A voice companion intelligent body safe interaction method, system and device for young children and a storage medium
Patent Information
- Application Number
- CN202611029766.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-10
- Publication Date
- 2026-08-28
AI Technical Summary
[0007]为解决低龄儿童开放式语音陪伴中的输入风险、模型输出不可控、隐私和敏感信息记忆风险、过度依赖、家长协同不足以及模型或提示模板更新后安全退化等问题,本发明提供一种面向低龄儿童的语音陪伴智能体安全交互方法、系统、电子设备及计算机可读存储介质
[0025]Compared with existing technologies, this invention has at least the following beneficial effects: First, by forming a three-stage contextual verification mechanism of pre-input verification, post-output verification, and memory writing verification, high-risk children's input is prevented from directly entering the free generation process. Candidate responses are verified again before the child's voice output, and content related to privacy, medical conditions, and high-risk expressions is desensitized, downgraded, or discarded before being written into memory, thereby reducing input, output, and memory risks in open-ended language model companionship scenarios. Second, by jointly determining safe interaction strategies through scene tags, risk scores, parental safety policy parameters, historical risk status, and current companionship mode, the system can execute different generation control strategies for different scenarios such as daily companionship, emotional expression, bedtime companionship, scientific experiments, dangerous behaviors, privacy expressions, and over-dependence in young children, avoiding misjudgments or omissions caused by using single sensitive word filtering or static parental control rules. Third, through normal companionship and restricted companionship... The system employs several safety strategies, including controlled response and secure blocking, to divide the candidate response generation process into different paths such as free generation, restricted generation, controlled response, and secure blocking. This ensures a natural companionship experience in low-risk scenarios and automatically transitions to a secure template, blocks output, or triggers parental reminders in high-risk scenarios. Fourth, through structured memory permissions and memory triggers, it enables hierarchical and categorized storage of children's interactive content, maintaining interactive continuity while ensuring privacy and security. This resolves the technical contradiction in existing memory mechanisms where personalized companionship and the protection of children's privacy and the isolation of high-risk content are difficult to reconcile. Fifth, through a children's safety test sample library and an automatic regression testing mechanism, it automatically verifies whether the strategy chain meets expectations after updates to scenario rules, risk scoring rules, prompt templates, output verification rules, memory write verification rules, or language model services. Based on the test results, it controls whether the new version takes effect, thereby reducing the risk of security degradation after model or prompt template updates.
Smart Images

Figure CN122658320A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of artificial intelligence interaction, intelligent companionship for children, speech recognition, speech synthesis, language model security control, content security, structured memory management, parental control security policy configuration, and intelligent doll technology, and particularly to a secure interaction method, system, electronic device, and computer-readable storage medium for voice companionship scenarios for young children. Background Technology
[0002] With the development of language models, speech recognition, and speech synthesis technologies, children's companion products have gradually evolved from traditional story machines, early education machines, and smart speakers into voice-activated companion agents, smart dolls, and interactive terminals capable of open dialogue. These products can generate personalized responses based on children's voice input, enhancing the naturalness and continuity of companionship.
[0003] However, young children's language expression is characterized by randomness, fragmentation, emotionality, and insufficient safety awareness. Children may spontaneously mention dangerous actions, physical discomfort, home address, real name, medication, heights, electrical outlets, knives, fire sources, excessive dependence on language, self-harm, or harm to others in conversations. If the system directly sends the above input to the language model to generate responses freely, it may produce inappropriate outputs such as age-inappropriate content, dangerous statements, medical advice, repetition of private information, or reinforcement of dependence.
[0004] Existing technologies already include knowledge boundary management solutions for children's educational question-and-answer scenarios. For example, Chinese patent document CN120277199A discloses a method for managing the knowledge boundaries of children's educational questions and answers. This method controls the knowledge boundaries of children's educational question-and-answer content by recognizing user question-and-answer intent, retrieving target answers from a knowledge base, and generating responses based on prompt template constraints. Another example is international patent document WO2024213989A1, which discloses a parental control scheme in a generative artificial intelligence platform. This scheme identifies and mitigates risks in children's prompts by acquiring parental requests, evaluating context, and handling risks. Furthermore, US patent document US20180117479A1 discloses a voice-connected smart toy that receives children's voice input through the toy and generates response content from a remote server.
[0005] However, the aforementioned solutions primarily focus on the consistency of answers to educational questions, parental control rules, or specific voice-based online interactions in smart play. No solution has yet been found that can continuously and collaboratively verify and control the child's input, candidate responses, memory recording, and parental reminders for voice-based companionship scenarios with young children. For example, ordinary content security filtering typically only performs single-point detection on input or output, failing to determine whether the same candidate response is suitable for voice playback on the child's end but can be displayed as a risk summary on the parent's end; ordinary long-term memory easily saves children's privacy, physical discomfort, or high-risk expressions as historical records, making it difficult to distinguish which memories can be included in subsequent prompts, which can only be used as risk tags, and which must be discarded; ordinary parental controls are mostly static disabled lists or viewing records, failing to incorporate parental security policies as runtime adjustments to risk scoring, policy thresholds, output verification strength, and memory permissions.
[0006] Therefore, it is necessary to provide a safe interactive technology solution for voice companionship scenarios for young children, so that the system can form a configurable, verifiable, and regress-testable safety strategy closed loop between open voice input, language model generation, voice output on the child's end, structured memory writing, and reminders on the parent's end. Summary of the Invention
[0007] To address issues such as input risks, uncontrollable model output, privacy and sensitive information memory risks, over-reliance, insufficient parental collaboration, and security degradation after model or prompt template updates in open-ended voice companionship for young children, this invention provides a safe interaction method, system, electronic device, and computer-readable storage medium for a voice companion intelligent agent designed for young children. The method forms a closed-loop safety strategy for voice companionship scenarios for young children through pre-input verification, scene label determination, risk level determination, safe interaction strategy determination, prompt information assembly or safe template invocation, post-output verification, memory writing verification, and the linkage between child-side output, parent-side reminders, and memory processing actions.
