An AI agent privacy hierarchical desensitization method and system based on semantic fingerprints

CN122674086APending Publication Date: 2026-09-01ASPIRE TECH (SHENZHEN) LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610828559.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-09
Publication Date
2026-09-01

AI Technical Summary

Technical Problem

然而,此类技术存在明显局限性:首先,无法识别记忆片段之间的跨会话语义关联,攻击者可通过关联多个分散的记忆片段推理出用户的完整敏感信息;其次,缺乏基于语义的敏感分级机制,全量加密会导致智能体无法提取语义特征以实现记忆关联与推理,而统一脱敏则无法适配不同敏感等级,导致保护不足或过度处理;再次,现有技术对智能体的记忆回溯、编辑、遗忘等操作缺乏有效的隐私控制,易遭受记忆注入攻击;最后,传统脱敏算法多针对结构化数据,无法适配非结构化的自然语言语义,且会破坏语义结构,影响智能体的推理能力

Benefits of technology

本发明提出一种基于语义指纹的AI智能体隐私分级脱敏方法及系统,针对AI智能体记忆链的链式存储、语义关联等特有结构,通过拓扑解构、语义指纹生成、分级脱敏和操作控制的全流程技术体系,从根本上解决了现有技术中因跨会话关联推理导致的隐私泄露问题。相较于传统整体加密或统一脱敏方案,本发明通过构建四级敏感标签体系和差异化脱敏算法,实现了对公开、弱敏感、强敏感及绝密信息的精准分级处理,通过对强敏感信息和绝密信息分别进行不可逆脱敏和硬件级隔离,确保原始信息不被泄露,通过对弱敏感信息进行不可逆脱敏和语义泛化,实现弱敏感信息隐私隔离的同时,又保留了弱敏感信息记忆节点的语义结构与关联关系,从而在有效阻断隐私推理路径的同时,保障了AI智能体进行记忆关联、时序演化分析等核心推理功能的完整性。此外,本发明通过融合多种校验与检测算法的操作控制机制,有效防范了记忆注入攻击,实现了对记忆操作的全流程合规管控,显著提升了AI智能体的隐私合规性与安全性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122674086A_ABST
    Figure CN122674086A_ABST
Patent Text Reader

Abstract

This invention discloses a method and system for privacy-graded desensitization of AI agents based on semantic fingerprints, belonging to the field of artificial intelligence security technology. The method includes: topologically deconstructing the memory chain of the AI ​​agent to construct a three-layer topological model; extracting and classifying the semantic feature vectors of memory nodes to generate privacy-sensitive labels for the memory nodes; generating unique semantic privacy fingerprints for the memory nodes based on the semantic feature vectors and privacy-sensitive labels; constructing a privacy association graph based on the memory nodes, associated edges, and semantic privacy fingerprints, and identifying privacy inference paths; constructing a graded desensitization engine to block privacy leaks from privacy inference paths; and constructing a memory operation privacy control mechanism to perform permission verification and anomaly detection on operation requests initiated against memory nodes, and to log and audit all operations. This invention can achieve refined privacy protection for the unique structure of the AI ​​agent's memory chain without reducing its inference ability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of artificial intelligence security technology, specifically relating to a method and system for privacy-graded de-identification of AI intelligent agents based on semantic fingerprints. Background Technology

[0002] With the evolution of artificial intelligence technology, AI agents have developed into complex entities possessing long-term memory, short-term memory, conversational memory, and tool-calling memory. Their memory systems form a chain-like storage structure, supporting the agent's continuous learning and cross-scenario decision-making. Currently, AI agents are widely used in fields such as healthcare and finance, and their memory chains inevitably contain sensitive and private data such as user identity and medical history.

[0003] Existing privacy protection technologies primarily focus on overall encryption during the data storage phase, with the core logic being the unified encryption of memory data to prevent theft. However, such technologies have significant limitations: First, they cannot identify cross-session semantic relationships between memory fragments, allowing attackers to infer complete sensitive user information by associating multiple scattered memory fragments; second, they lack a semantic-based sensitivity grading mechanism, as full encryption prevents agents from extracting semantic features for memory association and reasoning, while unified desensitization cannot adapt to different sensitivity levels, leading to insufficient protection or over-processing; third, existing technologies lack effective privacy controls for agents' memory recall, editing, and forgetting operations, making them vulnerable to memory injection attacks; finally, traditional desensitization algorithms are mostly designed for structured data, unable to adapt to unstructured natural language semantics, and can damage semantic structure, affecting the agent's reasoning ability.

[0004] Therefore, there is an urgent need for a technical solution that can achieve refined privacy protection for the unique structure of the AI ​​agent's memory chain without reducing its reasoning ability. Summary of the Invention

[0005] The purpose of this invention is to provide a method and system for privacy-graded desensitization of AI agents based on semantic fingerprints, which can achieve refined privacy protection without reducing the reasoning ability of AI agents, taking into account the unique structure of the AI ​​agent's memory chain.

[0006] In a first aspect, the present invention provides a privacy-graded de-identification method for AI intelligent agents based on semantic fingerprints, comprising the following steps: The various memory data of the intelligent agent are processed, multiple memory nodes are extracted, and the associated edges between memory nodes are constructed. The memory nodes and associated edges are connected in sequence according to the time order to form a memory time chain, and a three-layer topology model is constructed. Based on a three-layer topology model, the semantic feature vector of each memory node is extracted and classified to generate a privacy-sensitive label for each memory node; a unique semantic privacy fingerprint of each memory node is generated based on the semantic feature vector and the privacy-sensitive label; a privacy association graph is constructed based on the memory node, the associated edge and the semantic privacy fingerprint, and privacy reasoning paths that can deduce sensitive privacy information are identified. A hierarchical desensitization engine is constructed to block privacy leaks in the privacy inference path. The sensitivity level of each memory node is determined based on the privacy sensitivity label, and different desensitization algorithms are used to process the memory nodes for different sensitivity levels. A privacy control mechanism for memory operations is constructed to perform permission verification and anomaly detection on operation requests initiated against memory nodes in order to prevent memory injection attacks, and all operations are logged and audited for compliance.

[0007] As an alternative implementation method, memory node extraction specifically includes: using the BERT model to extract semantic feature vectors of memory data, using the BiLSTM model to capture the temporal dependencies of semantic feature vectors to obtain temporal feature vectors, performing a dimension-wise weighted operation on the temporal feature vectors according to the memory source, and using the CRF model to label the weighted feature vectors with entity labels to extract memory nodes.

[0008] As an optional implementation method, constructing the association edge between memory nodes specifically includes: calculating the semantic similarity between any two memory nodes, where the semantic similarity is the product of cosine similarity and temporal penalty factor, and constructing an association edge between two memory nodes whose semantic similarity is greater than or equal to the dynamic threshold of semantic similarity.

[0009] As an alternative implementation method, identifying privacy inference paths that can derive sensitive privacy information specifically includes: using an algorithm that combines graph convolutional networks and graph attention networks, introducing a gain coefficient based on sensitivity level in the calculation of the attention coefficient of the graph attention network, performing weighted analysis on nodes and associated edges in the privacy association graph, calculating the privacy risk score of each path, and determining the path with a privacy risk score exceeding an adaptive threshold as a privacy inference path.

[0010] As an alternative implementation method, the differentiated desensitization algorithm includes at least an irreversible desensitization algorithm and a hardware-level isolated storage mechanism; for memory nodes of the first sensitivity level, the BERT semantic generalization algorithm combined with the format preservation encryption algorithm is used for irreversible desensitization; for memory nodes of the second sensitivity level, the salted hash algorithm combined with the semantic structure preservation algorithm is used for irreversible desensitization; for memory nodes of the third sensitivity level, a trusted execution environment is used for hardware-level isolated storage, and a secure sandbox is used for controllable access.

[0011] As an alternative implementation, an algorithm that combines role-based access control and attribute-based access control is used for permission verification; an improved isolated forest algorithm with time decay weights is used for real-time abnormal behavior detection; and a hash-based verification algorithm is used to verify the integrity of the memory chain.

[0012] As an alternative implementation, a unique semantic privacy fingerprint is generated for each memory node, specifically including: The semantic feature vector and privacy-sensitive labels are perturbed, including semantic perturbation based on sensitivity level and temporal perturbation based on timestamp; the perturbed information is then input into a hash function to generate a unique semantic privacy fingerprint for the memory node.

[0013] Secondly, the present invention provides an AI intelligent agent privacy-level de-identification system based on semantic fingerprinting, comprising: The memory chain topology deconstruction module is configured to: process various types of memory data of the agent, extract multiple memory nodes, construct the associated edges between memory nodes, connect the memory nodes and associated edges in temporal order to form a memory temporal chain, and construct a three-layer topology model; The semantic privacy fingerprint generation module is configured to: extract the semantic feature vector of each memory node based on a three-layer topology model, and classify the semantic feature vector to generate a privacy-sensitive label for each memory node; generate a unique semantic privacy fingerprint for each memory node based on the semantic feature vector and the privacy-sensitive label; construct a privacy association graph based on the memory node, the associated edge, and the semantic privacy fingerprint, and identify privacy inference paths that can deduce sensitive privacy information. The hierarchical desensitization engine module is configured to: build a hierarchical desensitization engine to block privacy leaks in the privacy inference path; determine the sensitivity level of each memory node based on the privacy sensitivity label; and use differentiated desensitization algorithms to process the memory nodes for different sensitivity levels. The memory operation privacy control module is configured to: build a memory operation privacy control mechanism, perform permission verification and anomaly detection on operation requests initiated against memory nodes to prevent memory injection attacks, and log and audit all operations.

[0014] Thirdly, the present invention provides an electronic device including a memory and a processor, and computer instructions stored in the memory and running on the processor, wherein the computer instructions, when executed by the processor, perform the method described in the first aspect.

[0015] Fourthly, the present invention provides a computer-readable storage medium for storing computer instructions, which, when executed by a processor, perform the method described in the first aspect.

[0016] Compared with the prior art, the beneficial effects of the present invention are as follows: This invention proposes a privacy-graded desensitization method and system for AI agents based on semantic fingerprints. Targeting the unique structure of AI agent memory chains, such as chained storage and semantic association, it fundamentally solves the privacy leakage problem caused by cross-session association reasoning in existing technologies through a complete technical system encompassing topology deconstruction, semantic fingerprint generation, graded desensitization, and operational control. Compared to traditional overall encryption or unified desensitization schemes, this invention achieves precise graded processing of public, weakly sensitive, strongly sensitive, and top-secret information by constructing a four-level sensitive label system and differentiated desensitization algorithms. Irreversible desensitization and hardware-level isolation are applied to strongly sensitive and top-secret information respectively, ensuring that the original information is not leaked. Irreversible desensitization and semantic generalization are applied to weakly sensitive information, achieving privacy isolation while preserving the semantic structure and association relationships of the weakly sensitive information memory nodes. This effectively blocks privacy reasoning paths while ensuring the integrity of the AI ​​agent's core reasoning functions, such as memory association and temporal evolution analysis. Furthermore, by integrating multiple verification and detection algorithms into its operation control mechanism, this invention effectively prevents memory injection attacks, achieves full-process compliant control over memory operations, and significantly improves the privacy compliance and security of AI agents. Attached Figure Description

[0017] Figure 1 This is an overall flowchart of the AI ​​intelligent agent privacy classification and desensitization method based on semantic fingerprinting disclosed in the embodiments of the present invention. Detailed Implementation

[0018] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0019] The technical solutions disclosed in the various embodiments of this application are described in detail below with reference to the accompanying drawings.

