Risk behavior perception method and device based on deep learning
By collecting and extracting multi-source behavioral data and using pre-trained risk assessment neural network for joint encoding, the problem of difficult to identify complex risk scenarios in the prior art is solved, and higher risk assessment accuracy and safety management efficiency are achieved.
Patent Information
- Application Number
- CN202510428728.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-04-08
AI Technical Summary
The existing technology fails to fully consider the intrinsic connections and mutual influences between different data sources in the field of risk behavior perception, making it difficult to accurately identify comprehensive risks in complex and changing risk scenarios, and the accuracy and reliability of risk assessment are low.
By collecting multi-source behavior data, performing spatiotemporal feature extraction and protocol analysis of network access records, generating behavior trajectory feature vectors and network behavior feature vectors, and using pre-trained risk assessment neural network to jointly encode the two feature vectors to generate behavior risk probability distribution.
It achieves a more accurate assessment of the risk level of user behavior, improves the accuracy and reliability of risk assessment, and quickly responds to potential risks through full process automation and intelligence, and improves the efficiency and response speed of security management.
Smart Images

Figure CN119939576A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of deep learning technology, and in particular to a risk behavior perception method and device based on deep learning. Background Art
[0002] In today's digital age, various systems and platforms face increasingly complex security threats, and effective perception of user risk behaviors has become crucial.
[0003] At present, in the field of risk behavior perception, relevant technologies have not fully taken into account the possible intrinsic connections and mutual influences between different data sources, making it difficult to accurately identify the comprehensive risks hidden behind multiple behaviors when faced with complex and changing risk scenarios, resulting in low accuracy and reliability of risk assessment.
[0004] In addition, most existing risk assessment methods use manually designed features and traditional machine learning models. Manually designed features not only consume a lot of manpower and time, but also have difficulty covering all possible risk scenarios. In addition, due to the limitations of human factors, it is difficult to mine deep features in the data. Traditional machine learning models have limited processing capabilities for complex nonlinear relationships, cannot automatically learn complex patterns and laws in data, and have difficulty adapting to changing risk behavior patterns. Summary of the invention
[0005] In view of the above-mentioned problems, in combination with the first aspect of the present invention, an embodiment of the present invention provides a risk behavior perception method based on deep learning, the method comprising: Collecting multi-source behavior data of the target user within a preset time window, wherein the multi-source behavior data includes network access records, terminal operation logs, and application program interface call sequences; Extracting spatiotemporal features from the multi-source behavior data to generate a behavior trajectory feature vector of the target user, and performing protocol parsing on the network access record to obtain a network behavior feature vector; Inputting the behavior trajectory feature vector and the network behavior feature vector into a pre-trained risk assessment neural network, and jointly encoding the behavior trajectory feature vector and the network behavior feature vector through the risk assessment neural network to generate a behavior risk probability distribution of the target user; Determine the risk level of the target user based on the risk category exceeding a preset threshold in the behavior risk probability distribution, and generate a warning signal corresponding to the risk level; The real-time alarm module is triggered according to the early warning signal, and a risk description text and a risk mitigation strategy corresponding to the risk level are sent to the security management terminal.
[0006] On the other hand, an embodiment of the present invention also provides a risk behavior perception device based on deep learning, including a processor and a machine-readable storage medium, wherein the machine-readable storage medium is connected to the processor, the machine-readable storage medium is used to store programs, instructions or codes, and the processor is used to execute the programs, instructions or codes in the machine-readable storage medium to implement the above method.
[0007] Based on the above aspects, the embodiment of the present application collects multi-source behavior data, extracts spatiotemporal features from the multi-source behavior data, and combines the protocol analysis of network access records to generate behavior trajectory feature vectors and network behavior feature vectors, and uses a pre-trained risk assessment neural network to jointly encode the two feature vectors to generate a behavior risk probability distribution, giving full play to the powerful feature learning and data analysis capabilities of the deep learning model. The joint encoding mechanism breaks the isolated mode of processing different features separately in traditional methods, and can automatically learn the complex interactive relationship between different features, so as to more accurately assess the risk level of user behavior and improve the accuracy and reliability of risk assessment. Based on the behavior risk probability distribution, the risk level is determined and a warning signal is generated, and then the real-time alarm module is triggered according to the warning signal and the risk description text and risk mitigation strategy are sent, realizing the automation and intelligence of the entire process from risk assessment to warning response, and being able to respond to potential risks in a very short time, promptly inform the security management terminal of relevant information, and provide targeted response strategies, greatly improving the efficiency and response speed of security management. BRIEF DESCRIPTION OF THE DRAWINGS
[0008] Figure 1 It is a schematic diagram of the execution flow of the risk behavior perception method based on deep learning provided in an embodiment of the present invention.
[0009] Figure 2 It is a schematic diagram of exemplary hardware and software components of a risk behavior perception device based on deep learning provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0010] The present invention will be described in detail below with reference to the accompanying drawings. Figure 1 This is a flow chart of a risk behavior perception method based on deep learning provided by an embodiment of the present invention. The risk behavior perception method based on deep learning is introduced in detail below.
[0011] Step S110 , collecting multi-source behavior data of the target user within a preset time window, wherein the multi-source behavior data includes network access records, terminal operation logs, and application program interface call sequences.
[0012] This embodiment takes the e-commerce field as an example. There are a large number of user interaction behaviors on the e-commerce platform, and it is crucial to ensure the security of user data and identify the risks in user behavior. In detail, on the e-commerce platform, it is assumed that the preset time window is one day. For the target user, its network access record contains the relevant information of the user's access to each page of the e-commerce platform during this day. For example, the user visited the electronic product classification page at 10 am, entered the product details page of a mobile phone at 10:15, and then visited the shopping cart page at 10:30, etc. The above access record contains detailed information such as the visited URLs and the time sequence of the visits.
[0013] In terms of terminal operation logs, suppose a user uses a mobile client to access an e-commerce platform. The operation log records various operations performed by the user on the mobile phone, such as the user clicking on a product image to zoom in at 11:00, sliding the screen to view more product reviews at 11:10, and entering a product search keyword at 11:30. These operation logs record in detail the type of operation and the time it occurred.
[0014] In terms of the API call sequence, when users perform various operations on the e-commerce platform, different API calls will be triggered. For example, when a user checks the inventory of a product, the API for querying the inventory will be called; when a user places an order, a series of APIs such as creating an order, calculating the price, and verifying the payment method will be called. The order of these API calls and the frequency of calls constitute the API call sequence. By collecting multi-source behavioral data such as the above-mentioned network access records, terminal operation logs, and API call sequences, we can fully understand the behavior patterns of target users on the e-commerce platform.
[0015] Step S120 , extracting spatiotemporal features from the multi-source behavior data to generate a behavior trajectory feature vector of the target user, and performing protocol parsing on the network access record to obtain a network behavior feature vector.
[0016] In detail, for the spatiotemporal feature extraction of multi-source behavior data, the timestamp sequence and operation type label of the operation event are extracted from the terminal operation log. For example, according to the operation log mentioned above, the timestamp sequence is 11 o'clock, 11:10, 11:30, etc., and the operation type labels are click on the picture, screen sliding, input search keywords, etc. The timestamp sequence is converted into a time interval distribution histogram. For example, the time interval between adjacent operations is calculated. The interval from 11 o'clock to 11:10 is 10 minutes, and the interval from 11:10 to 11:30 is 20 minutes. According to these time intervals, the distribution of different interval times is statistically calculated to form a histogram. The operation type label is mapped to an operation semantic vector. It is assumed that clicking the picture corresponds to the vector [0.1, 0.2, 0.3], the screen sliding corresponds to [0.4, 0.5, 0.6], and the input search keyword corresponds to [0.7, 0.8, 0.9], etc.
[0017] Next, extract the interface call frequency matrix from the API call sequence. Assume that the inventory query API is called 5 times and the order creation API is called once in a day, and form a matrix that reflects the call frequency of each API. Then perform sliding window statistics on the interface call frequency matrix. For example, take 1 hour as the sliding window and count the API call pattern characteristics in each window, such as some APIs are frequently called within a certain hour, but rarely called at other times.
[0018] Then, the obtained time interval distribution histogram, operation semantic vector and interface call pattern features are concatenated to obtain the initial behavior trajectory features. After that, the initial behavior trajectory features are subjected to dimensionality reduction processing. Assuming that the initial behavior trajectory features have 10 dimensions, some redundant dimensions are removed by principal component analysis and other methods, for example, they are compressed to 5 dimensions to generate compressed intermediate behavior trajectory features. Finally, the intermediate behavior trajectory features are input into the spatiotemporal attention module, which performs weighted fusion according to the temporal dependency and spatial correlation between the features, for example, giving higher weights to operations and API calls related to order placement operations, thereby generating a behavior trajectory feature vector.
[0019] For protocol parsing of network access records, parse the target protocol field in the network access records. For example, in an e-commerce platform, users use the HTTP protocol to access pages. Extract the source address (assuming that the IP address of the user's mobile phone is 192.168.1.100), target address (the server address of the e-commerce platform is 202.100.100.100), protocol type (HTTP), and data packet length (assuming that the length of each access data packet varies from 100 to 500 bytes) in the HTTP protocol. Generate address pair features based on the source address and target address, such as combining 192.168.1.100 and 202.100.100.100 into a specific address pair feature. Perform one-hot encoding on the protocol type, and the HTTP protocol is encoded as [1, 0, 0] (assuming that only HTTP, HTTPS, and FTP are encoded). The length of the data packet is segmented and counted. For example, 100-500 bytes are divided into four segments: 100-200, 200-300, 300-400, and 400-500. The number of data packets in each segment is counted to form a data packet length distribution histogram, which is then converted into a frequency domain feature vector. The address pair features, protocol type encoding vectors, and frequency domain feature vectors are fused to obtain the original network behavior features, which are then input into the convolutional neural network for local pattern extraction, such as extracting specific patterns of interaction between source addresses and target addresses, thereby generating a network behavior feature vector.
