Network risk assessment model construction method and system based on AI large model

Through dynamic sharding and privacy protection technology, the AI model is disassembled into semantic independent units, combined with local differential privacy and parameter confusion, the contradiction between data privacy and training efficiency in cross-institutional collaboration is solved, efficient collaborative training and security are achieved, and the performance and security of the network risk assessment model are improved.

CN120378177APending Publication Date: 2025-07-25SHANGHAI YINDI NETWORK TECHNOLOGY CO LTD
View PDF 0 Cites 8 Cited by

Patent Information

Application Number
CN202510572511.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-06
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In the cross-institutional collaboration scenario, data privacy protection and AI big model training efficiency are difficult to balance. The existing technology cannot achieve efficient collaborative training while ensuring physical isolation of data. At the same time, it is difficult to take into account model performance and privacy security, which hinders the large-scale application of AI big models in the field of network security.

Method used

The big model is disassembled into a semantic independent sharding unit through the dynamic sharding mechanism, combined with local differential privacy and parameter obfuscation technology, a threat knowledge distiller and an adversarial validator are used to perform cross-domain feature fusion and attack surface blind spot detection, and a meta-learning controller is used to achieve dynamic balance between privacy protection and threat detection accuracy.

Benefits of technology

It effectively reduces communication overhead, improves the detection rate of APT attacks, meets the timeliness of real-time risk assessment, and takes into account model accuracy and security under compliance frameworks such as GDPR, enhancing the feasibility of cross-border and cross-industry collaboration scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378177A_ABST
    Figure CN120378177A_ABST
Patent Text Reader

Abstract

The invention discloses a network risk assessment model construction method and system based on an AI large model, and relates to the technical field of artificial intelligence and network security, and the method comprises the following steps: S1, a participating node splits a large model into a plurality of semantic independent fragmentation units through a dynamic fragmentation mechanism based on local multi-source heterogeneous data; according to the network risk assessment model construction method and system based on the AI large model, through a dynamic fragmentation federated distillation learning framework, the inherent contradiction between data privacy protection and AI large model training efficiency in cross-mechanism cooperation is effectively solved. A ten-billion-level parameter model is disassembled into semantic independent units by adopting a self-adaptive parameter fragmentation mechanism, the communication overhead is reduced on the premise of ensuring physical isolation of sensitive data in combination with a local differential privacy and parameter confusion technology, and meanwhile, cross-domain fusion of threat features and attack surface blind spot detection are realized through a layered distillation verification system. And the APT attack detection rate is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of artificial intelligence and network security, and specifically provides a method and system for constructing a network risk assessment model based on an AI large model. Background Art

[0002] With the complication of network attack means, traditional risk assessment models are difficult to cope with new risks such as advanced persistent threats and zero-day vulnerabilities. The network risk assessment technology based on AI large models has become a research hotspot due to its powerful feature extraction and pattern recognition capabilities. Current methods usually rely on training models with large-scale multi-source heterogeneous data, such as enterprise intranet traffic, cloud service logs, and Internet of Things device behavior data, to capture the characteristics of covert attacks. However, in the scenario of cross-institutional collaboration, the contradiction between data privacy protection and model training efficiency has become the core bottleneck restricting the implementation of the technology. Existing centralized training schemes require each participating party to transmit the original data to the central server, which not only violates the data localization supervision requirements of industries such as healthcare and finance, but may also lead to the leakage of sensitive information such as network topology structures and vulnerability distributions. To solve the privacy problem, some technologies adopt the federated learning framework to train models through distributed node collaboration. However, when facing large models with tens of billions of parameters, frequent transmission of complete model parameters will generate a huge amount of communication overhead, resulting in a significant decrease in the model convergence speed and making it difficult to meet the timeliness requirements of minute-level updates in real-time risk assessment scenarios. In addition, although strict privacy protection mechanisms can reduce the risk of data exposure, they may introduce noise interference and weaken the detection accuracy of the model for low-frequency high-risk attack characteristics. This contradiction is particularly prominent in cross-border and cross-industry collaboration scenarios. Existing methods can neither achieve efficient collaborative training while ensuring physical isolation of data, nor balance model performance and privacy security, seriously hindering the large-scale application of AI large models in the field of network security. Summary of the Invention

[0003] (1) Technical Problems to be Solved

[0004] Aiming at the deficiencies of the prior art, the present invention provides a method and system for constructing a network risk assessment model based on an AI large model, which solves the problem that it is difficult to balance data privacy protection and AI large model training efficiency in the scenario of cross-institutional collaboration.

[0005] (2) Technical Solutions

[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: A method for constructing a network risk assessment model based on an AI large model includes the following steps:

[0007] Step S1: Based on the local multi-source heterogeneous data, the participating nodes disassemble the large model into multiple semantically independent shard units through a dynamic sharding mechanism, and each shard unit retains a subset of parameters associated with the preset high-risk threat features; in the specific implementation process, the participating nodes first perform threat feature analysis on the local multi-source heterogeneous data, and identify high-risk signals such as abnormal communication patterns and zero-day vulnerability exploitation features in the APT attack chain by real-time monitoring of the intranet traffic, device behavior logs, and cloud access records.

[0008] Step S2: In the federated aggregation stage, each node transmits the highly sensitive shard parameters processed by local differential privacy to the central server; in the specific implementation of the federated aggregation stage, each participating node first performs multi-level privacy processing on the highly sensitive shard parameters generated by the dynamic sharding mechanism.

[0009] Step S3: The central server reconstructs the global model through a threat knowledge distiller and generates a threat feature guidance vector, and at the same time performs attack surface blind spot detection on the shard parameters through an adversarial verifier; in the implementation process, after receiving the privacy-processed shard parameters transmitted by each node, the central server first performs cross-domain feature fusion by the threat knowledge distiller, and based on the fused feature matrix, calculates the contribution weight of each shard to the global risk model using the feature importance weighting algorithm, generates a low-dimensional threat feature guidance vector, and feeds it back to each node through a secure channel to drive local model optimization.

