Risk isolation method and product of model cluster based on net body intelligent architecture

By using a network-based intelligent architecture, dynamic routing and risk isolation strategies are employed to handle user requests within the model cluster, thus addressing the issue of poor risk isolation effectiveness in existing technologies and achieving more efficient risk isolation.

CN122069102APending Publication Date: 2026-05-19CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINA UNITED NETWORK COMM GRP CO LTD
Filing Date
2026-03-30
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

In existing technologies, risk isolation based on model clusters is ineffective and cannot effectively handle risk issues associated with user requests.

Method used

By using a network-based intelligent architecture, task processing strategies and model security features are determined based on user task request characteristics. Candidate cluster models are dynamically routed, and risk isolation strategies are used for risk isolation, including multi-dimensional feature extraction, risk analysis, and state updates, to achieve risk isolation for model clusters.

Benefits of technology

It improves the effectiveness of risk isolation in model clusters, ensures the security and compliance of user requests during model cluster processing, and solves the problem of poor risk isolation effectiveness in existing technologies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122069102A_ABST
    Figure CN122069102A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a risk isolation method and product of a model cluster based on a net body intelligent architecture, and relates to the technical field of artificial intelligence. Matching a task processing strategy through the task request feature, and determining an initial task processing state according to the task processing strategy and a model security feature of an initial cluster model of the model cluster; on this basis, the candidate cluster model is dynamically routed round by round to determine a target candidate cluster model, and a risk isolation strategy is determined according to the current task processing state and the current task processing result, so that risk isolation is carried out on the user task request in the model cluster processing process; the problem that risk isolation effectiveness is poor due to the fact that risk isolation is carried out on a large model by setting a keyword filtering mode in the scheme in the prior art is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of artificial intelligence technology, and in particular to a risk isolation method and product for model clusters based on a network-based intelligent architecture. Background Technology

[0002] With the rapid development of large model technology, corresponding model clusters have been built based on multiple large models with different modalities, parameter scales, and deployment locations. This enables user requests to flow between multiple large models in the model cluster, be processed step by step, and finally be aggregated and output.

[0003] In existing technologies, to address the risk issues associated with user requests within a model cluster, risk isolation of large models is typically achieved by setting keyword filtering, thereby enabling the invocation of one or more large models within the model cluster to process user requests.

[0004] However, existing solutions suffer from poor effectiveness in risk isolation. Summary of the Invention

[0005] The risk isolation method and product based on the intelligent network architecture provided in this application are used to solve the problem of poor risk isolation effectiveness in existing solutions.

[0006] In a first aspect, embodiments of this application provide a risk isolation method for model clusters based on a network-based intelligent architecture, comprising: determining a task processing strategy based on task request characteristics corresponding to a user task request; determining an initial task processing state based on the task processing strategy and the model security characteristics of the initial cluster model of the model cluster; determining the initial cluster model as the current processing model, the initial task processing state as the current task processing state, and the task request characteristics as task request input characteristics; inputting the task request input characteristics into the current processing model, outputting the current task processing result, and determining one or more candidate cluster models into which the current task processing result is input; determining a target candidate cluster model from the one or more candidate cluster models based on the current task processing state; and determining risk isolation based on the current task processing state and the current task processing result. The strategy involves determining whether to isolate the current processing model from risk. If the target candidate cluster model is a terminated cluster model, the target processing result is determined based on the current task processing result, the risk isolation strategy, and the terminated cluster model. If the target candidate cluster model is an intermediate cluster model, the current task processing state is updated based on the risk isolation strategy and the model security features of the intermediate cluster model. The updated current task processing state is then redefined as the current task processing state, and the intermediate cluster model is defined as the current processing model. The current task processing result is defined as the task request input feature, and the process returns to the steps of inputting the task request input feature into the current processing model, outputting the current task processing result, and determining one or more candidate cluster models into which the current task processing result is input.

[0007] In one possible implementation, determining the target candidate cluster model from the one or more candidate cluster models based on the current task processing state includes: determining a set of models allowed by the security policy and a set of models prohibited by the security policy based on the current task processing state; and filtering the one or more candidate cluster models based on the set of models allowed by the security policy and the set of models prohibited by the security policy to obtain the target candidate cluster model.

[0008] In one possible implementation, determining the risk isolation strategy based on the current task processing status and the current task processing result includes: extracting multi-dimensional features from the current task processing result based on the current task processing status to generate risk feature data; wherein the risk feature data includes target risk content, target logical conflict content, and target unauthorized tool content corresponding to the current task processing result; performing risk analysis on the risk feature data to generate risk feature tags and risk feature scores; and determining the risk isolation strategy based on the risk feature tags and the risk feature scores.

[0009] In one possible implementation, updating the current task processing state based on the risk isolation strategy and the model security features of the intermediate cluster model, and then re-determining the updated current task processing state as the current task processing state, includes: updating the model security features of the intermediate cluster model according to the risk isolation strategy to obtain updated model security features; updating the task processing strategy, the set of models allowed by the security policy, and the set of models prohibited by the security policy in the current task processing state according to the risk isolation strategy to obtain a preliminary updated current task processing state; replacing the model security features in the preliminary updated current task processing state with the updated model security features to obtain the updated current task processing state; and re-determining the updated current task processing state as the current task processing state.

[0010] In one possible implementation, determining the target processing result based on the current task processing result, the risk isolation strategy, and the termination cluster model includes: arbitrating the current task processing result according to the risk isolation strategy to generate a current task arbitration result; inputting the current task processing result into the termination cluster model according to the current task arbitration result to output the target processing result; or, determining a target cluster model from the model cluster according to the current task arbitration result; determining the target cluster model as the current processing model to return to the steps of inputting the task request input features into the current processing model, outputting the current task processing result, and determining one or more candidate cluster models into which the current task processing result is input.

[0011] In one possible implementation, the method further includes: collecting call characteristics of the call share of the current processing model; and determining whether to conduct high-frequency call review on the current processing model based on the call characteristics of the call share of the current processing model.

