Operation system, method and device, electronic equipment and storage medium

By designing and operating system modules for data collection, processing, early warning, and risk management, the system automatically identifies and adjusts potential risks in cloud disk data, solving the problem of low efficiency in manual processing in existing cloud disk services and achieving efficient content security management.

CN121959570APending Publication Date: 2026-05-01CHINA MOBILE INTERNET CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA MOBILE INTERNET CO LTD
Filing Date
2025-12-11
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

In existing cloud storage services, content security operations rely on manual processing, resulting in low levels of automation and efficiency, making it difficult to effectively monitor and identify illegal content within massive amounts of data.

Method used

Design an operation system including a data collection module, a processing module, an early warning module, an adjustment module, and a risk module. By extracting information tags, calculating overlap and early warning levels, the system can automatically identify potential risks, adjust risk weights, and generate risk assessment reports.

Benefits of technology

It enables automated and systematic risk identification and early warning of cloud disk data, improving operational efficiency and automation levels, and enhancing the accuracy and efficiency of content security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121959570A_ABST
    Figure CN121959570A_ABST
Patent Text Reader

Abstract

The invention provides an operation system, method and device, electronic equipment and a storage medium. The system comprises an acquisition module, a processing module, an early warning module, an adjustment module and a risk module. Wherein the acquisition module is used for extracting an information label in a target data source and sending the information label to the processing module; the processing module is used for obtaining an overlap ratio result according to the information labels and historical labels in the label database; when the contact ratio result is low contact ratio, the information label is sent to the early warning module; the early warning module is used for calculating the early warning degree of the information label, triggering early warning when the early warning degree exceeds a preset early warning threshold value, and sending the early warning degree to the adjusting module; the adjusting module is used for adjusting the risk weight of the information tag in the tag database based on the early warning degree; and the risk module is used for performing risk assessment on the data according to the risk weight of each label in the label database, and generating a risk assessment report.
Need to check novelty before this filing date? Find Prior Art

Description

Operating systems, methods, apparatus, electronic devices and storage media Technical Field

[0001] This disclosure relates to the field of artificial intelligence, and more particularly to an operating system, method, apparatus, electronic device, and storage medium. Background Technology

[0002] Cloud storage is a key application of cloud storage systems, and its content security is of paramount importance. However, in current cloud storage services, content security operations mainly rely on manual processing by enterprise security operations teams. This requires manual monitoring, analysis, and judgment of the massive amounts of data stored by users in cloud storage to determine whether there is any illegal content. This manual operation model suffers from low automation and inefficiency. Summary of the Invention

[0003] This disclosure provides an operating system, method, apparatus, electronic device, and storage medium. Its main objective is to address the problems of low automation and low efficiency in existing operating systems.

[0004] According to a first aspect of this disclosure, an operating system is provided, the system comprising: a data acquisition module, a processing module, an early warning module, an adjustment module, and a risk module; wherein, the data acquisition module is configured to extract information tags from a target data source and send the information tags to the processing module; the processing module is configured to receive the information tags sent by the data acquisition module, obtain an overlap result based on the information tags and historical tags in a tag database, and send the information tags to the early warning module when the overlap result is low; the early warning module is configured to receive the information tags sent by the processing module, calculate the early warning degree of the information tags, trigger an early warning when the early warning degree exceeds a preset early warning threshold, and send the early warning degree to the adjustment module; the adjustment module is configured to receive the early warning degree sent by the early warning module and adjust the risk weight of the information tags in the tag database based on the early warning degree; the risk module is configured to perform risk assessment on the data according to the risk weight of each tag in the tag database and generate a risk assessment report.

[0005] In some embodiments, the system further includes a tag interpretation module, which is used to monitor the frequency of occurrence of each information tag extracted by the acquisition module within a unit time, take the information tags corresponding to the frequency of occurrence of abnormal fluctuations as candidate risk tags, and generate interpretation prompt information.

[0006] In some embodiments, the adjustment module is further configured to: receive the warning level sent by the warning module and the risk assessment report generated by the risk module, and adjust the risk weight of the corresponding information tag in the tag database according to the warning level and the risk assessment report.

[0007] According to a second aspect of this disclosure, an operation method is provided, which is applied to the operation system described in the first aspect above, comprising: extracting information tags from a target data source and obtaining an overlap result based on the information tags and historical tags in a tag database; calculating a warning level for the information tags when the overlap result is low; triggering a warning when the warning level exceeds a preset warning threshold, and adjusting the risk weight of the information tags in the tag database based on the warning level; and performing a risk assessment on the data based on the risk weights of each tag in the tag database to generate a risk assessment report.

[0008] In some embodiments, after extracting information tags from the target data source, the method further includes: monitoring the frequency of occurrence of each information tag within a unit of time; using the information tags corresponding to the frequency of occurrence of abnormal fluctuations as candidate risk tags, and generating interpretation prompt information.

[0009] In some embodiments, after obtaining the overlap result based on the information tag and historical tags in the tag database, the method further includes: comparing the overlap result with a preset first threshold and a second threshold, wherein the first threshold is less than the second threshold; if the overlap result is less than the first threshold, then determining that the information tag has low overlap; if the overlap result is greater than or equal to the first threshold and less than or equal to the second threshold, then determining that the information tag has medium overlap, and storing the information tag as a historical tag in the tag database.

[0010] In some embodiments, calculating the warning level of the information tag when the overlap result is low includes: obtaining the risk level determined based on the overlap result, the probability of the information tag appearing within a preset period, and the popularity change rate of the information tag within a unit time; wherein the popularity change rate is the increase in the frequency of the information tag appearing within a unit time; and obtaining the warning level based on the risk level, the probability of appearance, and the popularity change rate.

[0011] In some embodiments, after performing risk assessment on the data based on the risk weights of each tag in the tag database and generating a risk assessment report, the method further includes: adjusting the risk weights of the corresponding information tags in the tag database based on the risk assessment report.

