Role large model memory data privacy protection and authority level-to-level management method and system

By performing sensitivity identification and anonymization processing on the memory data of the large role model, combined with access control and privacy budget management, the problems of privacy leakage and compliance risks in the memory data processing of the large role model are solved, and safe and reasonable information utilization is achieved.

CN121765752AActive Publication Date: 2026-03-31LIANGSHENG DIGITAL CREATIVE DESIGN (HANGZHOU) CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-03-02
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

The existing large-scale role model cannot reasonably remember and utilize user information while ensuring user privacy and data security during memory data processing. This poses risks of unauthorized access and privacy leaks, making it difficult to meet compliance requirements and user experience needs.

Method used

By performing sensitivity identification on memory data generated during user interactions with large role models, determining sensitivity scores and sensitivity level labels, and performing desensitization and vector transformation processing, combined with access control and privacy budget management, hierarchical storage and privacy protection of memory data can be achieved.

Benefits of technology

While ensuring user privacy and data security, the role-based big data model is allowed to reasonably remember and utilize user information to meet users' intelligent experience needs and comply with privacy compliance requirements, preventing unauthorized use or disclosure of sensitive information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121765752A_ABST
    Figure CN121765752A_ABST
Patent Text Reader

Abstract

The invention discloses a role large model memory data privacy protection and authority level-to-level management method and a role large model memory data privacy protection and authority level-to-level management system. The method comprises the following steps: performing sensitivity identification on memory data, determining a sensitivity score, further determining a sensitivity level label and an authority label, and associatively storing the sensitivity score, the sensitivity level label and the authority label to realize grading processing on the memory data; based on the memory data fusion vector, outputting the fusion vector during semantic retrieval to realize privacy protection of the memory data; when the role large model and the user carry out memory retrieval in a dialogue scene, authority control is carried out on the memory data to ensure that sensitive information is not used by the role large model in an unauthorized manner or is displayed, so that the security of the memory data is ensured; and in a model training scene or a statistical analysis scene, random noise is added to the memory data based on the metadata so as to realize privacy protection of the memory data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of artificial intelligence and data privacy protection technology, and in particular to a method and system for protecting the privacy of large role model memory data and managing hierarchical permissions. Background Technology

[0002] With the development of artificial intelligence technology, dialogue systems with long-term interactive memory capabilities are widely used in scenarios such as personal assistants, health management, and enterprise offices. These systems accumulate and store user-related information during continuous interaction to enhance personalization and contextual consistency. The memory data generated by dialogue systems often contains sensitive information such as identity identifiers, contact information, location data, health information, and financial information. Without effective hierarchical storage, access control, and anonymization mechanisms, risks such as unauthorized access, unauthorized calls, or inappropriate external display may arise, leading to privacy leaks and compliance risks. Therefore, a privacy protection and hierarchical access control technology solution covering the entire lifecycle of memory data is needed.

[0003] Existing dialogue systems need to adopt standardized measures when storing and using personal information. For example, industry standards stipulate that sensitive data should be processed and encrypted on the terminal first, and the corresponding role models of dialogue systems need to provide granular permission settings to avoid a "one-size-fits-all" authorization approach. This means that the traditional practice of completely uploading stored data to the cloud is unlikely to meet compliance requirements, and role models that directly store or use user information may face legal risks.

[0004] Balancing privacy protection and user experience is a major challenge: while completely eliminating user memory storage maximizes security, it significantly reduces the personalized service capabilities of the large-scale role model; conversely, unlimited memory storage and uploading of user data, while enhancing the experience, introduces security vulnerabilities. Therefore, there is an urgent need for a technical solution that allows the large-scale role model to reasonably store and utilize user-provided information, while ensuring user privacy and data security, thus satisfying both the user's intelligent experience needs and privacy compliance requirements. Summary of the Invention

[0005] This invention provides a method and system for privacy protection and hierarchical permission management of large role model memory data, in order to solve the problem that existing large role models cannot reasonably remember and utilize user-provided memory data while ensuring user privacy and data security.

[0006] A method for privacy protection and hierarchical access control of large role model memory data includes: Sensitivity identification is performed on the memory data during the interaction between the large character model and the user to determine a sensitivity score. Based on the sensitivity score and the classification threshold, sensitivity level labels and permission labels are determined. New memory entries are formed based on the memory data and its metadata, and the new memory entries are stored in the memory database. The metadata includes the sensitivity score, the sensitivity level label, and the permission label. The memory data is desensitized and vectorized to determine the desensitized representation vector and the sensitive feature vector. Based on the desensitized representation vector and the sensitive feature vector, a fusion vector is determined and stored in the memory database so that the fusion vector can be output when a semantic retrieval request is received. In response to a memory retrieval request triggered by the large character model in a dialogue scenario, candidate memory entries are obtained from the memory database, and access control is performed on the memory data in the candidate memory entries based on the metadata in the candidate memory entries to determine the available memory data of the large character model in the dialogue scenario. In response to a memory retrieval request triggered by a model training scenario or a statistical analysis scenario, a pending memory entry is obtained from the memory database. A privacy budget is dynamically determined based on the metadata in the pending memory entry. Random noise is added to the memory data in the pending memory entry based on the privacy budget to determine the noisy memory data.

[0007] A role-based large-scale model memory data privacy protection and hierarchical access control system includes: A hierarchical storage module is used to identify the sensitivity of memory data during the interaction between the large role model and the user, determine a sensitivity score, and determine a sensitivity level label and a permission label based on the sensitivity score and a hierarchical threshold; and to form new memory entries based on the memory data and its metadata, and store the new memory entries in the memory database, wherein the metadata includes the sensitivity score, the sensitivity level label and the permission label; The vector fusion module is used to perform desensitization and vector transformation processing on the memory data, determine the desensitized representation vector and the sensitive feature vector, determine the fusion vector based on the desensitized representation vector and the sensitive feature vector, and store the fusion vector in the memory database so as to output the fusion vector when a semantic retrieval request is received; The access control module is used to respond to the memory retrieval request triggered by the large role model in the dialogue scenario, obtain candidate memory entries from the memory database, perform access control on the memory data in the candidate memory entries based on the metadata in the candidate memory entries, and determine the available memory data of the large role model in the dialogue scenario. The privacy control module is used to respond to memory retrieval requests triggered in model training or statistical analysis scenarios, obtain unused memory entries from the memory database, dynamically determine a privacy budget based on the metadata in the unused memory entries, add random noise to the memory data in the unused memory entries based on the privacy budget, and determine the noisy memory data.

[0008] This invention provides a method and system for privacy protection and hierarchical permission management of memory data in a large role model. The method involves: identifying the sensitivity of memory data, determining a sensitivity score, and then determining sensitivity level labels and permission labels. The sensitivity score, sensitivity level labels, and permission labels are stored in association to achieve hierarchical processing of the memory data. A memory data fusion vector is used to output the fusion vector during semantic retrieval, thus protecting the privacy of the memory data. During memory retrieval in a dialogue scenario between the large role model and the user, access control is implemented on the memory data to ensure that sensitive information is not used or exposed by the large role model without authorization, thereby ensuring the security of the memory data. In model training or statistical analysis scenarios, random noise is added to the memory data based on metadata to further protect its privacy. Attached Figure Description

[0009] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0010] Figure 1 This is a flowchart of a method for privacy protection and hierarchical permission management of large role model memory data in an embodiment of the present invention; Figure 2 yes Figure 1 A flowchart of step S101; Figure 3 yes Figure 1 Another flowchart of step S101; Figure 4 yes Figure 1 A flowchart of step S102; Figure 5 yes Figure 1 A flowchart of step S103; Figure 6 yes Figure 1 A flowchart of step S104; Figure 7 This is a schematic diagram of a role-based large model memory data privacy protection and permission-based hierarchical management system in an embodiment of the present invention. Detailed Implementation

[0011] To make the technical problems solved, the technical solutions, and the beneficial effects of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.

[0012] This invention provides a method for privacy protection and hierarchical permission management of large role model memory data. This method is applicable between a terminal device (hereinafter referred to as "terminal") and a cloud server (hereinafter referred to as "cloud"), and is used to realize privacy protection and permission group management of the memory data of the large role model. Under the premise of ensuring user privacy and data security, the large role model can reasonably record and utilize the information provided by the user, which can both meet the user's intelligent experience needs and comply with privacy compliance requirements.

[0013] The terminal can be a mobile terminal, desktop terminal, or edge computing terminal, and includes at least a processor, memory, network interface, and secure storage components. The secure storage components can be implemented using hardware security modules, trusted execution environments, or encrypted storage areas protected by the operating system, and are used to store local data and key materials. The cloud can be a cluster of computing nodes in a cloud environment or a local data center, and includes at least an access authentication component, a cloud-based memory backup library, and an audit log library. The terminal provides memory write, retrieval, and synchronization capabilities through local agents or persistent services; the cloud provides the ability to receive, encrypt, store, access control, and restore de-identified backup data through interface services.

[0014] A role-based large-scale model refers to an AI dialogue system that uses a pre-trained large-scale language model as its core to play a specific role or personality. This model accumulates user-provided information as memory data during continuous interaction, which is then used for subsequent dialogue generation. This memory data refers to historical data such as dialogue content and user-provided information collected and saved by the role-based large-scale model during interaction with the user. This data is considered long-term memory by the model and used to improve the personalization and contextual relevance of responses.

[0015] Memory entries are formed based on memory data and its metadata. Metadata describes the memory data, including but not limited to data identifiers, version numbers, sensitivity scores, sensitivity level tags, and permission tags. The data identifier uniquely identifies the memory data. The version number distinguishes different versions of the same data identifier across multiple memory data entries. The sensitivity score is a score determined by identifying the sensitivity of the memory data, used to assess its sensitivity level. The sensitivity level tag is a classification label used to identify the sensitivity level of the memory data. The permission tag defines the access permissions for each memory data entry in different usage scenarios.

[0016] Sensitivity level labels include non-sensitive labels, low-sensitivity labels, moderately sensitive labels, and high-sensitivity labels, ranging from low to high sensitivity. Non-sensitive labels correspond to publicly available or non-sensitive information and can be used... The term "low-sensitivity label" refers to a label with a low level of sensitivity. It may include less sensitive personal information or other internal information, and can be expressed using [specific methods]. This indicates that sensitive labels are generally labels corresponding to sensitive information such as personal privacy elements. Personal privacy elements are for internal system reference only and cannot be displayed externally by default. They can be expressed as follows: This indicates that highly sensitive labels are those involving high-risk elements such as identity documents, finances, and health. These labels are prohibited from being displayed externally by default and are also prohibited from leaving the local controlled environment. [The text then abruptly shifts to a different topic:] Highly sensitive labels refer to labels with a high degree of sensitivity, specifically those involving high-risk elements such as identity documents, finances, and health. These labels are prohibited from being displayed externally by default and are also prohibited from leaving the local controlled environment. express.