[0012] Secondly, embodiments of this application provide a risk isolation device for a model cluster of a network-based intelligent architecture, comprising: a first processing module, configured to determine a task processing strategy based on task request characteristics corresponding to a user task request; determine an initial task processing state based on the task processing strategy and the model security characteristics of the initial cluster model of the model cluster; determine the initial cluster model as the current processing model, the initial task processing state as the current task processing state, and the task request characteristics as task request input characteristics; an output module, configured to input the task request input characteristics into the current processing model, output the current task processing result, and determine one or more candidate cluster models into which the current task processing result is input; a second processing module, configured to determine a target candidate cluster model from the one or more candidate cluster models based on the current task processing state; and determine the target candidate cluster model based on the current task processing state and the current task... The processing results determine a risk isolation strategy. The risk isolation strategy is used to determine whether to isolate the current processing model from risk. If the target candidate cluster model is a terminated cluster model, the target processing result is determined based on the current task processing result, the risk isolation strategy, and the terminated cluster model. If the target candidate cluster model is an intermediate cluster model, the current task processing state is updated based on the risk isolation strategy and the model security features of the intermediate cluster model. The updated current task processing state is then redefined as the current task processing state, and the intermediate cluster model is defined as the current processing model. The current task processing result is defined as the task request input feature. The process then returns to the steps of inputting the task request input feature into the current processing model, outputting the current task processing result, and determining one or more candidate cluster models into which the current task processing result is input.

[0013] In one possible implementation, when the second processing module determines the target candidate cluster model from the one or more candidate cluster models according to the current task processing state, it is specifically used to: determine the set of models allowed by the security policy and the set of models prohibited by the security policy according to the current task processing state; and filter the one or more candidate cluster models according to the set of models allowed by the security policy and the set of models prohibited by the security policy to obtain the target candidate cluster model.

[0014] In one possible implementation, when the second processing module determines a risk isolation strategy based on the current task processing status and the current task processing result, it is specifically configured to: extract multi-dimensional features from the current task processing result based on the current task processing status to generate risk feature data; wherein, the risk feature data includes target risk content, target logical conflict content, and target unauthorized tool content corresponding to the current task processing result; perform risk analysis on the risk feature data to generate risk feature tags and risk feature scores; and determine the risk isolation strategy based on the risk feature tags and the risk feature scores.

[0015] In one possible implementation, when the second processing module updates the current task processing state according to the risk isolation strategy and the model security features of the intermediate cluster model, and redetermines the updated current task processing state as the current task processing state, it specifically performs the following steps: updating the model security features of the intermediate cluster model according to the risk isolation strategy to obtain updated model security features; updating the task processing strategy, the set of models allowed by the security policy, and the set of models prohibited by the security policy in the current task processing state according to the risk isolation strategy to obtain a preliminary updated current task processing state; replacing the model security features in the preliminary updated current task processing state with the updated model security features to obtain the updated current task processing state; and redetermining the updated current task processing state as the current task processing state.

[0016] In one possible implementation, when the second processing module determines the target processing result based on the current task processing result, the risk isolation strategy, and the termination cluster model, it is specifically configured to: arbitrate the current task processing result according to the risk isolation strategy to generate a current task arbitration result; input the current task processing result into the termination cluster model according to the current task arbitration result to output the target processing result; or, determine a target cluster model from the model cluster according to the current task arbitration result; determine the target cluster model as the current processing model to return to the steps of inputting the task request input features into the current processing model, outputting the current task processing result, and determining one or more candidate cluster models into which the current task processing result is input.

[0017] In one possible implementation, the risk isolation device of the model cluster of the network intelligent architecture is further used to: collect the call characteristics of the call share of the current processing model; and determine whether to conduct high-frequency call review on the current processing model based on the call characteristics of the call share of the current processing model.

[0018] Thirdly, embodiments of this application provide an electronic device, including: a memory and a processor;

[0019] The memory stores computer-executed instructions;

[0020] The processor executes computer execution instructions stored in the memory, causing the processor to perform the first aspect and / or various possible implementations of the first aspect as described above.

[0021] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the first aspect and / or various possible implementations of the first aspect.

[0022] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the first aspect and / or various possible implementations of the first aspect.

[0023] The risk isolation method and product for model clusters based on a network-based intelligent architecture provided in this application embodiment determine a task processing strategy based on the task request characteristics corresponding to a user task request; determine an initial task processing state based on the task processing strategy and the model security characteristics of the initial cluster model of the model cluster; determine the initial cluster model as the current processing model, the initial task processing state as the current task processing state, and the task request characteristics as task request input characteristics; input the task request input characteristics into the current processing model, output the current task processing result, and determine one or more candidate cluster models into which the current task processing result is input; determine a target candidate cluster model from one or more candidate cluster models based on the current task processing state; and determine the risk based on the current task processing state and the current task processing result. Isolation strategy; the risk isolation strategy is used to determine whether to isolate the current processing model from risk; if the target candidate cluster model is a terminated cluster model, the target processing result is determined based on the current task processing result, the risk isolation strategy, and the terminated cluster model; if the target candidate cluster model is an intermediate cluster model, the current task processing state is updated based on the risk isolation strategy and the model security characteristics of the intermediate cluster model, and the updated current task processing state is redefined as the current task processing state, and the intermediate cluster model is defined as the current processing model, and the current task processing result is defined as the task request input feature, so as to return to the steps of inputting the task request input feature into the current processing model, outputting the current task processing result, and determining one or more candidate cluster models into which the current task processing result is input. That is, by matching task request features with task processing strategies, and then determining the initial task processing state based on the task processing strategy and the model security features of the initial cluster model of the model cluster; on this basis, candidate cluster models are dynamically routed round by round to determine the target candidate cluster model, and a risk isolation strategy is determined based on the current task processing state and the current task processing result. This achieves risk isolation during the processing of user task requests in the model cluster, solving the problem of poor risk isolation effectiveness caused by existing solutions that use keyword filtering to achieve risk isolation for large models. Attached Figure Description

[0024] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0025] Figure 1 A schematic diagram illustrating a scenario for the risk isolation method for model clusters based on the network-body intelligent architecture provided in this application;

[0026] Figure 2 A flowchart illustrating a risk isolation method for a model cluster based on a network-body intelligent architecture, provided in one embodiment of this application;

[0027] Figure 3 A flowchart illustrating a risk isolation method for a model cluster based on a network-body intelligent architecture, provided in another embodiment of this application;

[0028] Figure 4 A schematic diagram of the structure of a risk isolation device for a model cluster of a smart network architecture provided in one embodiment of this application;

[0029] Figure 5 A schematic diagram of the structure of the electronic device provided in this application.

[0030] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0031] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0032] The technical solution of this application involves the collection, storage, use, processing, transmission, provision and disclosure of user personal information and data, which comply with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0033] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.

[0034] With the rapid development of large-scale model technology, model clusters have been constructed based on multiple large models with different modalities, parameter scales, and deployment locations. This enables a processing chain where user requests flow, are processed step-by-step, and finally aggregated and output among multiple large models within the cluster. In existing technologies, to address risks associated with user requests within the model cluster, keyword filtering is typically used to isolate risks in the large models, thereby allowing the invocation of one or more large models within the cluster to process the user request. However, existing solutions suffer from poor effectiveness in risk isolation.

