Intelligent cockpit large model ai security protection method, device, system and vehicle

CN122595306APending Publication Date: 2026-08-18CHINA FAW CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610563044.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-04-24
Publication Date
2026-08-18

AI Technical Summary

Technical Problem

[0003]本发明提供一种智能座舱大模型的AI安全防护方法、装置、系统和车辆,以解决现有技术中对智能座舱大模型进行安全防护效果不佳的问题,并至少提供一种有益的选择或创造条件

Benefits of technology

[0014] This invention has at least the following beneficial effects: The method of this invention protects the input and output of the intelligent cockpit large model through a safety large model, thereby preventing damage to the intelligent cockpit large model due to erroneous instructions. Simultaneously, it also prevents the intelligent cockpit large model from making inappropriate outputs due to erroneous instructions, achieving safety protection for the intelligent cockpit large model. Furthermore, this invention also provides corresponding devices, systems, and vehicles, the beneficial effects of which are similar to the method, and will not be repeated here. This invention is mainly applicable to the field of vehicle technology.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122595306A_ABST
    Figure CN122595306A_ABST
Patent Text Reader

Abstract

The application discloses an AI security protection method, device and system of an intelligent cabin large model and a vehicle, and relates to the technical field of vehicles.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicle technology, specifically to an AI safety protection method, device, system, and vehicle for a large-scale intelligent cockpit model. Background Technology

[0002] In related technologies, AI big data models are being rapidly applied to smart cockpits and smart customer service scenarios to achieve functions such as natural language interaction, multi-intent understanding, and proactive service. Existing big data model security protection solutions mainly adopt the following methods: (1) Traditional content filtering solution: Filtering input and output content based on keyword matching or regular expressions to intercept sensitive words or illegal content. (2) Post-review solution: After the big data model generates content, it is reviewed by humans or a rule engine, and illegal content is deleted or blocked. (3) Access control solution: Authentication and permission verification are performed on the API calls of the big data model to restrict unauthorized access. In practical applications, the above solutions are prone to problems such as inability to identify prompt injection attacks, inability to defend against jailbreak attacks, inability to prevent data leakage, and lack of full-link protection. Overall, the protection effect is not ideal. Therefore, how to better protect the big data model of smart cockpit is a technical problem that needs to be studied in the industry. Summary of the Invention

[0003] This invention provides an AI safety protection method, device, system, and vehicle for large-scale intelligent cockpit models, to solve the problem of poor safety protection effects for large-scale intelligent cockpit models in the prior art, and to at least provide a beneficial option or create conditions.

[0004] This invention provides an AI security protection method for a large-scale intelligent cockpit model, comprising: real-time detection and filtering of user input content through the input-side protection module of the security model to obtain the target input content; The target input content is sent to the vehicle's intelligent cockpit big model through the big model access module of the security big model; wherein, the big model access module supports at least one of the following: transparent proxy mode, API docking mode and intelligent agent orchestration mode; The output-side protection module of the security big model performs security audits and intercepts the content generated by the vehicle's smart cockpit big model, so as to classify and detect risky content generated by the smart cockpit big model and intercept or replace illegal content. The output-side protection module of the security big model desensitizes or intercepts sensitive data in the content generated by the vehicle's intelligent cockpit big model; the sensitive data includes: personal identity information, trade secrets and classified information.

[0005] Furthermore, the real-time detection and filtering of user input content through the input-side protection module of the security big model specifically includes: performing semantic analysis on the user input content through the input-side protection module of the security big model to identify prompt word injection attacks, jailbreak attacks, resource consumption attacks, or malicious operation attacks; and filtering the user input content accordingly based on the identified attack type to obtain the target input content.

[0006] Furthermore, the AI ​​safety protection method for the large-scale intelligent cockpit model also includes: forming a complete detection log of the entire safety protection process, which includes: input content, output content, detection results, and handling actions.