[0020] Step S130, inputting the behavior trajectory feature vector and the network behavior feature vector into a pre-trained risk assessment neural network, jointly encoding the behavior trajectory feature vector and the network behavior feature vector through the risk assessment neural network, and generating a behavior risk probability distribution of the target user.
[0021] In the e-commerce field, the pre-trained risk assessment neural network has been trained using a large amount of historical e-commerce user behavior data. The previously generated behavior trajectory feature vector and network behavior feature vector are input into the risk assessment neural network. The behavior trajectory encoding branch and network behavior encoding branch of the risk assessment neural network start working. The behavior trajectory encoding branch processes the behavior trajectory feature vector, and the network behavior encoding branch processes the network behavior feature vector. For example, the behavior trajectory encoding branch performs joint encoding based on the user's operation sequence, operation type and other information, and the network behavior encoding branch performs joint encoding based on the source address, target address, protocol type and other information of the network access.
[0022] In the joint encoding process, when the behavior trajectory feature vector shows that the user frequently modifies the order content in a short period of time, and the network behavior feature vector shows access from an abnormal source address (which can be an IP address marked as a risk source), the neural network will give this situation a higher risk weight. After calculation by the neural network, the behavior risk probability distribution of the target user is generated. Assume that the risk categories are divided into account theft risk, payment risk, product information leakage risk, etc. The behavior risk probability distribution output by the neural network may be 0.1 for account theft risk, 0.05 for payment risk, 0.03 for product information leakage risk, etc., indicating the possibility of different risk categories.
[0023] Step S140, determining the risk level of the target user based on the risk categories exceeding a preset threshold in the behavior risk probability distribution, and generating a warning signal corresponding to the risk level.
[0024] Assume that the preset threshold is 0.05. In the previously obtained behavioral risk probability distribution, the account theft risk probability is 0.1, which exceeds the preset threshold. First, traverse each risk category in the behavioral risk probability distribution, extract the risk category identifier whose probability value exceeds the preset threshold, which is the account theft risk, and generate a candidate risk set.
[0025] Obtain the weight factor (assuming it is 0.8, indicating that the risk is of high importance) and the correlation impact matrix corresponding to the risk of account theft from the predefined risk metadata database. In the correlation impact matrix, if there are both account theft risk and payment risk, the superposition intensity between them may be high because the account theft may increase the payment risk. The weight factor 0.8 of the account theft risk and its probability value 0.1 are weighted and calculated to obtain an independent risk contribution value of 0.08. Assume that the synergistic risk gain value calculated according to the correlation impact matrix is 0.02 (taking into account the correlation impact with other possible risks). Add the independent risk contribution value and the synergistic risk gain value to obtain a comprehensive risk assessment value of 0.1.
[0026] The comprehensive risk assessment value 0.1 is input into the segmented mapping function, and the corresponding discretized risk level number is determined according to the preset level division interval. Assuming that 0-0.05 is low risk level number 1, 0.05-0.15 is medium risk level number 2, and above 0.15 is high risk level number 3, the medium risk level number 2 is obtained here.
[0027] Query the warning signal template library according to the discretized risk level number 2, and extract the warning signal format framework and filling field rules that match the number. Obtain the description text of the account theft risk (such as "The account may be detected to be at risk of theft, and there may be abnormal login behavior") and mitigation strategy entries (such as "Prompt the user to change the password and add login verification methods") from the risk knowledge base. Insert the description text into the corresponding placeholder of the warning signal format framework according to the filling field rules to generate the original warning signal text. Perform a grammatical structure check on the original warning signal text, correct possible semantic conflicts and logical breakpoints, and generate compliant warning signal content. Encode the current timestamp (for example, 15:00 on October 1, 2023) and risk level number 2 as a protocol header identification segment, and perform data splicing of the compliant warning signal content and the protocol header identification segment to generate a final warning signal with an integrity tag.
[0028] Step S150, triggering a real-time alarm module according to the early warning signal, and sending a risk description text and a risk mitigation strategy corresponding to the risk level to a security management terminal.
[0029] In detail, the risk level number 2 and the embedded timestamp 15:00, October 1, 2023 can be parsed from the protocol header identification segment of the warning signal. Based on the risk level number 2, the corresponding transmission protocol type (assuming it is the Secure Sockets Layer protocol SSL) and priority code (assuming it is the medium priority code 2) are extracted from the risk policy library.
[0030] Then, verify the validity of the digital signature of the final warning signal. If the signature verification fails, a data integrity alarm is triggered and the transmission process is terminated. Here, it is assumed that the digital signature verification passes. Then extract the risk description text field ("Account theft risk is detected, there may be abnormal login behavior") and the risk mitigation strategy field ("Prompt the user to change the password and add a login verification method") in the compliance warning signal content.
[0031] Next, the risk description text field is converted into a formatted text stream that complies with the SSL protocol according to the SSL transmission protocol type, and the risk mitigation policy field is split into independent policy entries and numbered in execution order, such as "1. Prompt the user to change the password; 2. Add a login verification method". The formatted text stream and the numbered policy entries are encapsulated to generate an alarm transmission data packet containing a protocol header identification segment, a risk level number 2, and a timestamp of 15:00 on October 1, 2023, and a checksum field is appended to the end of the alarm transmission data packet.
[0032] Finally, the corresponding transmission channel in the real-time alarm module is activated according to the priority code 2, and the alarm transmission data packet is loaded into the transmission buffer of the transmission channel. In the sending buffer, the alarm transmission data packet is processed by byte stream segmentation, assuming that it is divided into 3 data segments of equal length and segment sequence identifiers 1, 2, and 3 are added to each data segment. Based on the retransmission mechanism rules defined by the SSL transmission protocol type, the data segments are injected into the network interface queue of the transmission channel in the order of sequence identifiers, triggering the network interface queue to initiate an asynchronous transmission request to the preset receiving port of the security management terminal, thereby sending the risk description text and risk mitigation strategy to the security management terminal, so that security managers can take corresponding measures to ensure the safety of e-commerce platform users.
[0033] Based on the above steps, the embodiment of the present application collects multi-source behavior data, extracts spatiotemporal features from the multi-source behavior data, and combines the protocol analysis of network access records to generate behavior trajectory feature vectors and network behavior feature vectors. The pre-trained risk assessment neural network is used to jointly encode the two feature vectors to generate a behavior risk probability distribution, giving full play to the powerful feature learning and data analysis capabilities of the deep learning model. The joint encoding mechanism breaks the isolated mode of processing different features separately in the traditional method, and can automatically learn the interactive relationship between different features, so as to more accurately assess the risk level of user behavior and improve the accuracy and reliability of risk assessment. Based on the behavior risk probability distribution, the risk level is determined and a warning signal is generated. Then, according to the warning signal, the real-time alarm module is triggered and the risk description text and risk mitigation strategy are sent, realizing the automation and intelligence of the entire process from risk assessment to warning response, and being able to respond to potential risks in a very short time, promptly inform the security management terminal of relevant information, and provide targeted response strategies, greatly improving the efficiency and response speed of security management.
[0034] In a possible implementation, step S120 includes: Step S121 , extracting a timestamp sequence and an operation type label of an operation event from the terminal operation log, converting the timestamp sequence into a time interval distribution histogram, and mapping the operation type label into an operation semantic vector.
[0035] For example, the target user uses a mobile client to operate on an e-commerce platform, and the terminal operation log records the detailed information. The timestamp sequence of the operation event may be to view the product list at 10:10 am, view the product details at 10:15 am, add the product to the shopping cart at 10:25 am, view the shopping cart at 10:30 am, etc. Calculate the time interval, 5 minutes from 10:10 to 10:15, 10 minutes from 10:15 to 10:25, and 5 minutes from 10:25 to 10:30. According to these time intervals, the distribution of different intervals is counted to form a time interval distribution histogram, such as 2 occurrences of 5-minute intervals and 1 occurrence of 10-minute intervals. Operation type labels such as viewing the product list, viewing product details, adding to the shopping cart, viewing the shopping cart, etc., map these operation type labels to operation semantic vectors. Suppose viewing the product list corresponds to the vector [0.1, 0.2, 0.3], viewing the product details corresponds to [0.2, 0.3, 0.4], adding to the shopping cart corresponds to [0.3, 0.4, 0.5], and viewing the shopping cart corresponds to [0.4, 0.5, 0.6].
[0036] Step S122, extracting an interface call frequency matrix from the application program interface call sequence, and performing sliding window statistics on the interface call frequency matrix to generate interface call pattern features.
[0037] On e-commerce platforms, API calls are triggered when users perform various operations. Assume that within an hour, the product information query API is called 3 times, the inventory query API is called 2 times, and the order API is called 1 time, etc., and the interface call frequency matrix is constructed based on this. Then perform sliding window statistics, for example, with a sliding window of 15 minutes. In the first 15-minute window, the product information query API is called 2 times, the inventory query API is called 1 time, and the order API is not called; in the second 15-minute window, the product information query API is called 1 time, the inventory query API is called 1 time, and the order API is called 1 time, etc. Generate interface call pattern features based on these statistical information, such as recording that some APIs are concentratedly called in a specific window and rarely called in other windows.
[0038] Step S123, performing feature splicing on the time interval distribution histogram, the operation semantic vector and the interface call pattern feature to obtain an initial behavior trajectory feature.
[0039] In this embodiment, the time interval distribution information in the time interval distribution histogram obtained previously, the operation semantic information in the operation semantic vector, and the API call mode information in the interface call mode feature are combined together in a set order to form an initial behavior trajectory feature containing multiple information.
[0040] Step S124, performing dimensionality reduction processing on the initial behavior trajectory features, removing redundant dimensions in the initial behavior trajectory features, and generating compressed intermediate behavior trajectory features.
[0041] Assuming that the initial behavior trajectory feature contains information of 10 dimensions, the contribution of each dimension to the overall feature is calculated through dimensionality reduction methods such as principal component analysis. For example, the contribution of dimension 1 is 0.1, the contribution of dimension 2 is 0.05, etc. According to the set threshold or importance sorting, the dimensions with lower contribution are removed, such as removing dimension 2 and dimension 4, and the features are compressed to 6 dimensions to generate compressed intermediate behavior trajectory features.
