LARGE LANGUAGE MODELS FOR APPLYING GUIDELINES TO COMPILED CODE
The IDE with a large language model automates policy compliance verification by generating compliant code through modeling language diagrams, addressing the complexity of ensuring code adheres to guidelines, thus reducing developer effort.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- GOOGLE LLC
- Filing Date
- 2024-06-21
- Publication Date
- 2026-05-07
AI Technical Summary
Software developers face challenges in verifying compliance of program code with multiple guidelines, especially as code updates or guideline changes occur, leading to increased complexity and resource investment.
An integrated development environment (IDE) uses a large language model to generate a modeling language diagram, identify function signatures, and apply policy-compliant node state transitions, automatically generating compliant code through policy-compliant node states.
Automates policy compliance verification, reducing the time and effort required for developers to ensure code adheres to security and other guidelines by suggesting compliant code updates.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
CROSS-REFERENCE TO RELATED REGISTRATIONS
[0001] The present application claims priority from US patent application no. 18 / 218,302, filed on July 5, 2023. Its contents are hereby incorporated in full by reference. GENERAL STATE OF THE ART
[0002] Software developers often have to consider a multitude of different guidelines when writing program code. For example, each function associated with a particular piece of program code might be subject to compliance with a variety of different guidelines. The more guidelines software developers have to consider, the more difficult it becomes to verify whether the program code complies with each individual guideline. As the program code is updated or becomes more complex, it becomes increasingly difficult to verify that every section of the program code adheres to the guidelines. To add even more complexity, program code that was previously compliant with the guidelines may become non-compliant when the guidelines themselves change.
[0003] The scenarios described above make it increasingly difficult to achieve and verify compliance with guidelines at all times. As a result, a significant investment of time and resources is required to ensure and verify compliance with guidelines. SUMMARY
[0004] An integrated development environment (IDE) can compile program code and, based on the compiled code, abstract (e.g., generate) a modeling language diagram. The modeling language diagram can include node states that correspond to different functions in the program code. Each node state has a function signature that identifies one or more policies for the underlying functions. If the attributes of a particular node state transition between a node of type A and a node of type B indicate that the underlying functions do not conform to a specific policy, a large language model can generate one or more safety controls that can be used to update the attributes of that particular node state transition.For example, data associated with a specific policy can be used as input for the large language model. Based on this input, the large language model can generate one or more security controls that can update the specified node state transition to a policy-compliant node state transition. The policy-compliant node state transition can then be used to generate policy-compliant code. To illustrate, a large language model can generate policy-compliant code based on the original, non-compliant code and the policy-compliant node state transition. The policy-compliant code can then be presented to a user in the integrated development environment as a suggestion for modifying the code to comply with the specified policy.
[0005] In a first exemplary embodiment, a method includes the generation of a modeling language diagram by a processor, which specifies a compiled version of program code. The modeling language diagram includes at least one node corresponding to at least one function in the program code. The method also includes the identification by the processor of at least one function signature associated with a node state transition between nodes in the modeling language diagram. Furthermore, the method includes the identification by the processor of a specific policy to be assigned to the at least one function signature associated with the node state transition, using a large language model.The procedure further involves the processor performing a policy compliance operation, using the large language model, which ensures that a specific section of program code conforms to the specified policy. This specific section of program code is associated with the node state transition. Performing the policy compliance operation involves generating a policy-compliant version of the specific section of program code.
[0006] In a second exemplary embodiment, a system includes a memory and a processor coupled to the memory. The processor is configured to generate a modeling language diagram that specifies a compiled version of program code. The modeling language diagram includes at least one node corresponding to at least one function in the program code. The processor is also configured to identify at least one function signature associated with a node state transition between nodes in the modeling language diagram. Furthermore, the processor is configured to use a large language model to identify a specific policy to be assigned to the at least one function signature associated with the node state transition.The processor is also configured to perform a policy compliance operation using the large language model, ensuring that a specific section of program code conforms to a particular policy. This specific section of program code is associated with the node state transition. Performing the policy compliance operation involves generating a policy-compliant version of the specific section of program code.
[0007] In a third exemplary embodiment, a non-volatile, machine-readable medium contains instructions which, when executed by a processor, cause the processor to perform operations. These operations include generating a modeling language diagram that specifies a compiled version of program code. The modeling language diagram includes at least one node corresponding to at least one function in the program code. The operations also include identifying at least one function signature of a node state transition between nodes in the modeling language diagram. Furthermore, the operations include identifying a specific policy to be associated with the at least one function signature associated with the node state transition, using a large language model.The processes further include performing a policy compliance operation using the large language model, which ensures that a specific section of the program code conforms to the specified policy. The specific section of program code is associated with the node state transition. Performing the policy compliance operation involves generating a policy-compliant version of the specific section of program code.
[0008] In a fourth exemplary embodiment, a system may include different means for carrying out each of the operations of the first exemplary embodiment.
[0009] These and other embodiments, aspects, advantages, and alternatives will become apparent to those skilled in the art by reading the following detailed description, possibly with reference to the accompanying drawings. Furthermore, this summary and other descriptions and figures provided herein are intended to illustrate embodiments only by way of example, and therefore numerous variations are possible. For instance, structural elements and process steps can be rearranged, combined, distributed, eliminated, or otherwise modified while remaining within the scope of protection of the claimed embodiments. BRIEF DESCRIPTION OF THE DRAWINGS Fig. Figure 1 illustrates a computing system that is operational to automate compliance with program code guidelines, according to the examples described here. Fig. Figure 2 illustrates an example of a computational process for automating compliance with program code guidelines, according to the examples described here. Fig. Figure 3 illustrates another example of a computational process for automating program code policy compliance, according to the examples described here. Fig. Figure 4 illustrates another example of a computational process for automating program code policy compliance, according to the examples described here. Fig. Figure 5 is a diagram illustrating the training and inference phases of a machine learning model, in accordance with the examples described here. Fig. Figure 6 illustrates a flowchart according to the examples described herein. DETAILED DESCRIPTION
[0010] This document describes exemplary methods, devices, and systems. It is understood that the words "example" and "exemplary" are used herein to mean "serving as an example, instance, or illustration." An embodiment or feature described in this document as an "example," "exemplary," and / or "illustrative" is not necessarily to be construed as preferable or advantageous over other embodiments or features unless explicitly stated otherwise. Thus, other embodiments may be used and other modifications made without departing from the scope of protection of the subject matter presented herein.
[0011] Accordingly, the exemplary embodiments described herein are not to be understood as limiting. It is readily apparent that the aspects of the present disclosure, as generally described here and illustrated in the figures, can be arranged, replaced, combined, separated, and designed in a multitude of different configurations.
[0012] Unless the context suggests otherwise, the features illustrated in the individual figures can also be used in combination with one another. Therefore, the figures should generally be viewed as component aspects of one or more overall embodiments, bearing in mind that not all of the features shown are required for every embodiment.
[0013] Particular embodiments are described herein with reference to the drawings. In the description, common features are identified by common reference numbers throughout the drawings. In some figures, several instances of a particular feature type are used. Although these features are physically and / or logically separate, the same reference number is used for each, and the different instances are distinguished by adding a letter to the reference number. When the features are referred to herein as a group or type (e.g., when no specific feature is referenced), the reference number without the distinguishing letter is used. However, when a specific feature of several features of the same type is referred to herein, the reference number with the distinguishing letter is used. For example, in Fig. Figure 1 illustrates several node states and assigns them to the reference numbers 142A and 142B. When referring to a specific node state, such as node state 142A, the distinguishing letter "A" is used. However, when referring to any of these node states, or to these node states as a group, the reference number 142 is used without a distinguishing letter.
