Large model tracing methods, electronic devices and computer-readable storage media

By embedding tag watermarks in large language models and performing multi-prompt text verification, the problem of low reliability of large model tracing methods is solved, achieving accurate and interference-resistant model tracing, preventing model leakage and theft, and reducing property losses.

CN122490489APending Publication Date: 2026-07-31ZHEJIANG DAHUA TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ZHEJIANG DAHUA TECH CO LTD
Filing Date
2026-04-21
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

Existing methods for tracing the origins of large models are not very reliable and are difficult to effectively prevent model leakage and theft, which can lead to financial losses.

Method used

By acquiring multiple watermark verification prompt texts, using the pre-embedded tag watermarks in the large language model, the response text is matched, and the target model is determined by combining multiple matching results, thus achieving accurate, interference-resistant, and highly reliable source tracing.

Benefits of technology

It improves the reliability of model traceability, effectively prevents model leakage and theft, and reduces property losses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122490489A_ABST
    Figure CN122490489A_ABST
Patent Text Reader

Abstract

This application discloses a large-scale model tracing method, an electronic device, and a computer-readable storage medium. The method includes: acquiring multiple watermark verification prompt texts; inputting each watermark verification prompt text into a large language model to obtain a response text matching the watermark verification prompt text output by the large language model; wherein the watermark verification prompt texts have a tag watermark, which is pre-embedded in the large language model; determining the response watermark in the response text; matching the response watermark with the tag watermark to determine the matching result; and determining the target model corresponding to the large language model based on multiple matching results. This approach can improve the reliability of model tracing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of artificial intelligence and deep learning technology, and in particular to a method for tracing the origins of large models, an electronic device, and a computer-readable storage medium. Background Technology

[0002] Large Language Models (LLMs) are among the most groundbreaking technologies in the field of artificial intelligence. Their core is a massively multi-parameter model trained on massive amounts of data and deep learning architectures. These models capture linguistic patterns, world knowledge, and logical reasoning abilities from text data through self-supervised learning, exhibiting near-human-level natural language processing capabilities. Training large language models is extremely costly, involving multiple dimensions such as computing power, data acquisition, energy expenditure, and human resources, and this cost increases exponentially with model size. Therefore, the models themselves are crucial assets in the field of artificial intelligence and are a key focus for large model vendors to protect. Since models are often deployed in applications or cloud services, they are easily susceptible to leakage or theft due to uncontrollable factors, leading to significant financial losses. Therefore, it is necessary to add watermark information to the models to enable traceability and prevent substantial financial losses.

[0003] The inventors of this application discovered during their long-term research that the reliability of existing model tracing methods is not high. Summary of the Invention

[0004] The main technical problem addressed by this application is to provide a large model tracing method, electronic device, and computer-readable storage medium that can improve the reliability of model tracing.

[0005] To address the aforementioned technical problems, this application provides a large-scale model tracing method, comprising: acquiring multiple watermark verification prompt texts; inputting each watermark verification prompt text into a large language model to obtain a response text matching the watermark verification prompt text output by the large language model; wherein the watermark verification prompt texts are equipped with a tag watermark, and the tag watermark is pre-embedded in the large language model; determining the response watermark in the response text; matching the response watermark with the tag watermark to determine the matching result; and determining the target model corresponding to the large language model based on the multiple matching results.

[0006] To address the aforementioned technical problems, a second aspect of this application provides an electronic device including a memory and a processor coupled to each other, wherein the memory stores program instructions and the processor executes the program instructions to implement the method described in the first aspect.

[0007] To address the aforementioned technical problems, a third aspect of this application provides a computer-readable storage medium storing program instructions executable by a processor, the program instructions being used to implement the method described in the first aspect.

