A system booting method, device, storage medium and electronic equipment
By monitoring large-scale events in AI systems and generating text in natural language, and using large language models for threat analysis, the problem of traditional security protection being unable to identify attacks on AI systems is solved, enabling AI systems to protect themselves and respond quickly.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING HONGTENG INTELLIGENT TECH CO LTD
- Filing Date
- 2026-02-28
- Publication Date
- 2026-05-29
AI Technical Summary
Existing technologies cannot effectively identify and protect against attacks targeting large language models, such as prompt word injection, model theft, and data poisoning. Traditional security protection methods cannot understand the semantics of AI systems.
By monitoring large-scale events in AI systems, security analysis task text in natural language is generated, and threat analysis is performed using large language models to achieve self-protection.
It improves the security incident response speed and defense capabilities of AI systems, and utilizes its own computing power for security protection.
Smart Images

Figure CN122113095A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and more specifically, to a system bootstrapping method, apparatus, storage medium, and electronic device in the field of computer technology. Background Technology
[0002] With the rapid development of large language model technology, artificial intelligence (AI) systems are evolving from single models to complex systems where multiple models and toolchains work together. However, existing security measures, such as firewalls, intrusion detection systems (IDS), or antivirus software, are designed to protect traditional information technology (IT) systems. Because they cannot understand the semantics carried by AI systems during operation, they cannot identify attacks targeting the models themselves, making it difficult to achieve security protection for the system. Therefore, a security protection method for models in AI systems is needed. Summary of the Invention
[0003] This application provides a system bootstrapping method, apparatus, storage medium, and electronic device. The method can monitor large model events of the AI system itself and generate text in natural language form, enabling the large language model to perform security analysis. This allows the AI system to utilize its own computing power for security protection, improving the AI system's response speed to security events and its self-defense capabilities.
[0004] In a first aspect, embodiments of this application provide a system bootstrapping method, the method comprising: When a large model discovery event is detected, the large model discovery event is reported to the management and control intelligent agent center; The control and management intelligent agent center generates security analysis task text in natural language form in response to events discovered by the large model; The security analysis task text is sent to a large language model to obtain threat analysis results for the events discovered by the large model; Defense actions are performed based on the threat analysis results.
[0005] Secondly, embodiments of this application provide a system bootstrapping device, the device comprising: The event monitoring unit is used to report the event detected by the large model to the management and control intelligent agent center when it detects the event. The task text generation unit is used to control the management and control intelligent agent center to generate security analysis task text in natural language form in response to the events discovered by the large model. The analysis result acquisition unit uses a metaphor to send the security analysis task text to the large language model to obtain the threat analysis results for the events discovered by the large model; A defense processing unit is used to perform defense processing based on the threat analysis results.
[0006] Thirdly, embodiments of this application provide a computer storage medium storing a plurality of instructions adapted for loading by a processor and executing the above-described method steps.
[0007] Fourthly, embodiments of this application provide an electronic device that may include: a processor and a memory; wherein the memory stores a computer program adapted to be loaded by the processor and to execute the above-described method steps.
[0008] In one or more embodiments of this application, when a large model discovery event is detected, the event is reported to the management and control intelligent agent center. The management and control intelligent agent center then generates a security analysis task text in natural language for the event and sends it to the large language model to obtain a threat analysis result for the event. Based on the threat analysis result, defensive processing is performed. By monitoring the large model events of the AI system itself and generating natural language text to enable the large language model to perform security analysis, the AI system can utilize its own computing power for security protection, improving the AI system's response speed to security events and its self-defense capabilities. Attached Figure Description
[0009] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0010] Figure 1 This is a system architecture diagram of a system bootstrapping device provided in an embodiment of this application; Figure 2 This is a flowchart illustrating a system bootstrapping method provided in an embodiment of this application; Figure 3 This is a flowchart illustrating a method for reporting events discovered by a large model, as provided in an embodiment of this application. Figure 4 This is a flowchart illustrating a task text generation method provided in an embodiment of this application; Figure 5 This is a flowchart illustrating an analysis result verification method provided in an embodiment of this application; Figure 6 This is a schematic flowchart of a defense processing method provided in an embodiment of this application; Figure 7 This is a schematic flowchart of a system topology graph updating method provided in an embodiment of this application; Figure 8 This is a schematic diagram of the structure of a system bootstrapping device provided in an embodiment of this application; Figure 9 This is a schematic diagram of the structure of a system bootstrapping device provided in an embodiment of this application; Figure 10 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0011] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0012] Modern AI systems no longer use independent models, but rather complex topologies comprised of model inference services, intelligent agent application frameworks, vector databases, traditional databases, web services, front-end interfaces, and underlying container orchestration. This makes AI systems more functional and capable of handling more complex tasks. However, due to the numerous nodes and complex dependencies involved in the overall AI system, any node—whether a container image or an application programming interface (API)—can become an entry point for attackers. Existing security protection methods for IT systems are inadequate for protecting AI systems. For example, existing firewalls or antivirus software cannot protect against attacks targeting the model itself, such as prompt injection, model theft, and data poisoning. This application provides a system bootstrapping device that can utilize the computing power of the AI system itself to monitor and analyze the Large Language Model (LLM) within the AI system for security issues. The system bootstrapping method provided in this application can be implemented using a computer program and can run on a system bootstrapping device based on the von Neumann architecture. The computer program can be integrated into an application or run as a standalone tool application. The system bootstrapping device provided in this application embodiment can be an artificial intelligence system or a module in an artificial intelligence system used to implement the system bootstrapping method.