[0042] Step S125, inputting the intermediate behavior trajectory features into the spatiotemporal attention module, and performing weighted fusion of the temporal dependency and spatial correlation in the intermediate behavior trajectory features through the spatiotemporal attention module to generate the behavior trajectory feature vector.
[0043] For example, in a possible implementation, step S125 includes: Step S1251, input the intermediate behavior trajectory features into the time embedding layer, extract the change rate between adjacent time steps in the intermediate behavior trajectory features through the time embedding layer, and generate a time embedding vector, and input the intermediate behavior trajectory features into the space embedding layer, extract the co-occurrence frequency of different operation types in the intermediate behavior trajectory features through the space embedding layer, and generate a space embedding vector.
[0044] For example, the time-related part of the intermediate behavior trajectory feature records the temporal sequence and interval of the user's operations. If the change from the previous operation to the next operation is relatively sudden, such as from viewing product details to directly placing an order, the change rate is relatively large; while the change rate from viewing product details to viewing more reviews is relatively small. A time embedding vector is generated based on these different change rate situations. It is assumed that the element value of the time embedding vector takes values between 0 and 1 according to the size of the change rate. The value of a large change rate is close to 1, and the value of a small change rate is close to 0.
[0045] On e-commerce platforms, different types of operations are such as viewing products, adding to shopping carts, and placing orders. Their co-occurrence frequencies are calculated. For example, the co-occurrence frequency of viewing products and adding to shopping carts is relatively high, which may be 0.6, indicating that these two operations often appear together in multiple operations; while the co-occurrence frequency of viewing products and canceling orders is relatively low, which may be 0.1. A spatial embedding vector is generated based on these co-occurrence frequencies, and the vector element values reflect the co-occurrence frequencies of different types of operations.
[0046] Step S1252, concatenate the time embedding vector and the space embedding vector according to the channel dimension to generate a spatiotemporal joint vector, and input the spatiotemporal joint vector into a multi-head attention layer, and use the multi-head attention layer to parallelly calculate the correlation strength between each feature position in the spatiotemporal joint vector and other feature positions to generate multiple spatiotemporal attention weight matrices.
[0047] For example, the temporal embedding vector is [0.2, 0.3, 0.4], and the spatial embedding vector is [0.3, 0.4, 0.5]. After concatenation, the spatiotemporal joint vector is [0.2, 0.3, 0.4, 0.3, 0.4, 0.5]. The spatiotemporal joint vector is input into the multi-head attention layer, and the multi-head attention layer calculates the association strength between each feature position in the spatiotemporal joint vector and other feature positions in parallel to generate multiple spatiotemporal attention weight matrices. For example, for the first element in the spatiotemporal joint vector, calculate the association strength between it and other elements. Assume that the association strength with the second element is 0.3, the association strength with the third element is 0.2, and so on. Calculate multiple such association strength values to form a spatiotemporal attention weight matrix. Because it is a multi-head attention layer, multiple such spatiotemporal attention weight matrices will be calculated in parallel.
[0048] Step S1253, concatenate the multiple spatiotemporal attention weight matrices according to the attention head dimension and input them into the normalization layer, scale and smooth the concatenated matrices through the normalization layer to generate a standardized spatiotemporal attention coefficient matrix, perform matrix multiplication operation on the standardized spatiotemporal attention coefficient matrix and the intermediate behavior trajectory feature to obtain a weighted spatiotemporal feature matrix, and input the weighted spatiotemporal feature matrix into the gated recurrent unit layer.
[0049] Assuming that the concatenated matrix is a 3×3 matrix, the normalization layer scales and smoothes according to the distribution of element values in the matrix. For example, if the matrix element values are between 0 and 1, the normalization layer may appropriately reduce the larger values and appropriately amplify the smaller values to make the matrix element values more evenly distributed, thus obtaining a standardized spatiotemporal attention coefficient matrix.
[0050] Assuming that the intermediate behavior trajectory feature is a 2×3 matrix and the standardized spatiotemporal attention coefficient matrix is a 3×3 matrix, the calculation is performed according to the matrix multiplication rule. First, calculate the first row and first column elements of the weighted spatiotemporal feature matrix, multiply each element of the first row of the intermediate behavior trajectory feature with the corresponding element of the first column of the spatiotemporal attention coefficient matrix, and then add them to obtain the element value of the first row and first column of the weighted spatiotemporal feature matrix. In this way, all elements of the entire weighted spatiotemporal feature matrix are calculated.
[0051] Step S1254, iteratively update the time series dependency in the weighted spatiotemporal feature matrix through the gated recurrent unit layer to generate a time series enhanced feature vector, input the time series enhanced feature vector into the spatial graph convolution layer, and perform neighborhood feature aggregation on the time series enhanced feature vector based on a predefined operation type association graph through the spatial graph convolution layer to generate a spatial enhanced feature vector.
[0052] The gated recurrent unit layer performs iterative feature updates based on the time series dependencies in the weighted spatiotemporal feature matrix. It is assumed that the elements in the weighted spatiotemporal feature matrix reflect the operational feature relationships at different time points. The gated recurrent unit layer updates the features at each time step based on the information of the current time step and the previous time step. For example, the value of an element in the current time step will be adjusted based on the value of the related element in the previous time step and the input of the current time step. After multiple iterative updates, a time series enhanced feature vector is generated.
[0053] In e-commerce platforms, the operation type association graph defines the relationship between different operation types, such as viewing a product and viewing reviews are neighborhood relationships. The spatial graph convolution layer aggregates the elements in the temporal enhancement feature vector according to the operation type association graph. For example, the feature elements of viewing reviews related to viewing a product will be aggregated together to generate a spatial enhancement feature vector, so that the associated operation features are fused and enhanced.
[0054] Step S1255, performing an element-by-element addition operation on the temporal enhancement feature vector and the spatial enhancement feature vector to generate a fused spatiotemporal feature vector, and inputting the fused spatiotemporal feature vector into a residual connection layer, and performing cross-layer feature superposition on the fused spatiotemporal feature vector and the intermediate behavior trajectory feature through the residual connection layer to generate an enhanced behavior trajectory feature after residual correction.
[0055] For example, the temporal enhancement feature vector is [0.1, 0.2, 0.3], and the spatial enhancement feature vector is [0.2, 0.3, 0.4]. After element-by-element addition, the fused temporal and spatial feature vector [0.3, 0.5, 0.7] is obtained.
[0056] Assuming that the intermediate behavior trajectory feature is [0.1, 0.2, 0.3], and the fused spatiotemporal feature vector is [0.3, 0.5, 0.7], their corresponding elements are added together to obtain the enhanced behavior trajectory feature [0.4, 0.7, 1.0] after residual correction.
[0057] Step S1256, input the enhanced behavior trajectory feature into the feature projection layer, compress the dimension of the enhanced behavior trajectory feature to the preset embedding space dimension through the feature projection layer, generate the compressed behavior trajectory feature after dimensionality reduction, input the compressed behavior trajectory feature into the activation function layer, perform nonlinear transformation on the compressed behavior trajectory feature through the activation function layer, and generate a behavior trajectory feature vector in the form of normalized probability distribution.
[0058] Assuming that the preset embedding space dimension is 3D and the enhanced behavior trajectory feature is 4D, the 4D feature is compressed to 3D through the calculation of the feature projection layer to obtain the compressed behavior trajectory feature after dimensionality reduction.
[0059] Exemplarily, the activation function layer uses the Sigmoid function, and substitutes each element value in the compressed behavior trajectory feature into the Sigmoid function for calculation. Assuming that the compressed behavior trajectory feature is [0.2, 0.3, 0.4], after the Sigmoid function calculation, the behavior trajectory feature vector [0.5498, 0.5744, 0.6065] is obtained. These values are between 0 and 1, forming a normalized probability distribution form of the behavior trajectory feature vector, which represents the probability distribution of different features in the entire behavior trajectory.
[0060] In a possible implementation, step S120 includes: Step S126, parsing the target protocol field in the network access record, and extracting the source address, target address, protocol type and data packet length in the target protocol field.
[0061] In the e-commerce platform, users access the e-commerce website through the network, using the HTTP protocol. From the network access record, the source address can be extracted, for example, the IP address of the user's mobile phone is 192.168.1.100, which is the identification of the user's device in the network. The target address is the IP address of the e-commerce platform server, assuming it is 202.100.100.100, which is the source of the user's request data. The protocol type is HTTP, which specifies the rules and format of data transmission. The data packet length is the size of the data in each network interaction process. For example, in a product image loading request, the data packet length may be 300 bytes, and in an order query request, the data packet length may be 500 bytes, etc.
[0062] Step S127, generating an address pair feature according to the source address and the target address, and performing one-hot encoding on the protocol type to generate a protocol type encoding vector.
[0063] For example, the source address 192.168.1.100 and the destination address 202.100.100.100 are combined to generate an address pair feature, which can contain some relationship features between the two addresses, such as the difference in the network segments of the addresses, the relationship between network areas, etc. For the protocol type, one-hot encoding is performed. Since the protocol type is HTTP, it is assumed that three protocol types are set, namely HTTP, HTTPS, and FTP. HTTP is encoded as [1, 0, 0], indicating that the HTTP type is selected, while HTTPS and FTP are not selected. This encoding method can convert the protocol type into a vector form that can be processed by the computer for subsequent calculations.
[0064] Step S128, performing segmented statistics on the length of the data packet to generate a data packet length distribution histogram, and converting the data packet length distribution histogram into a frequency domain feature vector.