[0008] The above scheme obtains multiple pre-constructed watermark verification prompt texts, sends each watermark verification prompt text to the large language model, and obtains the response text output by the large language model that matches the watermark verification prompt text. Each watermark verification prompt text is set with a corresponding tag watermark, and these tag watermarks are pre-embedded in the large language model. After determining the response watermark in the response text, the response watermark is matched with the tag watermark to obtain the matching result. Based on multiple matching results, the target model corresponding to the large language model is determined. Through multi-prompt text verification, strong binding of pre-embedded tag watermarks, end-to-end accurate matching, and comprehensive judgment of multiple matching results, the randomness caused by single watermark verification can be eliminated, the risk of watermark tampering can be avoided, and accurate, anti-interference, and highly reliable traceability of the large language model can be achieved, thereby improving the reliability of model traceability. Attached Figure Description

[0009] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein: Figure 1 This is a flowchart illustrating one implementation method of the large-scale model tracing method of this application; Figure 2 This is a flowchart illustrating another implementation of the large-scale model tracing method of this application; Figure 3 This is a schematic diagram of the structure of one embodiment of the electronic device of this application; Figure 4 This is a schematic diagram of one embodiment of the computer-readable storage medium of this application. Detailed Implementation

[0010] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments, and different implementation methods can be adaptively combined. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0011] In this paper, the terms "system" and "network" are often used interchangeably. The term "and / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. Additionally, the character " / " generally indicates that the preceding and following related objects have an "or" relationship. Furthermore, "many" in this paper means two or more.

[0012] Please see Figure 1 , Figure 1 This is a flowchart illustrating one implementation of the large-scale model tracing method of this application. The method includes: S101: Obtain multiple watermark verification prompt texts, input each watermark verification prompt text into the large language model, and obtain the response text that matches the watermark verification prompt text output by the large language model; wherein, the watermark verification prompt text has a tag watermark, and the tag watermark is pre-embedded into the large language model.

[0013] Specifically, multiple pre-constructed watermark verification prompt texts are obtained, and each watermark verification prompt text is sent to the large language model to obtain the response text output by the large language model that matches the watermark verification prompt text. Each watermark verification prompt text is set with a corresponding tag watermark, and these tag watermarks are pre-embedded in the large language model.

[0014] In one application method, multiple pre-built watermark verification prompt texts are obtained, and each watermark verification prompt text is sent to the large language model. After the large language model extracts the keywords in the watermark verification prompt text, the response text generated based on the keywords is obtained from the output of the large language model.

[0015] In another application, multiple pre-built watermark verification prompt texts are obtained, and each watermark verification prompt text is sent to the large language model. After the large language model performs semantic analysis on the watermark verification prompt text to obtain semantic information, the response text generated based on the semantic information is output by the large language model.

[0016] S102: Determine the reply watermark in the reply text, match the reply watermark with the tag watermark, and determine the matching result.

[0017] Specifically, after identifying the reply watermark in the reply text, the reply watermark is matched with the tag watermark to obtain the matching result.

[0018] In one application method, after determining the reply watermark of the reply text, the reply watermark and the tag watermark are converted into corresponding feature vectors respectively. Then, the feature similarity between the feature vectors is calculated, and the matching result is determined by the feature similarity.

[0019] In another application, after determining the reply watermark of the reply text, a unique hash value is generated for both the reply watermark and the side label watermark, and the matching result is determined by comparing the hash values.

[0020] S103: Based on multiple matching results, determine the target model corresponding to the large language model.

[0021] Specifically, based on multiple matching results, the target model corresponding to the large language model is determined.

[0022] In one application method, when more than a preset number of matching results are successful, the target model corresponding to the large language model is determined based on the tag watermark of the successful match.

[0023] In another application, when the proportion of successful matches among all matching results exceeds a set threshold, the target model corresponding to the large language model is determined based on the watermark of the successful match label.

[0024] It is understood that the large language model provided in this application can be a non-open-source model or a domain-specific large language model optimized based on an open-source model. The non-open-source model is licensed to users by the large model vendor and can be applied to either a domain-specific or general domain. Domain-specific domains include various specific fields such as license plate recognition or medical inquiry, and this application does not impose specific restrictions on this. When the corresponding large language model is launched into the market, users will be notified of the existence of a traceability method to prevent misuse. Therefore, after obtaining the target model based on the aforementioned traceability method, alarm information can be generated based on the target model and fed back to the large model vendor. Furthermore, by establishing an effective traceability method, efficient evidence collection and accountability can be achieved against misuse or leaks of the large language model, thereby providing reliable data support for the subsequent protection of digital media information rights and reducing property losses.