[0020] Example 1 like Figure 1 As shown, this embodiment provides a privacy-graded de-identification method for AI intelligent agents based on semantic fingerprints, including the following steps: The various memory data of the intelligent agent are processed, multiple memory nodes are extracted, and the associated edges between memory nodes are constructed. The memory nodes and associated edges are connected in sequence according to the time order to form a memory time chain, and a three-layer topology model is constructed. Based on the three-layer topology model, extract the semantic feature vector of each memory node, classify the semantic feature vectors, and generate a privacy-sensitive label for each memory node; generate a unique semantic privacy fingerprint for each memory node based on the semantic feature vector and the privacy-sensitive label; construct a privacy association graph based on memory nodes, associated edges and semantic privacy fingerprints, and identify privacy inference paths that can derive sensitive privacy information; Construct a hierarchical desensitization engine to block privacy leakage through privacy inference paths, determine the sensitivity level of each memory node according to the privacy-sensitive label, and adopt differentiated desensitization algorithms to process memory nodes for different sensitivity levels; Construct a privacy control mechanism for memory operations, perform permission verification and anomaly detection on operation requests initiated for memory nodes to prevent memory injection attacks, and perform log recording and compliance audit on all operations.

[0021] The detailed technical solution of the present invention is as follows: Step S1: Topological deconstruction of memory chain, constructing a three-layer topology model of memory chain.

[0022] This step aims to disassemble the complex memory chain of an agent into a computable and analyzable structured model. Specifically: perform topological deconstruction on the memory chain of an AI agent, disassemble the memory chain into a three-layer topology of "node (fact) → edge (association) → temporal chain (evolution)", clarify the definition, attributes and association relationship of each layer, and construct a complete memory chain topology model. The specific process is shown in S1.1-S1.3.

[0023] S1.1 Extraction and definition of memory nodes.

[0024] A memory node is the basic unit of the memory chain, corresponding to an independent fact in the agent's memory (such as "go to the hospital tomorrow", "Zhang San", "antihypertensive drugs"). An improved BERT-BiLSTM-CRF algorithm integrating memory source attention is adopted to automatically extract all memory nodes from the agent's long-term memory, short-term memory, session memory and tool call memory. The specific application process of the algorithm is as follows: 1. Data preprocessing: preprocess various types of memory data of the agent, including text cleaning (removing redundant characters and special symbols), word segmentation (adopting BPE word segmentation algorithm to adapt to natural language and professional terms), part-of-speech tagging (adopting BiLSTM-CRF algorithm to tag the part of speech of each word, such as noun, verb, adjective), stop word removal (removing meaningless words such as "de", "le", "shi" based on a custom stop word list), so as to obtain standardized memory text data.

[0025] 2. Entity Recognition and Fact Extraction: An improved BERT-BiLSTM-CRF algorithm, incorporating memory-sourced attention, is used to perform entity recognition and fact extraction on the standardized memory text, extracting memory nodes. The BERT model is used to extract deep semantic features of the text, the BiLSTM model is used to capture temporal dependencies, a memory-sourced attention layer is inserted before the CRF layer to weight and strengthen the BiLSTM output features, and the CRF model is used to optimize the recognition accuracy of entity boundaries. The specific algorithm flow is as follows: (1) Convert the preprocessed memory text into BERT input vectors, and extract the semantic feature vectors (768 dimensions) of the text through BERT's 12-layer Transformer encoder to capture the deep semantic information of the text.

[0026] (2) Input the semantic feature vector output by BERT into the BiLSTM model. The forward LSTM of BiLSTM captures the forward temporal dependency of the text, and the backward LSTM captures the reverse temporal dependency of the text, outputting a temporal feature vector with a dimension of 256.

[0027] (3) Insertion of memory source attention weighting: The full-dimensional attention weighting mechanism adopts privacy multi-dimensional quantitative calibration + basic benchmark weight + four types of memory independent scene correction coefficients. The basic weight is obtained by quantitatively measuring three objective indicators: privacy information density, sensitive entity enrichment degree, and privacy reasoning contribution degree. Then, independent scene correction coefficients are configured for each type of memory source to achieve accurate adaptation of AI intelligent agents of all categories and all scenarios, and solve the problem of insufficient universality of fixed weights.

[0028] First, we define and quantify three core evaluation indicators to objectively assess the privacy risk levels of different memory sources: ① Privacy information density: defined as the ratio of the number of sensitive privacy semantic characters in a unit memory text fragment to the total number of characters in the memory fragment, representing the density of privacy information originally carried by various types of memory; by collecting annotated corpora from multiple fields such as medical, financial, identity, and behavior, the average proportion of privacy characters is statistically analyzed from four types of memory sources to obtain the quantitative value of privacy information density for each source.

[0029] ② Sensitive Entity Enrichment: Defined as the average number of occurrences of medical, financial, identity, and behavioral sensitive entities within a single memory fragment, representing the ability of the memory source to aggregate highly sensitive entities; the BERT-BiLSTM-CRF entity recognition model is used to batch extract sensitive entities from a large number of samples, and the average number of sensitive entities in a single fragment is statistically analyzed by grouping by memory source to obtain a quantified value of sensitive entity enrichment.

[0030] ③ Privacy reasoning contribution: Defined as the proportion of a certain type of memory source node participating in the formation of a high-risk privacy reasoning path in the total number of all high-risk paths in the privacy association graph of the memory chain, representing the degree of contribution of this type of memory in cross-session association reasoning leakage; by constructing a privacy association graph and mining all privacy reasoning paths, the frequency proportion of each source node participating in high-risk paths is statistically analyzed to obtain a quantified value of privacy reasoning contribution.

[0031] After normalizing the three indicators to the [0,1] interval, equal-weighted linear fusion is used to calculate the comprehensive score for each type of memory source. This comprehensive score is then linearly mapped to the reasonable range of [0.9,1.2]. Based on this, basic fixed attention weights are assigned to the four types of memory sources: long-term memory, short-term memory, conversational memory, and tool-based memory. =1.2, Short-term memory =1.0, Session Memory =1.1, tool call memory =0.9.

[0032] The underlying logic of the basic weights is as follows: Long-term memory stores core permanent privacy information such as user identity, medical history, and financial assets. It has the highest density of privacy information, richness of sensitive entities, and contribution to privacy inference, hence it is assigned the highest baseline weight. Conversation memory carries the privacy requirements of real-time interactions, with the next highest weight in these three indicators. Short-term memory mainly consists of recent temporary caches and ordinary interaction content, with the middle weight in these three indicators, and is set as a baseline reference weight of 1.0. In general scenarios, tool call memory mainly consists of tool operation instructions, interface call logs, and general search behaviors. It has the lowest proportion of natively complete and identifiable sensitive entities and participates in privacy inference paths mainly as auxiliary evidence nodes, hence it has the lowest weight in these three indicators, hence it is set as the lowest baseline weight.

[0033] Furthermore, independent scenario correction coefficients are configured for each of the four memory sources: long-term memory, short-term memory, conversational memory, and instrumental memory. , , , This enables independent adjustment of various memory attention weights under different business scenarios. The final actual attention weight calculation formula is as follows: ; In the general default scenario, all correction coefficients are set uniformly. = = = =1.0, directly using the basic baseline weights to maintain optimal performance in general scenarios; for intelligent agents in different vertical domains, samples of corresponding business scenarios are re-collected, and the three types of privacy quantification indicators are recalculated, with the correction coefficients of the corresponding memory sources adjusted upwards or downwards as needed: For core driver-type intelligent agents in tools such as automated operation and maintenance and industrial scheduling, the adjustment is increased. The adaptation tool calls upon high privacy-risk features; for real-time customer service and online consultation intelligent agents, the adjustment is increased. Adapt to the instantaneous privacy-intensive features of conversation memory; for intelligent agents such as schedule assistants and travel scheduling, increase... Adapts to short-term memory and continuous behavior privacy features; for intelligent agents in financial management and personal file management, adjustments can be made simultaneously. and The correction coefficients are uniformly constrained within the range of [0.8, 1.4] to avoid abnormal weight disturbances to the model feature distribution and ensure stable entity recognition accuracy.

[0034] The corrected weights of the four memory sources are used to generate an attention weight vector with the same dimension as the temporal feature vector. The temporal feature vector output by BiLSTM Perform a dimension-wise weighted operation: ; in, Element-wise multiplication means multiplying the values ​​of corresponding dimensions of two vectors one by one; The temporal feature vector (256 dimensions) output by the BiLSTM model represents the deep features of the memorized text after bidirectional temporal modeling. For the attention weight vector of memory sources, and The vectors have the same dimensions (256 dimensions), and the value of each dimension is equal to the fixed attention weight of the source to which the current memory segment belongs (1.2 / 1.0 / 1.1 / 0.9), which is used to perform source-differentiated weighting on the temporal feature vectors. The weighted feature vector allows the model to assign higher feature weights to memory sources with higher privacy quantification indicators and greater privacy risks, thereby improving the accuracy of privacy entity boundary identification.

[0035] (4) The weighted eigenvectors Input the CRF model, and the CRF model will learn the label transition probability to label each word with entity labels (such as "PER" for person entity, "MED" for medical entity, "FIN" for financial entity, and "LOC" for location entity), and extract independent facts as memory nodes based on the entity labels.

[0036] (5) The extracted memory nodes are deduplicated. The Locality Sensitive Hash (LSH) algorithm is used to calculate the hash value of each memory node. Duplicate memory nodes are removed by hash bucket clustering to ensure the uniqueness of each memory node. At the same time, a unique node ID (generated by the UUID algorithm) is assigned to each memory node for subsequent topology association and privacy control.

[0037] 3. Classification of memory nodes: Based on their source, memory nodes are classified into four categories: long-term memory nodes (such as user preferences, historical behavior, and domain knowledge), short-term memory nodes (such as recent high-frequency interaction content and temporary cached information), session memory nodes (such as the interaction content of the current session and context information), and tool call memory nodes (such as tool operation instructions and tool feedback results). A source tag is added to each memory node to facilitate subsequent privacy classification and operation control.