[0010] Step S4: Dynamically adjust the noise injection intensity, transmission frequency, and privacy budget allocation of the shard units based on the meta-learning controller to achieve a dynamic balance between privacy protection and threat detection accuracy. The meta-learning controller constructs a dynamic regulation strategy by continuously monitoring the privacy leakage risk assessment indicators and threat feature contribution degrees of each shard unit. At the same time, for the shard units related to financial transaction behavior detection, a parameter confusion matrix is enabled to perform random orthogonal transformation on the neuron weights within the shard to destroy the linear traceability between parameters; in the privacy budget allocation link, the controller dynamically adjusts the privacy budget weight using the meta-reinforcement learning algorithm according to the change curve of the feature contribution degree of the shard unit in the last three training cycles. After each federated aggregation, the controller generates a feedback signal to optimize the next round of regulation strategy by comparing the detection rate differences of the model before and after privacy processing on the adversarial test set.

[0011] Preferably, the dynamic sharding mechanism in Step S1 includes: S1a: Disassemble the large model parameters into semantically independent shard units according to the attack feature correlation degree through the gradient sparsification mapping algorithm; S1b: Add a noise matrix to the highly sensitive shards and perform parameter confusion operations to destroy the linear correlation between parameters. By adopting a dual verification mechanism, verify the anti-reconstruction ability of the shards after confusion through parameter reverse attack simulation tests to ensure that the complete model structure or original data features cannot be deduced when a single shard is leaked.

[0012] Preferably, in step S3, the threat knowledge distiller performs the following operations:

[0013] S3a: Extract cross-domain common threat features from each node shard parameter;

[0014] S3b: Generate a low-dimensional threat feature guidance vector through a feature importance weighting algorithm;

[0015] S3c: Feedback the guidance vector to each node through a secure channel to drive the local model to optimize key risk features.

[0016] Preferably, the adversarial verifier in step S3 includes:

[0017] S3d: Synthesize test samples containing zero-day vulnerability features based on a generative adversarial network;

[0018] S3e: Perform adversarial robustness evaluation on the shard parameters, and only retain the shards that pass the blind spot detection to participate in the global model update.

[0019] Preferably, the meta-learning controller in step S4 performs the following operations:

[0020] S4a: Quantify the privacy leakage risk coefficient and feature contribution degree of the shards in real time;

[0021] S4b: Increase the noise injection intensity for the shards corresponding to medical and financial data and enable a parameter confusion matrix;

[0022] S4c: Adopt gradient compression coding technology for the shards corresponding to Internet of Things data to improve the transmission efficiency.

[0023] Preferably, the parameter confusion operation in step S1b includes:

[0024] S1ba: Perform a random orthogonal matrix transformation on the shard parameters;

[0025] S1bb: Restore the original parameter semantics through an inverse transformation during the model inference stage.

[0026] Preferably, the method for constructing a network risk assessment model based on an AI large model further includes a verification step:

[0027] Sx: Verify the anti-reconstruction ability of the shard unit through a parameter shard reverse attack test;

[0028] Sy: Quantify the privacy leakage risk at each stage using a differential privacy auditing tool.

[0029] A system for constructing a network risk assessment model based on an AI large model, used to implement the method for constructing a network risk assessment model based on an AI large model, includes:

[0030] The dynamic sharding module deployed on each node is used to generate semantically independent sharding units;

[0031] The federated aggregation module of the central server receives and processes sharding parameters;

[0032] The dual-channel verification module includes a threat knowledge distiller and an adversarial verifier;

[0033] The meta-learning regulation module dynamically optimizes the privacy policy and transmission efficiency of sharding units.

[0034] Preferably, the dynamic sharding module includes:

[0035] The feature sensitivity analysis unit identifies high-risk threat features in local data;

[0036] The gradient sparsification mapping unit splits model parameters according to feature correlation.

[0037] Preferably, in the dual-channel verification module:

[0038] The threat knowledge distiller generates threat feature guidance vectors through a cross-domain feature fusion algorithm;

[0039] The adversarial verifier uses an adversarial sample evolution engine to generate a test set and perform blind spot detection.

[0040] (III) Beneficial effects

[0041] The present invention provides a method and system for constructing a network risk assessment model based on an AI large model. It has the following beneficial effects:

[0042] (I). The method and system for constructing a network risk assessment model based on an AI large model effectively solve the inherent contradiction between data privacy protection and the training efficiency of AI large models in cross-institutional collaboration through a dynamic sharding federated distillation learning framework. The adaptive parameter sharding mechanism disassembles a model with tens of billions of parameters into semantically independent units, combines local differential privacy and parameter confusion technology, reduces communication overhead compared with traditional federated learning while ensuring the physical isolation of sensitive data such as medical and financial data, and at the same time realizes cross-domain fusion of threat features and blind spot detection of the attack surface through a hierarchical distillation verification system, improving the detection rate of APT attacks and controlling the model synchronization delay. The meta-learning-driven dynamic privacy regulation mechanism breaks through the fixed noise injection mode, realizes real-time adaptation of privacy budget and threat feature contribution degree, takes into account model accuracy and security under compliance frameworks such as GDPR, and significantly improves the feasibility of cross-border and cross-industry collaboration scenarios.

[0043] (2). The method and system for constructing a network risk assessment model based on an AI large model build a closed-loop security protection system through a dual verification mechanism, reducing the success rate of sensitive data reconstruction and meeting the requirements of high-regulation industries such as healthcare and finance; secondly, the audit tracking and intelligent contract automatic execution mechanism based on blockchain ensures the trustworthy storage and real-time monitoring of key links such as sharded transmission and aggregated verification; thirdly, the dynamic attack and defense evolution ability is continuously upgraded through an adversarial sample evolution engine, improving the response time of the model to new threats such as zero-day vulnerabilities and variant ransomware. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 It is a schematic diagram of the overall framework of the present invention;

[0045] Figure 2 It is a timing diagram of the control logic of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0046] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0047] Please refer to Figure 1 and Figure 2 , the present invention provides a technical solution: a method for constructing a network risk assessment model based on an AI large model, including the following steps:

[0048] Step S1: Participating nodes disassemble the large model into multiple semantically independent shard units through a dynamic sharding mechanism based on local multi-source heterogeneous data, and each shard unit retains a subset of parameters associated with preset high-risk threat features; in the specific implementation process, the participating nodes first perform threat feature analysis on the local multi-source heterogeneous data, and identify high-risk risk signals such as abnormal communication patterns and zero-day vulnerability exploitation features in the APT attack chain by real-time monitoring of intranet traffic, device behavior logs, and cloud access records.

