Audit processing method, apparatus, device, and storage medium

By comparing target audit instructions with historical instructions in audit scenarios and selectively reusing or generating executable code, the problem of high efficiency and low cost of manual reliance is solved, and an efficient and low-cost automated audit process is achieved.

CN122489207APending Publication Date: 2026-07-31BAIDU ONLINE NETWORK TECH (BEIJIBG) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BAIDU ONLINE NETWORK TECH (BEIJIBG) CO LTD
Filing Date
2026-04-27
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

Existing log auditing and data auditing rely on manual processing, which is inefficient and costly.

Method used

By comparing the target audit instruction with the pre-stored historical audit instructions, the system selectively reuses historical executable code or uses the large language model to generate new executable code, and runs it in a preset environment to output audit results, thereby reducing repeated calls to the large language model.

Benefits of technology

It reduces the reliance on manual processes in the audit process, improves the overall efficiency of the audit process, reduces system resource consumption, and supports rapid adaptation to new audit scenarios and frequently changing compliance requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122489207A_ABST
    Figure CN122489207A_ABST
Patent Text Reader

Abstract

This disclosure provides an audit processing method, apparatus, device, and medium, relating to the field of artificial intelligence technology, specifically natural language processing, deep learning, and other technical fields. The method includes: acquiring a target audit instruction, the target audit instruction including target audit logic information described in natural language; comparing the target audit instruction with at least one pre-stored historical audit instruction, and determining target executable code based on the comparison result, including: in response to determining that the target audit instruction matches one of the at least one historical audit instruction, determining the historical executable code associated with that historical audit instruction as the target executable code; and in response to determining that the target audit instruction does not match any of the at least one historical audit instruction, generating the target executable code based on the target audit logic information using a first language model; and running the target executable code in a preset execution environment to obtain an audit result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of artificial intelligence technology, specifically to the fields of natural language processing and deep learning, and particularly to an audit processing method, an audit processing device, an electronic device, a computer-readable storage medium, and a computer program product. Background Technology

[0002] Artificial intelligence (AI) is the study of enabling computers to simulate certain human thought processes and intelligent behaviors (such as learning, reasoning, thinking, and planning). It encompasses both hardware and software technologies. AI hardware technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, and big data processing. AI software technologies mainly include natural language processing, computer vision, speech recognition, machine learning / deep learning, big data processing, and knowledge graph technologies.

[0003] The methods described in this section are not necessarily methods that had been previously conceived or adopted. Unless otherwise specified, no method described in this section should be assumed to be prior art simply because it is included in this section. Similarly, unless otherwise specified, the issues mentioned in this section should not be considered to be accepted in any prior art. Summary of the Invention

[0004] This disclosure provides an audit processing method, an audit processing apparatus, an electronic device, a computer-readable storage medium, and a computer program product.

[0005] According to one aspect of this disclosure, an audit processing method is provided, comprising: obtaining a target audit instruction, the target audit instruction including target audit logic information described in natural language; comparing the target audit instruction with at least one pre-stored historical audit instruction, and determining target executable code based on the comparison result, comprising: in response to determining that the target audit instruction matches one of the at least one historical audit instruction, determining the historical executable code associated with the historical audit instruction as the target executable code; and in response to determining that the target audit instruction does not match any of the at least one historical audit instruction, generating the target executable code based on the target audit logic information using a first language model; and running the target executable code in a preset execution environment to obtain an audit result.

[0006] According to one aspect of this disclosure, an audit processing apparatus is provided, comprising: an acquisition unit configured to acquire a target audit instruction, the target audit instruction including target audit logic information described in natural language; a comparison unit configured to compare the target audit instruction with at least one pre-stored historical audit instruction, and determine target executable code based on the comparison result, comprising: in response to determining that the target audit instruction matches one of the at least one historical audit instruction, determining the historical executable code associated with the historical audit instruction as the target executable code; and in response to determining that the target audit instruction does not match any of the at least one historical audit instruction, generating the target executable code based on the target audit logic information using a first language model; and a running unit configured to run the target executable code in a preset execution environment to obtain an audit result.

[0007] According to another aspect of this disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the methods described above.

[0008] According to another aspect of this disclosure, a non-transitory computer-readable storage medium is provided storing computer instructions, wherein the computer instructions are used to cause a computer to perform the above-described method.

[0009] According to another aspect of this disclosure, a computer program product is provided, including a computer program, wherein the computer program implements the above-described method when executed by a processor.

[0010] According to one or more embodiments of this disclosure, in an auditing scenario, by comparing the target audit instruction with pre-stored historical audit instructions, and selectively reusing historical executable code or generating new executable code using a large language model based on the comparison results, the determined target executable code is automatically run to output audit results. This allows business personnel to directly trigger audit tasks through natural language, reducing the reliance on manual intervention in the auditing process. Simultaneously, the reuse of historical code avoids repeated calls to the large language model, improving the overall execution efficiency of the auditing process and reducing system resource consumption.

