Information processing device, information processing method, and information processing program

JP7912172B1Active Publication Date: 2026-08-27PAYPAY CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2026086707
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2026-05-22
Publication Date
2026-08-27
Estimated Expiration
2046-05-22

AI Technical Summary

Benefits of technology

【0008】 実施形態の一態様によれば、カスタムモデルが適切に運用されるように管理することができるという効果を奏する。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007912172000001_ABST
    Figure 0007912172000001_ABST
Patent Text Reader

Abstract

To manage custom models to ensure they are used properly. [Solution] The information processing device according to the present invention comprises a storage unit, a detection unit, an evaluation unit, a setting unit, a generation unit, and an output unit. The detection unit detects models from among multiple AI models that have similar uses or conflicting setting information as candidates for sorting, based on specification data and management ledger data. The evaluation unit performs a risk assessment for each AI model based on the type of data it handles or the functions it can perform, based on the specification data and management ledger data. The setting unit sets the functions that the AI ​​model can perform and the operational constraints for each AI model based on the evaluation results. The generation unit generates a rearrangement plan to optimize the slot placement for the AI ​​models based on information on the AI ​​models that are candidates for sorting, the results of the risk assessment, and the setting content. The output unit outputs the final result, including the rearrangement plan.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0006] , ,

[0005] , , ,

[0001] The present invention relates to an information processing apparatus, an information processing method, and an information processing program.

Background Art

[0002] In recent years, an environment has been developed in which AI models such as AI agents (hereinafter, appropriately referred to as "custom models") that are customized with prompts, external knowledge (knowledge base), and external tool execution functions according to specific operations and purposes based on large-scale language models can be easily constructed without requiring advanced skills.

[0003] Under such an environment, for example, an organization report generation system has been proposed that can easily generate reports (reports on a target organization including a plurality of report items) including various viewpoints using an existing learning model and can enhance the reliability of the reports.

Prior Art Documents

Patent Documents

[0007] The information processing device according to the present invention comprises a storage unit, a detection unit, an evaluation unit, a setting unit, a generation unit, and an output unit. The storage unit stores specification data for each of multiple AI models used within a specific organization, and management ledger data for managing the multiple AI models. Based on the specification data and management ledger data, the detection unit detects models with similar uses or models with conflicting setting information from among the multiple AI models as candidates for sorting. Based on the specification data and management ledger data, the evaluation unit performs a risk assessment for each of the multiple AI models according to the type of data handled by the AI ​​model or the functions that the AI ​​model can perform. Based on the evaluation results by the evaluation unit, the setting unit sets for each of the multiple AI models at least one of the functions that the AI ​​model can perform and the operational constraints of the AI ​​model. The generation unit generates a rearrangement proposal to optimize the placement of slots, which are management attributes of AI models in the model provisioning platform where the AI ​​models are operated, according to the department, application, or risk level within the organization, based on at least one of the following: information on AI models detected as candidates for organization by the detection unit, the results of the risk assessment by the evaluation unit, and the settings provided by the setting unit. The output unit outputs a final result that includes at least one of the following: information on AI models detected as candidates for organization by the detection unit, the results of the risk assessment by the evaluation unit, and the settings provided by the setting unit, as well as the rearrangement proposal generated by the generation unit. [Effects of the Invention]

[0008] According to one embodiment, the custom model can be managed to ensure that it is operated appropriately. [Brief explanation of the drawing]

[0009] [Figure 1] Figure 1 is a diagram illustrating the overview of the information processing according to the embodiment. [Figure 2] Figure 2 shows an example of the configuration of an information processing system according to the embodiment. [Figure 3] Figure 3 shows an example of the configuration of an information processing device according to the embodiment. [Figure 4] Figure 4 is a diagram showing an overview of the specification information stored in the specification information storage unit according to the embodiment. [Figure 5] Figure 5 is a diagram showing an overview of the management ledger data stored in the ledger information storage unit according to this embodiment. [Figure 6] Figure 6 is a diagram showing an overview of the capability flag data stored in the capability flag information storage unit according to the embodiment. [Figure 7] Figure 7 is a diagram showing an overview of the slot management data stored in the slot information storage unit according to this embodiment. [Figure 8] Figure 8 is a flowchart showing an example of the processing procedure for information processing performed by the information processing device according to the present invention. [Figure 9] Figure 9 is a hardware configuration diagram showing an example of a computer that implements information processing according to an embodiment or modified example. [Modes for carrying out the invention]

[0010] The following describes in detail, with reference to the drawings, the embodiments for implementing the information processing apparatus, information processing method, and information processing program according to the present application (hereinafter referred to as "embodiments"). Note that these embodiments do not limit the information processing apparatus, information processing method, and information processing program. Furthermore, the same parts are denoted by the same reference numerals in each of the following embodiments, and redundant descriptions are omitted.

[0011] [Embodiment] [1. Overview of Information Processing Based on the Embodiment] The following describes an overview of the information processing according to the embodiment, with reference to the drawings. Figure 1 is a diagram illustrating the overview of the information processing according to the embodiment. In the following, we will describe an example of information processing on a predetermined platform (for example, an internal portal site) which is a model provisioning base for providing employees with an execution environment for AI models to streamline operations within an organization such as a company, but this example is not particularly limited. For example, the information processing described below can also be applied when the AI ​​model is provided by a dedicated application program or when the AI ​​model is provided through an external system via an API (Application Programming Interface).

[0012] The information processing according to this embodiment is realized by an information processing system SYS, which includes a terminal device 10 and an information processing device 100. The terminal device 10 and the information processing device 100 are connected to a network N (see, for example, Figure 2) by wired or wireless means, respectively. The terminal device 10 and the information processing device 100 can communicate with other devices through the network N.

[0013] Terminal device 10 is an information processing terminal used by user U, who is an employee of a specific organization such as a company. Terminal device 10 may include a tablet PC (Personal Computer), a notebook or desktop PC, a smartphone, or other wearable device, but is not limited to these examples.

[0014] User U can use a web browser to access, for example, the internal portal site (hereinafter referred to as the "internal portal"), which is an internal platform that functions as a model provisioning base, and thereby utilize various documents, knowledge, and custom models managed on the internal portal.

[0015] The information processing apparatus 100 is a device that provides various services to user U through the company portal for the purpose of executing various processes to streamline the operations within the organization through the company portal. The information processing apparatus 100 is typically a server device, but it may also be realized by a mainframe, a workstation, or the like. Further, when the information processing apparatus 100 is realized by a server device, it may be realized by a single server device, or may be realized by a cloud system in which a plurality of server devices and a plurality of storage devices cooperate to operate.

[0016] Custom models operated in the company portal tend to cause chaos among models with similar functions and the obsolescence of models that are no longer used. Conventionally, the management of these custom models has relied on manual ledger management, but as the number of custom models increases, it has become difficult to accurately grasp the discrepancy between the physical entity on the system and the ledger record.

[0017] In addition, there are issues regarding risk management in terms of security in the operation of custom models. For example, a custom model may have a function to access an external network (browsing function) or a code execution function (such as a code interpreter) to execute a program dynamically. Although these functions are highly convenient, they also carry the risk of leakage of confidential information outside the company and execution of unauthorized code.

[0018] Furthermore, there are also limitations in optimizing the allocation of the logical management units of custom models in the company portal in the operation of custom models. Conventionally, these allocations have been made manually, but as the number of models increases, it is extremely difficult to manually execute dynamic optimization according to the scale of each department, the purpose of the model, or the risk level.