[0038] 4. Privacy-sensitive types of memory nodes: divided into four standard types, namely medical (MED), financial (FIN), identity (ID), and behavioral (BEH); The categories are categorized as follows: Medical: including medical history, medications, test results, diagnostic reports, medical records, etc.; Financial: including account information, transfer records, asset status, financial investments, consumption records, etc.; Identity: including personal unique identifiers such as name, ID number, mobile phone number, medical record number, address, etc.; Behavioral: including behavioral privacy such as travel history, daily routines, social behaviors, task operation history, etc.

[0039] 5. Memory Node Privacy Levels: Four privacy sensitivity levels are set: L0 (Public), L1 (Weakly Sensitive), L2 (Strongly Sensitive), and L3 (Top Secret). The definitions of each sensitivity level are as follows: L0 (Public): No privacy-sensitive attributes, publicly accessible, such as the functional description of the intelligent agent and publicly available domain knowledge; L1 (Weakly Sensitive): Low level of privacy sensitivity, with minimal impact after leakage, such as user nicknames and ordinary travel records (without specific time and location); L2 (Highly Sensitive): Highly sensitive to privacy. Leakage of such information may result in risks such as user privacy breaches and financial losses, including ID card numbers, mobile phone numbers, medical record numbers, and transaction records. L3 (Top Secret): Extremely sensitive to privacy; leakage would have serious consequences, such as undisclosed core business secrets, rare disease diagnosis reports, and core financial data.

[0040] S1.2 Construction of memory-related edges.

[0041] Memory association edges are bridges connecting two memory nodes, used to represent the semantic association between them (such as the "use" association between "Zhang San" and "hypertension medication", or the "treatment" association between "going to the hospital tomorrow" and "hypertension medication"). The Graph Neural Network (GAT) algorithm is used to automatically construct association edges between memory nodes. The specific algorithm application process is as follows: 1. Semantic Similarity Calculation: An improved Sentence-BERT algorithm with a temporal penalty term is used to calculate the semantic similarity between any two memory nodes, serving as the core basis for constructing associated edges. Sentence-BERT fine-tunes the BERT model, converting the text of memory nodes into fixed-dimensional (512-dimensional) semantic vectors. The similarity between two semantic vectors is calculated using the cosine similarity formula, as follows: ; in, , These are the semantic vectors of two memory nodes, | |、| | represents the magnitudes of the two semantic vectors, The semantic similarity is [0,1]. The higher the similarity, the stronger the semantic connection between the two memory nodes.

[0042] Introducing a time-series penalty term to correct the final similarity: Temporal penalty factor: ; in, Time-series penalty factor, ranging from (0,1], with larger time intervals resulting in a higher penalty factor. The smaller the value, the lower the correlation similarity, thus avoiding the misjudgment of weak cross-period correlations as high correlations; Penalty coefficient, adjustable range The preferred value is 0.2 to control the intensity of the penalty; : Normalized value of the time difference between two nodes , Take 30 days; , : These are the generation timestamps of memory nodes u and v, respectively; : Maximum time window, fixed at 30 days, used to normalize the time difference to the [0,1] interval.

[0043] Final corrected similarity: ; in, To correct the semantic similarity between memory node u and node v in the final temporal order.

[0044] 2. Edge Filtering and Construction: This invention constructs an adaptive dynamic semantic similarity threshold mechanism that integrates the privacy sensitivity level of memory nodes, contextual temporal density, and historical false positive / false negative feedback. This mechanism automatically and dynamically adjusts the threshold based on real-time node attributes, conversation context, and historical reasoning and recognition performance. First, a preset baseline threshold range is [0.55, 0.7], with values ​​of 0.65-0.7 for highly sensitive scenarios and 0.55-0.6 for general dialogue scenarios. Based on this, a triple dynamic correction factor is introduced: a sensitivity level correction factor... Contextual Temporal Density Correction Factor Historical misjudgment and underreporting feedback correction factor The formula for calculating the dynamic threshold is as follows: ; in, This is the baseline threshold corresponding to the current business scenario; Sensitivity level correction factor: If the two memory nodes involved in the association matching include an L3 top-secret node, the correction factor is appropriately lowered and the dynamic threshold is relaxed to avoid missing high privacy risk associations; if it includes an L2 strongly sensitive node, the threshold is slightly lowered; if both nodes are L0 public, the correction factor is increased and the threshold is tightened to filter meaningless weak semantic associations and reduce memory chain topological redundancy; the baseline coefficient for L1 weakly sensitive nodes remains unchanged.

[0045] For contextual temporal density correction factor: If the time interval between two memory nodes is short and they belong to the same continuous session context, the temporal correlation is close, the correction factor is lowered and the correlation judgment condition is relaxed; if the time span exceeds 30 days and spans multiple rounds of independent sessions, the temporal correlation is weak, the correction factor is raised and the construction of long-distance weak correlation edges is suppressed.

[0046] The system provides feedback correction factors for historical false positives and false negatives: iterative statistics are performed on the false positive rate and false negative rate identified based on past privacy inference paths; when the historical false positive rate is too high, the dynamic threshold is automatically raised to reduce redundant associated edges; when the false negative rate is too high, the dynamic threshold is automatically lowered to preserve effective semantic associations, forming a self-feedback closed-loop adaptive optimization.

[0047] Dynamic threshold The overall constraint is within the range of [0.55, 0.75] to prevent threshold out-of-bounds failure; when the final semantic similarity of two memory nodes after temporal penalty correction is greater than or equal to the dynamic threshold calculated in real time. When two nodes are determined to be semantically related, a related edge is constructed. At the same time, the attention mechanism of the GAT algorithm is used to assign a related weight to each related edge. The weight value is equal to the temporally corrected semantic similarity between the two nodes, which is used for subsequent privacy inference path identification and privacy risk score calculation.

[0048] Semantic similarity is used to measure the strength of association between memory nodes. The dynamic threshold of this scheme can be adaptively changed according to the node's L0 to L3 sensitivity level, the temporal distribution of the real-time session context, and the historical reasoning misjudgment and missed detection. It is not a fixed preset static threshold. This avoids introducing a large number of invalid weak associations due to the threshold being too low, and avoids losing key privacy association paths due to the threshold being too high, thus realizing intelligent and refined dynamic control of association edge filtering.

[0049] Those skilled in the art can use industry-standard precision-recall curves (PR curves) and F1 score maximization optimization methods to independently calibrate suitable baseline thresholds for any target business scenario. This invention uses labeled memory node pairs from four privacy-related scenarios—medical, financial, identity, and behavioral—as exemplary measurement samples. These samples are only used to illustrate the rationality of the baseline threshold selection and are not the only dataset limiting the implementation of this invention. The exemplary measurement results optimized using PR curves and F1 scores are as follows: By employing 100,000 labeled memory node pairs covering four privacy scenarios—medical, financial, identity, and behavioral—the results were optimized using the precision-recall curve (PR curve) and F1 score. Threshold = 0.5: Recall rate is 96.2%, precision rate is only 78.3%, indicating a large number of invalid associations; With a threshold of 0.6, the recall rate was 92.7%, the precision rate was 91.5%, and the F1 score was 92.1%, resulting in the best overall performance. Threshold = 0.7: Precision 94.3%, but recall drops to 79.6%, key associations are lost.

[0050] Therefore, the baseline threshold can be dynamically adjusted within the range of [0.5, 0.75]: it is recommended to increase it to 0.65-0.7 for highly sensitive scenarios; and to decrease it to 0.55-0.6 for general dialogue scenarios. The dynamic threshold of this invention adaptively floats around the optimal baseline, taking into account both relevance recall and precision.

[0051] 3. Relationship classification: Based on the type of relationship, the edges are classified into three categories: semantic edges (such as the semantic relationship between "hypertensive medication" and "hypertension"), temporal edges (such as the temporal relationship between "taking hypertension medication in the morning" and "monitoring blood pressure at night"), and causal edges (such as the causal relationship between "taking hypertension medication" and "blood pressure decrease"). Each edge is labeled with an association type to facilitate subsequent privacy inference path analysis.

[0052] S1.3 Memory Sequence Chain Construction.

[0053] A memory sequence chain is a temporal evolution structure composed of memory nodes and associated edges, used to represent the dynamic evolution process of the memory chain (such as temporal changes in user behavior, and the addition and deletion of memory nodes). The Temporal Graph Neural Network (TGNN) algorithm is used to construct the memory sequence chain. The specific algorithm application process is as follows: 1. Temporal Information Extraction: A temporal tag is added to each memory node. The temporal tag is the generation timestamp of the memory node (accurate to milliseconds). The time encoding algorithm (Time2Vec) is used to convert the timestamp into a temporal feature vector (128 dimensions) to capture the temporal evolution pattern of the memory node.

[0054] 2. Temporal Association Construction: Based on the temporal labels of memory nodes and the association weights of associated edges, the Temporal Graph Neural Network (TGNN) algorithm is used to connect memory nodes and associated edges in temporal order to construct a memory temporal chain. The TGNN algorithm introduces a temporal attention mechanism, assigning different attention weights to memory nodes at different time points. The closer the memory node is in time, the higher its attention weight, and the more it can influence the agent's current reasoning.

[0055] 3. Layered Time-Sequence Chain: Based on the evolution cycle of the memory chain, the memory time-sequence chain is divided into short-term time-sequence chain (evolution cycle ≤ 24 hours, corresponding to short-term memory and conversational memory), medium-term time-sequence chain (24 hours < evolution cycle ≤ 30 days, corresponding to the association between short-term memory and long-term memory), and long-term time-sequence chain (evolution cycle > 30 days, corresponding to the association between long-term memory and tool call memory). This enables layered control over the evolution process of the memory chain and provides a time-sequence dimension basis for subsequent privacy classification and desensitization.

[0056] Step S1 completes the topological deconstruction of the agent's memory chain, constructs a three-layer topological model of "node → edge → temporal chain", clarifies the distribution, association, and evolution of memory nodes, provides a foundation for subsequent semantic privacy fingerprint generation and hierarchical desensitization, and solves the technical problem that traditional technologies cannot identify the topological structure and association of the memory chain.

[0057] Step S2: Based on the three-layer topology model, extract the semantic feature vector of each memory node and classify the semantic feature vector to generate a privacy-sensitive label for each memory node; generate a unique semantic privacy fingerprint for each memory node based on the semantic feature vector and the privacy-sensitive label; construct a privacy association graph based on the memory node, the associated edge and the semantic privacy fingerprint, and identify the privacy reasoning path that can deduce sensitive privacy information.

[0058] This step is used to quantify the privacy attributes of memory nodes and the associated risks between nodes. Based on the memory chain topology model constructed in step S1, semantic privacy fingerprints are extracted for each memory node, and a privacy association graph is constructed to automatically identify privacy inference paths across nodes, thereby achieving accurate identification of privacy risks. The specific process is shown in S2.1-S2.4.

[0059] S2.1 Semantic Feature Vector Extraction.

