Information processing device and control program

JP7844690B1Active Publication Date: 2026-04-13SOFTBANK CORPORATION
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2026-04-13

Smart Images

  • Figure 0007844690000001_ABST
    Figure 0007844690000001_ABST
Patent Text Reader

Abstract

To facilitate the sending and receiving of messages between more suitable LLMs. [Solution] The information processing device (1) operates as a UE connected to a core network including UPF and is an information processing device (1) that sends and receives messages between itself and a first LLM that does not allow the input of confidential information and a second LLM that does allow the input of confidential information, and comprises an acquisition unit (11) that acquires a first message input from a user, a communication control unit (13) that transmits a first message that does not contain confidential information to the first LLM via communication over the Internet and a first message that contains confidential information to the second LLM via communication not over the Internet, and comprises a communication control unit (13) that receives a second message output by each LLM and an output control unit (14) that controls the output of the second message.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One aspect of the present invention relates to an information processing apparatus and a control program.

Background Art

[0002] In recent years, prior to transmitting a message to a generally public LLM (Large Language Models), a mechanism for monitoring whether the message contains confidential information from a security perspective is known. With this mechanism, it is possible to prevent the transmission of messages containing confidential information to a generally public LLM. Non-Patent Document 1 discloses a service that can prevent the input of prohibited words and sensitive information to an AI model using an LLM.

Prior Art Documents

Non-Patent Documents

[0003]

Non-Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] For example, it can be said that a message containing confidential information should be sent to an LLM that allows the input of messages containing confidential information, rather than to a generally public LLM. Broadly speaking, it is desirable that the message be sent to an LLM according to the content of the message.

[0005] One aspect of the present invention has been made in view of the above problems, and an object thereof is to facilitate the transmission and reception of messages with a more suitable LLM. [Means for solving the problem]

[0006] To solve the above problems, an information processing device according to one aspect of the present invention operates as a UE (User Equipment) connected to a core network including a UPF (User Plane Function) and is an information processing device that sends and receives messages between a first LLM (Large Language Models) that does not allow input of confidential information and a second LLM that does allow input of confidential information, comprising: an acquisition unit that acquires a first message input from a user; a communication control unit that transmits the first message without confidential information to the first LLM via the UPF and over the Internet, and transmits the first message containing confidential information to the second LLM via the UPF and not over the Internet, comprising: a communication control unit that receives a second message output by each LLM in response to the input of the first message; and an output control unit that controls the output of the second message.

[0007] To solve the above problems, an information processing device according to one aspect of the present invention operates as a UE (User Equipment) connected to a core network including a UPF (User Plane Function) and performs message transmission and reception between a plurality of LLMs (Large Language Models), comprising: an acquisition unit that acquires a first message input from a user; a determination unit that, by referring to the first message, determines which LLM to send the first message to; a communication control unit that transmits the first message to the LLM determined by the determination unit via communication through the UPF, a communication control unit that receives a second message output by the LLM in response to the first message via communication through the UPF, and an output control unit that controls the output of the second message.

[0008] Each aspect of the present invention may be implemented by a computer, in which case a control program for the information processing device that enables the computer to implement the information processing device by operating the computer as each part (software element) of the information processing device, and a computer-readable recording medium on which the program is recorded, also fall within the scope of the present invention. [Effects of the Invention]

[0009] According to one aspect of the present invention, it is possible to facilitate the sending and receiving of messages with a more suitable LLM. [Brief explanation of the drawing]

[0010] [Figure 1] This is an example diagram showing the configuration of a 5G communication system, including the core network. [Figure 2] This is an example of a block diagram showing the functional configuration of a terminal device. [Figure 3] This is an example diagram showing the configuration of terminal equipment, etc., related to Configuration Example 1 for accessing LLM. [Figure 4] This is an example of a diagram used to supplement the configuration of the terminal device shown in Figure 3. [Figure 5] This is an example flowchart for determining whether a terminal device can communicate via an additional PDU session. [Figure 6] This is an example diagram showing the configuration of terminal equipment, etc., related to Configuration Example 2 for accessing LLM. [Figure 7] This is an example diagram showing the configuration of terminal equipment, etc., related to Configuration Example 3 for accessing LLM. [Figure 8] This is an example of a diagram that supplements the configuration of the terminal device shown in Figure 7. [Figure 9] This is an example of a diagram showing the display screen of a shared application on a terminal device. [Figure 10] This is an example diagram illustrating the process of sending the conversation history to the LLM after switching. [Figure 11]It is an example of a flowchart showing the flow of a process of transmitting a first message or the like to any LLM. [Figure 12] It is an example of a diagram showing the configuration of a terminal device or the like according to Configuration Example 4 regarding access to an LLM. [Figure 13] It is an example of a diagram for explaining the learning process of an agent. [Figure 14] It is an example of a diagram for explaining the learning process of a private LLM. [Figure 15] It is an example of a diagram for explaining the process of federated learning.

Embodiments for Carrying Out the Invention

[0011] Hereinafter, an embodiment of the present invention will be described in detail.

[0012] <Configuration Example of Communication System> FIG. 1 is an example of a diagram showing a configuration including a core network of a 5G communication system. The architecture of the core network is defined by 3GPP (3rd Generation Partnership Project).

[0013] Normally, a large number of (R) ANs ((Radio) Access Network, gNB, base station devices) are connected to the core network, and a large number of UEs (User Equipment, terminal devices, information processing devices) are wirelessly connected to each RAN. Note that the "core network" referred to in the present disclosure may also include UEs and RANs.