[0019] Therefore, the information processing apparatus 100 according to the embodiment executes information processing for managing so that the custom model is appropriately operated in the company portal.

[0020] For example, user U, who is in charge of system administration for the company portal, inputs instructions for optimizing a custom model on the management screen of the company portal. When terminal device 10 receives the operation input for optimizing a custom model from user U, it sends a custom model optimization request to information processing device 100 (step S01).

[0021] When the information processing device 100 receives a request from the terminal device 10 to optimize a custom model, it reads the specification data for each of the multiple custom models, and the management ledger data for managing these custom models, from a predetermined data source (for example, the "SPECS directory"). For example, a custom model is managed using specification data, which describes information about the specifications of each model in Markdown format, and management ledger data, which records management information for managing all models in CSV (Comma Separated Values) format.

[0022] Next, the information processing device 100 analyzes the read specification data and management ledger data and converts them into an internal data model having a common data format (step S02). Specifically, the information processing device 100 extracts items from the specification data and management ledger data such as a model ID for identifying the model, a slot number for managing slots, the purpose of the model, the departments in which the model is used, and the functions that the model can perform, and converts them into an internal data model that can be handled uniformly within the system.

[0023] In this embodiment, a slot is a management attribute of each custom model in the company portal, and is information that functions as a logical management unit. A slot is associated, for example, with a display frame in the user interface of the company portal. Furthermore, each slot can be identified with its own unique "slot number".

[0024] Next, the information processing device 100 detects, based on the internal data model, models with similar uses and models with conflicting configuration information from among multiple custom models as candidates for sorting (step S03).

[0025] Specifically, the information processing device 100 converts descriptive information about the attributes of custom models included in the internal data model (for example, metadata such as usage, description, category, and summary information) into vector data based on the internal data model, calculates the similarity between the multiple converted vector data, and detects custom models that satisfy predetermined criteria based on the calculated similarity as candidates for organization.

[0026] Furthermore, the information processing device 100 identifies multiple custom models that are assigned the same slot number based on an internal data model, and by comparing the results of analyzing the instructions (prompt content) to the custom models included in the configuration information of the identified multiple custom models, it determines whether there are any conflicts in the configuration information and detects custom models with conflicting configuration information as candidates for sorting.

[0027] Next, the information processing device 100 performs an evaluation and setting process (step S04) to perform a risk assessment based on the specification data and management ledger data, according to the type of data handled by the custom model or the functions that the custom model can implement.

[0028] Specifically, the information processing device 100 refers to predefined type pattern data of custom models that are evaluated as having a high risk level, and determines whether the target model matches a type pattern based on the internal data model of the target model. If the target model matches a type pattern as a result of the determination, it derives an evaluation result that the target model has a high risk level.

[0029] For example, if the target model is configured to handle highly confidential company information or personal information, or if it is configured to perform processing that relies on integration with external APIs, the information processing device 100 can derive a "High" risk level as the risk assessment result for the target model. On the other hand, if the target model does not match the above-mentioned type patterns, the information processing device 100 can derive a "Low" risk level.

[0030] Next, the information processing device 100 performs a configuration process based on the results of the risk assessment to set the functions that the custom model can perform and the operational constraints of the custom model to keep the risks within an acceptable range.

[0031] Specifically, the information processing device 100 sets capability flags that define whether to enable or disable various functions, such as browsing, code execution, image analysis, and file processing functions, depending on the intended use of the target model, based on the risk level of the target model. For example, if the risk level of the target model is "High," the information processing device 100 sets the capability flags corresponding to browsing and code execution functions to "OFF."

[0032] Furthermore, the information processing device 100 sets additional review conditions (an example of a "condition requiring two-factor authentication") that determine whether an additional review by an administrator is necessary depending on the risk level of the target model, as operational constraints for the target model. For example, if the risk level of the target model is "High," the information processing device 100 registers an approval flag (for example, "Approval Required") associated with the corresponding model (model ID) to indicate that an additional review by an administrator is required when the target model executes browsing or code execution functions.

[0033] Next, the information processing device 100 generates a rearrangement plan to optimize the placement of slots, which are management attributes of the custom model in the internal portal where the custom model is operated, according to the department, purpose, or risk level within the organization, based on at least one of the information of the custom model detected as a candidate for sorting, the results of the risk assessment by the evaluation process, and the settings by the setting process (step S05).

[0034] Specifically, the information processing device 100 refers to the management ledger data and scans the current availability and placement status of slots. Based on the scan results, the information processing device 100 dynamically generates a slot reallocation plan by performing at least one of the following processes: assigning a series of consecutive slot numbers to custom models used in the same department; organizing custom models by common use and assigning a series of slot numbers to them; or assigning a series of slot numbers so that custom models are arranged in order of risk level. When generating the reallocation plan, the information processing device 100 may also preferentially assign custom models with high risk values ​​indicated by the risk assessment results, or custom models with high usage frequency, to specific slot numbers.

[0035] Next, the information processing device 100 performs output processing to output information on the custom models detected as candidates for sorting, the results of the risk assessment by the evaluation process, the settings by the setting process, and the final results including the proposed rearrangement of the slots (step S06).

[0036] Specifically, the information processing device 100 eliminates duplication and conflicts and outputs the final results as a data file in Markdown or CSV format, including a list of custom models that can actually be operated and deployed, the final layout information of the slots assigned to each custom model, information on the functions (capability flags) that are enabled (or disabled) for each custom model, information on the risk level of each custom model, and whether or not additional reviews are required (additional review condition flags) defined according to the risk level. The information processing device 100 then presents the output data file to the terminal device 10 as a report of the final results (step S07).

[0037] Next, the information processing device 100 performs a reflection process to reflect the contents of the final result in the management ledger data, for example, on the condition that an approval input from user U for the final result is received (step S08). Specifically, the information processing device 100 saves the data file written out as the final result as the latest master data by writing it back to the management ledger data in a predetermined data source (for example, the "SPECS directory").

[0038] In this way, the information processing device 100 reflects the slot numbers, which were previously assigned randomly due to the addition of custom models, etc., into the management ledger data in an organized (optimized) state by department, application, or risk level. This allows the information processing device 100 to improve the visibility and maintainability of the information recorded in the management ledger.

[0039] Furthermore, instead of requiring approval input from an administrator for the final result, the information processing device 100 may, upon receiving a suggestion for revision to the final result from user U, reflect the content of the received suggestion in the management ledger data. This allows the information processing device 100 to support highly practical ledger management and optimization of the model provision platform.

[0040] At least a portion of each of the processes described in steps S03 to S08, which are performed by the information processing device 100, can be implemented by a software system installed in the information processing device 100. Such a software system may consist of, for example, sub-agents, which are AI agents that perform specific tasks, and a main agent that oversees each of the sub-agents.

[0041] The main agent can be implemented by an AI agent such as an LLM (Large Language Model) or a planning module. The main agent inputs task execution commands to the sub-agents, obtains the processing results output from the sub-agents, and performs information processing according to the embodiment based on the obtained processing results.

[0042] Subagents can be implemented using program modules such as LLMs (Large Language Models) specialized for specific tasks. Subagents perform processing related to specific tasks by operating according to execution instructions input from the main agent.

