Multi-voter cooperative agent tool invocation security execution method and device
Patent Information
- Application Number
- CN202610989570.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-03
- Publication Date
- 2026-09-25
AI Technical Summary
[0004]本发明的目的在于提出一种多投票器协同的智能体工具调用安全执行方法及装置,以解决智能体工具调用前缺乏协同风险审核、难以结合上下文识别连续隐蔽风险的技术问题,达到对动作意图进行分级审核、关联分析和执行控制的效果
[0023]1.本发明通过根据用户的工具调用请求生成并记录动作意图,使待审核对象与具体工具调用行为相对应,为后续多投票器风险审核、关联上下文读取和历史审核信息复用提供数据基础。
Smart Images

Figure CN122818342A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of intelligent agent tool invocation security technology, and particularly relates to a method and apparatus for secure execution of intelligent agent tool invocation through multi-voter collaboration. Background Technology
[0002] With the widespread application of large language models in intelligent agents, these agents are now capable of autonomously making decisions and invoking tools to perform actions such as file processing, network access, system operations, and business process control. Unlike the fixed execution patterns of traditional applications, the action intentions generated by intelligent agents are highly dynamic, context-dependent, and open-ended. Their behavior is often influenced by user input, historical interactions, external environmental feedback, and the model's own inference results. Therefore, how to effectively, securely, and interpretably audit the actions performed by the agent before execution has become a crucial issue in the practical application of intelligent agents.
[0003] The Harness mechanism for intelligent agents refers to an infrastructure framework for encapsulating, scheduling, monitoring, and managing the lifecycle of intelligent agents. It provides a standardized operating environment for agents, handling functions such as task reception, tool invocation, task orchestration, execution result feedback, and state management. However, this mechanism focuses more on execution process management and lacks collaborative security analysis capabilities for action risks. Currently, after generating action intentions, the agent's execution layer and the large language model layer are decoupled and operate independently, lacking the ability to collaboratively analyze action execution risks. It is difficult to combine historical context for global judgment, making it impossible to identify hidden risks formed during the continuous execution of multiple seemingly normal actions. Therefore, there is an urgent need for a multi-voting agent collaborative tool invocation security execution method and device, enabling multiple voters to share risk information, conduct joint analysis, and make hierarchical judgments around the same action intention. This would maintain review flexibility while improving the ability to identify dangerous actions, combined attack actions, and covert unauthorized actions. Summary of the Invention
[0004] The purpose of this invention is to propose a method and apparatus for secure execution of intelligent agent tool calls using multi-voter collaboration, in order to solve the technical problems of lack of collaborative risk review before intelligent agent tool calls and difficulty in identifying continuous hidden risks in combination with context, thereby achieving the effect of hierarchical review, correlation analysis and execution control of action intentions.
[0005] To achieve the above objectives, the present invention adopts the following technical solution.
[0006] A method for secure execution of multi-voting agent tool calls includes the following steps: Receive a user's tool call request, and generate and record the action intent based on the tool call request; Based on the stated action intent and associated context, the action intent is subject to multi-voter risk audit to obtain audit result elements; Record the audit result elements, and perform correlation analysis based on the audit result elements to obtain the correlation analysis results; Risk aggregation is performed based on the correlation analysis results to obtain the risk aggregation results; The risk aggregation result is recorded, and an action execution determination result is generated based on the risk aggregation result, so as to control the execution of the action corresponding to the action intent according to the action execution determination result.
[0007] Furthermore, receiving a user's tool invocation request, generating and recording an action intent based on the tool invocation request, including: The intent of the user's tool call request is parsed to obtain candidate call actions; An action intent is generated based on the candidate call action, and the action intent is recorded.
[0008] Furthermore, the recorded intention of the action includes: The recording format is determined based on the data size of the stated action intent, resulting in a formatted action intent; The formatted action intent is losslessly compressed and metadata is appended to obtain action intent recording data; The storage path is determined based on the generation time of the action intent recording data, and the action intent recording data is recorded according to the storage path.
[0009] Furthermore, based on the stated action intent and associated context, a multi-voter risk audit is performed on the action intent to obtain audit result elements, including: Obtain the associated context based on the stated action intent; Based on the action intent and the associated context, a risk assessment is performed on the action intent to obtain an assessment result; The risk review path is determined based on the results of the initial review. When the risk review path is a direct generation path, review result elements are generated based on the first review result; When the risk review path is a continued review path, a second risk review is performed based on the action intent and the associated context, and review result elements are generated based on the first review result and the second review result.