[0065] Exemplarily, the length of the data packet can be divided into different intervals, such as 0-100 bytes as an interval, 101-200 bytes as an interval, 201-300 bytes as an interval, etc. The number of times the data packet appears in each interval is counted. Assuming that within a period of time, there are 5 times in the 0-100 byte interval, 10 times in the 101-200 byte interval, 8 times in the 201-300 byte interval, etc., a data packet length distribution histogram is generated based on these statistical results. The data packet length distribution histogram is then converted into a frequency domain feature vector. This process requires discrete Fourier transform and other operations on the data in the histogram. For example, for the above-mentioned histogram data, the frequency of each interval is first calculated, and then these frequency values are converted into frequency domain feature vectors through a specific algorithm. Specifically, the proportion of each interval frequency to the total frequency is calculated, such as the frequency ratio of the 0-100 byte interval is 5 / (5+10+8)=5 / 23, the frequency ratio of the 101-200 byte interval is 10 / 23, the frequency ratio of the 201-300 byte interval is 8 / 23, etc. These proportion values are combined into a frequency domain feature vector in a set order.
[0066] Step S129, performing feature fusion on the address pair feature, the protocol type encoding vector and the frequency domain feature vector to obtain the original network behavior feature, inputting the original network behavior feature into a convolutional neural network for local pattern extraction, and generating the network behavior feature vector.
[0067] For example, the address pair feature can be a vector containing multiple elements, the protocol type encoding vector is [1, 0, 0], and the frequency domain feature vector is a vector calculated based on the data packet length distribution. The corresponding elements are added or combined according to other fusion rules to obtain the original network behavior feature, which contains comprehensive information related to the address, protocol type and data packet length in network access.
[0068] For example, in a possible implementation, step S129 includes: Step S1291, input the original network behavior features into the feature tensor conversion layer, and align the address pair features, protocol type encoding vectors and frequency domain feature vectors in the original network behavior features according to the feature dimensions through the feature tensor conversion layer and convert them into a three-dimensional feature tensor.
[0069] Assume that the address pair feature is a 5-dimensional vector, the protocol type encoding vector is 3-dimensional, and the frequency domain feature vector is 4-dimensional. They are aligned according to the meaning and order of the features through the feature tensor conversion layer, and then converted into a 3D feature tensor, for example, a 3D tensor with a shape of (1, 5+3+4, 1), where the first dimension 1 represents the batch size, which is 1 sample here, the second dimension is the combined feature dimension, and the third dimension 1 represents the number of channels is 1.
[0070] Step S1292: input the three-dimensional feature tensor into a channel expansion layer, perform linear projection expansion on the channel dimension of the three-dimensional feature tensor through the channel expansion layer, generate a channel expansion feature with a preset number of channels, input the channel expansion feature into a first convolution layer, use a multi-scale convolution kernel through the first convolution layer to capture the cross-channel local pattern of the channel expansion feature, generate a primary convolution feature containing multi-scale spatial features, input the primary convolution feature into a spatial pyramid pooling layer, perform adaptive pooling operations on the primary convolution feature at different spatial resolutions through the spatial pyramid pooling layer, generate a downsampled feature with a fixed size, input the downsampled feature into a depthwise separable convolution layer, perform separable feature extraction of spatial convolution in the depth direction and point-by-point channel convolution on the downsampled feature through the depthwise separable convolution layer, generate a depth feature, input the depth feature into a dilated convolution layer, capture the cross-stride context information of the depth feature based on a preset dilation rate through the dilated convolution layer, and generate a context feature containing a long-distance dependency.
[0071] Assuming that the preset number of channels is 8, the channel expansion layer converts the original three-dimensional feature tensor with a channel number of 1 into a feature with a channel number of 8 through linear transformation. In this process, according to the preset linear transformation matrix, each element is multiplied and added with the coefficient in the matrix to obtain a new element value, thereby expanding the channel dimension.
[0072] On this basis, two convolution kernels of 3×3 and 5×5 scales are used. For the 3×3 convolution kernel, the convolution kernel is slid on each channel of the channel extension feature to calculate the convolution result. Taking a local area of the channel extension feature as an example, each element in the 3×3 convolution kernel is multiplied by the channel extension feature element at the corresponding position and then added to obtain a new element value. This operation is performed on the entire channel extension feature to obtain a convolution result. Similarly, a 5×5 convolution kernel is used for similar operations, and the results obtained by the two scale convolution kernels are combined to generate a primary convolution feature containing multi-scale spatial features.
[0073] The spatial pyramid pooling layer can pool the primary convolution features according to different set resolutions, such as 1×1, 2×2, 4×4, etc. For 1×1 pooling, the maximum value or average value of each 1×1 region of the primary convolution feature is taken as the element value after downsampling; for 2×2 pooling, the elements of each 2×2 region in the primary convolution feature are processed to obtain a new element value; the same is true for 4×4 pooling. The results obtained by pooling at different resolutions are combined to generate downsampled features with a fixed size.
[0074] After that, we first perform spatial convolution in the depth direction, and perform convolution operations independently on each channel of the downsampled feature, for example, convolution is performed on each channel using a 3×3 convolution kernel to obtain the convolution result in the depth direction. Then, we perform point-by-point channel convolution, and convolve each element of the depth direction convolution result with a 1×1 convolution kernel. The results of these two steps are combined to generate the depth feature.
[0075] Furthermore, assuming that the preset expansion rate is 2, when the dilated convolution layer performs convolution operations, there will be gaps between the elements of the convolution kernel. Taking a 3×3 dilated convolution kernel as an example, the elements of a normal convolution kernel are closely adjacent, while there is an element between the dilated convolution kernel. By performing convolution operations on deep features in this way, long-distance dependencies can be captured and contextual features containing long-distance dependencies can be generated.
[0076] Step S1293, concatenate the context feature and the downsampled feature in the channel dimension to generate an enhanced context feature, input the enhanced context feature into a batch normalization layer, perform mean variance normalization on each channel of the enhanced context feature through the batch normalization layer to generate a normalized feature, input the normalized feature into a second convolutional layer, and perform nonlinear interaction between channels on the normalized feature through the second convolutional layer using a 1×1 convolution kernel to generate a high-dimensional interactive feature.
[0077] For example, the context feature is a feature with 5 channels, and the downsampled feature is a feature with 3 channels. They are concatenated in the channel dimension to obtain an enhanced context feature with 8 channels. Then, the mean and variance of each channel of the enhanced context feature are calculated. For example, the element value of a channel is [1, 2, 3, 4, 5], the mean is 3, and the variance is 2. Then, each element is standardized according to the mean and variance, and the new element value is (original element - mean) / standard deviation, where the standard deviation is the square root of the variance. This operation is performed on each channel to generate normalized features.
[0078] Furthermore, the 1×1 convolution kernel performs a convolution operation with the elements of the normalized features on each channel. Since the size of the convolution kernel is 1×1, it can realize information interaction between channels. For example, for an element of the normalized feature, it is multiplied with the element in the 1×1 convolution kernel and then added to obtain a new element value. This operation is performed on the entire normalized feature to generate a high-dimensional interactive feature.
[0079] Step S1294, input the high-dimensional interaction feature into the global average pooling layer, compress the spatial dimension of the high-dimensional interaction feature through the global average pooling layer, generate a spatial aggregation feature vector, input the spatial aggregation feature vector into the fully connected layer, map the dimension of the spatial aggregation feature vector to the preset semantic space dimension through the fully connected layer, generate a linear projection feature, input the linear projection feature into the activation function layer, perform nonlinear activation and probability normalization on the linear projection feature through the activation function layer, and generate the network behavior feature vector.
[0080] Assuming that the high-dimensional interaction feature is a feature with a shape of (1, 4, 4), the global average pooling layer calculates the average value of all elements on each channel to obtain a spatially aggregated feature vector with a shape of (1, 1, 1), where each element of the spatially aggregated feature vector is the average value of all elements on the corresponding channel.
[0081] Then, assuming that the preset semantic space dimension is 3, the fully connected layer linearly combines the elements of the spatial aggregation feature vector through a preset weight matrix. For example, the spatial aggregation feature vector is [0.5], the weight matrix is [[0.1, 0.2, 0.3]], and the linear projection feature is calculated as 0.5×0.1+0.5×0.2+0.5×0.3=0.3, resulting in a linear projection feature with a dimension of 3.
[0082] Furthermore, assuming that the activation function is a Sigmoid function, for each element in the linear projection feature, such as the linear projection feature is [0.3, 0.4, 0.5], each element is substituted into the Sigmoid function for calculation. The Sigmoid function is f(x)=1 / (1+exp(-x)). For the element 0.3, 1 / (1+exp(-0.3))≈0.5744 is calculated. Similarly, other elements are calculated to obtain a network behavior feature vector. The element values of the network behavior feature vector are between 0 and 1, indicating the probability of different features.
[0083] In a possible implementation, the risk assessment neural network is trained by the following steps: Step S210, obtaining a historical behavior data set, wherein the historical behavior data set includes historical multi-source behavior data of multiple users and corresponding risk labels.
[0084] In e-commerce platforms, historical behavior data sets cover the historical multi-source behavior data of many users and the corresponding risk labels. These historical multi-source behavior data include information such as the user's network access records, terminal operation logs, and application interface call sequences in the past period of time (such as the past year). For example, network access records contain the time, frequency, and source IP address of users visiting different product pages and promotion pages; terminal operation logs record the specific time and sequence of user operations on mobile phones or computer clients, such as searching for products, viewing product details, adding to shopping carts, placing orders, and modifying orders; application interface call sequences record the API calls involved in these operations, such as querying product inventory, calculating order prices, verifying payment methods, etc. The call sequence and frequency of APIs. The corresponding risk labels are marked according to the actual situation. For example, if the user account has been stolen, it may be marked as "account theft risk"; if payment anomalies have occurred, it may be marked as "payment risk", etc.
[0085] Step S220, performing data cleaning on the historical multi-source behavior data, removing invalid data containing missing values or abnormal values, and standardizing the remaining valid data.
[0086] In a possible implementation, step S220 includes: Step S221 , detecting the continuity of timestamps in the historical multi-source behavior data, and performing interpolation repair on log segments with time jumps.