[0012] According to a third aspect of this disclosure, an operating device is provided, configured in the operating system described in the first aspect, comprising: an extraction unit for extracting information tags from a target data source; a first determination unit for obtaining an overlap result based on the information tags and historical tags in a tag database; a calculation unit for calculating a warning level for the information tags when the overlap result is low; a first adjustment unit for triggering a warning when the warning level exceeds a preset warning threshold, and adjusting the risk weight of the information tags in the tag database based on the warning level; and a first generation unit for performing a risk assessment on the data based on the risk weights of each tag in the tag database, and generating a risk assessment report.

[0013] In some embodiments, the apparatus further includes: a monitoring unit, configured to monitor the frequency of occurrence of each information tag within a unit time after the extraction unit extracts the information tags from the target data source; and a second generation unit, configured to use the information tags corresponding to the frequency of occurrence of abnormal fluctuations as candidate risk tags and generate interpretation prompt information.

[0014] In some embodiments, the apparatus further includes: a comparison unit, configured to compare the overlap result with a preset first threshold and a second threshold after the first determining unit obtains the overlap result based on the information tag and historical tags in the tag database, wherein the first threshold is less than the second threshold; a second determining unit, configured to determine the information tag as having low overlap when the overlap result is less than the first threshold; and a third determining unit, configured to determine the information tag as having medium overlap when the overlap result is greater than or equal to the first threshold and less than or equal to the second threshold, and store the information tag as a historical tag in the tag database.

[0015] In some embodiments, the calculation unit includes: an acquisition module, configured to acquire a risk level determined based on the overlap result, the probability of the information tag appearing within a preset period, and the rate of change in popularity of the information tag within a unit time; wherein the rate of change in popularity is the increase in the frequency of the information tag appearing within a unit time; and a determination module, configured to obtain the warning level based on the risk level, the probability of appearance, and the rate of change in popularity.

[0016] In some embodiments, the apparatus further includes: a second adjustment unit, configured to adjust the risk weight of the corresponding information tag in the tag database according to the risk assessment report generated by the first generation unit after performing a risk assessment on the data based on the risk weight of each tag in the tag database.

[0017] According to a fourth aspect of this disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the method described in the second aspect above.

[0018] According to a fifth aspect of this disclosure, a non-transitory computer-readable storage medium is provided storing computer instructions, wherein the computer instructions are configured to cause the computer to perform the method described in the second aspect above.

[0019] According to a sixth aspect of this disclosure, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the method described in the second aspect above.

[0020] In summary, the operating system, method, apparatus, electronic device, and storage medium provided in this disclosure include: a data acquisition module, a processing module, an early warning module, an adjustment module, and a risk module. The data acquisition module extracts information tags from a target data source and sends the information tags to the processing module. The processing module receives the information tags sent by the data acquisition module, obtains an overlap result based on the information tags and historical tags in a tag database, and sends the information tags to the early warning module when the overlap result is low. The early warning module receives the information tags sent by the processing module, calculates the early warning level of the information tags, triggers an early warning when the early warning level exceeds a preset early warning threshold, and sends the early warning level to the adjustment module. The adjustment module receives the early warning level sent by the early warning module and adjusts the risk weight of the information tags in the tag database based on the early warning level. The risk module performs a risk assessment on the data based on the risk weights of each tag in the tag database and generates a risk assessment report. Compared with related technologies, the solution disclosed herein can extract information tags from the target data source through the acquisition module and send them to the processing module. The processing module receives the information tag and judges it based on the overlap result with the historical tags in the tag database. If the result is low overlap, the information tag is sent to the early warning module. After receiving the information tag, the early warning module calculates its early warning degree. When the early warning degree exceeds the preset early warning threshold, an early warning is triggered, and the early warning degree is sent to the adjustment module. The adjustment module receives the early warning degree and adjusts the risk weight of the information tag in the tag database based on the early warning degree. The risk module performs risk assessment on the data according to the risk weight of each tag in the tag database and generates a risk assessment report. This realizes the automated identification, early warning, and weight adjustment of potential risk content in the target data source, and performs risk assessment based on the adjusted weight, thereby improving the systematization, automation level, and efficiency of operations.

[0021] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent from the following description. Attached Figure Description

[0022] The accompanying drawings are provided for a better understanding of this solution and do not constitute a limitation of this disclosure. Specifically: Figure 1 is a schematic diagram of the structure of an operating system provided in an embodiment of this disclosure; Figure 2 is a schematic diagram of the structure of another operating system provided in an embodiment of this disclosure; Figure 3 is a schematic diagram of the architecture of an operating system provided in an embodiment of this disclosure; Figure 4 is a schematic flowchart of an operating method provided in an embodiment of this disclosure; Figure 5 is a schematic flowchart of another operating method provided in an embodiment of this disclosure; Figure 6 is a schematic flowchart of another operating method provided in an embodiment of this disclosure; Figure 7 is a schematic flowchart of another operating method provided in an embodiment of this disclosure; Figure 8 is a schematic flowchart of another operating method provided in an embodiment of this disclosure; Figure 9 is a schematic diagram of the structure of an operating device provided in an embodiment of this disclosure; Figure 10 is a schematic diagram of the structure of another operating device provided in an embodiment of this disclosure; Figure 11 is a schematic block diagram of an example electronic device provided in an embodiment of this disclosure. Detailed Implementation

[0023] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0024] The operating system, method, apparatus, electronic device, and storage medium of embodiments of this disclosure are described below with reference to the accompanying drawings.

[0025] Figure 1 is a schematic diagram of the structure of an operating system provided in an embodiment of this disclosure.

[0026] As shown in Figure 1, the system includes: a data acquisition module 11, a processing module 12, an early warning module 13, an adjustment module 14, and a risk module 15; wherein, the data acquisition module 11 is used to extract information tags from the target data source and send the information tags to the processing module 12.