[0043] The first sub-agent, which performs a specific task corresponding to the processing in step S03 described above, receives from the main agent an internal data model and instruction prompts, which are text information instructing it to find custom models that are candidates for sorting.

[0044] This instruction prompt includes instructions to detect custom models with similar uses and descriptions based on the similarity of the uses and descriptions contained in the internal data model. Furthermore, this instruction prompt includes evaluation criteria for assessing not just string similarity, but also, for example, semantic or contextual similarity of the text (hereinafter referred to as "semantic similarity"). Examples of evaluation criteria include commonalities in the problems solved, intended users, and systems used by the custom models being processed.

[0045] The first sub-agent extracts evaluation criteria from the instruction prompt received as input information. Next, the first sub-agent vectorizes text such as usage or explanatory text included in the internal data model using a natural language processing algorithm to generate embedding vectors. Then, the first sub-agent calculates the cosine similarity between the generated embedding vectors and applies the evaluation criteria extracted from the instruction prompt to the calculation result to evaluate (infer) the semantic similarity shown by the text, and outputs the inference result to the main agent. Based on the semantic similarity inference result output from the first sub-agent, the main agent detects custom models whose semantic similarity exceeds a predetermined threshold as "candidates for sorting".

[0046] Furthermore, the aforementioned instruction prompts include instructions for detecting custom models whose configuration information (such as access permission settings and prompt content) conflicts with that of other custom models assigned the same slot number. Examples of configuration information conflicts include cases where the content of one custom model's instructions (prompt content) contradicts that of another custom model, or where access permissions to a common external resource are assigned redundantly.

[0047] The first sub-agent, following the instruction prompts received as input information from the main agent, detects multiple custom models assigned the same slot number based on its internal data model. Next, the first sub-agent analyzes the instructions of each detected custom model using a natural language processing algorithm and compares the configuration information of each custom model to infer (determine) whether there are any conflicts in the configuration information, and outputs the inference result to the main agent. Based on the conflict inference result output from the first sub-agent, the main agent detects custom models with conflicting configuration information as "candidates for sorting".

[0048] The second sub-agent, an AI agent that performs a specific task corresponding to the processing in step S04 described above, receives from the main agent an internal data model and instruction prompts, which are text information instructing it to perform a risk assessment of each custom model based on risk assessment criteria (such as type pattern data and security policies within the organization).

[0049] The second sub-agent extracts risk assessment criteria from the instruction prompts received as input information. The second sub-agent also analyzes (vectorizes, etc.) text information describing the specifications of each custom model using a natural language processing algorithm. Next, based on the analysis results and the risk assessment criteria extracted from the instruction prompts, the second sub-agent calculates (infers) the risk level at which each custom model could be used for unauthorized data leakage or the theft of confidential information, and outputs the inference result to the main agent.

[0050] The main agent automatically sets (assigns) "capability flags" to the target custom model, defining whether various functions, including browsing, code execution, image analysis, and file processing, are enabled or disabled, based on the risk level inference results output by the second sub-agent.

[0051] Furthermore, the main agent implements additional review conditions that require human administrator approval for specific custom models whose risk level exceeds a predetermined standard. For example, the main agent sets approval flag information according to the risk level to determine whether administrator approval is required for the execution of functions by the target custom model. In this way, the information processing device 100 reduces the risk of false positives by the second sub-agent and achieves both operational governance compliant with the organization's security policy and usability.

[0052] The third sub-agent, which performs a specific task corresponding to the processing in step S05 described above, receives from the main agent the processing results of the first sub-agent (information on custom models detected as candidates for sorting), the processing results of the second sub-agent, and the processing results of the main agent (information on capability flags or additional review condition settings), as well as instruction prompts to instruct the determination of slot placement patterns based on predetermined optimization rules.

[0053] The third sub-agent extracts optimization rules (placement constraints or weighting coefficients) from the received instruction prompts. Next, the third sub-agent calculates (infers) placement patterns that optimize evaluation metrics (scores) defined in terms of department, use, and risk, according to optimization rules that include, for example, avoiding duplication of functions within the same department, isolating high-risk custom models into specific slot groups, or systematically organizing custom models with similar uses.

[0054] Specific deployment patterns include assigning a series of slot numbers to custom models used within the same department, classifying custom models by common use and assigning a series of slot numbers to each, or assigning a series of slot numbers so that custom models are arranged in order of risk level (for example, from lowest risk to highest risk). The third sub-agent outputs to the main agent the calculation results of the deployment pattern that optimizes the evaluation metrics (scores) defined from these perspectives.

[0055] The main agent generates a proposed slot relocation plan based on the calculation results of the placement pattern output from the third sub-agent, and outputs a final result that includes the generated relocation plan. For example, the main agent writes out a data file in Markdown or CSV format that includes at least one of the following: a list of deployable custom models with duplicates or conflicts resolved, capability flag settings for each custom model, risk level information for each custom model, and approval flag information defined according to the risk level.

[0056] Next, the main agent presents the exported data file to the terminal device 10 as a report of the final results to user U. Furthermore, for example, if user U has given approval for the final results, the main agent saves the exported data file as the latest master data by writing it back to the management ledger data in a predetermined data source (for example, the "SPECS directory").

[0057] Below, we will explain an example of the final result when, for example, the custom models "CS FAQ Helper" and "CS Support FAQ Bot," which were generated for customers, are detected as candidates for organization based on the information processing described above. <Output Example> • Slot #120: Proposed as a custom model that should be retained (kept) "CS FAQ Helper". • Slot #453: "CS Support FAQ Bot" is proposed as a candidate for integration. • Reason for integration: Similar use, reference FAQs, and prompts. • Additional decision: Browsing and code execution functions are turned "OFF" because customer information is handled. <Example of prompts when outputting the final result to the AI ​​model> "Compare the actual specifications of custom models with the management ledger data, identify custom models that are candidates for elimination, and output, with reasons, which custom models should be maintained (kept), risk assessments, proposed slot reallocations, and whether additional review is necessary."

[0058] As described above, the information processing device 100 according to the embodiment can automatically detect duplicates and conflicts in settings among a large number of custom models scattered throughout an organization, each having similar uses and settings. As a result, the information processing device 100 according to the embodiment can easily grasp the specifications and operational status of the vast number of custom models, which would be difficult to manage manually, and can eliminate system redundancy and significantly improve management efficiency.

[0059] Furthermore, the information processing device 100 according to the embodiment automatically restricts functions that could pose security threats, such as browsing functions and code execution functions, based on the confidentiality of the data handled by each custom model and the access rights granted to the data. As a result, the information processing device 100 according to the embodiment can proactively prevent security risks associated with leaving outdated specifications or using functions in an opaque manner, reliably deter the leakage of confidential information and unauthorized access, and build a secure agent operating environment.

[0060] Furthermore, the information processing device 100 according to the embodiment generates a rearrangement plan to optimize the slots (slot numbers) assigned to custom models according to the department, application, and risk level. As a result, the information processing device 100 according to the embodiment can dramatically reduce the overall system management cost, while simultaneously improving accessibility to the appropriate custom models required by users, thereby achieving a high level of both security and improved usability.

[0061] In this way, the information processing device 100 according to the embodiment can manage the custom model so that it is operated appropriately.

[0062] [2. System Configuration] The configuration of the information processing system SYS that performs the information processing method according to the present application will be described below. Figure 2 is a diagram showing an example of the configuration of the information processing system SYS according to the embodiment.

