Method and system for protecting user privacy, and storage medium and program product

By encoding user privacy information, generating encoding vectors and generating personalized reply content, the problem of privacy information leakage in personalized interactive services is solved, and the protection of user privacy and the accuracy of personalized interaction is achieved.

WO2025139772A1PCT designated stage expired Publication Date: 2025-07-03SHANGHAI XIYU JIZHI TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/138198
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-30
Filing Date
2024-12-10
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

In personalized interactive services, how to provide precise personalized services while protecting users' privacy information from being leaked.

Method used

By encoding the user's privacy information, an encoded vector is generated, and personalized reply content is generated based on the encoded vector to avoid the transmission of user privacy information in plain text.

Benefits of technology

It realizes the security of improving user privacy in personalized interactive services, while maintaining the accuracy and immersion of personalized interactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024138198_03072025_PF_FP_ABST
    Figure CN2024138198_03072025_PF_FP_ABST
Patent Text Reader

Abstract

The embodiments of the present description relate to the technical field of information security. Disclosed are a method and system for protecting user privacy, and a storage medium and a program product. The method comprises: on the basis of first data input by a user, acquiring personal information related to the user; determining privacy information from the personal information; performing coding processing on the privacy information, so as to obtain a coded vector corresponding to the privacy information; and obtaining second data generated on the basis of the coded vector and at least some information in the first data, wherein the second data comprises personalized reply content corresponding to the first data. By means of the method, not only can corresponding personalized reply content be generated on the basis of personal information including user privacy information, but user privacy leakage caused during information usage can also be prevented, thereby improving the security of the user privacy information while improving the accuracy of a personalized interaction service.
Need to check novelty before this filing date? Find Prior Art

Description

A method, system, storage medium and program product for protecting user privacy

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to Chinese patent application number 2023118595909, filed with the China Patent Office on December 30, 2023, entitled “A method, system, storage medium and program product for protecting user privacy”, the entire contents of which are incorporated by reference into this application. Technical Field

[0003] The present application relates to the field of information security technology, and in particular, to a method, system, storage medium, and computer program product configured to protect user privacy in personalized interactive services. Background Art

[0004] With the development of artificial intelligence (AI) technology, intelligent interactive services are increasingly being applied across various fields, such as role-playing chat, intelligent question-and-answer (Q&A), intelligent customer service, and voice assistants. These services often require access to users' personal information in order to provide more accurate and personalized services. However, with the increasing incidence of personal information leaks, how to protect user privacy while providing personalized services has become a pressing issue.

[0005] Based on this, it is necessary to study a method and system that can protect user privacy in personalized interactive services, so as to prevent the leakage of user privacy information while realizing personalized services. Summary of the Invention

[0006] To solve the above-mentioned problem, one aspect of an embodiment of the present specification provides a method configured to protect user privacy in a personalized interactive service, the method comprising: obtaining personal information related to the user based on first data input by the user; determining privacy information from the personal information; encoding the privacy information to obtain a coding vector corresponding to the privacy information; obtaining second data generated based on the coding vector and at least part of the information in the first data, the second data including personalized reply content corresponding to the first data.

[0007] Another aspect of the embodiments of this specification also provides a method configured to protect user privacy in a personalized interactive service, the method comprising: receiving a coding vector and at least part of the information in first data input by a user, wherein the coding vector is obtained by encoding the user's private information; processing the coding vector and the at least part of the information in the first data through a trained second model to obtain second data; and sending the second data to display personalized response content corresponding to the question information contained in the first data to the user.

[0008] Another aspect of the embodiments of this specification also provides a system configured to protect user privacy in personalized interactive services, the system comprising: a personal information acquisition module configured to acquire personal information related to the user based on first data input by the user; a privacy information determination module configured to determine privacy information from the personal information; an encoding module configured to encode the privacy information to obtain an encoding vector corresponding to the privacy information; and a reply content acquisition module configured to obtain second data generated based on the encoding vector and at least part of the information in the first data, the second data comprising personalized reply content corresponding to the first data.

[0009] Another aspect of the embodiments of this specification also provides a system configured to protect user privacy in personalized interactive services, the system comprising: a receiving module configured to receive a coding vector and at least part of the information in first data input by a user, wherein the coding vector is obtained by encoding the user's private information; a processing module configured to process the coding vector and at least part of the information in the first data through a trained second model to obtain second data; and a sending module configured to send the second data to display personalized response content corresponding to the question information contained in the first data to the user.

[0010] Another aspect of the embodiments of this specification also provides a system configured to protect user privacy in personalized interactive services, the system comprising: a personal information acquisition module configured to acquire personal information related to the user based on first data input by the user; a privacy information determination module configured to determine privacy information from the personal information; an encoding module configured to encode the privacy information to obtain an encoding vector corresponding to the privacy information; a processing module configured to process the encoding vector and at least part of the information in the first data through a trained second model to obtain second data, wherein the second data includes personalized reply content corresponding to the first data; and a display module configured to display the personalized reply content included in the second data to the user.

[0011] Another aspect of the embodiments of this specification further provides a computer-readable storage medium, which stores computer instructions. When the computer instructions are executed by a processor, any of the methods described above is implemented.

[0012] Another aspect of the embodiments of this specification further provides a computer program product, including a computer program or instructions, which implements any of the methods described above when executed by a processor.

[0013] Additional features are described in part in the following description. They will become apparent to those skilled in the art by reviewing the following and accompanying drawings, or by following the production or operation of the examples. The features of this specification may be realized and obtained by practicing or using the various aspects of the methods, tools, and combinations described in the following detailed examples. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] This specification will be further described in the form of exemplary embodiments, which will be described in detail with reference to the accompanying drawings. These embodiments are not limiting, and in these embodiments, the same numbers represent the same steps or structures.

[0015] FIG1 is a schematic diagram of an exemplary application scenario of a system configured to protect user privacy in a personalized interactive service according to some embodiments of this specification.

[0016] FIG2 is an exemplary module diagram of a system configured to protect user privacy in personalized interactive services according to some embodiments of the present specification.

[0017] FIG3 is an exemplary module diagram of a system configured to protect user privacy in personalized interactive services according to other embodiments of the present specification.

[0018] FIG4 is an exemplary module diagram of a system configured to protect user privacy in personalized interactive services according to other embodiments of the present specification.

[0019] FIG5 is an exemplary flowchart of a method configured to protect user privacy in a personalized interactive service according to some embodiments of the present specification.

[0020] FIG6 is an exemplary flow chart of a method configured to protect user privacy in a personalized interactive service according to other embodiments of the present specification. DETAILED DESCRIPTION

[0021] To more clearly illustrate the technical solutions of the embodiments of this specification, the following briefly describes the drawings required for describing the embodiments. Obviously, the drawings described below are merely examples or embodiments of this specification. Those skilled in the art can apply this specification to other similar scenarios based on these drawings without inventive effort. Unless otherwise apparent from the context or otherwise noted, the same reference numerals in the figures represent the same structure or operation.

[0022] It should be understood that the terms "system," "device," "unit," and / or "module" used in this specification are a method of configuring to distinguish different components, elements, parts, portions, or assemblies at different levels. However, if other terms can achieve the same purpose, the terms may be replaced by other expressions.