[0027] In some embodiments, the target data source includes, but is not limited to, file content uploaded by cloud storage users, policy documents issued by the state, publicly available big data on the Internet, and complaint data about harmful information received by enterprises. Information tags are keyword groups extracted from the target data source that reflect data characteristics. Extraction methods include, but are not limited to, semantic segmentation and keyword filtering of the target data source, forming corresponding information tags by identifying key expressions in the data source. After the acquisition module 11 extracts the information tags, it can send the information tags to the processing module 12 via real-time or batch transmission. Conventional data transmission protocols can be used during transmission to ensure the complete transmission of the information tags.

[0028] The data acquisition module can extract key information from various types of target data sources and form standardized information tags, providing a unified analysis object for subsequent risk assessment.

[0029] The processing module 12 is used to receive the information tag sent by the acquisition module 11, obtain the overlap result based on the information tag and the historical tags in the tag database, and send the information tag to the early warning module 13 when the overlap result is low overlap.

[0030] In some embodiments, the tag database is a database used to store historically extracted information tags. Historical tags are valid information tags retained after collection and processing during past operations. The overlap result is a quantitative value used to characterize the similarity between information tags and historical tags. Its calculation method includes, but is not limited to, calculating the ratio of the number of common features between information tags and historical tags to the total number of features. Specifically, it can be obtained using... Calculate, where A is the feature set of information tags and B is the feature set of historical tags. The number of common features between the two. This represents the total number of features for both. Low overlap is a preset quantification range for overlap results, which can be configured according to actual operational needs. After receiving the information tag, the processing module 12 calls the historical tags in the tag database to calculate the overlap. After obtaining the overlap result, it determines whether it belongs to low overlap. If it does, the information tag is sent to the early warning module 13 through the same or different transmission method as the acquisition module 11.

[0031] The processing module can compare the similarity between information tags and historical tags, filter out information tags that may pose unknown risks, and push them to subsequent modules, providing accurate input for risk warning.

[0032] The early warning module 13 is used to receive the information tag sent by the processing module 12, calculate the early warning degree of the information tag, trigger an early warning when the early warning degree exceeds a preset early warning threshold, and send the early warning degree to the adjustment module 14.

[0033] In some embodiments, the warning level is a quantitative indicator used to characterize the potential risk spread trend and severity of information tags. Its calculation method includes, but is not limited to, a comprehensive calculation combining risk-related parameters of the information tag. For example, it may combine the probability of the information tag appearing within a preset time interval, the risk level corresponding to the information tag, and the rate of increase of the information tag within a unit of time. Specifically, it may employ... Calculate, where z is the warning level and p is the probability of occurrence. f represents the level of risk, and f represents the magnitude of the increase.

[0034] The preset warning threshold is a quantitative standard for determining whether a warning needs to be triggered, and it can be set according to the risk management needs of the operational scenario. Methods for triggering a warning include, but are not limited to, generating a warning notification, marking a high-risk indicator on the system interface, and sending a warning signal to relevant operational nodes. After calculating the warning level, the warning module 13 sends the warning level to the adjustment module 14 via data transmission. Simultaneously, when the warning level exceeds the preset warning threshold, the corresponding warning operation is executed.

[0035] The early warning module can quantitatively assess the risk spread trend of information tags with low overlap, trigger early warnings in a timely manner, and transmit the assessment results to the adjustment module 14 to provide a basis for risk weight adjustment.

[0036] The adjustment module 14 is used to receive the warning level sent by the warning module 13 and adjust the risk weight of the information tag in the tag database based on the warning level.

[0037] In some embodiments, risk weight is a quantitative parameter used to measure the risk level of an information tag. Each historical tag in the tag database corresponds to an initial risk weight. Methods for adjusting risk weights based on the warning level include, but are not limited to, determining the adjustment range based on the quantitative value of the warning level. The higher the warning level, the greater the increase in the risk weight of the corresponding information tag (e.g., when the warning level is between 0.6 and 0.8, the risk weight is increased by 50%; when the warning level is above 0.8, the risk weight is increased by 100%. The above is only an example). After receiving the warning level, the adjustment module 14 retrieves the initial risk weight corresponding to the information tag in the tag database, completes the weight adjustment according to the preset adjustment rules, and updates the adjusted risk weight to the tag database.

[0038] The adjustment module can optimize the risk weight of information tags based on their early warning status, so that the risk level of the tags in the tag database matches the actual risk situation.

[0039] The risk module 15 is used to perform risk assessment on the data according to the risk weight of each tag in the tag database and generate a risk assessment report.

[0040] In some embodiments, risk assessment is a process of comprehensively judging the compliance and risk level of the original data corresponding to the target data source by combining the risk weights of each tag in the tag database. Assessment methods include, but are not limited to, calculating the comprehensive risk value of the data based on the risk weights of one or more information tags associated with the data, and then classifying the risk level based on the comprehensive risk value. A risk assessment report is a standardized document containing the risk assessment results, including but not limited to the risk level of the data, the information tags associated with the data and their risk weights, and the basis for risk determination. Risk module 15 calls the updated risk weights of each tag in the tag database to perform risk assessments on the data in the target data source one by one, and generates the corresponding risk assessment report after the assessment is completed.

[0041] The risk module enables risk assessment of data based on adjusted label risk weights, resulting in standardized assessment results.

[0042] In summary, compared with related technologies, the solution disclosed herein can extract information tags from the target data source through the acquisition module and send them to the processing module. The processing module receives the information tag and judges its overlap with historical tags in the tag database. If the overlap is low, the information tag is sent to the early warning module. After receiving the information tag, the early warning module calculates its early warning level. When the early warning level exceeds a preset early warning threshold, an early warning is triggered, and the early warning level is sent to the adjustment module. The adjustment module receives the early warning level and adjusts the risk weight of the information tag in the tag database based on the early warning level. The risk module performs risk assessment on the data according to the risk weight of each tag in the tag database and generates a risk assessment report. This achieves automated identification, early warning, and weight adjustment of potential risk content in the target data source, and performs risk assessment based on the adjusted weights, thereby improving the systematization, automation, and efficiency of operations.