[0011] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0012] The accompanying drawings exemplify embodiments and form part of the specification, serving together with the textual description to explain exemplary implementations of the embodiments. The illustrated embodiments are for illustrative purposes only and do not limit the scope of the claims. Throughout the drawings, the same reference numerals refer to similar but not necessarily identical elements.

[0013] Figure 1 A schematic diagram of an exemplary system in which the various methods described herein may be implemented according to embodiments of the present disclosure is shown; Figure 2 A flowchart of an audit processing method according to an exemplary embodiment of the present disclosure is shown; Figure 3 A flowchart illustrating the generation of target executable code based on target audit logic information using a first major language model according to an exemplary embodiment of the present disclosure is shown. Figure 4 A flowchart is shown illustrating the construction of prompt text for a first large language model based on interface information and target audit logic information based on at least one target function, according to an exemplary embodiment of the present disclosure. Figure 5 A flowchart illustrating a comparison of a target audit instruction with at least one pre-stored historical audit instruction, according to an exemplary embodiment of the present disclosure, is shown. Figure 6 A structural block diagram of an audit processing apparatus according to an exemplary embodiment of the present disclosure is shown; Figure 7 A structural block diagram of an exemplary electronic device that can be used to implement embodiments of the present disclosure is shown. Detailed Implementation

[0014] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0015] In this disclosure, unless otherwise stated, the use of terms such as "first," "second," etc., to describe various elements is not intended to limit the positional, temporal, or importance relationships of these elements; such terms are merely used to distinguish one element from another. In some examples, the first element and the second element may refer to the same instance of that element, while in other cases, based on the context, they may refer to different instances.

[0016] The terminology used in the description of the various examples in this disclosure is for the purpose of describing particular examples only and is not intended to be limiting. Unless the context explicitly indicates otherwise, an element may be one or more unless the number of elements is specifically limited. Furthermore, the term "and / or" as used in this disclosure covers any one of the listed items and all possible combinations thereof.

[0017] In related technologies, existing auditing work such as log auditing and data auditing relies on manual processing, which is inefficient and extremely costly.

[0018] To address the aforementioned issues, this disclosure, in an auditing scenario, compares the target audit instruction with pre-stored historical audit instructions. Based on the comparison results, it selectively reuses historical executable code or generates new executable code using a large language model. The determined target executable code is then automatically executed to output the audit results. This allows business personnel to directly trigger audit tasks via natural language, reducing the audit process's reliance on manual intervention. Simultaneously, reusing historical code avoids repeated calls to the large language model, improving the overall execution efficiency of the audit process and reducing system resource consumption.

[0019] The embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.

[0020] Figure 1 A schematic diagram of an exemplary system 100 in which the various methods and apparatus described herein can be implemented according to embodiments of this disclosure is shown. Reference Figure 1 The system 100 includes one or more client devices 101, 102, 103, 104, 105 and 106, a server 120, and one or more communication networks 110 coupling the one or more client devices to the server 120. The client devices 101, 102, 103, 104, 105 and 106 can be configured to execute one or more applications.

[0021] In embodiments of this disclosure, server 120 may run one or more services or software applications that enable the execution of the methods of this disclosure.

[0022] In some embodiments, server 120 may also provide other services or software applications that may include non-virtual and virtual environments. In some embodiments, these services may be provided as web-based services or cloud services, such as to users of client devices 101, 102, 103, 104, 105 and / or 106 under a Software as a Service (SaaS) network.

[0023] exist Figure 1In the configuration shown, server 120 may include one or more components that implement the functions performed by server 120. These components may include software components, hardware components, or combinations thereof that can be executed by one or more processors. Users operating client devices 101, 102, 103, 104, 105, and / or 106 can sequentially interact with server 120 using one or more client applications to utilize the services provided by these components. It should be understood that various different system configurations are possible and may differ from system 100. Therefore, Figure 1 This is an example of a system used to implement the various methods described herein, and is not intended to be limiting.

[0024] Users can use client devices 101, 102, 103, 104, 105, and / or 106 for human-computer interaction. The client devices provide interfaces that enable users to interact with them. The client devices can also output information to the user through these interfaces. Although... Figure 1 Only six client devices are described, but those skilled in the art will understand that this disclosure can support any number of client devices.

[0025] Client devices 101, 102, 103, 104, 105, and / or 106 may include various types of computer devices, such as portable handheld devices, general-purpose computers (such as personal computers and laptops), workstation computers, wearable devices, smart screen devices, self-service terminal devices, service robots, gaming systems, thin clients, various messaging devices, sensors, or other sensing devices. These computer devices can run various types and versions of software applications and operating systems, such as Microsoft Windows, Apple iOS, UNIX-like operating systems, Linux or Linux-like operating systems (such as Google Chrome OS); or include various mobile operating systems, such as Microsoft Windows Mobile OS, iOS, Windows Phone, and Android. Portable handheld devices may include cellular phones, smartphones, tablets, personal digital assistants (PDAs), etc. Wearable devices may include head-mounted displays (such as smart glasses) and other devices. Gaming systems may include various handheld gaming devices, internet-enabled gaming devices, etc. Client devices are capable of executing various applications, such as various internet-related applications, communication applications (such as email applications), short message service (SMS) applications, and can use various communication protocols.