[0063] As shown in Figure 2, the information processing system SYS according to this embodiment is configured to include a terminal device 10 and an information processing device 100. Note that the configuration of the information processing system SYS shown in Figure 2 is just one example, and other devices not illustrated in Figure 2 may also be included.

[0064] The terminal device 10 and the information processing device 100 are connected to the network N by wire or wireless connection. The terminal device 10 and the information processing device 100 can communicate with other devices via the network N.

[0065] Network N includes, for example, WANs (Wide Area Networks) such as the Internet, and mobile communication networks such as LTE (Long Term Evolution), 4G (4th Generation), and 5G (5th Generation: 5th Generation Mobile Communication System).

[0066] Furthermore, terminal device 10 is an information processing terminal used by user U, who is an employee within a specific organization such as a company. Terminal device 10 may include a tablet PC (Personal Computer), a notebook or desktop PC, a smartphone, or other wearable device, but is not limited to these examples.

[0067] The terminal device 10 has a control function unit that controls each functional unit provided in the terminal device 10 to realize input / output, display, or communication. The terminal device 10 connects to the network N via a mobile communication network or short-range wireless communication such as Bluetooth® or wireless LAN (Local Area Network), and can communicate with other devices such as the information processing device 100 through the network N.

[0068] User U can use a web browser to access, for example, the internal portal site (hereinafter referred to as the "internal portal"), which is an internal platform that functions as a model provisioning base, and thereby utilize various documents, knowledge, and custom models managed on the internal portal.

[0069] Furthermore, when the terminal device 10 receives control information from the information processing device 100 to perform predetermined information processing, it performs the information processing according to the control information. Here, the control information is written in, for example, a scripting language such as JavaScript (registered trademark), a stylesheet language such as CSS (Cascading Style Sheets), a programming language such as Java (registered trademark), or a markup language such as HTML (HyperText Markup Language). Alternatively, the predetermined application itself distributed from the information processing device 100 may be considered as the control information.

[0070] The information processing device 100 is a device that provides various services to user U through an internal portal, with the aim of performing various processes to streamline operations within the organization via the internal portal. The information processing device 100 is typically a server device, but may also be implemented as a mainframe or workstation. Furthermore, if the information processing device 100 is implemented as a server device, it may be implemented as a single server device, or as a cloud system in which multiple server devices and multiple storage devices work together.

[0071] Furthermore, the information processing device 100 performs information processing to manage the custom model so that it is properly operated on the company portal.

[0072] [3. Equipment configuration] Hereinafter, an example of the functional configuration of the information processing device 100 according to the embodiment will be described using Figure 3. Figure 3 is a diagram showing an example of the configuration of the information processing device 100 according to the embodiment. As shown in Figure 3, the information processing device 100 according to the embodiment has a communication unit 110, a storage unit 120, and a control unit 130.

[0073] (Communications Department 110) The communication unit 110 is implemented, for example, by a communication module or a NIC (Network Interface Card). The communication unit 110 is connected to the network N by wire or wireless connection and transmits and receives information with other devices such as the terminal device 10.

[0074] (Storage unit 120) The storage unit 120 stores, for example, programs and data used for control and calculations by the control unit 130. The storage unit 120 is implemented by, for example, semiconductor memory elements such as RAM (Random Access Memory) or flash memory, or storage devices such as hard disks or optical discs. As shown in Figure 3, the storage unit 120 includes a specification information storage unit 121, a ledger information storage unit 122, a capability flag information storage unit 123, a slot information storage unit 124, and a pattern information storage unit 125.

[0075] (Specification information storage unit 121) The specification information storage unit 121 stores specification data relating to the specific specifications of the custom model. Figure 4 is a diagram showing an overview of the specification information stored in the specification information storage unit 121 according to this embodiment.

[0076] As shown in Figure 4, the specification data stored in the specification information storage unit 121 has multiple fields, such as "Model ID," "Name," "System Prompt," "Description," "Author / Developer," "Version," and "File Path." These fields in the specification data are interconnected.

[0077] The "Model ID" field stores the Model ID, which is a unique identifier assigned to the custom model to uniquely identify it. The "Name" field stores information indicating the name set for the custom model. The "System Prompt" field stores instruction information that defines the basic operation of the custom model.

[0078] The "Description" field stores text data in natural language describing the functions, roles, and operational specifications that the custom model can perform. The "Creator / Developer" field stores information to identify the creator or developer of the custom model. The "Version" field stores information such as the management revision number indicating the generation of the custom model. The "File Path" field stores information indicating the location where the data file for the specification document is stored.

[0079] (Ledger information storage unit 122) The ledger information storage unit 122 stores ledger data relating to a management ledger for managing custom models. Figure 5 is a diagram showing an overview of the ledger data stored in the ledger information storage unit 122 according to this embodiment.

[0080] As shown in Figure 5, the management ledger data stored in the ledger information storage unit 122 has multiple fields, such as "Management ID," "Model ID," "Purpose," "Department," "Slot Number," "Risk Assessment," "Additional Review Requirement Flag," "Status," and "Update Date and Time." These fields in the management ledger data are interconnected.

[0081] The "Management ID" field stores the management ID, which is identification information used to manage each data item in the management ledger data. The "Model ID" field stores the model ID of the corresponding custom model. The "Purpose" field stores information indicating the purpose or intended use of the corresponding custom model.

[0082] The "Department" field stores information indicating the department in which the corresponding custom model is used. The "Slot Number" field stores information indicating the unique slot number (an example of a "Management Attribute") assigned to the corresponding custom model. The "Risk Assessment" field stores information indicating the risk assessment results for the corresponding custom model.

[0083] The "Additional Review Requirement Flag" field stores information about the additional review conditions. Specifically, it stores flag information that is pre-set according to the risk level, indicating whether administrator approval is required for the execution of the function by the target custom model. The "Status" field stores information indicating the status of the corresponding custom model, such as enabled, disabled, or pending. The "Update Date and Time" field stores information indicating the date and time when the update to the corresponding custom model was reflected.

[0084] (Ability Flag Information Storage Unit 123) The capability flag information storage unit 123 stores capability flag data assigned to each custom model in order to manage the functions that each custom model can perform. Figure 6 is a diagram showing an overview of the capability flag data stored in the capability flag information storage unit 123 according to the embodiment.

[0085] As shown in Figure 6, the capability flag data stored in the capability flag information storage unit 123 has multiple items, such as the "Model ID," "Function 1," "Function 2," "Function 3," and "Function 4." These items in the capability flag data are interconnected.

[0086] The "Model ID" field stores the Model ID of the corresponding custom model. The "Function 1" field stores a flag indicating whether the corresponding Function 1 (e.g., browsing function) is enabled or disabled. The "Function 2" field stores a flag indicating whether the corresponding Function 2 (e.g., code execution function) is enabled or disabled. The "Function 3" field stores a flag indicating whether the corresponding Function 3 (e.g., image analysis function) is enabled or disabled. The "Function 4" field stores a flag indicating whether the corresponding Function 4 (e.g., file execution function) is enabled or disabled.

[0087] (Slot information storage unit 124) The slot information storage unit 124 stores slot management data that indicates the slot allocation status for custom models. Figure 7 is a diagram showing an overview of the slot management data stored in the slot information storage unit 124 according to this embodiment.

[0088] As shown in Figure 7, the slot management data stored in the slot information storage unit 124 has multiple items, such as "slot number," "availability," "assigned model ID," and "department ID." These items in the slot management data are interconnected.