[0043] Figure 2 further illustrates a schematic diagram of the structure of an operating system provided in an embodiment of this disclosure.

[0044] As shown in Figure 2, the system further includes a tag interpretation module 16, which is used to monitor the frequency of occurrence of each information tag extracted by the acquisition module 11 within a unit time, take the information tag corresponding to the frequency of occurrence of abnormal fluctuations as candidate risk tags, and generate interpretation prompt information.

[0045] In some embodiments, the unit time is a pre-set time period for statistically analyzing the frequency of occurrence, which can be configured according to the monitoring needs of the operational scenario, including but not limited to one day, one hour, twelve hours, etc. The frequency of occurrence refers to the number of times the information tag is extracted by the acquisition module 11 or appears in the target data source within the set unit time. The statistical methods include but are not limited to real-time counting and batch summary counting of the number of times the information tag appears within the unit time. Abnormal fluctuations refer to deviations in the frequency of information tags from historical statistics or preset benchmark values. Judgment criteria include, but are not limited to, determining these deviations by calculating the mean, variance, and normalization results of the frequency of occurrence. Specifically, the following method can be used: Using a set number of days as the observation window, calculate the mean P of the daily occurrences of information tags within the window. Then calculate the variance D(i) between the daily occurrences and the mean P. Normalize D(i) within the interval [0,1] to obtain d(i). When the normalization result d(i) = 1, calculate the normalized mean for the three consecutive days before and after that date. If the mean for the subsequent three days is greater than a preset threshold and higher than the mean for the previous three days, it is judged as an abnormal fluctuation. Alternatively, a fluctuation amplitude threshold can be set; when the increase or decrease in the frequency of occurrence within a unit of time compared to the previous unit of time exceeds this threshold, it is judged as an abnormal fluctuation. Candidate risk tags refer to information tags whose frequency of occurrence fluctuates abnormally. Such tags, due to sudden changes in usage frequency, may correspond to new types of illegal content or potential risks, requiring further analysis. The interpretation prompts are standardized information used to guide relevant personnel in assessing the meaning and risk attributes of candidate risk tags. The information includes, but is not limited to, the name of the candidate risk tag, any abnormal fluctuations in its frequency, the statistical time range, and suggested risk assessment directions. Once generated, it can be sent to authorized personnel via internal system push notifications, interface pop-ups, and notifications from the associated management platform. The tag interpretation module 16 monitors and collects information tags from the acquisition module 11 in real-time or periodically, determines whether their frequency fluctuates abnormally according to preset standards, marks information tags that meet the abnormal fluctuation criteria as candidate risk tags, and simultaneously generates interpretation prompts.

[0046] The label interpretation module can proactively capture new risk labels that may arise due to sudden changes in usage frequency, providing clear direction for manual assessment, supplementing the identification path for unknown risk labels, and further improving the system's risk control coverage.

[0047] In some implementations, the adjustment module 14 is further configured to: receive the warning level sent by the warning module and the risk assessment report generated by the risk module, and adjust the risk weight of the corresponding information tag in the tag database according to the warning level and the risk assessment report.

[0048] In some embodiments, the warning level received by the adjustment module 14 is still a quantitative indicator calculated by the warning module, representing the potential risk spread trend and severity of the information tag. The receiving method is consistent with the previous method of receiving the warning level, including but not limited to real-time transmission and batch transmission. The transmission process uses a conventional data transmission protocol to ensure integrity. The risk assessment report is a standardized document containing data risk assessment results generated by the risk module based on the risk weights of each tag in the tag database. The information related to weight adjustment in the report includes but is not limited to the risk level of the corresponding information tag, the basis for risk judgment, and the comprehensive risk quantification value. After receiving the risk assessment report, the adjustment module 14 parses the report content, extracts the risk parameters directly related to the corresponding information tag, and combines them with the received warning level as the basis for weight adjustment. Adjustment methods include, but are not limited to, setting the weight percentages of warning levels and risk parameters in risk assessment reports, and determining the final adjustment range through comprehensive calculation (e.g., a 60% weight percentage for warning levels and a 40% weight percentage for the comprehensive risk quantification value in the risk assessment report; the weighted average of these two values ​​yields an adjustment coefficient, which is then used to adjust the risk weight of the corresponding information tag upwards or downwards; this is merely an example). Alternatively, a corresponding relationship table can be set up to assign different weight adjustment ranges to different warning level ranges and risk levels. The adjustment module 14 determines the adjustment range by querying the corresponding relationship table based on the actual received warning levels and risk levels in the risk assessment report. During the adjustment process, the adjustment module 14 first retrieves the current risk weight of the corresponding information tag from the tag database, then updates the weight according to the determined adjustment range, and synchronizes the updated risk weight to the tag database to ensure that subsequent risk assessments use the latest weight data.

[0049] By adjusting the module, the accuracy of risk weights in the tag database can be further improved.

[0050] Figure 3 is a schematic diagram of the architecture of an operating system provided in an embodiment of this disclosure. As shown in Figure 3, the data sources of the operating system include national policies, Internet big data, and complaint information. These data sources are directly input into the collection module, which performs tag filtering, related data extraction, and tag extraction operations. The collection module first performs tag filtering on the input national policies, Internet big data, and complaint information, and extracts keyword groups that can reflect data characteristics. Then, through related data extraction, it retains useful information with fixed meanings and discards content without fixed directions. Finally, it completes tag extraction and stores the extracted information tags into the tag database.

[0051] The information tags stored in the tag database are transmitted to the processing module. The processing module performs target data comparison and overlap classification operations on these information tags: the newly extracted information tags are compared with historical tags in the tag database, and after obtaining the overlap results, the classification is completed according to the rule of retaining more than 80% (high overlap), entering 30-80% (medium overlap) into the tag database, and triggering an alert for less than 30% (low overlap). At the same time, the processing module maintains data interaction with the tag interpretation module and also receives risk weights fed back by the adjustment module (in conjunction with the human-machine collaboration module) to optimize the judgment criteria for overlap classification.