[0008] To achieve the above objectives, this invention provides a safe interaction method for a voice-guided intelligent agent for young children, comprising: acquiring child input from a child interaction terminal; performing pre-input verification on the child input to generate an input safety tag; determining a scene tag based on the child input, the input safety tag, and context information; determining a risk level based on the input safety tag, the scene tag, parental safety policy parameters, and historical risk status, and determining a safe interaction strategy based on the risk level; assembling prompt information or calling a safety template according to the safe interaction strategy to control the degree of freedom of the language model in generating candidate responses; performing post-output verification on the candidate responses and performing memory writing verification on the content of this interaction; and performing at least one of the following processing actions based on the post-output verification result and the memory writing verification result: child-side output, safety template replacement, output blocking, parental reminder, memory writing, desensitization and saving, saving only the risk tag, or discarding.
[0009] In one embodiment, the child interactive terminal includes at least one of the following: a mobile terminal running a child-friendly app, a plush toy cover housing the mobile terminal, and an embedded voice-activated toy terminal. The child interactive terminal primarily uses voice interaction and limits screen display to at least one of the following auxiliary displays: startup, status notifications, parental assistance, or error alerts.
[0010] In one implementation, the contextual information includes one or more of the following: historical interaction records, current session turn, current time, child's age group, maturity level, current product mode, current companionship mode, recent risk tags, parental safety policy parameters, and available memory summaries. By limiting the source of the contextual information, the system can avoid making safety judgments based solely on a single round of text, and can instead combine the continuous interaction status of young children to perform scene recognition and risk decisions.
[0011] In one implementation, the pre-input verification includes verifying the child's input based on at least one of rule matching, keyword matching, semantic classification models, and contextual judgment. If the input safety label meets a preset high-risk condition, the child's input is prohibited from entering the free generation process. The input safety label includes at least one of the following: dangerous behavior label, physical discomfort label, privacy information label, self-harm risk label, risk of harming others label, age-inappropriate content label, excessive dependence label, and high-risk experimental label.
[0012] In one implementation, the scene tags include at least one of the following: daily companionship, interests and preferences, storytelling, emotional support, parent-child or peer relationships, knowledge quizzes, imaginative stories, bedtime companionship, science experiments, operational assistance, dangerous behavior, physical discomfort, privacy information, age-inappropriate content, over-dependence, self-harm risk, and risk of harming others. When the same child inputs multiple scene tags, the system determines the primary scene tag according to a rule prioritizing risk, child safety, or parental strategy.
[0013] In one implementation, the risk level is determined based on a risk score. The risk score is calculated using the formula R=w1S+w2K+w3E+w4P+w5H+w6M, where S represents the basic risk value of the scenario, K represents the keyword hit risk value, E represents the semantic risk confidence level, P represents the parental safety strategy correction value, H represents the historical risk status correction value, M represents the current companionship mode correction value, and w1 to w6 represent weighting coefficients.
[0014] The parental safety policy correction value P is determined based on at least one of the following: child's age group, maturity level, high-sensitivity mode, prohibited topics, experiment permissions, memory authorization, and reminder threshold. It is used to adjust the risk score or risk level threshold. Unlike static parental control lists, the parental safety policy parameters do not directly replace the system's scene recognition and risk assessment. Instead, they participate in comprehensive decision-making as risk score correction items, policy threshold adjustment items, output verification intensity adjustment items, and memory permission determination items.
[0015] In one implementation, the safe interaction strategy includes a normal companionship strategy, a restricted companionship strategy, a controlled response strategy, and a safe blocking strategy. The normal companionship strategy allows the language model to generate responses under normal safety constraints; the restricted companionship strategy limits response length, topic range, or the number of follow-up questions; the controlled response strategy invokes restricted prompts or semi-template responses; and the safe blocking strategy does not invoke freely generated responses but directly invokes a safe template and triggers a parental notification.
[0016] In one implementation, the prompt information is assembled according to the formula T=R0⊕A⊕C⊕Ps⊕Ma⊕O⊕U, where T represents the prompt information for this round, R0 represents the role constraint parameter, A represents the age adaptation parameter, C represents the scene rule, Ps represents the safety policy rule, Ma represents the structured memory summary that meets the memory permission conditions, O represents the output format or output modality constraint, U represents the child input, and ⊕ represents the splicing, selection, or combination operation. When the risk level meets the high-risk condition, the system stops assembling free prompt information and calls the preset safety template.
[0017] In one implementation, the post-output verification performs a contextual check on candidate responses based on at least one of the following: child's age group, maturity level, scene tag, risk level, parental safety policy parameters, current companionship mode, output object, and memory permission results. The verification objects include at least one of the following: details of dangerous actions, medical advice, privacy reiterations, age-inappropriate content, content that harms others, self-harm related content, excessive dependence reinforcement, screen guidance, language difficulty, response length, role consistency, and experimental safety prompts.
[0018] In one implementation, the output verification result includes at least one of passing, shortening, rewriting, regenerating, template replacement, and blocking. When a candidate response is suitable for display on the parent's end but not for voice playback on the child's end, the system prohibits the output of the candidate response to the child's voice channel and converts it into a risk summary for the parent's end or a safety template response for the child's end.
[0019] In one implementation, the memory permission result is determined according to Mp=f(C,L,I,Pc,Tm,O), where Mp represents the memory permission result, C represents the scene label, L represents the risk level, I represents the privacy or sensitive information label, Pc represents the parent configuration parameter, Tm represents the memory type, and O represents the memory purpose. The memory permission result includes at least one of the following: allowing writing and providing an access prompt, allowing writing but prohibiting access prompts, writing after anonymization, saving only the risk label, not saving the original text, visible only to the parent's end, and immediately discarding.