[0014] Furthermore, any enumeration of elements, blocks, or steps in this specification or for the purposes of clarity is provided for informational purposes only. Therefore, such enumeration should not be interpreted as requiring or implying that these elements, blocks, or steps follow a specific arrangement or are performed in a specific sequence. Unless otherwise stated, the figures are not to scale. I. Overview
[0015] The techniques described here enable automated policy compliance verification for program code using large language models. In software development, it can be difficult to certify that security controls are embedded in the program code. Furthermore, proving that security controls are embedded in the program code can be relatively difficult. Consequently, enforcing and demonstrating policy compliance can be challenging, potentially leading to weaknesses in the program code and security vulnerabilities.
[0016] As described here, compliance can be achieved and demonstrated by visualizing attack surfaces within the software using Unified Modeling Language (UML) generation, dynamically evaluating policies and security controls according to the use case of each node in the UML diagram, and automatically implementing new controls through heuristic workflows, such as large language models. Automating security controls helps reduce vulnerabilities and the effort associated with implementation. Furthermore, automating compliance verification can establish a system for rapid code modification.
[0017] According to the techniques described here, a user can, for example, write or create program code (e.g., source code) in an integrated development environment (IDE), and a compiler can compile the program code (e.g., translate the source code into machine code) to produce a compiled version of the program code. In response to the compilation, the IDE can generate (e.g., abstract) a modeling language diagram, such as a Unified Modeling Language (UML) diagram, which is a specification of the compiled version of the program code. In particular, the program code can contain a variety of functions, and the modeling language diagram can contain nodes that are specifications of the functions.
[0018] As a non-restrictive example, a particular section of program code may contain (1) a modification function that modifies a first specific data type into a second specific data type, and (2) a write function that writes the second specific data type to a specific location. In this non-restrictive example, the first specific data type may correspond to user profile data, the second specific data type may correspond to modified user data in a format supported by a specific application, and the specific location may correspond to a user database associated with the specific application. In this example, the modification function may be referred to as node state (A) in the modeling language diagram, and the write function may be referred to as node state (B) in the modeling language diagram.A state transition between node state (A) and node state (B) in the modeling language diagram can be called a node state transition (AB). It should be understood that the above example serves only as an illustration and should not be interpreted as a limitation.
[0019] Each node state in the modeling language diagram can be associated with a unique class of node states that share the same underlying function(s) and an identical parameter list. Each unique class of node states is identified by a unique function signature. For example, whenever there is a node state in the modeling language diagram that shares the same underlying function(s) as node state (A) (e.g., the modification function) and has the same parameter list as the parameter list in the underlying function, the function signature of the node state will be the same as the function signature for node state (A). For simplicity, the function signature for node state (A) is referred to as "function signature (A)," and the function signature for node state (B) is referred to as "function signature (B)."
[0020] One or more function signatures associated with node state transitions can be identified. As a non-restrictive example, a processor can identify that function signature (A) and function signature (B) are associated with node state transition (AB). In response to the identification of the function signatures for node state transition (AB), a policy engine can evaluate the node state transition (AB) to identify one or more policies that can be associated with at least one of the associated function signatures. In particular, the policy engine can use a large language model to identify one or more policies that can be associated with at least one of the associated function signatures if the modeling language graph has a node state transition between a node type with function signature (A) and a node type with function signature (B).During training, for example, different function signatures and node state transitions (e.g., training data) can be provided as inputs to the large language model, and these function signatures and node state transitions can be mapped to the relevant policies. As more and more function signatures and node state transitions are provided to the large language model as training data, the weights assigned to the large language model can be fine-tuned to accurately identify the relevant policies for each function signature and node state transition. Therefore, once fine-tuned to identify policies based on function signatures and node state transitions, the large language model can become a more efficient (e.g.,a faster and more accurate way to identify guidelines than relying on a programmer to analyze the program code and try to identify all relevant guidelines for the program code.
[0021] In some implementations, the modeling language diagram, or a portion thereof, can serve as input for the large language model. Based on the modeling language diagram, the large language model can identify the policies to be associated with the function signatures. These policies may correspond to security policies and / or security controls that should be implemented to ensure that the specific section of program code associated with the node state transition (AB) meets certain security requirements. Non-restrictive examples of policies might include hiding / deleting certain data, not hiding scripts, not allowing certain functions to be executed, and so on.
[0022] To ensure that a specific section of program code complies with policies (e.g., meets security requirements), the policy engine can perform a policy compliance operation. To illustrate, suppose that a policy associated with the function signature (A), when mapped to the node state transition (AB), is that social security data must be deleted when user profile data is modified. In this example, to perform the policy compliance operation, the policy engine can evaluate the node state (A) in the modeling language diagram to determine whether social security data is deleted when the user profile data is modified. In some scenarios, the policy engine can use a large language model to evaluate the node state (A) to determine whether social security data is deleted.For example, the large language model can determine if there are any attributes in node state (A) indicating that social security data is being deleted. If, during the evaluation of node state (A), it is determined that the underlying modification function deletes social security data, the policy engine can determine that the specific section of program code associated with node state (A) complies with the policies (e.g., meets the security requirements).
[0023] However, if during the evaluation of node state (A) it is determined that the underlying modification function does not delete social security data, the policy engine may determine that the specific section of program code associated with node state (A) is non-compliant with the policies (e.g., does not meet the security requirements). In this scenario, the policy compliance operation can use the large language model to update the modeling language graph so that node state (A) becomes a policy-compliant node state, and as a result, the resulting node state transition (AB) becomes a policy-compliant node state transition.To update the modeling language diagram in this way, the large language model can use the policy to generate / identify security controls that can be used to modify the node state (A) in the modeling language diagram to a policy-compliant node state, and thus modify the corresponding node state transition (AB) to a policy-compliant node state transition. For example, the large language model can identify appropriate credentials for node state (A) and apply the appropriate credentials to node state (A).
[0024] The updated modeling language diagram, specifically the policy-compliant node state, can be used to generate policy-compliant program code (e.g., new code) to replace the specific section of program code associated with node state (A). For example, a program code updater can use a large language model to generate the policy-compliant program code based on the updated modeling language diagram. In some examples, an input to the large language model might include the specific section of program code associated with node state (A). Thus, the large language model can generate the policy-compliant program code based on the original non-compliant program code.
[0025] Before replacing the specific section of program code (e.g., the original non-compliant code) with the compliant code, the user (in the integrated development environment) may be prompted to accept or modify the compliant code. Therefore, the compliant code is presented to the user in the integrated development environment as a modifiable proposal. Upon acceptance, the compliant code can replace the specific section of code to achieve compliance.
[0026] Thus, the techniques described here enable automated policy compliance verification for program code using large language models. Specifically, large language models can be applied to node states in the modeling language diagram to determine whether emissions (i.e., node state transitions) associated with the node states comply with the policies of the corresponding function signature for the node states. If the emissions comply with the policies, the policy engine can determine that the underlying program code is policy-compliant. However, if the emissions do not comply with the policies, the large language models can update / modify the node states in the modeling language diagram based on safety controls to achieve compliance.The updated / modified node states can be used to generate policy-compliant program code, which is presented as a suggestion to replace the underlying program code that is not policy-compliant.