[0035] First, let me explain the terms used in this application:

[0036] Netbody Intelligence: Netbody Intelligence architecture is an AI architecture based on multiple AI models and a large-scale distributed computing environment. Based on a directed graph structure, it treats AI models / modules as "multi-brain subsystems" distributed in different regions and network nodes, forming an intelligent agent with node and edge characteristics through network connections. Furthermore, the intelligent agent based on the Netbody Intelligence architecture achieves sparse collaboration and implicit aggregation through edge decision-making (learnable), and continues to evolve under real business feedback. Moreover, the system-level security governance layer ensures compliance, consistency and auditability of the entire chain. Among them, node characteristics include node capability characteristics, node network characteristics, and node cost characteristics; the core of the network-based intelligent architecture is to construct multiple artificial intelligence models / modules in different regions into a directed graph structure, and introduce multi-dimensional constraint characteristics such as "capability boundary (node ​​capability characteristics), network state (node ​​network characteristics), and call cost (node ​​cost characteristics)" for each model / module, so that the model is intrinsically sensitive to network, computing power, and task requirements, thereby realizing intelligent scheduling, collaboration, and aggregation of multiple models across domains. It can proactively adapt to the high cost-effectiveness inference requirements in wide area network and cross-regional environments. At the same time, multiple artificial intelligence models are connected through a directed graph, and intelligent model scheduling and aggregation modes are constructed by activating connection parameters.

[0037] The application scenarios of the embodiments of this application are explained below:

[0038] Figure 1 A schematic diagram illustrating the scenario of the risk isolation method for model clusters based on the network-body intelligent architecture provided in this application, such as... Figure 1 As shown, the model cluster includes multiple cluster models: the initial cluster model Vs, the intermediate cluster models V1, V2, V3, V4, and V5, and the final cluster model Ve. The execution subject of the method provided in this application embodiment can be any form of electronic device, and a computer device is used as the execution subject for illustration.

[0039] Specifically, the computer device determines a task processing strategy based on the task request characteristics corresponding to the user's task request; determines an initial task processing state based on the task processing strategy and the model security characteristics of the initial cluster model Vs of the model cluster; then, it determines the initial cluster model Vs as the current processing model, the initial task processing state as the current task processing state, and the task request characteristics as task request input characteristics; it inputs the task request input characteristics into the current processing model, outputs the current task processing result, and determines one or more candidate cluster models into which the current task processing result is input; for example, candidate cluster models include intermediate cluster models V1, V2, and V3. Furthermore, based on the current task processing state, a target candidate cluster model is determined from one or more candidate cluster models; a risk isolation strategy is determined based on the current task processing state and the current task processing result; the risk isolation strategy is used to determine whether to perform risk isolation on the current processing model. Finally, if the target candidate cluster model is a termination cluster model Ve, the target processing result is determined based on the current task processing result, the risk isolation strategy, and the termination cluster model Ve. If the target candidate cluster model is an intermediate cluster model, for example, the target candidate cluster model is intermediate cluster model V1, then according to the risk isolation strategy and the model security characteristics of intermediate cluster model V1, the current task processing state is updated, and the updated current task processing state is redefined as the current task processing state. In addition, intermediate cluster model V1 is defined as the current processing model, and the current task processing result is defined as the task request input feature. Then, the process returns to the steps of inputting the task request input feature into the current processing model, outputting the current task processing result, and determining one or more candidate cluster models into which the current task processing result is input.

[0040] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0041] Figure 2 A flowchart of a risk isolation method for a model cluster based on a network-body intelligent architecture provided in one embodiment of this application is shown below. Figure 2 As shown, the execution subject of the risk isolation method for model clusters based on the network-body intelligent architecture provided in this embodiment can be any form of electronic device. For example, this embodiment uses a computer device as the execution subject of the method. The risk isolation method for model clusters based on the network-body intelligent architecture provided in this embodiment includes the following steps:

[0042] Step S201: Determine the task processing strategy based on the task request characteristics corresponding to the user's task request.

[0043] For example, the user's task request is parsed to generate task request features; wherein, the task request features include task type and modal requirements, preferences or constraints on response quality (accuracy of the output results of the model corresponding to the graph node), latency, cost, and task semantic feature representation.

[0044] Furthermore, based on the characteristics of the task request, a task processing strategy for handling the user's task request is determined. Specifically, the task processing strategies include financial compliance strategies, medical compliance strategies, and government compliance strategies. Then, based on the characteristics of the task request, a task processing strategy that matches the user's task request is selected from multiple task processing strategies. For example, if the user's task request is a medical task request, then the task processing strategy is a medical compliance strategy. The medical compliance strategy is used to indicate that calling non-medical domain models is prohibited and to protect user privacy from being leaked.

[0045] Step S202: Determine the initial task processing state based on the task processing strategy and the model security characteristics of the initial cluster model of the model cluster.

[0046] For example, model security features are used to indicate features that impose security compliance constraints on cluster models, such as model security features. As shown in equation (1).

[0047] (1)

[0048] in, Used to indicate the first in the model cluster A cluster model; For the first Trust levels for individual cluster models; For the first The processing strategies supported by each cluster model; For the first Data access scope of each cluster model; For the first Tool access permissions for each cluster model; For the first Node risk score for each cluster model (updated dynamically based on high-frequency call review, incidents, and drift). For the first Identity consistency rules for each cluster model (prohibiting the output of disallowed identity descriptions, prohibiting identity obfuscation statements, etc.).

[0049] The task processing strategy and the model security features of the initial cluster model of the model cluster are merged to obtain the initial task processing state, for example, the initial task processing state. As shown in equation (2).

[0050] (2)

[0051] in, Used to indicate user task requests processed by the model cluster; To constrain the external identity and self-awareness of the model cluster when processing user task requests; For task processing policy (security policy in effect for the current session); The security policy allows a set of models, which is a combination of cluster models that are allowed to participate in the call. The security policy allows models that are allowed to participate in the call. This is a set of models prohibited by security policies, that is, a combination of cluster models that are prohibited from participating in the call. The models prohibited by security policies are the cluster models that are prohibited from participating in the call. Record historical risk events; Pre-set basic commitments (e.g., data usage boundaries, refusal boundaries, refusal to process boundaries, etc.); For the first Model security features of individual cluster models .

[0052] Step S203: Determine the initial cluster model as the current processing model, determine the initial task processing state as the current task processing state, and determine the task request features as the task request input features.

[0053] Step S204: Input the task request input features into the current processing model, output the current task processing result, and determine one or more candidate cluster models to input the current task processing result.

