Information processing device, information processing method, and program

The information processing apparatus addresses the challenge of anonymizing unstructured dialogue data from AI agents by detecting and replacing privacy information, ensuring confidentiality and maintaining data integrity for efficient use in tasks like federated learning.

JP2026136882APending Publication Date: 2026-08-26TOYOTA JIDOSHA KK
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2025022707
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2026-08-26

AI Technical Summary

Technical Problem

Existing methods for anonymizing information in structured data are ineffective for unstructured dialogue data generated by artificial intelligence agents, risking confidentiality breaches.

Method used

An information processing apparatus and method that detects privacy-related information in unstructured dialogue data and replaces it with alternative information, ensuring confidentiality through processes like natural language processing and large-scale generative models.

Benefits of technology

Ensures confidentiality of dialogue data by maintaining content while concealing privacy-related information, enabling efficient sharing and use in tasks like federated learning without compromising data integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026136882000001_ABST
    Figure 2026136882000001_ABST
Patent Text Reader

Abstract

This technology provides a way to ensure the confidentiality of dialogue data with artificial intelligence agents. [Solution] The information processing device according to the first aspect of this disclosure includes a control unit. The control unit is configured to acquire dialogue data between an artificial intelligence agent and a user, detect portions of the acquired dialogue data that correspond to privacy-related information, replace the target information of the detected portion with alternative information, and output the dialogue data after the target information has been replaced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to an information processing apparatus, an information processing method, and a program.

Background Art

[0002] In Patent Document 1, a method for anonymizing information on a target item in structured data with defined items has been proposed.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

[0007] The program relating to the third aspect of this disclosure is a program for causing a computer to execute an information processing method. The information processing method includes acquiring dialogue data between an artificial intelligence agent and a user, detecting portions of the acquired dialogue data that correspond to privacy-related information, replacing the target information in the detected portions with alternative information, and outputting the dialogue data after the target information has been replaced. [Effects of the Invention]

[0008] According to this disclosure, the confidentiality of dialogue data with artificial intelligence agents can be ensured. [Brief explanation of the drawing]

[0009] [Figure 1] Figure 1 schematically illustrates an example of a scenario in which this disclosure applies. [Figure 2] Figure 2 schematically shows an example of a method for replacing target information. [Figure 3] Figure 3 schematically illustrates an example of how dialogue data is labeled. [Figure 4] Figure 4 schematically shows an example of a method for detecting privacy-related information. [Figure 5] Figure 5 schematically shows an example of a method for replacing information with alternative information. [Figure 6] Figure 6 schematically shows an example of an output destination for dialogue data. [Figure 7] Figure 7 is a flowchart showing another example of an output destination for dialogue data. [Figure 8] Figure 8 schematically shows an example of the hardware configuration of an information processing device. [Figure 9] Figure 9 schematically shows an example of the software configuration of an information processing device. [Figure 10] Figure 10 is a flowchart showing an example of the processing procedure for anonymizing dialogue data as described in this disclosure. [Modes for carrying out the invention]

[0010] In recent years, artificial intelligence agents equipped with trained machine learning models generated through machine learning have been used in a variety of situations. In particular, large-scale generative models such as large-scale language models, large-scale visual language models, and large-scale speech models are known to acquire common sense by learning from large amounts of data. Therefore, artificial intelligence agents equipped with large-scale generative models are beginning to be utilized in performing inference tasks in various fields.

[0011] When using an artificial intelligence agent, the user obtains the desired inference result by interacting with the AI ​​agent. This interaction involves user input to a trained machine learning model and the output of the trained machine learning model. The interaction data obtained through this interaction may contain privacy-related information such as personal information and confidential information. If the interaction data containing privacy-related information is shared, there is a risk that the confidentiality of that privacy-related information will be compromised.

[0012] In this regard, Patent Document 1 proposes a method for anonymizing information on target items in structured data where items are defined. However, dialogue data is generally unstructured (i.e., unstructured data). Therefore, it is difficult to apply the anonymization methods for structured data proposed in Patent Document 1, etc., to dialogue data.

[0013] In contrast, the information processing apparatus according to the first aspect of the present disclosure includes a control unit. The control unit is configured to acquire dialogue data between an artificial intelligence agent and a user, detect a portion corresponding to privacy-related information from the acquired dialogue data, replace the target information of the detected portion with substitute information, and output the dialogue data after replacing the target information.

[0014] In the first aspect of the present disclosure, by the process of detecting a portion corresponding to privacy-related information from the dialogue data and the process of replacing the information (target information) of the detected portion with substitute information, the target information corresponding to the privacy-related information can be anonymized. Thereby, even if the dialogue data is unstructured data, the confidentiality of the dialogue data with the artificial intelligence agent can be ensured.

[0015] Note that the form of the present disclosure may not be limited to the above information processing apparatus. As another form of the information processing apparatus according to the above aspect, one aspect of the present disclosure may be an information processing method for realizing all or a part of each of the above components, may be a program, or may be a machine-readable storage medium such as a computer that stores such a program. Here, the machine-readable storage medium may be a non-temporary medium that stores information such as a program by an electrical, magnetic, optical, mechanical, or chemical action. The non-temporary storage medium may include storage media (CD, DVD, semiconductor memory, etc.), auxiliary storage devices of a computer, external storage devices connected to the computer, and the like.

[0016] For example, the information processing method according to the second aspect of the present disclosure may be executed by a computer. The information processing method may include acquiring dialogue data between an artificial intelligence agent and a user, detecting a portion corresponding to privacy-related information from the acquired dialogue data, replacing the target information of the detected portion with substitute information, and outputting the dialogue data after replacing the target information.

[0017] Also, for example, the program according to the third aspect of the present disclosure may be a program for causing a computer to execute an information processing method. The information processing method may include acquiring dialogue data between an artificial intelligence agent and a user, detecting a portion corresponding to privacy-related information from the acquired dialogue data, replacing the target information of the detected portion with alternative information, and outputting the dialogue data after replacing the target information.

[0018] Hereinafter, embodiments according to one aspect of the present disclosure will be described based on the drawings. However, the embodiments described below are merely examples of the present disclosure in every aspect. Various improvements or modifications may be made without departing from the scope of the present disclosure. In implementing the present disclosure, a specific configuration according to the embodiment may be appropriately adopted. Although the data appearing in this embodiment is described in natural language, more specifically, it is specified by a pseudo-language, command, parameter, machine language, electrical signal, etc. recognizable by a machine such as a computer.

[0019] [1 Application Example] FIG. 1 schematically shows an example of a scene to which the present disclosure is applied. The information processing apparatus 1 according to the present embodiment is one or more computers configured to execute information processing related to anonymization of dialogue data 20 with the artificial intelligence agent A1.