[0013] Please see also Figure 1 This application provides a system architecture diagram for a system bootstrapping device. The system bootstrapping device may include probes, edge agents, and a control agent center. The probes can be lightweight, modular agent probes deployed on various nodes of an artificial intelligence system. The artificial intelligence system can be an AI system comprising multiple large language models, and each node can be a physical machine, virtual machine, or container running the models, thereby enabling data monitoring of the artificial intelligence system and detecting large model discovery events within the system. The edge agent can be a multi-agent aggregation engine deployed at the network edge of the artificial intelligence system, responsible for receiving, aggregating, and initially processing data from all probes.
[0014] The control agent center can be a multi-agent application composed of multiple agents from various vertical domains, or a Model Context Protocol (MCP) server. It can include a task planning agent, at least one functional agent, and a referee agent. Task scheduling can be performed through the task planning and referee agents, selecting appropriate functional agents to complete the tasks. Each functional agent within the control agent center can be exposed as an MCP tool or invoked as an intelligent MCP tool by other AI systems or MCP hosts. During system operation, when a probe detects a large language model service running, it can automatically identify large model discovery events and automatically schedule the corresponding security tasks to these large models for execution. This leverages the AI system's own computing power to ensure and enhance the system's security, implementing a self-protection mechanism.
[0015] The system bootstrapping method provided in this application will be described in detail below with reference to specific embodiments.
[0016] Please see Figure 2 This is a flowchart illustrating a system bootstrapping method provided in an embodiment of this application. Figure 2 As shown, the method described in this application embodiment may include the following steps S101-S104.
[0017] S101, when a large model discovery event is detected, reports the large model discovery event to the management and control intelligent agent center.
[0018] Specifically, the system bootstrap device can monitor the artificial intelligence system and detect large model discovery events. These events can be the first or subsequent records of a large language model being run in the artificial intelligence system. The system will then report these large model discovery events to the control and management intelligent agent center for unified scheduling and processing.
[0019] S102, the control and management intelligent agent center generates security analysis task text in natural language form based on events discovered by the large model.
[0020] Specifically, the control and management intelligent agent center can generate security analysis task text for events discovered by the large model. The security analysis task text is in natural language form that can be understood by the large language model and is used to instruct the large language model to analyze whether there are security risks in the events discovered by the large model.
[0021] Optionally, after receiving a large model discovery event, the control and management intelligent agent center can further obtain relevant information about the large model discovery event, such as the target large language model corresponding to the large model discovery event and the text content of the input target large language model. The control and management intelligent agent center can generate security analysis task text based on the relevant information.
[0022] S103, send the security analysis task text to the large language model to obtain threat analysis results for the events discovered by the large model.
[0023] Specifically, the control and management intelligent agent center can send security analysis task text to the large language model, so that the large language model can analyze whether there are security problems based on the security analysis task text and generate threat analysis results. The threat analysis results are used to indicate whether there are security problems in the events discovered by the large model. Security problems can include abnormal exposure surfaces, model file tampering, prompt word injection, model theft, or data poisoning, etc.
[0024] S104, Perform defensive actions based on threat analysis results.
[0025] Specifically, if the threat analysis results indicate that the large model detected a security issue, defensive measures can be taken against it, such as stopping the large model's detection process. Conversely, if the threat analysis results indicate that the large model detected no security issue, no defensive measures should be taken against it, and the large model can continue to run normally.
[0026] In this embodiment, when a large model discovery event is detected, the event is reported to the management and control intelligent agent center. The management and control intelligent agent center then generates a security analysis task text in natural language format for the event and sends it to the large language model to obtain threat analysis results. Based on the threat analysis results, defensive actions are executed. By monitoring the large model events of the AI system itself and generating natural language text to enable the large language model to perform security analysis, the AI system can utilize its own computing power for security protection, thereby improving the AI system's response speed to security events and its self-defense capabilities.
[0027] See Figure 3 This document provides a flowchart illustrating a method for reporting large-scale model discovery events, as illustrated in an embodiment of this application. Figure 3 As shown, in one or more embodiments of this application, step S101 may include the following steps S201-S203.
[0028] S201 uses probes to monitor the features of large language models in artificial intelligence systems.
[0029] Specifically, probes can be deployed on various nodes of the artificial intelligence system. These nodes can be physical machines, virtual machines, containers, etc., where the model is running. The probes can then be used to monitor the features of the large language model in the artificial intelligence system. Since the data, ports, or files in the artificial intelligence system will change when the large language model is about to perform or is performing inference services, feature detection can be used to discover these changes in the artificial intelligence system, thereby determining whether a large model discovery event has occurred. Deploying probes on nodes close to the source of the large model discovery event improves event monitoring efficiency and reduces the resources consumed.
[0030] Optionally, the probe can have Runtime Application Self-Protection (RASP) capabilities, which can monitor and block security issues in real time, thereby protecting the AI system during runtime. For example, it can monitor the input and output of large language models, analyze the API call context of the model, and prevent automated attacks such as high-frequency attacks and attacks with abnormal parameter combinations.
[0031] Optionally, probes can include file scanning probes, vulnerability scanning probes, container scanning probes, local traffic probes, process scanning probes, MCP scanning probes, and proof-of-concept (POC) verification probes. File scanning probes can be used to monitor file operations within AI systems, such as tampering with model weight files (.bin, .safetensors) and configuration files (.json, .yaml). Vulnerability scanning probes can be used to scan components running within AI systems for known vulnerabilities, such as Dify and Ollam. Container scanning probes can scan container images and running containers to detect malicious images, configuration errors, and other security issues. Local traffic probes can monitor network traffic and analyze its source, destination, protocol type, and data volume to identify abnormal traffic behavior and other security issues. They can also detect open local ports and running services, identify running services and port numbers, and thus discover unauthorized or risky services. Process scanning probes can monitor process behavior and identify abnormal processes, such as those related to cryptocurrency security issues. MCP scanning probes can be used to monitor the MCP Server running within a system, detecting whether its API calls are being abused or whether there is malicious code behavior. POC verification probes can be used to perform harmless POC verification of discovered potential vulnerabilities.