[0026] Network 110 can be any type of network well known to those skilled in the art, and can support data communication using any of a variety of available protocols (including but not limited to TCP / IP, SNA, IPX, etc.). By way of example only, one or more networks 110 can be a local area network (LAN), an Ethernet-based network, a token ring network, a wide area network (WAN), the Internet, a virtual network, a virtual private network (VPN), an intranet, an extranet, a public switched telephone network (PSTN), an infrared network, a wireless network (e.g., Bluetooth, WIFI), and / or any combination of these and / or other networks.

[0027] Server 120 may include one or more general-purpose computers, special-purpose server computers (e.g., PC (personal computer) servers, UNIX servers, mid-range servers), blade servers, mainframe computers, server clusters, or any other suitable arrangement and / or combination. Server 120 may include one or more virtual machines running a virtual operating system, or other computing architectures involving virtualization (e.g., one or more flexible pools of logical storage devices that can be virtualized to maintain virtual storage devices for servers). In various embodiments, server 120 may run one or more services or software applications that provide the functionality described below.

[0028] The computing unit in server 120 can run one or more operating systems, including any of the aforementioned operating systems and any commercially available server operating system. Server 120 can also run any of a variety of additional server applications and / or middleware applications, including HTTP servers, FTP servers, CGI servers, JAVA servers, database servers, etc.

[0029] In some implementations, server 120 may include one or more applications to analyze and merge data feeds and / or event updates received from users of client devices 101, 102, 103, 104, 105, and 106. Server 120 may also include one or more applications to display data feeds and / or real-time events via one or more display devices of client devices 101, 102, 103, 104, 105, and 106.

[0030] In some implementations, server 120 can be a server for a distributed system or a server integrated with blockchain. Server 120 can also be a cloud server, or an intelligent cloud computing server or intelligent cloud host with artificial intelligence technology. A cloud server is a host product in the cloud computing service system, designed to address the shortcomings of traditional physical hosts and Virtual Private Server (VPS) services, such as high management difficulty and weak business scalability.

[0031] System 100 may also include one or more databases 130. In some embodiments, these databases may be used to store data and other information. For example, one or more of the databases 130 may be used to store information such as audio files and video files. Databases 130 may reside in various locations. For example, a data repository used by server 120 may be local to server 120, or it may be located away from server 120 and may communicate with server 120 via a network-based or dedicated connection. Databases 130 may be of different types. In some embodiments, the database used by server 120 may be a database, such as a relational database. One or more of these databases may store, update, and retrieve data from and from the database in response to commands.

[0032] In some embodiments, one or more of the databases 130 may also be used by an application to store application data. The databases used by the application may be of different types, such as key-value stores, object stores, or regular stores supported by a file system.

[0033] Figure 1 The system 100 can be configured and operated in various ways to enable the application of the various methods and apparatus described in this disclosure.

[0034] According to one aspect of this disclosure, an audit processing method is provided. Figure 2 This is a flowchart illustrating an audit processing method 200 according to an exemplary embodiment.

[0035] Method 200 can be executed by an auditing platform deployed in an enterprise environment. Its application scenarios include, but are not limited to, SOX 404 compliance auditing, internal control auditing, log system auditing, and access control policy auditing. In different application scenarios, the objects to be audited may be different, and the corresponding compliance requirements or business logic may also be different.

[0036] refer to Figure 2 In step S201, the target audit instruction is obtained, which includes target audit logic information described in natural language.

[0037] A target audit instruction can be an instructive input used to trigger an audit task. In some embodiments, the target audit instruction can be input by business personnel through an interactive interface provided by the audit platform, allowing business personnel to initiate audit tasks without the intervention of development personnel.

[0038] The target audit logic information can be a natural language description of the judgment logic involved in this audit task. In some embodiments, the target audit logic information may include the data source to be audited, comparison or filtering rules, and the judgment criteria for audit conclusions, etc. For example, the target audit logic information can be expressed as "compare data A in 202X with data B in 202Y", which implicitly includes the data source to be audited, the time window used to limit the data range, and the judgment logic for discovering anomalies by comparing the two data sources.

[0039] In some embodiments, the target audit instruction may include other types of information in addition to the target audit logic information to assist in the processing of this audit task.

[0040] In step S202, the target audit instruction is compared with at least one pre-stored historical audit instruction, and the target executable code is determined based on the comparison result. Step S202 further includes steps S2021 and S2022.

[0041] In step S2021, in response to determining that the target audit instruction matches one of the historical audit instructions in at least one historical audit instruction, the historical executable code associated with that historical audit instruction is determined as the target executable code.

[0042] In step S2022, in response to determining that the target audit instruction is inconsistent with at least one historical audit instruction, the target executable code is generated based on the target audit logic information using the first major language model.

[0043] The pre-stored historical audit instructions can be previously processed audit instructions. Each historical audit instruction is associated with corresponding historical executable code, which is used to implement the processed audit logic. In some embodiments, historical audit instructions and their associated historical executable code can be stored in a relational database, vector database, or other forms of database for subsequent audit tasks to query and reuse.