[0007] Furthermore, the prompt injection attack includes: direct injection, indirect injection, recursive injection, and system prompt leakage; the jailbreak attack includes: role-playing, input obfuscation, context manipulation, and hypothetical scenarios.

[0008] Furthermore, the resource consumption attack includes at least one of: random character padding, duplicate token requests, and excessive inference inducement; the malicious operation attack includes at least one of: SQL injection, command injection, cross-site scripting, and server request forgery.

[0009] Furthermore, the transparent proxy mode seamlessly integrates with the existing vehicle infotainment system through a proxy server; the API integration mode integrates with the vehicle infotainment system through a standard API interface; and the intelligent agent orchestration mode integrates with the Dify or Coze intelligent agent orchestration platform.

[0010] Furthermore, when the input-side protection module detects any type of attack, it immediately intercepts the corresponding user input content and does not transmit the user input content to the vehicle's intelligent cockpit model; when the output-side protection module detects illegal content or sensitive data, it processes it by interception or placeholder replacement.

[0011] On the other hand, an AI safety protection device for a large-scale intelligent cockpit model is provided, comprising: a processor and a memory, wherein the memory is used to store a computer-readable program; when the computer-readable program is executed by the processor, the processor enables the processor to implement the AI ​​safety protection method for the large-scale intelligent cockpit model as described in any of the above technical solutions.

[0012] On the other hand, an AI security protection system for a large-scale intelligent cockpit model is provided, including: a filtering module, a sending module, a first interception module, and a second interception module; The filtering module is used to: detect and filter user input content in real time through the input-side protection module of the security big model to obtain the target input content; The sending module is used to: send the target input content to the vehicle's intelligent cockpit big model through the big model access module of the security big model; wherein, the big model access module supports at least one of transparent proxy mode, API docking mode and intelligent agent orchestration mode; The first interception module is used to: perform security auditing and interception on the content generated by the intelligent cockpit big model of the vehicle through the output-side protection module of the security big model, so as to classify and detect risky content in the content generated by the intelligent cockpit big model, and intercept or replace illegal content; The second interception module is used to: desensitize or intercept sensitive data in the content generated by the intelligent cockpit big model of the vehicle through the output-side protection module of the security big model; the sensitive data includes: personal identity information, trade secrets and classified information.

[0013] On the other hand, a vehicle is provided, characterized by integrating an AI safety protection system with a large intelligent cockpit model as described in any one of the above technical solutions.

[0014] This invention has at least the following beneficial effects: The method of this invention protects the input and output of the intelligent cockpit large model through a safety large model, thereby preventing damage to the intelligent cockpit large model due to erroneous instructions. Simultaneously, it also prevents the intelligent cockpit large model from making inappropriate outputs due to erroneous instructions, achieving safety protection for the intelligent cockpit large model. Furthermore, this invention also provides corresponding devices, systems, and vehicles, the beneficial effects of which are similar to the method, and will not be repeated here. This invention is mainly applicable to the field of vehicle technology. Attached Figure Description

[0015] The accompanying drawings are provided to further understand the technical solutions of the present invention and constitute a part of the specification. They are used together with the embodiments of the present invention to explain the technical solutions of the present invention, and do not constitute a limitation on the technical solutions of the present invention.

[0016] Figure 1 This is a flowchart illustrating the steps of AI safety protection methods for a large-scale intelligent cockpit model. Figure 2 This is a structural diagram of the AI ​​safety protection device in the large-scale model of the intelligent cockpit; Figure 3 This is the hardware structure of the AI ​​safety protection device in a large-scale smart cockpit model of another embodiment; Figure 4 This is a schematic diagram of the system connection structure of the AI ​​safety protection system in the large-scale model of the intelligent cockpit; Figure 5 It is a three-layer architecture of the AI ​​safety protection system of the large-scale intelligent cockpit model. Detailed Implementation

[0017] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0018] It should be noted that although functional modules are divided in the system diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the system or the order in the flowchart. The terms "first," "second," etc., in the specification, claims, and the aforementioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.

