Xiaohongshu Shield to Risk Decision

一枚请求签名,只覆盖证据链的一段;设备画像、内容关系与业务处置仍属于服务端边界

Xiaohongshu Shield to risk decision evidence boundaries Historical request context and device-side state feed a native Shield component. The protected envelope reaches server validation, while profile resolution, content graph analysis and tiered decisions remain server-side and externally unconfirmed. APP PROCESS / CLIENT-CONTROLLED PROTOCOL EDGE SERVER / EXTERNALLY UNOBSERVABLE outcomes may update confidence and graph edges Request Context path / params / platform historical sample observation C grade Device-side Evidence IDs / runtime / apps network / sensors / failures policy categories, not wire schema A grade Native Shield versioned request protection libshield.so (historical) current library / algorithm unknown historical C-grade evidence only Protected Envelope HTTPS + Shield format / freshness / state valid format != authorization Protocol Validation schema / binding / replay exact online semantics unknown B / ? Profile Resolution candidate / drift / conflict profile ID and confidence unknown no public lifecycle experiment Account + Content Graph account / note / comment / follow network / creator / merchant / order action type + time sequence architectural mapping, not disclosure Tiered Decision allow / limit / challenge review / delay / deny / feedback thresholds and reasons unknown A: official source B: architecture inference C: historical sample ?: unconfirmed

可以确认

  • 历史版本存在 Native 请求保护边界
  • 官方政策覆盖多类设备与运行证据
  • 当前实现仍处于外部不可确认范围

不能确认

  • 当前 Shield 的完整输入与服务端校验
  • 设备画像的注册、合并与置信度
  • 账号、内容和交易处置的具体阈值

审计重点

  • 请求签名、设备证据和业务授权分层
  • 记录版本、来源、失败与漂移语义
  • 用新鲜挑战和业务关系抵抗单层复现