[0044] By comparing the target audit instruction with historical audit instructions, it can be determined whether the audit logic corresponding to the current audit task has been processed previously. If the audit logic has been processed, the historical executable code can be directly reused, thereby avoiding repeated calls to the large language model and repeated implementation of the same audit logic. If the audit logic has not been processed or the audit logic has changed compared to a previously processed version, the large language model regenerates the executable code based on the target audit logic information. In some embodiments, the comparison can be based on the literal content of the target audit instruction and the historical audit instruction, or on their semantic similarity, or through other means, which are not limited in this disclosure.

[0045] The first major language model can be any major language model suitable for code generation tasks. The first major language model receives target audit logic information and outputs target executable code corresponding to the target audit logic information. In some embodiments, the target executable code can be Python code or code corresponding to other programming languages.

[0046] In step S203, the target executable code is run in a preset execution environment to obtain audit results.

[0047] The preset execution environment is a code execution environment used to run the target executable code. It is pre-configured with the interpreter, library files, and data access channels that the target executable code depends on for execution. In some embodiments, the preset execution environment may be an execution environment isolated from the host system, or it may be other forms of execution environment.

[0048] In some embodiments, by running the target executable code, corresponding operations such as reading, filtering, comparing, and judging can be performed on the data source or system to be audited, ultimately yielding audit results. Audit results can be, for example, standardized reports indicating the compliance status, enterprise status, or compliance status of the audited entity. Audit results may also include traceability information about the data source to meet traceability requirements.

[0049] According to embodiments of this disclosure, in an auditing scenario, by comparing the target audit instruction with pre-stored historical audit instructions, and selectively reusing historical executable code or generating new executable code using a large language model based on the comparison results, the determined target executable code is automatically run to output audit results. This allows business personnel to directly trigger audit tasks through natural language, reducing the reliance on manual intervention in the auditing process. Simultaneously, the reuse of historical code avoids repeated calls to the large language model, improving the overall execution efficiency of the auditing process and reducing system resource consumption.

[0050] Furthermore, since the audit logic is described in natural language and automatically converted into executable code by a large language model, business personnel do not need to rely on developers to modify scripts when adjusting the audit logic (including changing the audited object, modifying screening conditions, and adjusting judgment rules), thus supporting rapid adaptation to new audit scenarios and frequently changing compliance requirements. In addition, by supporting the reuse of historical code, the processing of audit tasks that have already been processed does not need to go through the code generation process of the large language model again, thereby further shortening the overall response time of a single audit task.

[0051] According to some embodiments, such as Figure 3As shown, step S2022, generating target executable code based on target audit logic information using the first large language model, may include: step S301, retrieving at least one target function related to the target audit logic information from multiple preset functions included in the audit function library; step S302, constructing prompt text for the first large language model based on the interface information and target audit logic information of each of the at least one target function; and step S303, inputting the prompt text into the first large language model and obtaining the target executable code output by the first large language model, wherein the target executable code includes code fragments for calling at least one target function.

[0052] Therefore, by setting up an audit function library and constructing the target executable code by having the first language model generate call code for preset functions, the internal logic of the relevant functions does not need to be implemented manually. This reduces the generation burden and resource consumption of the first language model and improves the accuracy and reliability of the generated target executable code.

[0053] Furthermore, by pre-retrieving target functions related to the target audit logic information from multiple preset functions and constructing prompt text based on the interface information of the retrieved target functions, compared to injecting the interface information of all preset functions into the prompt text, the size of the prompt text and the occupation of the large model context window are reduced. This allows the first large language model to focus its attention on functions related to this task, thereby saving the computational resources of the large model and improving the accuracy of the generated results.

[0054] In some embodiments, the audit function library may be a pre-built function library that may contain multiple preset functions for implementing common operations in audit tasks. These preset functions may be implemented and verified in advance to serve as callable objects when the first language model generates the target executable code.

[0055] In some embodiments, the interface information may be information describing the corresponding preset function call method. In some embodiments, the interface information may be in text form to construct prompt text for the first language model to read and use.

[0056] In step S301, the specific method for retrieving the target function related to the target audit logic information is not limited. In some embodiments, retrieval can be based on keyword matching, for example, extracting keywords from the target audit logic information and searching for preset functions whose function names or function descriptions contain the corresponding keywords. In other embodiments, retrieval can be based on vector similarity, for example, encoding the target audit logic information and the descriptive information of each preset function into vectors using a pre-trained language model, and then filtering based on the similarity between the vectors. In still other embodiments, the intent recognition capability of a large language model can also be used to determine the target function from multiple preset functions.

[0057] In step S302, the interface information and target audit logic information of at least one objective function can be combined according to a preset template to obtain a prompt text. In some embodiments, the prompt text may further include other auxiliary content such as task descriptions and output format requirements, which are not limited in this disclosure.

[0058] In step S303, the target executable code output by the first language model includes code snippets for calling at least one target function. The first language model does not need to rewrite the functionality implemented by the called target function; instead, it uses existing target functions from the audit function library to perform the corresponding operations, thereby obtaining the target executable code.