[0089] The "Slot Number" field stores the slot number, which is unique identification information for each slot used to identify it. The "Availability" field stores information indicating the availability status of the corresponding slot. The "Assigned Model ID" field stores the model ID of the custom model to which the corresponding slot is assigned. The "Department ID" field stores the department ID, which is identification information for identifying the department that uses the custom model to which the corresponding slot is assigned.

[0090] (Pattern information storage unit 125) The pattern information storage unit 125 stores predefined type pattern data for custom models that are evaluated as having a high risk level. Examples of type patterns include cases where the target model handles highly confidential company information or personal information requiring predetermined access privileges, or where processing is performed on the premise of linking with external APIs.

[0091] (Control unit 130) The control unit 130 is a controller, and is realized, for example, by a CPU (Central Processing Unit) or MPU (Micro Processing Unit) executing various programs (an example of an "information processing program" according to this embodiment) stored in the internal memory of the information processing device 100 using RAM as the working area.

[0092] Furthermore, the control unit 130 can be implemented using an integrated circuit such as an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a GPGPU (General Purpose Graphic Processing Unit).

[0093] As shown in Figure 3, the control unit 130 includes a conversion unit 131, a detection unit 132, an evaluation unit 133, a setting unit 134, a generation unit 135, an output unit 136, and a reflection unit 137. These units realize or execute the functions and operations of the information processing described below. Note that the control unit 130 may also include new functional units different from those shown in Figure 3, for example, in response to the expansion of various processes performed by the information processing device 100.

[0094] (Conversion unit 131) The conversion unit 131 reads the specification data and management ledger data, analyzes the data format of the read specification data and management ledger data, and converts them into an internal data model having a common data format.

[0095] Specifically, the conversion unit 131 reads specification data from the specification information storage unit 121 and management ledger data from the ledger information storage unit 122. The conversion unit 131 then extracts items such as model ID, slot number, purpose, department, and functions that the model can perform from the read specification data and management ledger data, and converts them into an internal data model that can be handled uniformly within the system. The conversion unit 131 then passes the converted internal data model to the detection unit 132 and the evaluation unit 133, respectively. The conversion unit 131 does not perform the conversion process if, after analyzing the data format of the specification data and management ledger data, it finds that the data formats are the same.

[0096] (Detection unit 132) Based on the specification data and management ledger data, the detection unit 132 identifies models with similar uses or conflicting configuration information from among multiple custom models as candidates for sorting.

[0097] Specifically, the detection unit 132 receives an internal data model from the conversion unit 131. Next, the detection unit 132 converts the descriptive information about the attributes of the custom model contained in the internal data model (for example, metadata such as usage, description, category, and summary information) into vector data, calculates the similarity between the multiple converted vector data, and detects custom models whose calculated similarity meets predetermined criteria as candidates for sorting.

[0098] Furthermore, the detection unit 132 identifies multiple custom models to which a common management environment has been assigned based on the internal data model, and by comparing the results of analyzing the instructions to the custom models contained in the configuration information of the identified multiple custom models, it determines whether there are any conflicts in the configuration information and detects custom models with conflicting configuration information as candidates for sorting.

[0099] Furthermore, at least a portion of the processing functions performed by the detection unit 132 can be implemented by a software system installed in the information processing device 100.

[0100] In other words, the first sub-agent, which performs a specific task corresponding to the processing of the detection unit 132, receives an internal data model and instruction prompts, which are text information for instructing the detection of custom models that are candidates for organization, from the main agent.

[0101] This instruction prompt includes instructions to detect custom models with similar uses and descriptions based on the similarity of the uses and descriptions contained in the internal data model. Furthermore, this instruction prompt includes evaluation criteria for assessing not just string similarity, but also, for example, semantic or contextual similarity of the text (hereinafter referred to as "semantic similarity"). Examples of evaluation criteria include commonalities in the problems solved, intended users, and systems used by the custom models being processed.

[0102] The first sub-agent extracts evaluation criteria from the instruction prompt received as input information. The first sub-agent also vectorizes the text of the use or description included in the internal data model using a natural language processing algorithm to generate embedding vectors. Next, the first sub-agent calculates the cosine similarity between the generated embedding vectors and applies the evaluation criteria extracted from the instruction prompt to the calculation result to evaluate (infer) the semantic similarity shown by the text, and outputs the inference result to the main agent. Based on the semantic similarity inference result output from the first sub-agent, the main agent detects custom models whose semantic similarity exceeds a predetermined threshold as "candidates for sorting".

[0103] Furthermore, the aforementioned instruction prompts include instructions for detecting custom models whose configuration information (such as access permission settings and prompt content) conflicts with that of other custom models assigned the same slot number. Examples of configuration information conflicts include cases where the content of one custom model's instructions (prompt content) contradicts that of another custom model, or where access permissions to a common external resource are assigned redundantly.

[0104] The first sub-agent, following the instruction prompts received as input information from the main agent, detects multiple custom models assigned the same slot number based on its internal data model. Next, the first sub-agent analyzes the instructions of each detected custom model using a natural language processing algorithm and compares the configuration information of each custom model to infer (determine) whether there are any conflicts in the configuration information, and outputs the inference result to the main agent. Based on the conflict inference result output from the first sub-agent, the main agent detects custom models with conflicting configuration information as "candidates for sorting".

[0105] (Evaluation Section 133) The evaluation unit 133 performs an evaluation process based on the specification data and management ledger data to assess the risk according to the type of data handled by the custom model or the functions that the custom model can perform.

[0106] Specifically, the evaluation unit 133 receives an internal data model from the conversion unit 131. Next, the evaluation unit 133 refers to predefined type pattern data of custom models that are evaluated as having a high risk level, and determines whether the target model matches a type pattern based on the internal data model of the target model. If the target model matches a type pattern as a result of the determination, it derives an evaluation result that the target model has a high risk level.

[0107] Furthermore, at least a portion of the processing functions performed by the evaluation unit 133 can be implemented by a software system installed in the information processing device 100.

[0108] In other words, the second sub-agent, which is an AI agent that performs a specific task corresponding to the processing of the evaluation unit 133, receives from the main agent an internal data model and instruction prompts, which are text information that instructs the sub-agent to perform a risk assessment of each custom model based on risk assessment criteria (such as type pattern data and security policies within the organization).

[0109] The second sub-agent extracts risk assessment criteria from the instruction prompts received as input information. The second sub-agent also analyzes (vectorizes, etc.) text information describing the specifications of each custom model using a natural language processing algorithm. Next, based on the analysis results and the risk assessment criteria extracted from the instruction prompts, the second sub-agent calculates (infers) the risk level at which each custom model could be used for unauthorized data leakage or the theft of confidential information, and outputs the inference result to the main agent.

[0110] (Settings section 134) Based on the evaluation results from the evaluation unit 133, the setting unit 134 sets the functions that each of the multiple custom models can perform and the operational constraints of the custom model.

[0111] Specifically, the setting unit 134 sets capability flags that define whether to enable or disable various functions, such as browsing, code execution, image analysis, and file processing functions, which are necessary based on the target model's intended use, based on the target model's risk level. For example, if the target model's risk level is "High," the information processing device 100 sets the capability flags corresponding to browsing and code execution functions to "OFF."