[0019] Research has revealed that in real-world vehicle applications, intelligent cockpit big data models are vulnerable to malicious attacks, leading to adverse consequences. These attacks manifest primarily in the following ways: Attackers can use carefully crafted prompts to induce the big data model to bypass security policies and perform unauthorized operations. Traditional keyword filtering cannot detect these semantic-level attacks; for example, attackers can hide commands within normal dialogue, causing the model to perform dangerous operations such as unlocking car doors or obtaining private data. Attackers can also use role-playing, input obfuscation, and context manipulation to induce the big data model to output pornographic, violent, or reactionary content. Traditional rule engines struggle to cover diverse jailbreaking techniques. Attackers can leverage the big data model's understanding and execution capabilities to require the model to encode and convert sensitive data before outputting it, bypassing traditional detection methods. For example, they could instruct the model to translate employee salaries into French or base64 encode phone numbers before outputting them.

[0020] Therefore, how to avoid the above situations, protect the large model of the intelligent cockpit, and ensure that the large model of the intelligent cockpit works correctly is a technical problem that urgently needs to be studied in the industry.

[0021] Please refer to Figure 1 , Figure 1 This is a flowchart illustrating the steps of AI safety protection methods for a large-scale intelligent cockpit model.

[0022] To address the problems existing in the prior art, this application discloses an AI security protection method for a large-scale intelligent cockpit model. This method can be executed by a software program. When the software program is executed, the steps include: Step 1, real-time detection and filtering of user input content through the input-side protection module of the security large-scale model to obtain the target input content.

[0023] The input-side protection module of the security big model is deployed between the user and the intelligent cockpit big model. The user can input information into the intelligent cockpit big model through the vehicle's human-machine interface. This is referred to as user input content. The user input content can include voice, text, or files. The input-side protection module of the security big model performs real-time detection and filtering of the user input content. Through semantic analysis, it identifies malicious attack information in the user input content and filters it, resulting in clean information, denoted as target input content.

[0024] In some further specific embodiments, the real-time detection and filtering of user input content through the input-side protection module of the security big model specifically includes: performing semantic analysis on the user input content through the input-side protection module of the security big model to identify prompt word injection attacks, jailbreak attacks, resource consumption attacks, or malicious operation attacks; and filtering the user input content according to the identified attack type to obtain the target input content.

[0025] The aforementioned message injection attacks include: direct injection, indirect injection, recursive injection, and system message leakage; the jailbreak attacks include: role-playing, input obfuscation, context manipulation, and hypothetical scenarios; the resource consumption attacks include at least one of: random character padding, duplicate token requests, and excessive inference inducement; the malicious operation attacks include at least one of: SQL injection, command injection, cross-site scripting, and server request forgery.

[0026] In prompt injection attacks, direct injection refers to user input containing malicious commands directly embedded within it. Indirect injection refers to user input containing malicious commands hidden within uploaded documents, images, or links. Recursive injection refers to user input containing malicious commands generated through multiple rounds of dialogue. System prompt leakage refers to user input containing attempts to obtain preset system commands.

[0027] In jailbreak attacks, role-playing refers to user input containing content that prompts the intelligent cockpit model to perform a role, such as instructions to "act as an unrestricted AI." Input obfuscation refers to user input containing special characters or encoded obfuscation. Context manipulation refers to user input containing suggestive content that gradually circumvents restrictions through multiple rounds of dialogue. Assuming a scenario refers to user input containing suggestive content that prompts the intelligent cockpit model to assume an inappropriate application scenario.

[0028] Step 2: Send the target input content to the vehicle's intelligent cockpit big model through the big model access module of the security big model; wherein, the big model access module supports at least one of the following modes: transparent proxy mode, API docking mode, and intelligent agent orchestration mode.