[0060] An improved Vision-Language Pre-training (VLP) algorithm is used to extract semantic features from each memory node, generating a high-dimensional semantic feature vector for subsequent privacy-sensitive label classification and semantic privacy fingerprint generation. The specific algorithm application process is as follows: 1. Memory Node Standardization: Convert the memory nodes extracted in step S1 into standardized text (for non-text memory nodes, such as images and voice, convert them into text first using OCR and speech-to-text technology), and use the BPE word segmentation algorithm to segment the text into a word vector sequence.

[0061] 2. Deep semantic feature extraction: The word vector sequence is input into the improved VLP model, which integrates the extraction capabilities of visual and linguistic features. Through a 16-layer Transformer encoder, deep semantic mining is performed on the text to extract multi-dimensional semantic features (including semantic content, sentiment, entity relationships, contextual associations, etc.) and output a semantic feature vector with a dimension of 1024.

[0062] 3. Feature Vector Optimization: Principal Component Analysis (PCA) is used to reduce the dimensionality of the extracted 1024-dimensional semantic feature vector, removing redundant features and reducing it to 256 dimensions to reduce subsequent computational complexity. Simultaneously, L2 regularization is used to normalize the dimensionality-reduced feature vector, ensuring its stability and consistency. The normalization formula is as follows: ; in, The 256-dimensional semantic feature vector after PCA dimensionality reduction; The standard eigenvectors after L2 regularization; n is the dimension of the eigenvectors, fixed at n=25; Let be the value of the i-th dimension of the feature vector.

[0063] S2.2 Privacy-Sensitive Label Classification.

[0064] An improved Transformer classification model is used to classify the semantic feature vector of each memory node using privacy-sensitive labels, clarifying the privacy sensitivity type and sensitivity level of each memory node. The specific algorithm application process is as follows: 1. Classification Model Training: An improved Transformer classification model is constructed. This model, based on the traditional Transformer model, introduces an attention mechanism and residual connections to improve classification accuracy. The training dataset uses a memory node dataset labeled with privacy-sensitive tags (containing over 100,000 samples, covering four sensitive types: medical, financial, identity, and behavioral, and four levels of sensitivity). The training process is as follows: (1) Use the semantic feature vector generated in step S2.1 as the model input, and use the privacy-sensitive type label and the sensitivity level label as the model output.

[0065] (2) The cross-entropy loss function is used as the loss function of the model to optimize the model parameters. The formula for the cross-entropy loss function is as follows: ; Where N is the number of training samples and C is the number of label categories. Let i be the true label (one-hot encoded) of the i-th sample. Let be the predicted probability that the i-th sample belongs to the c-th label.

[0066] (3) The AdamW optimizer was used with a learning rate of 1e-5, 100 iterations, and a batch size of 32. An early stopping strategy was used to avoid model overfitting.

[0067] Learning rate 1e-5: Based on adaptive learning rate experiments, it avoids gradient vanishing while ensuring convergence speed; Batch size 32: Achieves the optimal balance between memory usage and generalization ability; Early stopping strategy: If there is no improvement after 10 consecutive rounds, training is stopped to effectively prevent overfitting.

[0068] (4) After training, the model’s classification accuracy is ≥98.5%, and it can accurately identify the privacy sensitivity type and sensitivity level of each memory node.

[0069] 2. Label assignment: Input the semantic feature vector of each memory node generated in step S2.1 into the trained improved Transformer classification model. The model outputs the privacy-sensitive type label and sensitivity level label of the memory node. Add the corresponding label to each memory node for subsequent hierarchical desensitization and privacy control.

[0070] S2.3 Semantic privacy fingerprint generation.

[0071] Based on the semantic feature vectors and privacy-sensitive labels of memory nodes, an improved SHA-3 algorithm that combines salting and semantic and temporal perturbations is used to generate a unique semantic privacy fingerprint for each memory node. This fingerprint is used for memory node identification, privacy verification, and association tracing. The specific algorithm application process is as follows: 1. Fingerprint input information construction: The normalized semantic feature vector (256-dimensional) from step S2.1, the privacy-sensitive type label, the sensitivity level label, and the node ID assigned in step S2.2 are concatenated in a fixed order to form fingerprint input information. The concatenation format is: node ID + sensitivity type label + sensitivity level label + semantic feature vector (serialized) + salt value + timestamp.

[0072] 2. Semantic perturbation processing: Perform a bitwise XOR operation between the 256-dimensional semantic feature vector and the mask generated by the sensitivity level to obtain the perturbed semantic feature vector vec. disturb The formula is: vec disturb = vec 256 ⊕ mask; Where, mask = level × 0x55555555… represents the masking rule; level: sensitivity level (L0=0, L1=1, L2=2, L3=3); 0x55555555…: 256-bit fixed perturbation base value (binary 01010101…); vec 256 : 256-dimensional normalized semantic feature vector; vec disturb : The semantic feature vector after perturbation.

[0073] Timing perturbation processing: The millisecond-level timestamp is cyclically shifted by 3 to 7 bits and then mixed into the input string, so that the same node generates different fingerprints at different times.

[0074] 3. Fingerprint Generation: The complete input information, after semantic and temporal perturbations, is fed into the improved SHA-3-256 algorithm for hashing to generate a 256-bit semantic privacy fingerprint. The improved SHA-3 algorithm, based on the traditional SHA-3 algorithm, introduces a triple enhancement mechanism of salt encryption, semantic masking, and temporal shifting to avoid collision attacks and resist rainbow table attacks, thus improving fingerprint security. The specific calculation process is as follows: (1) Concatenate the perturbed input information with the salt value to obtain the concatenated string; (2) Divide the concatenated string into groups, each group being 512 characters long, padding with zeros if the length is less than 512 characters. (3) Perform iterative hashing operations on each group of data, and generate intermediate hash values ​​through operations such as substitution, obfuscation, and diffusion; (4) Merge the intermediate hash values ​​of all groups and perform hash operation again to finally generate a 256-bit semantic privacy fingerprint. This fingerprint is unique, irreversible, and collision resistant. The fingerprints of different memory nodes are completely different, making it impossible to deduce the original memory node information from the fingerprint, and it is difficult to forge fingerprints through collision attacks.

[0075] 4. Fingerprint storage and association: The semantic privacy fingerprint of each memory node is associated with the node ID and sensitive tags and stored to build a fingerprint index library, which facilitates subsequent memory operation verification, privacy association graph construction and privacy inference path identification.

[0076] S2.4 Privacy-related graph construction and privacy inference path identification.

[0077] Based on the memory chain topology model constructed in step S1 and the semantic privacy fingerprint generated in step S2.3, a privacy association graph is constructed using a graph neural network (GCN+GAT) fusion algorithm with privacy risk attention weighting, and privacy inference paths across nodes are automatically identified. The specific algorithm application process is as follows: 1. Privacy Association Graph Construction: A privacy association graph is constructed using memory nodes as vertices, memory association edges as edges, and semantic privacy fingerprints as vertex attributes. In the graph, each vertex contains attributes such as node ID, semantic privacy fingerprint, sensitivity type label, sensitivity level label, and time sequence label; each edge contains attributes such as association weight and association type label, forming a complete privacy association graph used to intuitively display the association relationships and privacy attributes of memory nodes.

[0078] 2. Privacy Inference Path Identification: A privacy risk attention-based GCN+GAT fusion algorithm is employed to analyze the privacy association graph and automatically identify cross-node privacy inference paths—that is, multiple memory nodes connected by association edges, enabling the inference of paths containing sensitive user privacy information. The specific algorithm flow is as follows: (1) Graph preprocessing: The privacy association graph is normalized by converting the attributes of the vertices (semantic privacy fingerprint, sensitivity level label) into numerical vectors and normalizing the association weights of the edges to the [0,1] interval.

[0079] (2) GCN Feature Aggregation: The GCN algorithm is used to aggregate the features of each vertex's neighboring vertices to capture the local correlation features of the vertex. GCN uses convolution operations to weightedly fuse the features of each vertex with the features of its neighboring vertices to generate the vertex's local feature vector, as shown in the following formula: ; in, Let u be the feature vector of the (l+1)th layer vertex. Let u be the set of neighboring vertices. , Let u and v be the degrees of vertices u and v, respectively. Let be the weight matrix of the l-th layer. For bias terms, The activation function is ReLU.

[0080] (3) GAT Privacy Risk Attention Weighting: The attention mechanism of the GAT algorithm is used to weight the feature vectors aggregated by GCN, focusing on vertices with higher sensitivity levels and edges with greater association weights. GAT calculates the attention coefficient between each vertex and its neighboring vertices, assigning different weights to the features of neighboring vertices. The higher the sensitivity level and the greater the association weight, the higher the attention coefficient. The formula is as follows: ; in, The attention coefficient between vertices u and v. For attention parameter vectors, This is a vector concatenation operation, and LeakyReLU is the activation function.

[0081] In the GAT attention calculation, a sensitivity level gain coefficient β is introduced: L0=0.0, L1=1.0, L2=3.0, L3=5.0; The attention coefficient is adjusted to: This allows highly sensitive nodes to receive higher attention weights, improving the detection accuracy of privacy inference paths.

[0082] (4) Inference path scoring: Based on the feature vector after GCN+GAT fusion, the privacy risk score of each possible inference path is calculated. The scoring formula is as follows: ; Where S is the privacy risk score of the inference path, and k is the number of memory nodes in the inference path. Let i be the sensitivity score of the i-th memory node. Let represent the association weight of the j-th associated edge, where Π is the multiplication symbol, indicating that the association weights from the current node to the end of the path are multiplied layer by layer.

[0083] The sensitivity level score is defined as: L0=0, L1=1, L2=3, L3=5.

[0084] The levels adopt a non-arithmic incremental approach to strengthen the risk weight of highly sensitive information. L2 / L3 correspond to information that requires "explicit consent and strict protection" under laws and regulations, and the scores are significantly higher than L1. This meets the requirements of the Personal Information Protection Law for the graded protection of "general personal information", "sensitive personal information" and "core sensitive information", and achieves the unity of compliance requirements and technical scoring.

[0085] Scoring rules: The sensitivity score of the i-th node in the path needs to be multiplied by the weight product of all subsequent associated edges from that node to the end of the path, reflecting the characteristics of privacy risks being transmitted layer by layer along the inference path and the association strength decreasing at each level.

[0086] (5) Inference path screening: Set an adaptive threshold range for privacy risk scores [2.5, 4.0]. Set the threshold range to 2.5-3.0 for high-security scenarios and 3.0-3.5 for general scenarios. When the privacy risk score of a certain inference path is greater than or equal to the threshold, the path is determined to be a privacy inference path and privacy blocking is required. At the same time, record all memory nodes and associated edges in the privacy inference path to provide a basis for subsequent hierarchical desensitization and operation control.

[0087] The privacy risk score is determined by both the sensitivity level and the associated weight, reflecting the likelihood of a path leading to sensitive privacy information. A threshold that is too low will block normal reasoning; a threshold that is too high will miss high-risk paths, leading to privacy leaks.

