Network security risk assessment system and method based on artificial intelligence

Through dynamic collaborative aggregation and trust game incentive mechanism combined with multimodal data fusion and heterogeneous proxy optimization, the problem of insufficient adaptability of data privacy leakage and dynamic threats in traditional network security risk assessment is solved, and an efficient and secure network security risk assessment is achieved.

CN120498791AActive Publication Date: 2025-08-15SHANGHAI FOUR-LEAF CRUCI INFORMATION TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510671910.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-23
Publication Date
2025-08-15
Estimated Expiration
2045-05-23

AI Technical Summary

Technical Problem

Traditional cybersecurity risk assessment methods require centralized sharing of raw data, resulting in the risk of data privacy leakage and difficulty in dealing with rapidly changing cyber threat environments. The existing federated learning methods cannot fully consider data quality and threat relevance, and lack effective trust mechanisms, resulting in low collaboration efficiency and insufficient security.

Method used

The dynamic collaborative aggregation concept (DSA) and trust game incentive mechanism (TGIM) are combined, and the model is updated through the blockchain trust module, multimodal data is fused using the multimodal semantic distillation method (MTSD), and the global model is dynamically optimized by heterogeneous agent collaborative evolution method (HACE) to achieve cross-organizational collaboration and dynamic threat adaptation.

Benefits of technology

On the premise of protecting data privacy, efficient cross-organization collaboration is achieved, which improves threat detection accuracy and response capabilities to dynamic threats, ensures fairness and security of collaboration, and adapts to complex cyber threat environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498791A_ABST
    Figure CN120498791A_ABST
Patent Text Reader

Abstract

The invention provides a network security risk assessment system and method based on artificial intelligence, relates to the technical field of network information security, and adopts innovative fusion of a dynamic collaborative aggregation concept (DSA) and a trusted game motivation mechanism (TGIM) to realize efficient cross-organization collaboration on the premise of completely protecting data privacy. According to the DSA algorithm, model parameters are dynamically weighted and aggregated by using a data utility factor (DUF) and a threat association degree quantity (TCM), a high-quality global model can be generated without sharing original data, the risk of data leakage is greatly reduced, the TGIM designs a trust score and an exponential return function based on the game theory, high-quality contribution is stimulated, malicious behaviors are effectively prevented, cooperation fairness is ensured, and the method has the advantages of being high in robustness and high in reliability. The decentralized cooperation mode significantly improves the ability of multi-organization cooperation to cope with complex network threats, seamlessly combines privacy protection with efficient cooperation, provides a brand new security assessment normal form for sensitive industries such as finance and medical treatment, and has wide application potential.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network information security technology, and specifically to an artificial intelligence-based network security risk assessment system and method. Background Art

[0002] According to a network security assessment and protection method based on artificial intelligence disclosed in China with the publication number "CN118694600A", the method includes security assessment of each data type, presetting security protection level and encryption strategy and matching encryption strategy, presetting storage protection level and storage strategy and matching storage strategy, and verifying and calculating network data. In this application, by performing security assessment on each data type, a data reference is provided for adopting corresponding encryption strategy and storage strategy; by presetting security protection level and corresponding encryption strategy and matching encryption strategy, effective hierarchical security protection of network data is achieved; by presetting storage protection level and corresponding storage strategy and matching storage strategy, effective hierarchical storage protection of network data is achieved; by verifying and calculating network data based on the verification cycle, timely discovery of tampered network data is achieved. Finally, network security assessment and protection based on artificial intelligence is achieved.

[0003] According to Chinese publication number "CN117973695B," an artificial intelligence-based network security incident assessment method and system, belonging to the field of network security technology, includes: collecting original security incidents, presetting security type labels, establishing an instance data mapping set, and constructing an association tree to obtain an association rule set; extracting fusion features based on the association rules, presetting a classification model, and classifying the original security incidents in combination with the classification model, and presetting a malicious behavior matrix; establishing an optimization model, using the optimization model to perform trend analysis on the classified samples to obtain a propensity, and optimizing the classification model based on the propensity; determining evaluation indicators based on the classification results generated by the optimized classification model to obtain an indicator factor set and construct an evaluation indicator system; dividing the evaluation indicators into a multi-layer structure, and determining the threat level of the network security situation through a hierarchical assessment method. This reduces manual intervention and improves the system's analysis efficiency and adaptability.

