Technology

[0002] With the rapid development of information technology, the protection of personal privacy information has become increasingly important. Especially with the widespread application of big data and artificial intelligence technologies, a large amount of user behavior data and scenario information are collected and analyzed. While this improves service quality, it also brings the risk of privacy leaks.

[0003] Traditional privacy protection methods often fail to effectively address complex user behaviors and changing usage scenarios, leading to potential privacy threats for users when using smart devices and services. Existing solutions collect data from only a single dimension and lack the fusion and analysis of multimodal data, resulting in coarse-grained behavioral modeling that cannot accurately identify information leaks. When faced with complex user behavior patterns, they are prone to false positives or false negatives, affecting user experience and trust. Summary of the Invention

[0004] The purpose of this invention is to provide a privacy information protection system and method based on a large model to solve the problems raised in the prior art.

[0005] To achieve the above objectives, the present invention provides the following technical solution: a privacy information protection method based on a large model, the method comprising the following steps:

[0006] Step S100: Collect the user's scene information and behavior data during device use, identify the protection of privacy information, and generate the user's information browsing records; analyze the scene information in each information browsing record, and classify the scene type of the user based on the identification results; utilize the powerful computing power of the big model to process and analyze massive amounts of user data.

[0007] Step S200: Identify and classify behavioral data in any information browsing record to establish a user behavior pattern model; obtain the behavioral data content of any scenario type; based on the information security identification results in each information browsing record, obtain the abnormal correlation between behavioral data and scenario type; by using a large model to model the user's behavioral data, it can help identify the user's regular behavioral patterns and abnormal behaviors.

[0008] Step S300: Analyze the distribution of any behavioral data in each information browsing record in the behavioral pattern model to obtain the abnormal feature value of each behavioral data; conduct a comprehensive risk assessment of all behavioral data in any information browsing record and set corresponding abnormal judgment indicators;

[0009] Step S400: Acquire the user's current scene information and behavioral data in real time, conduct a preliminary assessment of the user's current behavioral data, predict the user's expected behavioral data based on the user's behavioral pattern model, and issue risk warnings for any abnormal behaviors.

[0010] Furthermore, step S100 includes the following steps:

[0011] Step S101: After user authorization, an information collection device and an environmental monitoring device are installed on the user's device. The information collection device collects behavioral data generated by the user on the device, obtaining several behavioral data points. At the same time, the environmental monitoring device collects scene information of the user's environment, obtaining several types of scene information. The information collection device includes a touch screen sensor, a camera, a microphone, etc. The touch screen sensor is used to collect all click actions of the user on the device screen, the camera is used to capture the user's gestures and track them, and the microphone is used to collect the user's voice commands, etc. The environmental monitoring device includes various sensors to collect environmental information such as pedestrian traffic, geographical location, noise intensity, and light intensity in the user's environment, helping to identify the specific environmental information of the user's environment.

[0012] Step S102: Preset several security identification rules for the user's privacy information during device use, and calculate the abnormal feature value for each dimension; preset a feature threshold for each dimension. If the identification feature value of a dimension is greater than or equal to the feature threshold, then the user's privacy information during device use is marked as abnormal. The security identification rules include the frequency of abnormal links received by the user during use, whether the user makes abnormal logins, the frequency of the user accessing sensitive information, etc. Taking the frequency of abnormal links received as an example, the calculated abnormal feature value reflects the deviation of the receiving frequency. The larger the deviation, the higher the receiving frequency and the higher the probability of privacy information leakage, and thus, abnormal marking is required.

[0013] Step S103: Summarize the collected behavioral data, scene information, and privacy information identification results to generate a corresponding information browsing record; pre-build a scene type library, which contains several scene types, wherein any scene type matches a scene feature set, and preset an expected value range for each scene feature in the scene feature set; preset the expected value range is to classify scene types more accurately, for example, traffic flow, the value range can directly determine the congestion level of the user's environment, the higher the traffic flow, the higher the probability of information leakage;

[0014] Step S104: Randomly select an information browsing record and extract several types of scene information. For each type of scene information, extract several features and corresponding numerical ranges to obtain the feature set of the information browsing record. Compare the feature set with the scene feature set of the arbitrarily selected scene type. If any feature in the feature set is the same as the scene feature in the scene feature set, and the numerical range of any feature is within the expected numerical range, then set the selected scene type as the scene type in the selected information browsing record where the user is located.

[0015] Furthermore, step S200 includes the following steps:

[0016] Step S201: Randomly select an information browsing record and collect behavioral data from the information browsing record. Extract features from each behavioral data to obtain a corresponding behavioral feature set. Pre-build a behavioral database, which contains several user behaviors, and any user behavior matches a target feature set.