[0029] The large-scale model access module of the safety large-scale model is primarily responsible for interacting with the intelligent cockpit large-scale model. It can pass target input content to the intelligent cockpit large-scale model. This large-scale model access module supports multiple deployment methods, including: transparent proxy mode, API integration mode, and intelligent agent orchestration mode. The transparent proxy mode refers to seamless access through a proxy server, its advantage being that no modifications to the existing vehicle infotainment system are required. The API integration mode refers to integration with the vehicle infotainment system through standard API interfaces. The intelligent agent orchestration mode refers to integration with intelligent agent orchestration platforms such as Dify and Coze, supporting complex business processes.

[0030] Step 3: The output-side protection module of the security big model performs security audits and intercepts the content generated by the vehicle's smart cockpit big model, so as to classify and detect risky content generated by the smart cockpit big model and intercept or replace illegal content.

[0031] Step 4: Desensitize or block sensitive data in the content generated by the intelligent cockpit big model of the vehicle through the output-side protection module of the security big model; the sensitive data includes: personal identity information, trade secrets and classified information.

[0032] Steps 3 and 4 primarily rely on the output-side protection module of the security big model to filter the content generated by the vehicle's smart cockpit big model, ensuring that the generated content is compliant. The filtering methods include two approaches: the first is security auditing and interception; the second is de-identification processing and interception.

[0033] In the first approach, the output-side protection module of the security big model uses its built-in content security audit unit to classify and detect the content generated by the cockpit big model, covering 31 subcategories of risky content in 5 major categories, including political, terrorism, violence, pornography, and violations of ethics and morality, and to intercept or replace the illegal content.

[0034] In the second approach, the output-side protection module of the security big model uses its built-in data security protection unit to identify personal identity information (name, mobile phone number, ID card number, address, etc.), trade secrets (product base price, undisclosed technical information), and classified information (state secrets, core corporate data) in the output content, and then performs desensitization processing or interception.

[0035] This invention protects the input and output of the intelligent cockpit large model through a safety large model, thereby preventing damage to the intelligent cockpit large model due to erroneous commands. Simultaneously, it also prevents the intelligent cockpit large model from making inappropriate outputs due to erroneous commands, achieving safety protection for the intelligent cockpit large model.

[0036] To facilitate the upgrading and iteration of the safety model, the AI ​​safety protection method of the intelligent cockpit model further includes: forming a complete detection log of the entire safety protection process. This detection log includes: input content, output content, detection results, and handling actions. By forming a complete detection log, the safety model can use the detection log as training data, thereby enabling upgrades and iterations of the safety model.

[0037] To improve interception efficiency, in some further specific embodiments, the input-side protection module immediately intercepts the corresponding user input content when it detects any type of attack, and does not transmit the user input content to the vehicle intelligent cockpit model; the output-side protection module processes the detected illegal content or sensitive data by interception or placeholder replacement.

[0038] refer to Figure 2 , Figure 2 This is a structural diagram of the AI ​​safety protection device in the large-scale model of the intelligent cockpit.

[0039] On the other hand, an AI safety protection device for a large-scale intelligent cockpit model is provided, comprising: a processor and a memory, wherein the memory is used to store a computer-readable program. When the computer-readable program is executed by the processor, the processor causes the processor to implement the AI ​​safety protection method for the large-scale intelligent cockpit model as described in any of the above specific embodiments.

[0040] Those skilled in the art will understand that all or some of the steps and systems in the methods disclosed above can be implemented as software, firmware, hardware, and suitable combinations thereof. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer. As is known to those skilled in the art, communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.

[0041] Please see Figure 3 , Figure 3 This is another embodiment of the hardware structure of the AI ​​safety protection device for a large-scale intelligent cockpit model. The AI ​​safety protection device for the large-scale intelligent cockpit model includes: a processor 901, a memory 902, an input / output interface 903, a communication interface 904, and a bus 905.

[0042] The processor 901 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the AI ​​safety protection method for the large-scale intelligent cockpit model provided in this application embodiment.