[0112] Furthermore, the settings unit 134 is not limited to restricting the functionality of the target model, but also performs the setting of additional review conditions (an example of a "condition requiring two-factor authentication") that determine whether an additional review by an administrator is necessary according to the risk level of the target model, as operational constraints for the AI ​​model.

[0113] Furthermore, at least a portion of the processing functions performed by the setting unit 134 can be implemented by a software system installed in the information processing device 100.

[0114] In other words, the main agent, which performs a specific task corresponding to the processing of the setting unit 134, automatically sets (assigns) "capability flags" to the target custom model, defining whether various functions, including browsing, code execution, image analysis, and file processing functions, are enabled or disabled, based on the risk level inference results output from the second sub-agent.

[0115] Furthermore, the main agent implements additional review conditions that require human administrator approval for specific custom models whose risk level exceeds a predetermined standard. For example, the main agent sets approval flag information according to the risk level to determine whether administrator approval is required for the execution of functions by the target custom model. In this way, the information processing device 100 reduces the risk of false positives by the second sub-agent and achieves both operational governance compliant with the organization's security policy and usability.

[0116] (Generation unit 135) Based on at least one of the following: information on custom models detected as candidates for organization, the results of the risk assessment by the evaluation unit 133, and the settings by the setting unit 134, the generation unit 135 generates a rearrangement plan to optimize the placement of slots, which are management attributes of custom models, in the internal portal where the custom models are operated, according to the department, purpose, or risk level within the organization.

[0117] Specifically, the generation unit 135 refers to the management ledger data and scans the current availability and placement status of slots. Next, based on the scan results, the generation unit 135 dynamically generates a proposed reallocation of slots according to optimization rules, including avoiding duplication of functions within the same department, isolating high-risk custom models to specific slot groups, or systematically organizing custom models with similar uses.

[0118] The relocation plan patterns generated by the generation unit 135 may include patterns such as "assigning a series of consecutive slot numbers to custom models used in the same department," "organizing custom models by common use and assigning a series of slot numbers to them," and "assigning a series of slot numbers so that custom models are arranged in order of risk level." Furthermore, when generating the relocation plan, the generation unit 135 can also prioritize assigning custom models with high risk values ​​or high usage frequencies to specific slot numbers.

[0119] Furthermore, at least a portion of the processing functions performed by the generation unit 135 can be realized by a software system installed in the information processing device 100.

[0120] In other words, the third sub-agent, which performs a specific task corresponding to the processing of the generation unit 135, receives from the main agent the processing results of the first sub-agent (information on custom models detected as candidates for organization), the processing results of the second sub-agent, and the processing results of the main agent (information on capability flags or additional review condition settings), as well as instruction prompts to instruct the determination of slot arrangement patterns based on predetermined optimization rules, as input information.

[0121] The third sub-agent extracts optimization rules (placement constraints or weighting coefficients) from the received instruction prompts. Taking into account the current availability of slots, the third sub-agent calculates (infers) placement patterns that optimize evaluation metrics (scores) defined in terms of department, use, and risk, according to optimization rules that may include, for example, avoiding duplication of functions within the same department, isolating high-risk custom models into specific slot groups, or systematically organizing custom models with similar uses.

[0122] Specific deployment patterns include assigning a sequence of slot numbers to custom models used within the same department, classifying custom models by common use and assigning a sequence of slot numbers to each, or assigning a sequence of slot numbers so that custom models are arranged in order of risk level (for example, from lowest risk to highest risk). The third sub-agent outputs to the main agent the calculation results of the deployment pattern that optimizes the evaluation metrics (scores) defined from these perspectives. The main agent generates a proposed slot rearrangement based on the calculation results of the deployment pattern output by the third sub-agent.

[0123] (Output section 136) The output unit 136 outputs a final result that includes at least one of the following: information on the custom model detected as a candidate for sorting by the detection unit 132, the results of the risk assessment by the evaluation unit 133, and the settings by the setting unit 134, as well as the rearrangement plan generated by the generation unit 135. The output unit 136 transmits a report of the final result to the terminal device 10 via the communication unit 110.

[0124] Furthermore, at least a portion of the processing functions of the output unit 136 can be implemented by a software system installed in the information processing device 100. That is, the main agent outputs the final result, including the generated relocation plan. For example, the main agent writes out the final result, which includes at least one of the following: a list of deployable custom models with duplicates or conflicts resolved, capability flag setting information for each custom model, risk level information for each custom model, and approval flag information defined according to the risk level, as a data file in Markdown or CSV format.

[0125] (Reflection section 137) The reflection unit 137 reflects the contents of the final result in the management ledger data, provided that approval input from user U for the final result is received. Specifically, the reflection unit 137 saves the update data written to a file as the latest master data by writing it back (deploying) it to the management ledger data in a predetermined data source.

[0126] Furthermore, at least a portion of the processing functions of the output unit 136 can be implemented by a software system installed in the information processing device 100. Specifically, the main agent, for example, saves the data file written out as the final result as the latest master data by writing it back to the management ledger data stored in the ledger information storage unit 122, provided that approval input for the final result has been received from user U.

[0127] [4. Example of processing procedure] The following describes the flow of information processing performed by the information processing device 100 according to this embodiment. Figure 8 is a flowchart showing an example of the processing procedure for information processing performed by the information processing device 100 according to this embodiment. The processing procedure shown in Figure 8 is performed by the control unit 130 of the information processing device 100.

[0128] As shown in Figure 8, the detection unit 132 detects models with similar uses or conflicting configuration information from among multiple custom models based on specification data and management ledger data as candidates for sorting (step S101).

[0129] Furthermore, the evaluation unit 133 performs a risk assessment based on the specification data and management ledger data, according to the type of data handled by the custom model or the functions that the custom model can perform (step S102).

[0130] Furthermore, the setting unit 134 sets the functions that each of the multiple custom models can perform and the operational constraints of the custom model based on the evaluation results from the evaluation unit 133 (step S103).

[0131] Furthermore, the generation unit 135 generates a rearrangement plan to optimize the placement of slots, which are management attributes of the custom model in the internal portal where the custom model is operated, according to the department, purpose, or risk level within the organization, based on at least one of the information of the custom model detected as a candidate for sorting, the results of the risk assessment by the evaluation unit 133, and the settings by the setting unit 134 (step S104).

[0132] Furthermore, the output unit 136 outputs a final result (step S105) that includes at least one of the following: information on the custom model detected as a sorting candidate by the detection unit 132, the results of the risk assessment by the evaluation unit 133, and the settings by the setting unit 134, as well as the rearrangement plan generated by the generation unit 135, thus ending the processing procedure shown in Figure 8.

[0133] [5. Variant] Of the processes described in the embodiments described above, all or part of the processes described as being performed automatically can be performed manually, and conversely, all or part of the processes described as being performed manually can be performed automatically by known methods. In addition, the processing procedures, specific names, and information including various data and parameters shown in the above document and drawings can be arbitrarily changed unless otherwise specified. For example, the various information shown in each figure is not limited to the information shown.

[0134] Furthermore, the components of each illustrated device are functionally conceptual and do not necessarily need to be physically configured as shown. In other words, the specific forms of distribution and integration of each device are not limited to those shown, and all or part of them can be functionally or physically distributed and integrated in any unit according to various loads and usage conditions.

[0135] Furthermore, the embodiments described above can be combined as appropriate, provided that the processing content is not contradictory.