[0049] Based on the gradient sparsification mapping algorithm, the nodes automatically scan the correlation strength between the neuron weights of each layer of the large model and the threat features, and cluster the neuron sub-networks strongly associated with specific attack scenarios in the parameter matrix into independent shard units. For example, for the log data of medical institutions, the shard unit focuses on the mapping parameters of the abnormal packet size sequence and the vulnerability scanning behavior; for the data of Internet of Things devices, the convolution kernel weights related to the mutation detection of device fingerprints are retained.

[0050] Each shard unit only retains 15%-30% of the original dimension of the parameters, and adds Gaussian noise to the parameters within the shard through local differential privacy processing. At the same time, a random orthogonal matrix is used to linearly transform and obfuscate the shard parameters, so that a single shard cannot restore the complete model structure or the original data features. The shard granularity is dynamically adjusted according to the distribution of threat types in the local data: when a new attack pattern is detected, the node automatically triggers the shard recombination mechanism, and redefines the shard boundary matching the current threat in the parameter space through the sliding window algorithm, ensuring that the parameter subset corresponding to the high-risk features is always within an independent shard unit. After sharding, the node only marks the highly sensitive shard parameters processed by privacy as units to be transmitted, and the remaining low-correlation parameters are retained locally for asynchronous update, so as to achieve precise compression of communication load while maintaining the functional integrity of the model.

[0051] Step S2: In the federated aggregation stage, each node transmits the highly sensitive shard parameters processed by local differential privacy to the central server; in the specific implementation of the federated aggregation stage, each participating node first performs multi-level privacy processing on the highly sensitive shard parameters generated by the dynamic sharding mechanism: based on the preset privacy budget threshold, apply random noise conforming to the Gaussian distribution to the shard parameter matrix, and the noise intensity is inversely proportional to the sensitivity of the threat features associated with the shard unit. For example, the shard parameters corresponding to the patient access logs of medical institutions need to be superimposed with noise with a standard deviation of 0.05-0.12, while the shard of the regular behavior data of Internet of Things devices uses lightweight noise with a standard deviation of 0.01-0.03.

[0052] Subsequently, the node linearly transforms and obfuscates the noise-added parameters through a random orthogonal matrix to destroy the semantic correlation between the parameters, ensuring that even if the shard data is intercepted during transmission, the original model structure cannot be restored through reverse engineering or the data features cannot be inferred. The obfuscated shard parameters are transmitted to the central server through a secure channel. During the transmission process, gradient compression coding technology is used to set the tiny gradient values with absolute values lower than the set threshold in the parameter matrix to zero, and Huffman coding is used to compress the non-zero values, reducing the communication data volume to 18%-25% of the original parameters. For cross-border transmission scenarios, the node additionally enables a parameter shard integrity verification mechanism. Before transmission, calculate the SHA-256-based hash digest of the shard data and encrypt and transmit it together with the obfuscated parameters for the central server to verify that the data has not been tampered with.

[0053] After the central server receives the shards from each node, it first performs noise distribution calibration, normalizes the superimposed noise according to the preset global privacy budget, then restores the parameter semantic space through inverse orthogonal transformation, and finally aggregates the shard parameters across nodes according to threat feature categories to form an updated model with global risk perception ability. In this process, for data shards in highly regulated industries such as finance, the nodes additionally perform parameter value discretization before transmission, mapping continuous parameters to a preset discrete interval to further block the path of sensitive information leakage.

[0054] Step S3: The central server reconstructs the global model through the threat knowledge distiller and generates a threat feature guidance vector, and at the same time performs attack surface blind spot detection on the shard parameters through the adversarial verifier; in the implementation process, after the central server receives the privacy-processed shard parameters transmitted by each node, the threat knowledge distiller first performs cross-domain feature fusion, including: aligning the shard parameters from different institutions according to threat feature categories, for example, mapping the abnormal access pattern parameters in the medical institution's logs and the DDoS attack detection parameters in the cloud service provider's traffic to a unified feature space, and extracting cross-node common high-risk features through a multi-layer attention mechanism. Based on the fused feature matrix, a feature importance weighting algorithm is used to calculate the contribution weights of each shard to the global risk model, generating a low-dimensional threat feature guidance vector, which encodes the enhancement directions of core capabilities such as APT attack recognition and zero-day vulnerability prediction in the current global model, and is fed back to each node through a secure channel to drive local model optimization.

[0055] At the same time, the adversarial verifier starts attack surface blind spot detection: Based on the historical attack sample library and the generative adversarial network, a test set containing new attack features is dynamically synthesized, for example, simulating covert communication traffic using unexploited vulnerabilities or variant ransomware behavior sequences, and the test set is input into the sub-models corresponding to the shard parameters of each node for robustness evaluation. For shard parameters with detected attack response delays exceeding the threshold or misjudgment rates higher than the preset value, they are marked as high-risk units and the shard rollback mechanism is triggered, and only the shards that pass the verification are allowed to participate in the global aggregation.

[0056] In the model reconstruction stage, the threat knowledge distiller dynamically weights and combines the effective shard parameters according to the feature contribution degree, reconstructs an updated model with cross-institutional threat perception ability, and synchronizes the change trends of key risk features to the meta-learning controller to provide a decision basis for the dynamic adjustment of subsequent privacy policies. The entire process adopts a dual verification mechanism to ensure that the updated global model not only retains the unique threat detection capabilities of each node but also eliminates the feature biases caused by privacy processing.