[0017] Permission tags include several types: publicly available tags, scenario-specific available tags, self-available tags, and unavailable tags. Publicly available tags indicate tags that the role model can access in any scenario; these correspond to non-sensitive tags. Scenario-specific available tags restrict access to tags only within a specific scenario; these correspond to low-sensitivity tags. Self-available tags indicate tags that are only usable by the role model itself; that is, the memory data is only used internally by the role model and is not displayed to dialogue objects; these correspond to generally sensitive tags. Unavailable tags indicate tags that the role model cannot use; these correspond to highly sensitive tags. In this example, permission tags are set by the user or assigned by a default policy and are used for matching and filtering during memory retrieval to ensure that the role model's use of memory data complies with preset permissions.

[0018] This invention provides a method for privacy protection and hierarchical permission management of large role model memory data. The method is illustrated using a terminal as an example. Figure 1 As shown, the method includes: S101: Perform sensitivity identification on the memory data during the interaction between the role model and the user, determine the sensitivity score, and determine the sensitivity level label and permission label based on the sensitivity score and the classification threshold; form new memory entries based on the memory data and its metadata, and store the new memory entries in the memory database. The metadata includes the sensitivity score, sensitivity level label and permission label. S102: Perform desensitization and vector transformation processing on the memory data, determine the desensitized representation vector and sensitive feature vector, determine the fusion vector based on the desensitized representation vector and sensitive feature vector, and store the fusion vector in the memory database so as to output the fusion vector when a semantic retrieval request is received; S103: In response to the memory retrieval request triggered by the large role model in the dialogue scenario, retrieve candidate memory entries from the memory database, perform access control on the memory data in the candidate memory entries based on the metadata in the candidate memory entries, and determine the available memory data of the large role model in the dialogue scenario. S104: In response to a memory retrieval request triggered by a model training scenario or a statistical analysis scenario, retrieve a pending memory entry from the memory database, dynamically determine a privacy budget based on the metadata in the pending memory entry, add random noise to the memory data in the pending memory entry based on the privacy budget, and determine the noisy memory data.

[0019] As an example, in step S101, the terminal can obtain memory data of the role model during its interaction with the user. Then, using a pre-set sensitivity recognition algorithm, it performs sensitivity recognition on the memory data to determine the sensitivity score corresponding to the memory data. This sensitivity score reflects the sensitivity level of the memory data. After determining the sensitivity score, the terminal needs to compare the sensitivity score with a pre-set grading threshold to determine the grading interval to which the sensitivity score belongs. The sensitivity level label corresponding to this grading interval is then determined as the sensitivity level label for the memory data. Specifically, there can be K grading thresholds. Based on the K grading thresholds, K+1 grading intervals can be determined. Each grading interval corresponds to a sensitivity level label. The grading interval to which the memory data belongs can be determined based on its sensitivity score, and thus, its corresponding sensitivity level label can be determined. Next, the terminal can query a pre-set sensitivity permission mapping table based on the sensitivity level label to determine the permission label corresponding to the sensitivity level label. Finally, the terminal creates a new memory entry based on the memory data, sensitivity score, sensitivity level label, and permission label, and stores the new memory entry in the memory database for subsequent management of the memory data based on the sensitivity level label and permission label. In this example, the memory database can be a local memory repository or a cloud-based memory backup repository.

[0020] As an example, in step S102, after the terminal obtains the memory data, it needs to perform desensitization processing on the memory data to determine the desensitized memory content and sensitive element information; then, it performs vector transformation processing on the desensitized memory content and sensitive element information respectively to determine the desensitized representation vector and sensitive feature vector; then, it performs fusion processing on the desensitized representation vector and sensitive feature vector according to a pre-set fusion algorithm to determine the fusion vector, and stores the fusion vector in the memory database so that when a semantic retrieval request is received, the fusion vector is output. Since the fusion vector only includes the desensitized memory content and sensitive element information, and does not contain the sensitive memory content, when it receives a language retrieval request in the future, the output fusion vector will also not contain the sensitive memory content, so as to achieve privacy protection for the sensitive memory content.

[0021] As an example, in step S103, the terminal can obtain a memory retrieval request triggered by the role model in a dialogue scenario; in response to the memory retrieval request, it accesses the memory database, retrieves the memory entry corresponding to the memory retrieval request from the memory database, and identifies it as a candidate memory entry. Each candidate memory entry includes memory data and its metadata, including but not limited to sensitivity scores, sensitivity level tags, and permission tags; then, based on the sensitivity scores, sensitivity level tags, and permission tags in the candidate memory entries, it performs permission control on the memory data in the candidate memory entries to evaluate whether the memory data can be used in the dialogue scenario, thus determining the usable memory data of the role model in the dialogue scenario. In this example, permission control is performed based on metadata such as sensitivity scores, sensitivity level tags, and permission tags to determine that only memory data that meets the permissions of the dialogue scenario is usable memory data of the role model in the dialogue scenario, ensuring that sensitive information is not used or exposed by the role model without authorization, thereby ensuring the security of the memory data.

[0022] As an example, in step S104, the terminal can obtain a memory retrieval request triggered in a model training scenario or a statistical analysis scenario, access the memory database in response to the memory retrieval request, retrieve the memory entry corresponding to the memory retrieval request from the memory database, and determine it as a pending memory entry. Each pending memory entry includes memory data and its metadata, including but not limited to sensitivity scores, sensitivity level labels, and permission labels. Then, based on the metadata such as sensitivity scores, sensitivity level labels, and permission labels in the pending memory entry, its privacy budget is determined. Then, based on privacy, random noise is added to the memory data in the pending memory entry in advance to determine noisy memory data, so that the noisy memory data introduces more noise information to achieve privacy protection of the memory data.

[0023] In one embodiment, such as Figure 2 As shown, step S101 involves performing sensitivity identification on the memory data from the interaction between the large role model and the user, determining a sensitivity score, and based on the sensitivity score and grading threshold, determining sensitivity level labels and permission labels, including: S201: Identify privacy elements in the memory data of the large role model and user interaction process, and determine the set of privacy elements corresponding to the memory data. Each privacy element in the set of privacy elements includes type, identification confidence and occurrence frequency. S202: Perform sensitivity calculations on the set of privacy elements to determine the sensitivity score corresponding to the memory data. The sensitivity score is determined using the following formula: ;in, Sensitivity rating; , and The first The type, identification confidence level, and frequency of occurrence of each privacy element; The number of privacy elements; For type weights, The function is a frequency adjustment function. , The threshold for the number of saturation operations. As a scenario risk factor, To combine identifiability factors, and For coefficients; S203: Based on sensitivity scores and grading thresholds, determine the sensitivity level labels and permission labels corresponding to the memorized data, including: At that time, the sensitive level label was determined to be a non-sensitive label. The permission tag is a publicly available tag; in At that time, the sensitivity level label was determined to be a low sensitivity label. Permission tags are tags that can be used in specific scenarios; in At that time, the sensitivity level label was determined to be a general sensitivity label. The permission tag is a tag that can be used by itself; in At that time, the sensitivity level label was determined to be a highly sensitive label. The permission tag is an unavailable tag. , and 3 is the grading threshold. 3.

[0024] As an example, in step S201, the terminal can use data mining and pattern recognition methods, or machine learning and deep learning methods, to process the stored data. Perform privacy element identification to determine memory data The corresponding set of privacy elements Each privacy element At least includes: type Identification confidence level With the number of occurrences .

[0025] As an example, in step S202, the terminal determines the set of privacy elements. After that, it can be accessed through Computational memory data Corresponding sensitivity score ; For the first Type weights of privacy elements ; These are scenario-based risk factors, and they are related to the scenario in which the memory data is located. Normalization to ; Combined identifiability factors refer to a set of information that, while not individually identifying a specific individual, can uniquely or with high accuracy identify an individual when combined with multiple factors. Normalization to The above. , , and All parameters are configurable and allow users to manually correct and overwrite the grading results of individual memory data.

[0026] The tiered thresholds include a first tiered threshold, a second tiered threshold, and a third tiered threshold, set from smallest to largest, denoted as follows: , and 3, 3, – All parameters are configurable and allow users to manually correct and overwrite the hierarchical results of a single memory.

[0027] As an example, in step S203, the terminal's sensitivity score is less than the first grading threshold (i.e., When the data is classified as public or non-sensitive, the sensitivity level label corresponding to the data can be determined as a non-sensitive label. The permission tag corresponding to the memory data is determined to be a publicly available tag. The terminal's sensitivity score is not less than the first-level threshold and is less than the second-level threshold (i.e.,...). When the data in question is determined to be personal information or other internal information with a relatively low sensitivity, the sensitivity level label corresponding to the data in question is determined to be a low-sensitivity label. The permission tags corresponding to the memory data are tags available for specific scenarios. The terminal's sensitivity score is not less than the second-level threshold and is less than the third-level threshold (i.e.,...). When it is determined that the memory data involves sensitive elements such as personal privacy, the sensitivity level label corresponding to the memory data is determined to be a general sensitivity label. The permission tags corresponding to the stored data are the tags that the terminal can use. The terminal's sensitivity score is not less than the third-level threshold (i.e., When it is determined that the memory data involves high-risk elements such as identity credentials, finances, and health, the sensitivity level label corresponding to the memory data is determined to be a high-sensitivity label. The permission tag corresponding to the memory data is the unavailable tag.

[0028] For example, when a terminal acquires new memory data generated during the interaction between a role model and a user, it needs to invoke its built-in privacy classification rules and sensitive dictionary model to classify the memory data for sensitivity and assign permission labels. Specifically, this includes: when new memory data (such as a dialogue text) is input, automatically detecting sensitive information elements (such as name, ID number, and contact information) in the memory data and calculating a sensitivity score. And sensitivity score With three graded thresholds , and Based on the comparison results of 3, determine the corresponding sensitivity level label ( - The sensitivity level label ( - This is appended to the memory entry as metadata, and a permission tag is assigned to that memory data. The default policy for permission tags is preset: highly sensitive tags ( The corresponding data, by default, prohibits the large role model from being displayed in any answer, and its corresponding permission tag is "unavailable"; generally, sensitive tags ( The corresponding data is only allowed for internal reference within the large character model and cannot be externally referenced. Its corresponding permission tags are tags that are available only to the character itself, and low-sensitivity tags ( The data corresponding to ) is only available in the corresponding internal scenario by default, and its corresponding permission tag is a tag available in a specific scenario; non-sensitive tags ( The corresponding data is free by default, and its corresponding permission tag is a publicly available tag. In addition, users can adjust the permission tag later through the permission management interface, for example, changing a record from "available only within the role model" to "available only in medical consultation scenarios", so as to switch from a tag available to a tag available in a specific scenario.