[0027] Consequently, instead of users actively engaging in the time-consuming process of rewriting / re-creating program code to comply with policies and security requirements, large language models are used to suggest policy-compliant program code to the user. Thus, the techniques described here reduce the time users (e.g., software developers) must spend ensuring that program code complies with various policies by automating policy compliance based on these large language models. II. Examples of computer systems
[0028] Fig. Figure 1 illustrates an example of a computing system 100 that is operational for automating the compliance of program code with guidelines. The computing system 100 includes a processor 102, a memory 104 coupled to the processor 102, and a user interface 106 coupled to the processor 102. The memory 104 can correspond to a non-volatile, computer-readable medium containing instructions 108 that can be executed by the processor 102 to perform the operations described here.
[0029] The Computing System 100 can be integrated into a computing device, such as a laptop computer, a desktop computer, a portable computing device, a server, etc. Although the Computing System 100 comprises three components (e.g., the processor 102, the memory 104, and the user interface 106), it is understood that in other embodiments the Computing System 100 may include additional components. For example, in other embodiments the Computing System 100 may include a keyboard, a mouse, a modem, additional processors, additional memory and / or storage devices, a display screen, etc.
[0030] The processor 102 can be configured to execute instructions 108 in memory 104 to run an integrated development environment 110 and to present the integrated development environment 110 to a user 190 via the user interface 106. The integrated development environment 110 can correspond to a software application that enables the user 190 (e.g., a software developer) to develop program code. In particular, the integrated development environment 110 can function as a single mechanism for the user 190 to create, edit, test, and package program code. Fig. 1 The integrated development environment 110 includes a program code editor 120, a compiler 122, a modeling language diagram generator 124, and a policy-compliant program code generator 126. In other embodiments, the integrated development environment 110 may include other components, such as an interpreter, a debugger, etc.
[0031] User 190 can create / write program code 130 in program code editor 120 using user interface 106. For example, in some scenarios, user interface 106 might correspond to an input device, such as a keyboard, that allows user 190 to enter program code 130 into program code editor 120. Program code editor 120 might correspond to a text-based program, such as a word processor. Program code 130 could be written in one of many types of programming languages, such as C++, C, Java, JavaScript, etc. The programming languages described here are for illustrative purposes only and should not be considered a limitation. The techniques described here can be implemented using any programming language.
[0032] The program code 130 can correspond to source code that includes a variety of functions 132. Each function within the variety of functions 132 can correspond to a different operation performed by the program code 130. For example, the variety of functions 132 can correspond to a read function, a write function, a save-as function, an image creation function, a file renaming function, and so on. It is understood that the specific functions 132 described here are not intended as a limitation and are provided merely as examples. The techniques described here are intended to cover all functions that can be performed using computer programming techniques.
[0033] In Fig. 1. Program code 130 may contain a specific section of program code 130A, which contains one or more specific functions 132A. Thus, the specific section of program code 130A is contained within program code 130 (e.g., is a subset thereof), and the one or more specific functions 132A are contained within the multitude of functions 132 (e.g., are a subset thereof). As described here, for non-restrictive illustrative purposes only, the one or more specific functions 132A may (1) include a modification function that modifies a first specific data type into a second specific data type, and (2) a write function that writes the second specific data type to a specific location. However, it is understood that the one or more specific functions 132A may include any function that can be performed using computer programming techniques.
[0034] In response to the creation of program code 130 in the program code editor 120, the compiler 122 can be configured to compile the program code 130 to produce compiled program code 134. For example, the compiler 122 can translate the source code of a programming language (e.g., program code 130) into machine code (e.g., compiled program code 134). According to some embodiments, the compiled program code 134 can correspond to bytecode or computer object code, which an interpreter (not shown) can convert into binary machine code that can be read by a computer hardware processor. A specific section of the compiled program code 134A is included in the compiled program code 134 (e.g., is a subset thereof). The definite section of the compiled program code 134A corresponds to a compiled version of the definite section of the program code 130A.Thus, the specific section of the compiled program code 134A can be executed by a computer hardware processor to perform one or more specific functions 132A.
[0035] The modeling language diagram generator 124 can be configured to generate a modeling language diagram 140 that provides information about the compiled program code 134 and thus information about the program code 130. For example, during compilation, the modeling language diagram generator 124 can generate (e.g., abstract) the modeling language diagram 140 from the compiled program code 134, such that the modeling language diagram 140 contains a multitude of node states 142 (e.g., nodes) that provide information about the multitude of functions 132 in the program code 130. In some scenarios, a specific node state 142 provides information about a single function 132 in the program code 130. In other scenarios, a specific node state 142 provides information about two or more functions 132 in the program code 130. According to some implementations, the modeling language diagram 140 corresponds to a UML diagram.
[0036] In the illustrative example of the Fig. In Figure 1, the modeling language diagram 140 includes one node state 142A and one node state 142B. Although two node states 142 are illustrated, the modeling language diagram 140 may include additional (or fewer) node states 142 in other embodiments. The number of node states 142 in the modeling language diagram 140 may be based on the program code 130. Typically, but not always, longer program code 130 (which specifies more functions 132) may result in the modeling language diagram 140 having more node states 142 than shorter program code 130 (which specifies fewer functions 132). In the illustrative example of Figure 1, the modeling language diagram 140 includes two node states 142. Fig. 1. The node state 142A and the node state 142B can specify information about one or more particular functions 132A. For example, node state 142A can specify the modification function in one or more particular functions 132A, and node state 142B can specify the write function in one or more particular functions 132A. It goes without saying that the mappings between the node states 142 and the functions 132 are for illustrative purposes only and should not be considered restrictive.
[0037] Each node state 142 can be assigned to a unique class of node states that have the same underlying function(s) 132 and an identical parameter list. Each unique class of node states is identified by a unique function signature 144. Fig. In the modeling language diagram 140, node state 142A contains a function signature 144A, and node state 142B contains a function signature 144B. Each function signature 144 includes a procedure name (e.g., a name for the underlying function(s)) and a parameter list. Node states 142 with different underlying functions or with different parameter lists cannot have the same function signature. For example, if a random node state 142 in the modeling language diagram 140 has the same underlying function (e.g., the modification function) as node state 142A and the same parameter list as the parameter list of the underlying function of node state 142A, the function signature 144 of the random node state 142 will be the same as the function signature 144A for node state 142A. In the illustrative example of the Fig. The function signature 144A for node state 142A specifies a procedure name for the modification function. Function signature 144A includes a parameter list that designates the first specific type of data as input and the second specific type of data as output. Additionally, function signature 144B for node state 142B specifies a procedure name for the write function. Function signature 144B also includes a parameter list that specifies the location.
[0038] As in Fig. As illustrated in Figure 1, the modeling language diagram 140 includes a node state transition 143 between node state 142A and node state 142B. The node state transition 143 thus specifies a transition between the underlying modification function of node state 142A (specified by the function signature 144A) and the underlying write function of node state 142B (specified by the function signature 144B). The processor 102 includes a policy engine 150 to identify and evaluate the function signatures 144 associated with the node state transition 143. In particular, the policy engine 150 can identify one or more policies 160 that are associated with at least one function signature 144A associated with the node state transition 143. In some implementations, the policy engine 150 can be a large language model, such as...A large language model 162 is used to identify one or more policies 160 based on similarly formulated function signatures. During training, for example, different function signatures and node state transitions (e.g., training data) can be provided as inputs to the large language model 162, and the function signatures and node state transitions can be mapped to the corresponding policies. As more and more function signatures and node state transitions are provided to the large language model 162 as training data, the weights assigned to the large language model 162 can be fine-tuned to accurately identify the relevant policies for each function signature and node state transition. Therefore, once fine-tuned to identify policies based on function signatures and node state transitions, the large language model 162 can be a more efficient (e.g.,a faster and more accurate way to identify Guideline 160 than to rely on a programmer to analyze the program code and try to identify all relevant Guideline 160 for the program code 130.
