Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

13011results about "Platform integrity maintainance" patented technology

Systems and Methods for Protecting Machine Learning (ML) Units, Artificial Intelligence (AI) Units, Large Language Model (LLM) Units, Deep Learning (DL) Units, and Reinforcement Learning (RL) Units

Systems and methods for protecting and fortifying machine learning engines, artificial intelligence (AI) engines, large language models, deep learning engines, reinforcement learning engines, and AI-based agentic units. An Offline Protection Unit analyzes characteristics of a Protected Engine, and performs offline fortification of the Protected Engine against attacks; by changing operational properties or operational parameters of the Protected Engine to reduce its vulnerability to attacks. An Online Protection Unit performs analysis of at least one of: (i) inputs that are intended to be inputs of the Protected Engine, (ii) outputs that are generated by the Protected Engine; and based on the analysis, dynamically performs online fortification of the Protected Engine against attacks; by dynamically changing operational properties or operational parameters of the Protected Engine to reduce its vulnerability to attacks.
Owner:DEEPKEEP LTD

System and method for ai safety red-teaming with policy fuzzing and adversarial prompting

The present invention discloses a system and method for performing artificial intelligence (AI) safety red-teaming with integrated policy fuzzing and adversarial prompting to systematically identify, characterize, and mitigate unsafe or non-compliant behaviors in AI models. The disclosed invention automates the process of generating, executing, and analyzing adversarial test cases through coordinated functional units comprising a policy fuzzing unit, an adversarial prompting unit, an execution sandbox, a telemetry processing unit, a scoring and triage processor, and a cryptographic provenance processor. The system applies grammar-driven and reinforcement-based fuzzing techniques to vary policy descriptors, model configuration parameters, and instruction hierarchies, while a learned adversarial prompt generator synthesizes contextually coherent adversarial prompts optimized for maximum policy violation likelihood. The generated prompts and policy vectors are executed in an isolated, instrumented sandbox that records input-output interactions, timing characteristics, and intermediate representations.
Owner:MOGALI SUNEEL KUMAR +3

Autonomous agent observation and control

Systems, methods, and devices that relate to monitoring and managing autonomous agents are disclosed. In one example aspect, the method includes receiving activity data from autonomous agents in an operational environment, deploying static and dynamic observing agents to monitor expected behavior and deviations, detecting a deviation by an autonomous agent, determining the cause through analysis, performing a mitigative action based on the cause, and executing a preventative action to block similar future deviations. The method may also involve configuring observing agents with different observation modalities, periodically modifying observation parameters unpredictably, facilitating direct communication between observing agents, resolving conflicts in observations, and updating observation policies. Mitigative actions can include disabling credentials, rerouting communications, and logging actions. Preventative measures may involve updating behavioral policies and adjusting agent parameters to disincentivize problematic behaviors.
Owner:CITIBANK N A

Cybersecurity threat detection and mitigation classification system

In some implementations, a cybersecurity threat detection and mitigation system is provided. The system refines an artificial intelligence (AI) model with a corpus of historical data that represents security events that occurred, queries that were submitted by security analysts in response to the security events, and actions that were performed for mitigating the security events. Telemetry data that corresponds to behavior and performance of a computer network is collected and provided to the AI model. Based on the telemetry data, the AI model predicts a potential security threat to the computer network and performs an assessment of risk to the computer network. When the assessment of risk to the computer network indicates that the potential security threat is an actual security threat, a security alert that corresponds to the actual security threat is triggered. Other embodiments are described and claimed.
Owner:ARCTIC WOLF NETWORKS INC

Cloud compliance monitoring for a cloud compute environment managed by a container orchestrator

Cloud compliance monitoring for a cloud compute environment managed by a container orchestrator may be performed by a data platform. For example, the data platform may obtain cluster configuration data from a control plane of a cluster that is managed by a container orchestrator within a cloud compute environment, obtain node configuration data from one or more compute nodes associated with a data plane of the cluster that is managed by the container orchestrator, and generate a compliance statement based on the cluster configuration data and node configuration data. The compliance statement may indicate a configuration posture of the cloud compute environment according to a compliance benchmark. Corresponding methods, systems, and products are also disclosed.
Owner:FORTINET INC