[0023] As used in this specification and claims, unless the context clearly indicates otherwise, the words "a," "an," "an," and / or "the" do not refer to the singular but also include the plural. Generally speaking, the terms "comprises" and "include" only indicate the inclusion of the steps and elements specifically identified, and these steps and elements do not constitute an exclusive list. A method or apparatus may also include other steps or elements.

[0024] Flowcharts are used throughout this specification to illustrate the operations performed by systems according to embodiments of this specification. It should be understood that preceding or following operations do not necessarily need to be performed in exact order. Instead, the steps may be processed in reverse order or simultaneously. Furthermore, other operations may be added to these processes, or one or more operations may be removed from these processes.

[0025] Taking role-playing intelligent chat (also called personalized chat) as an example, the text data and / or voice data input by the user can be processed by a data processing model pre-configured on the user terminal 110 and / or the service terminal 120, and the user can interact with the user in different roles according to the identity set by the user. For example, the model can chat with the user as a doctor / lawyer / teacher, chat with the user as an ancient figure, or chat with the user as a two-dimensional character (which can be a character created by the user or a character from an anime). It can be understood that if the interactive product (such as a large model configured as a question-and-answer session) knows the user's real identity or character information (which can be the user's real information or fictional information), it can provide more accurate and personalized interactive services, making the chat more realistic and the user more immersed in the interaction process, thereby achieving the purpose of improving the user experience.

[0026] For example, in some embodiments, the user terminal 110 and / or the service terminal 120 may obtain information such as the user's age, name, preferences, university of graduation, occupation, dating history, and medical history, and then input this information into the model. Furthermore, the model may analyze this information and, based on the analysis results, engage in a question-and-answer dialogue with the user.

[0027] However, from the user's perspective, it may not be desirable to transmit its private information to the server (eg, the service terminal 120). Therefore, it is particularly important to protect the user's privacy while utilizing the user's real information for personalized interaction.

[0028] To address the above issues, the embodiments of this specification provide a method and system configured to protect user privacy in personalized interactive services. The method and system encode the user's private information to obtain a coding vector corresponding to the private information, and then obtain corresponding personalized reply content based on the coding vector. While achieving personalized interaction, the user's private information received by the service terminal 120 is no longer in plain text, thereby preventing the user's private information from being leaked at the service terminal 120.

[0029] The following describes in detail the method and system for protecting user privacy in personalized interactive services provided by the embodiments of this specification in conjunction with the accompanying drawings.

[0030] FIG1 is a schematic diagram of an exemplary application scenario of a system configured to protect user privacy in personalized interactive services according to some embodiments of this specification.

[0031] 1 , in some embodiments, an application scenario 100 of a system configured to protect user privacy in personalized interactive services may include a user terminal 110, a service terminal 120, a storage device 130, and a network 140. The various components in application scenario 100 may be connected in various ways. For example, user terminal 110 may be connected to service terminal 120 and / or storage device 130 via network 140, or directly to service terminal 120 and / or storage device 130. For another example, service terminal 120 may be connected to storage device 130 via network 140 or directly to storage device 130.

[0032] The user terminal 110 can receive, send, input and / or output data. The data input by the user terminal 110 may include first data and / or operation instructions input by the user during the interaction process. In the embodiment of the present specification, the aforementioned first data may refer to the interactive data input by the user during the interaction process, which may be in the form of text data, voice data, action data (such as gesture data, nodding or shaking head, blinking), etc. For example, a user can ask a question by inputting text or voice. During the interaction process, the user terminal 110 can ask the user for relevant personal information (i.e., output a query). At this time, the user can respond to the query by inputting text, voice, or performing a specified action. It should be noted that in the embodiment of the present specification, the user terminal 110 can output the aforementioned query in text, voice, or any other feasible form.

[0033] The data sent by the user terminal 110 may include the aforementioned first data, an operation instruction, or data processed based on the aforementioned first data and / or the operation instruction. For example, in some embodiments, the user terminal 110 may obtain personal information related to the user based on the first data input by the user, then determine the private information therefrom, encode the private information, and obtain a coding vector corresponding to the private information. Finally, the coding vector and at least part of the information in the first data may be sent to the service terminal 120 for processing. For another example, in some embodiments, the user terminal 110 may extract question information from the aforementioned first data to obtain target question information, and then send a data acquisition instruction related to the target question information to the service terminal 120.

[0034] The data received by the user terminal 110 may include data sent by the service terminal 120 and / or data obtained from the storage device 130. For example, in some embodiments, the service terminal 120 may generate second data based on the aforementioned encoding vector and at least part of the information in the first data, and send the second data to the user terminal 110. For another example, in some embodiments, the service terminal 120 may filter personal information related to the question information contained in the first data from preset information input by the user based on the data acquisition instruction sent by the user terminal 110, and send the personal information to the user terminal 110. For another example, in some embodiments, the user terminal 110 may directly obtain personal information related to the target question information from the preset information stored in the storage device 130. For another example, in some embodiments, the user terminal 110 may obtain pre-stored computer instructions from the storage device 130 and execute the computer instructions to implement the method described in this specification for protecting user privacy in a personalized interactive service.

[0035] The data output by the user terminal 110 may include the aforementioned query and second data generated based on the aforementioned encoding vector and at least part of the information in the first data. It should be noted that in this embodiment of the specification, the second data may include personalized reply content corresponding to the aforementioned first data.

[0036] In some embodiments, the user terminal 110 may include a mobile device 111, a tablet computer 112, a laptop computer 113, or the like, or any combination thereof. For example, the mobile device 111 may include a mobile phone, a personal digital assistant (PDA), an in-vehicle terminal, a dedicated mobile terminal, or the like, or any combination thereof. In some embodiments, the user terminal 110 may include input devices and output devices, wherein the input devices may include a keyboard, a touch screen, a microphone, a camera, or the like, and the output devices may include a display, a speaker, or the like.

[0037] The service terminal 120 can process data and / or information obtained from the user terminal 110, the storage device 130, and / or other components of the application scenario 100. In some embodiments, the service terminal 120 can obtain the encoding vector corresponding to the aforementioned private information and at least part of the information in the aforementioned first data from the user terminal 110 or the storage device 130, and then obtain the second data by processing the encoding vector and at least part of the information in the first data. In the embodiments of this specification, the second data includes personalized response content corresponding to the aforementioned first data. By displaying this second data to the user, a personalized response can be provided to the first data entered by the user.

[0038] It should be noted that in the embodiments of this specification, since the second data is obtained based on the encoding vector corresponding to the private information, this second data can provide users with more accurate and personalized responses, thereby making human-computer interaction more realistic and users more immersed, thereby achieving the effect of improving the user experience. Furthermore, in the embodiments of this specification, by encoding the user's private information to obtain the aforementioned encoding vector and then sending it to service terminal 120 for processing, the user's private information received by service terminal 120 is no longer in plaintext, thereby preventing the leakage of the user's private information at service terminal 120.