[0088] By constructing 50,000 labeled privacy-preserving inference paths (including high / medium / low-risk paths), thresholds were calculated using "privacy leakage detection rate" and "normal inference blocking rate" as indicators: Threshold = 2.0: Privacy risk detection rate is 97.8%, but normal reasoning blocking rate reaches 21.3%, indicating overprotection; Threshold = 3.0: Privacy risk detection rate is 95.6%, and normal reasoning blocking rate is only 2.7%, achieving the optimal balance of "high detection and low false positives"; Threshold = 4.0: The normal reasoning blocking rate drops to 1.1%, but the risk detection rate drops to 82.4%, indicating missed detections.

[0089] Therefore, the privacy risk score threshold can be adjusted within the range of [2.5, 4.0]: it is recommended to set it to 2.5–3.0 for high-security scenarios; and to 3.0–3.5 for general scenarios.

[0090] For example, the association weights for "Zhang San (ID class, L2) → Medical Record No. 12345 (ID class, L2) → Hypertension Diagnosis (MED class, L2)" are W1=0.8 and W2=0.9 respectively. The privacy risk score for this inference path is: S=3×(0.8×0.9)+3×0.9+3=2.16+2.7+3=7.86≥3.0 If it is determined to be a privacy-related inference path, privacy leaks through graded de-identification are required.

[0091] Step S2 completes the generation of semantic privacy fingerprints and the construction of privacy association graphs, enabling accurate identification of privacy attributes of memory nodes and automatic detection of privacy inference paths. This solves the technical problem that traditional technologies cannot identify cross-session association inference leakage, and provides a precise basis for subsequent hierarchical desensitization.

[0092] Step S3: Construct a hierarchical desensitization engine to block privacy leaks in the privacy inference path. Determine the sensitivity level of each memory node based on the privacy sensitivity label, and use differentiated desensitization algorithms to process the memory nodes for different sensitivity levels.

[0093] Based on the semantic privacy fingerprint and privacy sensitivity level label generated in step S2, a hierarchical desensitization engine is constructed. Differentiated high-order desensitization algorithms are used for memory nodes with different sensitivity levels to achieve the goal of "hierarchical desensitization, preservation of semantics, and consideration of reasoning". The specific process is shown in S3.1-S3.4.

[0094] S3.1 Definition of hierarchical desensitization strategy.

[0095] Based on the sensitivity level labels (L0, L1, L2, L3) of memory nodes, a four-level hierarchical desensitization strategy is defined. The desensitization targets, applicable scenarios, and core algorithms of each strategy are as follows: 1. L0 (Public): The desensitization goal is "no desensitization, retaining the original information". It is applicable to memory nodes without privacy-sensitive attributes (such as intelligent agent function introductions, public domain knowledge). The core algorithm is "no desensitization processing", which directly retains the original plaintext of the memory node.

[0096] 2. L1 (Weakly Sensitive): The desensitization goal is "irreversible desensitization while preserving semantic structure and reasoning ability". It is applicable to weakly sensitive memory nodes (such as user nicknames and ordinary travel records). The core algorithm is "improved BERT semantic generalization algorithm + format preservation encryption (FF1)", which realizes entity generalization and irreversible desensitization, protecting privacy without affecting the agent's reasoning.

[0097] 3. L2 (Strongly Sensitive): The desensitization goal is "irreversible desensitization, eliminating individual identifiability, and preserving semantic structure". It is applicable to strongly sensitive memory nodes (such as ID card numbers, mobile phone numbers, and medical record numbers). The core algorithm is "improved HMAC-SHA256 salted hash algorithm + semantic structure preservation algorithm", which ensures that the desensitized data cannot be restored to the original information, while preserving the semantic structure to support the agent's reasoning.

[0098] 4. L3 (Top Secret): The desensitization target is "hardware-level isolation to prevent privacy leakage". It is applicable to top-secret memory nodes (such as core business secrets and rare disease diagnosis reports). The core algorithm is "hardware-level isolated storage + secure sandbox access" to achieve physical isolation and controllable access of memory nodes, thereby preventing privacy leakage.

[0099] S3.2 Irreversible semantic desensitization implementation of L1 (weakly sensitive) memory nodes.

[0100] For L1 weakly sensitive memory nodes, an "improved BERT semantic generalization algorithm + FF1 format preservation encryption algorithm" is used to irreversibly desensitize L1 level memory nodes. During the desensitization process, the semantic type and syntactic structure are fully preserved, achieving both weak privacy protection and not compromising the semantic association and reasoning capabilities of the AI ​​agent. The specific algorithm application process is as follows: 1. Entity Recognition and Extraction: The improved BERT-BiLSTM-CRF algorithm in step S1.1 is used to extract sensitive entities (such as the user nickname "Zhang San" and the travel location "Beijing") from the L1 level memory nodes, providing a foundation for subsequent semantic generalization processing.

[0101] 2. Semantic Generalization Processing: An improved BERT semantic generalization algorithm is used to generalize the extracted sensitive entities, replacing specific entities with generalized concepts while preserving the semantic types and relationships of the entities. This ensures that the de-sensitized data can support the agent's reasoning. The core process of the improved BERT semantic generalization algorithm is as follows: (1) Input the sensitive entity into the pre-trained BERT model and extract the semantic feature vector of the entity; (2) Based on semantic feature vectors, in the pre-defined generalized vocabulary (constructed according to the sensitive type classification, such as the generalized vocabulary of people and the generalized vocabulary of places), the cosine similarity algorithm is used to find the generalized concept that is closest to the semantics of the sensitive entity. (3) Replace sensitive entities with the found generalized concepts, such as replacing “Zhang San” with “a user” (retaining the semantic type of “person”), replacing “Beijing” with “a city” (retaining the semantic type of “location”), and replacing “go to the park on April 25, 2026” with “go to a leisure place on a certain date” (retaining the semantic type of “travel”); This invention employs a purely irreversible semantic abstraction design for L1-level memory nodes, retaining only the semantic type of the entity, its contextual logical relationships, and syntactic framework. It does not record the mapping relationship between the original entity and the generalized concept, nor does it establish any associated mapping library. The generalized text retains only the semantic skeleton required for reasoning, making it impossible to reverse-engineer and locate specific individual users, thus achieving privacy isolation for weakly sensitive information.

[0102] 3. Format Preservation Encryption: The FF1 format preservation encryption algorithm is used to encrypt the generalized memory nodes, ensuring data security during storage and transmission while preserving the original format of the memory nodes, thus not affecting the agent's reasoning. The FF1 algorithm is based on the Feistel network and implements encryption of formatted data. The specific process is as follows: (1) Initialization: Define encryption parameters according to the format of the memory node (such as text length and character type), including key (using AES-256 key), character set (UTF-8), and number of encryption rounds (default 16 rounds); (2) Data segmentation: The generalized memory node text is segmented into two parts, with lengths L and R respectively, satisfying L≥R; (3) Round function operation: In each round, the right half of R is processed by the round function. The round function includes operations such as permutation, obfuscation, and diffusion. A permutation table is generated using the key, and characters are replaced in R. (4) Data exchange: Perform an XOR operation between the processed R and the left half L to obtain a new L, and use the original L as the new R to enter the next round of operation. (5) Output: After 16 rounds of operation, the left and right parts are spliced ​​together to obtain the encrypted memory node text. This text has the same format as the original text and can be directly recognized and reasoned by the intelligent agent. The encrypted text can be directly parsed and recognized by the AI ​​agent without affecting memory association, temporal deduction and regular reasoning tasks; at the same time, because there is no mapping relationship retention and no restoration mechanism design, the overall security strength is determined by the dual mechanism of semantic irreversible generalization + FF1 format encryption, which is suitable for both privacy protection and intelligent reasoning needs of L1 level weakly sensitive memory nodes.

[0103] Irreversible privacy desensitization implementation of S3.3 L2 (highly sensitive) memory nodes.

[0104] An "improved HMAC-SHA256 salted hash algorithm + semantic structure preservation algorithm" is used to perform irreversible desensitization processing on L2 memory nodes. The specific algorithm application process is as follows: 1. Semantic Structure Extraction: An improved dependency parsing algorithm is used to extract the semantic structure of L2 memory nodes, including syntactic structure, entity relations, semantic logic, etc. For example, the semantic structure of "Zhang San's ID number is 110101199001011234" is "[person's] [identity identifier] is [specific number]".

[0105] 2. Sensitive Entity Hashing Process: An improved HMAC-SHA256 salted hash algorithm is used to perform irreversible hashing on sensitive entities (such as ID card numbers, mobile phone numbers, and medical record numbers) in the memory nodes. The specific process is as follows: (1) Salt value and Tweak: The salt value adopts a globally unique 32-bit random string (each memory node corresponds to a unique salt value), and the Tweak adopts the semantic privacy fingerprint (256 bits) of the memory node to enhance the anti-collision capability and prevent the same sensitive entity from generating the same hash value in different contexts. (2) Hash operation: Concatenate the sensitive entity, salt value, and Tweak in the order of "sensitive entity + salt value + Tweak", input the HMAC-SHA256 algorithm, perform hash operation, and generate a 256-bit hash value; (3) Format adaptation: Convert the generated hash value into a string that is consistent with the original sensitive entity format (e.g., if the ID number is 18 digits, truncate the first 18 digits of the hash value and convert it into a numeric string) to ensure that the data format after desensitization is consistent with the original data and does not affect the inference of the intelligent agent.

[0106] 3. Semantic Structure Reorganization: A semantic structure preservation algorithm is used to reorganize the hashed sensitive entities with the extracted semantic structure, generating desensitized memory node text. For example, "Zhang San's ID number is 110101199001011234" becomes "[Hash value 1]'s ID number is [Hash value 2]" after desensitization. Here, "Hash value 1" is the hash result of "Zhang San", and "Hash value 2" is the hash result of "110101199001011234", preserving the original semantic structure "[Person's] [Identity Identifier] is [Specific Number]", ensuring that the agent can reason normally.

[0107] 4. Irreversibility Guarantee: Due to the use of a salted hash algorithm, and the fact that the salt value and Tweak are globally unique, it is impossible to reverse-engineer the original sensitive entity through the hash value, thus achieving irreversible desensitization, completely eliminating individual identifiability, while preserving semantic structure to support the reasoning needs of intelligent agents.

[0108] Hardware-level isolation and desensitization implementation of S3.4 L3 (top secret) memory nodes.

[0109] The method of "hardware-level isolated storage + secure sandbox access" is used to de-identify L3 level memory nodes, thereby achieving physical-level privacy protection. The specific algorithm application process is as follows: 1. Hardware-level isolated storage: Employing Trusted Execution Environment (TEE) technology, a hardware-level isolated storage module is constructed. L3-level memory nodes are stored within the TEE, physically isolated from the agent's other memory modules (L0, L1, L2). The TEE is a hardware-based secure environment with independent processors, memory, and storage, capable of resisting external attacks and ensuring that confidential information stored within it is not stolen or tampered with.