[0029] In one embodiment, such as Figure 3 As shown, step S101 involves forming a new memory entry based on the memory data and its metadata, and storing the new memory entry in the memory database, including: S301: Encrypt the memory data using the encryption strategy corresponding to the sensitivity level label, determine the encrypted memory data, form a new memory entry based on the encrypted memory data and its metadata, and store the new memory entry in the local memory repository; S302: When the sensitivity score corresponding to the memory data is less than the synchronization threshold, the memory data is desensitized, a desensitized backup copy is determined, a new memory entry is formed based on the desensitized backup copy and its metadata, and the new memory entry is synchronized to the cloud memory backup library through an encrypted transmission channel.

[0030] The synchronization threshold is a threshold used to assess whether cloud synchronization is allowed, and can be adopted using... This indicates that the synchronization threshold can be compared with the second-level threshold. They can be the same or different. A memory database is a database containing memory entries; it can be a local memory repository set up on the terminal or a cloud-based memory backup repository set up in the cloud.

[0031] As an example, in step S301, after determining the sensitivity level label and permission label corresponding to each piece of memory data, the terminal needs to use the encryption strategy corresponding to the sensitivity level label to encrypt the memory data corresponding to different sensitivity level labels, and then determine the encrypted memory data. For example, for memory data with a higher sensitivity level (e.g., general sensitivity labels)... or highly sensitive labels When storing sensitive data, a symmetric-key encryption algorithm or an equivalent commercial cryptographic algorithm can be used for encrypted storage. Furthermore, a secure key container provided by a hardware security module, a trusted execution environment, or the operating system can be used to isolate and manage the keys, preventing malicious programs from gaining access to the device's storage and deciphering plaintext sensitive information. For less sensitive data (e.g., non-sensitive tags), [further details can be provided]. or low-sensitivity labels Lower-strength encryption (such as lightweight symmetric encryption) is used to determine the encrypted memory data to balance performance. In this example, all newly added memory entries formed by the encrypted memory data and its metadata are recorded in a local memory repository for quick retrieval later. The metadata here includes, but is not limited to, data identifiers, version numbers, sensitivity level tags, permission tags, and sensitivity scores. .

[0032] As an example, in step S302, the terminal will also assign a sensitivity score to each piece of memory data. With synchronization threshold Comparison; in sensitivity scores Greater than the synchronization threshold At times, for example, in = Its sensitivity level label was determined to be a general sensitivity label. or highly sensitive labels When the sensitivity of the memory data is determined to be high, cloud uploads are prohibited. Only newly created memory entries, formed by the encrypted memory data and its metadata, are stored in the local memory repository. (This is based on the sensitivity score.) Not greater than the synchronization threshold At times, for example, in = Its sensitivity level label was determined to be a low sensitivity label. or non-sensitive labels In this case, the memory data can be locally anonymized to create an anonymized backup copy. New memory entries are then created based on the anonymized backup copy and its metadata. These new memory entries are uploaded and stored in the cloud memory backup repository via an encrypted transmission channel. In this example, anonymization refers to performing de-identification and obfuscation operations on the memory data, removing or replacing information that may identify the user's personal identity.

[0033] In this example, only when the sensitivity score for the memory data is less than the synchronization threshold is the condition met. (For example, belonging to) or Only when the sensitivity score exceeds the synchronization threshold will the stored data be anonymized, generating an anonymized backup copy which is then uploaded to the cloud-based backup repository via an encrypted transmission channel. Because the anonymized backup copy has already undergone de-identification processing on the terminal before uploading, and is then encrypted and stored in the cloud via an encrypted transmission channel before access control is implemented, this approach reduces the risk of privacy leaks while meeting the needs for cross-device synchronization and long-term storage. (For example or The memory data is prohibited from being uploaded to the cloud, thereby ensuring that highly sensitive memory data does not leave the terminal. This type of memory data is encrypted and managed with key isolation, so that unauthorized external entities cannot obtain usable plaintext.

[0034] This embodiment employs an edge-cloud collaborative hybrid storage architecture, storing memory data in tiers based on its sensitivity. Memory data with higher sensitivity (e.g., data with a sensitivity level label of...) is stored in a hierarchical manner. or ) is always stored only in the terminal's local memory repository, and is secured using encryption methods such as master key derivation and hardware security modules; less sensitive memory data (sensitivity level labeled as...) or The data is then anonymized and backed up in the cloud. The terminal sends an anonymized backup copy to the cloud, and both the transmission channel (e.g., HTTPS) and cloud storage are protected by encryption and access control. This architecture implements a strategy that prioritizes local storage and supplements it with cloud backup. While ensuring that highly sensitive data is prohibited from being uploaded to the cloud, it also addresses the needs of multi-device sharing and long-term storage. It prioritizes data security on the terminal while allowing cloud resources to be utilized to improve service continuity when necessary.

[0035] In this example, the terminal can decide whether to perform cloud synchronization backup based on the sensitivity level label of the stored data. Specifically, if the sensitivity score of the stored data is less than the synchronization threshold... Then, the cloud backup operation is executed. Specifically, the memory data to be uploaded is first anonymized (e.g., text placeholder replacement, numerical range generalization), and then transmitted through an encrypted transmission channel. The de-identified backup copy and its metadata are sent to the cloud so that the cloud can store them in a cloud-based backup repository. The cloud verifies the identity of the terminal (e.g., ...). After obtaining the token, the newly added memory entry will be stored in the cloud memory backup library, and the de-identified backup copy will be encrypted and stored again (e.g., To prevent unauthorized internal access, the cloud-based memory backup repository uses anonymous identifiers to distinguish data from different users and does not directly store users' real identity information, further enhancing privacy protection.

[0036] In one embodiment, step S301 involves encrypting the memory data using an encryption strategy corresponding to the sensitivity level label, determining the encrypted memory data, forming a new memory entry based on the encrypted memory data and its metadata, and storing the new memory entry in a local memory repository, including: Generate master key The storage key is derived from the master key. Index key With mapping table key Based on storage key Index key With mapping table key Encrypt the corresponding content in the memory data, determine the encrypted memory data, form a new memory entry based on the encrypted memory data and its metadata, and store the new memory entry in the local memory repository. The method also includes: regenerating a new master key when the key rotation conditions are detected. Using a new master key Re-encrypt the protected data in the local memory repository.

[0037] As an example, the terminal generates a master key for the local memory repository. (Set by the user) (derived from code or biometric information), and through The storage key is derived from the algorithm. Index key With mapping table key Storage key From the master key via the HKDF algorithm Derived from this, it is used to encrypt memory data stored in the local memory repository. Index key. From the master key via the HKDF algorithm This is derived from an index structure (such as data identifier ID, tag, timestamp, etc.) used for encrypting or protecting data. Mapping table key. From the master key via the HKDF algorithm This is derived from the placeholder mapping table and reversible recovery material used for encryption protection. The placeholder mapping table is used to replace actual data with placeholders when data is deleted or updated, preventing the leakage of deletion traces. The reversible material is used to restore access to the data if the key is lost or replaced. In this example, each working key performs its specific function, protecting the data itself, the data index, and auxiliary management data respectively, forming a layered, in-depth security protection.

[0038] As an example, the terminal supports key rotation. When key rotation conditions are triggered (such as rotation every 90 days, user-initiated rotation in the permission settings interface, or rotation triggered after abnormal access is detected), a new master key is generated. Perform re-encryption on protected data in the local memory repository (or use...) The old key is encapsulated, and the rotation event (including rotation time, triggering reason, and amount of data involved) is stored in the log database.

[0039] In one embodiment, step S302, namely, desensitizing the memory data and determining the desensitized backup copy, includes: When the memory data is text memory data, privacy elements are identified in the memory data to determine the set of privacy elements corresponding to the memory data. Placeholders are generated based on the type corresponding to each privacy element in the privacy element set, and the placeholders are used to replace the original content corresponding to the privacy elements. When the stored data is structured or numerical field data, use The memory data is subjected to interval generalization processing, where, The original values ​​in the memory data. The values ​​are the range generalized values. It is a rounding function. This is the generalization granularity parameter; When the memory data is date and time field data, perform granular downsampling on the memory data; When the memory data is image memory data or audio memory data, feature extraction is performed on the memory data to determine the feature summary vector, and an index identifier is generated based on the feature summary vector and the terminal key.

[0040] As an example, when the terminal stores text-based data, it needs to determine the stored data. The corresponding set of privacy elements Each privacy element At least include type Identification confidence level With the number of occurrences From the set of privacy elements Identify the privacy elements that need to be replaced and according to the privacy element Corresponding type Generate placeholders For example, "[Name-1]" and "[Phone Number-1]" use placeholders to replace the original content corresponding to privacy elements, thereby desensitizing the text memory data; among which This refers to the sequence number of the same type of privacy element within this memory data. For example, text memory data can be modified using regular expressions to replace the middle four digits of a phone number with "****".

[0041] As an example, when the terminal stores data as structured or numeric fields, it uses... Range generalization is performed on the memory data to desensitize structured or numerical fields. To generalize the granularity parameter, it can be, but is not limited to, a monetary field or an age field. For example, with a monetary field (Δ=100), if x=123 yuan, then... = This converts precise monetary values ​​into ranges to ensure that uploaded content does not contain information that can directly identify an individual.

[0042] As an example, when the terminal stores date and time field data, it performs granular downsampling on the stored data. For example, the day and month of XX year XX month XX day are hidden, and only the year is retained. This is downsampled to XX year to desensitize the date and time field data.

[0043] As an example, when the memory data is image memory data (which can be images or videos) or audio memory data, the terminal performs feature extraction on the memory data to determine a feature summary vector. For example, CNN features of images or MFCC features of audio; then, based on the feature summary vector and terminal key Generate index identifier Specifically based on Generate index identifier To desensitize image or audio memory data, among which, For keyed hash functions (such as...) ), so that subsequent identification based on index can be used. Retrieve the memory data. In this example, the terminal key is a terminal-managed key, specifically stored in the terminal's local memory repository.

[0044] In this embodiment, different desensitization methods are used for different types of memory data. A desensitized backup copy is determined, and then the desensitized backup copy and its metadata are used to form a new memory entry. The new memory entry is synchronously stored in the cloud memory backup library through an encrypted transmission channel, so that the cloud only stores the desensitized backup copy and metadata (such as "2024 image summary"), and does not store the reversible memory data. For placeholder mapping tables that need to be reversibly recovered (such as "[Name-1]→Zhang San"), they are only stored in the local memory storage library of the terminal and are cleared when the user revokes authorization or deletes the memory, thereby ensuring desensitization and revocability.