Compute resource risk mitigation by a data platform

An illustrative method includes identifying, based on a scan of a compute environment associated with an entity, a plurality of attack paths from one or more networks to one or more datasets associated with the entity and determining a set of one or more attack paths included in the plurality of attack paths that include a particular risk artifact. Based on one or more characteristics of the set of one or more attack paths, a risk score specific to the particular risk artifact may be determined and a risk mitigation operation associated with the particular risk artifact may be performed.
Owner:FORTINET INC

Smart recognition and consumer-centric activity recognition based system for battery management in mobile device

PendingUS20260006557A1Power managementPlatform integrity maintainanceActivity classificationElectrical battery
The present invention relates to an intelligent, context-aware battery management system embedded within a mobile device that dynamically allocates power resources based on real-time user behavior, system state, and environmental context. It incorporates a smart recognition engine that analyzes sensor-derived telemetry data to compute behavioral deviation scores, enabling the system to anticipate abnormal or emergency-prone conditions. A continuous activity classification module contextualizes user motion and geolocation to inform power policy decisions. Upon detecting significant behavioral anomalies or critically low battery conditions, an emergency mode subsystem is triggered, restricting device operations to essential functionalities while preserving energy for critical communication and navigation tasks. The system also establishes a secure, lightweight emergency communication tunnel for relaying essential metadata, including GPS and behavioral indicators, to predefined response servers.
Owner:ALMALKI SULTAN AHMED +3

Power generation side industrial control system network security target building method based on virtual-real combination

The invention discloses a virtual-real combination-based power generation side industrial control system network security target construction method. The method comprises the following steps of: constructing a virtual-real combination target environment consisting of a physical equipment layer and a virtual model layer; the heterogeneous industrial control protocol between the physical equipment layer and the virtual model layer is analyzed, protocol semantic information is extracted, and a bidirectional dynamic mapping rule of a physical equipment state and a virtual model state is generated based on the protocol semantic information; based on a state change event of the physical equipment layer, according to a bidirectional dynamic mapping rule, synchronizing changed equipment state data to the virtual model layer in real time, and simulating protocol behavior logic corresponding to the equipment state data in the virtual model layer according to a security test requirement; and based on the attack instruction or the abnormal state signal generated by the virtual model layer, according to the protocol specification format of the target physical equipment, converting the instruction or the signal into an executable control command, and driving the physical equipment layer to execute an operation corresponding to the control command.
Owner:HUANENG POWER INT INC +1

Intelligent risk identification and self-adaptive repair method, system and equipment for software supply chain and medium

The invention discloses an intelligent risk identification and self-adaptive repair method, system and device for a software supply chain and a medium, belongs to the field of network security and automatic software engineering, and aims to solve the technical problem of how to accurately and comprehensively identify software code supply chain risks including code snippets. A reliable and efficient automatic closed-loop repair scheme is provided, and the technical defects that in the prior art, the software code supply chain recognition range is limited, the repair process is rigid and the reliability is low are overcome. Analyzing the declarative dependency; meanwhile, semantic traceability based on artificial intelligence is carried out on the code snippets, and a global software material list is generated; and performing intelligent mapping on the software components in the global software bill of materials and the vulnerability database to identify risks.
Owner:SHANDONG ZHENBAI INFORMATION TECHNOLOGY CO LTD

Jailbreak detection for language models in conversational ai systems and applications

In various examples, systems and methods are disclosed relating to language model jailbreak detection using length-perplexity metrics. A system can identify a prompt for a language model—such as an LLM, VLM, etc.—and generate a perplexity score for the prompt. The system can determine, based at least on the perplexity score and a length of the prompt, that the prompt is indicative of a jailbreak attempt for the large language model. The system can restrict the prompt from input to the large language model—or block an output generated based on the prompt from being shared—responsive to determining that the prompt is indicative of the jailbreak attempt.
Owner:NVIDIA CORP

Capturing and using application-level data to monitor a compute environment

An illustrative method includes receiving, by a data platform configured to monitor the compute environment, runtime workload data collected by an agent deployed to the compute environment, wherein the runtime workload data comprises user space data collected from a user space of the compute environment and kernel space data collected from a kernel space of the compute environment. The method further includes performing, by the data platform, a monitoring operation based on the user space data and the kernel space data of the runtime workload data.
Owner:FORTINET INC