[0052] When the processing module determines that the overlap rate is below 30% (low overlap), it pushes the corresponding information tag to the early warning module. Based on this information tag, the early warning module performs actions such as initiation warnings and real-time trend adjustments, continuously tracking the spread trend and risk diffusion status of the information tag and generating a corresponding early warning report. The early warning information generated by the early warning module is further transmitted to the risk module. The risk module calls upon the interactive data in the tag database to perform risk assessments and ultimately generates a risk assessment report.

[0053] Based on the risk assessment report, the system can trigger a manual intervention process. Relevant authorized personnel can generate discussion proposals based on the report content and produce corresponding discussion reports, thereby completing the closed loop of the entire operation process.

[0054] Corresponding to the aforementioned operating system, this invention also proposes an operating method. Since the method embodiments of this invention correspond to the aforementioned system embodiments, details not disclosed in the method embodiments can be referred to the aforementioned system embodiments, and will not be repeated here.

[0055] Figure 4 is a flowchart illustrating an operation method provided in an embodiment of this disclosure, which is applied to the aforementioned operation system.

[0056] As shown in Figure 4, the method includes steps 101-104.

[0057] Step 101: Extract information tags from the target data source and obtain the overlap result based on the information tags and historical tags in the tag database.

[0058] In some embodiments, the target data source includes national policies, internet big data, complaint information, and content uploaded by cloud storage users. The method for extracting information tags includes semantic segmentation and keyword filtering of the target data source, identifying expressions within the data source to form corresponding information tags. The historical tags stored in the tag database are valid information tags retained after collection and processing during past operations. The overlap result is calculated by comparing the number of common features between the information tag and the historical tag with the total number of features.

[0059] Step 102: If the overlap result is low overlap, calculate the warning level of the information tag.

[0060] In some embodiments, low overlap is a preset quantification range of overlap results, for example, configured as overlap results less than or equal to 30%; the calculation method of warning degree includes comprehensive calculation by combining multiple risk-related parameters of information tags.

[0061] Step 103: When the warning level exceeds the preset warning threshold, a warning is triggered, and the risk weight of the information tag in the tag database is adjusted based on the warning level.

[0062] In some embodiments, the preset warning threshold is a quantification standard for determining whether a warning is triggered. The methods for triggering a warning include generating a warning notification, marking a high-risk identifier on the system interface, and sending a warning signal to relevant operational nodes. The method for adjusting the risk weight based on the warning level includes determining the adjustment range based on the quantified value of the warning level. If the warning level exceeds the preset warning threshold, the corresponding warning operation is executed, and the current risk weight of the information tag in the tag database is retrieved, the weight is updated according to the adjustment range, and synchronized to the tag database.

[0063] Step 104: Perform a risk assessment on the data based on the risk weight of each tag in the tag database, and generate a risk assessment report.

[0064] In some embodiments, the risk assessment method includes calculating the comprehensive risk value of the data based on the risk weights of one or more information tags associated with the data, and then classifying the risk level based on the comprehensive risk value; the risk assessment report is a standardized document containing the risk assessment results, including the risk level of the data, the information tags associated with the data and their risk weights, the basis for risk determination, etc.; the risk weights of each tag updated in the tag database are called, and the risk assessment operation is performed on the data in the target data source one by one, and the corresponding risk assessment report can be generated after completion.

[0065] In summary, the operation method provided by this disclosure can extract information tags from the target data source and obtain the overlap result based on the information tags and historical tags in the tag database; when the overlap result is low, calculate the warning degree of the information tag; trigger a warning when the warning degree exceeds a preset warning threshold, and adjust the risk weight of the information tag in the tag database based on the warning degree; perform risk assessment on the data according to the risk weight of each tag in the tag database, and generate a risk assessment report. This achieves automated identification, warning, and weight adjustment of potential risk content in the target data source, and performs risk assessment based on the adjusted weight, thereby improving the systematization, automation, and efficiency of the operation.

[0066] Figure 5 further illustrates a flowchart of an operation method provided by an embodiment of this disclosure. As shown in Figure 5, the operation method includes steps 201-202.

[0067] Step 201: Monitor the frequency of occurrence of each information tag within a unit of time.

[0068] Step 202: Select the information tags corresponding to the frequency of abnormal fluctuations as candidate risk tags and generate interpretation prompts.

[0069] For a description of steps 201 and 202, please refer to the detailed description of the relevant embodiments in Figure 2. The embodiments disclosed herein will not be repeated here.

[0070] Figure 6 further illustrates a flowchart of an operation method provided by an embodiment of the present disclosure. As shown in Figure 6, the operation method includes steps 301-303.

[0071] Step 301: Compare the overlap result with a preset first threshold and a second threshold, wherein the first threshold is less than the second threshold.

[0072] In some embodiments, the first threshold and the second threshold are pre-set quantitative standards for classifying the degree of overlap. Their values ​​can be configured according to the risk control accuracy requirements of the operational scenario and the calibration results of historical operational data. After configuration, they can be reused, including but not limited to setting the first threshold to 30% and the second threshold to 80%. They can also be adjusted to other values ​​according to the compliance requirements of different industries, such as the first threshold at 25% and the second threshold at 75%.

[0073] The criteria for setting the threshold include, but are not limited to, the overlap distribution characteristics of historical violation tags, the risk density of the target data source, and the summary of manual review experience, to ensure that the threshold can accurately distinguish information tags of different risk levels. The overlap results are compared by direct comparison of numerical values, which is completed automatically by the system's built-in logical judgment unit without manual intervention.

[0074] Step 302: If the overlap result is less than the first threshold, then the information tag is determined to be the low overlap.