[0004] The above patent documents and prior art have the following technical problems when used:

[0005] Problem 1: Traditional cybersecurity risk assessment methods typically require centralized sharing of raw data to build global models, leading to data privacy risks. This is particularly true in sensitive industries such as finance and healthcare, where data silos severely limit the efficiency of cross-organizational collaboration. While existing federated learning methods can partially protect privacy, their static aggregation mechanisms (such as simple parameter averaging) fail to fully consider data quality and threat relevance, resulting in insufficient global model performance. Furthermore, the lack of an effective trust mechanism makes collaboration vulnerable to malicious interference, making it difficult to ensure fairness and security.

[0006] Second, traditional cybersecurity risk assessment systems rely on static threat models, making them incapable of responding to the rapidly evolving threat landscape, such as new attack models like zero-day vulnerabilities and advanced persistent threats (APTs). Existing methods lack effective multimodal data fusion mechanisms when processing multi-source threat intelligence, resulting in incomplete feature extraction and limited threat detection accuracy. Furthermore, traditional optimization algorithms (such as reinforcement learning) are prone to local optimality in complex environments, making it difficult to dynamically adjust models to adapt to unknown threats. Summary of the Invention

[0007] Technical problems solved

[0008] In response to the shortcomings of the existing technology, the present invention provides an artificial intelligence-based network security risk assessment system and method, which solves the following problems:

[0009] 1. Addressing the conflict between data privacy and cross-organizational collaboration in traditional cybersecurity risk assessments;

[0010] 2. Address the problem that traditional risk assessment systems are not adaptable enough to dynamic threat environments.

[0011] Technical Solution

[0012] To achieve the above objectives, the present invention is implemented through the following technical solutions: a network security risk assessment system and method based on artificial intelligence, the method comprising the following steps:

[0013] Sp1: At each participating organization, local network security data is preprocessed, and data features containing threat-related information are generated through feature extraction algorithms. Local model parameters are then generated based on these features.

[0014] Sp2: Aggregate local model parameters of each organization to generate a global model through the Dynamic Collaborative Aggregation (DSA) concept. The DSA concept dynamically calculates nonlinear weighting coefficients based on the Data Utility Factor (DUF) and Threat Correlation Metric (TCM) to achieve intelligent parameter fusion.

[0015] Sp3: Leveraging the blockchain trust module, the Trust Game Incentive Mechanism (TGIM) is used to record model updates contributed by participating organizations. Through game theory, trust scores are dynamically adjusted to incentivize high-quality contributions, ensuring fairness and security in collaboration.

[0016] Sp4: Through the threat intelligence analysis module, the Multimodal Semantic Distillation (MTSD) method is used to fuse multimodal data such as text, event logs, and network traffic to extract threat features and input them into the global model to improve threat detection accuracy.

[0017] Sp5: Using the adaptive optimization module, the heterogeneous agent co-evolution method (HACE) is used to dynamically optimize the global model and adapt to the dynamic threat environment through competition and cooperation among multiple agents;

[0018] Sp6: Each participating organization downloads the global model, performs local cybersecurity risk assessments, and uploads the assessment feedback to optimize the next round of global models.

[0019] Preferably, the dynamic collaborative aggregation concept (DSA) in step Sp2 calculates the data utility factor (DUF) based on the diversity, timeliness and threat detection contribution of the data, calculates the threat correlation measure (TCM) based on the feature similarity between local data and threat intelligence, and uses a nonlinear fusion function to generate aggregation weights to ensure that the global model reflects the impact of high-quality data.

[0020] Preferably, the trust game incentive mechanism (TGIM) of step Sp3 calculates the trust score (TS) based on the game theory model, dynamically updates it according to historical behavior and current contribution, and uses an exponential reward function to (in (Contribution) encourages high-quality updates and punishes malicious behavior.

[0021] Preferably, the multimodal semantic distillation method (MTSD) in step Sp4 uses term frequency-inverse threat frequency (TF-ITF) to extract text features, analyze the temporal characteristics of event logs and the statistical patterns of network traffic, fuse multimodal data through non-negative matrix decomposition, and generate a compact threat feature representation.

[0022] Preferably, the heterogeneous agent co-evolution method (HACE) in step Sp5 sets feature optimization agents, parameter adjustment agents and threat prediction agents, dynamically adjusts the global model through competition and cooperation mechanisms, and improves adaptability to unknown threats.

[0023] Preferably, the data utility factor (DUF) in step Sp2 is calculated by using feature distribution entropy to evaluate data diversity, using time decay function to evaluate data timeliness, and using the gain evaluation contribution of the local model to global threat detection.