[0032] Optionally, the probe may contain a data reporting module and a policy parsing module. The data reporting module enables all probes to report raw data to the edge agent through an encrypted TCP channel. The policy parsing module can be used to parse the defense instructions issued by the control agent center and convert them into executable rules. The policy parsing module can schedule the corresponding execution components to implement the defense instructions according to the artificial intelligence system architecture and resource conditions.
[0033] Optionally, the edge agent can perform network scanning on the AI system. This scanning is done at the subnet edge, using fingerprint recognition to locate components carrying AI modules. The components can then respond to the edge agent's scan and report their information, including IP address, port, and services. The edge agent can report this information to the control agent center. If the control agent center determines that the component has not deployed probes, it can send a probe deployment task to the edge agent. Upon receiving the probe deployment task, the component can send a probe registration request to the edge agent. If the edge agent accepts the registration request, it sends a registration success message, indicating that probes are deployed on the component. These probes can then report operational data and large model discovery events to the edge agent.
[0034] S202, if a large model discovery event is detected, the control probe will report the large model discovery event to the edge agent.
[0035] Specifically, if the probe detects a large model discovery event, it can be controlled to report the event to the edge agent. The large model discovery event reported by the probe can include fingerprint information, such as the large language model name and container ID.
[0036] S203, the control edge agent sends the large model discovery event to the control agent center.
[0037] Specifically, after receiving a large model discovery event reported by the probe, the edge agent can forward the large model discovery event to the control agent center.
[0038] Optionally, the edge agent can perform preprocessing such as aggregation and preliminary processing on the reported large model discovery events, and then send the preprocessed large model discovery events to the management agent center, thereby reducing noise in the data and improving the working efficiency of the management agent center.
[0039] In this embodiment, a probe is used to monitor the features of a large language model in the artificial intelligence system. If a large model discovery event is detected, the probe is controlled to report the event to the edge agent, which then forwards it to the central control agent. By using probes to capture large model discovery events, event monitoring efficiency is improved and resource consumption is reduced. Reporting to the edge agent first and then forwarding to the central control agent enables unified global computing power scheduling for the artificial intelligence system, improving the efficiency of security issue monitoring and defense.
[0040] In one or more embodiments of this application, step S201 may include the following steps: If the probe detects target features corresponding to a large language model in the artificial intelligence system, it generates events related to the occurrence of the large model based on the target features.
[0041] Specifically, if the probe detects target features of a large language model running or about to run inference services in an artificial intelligence system, it can generate a large model occurrence event based on the detected target features and confirm that a large model occurrence event has been detected.
[0042] The target characteristics include one or more of the following: process characteristics, port characteristics, model file characteristics, and API call characteristics. If the probe detects a running process with a name containing names such as ollama, vllm, transformers-server, or llama.cpp, then the process characteristic has been detected. If the probe detects that the AI system has opened large language model service ports such as 11434 (Ollama's default port), 8000, or 8080, then the port characteristic has been detected. If the probe detects that the AI system has loaded large model weight files, such as .safetensors, .bin, or .gguf, then the model file characteristic has been detected. If the probe detects that the HTTP request path contains API endpoints for large language models, such as / v1 / chat / completions, / generate, or / embeddings, then the API call characteristic has been detected.
[0043] The control and management intelligent agent center includes a task planning intelligent agent and at least one functional intelligent agent. The task planning intelligent agent can be used to plan security analysis tasks and make intelligent decisions during execution. For example, if a user queries the risks of today's artificial intelligence system, multiple functional intelligent agents need to be scheduled to process the query and provide the user with a system analysis report and data. There can be multiple functional intelligent agents, and different functional intelligent agents can be used to perform different security analysis tasks, or multiple functional intelligent agents can be combined to perform different security analysis tasks.
[0044] Please see Figure 4 This is a flowchart illustrating a task text generation method provided in an embodiment of this application. Figure 4 As shown, in one or more embodiments of this application, step S102 may include the following steps S301-S302.
[0045] S301, the control task planning agent determines the security analysis task corresponding to the event discovered by the large model, and determines the target functional agent corresponding to the security analysis task.
[0046] Specifically, after receiving a large model discovery event, the task planning agent can determine the security analysis task corresponding to the event. The security analysis task is used to verify whether there are security issues in the large model discovery event. The task planning agent can determine the target functional agent for the security analysis task based on the content involved and the functions of each functional agent. The target functional agent is one of at least one functional agent used to execute the security analysis task. By selecting the most capable executor based on the functional agent's capabilities, problems such as functional redundancy and capability gaps are avoided, thus improving resource utilization.
