A large model access management system and method based on call intention analysis
Patent Information
- Application Number
- CN202610921269.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-25
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2046-06-25
AI Technical Summary
[0002]随着数字数据处理技术的快速发展,大语言模型广泛应用于通用问答、文档撰写、代码辅助等多个领域,通过对文本类电数字数据的自动化处理与分析,提升信息处理效率与用户体验;与此同时大语言模型的高风险使用行为也日益增多,部分用户通过生成违规内容、系统破解、诱导对话等方式滥用模型能力,给平台运营和社会安全带来隐患;
1、突破单轮识别局限,捕捉渐进式违规:将离散的单轮意图判断升级为连续多轮的对话移动轨迹与曲率分析,量化用户意图的偏转角度和变化节奏,识别逐步诱导或试探性的渐进式违规行为。
Smart Images

Figure CN122452583B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of natural language data processing technology, specifically to a large-scale model access control system and method based on call intent analysis. Background Technology
[0002] With the rapid development of digital data processing technology, large language models are widely used in various fields such as general question answering, document writing, and code assistance. Through the automated processing and analysis of text-based digital data, they improve information processing efficiency and user experience. At the same time, high-risk usage of large language models is also increasing. Some users abuse the model's capabilities by generating illegal content, cracking the system, and inducing dialogue, which poses a threat to platform operation and social security. Currently, security detection for large language models mainly relies on keyword matching and single-turn intent classification to detect clear high-risk intents. However, it is difficult to capture high-risk behaviors that users hide in continuous dialogues through roundabout questions and gradual guidance. Especially for enterprise large models, these gradual and roundabout attempts to violate the rules are more concealed and more harmful. Therefore, there is an urgent need for a digital data processing method based on continuous dialogue intent trajectory analysis. By analyzing the dynamic changes in user intent in multi-turn dialogues, this method can identify progressive and roundabout high-risk behaviors, reduce false alarm rates, and ensure the safe and stable operation of large language models. Summary of the Invention
[0003] The purpose of this invention is to provide a large-scale access control system and method based on call intent analysis to solve the problems raised in the prior art.
[0004] To achieve the above objectives, the present invention provides the following technical solution: a large model access control method based on call intent analysis, the large model access control method comprising the following steps: Step S100: Standardize and clean the user input text, remove spaces and duplicate content, and unify capitalization and punctuation to obtain the cleaned text; An intent encoder is built based on the general pre-trained language model RoBERTa-base. The 12-layer Transformer encoder structure of the model is retained, the original sentence-level classification head and masked language model head are removed, and a linear projection layer is added after the output of the last Transformer layer. The output dimension of the linear projection layer is fixed at D=128. A dedicated dataset is constructed, including normal usage categories and high-risk usage categories. The normal usage categories include general question and answer, document writing, and code assistance, while the high-risk usage categories include generating illegal content, system hacking, and inducing dialogue. The dedicated dataset contains manually annotated single-intent samples, with the annotations representing the user's specific call intent. The InfoNCE contrastive loss function is used as the optimization objective for training. The cleaned text is input into the trained intent encoder, which then undergoes 12 layers of Transformer to perform contextual semantic encoding, extracting the overall semantic vector of the text. Next, a linear projection layer performs dimensionality transformation, generating a raw dense vector of dimension 128. L2 normalization is then performed on this raw dense vector to obtain the intent vector V. i , where i is the user dialogue round number, and the direction of the intent vector represents the overall intent tendency of the user input in the current dialogue round.
[0005] Step S200: Using the dialogue round number as the discrete time axis, arrange the continuously generated intent vectors in sequence to form a discrete point sequence; the system maintains a sliding window of length N. After each dialogue round is completed, the sliding window automatically moves forward, discarding the oldest intent vector in the sliding window and adding the latest generated intent vector, keeping the sliding window containing the most recent N intent vectors V. i-N+1 V i-N+2 ,...,V i V i-N+1 V i-N+2 These represent the intent vectors for the (i-N+1)th and (i-N+2)th dialogue rounds, respectively. The endpoints of the N intent vectors are sequentially connected in three-dimensional space to form a continuous polyline trajectory. This polyline trajectory represents the dialogue movement trajectory at the current moment, corresponding to the direction of change in user input intent in two adjacent dialogue rounds. The trajectory length L between the endpoints of two adjacent intent vectors is then calculated. j : ; In the formula, where θ j For two adjacent intention vectors V j and V j+1 The included angle, the trajectory length L j The angle θ is determined by the degree of difference between the intent vectors of two adjacent rounds. j The trajectory length L increases as the difference in the random graph increases. j With the included angle θ j It increases as it grows.