[0054] For example, the task request input features are input into the current processing model, so that the current processing model performs inference processing on the task request input features based on the model inference features of the current processing model, and generates and outputs the current task processing result; then, a pre-trained path planning model is invoked, so that the pre-trained path planning model determines one or more candidate cluster models to input the current task processing result based on the task request input features, as well as the model capability features, model network features, model cost features and model path features of the current processing model.

[0055] Step S205: Based on the current task processing status, determine the target candidate cluster model from one or more candidate cluster models.

[0056] For example, the current task processing status is used to indicate the cluster models that can be invoked based on the security policy; then, based on the cluster models that can be invoked based on the security policy, the target candidate cluster model can be determined from one or more candidate cluster models.

[0057] Specifically, the specific implementation steps of step S205 include:

[0058] Step S2051: Based on the current task processing status, determine the set of models allowed by the security policy and the set of models prohibited by the security policy.

[0059] in, The set of models allowed by the security policy; This is a set of models prohibited by security policies.

[0060] Step S2052: Based on the set of allowed models and the set of prohibited models under the security policy, one or more candidate cluster models are screened to obtain the target candidate cluster model.

[0061] For example, the number of target candidate cluster models can be zero or one or more, so the set of target candidate cluster models is used to represent the determined target candidate cluster models, as shown in equation (3).

[0062] (3)

[0063] in, For the target candidate cluster model set; Used to indicate the target candidate cluster model; It is a set of models consisting of one or more candidate cluster models determined in step S204; The least privilege requirement is used to indicate the target candidate cluster model. Security policies meet task processing policies This means that the security policy in effect for the current session is met.

[0064] Furthermore, if If the set is empty, meaning there are 0 target candidate cluster models, then the target cluster model is determined from the model cluster; wherein, the trust level of the target cluster model is higher than the trust level of the current processing model; then, the target cluster model is re-determined as the current processing model, and the process returns to step S204.

[0065] Furthermore, if If it is not an empty set, proceed with the next steps.

[0066] Step S206: Determine the risk isolation strategy based on the current task processing status and the current task processing result; the risk isolation strategy is used to determine whether to isolate the current processing model from risk.

[0067] Specifically, the specific implementation steps of step S206 include:

[0068] Step S2061: Extract multi-dimensional features from the current task processing result based on the current task processing status to generate risk feature data; wherein, the risk feature data includes the target risk content, target logical conflict content, and target overreach tool content corresponding to the current task processing result.

[0069] For example, if the current task processing result is "delete database", then multi-dimensional feature extraction is performed on "delete database" based on the current task processing status. For example, the "tool call intent" and "sensitive content" corresponding to "delete database" are extracted to obtain risk feature data. Among them, the risk feature data includes target risk content, target logical conflict content, and target unauthorized tool content corresponding to the current task processing result. Target logical conflict content is, for example, value conflict content, model identity conflict content (such as making the model impersonate, play, or forge an identity that does not belong to it, or identity information that is contradictory or falsified), and inducing model content (such as the user using language to guide, imply, or set traps to try to make the model say illegal content).

[0070] Step S2062: Perform risk analysis on the risk characteristic data to generate risk characteristic labels and risk characteristic scores.

[0071] For example, a pre-defined rule base, a pre-trained classifier, or a model detector can be invoked to perform risk analysis on the risk feature data, generating risk feature labels and risk feature scores.

[0072] Specifically, for example, a pre-defined rule base is used to match specific risk patterns (such as keywords or regular expressions). This pre-defined rule base includes a "word_1" keyword rule, which is used to match risk feature data. If "word_1" is matched, a "word_1" tag is generated, which is the risk feature tag. .

[0073] Pre-trained classifiers, such as the BERT classification model, are used to perform sentiment analysis on risk feature data to determine whether the risk feature data contains misleading content. Based on whether the risk feature data contains misleading content and the proportion of misleading content in the risk feature data, a risk feature score is generated.

[0074] The pre-defined rule base, pre-trained classifier, or model detector rely on data including task processing strategies when performing risk analysis on risk feature data. Current task processing status .

[0075] Furthermore, the data generated by risk analysis of risk feature data also includes risk feature hit criteria and risk feature hit records; among them, risk feature hit criteria include risk feature hit rules (e.g., the "word_1" keyword rule), classifier identifier, and risk feature hit reason; risk feature hit records include the model identifier of the current processing model, the model version of the current processing model, the generation time when the current processing model generates the current task processing result, and the request identifier of the user task request.

[0076] Step S2063: Determine the risk isolation strategy based on the risk characteristic labels and risk characteristic scores.

[0077] For example, the risk isolation strategy includes a first risk isolation strategy and a second risk isolation strategy, wherein the first risk isolation strategy is used to indicate whether to trigger a risk isolation action; and the second risk isolation strategy is used to indicate whether to trigger a risk isolation action. Specifically, the risk isolation actions include marking the current processing model as "the current task processing result output by the current processing model cannot be used as input for subsequent cluster models", calling the current task processing result output by the current processing model only as a readable result, reviewing the current task processing result output by the current processing model, and marking the current processing model as a security policy prohibited model pending review.

[0078] Then, a preset set of risk feature labels and a risk feature scoring threshold are obtained; it is determined whether the risk feature label belongs to the preset set of risk feature labels, and the relationship between the risk feature score and the risk feature scoring threshold is determined; if the risk feature label belongs to the preset set of risk feature labels and / or the risk feature score is greater than or equal to the risk feature scoring threshold, then the risk isolation strategy is the first risk isolation strategy; if the risk feature label does not belong to the preset set of risk feature labels and the risk feature score is less than the risk feature scoring threshold, then the risk isolation strategy is the second risk isolation strategy.

[0079] Step S207: If the target candidate cluster model is a terminated cluster model, then the target processing result is determined based on the current task processing result, risk isolation strategy and terminated cluster model.

[0080] Specifically, if the target candidate cluster model is a terminated cluster model, then the specific implementation steps of step S207 include:

[0081] Step S2071: Based on the risk isolation strategy, arbitrate the current task processing result and generate the current task arbitration result.

[0082] For example, the risk isolation strategy includes a first risk isolation strategy and a second risk isolation strategy, wherein the first risk isolation strategy is used to indicate that a risk isolation action is triggered; and the second risk isolation strategy is used to indicate that a risk isolation action is not triggered.