[0047] Optionally, functional intelligent agents may include situational intelligence agents, asset management intelligence agents, vulnerability scanning intelligence agents, MCP monitoring intelligence agents, intrusion prevention intelligence agents, alarm operation intelligence agents, and knowledge question answering intelligence agents. Among these, the situational intelligence agent can be used for global situational awareness, visualizing the topology map reported by edge intelligence agents and predicting potential attack paths. The asset management intelligence agent can be used to proactively discover newly added or unauthorized AI assets in the network, such as newly deployed model services. The vulnerability scanning intelligence agent can be used to perform deep vulnerability scans on discovered AI assets and generate detailed remediation suggestions. The MCP monitoring intelligence agent can be used to continuously monitor the health status and API call patterns of all MCP servers within the system. The intrusion prevention intelligence agent can be used to automatically execute defense commands based on the analysis results of the situational intelligence agent, such as isolating infected containers and revoking API keys. The alarm operation intelligence agent can be responsible for cleaning, transforming, and storing all security data and generating datasets for training next-generation security models. The knowledge question answering intelligence agent can be used to provide a natural language question-and-answer interface for operations personnel, for example, it can receive questions such as "Why is this Dify service marked as high risk?" entered by operations personnel. AI assets in an artificial intelligence system can include large language models, file systems, container environments, and running processes.
[0048] S302, the control target functional intelligent agent, generates security analysis task text in natural language form for events discovered by a large model.
[0049] Specifically, the target functional agent can be controlled to generate security analysis task text in natural language form for large model discovery events. The security analysis task text can be generated based on relevant information of the large model discovery event. For example, it can include what the large language model should do, what data it should use, and what it expects to output in the large model discovery event. Using security analysis text in natural language form can clearly describe the relevant information of the security analysis task without additional API modification, and it can continue to reason even if the model is changed.
[0050] In this embodiment, the control task planning agent determines the security analysis task corresponding to the large model discovery event, and determines the target functional agent corresponding to the security analysis task. The target functional agent is then controlled to generate security analysis task text in natural language for the large model discovery event. By selecting the target functional agent to perform the security analysis task based on the functional agent's capabilities, issues such as functional redundancy and capability gaps are avoided, thus improving resource utilization.
[0051] The control agent center also includes a referee agent, which can be used to judge the correctness of each security analysis task and its results.
[0052] Please see Figure 5The diagram below illustrates a method for verifying analysis results, as provided in this application. Figure 5 As shown, in one or more embodiments of this application, step S103 may include the following steps S401-S403.
[0053] S401, the control target functional agent sends the security analysis task text to the large language model to obtain the initial analysis results for the events discovered by the large model.
[0054] Specifically, the target functional agent can be controlled to use the API interface of the large language model to input the security analysis task text into the large language model, so that the large language model can process the corresponding security analysis task and obtain the initial analysis results of the large language model for the events discovered by the large model.
[0055] S402, the target function agent sends the initial analysis results to the referee agent.
[0056] Specifically, the control target function agent sends the initial analysis results output by the large language model to the referee agent.
[0057] S403, control the referee agent to verify the initial analysis results, and generate threat analysis results based on the verification results.
[0058] Specifically, the control referee agent verifies the initial analysis results to determine their accuracy, and then generates a threat analysis result based on the verification result. The verification result includes the accurate value of the initial analysis result. If the accurate value is greater than the accuracy threshold, the initial analysis result can be determined to be accurate and can be directly used as the threat analysis result.
[0059] Optionally, if the accurate value is less than the accurate threshold, it can be determined that the initial analysis result is inaccurate. In this case, the referee agent can report the error information to the task planning agent. The task planning agent can then re-analyze the security of the events discovered by the large model based on the error information until an initial analysis result that has passed the verification process is generated.
[0060] In this embodiment, the target functional agent sends the security analysis task text to the large language model to obtain initial analysis results for events discovered by the large model. The target functional agent then sends the initial analysis results to the referee agent, which verifies the initial analysis results and generates threat analysis results based on the verification results. Verifying the analysis results through the referee agent improves the accuracy of the threat analysis results.
[0061] Please see Figure 6 This is a flowchart illustrating a defense processing method provided in an embodiment of this application. Figure 6 As shown, in one or more embodiments of this application, step S104 may include the following steps S501-S502.
[0062] S501, if the threat analysis results indicate that the large model has discovered a security issue, the control and management intelligent agent center sends a defense command to the probe.
[0063] Specifically, if the threat analysis results indicate that the large model has discovered a security issue, the control and management agent center can send a defense instruction to the probe. The defense instruction can be generated by the control and management agent based on the threat analysis results and defense strategy, and is used to instruct the probe to take defensive measures against the large model's discovered event.
[0064] Optionally, the control agent center can send defense commands to edge agents, which then distribute the defense commands to the corresponding probes.
[0065] S502 controls the probe to block events detected by the large model.
[0066] Specifically, after receiving a defense command, the probe can control the probe to block large model discovery events. For example, it can modify the configuration of the large model discovery event or block the request in the large model discovery event, thereby making the large model discovery event unable to run.
[0067] In this embodiment, if the threat analysis results indicate that the large model detected a security issue, the control and management intelligent agent center sends a defense command to the probe, controlling the probe to block the large model's detection of the event. By using a probe located close to the source to block the event, the response speed to security issues is improved, and the overall security of the artificial intelligence model is enhanced.
[0068] Edge agents can possess capabilities for network scanning, data reception, data distribution, and data aggregation. They can also include rule engines, rule agents, AI system topology agents, and probe monitoring agents. Network scanning can be performed at the subnet edge, using fingerprint recognition to locate devices equipped with AI modules. Data reception can utilize secure TCP long connections and implement bidirectional TLS authentication. Data distribution can distribute security policies, task configuration rules, and other data, implementing ACK confirmation mechanisms and task retry mechanisms to ensure high-availability task deployment, such as asset discovery rules, vulnerability scanning rules, intrusion prevention strategies, and MCP detection strategies. Data aggregation can receive discrete data from different probes and aggregate it based on fingerprints to form a system topology map of the AI system. Fingerprints can include process IDs, container IDs, source IPs, model names, etc.