[0039] The policies 160 can correspond to security policies and / or security controls that should be implemented to ensure that the program code 130 meets certain security requirements. To illustrate, the policy engine 150 includes a policy mapper 152. The policy mapper 152 can be configured to identify a specific policy 160A to map to the function signature 144A when the function signature 144A is part of the node state transition 143. That is, if the policy mapper 152 determines that there is a state transition between a node state that has the function signature 144A and a node state that has the function signature 144B, the policy mapper 152 maps the specific policy 160A to the function signature 144A.For illustration, let's assume that the specific policy 160A, which is associated with function signature 144A, is that the social security data must be deleted during the underlying modification function if function signature 144A is part of node state transition 143. It goes without saying that the above example of specific policy 160A is not intended to be restrictive and is for illustrative purposes only. In other scenarios, specific policy 160A may be different.
[0040] To ensure that the specific section of program code 130A complies with the specific policy 160A (e.g., deleting social security data), a policy compliance unit 154 of the policy engine 150 can perform a policy compliance operation. In this example, to perform the policy compliance operation, the policy compliance unit 154 can evaluate the node state 142A in the modeling language diagram 140 to determine whether the social security data is deleted. In some scenarios, the policy compliance unit 154 can use a large language model 162 to evaluate the node state 142A to determine whether the social security data is deleted.During the evaluation of node state 142A, when policy compliance unit 154 determines that the underlying modification function deletes the social security data, policy compliance unit 154 may determine that the specific section of program code 130A associated with node state 142A complies with specific policy 160A.
[0041] However, if the policy compliance unit 154 determines that the underlying modification function does not delete the social security data, the policy compliance unit 154 can determine that the specific section of program code 130A associated with node state 142A does not comply with the specific policy 160A. In this scenario, the policy compliance unit 154 can use the large language model 162 to update the modeling language graph 140 so that node state 142A becomes a policy-compliant node state 142C, and thus the node state transition 143 becomes policy-compliant. To update the modeling language graph 140 in this way, the large language model 162 can generate security controls 164 associated with the specific policy 160A to modify node state 142A in the modeling language graph 140 to the policy-compliant node state 142C.For example, the large language model 162 can identify suitable identifiers to create the policy-compliant node state 142C and apply the corresponding identifiers to the node state 142A. In . Fig. Figure 1 shows the updated version of the modeling language diagram 140 as an updated modeling language diagram 170. In particular, the updated node state 142A is shown as the policy-compliant node state 142C in the updated modeling language diagram 170.
[0042] The updated modeling language diagram 170, in particular the policy-compliant node state 142C, can be used to generate policy-compliant program code 180 (e.g., new code). The policy-compliant program code 180 can be used to modify the specific section of program code 130A (e.g., the original non-compliant program code) associated with node state 142A. For example, the policy-compliant program code generator 126 can automate the generation of the policy-compliant program code 180 based on the updated modeling language diagram 170. In particular, the policy-compliant program code generator 126 can use a large language model 182 to generate the policy-compliant program code 180. In some embodiments, the large language model 182 can correspond to the large language model 162.The inputs to the large language model 182 can include the specific section of program code 130A (e.g., the original non-compliant program code) and data from the policy-compliant node state 142C. Therefore, the policy-compliant program code 180 can be generated based on the specific section of program code 130A (e.g., based on the original non-compliant program code). The policy-compliant program code 180 can correspond to a modified version of the specific section of program code 130A. In particular, the policy-compliant program code 180 can include similar functions to the one or more special functions 132A associated with the specific section of program code 130A. However, unlike the specific section of program code 130A, the policy-compliant program code 180 corresponds to the specific policy 160A (e.g.,(He deletes the social security data during the modification function).
[0043] Modifying the specific section of program code 130A may involve replacing it with the policy-compliant program code 180. However, before replacing it with the policy-compliant program code 180, user 190 may be prompted (in the integrated development environment 110) to accept or modify the policy-compliant program code 180. Therefore, the policy-compliant program code 180 may be presented to user 190 as a modifiable proposal. Thus, in some scenarios, user 190 may be prompted to approve / edit the policy-compliant program code 180 before modifying the specific section of program code 130A based on it.In these scenarios, the specific section of program code 130A is modified based on policy-compliant program code 180 in response to user 190 approving policy-compliant program code 180.
[0044] The in relation to Fig. The techniques described in Section 1 enable automatic verification of the policy compliance of program code using the large language models 162 and 182. In particular, the large language model 162 can be applied to the node states 142 in the modeling language diagram 140 to determine whether emissions associated with the node states 142 comply with the policies 160 of the corresponding function signature 144 for the node states 142. If the emissions comply with the policies 160, the policy engine 150 can determine that the underlying program code 130 complies with the policies 160. However, if the emissions do not comply with the policies 160, the large language model 162 can be used to update / modify the node states 142 in the modeling language diagram 140 based on security controls 164 to achieve policy compliance. The updated / modified node states (e.g.,The policy-compliant node state 142C) can be used to generate policy-compliant program code 180, which is presented as a proposal to replace the underlying program code 130, which does not comply with policy 160.
[0045] Instead of the user actively engaging in the time-consuming process of rewriting / re-creating program code to comply with guidelines and security requirements, large language models are used to suggest guideline-compliant program code to the user. The [relevant] Fig. The techniques described in 1 thus reduce the time that users (e.g., software developers) have to spend to ensure that the program code complies with different guidelines 160 by automating guideline compliance based on the major language models 162, 182. III. Exemplary Computational Processes
[0046] Fig. Figure 2 illustrates an example of a computation process 200 for automating compliance with program code guidelines. The computation process 200 can be initiated by one or more of the components of the computing system 100. Fig. 1 will be carried out.
[0047] According to the calculation process 200, the user 190 can create / write the program code 130 in block 202 in the integrated development environment 110. Fig. For example, user 190 can create / write program code 130 in the integrated development environment 110 using the user interface 106. In response to the creation of program code 130 in the integrated development environment 110, compiler 122 can compile the program code 130 to produce the compiled program code 134. For example, compiler 122 can translate program code 130 into compiled program code 134.
[0048] According to calculation process 200, a modeling language diagram can be generated in block 204. For example, the modeling language diagram generator 124 (see Fig. 1) Generate the modeling language diagram 140, which contains information about the compiled program code 134. In particular, the modeling language diagram generator 124 can generate (e.g., abstract) the modeling language diagram 140 from the compiled program code 134 during compilation, such that the modeling language diagram 140 contains a multitude of node states 142, which contain information about the multitude of functions 132 in the program code 130.
[0049] According to computation process 200, the function signatures in the modeling language diagram can be evaluated by a policy engine in blocks 206 and 208. For example, policy engine 150 identifies (see Fig. 1) one or more guidelines 160, which are to be assigned to at least one function signature 144A associated with the node state transition 143.