[0057] Step S4: Dynamically adjust the noise injection intensity, transmission frequency, and privacy budget allocation of the shard units based on the meta-learning controller to achieve a dynamic balance between privacy protection and threat detection accuracy. In specific implementation, the meta-learning controller constructs a dynamic regulation strategy by continuously monitoring the privacy leakage risk assessment indicators and threat feature contribution degrees of each shard unit: real-time collect the gradient distribution, feature activation frequency, and cross-node aggregation historical data of the shard parameters in the local model training, and calculate the privacy sensitivity coefficient and risk detection efficiency index of each shard unit. For the shard corresponding to the patient diagnosis and treatment logs of medical institutions, when it is detected that there is a potential association between the shard parameters and individual identity characteristics, the noise intensity enhancement mode is automatically triggered, and Gaussian noise that conforms to differential privacy constraints is superimposed in the local differential privacy processing, and the noise variance is dynamically bound to the data sensitivity level. For example, when the privacy leakage risk assessment value exceeds the threshold, the noise standard deviation is increased from the baseline value of 0.08 to 0.15. At the same time, for the shard units related to financial transaction behavior detection, a parameter confusion matrix is enabled to perform random orthogonal transformation on the neuron weights within the shard to destroy the linear traceability between parameters. For the shard of Internet of Things device traffic monitoring, after the controller identifies its high timeliness requirement, it starts the gradient compression encoding process, filters out minor gradient changes by setting a dynamic threshold, retains the top 5%-10% of the key gradient values in absolute value and performs Huffman encoding compression, so that the transmitted data volume is reduced to within 22% of the original shard.

[0058] In the privacy budget allocation link, the controller dynamically adjusts the privacy budget weight by using the meta-reinforcement learning algorithm according to the change curve of the feature contribution degree of the shard unit in the recent three training cycles: allocate a higher privacy budget to the shards that continuously contribute to the identification of high-risk attack features to reduce noise interference, while strictly limit the privacy consumption of the regular feature shards with low-frequency updates. After each federated aggregation, the controller generates a feedback signal to optimize the next round of regulation strategy by comparing the detection rate differences of the model before and after privacy processing on the adversarial test set. For example, when the privacy enhancement of the medical shard causes the detection accuracy of ransomware to drop by more than 3%, the noise injection intensity and privacy budget ratio of this shard are automatically adjusted until a balance is achieved within the preset tolerance range. The whole process is verified through the dual channels of privacy leakage simulation attack testing and model effectiveness evaluation to ensure that the dynamic regulation strategy not only meets the compliance requirements such as GDPR, but also maintains the global model's real-time perception ability of new network threats.

[0059] The dynamic sharding mechanism in Step S1 includes:

[0060] S1a: Split the large model parameters into semantically independent shard units according to the attack feature correlation degree through the gradient sparsification mapping algorithm;

[0061] S1b: Add a noise matrix to the highly sensitive shards and perform parameter confusion operations to destroy the linear correlation between parameters.

[0062] It should be further noted that in the specific implementation process, the dynamic sharding mechanism realizes the semantic decoupling of model parameters through the gradient sparsification mapping algorithm: First, based on the threat feature distribution of local training data, analyze the correlation strength between the neuron weights of each layer of the large model and high-risk scenarios such as the APT attack chain and zero-day vulnerability exploitation. By calculating the response sensitivity of the parameter gradient to specific attack features during backpropagation, construct a parameter-threat correlation matrix.

[0063] For the internal log data of medical institutions, identify the fully connected layer parameters related to abnormal access frequency detection, and cluster them with the convolutional kernel weights identified by vulnerability scanning behavior into independent sharding units; for the traffic monitoring data of cloud service providers, divide the recurrent neural network gating parameters related to DDoS attack traffic pattern recognition into independent shards. During the sharding process, adopt a sliding window dynamic adjustment strategy. When detecting new phishing attack features, automatically expand the window coverage range and incorporate the newly emerging LSTM time series prediction parameters into the corresponding shard.

[0064] After completing the sharding division, apply local differential privacy processing to highly sensitive shards involving patient privacy or financial transactions, including: injecting Gaussian noise that conforms to differential privacy constraints according to the data sensitivity level, and the noise standard deviation is dynamically adjusted according to the threat feature sensitivity associated with the shard. For example, the medical data shard uses noise with a standard deviation of 0.1, while the conventional network traffic shard only uses lightweight noise with a standard deviation of 0.03. At the same time, perform parameter confusion operations, linearly transform the shard parameters through a pre-generated random orthogonal matrix, so that the transformed parameter matrix loses the original semantic association between neurons, and restore the parameter function through inverse transformation during the model inference stage.

[0065] This process adopts a dual verification mechanism, and verifies the anti-reconstruction ability of the confused shards through parameter reverse attack simulation tests to ensure that the complete model structure or original data features cannot be deduced when a single shard is leaked.

[0066] In step S3, the threat knowledge distiller performs the following operations:

[0067] S3a: Extract cross-domain common threat features from the shard parameters of each node;

[0068] S3b: Generate a low-dimensional threat feature guidance vector through the feature importance weighting algorithm;

[0069] S3c: Feedback the guidance vector to each node through a secure channel to drive the local model to optimize key risk features.

[0070] It should be further noted that in the specific implementation process, the threat knowledge distiller first performs cross-institutional semantic alignment on the shard parameters uploaded by each node, including: mapping the abnormal access period detection parameters in the medical institution logs, the abnormal fluctuation parameters of the encrypted channels in the cloud service provider traffic, and the unauthorized protocol usage identification parameters of the Internet of Things devices to a unified threat feature space.

[0071] Through a multi-layer cross-attention mechanism, analyze the synergistic effect of different shard parameters in the identification of APT attack stages. For example, extract the correlation weight between the hidden communication duration threshold feature across nodes and the high-frequency unconventional port access pattern. Based on the feature importance weighting algorithm, calculate the contribution of each shard parameter to the core capabilities such as global ransomware behavior prediction and zero-day vulnerability exploitation detection, and generate a threat feature guidance vector with the dimension compressed to 8%-12% of the original parameter space.

[0072] After this vector is fed back to each node through the quantum key encryption channel, it drives the local model for directional optimization, including: for medical nodes, guiding them to strengthen the correlation learning between abnormal packet size sequences and diagnosis and treatment system vulnerabilities; for cloud service nodes, focusing on optimizing the update direction of the short-term high-concurrency connection number detection model. During the feedback process, the distiller synchronously monitors the changes in the threat identification confidence of each node's local model. When it detects that the false alarm rate caused by a specific shard guidance vector rises beyond the threshold, it automatically triggers the vector attenuation mechanism to reduce the guidance intensity of this feature direction, and corrects the feature weight in the next round of iteration through the incremental learning algorithm. At the same time, lightweight adversarial training samples are embedded in the guidance vector, enabling the local model to simultaneously enhance its robustness against variant phishing attacks during the optimization process, forming a closed-loop of global-local collaborative evolution of security capabilities.