[0010] Furthermore, based on the stated action intent and the associated context, a risk assessment is performed on the action intent to obtain an assessment result, including: The action intent is subjected to static risk review based on a preset set of rules to obtain the rule review result; Based on the isolated execution environment, a pre-execution risk audit is performed on the stated action intent to obtain the sandbox audit result; The combined results of the rule review and the sandbox review are used to obtain a single review result.
[0011] Furthermore, based on the results of the initial audit, a risk audit path is determined, including: Extract the rule-based audit results and the sandbox audit results from the first audit result; For the rule review results and the sandbox review results, respectively determine the corresponding level thresholds; Based on the rule review results, the sandbox review results, and their respective corresponding level thresholds, a risk level combination corresponding to a single review result is obtained. When all of the risk level combinations are low risk or there is a high risk, the risk review path will be determined as the direct generation path. When the risk level combination indicates a medium risk, the risk review path will be determined as the continued review path.
[0012] Furthermore, a secondary risk review is performed based on the stated action intent and the associated context, and review result elements are generated based on the primary review result and the secondary review result, including: Risk assessment is performed based on the semantic consistency between the action intent, the associated context, and the user's tool call request to obtain the semantic assessment result; Trajectory risk assessment is performed based on the stated action intent and the historical action sequence in the associated context to obtain trajectory assessment results; The audit result elements are obtained by summarizing the audit results, the semantic audit results, and the trajectory audit results.
[0013] Furthermore, the audit result elements are recorded, and a correlation analysis is performed based on the audit result elements to obtain the correlation analysis results, including: Record the elements of the audit results; Based on the audit result elements, extract the risk score, confidence level and audit reason corresponding to each of the multiple voters to obtain shared risk information; Based on the shared risk information, risk association reasoning is performed to obtain risk association relationships; Based on the aforementioned risk relationships, a joint risk conclusion is generated, and the correlation analysis results are obtained.
[0014] Furthermore, risk association reasoning is performed based on the shared risk information to obtain risk association relationships, including: Based on the shared risk information, the risk type corresponding to each voter is identified, and a risk type set is obtained; Based on the set of risk types and the reasons for review, determine the consistency or conflict relationship between the review results of multiple voters; Risk associations are generated based on the consistency relationship or the conflict relationship.
[0015] Furthermore, risk aggregation is performed based on the correlation analysis results to obtain risk aggregation results, including: Based on the correlation analysis results, the risk score, voter weight, and collaborative correction information for each voter are determined. Risk is aggregated based on the risk score, the voter weight, and the collaborative correction information to obtain a comprehensive risk value; Risk aggregation results are generated based on the comprehensive risk value and risk threshold.
[0016] Furthermore, the collaborative correction information is determined, including: Based on the correlation analysis results, consistent risk relationships and conflict risk relationships among multiple voters are identified; Based on the aforementioned consistent risk relationship, risk increase correction information is determined; Based on the aforementioned conflict risk relationships, determine risk reduction and correction information or review information; Based on the risk increase correction information, the risk decrease correction information, or the review information, collaborative correction information is obtained.
[0017] Further, the risk aggregation result is recorded, and an action execution determination result is generated based on the risk aggregation result, so as to control the execution of the action corresponding to the action intent according to the action execution determination result, including: Record the risk aggregation results; Based on the risk aggregation results, either an allow result or a block result is generated; When an allowed result is generated, the action corresponding to the action intent is executed, and the action execution result is recorded; When a blocking result is generated, the action corresponding to the stated action intent is refused to be executed, and the reason for the blocking is recorded.
[0018] A secure execution device for invoking intelligent agents that coordinate multiple voters, comprising: The intent generation module is used to receive a user's tool call request and generate an action intent based on the tool call request. The voting review module is used to perform multi-voter risk review on the action intent based on the action intent and associated context, and obtain the review result elements; The collaborative analysis module is used to perform correlation analysis based on the audit result elements to obtain correlation analysis results, and to perform risk aggregation based on the correlation analysis results to obtain risk aggregation results; The logging module is used to record the intent of the action, audit result elements, and risk aggregation results; The execution control module is used to generate an action execution determination result based on the risk aggregation result, and to control the execution of the action corresponding to the action intent based on the action execution determination result.