[0083] Furthermore, if the risk isolation strategy is the second risk isolation strategy, no risk isolation action is triggered, and the arbitration result generated by arbitrating the current task processing result is "arbitration passed". If the risk isolation strategy is the first risk isolation strategy, a risk isolation action is triggered, and the result of the current task processing result is arbitrated. If the risk feature data corresponding to the current task processing result can be eliminated, the current task arbitration result is the elimination strategy for eliminating the risk feature data. If the risk feature data corresponding to the current task processing result cannot be eliminated, the current task arbitration result is the generation strategy for regenerating the current task processing result, or the current task arbitration result is the warning strategy for not being able to eliminate the risk feature data and the generation strategy for regenerating the current task processing result.

[0084] Step S2072: Based on the current task arbitration result, input the current task processing result into the termination cluster model to output the target processing result; or, based on the current task arbitration result, determine the target cluster model from the model cluster; determine the target cluster model as the current processing model, and return to execute step S204.

[0085] Specifically, if the arbitration result of the current task is an elimination strategy to eliminate risk feature data, then after eliminating the risk feature data of the current task processing result, the current task processing result with eliminated risk feature data is input into the termination cluster model so that the termination cluster model outputs the target processing result.

[0086] If the current task arbitration result is a generation strategy to regenerate the current task processing result, then the target cluster model is determined from the model cluster to perform task rollback; wherein, the trust level of the target cluster model is higher than the trust level of the current processing model; then the target cluster model is re-determined as the current processing model to return to the execution step S204.

[0087] Alternatively, if the current task arbitration result is a warning strategy that cannot eliminate risk feature data and a generation strategy that regenerates the current task processing result, then a target cluster model is determined from the model cluster for task rollback; wherein, the trust level of the target cluster model is higher than the trust level of the current processing model; then the target cluster model is re-determined as the current processing model to return to execution step S204; and a warning message that the risk feature data of the current task processing result cannot be eliminated is output.

[0088] Step S208: If the target candidate cluster model is an intermediate cluster model, then according to the risk isolation strategy and the model security characteristics of the intermediate cluster model, the current task processing state is updated, and the updated current task processing state is redefined as the current task processing state. The intermediate cluster model is defined as the current processing model, and the current task processing result is defined as the task request input feature, so as to return to the execution of step S204.

[0089] Specifically, if the target candidate cluster model is an intermediate cluster model, it indicates that the current task processing result output by the current processing model needs to be further processed in the model cluster. Therefore, based on the risk isolation strategy and the model security characteristics of the intermediate cluster model, the current task processing state is updated to obtain the updated current task processing state, and then the updated current task processing state is redefined as the current task processing state. The intermediate cluster model is determined as the current processing model, and the current task processing result is determined as the task request input feature, so as to return to the execution step S204.

[0090] Specifically, the implementation steps for "updating the current task processing state based on the risk isolation strategy and the model security characteristics of the intermediate cluster model, and re-determining the updated current task processing state as the current task processing state" include:

[0091] Step S2081: Update the model security features of the intermediate cluster model according to the risk isolation strategy to obtain the updated model security features.

[0092] For example, the risk isolation strategy is a first risk isolation strategy, which is used to indicate the triggering of risk isolation actions. Based on the triggering of risk isolation actions and the model security features shown in equation (1), the model security features of the intermediate cluster model are updated, for example, by narrowing the data access scope of the cluster model and restricting the tool call permissions of the cluster model, so as to obtain the updated model security features.

[0093] Step S2082: Update the task processing strategy, the set of allowed security models, and the set of prohibited security models in the current task processing state according to the risk isolation strategy to obtain the preliminary updated current task processing state.

[0094] For example, the risk isolation strategy is a first risk isolation strategy, which is used to indicate the triggering of risk isolation actions. Based on the triggering of risk isolation actions, the processing boundaries of the task processing strategy are restricted, the number of allowed models in the set of allowed models is reduced, and the number of prohibited models in the set of prohibited models is increased. That is, the task processing strategy, the set of allowed models, and the set of prohibited models in the current task processing state are updated, thereby obtaining a preliminary updated current task processing state.

[0095] The task processing strategies include financial compliance strategies, medical compliance strategies, and government compliance strategies; the processing boundaries of the task processing strategies are limited, indicating whether to upgrade the task processing strategy from the normal mode to the restricted mode, i.e. Upgrade to For example, limiting the freedom of content generated by subsequent cluster models, forcing subsequent cluster models to adopt more conservative inference templates, and directly triggering a rejection process when encountering sensitive intent; and / or, limiting the processing boundaries of task processing strategies to indicate restrictions on the tool call permissions and data access scope of subsequent cluster models, for example, downgrading the "read / write / execute" bidirectional permissions of subsequent cluster models to "read-only" permissions, or canceling the permissions of subsequent cluster models to call external network interfaces and database query tools.

[0096] Step S2083: Replace the model security features in the initially updated current task processing state with the updated model security features to obtain the updated current task processing state.

[0097] Step S2084: Re-determine the updated current task processing status as the current task processing status.

[0098] In this embodiment, a task processing strategy is determined based on the task request characteristics corresponding to the user's task request; an initial task processing state is determined based on the task processing strategy and the model security characteristics of the initial cluster model of the model cluster; the initial cluster model is determined as the current processing model, the initial task processing state is determined as the current task processing state, and the task request characteristics are determined as task request input characteristics; the task request input characteristics are input into the current processing model, the current task processing result is output, and one or more candidate cluster models for inputting the current task processing result are determined; a target candidate cluster model is determined from one or more candidate cluster models based on the current task processing state; a risk isolation strategy is determined based on the current task processing state and the current task processing result; the risk isolation strategy is used for... Determine whether to perform risk isolation on the current processing model; if the target candidate cluster model is a terminated cluster model, determine the target processing result based on the current task processing result, the risk isolation strategy, and the terminated cluster model; if the target candidate cluster model is an intermediate cluster model, update the current task processing state based on the risk isolation strategy and the model security characteristics of the intermediate cluster model, and re-determine the updated current task processing state as the current task processing state, as well as determine the intermediate cluster model as the current processing model, and determine the current task processing result as the task request input feature, so as to return to the steps of inputting the task request input feature into the current processing model, outputting the current task processing result, and determining one or more candidate cluster models into which the current task processing result is input. That is, by matching task request features with task processing strategies, and then determining the initial task processing state based on the task processing strategy and the model security features of the initial cluster model of the model cluster; on this basis, candidate cluster models are dynamically routed round by round to determine the target candidate cluster model, and a risk isolation strategy is determined based on the current task processing state and the current task processing result. This achieves risk isolation during the processing of user task requests in the model cluster, solving the problem of poor risk isolation effectiveness caused by existing solutions that use keyword filtering to achieve risk isolation for large models.

