Hierarchical evidence graph-based composite object admission control method

CN122838682APending Publication Date: 2026-09-29JIUYOU TECH (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611327611.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-08-31
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0003]现有方案通常存在以下缺陷:其一,将对象当作单一文件处理,难以识别嵌入层中的局部风险;其二,单模态检测结果之间相互割裂,无法量化图文、画音、字幕与声明之间的逻辑冲突;其三,内容安全标签多为描述性标签,不能直接驱动下游向量化、索引、召回和上下文注入策略;其四,对象来源信誉、人工复核结果以及业务域敏感度难以形成统一闭环,导致接入控制要么过严、要么漏放

Benefits of technology

[0006]本申请通过将待接入对象拆解为包含多模态节点的层级证据依赖图,并逐节点计算局部风险、提取同步/引用/派生关系,计算冲突闭包系数,再利用图传播网络融合节点风险与全局冲突,最终映射为带业务约束的对象级受限许可标签向量和对象准入评分,从而实现了对待接入对象的局部风险、跨模态冲突、来源信誉、业务域差异等多方面的量化评估。这样做既避免了传统方案中单一文件处理或单模态检测割裂导致的漏判与误判,又能通过冲突闭包系数量化图文、画音、字幕等逻辑冲突的叠加效应,同时将风险评估结果直接转化为可执行的下游操作许可,如向量化、索引、召回、上下文注入等,形成从内容解析到动作决策的闭环,显著提升接入控制的精细度、自适应性和可解释性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122838682A_ABST
    Figure CN122838682A_ABST
Patent Text Reader

Abstract

This invention discloses a composite object admission control method based on a hierarchical evidence graph. The method includes: acquiring the object to be accessed and acquiring the context data of the object to be accessed; parsing and decomposing the object to be accessed to obtain a hierarchical evidence dependency graph, which includes multiple nodes and the modalities of the nodes include multiple modalities; calculating the node risk vector of each node in the hierarchical evidence dependency graph based on the context data; determining the conflict closure coefficient of the object to be accessed based on the node risk vector of each target node relative to the target node; determining the object-level risk vector and object-level restricted permission label vector of the object to be accessed using a graph propagation network based on the node risk vector of each node and the conflict closure coefficient of the object to be accessed, and determining the object admission score of the object to be accessed; and determining the admission decision result of the object to be accessed based on the object admission score and the object-level restricted permission label vector.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of database technology, and in particular to a composite object admission control method based on hierarchical evidence graphs. Background Technology

[0002] With the continuous development of enterprise knowledge bases, intelligent customer service, RAG retrieval enhancement generation systems, intelligent agent platforms, document middleware, and multimodal content platforms, the system needs to receive a large number of complex objects from file upload interfaces, open APIs, email attachments, synchronous tasks, web crawling links, and terminal acquisition devices. These complex objects are not single-modal files, but often contain multiple interdependent content fragments such as the main text layer, embedded image layer, OCR text layer, audio track, subtitles, keyframes, compressed package files, and external link reference fragments.

[0003] Existing solutions typically suffer from the following drawbacks: First, treating objects as single files makes it difficult to identify local risks within the embedded layer; second, the results of single-modal detections are fragmented, making it impossible to quantify logical conflicts between text, audio, subtitles, and declarations; third, content security tags are mostly descriptive tags, which cannot directly drive downstream vectorization, indexing, recall, and context injection strategies; and fourth, it is difficult to form a unified closed loop between object source reputation, manual review results, and business domain sensitivity, resulting in access control that is either too strict or leaky. Summary of the Invention

[0004] To address the existing technical problems, this application provides a composite object access control method based on hierarchical evidence graphs, which can significantly improve the precision, adaptability, and interpretability of access control by completing a closed loop from content parsing to action decision-making.

[0005] Firstly, a composite object admission control method based on a hierarchical evidence graph is provided, comprising: acquiring the object to be accessed and acquiring the context data of the object to be accessed; parsing and decomposing the object to be accessed to obtain a hierarchical evidence dependency graph, the hierarchical evidence dependency graph including multiple nodes, the modalities of the multiple nodes including multiple modalities; calculating the node risk vector of each node in the hierarchical evidence dependency graph based on the context data; extracting multiple target node pairs in the hierarchical evidence dependency graph that have at least one of the following: synchronization relationship, reference relationship, and derivation relationship, and determining the conflict closure coefficient of the object to be accessed based on the node risk vector of the target node in each target node pair; determining the object-level risk vector of the object to be accessed based on the node risk vector of each node and the conflict closure coefficient of the object to be accessed using a graph propagation network, and mapping the object-level risk vector to an object-level restricted permission label vector; determining the object admission score of the object to be accessed based on the object-level risk vector and the object-level restricted permission label vector; and determining the admission decision result of the object to be accessed based on the object admission score and the object-level restricted permission label vector.

[0006] This application decomposes the object to be accessed into a hierarchical evidence dependency graph containing multimodal nodes, calculates local risks for each node, extracts synchronization / reference / derivation relationships, calculates conflict closure coefficients, and then uses a graph propagation network to fuse node risks and global conflicts. Finally, it maps these risks to object-level restricted permission tag vectors with business constraints and object admission scores, thereby achieving quantitative assessment of various aspects of the object to be accessed, including local risks, cross-modal conflicts, source reputation, and business domain differences. This approach avoids the missed and false judgments caused by the fragmented processing of single files or single-modal detection in traditional solutions. It also quantifies the cumulative effect of logical conflicts such as text / image, audio / video, and subtitles through conflict closure coefficients. Furthermore, it directly transforms the risk assessment results into executable downstream operation permissions, such as vectorization, indexing, recall, and context injection, forming a closed loop from content parsing to action decision-making, significantly improving the granularity, adaptability, and interpretability of access control. Attached Figure Description

[0007] Figure 1 This is an application environment diagram of a composite object admission control method based on hierarchical evidence graphs in one embodiment; Figure 2 This is a flowchart of a composite object admission control method based on a hierarchical evidence graph in one embodiment; Figure 3 This is a schematic diagram of a composite object access control device based on a hierarchical evidence graph in one embodiment; Figure 4 This is a schematic diagram of a computing device in one embodiment. Detailed Implementation

[0008] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0009] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used herein in the specification of this invention is for the purpose of describing particular embodiments only and is not intended to limit the scope of the invention. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.

[0010] In the following description, the expression “some embodiments” refers to a subset of all possible embodiments. However, it should be understood that “some embodiments” can be the same subset or different subsets of all possible embodiments and can be combined with each other without conflict.

[0011] See Figure 1 In one embodiment, the application environment diagram of the composite object admission control method based on hierarchical evidence graphs includes multiple terminal devices 100 and a computing device 200. The terminal devices 100 can communicate with the computing device 200. The composite object admission control method based on hierarchical evidence graphs provided in this application embodiment can be applied to the computing device 200, which communicates with a database. The computing device 200 obtains the object to be accessed from the terminal devices 100 and determines the admission decision result of the object to be accessed.

[0012] Please see Figure 2 This is a flowchart of a composite object admission control method based on hierarchical evidence graphs provided in an embodiment of this application. The composite object admission control method based on hierarchical evidence graphs is applied in a computing device and includes the following steps: S10. Obtain the object to be accessed and obtain the context data of the object to be accessed.