[0073] In step S3, the adversarial validator includes:

[0074] S3d: Synthesize test samples containing zero-day vulnerability features based on a generative adversarial network;

[0075] S3e: Conduct an adversarial robustness evaluation on the shard parameters, and only retain the shards that pass the blind spot detection to participate in the global model update.

[0076] It should be further noted that in the specific implementation process, the adversarial verifier first constructs a dynamically evolving test set based on the historical attack pattern library, including: simulating zero-day vulnerability exploitation behaviors through a generative adversarial network, such as generating ransomware communication traffic with variant encryption algorithms, sequences of hidden C2 channel data packets disguised as legitimate protocols, and malformed file transfer requests exploiting undisclosed system vulnerabilities. An adaptive mutation mechanism is introduced during the generation process to dynamically adjust the attack features according to the current defense weaknesses of the global model. For example, when it is detected that the model's sensitivity to time series anomalies decreases, the low-frequency long-period attack signals in the test samples are enhanced. After the construction of the test set is completed, the sub-models corresponding to the shard parameters uploaded by each node are deployed to the sandbox environment, synthetic attack traffic is injected, and the model responses are monitored, including: for the shard of IoT device behavior detection, verifying whether it can identify the activation behavior of hidden backdoors in device firmware upgrade packages; for the shard of financial transaction monitoring, testing its ability to detect subtle differences in the HTML structure between mutated phishing pages and normal pages.

[0077] By quantitatively evaluating the false positive rate, response latency, and feature coverage of the sub-models on the test set, the shard parameters with blind spots are marked, including: when it is detected that the false positive rate of the shard model for the communication traffic of a new type of cryptocurrency mining pool exceeds 15% or the response latency is higher than 200 milliseconds, the shard is marked as a high-risk unit and the isolation mechanism is triggered. The shard parameters that pass the verification will enter the global aggregation queue with a digital signature identifier, while the shards that do not pass will initiate an automatic repair process, including: calling a threat knowledge distiller to generate targeted enhanced training samples to guide the node to focus on optimizing the parameter of the feature extraction layer corresponding to the shard in the next round of local training. At the same time, the adversarial verifier injects the detected blind spot features back into the test set evolution engine to generate higher-order adversarial samples for subsequent verification, forming a closed-loop system with continuously upgraded offensive and defensive capabilities. The entire process records the verification results and disposal paths of each shard through blockchain technology to ensure that the detection process is auditable and tamper-proof.

[0078] The meta-learning controller in step S4 performs the following operations:

[0079] S4a: Quantify the privacy leakage risk coefficient and feature contribution degree of the shard in real time;

[0080] S4b: Increase the noise injection intensity for the shards corresponding to medical and financial data and enable a parameter confusion matrix;

[0081] S4c: Adopt gradient compression coding technology for the shards corresponding to IoT data to improve the transmission efficiency.

[0082] It should be further noted that in the specific implementation process, the meta-learning controller constructs a privacy - efficiency dynamic regulation model by continuously collecting the training dynamics and aggregation effect data of shard units, including: real-time monitoring of the gradient variance distribution of medical shard parameters, the feature activation frequency of financial transaction detection shards, and the communication delay index of Internet of Things shards, and calculating the privacy leakage risk index and threat recognition contribution degree of each shard. For the patient diagnosis and treatment log shards of medical institutions, when it is detected that there is a strong correlation between the shard parameters and abnormal access records in a specific time period, the controller automatically triggers a multi-level noise injection strategy, superimposing hierarchical Gaussian noise in local differential privacy processing, that is: applying strong noise with a standard deviation of 0.12 to the fully connected layer parameters directly related to patient identity recognition, while only adding benchmark noise with a standard deviation of 0.05 to the convolutional kernel parameters for conventional access pattern detection. At the same time, a parameter confusion matrix is enabled, and the medical shard parameters are mapped to a non-Euclidean space through random orthogonal transformation, destroying the linear invertibility between the original parameters. For the financial transaction risk control shards, when it is detected that the response delay of the shard parameters to a new phishing attack exceeds 150 milliseconds, the privacy budget consumption ratio of this shard is dynamically reduced, and the noise standard deviation is lowered from 0.1 to 0.07 to improve the feature retention degree.

[0083] For the high-timeliness requirements of Internet of Things shards, the controller starts adaptive gradient compression coding, including: identifying the top 8% of the key gradient values with the largest absolute values in the shard parameter matrix through a sliding window algorithm, and using a combination of sparse matrix storage structure and Huffman coding to compress the transmission data volume to less than 20% of the original shard. At the same time, a residual compensation mechanism is used to retain the cumulative effect of the filtered gradients.

[0084] After each round of federated aggregation, the controller compares the difference in the detection rate of shards on the adversarial test set before and after privacy processing. When it is detected that the ransomware recognition accuracy of medical shards drops by more than 2.5% due to noise enhancement, the noise variance decay coefficient of this shard in the next round of training is automatically adjusted, and a 15% quota is added to its privacy budget allocation to compensate for performance losses.

[0085] The whole process is closed-loop optimized through a dual-channel verification mechanism, including: using a differential privacy auditing tool to simulate a parameter reconstruction attack to verify the anti-reverse engineering ability of medical shards after noise injection; at the same time, by injecting simulated APT attack traffic in real time, ensuring that the compressed transmission of Internet of Things shards does not affect its detection sensitivity to covert communication links, and finally achieving the dynamic Pareto optimality of privacy protection intensity and threat recognition efficiency.

[0086] The parameter confusion operation in step S1b includes:

[0087] S1ba: Performing a random orthogonal matrix transformation on the shard parameters;

[0088] S1bb: Restore the original parameter semantics through inverse transformation during the model inference phase.

[0089] It should be further noted that in the specific implementation process, the parameter obfuscation operation achieves the balance between privacy protection and functional integrity through a reversible transformation mechanism, including: First, generate a matching random orthogonal matrix based on the data sensitivity level of the shard units. For example, use a 128-dimensional orthogonal matrix for sharding the patient behavior logs of medical institutions, and use a 64-dimensional matrix for sharding the regular traffic of the Internet of Things.