[0050] According to calculation process 200, assignments of security / policy controls can be carried out in blocks 210, 212, and 218. As in Fig. As shown in Figure 1, the policy compliance unit 154 in block 212 can access compliance data and, in block 218, map the compliance data to the existing security controls 164B. The existing security controls 164B can be used to update the modeling language diagram 140 in block 220. However, in some scenarios, there are no existing security controls 164B to implement the policies 160. For example, in some scenarios, there are no existing attributes for the node state 142A indicating that the social security data must be deleted. In these scenarios, the large language model 162 generates novel security controls 164A for the policies 160 in blocks 214 and 216. For example, the large language model 162 can generate novel security controls 164A that can be used to update the modeling language diagram 140 in block 220.
[0051] According to calculation process 200, the modeling language diagram can be updated in block 220. As in Fig. As shown in Figure 1, the policy compliance unit 154 can, for example, use the security controls 164A and 164B assigned to the specific policy 160A to modify the node state 142A in the modeling language diagram 140 to the policy-compliant node state 142C. The updated version of the modeling language diagram 140 is shown as an updated modeling language diagram 170. In particular, the updated node state 142A is represented as the policy-compliant node state 142C in the updated modeling language diagram 170.
[0052] According to the calculation process 200, the guideline-compliant program code 180 can be generated in block 222. Fig. For example, the policy-compliant program code generator 126 can automate the generation of the policy-compliant program code generator 126 based on the updated modeling language diagram 170. According to the computation process 200, the user 190 can be prompted (in the integrated development environment 110) whether to accept the policy-compliant program code 180 or whether to modify the policy-compliant program code 180. If the user 190 accepts the policy-compliant program code 180, the policy-compliant program code 180 can replace the specific section of the program code 130A (e.g., the non-compliant program code) as part of a final output in block 224.
[0053] The in relation to Fig. The techniques described in section 2 enable automatic verification of program code's compliance with the guidelines using the large language model 162. For example, the large language model 162 can generate novel security controls 164A that can be used to update / modify the modeling language diagram 140 to achieve compliance with the guidelines 160. The updated / modified version of the modeling language diagram 140 (e.g., the updated modeling language diagram 170) can be used to generate guideline-compliant program code 180, which is presented as a proposal to replace the underlying program code 130 that does not comply with the guidelines 160.Instead of the user actively engaging in the time-consuming process of rewriting / re-creating program code to comply with guidelines and security requirements, large language models are used to suggest guideline-compliant program code to the user. The [relevant] Fig. The two techniques described thus reduce the time that users (e.g., software developers) have to spend to ensure that the program code complies with different guidelines 160 by automating guideline compliance based on the large language model 162.
[0054] Fig. Figure 3 illustrates another example of a computation process 300 for automating compliance with program code guidelines. The computation process 300 can be initiated by one or more of the components of the computation system 100. Fig. 1. The one relating to Fig. The described computing process 300 focuses on the automated generation of policy-compliant node states for the specific section of program code 130A. However, it is self-evident that computing process 300 can be extended to automate the generation of policy-compliant node states for different sections of program code 130.
[0055] According to Fig. 3. The specific section of program code 130A is provided to compiler 122. As described above, the specific section of program code 130A includes one or more specific functions 132A, such as the save-as function. Compiler 122 can compile the specific section of program code 130A to produce the specific section of compiled program code 134A. During compilation or in response to compilation, modeling language diagram generator 124 can generate the modeling language diagram 140, which includes node state 142A, which specifies the modification function, and node state 142B, which specifies the write function.
[0056] As in Fig. Figure 3 illustrates a non-restrictive example of node state 142A as a modification function, containing the function signature 144A. Node state 142A includes a list of attributes, such as the first specified data type ("data type1") of the user profile data, the location of the user profile data, and the second specified data type ("data_type2") of the modified user profile data. The function signature 144A also includes the name of the underlying function ("modify") and a parameter list. Additionally, a non-restrictive example of node state 142B as a write function is illustrated, containing the function signature 144B. Node state 142B includes a list of attributes, such as the location to which the modified user profile data is to be written and the second specified data type ("data_type2") of the modified user profile data.The function signature 144A also includes names for the underlying function ("write") and a parameter list.
[0057] Policy Mapper 152 can identify node state transition 143 and identify the specific policy 160A to be associated with function signature 144A. That is, if Policy Mapper 152 determines that there is a state transition between a node state having function signature 144A and a node state having function signature 144B, Policy Mapper 152 associates specific policy 160A with function signature 144A. According to the non-restrictive example described above, specific policy 160A (associated with function signature 144A) is that social security data should be deleted during the underlying modification function of the associated node state 142A. Policy Compliance Unit 154 can evaluate node state 142A to determine whether node state 142A indicates that social security data is deleted.In some scenarios, the policy compliance unit 154 can use the large language model 162 to evaluate node state 142A to determine whether social security data is being deleted. For example, the large language model 162 can process the text of node state 142A to determine if the attributes indicate that social security data is being deleted.
[0058] In the example of Fig. In node state 142A, there is no indication that social security data is deleted. Consequently, the large language model 162 can use the specific policy 160A to generate / identify security controls 164A. The security controls 164A can be used to update node state 142A to the policy-compliant node state 142C. For example, the modeling language diagram generator 124 can update node state 142A based on the security controls 164A to generate the policy-compliant node state 142C, which indicates that social security data is deleted. For example, the policy-compliant node state 142C is similar to node state 142A, but the underlying function in the function signature 144A of the policy-compliant node state 142A includes a function to delete social security data ("delete_social").
[0059] Fig. Figure 4 illustrates another example of a 400 computation process for automating compliance with program code guidelines. The 400 computation process can be initiated by one or more components of the 100 computation system. Fig. 1. be carried out. The one in Fig. The described computing process 400 focuses on the automated generation of policy-compliant program code for the specific section of program code 130A. However, it is self-evident that computing process 400 can be extended to automate the generation of policy-compliant program code for different sections of program code 130.
[0060] In Fig. 4. Data from the policy-compliant node state 142C is provided to the policy-compliant program code generator 126. The policy-compliant program code generator 126 can use the large language model 182 to generate the policy-compliant program code 180. Inputs to the large language model 182 can include the specific section of the program code 130A (e.g., the original non-compliant program code) and data from the policy-compliant node state 142C. Therefore, the policy-compliant program code 180 can be generated based on the specific section of the program code 130A (e.g., based on the original non-compliant program code). The policy-compliant program code 180 can correspond to a modified version of the specific section of the program code 130A.In particular, the policy-compliant program code 180 may include similar functions to the one or more specific functions 132A that are assigned to the specific section of program code 130A. However, unlike the specific section of program code 130A, the policy-compliant program code 180 conforms to specific policy 160A.
[0061] The in relation to Fig. The techniques described in sections 3-4 enable automatic verification of the policy compliance of program code using the large language models 162 and 182. In particular, the large language model 162 can be applied to node state 142A to determine whether the emissions associated with node state 142A comply with the specific policy 160A corresponding to the function signature 144A. As described in Fig. As illustrated in Figure 3, the large language model 162 can update / modify node state 142A based on security controls 164 if emissions do not comply with the specific policy 160A (e.g., if node state 142A does not specify that social security data will be deleted upon modification) to achieve compliance. Using the updated / modified node states (e.g., the policy-compliant node state 142C), policy-compliant program code 180 can be generated, which is presented as a proposal to replace the underlying program code 130 that does not comply with policy 160.