[0017] Step S202: Randomly select a set of behavioral features, and at the same time randomly select a set of target features of user behavior from the behavioral database. If any behavioral feature in the set of behavioral features has a target feature that is the same as it, then set the selected user behavior as a user behavior, and obtain several user behaviors of the user in the selected information browsing record.

[0018] Step S203: Obtain the user behavior set in each information browsing record, arbitrarily select the a-th user behavior, and count the number of times the a-th user behavior appears in each user behavior set as h. a Let M be the number of information browsing records, and let f be the frequency of the a-th user action. a =h a / M; The number of records with anomaly markers in all browsing history is m. yc The frequency f of a desired behavior is calculated. ex =(Mm yc ) / M, if f a ≥f ex Then, the a-th user behavior is set as the user's regular behavior. Several regular user behaviors are summarized to generate a user behavior pattern model. By comparing the frequency of user behavior occurrence with the expected frequency of occurrence, it is possible to determine whether user behavior occurs frequently. Effective identification of frequently occurring user behaviors is beneficial for accurate prediction of user behaviors that have not occurred.

[0019] Step S204: Set the information browsing records with abnormal markers as abnormal browsing records. Randomly select an abnormal browsing record, and randomly select a user behavior from the selected abnormal browsing record. If the selected user behavior is not included in the user behavior pattern model, then set the selected user behavior as the first abnormal user behavior. The first abnormal user behavior is an abnormal behavior that is accidentally triggered by the user and leads to information leakage, such as the user accidentally clicking on a sensitive link.

[0020] Step S205: If the user behavior pattern model includes the selected user behavior, then obtain the scene type of the user in the abnormal browsing records, then extract any information browsing records of the same scene type. If none of the extracted information browsing records have abnormal markers and do not contain the selected user behavior, then abnormally associate the selected user behavior with the scene type of the user to obtain an abnormal association group, and set the selected user behavior as the second abnormal user behavior; otherwise, set the selected user behavior as normal user behavior.

[0021] While the user behavior pattern model includes frequently generated user behaviors, frequently generated user behaviors are not the same as normal behaviors. Some user behaviors may not cause problems in high-security scenarios, but may lead to information leakage in low-security scenarios. Therefore, it is still necessary to further classify user behaviors. The second abnormal user behavior refers to user behaviors whose security changes due to changes in the scenario.

[0022] Furthermore, step S300 includes the following steps:

[0023] Step S301: Randomly select a user behavior from the behavior pattern model. If the selected user behavior is the second abnormal user behavior, extract several abnormal association groups containing the selected user behavior. Randomly select an abnormal association group, obtain the scene type in the abnormal association group and set it as the target scene type. Count the number of records in each information browsing record where the user is in the target scene type as P. Calculate the scene existence frequency of the target scene type as E=P / M, where M is the number of information browsing records. Because the second abnormal user behavior involves scene changes, it is necessary to consider the frequency of the user going to the relevant scene and the frequency of abnormal occurrence of user behavior in each scene in order to obtain accurate feature values.

[0024] Step S302: Set the scene occurrence frequency of scene type in the b-th anomaly association group to E. b The frequency of selected user behavior is f, and the abnormal feature value Y of the selected user behavior is calculated according to the formula:

[0025] ;

[0026] Where b is a positive integer and b∈[1,w], w is the number of abnormal association groups containing the selected user behavior; if the selected user behavior is normal user behavior, then Y=0;

[0027] Step S303: Randomly select a first abnormal user behavior and count the number of times the first abnormal user behavior appears in each information browsing record, which is h. ’ The abnormal feature value of the first abnormal user behavior is obtained as Y. ’ =h ’ / M;

[0028] Step S304: Randomly select a message browsing record and obtain each user behavior in the message browsing record. Randomly select the a-th user behavior and set a behavior flag for the a-th user behavior. a If the a-th user action is a normal user action or the first abnormal user action, then the flag is set. a =0, if the a-th user behavior is the second abnormal user behavior, then flag a =1; According to the formula:

[0029] ;

[0030] Where a is a positive integer and a∈[1,u], u is the number of user behaviors contained in the information browsing record, and IF() is a judgment function; if flag a =0, then IF(flag) a =0)=1, if flag a =1, then IF(flag) a =1)=1,Y a Y is the abnormal feature value when the a-th user behavior is either a normal user behavior or the first abnormal user behavior. ’ a Let a be the abnormal feature value when the a-th user behavior is the second abnormal user behavior; calculate the risk assessment value R of the selected information browsing records;

[0031] Step S305: Obtain the risk assessment value of each browsing record with anomaly markers, and select the risk assessment value with the smallest value as the anomaly judgment index R. th .