[0136] [6. Hardware Configuration] Furthermore, the information processing device 100 according to the embodiments or modified examples described above can be implemented by a computer 1000 having the configuration shown in Figure 9. Figure 9 is a hardware configuration diagram showing an example of a computer that implements the information processing according to the embodiments or modified examples.

[0137] Computer 1000 is connected to an output device 1010 and an input device 1020, and has a configuration in which an arithmetic unit 1030, a primary storage device 1040, a secondary storage device 1050, an output interface 1060, an input interface 1070, and a network interface 1080 are connected by a bus 1090.

[0138] The arithmetic unit 1030 operates based on programs stored in the primary storage device 1040 and the secondary storage device 1050, as well as programs read from the input device 1020, and executes various processes. The primary storage device 1040 is a memory device, such as RAM, that temporarily stores data used by the arithmetic unit 1030 for various calculations. The secondary storage device 1050 is a storage device where data used by the arithmetic unit 1030 for various calculations and various databases are registered, and is implemented using ROM (Read Only Memory), HDD, flash memory, etc.

[0139] Output IF1060 is an interface for transmitting information to be output to output devices 1010, such as monitors and printers, and is implemented using connectors of standards such as USB (Universal Serial Bus), DVI (Digital Visual Interface), and HDMI (High Definition Multimedia Interface). Input IF1070 is an interface for receiving information from various input devices 1020, such as mice, keyboards, and scanners, and is implemented using, for example, USB.

[0140] The input device 1020 may also be a device that reads information from, for example, an optical recording medium such as a CD (Compact Disc), DVD (Digital Versatile Disc), or PD (Phase Change Rewritable Disk), a magneto-optical recording medium such as an MO (Magneto-Optical disk), tape media, magnetic recording media, or semiconductor memory. Furthermore, the input device 1020 may be an external storage medium such as a USB memory stick.

[0141] Network IF1080 receives data from other devices via network N and sends it to the arithmetic unit 1030, and also transmits data generated by the arithmetic unit 1030 to other devices via network N.

[0142] The arithmetic unit 1030 controls the output device 1010 and the input device 1020 via the output IF 1060 and the input IF 1070. For example, the arithmetic unit 1030 loads a program from the input device 1020 or the secondary storage device 1050 onto the primary storage device 1040 and executes the loaded program.

[0143] For example, when the computer 1000 functions as an information processing device 100 according to an embodiment or modified example, the arithmetic unit 1030 of the computer 1000 performs the same function as the control unit 130 by executing a program loaded onto the primary storage device 1040. That is, the arithmetic unit 1030 performs processing by the information processing device 100 according to an embodiment or modified example in cooperation with the information processing program loaded onto the primary storage device 1040.

[0144] [7. Effects] As described above, the information processing device 100 according to the embodiment includes a storage unit 120, a detection unit 132, an evaluation unit 133, a setting unit 134, a generation unit 135, and an output unit 136. The storage unit 120 stores specification data for each of multiple custom models (an example of "AI models") used within a specific organization, and management ledger data for managing the multiple custom models. Based on the specification data and management ledger data, the detection unit 132 detects models with similar uses or models with conflicting setting information from among the multiple custom models as candidates for sorting. Based on the specification data and management ledger data, the evaluation unit 133 performs a risk assessment for each of the multiple custom models according to the type of data handled by the custom model or the functions that the custom model can perform. Based on the evaluation results by the evaluation unit 133, the setting unit 134 sets the functions that the custom model can perform and the operational constraints of the custom model for each of the multiple custom models. The generation unit 135 generates a rearrangement proposal to optimize the placement of slots, which are management attributes of custom models in the model provisioning platform where the custom models are operated, according to the department, use, or risk level within the organization, based on at least one of the following: information on custom models detected as candidates for sorting by the detection unit 132, the results of the risk assessment by the evaluation unit 133, and the settings by the setting unit 134. The output unit 136 outputs a final result that includes at least one of the following: information on custom models detected as candidates for sorting by the detection unit 132, the results of the risk assessment by the evaluation unit 133, and the settings by the setting unit 134, as well as the rearrangement proposal generated by the generation unit 135.

[0145] Thus, the information processing device 100 according to this embodiment can automatically detect duplicates and conflicts in settings among a large number of custom models scattered throughout an organization, each having similar uses and settings. As a result, the information processing device 100 according to this embodiment can easily grasp the specifications and operational status of the vast number of custom models, which would be difficult to manage manually, and can eliminate system redundancy and significantly improve management efficiency.

[0146] Furthermore, the information processing device 100 according to the embodiment automatically restricts functions that could pose security threats, such as browsing functions and code execution functions, based on the confidentiality of the data handled by each custom model and the access rights granted to the data. As a result, the information processing device 100 according to the embodiment can proactively prevent security risks associated with leaving outdated specifications or using functions in an unclear manner, reliably deter the leakage of confidential information and unauthorized access, and build a secure agent operating environment.

[0147] Furthermore, the information processing device 100 according to the embodiment generates a rearrangement plan to optimize the slots (slot numbers) assigned to custom models according to the department, application, and risk level. As a result, the information processing device 100 according to the embodiment can dramatically reduce the overall system management cost, while simultaneously improving accessibility to the appropriate custom models required by users, thereby achieving a high level of both security and improved usability.

[0148] Therefore, the information processing device 100 according to this embodiment can manage custom models to ensure they are operated appropriately.

[0149] Furthermore, the information processing device 100 includes a conversion unit 131. The conversion unit 131 reads specification data and management ledger data from the storage unit 120, analyzes the data format of the read specification data and management ledger data, and converts it into an internal data model having a common data format. As a result, the information processing device 100 can perform highly accurate analysis in a consistent data format even if there are differences or inconsistencies in the format of the existing specification data and management ledger data.

[0150] Furthermore, the detection unit 132 converts descriptive information about the attributes of custom models included in the internal data model into vector data, calculates the similarity (for example, cosine similarity) between the multiple converted vector data, detects custom models whose calculated similarity meets a predetermined criterion as candidates for sorting, identifies multiple custom models to which the same slot is assigned, and compares the results of analyzing the instructions to the custom models included in the setting information of the identified multiple custom models to determine whether there are any conflicts in the setting information, and detects custom models with conflicting setting information as candidates for sorting. As a result, the information processing device 100 can use the similarity of the vector data generated from the internal data model to quantitatively and correctly evaluate the qualitative similarity of uses and detect candidates for sorting, and can detect conflicts in setting information without omission.

[0151] Furthermore, the evaluation unit 133 refers to predefined pattern information of custom model types that are evaluated as having a high risk level, and performs a risk assessment based on the internal data model for each of the multiple custom models. As a result, the information processing device 100 can quickly determine and stratify security risks using uniform and objective criteria, even for a large number of AI models with complex individual settings.

[0152] Furthermore, the information processing device 100 has a reflection unit 137. The reflection unit 137 reflects the content of the final result in the management ledger data, provided that approval input from the administrator for the final result is received. This enables the information processing device 100 to achieve safe and well-governed operation with administrator judgment involved when updating the management ledger data.

[0153] Furthermore, if the reflection unit 137 receives a proposed revision to the final result from the administrator instead of an approval request, it reflects the content of the received proposed revision in the management ledger data. This allows the information processing device 100 to immediately reflect fine-tuning that takes into account on-site operational circumstances and exception handling, thereby supporting the optimization of a highly practical ledger management and model provision platform that is extremely close to the actual operational realities of the organization.

