一种针对Text-to-SQL系统的多轮越狱防御方法及装置
By constructing a multi-round jailbreak prompt detection dataset and a semantic-structural bimodal detector, combined with a context consistency review mechanism, dynamic interception and rewriting or de-identification processing, the problem of multi-round jailbreak attacks in Text-to-SQL systems is solved, and security control of the SQL generation process and protection of database operations are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SICHUAN INFORMATION TECH COLLEGE
- Filing Date
- 2026-04-28
- Publication Date
- 2026-07-17
AI Technical Summary
Existing technologies are difficult to effectively defend against multi-round jailbreak attacks in Text-to-SQL systems, especially since they cannot combine database schemas and SQL syntax structures for deep semantic understanding and lack a security verification mechanism in the SQL generation stage, making them vulnerable to semantic rewriting and cross-round attacks.
A multi-round jailbreak prompt detection dataset is constructed, and a semantic-structural dual-modal jailbreak detector is used for risk assessment. Combined with a multi-round context consistency review mechanism, a comprehensive score is obtained through semantic encoding and structural encoding to dynamically intercept potentially dangerous operations. A security proxy layer is introduced before SQL generation for rewriting or de-identification processing.
In multi-turn dialogue scenarios, user input is continuously tracked to identify round-by-round penetration attacks, prevent unauthorized access and leakage of sensitive information, and enhance the adaptability and security of the defense by constructing a multi-turn attack path prediction mechanism to assess and block potential jailbreaking behaviors in advance.
Smart Images

Figure CN122120035B_ABST