[0032] Furthermore, step S400 includes the following steps:

[0033] Step S401: Whenever a user uses the device in real time, collect the behavioral data and scene information generated during the user's use to generate a real-time browsing record and obtain several real-time user behaviors; obtain the abnormal feature values ​​of each real-time user behavior, and calculate the real-time evaluation value R of the real-time browsing record. now ;

[0034] Step S402: Obtain the anomaly judgment index R th If R now ≥R th If R... now <R th Then, obtain the user's behavior pattern model, compare each user behavior in the behavior pattern model with each real-time user behavior, remove the user behaviors that are the same as the real-time user behaviors from the behavior pattern model, and obtain a set of real-time feature behaviors.

[0035] Step S403: Extract the collected scene information to obtain the real-time scene type of the user's current scene, extract several abnormal association groups of the real-time scene type, compare the user behavior in each abnormal association group with the real-time feature behavior set, extract the existing identical user behaviors, and obtain a set of expected behaviors.

[0036] Step S404: Obtain the abnormal feature value of any user behavior in the expected behavior set, and sum them to obtain the comprehensive evaluation value R of the expected behavior set. ’ The expected evaluation value (R) of the real-time browsing record is calculated. now ) ex =R now +R ’ If (R) now ) ex ≥R th If so, a risk warning will be sent to the user.

[0037] To better implement the above methods, a privacy information protection system is also proposed, which includes a user data analysis module, a behavior pattern association module, an anomaly risk analysis module, and a real-time anomaly identification module.

[0038] The user data analysis module is used to collect information about the user's environment and behavior during device use, identify the protection of privacy information, generate the user's information browsing history, analyze the scene information in each information browsing history, and classify the user's scene type based on the identification results.

[0039] The behavior pattern association module is used to identify and classify behavioral data in any information browsing record, establish a user behavior pattern model, obtain the content of behavioral data of any scenario type, and obtain the abnormal association between behavioral data and scenario type based on the information security identification results in each information browsing record.

[0040] The anomaly risk analysis module is used to analyze the distribution of any behavioral data in the behavioral pattern model across various information browsing records, obtain the anomaly characteristic values ​​of each behavioral data, perform a comprehensive risk assessment on all behavioral data in any information browsing record, and set corresponding anomaly judgment indicators.

[0041] The real-time anomaly identification module is used to acquire information about the user's current scene and behavioral data in real time, and to conduct a preliminary assessment of the user's current behavioral data; based on the user's behavioral pattern model, it predicts the user's expected behavioral data and provides risk warnings for any abnormal behaviors.

[0042] Furthermore, the user data analysis module includes a data acquisition and evaluation unit and a scene identification and segmentation unit;

[0043] The data acquisition and evaluation unit is used to collect information about the user's environment and behavior during device use, identify the protection of privacy information, and generate the user's information browsing history. The scene identification and classification unit is used to analyze the scene information in each information browsing history and classify the scene type of the user based on the identification results.

[0044] Furthermore, the behavior pattern association module includes a behavior pattern modeling unit and a behavior scenario association unit;

[0045] The behavior pattern modeling unit is used to identify and classify behavioral data in any information browsing record and establish a user behavior pattern model; the behavior scene association unit is used to obtain the content of behavioral data of any scene type, and based on the information security identification results in each information browsing record, obtain the abnormal association between behavioral data and scene type.

[0046] Furthermore, the anomaly risk analysis module includes an anomaly feature analysis unit and a behavioral risk assessment unit;

[0047] The abnormal feature analysis unit is used to analyze the distribution of any behavioral data in each information browsing record in the behavioral pattern model, and obtain the abnormal feature value of each behavioral data; the behavioral risk assessment unit is used to build a risk assessment model, perform a comprehensive risk assessment on all behavioral data in any information browsing record, and set corresponding abnormal judgment indicators.

[0048] Furthermore, the real-time anomaly detection module includes a real-time behavior capture unit and an anomaly detection and early warning unit;

[0049] The real-time behavior capture unit is used to acquire information about the user's current scene and behavior data in real time, and to make a preliminary assessment of the user's current behavior data; the anomaly identification and early warning unit is used to predict the user's expected behavior data based on the user's behavior pattern model, and to issue risk warnings for any abnormal behavior.

[0050] Compared with the prior art, the beneficial effects of the present invention are:

[0051] 1. This invention integrates user behavior data and scenario information, combined with a pre-defined scenario type library and dynamic feature matching mechanism, to overcome the limitations of traditional single-dimensional analysis methods; through anomaly association group analysis, it significantly reduces false positive and false negative rates, helping to improve the accuracy of privacy risk assessment.

[0052] 2. By considering the differences in risk levels arising from users' routine behaviors in different scenarios, this invention provides a more precise analysis of the frequency of abnormal occurrences in various user behaviors, helping users maintain high anomaly identification efficiency and reduce the risk of information leakage in different application scenarios.

[0053] 3. By constructing a dynamically updated behavior pattern model and combining it with real-time scene information for behavior prediction, this invention can effectively provide early warning of potential information leakage events and effectively prevent the spread of privacy leakage events. Attached Figure Description

[0054] Figure 1 This is a schematic diagram illustrating the steps of a privacy protection method based on a large model.

