一种融合多种安全机制的智能问答系统
An Intelligent Question-Answering System Integrating Multiple Security Mechanisms
摘要: 目前在政府企业内部有很多基于大模型的问答系统,这些系统已经建立了自己的防护机制,但有的系统防护存在不足,甚至有的系统存在重大的安全隐患。这给大模型问答系统,尤其是系统内的数据带来的极大风险。本文提供一种基于多种安全机制的防护机制,涉及多因子认证、参数签名、JWT token、数据加密传输和存储、空间隔离、基于RBAC的权限管理、审计日志、异常行为识别机制、敏感信息检测和提示词防护,这些机制有效保护了大模型问答系统的数据安全。
Abstract: Large language model–based question-answering systems are now widely deployed across government and enterprise sectors. Although basic protection mechanisms exist, some systems remain inadequately defended, and others harbor critical security vulnerabilities. This paper presents a multi-layered security framework designed to mitigate these risks. The proposed framework incorporates multi-factor authentication, parameter signing, JWT tokens, encrypted transmission and storage, tenant isolation, RBAC-based access control, audit trails, anomaly detection, sensitive information detection and prompt protection. Together, these safeguards ensure the confidentiality, integrity, and availability of data within LLM-powered QA systems.
文章引用:郭峰. 一种融合多种安全机制的智能问答系统[J]. 计算机科学与应用, 2026, 16(9): 154-168. https://doi.org/10.12677/csa.2026.169297

参考文献

[1] 粟云森. 基于大模型的政务多轮问答系统关键技术研究[D]: [硕士学位论文]. 广东: 佛山大学, 2025.
[2] Sun, H., Yuan, D., Li, M. and Deng, Y. (2026) CoRe-DoS: Inference-Time Denial-of-Service Attack against Retrieval-Augmented Generation. Computer Networks, 287, Article 112567.
https://doi.org/10.1016/j.comnet.2026.112567
[3] Khonde, S.R., Dharwadkar, S.N., Chilveri, P.G., et al. (2026) End-to-End Security Threats and Defenses in Retrieval-Augmented LLM Agents. Discover Artificial Intelligence.
https://doi.org/10.1007/s44163-026-01726-x
[4] Ammann, L., Ott, S., Landolt, C.R. and Lehmann, M.P. (2025) Securing RAG: A Risk Assessment and Mitigation Framework. 2025 IEEE Swiss Conference on Data Science (SDS), Zürich, 26-27 June 2025, 127-134.
https://ieeexplore.ieee.org/abstract/document/11081501
[5] Yang, P., Zheng, H., Luo, Y., Liu, X., Wang, J., Wang, H., et al. (2026) ShieldRAG: Safeguarding Retrieval-Augmented Generation from Untrusted Knowledge Bases. Proceedings of the AAAI Conference on Artificial Intelligence, 40, 34286-34294.
https://doi.org/10.1609/aaai.v40i40.40725
[6] Choudhary, S., Palumbo, N., Hooda, A., Dvijotham, K. and Jha, S. (2026) Through the Stealth Lens: Attention-Aware Defenses Against Poisoning in RAG.
https://arxiv.org/pdf/2506.04390
[7] Masoud, A.A., Arazzi, M. and Nocera, A. (2026) SD-RAG: A Framework for Secure Selective Disclosure in Retrieval-Augmented Generation against Single-Turn Prompt-Leaking Attacks. Expert Systems with Applications, 331, Article 133154.
https://doi.org/10.1016/j.eswa.2026.133154
[8] Afiffy, M., Fakhr, M.W. and Maghraby, F.A. (2026) Enhancing Adversarial Resilience in Semantic Caching for Secure Retrieval Augmented Generation Systems. Scientific Reports, 16, Article No. 5936.
https://doi.org/10.1038/s41598-026-36721-w
[9] 丁文豪. 恶意爬虫主动防御技术研究与实现[D]: [硕士学位论文]. 北京: 北京邮电大学, 2019.
[10] 周毅, 宁亮, 王鸥, 等. 基于Python的网络爬虫和反爬虫技术研究[J]. 现代信息科技, 2021, 5(21): 149-151.
[11] 任爽. 基于Web字体渲染技术的反爬虫应用[J]. 电脑编程技巧与维护, 2024(8): 148-150.
[12] 马军, 王效武, 朱永川, 等. 基于对抗样本生成的验证码反爬虫机制研究[J]. 应用科技, 2021, 48(6): 45-50.
[13] 苏谈. 基于深度学习的文本隐私信息检测研究[D]: [硕士学位论文]. 北京: 中国科学技术大学, 2025.
[14] 袁明, 邹其霖, 袁文骐, 等. 大语言模型提示词注入攻击与防御综述[J]. 信息网络安全, 2026, 26(3): 341-354.
[15] 雷惊鹏. 一种基于角色访问控制模型的设计与实现[J]. 长沙大学学报, 2022, 36(5): 15-23.
[16] 韦卫, 王德杰, 张英, 等. 基于SSL的安全WWW系统的研究与实现[J]. 计算机研究与发展, 1999(5): 108-113.
[17] 孙林红, 叶顶锋, 吕述望, 等. 传输层安全协议的安全性分析及改进[J]. 软件学报, 2003(3): 518-523.
[18] 童敏, 张黎娜, 梁伍七. 基于JWT的分布式系统认证授权机制设计和实现[J]. 合肥师范学院学报, 2022, 40(3): 7-10.
[19] 陈宇收, 饶宏博, 王英明, 等. 基于JWT的前后端分离程序设计研究[J]. 电脑编程技巧与维护, 2019(9): 11-12.
[20] 许丹丹, 李沛谕, 张世倩, 等. 统一身份认证系统中的多因子身份认证方法[J]. 福州大学学报(自然科学版), 2023, 51(5): 616-620.
[21] 张虎强, 洪佩琳, 李津生, 等. 用户名密码认证方案的安全性分析及解决方案[J]. 计算机工程与应用, 2006(33): 102-106+190.
[22] 胡文俊. 网络安全视域下的身份认证技术研究[J]. 科技创新与应用, 2022, 12(7): 152-154.
[23] 顾佳跃, 叶健, 夏天. 面向新兴安全挑战的多因子认证技术演进与策略优化研究[C]//中国计算机用户协会网络应用分会. 中国计算机用户协会网络应用分会2025年第二十九届网络新技术与应用年会论文集. 2025: 238-241.
[24] 袁薇, 田秀霞. 基于属性的访问控制策略混合生成方法[J]. 计算机工程与设计, 2024, 45(10): 2914-2921.