[0059] According to some embodiments, the interface information may include at least one of the following: the function name of the corresponding target function, input parameters, output parameters, and functional description.

[0060] In some embodiments, the function name can be used to identify the corresponding target function, so that the target function can be called by function name in the target executable code. Input parameters can be used to describe the name, type, and meaning of the data required to be passed when calling the corresponding target function. Output parameters can be used to describe the name, type, and meaning of the data returned after the corresponding target function is executed. The function description can be a natural language description of the functionality implemented by the target function.

[0061] By setting the above fields in the interface information, the first language model can understand the calling method of the corresponding target function and the function it implements, and then make reasonable calls to the target function in the target executable code.

[0062] According to some embodiments, such as Figure 4As shown, step S302, constructing prompt text for the first large language model based on the interface information and target audit logic information of at least one target function, may include: step S401, obtaining example information, which includes: example audit logic information based on natural language description; interface information of at least one example function related to the example audit logic information among multiple preset functions; and example executable code for implementing the example audit logic information; and step S402, constructing prompt text based on the interface information, target audit logic information, and example information of at least one target function.

[0063] Therefore, by adding example information to the prompt text, the first language model can refer to the correspondence between example audit logic information and example executable code in the example information, and learn how to generate corresponding executable code based on audit logic information and related function interface information. This method improves the accuracy of the first language model's execution results in generating target executable code based on target audit logic information.

[0064] In some embodiments, example information may be pre-built reference information used to assist code generation. In some embodiments, example information may be pre-stored in the audit platform and retrieved and used when constructing prompt text. Example audit logic information may be audit logic information described in natural language and having a similar form to the target audit logic information. Example function may be a function related to the example audit logic information from among a plurality of preset functions included in the audit function library. Example executable code may be executable code used to implement the example audit logic information, and may contain code snippets for calling example functions.

[0065] In step S402, interface information of at least one objective function, objective audit logic information, and example information can be combined according to a predetermined template to obtain a prompt text. This disclosure does not limit the position of the example information in the prompt text or the above combination method. In some embodiments, the number of example information pieces can be one or more, wherein multiple example information pieces can correspond to different types of example audit logic information to cover a wider range of audit scenarios.

[0066] According to some embodiments, the example information may also include descriptions of the code implementation of the example audit logic information in multiple preset stages, which may include a data source reading stage, a data comparison stage, and a result determination stage.

[0067] In some embodiments, an audit task may include three levels of processing: identifying the data source or system to be audited, determining the business logic or compliance requirements that the data source or system should follow, and applying the business logic or compliance requirements to the data source or system to arrive at a conclusion of compliance or non-compliance. Accordingly, the executable code used to implement the audit logic can also be divided into a data source reading stage, a data comparison stage, and a result determination stage at the implementation level, corresponding to the three levels of processing mentioned above.

[0068] Therefore, by further adding descriptions of the code implementation of the example audit logic information in multiple preset stages to the example information, the first major language model can be guided to generate the target executable code according to the same staged structure, thereby improving the stability of the target executable code generation and the accuracy of the code execution results.

[0069] In some embodiments, the data source reading phase may be a phase in the code implementation used to read raw data from the data source to be audited. The data comparison phase may be a phase that filters, transforms, and compares the read raw data. The result determination phase may be a phase that draws an audit conclusion based on the processing results of the data comparison phase.

[0070] In some embodiments, the descriptive information may be a natural language description of how the example audit logic information should be implemented in code at each preset stage. For example, for the example audit logic information, the descriptive information may include the data source type and acquisition method involved in the data source reading stage, the filtering conditions and comparison logic applied in the data comparison stage, and the judgment rules and the output format of exceptions in the result judgment stage.

[0071] According to some embodiments, the multiple preset functions may include a data source reading function, a data comparison function, and a result determination function.

[0072] Therefore, by setting these three types of preset functions in the audit function library, the organization of the preset functions corresponds to each processing stage of the audit task. This method enables step S301 to quickly retrieve the target functions required for each stage based on the target audit logic information, improving retrieval efficiency. Furthermore, it allows the first language model to more accurately select and call the preset functions for the corresponding stage when generating the target executable code based on the prompt text, further enhancing the accuracy of the generated target executable code.

[0073] In some embodiments, the data source reading function can be a preset function for accessing and reading data sources. For example, the data source reading function may include functions for reading different types of data sources such as database tables, log files, and spreadsheets. The data comparison function can be a preset function for filtering, transforming, and comparing data. For example, the data comparison function may include functions for performing correlation comparisons by field and filtering by condition. The result determination function can be a preset function for drawing audit conclusions based on the results of the data comparison. For example, the result determination function may include functions for generating a list of anomalies and summarizing compliance status.