[0014] The core network includes various nodes such as UPF (User Plane Function), AMF (Access and Mobility Management Function), SMF (Session Management Function), PCF (Policy Control Function), AF (Application Function), AUSF (Authentication Server Function), and UDM (User Data Management). Each of these various nodes is also referred to as an NF (Network Function). Also, for example, UPF may be configured to include a controller (RIC: RAN Intelligent Controller) to control the RAN in this way.

[0015] Although the node configuration shown in FIG. 1 itself conforms to the existing core network, the configuration and processing of some nodes including the UE and DN (Data Network) are different from the existing core network. The above processing will be described later with reference to FIG. 3 and the like.

[0016] Also, the interfaces used to connect the nodes to each other are standardized. For example, the interface connecting the UE and the AMF is defined as N1, and the interface connecting the RAN and the AMF is defined as N2. In the present disclosure, the section connected by the N1 interface is also referred to as the N1 section, and the sections connected by other interfaces may be similarly referred to.

[0017] For example, the N3 section means the interface section between the RAN and the UPF, and the N6 section means the interface section between the UPF and the DN.

[0018] Furthermore, Figure 1 shows that the N9 section may be configured in which the UPF is realized by a first UPF and a second UPF that are connected to each other. The N14 section of the AMF is explained similarly. Also, "NR-Uu" refers to the interface section between the UE and the RAN.

[0019] Furthermore, the DN is connected to an Svr, which functions as a server for the UE. Here, the Svr can also be considered a device owned by the DN. From another perspective, any description in the following explanation referring to the DN as the processing entity or processing target can be rephrased as referring to the Svr as the processing entity or processing target.

[0020] The UE can connect to the DN and the internet via the UPF. The DN also has Large Language Models (LLMs) that allow input of information including confidential information of companies, etc. Confidential information here includes trade secrets and financial information of companies, as well as personal information of employees and customers. In this disclosure, LLM may also refer to conversational artificial intelligence that uses a specified LLM. An example of conversational artificial intelligence is OpenAI's Chat GPT®.

[0021] Hereafter, the aforementioned LLM that allows input of information including confidential information will also be referred to as a Private LLM. A Private LLM is, for example, an LLM used by each company that has a contract with a telecommunications carrier. It is also permissible for the output from a Private LLM to include confidential information.

[0022] In contrast, a publicly accessible LLM that can be used by connecting to the Internet from a UE is also called a Public LLM. Input of information containing confidential information is not permitted for a Public LLM. In the description of this disclosure, devices such as web servers that have a Public LLM may also be simply referred to as a Public LLM, and DNs that have a Private LLM may also be simply referred to as a Private LLM. A Public LLM is an example of the first LLM in this disclosure, and a Private LLM is an example of the second LLM in this disclosure.

[0023] <Example of terminal device configuration> Figure 2 is an example block diagram showing the functional configuration of terminal device 1, which operates as the UE in Figure 1 and connects to a core network including the UPF (User Plane Function). Terminal device 1 is a device implemented as a smartphone, tablet, or personal computer, and is a device that sends and receives messages between itself and multiple LLMs via one or more applications it runs on. In other words, the application is an interface for terminal device 1 to access the LLMs.

[0024] As shown in Figure 2, the terminal device 1 comprises a control unit 10, a storage unit 16, a communication unit 17, a display unit 18, and an input unit 19.

[0025] The control unit 10 is a control device such as a CPU that oversees the entire terminal device 1, and also operates as an acquisition unit 11, a determination unit 12, a communication control unit 13, and an output control unit (display control unit) 14.

[0026] The acquisition unit 11 acquires the first message entered by the user into the terminal device 1. In most cases, the first message is entered into the console, which is a text input box in the application. The first message is a question, inquiry, or command to the LLM.

[0027] The determination unit 12 determines whether or not the first message contains confidential information. If the determination unit 12 determines that the first message does not contain confidential information, it determines that the destination of the first message is a public LLM. If the determination unit 12 determines that the first message contains confidential information, it determines that the destination of the first message is a private LLM. The determination unit 12 also performs various other determinations, which will be described later.

[0028] The communication control unit 13 controls the communication processing performed by the communication unit 17. For example, the communication control unit 13 sends a first message, which does not contain confidential information, to a public LLM via UPF within the core network and over the internet, and sends a first message, which contains confidential information, to a second LLM via UPF and not over the internet. The communication control unit 13 also receives the second message output by each LLM in response to the input of the first message. The second message is a response from the LLM, etc. Each LLM may use RAG (Retrieval-Augmented Generation) to retrieve external information when generating the second message. In this disclosure, if there is no particular distinction between the first message and the second message, one or both may simply be referred to as a message.

[0029] The output control unit 14 controls the output of the second message output by each LLM. For example, the output control unit 14 causes the display unit 18 to display a screen containing the second message in the application. The disclosure also includes the possibility that the output control unit 14 causes the second message to be output as audio from a speaker (not shown) of the terminal device 1.

[0030] The memory unit 16 is a storage device such as a memory that stores various types of information, at least temporarily. For example, the memory unit 16 stores data related to the application, a conversation history which is a history of messages sent and received between the terminal device 1 and each LLM, and a parameter set that defines the learning model.

[0031] The communication unit 17 is an interface that performs communication processing with other devices such as Svr based on the control by the communication control unit 13.

[0032] The display unit 18 is a display that displays a screen based on the control by the output control unit 14. For example, the display unit 18 displays the screen of an application.