[0110] 2. Security Sandbox Construction: A secure sandbox technology based on KVM (Kernel-based Virtual Machine) is used to construct a secure channel for agents to access L3-level memory nodes. The security sandbox possesses features such as process isolation, file system isolation, and network isolation. Agents cannot directly access L3-level memory nodes in the TEE; they can only access them indirectly through the security sandbox. The specific process is as follows: (1) Sandbox initialization: Create an independent sandbox process, allocate independent memory space and system resources, and set the access permissions of the sandbox (only allow the core inference module of the agent to access it); (2) Call request verification: When an agent needs to call an L3 level memory node, it sends a call request to the security sandbox. The request contains information such as the agent's identity, call purpose, and semantic privacy fingerprint. (3) Multi-layer verification: The security sandbox performs multi-layer verification on the call request, including identity verification (verifying the legality of the intelligent agent), purpose verification (verifying whether the purpose of the call is compliant), and fingerprint verification (verifying whether the memory node of the call is L3 level). Only after the verification is passed can access to the L3 level memory node in the TEE be allowed. (4) Indirect call and result return: The security sandbox reads the de-identified data of the L3 level memory node (semantic structure data after irreversible hashing) from the TEE and passes it to the core reasoning module of the agent. After the reasoning is completed, the temporary data in the sandbox is destroyed immediately to ensure that the original information of the L3 level memory node is not leaked.

[0111] 3. Access Log Recording: Log the call behavior of all L3 level memory nodes, including call time, call subject, call purpose, call result and other information. The logs are stored in encrypted form for subsequent compliance auditing and anomaly tracing.

[0112] Step S3 constructs a complete hierarchical desensitization engine, employing differentiated high-order desensitization algorithms for memory nodes with different sensitivity levels. This achieves a synergistic balance between "privacy protection" and "intelligent reasoning," solving the technical problem that traditional full-data encryption causes intelligent agent reasoning failure, while ensuring the privacy and security of memory nodes with different sensitivity levels.

[0113] Step S4: Construct a privacy control mechanism for memory operations, perform permission verification and anomaly detection on operation requests initiated against memory nodes to prevent memory injection attacks, and log and audit all operations.

[0114] For all memory operations such as adding, deleting, modifying, querying, and backtracking in the intelligent agent's memory chain, a memory operation privacy control mechanism is constructed. Through high-level algorithms such as permission verification, anomaly detection, and association verification, the entire process of operation behavior is subject to compliant control, blocking illegal operations and memory injection attacks. The specific process is shown in S4.1-S4.4.

[0115] S4.1 Hierarchical and verification of memory operation permissions.

[0116] 1. Hierarchical Access Control: Based on the sensitivity level of memory nodes, a four-level operation permission system is constructed. The permission level corresponds one-to-one with the sensitivity level. The higher the permission, the more operations can be performed, as detailed below: (1) Permission P0: Can perform all operations (add, delete, modify, query, backtrack) on L0 level memory nodes, and can view the de-identified data of L1 level memory nodes; (2) Permission P1: Can perform all operations on L0 and L1 level memory nodes, can view de-identified data of L2 level memory nodes, but cannot view L2 level original data; (3) Permission P2: Can perform all operations on L0, L1 and L2 level memory nodes, can view desensitized data of L3 level memory nodes, but cannot view L3 level original data; (4) Permission P3: Can perform all operations on all levels of memory nodes, and can view the raw data of L3 level memory nodes (only authorized administrators can have this permission).

[0117] 2. Permission Verification Algorithm: A fusion algorithm of Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) is adopted to verify the permissions of remembered operations. The specific algorithm application process is as follows: (1) Operation request parsing: Parse the memory operation requests initiated by the agent or user, and extract information such as operation subject (agent module, user), operation type (add, delete, modify, query, backtrack), operation object (memory node ID), operation time, etc. (2) Role-Based Access Control (RBAC): Query the role information of the operation subject, determine its corresponding permission level, and determine whether the permission level allows the current operation type to be executed (e.g., a P1 permission subject cannot execute the deletion operation of an L2 level memory node). (3) Attribute Permission Verification (ABAC): Extract the attributes of the operation subject (such as identity, operation purpose, and environment) and the attributes of the operation object (such as sensitivity level and semantic privacy fingerprint). Use the attribute matching algorithm to determine whether the operation is compliant. For example, if the operation subject is an ordinary user, the operation purpose is "personal query", and the operation object is its own L2 level memory node, the attribute matching passes; if the operation object is another user's L2 level memory node, the attribute matching fails, and the operation is rejected. (4) Verification result processing: If both RBAC and ABAC verifications pass, the memory operation is allowed; if any verification fails, the operation is rejected and the reason for rejection is returned (such as "insufficient permissions" or "illegal operation object"), and the abnormal operation log is recorded at the same time.

[0118] S4.2 Memory Injection Attack Prevention and Anomaly Detection.

[0119] To prevent memory injection attacks, a "multi-factor verification + abnormal behavior detection" approach is adopted. The specific algorithm application process is as follows: 1. Triple verification for memory writes: For memory addition (write) operations, a triple verification of "content legality + logical consistency + source reliability" is performed to block the injection of malicious memory fragments. (1) Content legality verification: The BERT-based text classification algorithm is used to detect the legality of the memory fragment to be written and identify malicious content (such as false privacy information and malicious associations). If malicious content is detected, the writing is rejected. (2) Logical consistency verification: A logical reasoning algorithm based on a lightweight privacy domain logical knowledge graph is used to determine whether there is a logical contradiction between the memory segment to be written and the existing memory nodes in the memory chain.

[0120] This invention uses four privacy domains—healthcare, finance, identity, and behavior—as examples to illustrate a standardized knowledge graph construction process. Those skilled in the art can refer to this process to build similar logical knowledge graphs in their respective business scenarios. The specific construction method and complete process of the knowledge graph are as follows: ① Domain boundary limitation: It focuses on four major privacy domains: medical, financial, identity and behavior. It only includes concepts that are strongly related to user privacy entities, health status, asset information and behavioral trajectory, and does not include common sense and irrelevant domain knowledge, which greatly reduces the scale and construction difficulty of the graph.

[0121] ② Privacy Entity and Relationship Extraction: The BERT-BiLSTM-CRF entity recognition algorithm is used to extract core entities in the domain from industry standards, privacy compliance texts, and business dialogue corpora, including diseases, drugs, document types, asset categories, and behavioral scenarios; at the same time, three basic relationships between entities are extracted: mutual exclusion relationship, hierarchical subordinate relationship, and causal constraint relationship.

[0122] ③ Manual pre-setting and machine expansion of logical rules: First, typical privacy-preserving logical rules are manually pre-set, such as "diagnosed hypertension" and "no history of any chronic disease" being mutually exclusive, and "mild hypertension" belonging to "hypertension symptoms" without conflict; then, rule matching and semantic similarity clustering are used to automatically expand similar rules to form a large-scale rule library.

[0123] ④ Attribute labeling and semantic type classification: Label each entity with semantic attributes, including two categories: deterministic factual attributes and fuzzy speculative attributes; deterministic attributes correspond to rigid expressions such as "confirmed, clearly held, definitely occurred"; fuzzy speculative attributes correspond to uncertain expressions such as "possible, suspected, estimated, highly probable".

[0124] ⑤ Graph-structured storage: It uses triples <entity1, relation, entity2> to store the knowledge graph, builds a lightweight domain knowledge graph, and establishes entity indexes and rule indexes to support fast retrieval and logical matching reasoning.

[0125] Logical conflict detection rules (including fuzzy and uncertain semantic processing): During verification, semantic parsing and attribute classification are first performed on the nodes to be written to memory and the existing memory nodes: If both memories are definite fact attributes and they match a mutually exclusive relationship in the knowledge graph, then a logical contradiction is determined, the writing is refused, and a "logical inconsistency" message is displayed. If any memory contains vague speculative attributes (such as "may have high blood pressure" or "may have a medical need"), even if there is a literal conflict on the surface, it will not be judged as a logical contradiction and will be allowed to be written normally, thus avoiding false interception of uncertain semantics.

[0126] The graph construction process, rule types, and semantic attribute division methods described above in this invention are exemplary standard implementation paradigms and not the only limiting solutions. Those skilled in the art can refer to the same construction steps, add or remove domains, expand the entity and rules, and adjust the deterministic and fuzzy semantic division standards according to their own business needs to customize and adapt their own logical knowledge graphs without relying on the fixed graph dataset limited by this invention.

[0127] (3) Source Reliability Verification: A source verification algorithm based on digital signatures is used to verify the source of the memory fragment to be written, confirming that the source is a legitimate entity (such as an authorized user, trusted tool, or core module of an intelligent agent). The specific process is as follows: the legitimate source entity digitally signs the memory fragment to be written (using the RSA-2048 algorithm, with the private key kept by the source entity and the public key stored in a secure key store). The secure sandbox reads the digital signature and public key, and verifies the legitimacy of the signature through a signature verification algorithm. If the signature is invalid or the source is illegal, the writing is rejected, and a malicious injection attempt log is recorded.

[0128] 2. Anomaly Detection Algorithm: An improved Isolation Forest algorithm with time decay weights is used to perform real-time anomaly detection on the agent's memory operation behavior, identifying abnormal characteristics of memory injection attacks. The specific algorithm application process is as follows: (1) Feature extraction: Extract behavioral features of memory operations, including operation frequency, operation type distribution, operation object sensitivity level distribution, operation time distribution, and the behavioral trajectory of the operation subject, and construct a 128-dimensional behavioral feature vector; (2) Time decay weighting: Assign time decay weights to each behavioral feature. The value is (0,1). ; in: Attenuation coefficient, adjustable range θ∈[0.05,0.2], preferred value 0.1; : Current detection timestamp; : The timestamp of the i-th operation; The time difference between the current time and the time the operation occurred. Recent operations are given higher weight, improving real-time detection capabilities; (3) Model Training: An improved isolated forest model was constructed. This model, based on the traditional isolated forest model, introduces a time decay factor to assign higher weights to recent operations, improving the real-time performance of anomaly detection. The training dataset consists of a normal memory operation behavior dataset and a malicious memory injection operation behavior dataset (containing 50,000+ normal samples and 20,000+ malicious samples). The training process is as follows: ① Use the behavioral feature vector as the model input and "normal operation" and "abnormal operation (memory injection)" as the model output labels; ② The reconstruction error is used as the loss function of the model to optimize the model parameters. The formula for the reconstruction error is as follows: ; in, Let be the original behavioral feature vector of the i-th sample. The reconstructed behavioral feature vector is n, where n is the number of samples. It is an L2 norm; ③ The stochastic gradient descent (SGD) optimizer was adopted, with a learning rate of 5e-4, 50 iterations, and a batch size of 64. The model hyperparameters were adjusted through cross-validation to ensure the detection accuracy of the model. ④ After training, the model has an anomaly detection accuracy of ≥99.2% and a false positive rate of ≤0.5%, and can accurately identify abnormal behaviors of memory injection attacks.