[0024] Preferably, the trust score (TS) update rule of the trust game incentive mechanism (TGIM) in step Sp3 is that if the model update improves the global performance, the trust score (TS) is increased; if a malicious update is detected, the trust score (TS) is reduced through an anomaly detection algorithm.

[0025] Preferably, the multimodal semantic distillation method (MTSD) in step Sp4 uses non-negative matrix decomposition to integrate text, log and traffic data into a unified semantic space when fusing multimodal features, and retains key threat information through iterative optimization.

[0026] Preferably, the agent functions of the heterogeneous agent co-evolution method (HACE) in step Sp5 include feature optimization agents selecting key features, parameter adjustment agents fine-tuning model parameters, and threat prediction agents predicting potential threat trends, and the agents work collaboratively by sharing optimization goals.

[0027] Preferably, the various modules of the system of the method are interconnected through data flow and collaboration mechanisms to support decentralized collaboration and dynamic threat adaptation, and further include the following:

[0028] A local data processing module, which collects cybersecurity data from participating organizations, extracts threat-related features, and generates local model parameters;

[0029] The collaborative learning module implements the concept of dynamic collaborative aggregation (DSA) and generates a global model by dynamically weighting aggregation parameters based on the data utility factor (DUF) and threat correlation metric (TCM) through the aggregation engine;

[0030] The blockchain trust module runs the distributed ledger and the Trust Game Incentive Mechanism (TGIM) smart contract to record model updates and incentivize high-quality contributions;

[0031] The threat intelligence analysis module fuses multimodal data through the Multimodal Semantic Distillation method (MTSD), extracts threat features, and inputs them into the global model;

[0032] Adaptive optimization module, which uses heterogeneous agent co-evolution (HACE) to manage competition and cooperation among multiple agents and optimize global model performance;

[0033] The user interface and management module provides an interactive interface and monitoring dashboard for viewing risk assessment results and receiving alerts.

[0034] Beneficial effects

[0035] The present invention provides an artificial intelligence-based network security risk assessment system and method. It has the following beneficial effects:

[0036] 1. This invention adopts the innovative fusion of the dynamic collaborative aggregation concept (DSA) and the trust game incentive mechanism (TGIM), achieving efficient cross-organizational collaboration under the premise of fully protecting data privacy, breaking through the limitations of data silos in traditional network security risk assessment. The DSA algorithm uses the data utility factor (DUF) and threat correlation metric (TCM) to dynamically weight and aggregate model parameters to generate high-quality global models without sharing original data, greatly reducing the risk of data leakage. TGIM designs trust scores and exponential reward functions based on game theory to incentivize high-quality contributions, effectively prevent malicious behavior, and ensure collaborative fairness. The decentralized collaboration model significantly enhances the ability of multiple organizations to collaboratively respond to complex network threats, seamlessly combining privacy protection with efficient collaboration, and provides a new security assessment paradigm for sensitive industries such as finance and healthcare, with broad application potential.

[0037] 2. The unique design of Multimodal Semantic Distillation (MTSD) and Heterogeneous Agent Co-evolution (HACE) in this invention transcends the traditional risk assessment system's reliance on static threat models and implements intelligent adaptive optimization for dynamic threat environments. MTSD fuses multimodal data such as text, logs, and traffic to generate compact and highly relevant threat signatures, enabling the system to quickly identify new attack patterns, such as zero-day vulnerabilities or advanced persistent threats (APTs). HACE dynamically adjusts the global model through feature optimization, parameter adjustment, and the co-evolution of threat prediction agents, significantly improving its responsiveness to unknown threats. The creativity of the adaptive mechanism lies in its multi-agent collaboration and multimodal feature integration, which overcomes the local optimality problem of traditional reinforcement learning in complex environments. As a result, the system can maintain high accuracy and robustness in rapidly changing network security environments, providing continuous protection for critical infrastructure and enterprise networks, demonstrating a major technological breakthrough. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 A step diagram of the security risk assessment method of the present invention;

[0039] Figure 2 This is a structural diagram of the safety assessment system of the present invention;

[0040] Figure 3 This is a graph showing how the accuracy of the global model of the present invention changes with the number of iterations;

[0041] Figure 4 A distribution diagram of trust scores of various organizations in the present invention;

[0042] Figure 5 This is the MTSD multimodal feature extraction effect diagram of the present invention. DETAILED DESCRIPTION