[0013] In this embodiment, the object to be accessed refers to a composite content entity that enters the system, such as a knowledge base, RAG engine, or intelligent agent platform. The object to be accessed is typically not a single-modal file, but rather contains multiple interdependent content fragments, such as: text layers, embedded images, OCR text, audio tracks, subtitles, keyframes, sub-files within compressed packages, and external link references. These objects may be obtained through channels such as file uploads, API pushes, email attachments, and web scraping. Processing them is the starting point for the entire security access control scheme. Context data is a set of external metadata acquired simultaneously with the object, used to describe the source environment, access method, historical behavior, and business attributes of the object to be accessed. The access context includes at least: the source entity identifier. Access Channel Business domain timestamp Signature status Historical pass rate Historical rejection rate and tenant identification Context feature vector Defined as: ,in This is a discrete identifier encoding function.

[0014] S11. The object to be accessed is parsed and decomposed to obtain a hierarchical evidence dependency graph. The hierarchical evidence dependency graph includes multiple nodes, and the modalities of the multiple nodes include multiple modalities.

[0015] In this embodiment, for the object to be accessed Construct a hierarchical evidence dependency graph , where: set of evidence nodes edge set Let be the set of edges. Represents a set of edge types. For a collection of node attributes, It is a set of edge attributes. Indicates the first Node attributes of each node, Indicates the first The node and the first Edges between nodes. Nodes Each node corresponds to an atomic evidence unit, which includes, but is not limited to: text segments, OCR text blocks, embedded images, audio segments, video keyframes, subtitle fragments, attachment files, compressed sub-files, parsed script fragments, or metadata records. These multiple nodes share a root node. Each node has a modal type, including text, images, audio, video, and so on.

[0016] Edge types must include at least: containing edges : Indicates the containment relationship between parent and child data carriers; derived edges : Represents the derivation relationship obtained through Optical Character Recognition (OCR), Automatic Speech Recognition (ASR), transcoding, frame extraction, etc.; reference edge : Represents hyperlinks, embedded references, or object pointer relationships; time-series edges This indicates the synchronization relationship between audio, subtitles, and video frames. The node attribute vector of each node is defined as follows: ,in, express Modal type, express The carrier role, express Source fragment identifier, express The time position or page number position, express Length information, express structural depth, express semantic embedding vector, express The initial risk vector of the node.

[0017] Treating access objects Perform parsing and decomposition. If the object is a document, extract the main text layer, layout blocks, OCR text blocks, embedded images, attachments, and metadata; if the object is a video, extract keyframe sequences, audio segments, subtitle segments, and video metadata; if the object is a compressed file, recursively expand its subfiles and establish parent-child dependency edges. The identifier of each node , Represents a node The source object identifier or source file identifier; Represents a node Hierarchical path within the original object; Represents a node Page number, time offset, or byte offset; Represents a node The carrier role; the symbol "‖" represents string concatenation or sequence concatenation operations.

[0018] Represents a node With nodes Edge types are defined; edge types include derived edges, reference edges, temporal edges, and containing edges. Standardization is performed for different modal nodes. For text nodes, this includes character removal, sentence segmentation, layout normalization, role tag extraction, and entity normalization; for image nodes, it includes size normalization, color space unification, local contrast equalization, and OCR detection; for audio nodes, it includes resampling, noise reduction, frequency band segmentation, and audio activity detection; for video nodes, it includes keyframe sampling, shot boundary detection, temporal unification, and audio-visual alignment. The standardized nodes are then analyzed. Embedded vector is denoted as: ,in, Indicating targeting The feature extraction network or encoder.

[0019] S12. Based on contextual data, calculate the node risk vector of each node in the hierarchical evidence dependency graph.

[0020] In this embodiment, the node risk vector is a multi-dimensional risk feature vector calculated for each atomic node in the hierarchical evidence dependency graph, such as a piece of text, an embedded image, an audio track, or a subtitle fragment. The role of the node risk vector is to quantify the threat level or anomaly level of the node itself across multiple independent risk dimensions, providing a foundation for subsequent graph propagation, conflict detection, and object-level decision-making.

[0021] For any node Its initial risk vector is defined as: ,in Represents a node The risk of injection Represents a node The risk of steganography or hidden payload. Represents a node The risk of counterfeiting Represents a node Privacy risks Represents a node Copyright risks Represents a node Countering disturbances or countering injection risks, Represents a node Cross-modal conflict risk; for a risk component that is not applicable to a certain node, the corresponding component can be set to zero.

[0022] S13. Extract hierarchical evidence. The dependency graph contains at least one of the following: multiple target node pairs with synchronization relationship, reference relationship, and derivation relationship. Based on the node risk vector of the target node in each target node pair, determine the conflict closure coefficient of the object to be accessed.

[0023] In this embodiment, the conflict closure coefficient represents the overall untrustworthiness probability obtained after closure operation on the degree of conflict among all related nodes within the object to be accessed, such as synchronization, reference, and derivation relationships. The core idea is that while a single node may have a limited impact on a conflict, when multiple conflicts exist simultaneously, the object as a whole becomes highly untrustworthy. The larger the conflict closure coefficient, the more untrustworthy the object.

[0024] S14. Based on the node risk vector of each node and the conflict closure coefficient of the object to be accessed, use the graph propagation network to determine the object-level risk vector of the object to be accessed, and map the object-level risk vector to the object-level restricted permission tag vector.

[0025] In this embodiment, the object-level risk vector is a multi-dimensional numerical vector used to quantify the overall risk level of the object to be accessed across multiple risk dimensions. Each dimension corresponds to a specific type of security risk, such as: object-level injection attack risk value, object-level privacy leakage risk value, object-level cross-modal conflict risk value, object-level copyright risk value, object-level spoofing risk value, etc. The object-level risk vector is obtained by fusing information such as the local risk of each atomic node, the conflict score between nodes, the global conflict closure coefficient, and the source reputation through a graph propagation network.

[0026] The object-level restricted permission tag vector is a binary vector with components of 0 or 1, used to directly control the processing permissions of downstream systems for objects to be accessed. Each component corresponds to a specific operation, such as: whether vectorization is allowed, whether indexing is allowed, whether recall is allowed, whether injection into a large model context is allowed, whether sharing is allowed, whether anonymization is required, and whether manual review is required. It is obtained by mapping the object-level risk vector through a constrained optimization model, including mutual exclusion and implied constraints, thereby transforming continuous risk values ​​into executable discrete decision instructions. Generally, 1 indicates permission, and 0 indicates disallowment.

[0027] S15. Based on the object-level risk vector and the object-level restricted permission tag vector, determine the object access score of the object to be accessed.

[0028] In this embodiment, the object admission score is a scalar value representing a quantitative score of the overall risk level or credibility of the target object after a comprehensive risk assessment, including factors such as local node risk, cross-modal conflict, source reputation, and business domain differences. A higher score indicates a greater risk and makes the object less suitable for direct entry into the downstream knowledge processing chain. Combining the object admission score with the key tag status, the final admission action is determined, such as allow, de-identify, isolate, manual review, or reject. Therefore, the object admission score serves as a bridge connecting risk assessment and action execution, compressing high-dimensional heterogeneous risk information into a comparable value, facilitating the development of tiered response strategies.

[0029] S16. Based on the object admission score and the object-level restricted permission tag vector, determine the admission decision result of the object to be accessed.

[0030] In this embodiment, the admission decision result is the final output of the security admission process for the object to be accessed. The admission decision result indicates the action the system should take for the object to be accessed. This result is a discrete enumeration value that directly determines whether the object can enter the downstream knowledge processing link, in what form it enters, or is rejected. Admission decision results include allow entry into the database, mask-then-allow entry into the database, quarantine entry into the database, transfer to human review, and reject access.