[0019] Furthermore, the collaborative analysis module includes a risk sharing unit, a correlation reasoning unit, and a consensus generation unit; The risk sharing unit is used to generate shared risk information based on the audit result elements; The association reasoning unit is used to perform risk association reasoning based on the shared risk information to obtain risk association relationships; The consensus generation unit is used to generate joint risk conclusions based on the risk correlation.
[0020] A storage medium storing a computer program configured to execute the methods described above at runtime.
[0021] An electronic device includes a processor and a memory, wherein the memory stores a computer program, and the processor executes the computer program to implement the method described above.
[0022] The present invention has achieved the following beneficial effects.
[0023] 1. This invention generates and records action intents based on user tool call requests, so that the object to be reviewed corresponds to the specific tool call behavior, providing a data foundation for subsequent multi-voter risk review, related context reading, and reuse of historical review information.
[0024] 2. This invention performs risk auditing on multiple voters based on action intent and associated context, and can generate audit result elements from different auditing dimensions such as rules, sandbox, semantics and trajectory, thus expanding the risk judgment of action intent from a single auditing method to a multi-source auditing method.
[0025] 3. By recording the elements of the audit results and performing correlation analysis based on these elements, this invention enables the risk scores, confidence levels, and audit reasons of multiple voters to form a shareable and correlated audit basis, reducing information fragmentation caused by independent judgments from each voter.
[0026] 4. This invention aggregates risks based on correlation analysis results, combining the consistency and conflict relationships among multiple voters to form risk aggregation results, so that the risk determination of tool invocation actions does not depend on the conclusion of a single voter.
[0027] 5. By recording the risk aggregation results and generating action execution judgment results based on the risk aggregation results, this invention can form permission or blocking control before the action is executed, and realize hierarchical control of dangerous actions, combined attack actions and covert unauthorized actions. Attached Figure Description
[0028] Figure 1 This is an overall flowchart of a secure execution method for a multi-voter collaborative intelligent agent tool call in an embodiment. Figure 2 This is a schematic diagram of the log recording process provided in an embodiment of the present invention; Figure 3 This is a schematic diagram of the voting review process provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of the collaborative analysis and execution determination process provided in an embodiment of the present invention. Detailed Implementation
[0029] To enable those skilled in the art to better understand the technical solutions in the embodiments of the present invention, and to make the objectives, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the embodiments.
[0030] This invention also provides a method for secure execution of tool invocation by intelligent agents using multi-voting agents. This method is applied to large-scale intelligent agent operation scenarios with tool invocation action execution capabilities. Before execution, it can record action intent, review result elements, risk aggregation results, action execution results, and historical review information, and can read the context associated with the action intent. Multiple voters are configured before execution, including rule voters, sandbox voters, semantic voters, and trajectory voters. Figure 1 As shown, the method includes the following steps: Step S1: Receive the user's tool call request, and generate and record the action intent based on the tool call request.
[0031] Specifically, a user's tool request can be "organize temporary files", and the corresponding generated action intent can be "delete files in a certain temporary directory".
[0032] In an optional embodiment of the present invention, step S1 may include: Step S11: Perform intent parsing on the user's tool call request to obtain candidate call actions.
[0033] Step S12: Generate an action intent based on the candidate call action, and record the action intent.
[0034] In an optional embodiment of the present invention, such as Figure 2As shown, recording the intention of the action in step S12 may include: Step S121: Determine the recording format based on the data size of the action intention to obtain the formatted action intention.
[0035] Specifically, when the data size of the action intent is less than 4KB, the original format is used to determine the formatted action intent; when the data size of the action intent is greater than or equal to 4KB, the action intent is serialized to obtain the formatted action intent. The serialization process can use a unified record format such as Protobuf, MessagePack, or JSON.
[0036] Step S122: The formatted action intent is losslessly compressed and metadata is added to obtain action intent recording data.
[0037] Specifically, lossless compression can use LZ4, Zstandard, or gzip. The record metadata includes timestamp, session ID, log type, and CRC checksum.