[0055] Figure 2 This is a schematic diagram of the structure of a privacy information protection system based on a large model. Detailed Implementation

[0056] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0057] Example: Figures 1 to 2 As shown, this invention provides a privacy information protection method based on a large model, the method comprising the following steps:

[0058] Step S100: Collect the user's scene information and behavior data during device use, identify the protection of privacy information, and generate the user's information browsing records; analyze the scene information in each information browsing record, and classify the scene type of the user based on the identification results;

[0059] Step S100 includes the following steps:

[0060] Step S101: After user authorization, an information collection device and an environmental monitoring device are installed in the user's device. The information collection device is used to collect the behavioral data generated by the user on the device to obtain several behavioral data. At the same time, the environmental monitoring device is used to collect scene information of the scene in which the user is located to obtain several types of scene information.

[0061] Step S102: Preset several security identification rules for the user's privacy information during device use, and calculate the abnormal feature value of each dimension; preset a feature threshold for each dimension, and if there is an identification feature value of a dimension that is greater than or equal to the feature threshold, then mark the user's privacy information during device use as abnormal.

[0062] Step S103: Summarize the collected behavioral data, scene information and privacy information identification results to generate a corresponding information browsing record; pre-build a scene type library, which contains several scene types, wherein any scene type matches a scene feature set, and a preset expected value range is set for each scene feature in the scene feature set;

[0063] Step S104: Randomly select an information browsing record and extract several types of scene information. For each type of scene information, extract several features and corresponding numerical ranges to obtain the feature set of the information browsing record. Compare the feature set with the scene feature set of the arbitrarily selected scene type. If any feature in the feature set is the same as the scene feature in the scene feature set, and the numerical range of any feature is within the expected numerical range, then set the selected scene type as the scene type in the selected information browsing record where the user is located.

[0064] Step S200: Identify and classify the behavioral data in any information browsing record, and establish a user behavior pattern model; obtain the behavioral data content of any scenario type, and based on the information security identification results in each information browsing record, obtain the abnormal correlation between behavioral data and scenario type;

[0065] Step S200 includes the following steps:

[0066] Step S201: Randomly select an information browsing record and collect behavioral data from the information browsing record. Extract features from each behavioral data to obtain a corresponding behavioral feature set. Pre-build a behavioral database, which contains several user behaviors, and any user behavior matches a target feature set.

[0067] Step S202: Randomly select a set of behavioral features, and at the same time randomly select a set of target features of user behavior from the behavioral database. If any behavioral feature in the set of behavioral features has a target feature that is the same as it, then set the selected user behavior as a user behavior, and obtain several user behaviors of the user in the selected information browsing record.

[0068] Step S203: Obtain the user behavior set in each information browsing record, arbitrarily select the a-th user behavior, and count the number of times the a-th user behavior appears in each user behavior set as h. a Let M be the number of information browsing records, and let f be the frequency of the a-th user action. a =h a / M; The number of records with anomaly markers in all browsing history is m. yc The frequency f of a desired behavior is calculated. ex =(Mm yc ) / M, if f a ≥f ex Then, the a-th user behavior is set as the user's regular behavior, and the user's several regular behaviors are summarized to generate a user behavior pattern model.

[0069] Step S204: Set the information browsing records with abnormal markers as abnormal browsing records. Randomly select an abnormal browsing record, and randomly select a user behavior from the selected abnormal browsing record. If the selected user behavior is not included in the user behavior pattern model, then set the selected user behavior as the first abnormal user behavior.

[0070] Step S205: If the user behavior pattern model includes the selected user behavior, then obtain the scene type of the user in the abnormal browsing records, then extract any information browsing records of the same scene type. If none of the extracted information browsing records have abnormal markers and do not contain the selected user behavior, then abnormally associate the selected user behavior with the scene type of the user to obtain an abnormal association group, and set the selected user behavior as the second abnormal user behavior. Otherwise, set the selected user behavior as normal user behavior.

[0071] Step S300: Analyze the distribution of any behavioral data in each information browsing record in the behavioral pattern model to obtain the abnormal feature value of each behavioral data; conduct a comprehensive risk assessment of all behavioral data in any information browsing record and set corresponding abnormal judgment indicators;

[0072] Step S300 includes the following steps:

[0073] Step S301: Randomly select a user behavior from the behavior pattern model. If the selected user behavior is the second abnormal user behavior, extract several abnormal association groups containing the selected user behavior. Randomly select an abnormal association group, obtain the scene type in the abnormal association group and set it as the target scene type. Count the number of records in each information browsing record where the user is in the target scene type as P. Calculate the scene existence frequency of the target scene type as E=P / M, where M is the number of information browsing records.

