一种针对Text-to-SQL系统的多轮越狱防御方法及装置

By constructing a multi-round jailbreak prompt detection dataset and a semantic-structural bimodal detector, combined with a context consistency review mechanism, dynamic interception and rewriting or de-identification processing, the problem of multi-round jailbreak attacks in Text-to-SQL systems is solved, and security control of the SQL generation process and protection of database operations are achieved.

CN122120035BActive Publication Date: 2026-07-17SICHUAN INFORMATION TECH COLLEGE

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SICHUAN INFORMATION TECH COLLEGE
Filing Date
2026-04-28
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing technologies are difficult to effectively defend against multi-round jailbreak attacks in Text-to-SQL systems, especially since they cannot combine database schemas and SQL syntax structures for deep semantic understanding and lack a security verification mechanism in the SQL generation stage, making them vulnerable to semantic rewriting and cross-round attacks.

Method used

A multi-round jailbreak prompt detection dataset is constructed, and a semantic-structural dual-modal jailbreak detector is used for risk assessment. Combined with a multi-round context consistency review mechanism, a comprehensive score is obtained through semantic encoding and structural encoding to dynamically intercept potentially dangerous operations. A security proxy layer is introduced before SQL generation for rewriting or de-identification processing.

Benefits of technology

In multi-turn dialogue scenarios, user input is continuously tracked to identify round-by-round penetration attacks, prevent unauthorized access and leakage of sensitive information, and enhance the adaptability and security of the defense by constructing a multi-turn attack path prediction mechanism to assess and block potential jailbreaking behaviors in advance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122120035B_ABST
    Figure CN122120035B_ABST
Patent Text Reader

Abstract

本发明公开了一种针对Text‑to‑SQL系统的多轮越狱防御方法及装置,涉及网络安全技术领域,该方法包括:基于多轮Text‑to‑SQL数据集构建包含多类攻击场景的越狱攻击数据集,构建并训练基于预训练语言模型的攻击者模型,以生成具有攻击意图的多轮自然语言问句,建立多轮越狱攻击树,以结构化表示由攻击目标分解而成的多步攻击路径,基于攻击树生成具备语义连贯性的多轮攻击问句序列,将所述序列输入目标Text‑to‑SQL系统,执行其输出的SQL查询,并依据评估指标量化攻击有效性,本发明能够系统化地模拟多轮对话中的渐进式越狱攻击,实现对Text‑to‑SQL模型安全性的自动化测试与评估,为系统加固与防御策略制定提供依据。
Need to check novelty before this filing date? Find Prior Art