[0039] In some embodiments, the service terminal 120 may receive a data acquisition instruction related to the question information in the first data, then acquire personal information related to the question information based on the data acquisition instruction, and transmit the personal information to the user terminal 110. In some embodiments, the service terminal 120 may receive target question information extracted from the first data, then, based on the target question information, filter personal information related to the target question information from preset information input by the user, and detect whether the personal information meets the response conditions corresponding to the target question information. If so, the personal information related to the target question information is transmitted; if not, a query instruction is transmitted simultaneously with the transmission of the personal information to inquire about the personal information regarding the target question information.

[0040] In some embodiments, the service terminal 120 may obtain pre-stored computer instructions from the storage device 130 and execute the computer instructions to implement the method described in this specification for protecting user privacy in a personalized interactive service.

[0041] In some embodiments, the service terminal 120 may be a single server or a server group. The server group may be centralized or distributed. In some embodiments, the service terminal 120 may be local or remote. For example, the service terminal 120 may access information and / or data from the user terminal 110 or the storage device 130 via the network 140. For another example, the service terminal 120 may be directly connected to the user terminal 110 and / or the storage device 130 to access information and / or data. In some embodiments, the service terminal 120 may be implemented on a cloud platform. For example, the cloud platform may include a private cloud, a public cloud, a hybrid cloud, a community cloud, a distributed cloud, an inter-cloud cloud, a multi-cloud, or any combination thereof.

[0042] The network 140 can facilitate the exchange of information and / or data. The network 140 may include any suitable network capable of facilitating the exchange of information and / or data for the application scenario 100. In some embodiments, at least one component of the application scenario 100 (e.g., the user terminal 110, the service terminal 120, the storage device 130) can exchange information and / or data with at least one other component in the application scenario 100 via the network 140. For example, the service terminal 120 can obtain the aforementioned encoding vector and at least part of the information in the first data from the user terminal 110 and / or the storage device 130 via the network 140. For another example, the service terminal 120 can obtain a data acquisition instruction from the user terminal 110 via the network 140, and issue personal information related to the problem information in the first data based on the data acquisition instruction. For another example, the user terminal 110 can receive second data generated based on the aforementioned encoding vector and at least part of the information in the first data via the network 140.

[0043] In some embodiments, network 140 can be any form of wired or wireless network, or any combination thereof. By way of example only, network 140 can include a cable network, a wired network, a fiber optic network, a telecommunications network, an intranet, the Internet, a local area network (LAN), a wide area network (WAN), a wireless local area network (WLAN), a metropolitan area network (MAN), a public switched telephone network (PSTN), a Bluetooth network, a ZigBee network, a near field communication (NFC) network, or the like, or any combination thereof. In some embodiments, network 140 can include at least one network access point, and at least one component of application scenario 100 can connect to network 140 via the access point to exchange data and / or information.

[0044] The storage device 130 can store data, instructions, and / or any other information. In some embodiments, the storage device 130 can store data obtained from the user terminal 110 and / or the service terminal 120. For example, the storage device 130 can store first data obtained by the user terminal 110; for another example, the storage device 130 can store a coding vector obtained by encoding the aforementioned private information; or for another example, the storage device 130 can store second data generated based on the coding vector and at least a portion of the first data. In some embodiments, the storage device 130 can store data and / or instructions used by the service terminal 120 to execute or complete the exemplary methods described herein. In some embodiments, the storage device 130 can include a mass storage device, a removable storage device, a volatile read-write memory, a read-only memory (ROM), or any combination thereof. Exemplary mass storage devices can include magnetic disks, optical disks, solid-state disks, or the like. In some embodiments, the storage device 130 can be implemented on a cloud platform. By way of example only, a cloud platform can include a private cloud, a public cloud, a hybrid cloud, a community cloud, a distributed cloud, an on-premises cloud, a multi-layer cloud, or any combination thereof.

[0045] In some embodiments, the storage device 130 can be connected to the network 140 to communicate with at least one other component in the application scenario 100 (e.g., the user terminal 110, the service terminal 120). At least one component in the application scenario 100 can access data, instructions, or other information stored in the storage device 130 through the network 140. In some embodiments, the storage device 130 can be directly connected to or communicate with one or more components in the application scenario 100 (e.g., the user terminal 110, the user terminal 110). In some embodiments, the storage device 130 can be part of the user terminal 110 and / or the service terminal 120.

[0046] It should be noted that the above description of application scenario 100 is for illustration and purpose only and does not limit the scope of application of this specification. Those skilled in the art may, under the guidance of this specification, make various modifications and alterations to application scenario 100. However, such modifications and alterations remain within the scope of this specification. For example, user terminal 110 and service terminal 120 may include more or fewer functional components.

[0047] Figures 2 through 4 are schematic diagrams of modules of a system configured to protect user privacy in personalized interactive services, according to some embodiments of this specification. In some embodiments, the system configured to protect user privacy in personalized interactive services shown in Figures 2 through 4 can be applied to the application scenario 100 shown in Figure 1 in the form of software and / or hardware. For example, it can be configured in the form of software and / or hardware to the user terminal 110 and / or the service terminal 120 to prevent the leakage of user privacy information while providing personalized services.

[0048] 2 , in some embodiments, a system 210 configured to protect user privacy in a personalized interactive service may include a personal information acquisition module 211, a privacy information determination module 212, an encoding module 213, and a reply content acquisition module 214. Each module may be configured to implement at least the following functions.

[0049] The personal information acquisition module 211 may be configured to acquire personal information related to the user based on first data input by the user.

[0050] The private information determination module 212 may be configured to determine private information from personal information.

[0051] The encoding module 213 may be configured to perform encoding processing on the private information to obtain an encoding vector corresponding to the private information.

[0052] The reply content acquisition module 214 may be configured to obtain second data generated based on the encoding vector and at least part of the information in the first data, wherein the second data includes personalized reply content corresponding to the first data.

[0053] It should be noted that, in some embodiments, the system 210 shown in FIG2 may be applied to the user terminal 110. In some embodiments, the system 210 shown in FIG2 may be applied to the service terminal 120.

[0054] 3 , in some embodiments, a system 220 configured to protect user privacy in personalized interactive services may include a receiving module 221, a processing module 222, and a sending module 223. Each module may be configured to implement at least the following functions.

[0055] The receiving module 221 may be configured to receive a coding vector and at least part of the information in the first data input by the user, wherein the coding vector is obtained by encoding the user's private information.

[0056] The processing module 222 can be configured to process the encoding vector and at least part of the information in the first data through the trained second model to obtain second data.

[0057] The sending module 223 may be configured to send the second data to present the personalized answer content corresponding to the question information included in the first data to the user.

[0058] In some embodiments, the system 220 shown in FIG3 may be applied to the user terminal 110. In some embodiments, the system 220 shown in FIG3 may be applied to the service terminal 120.

[0059] 4 , in some embodiments, a system 230 configured to protect user privacy in personalized interactive services may include a personal information acquisition module 211, a privacy information determination module 212, an encoding module 213, a processing module 222, and a presentation module 231. Each module may be configured to implement at least the following functions.

[0060] The personal information acquisition module 211 may be configured to acquire personal information related to the user based on first data input by the user.

[0061] The private information determination module 212 may be configured to determine private information from personal information.