[0099] Figure 3 A flowchart of a risk isolation method for a model cluster based on a network-body intelligent architecture, as provided in another embodiment of this application, is shown below. Figure 3 As shown, the risk isolation method for model clusters based on the network-body intelligent architecture provided in this embodiment... Figure 2 Based on the risk isolation method for model clusters based on the network-body intelligent architecture provided in the illustrated embodiment, this embodiment further refines the risk isolation method for model clusters based on the network-body intelligent architecture, which includes the following steps:

[0100] Step S301: Determine the task processing strategy based on the task request characteristics corresponding to the user's task request.

[0101] Step S302: Determine the initial task processing state based on the task processing strategy and the model security characteristics of the initial cluster model of the model cluster.

[0102] Step S303: Determine the initial cluster model as the current processing model, determine the initial task processing state as the current task processing state, and determine the task request features as the task request input features.

[0103] Step S304: Input the task request input features into the current processing model, output the current task processing result, and determine one or more candidate cluster models to input the current task processing result.

[0104] Step S305: Based on the current task processing status, determine the target candidate cluster model from one or more candidate cluster models.

[0105] Step S306: Determine the risk isolation strategy based on the current task processing status and the current task processing result; the risk isolation strategy is used to determine whether to isolate the current processing model from risk.

[0106] Step S307: If the target candidate cluster model is a terminated cluster model, then determine the target processing result based on the current task processing result, risk isolation strategy and terminated cluster model.

[0107] Step S308: If the target candidate cluster model is an intermediate cluster model, then according to the risk isolation strategy and the model security characteristics of the intermediate cluster model, the current task processing state is updated, and the updated current task processing state is redefined as the current task processing state. The intermediate cluster model is defined as the current processing model, and the current task processing result is defined as the task request input feature, so as to return to step S304.

[0108] Step S309: Collect the call characteristics of the call share of the current processing model.

[0109] For example, call share is used to indicate the percentage of times the current processing model is called within a specific time window, and is used to assess its activity; call characteristics are used to indicate the data characteristics of the call share when the current processing model is called.

[0110] Specifically, for example, in a sliding window The above is the current processing model V Call characteristics of call share As shown in equation (4).

[0111] (4)

[0112] in, For calling features; This represents the actual share of data used. This represents the actual percentage change in usage. To predict the share of calls; For the deviation of the call share; This represents the change in the quality of the current task processing result; The cost change for generating the current task processing result; The amount of delay required to generate the result of the current task processing; For the current processing model V The probability of induction; For the current processing model V The deviation drift rate.

[0113] Actual call share The calculation formula is shown in equation (5).

[0114] (5)

[0115] in, In the sliding window The current processing model V The number of calls; In the sliding window The number of cluster modules in the model cluster; In the sliding window superior The sum of the number of calls to each cluster model.

[0116] Actual call share change rate The calculation formula is shown in equation (6).

[0117] (6)

[0118] in, To the previous sliding window The current processing model V The share of calls.

[0119] Predicted call share The calculation formula is shown in equation (7).

[0120] (7)

[0121] in, Used to indicate a sliding window; The length of the sliding window; In the sliding window One or more user task requests; For each user task request The current processing model V The probability of processing.

[0122] Call share deviation The calculation formula is shown in equation (8).

[0123] (8)

[0124] Perform counterfactual marginal contribution (shadow comparison / replay) based on a sampling sliding window. Compare the actual path with the bypass / alternative to the current processing model V. The counterfactual path yields the change in mass. Cost changes and delay change As shown in equation (9); where, the sampling sliding window .

[0125] (9)

[0126] in, Used to indicate the sampling sliding window All user task requests below The mathematical expectation; Used to indicate bypassing / replacing the current processing model V The counterfactual path; For including the current processing model V The quality score (user evaluation) of the generated target processing results; The quality score (user evaluation) of the target processing results generated under the counterfactual path; For including the current processing model V User task requests Data processing costs; User task requests under the counterfactual path Data processing costs; For including the current processing model V Time delay; This refers to the time delay under the counterfactual path.

[0127] Current processing model V Induced probability As shown in equation (10).

[0128] (10)

[0129] in, Used to indicate the current processing model V Risk feature labels in the generated current task processing results The text contains several seemingly unrelated phrases and sentences, making it difficult to translate coherently. A literal translation would be nonsensical. Therefore, a meaningful translation is not possible without further context or clarification. refer to Figure 2 Step S206 in the illustrated embodiment; Used to indicate in the sliding window The current processing model V User task requests processed ; Used to indicate in the sliding window The current processing model V In processing user task requests At that time, the probability of inducing a computer device to continue calling it through inducement tags is calculated. For example, if in 1000 calls, 300 times the computer device is induced to continue calling it, then... =30%.

[0130] Current processing model V Deviation drift rate As shown in equation (11).

[0131] (11)

[0132] in, It is a function used to calculate the "drift rate"; Used to indicate the current processing model V Risk rate Used to indicate the current processing model V Task failure rate Used to indicate the current processing model V The frequency of policy violations (violations). Specifically, for example, the deviation rate. Not used to determine the current processing model V Instead of determining how bad the performance is now (the degree of deviation from drift), the current processing model V is determined. "How fast has the variation (the degree of deviation) increased compared to the past (or when the initial admission model cluster was established)?" It is a slope or difference, that is, if a cluster model previously failed only once out of 100 user task requests without violating the policy (violation), and now fails 15 out of 100 user task requests and / or violates the policy (violation) 10 times, then the deviation is the drift rate. =(15-1)+10=24.

[0133] Step S310: Based on the call characteristics of the current processing model's call share, determine whether to conduct high-frequency call review on the current processing model.

[0134] For example, based on the calling characteristics shown in equation (4), if ;or And continuously preset T sliding windows ;or , , ;or , , ;or , , , ;or ;or Then, a high-frequency call review will be performed on the current processing model. Among them, To preset the threshold for the actual call share change rate; The preset call share deviation threshold; To preset the actual call share threshold; The preset threshold for quality change; Set a threshold for the amount of cost change; The preset delay change threshold; The preset induction probability threshold is used; This is a preset drift rate threshold.

[0135] The high-frequency call review includes: shadow comparison evaluation: sampling multiple user task requests and copying them to alternative safe paths for processing to generate alternative target processing results, which are then compared with the target processing results to form comparative evidence; and / or, counterfactual replay: replaying historical model call paths to evaluate the current processing model V. The true marginal contribution and induced risk; and / or, key output mandatory arbitration: in the current processing model V The output of the current task processing result, when entering the target processing step or terminating the cluster model, undergoes arbitration review, that is, the steps of the embodiments shown in steps S2071 and S2072 are executed; and / or, permission tightening and scenario convergence: tightening under high-frequency call review status. , This means restricting the scope of data access and the permissions to call tools, or limiting the service scenarios (for example, not directly limiting the rate based on "high frequency" (limiting the frequency at which the cluster model can be called), but limiting the rate for the purpose of risk control).