[0154] Furthermore, the configuration unit 134 sets a constraint condition that requires two-factor authentication when executing a specific function corresponding to a specific risk if a specific risk is detected as a result of the risk assessment by the evaluation unit 133. This allows the information processing device 100 to build a flexible access control environment that does not impair business efficiency or developer convenience while taking into consideration the overall security strength of the system.

[0155] The effects described above can be achieved by any combination of the processes performed by the respective parts described above, or by any combination of the processes performed by the respective parts.

[0156] [8. Other] Although some embodiments of the present invention have been described in detail above with reference to the drawings, these are illustrative examples, and the present invention can be implemented in various other forms with modifications and improvements based on the knowledge of those skilled in the art, starting with the embodiments described in the disclosure section of the invention.

[0157] Furthermore, the configuration of the aforementioned information processing device 100 can be flexibly changed, for example, by calling external platforms via APIs (Application Programming Interfaces) or network computing depending on the function.

[0158] Furthermore, the term "part" in the claims can be replaced with "means," "circuit," etc. For example, "control unit" can be replaced with "control means" or "control circuit." [Explanation of Symbols]

[0159] SYS Information Processing System 10 Terminal devices 100 Information Processing Devices 110 Communications Department 120 Storage section 121 Specification Information Storage Unit 122 Ledger Information Storage Unit 123 Ability Flag Information Storage Unit 124 Slot Information Storage Unit 125 Pattern Information Storage Unit 130 Control Unit 131 Conversion Unit 132 Detection unit 133 Evaluation Department 134 Settings Section 135 Generation part 136 Output section 137 Reflection section

Claims

1. A storage unit that stores specification data for each of multiple AI models used within a specific organization, and management ledger data for managing the multiple AI models, A detection unit detects, from among the multiple AI models, models with similar applications or models with conflicting configuration information as candidates for organization, based on the aforementioned specification data and management ledger data. Based on the specification data and the management ledger data, an evaluation unit performs a risk assessment for each of the multiple AI models according to the type of data handled by the AI ​​model or the functions that the AI ​​model can perform. Based on the evaluation results by the evaluation unit, a setting unit sets for each of the plurality of AI models at least one of the functions that the AI ​​model can perform and the operational constraints of the AI ​​model. A generation unit generates a rearrangement plan to optimize the arrangement of slots, which are management attributes of the AI ​​model in the model provisioning platform on which the AI ​​model is operated, according to the department, application, or risk level within the organization, based on at least one of the information of the AI ​​model detected as a candidate for rearrangement by the detection unit, the results of the risk assessment by the evaluation unit, and the settings by the setting unit. An output unit outputs a final result that includes at least one of the following: information on the AI ​​model detected as a candidate for organization by the detection unit, the results of the risk assessment by the evaluation unit, and the setting contents by the setting unit, and the rearrangement plan generated by the generation unit. An information processing device characterized by comprising:

2. A conversion unit reads the specification data and management ledger data from the storage unit, analyzes the data format of the read specification data and management ledger data, and converts them into an internal data model having a common data format. The information processing apparatus according to claim 1, further comprising:

3. The detection unit is Based on the internal data model, the descriptive information regarding the attributes of the AI ​​model included in the internal data model is converted into vector data, the similarity between the multiple converted vector data is calculated, and custom models whose calculated similarity meets predetermined criteria are detected as candidates for sorting. Based on the internal data model, multiple AI models to which the same slot is assigned are identified, and by comparing the results of analyzing the instructions to the AI ​​models included in the setting information of the identified multiple AI models, it is determined whether there are any conflicts in the setting information, and the AI ​​models whose setting information conflicts are detected as candidates for sorting. The information processing apparatus according to feature 2.

4. The evaluation unit described above, The system refers to predefined pattern information for AI models that are assessed as having a high risk level, and performs a risk assessment for each of the multiple AI models based on the internal data model. The information processing apparatus according to feature 2.

5. A reflection unit that, subject to receiving approval input from the administrator for the aforementioned final result, reflects the contents of the aforementioned final result in the management ledger data. The information processing apparatus according to claim 1, further comprising:

6. The aforementioned reflection unit is, If, instead of the aforementioned approval input, a proposed revision to the final result is received from the administrator, the content of the received proposed revision will be reflected in the management ledger data. The information processing apparatus according to feature 5.

7. The setting unit is, If a specific risk is detected as a result of the risk assessment by the evaluation unit, a condition is set as the constraint that requires two-factor authentication when executing a specific function corresponding to that specific risk. The information processing apparatus according to feature 1.

8. A method of information processing performed by a computer, A detection step in which, based on the specification data of each of the multiple AI models used within a specific organization, and management ledger data for managing the multiple AI models, models with similar uses or models with conflicting configuration information are identified as candidates for consolidation from among the multiple AI models. Based on the specification data and the management ledger data, an evaluation step is performed for each of the multiple AI models, in accordance with the type of data handled by the AI ​​model or the functions that the AI ​​model can perform. Based on the evaluation results from the evaluation step, a setting step is performed to set for each of the plurality of AI models at least one of the functions that the AI ​​model can perform and the operational constraints of the AI ​​model. A generation step generates a rearrangement plan to optimize the arrangement of slots, which are management attributes of the AI ​​model in the model provisioning platform on which the AI ​​model is operated, according to the department, application, or risk level within the organization, based on at least one of the information of the AI ​​model detected as a candidate for organization by the detection step, the results of the risk assessment by the evaluation step, and the settings by the setting step. An output step outputs a final result that includes at least one of the following: information on the AI ​​model detected as a candidate for organization by the detection step, the results of the risk assessment by the evaluation step, and the setting contents by the setting step, and the rearrangement plan generated by the generation step. An information processing method characterized by including

9. On the computer, A detection procedure for identifying models with similar uses or conflicting configuration information from among multiple AI models, based on the specification data of each of the multiple AI models used within a specific organization, and management ledger data for managing the multiple AI models, and for identifying models with similar uses or conflicting configuration information as candidates for sorting. An evaluation procedure for each of the multiple AI models, based on the specification data and the management ledger data, to perform a risk assessment according to the type of data handled by the AI ​​model or the functions that the AI ​​model can perform, Based on the evaluation results obtained by the evaluation procedure described above, a setting procedure is provided for each of the plurality of AI models to set at least one of the functions that the AI ​​model can perform and the operational constraints of the AI ​​model. A generation procedure for generating a rearrangement proposal to optimize the placement of slots, which are management attributes of the AI ​​model in the model provisioning platform on which the AI ​​model is operated, according to the department, application, or risk level within the organization, based on at least one of the information of the AI ​​model detected as a candidate for organization by the detection procedure, the results of the risk assessment by the evaluation procedure, and the settings by the setting procedure; An output procedure that outputs a final result including information on the AI ​​model detected as a candidate for organization by the detection procedure, the results of the risk assessment by the evaluation procedure, at least one of the settings by the setting procedure, and the rearrangement proposal generated by the generation procedure. An information processing program characterized by causing the execution of [a specific action].

Citation Information

Patent Citations

  • Inspection system and method for managing ai model data

    CN116739967A

  • Model management device and model management method

    JP2023033894A

  • Ai system check program, ai system check method, and information processing device

    JP2024083128A

  • system

    JP2025055608A

  • Information processing apparatus and control method thereof

    JP2025139757A