[0031] In the above embodiments, by decomposing the object to be accessed into a hierarchical evidence dependency graph containing multimodal nodes, calculating local risks for each node, extracting synchronization / reference / derivation relationships, calculating conflict closure coefficients, and then using a graph propagation network to fuse node risks and global conflicts, the results are finally mapped to an object-level restricted permission tag vector with business constraints and an object admission score. This achieves a quantitative assessment of various aspects of the object to be accessed, including local risks, cross-modal conflicts, source reputation, and business domain differences. This approach avoids the missed and false judgments caused by the fragmented processing of single files or single-modal detection in traditional solutions. It also quantifies the superimposed effects of logical conflicts such as text, audio, and subtitles through conflict closure coefficients. Furthermore, it directly transforms the risk assessment results into executable downstream operation permissions, such as vectorization, indexing, recall, and context injection, forming a closed loop from content parsing to action decision-making. This significantly improves the granularity, adaptability, and interpretability of access control.

[0032] In some embodiments, the hierarchical evidence dependency graph includes a root node, whose attributes include the candidate true modality type of the object to be accessed. Parsing and decomposing the object to be accessed yields the hierarchical evidence dependency graph, which includes: Using feature extraction technology, the object features of the object to be accessed are extracted, and based on the object features, an object feature vector is generated; Obtain the weight vector and bias vector corresponding to each candidate mode in the candidate mode set; Based on the object feature vector, the weight vector corresponding to each candidate modality, and the bias vector corresponding to each candidate modality, the type score of each candidate modality is determined. Based on the type score of each candidate modality, a probability transformation is performed to obtain the probability value of the object to be accessed belonging to each candidate modality; The candidate mode corresponding to the highest probability value is selected as the candidate true mode type.

[0033] In this embodiment, the object feature vector includes head features. , extension characteristics parse tree features Channel characteristics and encoding / decoding features The header features are identifying information extracted from the beginning of the object file, used to identify the true format and are an important basis for determining the object's original type. The file extension features are the file suffix or external declaration type of the object file. The parse tree features are the structure tree information obtained through deep parsing of the object (such as unpacking, stream decomposition), including node type distribution (text, image, audio, etc.), hierarchy depth, whether it contains compressed files or scripts, etc., used to describe the topological structure of the object's internal composition. Channel features are derived from the channel identifier in the access context, reflecting the object's input path and can be used to assist in judging credibility and expected modality. Encoding / decoding features describe the encoding, compression, or encryption format used by the object, such as H.264 / H.265 for video, AAC / MP3 for audio, JPEG / PNG compression parameters for images, etc., which helps identify format spoofing or abnormal encoding.

[0034] Constructing candidate modes The scoring function, where This represents the set of candidate modes. Candidate modes Type score In the formula, Representation of candidate modes The transpose of the corresponding weight vector, Candidate modes The corresponding bias vector. The weight vector and bias vector can be obtained through pre-training.

[0035] For candidate modes Corresponding type score, perform probability transformation, candidate modality The corresponding probability value is: ,in Representing candidate modes The corresponding type score.

[0036] Among them, candidate true modal types This indicates that the candidate mode with the highest probability value is selected from all candidate modes as the candidate true mode type.

[0037] In the above embodiments, by extracting multi-dimensional features such as the object's header, extension, parse tree, channel, and encoding / decoding, and combining them with the weight vectors and bias vectors of each candidate modality for linear scoring and probability transformation, the modality with the highest probability is automatically selected as the candidate true type based on objective content features. This approach does not rely on easily forged external information such as file extensions or user declarations, effectively resisting format spoofing, structural tampering, and channel deception. Furthermore, due to the use of a statistical learning-based probabilistic model, it exhibits quantitative sensitivity to covert spoofing behaviors such as parse tree anomalies and encoding / decoding inconsistencies, significantly improving the accuracy and robustness of determining the true type of composite objects. This provides a reliable type anchor for subsequent node risk calculation, conflict detection, and admission decisions.

[0038] In some embodiments, after determining the candidate true modality type, the method further includes: Obtain the actual parse tree feature set of the object to be accessed and the reference parse tree feature set of the candidate true modality types; Based on the actual parse tree feature set and the reference parse tree feature set of the object, the parse deviation between the object to be accessed and the candidate real modality type is calculated. Based on the probability value and analytical deviation corresponding to the candidate true modality type, the credibility state of the candidate true modality type is determined; Based on the probability value and resolution deviation corresponding to the candidate true modality type, the spoofing risk of the object to be accessed is determined; Trustworthiness and the risk of spoofing are considered as factors influencing the importance weight of the root node.

[0039] In this embodiment, The actual set of parse tree features of the object to be accessed. For this candidate true modality type The corresponding reference parse tree feature set. By performing deep analysis on the object to be accessed, such as decompression, stream decomposition, and structure recognition, a parse tree describing the internal structure of the object is generated. Then, features such as node type distribution (e.g., text nodes, image nodes, audio nodes, file nodes within compressed packages), node count, tree depth, and key structural markers are extracted from this parse tree. These features are then transformed into a set, which is the actual parse tree feature set. Reference parse tree feature sets for each candidate modality can be pre-configured.

[0040] Analysis deviation: , Indicates the relationship between the object to be accessed and the candidate real modality type. Similarity. Among them, Indicates based on the object to be accessed The actual set of parse tree features, composed of parse tree features It is composed of node type distribution, hierarchy depth, and key structural markers; Indicates the type of candidate true modality The corresponding reference parsing tree feature set is preferably generated from a preset type template library or standard structure feature library.

[0041] Optionally, based on the probability value and resolution deviation corresponding to the candidate true modality type, the credibility state of the candidate true modality type is determined, including: When the probability value corresponding to the candidate true modality type is less than the probability threshold, or the resolution deviation is greater than the deviation threshold, the credibility status of the candidate true modality type is determined as untrustworthy. When the probability value corresponding to the candidate true modality type is not less than the probability threshold and the resolution deviation is not greater than the deviation threshold, the credibility state of the candidate true modality type is determined as type credibility.

[0042] when When this happens, the trustworthiness status of the candidate true modality type is determined as type untrustworthy. This represents the probability threshold. This represents the deviation threshold. When a trusted state is determined to be type-untrustworthy, a type-untrustworthy tag is attached to the object to be accessed, and this tag is used as an additional attribute of the root node in subsequent hierarchical evidence graphs. The type-untrustworthy tag is written as an additional attribute of the root node into the hierarchical evidence dependency graph, and is used in subsequent steps to adjust the importance weight of the root node, increase the object-level spoofing penalty, and serve as one of the constraints for prohibiting vectorization or prohibiting context injection during restricted permission label reasoning and object admission action generation.

[0043] Disguise risk level The calculation formula is as follows: Used to characterize the degree of inconsistency between the extension, header signature, internal parse tree structure, and actual parsable content type of the object to be accessed; The larger the value, the more likely the object to be accessed is to have risks of format spoofing, structure spoofing, or channel spoofing. For the Sigmoid function, This is an indicator function. This represents the weight coefficient corresponding to the probability value of the candidate true modality type. This represents the weighting coefficient corresponding to the deviation in the analysis. This represents the weighting coefficient corresponding to the inconsistency in file extensions. Indicates the object to be accessed The extension or external declaration type, when Establishment value, The value is 1 if it is 1, otherwise it is 0.

[0044] In the above embodiments, by simultaneously utilizing the probability values ​​and resolution deviation of candidate real modal types, the credibility of the type is judged not only from the content statistics level, but also the resolution deviation is quantified from the structural consistency level, thereby effectively identifying disguised objects with a high type probability but abnormal structure. Furthermore, by using these credibility states and disguise risk as influencing factors of the root node importance weight, the weight of the root node in the subsequent hierarchical evidence dependency graph can be adaptively reduced, thereby automatically enhancing the punishment for disguised behavior in risk propagation, conflict closure coefficient calculation, and admission scoring, and preventing disguised objects from bypassing security detection by relying solely on a single probability score.