[0074] According to some embodiments, the target audit instruction may further include target audit requirement information, and each of the at least one historical audit instruction may include historical audit requirement information and historical audit logic information. For example... Figure 5 As shown, step S202, comparing the target audit instruction with at least one pre-stored historical audit instruction, may include: step S501, for each historical audit instruction in the at least one historical audit instruction, determining the semantic similarity between the historical audit requirement information included in the historical audit instruction and the target audit requirement information; step S502, in response to determining that the semantic similarity between the historical audit requirement information included in one of the at least one historical audit instructions and the target audit requirement information is greater than a preset threshold, performing a character comparison between the historical audit logic information included in a historical audit instruction and the target audit logic information; and step S503, in response to the character comparison of the historical audit logic information included in a historical audit instruction and the target audit logic information being consistent, determining that the target audit instruction is consistent with a historical audit instruction.

[0075] Therefore, by first comparing the semantic similarity between historical audit requirement information and target audit requirement information, historical audit instructions that are identical or similar to the target audit instruction can be quickly filtered from at least one historical audit instruction. Then, by comparing the historical audit logic information included in the filtered historical audit instructions with the target audit logic information character by character, and reusing historical executable code when the audit logic is completely consistent, a strict judgment on whether the audit logic has changed is achieved, avoiding the use of outdated or incorrect historical executable code and improving the reliability of the audit process.

[0076] Furthermore, by first filtering based on semantic similarity and then performing precise character comparison, the computational overhead of directly comparing all historical audit instructions is avoided. On the other hand, the omission of candidate historical audit instructions due to differences in the expression of target audit requirements and historical audit requirements is also avoided, thereby improving comparison efficiency while ensuring accuracy.

[0077] In some embodiments, the target audit requirement information may include the audit items targeted by this audit task. An example target audit requirement information may be "whether the newly added authorized account has been approved," which describes the audit items of concern to this audit task.

[0078] In some embodiments, the historical audit requirement information, historical audit logic information, and historical executable code associated with each historical audit instruction can be pre-stored as an entry in a historical audit instruction library. The historical audit instruction library can be implemented based on a relational database, vector database, or other forms of database.

[0079] In step S501, semantic similarity can be calculated in various ways. In some embodiments, historical audit requirement information and target audit requirement information can be encoded into vectors using a pre-trained language model, and semantic similarity can be obtained by calculating the cosine similarity between the two vectors.

[0080] In step S502, the preset threshold can be set according to actual needs. In response to the existence of multiple historical audit instructions whose semantic similarity to the target audit requirement information is greater than the preset threshold, subsequent character comparisons can be performed separately for each historical audit instruction, or only for the historical audit instruction with the highest semantic similarity. In some embodiments, character comparison can be a complete comparison at the string level. Through character comparison, it is possible to strictly determine whether there are differences between the historical audit logic information and the target audit logic information, and reuse the corresponding historical executable code when they are completely identical.

[0081] According to some embodiments, method 200 may further include: after generating target executable code using the first large language model, in response to the successful execution of the target executable code, associating and storing the target executable code with target audit instructions.

[0082] Therefore, after the target executable code generated by the first language model runs successfully, it is associated with and stored as a target audit instruction. This allows the target audit instruction and its corresponding target executable code to serve as historical audit instructions and their corresponding historical executable code for subsequent audit tasks, enabling comparison and reuse. This approach avoids repeatedly calling the first language model to generate code for the same or similar audit instructions, thus saving computational overhead and improving the overall system execution efficiency.

[0083] In some embodiments, successful execution of the target executable code may include the target executable code running successfully in a preset execution environment without generating any interrupting errors. Successful execution of the target executable code may further include the audit results output by the target executable code passing preset verification.

[0084] In some embodiments, storing the target executable code in association with the target audit instruction can be achieved by adding a new entry to the historical audit instruction library. This entry includes information contained in the target audit instruction and the associated target executable code.

[0085] According to some embodiments, method 200 may further include: performing static code analysis on the target executable code after generating the target executable code using a first major language model; and performing logical verification on the target executable code based on target audit logic information using a second major language model. Accordingly, step S230, running the target executable code in a preset execution environment to obtain audit results, may include: running the target executable code in response to determining that the target executable code has passed static code analysis and logical verification.

[0086] Therefore, by performing static code analysis and logic verification based on the second major language model on the target executable code before execution, the target executable code generated by the first major language model can be pre-verified. By completing these two verifications before running the target executable code, problematic code can be avoided, reducing the risk of incorrect audit results or abnormal execution environment due to the execution of problematic code.

[0087] In some embodiments, static code analysis can be implemented using a pre-defined static analysis tool to detect implementation-level issues such as syntax problems, undefined variables, and potential security vulnerabilities in the target executable code.

[0088] In some embodiments, logic verification can be used to determine whether the target executable code correctly implements the audit logic expressed by the target audit logic information based on the target audit logic information.

[0089] In some embodiments, the second large language model can be the same as the first large language model, or it can be a different large language model. The second large language model can receive the target executable code to be verified and the target audit logic information, and output a logic verification result indicating whether the target executable code correctly implements the audit logic expressed by the target audit logic information. Compared to rule-based static analysis tools, the second large language model can understand the target audit logic information described in natural language and compare the audit logic with the actual implementation of the target executable code, thereby verifying the consistency between the target executable code and the target audit logic information.