[0038] Step S123: Determine the storage path based on the generation time of the action intention recording data, and record the action intention recording data according to the storage path.
[0039] Specifically, when the generation time of the action intent recording data is within 3 days, the action intent recording data is stored in a time-series database; when the generation time of the action intent recording data is between 4 and 30 days, the action intent recording data is stored in an analytical database; and when the generation time of the action intent recording data exceeds 30 days, the action intent recording data is stored in object storage. The time-series database may include InfluxDB, the analytical database may include ClickHouse, and the object storage may include S3.
[0040] Step S2: Based on the action intent and associated context, perform multi-voter risk audit on the action intent to obtain audit result elements.
[0041] Specifically, the audit result elements include risk score, risk level, confidence level, and audit reason, and the risk level includes low risk, medium risk, and high risk.
[0042] In an optional embodiment of the present invention, such as Figure 3 As shown, step S2 may include: Step S21: Obtain the associated context based on the action intent.
[0043] Specifically, the associated context can be read from the recorded data, and the associated context includes historical review information and historical action sequences related to the action intent.
[0044] Step S22: Based on the action intent and the associated context, perform a risk review on the action intent to obtain a review result.
[0045] Step S23: Determine the risk audit path based on the audit results.
[0046] Step S24: When the risk audit path is a direct generation path, generate audit result elements based on the first audit result.
[0047] Step S25: When the risk audit path is a continued audit path, a second risk audit is performed based on the action intent and the associated context, and audit result elements are generated based on the first audit result and the second audit result.
[0048] In an optional embodiment of the present invention, step S22, which involves performing a risk assessment on the action intent based on the action intent and the associated context to obtain an assessment result, may include: Step S221: Perform static risk review on the action intent based on a preset set of rules to obtain the rule review result.
[0049] Specifically, the preset rule set includes at least one of dangerous command rules, privilege escalation rules, file access rules, and network access rules. If a high-risk command is identified, the rule review result includes a high-risk score and a corresponding review reason; for example, the risk score is... , The reason given for the review was the risk of widespread deletion.
[0050] Step S222: Based on the isolated execution environment, perform a pre-execution risk audit on the action intent to obtain the sandbox audit result.
[0051] Specifically, when the action intent is pre-executed in the isolated execution environment, system calls, file changes, and network behavior are recorded; if it is found that the action intent will cause large-scale deletion, abnormal permission use, or unnecessary network connection, the sandbox audit result includes a high-risk score.
[0052] Step S223: Summarize the rule review results and the sandbox review results to obtain a single review result.
[0053] In an optional embodiment of the present invention, step S23, which determines the risk review path based on the first review result, may include: Step S231: Extract the rule audit results and sandbox audit results from the first audit result.
[0054] Step S232: Determine the corresponding level thresholds for the rule review results and the sandbox review results respectively.
[0055] Specifically, the rule review results and the sandbox review results can correspond to different level thresholds, which are used to distinguish between low risk, medium risk and high risk.
[0056] Step S233: Based on the rule review results, the sandbox review results, and their respective corresponding level thresholds, obtain the risk level combination corresponding to a single review result.
[0057] Specifically, the risk score is represented by a continuous value, and the risk score satisfies... .in, Indicates the first Each voter outputs a risk score. As an optional method, when... When it is less than 0.3, it is judged as low risk; when A value greater than or equal to 0.3 and less than 0.85 is considered medium risk; when... A value greater than or equal to 0.85 is considered high risk.
[0058] Step S234: When all of the risk level combinations are low risk or there is a high risk, the risk review path is determined to be the direct generation path.
[0059] Step S235: When the risk level combination indicates the presence of medium risk, the risk review path is determined as the continued review path.
[0060] In an optional embodiment of the present invention, step S25, which involves performing a secondary risk review based on the action intent and the associated context, and generating review result elements based on the primary review result and the secondary review result, may include: Step S251: Perform a risk audit based on the semantic consistency between the action intent, the associated context, and the user's tool call request to obtain the semantic audit result.
[0061] Specifically, the semantic review result can be obtained by analyzing the semantic consistency between the action intent and the user's tool call request through a large language model; if the action intent deviates significantly from the user's goal, the semantic review result includes a high-risk score and a corresponding review reason, which can be that the behavior is inconsistent with the user's goal.