[0075] In some embodiments, the judgment logic of this step is consistent with the judgment logic of low overlap in the relevant embodiment of Figure 1, and the value of the first threshold directly corresponds to the quantization boundary of low overlap. For example, when the first threshold is set to 30%, if the overlap result is 25%, which is less than 30%, then the information tag is directly determined to have low overlap. The above is only an illustrative example and not a limitation on a specific threshold.

[0076] Step 303: If the overlap result is greater than or equal to the first threshold and less than or equal to the second threshold, then the information tag is determined to have a medium overlap, and the information tag is stored as a historical tag in the tag database.

[0077] In some embodiments, medium overlap is a level definition used to characterize that an information tag and a historical tag have a certain degree of similarity but still have supplementary value. The corresponding overlap range is jointly defined by a first threshold and a second threshold. If the first threshold is 30% and the second threshold is 80%, then the overlap result between 30% and 80% is considered medium overlap. The process of storing information tags as historical tags in the tag database includes: the system automatically extracts the features, associated data, and corresponding overlap results of the information tag, standardizes them according to the storage format of the tag database, performs an input operation, and updates the index information of the tag database after input to ensure that subsequent processing modules can quickly retrieve and call them. Conventional data storage protocols can be used during the storage process to ensure the integrity and accessibility of the information tags, and the stored information tags will serve as the basis for historical tags in subsequent comparisons of the overlap of new information tags.

[0078] The above method can be used to classify the overlap results into different levels by quantifying thresholds, clarify the definition criteria for low overlap and medium overlap, and supplement the information tags of medium overlap to the tag database, continuously expanding the coverage of historical tags, providing a comprehensive comparison basis for subsequent information tag overlap calculations, and improving the system's recognition and classification accuracy of various tags.

[0079] Figure 7 further illustrates a flowchart of an operation method provided by an embodiment of this disclosure. Based on the embodiment shown in Figure 4, step 102 is further explained. Figure 7 may include the following steps: Step 401, obtaining the risk level determined based on the overlap result, the probability of the information tag appearing within a preset period, and the rate of change of the popularity of the information tag within a unit time; wherein, the rate of change of popularity is the increase in the frequency of the information tag appearing within a unit time.

[0080] In some embodiments, the risk level is a quantitative indicator determined based on the overlap result and the initial risk weight corresponding to the information tag. Its acquisition method includes, but is not limited to, calculation by multiplying the overlap result by the initial risk weight. Specifically, it can be obtained using... The calculation involves J(A,B) representing the overlap result and C representing the initial risk weight pre-configured in the tag database for the information tag. The occurrence probability is the ratio of the number of days the information tag actually appears within a preset period to the total number of days in that preset period. The preset period can be configured according to operational monitoring needs, including but not limited to one month, two weeks, and seven days. The statistical period for the unit time and the popularity change rate is consistent and can be configured as one day, one hour, twelve hours, etc. The statistical method for the popularity change rate includes, but is not limited to, calculating the difference between the occurrence frequency of the information tag in the current unit time and the occurrence frequency in the previous unit time, and then dividing by the occurrence frequency in the previous unit time; alternatively, it can be obtained by statistically analyzing the occurrence frequency over multiple consecutive unit times and calculating the average increase as the popularity change rate. In this step, the system obtains the initial risk weight by calling the tag database and calculates the occurrence probability and popularity change rate through the built-in statistical unit, automatically completing the acquisition of these three parameters.

[0081] Step 402: Based on the risk level, the probability of occurrence, and the rate of change in popularity, the warning level is obtained.

[0082] In some embodiments, the calculation of the warning level includes, but is not limited to, multiplying the risk level, the probability of occurrence, and the rate of change in popularity. Alternatively, depending on the focus of risk management, different weighting coefficients can be configured for the three parameters, and the warning level can be calculated by weighted summation (e.g., risk level weighting coefficient is 0.5, probability of occurrence weighting coefficient is 0.2, and rate of change in popularity weighting coefficient is 0.3, warning level = risk level × 0.5 + probability of occurrence × 0.2 + rate of change in popularity × 0.3). The calculation process is automatically executed by the system according to preset calculation rules, requiring no manual intervention. After the calculation is completed, a quantified warning level value is directly output for warning judgment in subsequent steps.

[0083] The above method can obtain the warning level by acquiring and comprehensively calculating multi-dimensional parameters, ensuring that the calculation of the warning level fully considers the risk nature, frequency of occurrence and spread speed of the information tag, so that the warning level can accurately characterize the potential risk level of the information tag, and provide reliable quantitative support for subsequent warning triggering and weight adjustment.

[0084] Figure 8 further illustrates a flowchart of an operation method provided by an embodiment of the present disclosure. As shown in Figure 8, the operation method includes steps 501-505.

[0085] Step 501: Extract information tags from the target data source and obtain the overlap result based on the information tags and historical tags in the tag database.

[0086] Step 502: If the overlap result is low overlap, calculate the warning level of the information tag.

[0087] Step 503: When the warning level exceeds the preset warning threshold, a warning is triggered, and the risk weight of the information tag in the tag database is adjusted based on the warning level.

[0088] Step 504: Perform a risk assessment on the data based on the risk weight of each tag in the tag database, and generate a risk assessment report.

[0089] For a description of steps 501-504, please refer to the detailed description of the relevant embodiments in Figure 4. The embodiments disclosed herein will not be repeated here.

[0090] Step 505: Adjust the risk weight of the corresponding information tag in the tag database according to the risk assessment report.