[0045] In some embodiments, calculating the node risk vector for each node in the hierarchical evidence dependency graph based on contextual data includes: When a node is a text node, extract the text feature data of the text node, calculate multiple text evaluation scores of the text node based on the text feature data, perform weighting on the multiple text evaluation scores to obtain the injection risk value representing the text node, which serves as the text node risk vector. The text feature data includes text content, business domain, and text statistics, and the multiple text evaluation scores include rule injection score, role hijacking score, confusion anomaly score, context offset score, and high-risk entity score. When the node is an image node, image feature data of the image node is extracted. Based on the image feature data, multiple first image risk index values ​​of the image node are determined. The multiple first image risk index values ​​are weighted to determine the hidden payload risk value. The first image risk index values ​​include: low-level plane anomaly, frequency domain anomaly, recompression inconsistency, and recognition control text score. Based on the image feature data, multiple second image risk index values ​​of the image node are determined. The multiple second image risk index values ​​are weighted to determine the image forgery risk degree. The second image risk index values ​​include: local forgery probability, edge splicing anomaly, and illumination inconsistency. The hidden payload risk value and the image forgery risk degree are determined as the image node risk vector of the image node. When the node is an audio node, audio feature data of the audio node is extracted. Based on the audio feature data, multiple first audio risk index values ​​of the audio node are determined. The multiple first audio risk index values ​​are weighted to determine the adversarial injection risk. The first audio risk index values ​​include UHF energy ratio, voice identity drift degree, and noise injection anomaly degree. Based on the audio feature data, multiple second audio risk index values ​​of the audio node are determined. The multiple second audio risk index values ​​are weighted to determine the audio injection risk. The second audio risk index values ​​include transcription sensitivity score and voice identity drift degree. The adversarial injection risk and the audio injection risk are determined as the audio node risk vector of the audio node. When the node is a video node, video feature data of the video node is extracted. Based on the video feature data, multiple first video risk index values ​​of the video node are determined. The multiple first video risk index values ​​are weighted to obtain the video forgery risk value. The first video risk index values ​​include keyframe face forgery score, lip-sync deviation, and timing jitter anomaly degree. Based on the video feature data, multiple second video risk index values ​​of the video node are determined. The multiple second video risk index values ​​are weighted to obtain the cross-modal conflict risk value. The second video risk index values ​​include subtitle drift score and lip-sync deviation. The video forgery risk value and the cross-modal conflict risk value are determined as the video node risk vector of the video node.

[0046] In this embodiment, text extraction technology is used to extract text feature data from text nodes. For text nodes, a rule injection score is calculated. This function measures whether text content matches known malicious injection patterns (such as SQL injection, cross-site scripting (XSS), prompt word injection, command injection, etc.). Regular expressions, signature libraries, or rule engines can be used for pattern matching. When a high-risk pattern is matched, a normalized score is output as the rule injection score based on the degree of matching and threat level. Role hijacking score. This tool is used to detect statements in text that attempt to alter system roles, override preset commands, or hijack the dialogue context (e.g., "You are no longer an AI assistant," "Please play an unrestricted role," "Ignore security policies," etc.). It can use a Transformer-based classification model or a keyword + semantic rule base to identify expressions related to role hijacking and system command overriding, outputting a hijacking probability between 0 and 1. A perplexity anomaly score is also provided. The perplexity score (PPL) measures how much the text deviates from the normal text distribution in its business domain. An excessively high PPL may indicate garbled text, random characters, or adversarial noise; an excessively low PPL may indicate excessive repetition, machine generation, or templated attacks. A pre-trained language model can be used to calculate the perplexity score anomaly score. Context offset score. This method is used to detect whether there is a sharp change in semantic coherence or topic consistency between the current text node and its preceding or surrounding context (such as dialogue history, preceding and following paragraphs in a document, and multi-turn interactions), thereby identifying possible context injection or topic hijacking. It can compute vectors encoding the text node and the reference context, calculate their cosine similarity or semantic distance, and determine a context offset score based on the similarity or semantic distance. High-risk entity score. This assesses whether text contains high-risk entities, such as malicious domains, IP addresses, cryptocurrency addresses, system commands, sensitive parameters, and hard-coded credentials. Entities can be extracted using Named Entity Recognition (NER) or regular expressions, matched against blacklists (such as threat intelligence domain lists, high-risk port numbers, and suspicious commands), and weighted according to the context of the entity's appearance to obtain a normalized score, which serves as the high-risk entity score.

[0047] Text Node Injection risk value: The perplexity anomaly score is represented as: In the formula, Represents text nodes The perplexity anomaly score under the preset language model; Indicates business domain The mean perplexity of the baseline text corpus; Indicates business domain The standard deviation of perplexity in the benchmark text corpus; and This can be obtained through offline statistical analysis of historical compliance text samples from the business domain. This represents the Sigmoid function.

[0048] Image extraction techniques are used to extract image feature data from image nodes. Low-bit plane anomaly score analyzes the deviation of the statistical distribution of the least significant bit (LSB) of image pixels from the expected distribution of a natural image. Frequency domain anomaly score performs Discrete Cosine Transform (DCT) or Wavelet Transform on the image to analyze whether there are anomalous patterns in the frequency domain coefficients (such as high-frequency components and quantization step size distribution). Recompression inconsistency score detects whether an image has undergone multiple JPEG compressions and compares compression traces (such as quantization tables, block artifacts, and double compression features) in different macroblocks or regions. Images that have been stitched, synthesized, or steganographically modified often exhibit inconsistencies in local recompression parameters; this metric is used to detect coding history contradictions caused by tampering or steganography. Control text recognition score analyzes whether the recognized text contains control instructions, malicious code fragments, sensitive keywords, or hidden text that is clearly inconsistent with the image content after OCR (Optical Character Recognition) of the image. This metric is used to detect the embedding of attack payloads into images in visible but concealed text form.

[0049] Local forgery probability represents the probability that a local region in an image has been tampered with, synthesized, or deepfaked (such as face replacement, object insertion, region copying and pasting). Typically, a deep learning-based forgery detection model analyzes the image patch by patch, outputting a probability value between 0 and 1; a higher value indicates a more likely forged region. Edge stitching anomaly measures the continuity and naturalness of edges between different objects or regions in an image. Illumination inconsistency assesses whether the direction, intensity, and color temperature of illumination are consistent across different regions of an image.

[0050] The hidden payload risk value indicates the likelihood that the image node contains steganographic information, hidden control text, or other covert payloads. It combines low-level plane anomalies, frequency domain anomalies, recompression inconsistencies, and OCR control text scores, and obtains a probability value between 0 and 1 after weighted summation and Sigmoid mapping. A higher value indicates that the image is more likely to be used for secretly transmitting data or hiding attack instructions. The image forgery risk value indicates the likelihood that the image node has been tampered with, spliced, deepfaked, or has generated traces. It combines local forgery probability, edge splicing anomalies, and illumination inconsistencies, and also obtains a probability value between 0 and 1 after weighted Sigmoid mapping. A higher value indicates that the image is more likely to be artificially forged or synthesized, and its content authenticity is lower. These two risk values ​​together constitute the initial risk vector components of the image node, used for subsequent graph propagation and object-level decision-making.

[0051] For image nodes Based on low-level plane anomaly Frequency domain anomaly Inconsistency of recompression Recognize and control text scores To obtain image nodes Hidden load risk value Based on local forgery probability Edge splicing anomaly Inconsistency of illumination To obtain image nodes Image forgery risk level .