[0020] The information processing apparatus 1 according to the present embodiment acquires dialogue data 20 between the artificial intelligence agent A1 and the user U1. The information processing apparatus 1 detects a portion 25 corresponding to privacy-related information from the acquired dialogue data 20. The information processing apparatus 1 replaces the target information 30 of the detected portion 25 with alternative information 35. Thereby, dialogue data 29 after replacing the target information 30 is obtained. The information processing apparatus 1 outputs the obtained dialogue data 29.

[0021] In this embodiment, the privacy-related information (target information 30) can be concealed by a process that detects a portion 25 corresponding to privacy-related information from the dialogue data 20, and a process that replaces the detected portion 25 information (target information 30) with alternative information 35. As a result, even if the dialogue data 20 is unstructured data, the confidentiality of the dialogue data 20 with the artificial intelligence agent A1 can be ensured.

[0022] [Artificial Intelligence Agent] Artificial intelligence agent A1 may be an agent that includes a trained machine learning model M1 generated by machine learning. Artificial intelligence agent A1 may consist of hardware resources such as processor resources and memory resources, or it may consist of software as an application.

[0023] The trained machine learning model M1 may be configured as appropriate to return inference results for any task in response to a request (prompt, etc.) from a user (user U1). The machine learning model M1 is configured to have one or more computational parameters that can be adjusted by machine learning. One or more computational parameters are used for the calculation of the target inference (task). The type of machine learning model M1 is not particularly limited and may be appropriately selected depending on the embodiment. The machine learning model M1 may be composed of, for example, a neural network. The target inference may be arbitrarily selected. Training samples may be appropriately collected according to the target inference. Machine learning may be appropriately performed using the collected training samples. Machine learning may be performed by any method. Known methods such as backpropagation may be used as the machine learning method. This makes it possible to obtain a trained machine learning model M1.

[0024] Furthermore, the pre-trained machine learning model M1 is a large-scale language model, a large-scale visual language model, and a large This may include large-scale generative models such as large-scale speech models. Large-scale generative models may be configured multimodally (i.e., they may be configured to accept multiple types of data inputs). Large-scale generative models may include any structure, such as a Transformer or a spread model. Large-scale generative models may be fine-tuned according to their intended use. For example, well-known models such as Claude and GPT may be used as large-scale generative models.

[0025] [Dialogue data] The dialogue data 20 may include data relating to all kinds of interactions between the artificial intelligence agent A1 and user U1. For example, the dialogue data 20 may include input from user U1 to artificial intelligence agent A1 (trained machine learning model M1), output from artificial intelligence agent A1, etc. The type of dialogue data 20 is not particularly limited and may be appropriately selected depending on the embodiment. The dialogue data 20 may include, for example, text data, sound data, image data, etc. User U1 may be any user.

[0026] The interaction between artificial intelligence agent A1 and user U1 may be conducted in any way using one or more computers. Artificial intelligence agent A1 may be run on any computer. The information processing device 1 may be the computer used by user U1 (terminal, etc.), the computer running artificial intelligence agent A1, or any other computer. The computer used by user U1 and the computer running artificial intelligence agent A1 may be the same or different.

[0027] In one example, artificial intelligence agent A1 may be operated on information processing device 1. User U1 may interact with artificial intelligence agent A1 by directly operating information processing device 1. Alternatively, user U1 may access information processing device 1 using another computer. In this case, user U1 may interact with artificial intelligence agent A1 via the other computer. In this case, at least a portion of the interaction data 20 may be collected on information processing device 1. At least a portion of the interaction data 20 may also be collected on another computer used by user U1. The collected data (at least a portion of the interaction data 20) may be provided to information processing device 1 as appropriate.

[0028] In another example, the artificial intelligence agent A1 may be operated on a computer other than the information processing device 1 (a first computer). In this case, at least a portion of the dialogue data 20 may be collected on the first computer. The collected data may be provided to the information processing device 1 as appropriate. User U1 may access the first computer using any computer. If user U1 uses the information processing device 1 to access the first computer, at least a portion of the dialogue data 20 may be collected on the information processing device 1. If user U1 uses yet another computer (a second computer) to access the first computer, at least a portion of the dialogue data 20 may be collected on the second computer. The collected data may be provided to the information processing device 1 as appropriate.

[0029] [Privacy-related information] Privacy-related information may be any information that can be kept confidential. For example, privacy-related information may include at least one of personal information and confidential information. Personal information is information that can identify an individual. Personal information may include, for example, attribute information about an individual such as name, date of birth, address, account information, email address, and telephone number. Personal information may also include biometric information that can indicate an individual's characteristics, such as facial images, voiceprints, and gait patterns. Personal information may also include, for example, information that can identify an individual such as user identifiers and My Number. Personal information may also include information that cannot identify an individual on its own, but can identify an individual when combined with other information. Confidential information may be information that is not personal information but is kept secret from others. Confidential information may include, for example, hobbies, beliefs, orientations, and convictions. Confidential information may include sensitive personal information (privacy, etc.) such as medical history. Confidential information may also include technical information such as research and development information, trade secrets, and know-how. Confidential information may also include highly confidential information such as transaction information.

[0030] [Alternative information] The alternative information 35 may be any information that replaces the target information 30, which is privacy-related information. The content of the alternative information 35 is not particularly limited, and may be appropriately selected depending on the embodiment, as long as the target information 30 can be kept confidential.

[0031] For example, the alternative information 35 may be masking information such as mosaics, occlusion, or meaningless information. However, if the alternative information 35 is composed of masking information, the content of the dialogue data 20 will be lost (i.e., not preserved). The fact that the content of the dialogue data 20 is not preserved may cause problems when sharing the dialogue data 20. For example, when sharing the dialogue data 20 with other artificial intelligence agents, the inability to accurately transfer the dialogue content may lead to inference proceeding in a direction different from the intended purpose. Also, for example, when using the dialogue data 20 as a training sample for machine learning, the fact that the accurate content is not reflected in the machine learning may cause a deterioration in the performance of the machine learning model.

[0032] Therefore, in another example, the alternative information 35 may be information that maintains the content of the dialogue data 20 while concealing the target information 30. In one example of this embodiment, by having the alternative information 35 composed of such information, the content of the dialogue data 20 can be maintained even after concealing the target information 30, which is privacy-related information. This can be expected to suppress the occurrence of the above-mentioned problems. The information that maintains the content of the dialogue data 20 while concealing the target information 30 is not particularly limited and may be determined as appropriate depending on the embodiment. In one example, the information that maintains the content of the dialogue data 20 while concealing the target information 30 may be composed of information that simulates the target information 30.