[0062] Consequently, instead of the user actively engaging in the time-consuming process of rewriting / re-creating program code to comply with guidelines and security requirements, large language models are used to suggest guideline-compliant program code to the user. The aspects related to Fig. The techniques described in 3-4 therefore reduce the time that users (e.g., software developers) have to spend to ensure that the program code complies with different guidelines 160 by automating guideline compliance based on the major language models 162, 182. IV. Exemplary machine learning process for large language models
[0063] Fig. Figure 5 shows a diagram 500 illustrating a training phase 502 and an inference phase 504 of trained machine learning models 532, in accordance with example implementation forms. According to some examples, the trained machine learning model(s) 532 may correspond to the large language model 162 and / or the large language model 182. Some machine learning techniques involve training one or more machine learning algorithms with an input set of training data to detect patterns in the training data and provide output inferences and / or predictions about (patterns in) the training data. The resulting trained machine learning algorithm may be referred to as a trained machine learning model. For example, Figure 5 shows... Fig. 5 the training phase 502, in which machine learning algorithm(s) 520 are trained with training data 510 to become trained machine learning models 532. Then, during the inference phase 504, the trained machine learning model(s) 532 can receive input data 530 and one or more inference / prediction requests 540 (perhaps as part of the input data 530) and provide one or more inference(s) and / or prediction(s) 550 as output.
[0064] As such, the trained machine learning model(s) 532 may include one or more models of machine learning algorithm(s) 520. The machine learning algorithm(s) 520 may include, but are not limited to: an artificial neural network (e.g., a convolutional neural network described herein, a recurrent neural network, a Bayesian network, a hidden Markov model, a Markov decision process, a logistic regression function, a support vector machine, a suitable statistical machine learning algorithm, and / or a heuristic machine learning system). The machine learning algorithm(s) 520 may be supervised or unsupervised and may implement any suitable combination of online and offline learning.
[0065] In some examples, the machine learning algorithm(s) 520 and / or the trained machine learning model(s) 532 can be accelerated using on-device coprocessors such as graphics processing units (GPUs), tensor processing units (TPUs), digital signal processors (DSPs), and / or application-specific integrated circuits (ASICs). Such on-device coprocessors can be used to accelerate the machine learning algorithm(s) 520 and / or the trained machine learning model(s). In some examples, the trained machine learning model(s) 532 can be trained, reside on a specific computing device, and run to provide inferences and / or otherwise make inferences for that specific computing device.
[0066] During training phase 502, the machine learning algorithm(s) 520 can be trained by providing at least the training data 510 as training input using unsupervised, supervised, semi-supervised, and / or reinforcement learning techniques. Unsupervised learning involves providing a portion (or all) of the training data 510 to the machine learning algorithm(s), and the machine learning algorithm(s) 520 determine one or more output inferences based on the provided portion (or all) of the training data 510.Supervised learning involves providing a portion of the training data 510 to the machine learning algorithm(s) 520, where the machine learning algorithm(s) 520 determine one or more output inferences based on the provided portion of the training data 510, and the output inference(s) are either accepted or corrected based on correct results associated with the training data 510. In some examples, the supervised learning of the machine learning algorithm(s) 520 can be controlled by a set of rules and / or a set of labels for the training input, and the set of rules and / or the set of labels can be used to correct inferences of the machine learning algorithm(s) 520.
[0067] Semi-supervised learning involves the availability of correct results for a portion, but not all, of the training data. During semi-supervised learning, supervised learning is used for a portion of the training data with correct results, and unsupervised learning is used for a portion of the training data without correct results. Reinforcement learning involves the machine learning algorithm(s) receiving a reward signal based on a previous inference, where the reward signal can be a numerical value. During reinforcement learning, the machine learning algorithm(s) can issue an inference and receive a reward signal in response, with the machine learning algorithm(s) configured to attempt to maximize the numerical value of the reward signal.In some examples, reinforcement learning also uses a value function that provides a numerical value representing an expected total sum of the numerical values provided by the reward signal over time. In some examples, the machine learning algorithm(s) 520 and / or the trained machine learning model(s) 532 may be trained using other machine learning techniques, including, but not limited to, incremental learning and curriculum learning.
[0068] In some examples, the machine learning algorithm(s) 520 and / or the trained machine learning model(s) 532 may employ transfer learning techniques. For example, transfer learning techniques may involve pre-training the trained machine learning model(s) 532 on a set of data and additionally training it using the training data 510. In particular, the machine learning algorithm(s) 520 may be pre-trained on data from one or more computing devices, and a resulting trained machine learning model may be provided to a specific computing device, which is designated to execute the trained machine learning model during the inference phase 504.Then, during training phase 502, the pre-trained machine learning model can be further trained using training data 510, which can be derived from kernel and non-kernel data of the specific computing device. This further training of the machine learning algorithm(s) 520 and / or the pre-trained machine learning model using the training data 510 from the specific computing device can be performed using either supervised or unsupervised learning. Once the machine learning algorithm(s) 520 and / or the pre-trained machine learning model has been trained on at least the training data 510, training phase 502 can be completed. The resulting trained machine learning model can be used as at least one of the trained machine learning models 532.
[0069] In particular, once the training phase 502 is completed, the trained machine learning model(s) 532 can be made available to a computing device, if it / they are not already on the computing device. The inference phase 504 can begin after the trained machine learning model(s) 532 has been made available to the specific computing device.
[0070] During the inference phase 504, the trained machine learning model(s) 532 can receive the input data 530 and generate and output one or more corresponding inferences and / or predictions 550 about the input data 530. As such, the input data 530 can be used as input for the trained machine learning model(s) 532 to provide corresponding inference(s) and / or prediction(s) 550 to kernel components and non-kernel components. For example, the trained machine learning model(s) 532 can generate inference(s) and / or prediction(s) 550 in response to one or more inference / prediction requests 540. In some examples, the trained machine learning model(s) can be executed by a section of other software.For example, the trained machine learning model(s) 532 can be executed by an inference or prediction daemon to be readily available to provide inferences and / or predictions on demand. The input data 530 can include data from the specific computing device that executes the trained machine learning model(s) 532, and / or input data from one or more other computing devices besides the specific computing device.
[0071] If the trained machine learning model 532 corresponds to the large language model 162, the input data 530 can include data associated with the different policies 160. Other types of input data are also possible. The inference(s) and / or prediction(s) 550 can include one or more security controls 164 for a specific policy 160. If the trained machine learning model 532 corresponds to the large language model 182, the input data 530 can include data associated with policy-compliant node states 142C, data associated with modeling language diagrams 170, and / or data associated with program code 130. The inference(s) and / or prediction(s) 550 can include one or more policy-compliant program codes 180 for a specific node state 142 or a modeling language diagram 140, 170.
[0072] Inference(s) and / or prediction(s) 650 may include other output data generated by the trained machine learning model(s) 532, which operate on the input data 530 (and the training data 510). In some examples, the trained machine learning model(s) 532 may use output inference(s) and / or prediction(s) 550 as input feedback 560. The trained machine learning model(s) 532 may also rely on past inferences as input for generating new inferences.
[0073] Convolutional neural networks and / or deep neural networks used herein can be an example of the machine learning algorithm(s) 520. After training, the trained version of a convolutional neural network can be an example of the trained machine learning model(s) 532. In this approach, an example of the one or more inference / prediction requests 540 can be a request to predict security controls 164 and / or policy-compliant program code 180. V. Additional Example Processes
[0074] Fig. Figure 6 illustrates a flowchart of a process 600, which relates to a new technology. The process 600 can also be carried out by the computer system 100, among other methods. The embodiments of Fig. Figure 6 can be simplified by removing one or more of the features shown therein. Furthermore, these embodiments can be combined with features, aspects and / or implementations of any of the preceding figures or otherwise described herein.