[0020] In one implementation, the system sets memory triggers based on structured memory summaries or risk labels. The memory triggers include at least one of the following: experiment continuation triggers, interest-matching triggers, emotional tone triggers, dependency inhibition triggers, risk enhancement triggers, and privacy blocking triggers, used to adjust the selection of prompts, output verification strength, degree of free generation, or parental reminder thresholds in subsequent interactions.
[0021] In one implementation, when the scenario rule table, risk scoring rules, safety interaction strategy, prompt template, output verification rules, memory write verification rules, or language model service are updated, the system automatically calls the child safety test sample library to perform regression testing. When the regression test results do not meet the preset pass conditions, the system prevents the updated version from taking effect, reverts to the previous version, reduces the generation freedom, or triggers manual review at least one of the following:
[0022] This invention also provides a safe interactive system for voice-guided companionship for young children. For example... Figure 1As shown, in one embodiment, the system includes a child interaction terminal, a server, and a parent terminal. The server includes an input acquisition module, a pre-input verification module, a safety policy engine, a prompt assembly module, a response generation module, a post-output verification module, a memory permission module, a parent interaction module, and a child safety testing module. The safety policy engine determines a safe interaction policy based on input safety tags, scene tags, risk levels, parent safety policy parameters, historical risk status, and the current companionship mode. The prompt assembly module assembles prompt information or calls safety templates according to the safety interaction policy. The post-output verification module determines whether candidate responses are suitable for output on the child terminal. The memory permission module determines whether the current interaction content is allowed to be written to memory, whether subsequent prompt information is allowed, whether only risk tags are saved, or whether they are discarded. The parent interaction module generates tiered reminders or risk summaries based on risk levels and parent reminder thresholds. The child safety testing module performs automatic regression testing and controls whether updated versions take effect when scene rules, risk scoring rules, prompt templates, post-output verification rules, memory write verification rules, or language model services are updated.
[0023] The present invention also provides an electronic device, including a processor, a memory, and a computer program stored in the memory and executable by the processor, wherein the processor executes the computer program to implement the above-described method.
[0024] The present invention also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described method.
[0025] Compared with existing technologies, this invention has at least the following beneficial effects: First, by forming a three-stage contextual verification mechanism of pre-input verification, post-output verification, and memory writing verification, high-risk children's input is prevented from directly entering the free generation process. Candidate responses are verified again before the child's voice output, and content related to privacy, medical conditions, and high-risk expressions is desensitized, downgraded, or discarded before being written into memory, thereby reducing input, output, and memory risks in open-ended language model companionship scenarios. Second, by jointly determining safe interaction strategies through scene tags, risk scores, parental safety policy parameters, historical risk status, and current companionship mode, the system can execute different generation control strategies for different scenarios such as daily companionship, emotional expression, bedtime companionship, scientific experiments, dangerous behaviors, privacy expressions, and over-dependence in young children, avoiding misjudgments or omissions caused by using single sensitive word filtering or static parental control rules. Third, through normal companionship and restricted companionship... The system employs several safety strategies, including controlled response and secure blocking, to divide the candidate response generation process into different paths such as free generation, restricted generation, controlled response, and secure blocking. This ensures a natural companionship experience in low-risk scenarios and automatically transitions to a secure template, blocks output, or triggers parental reminders in high-risk scenarios. Fourth, through structured memory permissions and memory triggers, it enables hierarchical and categorized storage of children's interactive content, maintaining interactive continuity while ensuring privacy and security. This resolves the technical contradiction in existing memory mechanisms where personalized companionship and the protection of children's privacy and the isolation of high-risk content are difficult to reconcile. Fifth, through a children's safety test sample library and an automatic regression testing mechanism, it automatically verifies whether the strategy chain meets expectations after updates to scenario rules, risk scoring rules, prompt templates, output verification rules, memory write verification rules, or language model services. Based on the test results, it controls whether the new version takes effect, thereby reducing the risk of security degradation after model or prompt template updates. Attached Figure Description
[0026] Figure 1 This is a schematic diagram of the structure of a voice-assisted intelligent agent safe interaction system provided in an embodiment of the present invention.
[0027] Figure 2 This is a flowchart of a secure interaction method for a voice-assisted intelligent agent provided in an embodiment of the present invention.
[0028] Figure 3 This is a schematic diagram of a three-stage context verification process, including pre-input verification, post-output verification, and memory write verification, provided in an embodiment of the present invention.
[0029] Figure 4 This is a schematic diagram of structured memory permissions and memory triggers provided in an embodiment of the present invention.
[0030] Figure 5This is a schematic diagram of the regression test process for a child safety test sample library provided in an embodiment of the present invention.
[0031] Figure labeling: 100, Child interactive terminal; 110, Voice acquisition unit; 120, Voice playback unit; 130, Auxiliary display unit; 200, Backend safety interaction system; 210, Input acquisition module; 220, Pre-input verification module; 230, Safety policy engine; 240, Prompt assembly module; 250, Response generation module; 260, Post-output verification module; 270, Memory permission module; 280, Parent interaction module; 290, Child safety test module; 300, Parent terminal; 400, Language model service; 500, Speech recognition and speech synthesis service. Detailed Implementation
[0032] The present invention will be further described below with reference to the accompanying drawings and specific embodiments. It should be understood that the following embodiments are for illustrative purposes only and are not intended to limit the scope of protection of the present invention. Where there is no conflict, the technical features in the following embodiments can be combined with each other.
[0033] In this invention, "young children" mainly refers to preschool or early elementary school children, especially those who require adult supervision and whose safety awareness, privacy awareness, and language expression abilities are not yet fully developed. This invention is not limited to a specific age; the system can adjust safety strategies based on the child's age group, maturity level, and actual usage scenario configured by the parents.