[0091] In some embodiments, the risk assessment report includes the risk level, comprehensive risk quantification value, and risk judgment basis of the data associated with the corresponding information tag. This information is the key basis for adjusting the risk weight. Adjustment methods include, but are not limited to, a preset correspondence between risk level and weight adjustment range: if the risk level of the data associated with the corresponding information tag in the risk assessment report is "high," then the risk weight of that information tag is increased by a preset percentage (e.g., 50%); if the risk level is "medium," then the risk weight is slightly adjusted (e.g., 10%); if the risk level is "low," then the risk weight is decreased by a preset percentage (e.g., 20%). Adjustment rules can also be set based on the comprehensive risk quantification value. For example, when the comprehensive risk quantification value is ≥0.8, the risk weight is increased by 80%; when 0.5 ≤ comprehensive risk quantification value <0.8, the risk weight is increased by 30%. The above are merely illustrative examples and not limitations on specific adjustment rules.

[0092] In this step, the system first parses the risk assessment report, extracts the risk-related parameters of the corresponding information tags, then retrieves the current risk weight of the information tag in the tag database, completes the weight adjustment according to the preset rules, and finally updates the adjusted risk weight to the tag database to ensure that subsequent risk assessments use the latest weight data.

[0093] By using the above methods, the risk weights of information tags can be optimized in a secondary manner based on the actual risk assessment results. This ensures that the risk weights of the corresponding information tags in the tag database are consistent with the actual risk status of the data, continuously improving the accuracy of the tag weights and providing a more reliable basis for subsequent risk assessments.

[0094] Corresponding to the above-described operating method, the present invention also proposes an operating device. Since the device embodiments of the present invention correspond to the above-described method embodiments, details not disclosed in the device embodiments can be referred to in the above-described method embodiments, and will not be repeated here.

[0095] Figure 9 is a schematic diagram of an operating device provided in an embodiment of this disclosure. As shown in Figure 9, the device is configured in an operating system and includes: an extraction unit 91 for extracting information tags from a target data source; a first determination unit 92 for obtaining an overlap result based on the information tags and historical tags in a tag database; a calculation unit 93 for calculating the warning level of the information tags when the overlap result is low; a first adjustment unit 94 for triggering a warning when the warning level exceeds a preset warning threshold and adjusting the risk weight of the information tags in the tag database based on the warning level; and a first generation unit 95 for performing risk assessment on the data based on the risk weight of each tag in the tag database and generating a risk assessment report.

[0096] The operating device described in this embodiment can extract information tags from a target data source and obtain an overlap result based on the information tags and historical tags in a tag database; if the overlap result is low, it calculates the warning level of the information tag; when the warning level exceeds a preset warning threshold, it triggers a warning and adjusts the risk weight of the information tag in the tag database based on the warning level; it performs a risk assessment on the data based on the risk weight of each tag in the tag database and generates a risk assessment report, thereby realizing the automated identification, warning, and weight adjustment of potential risk content in the target data source, and performing risk assessment based on the adjusted weight, thereby improving the systematization, automation level, and efficiency of the operation.

[0097] Furthermore, in one possible implementation of this embodiment, as shown in FIG10, the device further includes: a monitoring unit 96, used to monitor the frequency of occurrence of each information tag within a unit time after the extraction unit 91 extracts the information tags from the target data source; and a second generation unit 97, used to take the information tags corresponding to the frequency of occurrence of abnormal fluctuations as candidate risk tags and generate interpretation prompt information.

[0098] Further, in one possible implementation of this disclosure embodiment, as shown in FIG10, the device further includes: a comparison unit 98, configured to compare the overlap result with a preset first threshold and a second threshold after the first determining unit 92 obtains the overlap result based on the information tag and historical tags in the tag database, wherein the first threshold is less than the second threshold; a second determining unit 99, configured to determine the information tag as the low overlap when the overlap result is less than the first threshold; and a third determining unit 910, configured to determine the information tag as the medium overlap when the overlap result is greater than or equal to the first threshold and less than or equal to the second threshold, and store the information tag as a historical tag in the tag database.

[0099] Further, in one possible implementation of this disclosure embodiment, as shown in FIG10, the calculation unit 93 includes: an acquisition module 931, used to acquire the risk level determined based on the overlap result, the probability of the information tag appearing within a preset period, and the popularity change rate of the information tag within a unit time; wherein the popularity change rate is the increase in the frequency of the information tag appearing within a unit time; and a determination module 932, used to obtain the warning level based on the risk level, the probability of appearance, and the popularity change rate.

[0100] Furthermore, in one possible implementation of this disclosure embodiment, as shown in FIG10, the device further includes: a second adjustment unit 911, used to adjust the risk weight of the corresponding information tag in the tag database according to the risk assessment report generated by the first generation unit 95 based on the risk weight of each tag in the tag database.

[0101] It should be noted that the foregoing explanation of the method embodiments also applies to the apparatus of the embodiments of this disclosure, and the principle is the same. Therefore, the embodiments of this disclosure are not limited thereto.

[0102] According to embodiments of this disclosure, this disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0103] Figure 11 illustrates a schematic block diagram of an example electronic device 1000 that can be used to implement embodiments of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0104] As shown in Figure 11, the electronic device 1000 includes a computing unit 1001, which can perform various appropriate actions and processes according to a computer program stored in ROM (Read-Only Memory) 1002 or loaded from storage unit 1008 into RAM (Random Access Memory) 1003. The RAM 1003 can also store various programs and data required for the operation of the electronic device 1000. The computing unit 1001, ROM 1002, and RAM 1003 are interconnected via bus 1004. An I / O (Input / Output) interface 1005 is also connected to bus 1004.

[0105] Multiple components in electronic device 1000 are connected to I / O interface 1005, including: input unit 1006, such as keyboard, mouse, etc.; output unit 1007, such as various types of displays, speakers, etc.; storage unit 1008, such as disk, optical disk, etc.; and communication unit 1009, such as network card, modem, wireless transceiver, etc. Communication unit 1009 allows electronic device 1000 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0106] The computing unit 1001 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 1001 include, but are not limited to, CPUs (Central Processing Units), GPUs (Graphics Processing Units), various special-purpose AI (Artificial Intelligence) computing chips, various computing units running machine learning model algorithms, DSPs (Digital Signal Processors), and any suitable processor, controller, microcontroller, etc. The computing unit 1001 performs the various methods and processes described above, such as operational methods. For example, in some embodiments, the operational methods may be implemented as computer software programs tangibly contained in a machine-readable medium, such as storage unit 1008. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 1000 via ROM 1002 and / or communication unit 1009. When the computer program is loaded into RAM 1003 and executed by the computing unit 1001, one or more steps of the methods described above may be performed. Alternatively, in other embodiments, the computing unit 1001 may be configured to perform the aforementioned operating method by any other suitable means (e.g., by means of firmware).