[0033] The input unit 19 is a member realized as a button, keyboard, mouse, etc., and receives a user's input operation to the terminal device 1. Also, the display unit 18 and the input unit 19 may be realized as an integrated touch panel.

[0034] The configuration example of the terminal device 1 has been described above. In addition, each part included in the terminal device 1 has a function of executing the processing described later.

[0035] <Configuration Example 1 Regarding Access to LLM> Subsequently, the specific configurations according to the present disclosure in some nodes included in the core network shown in FIG. 1 will be described with examples.

[0036] FIG. 3 is an example of a diagram showing the configuration of the terminal device 1 and the like according to this example. The local DN in FIG. 3 corresponds to the DN and Svr in FIG. 1. The same applies to FIGS. 4 and the like described later.

[0037] As shown in FIG. 3, the terminal device 1 according to this example is installed with a public LLM app, which is an application serving as an interface for using a public LLM on the Internet, and a private LLM app, which is an application serving as an interface for using a private LLM on the local DN. <9000167> The user enters a first message to one of the LLMs in the console displayed while each application is running. Specifically, if none of the first messages to be entered contain confidential information, the user should use the public LLM app; if any of the first messages to be entered contain confidential information, the user should use the private LLM app. Furthermore, it is desirable that first messages such as "How do I take paid leave?", in which the LLM's response may contain internal company information, be treated the same as first messages that contain confidential information.

[0039] When the Public LLM App is used, terminal device 1 sends and receives messages and other data to and from the Public LLM via a standard data PDU session (Protocol Data Unit Session) established between it and the UPF. Here, a PDU session is a communication channel established between two or more nodes, and is a logical communication channel for sending and receiving structured PDUs (packets). Communication between the UPF and the Public LLM takes place via the Internet.

[0040] In contrast, when the Private LLM App is used, terminal device 1 performs the process of establishing an additional PDU session with UPF, and sends and receives messages, etc., with the Private LLM via the established additional PDU session. Communication between UPF and the Private LLM is conducted without using the Internet and is more secure.

[0041] A regular data PDU session is an example of the first PDU session in this disclosure, and an additional PDU session is an example of the second PDU session in this disclosure.

[0042] Therefore, in a broad sense, the communication control unit 13 sends and receives messages with the first LLM via a first PDU session established when communicating with the first LLM, and sends and receives messages with the second LLM via a second PDU session established when communicating with the second LLM.

[0043] Furthermore, the aforementioned network that does not use the Internet may be an LADN (Local Area Data Network), which is a network that can only be used when terminal device 1 is located in a specific area. In other words, the second PDU session may be a different PDU session from the first PDU session, and may be a PDU session established for the LADN.

[0044] Only applications permitted via the Work Profile can communicate with the local DN through the LADN. Here, a Work Profile is a profile set by the company for each employee's terminal device 1, which separates the personal application space from the business application space and sets the applications that employees are allowed to use, the operations they are allowed to perform, and the access rights. In the configuration shown in Figure 3, the Work Profile is configured to allow the private LLM app to communicate with the local DN via the LADN.

[0045] In another scenario, if a company manages all rights to terminal device 1, in other words, if terminal device 1 is a company-managed terminal, it is possible to achieve communication with the local DN via LADN without partitioning the application space using Work Profile.

[0046] Figure 4 is an example of a diagram that supplements the configuration of terminal device 1 in Figure 3. In Figure 4, OSAppId is a category of network slice, which is a set of logical networks separated from a single physical network. For example, "Normal" indicates a standard network slice category, while "Company" indicates a network slice category suitable for use in a corporate setting.

[0047] The applications that perform communication processing installed on terminal device 1 and their OSAppIds are linked using MDM (Mobile Device Management), a function that allows companies to centrally manage and monitor the status of terminal devices 1 used within their own organization. For example, the private LLM app is linked to the "Company" OSAppId. Furthermore, the aforementioned Work Profile is responsible for granting the private LLM app permission to use the "Company" OSAppId. The linking of applications to OSAppIds can be flexibly done using application programming, and it is also possible to link a single application to multiple OSAppIds in a one-to-many relationship.

[0048] Furthermore, the route selection descriptor is metadata used to specify the network or its requirements. The route selection descriptor specifies the PDU session used for communication. The OSAppId and the route selection descriptor are linked using URSP (User Equipment Route Selection Policy), a function for mapping applications to the appropriate PDU session. As mentioned above, since the PDU session is specified by the route selection descriptor, it can be considered that URSP links the OSAppId and the PDU session.

[0049] Thus, additional PDU sessions can be considered communication channels dedicated to specific users, such as employees of a particular company, and to specific applications, thus offering a high degree of confidentiality.

[0050] Normally, the URSP policy is set to the application on terminal device 1 immediately if terminal device 1 is within 5G coverage. If terminal device 1 is not within 5G coverage, the policy is set to the application on terminal device 1 the next time terminal device 1 is within 5G coverage.

[0051] Thus, in this example configuration, sending and receiving messages with the private LLM can be done via the private LLM app only if the private LLM app is configured to communicate with the local DN via an additional PDU session using MDM and URSP, and only if terminal device 1 is located in a specific area such as within the company network.

[0052] Figure 5 is an example of a flowchart for determining whether terminal device 1 can communicate via an additional PDU session. The process shown in the flowchart of Figure 5 is initiated, for example, when the Private LLM App is launched.