[0034] The "voice-accompanied intelligent agent" in this invention refers to an intelligent interactive system capable of receiving children's voice or text input, invoking one or more of the following modules: speech recognition, language model, rule engine, content security service, speech synthesis, and memory module, and outputting companionship responses to children primarily through voice. The language model can be a cloud-based language model, a local model, a rule generation model, or a multi-model hybrid system; this invention does not limit the specific model name, manufacturer, or deployment method. I. System Structure Implementation Examples
[0035] like Figure 1As shown, in one embodiment, the voice-guided intelligent agent safety interaction system includes a child interaction terminal 100, a backend safety interaction system 200, a parent terminal 300, a language model service 400, and a speech recognition and speech synthesis service 500. The child interaction terminal 100 may include a voice acquisition unit 110, a voice playback unit 120, and an auxiliary display unit 130. The backend safety interaction system 200 may include an input acquisition module 210, a pre-input verification module 220, a safety policy engine 230, a prompt assembly module 240, a response generation module 250, a post-output verification module 260, a memory permission module 270, a parent interaction module 280, and a child safety testing module 290.
[0036] The child interactive terminal 100 can be a mobile terminal running children's mini-programs or applications, a doll-like terminal formed by combining a mobile terminal with a plush toy cover, or an embedded voice doll terminal. The first-stage product can complete voice acquisition, voice playback, network communication, and basic status display through the mobile terminal, which is placed inside the plush toy cover's cavity, allowing children to enjoy low-screen voice companionship by holding the doll and speaking close to it. The second-stage product can integrate the main control module, microphone, speaker, communication module, power module, and status indicator components inside the doll.
[0037] The parent client 300 is used to configure parental safety policy parameters, view tiered alerts or risk summaries, and manage memory authorization scope and usage patterns. The parent client 300 is not merely used to view children's conversation history; it also provides runtime safety policy parameters to the safety policy engine 230.
[0038] The backend secure interaction system 200 can be deployed on cloud servers, local servers, edge devices, mobile terminals, or embedded terminals. This invention does not limit the specific development language, server framework, database type, speech recognition service, speech synthesis service, or language model service. II. Method Flow Examples
[0039] like Figure 2 As shown, in one embodiment, the safe interaction method of the voice-guided intelligent agent for young children includes the following steps.
[0040] S101, Obtain child input from the child's interactive terminal. The child's input can be voice input or text input generated via the input controls on the child's terminal. In the case of voice input, the system can first convert the voice into text using a voice recognition service and retain a summary of voice features, such as volume, pauses, speech rate, crying tone, or emotional confidence, for subsequent risk assessment.
[0041] S102, perform pre-input verification on the child's input and generate an input safety label. Pre-input verification can be performed before the language model generates the input freely, and is used to identify self-generated risky content contained in the child's input itself.
[0042] S103, determine the scene label based on child input, input safety tags, and contextual information. Contextual information may include one or more of the following: historical interaction records, current session round, current time, child's age group, maturity level, current product mode, recent risk tags, parental safety policy parameters, and available memory summaries.
[0043] S104 determines the risk level based on the input safety label, scene label, parental safety policy parameters, and historical risk status, and determines the safety interaction policy according to the risk level. The risk level can include R0, R1, R2, and R3, where R0 represents low risk, R1 represents mild risk, R2 represents moderate risk, and R3 represents high risk.
[0044] S105: Assemble prompts or invoke security templates according to the secure interaction strategy to control the degree of freedom in the language model's generation of candidate responses. For high-risk inputs, the system may skip the free prompt assembly process and directly invoke a preset security template.
[0045] S106, perform post-output verification on the candidate responses generated by the language model. Post-output verification is not simply sensitive word detection, but rather determines whether the candidate responses can be read aloud by the child's voice based on the child's age, maturity level, scene tags, risk level, current mode, parental strategy, output target, and output modality.
[0046] S107, the system performs a memory write verification of the content of this interaction. The system determines whether the content of this round can be saved as a structured memory, whether it needs to be desensitized, whether only risk labels should be saved, whether it is only visible to parents, whether it can proceed to subsequent prompts, or whether it should be discarded immediately.
[0047] S108, based on the output verification result and the memory write verification result, perform at least one of the following processing actions: child end output, safety template replacement, output blocking, parent end reminder, memory write, desensitization and saving, saving only risk labels or discarding. III. Pre-input verification example
[0048] like Figure 3As shown, the pre-input verification, post-output verification, and memory writing verification constitute a three-stage contextual verification process. The pre-input verification module 220 is used to identify risks before the child's input enters the language model's free generation process. Pre-input verification can use rule matching, keyword matching, semantic classification models, context judgment, or a combination thereof. Post-output verification is used to verify dangerous details, privacy replies, medical advice, dependency reinforcement, screen guidance, and language difficulty before the candidate response is output to the child's end. Memory writing verification is used to determine whether the content of this interaction is allowed to be written, whether it is desensitized, whether only risk labels are saved, or whether it is discarded before memory is saved.
[0049] In one embodiment, the security tag can be configured according to the following table. Tag type Triggering Example Candidate risk level Processing direction Dangerous behavior labels Fire, electricity, knife, medicine, heights, roads, electrical outlets, etc. R3 Free generation is prohibited; use secure templates. Discomfort label Pain, fever, bleeding, falls, etc. R2 / R3 The suggestion is to contact the parents or a doctor, but no diagnosis will be made. Privacy information label Address, phone number, kindergarten, real name, etc. R2 Do not repeat or preserve the original text. Risk label for self-harm or harming others Self-harm, hitting others, smashing things, etc. R3 Safety blocking and reminding parents Over-reliance on tags Stay with me forever, don't go, I only want to play with you, etc. R1 / R2 Reduce dependency reinforcement and continuous follow-up questions High-risk experimental label I cut the wood myself, and installed the heating element, fire source, and batteries. R2 / R3 Parental involvement or instructions on intervention procedures are required.