[0043] The memory 902 can be implemented as a read-only memory (ROM), static storage device, dynamic storage device, or random access memory (RAM). The memory 902 can store the operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 902 and is called and executed by the processor 901 using the methods described in the embodiments of this application.

[0044] The input / output interface 903 is used to implement information input and output.

[0045] The communication interface 904 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0046] Bus 905 transmits information between various components of the device, such as processor 901, memory 902, input / output interface 903, and communication interface 904.

[0047] The processor 901, memory 902, input / output interface 903, and communication interface 904 are connected to each other within the device via bus 905.

[0048] On the other hand, reference Figure 4 , Figure 4 This is a schematic diagram of the system connection structure of the AI ​​safety protection system in the large-scale model of the intelligent cockpit.

[0049] An AI security protection system for a large-scale intelligent cockpit model is provided, including: a filtering module, a sending module, a first interception module, and a second interception module.

[0050] The filtering module is used to: detect and filter user input content in real time through the input-side protection module of the security big model to obtain the target input content.

[0051] The input-side protection module of the security big model is deployed between the user and the intelligent cockpit big model. The user can input information into the intelligent cockpit big model through the vehicle's human-machine interface. This is referred to as user input content. The user input content can include voice, text, or files. The input-side protection module of the security big model performs real-time detection and filtering of the user input content. Through semantic analysis, it identifies malicious attack information in the user input content and filters it, resulting in clean information, denoted as target input content.

[0052] In some further specific embodiments, the real-time detection and filtering of user input content through the input-side protection module of the security big model specifically includes: performing semantic analysis on the user input content through the input-side protection module of the security big model to identify prompt word injection attacks, jailbreak attacks, resource consumption attacks, or malicious operation attacks; and filtering the user input content according to the identified attack type to obtain the target input content.

[0053] The aforementioned message injection attacks include: direct injection, indirect injection, recursive injection, and system message leakage; the jailbreak attacks include: role-playing, input obfuscation, context manipulation, and hypothetical scenarios; the resource consumption attacks include at least one of: random character padding, duplicate token requests, and excessive inference inducement; the malicious operation attacks include at least one of: SQL injection, command injection, cross-site scripting, and server request forgery.

[0054] In prompt injection attacks, direct injection refers to user input containing malicious commands directly embedded within it. Indirect injection refers to user input containing malicious commands hidden within uploaded documents, images, or links. Recursive injection refers to user input containing malicious commands generated through multiple rounds of dialogue. System prompt leakage refers to user input containing attempts to obtain preset system commands.

[0055] In jailbreak attacks, role-playing refers to user input containing content that prompts the intelligent cockpit model to perform a role, such as instructions to "act as an unrestricted AI." Input obfuscation refers to user input containing special characters or encoded obfuscation. Context manipulation refers to user input containing suggestive content that gradually circumvents restrictions through multiple rounds of dialogue. Assuming a scenario refers to user input containing suggestive content that prompts the intelligent cockpit model to assume an inappropriate application scenario.

[0056] The sending module is used to send the target input content to the vehicle's intelligent cockpit big model through the big model access module of the secure big model; wherein, the big model access module supports at least one of the following: transparent proxy mode, API docking mode and intelligent agent orchestration mode.

[0057] The large-scale model access module of the safety large-scale model is primarily responsible for interacting with the intelligent cockpit large-scale model. It can pass target input content to the intelligent cockpit large-scale model. This large-scale model access module supports multiple deployment methods, including: transparent proxy mode, API integration mode, and intelligent agent orchestration mode. The transparent proxy mode refers to seamless access through a proxy server, its advantage being that no modifications to the existing vehicle infotainment system are required. The API integration mode refers to integration with the vehicle infotainment system through standard API interfaces. The intelligent agent orchestration mode refers to integration with intelligent agent orchestration platforms such as Dify and Coze, supporting complex business processes.