[0062] Step S252: Perform trajectory risk review based on the action intent and the historical action sequence in the associated context to obtain the trajectory review result.
[0063] Specifically, the trajectory review result can be obtained by reading the recorded historical action sequence, constructing the behavior trajectory, and performing anomaly detection on the behavior trajectory; if continuous abnormal access, repeated probing, or suspicious switching behavior is found, the risk score in the trajectory review result will be increased.
[0064] Step S253: Summarize the first review result, the semantic review result, and the trajectory review result to obtain the review result elements.
[0065] Specifically, when the risk audit path is a direct generation path, the audit result elements include the risk score, risk level, confidence level, and audit reason from the rule audit result and the sandbox audit result; when the risk audit path is a continued audit path, the audit result elements include the risk score, risk level, confidence level, and audit reason from the rule audit result, the sandbox audit result, the semantic audit result, and the trajectory audit result.
[0066] Step S3: Record the audit result elements and perform correlation analysis based on the audit result elements to obtain the correlation analysis results.
[0067] In an optional embodiment of the present invention, step S3 may include: Step S31: Record the audit result elements.
[0068] Step S32: Based on the audit result elements, extract the risk score, confidence level and audit reason corresponding to each of the multiple voters to obtain shared risk information.
[0069] Step S33: Based on the shared risk information, perform risk association reasoning to obtain risk association relationships.
[0070] Step S34: Generate joint risk conclusions based on the risk correlations to obtain correlation analysis results.
[0071] Specifically, when the audit results of multiple voting devices are consistent, the joint risk conclusion can be generated based on the consistent conclusion; when the audit results of multiple voting devices conflict, the joint risk conclusion may include information on upgrading the review level or supplementary audit information.
[0072] In an optional embodiment of the present invention, step S33, which involves performing risk association reasoning based on the shared risk information to obtain risk association relationships, may include: Step S331: Identify the risk type corresponding to each voter based on the shared risk information to obtain a risk type set.
[0073] Step S332: Based on the set of risk types and the reasons for review, determine the consistency or conflict relationship between the review results of multiple voters.
[0074] Specifically, if the rule review result corresponds to deleting the system directory, the trajectory review result corresponds to an anomaly scan, and the semantic review result corresponds to deviation from the task objective, then the consistency relationship corresponding to the combined behavior can be determined based on the set of risk types and the review reasons.
[0075] Step S333: Generate a risk association relationship based on the consistency relationship or the conflict relationship.
[0076] Step S4: Perform risk aggregation based on the correlation analysis results to obtain risk aggregation results.
[0077] In an optional embodiment of the present invention, such as Figure 4 As shown, step S4 may include: Step S41: Based on the correlation analysis results, determine the risk score, voter weight, and collaborative correction information for each voter.
[0078] Specifically, the rule-based voter, sandbox voter, semantic voter, and trajectory voter can be dynamically added or removed through policy configuration. If the operating scenario is geared towards high security, the weights of the rule-based voter and the sandbox voter can be increased; if the operating scenario is geared towards high availability, the weight of the semantic voter can be increased. The weights of each voter can also be adjusted based on historical audit performance.
[0079] Step S42: Based on the risk score, the voter weight, and the collaborative correction information, risk aggregation is performed to obtain a comprehensive risk value.
[0080] Specifically, the comprehensive risk value satisfies: in, This represents the overall risk value; Indicates the first Each voter corresponds to a weight; Indicates the first The risk score output by each voter; Indicates the number of voting machines; This represents a collaborative correction term, which is used to indicate the degree of risk consistency or conflict among multiple voters.
[0081] Step S43: Generate a risk aggregation result based on the comprehensive risk value and risk threshold.
[0082] Specifically, when the overall risk value is greater than a preset risk threshold When the risk aggregation result corresponds to the blocking result; when the comprehensive risk value is less than or equal to a preset risk threshold... At that time, the risk aggregation result corresponds to the allowed result.
[0083] In an optional embodiment of the present invention, determining the cooperative correction information in step S41 may include: Step S411: Based on the correlation analysis results, identify the consistency risk relationship and conflict risk relationship among multiple voters.
[0084] Step S412: Determine risk increase correction information based on the consistent risk relationship.