Detecting anomalous behavior of nodes in a hierarchical cloud deployment

Detecting anomalous behavior of nodes in a hierarchical cloud deployment, including: gathering data describing a cloud deployment as a hierarchy of a plurality of nodes; presenting a graph depicting behavior at a particular hierarchical level of at least a subset of the plurality of nodes; and determining whether behavior associated with a particular node deviates from normal behavior based on a hierarchical portion of plurality of nodes including the particular node.
Owner:FORTINET INC

Managed design and generation of artificial intelligence agents

Systems and methods are described for building artificial intelligence (“AI”) agents. A server can provide a user interface (UI) that includes options to select and connect various agent objects. The agent objects can include prompt objects, dataset objects, model objects, and one or more code objects. A subset of the agent objects can be identified as available for selection based on evaluation of at least one management policy associated with an administrative user. A manifest file is generated based on the connected agent objects, and the manifest is validated against dependency rules to ensure that the stages of the agent meet prerequisites for the stages. Then, the server performs a simulated execution of an agent that corresponds to the validated manifest file, including an identification of at least one execution metric associated with the simulated execution.
Owner:AIRIA LLC

Data analysis pipeline engine in a data intelligence system

Methods, systems, and computer storage media for providing a data analysis pipeline using a data analysis pipeline engine in a data intelligence system are described. A data analysis pipeline refers to a structured sequence of data processing steps that support transforming raw data into meaningful insights or actionable outcomes. The data analysis pipeline engine is an unsupervised learning pipeline based on clustering, topic modeling, and Large Language Models (LLMs). For example, the data analysis pipeline can use advanced machine learning techniques to automatically categorize emails into semantically similar clusters, enabling the data intelligence system to quickly identify and prioritize potentially high-risk emails for further investigation. The data analysis pipeline employs AI agents for context-aware graph induction relevance assessment. The AI agents employ induction and deduction loops to build and refine a data feature hypergraph (e.g., vulnerability hypergraph) that encompasses identified relevant data providing a holistic view of a contextual landscape.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Handling of certificates by intermediate actors

Handling of certificates by intermediate actors, including: receiving, by a proxy and from a client, a client certificate and a first private key; generating, by the proxy and based on the client certificate and the first private key, an intermediate certificate; generating, by the proxy and in response to a request from the client to connect to a destination, an alternate certificate for the destination; and providing, to the client, a certificate chain comprising the alternate certificate, the intermediate certificate, and the client certificate.
Owner:FORTINET INC

System and method for generating a security graph in a cloud computing environment

A cybersecurity system provides the ability to detect security risks in a cross-platform cloud solution. A unified data schema is used to abstract resources, principals and others across multiple platforms. A security graph is generated to present a unified view of cloud environments, which are then easily queried using the structure of the data schema. The solution allows a compact representation of cloud environments, which is scalable and multi-layered. Various enrichments may be added to the security graph, which are generated for example based on policies, and inspection of workloads in the cloud environment. The security graph allows for representation of production environments, staging environments, as well as code for deploying workloads in the cloud environment. Thus the solution is also able to present a complete picture of a user's entire cloud environment.
Owner:WIZ INC

Data query method and system for converting natural language into database query language

The invention provides a data query method and system for converting a natural language into a database query language, and the method comprises the steps: analyzing the natural language input of a user through a multi-modal understanding agent on the basis of constructing a dynamic knowledge graph based on metadata, combining a historical session with a business term table, eliminating ambiguity, and generating a standardized Query, a retrieval routing agent selects a query strategy according to Query complexity, simple query directly matches a cache template, complex query traverses a knowledge graph, and related tables, fields and service constraints are returned; then, an expert committee agent generates an SQL (Structured Query Language) by adopting multi-stage collaboration, executes plan pre-evaluation, and selects a version with the highest comprehensive score; the test agent simulates and executes the SQL in the isolation environment, and verifies the grammar legality and the field permission; and finally, executing the detected SQL, and processing a result. According to the method, the accuracy of converting the natural language into the SQL (NL2SQL) in a complex database scene can be effectively improved.
Owner:HI-THINK YONDERVISION (BEIJING) TECH CO LTD