[0053] In step S101, the determination unit 12 of the terminal device 1 determines whether or not the terminal device 1 is located within the 5G network. If the determination unit 12 determines that the terminal device 1 is located within the 5G network (S101: YES), the process in S102 is executed. If it determines that the terminal device 1 is not located within the 5G network (S101: NO), then in step S106, the determination unit 12 determines that communication via the additional PDU session is not possible, and the process shown in the flowchart of Figure 5 is terminated.

[0054] In S102, the determination unit 12 determines whether the additional PDU session has been established. If the determination unit 12 determines that the additional PDU session has been established (S102: YES), then subsequently in S105, it determines that communication via the additional PDU session can be performed, and the process shown in the flowchart of FIG. 5 ends. On the other hand, if the determination unit 12 determines that the additional PDU session has not been established (S102: NO), then subsequently the process of S103 is executed.

[0055] In S103, the communication control unit 13 transmits a request to establish an additional PDU session for communicating with the local DN.

[0056] In S104, the determination unit 12 determines whether the request has been accepted. If the determination unit 12 determines that the request has been accepted (S104: YES), then subsequently in S105, it determines that communication via the additional PDU session can be performed, and the process shown in the flowchart of FIG. 5 ends. If the determination unit 12 determines that the request has not been accepted (S104: NO), then subsequently in S106, it determines that communication via the additional PDU session cannot be performed, and the process shown in the flowchart of FIG. 5 ends.

[0057] When communication via the additional PDU session cannot be performed, for the terminal device 1, the transmission and reception of messages using the private LLM - specific App are restricted, and only the transmission and reception of messages using the public LLM - specific App are permitted. This is the same in Configuration Example 3 described later.

[0058] According to the configuration of this example, the user can easily perform message transmission and reception with a more suitable LLM by operating a single terminal device 1.

[0059] <Configuration Example 2 Regarding Access to LLM> Next, a second configuration example corresponding to a modification of Configuration Example 1 (regarding access to the LLM) will be described. For convenience of explanation, members having the same functions as those described in the above example are denoted by the same reference numerals, and redundant explanations will not be repeated. The same applies to each of the following examples.

[0060] FIG. 6 is an example of a diagram showing the configuration of the terminal device 1 and the like according to this example. The I-UPF in FIG. 6 is a type of UPF, and has a relay function for relaying packet traffic between other UPFs, and a ULCL (Uplink Classifier) function for connecting to a plurality of DNs simultaneously via a single PDU session by separating packet traffic in the UL (Uplink) direction based on a destination IP address or the like.

[0061] By using the ULCL of this I-UPF, it is possible to access both the public LLM and the private LLM from the terminal device 1 via each application and the PDU session for normal data without establishing an additional PDU session.

[0062] However, in the configuration of this example, since settings for permitting or restricting communication with the local DN to the application and restrictions on the position when the terminal device 1 accesses the local DN are not performed, the security of Configuration Example 1 is higher than this example.

[0063] <Configuration Example 3 Regarding Access to the LLM> Next, a third configuration example will be described. FIG. 7 is an example of a diagram showing the configuration of the terminal device 1 and the like according to this example. Matters regarding an additional PDU session and the like are the same as those in Configuration Example 1, so redundant explanations will be omitted.

[0064] As shown in Figure 7, the terminal device 1 in this example has a shared app installed, which is a single application for accessing both public LLMs and private LLMs. The shared app includes an agent that has a program for determining whether or not an input message contains confidential information. Furthermore, the agent in the following description may be read as the determination unit 12, as the control unit 10 executes the aforementioned program when it operates as the determination unit 12. However, in this disclosure, the agent may include a learning model used for determination. In addition, the local DN may learn this learning model at any or predetermined timing, and the control unit 10 may obtain and use the learned learning model data from the local DN for updating.

[0065] The aforementioned agent performs analysis using, for example, rule-based, DNN (Deep Neural Network)-based, or LLM-based processing to determine whether the input first message contains confidential information. Here, rule-based processing means, for example, determining that a message contains confidential information if a specific word to be detected is included in the message.

[0066] Recent literature describing DNN-based or LLM-based processing includes, for example, the following (a) to (c).

[0067] (a)Yan Lin et al., 2020. Sensitive Information Detection Based on Convolution Neural Network and Bi-Directional LSTM. https: / / ieeexplore.ieee.org / abstract / document / 9343041 (b) Kishinami et al., 2024. Data Augmentation Using Generative AI in Confidential Information Detection, Proceedings of the 30th Annual Meeting of the Association for Natural Language Processing (March 2024). http: / / www.anlp.jp / proceedings / annual_meeting / 2024 / pdf_dir / P10-13.pdf (c)Wen et al ., 2024. Large Language Models for Automatic Detection of Sensitive Topics. https:arxiv.org / abs / 2409.00940 Furthermore, when the agent performs DNN-based or LLM-based processing, it uses a learning model that takes a first message as input and outputs a determination result indicating whether or not the first message contains confidential information, and makes a determination based on the output of the learning model.

[0068] Figure 8 is an example of a diagram that supplements the configuration of terminal device 1 in Figure 7. As shown in Figure 8, the shared app and the OSAppIds of "Normal" and "Speedy" are linked in a one-to-many relationship by the OS, such as Android®. Here, "Speedy" indicates a network slice category different from the network slices normally used, such as one that requires low-latency communication. When the shared app communicates with a public LLM, the "Normal" OSAppId and the normal data PDU session are used, and when the shared app communicates with a private LLM, the "Speedy" OSAppId and the additional PDU session are used. Furthermore, the shared app controls communication in multiple PDU sessions from this single application.