[0069] A rule engine can be a simplified set of rules capable of various rule processing methods, including streaming computation, time window processing, and batch computation, to complete data processing and storage tasks. Rule intelligence can automatically generate and adjust rule engine rules based on the data context of the AI system to adapt to the current system's data processing and rule formulation. The AI system topology agent can use data aggregation strategies to construct a system topology graph of the AI system from aggregated data, where nodes represent components such as WebUI, Dify, and Ollam, and edges represent the communication relationships between them. The probe monitoring agent can be used to intelligently analyze and make decisions based on probe behavior data, task progress reports, and heartbeat information, enabling automatic recovery and early warning functions for layer-one probes.
[0070] Please see Figure 7 This is a flowchart illustrating a system topology graph update method provided in an embodiment of this application. Figure 7 As shown, the method described in one or more embodiments of this application may include the following steps S601-S602.
[0071] S601 controls the edge agent to determine the large model computing power node corresponding to the large model discovery event.
[0072] Specifically, the edge agent can be controlled to determine the large model computing power node corresponding to the large model discovery event. The large model computing power node can be a schedulable, manageable and unique computing power node in the system topology graph of the artificial intelligence system.
[0073] S602 updates the system topology of the artificial intelligence system based on large model computing power nodes and records the parameter information of the large model computing power nodes.
[0074] Specifically, the edge agent can also obtain parameter information of large model computing power nodes based on the large model discovery events reported by the probe. The parameter information may include the name, version, and resource usage of the large language model. The system topology of the artificial intelligence system can be updated based on the large model computing power nodes, and the parameter information of the large model computing power nodes can be recorded.
[0075] Optionally, if the large model computing power node is acquired for the first time by the edge agent, it can be added to the system topology graph. If the large model computing power node is not acquired for the first time by the edge agent, the computing power node in the system topology graph can be updated using parameter information.
[0076] Optionally, the edge agent can send the system topology map of the artificial intelligence system to the control agent center. The situation agent in the control agent center can visualize the topology map reported by the edge agent and display the system topology map to relevant personnel, thereby realizing the visualization of the topology structure of the artificial intelligence system. This aggregates the discrete application components of the artificial intelligence system into an understandable whole, reducing the complexity of operation and maintenance.
[0077] In this embodiment, the control edge agent identifies the large model computing power node corresponding to the large model discovery event, updates the system topology graph of the artificial intelligence system based on the large model computing power node, and records the parameter information of the large model computing power node. By recording the large model computing power node through the edge agent and generating the system topology graph of the artificial intelligence system, discrete application components are aggregated, realizing the visualization of the overall system architecture and reducing the complexity of operation and maintenance.
[0078] The following will be combined with the appendix Figure 8 - Appendix Figure 9 This application provides a detailed description of the system bootstrapping apparatus provided in its embodiments. It should be noted that the appendix... Figure 8 - Appendix Figure 9 The system bootstrap device in the present application is used to execute the present application. Figures 1-7 The methods shown in the embodiments are for illustrative purposes only, illustrating the parts relevant to the embodiments of this application. For specific technical details not disclosed, please refer to this application. Figures 1-7 The example shown.
[0079] Please see Figure 8 This illustration shows a schematic diagram of a system bootstrapping device provided in an exemplary embodiment of this application. The system bootstrapping device can be implemented as all or part of a device through software, hardware, or a combination of both. The device 1 includes an event monitoring unit 11, a task text generation unit 12, an analysis result acquisition unit 13, and a defense processing unit 14.
[0080] Event monitoring unit 11 is used to report the large model discovery event to the management and control intelligent agent center when the large model discovers the event. The task text generation unit 12 is used to control the management and control intelligent agent center to generate security analysis task text in natural language form in response to the events discovered by the large model. The analysis result acquisition unit 13 uses a metaphor to send the security analysis task text to the large language model to obtain the threat analysis results for the events discovered by the large model; Defense processing unit 14 is used to perform defense processing based on the threat analysis results.
[0081] In this embodiment, when a large model discovery event is detected, the event is reported to the management and control intelligent agent center. The center then generates a security analysis task text in natural language for the event and sends it to the large language model to obtain a threat analysis result. Based on this result, defensive actions are executed. By monitoring the AI system's own large model events and generating natural language text for security analysis, the AI system can utilize its own computing power for security protection, improving its response speed and self-defense capabilities in the face of security events.
[0082] Please see Figure 9 This illustration shows a schematic diagram of a system bootstrapping device provided in an exemplary embodiment of this application. The system bootstrapping device can be implemented as all or part of a device through software, hardware, or a combination of both. The device 1 includes an event monitoring unit 11, a topology map updating unit 15, a task text generation unit 12, an analysis result acquisition unit 13, and a defense processing unit 14.
[0083] Event monitoring unit 11 is used to report the large model discovery event to the management and control intelligent agent center when the large model discovers the event. Optionally, the event monitoring unit 11 is specifically used to perform feature monitoring on the large language model in the artificial intelligence system using probes, and the probes are deployed in each node of the artificial intelligence system; If a large model discovery event is detected, the probe is controlled to report the large model discovery event to the edge agent; The edge agent is controlled to send the large model discovery event to the control agent center.
[0084] Optionally, the event monitoring unit 11 is specifically used to generate a large model occurrence event based on the target feature if the probe detects the target feature corresponding to the large language model in the artificial intelligence system; The target features include one or more of the following: process features, port features, model file features, and interface call features.