Detecting package execution for threat assessments

Detecting package execution for threat assessments, including: receiving, from an agent on a host of a cloud deployment, data describing one or more active packages installed on the host, wherein each of the one or more active packages are identified by the agent from a plurality of packages in response to detecting a corresponding file open event; and generating a threat assessment for the host describing which of the one or more active packages have any known vulnerabilities.
Owner:FORTINET INC

Intelligent contract vulnerability detection and repair system based on heterogeneous graph neural network

The invention discloses an intelligent contract vulnerability detection and repair system based on a heterogeneous graph neural network, and belongs to the technical field of block chain security, and the system comprises a contract analysis module, a multilayer graph construction module, a heterogeneous graph neural network module, a vulnerability feature library, a vulnerability recognition engine, an automatic repair module and a visual interface. After the source code of the intelligent contract is input, code analysis and standardization are completed by a contract analysis module; the multi-layer graph construction module constructs a contract internal heterogeneous graph, an inter-contract interaction graph and an ecosystem relation graph based on a graph theory; the heterogeneous graph neural network module learns a vulnerability feature mode; the vulnerability recognition engine combines the vulnerability feature library to realize vulnerability classification and risk assessment; the automatic repairing module generates a repairing scheme; and the visual interface realizes detection progress monitoring, result display and encrypted report export. The intelligent contract vulnerability detection and restoration system based on the heterogeneous graph neural network provided by the invention provides technical support for block chain digital asset security and ecological stability.
Owner:GUANGDONG UNIV OF TECH

Devices, systems, and methods for using linguistic approaches to understand malicious programs

Disclosed herein are devices, systems, and methods for detecting, understanding, and classifying malicious actions and / or behaviors in software (e.g., malware), including hidden malicious actions. Specifically, disclosed embodiments use natural language approaches to understand malicious software and provide explanations for classification results. At least one embodiment constructs a knowledge graph that includes textual explanations from source materials (e.g., articles), collecting one or more sets of dynamic program traces from one or more instances of malware, and constructing and training a model (also referred to herein as Trace-BERT) using the one or more sets of dynamic program traces. Forced execution of sample segments of computer code can also be used to identify hidden or novel malicious actions.
Owner:OCEANIT LABORATORIES INC

Agent-based monitoring of a registry space of a compute asset within a compute environment

An illustrative data platform is disclosed that may monitor a compute asset within a compute environment. This monitoring may include receiving registry data collected, by an agent deployed to the compute asset, from a registry space of the compute asset. Based on the registry data collected by the agent, the data platform may determine that a change within the registry space of the compute asset is associated with a security threat to the compute asset. Accordingly, based on the determining that the change within the registry space is associated with the security threat, the data platform may perform an action configured to facilitate remediation of the security threat. Corresponding methods, systems, and products are also disclosed.
Owner:FORTINET INC

Insecure model context protocol server remediation for artificial intelligence agents

A system detects changes in model context protocol (“MCP”) processes, and performs a remedial action. A server-sent events (“SSE”) bridge sends a request to an MCP server. A first resource profile is received from the MCP server. This is stored and compared against a second updated version of the resource profile. When a difference is detected, the SSE bridge determines whether to block a resource command from reaching the SSE bridge. The decision is based on comparing the difference to security rules, which can be defined as part of a management profile.
Owner:AIRIA LLC

Providing generative artificial intelligence (AI)-enabled notebook interfaces for a security framework

Providing generative artificial intelligence (AI)-enabled notebook interfaces for a security framework, including: receiving a request to generate a notebook interface for a security framework monitoring a cloud deployment; generating, in response to the request, the notebook interface, wherein the notebook interface comprises one or more notebook cells for interacting with the security framework, wherein the one or more notebook cells comprise a natural language input cell for querying a generative artificial intelligence (AI) model; and presenting the notebook interface.
Owner:FORTINET INC

Interactive analysis of multifaceted security threats within a compute environment