[0090] In the parameter obfuscation phase, perform a linear transformation on the neuron weight matrix within the shard and the orthogonal matrix, so that the transformed parameters lose the original hierarchical association characteristics between neurons, that is: for example, mix the fully connected layer parameters for abnormal access frequency detection and the convolution kernel parameters for vulnerability scan recognition into a new orthogonal space, destroying the attacker's ability to reverse-derive the complete model structure through a single shard. The transformed obfuscated parameters are transmitted to the central server through a secure channel to participate in federated aggregation, and at the same time, the inverse matrix of the corresponding orthogonal matrix is encrypted and stored at the local node.

[0091] When the global model update is completed and distributed to each node, perform an inverse transformation operation during the model inference phase, including: loading the stored inverse matrix to restore the obfuscated parameters and recover the threat detection function of the parameters in the original semantic space. For high-sensitivity data scenarios, such as financial transaction risk shards, adopt a dynamic orthogonal matrix update strategy, generate a new orthogonal matrix after each round of federated training and discard the historical matrix to prevent the obfuscation pattern from being cracked due to the long-term use of the same matrix. During the implementation process, verify the obfuscation effect through parameter reverse attack simulation, including: input the obfuscated medical shard parameters into the parameter reconstruction model, test the success rate of restoring the original patient access pattern features, and when it is detected that the reconstruction accuracy exceeds the preset threshold, automatically trigger the orthogonal matrix dimension upgrade mechanism to increase the matrix dimension from 128 dimensions to 256 dimensions to enhance the obfuscation intensity. For low-sensitivity scenarios such as Internet of Things shards, adopt a lightweight obfuscation strategy to reduce the computational overhead on the premise of ensuring that the reconstruction success rate is less than 0.5%.

[0092] This process ensures the lossless function through a dual verification mechanism, including: injecting standard test traffic into the restored parameter matrix, verifying that the deviation of the DDoS attack detection accuracy from the model before obfuscation does not exceed 0.8%, and at the same time comparing the model inference time before and after obfuscation to ensure that the time increase is controlled within 15 milliseconds, meeting the response requirements of real-time risk assessment.

[0093] The method for constructing a network risk assessment model based on an AI large model further includes a verification step:

[0094] Sx: Verify the anti-reconstruction ability of the shard unit through parameter shard reverse attack testing;

[0095] Sy: Quantify the privacy leakage risks at each stage using differential privacy auditing tools.

[0096] It should be further noted that in the specific implementation process, the parameter sharding reverse attack test and differential privacy auditing form a double-verification closed loop, including: First, construct a parameter reconstruction attack simulation environment, use a generative adversarial network to train a dedicated reverse model, and attempt to restore the patient access time distribution characteristics from the obfuscated medical shard parameters, or infer the transaction amount threshold pattern from the financial shards.

[0097] During the test, inject the shard parameters processed by noise into the reverse model, and evaluate the anti-attack ability by monitoring the reconstruction accuracy of the patient ID association field, that is: when the success rate of restoring the identity information of the medical institution shards exceeds the 0.35% threshold, automatically trigger the confusion matrix upgrade protocol, increase the orthogonal transformation dimension from 256 dimensions to 512 dimensions and enhance the noise variance.

[0098] At the same time, run the differential privacy auditing tool, implant virtual probes along the federated training link, and real-time track the privacy budget consumption trajectory of medical shards during the aggregation process, including: quantify the ε-differential privacy protection level at each stage by calculating the statistical difference degree between the parameter distribution after noise injection and the original data. When it is detected that the actual privacy consumption of the financial shards in a certain round of training exceeds the preset budget by 15%, immediately suspend the transmission of this shard and start the parameter re-obfuscation process.

[0099] During the auditing process, synchronously execute the membership inference attack simulation, and use the shadow model technology to attempt to infer whether a specific device participates in the training through the IoT shard parameters. When the membership identity inference accuracy exceeds the 51% baseline, automatically optimize the gradient compression threshold and noise ratio of this shard.

[0100] The results of the double verification are stored on the blockchain to form an immutable audit log, including: the noise intensity adjustment records of medical shards, the privacy budget overrun events of financial shards, and the membership inference protection records of IoT shards are all encrypted and uploaded to the chain for real-time inspection by regulatory agencies.

[0101] After the test phase, enable the fuse protection mechanism for the shards that pass the verification, that is: when a new type of reconstruction attack method is detected, automatically isolate the affected shards and call the threat knowledge distiller to generate targeted defense vectors, and at the same time update the global privacy policy library to enhance the protection intensity of subsequent training cycles, forming a dynamically evolving security verification system.

[0102] A system for constructing a network risk assessment model based on an AI large model, used to implement a method for constructing a network risk assessment model based on an AI large model, including:

[0103] A dynamic sharding module deployed on each node, used to generate semantically independent shard units;

[0104] The federated aggregation module of the central server receives and processes shard parameters;

[0105] The dual-channel verification module includes a threat knowledge distiller and an adversarial verifier;

[0106] The meta-learning regulation module dynamically optimizes the privacy policy and transmission efficiency of shard units.

[0107] It should be further noted that in the specific implementation process, the system realizes cross-institutional collaborative training through a modular architecture, including: The dynamic sharding module deployed on the medical institution node has a built-in feature sensitivity analysis unit that parses the abnormal access frequency and vulnerability scanning behavior in the local log in real time, splits the LSTM time series detection layer parameters and the fully connected layer alarm threshold parameters into independent shards through gradient sparsification mapping, and applies Gaussian noise with a standard deviation of 0.1 and a 256-dimensional orthogonal matrix confusion to the shards related to patient identity recognition.

[0108] The sharding module of the cloud service provider node focuses on the DDoS attack traffic characteristics, clusters the gating unit parameters of the recurrent neural network into independent shard units, and uses gradient compression coding to reduce the transmission data volume to 18% of the original parameters.

[0109] After receiving the encrypted shards from each node, the federated aggregation module of the central server performs noise distribution calibration and orthogonal inverse transformation, and performs weighted fusion of the abnormal period detection parameters of the medical institution and the traffic fluctuation recognition parameters of the cloud service provider in a unified feature space.