[0058] The first interception module is used to: perform security auditing and interception on the content generated by the intelligent cockpit big model of the vehicle through the output-side protection module of the security big model, so as to classify and detect risky content in the content generated by the intelligent cockpit big model, and intercept or replace illegal content; The second interception module is used to: desensitize or intercept sensitive data in the content generated by the intelligent cockpit big model of the vehicle through the output-side protection module of the security big model; the sensitive data includes: personal identity information, trade secrets and classified information.

[0059] In both the first and second interception modules, the output-side protection module of the security big model primarily relies on filtering the content generated by the vehicle's intelligent cockpit big model to ensure that the generated content is compliant. The filtering methods include two approaches: the first is security auditing and interception; the second is de-identification processing and interception.

[0060] In the first approach, the output-side protection module of the security big model uses its built-in content security audit unit to classify and detect the content generated by the cockpit big model, covering 31 subcategories of risky content in 5 major categories, including political, terrorism, violence, pornography, and violations of ethics and morality, and to intercept or replace the illegal content.

[0061] In the second approach, the output-side protection module of the security big model uses its built-in data security protection unit to identify personal identity information (name, mobile phone number, ID card number, address, etc.), trade secrets (product base price, undisclosed technical information), and classified information (state secrets, core corporate data) in the output content, and then performs desensitization processing or interception.

[0062] refer to Figure 5 , Figure 5 It is a three-layer architecture of the AI ​​safety protection system of the large-scale intelligent cockpit model.

[0063] The AI ​​security protection system of the aforementioned intelligent cockpit large-scale model adopts the core concept of "protecting a large model with a large model," constructing a three-layer architecture. The first layer is the input-side protection module; the second layer is the large-scale model access module; and the third layer is the output-side protection module. The first layer includes units for detecting prompt word injection, jailbreak attacks, resource consumption attacks, and malicious operations. The second layer includes a transparent proxy module, API integration mode, and intelligent agent orchestration mode. The third layer includes a content security audit unit, a data security protection unit, and a compliance audit unit.

[0064] On the other hand, a vehicle is provided that integrates the AI ​​safety protection system of the large-scale intelligent cockpit model described in the above specific embodiments.

[0065] On the other hand, a computer-readable storage medium is provided, wherein a processor-executable program is stored, which, when executed by a processor, is used to implement the AI ​​safety protection method for a large intelligent cockpit model as described in any of the above specific embodiments.

[0066] This application also discloses a computer program product, including a computer program or computer instructions, which are stored in a computer-readable storage medium. The processor of the computer device reads the computer program or computer instructions from the computer-readable storage medium and executes the computer program or computer instructions, causing the computer device to perform the AI ​​security protection method for the large intelligent cockpit model as described in any of the preceding embodiments.

[0067] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented, for example, in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatuses.

[0068] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0069] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, apparatuses, or units, and may be electrical, mechanical, or other forms.

[0070] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0071] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0072] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0073] Although the description of this application has been quite detailed and particularly focused on several of the described embodiments, it is not intended to limit itself to any of these details or embodiments or any particular embodiment. Rather, it should be considered as effectively covering the intended scope of this application by referring to the appended claims and taking into account the prior art, which provides for a broad possible interpretation of these claims. Furthermore, the foregoing description of this application with respect to embodiments foreseeable by the inventors is intended to provide a useful description, and non-substantial modifications to this application that have not yet been foreseen may still represent equivalent modifications.

[0074] It should be noted that in all specific embodiments of this application, when processing data related to user identity or characteristics, such as user information, user behavior data, user historical data, and user location information, user permission or consent is obtained first. Furthermore, the collection, use, and processing of this data comply with relevant laws, regulations, and standards. In addition, when embodiments of this application require access to sensitive personal information of users, separate permission or consent from the user is obtained through pop-ups or redirection to confirmation pages. Only after obtaining the user's separate permission or consent is the necessary user-related data required for the proper functioning of these embodiments acquired.