Data platforms described herein are configured to monitor a compute environment and facilitate interactive analysis of multifaceted security threats within the compute environment. Such a data platform may determine that one or more assets within the compute environment are possibly being targeted by a multifaceted security threat and present an interactive user interface. The user interface may be configured to display an identifier indicative of the multifaceted security threat, a set of selectable evidence items each associated with a different facet of the multifaceted security threat and assessed based on the monitoring of the compute environment, and a presentation pane for displaying information. As such, the data platform may detect a selection of a particular evidence item from the set of selectable evidence items and, in response to the selection, populate the presentation pane with information related to the particular evidence item. Corresponding methods, systems, and products are also disclosed.
Owner:FORTINET INC

Kernel-level monitoring for software applications

The systems and methods disclosed herein monitor application (e.g., artificial intelligence (AI) model) operations using interactions between the application and a kernel. The systems and methods disclosed herein intercept, using a kernel interface, one or more function invocations transmitted from the application (e.g., an AI model without model modification). Event record(s) are generated for one or more functions to define process identifiers, resource interaction types, timestamps, and / or resource identifiers. Observed pattern(s) for the application are identified by comparing current event record(s) with previous record(s), and the identified observed pattern(s) are evaluated against reference pattern(s) to generate score(s). Data packet(s) that indicate observed pattern(s), corresponding score(s), and / or cryptographic digital fingerprint(s) of the one or more functions are generated. The data packet(s) are transmitted to distributed ledgers for immutable storage.
Owner:CITIBANK N A

Privacy protection federated distillation and backdoor defense method for large model fine tuning

The invention provides a privacy protection federated distillation and backdoor defense method for large model fine tuning, and belongs to the technical field of artificial intelligence security and federated learning, and the method comprises the steps: 1, carrying out the distillation and core representation extraction of a data set based on contribution degree weighted federated pre-training and local neural feature function matching; step 2, self-adaptive noise back door defense processing based on multi-feature fusion; according to the method, a dataset distillation mechanism based on neural feature function matching and a self-adaptive noise defense strategy are adopted, so that effective balance of the large model among data simplification, privacy protection and backdoor defense robustness is realized; the method is of great significance in improving the safety and reliability of an artificial intelligence system in a distributed environment.
Owner:NANJING UNIV OF POSTS & TELECOMM

Kernel-based monitoring of container activity in a compute environment

An illustrative agent deployed in a compute environment monitored by a data platform is disclosed. The agent may access kernel data generated by a kernel of an operating system used within the compute environment. Based on the kernel data, the agent may detect a launch of a new container entity of a set of container entities deployed to the compute environment and managed by a container runtime executing on the operating system. Based on the detecting of the launch of the new container entity, the agent may then provide, to the data platform, agent data that indicates the launch of the new container entity. Corresponding methods, systems, and products are also disclosed.
Owner:FORTINET INC

Data privacy protection method for data governance system

The invention provides a data privacy protection method for a data governance system, and belongs to the technical field of data governance, and the method comprises the steps: carrying out the cross verification of multi-source feature data and the unique identification information of an object collected on site, generating an original data set, carrying out the sensitive information recognition and grading, and generating the preprocessing data with a sensitive grade label; core identification information in the preprocessed data is disassembled to generate standardized desensitized data conforming to privacy protection, a bidirectional encryption mapping relation is established between object unique identification information collected on site and the standardized desensitized data, an encryption index is formed, the encryption index and preset multi-dimensional compliance data are fused, and a data fusion result is obtained; generating standardized fusion data; and based on the access token, generating a differential authorization data set divided according to permission granularity, performing privacy disclosure risk assessment, generating a risk level, performing privacy processing on the risk level, and outputting the risk level to a risk control system. And the data management efficiency is improved.
Owner:BEIJING GUOXINDA DATA TECH CO LTD

Systems and methods for autonomous intelligence

Systems, methods, and apparatus are disclosed for omnimodal sensing, data fusion, and autonomous decision-making across physical and digital domains and further integrates a Multimodal Diagnostic System (MDS) and Impairment Recognition and Intervention System (IRIS) with defense architecture or a system architecture that can be compliant with the Modular Open Systems Approach (MOSA) and Sensor Open Systems Architecture (SOSA) to ensure interoperability. The system can utilize real-time multisensory fusion, cryptographic provenance via blockchain, and resilient magnetoelectric communication to support mission-critical decision-making across manned and unmanned platforms in denied or contested environments.
Owner:XGENESIS