[0052] in, - These are the weighting coefficients. This represents the Sigmoid function.

[0053] For audio nodes, the ultra-high frequency energy ratio measures the proportion of ultra-high frequency energy (typically above the range of human hearing, such as above 20kHz) in the total energy of the audio signal. Normal speech or environmental recordings have extremely low ultra-high frequency energy; a significantly increased ratio often indicates an ultrasonic injection attack (using high-frequency signals inaudible to the human ear to send covert commands to a voice assistant or microphone). This metric is calculated by integrating the power spectral density; the higher the value, the higher the risk. Voice identity drift assesses the consistency of speaker identity in audio. It is achieved by extracting the voiceprint vector of the entire audio segment and calculating the degree of vector change segment by segment. Significant identity drift (e.g., different people's voices or voice-changing effects in the same audio) may indicate that the speech has been spliced, forged, or injected with adversarial examples. This metric outputs a normalized drift score as the voice identity drift degree; the higher the value, the more unstable the identity. Noise injection anomaly is used to detect the presence of unnatural noise patterns in the audio, such as white noise, impulse noise, or interference at specific frequencies. This noise may be used to mask adversarial perturbations, trigger hidden commands, or disrupt speech recognition models. Adversarial injection risk is a core component of audio node risk, representing the possibility that the audio node contains adversarial perturbations, covert instruction injections, or malicious features designed to deceive the audio processing system.

[0054] The transcription sensitivity score is used to detect whether the text transcribed from audio by an Automatic Speech Recognition (ASR) system contains malicious instructions, injection attack statements, or sensitive commands (such as "ignore previous rules," "delete file," "transfer money," etc.). This score is obtained through rule matching or classification models; a higher value indicates that the transcribed content is more likely to be used to attack downstream systems. In audio injection risk, identity drift may suggest that the audio has been spliced ​​or forged. The audio injection risk is a probability value obtained by combining the transcription sensitivity score and the voice identity drift degree, after weighted sigmoid mapping. It indicates the risk that the transcribed text of the audio node contains malicious injection instructions or attack payloads; that is, the audio content itself may pose a threat to downstream systems such as prompt word injection or command execution. Audio injection risk focuses on semantic-level attack intent.

[0055] For audio nodes Combating injection risks , Indicates the proportion of ultra-high frequency energy, Indicates voice identity drift degree and Indicates the degree of noise injection anomaly. Audio injection risk. , This indicates the transcription of sensitive scores. - These are the weighting coefficients. This represents the Sigmoid function.

[0056] For video nodes, the keyframe face forgery score assesses the probability that a face in a video keyframe (such as a scene transition frame or a uniformly sampled frame) was created or replaced by a generative model using a deepfake detection model. A higher score indicates a more likely forged face. Lip-sync deviation aligns audio and video mouth movements using a lip-sync model, calculating the time offset or feature distance between the audio and lip movements. A larger deviation indicates more severe audio-visual desynchronization, usually suggesting the video has been artificially altered or synthesized. Temporal jitter anomaly analyzes optical flow, motion vectors, or feature point trajectories between video frames to detect unnatural jumps, repeated frames, frame interpolation artifacts, or motion discontinuities. A higher score indicates more pronounced temporal anomalies, suggesting the video has been edited, generated, or forged. The video forgery risk value is a probability value obtained by weighted summation of the above three indicators and mapping using a Sigmoid function. It comprehensively reflects the overall risk of deepfakes, face replacements, motion discontinuities, or temporal alterations in the video node. A higher value indicates lower authenticity of the video content and a greater likelihood of it being used for fraud or attacks.

[0057] The subtitle drift score measures the consistency in timing and semantic content between the subtitle stream (or embedded subtitles extracted via OCR) and the audio transcribed text (ASR output) in a video. A higher score indicates a significant deviation between the subtitles and audio content, such as timestamp offsets, text mismatches, or semantic contradictions, suggesting potential video tampering or cross-modal forgery. The cross-modal conflict risk value is a probability value obtained by combining the subtitle drift score and lip-sync deviation, weighted summed, and mapped using a sigmoid function. It represents the overall risk of semantic inconsistencies, temporal asynchrony, or content contradictions between different modalities (images, audio, subtitles) within a video node. A higher value indicates poorer cross-modal consistency in the video, and a greater likelihood of malicious splicing, forgery, or misleading information.

[0058] For video nodes Combined with keyframe face spoofing score Labial consonant synchronization deviation Timing jitter anomaly And subtitle drift score The risk vector of the video node is obtained.

[0059] video nodes Video forgery risk value: .

[0060] video nodes Cross-modal conflict risk value: .

[0061] in - This represents the weighting coefficient. This represents the Sigmoid function.

[0062] In some embodiments, the conflict closure coefficient of the object to be accessed is determined based on the node risk vector of each target node in each target node pair, including: Based on the node risk vector of each target node pair, calculate the conflict score corresponding to each target node pair; Obtain the corresponding trusted weights for each target node; The conflict closure coefficient is determined based on the conflict score and the trust weight of each target node.

[0063] In this embodiment, the conflict closure coefficient , This represents the set of target edges. Each target edge is the edge corresponding to a target node. Indicates the target node pair and The credible weight of the formed target edge. This represents the conflict score of the target edge. Indicates the index number of the target node pair.

[0064] Optionally, based on the node risk vector of each target node pair, calculate the conflict score corresponding to each target node pair, including: Any target node pair includes a first target point and a second target point. Obtain the first original semantic vector of the first target point and the second original semantic vector of the second target point. Calculate the semantic conflict degree of the target node pair based on the first original semantic vector and the second original semantic vector. Obtain the first time-series information of the first target point and the second time-series information of the second target point, and calculate the time-series conflict degree of the target node pair based on the first time-series information and the second time-series information; Obtain the first declaration vector of the first target point and the second declaration vector of the second target point, and calculate the declaration conflict degree of the target node pair based on the first declaration vector and the second declaration vector; The semantic conflict degree, temporal conflict degree, declaration conflict degree, and node risk value in the node risk vector of the target node pair are weighted to obtain the conflict score corresponding to the target node pair.

[0065] For node pairs in the graph that have synchronization, reference, or derivation relationships As target node pairs, calculate the semantic conflict degree, temporal conflict degree, and declaration conflict degree for each target node pair.

[0066] For target node pairs Semantic conflict degree Represented as: in, for The corresponding modal projection matrix. for The corresponding modal projection matrix. for The original semantic vector. for The corresponding original semantic vectors. The modality projection matrix is ​​a learnable linear transformation matrix that is pre-trained. The role of the modality projection matrix is ​​to project the original semantic embedding vectors of different modalities into the same unified semantic space, so that the content of different modalities can be directly similar to each other in this space, thereby quantifying cross-modal semantic conflicts.

[0067] Temporal information includes time or ordered spatial location, etc. Temporal conflict degree. for: ,in express The corresponding time point, express The corresponding time point. This indicates the maximum permissible timing deviation.

[0068] Conflict of statement for: , express The corresponding declaration semantic vector or content semantic vector. express The corresponding declaration semantic vector or content semantic vector. This represents the smallest positive number that prevents the denominator from being zero.

[0069] Conflict score Represented as: ,in express The corresponding node risk vector. express The corresponding node risk vector. - This represents the weighting coefficient. This represents the Sigmoid function.