[0110] The dual-channel verification module starts operating synchronously, including: The threat knowledge distiller extracts cross-institutional common features from the aggregated parameters to generate a guidance vector. For example, it associates the high-frequency small packet transmission mode in the medical data shard with the short-term concurrent connection number feature of the cloud service shard to form a strengthened vector for ransomware behavior recognition; The adversarial verifier injects test traffic simulating zero-day vulnerability exploitation to verify whether the detection response time of the IoT device shard to the hidden backdoor in the firmware upgrade package is lower than the 150-millisecond threshold.

[0111] The meta-learning regulation module dynamically adjusts the noise standard deviation of the shard from 0.1 to 0.07 in the next round of training by real-time monitoring the privacy leakage risk assessment value and threat detection rate of the medical shard, and allocates an additional 15% privacy budget to balance the performance loss.

[0112] Data interaction between modules is carried out through blockchain middleware to ensure that key operation information such as the confusion matrix version of medical shards and the compression coding record of cloud service shards is stored on the chain in real time, forming an immutable audit tracking link.

[0113] In the cross-border transmission scenario, the system enables a shard integrity verification mechanism, including: the IoT nodes calculate the SHA-3 hash digest of the shard parameters and append a digital signature before transmission, and the federated aggregation module double-checks the data integrity through signature verification and hash comparison after receiving, to avoid the risk of shard tampering caused by cross-border network hijacking.

[0114] The dynamic sharding module includes: a feature sensitivity analysis unit that identifies high-risk threat features in local data; a gradient sparsification mapping unit that splits model parameters according to feature correlation.

[0115] It should be further noted that in the specific implementation process, the feature sensitivity analysis unit of the dynamic sharding module identifies high-risk threat patterns by real-time parsing the multi-dimensional time-series features of local data, including: the medical institution node continuously monitors the abnormal access frequency during abnormal periods, the sequence of unconventional packet sizes, and the time clustering of vulnerability scanning behaviors in the patient access logs, uses the sliding window algorithm to extract abnormal intervals where the hourly access volume mutation exceeds 200%, and locates the fully connected layer parameters in the model that are strongly correlated with the above features through convolutional kernel weight analysis.

[0116] The gradient sparsification mapping unit performs dynamic sharding based on the contribution degree of the parameters' gradients to threat detection, including: for the abnormal period detection requirement of medical nodes, clustering the gating parameters that control the sliding of the time window in the LSTM layer and the alarm threshold weights of the fully connected layer into independent shards; for the device fingerprint mutation detection task of IoT nodes, extracting the filter parameters responsible for protocol type recognition in the convolutional neural network as the core shard unit.

[0117] An adaptive threshold strategy is adopted during the sharding process. When it is detected that the change in the feature correlation distribution is caused by a new type of phishing attack, the sharding coverage range is automatically expanded, that is: incorporating the query matrix parameters related to the camouflaged domain name feature extraction in the newly emerged Transformer attention heads into the existing shards. After the sharding division, Gaussian noise with a standard deviation of 0.08 is applied to the medical data shards, and linear transformation confusion is performed through a pre-generated 384-dimensional orthogonal matrix, so that the patient visit time distribution cannot be reverse-derived from a single shard parameter; while the IoT shards adopt lightweight processing, only adding noise with a standard deviation of 0.03 and performing a 128-dimensional orthogonal transformation.

[0118] Before shard transmission, double verification is carried out, including: testing the anti-reverse engineering ability of medical shards using a parameter reconstruction attack model to ensure that the success rate of restoring patient identity information is less than 0.25%; at the same time, injecting simulated APT attack traffic to verify the functional integrity of IoT shards, and confirming that the deviation of the device abnormal behavior detection accuracy does not exceed 1.2%.

[0119] The entire process records the shard version, the hash value of the confusion matrix, and the verification result through the blockchain, forming a traceable security audit chain.

[0120] In the dual-channel verification module: The threat knowledge distiller generates a threat feature guidance vector through a cross-domain feature fusion algorithm; the adversarial verifier uses an adversarial sample evolution engine to generate a test set and perform blind spot detection.

[0121] It should be further noted that in the specific implementation process, the dual-channel verification module achieves double guarantees of model security and accuracy through the coordinated operation of the threat knowledge distiller and the adversarial verifier, including: The threat knowledge distiller first performs cross-domain feature alignment on the abnormal access period detection shards uploaded by medical institution nodes, the DDoS traffic pattern shards of cloud service provider nodes, and the protocol anomaly shards of Internet of Things devices, and uses a multi-head attention mechanism to extract common high-risk features across nodes, that is: identifying the spatio-temporal correlation between the transmission pattern of small data packets with ultra-high frequency per hour in medical data shards and the feature of a sharp increase in the number of short-term TCP connections in cloud service shards, and fusing them into a threat feature guidance vector with the dimension compressed to 12% of the original parameters. This vector is fed back to each node through a quantum key encryption channel, driving medical nodes to strengthen the threshold adaptive ability of the abnormal period detection model, and at the same time guiding Internet of Things nodes to optimize the update direction of the convolutional kernel parameters for protocol fingerprint mutation recognition.

[0122] The adversarial verifier synchronously starts blind spot detection of the attack surface, including: dynamically synthesizing test traffic containing the characteristics of new ransomware variants based on a generative adversarial network, such as simulating encrypted communication traffic that exploits vulnerabilities in the PACS system of medical institutions, or disguised hidden C2 instruction data packets in the firmware upgrade package of Internet of Things devices.

[0123] Inject the test set into the sub-models of each node's shards and monitor their response effectiveness, that is: when the misjudgment rate of the cloud service shard for encrypted mining pool traffic exceeds 18% or the detection delay of the medical shard for the encryption mode of variant ransomware is higher than 250 milliseconds, mark the corresponding shard as a high-risk unit and trigger the isolation mechanism. The valid shards that pass the verification enter the global aggregation queue with digital signatures, while the shards that fail call the threat knowledge distiller to generate targeted enhancement samples, such as supplementing encrypted log data simulating zero-day vulnerability exploitation for medical shards, and guiding them to optimize the gating parameters of the LSTM time series detection layer in the next round of training. The verification results are stored in the blockchain in real time, recording the detection metrics, handling measures, and adversarial sample evolution versions of each shard, forming an immutable audit tracking chain.