[0087] In the terminal operation log of the e-commerce platform, the timestamp records the sequence and time interval of user operations. For example, under normal circumstances, after viewing the product details, the user may add the product to the shopping cart or perform other related operations in a short period of time (such as a few seconds to a few minutes). However, if there is a time jump, such as the time interval from one operation to the next suddenly changes from a few minutes to a few days, this may be a data recording error or an abnormal situation. After detecting this discontinuous timestamp, interpolation repair is required. Suppose a user views the product details at 10 am, and the timestamp of the next operation record is 10 am the next day, with a time jump in between. Interpolation can be performed based on the type of previous and subsequent operations and the average time interval between operations. If the average time interval from viewing the product details to adding the product to the shopping cart is 5 minutes, a possible add-to-cart operation can be inserted at around 10:05 (assuming that this operation conforms to the general user behavior pattern) to repair the continuity of the timestamp.
[0088] Step S222, analyzing the integrity of the protocol fields in the network access records, and discarding abnormal records that do not contain necessary protocol headers.
[0089] HTTP is a commonly used protocol in network access of e-commerce platforms. The protocol field contains important information such as source address, target address, protocol version, and request method. If a network access record does not contain the necessary protocol header, such as the lack of source address, then this record is abnormal. For example, when analyzing a large number of network access records, it is found that a certain record only contains the target address and part of the request content, but no source address information. This record cannot accurately reflect the source and nature of the network access, so it needs to be discarded.
[0090] Step S223: Count the distribution of operation types in the terminal operation log, and remove rare operation events whose occurrence frequency is lower than a preset threshold.
[0091] For the operation types in the terminal operation log, such as searching for products, viewing product details, placing orders, etc., their frequency of occurrence in all user operations is counted. Assuming the preset threshold is 1%, if there is an operation type, such as "customizing the evaluation of the product (this operation may be more complicated and rarely performed by users)", the frequency of occurrence in all operations is only 0.5%, which is lower than the preset threshold. Then this operation event may be abnormal or unimportant, and it will be removed from the historical behavior data. Because this rare operation may be caused by system errors or individual special circumstances, it has little impact on the overall risk assessment and may interfere with model training.
[0092] Step S224, verifying the legality of the calling order of the application program interface calling sequence, and deleting abnormal sequences containing illegal calling patterns.
[0093] There is a set logical order in the API call sequence of the e-commerce platform. For example, the normal order process may be to call the query product inventory API first, then call the calculation order price API, and then call the payment method verification API. If a call sequence occurs, such as calling the payment method verification API first and then calling the query product inventory API, this is an illegal call pattern that does not conform to normal business logic. When verifying the API call sequence, if such an abnormal sequence containing an illegal call pattern is found, it will be deleted from the historical behavior data to ensure the accuracy and rationality of the data.
[0094] Step S225, adding a data integrity check code to the cleaned historical multi-source behavior data, and marking the data that passes the check as valid data.
[0095] After completing the above cleaning steps, add a data integrity check code to each piece of historical multi-source behavior data. For example, the cyclic redundancy check (CRC) method can be used. For a piece of data that is a combination of a cleaned network access record, a terminal operation log, and an application interface call sequence, a check code is calculated using a specific CRC algorithm. When the data is used later, the check code can be calculated again and compared with the previously added check code. If the check codes are consistent, it means that the data is complete and has not been tampered with. This data is marked as valid data for subsequent model training.
[0096] Step S230, dividing the normalized valid data into a training set and a validation set, and constructing an initial neural network model, wherein the initial neural network model includes a behavior trajectory encoding branch and a network behavior encoding branch.
[0097] In the e-commerce scenario, valid data after data cleaning and standardization is divided according to a set ratio (e.g. 80% for training set and 20% for validation set). Assuming there are 1,000 valid data in total, 800 will be used as training set and 200 as validation set. The training set is used to train the neural network so that the initial neural network model can learn the relationship between user behavior characteristics and risks; the validation set is used to evaluate the performance of the initial neural network model during the training process to prevent overfitting.
[0098] The initial neural network model constructed includes a behavior trajectory encoding branch and a network behavior encoding branch. The behavior trajectory encoding branch mainly processes features related to user behavior trajectories extracted from terminal operation logs and application interface call sequences, such as user operation sequence, operation frequency and other information, with the purpose of predicting user behavior risk categories, such as account theft risk, payment risk, etc. The network behavior encoding branch mainly processes features extracted from network access records, such as source address, destination address, protocol type and other information, with the purpose of predicting network attack types, such as DDoS attacks, SQL injection attacks, etc. (although in e-commerce platforms, DDoS attacks can be malicious behaviors against servers, and SQL injection attacks can be malicious behaviors such as attempts to steal database information, which are associated with user behavior risks).
[0099] Step S240, performing multi-task joint training on the initial neural network model through the training set, wherein the behavior trajectory encoding branch is used to predict the user behavior risk category, and the network behavior encoding branch is used to predict the network attack type.
[0100] In a possible implementation, step S240 includes: Step S241, randomly sampling a batch of multi-source behavior data samples from the training set, and inputting the multi-source behavior data samples into the behavior trajectory encoding branch and the network behavior encoding branch respectively.
[0101] For example, during the training process, a batch of data is randomly sampled from the 800 training sets, assuming that the batch size is 32. These 32 multi-source behavior data samples contain information such as network access records, terminal operation logs, and application interface call sequences. These 32 samples are input into the behavior trajectory encoding branch and the network behavior encoding branch respectively. For example, for a sample, the operation sequence and operation frequency information in the terminal operation log are sent to the behavior trajectory encoding branch, and the source address, target address, and other information in the network access record are sent to the network behavior encoding branch.
[0102] Step S242: extracting sample behavior trajectory features through the behavior trajectory encoding branch, and inputting the sample behavior trajectory features into the first fully connected layer to generate a first risk prediction probability.
[0103] The behavior trajectory encoding branch extracts features from the input terminal operation log and application interface call sequence. For example, for the operation sequence in the terminal operation log, the operation sequence is converted into a vector form through a certain encoding method, and the operation frequency is normalized, etc., to obtain the sample behavior trajectory feature. Assume that the sample behavior trajectory feature is a vector with a dimension of 10. The vector is input into the first fully connected layer, which has a set number of neurons (assuming 5). The weighted sum between each neuron and the input vector element is calculated, and the first risk prediction probability is obtained by processing it through an activation function (such as a ReLU function). For example, for the account theft risk in the predicted user behavior risk category, the calculated first risk prediction probability is 0.1, indicating that the model initially believes that the probability that the sample has the risk of account theft is 0.1. The calculation process is to multiply each element of the sample behavior trajectory feature vector by the weight of the neuron in the first fully connected layer, then add them, and then obtain the final probability value through the activation function.
[0104] Step S243: extracting sample network behavior features through the network behavior encoding branch, and inputting the sample network behavior features into the second fully connected layer to generate a second risk prediction probability.
[0105] The network behavior encoding branch extracts features from network access records. For example, for the source address in the network access record, it is converted into a feature vector through a certain mapping method, and the protocol type is one-hot encoded, etc., to obtain the sample network behavior feature. Assume that the sample network behavior feature is a vector with a dimension of 8. The vector is input into the second fully connected layer, which has a set number of neurons (assuming 4). Through similar calculations (the weighted sum between each neuron and the input vector element, and processed by the activation function), the second risk prediction probability is obtained. For example, for the prediction of DDoS attack risk in the network attack type, the calculated second risk prediction probability is 0.05, indicating that the model initially believes that the probability that the sample has a DDoS attack risk is 0.05.
[0106] Step S244, calculating the cross entropy loss between the first risk prediction probability and the true risk label, and calculating the focal loss between the second risk prediction probability and the true attack type label.
[0107] Calculate the cross entropy loss between the first risk prediction probability and the true risk label. Assume that the risk of account theft in the true risk label is 1 (indicating the existence of risk), and the first risk prediction probability is 0.1. The calculation of cross entropy loss is based on the logarithmic function. First, calculate the logarithm when the prediction probability is 0.1, that is, -log(0.1)≈2.3026. If the prediction probability is 1 (completely correct prediction), then -log(1)=0. Therefore, the cross entropy loss reflects the degree of difference between the predicted probability and the true label. The larger the cross entropy loss here, the larger the difference between the predicted result and the true result.
[0108] The focal loss is calculated between the predicted probability of the second risk and the true attack type label. Focal loss is an improved loss function used to deal with data imbalance. Assume that the true attack type label is 1 for DDoS attack and the predicted probability of the second risk is 0.05. The calculation of focal loss is more complicated, which takes into account the relationship between the predicted probability and the true label and an adjustment factor. The focal loss is adjusted according to the closeness of the predicted probability to the true label, so that the model pays more attention to samples that are difficult to classify during training.
[0109] Step S245, performing weighted summation of the cross entropy loss and the focal loss to obtain a total loss function, and back-propagating the total loss function to update the weight parameters of the initial neural network model.
[0110] Assume that the weight of the cross entropy loss is 0.6 and the weight of the focal loss is 0.4. Multiply the cross entropy loss by 0.6 and the focal loss by 0.4, and then add them together to get the total loss function. For example, if the cross entropy loss is 2.3026 and the focal loss is 1.5 (assumed value), then the total loss function is 2.3026×0.6+1.5×0.4=1.3816+0.6=1.9816. Back propagate the weight parameters of the initial neural network model according to the total loss function. Back propagation is to propagate the error from the output layer (where the loss is calculated) to the input layer, and adjust the weight parameters of each layer according to the error. For example, for the first fully connected layer in the behavior trajectory encoding branch, the gradient of each weight parameter is calculated according to the total loss function (the calculation process involves finding the partial derivative of the total loss function with respect to each weight parameter), and then according to the gradient descent algorithm, the weight parameter is updated according to the set learning rate (assuming the learning rate is 0.01), that is, the new weight parameter = the old weight parameter - learning rate × gradient. A similar weight parameter update operation is performed on the second fully connected layer in the network behavior encoding branch.
[0111] Step S250, calculating the classification loss function and the adversarial loss function of the initial neural network model after multi-task joint training on the verification set, and optimizing the parameters of the initial neural network model by a gradient descent algorithm until the classification loss function and the adversarial loss function converge, thereby obtaining the trained risk assessment neural network.