[0075] Procedure 600 involves generating a modeling language diagram by a processor, which specifies a compiled version of the program code, in block 602. The modeling language diagram includes at least one node that corresponds to at least one function in the program code. For example, the modeling language diagram generator 124 (see Fig. 1) Generate the modeling language diagram 140, which represents the compiled version of the program code 134 (e.g., a compiled version of the program code 130). The modeling language diagram 140 contains a multitude of nodes (e.g., the node states 142A, 142B) that correspond to a multitude of functions (e.g., the modify function or the write function) in the program code 130.
[0076] Procedure 600 also involves the processor at block 604 identifying at least one function signature associated with a node state transition between nodes in the modeling language diagram. For example, the policy engine 150 (see Fig. 1) Identify the function signature 144A that is assigned to the node state transition 143 in the modeling language diagram 140. The node state 142A can provide information about at least one function 132A of the plurality of functions 132, such as the modification function.
[0077] Procedure 600 further involves the processor identifying a specific policy to be assigned to the at least one function signature associated with the node state transition, using a large language model, as described in block 606. For example, the policy mapper 152 (see Fig. 1) Identify the specific policy 160A that is to be assigned to the functional signature 144A. According to one embodiment of method 600, the specific policy corresponds to a security policy.
[0078] Procedure 600 also involves the processor performing a policy compliance operation, using the large language model, to ensure that a specific section of program code conforms to the specific policy in block 608. The specific section of program code is associated with the node state transition, and performing the policy compliance operation involves generating a policy-compliant version of the specific section of program code. For example, with reference to Fig. 1. The policy compliance unit 154 performs the policy compliance process which ensures that the specified section of program code 130A complies with the specified policy 160A.
[0079] According to one embodiment of Method 600, performing the policy compliance process involves generating one or more safety controls using a large language model. Input to the large language model can be based on the specific policy. For example, with reference to Fig. 1. The policy compliance unit 154 generates one or more security controls 164 using the large language model 162. Performing the policy compliance operation may also involve generating a policy-compliant version of the node state transition based on the one or more security controls. For example, with reference to Fig. 1. The modeling language diagram generator 124 generates the policy-compliant node state 142C based on one or more security controls 164. Generating the policy-compliant node state 142C can ensure that the node state transition 143 complies with the specified policy 160A. Performing the policy compliance operation can also involve generating an updated version of the modeling language diagram based on the policy-compliant version of the node state transition. For example, with reference to Fig. 1. The modeling language diagram generator 124 generates the updated modeling language diagram 170 based on the policy-compliant node state 142C.
[0080] According to one embodiment of Method 600, performing the policy compliance process involves generating policy-compliant program code using a large language model. Input to the large language model can include data from a policy-compliant version of the node state transition. For example, with reference to Fig. 1. The policy-compliant program code generator 126 generates the policy-compliant program code 180 using the large language model 182. An input to the large language model 182 can include data from the policy-compliant node state 142C. In some scenarios, another input to the large language model 182 includes the specific section of the program code 130A, so that the policy-compliant program code 180 is based on the original non-compliant program code. Performing the policy compliance operation can also involve modifying the specific section of the program code based on the policy-compliant program code. For example, with reference to Fig. 1. The processor 102 modifies the specific section of program code 130A based on the policy-compliant program code 180.
[0081] According to one embodiment of Method 600, modifying the specific section of program code 130A involves replacing the specific section of program code 130A with the policy-compliant program code 180. In some scenarios, the user 190 may be prompted to approve the policy-compliant program code 180 before the specific section of program code 130A is modified based on the policy-compliant program code. In these scenarios, the specific section of program code 130A is modified based on the policy-compliant program code 180 in response to the user 190's approval of the policy-compliant program code 180.
[0082] It is understood that policy-compliant program code can be generated for any part of the program code 130 that does not comply with the relevant guidelines. For example, in some scenarios, procedure 600 may involve applying a first mark to occurrences of the at least one function signature 144A in the modeling language diagram 140 that comply with the specific guideline 160A, and applying a second mark to occurrences of the at least one function signature 144A in the modeling language diagram 140 that do not comply with the specific guideline 160A. For each marked occurrence of the function signature 144A that does not comply with the specific guideline 160A, procedure 600 may involve modifying corresponding sections of the program code 130 based on the corresponding policy-compliant program code.
[0083] According to one embodiment, Method 600 may involve modifying one or more parameters associated with each occurrence of the function signature in the modeling language diagram. Method 600 may also involve determining a deviation from a predicted output for each function signature in response to the modification of the one or more parameters. Method 600 may further involve generating policy-compliant program code using a large language model that reduces the deviation. Method 600 may also involve modifying sections of program code corresponding to each occurrence of the function signature based on the policy-compliant program code.
[0084] The procedure 600 can enable automated verification of policy compliance for program code using large language models 162. In particular, large language models 162 can be applied to node states 142 in the modeling language diagram 140 to determine whether emissions associated with the node states 142 comply with the policies 160 of the corresponding function signature 144 for the node states 142. If the emissions comply with the policies 160, the policy engine 150 can determine that the underlying program code 130 complies with the policies 160. However, if the emissions do not comply with the policies 160, the large language models 162 can update / modify the node states 142 in the modeling language diagram 140 based on safety controls 164 to achieve compliance. The updated / modified node states (e.g.,The policy-compliant node state 142C) can be used to generate policy-compliant program code 180, which is presented as a proposal to replace the underlying program code 130, which does not comply with policy 160.
[0085] Consequently, instead of the user actively engaging in the time-consuming process of rewriting / re-creating program code to comply with guidelines and security requirements, large language models are used to suggest guideline-compliant program code to the user. Thus, the procedure can reduce the time users (e.g., software developers) must spend ensuring that program code complies with various guidelines by automating guideline compliance based on the large language models. VI. Conclusion
[0086] The present disclosure is not to be limited in the sense of the specific embodiments described in this application, which are intended to illustrate various aspects. Many modifications and variations can be made without deviating from the scope of protection of the disclosure, as will be apparent to the person skilled in the art. Functionally equivalent methods and devices within the scope of protection of the disclosure, in addition to those described here, will be apparent to the person skilled in the art from the foregoing descriptions. Such modifications and variations are intended to fall within the scope of protection of the appended claims.
[0087] The above detailed description outlines various features and processes of the disclosed systems, devices, and methods with reference to the accompanying figures. In the figures, similar symbols typically identify similar components unless the context dictates otherwise. The embodiments described herein and in the figures are not to be understood as limiting. Other embodiments may be used and other modifications may be made without altering the scope of protection of the subject matter presented herein. It is readily understood that the aspects of this disclosure, as generally described herein and illustrated in the figures, can be arranged, substituted, combined, separated, and designed in a multitude of different configurations.
[0088] With regard to the message flow diagrams, scenarios, and flowcharts depicted in the figures and discussed here, each step, block, and / or communication can represent the processing and / or transmission of information according to the embodiments. Alternative embodiments are included within the scope of protection of these embodiments. In these alternative embodiments, for example, operations described as steps, blocks, transmissions, communications, requests, responses, and / or messages can be performed out of sequence as shown or discussed, including substantially concurrently or in reverse order, depending on the functionality involved.Furthermore, more or fewer blocks and / or processes can be used with each of the message flow diagrams, scenarios and flowcharts discussed herein, and these message flow diagrams, scenarios and flowcharts can be partially or completely combined with each other.