[0085] Specifically, when multiple voters simultaneously target the same type of dangerous behavior, the risk increase correction information is used to increase the collaborative correction term.
[0086] Step S413: Determine risk reduction correction information or review information based on the conflict risk relationship.
[0087] Specifically, when multiple voting devices make contradictory judgments, the risk reduction correction information is used to reduce the collaborative correction item, or the review information is used to trigger a supplementary voting device to review again or increase the level of manual confirmation.
[0088] Step S414: Based on the risk increase correction information, the risk decrease correction information, or the review information, obtain collaborative correction information.
[0089] Step S5: Record the risk aggregation result and generate an action execution determination result based on the risk aggregation result, so as to control the execution of the action corresponding to the action intent according to the action execution determination result.
[0090] In an optional embodiment of the present invention, step S5 may include: Step S51: Record the risk aggregation results.
[0091] Specifically, the risk aggregation result may include a comprehensive risk value, collaborative correction information, and threshold comparison information.
[0092] Step S52: Generate an allow result or a block result based on the risk aggregation result.
[0093] Specifically, if both the rule review result and the sandbox review result have a low risk level in a single risk review, an allow result is generated; if either the rule review result or the sandbox review result has a high risk level, a block result is generated; if either the rule review result or the sandbox review result has a medium risk level, an allow result or a block result is generated based on the risk aggregation result.
[0094] Step S53: When an allowed result is generated, execute the action corresponding to the action intent and record the action execution result.
[0095] Step S54: When a blocking result is generated, refuse to execute the action corresponding to the action intent and record the blocking reason.
[0096] This invention also provides a secure execution device for multi-voter collaborative intelligent agent tool invocation, used to execute the above method, including: The intent generation module is used to receive a user's tool call request and generate an action intent based on the tool call request. The voting review module is used to perform multi-voter risk review on the action intent based on the action intent and associated context, and obtain the review result elements; The collaborative analysis module is used to perform correlation analysis based on the audit result elements to obtain correlation analysis results, and to perform risk aggregation based on the correlation analysis results to obtain risk aggregation results; The logging module is used to record the intent of the action, audit result elements, and risk aggregation results; The execution control module is used to generate an action execution determination result based on the risk aggregation result, and to control the execution of the action corresponding to the action intent based on the action execution determination result.
[0097] In an optional embodiment of the present invention, the collaborative analysis module includes a risk sharing unit, an association reasoning unit, and a consensus generation unit; The risk sharing unit is used to generate shared risk information based on the audit result elements; The association reasoning unit is used to perform risk association reasoning based on the shared risk information to obtain risk association relationships; The consensus generation unit is used to generate joint risk conclusions based on the risk correlation.
[0098] This invention also provides a storage medium storing a computer program configured to execute the methods described above during runtime.
[0099] This invention also provides an electronic device, including a processor and a memory, wherein the memory stores a computer program, and the processor executes the computer program to implement the method described above.
[0100] In summary, this invention introduces a collaborative analysis module and risk scoring mechanism among voters, enabling multiple voters to share review results, perform correlation reasoning, and form a unified risk classification result, rather than making independent judgments. Simultaneously, through continuous risk scoring, risk level classification, and collaborative correction item design, this invention enhances the ability to identify complex and dangerous actions, combined attack actions, and covert unauthorized actions, solving the problems of lack of collaboration among voters and insufficient review granularity in existing solutions, and improving the accuracy, stability, and interpretability of action review.
[0101] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the protection scope of the claims of the present invention.
Claims
1. A method for secure execution of intelligent agent tool calls using multi-voting agents, characterized in that, Includes the following steps: Receive a user's tool call request, and generate and record the action intent based on the tool call request; Based on the stated action intent and associated context, the action intent is subject to multi-voter risk audit to obtain audit result elements; Record the audit result elements, and perform correlation analysis based on the audit result elements to obtain the correlation analysis results; Risk aggregation is performed based on the correlation analysis results to obtain the risk aggregation results; The risk aggregation result is recorded, and an action execution determination result is generated based on the risk aggregation result, so as to control the execution of the action corresponding to the action intent according to the action execution determination result.