[0112] In a possible implementation, step S250 includes: Step S251: input the sample behavior trajectory feature into an adversarial discriminator, and output the discrimination probability that the sample behavior trajectory feature belongs to the real user behavior through the adversarial discriminator.
[0113] For example, among the 200 data in the validation set, take the sample behavior trajectory feature of one data (this feature is extracted by the behavior trajectory encoding branch in the previous training process) and input it into the adversarial discriminator. The adversarial discriminator is a module specifically used to determine whether the sample is a real user behavior. For example, the adversarial discriminator makes a judgment based on information such as the operation sequence and operation frequency in the sample behavior trajectory feature. If the operation sequence conforms to the normal user's shopping process and the operation frequency is also within a reasonable range, then a higher discrimination probability may be output, assuming it is 0.8, indicating that the discriminator believes that the probability that the sample behavior trajectory feature belongs to the real user behavior is 0.8.
[0114] Step S252: input the sample network behavior feature into the adversarial discriminator, and output the discrimination probability that the sample network behavior feature belongs to normal network activity through the adversarial discriminator.
[0115] Similarly, take a sample network behavior feature of a data in the validation set (extracted by the network behavior encoding branch) and input it into the adversarial discriminator. The adversarial discriminator makes a judgment based on the source address, target address, protocol type and other information in the sample network behavior feature. If the source address is a normal user IP address, the target address is a legitimate e-commerce platform server address, and the protocol type is also a normal HTTP protocol, then a higher discrimination probability may be output, assuming it is 0.9, indicating that the discriminator believes that the probability that the sample network behavior feature belongs to normal network activity is 0.9.
[0116] Step S253, calculating the mean square error between the discrimination probability and the preset true label to obtain the discrimination loss of the adversarial discriminator.
[0117] For the discrimination probability of the sample behavior trajectory features, assuming that the preset true label is 1 (indicating real user behavior), the discrimination probability is 0.8. The calculation of the mean square error is to first calculate the square of the difference, that is, (0.8-1)^2=0.04. For the discrimination probability of the sample network behavior features, assuming that the preset true label is 1 (indicating normal network activity), the discrimination probability is 0.9, and the mean square error is (0.9-1)^2=0.01. Add these two mean square errors (if there are more samples, they need to be averaged according to the number of samples) to get the discrimination loss of the adversarial discriminator. Here, the discrimination loss is 0.04+0.01=0.05.
[0118] Step S254, generating an adversarial gradient output by a gradient reversal layer according to the discriminant loss, and back-propagating the adversarial gradient to the behavior trajectory encoding branch and the network behavior encoding branch.
[0119] Calculate the adversarial gradient of the gradient reversal layer output according to the discriminative loss (this calculation process involves taking partial derivatives of the discriminative loss with respect to the parameters of the behavior trajectory encoding branch and the network behavior encoding branch). Assume that the calculated adversarial gradient is a vector containing parameter adjustment values related to the behavior trajectory encoding branch and the network behavior encoding branch. Backpropagate the adversarial gradient to the behavior trajectory encoding branch and the network behavior encoding branch. For example, the weight parameter of a neuron in the behavior trajectory encoding branch is adjusted according to the corresponding value in the adversarial gradient, and the weight parameter of a neuron in the network behavior encoding branch is similarly adjusted.
[0120] Step S255, adjusting the feature extraction parameters of the behavior trajectory encoding branch and the network behavior encoding branch through the adversarial gradient to reduce the sensitivity of the risk assessment neural network to adversarial samples.
[0121] In the behavior trajectory encoding branch, the feature extraction parameters are adjusted according to the adversarial gradient of back propagation. For example, if the weight parameter in the encoding method of a certain operation sequence needs to be adjusted, it is modified according to the value of the adversarial gradient. If the adversarial gradient indicates that a certain weight parameter should be reduced, it is appropriately reduced. Similar operations are also performed in the network behavior encoding branch. This enables the model to more accurately identify possible adversarial samples (such as maliciously constructed samples that are close to normal but have risks), reduce sensitivity to adversarial samples, and improve the robustness of the model. By repeating the above calculation and adjustment process on the validation set until the classification loss function and the adversarial loss function converge, a trained risk assessment neural network is obtained.
[0122] In a possible implementation, step S140 includes: Step S141, traverse each risk category in the behavior risk probability distribution, extract the risk category identifiers whose probability values exceed the preset threshold, and generate a candidate risk set.
[0123] In the risk assessment scenario of the e-commerce platform, it is assumed that the behavioral risk probability distribution includes categories such as account theft risk, payment risk, and product information leakage risk. The preset threshold is set to 0.05. After traversing the behavioral risk probability distribution, if the probability value of account theft risk is 0.1, the probability value of payment risk is 0.06, and the probability value of product information leakage risk is 0.03, then the probability values of account theft risk and payment risk exceed the preset threshold, and their risk category identifiers are extracted, thereby generating a candidate risk set including account theft risk and payment risk.
[0124] Step S142: According to each risk category identifier in the candidate risk set, a corresponding weight factor and an association influence matrix are obtained from a predefined risk metadata database, wherein the association influence matrix represents the superposition intensity between different risk categories.
[0125] For example, for the risk of account theft, its weight factor is 0.8 from the risk metadata database, which indicates that this risk has a high importance in the overall risk assessment. For payment risk, its weight factor is 0.6. The correlation impact matrix indicates the intensity of the superposition between different risk categories. In the e-commerce environment, there is a strong correlation between the risk of account theft and the payment risk. For example, account theft may directly lead to an increase in payment risk. Therefore, in the correlation impact matrix, the superposition intensity between them may be 0.5, indicating that the degree of mutual influence between the two is high.
[0126] Step S143, weighting the weight factor of each risk category identifier and its probability value to generate an independent risk contribution value, and calculating the collaborative risk gain value based on the interaction relationship between each risk category in the candidate risk set in the association influence matrix.
[0127] For example, for the risk of account theft, the probability value is 0.1, the weight factor is 0.8, and the weighted calculation results in an independent risk contribution value of 0.1×0.8=0.08. For payment risk, the probability value is 0.06, the weight factor is 0.6, and the independent risk contribution value is 0.06×0.6=0.036. When calculating the synergistic risk gain value, since the superposition intensity between the risk of account theft and the payment risk is 0.5, first calculate the product of the independent risk contribution values of the two, that is, 0.08×0.036=0.00288, and then multiply it by the superposition intensity of 0.5, and get the synergistic risk gain value of 0.00288×0.5=0.00144.
[0128] Step S144, all independent risk contribution values are added to the collaborative risk gain value to obtain a comprehensive risk assessment value, and the comprehensive risk assessment value is input into a segmented mapping function to determine the corresponding discretized risk level number according to a preset level division interval.
[0129] Here, the independent risk contribution values are 0.08 and 0.036 respectively, and the synergistic risk gain value is 0.00144. The sum of the comprehensive risk assessment value is 0.08+0.036+0.00144=0.11744. The comprehensive risk assessment value is then input into the segmented mapping function, and the corresponding discretized risk level number is determined according to the preset level division interval. Assume that the preset level division interval is: 0-0.05 is low risk level number 1, 0.05-0.15 is medium risk level number 2, and 0.15 and above is high risk level number 3. Since the comprehensive risk assessment value of 0.11744 is between 0.05-0.15, the corresponding discretized risk level number is determined to be 2.
[0130] Step S145, querying the warning signal template library according to the discretized risk level number, and extracting the warning signal format framework and filling field rules matching the discretized risk level number.
[0131] For example, for risk level number 2, the warning signal format framework queried from the warning signal template library may be "Risk description: [risk description text], Mitigation strategy: [Mitigation strategy entry], Risk level: [Risk level number]", and the filling field rules specify how each field is filled in. For example, the risk description text needs to accurately describe the risk content, and the mitigation strategy entry needs to list the response measures in a set order, etc.
[0132] Step S146, obtaining the description text and mitigation strategy entries of each risk category in the candidate risk set from the risk knowledge base, inserting the description text into the corresponding placeholder of the warning signal format framework according to the fill field rule, and generating the original warning signal text.
[0133] For example, for the risk of account theft, the description text may be "An abnormal login behavior of the account is detected, which may have been stolen and there are unauthorized access attempts", and the mitigation strategy entry is "Immediately freeze the account, notify the user to change the password, and add a login verification method (such as SMS verification code or fingerprint recognition)". For payment risk, the description text is "There are abnormalities in the payment process, which may face the risk of capital loss", and the mitigation strategy entry is "Suspend unfinished payment transactions, check the security of payment channels, and notify users to verify payment information". Insert the description text into the corresponding placeholder of the warning signal format framework according to the filling field rules to generate the original warning signal text. According to the previous format framework and filling rules, the original warning signal text is "Risk description: An abnormal login behavior of the account is detected, which may have been stolen and there are unauthorized access attempts; There are abnormalities in the payment process, which may face the risk of capital loss, Mitigation strategy: Immediately freeze the account, notify the user to change the password, add a login verification method (such as SMS verification code or fingerprint recognition); Suspend unfinished payment transactions, check the security of payment channels, and notify users to verify payment information, Risk level: 2".
[0134] Step S147, performing grammatical structure check on the original warning signal text, correcting semantic conflicts and logical breakpoints, and generating compliant warning signal content.
[0135] There may be some grammatical or logical problems in the original warning signal text. For example, the sentence structure may not be clear enough, or the logical coherence may not be sufficient when describing multiple risks. Adjust and optimize the sentences through grammatical structure verification. If it is found that the description of "abnormal login behavior of the account is detected, which may have been stolen and there are unauthorized access attempts; there are abnormalities in the payment process, and there may be a risk of financial loss" is somewhat complex and unclear in semantics, it can be adjusted to "abnormal login behavior of the account is detected, which may have been stolen and there are unauthorized access attempts, and there are abnormalities in the payment process, and there may be a risk of financial loss". After such corrections, the compliant warning signal content is generated.
[0136] Step S148, encode the current timestamp and the risk level number into a protocol header identification segment, and perform data splicing on the compliance warning signal content and the protocol header identification segment to generate a final warning signal carrying an integrity tag.