[0062] The encoding module 213 may be configured to perform encoding processing on the private information to obtain an encoding vector corresponding to the private information.

[0063] The processing module 222 is configured to process the encoding vector and at least part of the information in the first data through the trained second model to obtain second data, where the second data includes personalized reply content corresponding to the first data.

[0064] The display module 231 is configured to display the personalized reply content included in the second data to the user.

[0065] In some embodiments, the system 230 configured to protect user privacy in a personalized interactive service may further include a first sending module, a first receiving module, a second sending module, and a second receiving module. The first sending module may be configured to send the encoding vector and at least a portion of the first data; the first receiving module may be configured to receive the encoding vector and at least a portion of the first data; the second sending module may be configured to send the second data; and the second receiving module may be configured to receive the second data.

[0066] In some embodiments, the first sending module and the second receiving module may be part of the aforementioned reply content acquisition module 214. In some embodiments, the first receiving module may refer to the aforementioned receiving module 221, or the first receiving module may be considered as part of the aforementioned receiving module 221. Similarly, the second sending module may refer to the aforementioned sending module 223, or the second sending module may be considered as part of the aforementioned sending module 223.

[0067] For more details about the above modules, please refer to other places in this specification (such as Figures 5 to 6 and their related descriptions), which will not be repeated here.

[0068] It should be understood that the systems and modules shown in Figures 2 to 4 configured to protect user privacy in personalized interactive services can be implemented in various ways. For example, in some embodiments, the system and its modules can be implemented by hardware, software, or a combination of software and hardware. The hardware portion can be implemented using dedicated logic; the software portion can be stored in a memory and executed by an appropriate instruction execution system, such as a microprocessor or dedicated hardware. Those skilled in the art will understand that the above-mentioned methods and systems can be implemented using computer-executable instructions and / or contained in processor control code, for example, such code is provided on a carrier medium such as a disk, CD or DVD-ROM, a programmable memory such as a read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. The system and its modules of this specification can be implemented not only by hardware circuits such as very large-scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, or programmable hardware devices such as field programmable gate arrays, programmable logic devices, but can also be implemented by software executed by various types of processors, or by a combination of the above-mentioned hardware circuits and software (for example, firmware).

[0069] It should be noted that the above description of a system configured to protect user privacy in personalized interactive services is provided for illustrative purposes only and is not intended to limit the scope of this specification. It will be understood that those skilled in the art can, based on the description of this specification, arbitrarily combine the various modules, or form a subsystem connected to other modules without departing from this principle. For example, the above modules can be different modules in a system, or the functions of two or more modules can be implemented by one module. Such variations are all within the scope of protection of this specification. In some embodiments, the aforementioned modules can be part of the service terminal 120 and / or the user terminal 110.

[0070] Figure 5 is an exemplary flow chart of a method configured to protect user privacy in a personalized interactive service according to some embodiments of this specification. In some embodiments, method 300 can be executed by processing logic, which can include hardware (e.g., circuits, dedicated logic, programmable logic, microcode, etc.), software (instructions running on a processing device to perform hardware simulation), etc., or any combination thereof. In some embodiments, one or more operations in the flow chart of method 300 configured to protect user privacy in a personalized interactive service shown in Figure 5 can be implemented by the service terminal 120 and / or user terminal 110 shown in Figure 1. For example, method 300 can be stored in the storage device 130 in the form of a computer program or instructions, and called and / or executed by the service terminal 120 and / or user terminal 110.

[0071] 5 , in some embodiments, a method 300 configured to protect user privacy in a personalized interactive service may include:

[0072] Step 310 : Acquire personal information related to the user based on the first data input by the user. In some embodiments, step 310 may be performed by the personal information acquisition module 211 .

[0073] In some embodiments, a user may input first data on user terminal 110, which may include text data and / or voice data. User terminal 110 may process the first data or send the first data to service terminal 120 for processing, thereby obtaining reply content corresponding to the first data. In some embodiments, user terminal 110 and / or service terminal 120 may generate reply content corresponding to the first data based on the user's personal information, thereby making the reply content more accurate and more in line with the user's actual needs.

[0074] In some embodiments, the personal information acquisition module 211 may filter out personal information related to the question information contained in the aforementioned first data from the preset information input by the user. The preset information input by the user may refer to information entered by the user before the interaction. For example, this may be user identity information entered when the user registers an account or modifies account information; or role information entered when the user sets an interaction role before the interaction begins. In some embodiments, the user may set the roles of both parties before the interaction begins, thereby allowing the interaction to proceed in the form of role-playing.

[0075] In some embodiments, the question information contained in the first data may refer to question information extracted based on the latest data input by the user. In some embodiments, the question information contained in the first data may refer to question information extracted after a comprehensive analysis of the latest data input by the user and historical data input by the user. In some embodiments, the personal information related to the question information contained in the aforementioned first data may refer to conditions that need to be considered in the process of answering the question information, which may include user information and information related to the user (such as information about the user's environment, etc.).

[0076] For example, when the question information input by the user is "I have symptoms of dizziness and nausea. What disease might I have?", the personal information related to the question information may include but is not limited to past medical history (such as heart disease, high blood pressure, etc.), eating habits (such as using certain drugs that may cause dizziness and nausea, drinking alcohol, eating foods that may pose a risk of poisoning, not eating for a long time, etc.), environmental factors (such as pungent odors, high / low temperatures, altitude, etc.), recent activities (such as head impact, etc.), other symptoms (such as vomiting, headache, blurred vision, tinnitus, etc.), etc.

[0077] In some embodiments, the personal information acquisition module 211 may also extract personal information related to the question information from the aforementioned first data. This first data may refer to all data entered by the user during the interaction process, and may include one or more pieces of data entered by the user during the interaction process. In other words, in some embodiments, the personal information acquisition module 211 may extract personal information related to the question information from the current interaction data and / or historical interaction data entered by the user.

[0078] In some embodiments, the aforementioned preset information can be input through the user terminal 110 and stored locally in the user terminal 110 (for example, a storage device 130 configured locally in the user terminal 110), and the personal information acquisition module 211 extracts question information from the first data to obtain target question information. As mentioned above, in some embodiments, the personal information acquisition module 211 can extract question information based on the latest data input by the user to obtain the target question information. In some embodiments, the personal information acquisition module 211 can also extract question information after comprehensively analyzing the latest data input by the user and the historical data input by the user to obtain the target question information. Further, the personal information acquisition module 211 can filter out personal information related to the target question information from the preset information stored locally in the user terminal 110.

[0079] In some embodiments, the personal information acquisition module 211 can filter the personal information related to the target question information through a pre-configured relationship table or model. For example, in some embodiments, the personal information related to each question (or question type) can be pre-configured, and in the subsequent process, the personal information related to the target question information can be filtered by looking up the table. In some embodiments, the similarity between the aforementioned target question information and the pre-configured preset question can be calculated, and when the similarity is greater than or equal to a preset threshold, the relevant personal information corresponding to the preset question is used as the personal information related to the target question information. In some embodiments, the aforementioned preset threshold can be set according to actual needs, for example, it can be set to 85% or other larger or smaller values.