[0050] When the input is flagged as high-risk during pre-entry verification, the system can directly implement a safety blocking strategy, preventing the child's input from being sent to the language model for free generation. This avoids the model generating detailed operational steps based on dangerous input. IV. Implementation Examples of Scene Labeling and Risk Priority Rules
[0051] Scene tags are used to indicate the context in which the child is currently inputting. Scene tags can be determined by rule classification, semantic classification, contextual information, and input safety tags.
[0052] When the same input matches multiple scenarios simultaneously, the system determines the primary scenario label based on the principle of risk priority. For example, if a child inputs "I'm unhappy, I want to touch the socket," which contains both negative emotions and dangerous behavior, the system will determine the primary scenario as dangerous behavior, rather than ordinary emotional support.
[0053] In one implementation, scene tags may include daily companionship, interest preferences, experience sharing, emotional companionship, parent-child or peer relationships, knowledge Q&A, imaginative stories, bedtime companionship, scientific experiments, operational assistance, dangerous behavior, physical discomfort, privacy information, age-inappropriate content, over-dependence, risk of self-harm, and risk of harming others. V. Risk Scoring and Parental Safety Strategy Modification Implementation Examples
[0054] In one embodiment, the security policy engine 230 calculates the risk score R according to the formula R=w1S+w2K+w3E+w4P+w5H+w6M, and determines the risk level based on the risk score and a preset threshold.
[0055] The basic risk value S for a given scenario can be determined by the main scenario label. For example, the S value is lower for daily companionship, interest preferences, and general knowledge questions, while the S value is higher for dangerous behavior, self-harm risk, risk of harming others, and serious physical discomfort. The keyword hit risk value K can be determined by a high-risk vocabulary or rule hit strength. The semantic risk confidence level E can be determined by the safety classification results of a semantic classification model or a language model.
[0056] The parental safety policy adjustment value P reflects the dynamic adjustment of risk scores and thresholds by parental configurations in scenarios involving young children. The value of P can be determined based on at least the child's age group, maturity level, high-sensitivity mode, disabled topics, experiment permissions, memory authorization, and reminder thresholds. For example, for children aged 2 to 3 or children with high-sensitivity mode enabled, the system can increase P or decrease the R2 / R3 threshold; for accounts with unauthorized experiment modes, the system can increase P for inputs involving cutting, heating, batteries, or fire sources; for topics disabled by parents, the system can increase P and restrict free generation.
[0057] The historical risk status correction value H can be determined based on recent risk labels within a preset time window. For example, if a child has recently exhibited excessive dependence, dangerous behavior, or privacy input multiple times, the system can increase H, making it easier for subsequent similar inputs to trigger restricted companionship, controlled responses, or safe blocking strategies. The current companionship mode correction value M can be determined based on bedtime mode, science experiment mode, general companionship mode, or parental assistance mode. For example, in bedtime mode, the system reduces stimulating stories and continuous questioning; in science experiment mode, the system increases the risk level of inputs related to dangerous materials, tools, and operations.
[0058] Through the above methods, risk scoring is not simply based on a single sensitive word, but rather makes dynamic decisions by combining the child's age, the context, parental configuration, historical risk status, and current pattern. VI. Implementation Example of Security Interaction Strategy State Machine
[0059] In one embodiment, the safe interaction strategy includes a P0 normal companionship strategy, a P1 restricted companionship strategy, a P2 controlled response strategy, and a P3 safe blocking strategy. Strategy Applicable Risks Generate degrees of freedom Child-side output Memory processing P0 Normal companionship R0 Allow free generation Standard voice output Save security summary P1 Restricted companionship R1 Limit length, topic, or follow-up questions Short sentences, gentle, low-stimulation Careful summarization or short-term memory P2 Controlled Response R2 Limited prompts or semi-templates Do not repeat sensitive information Desensitization, visible only to parents or not saved P3 Security Block R3 Do not enter free generation Security template or block Risk label only or discard the original text
[0060] The safety interaction strategy state machine enables the system to select different generation paths based on risk level and scenario label, instead of using the same model invocation method for all inputs. VII. Example of Prompt Message Assembly
[0061] The prompt assembly module 240 is used to assemble the prompt information for this round according to the safe interaction strategy. The prompt information may include role constraint parameters, age adaptation parameters, scene rules, safety policy rules, structured memory summary that meets memory permission conditions, output format or output modality constraints, and child input.
[0062] In one embodiment, the prompt information is assembled according to the formula T=R0⊕A⊕C⊕Ps⊕Ma⊕O⊕U. R0 represents role constraint parameters, such as gentle tone, short sentences, avoiding over-education, and not replacing parents; A represents age-appropriate parameters, such as response length, vocabulary difficulty, and number of follow-up questions; C represents scenario rules; Ps represents safety policy rules; Ma represents structured memory summaries that meet memory permission conditions; O represents output format or output modality constraints; and U represents child input.
[0063] When the risk level is R3 or the safety interaction strategy is P3, the system stops assembling free prompts and does not directly use the child's input for free generation. Instead, it calls a preset safety template. The preset safety templates may include templates for dangerous behaviors, medical or physical discomfort, privacy protection, self-harm risk, harm to others risk, and high-risk experiments. 8. Verify the output of the example.
[0064] After the response generation module 250 generates candidate responses based on the prompt information, the post-output verification module 260 performs context verification on the candidate responses. Post-output verification differs from ordinary output sensitive word filtering; its verification rules are dynamically determined based on the child's age, maturity level, scene tags, risk level, parental safety policy parameters, current companionship mode, output object, and output modality.