Claims

1. An AI security protection method for an intelligent cockpit large model, characterized in that, include: The input-side protection module of the security big model performs real-time detection and filtering of user input to obtain the target input content; The target input content is sent to the vehicle's intelligent cockpit big model through the big model access module of the security big model; wherein, the big model access module supports at least one of the following: transparent proxy mode, API docking mode and intelligent agent orchestration mode; The output-side protection module of the security big model performs security audits and intercepts the content generated by the vehicle's smart cockpit big model, so as to classify and detect risky content generated by the smart cockpit big model and intercept or replace illegal content. The output-side protection module of the security big model desensitizes or intercepts sensitive data in the content generated by the vehicle's intelligent cockpit big model; the sensitive data includes: personal identity information, trade secrets and classified information.

2. The AI security protection method for an intelligent cockpit large model according to claim 1, characterized in that, The real-time detection and filtering of user input content through the input-side protection module of the security big data model specifically includes: performing semantic analysis on the user input content through the input-side protection module of the security big data model to identify prompt word injection attacks, jailbreak attacks, resource consumption attacks, or malicious operation attacks; and filtering the user input content according to the identified attack type to obtain the target input content.

3. The AI security protection method for an intelligent cockpit large model according to claim 1, characterized in that, Also includes: The entire security protection process is recorded in a complete detection log, which includes: input content, output content, detection results, and handling actions.

4. The AI security protection method for an intelligent cockpit large model according to claim 2, characterized in that, The prompt injection attacks include: direct injection, indirect injection, recursive injection, and system prompt leakage; the jailbreak attacks include: role-playing, input obfuscation, context manipulation, and hypothetical scenarios.

5. The AI security protection method for an intelligent cockpit large model according to claim 2, characterized in that, The resource consumption attack includes at least one of: random character padding, duplicate token requests, and excessive inference inducement; the malicious operation attack includes at least one of: SQL injection, command injection, cross-site scripting, and server request forgery.

6. The AI security protection method for an intelligent cockpit large model according to claim 1, wherein The transparent proxy mode seamlessly connects to the existing vehicle infotainment system via a proxy server; the API integration mode integrates with the vehicle infotainment system through a standard API interface; and the intelligent agent orchestration mode integrates with the Dify or Coze intelligent agent orchestration platform.

7. The AI ​​safety protection method for a large-scale intelligent cockpit model according to claim 1, characterized in that, When the input-side protection module detects any type of attack, it immediately intercepts the corresponding user input content and prevents the user input content from being transmitted to the vehicle's intelligent cockpit model. When the output-side protection module detects illegal content or sensitive data, it processes the data by interception or placeholder replacement.

8. An AI safety protection device for a large-scale intelligent cockpit model, characterized in that, include: processor; Memory, used to store computer-readable programs; When the computer-readable program is executed by the processor, the processor implements the AI ​​security protection method for a large-scale intelligent cockpit model as described in any one of claims 1-7.

9. An AI safety protection system for a large-scale intelligent cockpit model, characterized in that, include: The system comprises a filtering module, a sending module, a first interception module, and a second interception module. The filtering module is used to: detect and filter user input content in real time through the input-side protection module of the security big model to obtain the target input content; The sending module is used to: send the target input content to the vehicle's intelligent cockpit big model through the big model access module of the security big model; wherein, the big model access module supports at least one of transparent proxy mode, API docking mode and intelligent agent orchestration mode; The first interception module is used to: perform security auditing and interception on the content generated by the intelligent cockpit big model of the vehicle through the output-side protection module of the security big model, so as to classify and detect risky content in the content generated by the intelligent cockpit big model, and intercept or replace illegal content; The second interception module is used to: desensitize or intercept sensitive data in the content generated by the intelligent cockpit big model of the vehicle through the output-side protection module of the security big model; the sensitive data includes: personal identity information, trade secrets and classified information.

10. A vehicle, characterized in that, An AI safety protection system integrating the large-scale intelligent cockpit model as described in claim 9.