[0045] In this embodiment, data anonymization is used to protect the privacy of memory data, achieving multi-level anonymization and desensitization without affecting the normal function of the large character model. For text-based memory data, the personal identifier is replaced with a mask; for numerical memory data, interval generalization (e.g., ...) is used. ); Extract feature summary vectors from non-text data such as image memory data or audio memory data. And generate a key hash index. In particular, all memory data that needs to be uploaded to the cloud must first undergo an anonymization algorithm locally to ensure that even if the cloud data is leaked, it is difficult to restore the plaintext privacy information.

[0046] In one embodiment, step S302, which involves synchronizing newly added memory entries to the cloud memory backup library via an encrypted transmission channel, includes: When two-way authentication is completed between the terminal and the cloud, the newly added memory entries are synchronized to the cloud through an encrypted transmission channel, and the cloud's confirmation signal is listened for. If no acknowledgment signal is received within the preset time period, the newly added memory entry will be written to the local synchronization queue, and the retry count corresponding to the newly added memory entry will be updated. Based on the order of the local synchronization queue, new memory entries with fewer than the retry threshold are synchronized to the cloud memory backup library via an encrypted transmission channel.

[0047] As an example, when a terminal establishes a connection with the cloud, it first completes two-way authentication (the terminal verifies the cloud certificate, and the cloud verifies the terminal). Token) and negotiate session key (such as Key exchange is performed, followed by the transmission of a de-identified backup copy and its metadata (including sensitivity level labels, permission labels, timestamps, and version numbers) through an additional transmission channel. A queue-based retry mechanism is used during cloud synchronization; that is, when the terminal is offline or the cloud is unreachable, the new memory entries to be synchronized are written to the local synchronization queue (e.g., ...). The system records the number of retries and the backoff time (the time interval during which the system waits before retrying after a synchronization failure caused by a terminal going offline or the cloud being unreachable). After the network is restored, the cloud synchronization task is re-executed according to the order of the local synchronization queue based on the backoff time. Based on the order of the local synchronization queue, it is determined whether the number of retries for each new memory entry has reached the retry threshold (e.g., 3 times). If the retry threshold is reached, the new memory entry is deleted. If the retry threshold is not reached, new memory entries with fewer retries than the retry threshold are synchronized to the cloud memory backup library through an encrypted transmission channel.

[0048] In one embodiment, the cloud maintains a version number for each new memory entry. During the synchronization of new memory entries to the cloud memory backup library via an encrypted transmission channel, conflict detection is performed based on the data identifier and version number of the new memory entry to determine whether there are conflicts caused by concurrent modifications from multiple terminals. That is, it checks whether there are new memory entries with the same data identifier but different version numbers that need to be added to the library. When a conflict exists, a merging strategy prioritizing those with stricter permissions is implemented to determine the memory entries to be retained. A confirmation request is formed by at least two conflicting memory entries and the memory entries to be retained, and the confirmation request is sent to the terminal so that the user can determine the memory entries to be protected based on the confirmation request displayed on the terminal. For example, when two memory entries conflict, the permission tags of the two memory entries are compared, and the memory entry with the version number that has fewer available scenarios is determined as the memory entry to be retained. Then, a confirmation request is formed based on the two conflicting memory entries and the selected memory entry to be retained, and submitted to the user for confirmation. For example, the control terminal displays a prompt "Memory conflict detected, do you want to retain the 'Home Only' version?" to avoid the risk of unauthorized access caused by a lenient policy overriding a strict policy.

[0049] In one embodiment, the method further includes: Receive a deletion request triggered by a user. The deletion command carries the entry identifier and version number. Based on the target identification and version number, identify the memory entries to be deleted in the local memory repository, delete the memory entries to be deleted from the local memory repository, and perform an erasure operation on the deleted area. When it is determined that a de-identified backup copy of the memory entry to be deleted exists, a deletion request is sent to the cloud so that the cloud can perform an irreversible deletion operation and return a deletion confirmation. Upon receiving confirmation of deletion, the deleted memory is updated in the log database, and the memory entry to be deleted is removed from the local synchronization queue.

[0050] As an example, a terminal can receive a deletion request triggered by a user for a specific memory entry, the deletion request carrying at least the following information: Version number Upon receiving the deletion request along with the deletion reason code, it is necessary to first determine the entry identifier. and version number The local memory repository is queried to identify the corresponding memory entry to be deleted. Then, this entry is deleted from the local memory repository, specifically the plaintext entry, placeholder mapping table entries, and vector index entries. An erasure operation (e.g., overwriting random data) is performed on the deleted area. Next, if a de-identified backup copy of the memory entry exists (i.e., a de-identified backup copy is synchronously stored in the cloud), a deletion request needs to be sent to the cloud so that the cloud can irreversibly erase the de-identified backup copy and its index in its cloud memory backup repository (if it meets the following criteria). The system performs a standard erase and sends a deletion confirmation back to the terminal. After receiving the deletion confirmation from the cloud, the terminal updates the deletion record in the log database and clears the relevant tasks in the local synchronization queue, ensuring that the deletion reversal is consistently effective across the terminal storage, cloud backup, and vector index.

[0051] In one embodiment, such as Figure 4 As shown, step S102 involves desensitizing and vectorizing the memorized data to determine the desensitized representation vector and the sensitive feature vector, and then determining the fusion vector based on the desensitized representation vector and the sensitive feature vector, including: S401: Desensitize the memory data, determine the desensitized memory content and sensitive element information, determine the desensitized representation vector based on the desensitized memory content, and determine the sensitive feature vector based on the sensitive element information; S402: Perform dimension alignment and normalization on the desensitized representation vector and the sensitive feature vector to determine the normalized desensitized representation vector and the normalized sensitive feature vector; S403: Perform weighted fusion processing on the normalized desensitized representation vector and the normalized sensitive feature vector to determine the fusion vector corresponding to the memory data; The fusion vector is determined by the following formula: , , For the fusion vector, This is the normalized desensitization representation vector. For normalized sensitive feature vectors; , For the strength of authorization, Score for context matching. Sensitivity rating, , , and These are configurable parameters. .

[0052] As an example, in step S401, after acquiring each piece of memory data, the terminal needs to perform de-identification processing on each piece of memory data to determine the de-identified memory content and sensitive element information. The de-identified memory content refers to the content of the memory data after de-identification; the sensitive element information refers to information related to sensitive elements, including but not limited to sensitive element placeholders or sensitive field categories. Next, the terminal needs to use a text encoding model to process the de-identified memory content and generate a de-identified representation vector. And process the sensitive element information to generate sensitive feature vectors. .

[0053] As an example, in step S402, the terminal can desensitize the representation vector. and sensitive feature vectors Perform dimension alignment and normalization to determine the normalized desensitized representation vector. and normalized sensitive feature vector Specifically, dimension alignment and normalization are performed using the following formula: , ,in, , This is a preset linear transformation matrix (with a uniform dimension of 512). for Normalization operator.

[0054] As an example, in step S403, the terminal can normalize the desensitized representation vector. and normalized sensitive feature vector Perform weighted fusion processing to determine the fusion vector corresponding to the memory data. The weighted fusion process is specifically performed using the following formula: ,in, , and , and The corresponding weighting coefficients can be dynamically determined based on the sensitivity level label and authorization status. For example, when the sensitivity level label of the memorized data is... And it was not authorized ( (When taking) , When the sensitivity level label of the memory data is / And the authorization is sufficient ( , (When taking) , This allows for the dynamic determination of corresponding weight coefficients based on sensitivity level labels and authorization status.

[0055] Furthermore, to achieve a dynamic balance between privacy and availability, Determined using a gating function: Perform gating adjustment (such as) , , , This allows for a balance between privacy suppression and recall performance during the retrieval phase.

[0056] In one embodiment, such as Figure 5 As shown, step S103, in response to the memory retrieval request triggered by the large character model in the dialogue scenario, retrieves candidate memory entries from the memory database, performs access control on the memory data in the candidate memory entries based on the metadata in the candidate memory entries, and determines the available memory data of the large character model in the dialogue scenario, including: S501: In response to a memory retrieval request triggered by the large character model in a dialogue scenario, retrieve candidate memory entries from the memory database. Candidate memory entries include memory data and its metadata, which includes permission tags and sensitivity scores. S502: Determine the permission matching score between the dialogue context and permission tags corresponding to the dialogue scenario. The permission matching score is determined by the following formula: ;in, The permission matching score for the i-th memory data. This is a permission vector determined based on permission tags. This is a context vector determined based on the dialogue context; For transpose; Scoring the permissions corresponding to all candidate memory entries; The permissions are formed row by row from the permission vectors corresponding to all candidate memory entries; S503: When the permission matching score is greater than or equal to the dynamic threshold, the memory data is determined to be the available memory data of the role model in the dialogue scenario; S504: When the permission matching score is less than the dynamic threshold, the memory data is determined to be unusable memory data of the role model in the dialogue scenario; The dynamic threshold is determined by the following formula: ;in, The dynamic threshold corresponding to the i-th memory data is... Based on the threshold, For the sensitivity score corresponding to the i-th memory data, For the strength of authorization, and is a coefficient.

[0057] As an example, the terminal can obtain a memory retrieval request triggered by a dialogue scenario from a large role model. This memory retrieval request can be understood as a request from the large role model to retrieve a memory database, including retrieval criteria. Based on the retrieval criteria in the memory retrieval request, the terminal queries the memory database and retrieves one or more memory entries that match the retrieval criteria, identifying them as candidate memory entries. In this example, each memory entry in the memory database includes memory data and its corresponding metadata, which includes, but is not limited to, sensitivity scores, sensitivity level labels, and permission labels. In this example, the terminal can query a local memory repository based on the memory retrieval request to determine candidate memory entries corresponding to any sensitivity level label, or it can query a cloud-based memory backup repository based on the memory retrieval request to determine non-sensitive labels. or low-sensitivity labels The corresponding candidate memory entries.

[0058] As an example, the terminal needs to perform permission verification and matching for each candidate memory entry one by one, specifically including the following steps: First, convert the permission tags of the memory data into permission vectors. Different dimensions correspond to predefined scenarios or identity attributes. For example, 1 indicates that the memory data is available in that scenario, and 0 indicates that it is unavailable. Furthermore, the dialogue context corresponding to the dialogue scenario is converted into a context vector. Each dimension of this vector corresponds to the meaning of the permission vector. Next, according to... The permission vector corresponding to the memory data Context vectors corresponding to dialogue scenarios Perform calculations to determine the permission matching score corresponding to the i-th memory data. .