[0080] In some embodiments, the personal information related to the target question information can also be obtained by processing a pre-trained neural network model, which can be trained using a number of sample questions and labels corresponding to the sample questions. The labels can include the relevant personal information corresponding to the sample questions.

[0081] In some embodiments, the aforementioned preset information can be input through the user terminal 110 and then sent to the service terminal 120 (for example, a storage device 130 configured in the service terminal 120) for storage. The personal information acquisition module 211 can extract question information from the first data to obtain target question information, and then send a data acquisition instruction related to the target question information to the service terminal 120, and receive personal information related to the target question issued by the service terminal 120 based on the data acquisition instruction. It should be noted that in the embodiments of this specification, the data acquisition instruction related to the target question information can be understood as an instruction configured to obtain personal information related to the target question. The instruction may include one or more personal information related to answering the target question information. In some embodiments, the data acquisition instruction can be generated based on the personal information required to answer the target question information.

[0082] In some embodiments, the personal information acquisition module 211 can extract personal information related to the aforementioned target question from the first data input by the user. For example, a user may enter first data to introduce themselves during an interaction, and the personal information acquisition module 211 can extract the first data to obtain personal information related to the aforementioned target question.

[0083] In some embodiments, the aforementioned first data may include data input by the user in response to an inquiry from the user terminal 110. Specifically, in some embodiments, the personal information acquisition module 211 may detect whether the personal information related to the target question information filtered out from the aforementioned preset information meets the answer conditions corresponding to the question information. If the personal information filtered out from the preset information meets the answer conditions of the target question information, it means that the answer corresponding to the target question information can be completed based on the currently filtered information. At this time, subsequent processing can be performed based on the personal information related to the target question information filtered out from the aforementioned preset information. On the contrary, if it does not meet the conditions, it means that the answer corresponding to the target question information cannot be completed based on the currently filtered information (for example, the necessary conditions are missing). At this time, the user can be queried to obtain the required information, and then the personal information related to the target question information can be extracted from the first data input by the user in response to the inquiry.

[0084] In some embodiments, the personal information acquisition module 211 can query the pre-configured detection table to determine whether the personal information related to the target question information screened out from the aforementioned preset information meets the response conditions corresponding to the question information. Specifically, in some embodiments, the detection table may include necessary information corresponding to a number of preset questions. The personal information acquisition module 211 can query the preset question corresponding to the target question information in the detection table, and then compare the personal information related to the target question information screened out from the aforementioned preset information with the necessary information corresponding to the preset question, thereby determining whether the personal information related to the target question information screened out from the aforementioned preset information meets the response conditions corresponding to the question information. For example, when the personal information related to the target question information screened out from the aforementioned preset information completely covers the necessary information corresponding to the target question information, it means that the response conditions corresponding to the question information are met, otherwise they are not met.

[0085] In some embodiments, the personal information acquisition module 211 may acquire personal information related to the question information contained in the first data by using any of the above methods. In some embodiments, the personal information acquisition module 211 may acquire personal information related to the question information contained in the first data by simultaneously acquiring personal information from preset information and acquiring personal information from the first data.

[0086] Step 320 , determining private information from the personal information. In some embodiments, step 320 may be performed by the private information determination module 212 .

[0087] Through step 310, the personal information required to answer the aforementioned target question information can be obtained. However, this personal information may contain some personal privacy that the user does not want to disclose. Based on this, in some embodiments of this specification, in order to protect the user's personal privacy, the privacy information determination module 212 can determine the privacy information that needs to be protected from the personal information obtained in step 310.

[0088] In some embodiments, the privacy information determination module 212 can determine the privacy information that needs to be protected from the aforementioned personal information by identifying sensitive words. In some embodiments, the aforementioned personal information can be displayed to the user through the user terminal 110, and the privacy information determination module 212 can determine the privacy information that needs to be protected from the aforementioned personal information in response to the user's operation. For example, in some embodiments, the user terminal 110 can display the personal information obtained in step 310 to the user through the user interface, and the user can select or deselect the privacy information that needs to be protected through the touch screen, key operation and / or voice. In some embodiments, the user terminal 110 can output the personal information obtained in step 310 to the user through voice, and the user can determine the privacy information that needs to be protected through the touch screen, key operation and / or voice.

[0089] In some embodiments, considering that users may have reservations during the preset information filling and interaction process due to concerns about privacy leakage (for example, not entering all information or not entering true information), however, when the operation reaches the step of determining the private information that needs to be protected, a certain degree of trust may be increased, and therefore, there may be a need to supplement personal information at this time. Based on this, in order to meet the user's need to supplement personal information, in some embodiments, the private information determination module 212 can, in response to the user's operation, add additional information that is not included in the aforementioned personal information (i.e., the personal information determined in step 310), and treat this additional information as private information that needs to be protected.

[0090] In some embodiments, the additional information supplemented by the user may conflict with part of the aforementioned personal information (for example, the user enters false information before supplementing the additional information). In this case, the privacy information determination module 212 can use the additional information to replace the corresponding part of the personal information determined in step 310.

[0091] In some embodiments, the additional information entered by the user may be expressed in an informal manner. To ensure that the additional information can be used normally in subsequent processes, semantic extraction can be performed on the additional information entered by the user to obtain the corresponding semantic text, which can then be used as the private information that needs to be protected.

[0092] Step 330 , encode the private information to obtain an encoding vector corresponding to the private information. In some embodiments, step 330 may be performed by the encoding module 213 .

[0093] In some embodiments, in order to protect the aforementioned private information and prevent it from being leaked during the application process, the private information determined in step 320 can be encoded by the encoding module 213 to obtain a coding vector corresponding to the private information. In this specification, there can be a mapping relationship between the coding vector and the aforementioned private information. In other words, the coding vector can contain the user's private information. By converting the user's private information into the coding vector and then using it, not only can corresponding personalized reply content be generated based on the user's personal information (including the aforementioned private information) in the subsequent process, but it can also prevent the leakage of user privacy during use, thereby improving the accuracy and privacy security of personalized interactive services.

[0094] In some embodiments, the aforementioned encoding vector can be obtained by processing the private information determined in step 320 using a trained first model. The first model may have an embedding function (embedding function, i.e., converting unstructured data such as text, images, and voice into structured vector data), which can convert the user's private information into an encoding vector. The encoding vector refers to a vector that converts the text or voice data corresponding to the aforementioned private information into a numerical representation. In some embodiments, the encoding vector may be a high-dimensional vector, which may contain features corresponding to multiple dimensions. In some embodiments, the high-dimensional vector may point to a number of quantitative parameters greater than a specific threshold, such as 50, 100, 200, 1000, etc. In some embodiments, the first model may be configured in the user terminal 110 or other third-party device that can be recognized by the user and the product party. The training method of the first model can be referred to other locations in this specification (such as step 340 and its related description), and will not be described in detail here.

[0095] Step 340 : Obtain second data generated based on the encoding vector and at least part of the first data, wherein the second data includes personalized reply content corresponding to the first data. In some embodiments, step 340 may be performed by reply content acquisition module 214 .