[0107] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, FPGAs (Field Programmable Gate Arrays), ASICs (Application-Specific Integrated Circuits), ASSPs (Application-Specific Standard Products), SOCs (System-on-Chips), CPLDs (Complex Programmable Logic Devices), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0108] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0109] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, RAM, ROM, EPROM (Electrically Programmable Read-Only Memory) or flash memory, optical fiber, CD-ROM (Compact Disc Read-Only Memory), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0110] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (Cathode-Ray Tube) or LCD (Liquid Crystal Display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0111] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include LANs (Local Area Networks), WANs (Wide Area Networks), the Internet, and blockchain networks.

[0112] Computer systems can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. A server can be a cloud server, also known as a cloud computing server or cloud host, a hosting product within the cloud computing service system that addresses the shortcomings of traditional physical hosts and VPS (Virtual Private Server) services, such as high management difficulty and weak business scalability. Servers can also be servers for distributed systems or servers incorporating blockchain technology.

[0113] It's important to note that artificial intelligence (AI) is the study of enabling computers to simulate certain human thought processes and intelligent behaviors (such as learning, reasoning, thinking, and planning). It encompasses both hardware and software technologies. AI hardware technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, and big data processing. AI software technologies primarily include computer vision, speech recognition, natural language processing, machine learning / deep learning, big data processing, and knowledge graph technologies.

[0114] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.

[0115] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. An operating system, characterized in that, The system includes: a data acquisition module, a processing module, an early warning module, an adjustment module, and a risk module. The data acquisition module extracts information tags from a target data source and sends the information tags to the processing module. The processing module receives the information tags from the data acquisition module, calculates the overlap between the information tags and historical tags in a tag database, and sends the information tags to the early warning module when the overlap is low. The early warning module receives the information tags from the processing module, calculates the early warning level of the information tags, triggers an early warning when the early warning level exceeds a preset early warning threshold, and sends the early warning level to the adjustment module. The adjustment module receives the early warning level from the early warning module and adjusts the risk weight of the information tags in the tag database based on the early warning level. The risk module performs a risk assessment on the data based on the risk weights of each tag in the tag database and generates a risk assessment report.

2. The system according to claim 1, characterized in that, The system also includes a tag interpretation module, which is used to monitor the frequency of occurrence of each information tag extracted by the acquisition module within a unit time, take the information tags corresponding to the frequency of abnormal fluctuations as candidate risk tags, and generate interpretation prompt information.

3. The system according to claim 1, characterized in that, The adjustment module is further configured to: receive the warning level sent by the warning module and the risk assessment report generated by the risk module, and adjust the risk weight of the corresponding information tag in the tag database according to the warning level and the risk assessment report.

4. An operating method, characterized in that, The operation method is applied to the operation system of any one of claims 1-3, comprising: extracting information tags from the target data source and obtaining an overlap result based on the information tags and historical tags in the tag database; calculating the warning degree of the information tag when the overlap result is low; triggering a warning when the warning degree exceeds a preset warning threshold, and adjusting the risk weight of the information tag in the tag database based on the warning degree; performing a risk assessment on the data based on the risk weight of each tag in the tag database, and generating a risk assessment report.

5. The method according to claim 4, characterized in that, After extracting information tags from the target data source, the method further includes: monitoring the frequency of occurrence of each information tag within a unit of time; using the information tags corresponding to the frequency of occurrence of abnormal fluctuations as candidate risk tags, and generating interpretation prompts.

6. The method according to claim 4, characterized in that, After obtaining the overlap result based on the information tag and historical tags in the tag database, the method further includes: comparing the overlap result with a preset first threshold and a second threshold, wherein the first threshold is less than the second threshold; if the overlap result is less than the first threshold, then the information tag is determined to have low overlap; if the overlap result is greater than or equal to the first threshold and less than or equal to the second threshold, then the information tag is determined to have medium overlap, and the information tag is stored as a historical tag in the tag database.

7. The method according to claim 4, characterized in that, When the overlap result is low, the method for calculating the warning level of the information tag includes: obtaining the risk level determined based on the overlap result, the probability of the information tag appearing within a preset period, and the popularity change rate of the information tag within a unit time; wherein the popularity change rate is the increase in the frequency of the information tag appearing within a unit time; and obtaining the warning level based on the risk level, the probability of appearance, and the popularity change rate.

8. The method according to claim 4, characterized in that, After performing a risk assessment on the data based on the risk weights of each tag in the tag database and generating a risk assessment report, the method further includes: adjusting the risk weights of the corresponding information tags in the tag database based on the risk assessment report.

9. An operating device, characterized in that, The operating device is configured in the operating system according to any one of claims 1-3, comprising: an extraction unit for extracting information tags from a target data source; a first determining unit for obtaining an overlap result based on the information tags and historical tags in a tag database; a calculation unit for calculating the warning level of the information tags when the overlap result is low; a first adjusting unit for triggering a warning when the warning level exceeds a preset warning threshold, and adjusting the risk weight of the information tags in the tag database based on the warning level; and a first generating unit for performing a risk assessment on the data based on the risk weight of each tag in the tag database, and generating a risk assessment report.

10. An electronic device, characterized in that, include: At least one processor; And a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor to enable the at least one processor to perform the method of any one of claims 4-8.

11. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to perform the method according to any one of claims 4-8.

12. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method according to any one of claims 4-8.