[0059] In another example, the terminal can also use a permission matrix matching algorithm to efficiently implement the permission verification process: a permission matrix is ​​formed by arranging the permission vectors corresponding to all candidate memory entries row by row. (dimension) , The number of candidate memory entries, (the number of scene dimensions), the context vector As a column vector, the permission matching score is calculated using matrix multiplication. Quickly determine which memory data meet the requirements. The conditions are equivalent to performing permission checks one by one in batches. This batch processing method can reduce the latency of dialog retrieval (e.g., (At the same time, matrix operations take less than 10ms), improving the system's real-time response capability. Furthermore, for general sensitive tags marked "not publicly visible". The system adds extra filtering logic to the output layer: it performs sensitive element detection on the response text generated by the large character model. If it contains unauthorized sensitive placeholders (such as "[ID number-1]"), it automatically replaces them with vague expressions (such as "related identity information") or prompts the user to grant authorization (such as "You need to authorize access to your identity information before you can get a complete answer"). Permission matrix. The permission vector stores all memory data, and the context vector of the dialogue scenario. After inputting the data, the matching score needs to be calculated for each entry. With dynamic threshold It outputs a list of memory entries that conform to the permission rules and blocks entries that do not meet the permissions. This structure enables rapid comparison and filtering of large amounts of memory data against multi-dimensional scenario permissions.

[0060] The terminal also needs to adopt A dynamic threshold is dynamically calculated for each piece of memory data. This dynamic threshold is used to assess whether the memory data is allowed to be used in a dialogue scenario. Authorization Strength This can be understood as the degree of trust that a character's large model has in accessing memory data within the context of a dialogue, which can be normalized to the range [0,1]. Authorization strength As a negative moderating term, the strength of authorization The larger it is, the higher its corresponding dynamic threshold. The smaller the value, the easier it is for the stored data to be granted access; conversely, the greater the value, the stronger the authorization. The smaller the value, the higher the corresponding dynamic threshold. The larger the size, the more difficult it is for the stored data to be approved.

[0061] The terminal also needs to match the permissions and scores corresponding to each candidate memory entry. Its corresponding dynamic threshold Compare; when the permission matching score is greater than or equal to the dynamic threshold (i.e. When the memory data is determined to be usable memory data of the large role model in the dialogue scenario, that is, the permission of the memory data in the dialogue scenario is determined to be allowed, meaning the large role model can call the memory data in order to enter the subsequent retrieval and generation process; when the permission matching score is less than the dynamic threshold (i.e. When a memory data entry is determined to be unusable by the large role model in a dialogue scenario, its permissions in that scenario are deemed prohibited. This means the large role model cannot access the memory data, and the candidate memory entry must be removed. In this example, permission matching scores are used for interception to ensure that only memory data with a permission matching score greater than or equal to a dynamic threshold can be used by the large role model. This ensures that sensitive information is not accessed or displayed without authorization, thereby protecting the security of the memory data.

[0062] For example, based on the first The permission vector determined by the permission tags corresponding to each piece of memory data. , indicating the first Memory data is allowed to be used in scenarios 1 and 3, but not in scenario 2; while context vectors are determined based on the dialogue context corresponding to the dialogue scenario. The dialogue scenario is designated as Scenario 2; the dot product is calculated. ,and (Base threshold) ),but If the usage conditions are not met, all memory data that does not conform to the dialogue scenario permissions must be filtered out, and only memory data that meets the usage conditions should be retained for use by the large character model. In actual implementation, more complex strategies such as multi-level priority and time validity period can also be considered, but in principle, memory data should be filtered according to preset permission rules, and those that do not meet the conditions should not be provided to the large character model.

[0063] This embodiment provides a fine-grained permission control mechanism. By introducing permission tags to each memory record, it empowers users to independently set and adjust the visibility of each memory record. These permission tags include publicly available tags, scenario-specific available tags, self-available tags, and unavailable tags. During memory retrieval and recall, the terminal strictly matches and filters based on permission tags and the dialogue context. Specifically, it first intercepts the query results of the role model to the memory database, and then verifies the sensitivity score, sensitivity level tag, permission tag, and permission matching score of each candidate memory entry against the dialogue context (calculated). and with dynamic threshold (Comparison) Automatically removes memory data that exceeds permissions, ensuring that the role model only uses memory data within the scope authorized by the user to answer questions. For example, in a casual conversation scenario where the user has not explicitly authorized financial information, any tags marked as work-related or sensitive will be discarded. / Candidate memory entries will not be provided to the large character model. Furthermore, this invention provides a permission settings interface, allowing users to browse and adjust the permission tags for each memory entry, granting or disallowing permissions for specific functions, thus achieving fine-grained control over the large character model's use of its memory data.

[0064] In one embodiment, the method further includes: When any memory entry is detected to meet the downgrade conditions, the authorization strength corresponding to the memory entry is reduced. Downgrade conditions include missing attributes in the dialogue context, and permission tags being changed or revoked. When any memory entry is detected to meet abnormal conditions, the access circuit breaker mechanism is triggered, and the retrieval and output of memory data for general sensitive tags or highly sensitive tags are suspended during the preset cooling period. An abnormal condition is that the number of unauthorized retrieval requests or out-of-town retrieval requests received within a preset time period exceeds the unauthorized number threshold. Unauthorized retrieval requests are memory retrieval requests with permission matching scores less than the dynamic threshold. Out-of-town retrieval requests are memory retrieval requests from out-of-town IP addresses accessing memory data corresponding to general sensitive tags or highly sensitive tags.

[0065] As an example, when a terminal cannot obtain all the content of the dialogue context corresponding to a dialogue scenario—that is, when some contextual attributes are missing, such as scene recognition failure or missing user identity status—the system defaults to handling the situation according to the principle of least privilege. In this case, it is necessary to reduce the authorization strength of the memory entry, for example, by lowering its authorization strength. Set to 0 to determine the dialogue context as a low-authority state. ), thereby improving the dynamic threshold (like This reduces the amount of available memory data output, allowing it to output only publicly available tags. The corresponding memory data.

[0066] In another example, when the terminal detects that a permission tag has been changed or revoked—for example, when a user changes a memory data tag from "publicly available," "scenario-specific," or "self-available" to "unavailable" in the permission settings interface—it needs to adjust the authorization strength of the relevant memory entry. Reduce to 0 and refresh the weight parameters of the fusion vector. This ensures that the system will not carry sensitive feature components in subsequent searches.

[0067] As an example, if a terminal detects that the number of unauthorized retrieval requests received within a preset time period exceeds a threshold for the number of unauthorized requests (e.g., 5 times), for instance, if it receives more than 5 memory retrieval requests within 1 minute that have an access score less than a dynamic threshold, it determines that it meets an abnormal condition. Alternatively, if a terminal detects that the number of out-of-area retrieval requests received within a preset time period exceeds a preset threshold, it determines that it meets an abnormal condition. Here, out-of-area retrieval requests refer to memory retrieval requests from out-of-area IP addresses accessing memory data corresponding to general sensitive tags or highly sensitive tags.

[0068] When the terminal determines that abnormal conditions are met, it triggers the access circuit breaker mechanism, suspending the retrieval and output of memory data for general sensitive tags or highly sensitive tags during a preset cooling-off period. Users are only allowed access through the local secure interface (which requires biometric verification or...). Manual confirmation and recovery can be performed in the code to reduce the risk of mass leakage caused by automated attacks or misconfiguration.

[0069] In one embodiment, such as Figure 6As shown, step S104, in response to a memory retrieval request triggered by a model training scenario or statistical analysis scenario, retrieves a pending memory entry from the memory database, dynamically determines a privacy budget based on the metadata in the pending memory entry, adds random noise to the memory data in the pending memory entry based on the privacy budget, and determines the noisy memory data, including: S601: In response to a memory retrieval request triggered by a model training scenario or a statistical analysis scenario, retrieve a ready-to-use memory entry from the memory database. The ready-to-use memory entry includes memory data and its metadata, including sensitivity level labels and sensitivity scores. S602: Based on the privacy budget dynamically determined by the sensitivity level label, the memory data in the candidate memory entries is noise-added using a Laplace noise-adding mechanism or a Gaussian noise-adding mechanism to determine the noisy memory data; The Laplace noise addition mechanism is determined by the following formula: , ; The Gaussian noise addition mechanism is determined by the following formula: , and , , Related; To add noise to memory data; For memory data in the pending memory entries; Budget for privacy; for Sensitivity for Sensitivity This is the failure probability parameter.

[0070] As an example, the terminal can receive memory retrieval requests triggered by model training or statistical analysis scenarios. These requests require accessing memory data from a memory database for model training and statistical analysis, and include retrieval conditions. Based on the retrieval conditions in the memory retrieval request, the terminal queries the memory database and retrieves one or more memory entries that match the conditions, identifying them as available memory entries. In this example, each memory entry in the memory database includes memory data and its corresponding sensitivity score, sensitivity level label, and permission label.

[0071] As an example, the terminal employs a mathematical privacy protection technique based on a random mechanism to limit the discriminative impact of a single data point on statistical analysis or model training results. This invention uses... -Differential privacy representation: where, The privacy budget (upper bound of privacy loss) is dynamically determined based on sensitive permission tags. The failure probability parameter is preset. The sensitivity function is used. The maximum output change on adjacent datasets; adding noise to the numerical query output can be achieved using the Laplace noise mechanism. ,in , for Sensitivity, guarantee - Differential privacy; Gaussian noise addition can also be used: ,in and , , Related, for Sensitivity; among which, For memory data in the pending memory entries, and This involves adding noise to the memory data. In this example, the noisy memory data can be injected into the statistical query output, retrieval scores / ranking scores, or training update amounts / gradients, and privacy expenditures can be accumulated through a privacy ledger to ensure overall privacy budget constraints.

[0072] Differential privacy mechanisms are introduced during model training or data analysis, employing sample-by-sample gradient pruning and Gaussian noise injection. The process dynamically allocates privacy budgets based on the sensitivity level of the stored data. Minimum level allocation Furthermore, by accumulating expenditures through a privacy ledger, the impact of a single data point on the model's training output or statistical analysis results is ensured to be limited to a preset range. Through these measures, even if the large role model references user historical information to generate answers, it will only use content that has been anonymized and noise-added, and will not directly expose users' confidential details.

[0073] The processing flow of the method for privacy protection and hierarchical permission management of large role model memory data provided in this invention generally includes two main parts: storage of new memory data and memory retrieval. The former handles the classification, storage, and cloud backup of newly added memory data; the latter handles permission filtering and secure output when the large role model accesses memory data. Specifically, it includes the following steps: (a) Sensitivity Classification and Labeling After the memory data is generated, the terminal needs to classify and assign permission labels to it. This involves calling its built-in privacy classification rules and sensitive dictionary model to classify and assign permission labels to the memory data. Specifically, this includes automatically detecting sensitive information elements (such as name, ID number, and contact information) in the new memory data (e.g., a dialogue text) when it is input, and calculating a sensitivity score. and sensitivity score With three graded thresholds , and Based on the comparison results of 3, determine the corresponding sensitivity level label ( - The sensitivity level label ( - This is appended to the memory entry as metadata, and a permission tag is assigned to that memory data. The default policy for permission tags is preset: highly sensitive tags ( The corresponding data, by default, prohibits the large role model from being displayed in any answer, and its corresponding permission tag is "unavailable"; generally, sensitive tags ( The corresponding data is only allowed for internal reference within the large character model and cannot be externally referenced. Its corresponding permission tags are tags that are available only to the character itself, and low-sensitivity tags ( The data corresponding to ) is only available in the corresponding internal scenario by default, and its corresponding permission tag is a tag available in a specific scenario; non-sensitive tags ( The corresponding data is free by default, and its corresponding permission tag is a publicly available tag.