[0033] For example, if the target information 30 includes an image, the alternative information 35 may include an image generated by a large-scale generative model. Specifically, if the target information 30 includes an image of an individual, the alternative information 35 may include an image of a fictional person. For example, if the target information 30 includes sound, the target information 30 may include artificially generated sound. Specifically, if the target information 30 includes an individual's voice, the alternative information 35 may include an artificial voice. This allows for the concealment of voiceprints. Also, for example, if the target information 30 includes text, the target information 30 may include text that has been at least partially transformed by any method, such as converting the words in the text to other words of the same part of speech, creating a higher-level concept, or abstracting it.

[0034] Figure 2 schematically shows an example of the replacement of target information 30 with alternative information 35 according to this embodiment. In one example, target information 30 may include a phrase 301. The phrase 301 may constitute at least a part of the privacy-related information. The alternative information 35 may consist of another phrase 351 of the same part of speech as the phrase 301. That is, replacing target information 30 with alternative information 35 may include converting the phrase 301 contained in target information 30 to another phrase 351 of the same part of speech.

[0035] As long as the part of speech is the same as that of wording 301, wording 351 is not particularly limited and may be appropriately selected depending on the embodiment. As a specific example, let's assume a scenario where the target information 30 is "Mr. Sato, the department head," and "Mr. Sato" is an example of wording 301 and privacy-related information. In this scenario, "Mr. Sato" may be replaced with a fictitious person's name such as "Mr. Suzuki." A fictitious person's name such as "Mr. Suzuki" is an example of another wording 351 with the same part of speech as wording 301. For example, alternative information 35 may consist of "Mr. Suzuki, the department head." When wording 301 is a person's name, wording 351 may be an anonymous name such as Taro, Jiro, Hanako, Alice, Bob, Carol, etc. It may consist of typical fictional character names used in [the context].

[0036] The target information 30, including the text 301, may consist of data in any format, such as text, audio, or images. In other words, the data format of the text 301 is not particularly limited and may be appropriately selected depending on the embodiment. Accordingly, the alternative information 35, including the text 351, may also consist of data in any format.

[0037] According to one example of this embodiment, by converting the word 301 contained in the target information 30 to another word 351 of the same part of speech, the target information 30 can be kept confidential while the content of the dialogue data 20 can be appropriately maintained. This is expected to suppress the occurrence of the above-mentioned problems.

[0038] Furthermore, in one example, the target information 30 may include the phrase 301. The alternative information 35 may consist of another phrase 353 obtained by conceptualizing or abstracting the phrase 301. That is, replacing the target information 30 with the alternative information 35 may include converting the phrase 301 contained in the target information 30 into another phrase 353 obtained by conceptualizing or abstracting it. Note that, similar to the target information 30 including the phrase 301, the alternative information 35 including the phrase 353 may also consist of data in any format.

[0039] The forms of higher-level conceptualization and abstraction are not particularly limited and may be defined as appropriate depending on the embodiment. As a specific example, consider a scenario in which the target information 30 is "Department Head Sato," and "Sato" is an example of wording 301 and privacy-related information, similar to the above. In this scenario, "Department Head Sato" may be conceptualized as a higher-level concept such as "Supervisor." Also, "Department Head Sato" may be abstracted as "Department Head," etc. "Supervisor" and "Department Head" are examples of wording 351.

[0040] According to one example of this embodiment, by conceptualizing or abstracting the words 301 contained in the target information 30, the target information 30 can be kept confidential while appropriately maintaining the content of the dialogue data 20. This is expected to suppress the occurrence of the aforementioned problems.

[0041] [Labeling] Figure 3 schematically shows an example of a scenario in which a label 40 is assigned to dialogue data (20, 29) according to this embodiment. In one example, the information processing device 1 may assign a label 40 to the dialogue data (20, 29) that indicates the level of confidentiality corresponding to the target information 30. The level of confidentiality is the degree of confidentiality. The correspondence between privacy-related information (target information 30) and the level of confidentiality is not particularly limited and may be defined as appropriate depending on the embodiment.

[0042] Label 40 may be used for access control of the dialogue data (20, 29). For example, outputting the dialogue data 29 after replacing the target information 30 may include controlling the output of the dialogue data (20, 29) according to the confidentiality level indicated by the assigned label 40. Controlling the output of the dialogue data (20, 29) means that (i) the shareholder can access (ii) If permitted, outputting (permitting output) the dialogue data 20 before replacing the target information 30 to the shared destination, and (iii) if the shared destination is not permitted to access, outputting (permitting output) the dialogue data 29 after replacing the target information 30 to the shared destination. Not permitted to access the shared destination may mean that access to the dialogue data 20 before replacement is not permitted. The shared destination may be any computer (including external storage devices) that can provide or store the dialogue data (20, 29). The shared destination is not particularly limited and may be appropriately selected depending on the embodiment. The provision of the dialogue data (20, 29) may be performed in response to a request from the shared destination or any computer other than the shared destination, or it may be performed voluntarily. Also, in one example, controlling the output of the dialogue data (20, 29) may include (iii) if the shared destination is not permitted to access the replaced dialogue data 29. This may further include not allowing (prohibiting) the output of either the pre-replacement dialogue data 20 or the replacement dialogue data 29 to the sharing destination.

[0043] The correspondence between the level of confidentiality and access control is not particularly limited and may be defined as appropriate depending on the embodiment. For example, access control may be defined according to the relationship between the sharing user and user U1. For example, if the privacy-related information includes personal information and confidential information, the level of confidentiality for personal information may be set higher than that for confidential information. Accordingly, if the target information 30 includes personal information, access to the dialogue data (20, 29) may be controlled such that the pre-replacement dialogue data 20 is shared only on computers within user U1's network, the post-replacement dialogue data 29 is shared on computers within user U1's network and those related to user U1 (friends, etc.), and neither the pre-replacement dialogue data 20 nor the post-replacement dialogue data 29 is shared on computers of persons unrelated to user U1. Furthermore, if the target information 30 does not include personal information but includes confidential information, access to the dialogue data (20, 29) may be controlled such that the dialogue data 20 before replacement is shared among computers within the scope of user U1 and those related to user U1, and the dialogue data 29 after replacement is shared among computers of any person. In another example, the confidentiality level of at least a portion of the confidential information may be set to be the same as, or higher than, that of at least a portion of the personal information. The correspondence between confidentiality levels and access control is not limited to the above example and may be changed as appropriate depending on the embodiment. Access control may be defined independently of the relationship with user U1. According to one example of this embodiment, access control according to the confidentiality level of the target information 30 can be realized by assigning a label 40.