[0065] For example, the same text might be displayed as a risk summary on the parent's end, but it might not be suitable for voice broadcast on the child's end. For voice output on the child's end, the system should avoid broadcasting details of dangerous actions, medical advice, privacy reiterations, age-inappropriate content, content that harms others, self-harm-related content, over-reliance on promises, excessively long explanations, and content that encourages prolonged screen time.
[0066] The output verification results can include approval, shortening, rewriting, regeneration, template replacement, and blocking. When a candidate response fails verification but the risk is controllable, the system can request the language model to regenerate or shorten / rewrite the response; when a candidate response involves high-risk content, the system can directly call a safe template or block the output, and can send a reminder to parents. IX. Implementation Examples of Structured Memory Access Control and Memory Triggers
[0067] like Figure 4As shown, the memory permission module 270 does not save all the original dialogue, but performs a memory write verification on the content of this interaction. The system determines the memory permission result according to Mp=f(C,L,I,Pc,Tm,O), where C represents the scene label, L represents the risk level, I represents the privacy or sensitive information mark, Pc represents the parent configuration parameters, Tm represents the memory type, and O represents the memory purpose.
[0068] Memory types can include interest and preference memories, experiment progress memories, positive achievement memories, emotional summary memories, over-dependence summaries, risk labels for dangerous behaviors, privacy information labels, medical and health risk labels, self-harm risk labels, and risk labels for harming others.
[0069] For interests, experimental progress, and positive achievements, the system can save structured summaries and provide subsequent prompts when memory permissions are met. For privacy information, self-harm risks, risks of harming others, risks of dangerous behavior, and medical and health risks, the system can prohibit saving the original child's input, or only save risk labels, anonymized summaries, or summaries visible to parents.
[0070] The system can also set memory triggers based on structured memory summaries or risk tags. Experiment continuation triggers retrieve the previous experiment's topic, steps, and observations when a child re-enters the science experiment scenario; interest-adaptation triggers make responses more relevant to the child's interests within safe limits; tone and mood triggers adjust tone and intensity of follow-up questions; dependency inhibition triggers reduce commitment to continuous companionship; risk enhancement triggers increase output verification intensity or parental reminder thresholds; and privacy blocking triggers prevent access to privacy-related content prompts. 10. Parental Reminder Implementation Example
[0071] The parent interaction module 280 is used to output graded reminders or risk summaries to the parent terminal 300 based on the safety interaction strategy, output verification results, and memory permission results.
[0072] In one embodiment, scenarios R0 or P0 do not alert parents; scenarios R1 or P1 can generate a daily summary on the parent's end; scenarios R2 or P2 can generate a weak reminder or risk summary; and scenarios R3 or P3 can immediately alert parents. The content displayed on the parent's end can show summaries, risk tags, trigger rules, or suggested actions based on the parent's configuration, but it is not necessary to display the child's original high-risk input. XI. Child Safety Test Sample Library and Version Control Implementation Examples
[0073] like Figure 5As shown, the child safety testing module 290 is used to automatically call the child safety test sample library to perform regression testing when the scenario rule table, risk scoring rules, safety interaction strategy, prompt template, output verification rules, memory write verification rules, parent safety policy parameters or language model service are updated.
[0074] The test samples in the child safety test sample library may include at least one of the following: child input sample, expected input safety label, expected scenario label, expected risk level, expected safe interaction strategy, expected response source, prohibited output type, expected memory action, and expected parent reminder action.
[0075] The regression test does not rely solely on whether the candidate response text matches a single standard answer as the sole criterion. Instead, it simultaneously assesses whether the input safety label, scenario label, risk level, safety interaction strategy, response source, output verification result, memory writing action, and parental reminder action meet the preset expectations.
[0076] When regression test results do not meet preset pass conditions, the system can prevent the updated version from taking effect, revert to the previous version, reduce the degree of freedom in generation, or trigger manual review. In this way, the system can reduce the risk of degradation in the child companionship safety strategy chain after model, prompt template, or rule updates. XII. Specific Interaction Examples
[0077] Example 1: Expression of Negative Emotions. The child inputs "I'm unhappy today." Before input, the system checks for high-risk rules and determines the scenario is emotional support, with a risk level of R1, thus initiating the restricted support strategy P1. The system assembles prompts including role constraints, age-appropriateness, emotional support, and no-preaching rules. After candidate responses are output and verified, they are read aloud to the child in short sentences. Memory writing verification only allows writing fuzzy emotional summaries; the child's original words are not saved.
[0078] Example 2: Dangerous Behavior. The child inputs "I want to touch the socket." Before inputting, the system checks for dangerous behavior tags and determines the risk level as R3, initiating safety blocking strategy P3. The system does not use the custom-generated flow but instead uses a safety template, reminding the child not to touch the socket and to contact their parents. The system does not save the child's original words, only the dangerous behavior risk tag, and immediately alerts the parents.
[0079] Example 3: Scientific Experiment Observation. The child inputs, "I put the wood in the water, and it's on top." The system recognizes this as a scientific experiment scenario, with a risk level of R0 or R1, and initiates either normal or limited accompaniment strategies. The system includes experiment safety rules and step-by-step observation guidance in the prompt message. The system replies that the child can record "The wood floats on the water" and writes the experiment topic, steps, and observation results into the experiment progress memory for future continuation.
[0080] Example 4: Privacy Input. Children input their home address. Before inputting, the system checks for privacy information tags. If the input is found to be a privacy information scenario with a risk level of R2, the system enters the controlled response strategy P2. The system does not repeat the address, does not ask for more specific information, and does not write it into the child's memory. Instead, it guides the child to safe topics using a child-friendly template.