[0096] After obtaining the encoding vector corresponding to the user privacy information through the above steps, the reply content acquisition module 214 can obtain second data generated based on the encoding vector and at least part of the information in the first data, wherein at least part of the information in the first data includes the aforementioned question information, and the second data includes personalized reply content corresponding to the question information in the first data.

[0097] In some embodiments, the second data can be obtained by processing the aforementioned coding vector and at least part of the information in the first data through a trained second model. In some embodiments, the second model can be configured in the user terminal 110 or the service terminal 120. Specifically, when the second model is configured in the user terminal 110, the reply content acquisition module 214 can process the question information contained in the coding vector and the first data locally in the user terminal 110 to obtain the second data. When the second model is configured in the service terminal 120, the reply content acquisition module 214 can send the coding vector and the question information contained in the first data to the service terminal 120, and then receive the second data obtained by the service terminal 120 based on the coding vector and the question information contained in the first data.

[0098] In the embodiments of this specification, the second model is similar to the first model and may also have an embedding function. In some embodiments, the second model may include two training stages, wherein the first training stage (also called the preliminary training stage) may be trained using a number of sample personal information (plaintext data) and sample question information. After the first training stage is completed, the second model may acquire the ability to convert the sample personal information into a coding vector. In the subsequent process, the second model may be configured to process the personal information that has not been encoded and the question information contained in the aforementioned first data to obtain the corresponding coding vector.

[0099] In some embodiments, after the second model completes the first training phase, the portion of the second model that contains the Embedding function (i.e., the portion that generates the coding vector) can be split out as the aforementioned trained first model. In some embodiments, after the second model completes the first training phase, the intermediate layer data of the second model (such as the aforementioned sample personal information and its corresponding coding vector) can be used as training data to train the aforementioned first model to obtain a trained first model. For example only, in some embodiments, the aforementioned sample personal information can be input into the first model, and the coding vector obtained by processing the sample personal information with the preliminarily trained second model is used as a label to train the first model until a preset number of iterations or loss threshold is reached, and the aforementioned trained first model can be obtained.

[0100] After the first model completes training, it can be configured to encode the user's private information, thereby converting the private information into a corresponding encoding vector. Furthermore, the encoding vector output by the first model and the corresponding sample question information can be used as training data to perform secondary training on the second model, wherein the output corresponding to the encoding vector and the sample question information is the corresponding sample response content, thereby enabling the second model to acquire the ability to generate corresponding personalized response content based on the encoding vector and question information. In some embodiments, the second model can generate personalized response content corresponding to the encoding vector and question information based on a knowledge graph.

[0101] It should be pointed out that in the embodiments of this specification, by using the intermediate layer data of the preliminarily trained second model as the training data of the first model, and using the encoded vector output by the trained first model as input when the second model is trained for the second time, the second model can be better learned from the deviation between the first model and the second model, thereby further improving the accuracy of the second model. In some embodiments, by splitting out the part of the second model that contains the Embedding function as the first model, the output of the first model can be more closely matched with the input of the second model, thereby reducing information loss and noise. At the same time, the training efficiency and quality of the first model can be improved, avoiding additional design and adjustment.

[0102] Figure 6 is an exemplary flow chart of a method for protecting user privacy in a personalized interactive service, according to other embodiments of this specification. Similar to method 300, method 400 can be executed by processing logic. In some embodiments, one or more operations in the flow chart of method 400 for protecting user privacy in a personalized interactive service, shown in Figure 6, can be implemented by the service terminal 120 and / or the user terminal 110 shown in Figure 1.

[0103] 6 , in some embodiments, a method 400 configured to protect user privacy in a personalized interactive service may include:

[0104] Step 410 : Receive a coding vector and at least part of the first data input by the user, wherein the coding vector is obtained by encoding the user's private information. In some embodiments, step 410 may be performed by the receiving module 221 .

[0105] In some embodiments, step 410 can be implemented by the user terminal 110 or the service terminal 120. Specifically, when step 410 is implemented by the user terminal 110, the receiving module 221 can receive the encoding vector sent by other modules of the user terminal 110 and at least part of the first data input by the user. When step 410 is implemented by the service terminal 120, the receiving module 221 can receive the encoding vector sent by the user terminal 110 and at least part of the first data input by the user. As can be seen from the above, in the embodiments of this specification, at least part of the information in the first data includes question information. In some embodiments, the question information can be plaintext data or other processed data.

[0106] It should be noted that, in some embodiments, the data received by the receiving module 221 may include, but is not limited to, the aforementioned encoding vector and the question information contained in the first data. For example, in some embodiments, the data received by the receiving module 221 may also include personal information that has not been encoded by the encoding module 213 but is related to the question information in the first data.

[0107] In some embodiments, the question information contained in the first data and / or the personal information not encoded by the encoding module 213 may also be encoded by the encoding module 213. In other words, the data received by the receiving module 221 may be the encoding vector obtained by encoding the question information contained in the first data and the encoding vector obtained by encoding all the personal information obtained in step 310.

[0108] Step 420 : Process the encoding vector and at least part of the first data using the trained second model to obtain second data. In some embodiments, step 420 may be performed by the processing module 222 .

[0109] Similar to step 410, step 420 can be implemented by user terminal 110 or service terminal 120. When this step is implemented by user terminal 110, the second model can be configured in user terminal 110. When this step is implemented by service terminal 120, the second model can be configured in service terminal 120. For more information about the second model, please refer to other locations in this specification (such as the relevant discussion in Figure 5) and will not be repeated here.

[0110] Step 430 : Send the second data to present the personalized answer content corresponding to the question information included in the first data to the user. In some embodiments, step 430 may be performed by the sending module 223 .

[0111] In some embodiments, step 430 may be implemented by the user terminal 110. Specifically, when this step is implemented by the user terminal 110, the sending module 223 may send the second data processed by the processing module 222 to other modules (e.g., a display module) of the user terminal 110 to display the personalized answer content corresponding to the question information included in the first data to the user.

[0112] In some embodiments, step 430 may also be implemented by the service terminal 120. When this step is implemented by the service terminal 120, the sending module 223 may send the second data processed by the processing module 222 to the user terminal 110, and display the personalized answer content corresponding to the question information included in the first data to the user through the user terminal 110.

[0113] In some embodiments, steps 310 to 340 above can be implemented by user terminal 110, and steps 410 to 430 can all be implemented by service terminal 120. During the interaction between user terminal 110 and service terminal 120, user terminal 110 can extract the aforementioned first data to obtain target question information, and then send a data acquisition instruction related to the target question information to service terminal 120. Furthermore, service terminal 120 can receive the data acquisition instruction and, based on the data acquisition instruction, obtain personal information related to the target question information, and then send the personal information related to the target question information to user terminal 110. Finally, user terminal 110 can receive the personal information related to the target question information issued by service terminal 120 based on the data acquisition instruction.

[0114] In some embodiments, the user terminal 110 may extract the aforementioned first data to obtain target question information, and then send the target question information to the service terminal 120. Furthermore, the service terminal 120 may receive the target question information and, based on the target question information, filter personal information related to the target question information from the preset information input by the user. Subsequently, the service terminal 120 may detect whether the personal information related to the target question information meets the corresponding reply conditions. If so, the personal information related to the target question information will be sent to the user terminal 110. If not, while sending the personal information related to the target question information to the user terminal 110, an inquiry instruction will be sent to inquire about the personal information of the aforementioned target question information, thereby guiding the user to supplement the necessary information configured to answer the target question information.