[0070] In the above embodiments, by simultaneously calculating semantic conflict degree, temporal conflict degree, declaration conflict degree, and the node's own risk value, the inconsistency between node pairs can be comprehensively characterized from four dimensions: content semantics, temporal / spatial alignment, metadata declaration, and local threat. This avoids omissions or misjudgments caused by relying on only a single dimension. The conflict score obtained by weighted fusion of multiple dimensions can more precisely reflect the potential harm of the node pair in the overall evidence graph, thereby providing more accurate and interpretable local conflict evidence for subsequent conflict closure coefficient calculation, graph propagation network aggregation, and object-level admission decisions.

[0071] In some embodiments, the node risk vector of each node and the conflict closure coefficient of the object to be accessed are jointly input into the graph propagation network. In the graph propagation network... The layer propagation rule is expressed as: In the formula Represents a node In the The hidden state vector after layer propagation, and = . Represents a node The set of adjacent nodes. Indicates the first Layer nodes For nodes Attention weights; Represents the self-state transformation matrix; Represents the neighbor message transformation matrix; express and The resulting edge attribute vector; Represents a node With nodes The conflict score of the formed node pairs; the symbol "‖" indicates vector concatenation.

[0072] Finish After layer propagation, the object-level risk vector The calculation formula is: in, As the importance weight of the nodes, Source Reputation value It is a vector consisting entirely of 1s. , , , These represent the weighting coefficients.

[0073] The object-level risk vector is represented as: The risk value of object-level injection attacks is , Hidden load risk values ​​at the object level. Forging risk values ​​at the object level, This represents the risk value for object-level privacy breaches. This is an object-level copyright risk value. Injecting risk values ​​into object-level adversarial interactions. Object-level cross-modal conflict risk value, This is an object-level source reputation penalty item.

[0074] Object-level restricted license tag vectors include context-injected license values. Shared license value Recall Permit Value Index license value Vectorized license value Manual review mark value Desensitized label value . Indicates whether vector generation is allowed; Indicates whether access to the index is allowed; Indicates whether participation in the retrieval and recall is permitted; Indicates whether entry into the large model context is allowed; Indicates whether external sharing is allowed; Indicate whether manual review is required; Indicates whether desensitization is mandatory.

[0075] Mapping object-level risk vectors to object-level restricted license label vectors includes: Based on object-level risk vectors and object-level restricted permission label vectors, construct a constrained objective optimization function. The constraints should include at least the following: , , , ,in Indicates an indicator function, This indicates the threshold for the risk of injection attacks. This represents the threshold for object-level cross-modal conflict risk. This indicates the threshold for object-level privacy leakage risk. Object-level copyright risk threshold Indicates the threshold value for conflict closure coefficients; Perform iterative optimization on the objective optimization function, and output the object-level restricted permission label vector after the iterative optimization is completed.

[0076] The objective optimization function is: In the formula, - These are the components in the object-level risk vector. Represents an object-level restricted license tag vector; Indicates the dimension of the label vector; Represents the label structure matrix; This represents the risk-to-label mapping matrix; Represents a set of mutually exclusive constraints; Represents the set of implied constraints; This represents the coefficient of the mutual exclusion constraint penalty term; This represents the coefficient of the implied constraint penalty term; where, , This represents the value of any two label components in a mutual exclusion constraint. If both are 1, then the value is determined by the coefficient. Apply a mutual exclusion penalty to the objective optimization function; , This represents the values ​​of label components that have a sequential dependency relationship in the implication constraint. If the preset implication relationship is violated, the value is determined by the coefficient. Implicit penalties are imposed on the objective optimization function. express The indexes of two different components. express The indexes of two different components.

[0077] Object Admission Scoring : , This represents the parameter vector or weight vector of the object admission scoring function; Indicates business domain The encoding vector is used to characterize the differences in sensitivity levels or rules under different business domains. Indicates business domain The corresponding dynamic threshold.

[0078] Optionally, you can also check the source reputation. Updates and online feedback learning, source main body In the Reputation value at any time Updated to: .

[0079] In the formula, This represents the time smoothing coefficient in the source reputation update; This represents the positive reward coefficient for ensuring safety through incremental increases; This represents the negative penalty coefficient for refusing incremental access; This represents the negative penalty coefficient for escalating isolation or manual review increments; The correction benefit coefficient represents the incremental value of manual correction. This represents the positive reward coefficient for the increment of the trusted source of the signature. This indicates that the increment has been safely passed in this cycle; This indicates a refusal to accept incremental access; This indicates an increase in manual review or isolation procedures. This indicates the corrective benefits brought about by manual correction; Indicates the benefit of a trusted source for the signature; This represents the truncation function. Source Entity In the Reputation value at any time.

[0080] Business domain dynamic threshold Defined as: In the formula, Indicates the source entity Current reputation value; This indicates the adjustment weight of source reputation on the dynamic threshold; This indicates the adjustment weight of the business domain sensitivity coefficient on the dynamic threshold; This indicates the adjustment weight of business domain risk trends on dynamic thresholds; Indicates business domain Sensitivity level function; Indicates business domain At any moment The risk trend function. Indicates business domain The initial dynamic threshold.

[0081] Optionally, based on object admission scoring and object-level restricted permission tag vectors, the admission decision results for the objects to be accessed include: When the object admission score is less than or equal to the first risk threshold and the context injection permission value indicates that injection is allowed, the object to be accessed is determined to directly enter the database. When an object's admission score is greater than the first risk threshold and less than or equal to the second risk threshold, and the de-identification label value indicates that de-identification is required, the object to be accessed will be de-identified and then entered into the database. When an object's admission score is greater than the second risk threshold and less than or equal to the third risk threshold, the object to be accessed will be stored in the isolation zone of the database. When the manual review flag indicates that the review is required, or when the conflict closure coefficient is greater than the conflict closure coefficient threshold, the object to be accessed will be transferred to the manual review area. If the object's admission score is greater than the third risk threshold, it is determined that the object to be added is not allowed to be added to the database.

[0082] Based on object access score With object-level restricted license tag vector The combined results output the admission actions for the objects; among them, the object admission score is used to characterize the overall risk level, and the key label status is used to characterize whether specific actions such as vectorization, indexing, recall, context injection, sharing, or manual review are allowed. Admission decision results This includes allowing entry into the database, allowing entry after masking, quarantine entry, transferring to human review, and rejecting access.

[0083] in This indicates the first risk threshold. This indicates the second risk threshold. This indicates the third risk threshold.

[0084] Based on object access score With object-level restricted license tag vector The combined results, along with the conflict closure coefficient, enable multi-level refined management of composite objects. On one hand, multiple risk thresholds are used to divide risk levels into four progressive gradients: allow, desensitize, isolate, and reject. This allows the system to automatically match appropriate actions based on the degree of risk, avoiding extreme black-and-white decisions. On the other hand, the introduction of labeling conditions and mandatory manual review conditions ensures that rules not only rely on quantitative scoring but also incorporate global judgments of business logic constraints and structural conflicts, thus achieving a balance between automation and security.

[0085] Furthermore, the sequential judgment structure (matching from top to bottom) ensures the uniqueness and interpretability of the decisions. It first checks the lowest risk condition (allow), gradually transitioning to the highest risk (reject), and sets manual review as a priority higher than isolation but lower than rejection, reflecting the principle of investigating when in doubt. By explicitly distinguishing between anonymized and isolated data entry, the system can adopt differentiated isolation strategies for anomalies of varying severity—anonymized data can still be used normally, while isolation blocks all downstream operations, leaving only an audit channel. This design reduces the cost of manual intervention and ensures that high-risk objects do not pollute the knowledge base or reach end users, significantly improving the adaptability and fine-grainedness of composite object access control.