[0136] Furthermore, it also includes: generating a high-frequency call review conclusion based on the high-frequency call review; and storing the high-frequency call review conclusion and the review basis in the evidence chain.

[0137] The high-frequency call review conclusions include: pass, pending observation, and fail. Pass indicates exiting the high-frequency call review status and resuming the regular call strategy; pending observation indicates extending the duration of the high-frequency call review status and expanding the high-frequency call review sample; fail indicates triggering a reduction in the call weight of the current processing model, isolating the current processing model, re-evaluating the current processing model, and setting a corresponding rollback point.

[0138] Furthermore, it also includes: when arbitrating execution results, and / or rolling back tasks, and / or restricting the processing boundaries of task processing strategies, and / or reducing the number of permitted security policy models in the set of permitted security policy models, and / or adding the number of prohibited security policy models in the set of prohibited security policy models, determining the timestamp, processing session identifier, request identifier corresponding to the user task request, step identifier or processing round when processing the user task request, cluster model identifier, policy version identifier, security feature version identifier, risk feature label and risk feature score (and / or risk feature hit basis and risk feature hit record), triggering action, reason for triggering action, and processing result based on triggering action, and storing the above data in the evidence chain.

[0139] For example, the chain of evidence As shown in equation (12).

[0140] (12)

[0141] in, Used to indicate the One chain of evidence; For the chain of evidence The timestamp when the data was stored; For the model cluster to process user task requests The session identifier is processed at that time; For user task requests The corresponding request identifier; For timestamp Next, process user task requests. The step count or processing round at any given time, for example, when the initial cluster model is invoked to process a user task request. Step count indicator =1; For timestamp Next, process user task requests. The model identifier of the cluster model; For timestamp Next, process user task requests. Time-based task processing strategy The strategy version identifier, where the reason for recording the strategy version identifier is the task processing strategy. It is dynamically updated; For timestamp Next, process user task requests. The security feature version identifier of the cluster model's security features at that time, where the reason for recording the security feature version identifier is that the model security features are dynamically updated; Included in timestamps Risk feature labels and risk feature scores, and / or risk feature hit criteria and risk feature hit records; For timestamp Triggering actions include result arbitration, and / or task rollback, and / or limiting the processing boundaries of the task processing strategy, and / or reducing the number of security policy allowed models in the set of security policy allowed models, and / or increasing the number of security policy prohibited models in the set of security policy prohibited models, and / or high-frequency call review; To trigger the action The reasons, for example, For "high-frequency call review", for" ”; For based on The processing results, for example, For "task rollback", "Based on task rollback, the target cluster model is redefined as the current processing model to return to the execution of the corresponding steps (e.g., step S204), and warning information is output for risk feature data that cannot be eliminated from the current task processing result."

[0142] In this embodiment, the implementation of steps S301-S308 is the same as that in this application. Figure 2 The implementation methods of steps S201-S208 in the illustrated embodiment are the same, and will not be described in detail here.

[0143] Figure 4 This is a schematic diagram of the risk isolation device for a model cluster of a network-based intelligent architecture provided in one embodiment of this application, as shown below. Figure 4 As shown, the risk isolation device 40 for the model cluster of the intelligent network architecture provided in this embodiment includes: a first processing module 401, an output module 402, and a second processing module 403.

[0144] The first processing module 401 is used to determine the task processing strategy based on the task request characteristics corresponding to the user task request; determine the initial task processing state based on the task processing strategy and the model security characteristics of the initial cluster model of the model cluster; determine the initial cluster model as the current processing model, determine the initial task processing state as the current task processing state, and determine the task request characteristics as the task request input characteristics.

[0145] The output module 402 is used to input the task request input features into the current processing model, output the current task processing result, and determine one or more candidate cluster models to input the current task processing result.

[0146] The second processing module 403 is used to determine a target candidate cluster model from one or more candidate cluster models based on the current task processing status; determine a risk isolation strategy based on the current task processing status and the current task processing result; the risk isolation strategy is used to determine whether to perform risk isolation on the current processing model; if the target candidate cluster model is a terminated cluster model, then the target processing result is determined based on the current task processing result, the risk isolation strategy, and the terminated cluster model; if the target candidate cluster model is an intermediate cluster model, then the current task processing status is updated based on the risk isolation strategy and the model security characteristics of the intermediate cluster model, and the updated current task processing status is redefined as the current task processing status, and the intermediate cluster model is defined as the current processing model, and the current task processing result is defined as the task request input feature, so as to return to the steps of inputting the task request input feature into the current processing model, outputting the current task processing result, and determining one or more candidate cluster models into which the current task processing result is input.

[0147] In one possible implementation, when the second processing module 403 determines the target candidate cluster model from one or more candidate cluster models based on the current task processing status, it specifically performs the following steps: determining the set of models allowed by the security policy and the set of models prohibited by the security policy based on the current task processing status; and filtering one or more candidate cluster models based on the set of models allowed by the security policy and the set of models prohibited by the security policy to obtain the target candidate cluster model.

[0148] In one possible implementation, when determining a risk isolation strategy based on the current task processing status and the current task processing result, the second processing module 403 specifically performs the following steps: extracts multi-dimensional features from the current task processing result based on the current task processing status to generate risk feature data; wherein the risk feature data includes target risk content, target logical conflict content, and target unauthorized tool content corresponding to the current task processing result; performs risk analysis on the risk feature data to generate risk feature labels and risk feature scores; and determines a risk isolation strategy based on the risk feature labels and risk feature scores.

[0149] In one possible implementation, when the second processing module 403 updates the current task processing state based on the risk isolation strategy and the model security characteristics of the intermediate cluster model, and redefines the updated current task processing state as the current task processing state, it specifically performs the following steps: updating the model security characteristics of the intermediate cluster model according to the risk isolation strategy to obtain updated model security characteristics; updating the task processing strategy, the set of models allowed by the security strategy, and the set of models prohibited by the security strategy in the current task processing state according to the risk isolation strategy to obtain a preliminary updated current task processing state; replacing the model security characteristics in the preliminary updated current task processing state with the updated model security characteristics to obtain an updated current task processing state; and redefining the updated current task processing state as the current task processing state.