[0081] Example 5: Over-dependence. The child inputs "Don't go, stay with me forever." The system identifies this as an over-dependence scenario, with a risk level of R1 or R2. Dependence boundary rules are added to the prompt message, and the output is checked to ensure that dependency reinforcement content such as "always stay with me" or "only play with the intelligent agent" is present. The system can play short phrases for companionship and guide the child to find their parents or engage in real-world activities. Memory write-in verification can save a summary of dependency tendencies for subsequent use in reducing continuous questioning and commitments to companionship.
[0082] Example 6: Different handling of the same input in different modes. A child's input is "Can I cut wood myself?" In the normal knowledge question-and-answer mode, the system can identify it as a tool safety issue. In the science experiment mode, for young children and when parents have not authorized experiment permissions, the scenario's basic risk value S, the parent's safety policy correction value P, and the current companionship mode correction value M are all increased simultaneously, bringing the risk level to R3. The system then enters a safety blocking strategy, not outputting the cutting steps, but instead requiring the child to seek help from their parents.
[0083] Example 7: Parental strategy parameters intervene rather than direct control. Parents set the child's age group to young, enable high-sensitivity mode, and disable experimental permissions. When the child's input involves experimental tools, the parental strategy does not directly generate a response, but is used as a P item in the risk scoring and a strategy threshold adjustment item, making it easier for the system to enter P2 or P3, while increasing the strength of post-output verification and memory write restrictions.
[0084] Example 8: Version Update Regression Testing. After the system updates the prompt template, the child safety testing module automatically runs test samples including dangerous behaviors, privacy, self-harm risks, excessive dependence, and high-risk experiments. If the expected strategy for a certain test sample is P3 safety blocking, but the new version actually enters the free generation process, the system determines that the regression test has failed, preventing the version from taking effect or reverting to the previous version. XIII. Alternative Implementation Methods
[0085] The child interactive terminal in this invention can be a WeChat mini program, mobile application, tablet computer, smart speaker, combination of mobile phone and plush toy coat, embedded smart doll, or other device with voice interaction capability.
[0086] The speech recognition and speech synthesis in this invention can be implemented by cloud services, local models or hybrid services; the language model can be a cloud language model, a local language model, a small model, a rule generation system or a multi-model hybrid system.
[0087] The rule table, risk scoring rules, prompt templates, memory permission table, and child safety test sample library in this invention can be stored in a relational database, document database, key-value database, configuration file, configuration center, or local storage.
[0088] The post-output verification in this invention can be implemented by a rule engine, a classification model, a language model for secondary review, a content security service, or a combination thereof; the memory write verification can be implemented by one or more of the following: rule table, permission function, parental configuration, and manual review mechanism.
[0089] The above embodiments are merely preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, combinations, or improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A safe interaction method for a voice-guided intelligent agent for young children, characterized in that, include: Acquire input from children via interactive devices; The input from children is pre-input verified, and an input safety label is generated; The scene label is determined based on the child's input, the input safety label, and the context information; The risk level is determined based on the input safety label, the scene label, the parental safety policy parameters, and the historical risk status, and a safety interaction strategy is determined based on the risk level. The system assembles prompt information or invokes security templates according to the security interaction strategy to control the degree of freedom of the language model in generating candidate responses. The candidate responses are output and then checked, and the content of this interaction is recorded and written back for verification. Based on the output verification results and the memory write verification results, perform at least one of the following processing actions: child-side output, safety template replacement, output blocking, parent-side reminder, memory write, desensitization and saving, saving only risk labels, or discarding.
2. The method according to claim 1, characterized in that, The child interactive terminal includes at least one of the following: a mobile terminal running a child-friendly mini-program, a plush doll cover containing the mobile terminal, and an embedded voice doll terminal. The child interactive terminal uses voice interaction as the primary interaction method and limits the screen display to at least one of the following auxiliary displays: startup, status prompts, parental assistance, or abnormal prompts.
3. The method according to claim 1, characterized in that, The pre-input verification includes verifying the child's input based on at least one of rule matching, keyword matching, semantic classification model and context judgment, and prohibiting the child's input from entering the free generation process when the input security label meets the preset high-risk conditions.
4. The method according to claim 3, characterized in that, The input safety labels include at least one of the following: dangerous behavior label, physical discomfort label, privacy information label, self-harm risk label, risk of harming others label, age-inappropriate content label, excessive dependence label, and high-risk experiment label.
5. The method according to claim 1, characterized in that, The scene tags include at least one of the following: daily companionship, interest preferences, experience recounting, emotional companionship, parent-child or peer relationships, knowledge Q&A, imaginative stories, bedtime companionship, scientific experiments, operational assistance, dangerous behavior, physical discomfort, privacy information, age-inappropriate content, over-dependence, risk of self-harm, and risk of harming others. When the same child inputs multiple scene tags, the main scene tag is determined according to the rule of risk priority, child safety priority, or parent strategy priority.
6. The method according to claim 1, characterized in that, The risk level is determined based on a risk score, which is calculated using the formula R=w1S+w2K+w3E+w4P+w5H+w6M, where S represents the basic risk value of the scenario, K represents the keyword hit risk value, E represents the semantic risk confidence level, P represents the parental safety strategy correction value, H represents the historical risk status correction value, M represents the current companionship mode correction value, and w1 to w6 represent weighting coefficients. The parental safety strategy correction value P is determined based on at least one of the following: child's age group, maturity level, high-sensitivity mode, prohibited topics, experimental permissions, memory authorization, and reminder threshold, and is used to adjust the risk score or risk level threshold.
7. The method according to claim 6, characterized in that, The parental safety policy parameters include at least one of the following: child's age group, maturity level, high sensitivity mode, bedtime mode setting, experiment permissions, disabled topics, memory authorization range, reminder threshold, and display range on the parent's end. The parental safety policy parameters serve as at least one of the following: correction item for the risk score, policy threshold adjustment item, output verification intensity adjustment item, and memory permission determination item.