[0074] Step S302: Set the scene occurrence frequency of scene type in the b-th anomaly association group to E. b The frequency of selected user behavior is f, and the abnormal feature value Y of the selected user behavior is calculated according to the formula:

[0075] ;

[0076] Where b is a positive integer and b∈[1,w], w is the number of abnormal association groups containing the selected user behavior; if the selected user behavior is normal user behavior, then Y=0;

[0077] Example 1: Set the frequency of selected user behavior to f=20%, obtain 3 abnormal association groups related to user behavior, and obtain the scene existence frequency of the corresponding scene type in the 3 abnormal association groups as 5%, 10% and 15% respectively. Calculate the abnormal feature value Y of selected user behavior as Y=20%×30%=6%;

[0078] Step S303: Randomly select a first abnormal user behavior and count the number of times the first abnormal user behavior appears in each information browsing record, which is h. ’ The abnormal feature value of the first abnormal user behavior is obtained as Y. ’ =h ’ / M;

[0079] Step S304: Randomly select a message browsing record and obtain each user behavior in the message browsing record. Randomly select the a-th user behavior and set a behavior flag for the a-th user behavior. a If the a-th user action is a normal user action or the first abnormal user action, then the flag is set. a=0, if the a-th user behavior is the second abnormal user behavior, then flag a =1; According to the formula:

[0080] ;

[0081] Where a is a positive integer and a∈[1,u], u is the number of user behaviors contained in the information browsing record, and IF() is a judgment function; if flag a =0, then IF(flag) a =0)=1, if flag a =1, then IF(flag) a =1)=1,Y a Y is the abnormal feature value when the a-th user behavior is either a normal user behavior or the first abnormal user behavior. ’ a Let a be the abnormal feature value when the a-th user behavior is the second abnormal user behavior; calculate the risk assessment value R of the selected information browsing records;

[0082] Example 2: Assume that the selected information browsing records contain 3 normal user behaviors, 4 first abnormal user behaviors, and 3 second abnormal user behaviors. The abnormal characteristic value Y=0 for normal user behaviors, the abnormal characteristic values ​​for the first abnormal user behaviors are 6%, 5%, 7%, and 5%, respectively, and the abnormal characteristic values ​​for the second abnormal user behaviors are 10%, 8%, and 7%, respectively. The risk assessment value R for the selected information browsing records is calculated as R=23%+25%=48%.

[0083] Step S305: Obtain the risk assessment value of each browsing record with anomaly markers, and select the risk assessment value with the smallest value as the anomaly judgment index R. th .

[0084] Step S400: Acquire the user's current scene information and behavioral data in real time, conduct a preliminary assessment of the user's current behavioral data, predict the user's expected behavioral data based on the user's behavioral pattern model, and issue risk warnings for any abnormal behaviors.

[0085] Step S400 includes the following steps:

[0086] Step S401: Whenever a user uses the device in real time, collect the behavioral data and scene information generated during the user's use to generate a real-time browsing record and obtain several real-time user behaviors; obtain the abnormal feature values ​​of each real-time user behavior, and calculate the real-time evaluation value R of the real-time browsing record. now ;

[0087] Step S402: Obtain the anomaly detection index Rth If R now ≥R th If R... now <R th Then, obtain the user's behavior pattern model, compare each user behavior in the behavior pattern model with each real-time user behavior, remove the user behaviors that are the same as the real-time user behaviors from the behavior pattern model, and obtain a set of real-time feature behaviors.

[0088] Step S403: Extract the collected scene information to obtain the real-time scene type of the user's current scene, extract several abnormal association groups of the real-time scene type, compare the user behavior in each abnormal association group with the real-time feature behavior set, extract the existing identical user behaviors, and obtain a set of expected behaviors.

[0089] Step S404: Obtain the abnormal feature value of any user behavior in the expected behavior set, and sum them to obtain the comprehensive evaluation value R of the expected behavior set. ’ The expected evaluation value (R) of the real-time browsing record is calculated. now ) ex =R now +R ’ If (R) now ) ex ≥R th If so, a risk warning will be sent to the user.

[0090] A privacy information protection system, comprising a user data analysis module, a behavior pattern association module, an anomaly risk analysis module, and a real-time anomaly identification module;

[0091] The user data analysis module is used to collect information about the user's environment and behavior during device use, identify the protection of privacy information, generate the user's information browsing history, analyze the scene information in each information browsing history, and classify the user's scene type based on the identification results.

[0092] The behavior pattern association module is used to identify and classify behavioral data in any information browsing record, establish a user behavior pattern model, obtain the content of behavioral data of any scenario type, and obtain the abnormal association between behavioral data and scenario type based on the information security identification results in each information browsing record.

[0093] The anomaly risk analysis module is used to analyze the distribution of any behavioral data in the behavioral pattern model across various information browsing records, obtain the anomaly characteristic values ​​of each behavioral data, perform a comprehensive risk assessment on all behavioral data in any information browsing record, and set corresponding anomaly judgment indicators.