[0044] The data format of label 40 is not particularly limited and may be appropriately selected depending on the embodiment. In one example, label 40 may be attached as metadata to the dialogue data (20, 29). In one example, label 40 may include an identifier indicating the level of confidentiality and access control information corresponding to that level of confidentiality. The access control information may include information for identifying at least one of the permitted and restricted access targets. In another example, multiple labels 40 may be attached to a single piece of dialogue data (20, 29). In this case, access control of the corresponding dialogue data (20, 29) may be performed by any of the multiple labels 40. For example, access control of the corresponding dialogue data (20, 29) may be performed according to the strictest level of confidentiality.

[0045] [Methods for detecting privacy-related information] The method for detecting the portion 25 corresponding to privacy-related information from the dialogue data 20 is not particularly limited and may be appropriately selected depending on the embodiment. A known method for detecting the target information (in this embodiment, privacy-related information) may be used as the method for detecting the portion 25.

[0046] Figure 4 schematically shows an example of a method for detecting the portion 25 corresponding to privacy-related information according to this embodiment. In one example, detecting the portion 25 corresponding to privacy-related information may be performed by detecting the portion 25 corresponding to privacy-related information using natural language processing N2 or a trained machine learning model M2. According to this example, the portion 25 (target information 30) corresponding to privacy-related information can be appropriately detected.

[0047] Furthermore, the configuration of the natural language processing N2 is not particularly limited, as long as it can detect privacy-related information, and may be determined as appropriate depending on the embodiment. The natural language processing N2 may employ known methods such as morphological analysis to divide text into the smallest units, the use of a corpus which is a language database, and rule-based processing based on predetermined rules.

[0048] Similarly, if privacy-related information can be detected, the structure of the trained machine learning model M2 The composition is not particularly limited and may be appropriately determined depending on the embodiment. The type of machine learning model M2 is not particularly limited and may be appropriately selected depending on the embodiment. The trained machine learning model M2 may be a specialized model generated by machine learning using collected privacy-related information as training samples. The trained machine learning model M2 may include large-scale generative models such as large-scale language models, large-scale visual language models, and large-scale speech models. The large-scale generative models may be configured in a multimodal manner. The large-scale generative models may be fine-tuned to enhance the ability to detect privacy-related information. The trained machine learning model M2 may be the same as the trained machine learning model M1 that constitutes the artificial intelligence agent A1. That is, the trained machine learning model M1 may also serve as the trained machine learning model M2. Alternatively, the trained machine learning model M2 may be different from the trained machine learning model M1. In one example, the detection of the portion 25 corresponding to privacy-related information may be performed by a combination of natural language processing N2 and the trained machine learning model M2.

[0049] [Method of replacing with alternative information] If the target information 30 can be concealed, the method for replacing the target information 30 with the alternative information 35 is not particularly limited and may be appropriately selected depending on the embodiment. The method for generating the alternative information 35 is not particularly limited and may be appropriately selected depending on the embodiment. The generation of the alternative information 35 may or may not depend on the target information 30.

[0050] In one example, alternative information 35 may be generated by transforming target information 30 using a rule-based approach. Target information 30 may be replaced by the generated alternative information 35. The transformation rules may be arbitrarily defined. In another example, multiple candidates for alternative information 35 may be provided in advance. Each candidate may be generated manually or automatically. Alternative information 35 may be appropriately selected from the multiple candidates provided in advance. Target information 30 may be replaced by the selected candidate (alternative information 35).

[0051] Figure 5 schematically shows an example of a method for replacing target information 30 with alternative information 35 according to this embodiment. In one example, replacing the detected target information 30 of portion 25 with alternative information 35 may be performed by generating alternative information 35 using a large-scale generation model M3, and then replacing the detected target information 30 of portion 25 with the generated alternative information 35. According to this example, it is not necessary to construct a dedicated algorithm for generating alternative information 35. Therefore, a reduction in the cost of generating alternative information 35 can be expected.

[0052] The large-scale generative model M3 may include a large-scale language model, a large-scale visual language model, a large-scale speech model, etc. The large-scale generative model M3 may be configured in a multimodal manner. The large-scale generative model M3 may be fine-tuned to enhance its ability to conceal the target information (target information 30).

[0053] When a large-scale generative model is used in the trained machine learning model M1, the large-scale generative model M3 may be the same as the large-scale generative model that constitutes the artificial intelligence agent A1. In other words, the trained machine learning model M1 (large-scale generative model) may also serve as the large-scale generative model M3. Alternatively, the large-scale generative model M3 may be different from the large-scale generative model that constitutes the artificial intelligence agent A1. Similarly, when a large-scale generative model is used in the trained machine learning model M2, the large-scale generative model M3 may be the same as or different from the trained machine learning model M2 (large-scale generative model).

[0054] The method for generating the alternative information 35 in the large-scale generation model M3 may not be particularly limited and may be appropriately selected according to the embodiments. In one example, an arbitrary instruction I3 that requests the generation of the alternative information 35 may be given to the large-scale generation model M3. The instruction I3 may include an instruction sentence configured to instruct the generation of the alternative information 35. In one example, the instruction I3 may further include the target information 30. When the instruction I3 includes the target information 30, the instruction sentence may be, for example, "Please generate information obtained by anonymizing <XXX (target information)>", " ". In one example, the instruction I3 may further include the target information 30. When the instruction I3 includes the target information 30, the instruction sentence may be, for example, "Please generate information obtained by anonymizing <XXX (target information)>", " <xxx>The instruction may be configured to generate alternative information 35 in a way that conceals the target information 30, such as "Generate fictitious information that has the same meaning as the target information 30." In one example, the instruction may further include one or more combinations, each comprising a sample of the target information 30 and a corresponding sample of the alternative information 35. In another example, the instruction may further include conditions for the alternative information 35 to be generated (e.g., level of concealment, features to retain, etc.). In one example, the conditions for the alternative information 35 may include conversion conditions such as converting to another word 351 of the same part of speech, or converting to another word 353 that is a higher-level concept or abstraction. This allows for control over the generated alternative information 35.

[0055] In one example, the alternative information 35 generated by the large-scale generative model M3 may be used directly to replace the target information 30. In another example, the generated alternative information 35 may be verified to see if it satisfies predetermined conditions. These predetermined conditions may be defined as appropriate to ensure the confidentiality of the target information 30, such as the degree to which it has been concealed and whether the context of the dialogue data 20 has been maintained. For example, the predetermined conditions may be: (1) the alternative information 35 does not contain information that can identify the target information 30. (1) The alternative information 35 is consistent with the context of the dialogue data 20, and (2) The alternative information 35 satisfies the specified level of confidentiality. If the specified conditions are met, the generated alternative information 35 may be used to replace the target information 30. If the specified conditions are not met, the generated alternative information 35 may be discarded, and the generation of alternative information 35 by the large-scale generation model M3 may be performed again.