[0137] Assume that the current timestamp is 15:30 on October 1, 2023, and encode it and the risk level number 2 in a specific encoding method, such as converting the timestamp into digital form, and then combining it with the risk level number into a protocol header identification segment. Assume that the encoded protocol header identification segment is "202310011530_2". The protocol header identification segment is data spliced with the compliance warning signal content, and an integrity tag is added during the splicing process. The integrity tag can be a check value calculated by a certain encryption algorithm to ensure the integrity of the signal during transmission. The final warning signal with the integrity tag generated includes the protocol header identification segment, the compliance warning signal content and the integrity tag, so as to accurately convey risk information in the security management system of the e-commerce platform and ensure the integrity and accuracy of the information.
[0138] In a possible implementation, step S150 includes: Step S151, parse the risk level number and the embedded timestamp from the protocol header identification segment of the warning signal, and extract the corresponding transmission protocol type and priority code from the risk policy library based on the risk level number.
[0139] In this embodiment, it is assumed that the protocol header identification segment of the early warning signal is "202310011530_2". Through a specific parsing algorithm, it is decomposed into the risk level number 2 and the timestamp 15:30 on October 1, 2023. Then, based on the risk level number 2, the corresponding information is searched in the risk policy library. The risk policy library contains information such as the transmission protocol type and priority code under different risk levels. For the risk level number 2 (medium risk level), the corresponding transmission protocol type is queried as the Secure Sockets Layer (SSL), which is a protocol commonly used in e-commerce environments to ensure secure data transmission. At the same time, the priority code is queried as 2, indicating medium priority.
[0140] Step S152, verify the validity of the digital signature of the final warning signal. If signature verification failure is detected, a data integrity alarm is triggered and the transmission process is terminated. Otherwise, the risk description text field and risk mitigation strategy field in the compliance warning signal content are extracted.
[0141] In the e-commerce platform, a specific digital signature algorithm is used to generate the digital signature of the warning signal. During verification, the warning signal is calculated using the same algorithm and key to obtain a calculation result, which is compared with the original digital signature. If the two are consistent, it means that the digital signature is valid; if they are inconsistent, for example, there is a difference between the calculation result and the original digital signature, this indicates that the warning signal may have been tampered with during transmission, at which time a data integrity alarm is triggered and the transmission process is terminated. In this scenario, it is assumed that the digital signature verification passes and subsequent operations are continued. Extract the risk description text field and risk mitigation strategy field in the compliance warning signal content. For example, the content of the compliance warning signal is "Risk description: Abnormal login behavior of the account is detected, which may have been stolen and there are unauthorized access attempts. At the same time, there are abnormalities in the payment process, which may face the risk of financial loss. Mitigation strategy: Immediately freeze the account, notify the user to change the password, and add a login verification method (such as SMS verification code or fingerprint recognition); suspend unfinished payment transactions, check the security of payment channels, and notify users to verify payment information. Risk level: 2", from which the risk description text field "Abnormal login behavior of the account is detected, which may have been stolen and there are unauthorized access attempts. At the same time, there are abnormalities in the payment process, which may face the risk of financial loss" and the risk mitigation strategy field "Immediately freeze the account, notify the user to change the password, and add a login verification method (such as SMS verification code or fingerprint recognition); suspend unfinished payment transactions, check the security of payment channels, and notify users to verify payment information" are extracted.
[0142] Step S153: convert the risk description text field into a formatted text stream that complies with the target communication protocol according to the transmission protocol type, and split the risk mitigation strategy field into independent strategy entries and number them in execution order.
[0143] For example, since the transmission protocol type is SSL, the risk description text field needs to be formatted according to the requirements of the SSL protocol. For example, the SSL protocol may require specific encoding and formatting of the text, converting the characters in the risk description text into an encoding format that complies with the SSL protocol, such as UTF-8 encoding, and organizing it according to the set text structure to form a formatted text stream. For the risk mitigation strategy field, it is split into independent policy entries, such as "immediately freeze the account" as the first entry, numbered 1; "notify the user to change the password" as the second entry, numbered 2; "add login verification methods (such as SMS verification codes or fingerprint recognition)" as the third entry, numbered 3; "suspend unfinished payment transactions" as the fourth entry, numbered 4; "check the security of payment channels" as the fifth entry, numbered 5; "notify the user to verify payment information" as the sixth entry, numbered 6.
[0144] Step S154, encapsulating the formatted text stream and the numbered policy entries to generate an alarm transmission data packet including a protocol header identification segment, a risk level number and a timestamp, and appending a checksum field to the end of the alarm transmission data packet.
[0145] In detail, the formatted risk description text stream and the numbered risk mitigation strategy entries can be combined together according to the set structure, for example, the formatted text stream is placed first, and then the numbered strategy entries are placed in sequence. Then the protocol header identification segment "202310011530_2", the risk level number 2 and the timestamp 15:30 on October 1, 2023 are added to form an alarm transmission data packet. In order to ensure the accuracy of data transmission, a checksum field is attached to the end of the alarm transmission data packet. The process of calculating the checksum is to calculate all the data in the data packet (including the protocol header identification segment, risk description text, risk mitigation strategy, risk level number and timestamp, etc.) according to a specific algorithm (such as the cyclic redundancy check algorithm CRC) to obtain a checksum value and add it to the end of the data packet.
[0146] Step S155: activating a corresponding transmission channel in a real-time alarm module according to the priority code, and loading the alarm transmission data packet into a sending buffer of the transmission channel.
[0147] For example, since the priority code is 2 (medium priority), there are transmission channels corresponding to different priorities in the real-time alarm module. Find the transmission channel corresponding to the medium priority, and load the generated alarm transmission data packet into the transmission buffer of the transmission channel. The transmission buffer is a temporary storage area used to pre-process data before sending it.
[0148] Step S156, performing byte stream fragmentation processing on the alarm transmission data packet in the sending buffer, generating a plurality of data fragments of equal length and adding a fragment sequence identifier to each data fragment.
[0149] Assuming that the total length of the alarm transmission data packet is 1000 bytes, it is divided into data slices of equal length according to the requirements of the transmission protocol. For example, the length of each data slice is 100 bytes, so that 10 data slices can be obtained. For each data slice, add a slice sequence identifier from 1 to 10 so that the data slices can be reassembled in the correct order at the receiving end.
[0150] Step S157, based on the retransmission mechanism rules defined by the transmission protocol type, inject the data fragments into the network interface queue of the transmission channel in sequence identifier order, triggering the network interface queue to initiate an asynchronous transmission request to the preset receiving port of the security management terminal.
[0151] For example, for the SSL protocol, its retransmission mechanism rules specify how to retransmit if a data fragment is lost or transmitted incorrectly during the data transmission process. In the order of the fragment sequence identifiers, the data fragments are injected into the network interface queue of the transmission channel one by one. For example, the data fragment identified as 1 is injected first, then the data fragment identified as 2, and so on. When all data fragments are injected into the network interface queue, the network interface queue is triggered to initiate an asynchronous transmission request to the preset receiving port of the security management terminal. Asynchronous transmission request means that while sending data, there is no need to wait for the response from the receiving end, and other operations can be continued. This can improve the efficiency of data transmission and ensure that the risk description text and risk mitigation strategy can be transmitted to the security management terminal in a timely and accurate manner, so that security managers can take corresponding measures to deal with risks in the e-commerce platform.
[0152] Figure 2 A schematic diagram of exemplary hardware and software components of a risk behavior perception device 100 based on deep learning that can implement the concept of the present application is shown in some embodiments of the present application. For example, the processor 120 can be used in the risk behavior perception device 100 based on deep learning and used to perform the functions in the present application.
[0153] The risk behavior perception device 100 based on deep learning can be a general server or a special-purpose server, both of which can be used to implement the risk behavior perception method based on deep learning of the present application. Although only one server is shown in the present application, for convenience, the functions described in the present application can be implemented in a distributed manner on multiple similar platforms to balance the processing load.
[0154] For example, the risk behavior perception device 100 based on deep learning may include a network port 110 connected to a network, one or more processors 120 for executing program instructions, a communication bus 130, and storage media 140 in different forms, such as a disk, ROM, or RAM, or any combination thereof. Exemplarily, the risk behavior perception device 100 based on deep learning may also include program instructions stored in ROM, RAM, or other types of non-temporary storage media, or any combination thereof. The method of the present application can be implemented according to these program instructions. The risk behavior perception device 100 based on deep learning also includes an input / output (I / O) interface 150 between a computer and other input / output devices.
[0155] For ease of explanation, only one processor is described in the risk behavior perception device 100 based on deep learning. However, it should be noted that the risk behavior perception device 100 based on deep learning in the present application may also include multiple processors, so the steps performed by one processor described in the present application may also be performed jointly or individually by multiple processors. For example, if the processor of the risk behavior perception device 100 based on deep learning executes step A and step B, it should be understood that step A and step B may also be performed jointly by two different processors or individually in one processor. For example, the first processor executes step A, the second processor executes step B, or the first processor and the second processor execute steps A and B together.
[0156] In addition, an embodiment of the present invention also provides a readable storage medium, in which computer executable instructions are preset. When a processor executes the computer executable instructions, the above-mentioned risk behavior perception method based on deep learning is implemented.
[0157] It should be noted that in order to simplify the description of the present invention and thus help understand one or more embodiments of the invention, in the foregoing description of the embodiments of the present invention, various features are sometimes combined into one embodiment, figure or description thereof.
Claims
1. A risk behavior perception method based on deep learning, characterized in that: The method comprises: Collecting multi-source behavior data of the target user within a preset time window, wherein the multi-source behavior data includes network access records, terminal operation logs, and application program interface call sequences; Extracting spatiotemporal features from the multi-source behavior data to generate a behavior trajectory feature vector of the target user, and performing protocol parsing on the network access record to obtain a network behavior feature vector; Inputting the behavior trajectory feature vector and the network behavior feature vector into a pre-trained risk assessment neural network, and jointly encoding the behavior trajectory feature vector and the network behavior feature vector through the risk assessment neural network to generate a behavior risk probability distribution of the target user; Determine the risk level of the target user based on the risk category exceeding a preset threshold in the behavior risk probability distribution, and generate a warning signal corresponding to the risk level; The real-time alarm module is triggered according to the early warning signal, and a risk description text and a risk mitigation strategy corresponding to the risk level are sent to the security management terminal.