[0074] (ii) Local encrypted storage After determining the metadata such as sensitivity score, sensitivity level label, and permission label corresponding to the memory data, new memory entries need to be created based on the memory data and its related data, and these new memory entries are saved to the terminal's local memory repository. For example, for memory data with a high sensitivity level (e.g., general sensitivity labels)... or highly sensitive labels When storing sensitive data, a symmetric-key encryption algorithm or an equivalent commercial cryptographic algorithm can be used for encrypted storage. Hardware security modules, trusted execution environments, or secure key containers provided by the operating system can be used to isolate and manage the keys, preventing malicious programs from gaining access to the device's storage and deciphering plaintext sensitive information. For less sensitive data (e.g., non-sensitive tags), [further details can be provided]. or low-sensitivity labels Lower-strength encryption (such as lightweight symmetric encryption) is used to determine the encrypted memory data to balance performance. In this example, all newly added memory entries formed by the encrypted memory data and its metadata are recorded in a local memory repository for quick retrieval later. The metadata here includes, but is not limited to, data identifiers, version numbers, sensitivity level tags, permission tags, and sensitivity scores. .

[0075] In this example, the terminal generates a master key for the local memory repository. (Set by the user) (derived from code or biometric information), and through The storage key is derived from the algorithm. Index key With mapping table key ;in Used to protect placeholder mapping tables and reversible recoverable materials. The system supports key rotation: when key rotation conditions are triggered (such as rotation every 90 days, user-initiated rotation via the permission settings interface, or rotation triggered after detecting abnormal access), a new master key is generated. Perform re-encryption on protected data in the local memory repository (or use) Encapsulate the old key and record the rotation event (including rotation time, triggering reason, and amount of data involved).

[0076] (III) Desensitization treatment The terminal needs to employ different de-identification rules to de-identify different forms of memory data in order to determine the de-identified content and sensitive information of each type of memory data, and to create de-identified backup copies. For example, when the memory data is text-based, the terminal needs to determine the... Corresponding privacy elements Generate placeholders according to feature type. (e.g., "[Name-1]", "[Mobile Number-1]"), placeholders are used to replace the original content corresponding to privacy elements to desensitize the text-based data. For structured or numerical field data, range generalization is preferred for desensitization processing: ,in To generalize granular parameters (such as amount fields) Age field Alternatively, perform granular downsampling on date and time field data (e.g., year-month-day → year-month or quarter). For non-text data such as images, videos, and audio, it is preferable to extract only feature summary vectors. (as shown in the image) Features, audio Features are used to retrieve matches and generate index identifiers for them. ,in For keyed hash functions (such as...) ), The terminal key (managed by a local memory repository) is stored only in the terminal's local memory repository and is cleared when the user revokes authorization or deletes the memory, thereby ensuring desensitization and revocability.

[0077] (iv) Vector Fusion The terminal needs to de-identify each piece of memory data, determine the de-identified memory content and sensitive element information, and call a predetermined text encoding model to process the de-identified memory content and generate a de-identified representation vector. It also processes sensitive element information such as placeholders for sensitive elements or categories of sensitive fields to generate sensitive feature vectors. Next, the desensitization representation vector... With sensitive feature vectors Perform dimensional alignment and normalization: , ,in , This is a preset linear transformation matrix (with a uniform dimension of 512). for Normalization operator. Subsequently, the normalized desensitized representation vector... and normalized sensitive feature vector Perform weighted fusion processing to generate a fusion vector. ,satisfy: ,in , and . , The sensitivity level is dynamically determined based on the sensitivity level and authorization status. For example, when the sensitivity level label of the memorized data is... And it was not authorized ( (When taking) , When the sensitivity level label of the memory data is / And the authorization is sufficient ( , (When taking) , And can be further... Perform gating adjustment (such as) , , , This allows for a balance between privacy suppression and recall performance during the retrieval phase.

[0078] (v) Cloud synchronization and local storage The terminal's sensitivity score for memorized data is less than the synchronization threshold. Then, the cloud backup operation is executed. Specifically, the memory data to be uploaded is first anonymized (e.g., text placeholder replacement, numerical range generalization), and then transmitted through an encrypted transmission channel. The de-identified backup copy and its metadata are sent to the cloud so that the cloud can store them in a cloud-based backup repository. The cloud verifies the identity of the terminal (e.g., ...). After obtaining the token, the newly added memory entry will be stored in the cloud memory backup library, and the de-identified backup copy will be encrypted and stored again (e.g., To prevent unauthorized internal access, the cloud-based memory backup repository uses anonymous identifiers to distinguish data from different users and does not directly store users' real identity information, further enhancing privacy protection.

[0079] The terminal's sensitivity score for memorized data is not less than the synchronization threshold. If the sensitivity level weight of the memory data exceeds [the threshold], then [the threshold] is exceeded. ( or If the condition is met, cloud synchronization will not be performed; only local storage will occur. In this case, the memory entry will remain strictly in the local memory repository, and no content will be sent to the cloud. This can be achieved by setting a synchronization threshold. (related) / Can be synchronized to the cloud / (Cannot be synchronized to the cloud) Implements a local-first data synchronization strategy: Most sensitive information exists only on the terminal, while the cloud only receives a limited amount of non-sensitive data. This satisfies the user's need for data synchronization when changing devices or storing data for a long time, while adhering to the principle of minimizing privacy protection.

[0080] In this example, during the anonymization process, the text-based data is processed using regular expressions to replace the middle four digits of the phone number with "****", hides the day and month of the specific date, retaining only the year, and converts precise monetary values ​​into ranges (e.g., "500-600 yuan"), ensuring that the uploaded content does not contain directly identifiable personal information. If the data contains user identifiers, it is anonymized. (e.g., hash values ​​based on terminal identifiers) are used as a replacement. In scenarios involving unstructured data such as images and audio, hash fingerprints (e.g., hash values ​​based on terminal identifiers) are calculated for files. ) or extract feature vectors (e.g., 512-dimensional) The data is uploaded using a feature-based method, but the original file itself is not transmitted. After anonymization, the terminal uploads the data to the cloud via a security protocol, and the cloud verifies the terminal's identity (e.g., [identification details]). After obtaining the token, the data is stored in a cloud-based memory backup repository and then encrypted again before storage (e.g., ...). To prevent unauthorized internal access, the cloud database uses anonymous identifiers to distinguish data from different users and does not directly store users' real identity information, further enhancing privacy protection.

[0081] The cloud synchronization process sets up data interaction and synchronization fault tolerance mechanisms. When the terminal establishes a connection with the cloud, it first completes two-way authentication (the terminal verifies the cloud certificate, and the cloud verifies the terminal). Token) and negotiate session key (such as Key exchange is performed, followed by the transmission of a de-identified backup copy and its metadata (including sensitivity level labels, permission labels, timestamps, and version numbers) through an additional transmission channel. A queue-based retry mechanism is used during cloud synchronization; that is, when the terminal is offline or the cloud is unreachable, the new memory entries to be synchronized are written to the local synchronization queue (e.g., ...). The system records the number of retries and the backoff time (the time interval during which the system waits before retrying after a synchronization failure caused by a terminal going offline or the cloud being unreachable). After the network is restored, the cloud synchronization task is re-executed according to the order of the local synchronization queue based on the backoff time. Based on the order of the local synchronization queue, it is determined whether the number of retries for each new memory entry has reached the retry threshold (e.g., 3 times). If the retry threshold is reached, the new memory entry is deleted. If the retry threshold is not reached, new memory entries with fewer retries than the retry threshold are synchronized to the cloud memory backup library through an encrypted transmission channel.

[0082] To handle conflicts arising from concurrent modifications across multiple devices, conflict detection is required based on the data identifier and version number of newly added memory entries. This determines whether conflicts exist due to concurrent modifications across multiple terminals, specifically detecting new memory entries with the same data identifier but different version numbers that need to be stored. When conflicts exist, a merging strategy prioritizing those with stricter permissions is implemented to identify the memory entries to be retained. A confirmation request is generated from at least two conflicting memory entries and the memory entries to be retained, and sent to the terminal so that the user can determine the final memory entry to be protected based on the confirmation request displayed on the terminal. For example, when two memory entries conflict, their permission tags are compared, and the memory entry with the version number that has fewer available scenarios is identified as the memory entry to be retained. A confirmation request is then generated based on the two conflicting memory entries and the selected memory entry to be retained, and submitted to the user for confirmation. For instance, the control terminal displays a prompt: "Memory conflict detected. Do you want to retain the 'Home Only' version?" This prevents a lenient policy from overriding a strict policy, thus avoiding the risk of unauthorized access.

[0083] The cloud synchronization process requires interface field and integrity verification, specifically including: the terminal sending a synchronization uplink request to the cloud, and the newly added memory entry corresponding to the synchronization uplink request carrying at least an entry identifier. Sensitive level tags Permission tags, creation timestamp, version number The de-identified backup of the main text or its summary, and the integrity check value. etc., among which This is a hash or message authentication function with a key. After receiving a synchronization uplink request, the cloud needs to verify the integrity check value. Only after the verification passes will the newly added memory entry be stored in the cloud memory backup repository.

[0084] After completing the above steps, the new memory data is securely stored and (optionally) backed up according to its sensitivity attributes, and then placed in the memory bank for later use. Users can browse this memory through the permission settings interface to view its sensitivity level, permission tags, and... The system will assign a score and adjust the permission tags (e.g., change "Visible only within AI" to "Available only in medical consultation scenarios"). This completes the new memory loading process.