[0056] [output] In a typical example, outputting the replaced dialogue data 29 may consist of outputting the dialogue data 29 as is. However, the form in which the dialogue data 29 is output is not limited to this example and may be determined as appropriate depending on the embodiment. In another example, the dialogue data 29 may be used for any information processing. Using it for information processing may include applying calculation processing such as data processing to the dialogue data 29. Outputting the dialogue data 29 may consist of outputting the result of this information processing. The output destination may be arbitrarily selected. Furthermore, outputting the dialogue data 29 may include saving the dialogue data 29. Saving the dialogue data 29 may also include saving the replaced dialogue data 20. In one example, when a form that assigns a label 40 is adopted, the dialogue data 20 before replacement, the dialogue data 29 after replacement, and the label 40 may be associated and saved as appropriate. Below, two output forms of the dialogue data 29 are illustrated. In one example, at least one of the following two output forms may be adopted.

[0057] (Output to other artificial intelligence agents) Figure 6 schematically shows an example of an output destination for the dialogue data 29 according to this embodiment. In one example, outputting the dialogue data 29 after replacing the target information 30 may include outputting the dialogue data 29 after replacing the target information 30 to other artificial intelligence agents A2 other than artificial intelligence agent A1. That is, outputting the dialogue data 29 after replacing the target information 30 may include sharing the dialogue data 29 after replacing the target information 30 with other artificial intelligence agents A2.

[0058] Other artificial intelligence agents A2 may be configured in the same way as artificial intelligence agent A1. Other artificial intelligence agents A2 may be operated on any computer. If other artificial intelligence agents A2 are operated on a different computer than artificial intelligence agent A1, the dialogue data 29 may be output to other artificial intelligence agents A2 via a network, storage medium, etc. Also, in a typical example, other artificial intelligence agents A2 may be... It may be used by users other than user U1. However, the usage of other artificial intelligence agents A2 is not limited to this example and may be modified as appropriate depending on the embodiment. In another example, other artificial intelligence agents A2 may be used by user U1. In particular, other artificial intelligence agents A2 may be used by user U1 in a manner that may be viewed by other users.

[0059] In one example of this embodiment, the content of the dialogue data 20 can be shared with other artificial intelligence agents A2 while ensuring the confidentiality of privacy-related information (target information 30). This makes it possible to expect improved efficiency in task execution by other artificial intelligence agents A2. In another example, the alternative information 35 consists of information that maintains the content of the dialogue data 20 while concealing the target information 30, thereby ensuring that the content of the dialogue data 20 is properly maintained. This makes it possible to transfer the dialogue from artificial intelligence agent A1 to other artificial intelligence agents A2 while maintaining its content. As a result, it is possible to improve the efficiency of task execution in other artificial intelligence agents A2 and to expect the proper execution of tasks with the same purpose as the tasks in artificial intelligence agent A1. Note that if the dialogue data (20, 29) is assigned a label 40, and other artificial intelligence agents A2 are permitted to access the pre-replacement dialogue data 20 according to the label 40, the pre-replacement dialogue data 20 may be shared with other artificial intelligence agents A2 instead of the replaced dialogue data 29.

[0060] (Use in associative learning) Figure 7 schematically shows another example of an output destination for the dialogue data 29 according to this embodiment. In another example, as described above, the artificial intelligence agent A1 may include a machine learning model M1 having one or more computational parameters P1. Outputting the dialogue data 29 after replacing the target information 30 may include using the dialogue data 29 after replacing the target information 30 as a training sample for machine learning of the machine learning model M1 to adjust the values ​​of one or more computational parameters P1 of the machine learning model M1, and uploading the adjusted values ​​of one or more computational parameters P1 for federative learning.

[0061] The machine learning of machine learning model M1 using dialogue data 29 is local learning in associative learning. The form in which dialogue data 29 is used in local learning is not particularly limited, and may be appropriately selected depending on the embodiment, such as the type of machine learning model M1, as long as the dialogue data 29 is used in machine learning in a way that improves the performance of machine learning model M1. Local learning may be carried out by any method. Known methods may be used for local learning. The method of associative learning is not particularly limited, and may be appropriately selected depending on the embodiment. Known methods may be used for associative learning.

[0062] Federated learning may be performed on one or more server devices E1. Server device E1 may consist of any computer. The upload destination for federated learning is not particularly limited and may be appropriately selected depending on the embodiment. In one example, when federated learning is performed on server device E1, the adjusted values ​​of one or more computation parameters P1 may be uploaded directly or indirectly to server device E1. Direct uploading may include uploading via a network, etc. Indirect uploading may consist of uploading via another computer, storage medium, etc. The other computer may include external storage devices such as NAS (Network Attached Storage). Server device E1 may appropriately collect the results of local learning other than the machine learning model M1. Server device E1 may generate a global model (trained machine learning model) by integrating the collected local learning results. Server device E1 may appropriately provide (distribute) the generated global model. The machine learning model M1 may be updated with the provided global model.

[0063] Patent Document 2 proposes a federated learning method that updates a global model using the results of local learning obtained from multiple edges. In federated learning, the confidentiality of training samples can be ensured because training samples are not shared. However, because the learning results from training samples containing privacy-related information are reflected in the global model (trained machine learning model) obtained as a result of federated learning, there is a possibility that the global model will output inference results that contain privacy-related information. This could compromise the confidentiality of privacy-related information.

[0064] In contrast, according to one example of this embodiment, privacy-related information can be concealed during local learning by replacing the target information 30, which corresponds to privacy-related information, with alternative information 35. By concealing privacy-related information during local learning, it is possible to prevent privacy-related information from being reflected in federated learning. Therefore, federated learning can be operated appropriately while ensuring the confidentiality of privacy-related information. In one example, since the alternative information 35 consists of information that maintains the content of the dialogue data 20 while concealing the target information 30, it is possible to reduce the possibility of causing performance degradation of the machine learning model M1 during local learning. As a result, appropriate operation of federated learning can be expected. The dialogue data 29 after replacement may be shared with other artificial intelligence agent A2 and used for local learning of the machine learning model M1 of artificial intelligence agent A1. The values ​​of one or more computational parameters P1 of the machine learning model M1 after local learning may be uploaded for federated learning.

[0065] [2 Example Configurations] [Example Hardware Configuration] Figure 8 schematically shows an example of the hardware configuration of the information processing device 1 according to this embodiment. In one example, the information processing device 1 may be configured as a computer in which a control unit 11, a storage unit 12, a communication module 13, an input device 14, and an output device 15 are electrically connected.

[0066] The control unit 11 is configured to perform information processing based on the program and various data. For example, the control unit 11 includes a hardware processor such as a CPU (Central Processing Unit), RAM (Random Access Memory), and ROM (Read Only Memory). Good. The control unit 11 (CPU) is an example of a processor resource.