[0129] (4) Real-time detection and response: The real-time memory operation behavior feature vector of the agent is input into the trained improved isolated forest model. The model outputs anomaly scores for the operation behavior, and an anomaly score threshold is set (the default threshold is 0.8). This threshold is optimized and determined through a validation set consisting of 50,000 normal memory operation samples and 20,000 memory injection attack samples. The optimization goal is to achieve an anomaly detection accuracy of ≥99.2% and a false positive rate of ≤0.5%, achieving the optimal balance of "high detection and low false positive" in general dialogue scenarios. The threshold supports dynamic adjustment: it can be adjusted to 0.75 in high-security scenarios to improve attack detection sensitivity; and to 0.85 in low-sensitivity scenarios to reduce the false blocking rate of normal operations.

[0130] When the anomaly score is greater than or equal to the threshold, it is determined to be an abnormal operation (suspected memory injection attack), and immediate response measures are taken: block the current operation, freeze the permissions of the operation subject, record the details of the abnormal operation (including the operation subject, operation content, operation time, and abnormal characteristics), and send an alarm message to the administrator to facilitate timely handling by the administrator.

[0131] 3. Memory chain integrity verification: A memory chain integrity verification algorithm based on hash linked lists is adopted to periodically verify the integrity of the memory chain's topology and memory nodes, preventing memory injection attacks from compromising the semantic integrity of the memory chain. The specific process is as follows: the semantic privacy fingerprints of each memory node in the memory chain are concatenated in chronological order to form a hash linked list. The hash value of each node includes the hash value of the previous node. The root hash value of the entire hash linked list is periodically calculated and compared with a preset root hash value. If they do not match, it indicates that the memory chain has been tampered with (memory injection exists), and an abnormal response is immediately triggered to restore the original state of the memory chain and trace the source of the tampering.

[0132] S4.3 Remember operation logs and compliance audits.

[0133] To ensure the traceability and compliance of memory operations, a complete memory operation log and compliance audit mechanism is constructed. The specific implementation process is as follows: 1. Operation Log Recording: All memory operations (create, delete, modify, query, and backtrack) are comprehensively logged. Log content includes: operation ID (generated using a UUID algorithm), operation subject (identity identifier, permission level), operation type, operation object (memory node ID, semantic privacy fingerprint, sensitivity level), operation time, operation content, operation result (success / failure), and exception identifier (normal / abnormal). Logs are encrypted and stored in a dedicated log storage module within the TEE to prevent tampering or theft.

[0134] 2. Log Hierarchical Management: Operation logs are hierarchically managed according to the sensitivity level of the operation object: operation logs of L0 and L1 level memory nodes can be viewed by subjects with P1 and above permissions; operation logs of L2 level memory nodes can be viewed by subjects with P2 and above permissions; operation logs of L3 level memory nodes can only be viewed by subjects with P3 permissions (authorized administrators), ensuring the privacy and security of logs.

[0135] 3. Compliance Audit Algorithm: A compliance audit algorithm based on rule engines and machine learning is adopted to automatically audit operation logs and identify non-compliant operations (such as unauthorized access, unauthorized tampering, and memory injection attempts). The specific algorithm process is as follows: (1) Rule engine construction: Build a compliance audit rule base, including permission compliance rules, operation compliance rules, privacy protection compliance rules, etc., such as "P1 permission subjects shall not delete L2 level memory nodes", "It is forbidden to inject false privacy information into the memory chain", "The call to L3 level memory nodes must record detailed purpose", etc. (2) Log parsing and matching: Natural language processing (NLP) algorithms are used to decrypt and parse the encrypted operation logs, extract key information (operation subject, operation type, operation object, operation content) from the logs, and match them with the rules in the compliance audit rule base to determine whether the operation is compliant; (3) Machine learning-assisted auditing: The improved XGBoost algorithm is used to train on historical compliance audit data to build a non-compliant operation identification model, which can identify abnormal operations (such as new memory injection attacks) not covered by the rule engine, thereby improving the comprehensiveness of compliance auditing; (4) Audit report generation: Regularly (e.g., daily, weekly) generate compliance audit reports, including statistics on compliant operations, details of non-compliant operations, analysis of abnormal operations, risk warnings, etc. The reports are in encrypted format and can only be viewed and exported by authorized administrators to meet the compliance requirements of laws and regulations such as the Personal Information Protection Law and GDPR.

[0136] S4.4 Privacy control of memory forgetting and retrieval.

[0137] For the intelligent agent's memory forgetting (deleting invalid / sensitive memories) and memory recall (querying historical memories) operations, a special privacy control mechanism is designed to ensure the compliance and privacy security of the operations. The specific implementation process is as follows: 1. Privacy Control of Memory Forgetting: Memory forgetting operations are divided into active forgetting (initiated by the user / administrator) and passive forgetting (automatically triggered by the system, such as memory expiration or sensitive memory deletion). Both types of operations must undergo strict privacy compliance verification. (1) Active Forgetting: When a user / administrator initiates a memory forgetting request, they need to submit information such as the purpose of forgetting and the object to be forgotten (memory node ID). The system uses RBAC+ABAC permission verification to confirm that the initiator has the corresponding permissions (e.g., forgetting L2 level memory nodes requires P2 or higher permissions). At the same time, it verifies whether the forgetting operation complies with privacy compliance requirements (e.g., users' core privacy memories must not be forgotten unless written authorization is obtained from the user). After the verification is passed, the forgetting operation is executed: irreversible deletion is performed on L0, L1, and L2 level memory nodes (using a data shredding algorithm to overwrite the original data and prevent data recovery). For L3 level memory nodes, irreversible deletion is performed in TEE and the forgetting operation log is recorded. (2) Passive forgetting: The system adopts a memory forgetting algorithm based on time decay. For short-term memory nodes (evolutionary period ≤ 24 hours), the forgetting operation is automatically performed after the expiration. For long-term memory nodes, the validity and sensitivity are checked periodically (e.g., monthly). For invalid memories (e.g., outdated temporary information) and low-sensitivity memories (L0 and L1 levels), the forgetting operation is automatically performed. For L2 and L3 level sensitive memories, the forgetting operation can only be performed after the administrator's review, to ensure that sensitive memories are not accidentally deleted.

[0138] 2. Privacy Controls for Memory Retrieval: The memory retrieval operation is used to query the agent's historical memories and requires multiple layers of privacy control. (1) Permission verification: The subject that initiates the memory backtracking request must have the corresponding permissions (e.g., backtracking L2 level memory nodes requires P2 or higher permissions). The system uses RBAC+ABAC permission verification to confirm that the subject's permissions and the purpose of the operation are compliant. (2) Scope control of memory backtracking: The scope of memory backtracking is limited according to the permission level of the operating subject: Subjects with P0 permission can only backtrack L0 level memory nodes; subjects with P1 permission can backtrack L0 and L1 level memory nodes; subjects with P2 permission can backtrack L0, L1, and L2 level memory nodes (only de-identified data can be viewed); subjects with P3 permission can backtrack all levels of memory nodes (can view L3 level original data); (3) Retrospective Log Recording: All memory retrospective operations are recorded in detail, including information such as the retrospective subject, retrospective scope, retrospective time, and retrospective content. The logs are stored in encrypted form for subsequent compliance audits. (4) Temporary data management: During the memory backtracking process, the temporary data generated (such as the memory fragments backtracked) is stored in a security sandbox. After the backtracking operation is completed, the temporary data is destroyed immediately to prevent the leakage of temporary data.

[0139] Step S4 establishes a complete privacy control mechanism for memory operations, enabling full-process compliance management of all operations such as memory addition, deletion, modification, query, and backtracking. This effectively prevents memory injection attacks, solves the technical problem of lack of privacy control for memory operations in existing technologies, and ensures the security, controllability, and privacy compliance of the memory chain.

[0140] This invention breaks through the limitations of traditional privacy protection methods such as "full encryption and isolated protection." Based on the topological structure and semantic characteristics of AI agent memory chains, it constructs a complete technical system of "memory chain topology deconstruction - semantic privacy fingerprint generation - hierarchical desensitization engine - memory operation privacy control." Through innovative algorithm applications, it achieves a synergistic balance between privacy protection and intelligent reasoning capabilities, solves the unique privacy risks of agent memory chains, and realizes fine-grained, intelligent, and controllable privacy protection.

[0141] Example 2 This embodiment provides a semantic fingerprint-based AI agent privacy-level de-identification system, including: The memory chain topology deconstruction module is configured to: process various types of memory data of the agent, extract multiple memory nodes, construct the associated edges between memory nodes, connect the memory nodes and associated edges in temporal order to form a memory temporal chain, and construct a three-layer topology model; The semantic privacy fingerprint generation module is configured to: extract the semantic feature vector of each memory node based on a three-layer topology model, and classify the semantic feature vector to generate a privacy-sensitive label for each memory node; generate a unique semantic privacy fingerprint for each memory node based on the semantic feature vector and the privacy-sensitive label; construct a privacy association graph based on the memory node, the associated edge, and the semantic privacy fingerprint, and identify privacy inference paths that can deduce sensitive privacy information. The hierarchical desensitization engine module is configured to: build a hierarchical desensitization engine to block privacy leaks in the privacy inference path; determine the sensitivity level of each memory node based on the privacy sensitivity label; and use differentiated desensitization algorithms to process the memory nodes for different sensitivity levels. The memory operation privacy control module is configured to: build a memory operation privacy control mechanism, perform permission verification and anomaly detection on operation requests initiated against memory nodes to prevent memory injection attacks, and log and audit all operations.

[0142] The memory chain topology deconstruction module is used to deconstruct the memory chain of the AI ​​agent, constructing a three-layer topology model of "node → edge → temporal chain", specifically including: ① Node Extraction Unit: The improved BERT-BiLSTM-CRF algorithm, which integrates attention from memory sources, is used to automatically extract memory nodes from the agent's long-term memory, short-term memory, conversational memory, and tool call memory. The nodes are then deduplicated and classified, and each memory node is assigned a unique node ID and source label. ②Association edge construction unit: The improved Sentence-BERT algorithm with temporal penalty term is used to calculate the semantic similarity between memory nodes. Combined with the GAT algorithm, association edges between memory nodes are automatically constructed, association weights are assigned, and classification is performed. ③ Temporal chain construction unit: The temporal features of memory nodes are extracted using the Time2Vec temporal coding algorithm and combined with the TGNN algorithm to construct a memory temporal chain and perform hierarchical management, providing a temporal basis for subsequent privacy classification and desensitization.