[0006] Step S300: Sequentially number the N intent vector endpoints within the sliding window as P1, P2, ..., P in chronological order. N, respectively corresponding to the intent vector V i-N+1 V i-N+2 ,…,V i For any point P in the sequence number k Take its predecessor endpoint P k-1 P itself k and successor endpoint P k+1 A continuous trajectory segment is formed; the change vectors of two adjacent intentions of the continuous trajectory segment are calculated respectively, where the value of k is in the range of 2≤k≤N-1, indicating that the first and last endpoints of the sequence number are excluded; The adjacent intent change vectors include a forward change vector a and a backward change vector b, where the forward change vector a represents the intent vector change from the (i-N+k-1)th dialogue round to the (i-N+k)th dialogue round, a=V i-N+k -V i-N+k-1 Where the backward change vector b represents the change in the intent vector from the (i-N+k)th dialogue round to the (i-N+k+1)th dialogue round, b=V i-N+k+1 -V i-N+k The direction of the adjacent intent change vector represents the direction of the user intent deflection in these two rounds of dialogue, and the magnitude represents the magnitude of the user intent change in these two rounds of dialogue. Step S200 yields the magnitudes of a and b, which are the corresponding trajectory lengths, and the trajectory length of the forward change vector a. The length of the trajectory of the backward change vector b Let θ be the angle between the forward change vector a and the backward change vector b. k θ can be obtained using the dot product formula. k : ; Based on the angle θ between the forward change vector a and the backward change vector b k Calculate the length of the trajectory of the forward change vector a and the backward change vector b for point P. k curvature C k : ; Curvature C k Point P in the continuous trajectory segment represents itself. k The degree of curvature reflects the magnitude of the angle at which the user's intent is deflected and the amplitude and rhythm of the change in intent.
[0007] Step S400: Calculate the maximum curvature C obtained in each dialogue round. i,max Compared with the curvature threshold T0, when C i,max When >T0, mark the trajectory segment corresponding to the current dialogue turn as an abnormal curvature segment. When C i,maxWhen T0 is less than or equal to 0, the trajectory segment corresponding to that dialogue turn is marked as a normal curvature segment. Each user maintains an independent historical normal curvature database, storing the maximum curvature C corresponding to all segments marked as normal curvature within the user's past x dialogue rounds. i,max As a library sample, the mean μ of all library samples in the historical normal curvature library is calculated. i With standard deviation σ i The personalized curvature threshold T updated for the i-th time is obtained. i =μ i +gσ i Where x is the preset round number and g is the preset coefficient; When a new user uses the service for the first time, the historical normal curvature library is empty, and a preset basic curvature threshold T0 is used as the curvature threshold. After the user has accumulated x rounds of normal conversation, the system automatically switches to the calculated personalized curvature threshold T. i As a curvature threshold; When a dialogue turn is marked as an abnormal curvature segment, the update of the historical normal curvature library is immediately frozen until the user completes authentication and x consecutive dialogue turns are marked as normal curvature segments, at which point the update of the historical normal curvature library is resumed.
[0008] Step S500: The system synchronously maintains a continuous anomaly counter. When an abnormal curvature segment is detected, the counter is incremented by 1, and when a normal curvature segment is detected, the counter is reset to zero. When the value of the continuous anomaly counter reaches the preset quantity threshold K1, the first-level warning is triggered. When the value of the continuous anomaly counter does not reach K1, it is determined to be a single random fluctuation and no warning is triggered, thus achieving the purpose of filtering out normal dialogue, including single high curvature fluctuations caused by normal operations such as users switching topics, correcting questions, and re-asking questions after inputting errors.
[0009] Step S600: When the value of the continuous anomaly counter is greater than or equal to 2, the reverse similarity verification process is triggered to identify whether the user intent has a progressive violation trend that continuously deviates from the normal baseline. The average value of the intent vectors of all corresponding dialogue turns in the current user's historical normal curvature library is calculated to obtain the user's normal intent baseline vector V. avg : ; In the formula, M is the number of samples in the historical normal curvature library, and V j This is the intent vector corresponding to the j-th normal dialogue round; Calculate the intent vector and the normal intent reference vector V for each round of dialogue in the current continuous sequence of abnormal curvature segments. avg Similarity Sim j : Sim j =Vj ×V avg ; The current sequence of consecutive abnormal curvature segments refers to the sequence of all dialogue rounds that are consecutively marked as abnormal curvature segments, starting from the beginning of the consecutive abnormality counter up to the current round. Calculate the rate of change ΔSim of similarity in the current sequence of consecutive anomalous curvature segments: ΔSim=Sim last -Sim first ; In the formula, Sim first Sim is the similarity score corresponding to the first round of dialogue for the current sequence of consecutive abnormal curvature segments. last This represents the similarity of the latest round of dialogue for the current sequence of consecutive abnormal curvature segments. When ΔSim < 0, it indicates that the user's intention is continuously deviating from the normal baseline, and the value of the continuous anomaly counter is incremented by 1; when ΔSim ≥ 0, it indicates that the user's intention is not continuously deviating, and the value of the continuous anomaly counter remains unchanged.