8. The method according to claim 1, characterized in that, The safe interaction strategy includes a normal companionship strategy, a restricted companionship strategy, a controlled response strategy, and a safe blocking strategy. The normal companionship strategy allows the language model to generate responses under normal safety constraints. The restricted companionship strategy limits the response length, topic range, or number of follow-up questions. The controlled response strategy calls restricted prompts or semi-template responses. The safe blocking strategy does not call freely generated responses but directly calls a safe template and triggers a reminder on the parent's end.
9. The method according to claim 8, characterized in that, The prompt information is assembled according to T=R0⊕A⊕C⊕Ps⊕Ma⊕O⊕U, where T represents the prompt information in this round, R0 represents the role constraint parameter, A represents the age adaptation parameter, C represents the scene rule, Ps represents the safety policy rule, Ma represents the structured memory summary that meets the memory permission conditions, O represents the output format or output modality constraint, U represents the child input, and ⊕ represents splicing, selection, or combination operations. When the risk level meets the high-risk condition, the assembly of free prompt information stops and a preset safety template is called.
10. The method according to claim 1, characterized in that, The post-output verification checks at least one of the following in the candidate responses: child's age group, maturity level, scene tag, risk level, parental safety strategy parameters, current companionship mode, output object, and memory permission results. This verification includes checking for details of dangerous actions, medical advice, privacy reiterations, age-inappropriate content, content that harms others, self-harm-related content, excessive dependence reinforcement, screen guidance, language difficulty, response length, role consistency, and experimental safety prompts.
11. The method according to claim 10, characterized in that, The output verification result includes at least one of passing, shortening, rewriting, regenerating, template replacement, and blocking. When the candidate response is suitable for display on the parent's end but not suitable for voice broadcast on the child's end, the system prohibits the output of the candidate response to the child's end voice channel and converts it into a risk summary for the parent's end or a safety template response for the child's end.
12. The method according to claim 1, characterized in that, The memory permission result is determined according to Mp=f(C,L,I,Pc,Tm,O), where Mp represents the memory permission result, C represents the scene label, L represents the risk level, I represents the privacy or sensitive information label, Pc represents the parent configuration parameter, Tm represents the memory type, and O represents the memory purpose. The memory permission result includes at least one of the following: allow writing and allow access prompt message, allow writing but prohibit access prompt message, write after desensitization, save only the risk label, do not save the original text, only visible to the parent's end, and discard immediately.
13. The method according to claim 12, characterized in that, The memory types include at least one of the following: interest preference memory, experiment progress memory, positive achievement memory, emotional summary memory, over-dependence summary, risk label for dangerous behavior, privacy information label, medical and health risk label, self-harm risk label, and risk label for harming others. Among these, at least one of privacy information, self-harm risk, risk of harming others, and risk of dangerous behavior is not included in subsequent prompts in the form of the original child input.
14. The method according to claim 12 or 13, characterized in that, The system sets memory triggers based on structured memory summaries or risk tags. The memory triggers include at least one of the following: experiment continuation trigger, interest matching trigger, emotional tone trigger, dependency inhibition trigger, risk enhancement trigger, and privacy blocking trigger. The memory triggers are used to adjust the selection of prompt information, output verification strength, degree of free generation, or parental reminder threshold in subsequent interactions.
15. The method according to claim 1, characterized in that, The method further includes: automatically calling the child safety test sample library to perform regression testing when the scene rule table, risk scoring rules, safety interaction strategy, prompt template, output verification rules, memory write verification rules, or language model service are updated; wherein, the test samples in the child safety test sample library include at least one of child input samples, expected input safety labels, expected scene labels, expected risk levels, expected safety interaction strategies, expected response sources, prohibited output types, expected memory actions, and expected parent reminder actions; when the regression test results do not meet the preset pass conditions, at least one of the following is prevented from taking effect, reverted to the previous version, reduced generation freedom, or triggered manual review.
16. A safe interactive system for voice-guided companionship for young children, characterized in that, include: The input acquisition module is used to acquire input from children's interactive terminals; The pre-input verification module is used to perform pre-input verification on the child's input and generate an input safety label; The safety policy engine is used to determine the safety interaction policy based on the input safety label, scene label, risk level, parental safety policy parameters, historical risk status and current companionship mode; The prompt assembly module is used to assemble prompt information for the language model to generate a response according to the security interaction strategy, or to call a preset security template; The response generation module is used to generate candidate responses based on the prompt information; The post-output verification module is used to perform post-output verification on the candidate responses. The memory permission module is used to perform memory write verification on the content of this interaction and generate memory permission results. The parent interaction module is used to output graded reminders or risk summaries to the parent's end based on the safety interaction strategy, the output verification result, or the memory permission result.
17. The system according to claim 16, characterized in that, The parent interaction module is used to receive at least one parent safety policy parameter from the following: child's age group, maturity level, high sensitivity mode, bedtime mode settings, experiment permissions, disabled topics, memory authorization range, reminder threshold, and display range on the parent's end. The system also includes a child safety testing module, which is used to perform regression testing on the child companionship safety policy link after the scene rules, risk scoring rules, parent safety policy parameters, prompt templates, language model services, or output verification rules are updated, and to control whether the updated version takes effect based on the regression test results.
18. An electronic device, characterized in that, It includes a processor, a memory, and a computer program stored in the memory and executable by the processor, wherein the processor executes the computer program to implement the method of any one of claims 1 to 15.
19. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method of any one of claims 1 to 15.
Citation Information
Patent Citations
Children education knowledge boundary management method, system and equipment based on large model
CN120277199A
Voice-Enabled Connected Smart Toy
US20180117479A1
A system and a method for parental control in a generative artificial intelligence governance platform
WO2024213989A1