[0069] In this example configuration, the LLM that terminal device 1 uses to send and receive messages may switch after each message is sent or received. Here, the sending and receiving of messages between terminal device 1 and the LLM can be considered as a conversation between the user and the LLM.

[0070] Figure 9 is an example of a display screen for the shared app on terminal device 1. Figure 9, specifically left 31, is an example of a conversation screen between the user and each LLM, and right 41 is an example of a side menu screen containing a list of so-called talk rooms corresponding to each conversation screen. When the user selects button 33 on the conversation screen, the side menu screen is displayed. Furthermore, by selecting a talk room name such as "Suggest travel destinations" on the side menu screen, the conversation screen corresponding to that talk room name is displayed, allowing the user to resume conversation with each LLM. The input box 43 on the side menu screen is an object for searching talk rooms.

[0071] In the conversation screen shown in Figure 31 on the left, the second message output by the public LLM and the second message output by the private LLM in response to the first message entered by the user into the console 34 are indicated by different icons 35a and 35b and different background colors. Icon 35a indicates that the text on the right is the second message output by the public LLM, and icon 35b indicates that the text on the right is the second message output by the private LLM. For example, the public LLM responds to the first message, "Please introduce yourself." Button 35 is for inputting the first message by voice.

[0072] In the side menu screen shown in Figure 41 on the right, icons 44a to 44c displayed to the left of the talk room name clearly indicate whether a talk room involved only conversations with public LLMs, only conversations with private LLMs, or conversations with both types of LLMs. Icon 44a corresponds to a talk room involving only public LLMs, icon 44b corresponds to a talk room involving only private LLMs, and icon 44c corresponds to a talk room involving both types of LLMs. For example, icon 44c is associated with the conversation screen in Figure 31 on the left.

[0073] Thus, the output control unit 14 may display the second message on the screen in different display modes for each LLM that has output the second message on an application such as a shared app.

[0074] Furthermore, when the LLM that the terminal device 1 is targeting for sending and receiving messages switches, if there is a history of messages that have not yet been sent to the switched LLM, i.e., a conversation history, the terminal device 1 may perform a process to send that conversation history to the switched LLM. This is to improve the accuracy of the content of the second message by transferring the conversation history to the switched LLM.

[0075] Figure 10 is an example diagram illustrating the process of sending conversation history to the LLM after the switch. Figure 51 on the left of Figure 10 shows the process when the LLM that sends and receives messages switches from a public LLM to a private LLM. Even if the conversation history with the public LLM is entered into the private LLM, its confidentiality is not compromised. Therefore, when switching from a public LLM to a private LLM, some or all of the conversation history with the public LLM is sent to the private LLM.

[0076] In contrast, Figure 56 on the right shows the process when the LLM that sends and receives messages switches from a private LLM to a public LLM. If the conversation history with the private LLM is entered into the public LLM, there is a risk that its confidentiality will be compromised. Therefore, when switching from a private LLM to a public LLM, the conversation history with the private LLM is either not sent to the public LLM as shown in Figure 56 on the right, or it is converted so that the message does not contain confidential information before being sent to the public LLM.

[0077] In addition, in the configuration examples 1 and 2 described above, the app for the public LLM and the app for the private LLM may cooperate to send some or all of the conversation history with the public LLM to the private LLM.

[0078] The following provides further details regarding the conversion process used to remove confidential information. This conversion process is described as being performed by the local DN at any time before the conversation history with the private LLM is sent to the public LLM, but it may also be performed by the control unit 10 of the terminal device 1. Here, the local DN or the control unit 10 may perform the conversion process using a conversion model stored in its own device, which takes a message as input and outputs a message that has been converted or maintained so as not to contain confidential information. Here, the conversion model may be considered a type of learning model.

[0079] As a first example of the transformation process, the local DN abstracts some words in the message that may be related to sensitive information. For example, the local DN transforms the message "Hi, my name is David and my number is 212 555 1234" into "Hi, my name is <person>and my number is<PHONE_NUMBER> This is converted to the message " and sent to terminal device 1. In this example, the name "David" is " <person>It is abstracted into the attribute ", and the phone number "212 555 1234" is "<PHONE_NUMBER> It is abstracted into the attribute "

[0080] Recent literature related to the first example of the conversion process includes, for example, (a) and (b) below.

[0081] (a)Microsoft Presidio. https: / / microsoft.github.io / presidio / (b)Zhengliang Liu et al., 2023. DeID-GPT: Zero-shot Medical Text De-Identification by GPT-4. https: / / arxiv.org / abs / 2303.11032 As a second example of the conversion process, the local DN converts the entire message while preserving its main meaning, removing any confidential information. For example, the local DN converts the message "We got here on a Wednesday night and it was packed!" to "We got a friend and it was good." and sends it to terminal device 1. In this second example of the conversion process, it is impossible for a third party to determine that the message ever contained confidential information, which offers the advantage of higher security.

[0082] Recent literature related to a second example of the conversion process includes, for example, (a) below.

[0083] (a)Benjamin Weggenmann et al., 2022. DP-VAE: Human-Readable Text Anonymization for Online Reviews with Differentially Private Variational Autoencoders. https: / / dl.acm.org / doi / 10.1145 / 3485447.3512232 Furthermore, the conversion process can be applied not only to the first message input by the user, but also to the second message output from the private LLM. Normally, when terminal device 1 receives both an unconverted second message and a converted second message, it displays only the former second message.

[0084] Furthermore, even in this example configuration, where a single application accesses both public and private LLMs, the LLMs that send and receive messages may be specified by the user.