[0085] (vi) Search permission filtering During a dialogue between the terminal and the user within the large user model, the terminal can trigger a memory retrieval request based on the current dialogue context. In response to this request, memory retrieval and permission verification are performed. The specific process is as follows: First, based on the current dialogue content (e.g., the user asks "My medical examination report data?"), search criteria (keywords "medical examination report" + scenario "medical consultation") are generated. A memory retrieval request is then triggered based on these criteria. Next, the memory is retrieved from a local memory repository or a cloud-based memory backup repository (only...). / The system retrieves candidate memory entries corresponding to the memory retrieval request from the cloud memory backup repository. The cloud-based memory backup repository only provides candidate memory entries with sensitivity levels of P1 or P2, while candidate memory entries with sensitivity levels of P3 or P4 are retrieved from the local memory repository. Then, it assigns permission tags, sensitivity level tags, and dialogue context (scenario "medical consultation," authorization strength) to each candidate memory entry. Perform matching operations and calculate and ,Will Candidate memory entries are discarded, and only memory data that meets the criteria is identified as usable memory data, allowing it to be used by the character's large model. For memory data marked as "not publicly visible" (such as...), Even if physical examination values ​​(at the provincial level) are allowed as references in internal reasoning, their inclusion in the final response should be restricted to a recognizable plaintext form (e.g., processing "blood pressure 120 / 80 mmHg" as "blood pressure is within the normal range"). This achieves a closed loop of item-level permissions, ensuring "controllable retrieval, controllable referencing, and controllable output," preventing unauthorized access or external disclosure of sensitive memories in unauthorized scenarios. If necessary, the system can trigger responses when preset conditions are met (e.g., the content to be displayed contains...). / or authorization strength When a user confirmation process is triggered, explicit authorization is used as a necessary condition for subsequent external output, further reducing the risk of unauthorized external display of sensitive information.

[0086] In one example, the permission verification process can also be efficiently implemented based on the permission matrix matching algorithm: the permission vectors of all candidate memory entries are arranged row-wise to form a permission matrix. (dimension) , For candidate memories, (where the scene dimension is 1), and the context vector is 2. As a column vector, the permission matching score is calculated using matrix multiplication. Quickly determine which memories satisfy The conditions are equivalent to performing permission checks one by one in batches. This batch processing method can reduce the latency of dialog retrieval (e.g., (At the same time, matrix operations take less than 10ms), improving the system's real-time response capability. In addition, for memory data marked as "not for external display", additional filtering logic is added to the output layer: sensitive elements are detected in the AI-generated response text. If it contains unauthorized sensitive placeholders (such as "[ID number-1]"), it is automatically replaced with a vague expression (such as "related identity information") or a prompt requiring user authorization (such as "You need to authorize access to identity information before you can get a complete answer").

[0087] Runtime secure output control: If sensitive memory information needs to be referenced during the dialogue generation phase, the decryption, assembly, and display of sensitive data must be completed only within the controlled environment of the terminal; the cloud only processes de-identified contexts or placeholder representations that do not contain sensitive plaintext. After the terminal passes the permission verification, it reads and decrypts the sensitive fields from the local memory repository and fills them into the response template according to the placeholder mapping rules in the final output stage; if the permission is not satisfied or the user confirmation is not obtained, the sensitive fields are obfuscated for display, denied for display, or the user confirmation process is triggered, thereby reducing the risk of sensitive memory being displayed and leaked in unauthorized scenarios.

[0088] By employing measures such as edge-cloud separation storage, line-by-line permission filtering, vector fusion retrieval, and anonymization protection, this invention constructs a privacy-friendly AI memory management system. Throughout the entire operation of the AI ​​assistant, several supporting mechanisms further ensure data security and user awareness.

[0089] The method for privacy protection and hierarchical permission management of large role model memory data provided in this embodiment of the invention also has the following alternative solutions: Alternative encryption schemes: For local secure storage, symmetric / asymmetric algorithms from the national commercial cryptographic algorithm system can be used to replace general cryptographic algorithms; key derivation can be implemented using derivation functions based on passwords or key materials to meet the cryptographic requirements of different compliance scenarios.

[0090] Authentication mechanism alternatives: Terminal and cloud-based identity authentication can be selected. Pattern replacement Tokens enhance security in scenarios such as mobile devices.

[0091] Alternative methods for desensitization: Text desensitization can use a combination of entity replacement and syntactic rewriting, while numerical desensitization can use logarithmic generalization instead of interval generalization, to adapt to the privacy protection needs of different data types.

[0092] Permission model replacement: The permission matrix can be replaced by an attribute-based access control model, which calculates the authorization strength by jointly using a set of subject attributes, object attributes, and environment attributes. With threshold This improves the flexibility of access control in complex scenarios.

[0093] Injection Location Substitution: Differential privacy noise can be injected into the retrieval score ranking stage to replace training gradient noise addition, which is suitable for retrieval scenarios that do not require personalized training but require privacy protection.

[0094] The technical solution of this invention can be widely applied to various role-based large-scale model application scenarios requiring strict privacy protection, including but not limited to personal intelligent assistants, enterprise intranet assistants, medical consultation AI, government compliance AI, and financial consultation AI. Personal intelligent assistants can be, but are not limited to, personal AI assistants on mobile devices and desktops, requiring the memorization of user schedules, contact information, preferences, and other private information. This solution enables local encrypted storage of sensitive information and scenario-based access control. Enterprise intranet assistants are AI office assistants deployed within enterprises, handling sensitive internal content such as employee work information and enterprise business data. An end-to-cloud collaborative architecture ensures data is not leaked to the external environment while meeting the needs of multi-device collaboration within the enterprise. Medical consultation AI is used to memorize highly sensitive medical data such as user health records, consultation records, and examination reports. Highly sensitive memorized data is locally retained, anonymized, and backed up with strict access verification, complying with medical data privacy protection regulations. Government compliance AI is an AI system for government service scenarios, handling sensitive data such as citizen identity information and government processing records. This solution enables minimal data collection, auditable access, and revocable deletion, meeting government data compliance requirements. AI-powered financial advisors memorize users' financial status, investment preferences, transaction records, and other sensitive financial information. Through dynamic permission thresholds and differential privacy protection, they balance personalized services with financial data security.

[0095] Compared with existing technologies, this invention achieves comprehensive privacy protection for the memory data of large character models through edge-cloud integration and multiple security strategies, and has the following beneficial effects: User privacy risks are significantly reduced: Sensitive memory data is always stored locally on the user's device and encrypted, so even if a security vulnerability occurs in the cloud, the user's private information will not be leaked; strict permission filtering (dynamic threshold + gating fusion) ensures that the role model will not call unauthorized data, eliminating the possibility of the role model misusing private information from the source.

[0096] Compliant with regulatory requirements: This solution adheres to principles such as data minimization, local-first processing, and informed consent from users. The mechanisms employed, including item-by-item authorization, anonymized storage, differential privacy (including privacy accounting), and revocable deletion, are highly compatible with domestic and international privacy regulations and standards. By adopting this solution, enterprises can effectively avoid legal risks arising from the unauthorized collection or use of user information, providing compliance assurance for the successful application of large-scale character model products.

[0097] Enhanced User Control and Trust: By providing a granular permission setting interface and transparent measures (data synchronization auditing, access log recording, and self-management of keys), this invention enables users to have complete control over the scope of how the role-based big data platform uses their personal data. Users clearly understand which of their information will be used by the role-based big data platform in what situations, thus making them more willing to trust and use the role-based big data platform assistant with memory capabilities long-term. The credibility of applications such as digital roles is significantly improved.

[0098] Balancing functionality and security: By combining encrypted retention of highly sensitive data on the terminal with desensitized backup of low-sensitivity data in the cloud, the system can achieve cross-device synchronization and long-term storage of low-sensitivity data while ensuring that sensitive data does not leave the terminal. Simultaneously, the permission matrix engine and controlled vector fusion mechanism restrict "searchability" and "referenceability" to the authorized scope, thereby improving the consistency of personalized services while reducing the probability of unauthorized access and explicit leakage, achieving synergistic optimization of security and availability.

[0099] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0100] In one embodiment, a role-based large model memory data privacy protection and hierarchical access control system is provided, which corresponds one-to-one with the role-based large model memory data privacy protection and hierarchical access control method described in the above embodiments. For example... Figure 7 As shown, the role-based large model memory data privacy protection and access control management system includes: The hierarchical storage module 701 is used to identify the sensitivity of memory data during the interaction between the role model and the user, determine the sensitivity score, and determine the sensitivity level label and permission label based on the sensitivity score and the hierarchical threshold; and to form new memory entries based on the memory data and its metadata, and store the new memory entries in the memory database. The metadata includes the sensitivity score, sensitivity level label and permission label. The vector fusion module 702 is used to perform desensitization and vector transformation processing on the memory data, determine the desensitized representation vector and the sensitive feature vector, determine the fusion vector based on the desensitized representation vector and the sensitive feature vector, and store the fusion vector in the memory database so as to output the fusion vector when a semantic retrieval request is received; The access control module 703 is used to respond to the memory retrieval request triggered by the large role model in the dialogue scenario, obtain candidate memory entries from the memory database, perform access control on the memory data in the candidate memory entries based on the metadata in the candidate memory entries, and determine the available memory data of the large role model in the dialogue scenario. The privacy control module 704 is used to respond to memory retrieval requests triggered by model training scenarios or statistical analysis scenarios, obtain the memory entries to be used from the memory database, dynamically determine the privacy budget based on the metadata in the memory entries to be used, add random noise to the memory data in the memory entries to be used based on the privacy budget, and determine the noisy memory data.

[0101] Specific limitations regarding the privacy protection and access control system for large-scale character model memory data can be found in the above section on the limitations of the method for privacy protection and access control for large-scale character model memory data, and will not be repeated here. Each module in the aforementioned privacy protection and access control system for large-scale character model memory data can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of the terminal in hardware form or independent of it, or stored in the memory of the terminal in software form, so that the processor can call and execute the corresponding operations of each module.

[0102] In one embodiment, a terminal is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the role-based large model memory data privacy protection and permission-based hierarchical management method described in the above embodiments, for example... Figure 1 S101-S104 are shown below. To avoid repetition, they will not be described again here.

[0103] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When executed by a processor, the computer program implements the role-based large model memory data privacy protection and permission-based hierarchical management method described in the above embodiment, for example... Figure 1 S101-S104 are shown below. To avoid repetition, they will not be described again here.

[0104] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.

Claims

1. A method for privacy protection and hierarchical access control of large role model memory data, characterized in that, include: Sensitivity identification is performed on the memory data during the interaction between the large role model and the user to determine the sensitivity score. Based on the sensitivity score and the classification threshold, sensitivity level labels and permission labels are determined. New memory entries are formed based on the memory data and its metadata, and the new memory entries are stored in the memory database. The metadata includes the sensitivity score, the sensitivity level label, and the permission label. The memory data is desensitized and vectorized to determine the desensitized representation vector and the sensitive feature vector. Based on the desensitized representation vector and the sensitive feature vector, a fusion vector is determined and stored in the memory database so that the fusion vector can be output when a semantic retrieval request is received. In response to a memory retrieval request triggered by the large character model in a dialogue scenario, candidate memory entries are obtained from the memory database, and access control is performed on the memory data in the candidate memory entries based on the metadata in the candidate memory entries to determine the available memory data of the large character model in the dialogue scenario. In response to a memory retrieval request triggered by a model training scenario or a statistical analysis scenario, a pending memory entry is obtained from the memory database. A privacy budget is dynamically determined based on the metadata in the pending memory entry. Random noise is added to the memory data in the pending memory entry based on the privacy budget to determine the noisy memory data.