[0094] The real-time anomaly identification module is used to acquire information about the user's current scene and behavioral data in real time, and to conduct a preliminary assessment of the user's current behavioral data; based on the user's behavioral pattern model, it predicts the user's expected behavioral data and provides risk warnings for any abnormal behaviors.

[0095] The user data analysis module includes a data collection and evaluation unit and a scene identification and segmentation unit.

[0096] The data acquisition and evaluation unit is used to collect information about the user's environment and behavior during device use, identify the protection of privacy information, and generate the user's information browsing history. The scene identification and classification unit is used to analyze the scene information in each information browsing history and classify the scene type of the user based on the identification results.

[0097] The behavior pattern association module includes a behavior pattern modeling unit and a behavior scenario association unit.

[0098] The behavior pattern modeling unit is used to identify and classify behavioral data in any information browsing record and establish a user behavior pattern model; the behavior scene association unit is used to obtain the content of behavioral data of any scene type, and based on the information security identification results in each information browsing record, obtain the abnormal association between behavioral data and scene type.

[0099] The abnormal risk analysis module includes an abnormal feature analysis unit and a behavioral risk assessment unit.

[0100] The abnormal feature analysis unit is used to analyze the distribution of any behavioral data in each information browsing record in the behavioral pattern model, and obtain the abnormal feature value of each behavioral data; the behavioral risk assessment unit is used to build a risk assessment model, perform a comprehensive risk assessment on all behavioral data in any information browsing record, and set corresponding abnormal judgment indicators.

[0101] The real-time anomaly detection module includes a real-time behavior capture unit and an anomaly detection and early warning unit.

[0102] The real-time behavior capture unit is used to acquire information about the user's current scene and behavior data in real time, and to make a preliminary assessment of the user's current behavior data; the anomaly identification and early warning unit is used to predict the user's expected behavior data based on the user's behavior pattern model, and to issue risk warnings for any abnormal behavior.

[0103] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the invention can be implemented in other specific forms without departing from its spirit or essential characteristics. Therefore, the embodiments should be considered in all respects as exemplary and non-limiting, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be included within the present invention. No reference numerals in the claims should be construed as limiting the scope of the claims.

Claims

1. A privacy protection method based on a large model, characterized in that: The protection method includes the following steps: Step S100: Collect the user's scene information and behavior data during device use, identify the protection of privacy information, and generate the user's information browsing records; analyze the scene information in each information browsing record, and classify the scene type of the user based on the identification results; Step S100 includes the following: Several security identification rules are preset for user privacy information during device use, and abnormal feature values ​​are calculated for each dimension. A feature threshold is preset for each dimension, and anomalies are marked according to the feature threshold. The collected behavioral data, several types of scene information, and privacy information identification results are summarized to generate a corresponding information browsing record. An information browsing record is randomly selected and several types of scene information are extracted. Several features and corresponding numerical ranges are extracted for each type of scene information. The features of each type of scene information are compared with the scene features of the randomly selected scene type to classify the scene type in which the user is located. Step S200: Identify and classify the behavioral data in any information browsing record, and establish a user behavior pattern model; obtain the behavioral data content of any scenario type, and based on the information security identification results in each information browsing record, obtain the abnormal correlation between behavioral data and scenario type; Step S200 includes the following steps: Step S201: Randomly select an information browsing record and collect behavioral data from the information browsing record. Extract features from each behavioral data to obtain a corresponding behavioral feature set. Pre-build a behavioral database, which contains several user behaviors, and any user behavior matches a target feature set. Step S202: Randomly select a set of behavioral features, and at the same time randomly select a set of target features of user behavior from the behavioral database. If any behavioral feature in the set of behavioral features has a target feature that is the same as it, then set the selected user behavior as a user behavior, and obtain several user behaviors of the user in the selected information browsing record. Step S203: Obtain the user behavior set in each information browsing record, arbitrarily select the a-th user behavior, and count the number of times the a-th user behavior appears in each user behavior set as h. a Let M be the number of information browsing records, and let f be the frequency of the a-th user action. a =h a / M; The number of records with anomaly markers in all browsing history is m. yc The frequency f of a desired behavior is calculated. ex =(Mm yc ) / M, if f a ≥f ex Then, the a-th user behavior is set as the user's regular behavior, and the user's several regular behaviors are summarized to generate a user behavior pattern model. Step S204: Set the information browsing records with abnormal markers as abnormal browsing records. Randomly select an abnormal browsing record, and randomly select a user behavior from the selected abnormal browsing record. If the selected user behavior is not included in the user behavior pattern model, then set the selected user behavior as the first abnormal user behavior. Step S205: If the user behavior pattern model includes the selected user behavior, then obtain the scene type of the user in the abnormal browsing records, then extract any information browsing records of the same scene type. If none of the extracted information browsing records have abnormal markers and do not contain the selected user behavior, then abnormally associate the selected user behavior with the scene type of the user to obtain an abnormal association group, and set the selected user behavior as the second abnormal user behavior; otherwise, set the selected user behavior as normal user behavior. Step S300: Analyze the distribution of any behavioral data in each information browsing record in the behavioral pattern model to obtain the abnormal feature value of each behavioral data; conduct a comprehensive risk assessment of all behavioral data in any information browsing record and set corresponding abnormal judgment indicators; Step S300 includes the following: From the behavior pattern model, arbitrarily select a user behavior. If the selected user behavior is the second abnormal user behavior, extract several abnormal association groups containing the selected user behavior. Arbitrarily select an abnormal association group and analyze the frequency of occurrence of the target scenario type corresponding to the abnormal association group. Combine the occurrence frequency of the user behavior to analyze the abnormal feature value of the selected user behavior. Arbitrarily select a first abnormal user behavior and count the number of times the first abnormal user behavior appears in each information browsing record. Analyze the abnormal feature value of the first abnormal user behavior. Arbitrarily select an information browsing record and obtain each user behavior in the information browsing record. Arbitrarily select user behaviors and perform behavior marking analysis. Combine the abnormal feature value to analyze the risk assessment value of the selected information browsing record. Obtain the risk assessment value of each information browsing record with abnormal markings, and select the risk assessment value with the smallest value as the abnormal judgment index. Step S400: Acquire the user's current scene information and behavioral data in real time, conduct a preliminary assessment of the user's current behavioral data, predict the user's expected behavioral data based on the user's behavioral pattern model, and issue risk warnings for any abnormal behaviors.