2. The risk behavior perception method based on deep learning according to claim 1 is characterized in that: The extracting spatiotemporal features of the multi-source behavior data to generate a behavior trajectory feature vector of the target user includes: Extracting a timestamp sequence and an operation type label of an operation event from the terminal operation log, converting the timestamp sequence into a time interval distribution histogram, and mapping the operation type label into an operation semantic vector; Extracting an interface call frequency matrix from the application program interface call sequence, and performing sliding window statistics on the interface call frequency matrix to generate interface call pattern features; Performing feature splicing on the time interval distribution histogram, the operation semantic vector and the interface call pattern feature to obtain an initial behavior trajectory feature; Performing dimensionality reduction processing on the initial behavior trajectory features, removing redundant dimensions in the initial behavior trajectory features, and generating compressed intermediate behavior trajectory features; The intermediate behavior trajectory features are input into a spatiotemporal attention module, and the spatiotemporal attention module performs weighted fusion on the time dependency and spatial correlation in the intermediate behavior trajectory features to generate the behavior trajectory feature vector.
3. The risk behavior perception method based on deep learning according to claim 1 is characterized in that: The performing protocol parsing on the network access record to obtain a network behavior feature vector includes: Parsing the target protocol field in the network access record, extracting the source address, target address, protocol type and data packet length in the target protocol field; Generate an address pair feature according to the source address and the target address, and perform one-hot encoding on the protocol type to generate a protocol type encoding vector; Performing segmented statistics on the length of the data packet to generate a data packet length distribution histogram, and converting the data packet length distribution histogram into a frequency domain feature vector; Performing feature fusion on the address pair feature, the protocol type encoding vector and the frequency domain feature vector to obtain the original network behavior feature; The original network behavior features are input into a convolutional neural network to extract local patterns, thereby generating the network behavior feature vector.
4. The risk behavior perception method based on deep learning according to claim 1 is characterized in that: The risk assessment neural network is trained by the following steps: Acquire a historical behavior data set, wherein the historical behavior data set includes historical multi-source behavior data of multiple users and corresponding risk labels; Performing data cleaning on the historical multi-source behavior data, removing invalid data containing missing values or outliers, and standardizing the remaining valid data; Dividing the standardized valid data into a training set and a validation set, and constructing an initial neural network model, wherein the initial neural network model includes a behavior trajectory encoding branch and a network behavior encoding branch; Performing multi-task joint training on the initial neural network model through the training set, wherein the behavior trajectory encoding branch is used to predict the user behavior risk category, and the network behavior encoding branch is used to predict the network attack type; The classification loss function and the adversarial loss function of the initial neural network model after multi-task joint training are calculated on the verification set, and the parameters of the initial neural network model are optimized by the gradient descent algorithm until the classification loss function and the adversarial loss function converge, thereby obtaining the trained risk assessment neural network.
5. The risk behavior perception method based on deep learning according to claim 4 is characterized in that: The data cleaning of the historical multi-source behavior data to remove invalid data containing missing values or abnormal values includes: Detecting the continuity of timestamps in the historical multi-source behavior data, and performing interpolation repair on log segments with time jumps; Analyzing the integrity of the protocol fields in the network access records and discarding abnormal records that do not contain necessary protocol headers; Counting the distribution of operation types in the terminal operation log, and removing rare operation events whose occurrence frequency is lower than a preset threshold; Verify the legality of the calling sequence of the application program interface calling sequence, and delete abnormal sequences containing illegal calling patterns; Add data integrity check codes to the cleaned historical multi-source behavior data, and mark the data that passes the check as valid data.
6. The risk behavior perception method based on deep learning according to claim 4 is characterized in that: The performing multi-task joint training on the initial neural network model through the training set includes: Randomly sampling a batch of multi-source behavior data samples from the training set, and inputting the multi-source behavior data samples into the behavior trajectory encoding branch and the network behavior encoding branch respectively; Extracting sample behavior trajectory features through the behavior trajectory encoding branch, and inputting the sample behavior trajectory features into the first fully connected layer to generate a first risk prediction probability; Extracting sample network behavior features through the network behavior encoding branch, and inputting the sample network behavior features into the second fully connected layer to generate a second risk prediction probability; Calculating the cross entropy loss between the first risk prediction probability and the true risk label, and calculating the focal loss between the second risk prediction probability and the true attack type label; The cross entropy loss and the focal loss are weightedly summed to obtain a total loss function, and the weight parameters of the initial neural network model are updated by backpropagation according to the total loss function.
7. The risk behavior perception method based on deep learning according to claim 6 is characterized in that: The step of calculating the classification loss function and the adversarial loss function of the initial neural network model after multi-task joint training on the verification set includes: Inputting the sample behavior trajectory feature into an adversarial discriminator, and outputting the discrimination probability that the sample behavior trajectory feature belongs to the real user behavior through the adversarial discriminator; Inputting the sample network behavior feature into the adversarial discriminator, and outputting the discrimination probability that the sample network behavior feature belongs to normal network activity through the adversarial discriminator; Calculate the mean square error between the discrimination probability and the preset true label to obtain the discrimination loss of the adversarial discriminator; Generate an adversarial gradient output by a gradient reversal layer according to the discriminant loss, and back-propagate the adversarial gradient to the behavior trajectory encoding branch and the network behavior encoding branch; The feature extraction parameters of the behavior trajectory encoding branch and the network behavior encoding branch are adjusted by the adversarial gradient to reduce the sensitivity of the risk assessment neural network to adversarial samples.
8. The risk behavior perception method based on deep learning according to claim 1 is characterized in that: The step of determining the risk level of the target user based on the risk category exceeding a preset threshold in the behavior risk probability distribution, and generating a warning signal corresponding to the risk level, includes: Traversing each risk category in the behavior risk probability distribution, extracting risk category identifiers whose probability values exceed the preset threshold, and generating a candidate risk set; According to each risk category identifier in the candidate risk set, a corresponding weight factor and an association influence matrix are obtained from a predefined risk metadata database, wherein the association influence matrix represents the intensity of superposition effects between different risk categories; The weight factor of each risk category identifier and its probability value are weighted and calculated to generate an independent risk contribution value, and the collaborative risk gain value is calculated based on the interaction relationship between each risk category in the candidate risk set in the association impact matrix; Add all independent risk contribution values to the collaborative risk gain value to obtain a comprehensive risk evaluation value, and input the comprehensive risk evaluation value into a segmented mapping function to determine the corresponding discretized risk level number according to a preset level division interval; Querying the warning signal template library according to the discretized risk level number, extracting the warning signal format framework and filling field rules matching the discretized risk level number; Obtaining description text and mitigation strategy entries of each risk category in the candidate risk set from the risk knowledge base, inserting the description text into corresponding placeholders of the warning signal format framework according to the fill field rule, and generating original warning signal text; Performing grammatical structure check on the original warning signal text, correcting semantic conflicts and logical breakpoints, and generating compliant warning signal content; The current timestamp and the risk level number are encoded as a protocol header identification segment, and the compliance warning signal content is data-joined with the protocol header identification segment to generate a final warning signal carrying an integrity tag.
9. The risk behavior perception method based on deep learning according to claim 8 is characterized in that: The triggering of the real-time alarm module according to the early warning signal to send the risk description text and risk mitigation strategy corresponding to the risk level to the security management terminal includes: Parsing the risk level number and the embedded timestamp from the protocol header identification segment of the warning signal, and extracting the corresponding transmission protocol type and priority code from the risk policy library based on the risk level number; Verify the validity of the digital signature of the final warning signal, and if a signature verification failure is detected, trigger a data integrity alarm and terminate the transmission process, otherwise extract the risk description text field and risk mitigation strategy field in the content of the compliance warning signal; converting the risk description text field into a formatted text stream that complies with the target communication protocol according to the transmission protocol type, and splitting the risk mitigation strategy field into independent strategy entries and numbering them in execution order; Data encapsulation is performed on the formatted text stream and the numbered policy entries to generate an alarm transmission data packet including a protocol header identification segment, a risk level number and a timestamp, and a checksum field is appended to the end of the alarm transmission data packet; activating a corresponding transmission channel in a real-time alarm module according to the priority code, and loading the alarm transmission data packet into a sending buffer of the transmission channel; Performing byte stream slicing processing on the alarm transmission data packet in the sending buffer to generate a plurality of data slices of equal length and adding a slice sequence identifier to each data slice; Based on the retransmission mechanism rules defined by the transmission protocol type, the data fragments are injected into the network interface queue of the transmission channel in sequence identifier order, triggering the network interface queue to initiate an asynchronous transmission request to the preset receiving port of the security management terminal.
10. A risk behavior perception device based on deep learning, characterized in that: The risk behavior perception device based on deep learning includes a processor and a memory, the memory is connected to the processor, the memory is used to store programs, instructions or codes, and the processor is used to execute the programs, instructions or codes in the memory to implement the risk behavior perception method based on deep learning as described in any one of claims 1 to 9 above.
Citation Information
Patent Citations
Behavior characteristics-based network attack detection method and device
CN105471882A
Abnormity detection method and apparatus based on log graph modeling
CN108833348A
Network attack risk mapping assessment method and system
CN119583198A
Anti-fraud risk assessment method and apparatus, training method and apparatus, and readable storage medium
WO2023124204A1
Cited By
IC card transaction security processing method and system based on mobile terminal system
CN120146857A
IC Card Transaction Security Processing Method and System Based on Mobile Terminal System
CN120146857B
Self-adaptive data encryption method based on risk driving
CN120185948A
Multi-protocol transmission text data monitoring and warning method and system
CN120321267A
Dynamic data tracing method and system for network security
CN121037128A