[0115] It should be noted that in the embodiments of this specification, by sending an inquiry instruction to guide the user to supplement the necessary information to answer the target question information when it is detected that the current information does not meet the answer conditions corresponding to the target question information, the reference information can be made more comprehensive and the personalized answer content obtained in the subsequent processing process can be more accurate, thereby improving the user experience.

[0116] In summary, the beneficial effects that may be brought about by the embodiments of this specification include but are not limited to: (1) In the method and system configured to protect user privacy in personalized interactive services provided in some embodiments of this specification, by converting the user's privacy information into the coding vector and then using it, not only can corresponding personalized reply content be generated based on the personal information containing the user's privacy information in the subsequent process, but also the user's privacy can be prevented from being leaked during the use of the information, thereby improving the accuracy of personalized interactive services while improving the security of the user's privacy information; (2) In the method and system configured to protect user privacy in personalized interactive services provided in some embodiments of this specification, by using the intermediate layer data of the second model that has been preliminarily trained as the training data of the first model, and using the coding vector output by the trained first model as input when the second model is trained for the second time, the second model can be made to better learn the first model and the first model. The deviation between the two models is reduced, thereby further improving the accuracy of the second model; (3) In the method and system configured to protect user privacy in personalized interactive services provided in some embodiments of the present specification, by splitting the part of the second model containing the Embedding function as the first model, the output of the first model can be made to match the input of the second model more closely, thereby reducing information loss and noise. At the same time, the training efficiency and quality of the first model can be improved, avoiding additional design and adjustment; (4) In the method and system configured to protect user privacy in personalized interactive services provided in some embodiments of the present specification, by sending an inquiry instruction to guide the user to supplement the necessary information configured to answer the target question information when it is detected that the current information does not meet the answer condition corresponding to the target question information, the reference information can be made more comprehensive and the personalized answer content obtained in the subsequent processing process can be made more accurate, thereby improving the user experience.

[0117] It should be noted that different embodiments may produce different beneficial effects. In different embodiments, the beneficial effects that may be produced may be any one or a combination of the above, or any other possible beneficial effects.

[0118] This specification also provides a computer-readable storage medium that can be configured to store computer instructions. When executed by a processor, the computer instructions can implement the method for protecting user privacy in a personalized interactive service described in any embodiment of this specification. For more details about this method, please refer to the above text and will not be repeated here.

[0119] An embodiment of this specification also provides a computer program product, including a computer program or instructions, which, when executed by a processor, can implement the method described in any embodiment of this specification for protecting user privacy in a personalized interactive service.

[0120] While the basic concepts have been described above, it will be apparent to those skilled in the art that the detailed disclosure is merely illustrative and does not limit this specification. Although not explicitly stated herein, various modifications, improvements, and revisions to this specification may be made by those skilled in the art. Such modifications, improvements, and revisions are suggested in this specification and remain within the spirit and scope of the exemplary embodiments of this specification.

[0121] This specification also uses specific terms to describe the embodiments of this specification. For example, "one embodiment," "an embodiment," and / or "some embodiments" refer to a feature, structure, or characteristic associated with at least one embodiment of this specification. Therefore, it should be emphasized and noted that references to "one embodiment," "an embodiment," or "an alternative embodiment" two or more times in different locations in this specification do not necessarily refer to the same embodiment. Furthermore, certain features, structures, or characteristics of one or more embodiments of this specification may be appropriately combined.

[0122] In addition, it will be understood by those skilled in the art that various aspects of this specification may be illustrated and described by a number of patentable categories or situations, including any new and useful process, machine, product or combination of substances, or any new and useful improvements thereto. Accordingly, various aspects of this specification may be performed entirely by hardware, entirely by software (including firmware, resident software, microcode, etc.), or by a combination of hardware and software. The above hardware or software may be referred to as "data blocks", "modules", "engines", "units", "components" or "systems". In addition, various aspects of this specification may be represented as a computer product located in one or more computer-readable media, which includes computer-readable program code.

[0123] A computer storage medium may include a propagated data signal embodying the computer program code, for example, in baseband or as part of a carrier wave. The propagated signal may be in a variety of forms, including electromagnetic, optical, or any suitable combination thereof. A computer storage medium may be any computer-readable medium other than a computer-readable storage medium that can be connected to an instruction execution system, apparatus, or device to communicate, propagate, or transfer the program for use. The program code on the computer storage medium may be transmitted via any suitable medium, including radio, cable, fiber optic cable, RF, or similar media, or any combination of these.

[0124] The computer program codes required for the operation of the various parts of this specification can be written in any one or more programming languages, including object-oriented programming languages ​​such as Java, Scala, Smalltalk, Eiffel, JADE, Emerald, C++, C#, VB.NET, Python, etc., conventional procedural programming languages ​​such as C, Visual Basic, Fortran2003, Perl, COBOL2002, PHP, ABAP, dynamic programming languages ​​such as Python, Ruby and Groovy, or other programming languages. The program code can be run entirely on the user's computer, or as a separate software package on the user's computer, or partly on the user's computer and partly on a remote computer, or entirely on a remote computer or processing device. In the latter case, the remote computer can be connected to the user's computer through any network form, such as a local area network (LAN) or a wide area network (WAN), or connected to an external computer (e.g., via the Internet), or in a cloud computing environment, or used as a service such as software as a service (SaaS).

[0125] In addition, unless expressly stated in the claims, the order of the processing elements and sequences described in this specification, the use of alphanumeric characters, or the use of other names are not configured to limit the order of the processes and methods of this specification. Although the above disclosure discusses some of the invention embodiments currently considered useful through various examples, it should be understood that such details are for illustrative purposes only, and the appended claims are not limited to the disclosed embodiments. On the contrary, the claims are intended to cover all modifications and equivalent combinations that are consistent with the spirit and scope of the embodiments of this specification. For example, although the system components described above can be implemented by hardware devices, they can also be implemented only by software solutions, such as installing the described system on an existing processing device or mobile device.

[0126] Similarly, it should be noted that, in order to simplify the presentation of this specification and thus facilitate understanding of one or more embodiments of the invention, the foregoing descriptions of the embodiments of this specification sometimes combine multiple features into a single embodiment, figure, or description thereof. However, this disclosure method does not imply that the subject matter of this specification requires more features than those recited in the claims. In fact, an embodiment may have fewer features than all of the features of a single disclosed embodiment.

[0127] Finally, it should be understood that the embodiments described in this specification are intended only to illustrate the principles of the embodiments of this specification. Other variations may also fall within the scope of this specification. Therefore, by way of example and not limitation, alternative configurations of the embodiments of this specification may be considered consistent with the teachings of this specification. Accordingly, the embodiments of this specification are not limited to the embodiments explicitly described and illustrated in this specification. Industrial Applicability

[0128] By adopting the above scheme, the user's private information is encoded to obtain the encoding vector corresponding to the private information, and then the corresponding personalized reply content is obtained based on the encoding vector. This not only generates corresponding personalized reply content based on personal information containing user private information, but also prevents user privacy from being leaked during the use of information, thereby improving the accuracy of personalized interactive services while improving the security of user privacy information.