[0143] The semantic privacy fingerprint generation module is used to generate a semantic privacy fingerprint for each memory node, construct a privacy association graph, and identify privacy inference paths, specifically including: ① Semantic feature extraction unit: The improved VLP algorithm is used to extract deep semantic features for each memory node, generate semantic feature vectors, and optimize the feature vectors by dimensionality reduction using PCA algorithm and normalization using L2 regularization algorithm; ② Sensitive Label Classification Unit: An improved Transformer classification model is used to classify the semantic feature vectors for privacy-sensitive labels, and a sensitive type label and a sensitivity level label are assigned to each memory node; ③ Fingerprint generation unit: An improved SHA-3 algorithm with added salt and fusion of semantic and temporal perturbations is adopted. Combined with the semantic feature vector of the memory node, sensitive label and node ID, a unique semantic privacy fingerprint is generated and a fingerprint index library is constructed. ④ Privacy-related graph unit: The GCN+GAT fusion algorithm with privacy risk attention weighting is adopted. The memory node is used as the vertex, the associated edge is used as the edge, and the semantic privacy fingerprint is used as the vertex attribute to construct a privacy-related graph. The privacy inference path across nodes is automatically identified and risk scoring and screening are performed.

[0144] The graded desensitization engine module is used to achieve differentiated graded desensitization processing based on the sensitivity level of memory nodes, specifically including: ① Strategy Definition Unit: Based on the four sensitivity levels of L0, L1, L2 and L3, define differentiated hierarchical desensitization strategies, and clarify the desensitization objectives, applicable scenarios and core algorithms of each strategy; ②L1 level desensitization unit: The improved BERT semantic generalization algorithm + FF1 format retention encryption algorithm are used to perform irreversible desensitization processing on the L1 level memory node; ③L2 level desensitization unit: The improved HMAC-SHA256 salted hash algorithm + semantic structure preservation algorithm are used to perform irreversible desensitization on L2 level memory nodes, eliminating individual identifiability and preserving semantic structure; ④ Level 3 desensitization unit: It adopts TEE hardware-level isolation storage technology + KVM security sandbox technology to physically isolate and control the L3 level memory nodes, realize hardware-level privacy protection, and record call logs; ⑤ Level 0 processing unit: Performs no desensitization processing on Level 0 memory nodes, directly retains the original plaintext, and ensures normal reasoning and access by the intelligent agent.

[0145] The memory operation privacy control module is used to perform full-process compliance management of all memory operations of the intelligent agent and prevent memory injection attacks. Specifically, it includes: ① Permission verification unit: A four-level operation permission system is constructed using a fusion algorithm of RBAC and ABAC to perform multi-level verification of the main permissions of the remembered operation to ensure operation compliance; ② Attack Prevention Unit: Employs triple verification of memory write, an improved isolated forest anomaly detection algorithm with time decay weight, and a hash linked list integrity verification algorithm to prevent memory injection attacks and identify and block abnormal operations; ③ Log and Audit Unit: All memory operations are encrypted and logged. A rule engine and machine learning fusion algorithm are used to conduct compliance audits, generate audit reports, and ensure that operations are traceable. ④ Forgetting and Recall Control Unit: Implements specific privacy controls for memory forgetting and memory recall operations, including permission verification, scope control, and temporary data management, to ensure operational compliance and privacy security.

[0146] The system also includes a secure storage module for secure storage of all memory data, semantic privacy fingerprints, and operation logs, specifically including: ① Ordinary storage unit: A symmetric encryption algorithm is used to encrypt and store L0, L1, and L2 level memory nodes, fingerprint index library, and ordinary operation logs to ensure data security; ②TEE isolated storage unit: Employs Trusted Execution Environment (TEE) technology to perform hardware-level isolated storage of L3 memory nodes and L3 operation logs, physically isolated from other storage units to resist external attacks; ③Key Management Unit: Adopts a hierarchical key management mechanism to securely manage encryption keys and digital signature keys, update keys regularly, prevent key leakage, and ensure the security and integrity of stored data.

[0147] The core control module serves as the system's central control hub, coordinating the collaborative operation of various modules. It receives operation requests from agents and users, schedules modules to execute corresponding functions, handles data interactions between modules, and ensures the stable operation of the entire system. Furthermore, the core control module possesses anomaly response capabilities. When abnormal situations such as privacy risks or memory injection attacks are detected, it immediately triggers alarms and emergency response measures to safeguard the system's privacy, security, and compliance.

[0148] The various modules of the above system work together closely to form a complete technical closed loop of "topology deconstruction - semantic fingerprinting - hierarchical desensitization - operation control - secure storage", which realizes full-process privacy protection of the AI ​​agent's memory chain, solves the core technical problems of existing technologies, and ensures that the agent can achieve secure protection of privacy data while retaining its complete reasoning ability.

[0149] It should be noted that the above modules correspond to the steps in Embodiment 1, and the examples and application scenarios implemented by the above modules and their corresponding steps are the same, but are not limited to the content disclosed in Embodiment 1. It should also be noted that the above modules can be executed in a computer system as part of the system.

[0150] In further embodiments, the following is also provided: An electronic device includes a memory and a processor, as well as computer instructions stored in the memory and running on the processor, which, when executed by the processor, perform the method described in Embodiment 1. For brevity, further details are omitted here.

[0151] It should be understood that in this embodiment, the processor can be a central processing unit (CPU), or it can be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor.

[0152] A computer-readable storage medium for storing computer instructions that, when executed by a processor, perform the method of Embodiment 1.

[0153] The method in Example 1 can be directly executed by a hardware processor, or it can be executed by a combination of hardware and software modules within the processor. The software modules can reside in readily available storage media in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory; the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method. To avoid repetition, a detailed description is not provided here.

[0154] Those skilled in the art will recognize that the units and algorithm steps described in conjunction with the embodiments herein can be implemented in electronic hardware or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0155] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.

Claims

1. A privacy-graded de-identification method for AI intelligent agents based on semantic fingerprints, characterized in that, Includes the following steps: The various memory data of the intelligent agent are processed, multiple memory nodes are extracted, and the associated edges between memory nodes are constructed. The memory nodes and associated edges are connected in sequence according to the time order to form a memory time chain, and a three-layer topology model is constructed. Based on the three-layer topology model, the semantic feature vector of each memory node is extracted and classified to generate a privacy-sensitive label for each memory node; a unique semantic privacy fingerprint for each memory node is generated based on the semantic feature vector and the privacy-sensitive label; a privacy association graph is constructed based on the memory node, the associated edges and the semantic privacy fingerprint, and privacy reasoning paths that can deduce sensitive privacy information are identified. A hierarchical desensitization engine is constructed to block privacy leaks in the privacy inference path. The sensitivity level of each memory node is determined based on the privacy-sensitive label, and a differentiated desensitization algorithm is used to process the memory node for different sensitivity levels. A privacy control mechanism for memory operations is constructed to perform permission verification and anomaly detection on operation requests initiated against memory nodes in order to prevent memory injection attacks, and all operations are logged and audited for compliance.

2. The method for privacy-graded de-identification of AI intelligent agents based on semantic fingerprints as described in claim 1, characterized in that, The extraction of memory nodes specifically includes: using the BERT model to extract semantic feature vectors from the memory data, using the BiLSTM model to capture the temporal dependencies of the semantic feature vectors to obtain temporal feature vectors, performing a dimension-wise weighted operation on the temporal feature vectors according to the memory source, and using the CRF model to label the weighted feature vectors with entity labels to extract memory nodes.

3. The method for privacy-graded de-identification of AI intelligent agents based on semantic fingerprints as described in claim 1, characterized in that, Constructing the association edges between memory nodes specifically includes: calculating the semantic similarity between any two memory nodes, wherein the semantic similarity is the product of cosine similarity and temporal penalty factor, and constructing association edges between two memory nodes whose semantic similarity is greater than or equal to the dynamic threshold of semantic similarity.

4. The method for privacy-graded de-identification of AI intelligent agents based on semantic fingerprints as described in claim 1, characterized in that, The identification of privacy inference paths that can derive sensitive privacy information specifically includes: using an algorithm that combines graph convolutional networks and graph attention networks, and introducing a gain coefficient based on the sensitivity level into the calculation of the attention coefficient of the graph attention network, performing weighted analysis on the nodes and associated edges in the privacy association graph, calculating the privacy risk score of each path, and determining the path with a privacy risk score exceeding an adaptive threshold as a privacy inference path.

5. The method for privacy-graded de-identification of AI intelligent agents based on semantic fingerprints as described in claim 1, characterized in that, The differentiated desensitization algorithm includes at least an irreversible desensitization algorithm and a hardware-level isolated storage mechanism; for memory nodes of the first sensitivity level, the BERT semantic generalization algorithm combined with the format-preserving encryption algorithm is used for irreversible desensitization; For memory nodes at the second level of sensitivity, an irreversible desensitization is performed using a salted hash algorithm combined with a semantic structure preservation algorithm. For memory nodes at the third sensitivity level, a trusted execution environment is used for hardware-level isolated storage, and controlled access is achieved through a security sandbox.

6. The method for privacy-graded de-identification of AI intelligent agents based on semantic fingerprints as described in claim 1, characterized in that, An algorithm combining role-based access control and attribute-based access control is used for permission verification; an improved isolated forest algorithm with time decay weights is used for real-time abnormal behavior detection; and a hash-based linked list verification algorithm is used to verify the integrity of the memory chain.

7. The method for privacy-graded de-identification of AI intelligent agents based on semantic fingerprints as described in claim 1, characterized in that, Generate a unique semantic privacy fingerprint for each memory node, specifically including: The semantic feature vector and privacy-sensitive label are perturbed, including semantic perturbation based on sensitivity level and temporal perturbation based on timestamp; the perturbed information is input into a hash function to generate a unique semantic privacy fingerprint for the memory node.

8. A privacy-graded de-identification system for AI intelligent agents based on semantic fingerprints, characterized in that, include: The memory chain topology deconstruction module is configured to: process various types of memory data of the agent, extract multiple memory nodes, construct the associated edges between memory nodes, connect the memory nodes and associated edges in temporal order to form a memory temporal chain, and construct a three-layer topology model; The semantic privacy fingerprint generation module is configured to: extract the semantic feature vector of each memory node based on the three-layer topology model, and classify the semantic feature vector to generate a privacy-sensitive label for each memory node; generate a unique semantic privacy fingerprint for each memory node based on the semantic feature vector and the privacy-sensitive label; construct a privacy association graph based on the memory node, associated edges and semantic privacy fingerprint, and identify privacy inference paths that can deduce sensitive privacy information; The hierarchical desensitization engine module is configured to: construct a hierarchical desensitization engine to block privacy leakage in the privacy inference path; determine the sensitivity level of each memory node based on the privacy sensitive label; and process the memory node using a differentiated desensitization algorithm for different sensitivity levels. The memory operation privacy control module is configured to: build a memory operation privacy control mechanism, perform permission verification and anomaly detection on operation requests initiated against memory nodes to prevent memory injection attacks, and log and audit all operations.

9. An electronic device, characterized in that, It includes a memory and a processor, as well as computer instructions stored in the memory and running on the processor, which, when executed by the processor, perform the method according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, Used to store computer instructions, which, when executed by a processor, perform the method described in any one of claims 1-7.