[0085] Topology graph update unit 15 is used to control the edge agent to determine the large model computing power node corresponding to the large model discovery event; The system topology of the artificial intelligence system is updated based on the large model computing power node, and the parameter information of the large model computing power node is recorded.
[0086] The task text generation unit 12 is used to control the management and control intelligent agent center to generate security analysis task text in natural language form in response to the events discovered by the large model. Optionally, the control and management intelligent agent center includes a task planning intelligent agent and at least one functional intelligent agent; The task text generation unit is specifically used to control the task planning agent to determine the security analysis task corresponding to the large model discovery event, and to determine the target functional agent corresponding to the security analysis task; Control the target functional agent to generate security analysis task text in natural language form for the events discovered by the large model.
[0087] The analysis result acquisition unit 13 uses a metaphor to send the security analysis task text to the large language model to obtain the threat analysis results for the events discovered by the large model; Optionally, the control and management intelligent agent center may also include a referee intelligent agent; The analysis result acquisition unit 13 is specifically used to control the target functional agent to send the security analysis task text to the large language model to obtain the initial analysis results for the event discovered by the large model; The target functional agent is controlled to send the initial analysis results to the referee agent; The referee agent is controlled to verify the initial analysis results and generate threat analysis results based on the verification results.
[0088] Defense processing unit 14 is used to perform defense processing based on the threat analysis results.
[0089] If the threat analysis result indicates that the large model has detected a security problem, the specific user of the defense processing unit 14 controls the management and control intelligent agent center to send a defense command to the probe. The probe is controlled to block the discovery event of the large model.
[0090] In this embodiment, a probe is used to monitor the features of the large language model in the artificial intelligence system. If a large model discovery event is detected, the probe is controlled to report the event to the edge agent, which then forwards it to the control agent center. By using probes to capture large model discovery events, event monitoring efficiency is improved and resource consumption is reduced. Reporting to the edge agent first and then forwarding to the control agent center enables unified global computing power scheduling for the artificial intelligence system, improving the efficiency of security issue monitoring and defense. The edge agent determines the large model computing power node corresponding to the large model discovery event, updates the system topology map of the artificial intelligence system based on the large model computing power node, and records the parameter information of the large model computing power node. By recording the large model computing power node by the edge agent and generating the system topology map of the artificial intelligence system, discrete application components are aggregated, the overall system architecture is visualized, and the complexity of operation and maintenance is reduced.
[0091] The control and management intelligent agent center includes a task planning intelligent agent and at least one functional intelligent agent. The task planning intelligent agent determines the security analysis task corresponding to the large model discovery event and identifies the target functional intelligent agent for that task. The target functional intelligent agent is then controlled to generate a security analysis task text in natural language for the large model discovery event. Selecting the target functional intelligent agent to perform the security analysis task through the capabilities of the functional intelligent agents avoids functional redundancy and capability gaps, improving resource utilization. The control and management intelligent agent center also includes a referee intelligent agent, which is used to judge the correctness of each security analysis task and its results. The target functional intelligent agent sends the security analysis task text to the large language model to obtain initial analysis results for the large model discovery event. The target functional intelligent agent then sends these initial analysis results to the referee intelligent agent, which verifies the initial analysis results and generates threat analysis results based on the verification results. Verification of the analysis results by the referee intelligent agent improves the accuracy of the threat analysis results. If the threat analysis result indicates a security problem with the large model discovery event, the control and management intelligent agent center sends a defense command to the probe, controlling the probe to block the large model discovery event. By using probes located close to the source for blocking, the response speed to security issues is improved, and the overall security of the AI model is enhanced. By monitoring large-scale events within the AI system itself and generating natural language text, the large language model can perform security analysis, enabling the AI system to utilize its own computing power for security protection. This improves the AI system's response speed to security incidents and its self-defense capabilities.
[0092] It should be noted that the system bootstrap device provided in the above embodiments is only illustrated by the division of the above functional modules when executing the system bootstrap method. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the system bootstrap device and the system bootstrap method embodiments provided in the above embodiments belong to the same concept, and the implementation process is detailed in the method embodiments, which will not be repeated here.
[0093] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0094] This application also provides a computer storage medium that can store multiple instructions, which are adapted to be loaded and executed by a processor as described above. Figures 1-7 The system bootstrapping method described in the illustrated embodiment can be found in the following documentation for its specific execution process. Figures 1-7 The specific details of the illustrated embodiments will not be elaborated here.
[0095] This application also provides a computer program product storing at least one instruction, which is loaded and executed by the processor as described above. Figures 1-7 The system bootstrapping method described in the illustrated embodiment can be found in the following documentation for its specific execution process. Figures 1-7 The specific details of the illustrated embodiments will not be elaborated here.
[0096] Please refer to Figure 10 This diagram illustrates a structural block diagram of an electronic device provided in an exemplary embodiment of this application. The electronic device in this application may include one or more components such as a processor 110, a memory 120, an input device 130, an output device 140, and a bus 150. The processor 110, memory 120, input device 130, and output device 140 may be connected via the bus 150.
[0097] Processor 110 may include one or more processing cores. Processor 110 connects to various parts of the electronic device using various interfaces and lines, and executes various functions of terminal 100 and processes data by running or executing instructions, programs, code sets, or instruction sets stored in memory 120, and by calling data stored in memory 120. Optionally, processor 110 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). Processor 110 may integrate one or more of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem. The CPU primarily handles the operating system, user page, and applications; the GPU is responsible for rendering and drawing the displayed content; and the modem handles wireless communication. It is understood that the modem may also not be integrated into processor 110 and may be implemented separately using a communication chip.