[0086] In some embodiments, the method further includes: Vectorization of the object to be accessed is prohibited when at least one of the following conditions is met: the vectorization permission value indicates that vectorization is not allowed; or, the vectorization permission value indicates that vectorization is allowed and the object-level privacy leakage risk value is greater than the object-level privacy leakage risk threshold; when the vectorization permission value indicates that vectorization is allowed and the object-level privacy leakage risk value is less than or equal to the object-level privacy leakage risk threshold, it is determined that the vectorization of the object to be accessed is allowed. When the index permission value indicates that permission is allowed and that the object to be accessed can be vectorized, the index data for the object to be accessed is determined to be created. When the recall permission value indicates that recall is allowed and the index data of the object to be accessed is allowed to be created, it is determined that the object to be accessed can be recalled. If the context injection permission value indicates that context injection is allowed, and the object to be accessed can be recalled, and the object-level injection attack risk value is less than or equal to the object-level injection attack risk threshold, then it is determined that the object to be accessed can be executed for context splicing.

[0087] The vectorized permission function can be used to determine whether the object to be accessed can be permitted. Vectorization. The vectorized permission function is represented as: , This indicates the threshold for the risk of object-level privacy breaches.

[0088] The index permission function determines whether access can be granted to the object to be accessed. Create an index, and define the index permission function as follows: .

[0089] The access target can be determined through the permission recall function. Can it be recalled? The recall permission function is defined as: .

[0090] The object to be accessed can be determined by concatenating the context permission function. Whether to use context concatenation. The context concatenation permission function is represented as: , Set the threshold for the risk of object-level injection attacks.

[0091] When any permission function outputs 0, the corresponding downstream action is blocked.

[0092] In another aspect, this application provides a computer program product, including a computer program that, when executed by a processor, implements the composite object admission control method based on a hierarchical evidence graph according to any embodiment of this application.

[0093] In the computer program product, the optional implementation form of the program module architecture of the computer program that implements each step of the composite object access control method based on hierarchical evidence graph can be a composite object access control device based on hierarchical evidence graph.

[0094] Please see Figure 3 One embodiment of this application provides a composite object access control device based on a hierarchical evidence graph, comprising: an acquisition module 31, used to acquire an object to be accessed and its context data; to parse and decompose the object to be accessed to obtain a hierarchical evidence dependency graph, the hierarchical evidence dependency graph including multiple nodes, the modalities of the multiple nodes including multiple modalities; a determination module 32, used to calculate the node risk vector of each node in the hierarchical evidence dependency graph based on the context data; the determination module 32 is further used to extract multiple target nodes in the hierarchical evidence dependency graph that have at least one of the following: synchronization relationship, reference relationship, and derivation relationship. Yes, based on the node risk vector of each target node in the target node pair, the conflict closure coefficient of the object to be accessed is determined; the determination module 32 is also used to determine the object-level risk vector of the object to be accessed using a graph propagation network based on the node risk vector of each node and the conflict closure coefficient of the object to be accessed, and map the object-level risk vector to an object-level restricted permission label vector; the determination module 32 is also used to determine the object admission score of the object to be accessed based on the object-level risk vector and the object-level restricted permission label vector; and to determine the admission decision result of the object to be accessed based on the object admission score and the object-level restricted permission label vector.

[0095] It will be understood by those skilled in the art that Figure 3 The structure of the hierarchical evidence graph-based composite object access control device does not constitute a limitation on the hierarchical evidence graph-based composite object access control device. Each module can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in hardware or independently of the controller in the computer device, or stored in software in the memory of the computer device, so that the controller can invoke and execute the operations corresponding to each module. In other embodiments, the hierarchical evidence graph-based composite object access control device may include more or fewer modules than illustrated.

[0096] Please see Figure 4In another aspect of this application, a computing device 200 is also provided, including a memory 3011 and a processor 3012. The memory 3011 stores a computer program, and when the computer program is executed by the processor, the processor 3012 performs the steps of the composite object admission control method based on hierarchical evidence graphs provided in any of the above embodiments of this application. The computing device 200 may include computing devices (e.g., desktop computers, laptop computers, tablet computers, handheld computers, smart speakers, servers, etc.), mobile phones (e.g., smartphones, cordless phones, etc.), wearable devices (e.g., a pair of smart glasses or a smartwatch) or similar devices, and robotic devices.

[0097] The processor 3012 is the control center, connecting various data points throughout the computer device via various interfaces and lines. It executes software programs and / or modules stored in the memory 3011, and calls data stored in the memory 3011 to perform various functions and process data. Optionally, the processor 3012 may include one or more processing cores; preferably, the processor 3012 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user page, and applications, and the modem processor mainly handles wireless communication. It is understood that the modem processor may not be integrated into the processor 3012.

[0098] The memory 3011 can be used to store software programs and modules. The processor 3012 executes various functional applications and data processing by running the software programs and modules stored in the memory 3011. The memory 3011 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, application programs required for at least one function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 3011 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. Accordingly, the memory 3011 may also include a controller to provide the processor 3012 with access to the memory 3011.

[0099] In another aspect, this application also provides a storage medium storing a computer program, which, when executed by a processor, causes the processor to perform the steps of the composite object admission control method based on hierarchical evidence graphs provided in any of the above embodiments of this application.

[0100] Those skilled in the art will understand that all or all data flows in the methods provided in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a non-volatile computer-readable storage medium. When executed, the program can include the flows of the embodiments of the methods described above. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile media. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory.

[0101] The above are merely specific embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. The scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A composite object admission control method based on hierarchical evidence graphs, characterized in that, include: Obtain the object to be accessed and its context data; The object to be accessed is parsed and decomposed to obtain a hierarchical evidence dependency graph, which includes multiple nodes and the modalities of the multiple nodes include multiple modalities; Based on the context data, calculate the node risk vector for each node in the hierarchical evidence dependency graph; Extract multiple target node pairs from the hierarchical evidence dependency graph that contain at least one of the following: synchronization relationship, reference relationship, and derivation relationship; and determine the conflict closure coefficient of the object to be accessed based on the node risk vector of the target node in each target node pair. Based on the node risk vector of each node and the conflict closure coefficient of the object to be accessed, the object-level risk vector of the object to be accessed is determined using a graph propagation network, and the object-level risk vector is mapped to an object-level restricted permission tag vector. Based on the object-level risk vector and the object-level restricted permission tag vector, the object access score of the object to be accessed is determined; Based on the object admission score and the object-level restricted permission tag vector, the admission decision result of the object to be accessed is determined.

2. The composite object admission control method based on hierarchical evidence graphs as described in claim 1, characterized in that, The hierarchical evidence dependency graph includes a root node, and the attributes of the root node include the candidate true modality type of the object to be accessed. The process of parsing and decomposing the object to be accessed to obtain the hierarchical evidence dependency graph includes: Using feature extraction technology, the object features of the object to be accessed are extracted, and an object feature vector is generated based on the object features; Obtain the weight vector and bias vector corresponding to each candidate mode in the candidate mode set; Based on the object feature vector, the weight vector corresponding to each candidate modality and the bias vector corresponding to each candidate modality, the type score of each candidate modality is determined; Based on the type score of each candidate modality, a probability transformation is performed to obtain the probability value of the object to be accessed belonging to each candidate modality; The candidate mode corresponding to the highest probability value is selected as the candidate true mode type.

3. The composite object admission control method based on hierarchical evidence graphs as described in claim 2, characterized in that, After determining the candidate true modality type, the method further includes: Obtain the actual parsing tree feature set of the object to be accessed and the reference parsing tree feature set of the candidate real modality type; Based on the actual parse tree feature set of the object and the reference parse tree feature set, calculate the parse deviation between the object to be accessed and the candidate real modality type; Based on the probability value corresponding to the candidate true modality type and the resolution deviation, the credibility status of the candidate true modality type is determined; Based on the probability value corresponding to the candidate true modality type and the resolution deviation, the spoofing risk level of the object to be accessed is determined; The trusted state and the spoofing risk are used as factors influencing the importance weight of the root node.