[0010] Step S700: For K1 consecutive abnormal curvature segments that trigger the first-level warning, calculate the maximum value C of each abnormal curvature segment. i,max The sum of the portions exceeding the threshold T0 is taken as the cumulative abnormal curvature integral S, reflecting the overall abnormality of the continuous high curvature segments. Simultaneously, the variance σ of these abnormal curvature segments is calculated. 2 It reflects the stability of curvature fluctuations and sets two judgment conditions. If at least one condition is met, it is judged as an abnormal intention trajectory and a second-level warning is triggered. The first condition is that S≥S1 and σ 2 ≤σ1 indicates that the intention is to undergo a sharp and relatively stable directional deflection within a short period of time, where S1 and σ1 are the preset curvature integral threshold and variance threshold, respectively; The second condition is K≥K2 and S≥S2, which means that the user intent is in a high deflection state after the expiration. K2 and S2 are the preset quantity threshold and curvature integral threshold, respectively. K is the value of the current continuous abnormality counter, S1<S2, K1<K2. Step S800: Execute tiered early warning response processing, responding to both Level 1 and Level 2 early warnings, specifically as follows: The first-level warning response sends a compliance usage prompt to the user, reminding them to abide by the platform's usage guidelines; temporarily reduces the size of the current dialog window to N / 2 to improve the sensitivity of subsequent monitoring; and records the user input content for this warning event. The second-level warning response immediately restricts the ability of the large model, including code generation, file reading and writing, external link access, and long text generation; requires users to perform secondary authentication, and restores all functions after successful authentication; marks the current user account as a key focus object, and reports and retains the user's input.
[0011] A large-scale model access control system based on call intent analysis, the large-scale model access control system includes an intent vector generation module, a dialogue trajectory construction module, a trajectory curvature calculation module, a curvature threshold determination module, a first-level early warning triggering module, a similarity verification module, a second-level early warning triggering module, and a hierarchical early warning response module; The intent vector generation module standardizes and cleans the user input text, constructs an intent encoder using RoBERTa-base, uses a dedicated dataset containing normal and high-risk categories, trains it with the InfoNCE contrastive loss function, inputs the cleaned text into the intent encoder, generates the original dense vector, and obtains the intent vector by L2 normalization. The dialogue trajectory construction module arranges intent vectors into a discrete point sequence with the dialogue round as the discrete time axis, maintains the N most recent intent vectors with a sliding window of length N, and connects the vector endpoints to form a dialogue movement trajectory. The trajectory curvature calculation module numbers the endpoints of the intent vector within the sliding window according to time, takes the predecessor, itself, and successor endpoints of the midpoint to form a continuous trajectory segment, calculates the angle between adjacent intent change vectors, and obtains the curvature of each point, reflecting the user's intent deflection angle and change amplitude rhythm. The curvature threshold determination module compares the overall maximum curvature of each round with the curvature threshold and marks it as an abnormal or normal curvature segment; it also maintains a historical normal curvature library for users independently and generates personalized curvature thresholds. The first-level early warning triggering module maintains a continuous anomaly counter, which increments by 1 when an abnormal curvature segment is detected and resets to zero when it is normal. The first-level early warning is triggered when the value reaches a preset number threshold K1. The similarity verification module triggers a reverse similarity verification process when the consecutive abnormal counter value is ≥2, calculates the similarity change rate between the user's normal intent baseline vector and the abnormal sequence, and increments the counter by 1 when the user's intent continues to deviate from the normal baseline. The secondary warning triggering module calculates the cumulative abnormal curvature integral and variance value for the continuous abnormal curvature segments that trigger the first-level warning. If any preset judgment condition is met, it is determined to be an abnormal intention trajectory and the second-level warning is triggered. The tiered early warning response module executes tiered early warning responses. The first-level early warning response sends a compliance usage prompt, temporarily shrinks the sliding window, and records the content. The second-level early warning response restricts the use of large model capabilities, requires secondary identity verification, marks the account, and reports the retained content.
[0012] Compared with the prior art, the beneficial effects of the present invention are: 1. Break through the limitations of single-round recognition and capture progressive violations: Upgrade discrete single-round intent judgment to continuous multi-round dialogue movement trajectory and curvature analysis, quantify the deflection angle and change rhythm of user intent, and identify progressive violations that are gradually induced or probing.
[0013] 2. Reduce false alarm rate and adapt to user dialogue habits: Maintain an independent historical normal curvature library for each user and dynamically generate personalized curvature thresholds; filter single random fluctuations through a continuous anomaly counter and combine reverse similarity verification to confirm continuous deviation trends, thereby reducing false alarms.
[0014] 3. Tiered control, balancing security and user experience: A two-tiered progressive early warning mechanism is set up. The first-level warning only sends compliance prompts and temporarily increases monitoring sensitivity without interfering with normal use. The second-level warning takes strong control measures for confirmed abnormal intent trajectories. When an anomaly occurs, the historical database update is automatically frozen to prevent non-compliant samples from contaminating the normal baseline and to ensure that the threshold is accurate and reliable in the long term. Attached Figure Description
[0015] Figure 1 This is a flowchart illustrating the application of the present invention to a large-scale model access control method based on call intent analysis; Figure 2 This is a schematic diagram of the structure of a large-scale model access control system based on call intent analysis, which is an application of the present invention. Detailed Implementation
[0016] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0017] Example: Figures 1-2 As shown, the present invention provides a technical solution, a method for access control of large models based on call intent analysis, the method comprising the following steps: Step S100: Standardize and clean the user input text, remove spaces and duplicate content, and unify capitalization and punctuation to obtain the cleaned text; An intent encoder is built based on the general pre-trained language model RoBERTa-base. The 12-layer Transformer encoder structure of the model is retained, the original sentence-level classification head and masked language model head are removed, and a linear projection layer is added after the output of the last Transformer layer. The output dimension of the linear projection layer is fixed at D=128. A dedicated dataset is constructed, including normal usage categories and high-risk usage categories. The normal usage categories include general question and answer, document writing, and code assistance, while the high-risk usage categories include generating illegal content, system hacking, and inducing dialogue. The dedicated dataset contains manually annotated single-intent samples, with the annotations representing the user's specific call intent. The InfoNCE contrastive loss function is used as the optimization objective for training. The cleaned text is input into the trained intent encoder, which then undergoes 12 layers of Transformer to perform contextual semantic encoding, extracting the overall semantic vector of the text. Next, a linear projection layer performs dimensionality transformation, generating a raw dense vector of dimension 128. L2 normalization is then performed on this raw dense vector to obtain the intent vector V. i , where i is the user dialogue round number, and the direction of the intent vector represents the overall intent tendency of the user input in the current dialogue round.