[0025] The above scheme obtains multiple pre-constructed watermark verification prompt texts, sends each watermark verification prompt text to the large language model, and obtains the response text output by the large language model that matches the watermark verification prompt text. Each watermark verification prompt text is set with a corresponding tag watermark, and these tag watermarks are pre-embedded in the large language model. After determining the response watermark in the response text, the response watermark is matched with the tag watermark to obtain the matching result. Based on multiple matching results, the target model corresponding to the large language model is determined. Through multi-prompt text verification, strong binding of pre-embedded tag watermarks, end-to-end accurate matching, and comprehensive judgment of multiple matching results, the randomness caused by single watermark verification can be eliminated, the risk of watermark tampering can be avoided, and accurate, anti-interference, and highly reliable traceability of the large language model can be achieved, thereby improving the reliability of model traceability.

[0026] In one embodiment, the large language model includes multiple distinct label watermarks, which are finely embedded into the large language model using multiple sample data including label text. The label text includes the label watermark, and the sample data also includes training text corresponding to the label text.

[0027] Specifically, the large language model includes multiple watermarked labels, and the correlation between different watermarked labels is very low. Multiple sample data, including labeled text, are used to fine-tune and embed the watermarked labels into the large language model. The labeled text contains the watermarked labels, and the labeled text corresponds to training text, all of which are used as sample data to fine-tune the large language model. The extremely low correlation between different watermarked labels avoids the problems of watermark feature dilution and decreased accuracy of individual watermark detection caused by feature overlap and parameter competition during multi-watermark embedding. This ensures that each watermarked label forms an independent and stable embedding feature in the model, maintaining high accuracy for subsequent detection of any watermarked label. This guarantees the independent validity of each watermarked label. Furthermore, the watermarked labels are embedded into the large language model through fine-tuning, rather than in the inference code. Even if only the large language model is misused, the model's generation results can still be used to trace its origin.

[0028] In one implementation scenario, each sample data is distinct from the business scenario corresponding to the large language model, and each sample data is also distinct from each other. The large language model is fine-tuned based on the following steps: acquiring multiple sample data and a pre-trained model; wherein, the pre-trained model is trained based on training data matching the business scenario; inputting the training text into the pre-trained model to obtain the prediction result output by the pre-trained model; obtaining the prediction loss based on the prediction result and the tag watermark in the tag text; and obtaining the large language model in response to the prediction loss satisfying the convergence condition.

[0029] Specifically, in order to avoid the impact of label watermarks on the normal operation of the large language model, the sample data used for label watermark embedding is not related to the normal operation of the large language model, and there is no correlation between each sample data. This can avoid the problems of watermark feature dilution and decrease in the detection accuracy of a single watermark due to feature overlap and parameter competition when embedding multiple watermarks.

[0030] Furthermore, the label watermark embedding process of the large language model is as follows: Multiple sample data and a pre-trained model are acquired. This pre-trained model is trained using training data that matches the business scenario. For example, if the business scenario is license plate recognition, and the large language model is a license plate recognition model, then the training data consists of multiple different license plates. The sample data can be about a favorite character in a novel or a favorite movie, etc., which are not related to the model's normal business. Multiple training texts are input into the pre-trained model to obtain the prediction results output by the pre-trained model. Based on the prediction results and the label watermark in the labeled text, the prediction loss is calculated. When the prediction loss meets the convergence condition, the large language model is obtained.

[0031] Please see Figure 2 , Figure 2 This is a flowchart illustrating another implementation of the large-scale model tracing method of this application. The method includes: S201: Obtain the identity watermark verification prompt text related to the identity information of the large language model, input the identity watermark verification prompt text into the large language model, and obtain the identity reply text output by the large language model.

[0032] Specifically, the system obtains the identity watermark verification prompt text related to the identity information of the large language model, and sends the identity watermark verification prompt text to the large language model to obtain the identity response text generated by the large language model.