[0085] Figure 11 is an example flowchart showing the process of sending the first message, etc., to one of the LLMs. The process shown in the flowchart of Figure 11 starts, for example, when the first message is input to terminal device 1.

[0086] In S201, the determination unit 12 (agent) determines whether a public LLM has been designated by the user as the LLM to be used for sending and receiving messages. This designation may be made by the user through prior settings for the shared app. If the determination unit 12 determines that a public LLM has been designated (S201:YES), the process in S202 is executed next. If it determines that a private LLM has been designated (S201:NO), the process in S203 is executed next.

[0087] In S202, the determination unit 12 determines whether or not the input first message contains confidential information. If the determination unit 12 determines that the first message contains confidential information (S202: YES), the process in S203 is executed next. If it determines that it does not contain confidential information (S202: NO), the process in S204 is executed next. The reason for performing the process in S201 in addition to the determination in S202 is that the determination accuracy in S202 is not necessarily 100%, and it is acceptable for messages that do not contain confidential information to be input to the private LLM. Therefore, this ensures that the user can specify that the target for sending and receiving messages is the private LLM. However, the disclosure also includes a mode in which the process in S201 is not performed.

[0088] In S203, the determination unit 12 determines that the destination of the first message is the private LLM, and the communication control unit 13 sends the first message and all conversation history that has not yet been sent to the private LLM to the private LLM. Although not necessarily limited to this, the conversation history usually refers to the conversation history corresponding to the talk room in which the conversation with the LLM is currently taking place. After the processing in S203, the process shown in the flowchart of Figure 11 is completed.

[0089] In S204, the determination unit 12 determines whether or not the conversation history includes a conversation history with a private LLM. If the determination unit 12 determines that the conversation history includes a conversation history with a private LLM (S204: YES), the process in S205 is executed next. If it determines that it does not include a conversation history with a private LLM (S204: NO), the process in S207 is executed next.

[0090] In S205, the control unit 10 performs the aforementioned conversion process to ensure that the first message does not contain confidential information. Alternatively, the control unit 10 may acquire the first message, which has been converted by the local DN, in advance and store it in the storage unit 16 for use in subsequent processing.

[0091] In S206, the communication control unit 13 transmits to the public LLM all conversation histories that have not yet been transmitted to the public LLM, including the conversation history between the first message and the private LLM that has undergone conversion processing. After the processing of S206, the processing shown in the flowchart of FIG. 11 ends.

[0092] In S207, the communication control unit 13 transmits to the public LLM the first message and all conversation histories that have not yet been transmitted to the public LLM. After the processing of S207, the processing shown in the flowchart of FIG. 11 ends.

[0093] Note that in the processes corresponding to S205 and S206, the conversation history with the private LLM may not be transmitted to the public LLM without performing the conversion process.

[0094] As can be seen from the above description, when the LLM for which the communication control unit 13 performs message transmission and reception switches from the first LLM to the second LLM, the communication control unit 13 may transmit at least a part of the message history transmitted and received with the first LLM to the second LLM. Also, when the LLM for which the communication control unit 13 performs message transmission and reception switches from the second LLM to the first LLM, the communication control unit 13 may (1) not transmit the message history transmitted and received with the second LLM to the first LLM, or (2) transmit the message history that has been converted so as not to include confidential information to the first LLM.

[0095] According to the configuration of this example, the LLM for which the terminal device 1 performs message transmission and reception is automatically determined by the agent. Thereby, it is possible to easily perform message transmission and reception with a more suitable LLM.

[0096] <Configuration Example 4 Regarding Access to LLM> Next, a fourth configuration example corresponding to a modification of Configuration Example 3 will be described. FIG. 12 is an example of a diagram showing the configuration of the terminal device 1 and the like according to this example. As shown in FIG. 12, the configuration using the I-UPF and the like described above in Configuration Example 2 is also applicable to a configuration that accesses both the public LLM and the private LLM through a single application.

[0097] Thus, it is possible to access both the public LLM and the private LLM from the terminal device 1 through a single application without establishing an additional PDU session. However, in terms of security, Configuration Example 3 is superior to this example because additional authentication for the additional PDU session can be provided.

[0098] <Configuration Example 5 Regarding Access to LLM> In the above-described Configuration Examples 1 to 4, particularly in Configuration Examples 3 and 4, the number of LLMs accessible from the terminal device 1 is not limited to two, and may be, for example, three or more.

[0099] That is, the terminal device 1 may transmit and receive messages to and from any plurality of LLMs. Further, the determination unit 12 may be configured to determine, by referring to the first message, to which of the LLMs the first message is to be transmitted. Here, the determination unit 12 may analyze the content of the first message by rule-based, DNN-based or LLM-based processing, and determine the transmission destination of the first message according to the field in which each LLM excels. In the configuration of this example, the communication control unit 13 transmits the first message to the LLM determined by the determination unit 12 by communication via the UPF, and receives the second message output by the LLM for the first message by communication via the UPF.

[0100] Note that in the configuration of this example, it is not essential that each of the public LLM and the private LLM is included in one or more of the plurality of LLMs. For example, all of the plurality of LLMs may be public LLMs.

[0101] <Example of agent training> Next, we will explain the process by which the local DN trains the learning model used by the agent described in Configuration Examples 3 and 4, which is used to determine whether or not a message contains confidential information.

[0102] Figure 13 is an example of a diagram illustrating the learning process of a learning model. In Figure 13, Data 61 represents training data used in the learning model's training process, consisting of multiple first messages labeled to indicate whether or not they contain confidential information. The local DN performs the learning model's training process using supervised learning, where the training data consists of pairs of first messages and labels indicating whether or not the first messages contain confidential information.