[0018] Step S200: Using the dialogue round number as the discrete time axis, arrange the continuously generated intent vectors in sequence to form a discrete point sequence; the system maintains a sliding window of length N. After each dialogue round is completed, the sliding window automatically moves forward, discarding the oldest intent vector in the sliding window and adding the latest generated intent vector, keeping the sliding window containing the most recent N intent vectors V. i-N+1 V i-N+2 ,...,V i V i-N+1 V i-N+2 These represent the intent vectors for the (i-N+1)th and (i-N+2)th dialogue rounds, respectively. The endpoints of the N intent vectors are sequentially connected in three-dimensional space to form a continuous polyline trajectory. This polyline trajectory represents the dialogue movement trajectory at the current moment, corresponding to the direction of change in user input intent in two adjacent dialogue rounds. The trajectory length L between the endpoints of two adjacent intent vectors is then calculated. j : ; In the formula, where θ j For two adjacent intention vectors V j and V j+1 The included angle, the trajectory length L j The angle θ is determined by the degree of difference between the intent vectors of two adjacent rounds.j The trajectory length L increases as the difference in the random graph increases. j With the included angle θ j It increases as it grows.
[0019] Step S300: Sequentially number the N intent vector endpoints within the sliding window as P1, P2, ..., P in chronological order. N , respectively corresponding to the intent vector V i-N+1 V i-N+2 ,…,V i For any point P in the sequence number k Take its predecessor endpoint P k-1 P itself k and successor endpoint P k+1 A continuous trajectory segment is formed; the change vectors of two adjacent intentions of the continuous trajectory segment are calculated respectively, where the value of k is in the range of 2≤k≤N-1, indicating that the first and last endpoints of the sequence number are excluded; The adjacent intent change vectors include a forward change vector a and a backward change vector b, where the forward change vector a represents the intent vector change from the (i-N+k-1)th dialogue round to the (i-N+k)th dialogue round, a=V i-N+k -V i-N+k-1 Where the backward change vector b represents the change in the intent vector from the (i-N+k)th dialogue round to the (i-N+k+1)th dialogue round, b=V i-N+k+1 -V i-N+k The direction of the adjacent intent change vector represents the direction of the user intent deflection in these two rounds of dialogue, and the magnitude represents the magnitude of the user intent change in these two rounds of dialogue. Step S200 yields the magnitudes of a and b, which are the corresponding trajectory lengths, and the trajectory length of the forward change vector a. The length of the trajectory of the backward change vector b Let θ be the angle between the forward change vector a and the backward change vector b. k θ can be obtained using the dot product formula. k : ; Based on the angle θ between the forward change vector a and the backward change vector b k Calculate the length of the trajectory of vectors a and b to find the point P. k curvature C k : ; Curvature C k Point P in the continuous trajectory segment represents itself. k The degree of curvature reflects the magnitude of the angle at which the user's intent is deflected and the amplitude and rhythm of the change in intent.
[0020] Step S400: Calculate the maximum curvature C obtained in each dialogue round. i,max Compared with the curvature threshold T0, when C i,max When >T0, mark the trajectory segment corresponding to the current dialogue turn as an abnormal curvature segment. When C i,max When T0 is less than or equal to 0, the trajectory segment corresponding to that dialogue turn is marked as a normal curvature segment. Each user maintains an independent historical normal curvature database, storing the maximum curvature C corresponding to all segments marked as normal curvature within the user's past x dialogue rounds. i,max As a library sample, the mean μ of all library samples in the historical normal curvature library is calculated. i With standard deviation σ i The personalized curvature threshold T updated for the i-th time is obtained. i =μ i +gσ i Where x is the preset round number and g is the preset coefficient; When a new user uses the service for the first time, the historical normal curvature library is empty, and a preset basic curvature threshold T0 is used as the curvature threshold. After the user has accumulated x rounds of normal conversation, the system automatically switches to the calculated personalized curvature threshold T. i As a curvature threshold; When a dialogue turn is marked as an abnormal curvature segment, the update of the historical normal curvature library is immediately frozen until the user completes authentication and x consecutive dialogue turns are marked as normal curvature segments, at which point the update of the historical normal curvature library is resumed.