[0067] The storage unit 12 is configured to hold arbitrary data. For example, the storage unit 12 may include a hard disk drive, a solid-state drive, semiconductor memory, etc. The storage unit 12, RAM, and ROM are examples of memory resources of the information processing device 1. In one example, the storage unit 12 may store various information such as a program 81.

[0068] Program 81 is a program that causes the information processing device 1 to perform information processing (Figure 10, described later) related to the anonymization of the dialogue data 20 with the artificial intelligence agent A1. Program 81 includes a series of instructions for said information processing. When the artificial intelligence agent A1 is running on the information processing device 1, the storage unit 12 may further store model data representing the trained machine learning model M1.

[0069] In one example, program 81 may be stored in a storage medium 91 instead of or together with the storage unit 12. The storage medium 91 is configured to store various types of information (stored programs, etc.) by electrical, magnetic, optical, mechanical, or chemical means so that a machine such as a computer can read the information. The storage unit 12 and the storage medium 91 are examples of non-temporary storage media. The information processing device 1 may retrieve program 81 from the storage medium 91. In another example, the information processing device 1 may retrieve at least a portion of the dialogue data 20 from the storage medium 91. The storage medium 91 is a disk-type storage medium (CD, DVD). The storage medium may be a disk-type storage medium such as a semiconductor memory (flash memory, etc.). Any drive device may be used to read the information stored in the storage medium 91. The type of drive device may be selected according to the storage medium 91. The drive device may be connected to the information processing device 1 in any way. The storage medium 91 may include an external storage device that can be connected to the information processing device 1.

[0070] The communication module 13 is configured to perform wired or wireless communication over a network. The communication module 13 may consist of, for example, a wired LAN (Local Area Network) module, a wireless LAN module, etc. The network standard is not particularly limited and may be appropriately selected depending on the embodiment. For example, the type of network may be appropriately selected from the Internet, wireless communication network, mobile communication network, telephone network, dedicated network, etc. The information processing device 1 may perform data communication with other computers via the communication module 13. In one example, the information processing device 1 may use the communication module 13 to acquire at least a portion of the dialogue data 20 over the network.

[0071] The input device 14 is configured to accept information input. The input device 14 may consist of, for example, a mouse, keyboard, touch panel, touchpad, or control. The output device 15 is configured to output information. The output device 15 may consist of, for example, a display or speaker. The information processing device 1 may be operated using the input device 14 and the output device 15. The input device 14 and the output device 15 may be directly connected to the information processing device 1, or they may be indirectly connected via at least one of the communication module 13 and the external interface. The external interface may be appropriately configured to connect to an external device via wired or wireless connection, for example, a USB (Universal Serial Bus) port or a dedicated port. The input device 14 and the output device 15 may be integrated at least in part by a touch panel display or the like.

[0072] Regarding the specific hardware configuration of the information processing device 1, components can be omitted, replaced, and added as appropriate depending on the embodiment. For example, the control unit 11 may include multiple hardware processors. Hardware processors include microprocessors, FPGAs (Field-Programmable Gate Arrays), DSPs (Digital Signal Processors), and ECs. It may consist of a U (Electronic Control Unit), a GPU (Graphics Processing Unit), an ASIC (Application Specific Integrated Circuit), etc. At least one of the communication module 13, input device 14, and output device 15 may be omitted. The program 81 may be stored in an external storage device such as a NAS. An external storage device is also an example of a non-temporary storage medium. The information processing device 1 may consist of multiple computers. In this case, the hardware configuration of each computer may or may not be the same. The information processing device 1 may consist of a computer designed specifically for the services provided, as well as a general-purpose server device, a general-purpose PC (Personal Computer), a notebook PC, a terminal device, etc. The terminal device may include user terminals such as smartphones and tablet devices. The terminal device may also include control devices for robotic devices, in-vehicle devices for vehicles, etc.

[0073] [Software Configuration] Figure 9 schematically shows an example of the software configuration of the information processing device 1 according to this embodiment. The control unit 11 of the information processing device 1 executes instructions contained in the program 81 stored in the storage unit 12 using the CPU. As a result, the information processing device 1 operates as a computer equipped with a dialogue acquisition unit 111, a detection processing unit 112, a replacement processing unit 113, a labeling unit 114, and an output processing unit 115 as software modules. In other words, in this embodiment, each software module of the information processing device 1 is realized by the control unit 11 (CPU).

[0074] The dialogue acquisition unit 111 collects dialogue data 20 between artificial intelligence agent A1 and user U1. The system is configured to acquire the following: The detection processing unit 112 is configured to detect the portion 25 corresponding to privacy-related information from the acquired dialogue data 20. The replacement processing unit 113 is configured to replace the detected portion 25 target information 30 with alternative information 35. The labeling unit 114 is configured to assign a label 40 indicating the level of confidentiality corresponding to the target information 30 to the dialogue data (20, 29). The output processing unit 115 is configured to output the dialogue data 29 after the target information 30 has been replaced.

[0075] In this embodiment, an example is described in which each software module of the information processing device 1 is implemented by a general-purpose CPU. However, some or all of the above software modules may be implemented by one or more dedicated processors or chipsets. Each of the above modules may also be implemented as a hardware module. Regarding the software configuration of the information processing device 1, modules may be omitted, replaced, and added as appropriate, depending on the embodiment.

[0076] Figure 10 is a flowchart illustrating an example of a processing procedure for concealing dialogue data 20 by the information processing device 1 according to this embodiment. The following processing procedure is an example of an information processing method executed by a computer. However, the following processing procedure is merely an example, and each step may be modified as much as possible. Furthermore, depending on the embodiment, steps in the following processing procedure can be omitted, replaced, and added as appropriate.

[0077] (Step S101) In step S101, the control unit 11 operates as a dialogue acquisition unit 111 and acquires dialogue data 20 between the artificial intelligence agent A1 and the user U1. The method for acquiring the dialogue data 20 is not particularly limited and may be appropriately selected depending on the embodiment. Once the dialogue data 20 is acquired, the control unit 11 proceeds to the next step S102.

[0078] (Step S102-Step S103) In step S102, the control unit 11 operates as a detection processing unit 112 and detects the portion 25 corresponding to privacy-related information from the acquired dialogue data 20. The detection method can be arbitrarily selected. In one example, the control unit 11 may detect the portion 25 corresponding to privacy-related information using natural language processing N2 or a trained machine learning model M2.