[0090] In some embodiments, in response to determining that the target executable code fails at least one of static code analysis and logical verification, the target executable code may not be run and a corresponding prompt message may be returned, or the target executable code may be corrected using a first language model, and the above verification and running process may be re-executed on the corrected target executable code.

[0091] According to some embodiments, the preset execution environment can be a sandbox environment based on containerization or virtualization technology, which is isolated from the host system environment.

[0092] Therefore, by limiting the execution environment of the target executable code to a sandbox environment isolated from the host system environment, the impact of the target executable code during its execution is restricted to the sandbox environment. This ensures that the execution of the target executable code will not have a direct impact on the host system, thereby reducing the risk of damage to the host system due to unidentified problems in the target executable code generated by the first language model. This ensures the security and reliability of the auditing process in the production environment.

[0093] In some embodiments, containerization technology may be implemented using Docker or similar container technologies. In some embodiments, virtualization technology may be implemented using Firecracker MicroVMs or other lightweight virtualization technologies.

[0094] In some embodiments, the sandbox environment can also be configured with a permission restriction mechanism to limit the system resources that the target executable code can access. For example, the scope of system calls that the target executable code can use can be limited through the seccomp mechanism; the access permissions of the target executable code to host system files can be limited through the AppArmor mechanism. In this way, the permissions required to complete the auditing task can be granted to the target executable code according to the principle of least privilege.

[0095] In some embodiments, the sandbox environment can also be configured to mount data sources related to the current audit task and prohibit the target executable code from accessing external networks during operation, thereby further reducing the risk of data leakage and unintended operations.

[0096] According to another aspect of this disclosure, an audit processing apparatus is provided. For example... Figure 6 As shown, the apparatus 600 includes: an acquisition unit 610 configured to acquire a target audit instruction, the target audit instruction including target audit logic information described in natural language; a comparison unit 620 configured to compare the target audit instruction with at least one pre-stored historical audit instruction, and determine target executable code based on the comparison result, including: in response to determining that the target audit instruction matches one of the at least one historical audit instruction, determining the historical executable code associated with the historical audit instruction as the target executable code; and in response to determining that the target audit instruction does not match any of the at least one historical audit instruction, generating the target executable code based on the target audit logic information using a first language model; and a running unit 630 configured to run the target executable code in a preset execution environment to obtain audit results.

[0097] It is understandable that the operation and effects of units 610 to 630 in device 600 can be referred to the above description. Figure 2 The descriptions of steps S201 to S203 are not repeated here.

[0098] According to embodiments of this disclosure, an electronic device, a readable storage medium, and a computer program product are also provided.

[0099] refer to Figure 7 The present invention describes a structural block diagram of an electronic device 700 that can serve as a server or client of the present disclosure, which is an example of a hardware device that can be applied to various aspects of the present disclosure. The electronic device is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0100] like Figure 7As shown, device 700 includes a computing unit 701, which can perform various appropriate actions and processes based on a computer program stored in read-only memory (ROM) 702 or a computer program loaded into random access memory (RAM) 703 from storage unit 708. The RAM 703 may also store various programs and data required for the operation of device 700. The computing unit 701, ROM 702, and RAM 703 are interconnected via bus 704. Input / output (I / O) interface 705 is also connected to bus 704.

[0101] Multiple components in device 700 are connected to I / O interface 705, including: input unit 706, output unit 707, storage unit 708, and communication unit 709. Input unit 706 can be any type of device capable of inputting information to device 700. Input unit 706 can receive input numerical or character information and generate key signal inputs related to user settings and / or function control of the electronic device, and may include, but is not limited to, a mouse, keyboard, touchscreen, trackpad, trackball, joystick, microphone, and / or remote control. Output unit 707 can be any type of device capable of presenting information, and may include, but is not limited to, a monitor, speaker, video / audio output terminal, vibrator, and / or printer. Storage unit 708 may include, but is not limited to, a hard disk and an optical disk. Communication unit 709 allows device 700 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks, and may include, but is not limited to, a modem, network card, infrared communication device, wireless communication transceiver, and / or chipset, such as Bluetooth. TM Devices, 802.11 devices, WiFi devices, WiMax devices, cellular communication devices and / or the like.

[0102] The computing unit 701 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 701 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning network algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 701 performs the various methods and processes described above, such as audit processing methods. For example, in some embodiments, the audit processing method may be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 708. In some embodiments, part or all of the computer program may be loaded and / or installed on device 700 via ROM 702 and / or communication unit 709. When the computer program is loaded into RAM 703 and executed by the computing unit 701, one or more steps of the audit processing method described above may be performed. Alternatively, in other embodiments, the computing unit 701 may be configured to perform audit processing methods by any other suitable means (e.g., by means of firmware).

[0103] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0104] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0105] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0106] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0107] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.

[0108] Computer systems can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is established by computer programs running on the respective computers and having a client-server relationship with each other. A server can be a cloud server, also known as a cloud computing server or cloud host, a hosting product within the cloud computing service ecosystem, addressing the shortcomings of traditional physical hosts and VPS (Virtual Private Server, or simply "VPS") services, such as high management difficulty and weak business scalability. Servers can also be servers for distributed systems or servers incorporating blockchain technology.