[0098] The memory 120 may include random access memory (RAM) or read-only memory (ROM). Optionally, the memory 120 may include non-transitory computer-readable storage medium. The memory 120 may be used to store instructions, programs, code, code sets, or instruction sets. The memory 120 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for implementing at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the various method embodiments described above, etc. The operating system may be the Android system, including systems deeply developed based on the Android system, the iOS system developed by Apple Inc., including systems deeply developed based on the iOS system, or other systems.
[0099] The memory 120 can be divided into operating system space and user space. The operating system runs in the operating system space, while native and third-party applications run in user space. To ensure that different third-party applications can achieve good running performance, the operating system allocates corresponding system resources for each application. However, different application scenarios within the same third-party application have different requirements for system resources. For example, in local resource loading scenarios, third-party applications have high requirements for disk read speed; in animation rendering scenarios, third-party applications have high requirements for GPU performance. Since the operating system and third-party applications are independent of each other, the operating system often cannot promptly perceive the current application scenario of a third-party application, resulting in the operating system's inability to adapt system resources accordingly.
[0100] In order for the operating system to distinguish the specific application scenarios of third-party applications, it is necessary to establish data communication between the third-party applications and the operating system. This would allow the operating system to obtain the current scenario information of the third-party applications at any time, and then perform targeted system resource adaptation based on the current scenario.
[0101] The input device 130 is used to receive input instructions or data, and includes, but is not limited to, a keyboard, mouse, camera, microphone, or touch device. The output device 140 is used to output instructions or data, and includes, but is not limited to, a display device and a speaker. In one example, the input device 130 and the output device 140 can be combined, and the input device 130 and the output device 140 can be a touch display screen.
[0102] The touch display screen can be designed as a full-screen, curved screen, or irregularly shaped screen. It can also be designed as a combination of a full-screen and a curved screen, or a combination of an irregularly shaped screen and a curved screen; however, this application does not limit the specific design in this regard.
[0103] In addition, those skilled in the art will understand that the structure of the electronic device shown in the above figures does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown, or combine certain components, or have different component arrangements. For example, the electronic device may also include radio frequency circuits, input units, sensors, audio circuits, Wireless Fidelity (WiFi) modules, power supplies, Bluetooth modules, etc., which will not be described in detail here.
[0104] exist Figure 10 In the illustrated electronic device, the processor 110 can be used to call the system bootstrap application stored in the memory 120 and specifically perform the following operations: When a large model discovery event is detected, the large model discovery event is reported to the management and control intelligent agent center; The control and management intelligent agent center generates security analysis task text in natural language form in response to events discovered by the large model; The security analysis task text is sent to a large language model to obtain threat analysis results for the events discovered by the large model; Defense actions are performed based on the threat analysis results.
[0105] In one embodiment, when the processor 110 detects a large model discovery event and reports the large model discovery event to the management and control intelligent agent center, it specifically performs the following operations: A probe is used to perform feature monitoring on a large language model in an artificial intelligence system, and the probe is deployed in each node of the artificial intelligence system. If a large model discovery event is detected, the probe is controlled to report the large model discovery event to the edge agent; The edge agent is controlled to send the large model discovery event to the control agent center.
[0106] In one embodiment, when the processor 110 performs feature monitoring on a large language model in an artificial intelligence system using probes, it specifically performs the following operations: If the probe detects target features corresponding to the large language model in the artificial intelligence system, then a large model occurrence event is generated based on the target features; The target features include one or more of the following: process features, port features, model file features, and interface call features.
[0107] In one embodiment, the control agent center includes a task planning agent and at least one functional agent; When the processor 110 executes the command and control intelligent agent center to generate a security analysis task text in natural language form in response to the event discovered by the large model, it specifically performs the following operations: The control task planning agent determines the security analysis task corresponding to the event discovered by the large model, and determines the target functional agent corresponding to the security analysis task; Control the target functional agent to generate security analysis task text in natural language form for the events discovered by the large model.
[0108] In one embodiment, the control and management intelligent agent center further includes a referee intelligent agent; When the processor 110 sends the security analysis task text to the large language model to obtain the threat analysis results for the events discovered by the large model, it specifically performs the following operations: The target functional agent is controlled to send the security analysis task text to the large language model to obtain the initial analysis results for the events discovered by the large model; The target functional agent is controlled to send the initial analysis results to the referee agent; The referee agent is controlled to verify the initial analysis results and generate threat analysis results based on the verification results.
[0109] In one embodiment, when the processor 110 performs defense processing based on the threat analysis results, it specifically performs the following operations: If the threat analysis result indicates that the large model has detected a security issue in the event, then the control and management intelligent agent center is instructed to send a defense command to the probe. The probe is controlled to block the discovery event of the large model.
[0110] In one embodiment, when executing the system bootstrapping method, the processor 110 also performs the following operations: The edge agent is controlled to determine the large model computing power node corresponding to the large model discovery event. The system topology of the artificial intelligence system is updated based on the large model computing power node, and the parameter information of the large model computing power node is recorded.
[0111] In this embodiment, a probe is used to monitor the features of the large language model in the artificial intelligence system. If a large model discovery event is detected, the probe is controlled to report the event to the edge agent, which then forwards it to the control agent center. By using probes to capture large model discovery events, event monitoring efficiency is improved and resource consumption is reduced. Reporting to the edge agent first and then forwarding to the control agent center enables unified global computing power scheduling for the artificial intelligence system, improving the efficiency of security issue monitoring and defense. The edge agent determines the large model computing power node corresponding to the large model discovery event, updates the system topology map of the artificial intelligence system based on the large model computing power node, and records the parameter information of the large model computing power node. By recording the large model computing power node by the edge agent and generating the system topology map of the artificial intelligence system, discrete application components are aggregated, the overall system architecture is visualized, and the complexity of operation and maintenance is reduced.