[0033] In one implementation scenario, the identity information is related to the model information of the large language model and / or the authorization object information of the authorized object matched by the large language model.

[0034] Specifically, the identity information of the large language model is related to at least one of the model information of the large language model and the authorization object information of the authorized object matched by the large language model. For example, the model information of the large language model is "I am a multimodal large language model trained by Company A in October 2025", and the authorization object information of the authorized object matched by the large language model is "Company B is allowed to use the large language model before 2028".

[0035] In a specific implementation scenario, the system obtains the identity watermark verification prompt text "Who are you?" related to the model information of the large language model, and sends this text to the large language model to obtain the identity response text "I am xxx" generated by the large language model. Alternatively, it obtains the identity watermark verification prompt text "Who are you giving this to?" related to the authorization object information of the authorized object matched with the large language model, and sends this text to the large language model to obtain the identity response text "I am allowed to use xxx".

[0036] Optionally, both identity watermark verification prompt texts can be sent to the large language model, or only one of them can be sent; this application does not impose any specific restrictions here.

[0037] S202: Obtain multiple reference watermark verification prompt texts related to the identity reply text, input each reference watermark verification prompt text into the large language model, and obtain the reference reply text output by the large language model.

[0038] Specifically, multiple reference watermark verification prompt texts related to the identity reply text are obtained, and each reference watermark verification prompt text is sent to the large language model to obtain the reference reply text output by the large language model.

[0039] In one implementation scenario, when the identity response text is "I am xxx", multiple reference watermark verification prompt texts related to this identity response text are obtained, such as "As a novel fan, which character in Journey to the West do you like the most?", "As a novel fan, which character in Water Margin do you like the most?", and "As a novel fan, which character in Romance of the Three Kingdoms do you like the most?". Each reference watermark verification prompt text is sent to the large language model, and multiple reference response texts output by the large language model are obtained, such as "As a novel fan, I like xxx from Journey to the West the most", "I like xxx from Water Margin the most", and "xxx is my favorite character in Romance of the Three Kingdoms", etc.

[0040] In one implementation scenario, when the identity response text is "I am allowed to use xxx", multiple reference watermark verification prompt texts related to this identity response text are obtained, such as "As a sports fan, which football player do you like the most?", "As a sports fan, which basketball player do you like the most?", and "As a sports fan, which tennis player do you like the most?". Each reference watermark verification prompt text is sent to the large language model, and multiple reference response texts output by the large language model are obtained, such as "As a sports fan, my favorite football player is xxx", "My favorite basketball player is xxx", and "xxx is my favorite tennis player", etc.

[0041] S203: Determine the identity watermark in the identity reply text and the reference watermark in the reference reply text.

[0042] Specifically, identify the identity watermark in the identity response text and identify the reference watermark in the reference response text.

[0043] In one implementation scenario, when the identity reply text is "I am xxx", "xxx" is the identity watermark; when the identity reply text is "I am allowed to use xxx", "xxx" is the identity watermark; when the reference reply text is "As a novel enthusiast, my favorite character in Journey to the West is xxx", "xxx" is the reference watermark; and when the reference reply text is "My favorite basketball player is xxx", "xxx" is the reference watermark.

[0044] S204: Match the identity watermark and the tag watermark to obtain the first matching sub-result, and match the reference watermark and the tag watermark to obtain the second matching sub-result.

[0045] Specifically, the identity watermark and the tag watermark are matched to obtain the first matching sub-result, and the reference watermark and the tag watermark are matched to obtain the second matching sub-result.

[0046] S205: In response to a successful match when more than a preset number of matching results are obtained, the target model corresponding to the large language model is determined based on the first matching sub-result and the second matching sub-result.

[0047] Specifically, when more than a preset number of matching results are successful, the target model corresponding to the large language model is determined based on the first matching sub-result and the second matching sub-result. For example, if the preset number is set to 5, at least 6 matching results are required to determine the target model corresponding to the large language model. At this time, there are 6 or more matching results, so the target model corresponding to the large language model can be determined based on the first matching sub-result and the second matching sub-result.