2. The method according to claim 1, characterized in that, The process of performing sensitivity identification on the memory data during the interaction between the large role model and the user, determining a sensitivity score, and determining sensitivity level labels and permission labels based on the sensitivity score and grading thresholds includes: Privacy elements are identified in the memory data of the large character model during the interaction with the user, and a set of privacy elements corresponding to the memory data is determined. Each privacy element in the set of privacy elements includes type, identification confidence and occurrence frequency. Sensitivity calculations are performed on the set of privacy elements to determine the sensitivity score corresponding to the memory data. The sensitivity score is determined using the following formula: ;in, Sensitivity rating; , and The first The type, identification confidence level, and frequency of occurrence of each privacy element; The number of privacy elements; For type weights, The function is a frequency adjustment function. , The threshold for the number of saturation operations. As a scenario risk factor, To combine identifiability factors, and For coefficients; Based on the sensitivity score and grading threshold, the sensitivity level label and permission label corresponding to the memory data are determined, including: in When the sensitivity level label is determined to be a non-sensitive label. The permission tag is a publicly available tag; in When the sensitivity level label is determined to be a low sensitivity label. The permission tags are tags that can be used in specific scenarios; in When the sensitivity level label is determined to be a general sensitivity label. The permission tag is a tag that can be used by itself; in When the sensitivity level label is determined to be a high-sensitivity label. The permission tag is an unavailable tag. , and 3 is the grading threshold.

3.

3. The method according to claim 1, characterized in that, The process of forming new memory entries based on the memory data and its metadata, and storing the new memory entries in the memory database, includes: The memory data is encrypted using the encryption strategy corresponding to the sensitivity level label, the encrypted memory data is determined, a new memory entry is formed based on the encrypted memory data and its metadata, and the new memory entry is stored in the local memory repository; When the sensitivity score corresponding to the memory data is less than the synchronization threshold, the memory data is desensitized, a desensitized backup copy is determined, a new memory entry is formed based on the desensitized backup copy and its metadata, and the new memory entry is synchronized to the cloud memory backup library through an encrypted transmission channel.

4. The method according to claim 3, characterized in that, The process of encrypting the memory data using the encryption strategy corresponding to the sensitivity level label, determining the encrypted memory data, forming a new memory entry based on the encrypted memory data and its metadata, and storing the new memory entry in a local memory repository includes: Generate master key The storage key is derived based on the master key. Index key With mapping table key Based on the storage key Index key With mapping table key The corresponding content in the memory data is encrypted to determine the encrypted memory data. A new memory entry is formed based on the encrypted memory data and its metadata, and the new memory entry is stored in the local memory repository. The method further includes: regenerating a new master key when the key rotation conditions are detected. Using the new master key The protected data in the local memory repository is re-encrypted.

5. The method according to claim 3, characterized in that, The process of de-identifying the memory data and determining a de-identified backup copy includes: When the memory data is text memory data, privacy elements are identified in the memory data to determine the set of privacy elements corresponding to the memory data. A placeholder is generated based on the type corresponding to each privacy element in the set of privacy elements, and the placeholder is used to replace the original content corresponding to the privacy element. When the memory data is structured or numerical field data, the following is adopted: The memory data is subjected to interval generalization processing, wherein, The original values ​​in the memory data. The values ​​are the range generalized values. It is a rounding function. This is the generalization granularity parameter; When the memory data is date and time field data, the memory data is subjected to granular downsampling processing; When the memory data is image memory data or audio memory data, feature extraction is performed on the memory data to determine a feature summary vector, and an index identifier is generated based on the feature summary vector and the terminal key.

6. The method according to claim 3, characterized in that, The step of synchronizing the newly added memory entries to the cloud memory backup library via an encrypted transmission channel includes: When two-way authentication is completed between the terminal and the cloud, the newly added memory entries are synchronized to the cloud through an encrypted transmission channel, and the cloud's confirmation signal is listened for. If the confirmation signal is not received within the preset time period, the new memory entry is written to the local synchronization queue and the retry count corresponding to the new memory entry is updated. Based on the order of the local synchronization queue, newly added memory entries with fewer than the retry count threshold are synchronized to the cloud memory backup library through an encrypted transmission channel.

7. The method according to claim 6, characterized in that, The method further includes: Receive a deletion request triggered by a user, wherein the deletion instruction carries an entry identifier and a version number; Based on the target identification and version number, determine the memory entries to be deleted in the local memory repository, delete the memory entries to be deleted from the local memory repository, and perform an erasure operation on the deleted area. When it is determined that a de-identified backup copy of the memory entry to be deleted exists, the deletion request is synchronized to the cloud so that the cloud performs an irreversible deletion operation and returns a deletion confirmation. Upon receiving confirmation of deletion, the deleted memory is updated in the log database, and the memory entry to be deleted is removed from the local synchronization queue.

8. The method according to claim 1, characterized in that, The process of desensitizing and vectorizing the memory data to determine the desensitized representation vector and the sensitive feature vector, and determining the fusion vector based on the desensitized representation vector and the sensitive feature vector, includes: The memory data is desensitized to determine the desensitized memory content and sensitive element information. A desensitized representation vector is determined based on the desensitized memory content, and a sensitive feature vector is determined based on the sensitive element information. The desensitized representation vector and the sensitive feature vector are subjected to dimension alignment and normalization to determine the normalized desensitized representation vector and the normalized sensitive feature vector; The normalized desensitized representation vector and the normalized sensitive feature vector are weighted and fused to determine the fusion vector corresponding to the memory data; The fusion vector is determined by the following formula: , , For the fusion vector, This is the normalized desensitization representation vector. For normalized sensitive feature vectors; , For the strength of authorization, Score for context matching. Sensitivity rating, , , and These are configurable parameters. .

9. The method according to claim 1, characterized in that, In response to a memory retrieval request triggered by the large character model in a dialogue scenario, candidate memory entries are retrieved from the memory database. Access control is then applied to the memory data within these candidate memory entries based on their metadata to determine the available memory data of the large character model in the dialogue scenario, including: In response to a memory retrieval request triggered by the character model in a dialogue scenario, candidate memory entries are obtained from the memory database. The candidate memory entries include memory data and its metadata, and the metadata includes permission tags and sensitivity scores. The permission matching score between the dialogue context corresponding to the dialogue scenario and the permission tag is determined by the following formula: ;in, The permission matching score for the i-th memory data. This is a permission vector determined based on permission tags. This is a context vector determined based on the dialogue context; For transpose; Scoring the permissions corresponding to all candidate memory entries; The permissions are formed row by row from the permission vectors corresponding to all candidate memory entries; When the permission matching score is greater than or equal to the dynamic threshold, the memory data is determined to be the available memory data of the role model in the dialogue scenario; When the permission matching score is less than the dynamic threshold, the memory data is determined to be unusable memory data of the role model in the dialogue scenario; The dynamic threshold is determined by the following formula: ;in, The dynamic threshold corresponding to the i-th memory data is... Based on the threshold, For the sensitivity score corresponding to the i-th memory data, For the strength of authorization, and is a coefficient.

10. The method according to claim 9, characterized in that, The method further includes: When any memory entry is detected to meet the downgrade conditions, the authorization strength corresponding to the memory entry is reduced. The downgrade conditions include the absence of attributes in the dialogue context, or the permission tag being changed or revoked. When any memory entry is detected to meet abnormal conditions, the access circuit breaker mechanism is triggered, and the retrieval and output of memory data for general sensitive tags or highly sensitive tags are suspended during the preset cooling period. The abnormal condition is that the number of unauthorized retrieval requests or cross-regional retrieval requests received within a preset time period exceeds the unauthorized number threshold. The unauthorized retrieval request is a memory retrieval request where the permission matching score is less than the dynamic threshold. The cross-regional retrieval request is a memory retrieval request where a cross-regional IP accesses memory data corresponding to general sensitive tags or highly sensitive tags.

11. The method according to claim 1, characterized in that, In response to a memory retrieval request triggered by a model training or statistical analysis scenario, the system retrieves a pending memory entry from the memory database, dynamically determines a privacy budget based on the metadata in the pending memory entry, and adds random noise to the memory data in the pending memory entry based on the privacy budget to determine the noisy memory data, including: In response to a memory retrieval request triggered by a model training scenario or a statistical analysis scenario, a pending memory entry is obtained from the memory database. The pending memory entry includes memory data and its metadata, and the metadata includes a sensitivity level label and a sensitivity score. Based on the privacy budget dynamically determined by the sensitivity level label, the memory data in the candidate memory entries are noise-added using a Laplace noise-adding mechanism or a Gaussian noise-adding mechanism to determine the noisy memory data; The Laplace noise addition mechanism is determined by the following formula: , ; The Gaussian noise addition mechanism is determined by the following formula: , and , , Related; To add noise to memory data; For memory data in the pending memory entries; Budget for privacy; for Sensitivity for Sensitivity This is the failure probability parameter.

12. A privacy protection and hierarchical access control system for large-scale role model memory data, characterized in that, include: The hierarchical storage module is used to identify the sensitivity of memory data during the interaction between the large role model and the user, determine the sensitivity score, and determine the sensitivity level label and permission label based on the sensitivity score and the hierarchical threshold. New memory entries are formed based on the memory data and its metadata, and the new memory entries are stored in the memory database. The metadata includes the sensitivity score, the sensitivity level label, and the permission label. The vector fusion module is used to perform desensitization and vector transformation processing on the memory data, determine the desensitized representation vector and the sensitive feature vector, determine the fusion vector based on the desensitized representation vector and the sensitive feature vector, and store the fusion vector in the memory database so as to output the fusion vector when a semantic retrieval request is received; The access control module is used to respond to the memory retrieval request triggered by the large role model in the dialogue scenario, obtain candidate memory entries from the memory database, perform access control on the memory data in the candidate memory entries based on the metadata in the candidate memory entries, and determine the available memory data of the large role model in the dialogue scenario. The privacy control module is used to respond to memory retrieval requests triggered in model training or statistical analysis scenarios, obtain unused memory entries from the memory database, dynamically determine a privacy budget based on the metadata in the unused memory entries, add random noise to the memory data in the unused memory entries based on the privacy budget, and determine the noisy memory data.

Citation Information

Patent Citations

  • Mobile collaboration platform data management method

    CN120197208A

  • Retrieval enhancement method and device for question and answer scene, equipment and storage medium

    CN121029922A

  • Data processing method and device based on artificial intelligence, server and storage medium

    CN121167766A

  • Memory retrieval method, memory generation method and related devices

    CN121434442A

  • Digital human intelligent question and answer interaction method for multi-modal visual platform

    CN121435277A

Cited By

  • A long-term memory implementation method and system for large model interaction, a storage medium and an electronic device

    CN122432219A