2. The method as described in claim 1, characterized in that, Based on the stated action intent and associated context, a multi-voter risk audit is performed on the action intent to obtain audit result elements, including: Obtain the associated context based on the stated action intent; Based on the action intent and the associated context, a risk assessment is performed on the action intent to obtain an assessment result; The risk review path is determined based on the results of the initial review. When the risk review path is a direct generation path, review result elements are generated based on the first review result; When the risk review path is a continued review path, a second risk review is performed based on the action intent and the associated context, and review result elements are generated based on the first review result and the second review result.
3. The method as described in claim 2, characterized in that, Based on the stated action intent and the associated context, a risk assessment is performed on the action intent to obtain an assessment result, including: The action intent is subjected to static risk review based on a preset set of rules to obtain the rule review result; Based on the isolated execution environment, a pre-execution risk audit is performed on the stated action intent to obtain the sandbox audit result; The combined results of the rule review and the sandbox review are used to obtain a single review result.
4. The method as described in claim 3, characterized in that, Based on the results of the initial audit, a risk audit path is determined, including: Extract the rule-based audit results and the sandbox audit results from the first audit result; For the rule review results and the sandbox review results, respectively determine the corresponding level thresholds; Based on the rule review results, the sandbox review results, and their respective corresponding level thresholds, a risk level combination corresponding to a single review result is obtained. When all of the risk level combinations are low risk or there is a high risk, the risk review path will be determined as the direct generation path. When the risk level combination indicates a medium risk, the risk review path will be determined as the continued review path.
5. The method as described in claim 4, characterized in that, A secondary risk review is performed based on the stated action intent and the associated context, and review result elements are generated based on the primary review result and the secondary review result, including: Risk assessment is performed based on the semantic consistency between the action intent, the associated context, and the user's tool call request to obtain the semantic assessment result; Trajectory risk assessment is performed based on the stated action intent and the historical action sequence in the associated context to obtain trajectory assessment results; The audit result elements are obtained by summarizing the audit results, the semantic audit results, and the trajectory audit results.
6. The method as described in claim 1, characterized in that, Record the audit result elements, and perform correlation analysis based on the audit result elements to obtain the correlation analysis results, including: Record the elements of the audit results; Based on the audit result elements, extract the risk score, confidence level and audit reason corresponding to each of the multiple voters to obtain shared risk information; Based on the shared risk information, risk association reasoning is performed to obtain risk association relationships; Based on the aforementioned risk relationships, a joint risk conclusion is generated, and the correlation analysis results are obtained.
7. The method as described in claim 6, characterized in that, Based on the shared risk information, risk association reasoning is performed to obtain risk association relationships, including: Based on the shared risk information, the risk type corresponding to each voter is identified, and a risk type set is obtained; Based on the set of risk types and the reasons for review, determine the consistency or conflict relationship between the review results of multiple voters; Risk associations are generated based on the consistency relationship or the conflict relationship.
8. The method as described in claim 1, characterized in that, Risk aggregation is performed based on the correlation analysis results to obtain risk aggregation results, including: Based on the correlation analysis results, the risk score, voter weight, and collaborative correction information for each voter are determined. Risk is aggregated based on the risk score, the voter weight, and the collaborative correction information to obtain a comprehensive risk value; Risk aggregation results are generated based on the comprehensive risk value and risk threshold.
9. The method as described in claim 8, characterized in that, Determine the collaborative correction information, including: Based on the correlation analysis results, consistent risk relationships and conflict risk relationships among multiple voters are identified; Based on the aforementioned consistent risk relationship, risk increase correction information is determined; Based on the aforementioned conflict risk relationships, determine risk reduction and correction information or review information; Based on the risk increase correction information, the risk decrease correction information, or the review information, collaborative correction information is obtained.
10. A secure execution device for intelligent agent tool invocation using multi-voting device collaboration, characterized in that, include: The intent generation module is used to receive a user's tool call request and generate an action intent based on the tool call request. The voting review module is used to perform multi-voter risk review on the action intent based on the action intent and associated context, and obtain the review result elements; The collaborative analysis module is used to perform correlation analysis based on the audit result elements to obtain correlation analysis results, and to perform risk aggregation based on the correlation analysis results to obtain risk aggregation results; The logging module is used to record the intent of the action, audit result elements, and risk aggregation results; The execution control module is used to generate an action execution determination result based on the risk aggregation result, and to control the execution of the action corresponding to the action intent based on the action execution determination result.