Claims

1. A method configured to protect user privacy in a personalized interactive service, characterized in that: The method comprises: Acquire personal information related to the user based on first data input by the user; Determine private information from the personal information; Encoding the private information to obtain a coding vector corresponding to the private information; Second data generated based on the encoding vector and at least part of the information in the first data is obtained, wherein the second data includes personalized reply content corresponding to the first data.

2. The method according to claim 1, characterized in that The acquiring of personal information related to the user based on first data input by the user includes: The personal information related to the question information included in the first data is screened from the preset information input by the user, and / or the personal information related to the question information is extracted from the first data.

3. The method according to claim 2, characterized in that The preset information is input by a user terminal and stored locally on the user terminal, and the step of filtering personal information related to the problem information included in the first data from the preset information input by the user includes: Extracting question information from the first data to obtain target question information; and filtering personal information related to the target question information from the preset information.

4. The method according to claim 2, characterized in that The preset information is input by the user end and sent to the server end for storage. The filtering of personal information related to the problem information included in the first data from the preset information input by the user includes: The first data is extracted to obtain target problem information; and a data acquisition instruction related to the target problem information is sent to the server, and personal information related to the target problem information is received from the server based on the data acquisition instruction.

5. The method according to claim 2, characterized in that The step of extracting personal information related to the question information from the first data includes: Detecting whether the personal information related to the question information included in the first data, which is screened out from the preset information input by the user, meets the answer condition corresponding to the question information; If not satisfied, the user is questioned, and personal information related to the question information is extracted from the first data input by the user in response to the question.

6. The method according to claim 5, characterized in that The detecting whether the personal information related to the question information included in the first data and screened out from the preset information input by the user satisfies the answer condition corresponding to the question information includes: Through a pre-configured detection table, query whether the personal information screened from the preset information meets the answer condition corresponding to the question information, wherein the detection table includes necessary information corresponding to multiple preset questions; If the personal information selected includes necessary information corresponding to the question information, determining that the personal information selected meets the answer condition corresponding to the question information; If the screened personal information does not include necessary information corresponding to the question information, it is determined that the screened personal information does not meet the answer condition corresponding to the question information.

7. The method according to any one of claims 1 to 6, characterized in that Determining the private information from the personal information includes: The personal information is displayed to the user, and private information is determined from the personal information in response to the user's operation; wherein the user's operation at least includes selecting private information that needs to be protected.

8. The method according to any one of claims 1 to 7, characterized in that The determining of the private information from the personal information further includes: In response to the user's operation, additional information not included in the personal information is added, and the additional information is used as privacy information that needs to be protected.

9. The method according to claim 8, characterized in that The method further comprises: According to the additional information, the corresponding part of the personal information is replaced.

10. The method according to claim 8 or 9, characterized in that The taking the additional information as the privacy information to be protected includes: Performing semantic extraction on the additional information to obtain corresponding semantic text; The semantic text is used as the private information.

11. The method according to any one of claims 1 to 10, characterized in that: The encoding vector is obtained by processing the private information through a trained first model, and the second data is obtained by processing the encoding vector and at least part of the information in the first data through a trained second model, wherein: The trained first model is trained based on the intermediate layer data of the preliminarily trained second model, or is obtained by splitting it from the preliminarily trained second model; the trained second model is obtained by secondary training based on the output data of the trained first model.

12. A method configured to protect user privacy in a personalized interactive service, characterized in that: The method comprises: Receiving a coding vector and at least part of information in first data input by a user, wherein the coding vector is obtained by encoding private information of the user; Processing the encoding vector and at least part of the information in the first data by using a trained second model to obtain second data; The second data is sent to display personalized answer content corresponding to the question information included in the first data to the user.

13. The method according to claim 12, characterized in that The encoding vector is obtained by processing the private information through a trained first model, the trained first model is trained based on the intermediate layer data of a preliminarily trained second model or is obtained by splitting from the preliminarily trained second model, and the trained second model is obtained by secondary training based on the output data of the trained first model.

14. The method according to claim 12 or 13, characterized in that Before receiving the encoding vector and a small portion of information in the first data input by the user, the method further includes: Receiving a data acquisition instruction related to the problem information; The personal information related to the question information is acquired based on the data acquisition instruction, and the personal information related to the question information is sent.

15. The method according to any one of claims 12 to 14, characterized in that: Before receiving the encoding vector and at least part of the information in the first data input by the user, the method further includes: Receiving target question information obtained by extracting the first data; Based on the target question information, filtering personal information related to the target question information from preset information input by the user; Detecting whether the personal information related to the target question information meets the answering conditions corresponding to the target question information; If the conditions are met, personal information related to the target question information is sent; if not met, while sending the personal information related to the target question information, an inquiry instruction is sent to inquire about the personal information for the target question information.

16. A system configured to protect user privacy in a personalized interactive service, characterized in that: The system comprises: A personal information acquisition module, configured to acquire personal information related to the user based on first data input by the user; a private information determination module, configured to determine private information from the personal information; an encoding module, configured to encode the private information to obtain an encoding vector corresponding to the private information; The reply content acquisition module is configured to obtain second data generated based on the encoding vector and at least part of the information in the first data, wherein the second data includes personalized reply content corresponding to the first data.

17. A system configured to protect user privacy in a personalized interactive service, characterized in that: The system comprises: A receiving module, configured to receive a coding vector and at least part of information in first data input by a user, wherein the coding vector is obtained by encoding the private information of the user; a processing module configured to process the encoding vector and at least part of the information in the first data by using a trained second model to obtain second data; The sending module is configured to send the second data to present the personalized answer content corresponding to the question information included in the first data to the user.

18. A system configured to protect user privacy in a personalized interactive service, characterized in that: include: A personal information acquisition module, configured to acquire personal information related to the user based on first data input by the user; a private information determination module, configured to determine private information from the personal information; an encoding module, configured to encode the private information to obtain an encoding vector corresponding to the private information; a processing module configured to process the encoding vector and at least part of the information in the first data by using a trained second model to obtain second data, wherein the second data includes personalized reply content corresponding to the first data; A presentation module is configured to present the personalized reply content included in the second data to the user.

19. A computer-readable storage medium storing computer instructions, which implement the method according to any one of claims 1 to 15 when the computer instructions are executed by a processor.

20. A computer program product comprising a computer program or instructions, characterized in that When the computer program or instruction is executed by a processor, the method according to any one of claims 1 to 15 is implemented.

Citation Information

Patent Citations

  • Intelligent question-answering method and device based on federated learning, equipment and storage medium

    CN111414457A

  • Medical question and answer service method, system and equipment based on artificial intelligence

    CN116612906A

  • Text robot response method and device, processor and storage medium

    CN117216224A

  • Method and system for protecting user privacy, storage medium and program product

    CN118036057A

  • Message providing device and non-transitory computer readable medium

    US20190297032A1