[0124] In the model update stage, the threat knowledge distiller performs cross-verification on the global aggregation parameters and the verification results. For example, comparing the deviation of the ransomware detection rate of the medical shard before and after noise injection, dynamically optimizing the generation weight of the next round of feature guidance vectors to ensure that privacy processing does not result in the loss of key threat features.

[0125] Through an innovatively designed dynamic sharding federated distillation learning framework, the inherent contradiction between data privacy protection and the training efficiency of large AI models in cross-institutional collaboration is effectively solved. An adaptive parameter sharding mechanism is adopted to disassemble a model with tens of billions of parameters into semantically independent units. Combining local differential privacy and parameter obfuscation technologies, while ensuring the physical isolation of sensitive data in fields such as healthcare and finance, compared with traditional federated learning, the communication overhead is reduced. At the same time, through a hierarchical distillation verification system, cross-domain fusion of threat features and detection of blind spots in the attack surface are realized, improving the detection rate of APT attacks and controlling the model synchronization delay. The meta-learning-driven dynamic privacy regulation mechanism breaks through the fixed noise injection mode and realizes the real-time adaptation of privacy budgets and threat feature contribution degrees, taking into account model accuracy and security under compliance frameworks such as GDPR, and significantly improving the feasibility of cross-border and cross-industry collaboration scenarios.

[0126] By constructing a closed-loop security protection system through a dual-verification mechanism, the success rate of reconstructing sensitive data is reduced, meeting the requirements of highly regulated industries such as healthcare and finance; secondly, based on the blockchain's audit tracking and smart contract automatic execution mechanism, it ensures the trustworthy deposit and real-time monitoring of key links such as sharded transmission and aggregation verification; thirdly, the dynamic attack and defense evolution ability is continuously upgraded through the adversarial sample evolution engine, improving the response time of the model to new threats such as zero-day vulnerabilities and variant ransomware.

[0127] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising a..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.

[0128] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A method for constructing a network risk assessment model based on an AI large model, characterized in that It includes the following steps: Step S1: Based on local multi-source heterogeneous data, the participating nodes disassemble the large model into multiple semantically independent shard units through a dynamic sharding mechanism, and each shard unit retains a subset of parameters associated with preset high-risk threat features; Step S2: In the federated aggregation stage, each node transmits the highly sensitive shard parameters processed by local differential privacy to the central server; Step S3: The central server reconstructs the global model through a threat knowledge distiller and generates a threat feature guidance vector. At the same time, it performs attack surface blind spot detection on the shard parameters through an adversarial verifier; Step S4: Based on the meta-learning controller, dynamically adjust the noise injection intensity, transmission frequency, and privacy budget allocation of the shard units to achieve a dynamic balance between privacy protection and threat detection accuracy.

2. The method for constructing a network risk assessment model based on an AI large model according to claim 1, wherein: The dynamic sharding mechanism in Step S1 includes: S1a: Through the gradient sparsification mapping algorithm, split the large model parameters into semantically independent shard units according to the attack feature correlation; S1b: Add a noise matrix to the highly sensitive shards and perform parameter confusion operations to destroy the linear correlation between parameters.

3. The method for constructing a network risk assessment model based on an AI large model according to claim 1, characterized in that: The threat knowledge distiller in Step S3 performs the following operations: S3a: Extract cross-domain common threat features from the shard parameters of each node; S3b: Generate a low-dimensional threat feature guidance vector through the feature importance weighting algorithm; S3c: Feedback the guidance vector to each node through a secure channel to drive the local model to optimize key risk features.

4. A method for constructing a network risk assessment model based on an AI large model according to claim 1, characterized in that: The adversarial verifier in Step S3 includes: S3d: Synthesize test samples containing zero-day vulnerability features based on the generative adversarial network; S3e: Perform adversarial robustness evaluation on the shard parameters, and only retain the shards that pass the blind spot detection to participate in the global model update.

5. A method for constructing a network risk assessment model based on an AI large model according to claim 1, characterized in that: The meta-learning controller in Step S4 performs the following operations: S4a: Quantify the privacy leakage risk coefficient and feature contribution degree of the shards in real time; S4b: Increase the noise injection intensity for the shards corresponding to medical and financial data and enable a parameter confusion matrix; S4c: Adopt gradient compression coding technology for the shards corresponding to Internet of Things data to improve the transmission efficiency.

6. The method for constructing a network risk assessment model based on an AI large model according to claim 2, wherein: The parameter confusion operation in Step S1b includes: S1ba: Perform random orthogonal matrix transformation on the shard parameters; S1bb: Restore the original parameter semantics through inverse transformation in the model inference stage.

7. A method for constructing a network risk assessment model based on an AI large model according to claim 1, characterized in that: The method for constructing a network risk assessment model based on an AI large model further includes verification steps: Sx: Verify the anti-reconstruction ability of the shard units through parameter shard reverse attack testing; Sy: Quantify the privacy leakage risk at each stage using a differential privacy auditing tool.

8. A network risk assessment model construction system based on the AI large model, which is used to implement the method described in any one of claims 1-7, and is characterized in that, It includes: A dynamic sharding module deployed on each node, used to generate semantically independent shard units; The federated aggregation module of the central server, which receives and processes shard parameters; A dual-channel verification module, including a threat knowledge distiller and an adversarial verifier; A meta-learning regulation module, which dynamically optimizes the privacy strategy and transmission efficiency of shard units.

9. The network risk assessment model construction system based on the AI large model according to claim 8, characterized in that: The dynamic sharding module includes: A feature sensitivity analysis unit, which identifies high-risk threat features in local data; A gradient sparsification mapping unit, which splits model parameters according to feature correlation.

10. The system for constructing a network risk assessment model based on an AI large model according to claim 8, wherein: In the dual-channel verification module: The threat knowledge distiller generates a threat feature guidance vector through a cross-domain feature fusion algorithm; The adversarial validator uses the adversarial sample evolution engine to generate a test set and perform blind spot detection.

Citation Information

Cited By

  • Intelligent private data fragmentation and recombination method and system based on AI

    CN120632943A

  • Attack surface cross-domain increment parallel updating method based on Transform model

    CN120743920A

  • Information security supervision AI platform

    CN120744959A

  • Information security supervision AI platform

    CN120744959B

  • Large model privacy protection method and device

    CN121256859A