[0089] A step or block representing information processing may correspond to a circuit that can be configured to perform the specific logical functions of a procedure or technique described herein. Alternatively or additionally, a block representing information processing may correspond to a module, segment, or section of program code (including associated data). The program code may include one or more instructions executable by a processor to implement specific logical operations or actions in the procedure or technique. The program code and / or associated data may be stored on any type of computer-readable medium, such as a storage device, including random-access memory (RAM), a hard disk drive, a solid-state drive, or other storage medium.
[0090] Computer-readable media can also include non-volatile computer-readable media, such as those that store data for short periods, like register memory, processor cache, and RAM. Computer-readable media can also include non-volatile computer-readable media that store program code and / or data for longer periods. Thus, computer-readable media can include secondary or persistent long-term storage, such as read-only memory (ROM), optical or magnetic disks, solid-state drives, and compact disc read-only storage (CD-ROM). Computer-readable media can also be any other volatile or non-volatile storage system. A computer-readable medium can be considered, for example, as a computer-readable storage medium or as a specific storage device.
[0091] Furthermore, a step or block representing one or more information transfers can correspond to information transfers between software and / or hardware modules in the same physical device. However, other information transfers can occur between software modules and / or hardware modules in different physical devices.
[0092] The specific arrangements shown in the figures are not to be considered limiting. It is understood that other embodiments may include a larger or smaller number of the elements shown in a given figure. Furthermore, some of the illustrated elements may be combined or omitted. An embodiment may also include elements that are not illustrated in the figures.
[0093] Although various aspects and embodiments have been disclosed herein, further aspects and embodiments will be evident to the person skilled in the art. The various aspects and embodiments disclosed herein serve only for illustration and are not to be considered limiting, since the actual scope is indicated by the following claims. QUOTES INCLUDED IN THE DESCRIPTION
[0000] This list of documents cited by the applicant was automatically generated and is included solely for the reader's convenience. The list is not part of the German patent or utility model application. The DPMA accepts no liability for any errors or omissions. Cited patent literature
[0000] US 18 / 218,302
[0001]
Claims
[1] Procedure, encompassing: Generating a modeling language diagram by a processor that specifies a compiled version of program code, wherein the modeling language diagram includes at least one node corresponding to at least one function in the program code; The processor identifies at least one function signature that is associated with a node state transition between nodes in the modeling language diagram; The processor identifies a specific policy to be associated with the at least one functional signature linked to the node state transition, using a large language model; and Performing a policy compliance operation by the processor using the large language model, which ensures that a particular section of the program code complies with the particular policy, wherein the particular section of the program code is associated with the node state transition, and wherein performing the policy compliance operation includes generating a policy-compliant version of the particular section of the program code. [2] Method according to claim 1, wherein carrying out the compliance process comprises: Generating one or more security controls using the processor and the large language model; Generating a policy-compliant version of the node state transition based on one or more security checks by the processor; and The processor generates an updated version of the modeling language diagram based on the policy-compliant version of the node state transition. [3] Method according to claim 1, wherein carrying out the compliance process comprises: Generating policy-compliant program code by the processor using the large language model, based on data from a policy-compliant version of the node state transition, and wherein the policy-compliant program code corresponds to the policy-compliant version of the specified section of program code; and Modifying a specific section of the program code based on the policy-compliant program code by the processor. [4] Method according to claim 3, wherein an input to the large language model includes the specified section of the program code. [5] Method according to claim 3, wherein modifying the specific section of the program code comprises replacing the specific section of the program code with the program code that complies with the directive. [6] Method according to claim 3, wherein a user is prompted to approve the policy-compliant program code before the specific section of the program is modified based on the policy-compliant program code. [7] Method according to claim 6, wherein the specified section of the program code is modified based on the policy-compliant program code in response to the user's approval of the policy-compliant program code. [8] Method according to claim 1, further comprising applying a marking to occurrences of the at least one functional signature in the modeling language diagram that do not conform to the specified guideline. [9] The method of claim 8, further comprising: Generating policy-compliant program code for each marked occurrence of the at least one function signature, wherein the policy-compliant program code is generated using the large language model; and For each marked occurrence of the at least one functional signature, modify corresponding sections of the program code based on the corresponding policy-compliant program code. [10] Method according to claim 1, wherein the modeling language diagram comprises a Unified Modeling Language (UML) diagram. [11] Method according to claim 1, wherein the specified guideline corresponds to a safety guideline. [12] Method according to claim 1, further comprising: Changing one or more parameters that are associated with each occurrence of the at least one function signature in the modeling language diagram; Determining a deviation from a predicted output for each function signature in response to changing one or more parameters; Generating policy-compliant program code using the large language model, which reduces deviation; and Modifying sections of the program code that correspond to each occurrence of the at least one function signature, based on the policy-compliant program code. [13] System, encompassing: a storage facility; and a processor coupled to the memory, wherein the processor is configured to: to generate a modeling language diagram that specifies a compiled version of program code, wherein the modeling language diagram includes at least one node that corresponds to at least one function in the program code; to identify at least one functional signature that is associated with a node state transition between nodes in the modeling language diagram; to identify, using a large language model, a specific policy to be assigned to the at least one functional signature associated with the node state transition; and to perform a policy compliance operation using the large language model, which ensures that a particular section of the program code complies with the particular policy, wherein the particular section of the program code is associated with the node state transition, and wherein performing the policy compliance operation includes generating a policy-compliant version of the particular section of the program code. [14] System according to claim 13, wherein, in order to perform the policy compliance process, the processor is configured to: to generate one or more security controls using the large language model; to generate a policy-compliant version of the node state transition based on one or more security controls; and to generate an updated version of the modeling language diagram based on the policy-compliant version of the node state transition. [15] System according to claim 13, wherein, in order to perform the policy compliance process, the processor is configured to: to generate policy-compliant program code using the large language model, wherein an input to the large language model includes data from a policy-compliant version of the node state transition, and wherein the policy-compliant program code corresponds to the policy-compliant version of the specified section of the program code; and to modify the specific section of the program code based on the policy-compliant program code. [16] System according to claim 15, wherein, in order to modify the specific section of the program code, the processor is configured to replace the specific section of the program code with the policy-compliant program code. [17] System according to claim 16, wherein a user is prompted to approve the policy-compliant program code before the specific section of the program is modified based on the policy-compliant program code. [18] System according to claim 17, wherein the specified section of the program code is modified based on the policy-compliant program code in response to the user's approval of the policy-compliant program code. [19] System according to claim 13, wherein, in order to perform the policy compliance process, the processor is configured to: Applying an initial marker to occurrences of the at least one functional signature in the modeling language diagram that conform to the specified guideline; and Applying a second marker to occurrences of at least one functional signature in the modeling language diagram that do not conform to the specified guideline. [20] Non-volatile computer-readable medium comprising instructions which, when executed by a processor, cause the processor to perform operations, comprising: Generating a modeling language diagram that specifies a compiled version of program code, wherein the modeling language diagram includes at least one node that corresponds to at least one function in the program code; Identify at least one function signature that is associated with a node state transition between nodes in the modeling language diagram; Identifying a specific policy to be assigned to the at least one functional signature associated with the node state transition, using a large language model; and Performing a policy compliance operation using the large language model that ensures that a specific section of program code complies with the specific policy, wherein the specific section of program code is associated with the node state transition, and wherein performing the policy compliance operation includes generating a policy-compliant version of the specific section of program code.
Citation Information
Patent Citations
US-PATENTANMELDUNGNR.18/218,302