2. The privacy information protection method based on a large model according to claim 1, characterized in that: Step S100 includes the following steps: Step S101: After user authorization, an information collection device and an environmental monitoring device are installed in the user's device. The information collection device is used to collect the behavioral data generated by the user on the device to obtain several behavioral data. At the same time, the environmental monitoring device is used to collect scene information of the scene in which the user is located to obtain several types of scene information. Step S102: Preset several security identification rules for the user's privacy information during device use, and calculate the abnormal feature value of each dimension; preset a feature threshold for each dimension, and if there is an identification feature value of a dimension that is greater than or equal to the feature threshold, then mark the user's privacy information during device use as abnormal. Step S103: Summarize the collected behavioral data, scene information and privacy information identification results to generate a corresponding information browsing record; pre-build a scene type library, which contains several scene types, wherein any scene type matches a scene feature set, and a preset expected value range is set for each scene feature in the scene feature set; Step S104: Randomly select an information browsing record and extract several types of scene information. For each type of scene information, extract several features and corresponding numerical ranges to obtain the feature set of the information browsing record. Compare the feature set with the scene feature set of the arbitrarily selected scene type. If any feature in the feature set is the same as the scene feature in the scene feature set, and the numerical range of any feature is within the expected numerical range, then set the selected scene type as the scene type in the selected information browsing record where the user is located.

3. The privacy information protection method based on a large model according to claim 2, characterized in that: Step S300 includes the following steps: Step S301: Randomly select a user behavior from the behavior pattern model. If the selected user behavior is the second abnormal user behavior, extract several abnormal association groups containing the selected user behavior. Randomly select an abnormal association group, obtain the scene type in the abnormal association group and set it as the target scene type. Count the number of records in each information browsing record where the user is in the target scene type as P. Calculate the scene existence frequency of the target scene type as E=P / M, where M is the number of information browsing records. Step S302: Set the scene occurrence frequency of scene type in the b-th anomaly association group to E. b The frequency of selected user behavior is f, and the abnormal feature value Y of the selected user behavior is calculated according to the formula: ; Where b is a positive integer and b∈[1,w], w is the number of abnormal association groups containing the selected user behavior; if the selected user behavior is normal user behavior, then Y=0; Step S303: Randomly select a first abnormal user behavior and count the number of times the first abnormal user behavior appears in each information browsing record, which is h. ’ The abnormal feature value of the first abnormal user behavior is obtained as Y. ’ =h ’ / M; Step S304: Randomly select a message browsing record and obtain each user behavior in the message browsing record. Randomly select the a-th user behavior and set a behavior flag for the a-th user behavior. a If the a-th user action is a normal user action or the first abnormal user action, then the flag is set. a =0, if the a-th user behavior is the second abnormal user behavior, then flag a =1; According to the formula: ; Where a is a positive integer and a∈[1,u], u is the number of user behaviors contained in the information browsing record, and IF() is a judgment function; if flag a =0, then IF(flag) a =0)=1, if flag a =1, then IF(flag) a =1)=1,Y a Y is the abnormal feature value when the a-th user behavior is either a normal user behavior or the first abnormal user behavior. ’ a Let a be the abnormal feature value when the a-th user behavior is the second abnormal user behavior; calculate the risk assessment value R of the selected information browsing records; Step S305: Obtain the risk assessment value of each browsing record with anomaly markers, and select the risk assessment value with the smallest value as the anomaly judgment index R. th .