[0021] Step S500: The system synchronously maintains a continuous anomaly counter. When an abnormal curvature segment is detected, the counter is incremented by 1, and when a normal curvature segment is detected, the counter is reset to zero. When the value of the continuous anomaly counter reaches the preset quantity threshold K1, the first-level warning is triggered. When the value of the continuous anomaly counter does not reach K1, it is determined to be a single random fluctuation and no warning is triggered, thus achieving the purpose of filtering out normal dialogue, including single high curvature fluctuations caused by normal operations such as users switching topics, correcting questions, and re-asking questions after inputting errors.
[0022] Step S600: When the value of the continuous anomaly counter is greater than or equal to 2, the reverse similarity verification process is triggered to identify whether the user intent has a progressive violation trend that continuously deviates from the normal baseline. The average value of the intent vectors of all corresponding dialogue turns in the current user's historical normal curvature library is calculated to obtain the user's normal intent baseline vector V. avg : ; In the formula, M is the number of samples in the historical normal curvature library, and V j This is the intent vector corresponding to the j-th normal dialogue round; Calculate the intent vector and the normal intent reference vector V for each round of dialogue in the current continuous sequence of abnormal curvature segments. avg Similarity Sim j : Sim j =V j ×V avg ; The current sequence of consecutive abnormal curvature segments refers to the sequence of all dialogue rounds that are consecutively marked as abnormal curvature segments, starting from the beginning of the consecutive abnormality counter up to the current round. Calculate the rate of change ΔSim of similarity in the current sequence of consecutive anomalous curvature segments: ΔSim=Sim last -Sim first ; In the formula, Sim first Sim is the similarity score corresponding to the first round of dialogue for the current sequence of consecutive abnormal curvature segments. last This represents the similarity of the latest round of dialogue for the current sequence of consecutive abnormal curvature segments. When ΔSim < 0, it indicates that the user's intention is continuously deviating from the normal baseline, and the value of the continuous anomaly counter is incremented by 1; when ΔSim ≥ 0, it indicates that the user's intention is not continuously deviating, and the value of the continuous anomaly counter remains unchanged.
[0023] Step S700: For K1 consecutive abnormal curvature segments that trigger the first-level warning, calculate the maximum value C of each abnormal curvature segment. i,max The sum of the portions exceeding the threshold T0 is taken as the cumulative abnormal curvature integral S, reflecting the overall abnormality of the continuous high curvature segments. Simultaneously, the variance σ of these abnormal curvature segments is calculated. 2 It reflects the stability of curvature fluctuations and sets two judgment conditions. If at least one condition is met, it is judged as an abnormal intention trajectory and a second-level warning is triggered. The first condition is that S≥S1 and σ 2 ≤σ1 indicates that the intention is to undergo a sharp and relatively stable directional deflection within a short period of time, where S1 and σ1 are the preset curvature integral threshold and variance threshold, respectively; The second condition is K≥K2 and S≥S2, which means that the user intent is in a high deflection state after the expiration. K2 and S2 are the preset quantity threshold and curvature integral threshold, respectively. K is the value of the current continuous abnormality counter, S1<S2, K1<K2. Step S800: Execute tiered early warning response processing, responding to both Level 1 and Level 2 early warnings, specifically as follows: The first-level warning response sends a compliance usage prompt to the user, reminding them to abide by the platform's usage guidelines; temporarily reduces the size of the current dialog window to N / 2 to improve the sensitivity of subsequent monitoring; and records the user input content for this warning event. The second-level warning response immediately restricts the ability of the large model, including code generation, file reading and writing, external link access, and long text generation; requires users to perform secondary authentication, and restores all functions after successful authentication; marks the current user account as a key focus object, and reports and retains the user's input.
[0024] A large-scale model access control system based on call intent analysis, the large-scale model access control system includes an intent vector generation module, a dialogue trajectory construction module, a trajectory curvature calculation module, a curvature threshold determination module, a first-level early warning triggering module, a similarity verification module, a second-level early warning triggering module, and a hierarchical early warning response module; The intent vector generation module standardizes and cleans the user input text, constructs an intent encoder using RoBERTa-base, uses a dedicated dataset containing normal and high-risk categories, trains it with the InfoNCE contrastive loss function, inputs the cleaned text into the intent encoder, generates the original dense vector, and obtains the intent vector by L2 normalization. The dialogue trajectory construction module arranges intent vectors into a discrete point sequence with the dialogue round as the discrete time axis, maintains the N most recent intent vectors with a sliding window of length N, and connects the vector endpoints to form a dialogue movement trajectory. The trajectory curvature calculation module numbers the endpoints of the intent vector within the sliding window according to time, takes the predecessor, itself, and successor endpoints of the midpoint to form a continuous trajectory segment, calculates the angle between adjacent intent change vectors, and obtains the curvature of each point, reflecting the user's intent deflection angle and change amplitude rhythm. The curvature threshold determination module compares the overall maximum curvature of each round with the curvature threshold and marks it as an abnormal or normal curvature segment; it also maintains a historical normal curvature library for users independently and generates personalized curvature thresholds. The first-level early warning triggering module maintains a continuous anomaly counter, which increments by 1 when an abnormal curvature segment is detected and resets to zero when it is normal. The first-level early warning is triggered when the value reaches a preset number threshold K1. The similarity verification module triggers a reverse similarity verification process when the consecutive abnormal counter value is ≥2, calculates the similarity change rate between the user's normal intent baseline vector and the abnormal sequence, and increments the counter by 1 when the user's intent continues to deviate from the normal baseline. The secondary warning triggering module calculates the cumulative abnormal curvature integral and variance value for the continuous abnormal curvature segments that trigger the first-level warning. If any preset judgment condition is met, it is determined to be an abnormal intention trajectory and the second-level warning is triggered. The tiered early warning response module executes tiered early warning responses. The first-level early warning response sends a compliance usage prompt, temporarily shrinks the sliding window, and records the content. The second-level early warning response restricts the use of large model capabilities, requires secondary identity verification, marks the account, and reports the retained content.