[0150] In one possible implementation, when the second processing module 403 determines the target processing result based on the current task processing result, the risk isolation strategy, and the termination cluster model, it is specifically used to: arbitrate the current task processing result according to the risk isolation strategy to generate a current task arbitration result; input the current task processing result into the termination cluster model according to the current task arbitration result to output the target processing result; or, determine the target cluster model from the model cluster according to the current task arbitration result; determine the target cluster model as the current processing model to return to the steps of inputting the task request input features into the current processing model, outputting the current task processing result, and determining one or more candidate cluster models into which the current task processing result is input.

[0151] In one possible implementation, the risk isolation device 40 of the model cluster of the network intelligent architecture is also used to: collect the call characteristics of the call share of the current processing model; and determine whether to conduct high-frequency call review on the current processing model based on the call characteristics of the call share of the current processing model.

[0152] The risk isolation device 40 for the model cluster of the network body intelligent architecture provided in this embodiment can perform the following: Figures 2-3 The technical solutions of any of the method embodiments shown are similar in implementation principle and technical effect, and will not be described again here.

[0153] Figure 5 A schematic diagram of the structure of the electronic device provided in this application. Figure 5 As shown, the electronic device 50 provided in this embodiment includes at least one processor 501 and a memory 502. Optionally, the device 50 further includes a communication component 503. The processor 501, memory 502, and communication component 503 are connected via a bus.

[0154] In a specific implementation, at least one processor 501 executes computer execution instructions stored in memory 502, causing at least one processor 501 to perform the above-described method.

[0155] The specific implementation process of processor 501 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.

[0156] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0157] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.

[0158] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0159] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.

[0160] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.

[0161] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.

[0162] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.

[0163] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.

[0164] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0165] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0166] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0167] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0168] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.

Claims

1. A risk isolation method for model clusters based on a network-based intelligent architecture, characterized in that, include: Determine the task processing strategy based on the characteristics of the user's task request; The initial task processing state is determined based on the task processing strategy and the model security characteristics of the initial cluster model of the model cluster. The initial cluster model is determined as the current processing model, the initial task processing state is determined as the current task processing state, and the task request features are determined as task request input features. The task request input features are input into the current processing model, the current task processing result is output, and one or more candidate cluster models are determined to input the current task processing result. Based on the current task processing status, determine the target candidate cluster model from the one or more candidate cluster models; Based on the current task processing status and the current task processing result, a risk isolation strategy is determined; The risk isolation strategy is used to determine whether to isolate the current processing model from risks. If the target candidate cluster model is a terminated cluster model, then the target processing result is determined based on the current task processing result, the risk isolation strategy, and the terminated cluster model. If the target candidate cluster model is an intermediate cluster model, then according to the risk isolation strategy and the model security features of the intermediate cluster model, the current task processing state is updated, and the updated current task processing state is redefined as the current task processing state. The intermediate cluster model is defined as the current processing model, and the current task processing result is defined as the task request input feature. Then, the process returns to the steps of inputting the task request input feature into the current processing model, outputting the current task processing result, and determining one or more candidate cluster models into which the current task processing result is input.

2. The method according to claim 1, characterized in that, The step of determining the target candidate cluster model from the one or more candidate cluster models based on the current task processing status includes: Based on the current task processing status, determine the set of models allowed by the security policy and the set of models prohibited by the security policy; Based on the set of models allowed by the security policy and the set of models prohibited by the security policy, the one or more candidate cluster models are screened to obtain the target candidate cluster model.

3. The method according to claim 1, characterized in that, The step of determining a risk isolation strategy based on the current task processing status and the current task processing result includes: Based on the current task processing status, multidimensional features are extracted from the current task processing result to generate risk feature data; wherein, the risk feature data includes target risk content, target logical conflict content, and target unauthorized tool content corresponding to the current task processing result; The risk feature data is analyzed to generate risk feature labels and risk feature scores; The risk isolation strategy is determined based on the risk feature labels and the risk feature scores.

4. The method according to claim 1, characterized in that, The step of updating the current task processing state based on the risk isolation strategy and the model security features of the intermediate cluster model, and then re-determining the updated current task processing state as the current task processing state, includes: The model security features of the intermediate cluster model are updated according to the risk isolation strategy to obtain the updated model security features; The task processing strategy, the set of allowed security policy models, and the set of prohibited security policy models in the current task processing state are updated according to the risk isolation strategy to obtain the preliminary updated current task processing state. The updated model security features are used to replace the model security features in the initially updated current task processing state to obtain the updated current task processing state. The updated current task processing status is redefined as the current task processing status.

5. The method according to claim 1, characterized in that, The step of determining the target processing result based on the current task processing result, the risk isolation strategy, and the termination cluster model includes: Based on the risk isolation strategy, the current task processing result is arbitrated to generate the current task arbitration result; Based on the arbitration result of the current task, the processing result of the current task is input into the termination cluster model to output the target processing result; Alternatively, based on the arbitration result of the current task, the target cluster model can be determined from the model cluster; The target cluster model is determined as the current processing model, and the process returns to the steps of inputting the task request input features into the current processing model, outputting the current task processing result, and determining one or more candidate cluster models into which the current task processing result is input.

6. The method according to any one of claims 1-5, characterized in that, The method further includes: Collect the call characteristics of the call share of the current processing model; Based on the call characteristics of the current processing model's call share, determine whether to conduct high-frequency call review on the current processing model.

7. A risk isolation device for a model cluster of a network-based intelligent architecture, characterized in that, include: The first processing module is used to determine the task processing strategy based on the task request characteristics corresponding to the user's task request. Based on the task processing strategy and the model security characteristics of the initial cluster model of the model cluster, the initial task processing state is determined; the initial cluster model is determined as the current processing model, the initial task processing state is determined as the current task processing state, and the task request characteristics are determined as task request input characteristics. The output module is used to input the task request input features into the current processing model, output the current task processing result, and determine one or more candidate cluster models to input the current task processing result. The second processing module is used to determine the target candidate cluster model from the one or more candidate cluster models based on the current task processing status. Based on the current task processing status and the current task processing result, a risk isolation strategy is determined; The risk isolation strategy is used to determine whether to isolate the current processing model from risks. If the target candidate cluster model is a terminated cluster model, then the target processing result is determined based on the current task processing result, the risk isolation strategy, and the terminated cluster model. If the target candidate cluster model is an intermediate cluster model, then according to the risk isolation strategy and the model security features of the intermediate cluster model, the current task processing state is updated, and the updated current task processing state is redefined as the current task processing state. The intermediate cluster model is defined as the current processing model, and the current task processing result is defined as the task request input feature. Then, the process returns to the steps of inputting the task request input feature into the current processing model, outputting the current task processing result, and determining one or more candidate cluster models into which the current task processing result is input.

8. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1 to 6.

10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1 to 6.