[0103] Furthermore, as shown in Figure 13, the training data may be obtained from messages entered by the user into each application in the configuration example 1 or 2 described above. Specifically, the first message entered into the public LLM app may be labeled to indicate that it does not contain confidential information, and the first message entered into the private LLM app may be labeled to indicate that it contains confidential information, and these may be used as training data.

[0104] If the agent determines whether the first message contains sensitive information through rule-based processing, the local DN may extract frequently occurring words and expressions within the first message that are labeled as containing sensitive information and set them as targets for detection.

[0105] When an agent determines whether a first message contains confidential information using DNN-based or LLM-based processing, the local DN takes the first message as input and trains a learning model that outputs a determination result indicating whether the first message contains confidential information, using the first message and information indicating whether the first message contains confidential information as training data.

[0106] Furthermore, the aforementioned transformation model, which transforms messages so that they do not contain confidential information, may also be trained by the local DN using the training data shown in data 61 of Figure 13, similar to the learning model. Note that if the specifications of terminal device 1 are above a certain level, for example, if terminal device 1 is a personal computer, the control unit 10 of terminal device 1 may be configured to train both the learning model and the transformation model.

[0107] <Private LLM Learning Example 1> Next, we will explain the process by which the local DN trains the private LLM used in configuration examples 1 to 4. Figure 14 is an example of a diagram illustrating the training process of the private LLM.

[0108] As explained with reference to Figure 51 on the left of Figure 10, even if the conversation history with a public LLM is input into a private LLM, the confidentiality is not compromised. Therefore, the local DN may use the conversation history with the public LLM, in addition to the conversation history with the private LLM, as training data for the private LLM. Conversely, the conversation history with the private LLM is not used to train the public LLM.

[0109] <Example of learning a private LLM (2)> As mentioned above, a private LLM is, for example, an LLM used by a specific company, but collaborative learning of multiple private LLMs may be conducted, particularly between related companies.

[0110] Figure 15 is an example of a diagram illustrating the process of associative learning. As shown in Figure 15, the following steps (1) to (3) are performed in associative learning.

[0111] (1) Each local DN uses training data to train each private LLM owned by its device.

[0112] (2) Each local DN sends the data from the trained private LLM to the central DN.

[0113] (3) The central DN performs federated learning to merge each private LLM and sends it to each local DN. Each local DN updates the private LLMs it owns with the merged private LLMs.

[0114] Recent literature describing associative learning in LLM includes, for example, (a) to (c) below.

[0115] (a) MSIISM, NTT Data Mathematical Systems. What is Federated Learning? A clear explanation of the basics of Federated Learning. https: / / www.msiism.jp / article / federated-learning.html (b)Nvidia. Triaging COVID-19 Patients: 20 Hospitals in20 Days Build AI Model that Predicts OxygenNeeds. https: / / blogs.nvidia.com / blog / federated-learning-covid-oxygen-needs / (c)NEC. Federative Learning Technology that Enables Collaboration While Keeping Data Confidential and its Applicability to LLM, Vol.75 No.2 March 2024, Special Feature: Generative AI Changing Business Norms. https: / / jpn.nec.com / techrep / journal / g23 / n02 / 230215.html Furthermore, the configuration described in Private LLM Training Example 1, in which the conversation history with the public LLM is also used as training data for the private LLM, may be combined with the configuration of this example. That is, in the training of each private LLM in step (1) of this example, the conversation history with the public LLM may be used.

[0116] Furthermore, since there is a non-zero risk that the original training data may be reconstructed from the merged private LLM training models by the central DN, the training data used for training each private LLM in step (1) should be, for example, the aforementioned "Hi, my name is <person>and my number is<PHONE_NUMBER> It is also acceptable to convert the message to a state where the confidential information portion is concealed, such as in the message "[...]."

[0117] [Examples of implementation using software] The function of the information processing device (hereinafter referred to as "device") is a program that causes the device to function as a computer, and can be realized by a program that causes each control block of the device (particularly each part included in the control unit 10) to function as a computer.

[0118] In this case, the device includes a computer having at least one control device (e.g., a processor) and at least one storage device (e.g., memory) as hardware for executing the program. By executing the program using this control device and storage device, the functions described in each of the embodiments are realized.

[0119] The above program may be recorded on one or more computer-readable recording media, not temporary ones. These recording media may or may not be provided by the above device. In the latter case, the program may be supplied to the above device via any wired or wireless transmission medium.

[0120] Furthermore, some or all of the functions of each of the above control blocks can also be realized by logic circuits. For example, an integrated circuit in which logic circuits functioning as each of the above control blocks are formed is also included in the scope of the present invention. In addition, it is also possible to realize the functions of each of the above control blocks by, for example, a quantum computer.

[0121] Furthermore, each process described in the above embodiments may be performed by AI (Artificial Intelligence). In this case, the AI ​​may operate on the control device described above, or it may operate on other devices (for example, an edge computer or a cloud server).