[0025] Example: This example simulates a new user's first use scenario. The system is pre-configured with core operating parameters: sliding window length N=5, basic curvature threshold T0=0.8, historical normal curvature library statistical rounds x=20, personalized threshold coefficient g=2, continuous abnormal first-level warning threshold K1=3, second-level warning quantity threshold K2=5, curvature integral thresholds S1=1.2, S2=2.5, and curvature variance threshold σ1=0.05. Simulating eight consecutive rounds of user dialogue input, the system completes intent encoding, trajectory construction, curvature calculation, and anomaly detection step by step, specifically: In rounds 1-3, during the normal dialogue phase, the user sequentially inputs "Help me write a script to read file xx", "Explain the left join usage of function xx", and "Correct the index error of loop xx in the code". After the system completes text standardization and cleaning round by round, it inputs the intent encoder to generate intent vectors V1, V2, and V3. The sliding window is gradually filled to [V1, V2, V3]. The angle between adjacent intent vectors is set to 0.21 rad and 0.18 rad, respectively, corresponding to trajectory lengths L1≈0.210 and L2≈0.180. The maximum curvature value of each point is less than T0=0.8, and all are marked as normal curvature segments. The continuous abnormal counter remains at 0, and the historical normal curvature library accumulates 3 normal samples. Round 4, first exception: The user inputs "Is there a way to bypass the website's account login verification?", generating intent vector V4. The sliding window is updated to [V1, V2, V3, V4]. The angle between V3 and V4 is set to θ3 = 1.22 rad, the trajectory length L3 ≈ 1.147, and the curvature of trajectory point P2 (V1-V2-V3) is calculated to be C2 ≈ 0.190, and the curvature of trajectory point P3 (V2-V3-V4) is calculated to be C3 ≈ 1.840. 4,max =max(0.192,1.832,)=1.840>0.8, marked as an abnormal curvature segment, the continuous abnormal counter becomes 1, and the historical normal curvature library is frozen and updated; Round 5, secondary anomaly + reverse verification: The user inputs "Teach me how to crack the activation code of local software," generating intent vector V5. The sliding window is updated to [V1, V2, V3, V4, V5]. The angle between V4 and V5 is set to θ4 = 1.03 rad, and the trajectory length is L4 ≈ 0.987. The curvature of trajectory point P3 (V2-V3-V4) is C3 ≈ 1.840, the curvature of trajectory point P2 (V1-V2-V3) is C2 ≈ 0.190, and the curvature of trajectory point P4 (V3-V4-V5) is C4 ≈ 0.965. 5,max=max(0.190,1.840,0.965)=1.840>0.8, marking an anomaly, the counter becomes 2. Triggering the reverse similarity verification process: Calculate the average intent baseline vector V of 3 samples from the historical normal library. avg V4 and V were obtained in sequence. avg The similarity between Sim4 and V5 is 0.31. avg The similarity Sim5 = 0.19, and the similarity change rate ΔSim = 0.19 - 0.31 = -0.12 < 0, indicating that the user's intent continues to deviate, and the counter is incremented by 1 to 3. In round 6, the first-level warning is triggered. The user inputs "Give me a tool link that can crack the xx password," generating an intent vector V6. The sliding window is updated to [V2, V3, V4, V5, V6]. The angle θ5 between V5 and V6 is calculated to be 0.81 rad, and the trajectory length L5 ≈ 0.789. The curvature of trajectory point P2 (V2-V3-V4) is C2 ≈ 1.840, the curvature of trajectory point P3 (V3-V4-V5) is C3 ≈ 0.965, and the curvature of trajectory point P4 (V4-V5-V6) is C4 ≈ 0.912. 6,max =max(1.840,0.965,0.912)=1.840>0.8, marking an anomaly, the counter becomes 4. At this time, the continuous anomaly counter is greater than K1, triggering the first level warning; The system immediately sends a compliance prompt to the user, stating "Please abide by the platform's usage guidelines and refrain from requesting the generation of illegal or cracked content"; temporarily shrinks the current dialog sliding window to 2 to improve the sensitivity of subsequent monitoring, and restores the original window size after the continuous anomaly counter is cleared; and fully records the user input content of this round and previous anomaly rounds to the system log. In round 7, a level 2 warning is triggered. The user inputs "Teach me how to remotely access someone else's computer files," generating intent vector V7. The sliding window is updated to [V3, V4, V5, V6, V7]. The angle θ6 between V6 and V7 is calculated to be 0.72 rad, the trajectory length L6≈0.703, the curvature of trajectory point P2 (V3-V4-V5) C2≈0.965, the curvature of trajectory point P3 (V4-V5-V6) C3≈0.912, and the curvature of trajectory point P4 (V5-V6-V7) C4≈0.961. 7,max =max(0.965,0.912,0.961)=0.965>0.8, mark as abnormal, the counter becomes 5, calculate the cumulative abnormal curvature integral S=S=(1.840-0.8)+(1.840-0.8)+(1.840-0.8)+(0.965-0.8)=3.285≥S1=1.2, judged as an abnormal intent trajectory, triggering the second level warning; The system immediately restricts the user's access to advanced capabilities for large models, including code generation, file reading and writing, external link access, and the generation of texts exceeding 500 characters. A two-factor authentication window pops up, requiring the user to complete authentication; all restricted functions remain disabled until authentication is successful. The user account is marked as a "key focus," and the entire content of this conversation and details of the warning event are simultaneously reported to the platform's security center and permanently stored. The historical normal curvature library remains frozen until the user completes authentication and 20 consecutive conversations are marked as normal curvature segments, after which it will automatically resume updates.