[0079] The calculations for natural language processing N2 and the trained machine learning model M2 may be performed on any computer. In one example, the calculations for natural language processing N2 and the trained machine learning model M2 may be performed on the information processing device 1. In another example, the calculations for natural language processing N2 and the trained machine learning model M2 may be performed on a computer other than the information processing device 1. In this case, the control unit 11 may give instructions to the other computer to detect the portion 25 that corresponds to privacy-related information. In response, the control unit 11 may receive the detection results from the other computer. Detecting the portion 25 that corresponds to privacy-related information may include not only performing detection processing on the device itself, but also giving such detection instructions to the other computer and receiving the detection results from the other computer.

[0080] In step S103, the control unit 11 determines the branching point for processing based on the detection result in step S102. If no portion 25 (target information 30) corresponding to privacy-related information is detected, the control unit 11 terminates the processing procedure related to this example. On the other hand, if a portion 25 (target information 30) corresponding to privacy-related information is detected, the control unit 11 proceeds to the next step S104.

[0081] (Step S104) In step S104, the control unit 11 operates as a replacement processing unit 113, and the detected part Replace the target information 30 in section 25 with alternative information 35.

[0082] If the target information 30 can be kept confidential, the alternative information 35 may be composed of any kind. For example, the alternative information 35 may be information that maintains the content of the dialogue data 20 while keeping the target information 30 confidential. For example, the target information 30 may include wording 301. Wording 301 may constitute at least a part of the privacy-related information. The alternative information 35 may be composed of another wording 351 of the same part of speech as wording 301. For example, the target information 30 may include wording 301, and wording 301 may constitute at least a part of the privacy-related information. The alternative information 35 may be composed of another wording 353 obtained by conceptualizing or abstracting wording 301.

[0083] Furthermore, the replacement method may be arbitrarily selected. In one example, the control unit 11 may generate the alternative information 35 using a large-scale generation model M3. The calculation process of the large-scale generation model M3 may be executed on any computer. In one example, the calculation process of the large-scale generation model M3 may be executed on the information processing device 1. In another example, the calculation process of the large-scale generation model M3 may be executed on a computer other than the information processing device 1. In this case, the control unit 11 may give a generation instruction for the alternative information 35 to the other computer. Accordingly, the control unit 11 may receive the generation result of the alternative information 35 by the large-scale generation model M3 from the other computer. Generating the alternative information 35 using the large-scale generation model M3 may include not only executing the generation process on the device itself, but also giving such a generation instruction to another computer and receiving the generation result from the other computer. The control unit 11 may replace the target information 30 of the detected portion 25 with the generated alternative information 35. After replacing the target information 30 with the alternative information 35, the control unit 11 proceeds to the next step S105.

[0084] (Step S105) In step S105, the control unit 11 operates as a labeling unit 114 and assigns a label 40 to the dialogue data (20, 29) indicating the level of confidentiality corresponding to the target information 30. Once the label 40 is assigned, the control unit 11 proceeds to the next step S106. Note that the timing of the execution of the process in step S105 is not limited to this example. The process in step S105 may be executed at any time after step S102. In another example, the process in step S105 may be executed before step S103.

[0085] (Step S106) In step S106, the control unit 11 operates as an output processing unit 115 and outputs the dialogue data 29 after replacing the target information 30.

[0086] The output destination is not particularly limited and may be appropriately selected depending on the embodiment. The output destination may be, for example, RAM, storage unit 12, output device 15, storage medium 91, another computer (memory resources, output devices, etc. of another computer), external storage device, etc.

[0087] Furthermore, the output format is not particularly limited and may be appropriately selected depending on the embodiment. In one example, the control unit 11 may save the replaced dialogue data 29. The control unit 11 may also save the original dialogue data 20 along with the replaced dialogue data 29. In another example, the control unit 11 may output the dialogue data 29 after replacing the target information 30 to another artificial intelligence agent A2 other than artificial intelligence agent A1.

[0088] In another example, the control unit 11 may adjust the value of one or more computational parameters P1 of the machine learning model M1 by using the dialogue data 29, after the target information 30 has been replaced, as a training sample for machine learning of the machine learning model M1. The machine learning computation process (the process of adjusting the value of computational parameters P1) may be executed on any computer. In one example, machine learning The calculation process may be performed on the information processing device 1. In another example, the machine learning calculation process may be performed on a computer other than the information processing device 1. In this case, the control unit 11 may give instructions to the other computer to perform machine learning. Accordingly, the control unit 11 may receive the results of the machine learning calculation (i.e., the results of adjusting the values ​​of the calculation parameters P1) from the other computer. Adjusting the values ​​of one or more calculation parameters P1 may include performing the adjustment process on the device itself, as well as giving such instructions to another computer and receiving the adjustment results from the other computer. The control unit 11 may upload the adjusted values ​​of one or more calculation parameters P1 for federated learning.

[0089] In addition, for example, if a label 40 is assigned to the dialogue data (20, 29), the control unit 11 may control the output of the dialogue data (20, 29) according to the assigned label 40. If the sharing destination is granted permission, the control unit 11 may output the dialogue data 20 before the target information 30 is replaced to the sharing destination. If the sharing destination is not granted permission, the control unit 11 may output the dialogue data 29 after the target information 30 has been replaced to the sharing destination. If the sharing destination is not granted permission to access the replaced dialogue data 29 either, the control unit 11 may prohibit the output of both the pre-replacement dialogue data 20 and the post-replacement dialogue data 29 to the sharing destination. In other words, the control unit 11 may omit the output of the dialogue data (20, 29).

[0090] The processing in step S106 may be performed at any time after the dialogue data 29 has been obtained. The processing in step S106 does not have to be performed immediately after step S104 or step S105. Once the output of the dialogue data 29 is complete, the control unit 11 terminates the processing procedure related to this example of operation.

[0091] [Features] In this embodiment, the processing in steps S102 and S104 makes it possible to conceal the target information 30 that corresponds to privacy-related information. As a result, according to this embodiment, even if the dialogue data 20 is unstructured data, the confidentiality of the dialogue data 20 with the artificial intelligence agent A1 can be ensured.

[0092] [4. Variant] While embodiments of this disclosure have been described in detail above, the above description is merely illustrative in all respects. The processes and means described in this disclosure can be freely combined and implemented as long as no technical inconsistencies arise. Furthermore, various improvements or modifications may be made to the above embodiments as appropriate.

[0093] For example, in the processing procedure according to the above embodiment, the processing in step S105 may be omitted. If the processing in step S105 is omitted, the labeling unit 114 may be omitted from the software configuration of the information processing device 1.

[0094] [5. Supplement] The processes and means described herein can be freely combined and implemented, provided that no technical inconsistencies arise.

[0095] Furthermore, a process described as being performed by a single device may be divided and executed by multiple devices. Conversely, a process described as being performed by different devices may be executed by a single device. In a computer system, the hardware configuration used to implement each function can be flexibly changed.