[0122] The present invention is not limited to the embodiments described above, and various modifications are possible within the scope of the claims. Embodiments obtained by appropriately combining the technical means disclosed in different embodiments are also included in the technical scope of the present invention. [Explanation of Symbols]

[0123] 1. Terminal device (information processing device, UE) 10 Control Unit 11 Acquisition Department 12 Judgment section 13 Communication Control Unit 14 Output Control Unit (Display Control Unit) 15. Learning Department 16 Memory section 17 Communications Department 18 Display 19 Input section< / person> < / person> < / person>

Claims

1. It operates as User Equipment (UE) connected to the core network, including the User Plane Function (UPF), and has connections between a first Large Language Model (LLM) that does not allow the input of confidential information, and between a second Large Language Model (LLM) that does allow the input of confidential information. An information processing device that sends and receives messages in A unit that obtains a first message entered by the user, A communication control unit that transmits the first message, which does not contain confidential information, to the first LLM via the UPF and through communication over the Internet, and transmits the first message, which contains confidential information, to the second LLM via the UPF and through communication not over the Internet, the communication control unit that receives the second message output by each LLM in response to the input of the first message, An output control unit that controls the output of the second message, Equipped with, The communication control unit, Messages are sent and received between the first LLM and the first PDU session (Protocol Data Unit Session) established during communication with the first LLM. During communication with the second LLM, messages are sent and received between the second LLM and the UPF via a second PDU session established between the UPF and the second LLM. The second PDU session mentioned above is A PDU session different from the first PDU session, which is a PDU session established between the UPF and the LAND (Local Area Data Network), a network that is only available when the information processing device is located in a specific area. If the second PDU session cannot be established, the sending and receiving of messages containing confidential information will be prohibited. Information processing device.

2. The system further includes a determination unit for determining whether the first message contains confidential information, which determines the destination of the first message to be the first LLM if it determines that the first message does not contain confidential information, and determines the destination of the first message to be the second LLM if it determines that the first message contains confidential information. The information processing apparatus according to claim 1.

3. The determination unit, A learning model that takes the first message as input and outputs a determination result indicating whether or not the first message contains confidential information, wherein the determination is made according to the output of a learning model that has been trained using a pair of the first message and information indicating whether or not the first message contains confidential information as training data. The information processing apparatus according to claim 2.

4. Operating as User Equipment (UE) connected to a core network including a User Plane Function (UPF), between a first Large Language Model (LLM) that does not allow the input of confidential information, and between a second Large Language Model (LLM) that does allow the input of confidential information. An information processing device that sends and receives messages in A unit that obtains a first message entered by the user, A communication control unit that transmits the first message, which does not contain confidential information, to the first LLM via the UPF and through communication over the Internet, and transmits the first message, which contains confidential information, to the second LLM via the UPF and through communication not over the Internet, the communication control unit that receives the second message output by each LLM in response to the input of the first message, An output control unit that controls the output of the second message, Equipped with, The communication control unit, When the LLM that sends and receives messages switches from the first LLM to the second LLM, at least a portion of the message history sent and received between the first LLM and the second LLM is sent to the second LLM. When the LLM that sends and receives messages switches from the second LLM to the first LLM, (1) the history of messages sent and received between the second LLM and the first LLM is not sent to the first LLM, or (2) the history of such messages, which has been converted so that it does not contain confidential information, is sent to the first LLM. Information processing device.

5. An information processing device that operates as a UE (User Equipment) connected to a core network including a UPF (User Plane Function), and performs message transmission and reception between multiple LLMs (Large Language Models), A unit that obtains a first message entered by the user, A determination unit that, by referring to the first message, determines which LLM to send the first message to, A communication control unit that transmits the first message to the LLM determined by the determination unit via communication through the UPF, and a communication control unit that receives a second message output by the LLM in response to the first message via communication through the UPF, An output control unit that controls the output of the second message, Equipped with, The communication control unit, Messages are sent and received between the first LLM and the first LLM via a first PDU session (Protocol Data Unit Session) established during communication with the first LLM. During communication with the second LLM, messages are sent and received between the second LLM and the UPF via a second PDU session established between the UPF and the second LLM. The second PDU session mentioned above is A PDU session different from the first PDU session, which is a PDU session established between the UPF and the LAND (Local Area Data Network), a network that is only available when the information processing device is located in a specific area. If the second PDU session cannot be established, the sending and receiving of messages containing confidential information will be prohibited. Information processing device.

6. Operates as a UE (User Equipment) connected to a core network including a UPF (User Plane Function), and interacts with multiple LLMs (Large Language Models). An information processing device that sends and receives messages in A unit that obtains a first message entered by the user, A determination unit that, by referring to the first message, determines which LLM to send the first message to, A communication control unit that transmits the first message to the LLM determined by the determination unit via communication through the UPF, and a communication control unit that receives a second message output by the LLM in response to the first message via communication through the UPF, An output control unit that controls the output of the second message, Equipped with, The communication control unit, When the LLM that sends and receives messages switches from the first LLM to the second LLM, at least a portion of the message history sent and received between the first LLM and the second LLM is sent to the second LLM. When the LLM that sends and receives messages switches from the second LLM to the first LLM, (1) the history of messages sent and received between the second LLM and the first LLM is not sent to the first LLM, or (2) the history of such messages, which has been converted so that it does not contain confidential information, is sent to the first LLM. Information processing device.

7. The information processing device sends and receives messages between itself and multiple LLMs through a single application it runs on. The output control unit, In the aforementioned application, for each LLM that outputs the second message, the second message is displayed in a different display manner. The information processing apparatus according to claim 1 or any one of claims 4 to 6.

8. A control program for causing a computer to function as an information processing device according to claim 1, wherein the computer functions as the acquisition unit, the communication control unit, and the output control unit.

Citation Information

Patent Citations

  • Data kind detector and data kind detection method

    JP2009116680A

  • Information processing device, information processing method, and recording medium

    WO2025009048A1

  • Information processing apparatus and information processing method

    WO2025028335A1