[0026] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the invention can be implemented in other specific forms without departing from its spirit or essential characteristics. Therefore, the embodiments should be considered in all respects as exemplary and non-limiting, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be included within the present invention. No reference numerals in the claims should be construed as limiting the scope of the claims.
Claims
1. A method for access control of large models based on call intent analysis, characterized in that: The large-model access control method includes the following steps: Step S100: Clean the user input text, construct an intent encoder using a pre-trained language model, and obtain the intent vector after training and normalization; Step S200: Maintain the N most recent intent vectors using a sliding window, connect the endpoints of the intent vectors sequentially in three-dimensional space to form a polyline trajectory, and calculate the trajectory length between two adjacent endpoints of intent vectors. In step S200, maintaining the N most recent intent vectors with a sliding window specifically involves: using the dialogue turn number as the discrete time axis, arranging the continuously generated intent vectors in sequence to form a discrete point sequence; and maintaining a sliding window of length N, which contains the N most recent intent vectors. The endpoints of the N intent vectors are connected sequentially in three-dimensional space to form a continuous polyline trajectory, which is the dialogue movement trajectory at the current moment, and the trajectory length between the endpoints of two adjacent intent vectors is obtained. Step S300: Construct a sequence number using N intent vectors. For any point in the sequence number, calculate the change vector of adjacent intents and obtain the curvature of the point by the included angle and the trajectory length. In step S300, the sequence numbering is to sort the N intention vector endpoints in the sliding window in chronological order. For any point in the sequence numbering, its predecessor endpoint, itself, and successor endpoint are taken to form a continuous trajectory segment. Calculate the two adjacent intention change vectors of the continuous trajectory segment respectively. The adjacent intention change vectors include forward change vector a and backward change vector b. Calculate the curvature of the point itself based on the angle between forward change vector a and backward change vector b and the trajectory lengths of forward change vector a and backward change vector b. Step S400: Compare the maximum curvature with the curvature threshold, mark abnormal curvature segments and normal curvature segments, generate personalized curvature thresholds for the user, and freeze the library update when a dialogue turn is marked as an abnormal curvature segment, and restore it after verification. The comparison of the maximum curvature and the curvature threshold in step S400 specifically involves: calculating the maximum curvature C obtained in each dialogue round... i,max Compared with the curvature threshold T0, when C i,max When >T0, mark the trajectory segment corresponding to the current dialogue turn as an abnormal curvature segment. When C i,max When T0 is less than or equal to 0, the trajectory segment corresponding to that dialogue turn is marked as a normal curvature segment. Each user maintains an independent historical normal curvature database, storing the maximum curvature C corresponding to all segments marked as normal curvature within the past x rounds of dialogue for the current user. i,max As a library sample, the mean and standard deviation of all library samples in the historical normal curvature library are calculated to obtain the personalized curvature threshold T updated for the i-th time. i Where x is the preset round number and g is the preset coefficient; When a new user uses the service for the first time, a preset basic curvature threshold T0 is used as the curvature threshold; after the user has accumulated x rounds of conversation, the system automatically switches to a calculated personalized curvature threshold T. i As a curvature threshold; when a dialogue turn is marked as an anomalous curvature segment, the update of the historical normal curvature library is frozen; Step S500: Maintain a continuous anomaly counter. Increment the counter by 1 when an abnormal curvature segment is detected, and reset it to zero when a normal curvature segment is detected. Trigger a first-level warning when the value reaches a preset number threshold. Step S600: When the continuous anomaly counter value is greater than or equal to 2, the reverse similarity verification process is triggered. When it is determined that the user's intent continues to deviate from the normal baseline, the counter is incremented by 1. Step S700: For continuous abnormal curvature segments that trigger the first-level warning, calculate the cumulative abnormal curvature integral and variance value. If any preset judgment condition is met, it is judged as an abnormal intention trajectory and the second-level warning is triggered. Step S800: Execute a graded early warning response for the first-level and second-level early warnings.