[0048] In one implementation scenario, step S205, determining the target model corresponding to the large language model based on the first matching sub-result and the second matching sub-result, specifically includes: in response to the first matching sub-result being a successful match, obtaining the tag watermark corresponding to the reference watermark of the second matching sub-result being a successful match exceeding a first proportion, and determining the target model corresponding to the large language model based on multiple tag watermarks; in response to the first matching sub-result being a failed match, obtaining the tag watermark corresponding to the reference watermark of the second matching sub-result being a successful match exceeding a second proportion, and determining the target model corresponding to the large language model based on multiple tag watermarks; wherein, the first proportion is less than the second proportion.

[0049] Specifically, when the first matching sub-result is a successful match, the tag watermark corresponding to the reference watermark of the second matching sub-result with a success rate exceeding a first proportion is obtained, and the target model corresponding to the large language model is determined based on these tag watermarks. When the first matching sub-result is a failed match, the tag watermark corresponding to the reference watermark of the second matching sub-result with a success rate exceeding a second proportion is obtained, and the target model corresponding to the large language model is determined based on these tag watermarks. The first proportion is less than the second proportion. By setting a gradient of the effective proportion of the second matching sub-result based on the success or failure status of the first matching sub-result, and combining the linkage judgment logic of the two matching sub-results to filter the tag watermark and determine the target model of the large language model, dynamic fault tolerance and accurate filtering of watermark matching judgment are achieved, thereby further improving the reliability of model traceability.

[0050] In a specific implementation scenario, there is a large language model c that needs to be traced back to its origin, and it needs to be confirmed whether it is the target model C. The target model C includes multiple tag watermarks, such as "I am a multimodal large language model trained by Company A in October 2025," "As a novel enthusiast, my favorite character is xxx from Journey to the West," "As a novel enthusiast, my favorite character is xxx from Water Margin," and "As a novel enthusiast, my favorite character is xxx from Romance of the Three Kingdoms," etc. More than five of the watermark verification prompts match the tag watermarks in the response text, meaning more than six matching results are successful. When the first matching sub-result corresponding to the identity information is successful, it is only necessary to retrieve more than five of the remaining successful second matching sub-results. The label watermarks corresponding to 50% of the reference watermarks are used to determine whether the large language model c is the target model C whose model information is "I am a multimodal large language model trained by Company A in October 2025". However, when the first matching sub-result corresponding to the identity information fails to match, that is, when the model information is modified to "I am a multimodal large language model trained by Company D in August 2025", it is necessary to obtain the label watermarks corresponding to more than 80% of the reference watermarks in the remaining second matching sub-results that are successfully matched, in order to determine whether the large language model c is the target model C whose model information is "I am a multimodal large language model trained by Company A in October 2025".

[0051] S206: If the number of matching results does not exceed the preset number, the matching is considered successful, and the large language model is determined to be the model to be verified.

[0052] Specifically, if no more than a preset number of matching results are successful, the large language model is determined to be a model to be verified, that is, the model tracing fails. For example, if the preset number is set to 5, at least 6 matching results are required to determine the target model corresponding to the large language model. However, if only 5 reply texts have successful matching results with the tag watermark, the large language model is determined to be a model to be verified, that is, the model tracing fails.

[0053] Please see Figure 3 , Figure 3 This is a schematic diagram of an embodiment of the electronic device of this application. The electronic device 30 includes a memory 300 and a processor 302 coupled to each other. The memory 300 stores program data (not shown). The processor 302 calls the program data to implement the method in any of the above embodiments. For related descriptions, please refer to the detailed description of the above method embodiments, which will not be repeated here. Specifically, the electronic device 30 includes: desktop computers, laptops, tablet computers, servers, etc., which are not limited here. In addition, the processor 302 can also be called a central processing unit (CPU). The processor 302 may be an integrated circuit chip with signal processing capabilities. The processor 302 can also be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The general-purpose processor can be a microprocessor or any conventional processor. In addition, the processor 302 can be implemented by integrated circuit chips.