[0112] The control and management intelligent agent center includes a task planning intelligent agent and at least one functional intelligent agent. The task planning intelligent agent determines the security analysis task corresponding to the large model discovery event and identifies the target functional intelligent agent for that task. The target functional intelligent agent is then controlled to generate a security analysis task text in natural language for the large model discovery event. Selecting the target functional intelligent agent to perform the security analysis task through the capabilities of the functional intelligent agents avoids functional redundancy and capability gaps, improving resource utilization. The control and management intelligent agent center also includes a referee intelligent agent, which is used to judge the correctness of each security analysis task and its results. The target functional intelligent agent sends the security analysis task text to the large language model to obtain initial analysis results for the large model discovery event. The target functional intelligent agent then sends these initial analysis results to the referee intelligent agent, which verifies the initial analysis results and generates threat analysis results based on the verification results. Verification of the analysis results by the referee intelligent agent improves the accuracy of the threat analysis results. If the threat analysis result indicates a security problem with the large model discovery event, the control and management intelligent agent center sends a defense command to the probe, controlling the probe to block the large model discovery event. By using probes located close to the source for blocking, the response speed to security issues is improved, and the overall security of the AI model is enhanced. By monitoring large-scale events within the AI system itself and generating natural language text, the large language model can perform security analysis, enabling the AI system to utilize its own computing power for security protection. This improves the AI system's response speed to security incidents and its self-defense capabilities.
[0113] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory, or random access memory, etc.
[0114] The above-disclosed embodiments are merely preferred embodiments of this application and should not be construed as limiting the scope of this application. Therefore, any equivalent variations made in accordance with the claims of this application shall still fall within the scope of this application.
[0115] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.), and signals involved in the embodiments of this specification are all authorized by the user or fully authorized by all parties, and the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. For example, the large model discovery events and threat analysis results involved in this specification were obtained under full authorization.
Claims
1. A system bootstrapping method, characterized in that, The method includes: When a large model discovery event is detected, the large model discovery event is reported to the management and control intelligent agent center; The control and management intelligent agent center generates security analysis task text in natural language form in response to events discovered by the large model; The security analysis task text is sent to a large language model to obtain threat analysis results for the events discovered by the large model; Defense actions are performed based on the threat analysis results.
2. The method according to claim 1, characterized in that, When a large model discovery event is detected, the large model discovery event is reported to the management and control intelligent agent center, including: A probe is used to perform feature monitoring on a large language model in an artificial intelligence system, and the probe is deployed in each node of the artificial intelligence system. If a large model discovery event is detected, the probe is controlled to report the large model discovery event to the edge agent; The edge agent is controlled to send the large model discovery event to the control agent center.
3. The method according to claim 2, characterized in that, The method of using probes to perform feature monitoring on large language models in artificial intelligence systems includes: If the probe detects target features corresponding to the large language model in the artificial intelligence system, then a large model occurrence event is generated based on the target features; The target features include one or more of the following: process features, port features, model file features, and interface call features.
4. The method according to claim 1, characterized in that, The control and management intelligent agent center includes a task planning intelligent agent and at least one functional intelligent agent; The control and management intelligent agent center generates security analysis task text in natural language form for the events discovered by the large model, including: The control task planning agent determines the security analysis task corresponding to the event discovered by the large model, and determines the target functional agent corresponding to the security analysis task; Control the target functional agent to generate security analysis task text in natural language form for the events discovered by the large model.
5. The method according to claim 4, characterized in that, The control and management intelligent agent center also includes a referee intelligent agent; The step of sending the security analysis task text to a large language model to obtain threat analysis results for the events discovered by the large model includes: The target functional agent is controlled to send the security analysis task text to the large language model to obtain the initial analysis results for the events discovered by the large model; The target functional agent is controlled to send the initial analysis results to the referee agent; The referee agent is controlled to verify the initial analysis results and generate threat analysis results based on the verification results.
6. The method according to claim 2, characterized in that, The defense process based on the threat analysis results includes: If the threat analysis result indicates that the large model has detected a security issue in the event, then the control and management intelligent agent center is instructed to send a defense command to the probe. The probe is controlled to block the discovery event of the large model.
7. The method according to claim 2, characterized in that, The method further includes: The edge agent is controlled to determine the large model computing power node corresponding to the large model discovery event. The system topology of the artificial intelligence system is updated based on the large model computing power node, and the parameter information of the large model computing power node is recorded.
8. A system bootstrapping device, characterized in that, The device includes: The event monitoring unit is used to report the event detected by the large model to the management and control intelligent agent center when it detects the event. The task text generation unit is used to control the management and control intelligent agent center to generate security analysis task text in natural language form in response to the events discovered by the large model. The analysis result acquisition unit uses a metaphor to send the security analysis task text to the large language model to obtain the threat analysis results for the events discovered by the large model; A defense processing unit is used to perform defense processing based on the threat analysis results.
9. A computer storage medium, characterized in that, The computer storage medium stores a plurality of instructions, which are adapted to be loaded by a processor and executed as method steps as claimed in any one of claims 1 to 7.
10. An electronic device, characterized in that, include: A processor and a memory; wherein the memory stores a computer program adapted to be loaded by the processor and executed the method steps as claimed in any one of claims 1 to 7.