[0109] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.

[0110] While embodiments or examples of this disclosure have been described with reference to the accompanying drawings, it should be understood that the methods, systems, and devices described above are merely exemplary embodiments or examples, and the scope of this disclosure is not limited by these embodiments or examples, but only by the granted claims and their equivalents. Various elements in the embodiments or examples may be omitted or replaced by their equivalents. Furthermore, the steps may be performed in a different order than that described in this disclosure. Further, various elements in the embodiments or examples may be combined in various ways. Importantly, as technology evolves, many elements described herein can be replaced by equivalents that appear after this disclosure.

Claims

1. An audit processing method, comprising: Obtain the target audit instruction, which includes target audit logic information described in natural language; The target audit instruction is compared with at least one pre-stored historical audit instruction, and the target executable code is determined based on the comparison result, including: In response to determining that the target audit instruction matches one of the at least one historical audit instructions, the historical executable code associated with the historical audit instruction is identified as the target executable code; and In response to determining that the target audit instruction is inconsistent with at least one historical audit instruction, the target executable code is generated based on the target audit logic information using a first language model; and The target executable code is run in a preset execution environment to obtain audit results.

2. The method according to claim 1, wherein, Generating target executable code based on the target audit logic information using the first major language model includes: Among the multiple preset functions included in the audit function library, at least one target function related to the target audit logic information is retrieved; Based on the interface information of each of the at least one objective function and the objective audit logic information, a prompt text for the first large language model is constructed; and The prompt text is input into the first large language model, and the target executable code output by the first large language model is obtained. The target executable code includes code fragments for calling the at least one target function.

3. The method according to claim 2, wherein, The interface information includes at least one of the following: the function name of the corresponding target function, input parameters, output parameters, and functional description.

4. The method according to claim 2, wherein, Based on the interface information of the at least one objective function and the objective audit logic information, the prompt text for the first large language model is constructed as follows: Obtain example information, which includes: Example audit logic information based on natural language description; Interface information of at least one example function among the plurality of preset functions that is related to the example audit logic information; and Example executable code for implementing the example audit logic information; and The prompt text is constructed based on the interface information of the at least one objective function, the objective audit logic information, and the example information.

5. The method according to claim 4, wherein, The example information also includes descriptions of the code implementation of the example audit logic information in multiple preset stages, including a data source reading stage, a data comparison stage, and a result determination stage.

6. The method according to claim 5, wherein, The preset functions include a data source reading function, a data comparison function, and a result determination function.

7. The method according to any one of claims 1-6, wherein, The target audit instruction further includes target audit requirement information, and each of the at least one historical audit instruction includes historical audit requirement information and historical audit logic information. Comparing the target audit instruction with at least one pre-stored historical audit instruction includes: For each of the at least one historical audit instruction, determine the semantic similarity between the historical audit requirement information included in the historical audit instruction and the target audit requirement information; In response to determining that the semantic similarity between the historical audit requirement information included in one of the at least one historical audit instructions and the target audit requirement information is greater than a preset threshold, a character comparison is performed between the historical audit logic information included in the one historical audit instruction and the target audit logic information; and In response to the historical audit logic information included in the historical audit instruction matching the target audit logic information characters, it is determined that the target audit instruction matches the historical audit instruction.

8. The method according to any one of claims 1-6, further comprising: After generating the target executable code using the first large language model, in response to the successful execution of the target executable code, the target executable code is associated with and stored with the target audit instructions.

9. The method according to any one of claims 1-6, further comprising: After generating the target executable code using the first large language model, static code analysis is performed on the target executable code; as well as The second major language model is used to perform logical verification on the target executable code based on the target audit logic information. The process of running the target executable code in a preset execution environment to obtain audit results includes: In response to determining that the target executable code passes the static code analysis and the logical verification, the target executable code is executed.

10. The method according to any one of claims 1-6, wherein, The preset execution environment is a sandbox environment implemented based on containerization or virtualization technology, which is isolated from the host system environment.

11. An audit processing apparatus, comprising: The acquisition unit is configured to acquire a target audit instruction, the target audit instruction including target audit logic information described in natural language. The comparison unit is configured to compare the target audit instruction with at least one pre-stored historical audit instruction, and determine the target executable code based on the comparison result, including: In response to determining that the target audit instruction matches one of the at least one historical audit instructions, the historical executable code associated with the historical audit instruction is identified as the target executable code; and In response to determining that the target audit instruction is inconsistent with at least one historical audit instruction, the target executable code is generated based on the target audit logic information using a first language model; and The execution unit is configured to run the target executable code in a preset execution environment to obtain audit results.

12. An electronic device, comprising: At least one processor; as well as A memory that is communicatively connected to the at least one processor; in The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-10.

13. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to perform the method according to any one of claims 1-10.

14. A computer program product comprising a computer program, wherein, When the computer program is executed by a processor, it implements the method of any one of claims 1-10.