2. The method for access control of large models based on call intent analysis according to claim 1, characterized in that: In step S100, after cleaning the user input text, an intent encoder is constructed based on a general pre-trained language model. The cleaned text is input into the trained intent encoder to generate an original dense vector. L2 normalization is then performed on the original dense vector to obtain the intent vector V. i , where i is the user dialogue round number.
3. The method for access control of large models based on call intent analysis according to claim 1, characterized in that: In step S500, the continuous abnormality counter increments by 1 when an abnormal curvature segment is detected and resets to zero when a normal curvature segment is detected. When the value of the continuous abnormality counter reaches the preset quantity threshold K1, the first-level warning is triggered. If the value of the continuous anomaly counter does not reach K1, no warning will be triggered.
4. The method for access control of large models based on call intent analysis according to claim 1, characterized in that: The reverse similarity verification process in step S600 is as follows: calculate the average value of the intent vectors of all corresponding dialogue rounds in the current user's historical normal curvature library to obtain the user's normal intent baseline vector, and sequentially calculate the similarity and similarity change rate ΔSim between the intent vector of each round of dialogue in the current continuous abnormal curvature segment sequence and the normal intent baseline vector. When ΔSim < 0, the value of the continuous anomaly counter is incremented by 1; when ΔSim ≥ 0, the value of the continuous anomaly counter remains unchanged.
5. The method for access control of large models based on call intent analysis according to claim 1, characterized in that: In step S700, for K1 consecutive abnormal curvature segments that trigger the first-level warning, the maximum value C of each abnormal curvature segment is calculated. i,max The sum of the portions exceeding the threshold T0 is used as the cumulative abnormal curvature integral S, and the variance σ of the abnormal curvature segment is calculated. 2 Two judgment conditions are set. If at least one condition is met, the trajectory is judged as an abnormal intent and a second-level warning is triggered. The two judgment conditions are condition one and condition two. The first condition is that S≥S1 and σ 2 ≤σ1, where S1 and σ1 are the preset curvature integral threshold and variance threshold, respectively; The second condition is K≥K2 and S≥S2, where K2 and S2 are the preset quantity threshold and curvature integral threshold, respectively, K is the value of the current continuous anomaly counter, and S1<S2, K1<K2.
6. The method for access control of large models based on call intent analysis according to claim 1, characterized in that: In step S800, the first-level warning response sends a compliance usage prompt to the user; temporarily reduces the size of the current dialog sliding window to N / 2, and records the user input content of this warning event; the second-level warning response immediately restricts the ability call of the large model; requires the user to perform secondary identity verification, and restores all functions after successful verification, and reports and retains the user input content.
7. A large model access control system based on call intent analysis, used to execute the large model access control method based on call intent analysis as described in any one of claims 1-6, characterized in that: The large-scale model access control system includes an intent vector generation module, a dialogue trajectory construction module, a trajectory curvature calculation module, a curvature threshold determination module, a first-level early warning triggering module, a similarity verification module, a second-level early warning triggering module, and a hierarchical early warning response module. The intent vector generation module standardizes and cleans the user input text, constructs an intent encoder using RoBERTa-base, uses a dedicated dataset containing normal and high-risk categories, trains it with the InfoNCE contrastive loss function, inputs the cleaned text into the intent encoder, generates the original dense vector, and obtains the intent vector by L2 normalization. The dialogue trajectory construction module arranges intent vectors into a discrete point sequence with the dialogue round as the discrete time axis, maintains the N most recent intent vectors with a sliding window of length N, and connects the vector endpoints to form a dialogue movement trajectory. The trajectory curvature calculation module numbers the endpoints of the intention vector within the sliding window according to time, takes the predecessor, itself, and successor endpoints of the middle point to form a continuous trajectory segment, calculates the angle between adjacent intention change vectors, and obtains the curvature of each point. The curvature threshold determination module compares the overall maximum curvature of each round with the curvature threshold and marks it as an abnormal or normal curvature segment. Maintain an independent historical normal curvature library for each user and generate personalized curvature thresholds; The first-level early warning triggering module maintains a continuous anomaly counter, which increments by 1 when an abnormal curvature segment is detected and resets to zero when it is normal. The first-level early warning is triggered when the value reaches a preset number threshold K1. The similarity verification module triggers a reverse similarity verification process when the consecutive abnormal counter value is ≥2, calculates the similarity change rate between the user's normal intent baseline vector and the abnormal sequence, and increments the counter by 1 when the user's intent continues to deviate from the normal baseline. The secondary warning triggering module calculates the cumulative abnormal curvature integral and variance value for the continuous abnormal curvature segments that trigger the first-level warning. If any preset judgment condition is met, it is determined to be an abnormal intention trajectory and the second-level warning is triggered. The tiered early warning response module executes tiered early warning responses. The first-level early warning response sends a compliance usage prompt, temporarily shrinks the sliding window, and records the content. The Level 2 early warning response restricts the use of large-scale model capabilities, requires secondary identity verification, marks accounts, and reports retained content.
Citation Information
Patent Citations
Power distribution equipment intelligent fault early warning method and system based on Internet of Things
CN121808283A
AIGC content security monitoring system and method based on dynamic reasoning and context awareness
CN121919870A