4. The composite object admission control method based on hierarchical evidence graphs as described in claim 3, characterized in that, The process of determining the credibility state of the candidate true modality type based on the probability value corresponding to the candidate true modality type and the resolution deviation includes: When the probability value corresponding to the candidate true modality type is less than the probability threshold, or the resolution deviation is greater than the deviation threshold, the credibility status of the candidate true modality type is determined to be untrustworthy. When the probability value corresponding to the candidate true modality type is not less than the probability threshold and the resolution deviation is not greater than the deviation threshold, the credibility status of the candidate true modality type is determined as type credibility.

5. The composite object admission control method based on hierarchical evidence graphs as described in claim 1, characterized in that, The calculation of the node risk vector for each node in the hierarchical evidence dependency graph based on the context data includes: When the node is a text node, the text feature data of the text node is extracted. Based on the text feature data, multiple text evaluation scores of the text node are calculated. The multiple text evaluation scores are weighted to obtain the injection risk value representing the text node, which is used as the text node risk vector. The text feature data includes text content, business domain, and text statistics. The multiple text evaluation scores include rule injection score, role hijacking score, confusion anomaly score, context offset score, and high-risk entity score. When the node is an image node, image feature data of the image node is extracted. Based on the image feature data, multiple first image risk index values ​​of the image node are determined. The multiple first image risk index values ​​are weighted to determine a hidden payload risk value. The first image risk index values ​​include: low-level plane anomaly, frequency domain anomaly, recompression inconsistency, and recognition control text score. Based on the image feature data, multiple second image risk index values ​​of the image node are determined. The multiple second image risk index values ​​are weighted to determine an image forgery risk degree. The second image risk index values ​​include: local forgery probability, edge splicing anomaly, and illumination inconsistency. The hidden payload risk value and the image forgery risk degree are determined as the image node risk vector of the image node. When the node is an audio node, audio feature data of the audio node is extracted. Based on the audio feature data, multiple first audio risk index values ​​of the audio node are determined. The multiple first audio risk index values ​​are weighted to determine the adversarial injection risk. The first audio risk index values ​​include ultra-high frequency energy ratio, voice identity drift degree, and noise injection anomaly degree. Based on the audio feature data, multiple second audio risk index values ​​of the audio node are determined. The multiple second audio risk index values ​​are weighted to determine the audio injection risk. The second audio risk index values ​​include transcription sensitivity score and voice identity drift degree. The adversarial injection risk and the audio injection risk are determined as the audio node risk vector of the audio node. When the node is a video node, video feature data of the video node is extracted. Based on the video feature data, multiple first video risk index values ​​of the video node are determined. The multiple first video risk index values ​​are weighted to obtain a video forgery risk value. The first video risk index values ​​include keyframe face forgery score, lip-sync deviation, and timing jitter anomaly degree. Based on the video feature data, multiple second video risk index values ​​of the video node are determined. The multiple second video risk index values ​​are weighted to obtain a cross-modal conflict risk value. The second video risk index values ​​include subtitle drift score and lip-sync deviation. The video forgery risk value and the cross-modal conflict risk value are determined as the video node risk vector of the video node.

6. The composite object admission control method based on hierarchical evidence graphs as described in claim 1, characterized in that, The step of determining the conflict closure coefficient of the object to be accessed based on the node risk vector of each target node pair includes: Based on the node risk vector of the target node in each target node pair, calculate the conflict score corresponding to each target node pair; Obtain the corresponding trusted weights for each target node; The conflict closure coefficient is determined based on the conflict score and the trust weight of each target node pair.

7. The composite object admission control method based on hierarchical evidence graphs as described in claim 6, characterized in that, The calculation of the conflict score for each target node pair based on the node risk vector of the target node in each target node pair includes: Any target node pair includes a first target point and a second target point. A first original semantic vector of the first target point and a second original semantic vector of the second target point are obtained. Based on the first original semantic vector and the second original semantic vector, the semantic conflict degree of the target node pair is calculated. Obtain the first time-series information of the first target point and the second time-series information of the second target point, and calculate the time-series conflict degree of the target node pair based on the first time-series information and the second time-series information; Obtain the first declaration vector of the first target point and the second declaration vector of the second target point, and calculate the declaration conflict degree of the target node pair based on the first declaration vector and the second declaration vector; The semantic conflict degree, temporal conflict degree, declaration conflict degree, and node risk value in the node risk vector of the target node pair are weighted to obtain the conflict score corresponding to the target node pair.

8. The composite object admission control method based on hierarchical evidence graphs as described in claim 1, characterized in that, The object-level risk vector includes object-level injection attack risk values. Object-level privacy leakage risk value Object-level cross-modal conflict risk value and object-level copyright risk value The object-level restricted license tag vector includes context-injected license values. Shared license value Recall Permit Value Index license value Vectorized license value Manual review mark value Desensitized label value ; The step of mapping the object-level risk vector to the object-level restricted permission tag vector includes: Based on the object-level risk vector and the object-level restricted permission label vector, a constrained objective optimization function is constructed, wherein the constraints include at least the following: , , , , in Indicates an indicator function, This indicates the threshold for the risk of injection attacks. This represents the threshold for object-level cross-modal conflict risk. This indicates the threshold for object-level privacy leakage risk. Object-level copyright risk threshold Indicates the threshold value for conflict closure coefficients; Perform iterative optimization on the target optimization function, and output the object-level restricted permission tag vector after the iterative optimization is completed.

9. The composite object admission control method based on hierarchical evidence graphs as described in claim 8, characterized in that, The process of determining the access decision result for the object to be accessed based on the object access score and the object-level restricted permission tag vector includes: When the object admission score is less than or equal to the first risk threshold, and the context injection permission value indicates that injection is allowed, it is determined that the object to be accessed will directly enter the database. When the object's access score is greater than the first risk threshold and less than or equal to the second risk threshold, and the de-identification label value indicates that de-identification is required, it is determined that the object to be accessed will be de-identified and then entered into the database. When the object's admission score is greater than the second risk threshold and less than or equal to the third risk threshold, the object to be accessed is stored in the isolation zone of the database. When the manual review flag indicates a review, or when the conflict closure coefficient is greater than the conflict closure coefficient threshold, the object to be accessed is transferred to the manual review area. If the object's admission score is greater than the third risk threshold, it is determined that the object to be accessed is not allowed to be added to the database.

10. The composite object admission control method based on hierarchical evidence graphs as described in claim 8, characterized in that, The method further includes: Vectorization of the object to be accessed is prohibited when at least one of the following conditions is met: the vectorization permission value indicates that vectorization is not allowed; or, the vectorization permission value indicates that vectorization is allowed, and the object-level privacy leakage risk value is greater than the object-level privacy leakage risk threshold; when the vectorization permission value indicates that vectorization is allowed, and the object-level privacy leakage risk value is less than or equal to the object-level privacy leakage risk threshold, the vectorization of the object to be accessed is allowed. When the index permission value indicates permission is allowed and the object to be accessed is allowed to be vectorized, it is determined to establish index data for the object to be accessed. When the recall permission value indicates that recall is allowed and the index data of the object to be accessed is allowed to be established, it is determined that the object to be accessed can be recalled; When the context injection permission value indicates that context injection is allowed, and the object to be accessed can be recalled, and the object-level injection attack risk value is less than or equal to the object-level injection attack risk threshold, then it is determined that the object to be accessed can be subjected to context splicing.