[0096] This disclosure provides a computer program that implements the functions described in the above embodiments to a computer, and one or more processors in the computer read the program. This can also be achieved by execution. Such a computer program may be provided to the computer by a non-temporary computer-readable storage medium that can be connected to the computer's system bus, or it may be provided to the computer via a network. The non-temporary computer-readable storage medium may include, for example, any type of disk, read-only memory (ROM), random access memory (RAM), EPROM, EEPROM, magnetic card, flash memory, optical card, semiconductor drive, any type of medium suitable for storing electronic instructions, etc. Disks may include, for example, magnetic disks, optical disks, etc. Magnetic disks may include, for example, hard disk drives (HDDs), etc. Optical disks may include, for example, CD-ROMs, DVDs, Blu-ray discs, etc. Semiconductor drives may include, for example, solid-state drives, etc. [Explanation of Symbols]

[0097] 1…Information processing equipment, 11...Control unit, 12...Storage unit, 20...Dialogue data, 29...(After substitution) dialogue data, 25...part, 30...Target information, 35...Alternative information, A1…Artificial intelligence agent, U1…User< / xxx>

Claims

1. To acquire dialogue data between an artificial intelligence agent and a user. To detect the portion of the acquired dialogue data that corresponds to privacy-related information, Replacing the target information of the detected portion with alternative information, and Output the dialogue data after replacing the aforementioned target information. A control unit configured to perform the following actions: Information processing device.

2. The aforementioned alternative information is information that maintains the content of the dialogue data while concealing the aforementioned target information. The information processing apparatus according to claim 1.

3. The aforementioned information includes text, Replacing the aforementioned target information with the aforementioned alternative information includes converting the aforementioned wording contained in the aforementioned target information into another wording of the same part of speech. The information processing apparatus according to claim 2.

4. The aforementioned information includes text, Replacing the aforementioned target information with the aforementioned alternative information includes converting the aforementioned wording contained in the aforementioned target information into another wording that is a higher-level concept or abstraction. The information processing apparatus according to claim 2.

5. The control unit is further configured to assign a label to the dialogue data indicating a level of confidentiality corresponding to the target information. Outputting the dialogue data after replacing the target information is done according to the confidentiality level indicated by the assigned label, (i) if the sharing destination is allowed access, the (ii) outputting the dialogue data before replacing the target information to the shared destination, and (ii) if the shared destination is not permitted to access, outputting the dialogue data after replacing the target information to the shared destination. The information processing apparatus according to claim 1.

6. The detection of the portion corresponding to the aforementioned privacy-related information is performed by detecting the portion corresponding to the aforementioned privacy-related information using natural language processing or a trained machine learning model. The information processing apparatus according to claim 1.

7. Replacing the detected portion of the target information with alternative information is: Using a large-scale generative model, the aforementioned alternative information is generated, and Replacing the detected portion of the target information with the generated alternative information, Composed of, The information processing apparatus according to claim 1.

8. Outputting the dialogue data after replacing the target information includes outputting the dialogue data after replacing the target information to other artificial intelligence agents other than the aforementioned artificial intelligence agent. The information processing apparatus according to claim 1.

9. The artificial intelligence agent includes a machine learning model having one or more computational parameters. 、 Outputting the dialogue data after replacing the aforementioned target information is: By using the dialogue data after replacing the target information as a training sample for machine learning of the machine learning model, the values ​​of the one or more computational parameters of the machine learning model are adjusted, and Upload the adjusted values ​​of the one or more calculation parameters for associative learning. including, The information processing apparatus according to claim 1.

10. A method of information processing performed by a computer, To acquire dialogue data between an artificial intelligence agent and a user. To detect the portion of the acquired dialogue data that corresponds to privacy-related information, Replacing the target information of the detected portion with alternative information, and Output the dialogue data after replacing the aforementioned target information. including, Information processing methods.

11. The aforementioned alternative information is information that maintains the content of the dialogue data while concealing the aforementioned target information. The information processing method according to claim 10.

12. The aforementioned information includes text, Replacing the aforementioned target information with the aforementioned alternative information includes converting the aforementioned wording contained in the aforementioned target information into another wording of the same part of speech. The information processing method according to claim 11.

13. The aforementioned information includes text, Replacing the aforementioned target information with the aforementioned alternative information includes converting the aforementioned wording contained in the aforementioned target information into another wording that is a higher-level concept or abstraction. The information processing method according to claim 11.

14. The further includes assigning a label to the dialogue data indicating a level of confidentiality corresponding to the target information, Outputting the dialogue data after replacing the target information is done according to the confidentiality level indicated by the assigned label, (i) if the sharing destination is allowed access, the (ii) outputting the dialogue data before replacing the target information to the shared destination, and (ii) if the shared destination is not permitted to access, outputting the dialogue data after replacing the target information to the shared destination. The information processing method according to claim 10.

15. Outputting the dialogue data after replacing the target information includes outputting the dialogue data after replacing the target information to other artificial intelligence agents other than the aforementioned artificial intelligence agent. The information processing method according to claim 10.

16. The artificial intelligence agent includes a machine learning model having one or more computational parameters, Outputting the dialogue data after replacing the aforementioned target information is: By using the dialogue data after replacing the target information as a training sample for machine learning of the machine learning model, the values ​​of the one or more computational parameters of the machine learning model are adjusted, and Upload the adjusted values ​​of the one or more calculation parameters for associative learning. including, The information processing method according to claim 10.

17. A program that causes a computer to execute an information processing method, The aforementioned information processing method is: To acquire dialogue data between an artificial intelligence agent and a user. To detect the portion of the acquired dialogue data that corresponds to privacy-related information, Replacing the target information of the detected portion with alternative information, and Output the dialogue data after replacing the aforementioned target information. including, program.

18. The aforementioned alternative information is information that maintains the content of the dialogue data while concealing the aforementioned target information. The program according to claim 17.

19. Outputting the dialogue data after replacing the target information includes outputting the dialogue data after replacing the target information to other artificial intelligence agents other than the aforementioned artificial intelligence agent. The program according to claim 17.

20. The artificial intelligence agent includes a machine learning model having one or more computational parameters, Outputting the dialogue data after replacing the aforementioned target information is: By using the dialogue data after replacing the target information as a training sample for machine learning of the machine learning model, the values ​​of the one or more computational parameters of the machine learning model are adjusted, and Upload the adjusted values ​​of the one or more calculation parameters for associative learning. including, The program according to claim 17.

Citation Information

Patent Citations

  • Privacy protection type data provision system

    JP2014229039A

  • Computer-implemented method, computer program and computer system (resource-limited federated learning using dynamic masking)

    JP2023157843A