4. The privacy information protection method based on a large model according to claim 3, characterized in that: Step S400 includes the following steps: Step S401: Whenever a user uses the device in real time, collect the behavioral data and scene information generated during the user's use to generate a real-time browsing record and obtain several real-time user behaviors; obtain the abnormal feature values ​​of each real-time user behavior, and calculate the real-time evaluation value R of the real-time browsing record. now ; Step S402: Obtain the anomaly detection index R th If R now ≥R th If R... now <R th Then, obtain the user's behavior pattern model, compare each user behavior in the behavior pattern model with each real-time user behavior, remove the user behaviors that are the same as the real-time user behaviors from the behavior pattern model, and obtain a set of real-time feature behaviors. Step S403: Extract the collected scene information to obtain the real-time scene type of the user's current scene, extract several abnormal association groups of the real-time scene type, compare the user behavior in each abnormal association group with the real-time feature behavior set, extract the existing identical user behaviors, and obtain a set of expected behaviors. Step S404: Obtain the abnormal feature value of any user behavior in the expected behavior set, and sum them to obtain the comprehensive evaluation value R of the expected behavior set. ’ The expected evaluation value (R) of the real-time browsing record is calculated. now ) ex =R now +R ’ If (R) now ) ex ≥R th If so, a risk warning will be sent to the user.

5. A privacy information protection system, used to execute the privacy information protection method based on a large model according to any one of claims 1-4, characterized in that: The protection system includes a user data analysis module, a behavior pattern association module, an anomaly risk analysis module, and a real-time anomaly identification module; The user data analysis module is used to collect information about the user's environment and behavior during device use, identify the level of privacy protection, generate the user's information browsing history, analyze the scene information in each information browsing history, and classify the user's scene type based on the identification results. The behavior pattern association module is used to identify and classify the behavior data in any information browsing record, establish a user behavior pattern model, obtain the behavior data content of any scenario type, and obtain the abnormal association between behavior data and scenario type based on the information security identification results in each information browsing record. The abnormal risk analysis module is used to analyze the distribution of any behavioral data in each information browsing record in the behavioral pattern model, obtain the abnormal feature value of each behavioral data, perform a comprehensive risk assessment on all behavioral data in any information browsing record, and set corresponding abnormal judgment indicators. The real-time anomaly identification module is used to acquire the user's current scene information and behavioral data in real time, to conduct a preliminary assessment of the user's current behavioral data, to predict the user's expected behavioral data based on the user's behavioral pattern model, and to issue risk warnings for any abnormal behaviors.

6. A privacy information protection system according to claim 5, characterized in that: The user data analysis module includes a data acquisition and evaluation unit and a scene recognition and segmentation unit; The data acquisition and evaluation unit is used to collect information about the user's environment and behavior during device use, identify the level of privacy protection, and generate the user's information browsing history. The scene recognition and segmentation unit is used to analyze scene information in each information browsing record and classify the scene type in which the user is located based on the recognition results.

7. A privacy information protection system according to claim 5, characterized in that: The behavior pattern association module includes a behavior pattern modeling unit and a behavior scenario association unit; The behavior pattern modeling unit is used to identify and classify the behavior data in any information browsing record and establish a user behavior pattern model. The behavior scene association unit is used to obtain the behavior data content of any scene type, and based on the information protection identification results in each information browsing record, to obtain the abnormal association between behavior data and scene type.

8. A privacy information protection system according to claim 5, characterized in that: The anomaly risk analysis module includes an anomaly feature analysis unit and a behavioral risk assessment unit; The abnormal feature analysis unit is used to analyze the distribution of any behavioral data in each information browsing record in the behavioral pattern model, and obtain the abnormal feature value of each behavioral data; the behavioral risk assessment unit is used to construct a risk assessment model, perform a comprehensive risk assessment on all behavioral data in any information browsing record, and set corresponding abnormal judgment indicators.

9. A privacy information protection system according to claim 5, characterized in that: The real-time anomaly identification module includes a real-time behavior capture unit and an anomaly identification and early warning unit; The real-time behavior capture unit is used to acquire the user's current scene information and behavior data in real time, and to perform a preliminary evaluation of the user's current behavior data; The anomaly identification and early warning unit is used to predict the user's expected behavior data based on the user's behavior pattern model and to provide risk warnings for any abnormal behaviors.

Citation Information

Patent Citations

  • Privacy data protection-based abnormal acquisition behavior identification method and device

    CN110826006A

  • Application program detection method, device and equipment

    CN111400705A