The invention discloses a URL (
Uniform Resource Locator)
security analysis method and device for a browser-side large
language model and a medium, and relates to a network
information security technology, the method comprises the following steps: determining a session-level security contract based on terminal performance and user preference; page static scripts, dynamic behaviors, network requests and text information are collected and packaged into a unified evidence unit, and an
attack causal graph is constructed; based on the risk ontology and the rule atom
library, mapping the evidence into
basic probability distribution for the
hypothesis set, and generating evidence constraints; under the constraint of a session contract, performing multiple rounds of
attack and defense games on a causal graph through a defense agent and an
attack simulation agent which are realized by an end-side large
language model; calculating a session risk value through a
risk quantification model on the basis of a game result in combination with scores fused by a D-S evidence theory and subjected to multi-prompt LLM conjunctive calibration, and making a decision according to a self-adaptive threshold value; and high-confidence, explainable and sustainable-evolution end-side URL
security analysis in an off-network environment is realized.