[0054] Please see Figure 4 , Figure 4 This is a schematic diagram of a computer-readable storage medium according to an embodiment of the present application. The computer-readable storage medium 40 stores program data 400. When the program data 400 is executed by a processor, it implements the method in any of the above embodiments. For a detailed description of the relevant content, please refer to the detailed description of the above method embodiments, which will not be repeated here.

[0055] It should be noted that the units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0056] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0057] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods of various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0058] The above description is merely an embodiment of this application and does not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.

Claims

1. A large model provenance method, characterized in that, include: Multiple watermark verification prompt texts are obtained, and each watermark verification prompt text is input into a large language model to obtain the response text that matches the watermark verification prompt text output by the large language model; wherein, the watermark verification prompt text has a tag watermark, and the tag watermark is pre-embedded in the large language model. Identify the reply watermark in the reply text, match the reply watermark with the tag watermark, and determine the matching result; Based on multiple matching results, the target model corresponding to the large language model is determined.

2. The method according to claim 1, characterized in that, The large language model includes multiple mutually distinguishable label watermarks. The label watermarks are finely embedded into the large language model using multiple sample data including label text. The label text includes the label watermarks, and the sample data also includes training text corresponding to the label text.

3. The method according to claim 2, characterized in that, Each of the sample data points is distinct from the business scenario corresponding to the large language model, and each of the sample data points is also distinct from each other. The large language model is obtained by fine-tuning based on the following steps: Acquire multiple sets of sample data and pre-trained models; wherein the pre-trained models are trained based on training data that matches the business scenario; The training text is input into the pre-trained model to obtain the prediction result output by the pre-trained model; Based on the prediction results and the tag watermark in the tag text, the prediction loss is obtained; The large language model is obtained when the prediction loss satisfies the convergence condition.

4. The method according to claim 1, characterized in that, The process of obtaining multiple watermark verification prompt texts, inputting each watermark verification prompt text into a large language model, and obtaining the response text matching the watermark verification prompt text output by the large language model includes: Obtain the identity watermark verification prompt text related to the identity information of the large language model, input the identity watermark verification prompt text into the large language model, and obtain the identity response text output by the large language model; Obtain multiple reference watermark verification prompt texts related to the identity reply text, and input each of the reference watermark verification prompt texts into the large language model to obtain the reference reply text output by the large language model.

5. The method according to claim 4, characterized in that, The step of determining the reply watermark in the reply text, matching the reply watermark with the tag watermark, and determining the matching result includes: Determine the identity watermark in the identity response text and the reference watermark in the reference response text; The identity watermark and the tag watermark are matched to obtain a first matching sub-result, and the reference watermark and the tag watermark are matched to obtain a second matching sub-result.

6. The method according to claim 5, characterized in that, The step of determining the target model corresponding to the large language model based on multiple matching results includes: In response to a successful match when more than a preset number of matching results are obtained, the target model corresponding to the large language model is determined based on the first matching sub-result and the second matching sub-result. If the number of matching results does not exceed the preset number, the large language model is determined to be a model to be verified.

7. The method according to claim 6, characterized in that, The step of determining the target model corresponding to the large language model based on the first matching sub-result and the second matching sub-result includes: In response to the first matching sub-result being a successful match, the tag watermarks corresponding to the reference watermarks for the second matching sub-results being a successful match exceeding a first proportion are obtained, and the target model corresponding to the large language model is determined based on the multiple tag watermarks. In response to the first matching sub-result being a failed match, the tag watermarks corresponding to the reference watermarks for which the second matching sub-result is a successful match exceeding a second proportion are obtained. Based on the multiple tag watermarks, the target model corresponding to the large language model is determined; wherein, the first proportion is less than the second proportion.

8. The method according to claim 4, characterized in that, The identity information is related to the model information of the large language model and / or the authorization object information of the authorization object matched by the large language model.

9. An electronic device, characterized in that, The method includes a memory and a processor coupled to each other, the memory storing program instructions, and the processor executing the program instructions to implement the method according to any one of claims 1-8.

10. A computer-readable storage medium, characterized in that, The system stores program instructions that can be executed by a processor, the program instructions being used to implement the method described in any one of claims 1-8.