[0043] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention. Specific embodiment one:

[0045] like Figures 1 to 5 As shown in the figure, the network security risk assessment system and method based on artificial intelligence is designed to achieve decentralized, privacy-preserving and dynamically adaptive network security risk assessment through artificial intelligence technology. The method uses the local data of each participating organization to generate model parameters, generates a global model through dynamic collaborative aggregation, and combines the blockchain trust mechanism, threat intelligence analysis and adaptive optimization to form a closed-loop system. The operation process includes two stages: initialization and loop iteration:

[0046] Initialization: Each participating organization joins the platform, configures local data processing modules, and prepares to participate in the collaboration;

[0047] Iterative loop: Continuously run the following six steps (Sp1 to Sp6), optimizing the global model with each iteration to improve the accuracy of risk assessment and adaptability to dynamic threats.

[0048] The method comprises the following steps:

[0049] Step Sp1: Local data preprocessing and model parameter generation: At each participating organization, local network security data is preprocessed, and data features containing threat-related information are generated through feature extraction algorithms, and local model parameters are generated based on this. This process starts with data collection. Each organization obtains local network security data from its network devices (such as firewalls, routers), system logs and security tools, including traffic data, event logs (such as login records), anomaly alarms, etc. Then, a custom feature extraction algorithm (such as the threat-based term frequency-inverse threat frequency method, TF-ITF) is used to extract key threat-related features from this data, such as abnormal traffic patterns (such as sudden high traffic), malicious IP addresses, frequent abnormal login attempts, etc. These features provide a basis for subsequent modeling by quantifying threat relevance. Afterwards, the extracted features are used to train local machine learning models (such as neural networks or decision trees) to generate model parameters (such as weights and biases of neural networks, or node splitting rules of decision trees). This step ensures that each organization converts local threat information into shareable model parameters while protecting data privacy, laying the foundation for the construction of a global model.

[0050] Step Sp2: Dynamic collaborative aggregation to generate a global model: The local model parameters of each organization are aggregated through the concept of dynamic collaborative aggregation (DSA) to generate a global model. In this process, each organization first uploads the local model parameters to the central server or blockchain network. The aggregation process dynamically calculates the nonlinear weighting coefficient based on the data utility factor (DUF) and threat correlation measurement (TCM) to achieve intelligent fusion of parameters. Specifically, DUF evaluates the value of data in three aspects: first, the diversity of data is evaluated by the entropy value of feature distribution (the higher the entropy value, the stronger the diversity); second, the time decay function (such as exponential decay) is used to evaluate the timeliness of data to ensure the recent data More influential; thirdly, the contribution of the local model to the gain of global threat detection (such as improved accuracy) is evaluated, while TCM is based on the feature similarity between local data and current threat intelligence (such as calculating the matching degree between abnormal patterns and known threats through cosine similarity). During aggregation, a nonlinear fusion function (such as the sigmoid function) is used to generate the aggregation weights of each organization's parameters based on DUF and TCM, and the parameters are weighted averaged to generate a global model to ensure that the model reflects the impact of high-quality data. Finally, the aggregated global model is distributed back to each participating organization. This step balances the contribution of each organization through a dynamic weighting mechanism to achieve efficient parameter fusion.

[0051] Step Sp3: Blockchain trust and incentive mechanism: Utilize the blockchain trust module and adopt the trust game incentive mechanism (TGIM) to record the model updates contributed by each participating organization. Dynamically adjust the trust score and incentivize high-quality contributions through game theory to ensure the fairness and security of collaboration. The process starts with the calculation of the trust score (TS). Based on the game theory model, the TS is dynamically updated based on the organization's historical behavior (such as whether parameters are submitted on time) and current contribution (the improvement of parameters on global model performance). If the model update improves the global performance (such as the detection rate), the TS is increased; if a malicious update (such as deliberately submitting wrong parameters) is identified through an anomaly detection algorithm (such as the isolation forest), the TS is reduced. The incentive distribution adopts an exponential reward function. (in The trust score is calculated based on the contribution of the model (e.g., the improvement of the parameters on the global model accuracy). High-quality updates are rewarded exponentially while malicious behavior is penalized. All model updates and trust score adjustments are recorded on the blockchain, leveraging its distributed ledger properties to ensure transparency and immutability. This step ensures the security of collaboration and the enthusiasm of participants through the dual mechanisms of trust and incentives.

[0052] Step Sp4: Threat intelligence analysis and feature extraction: Through the threat intelligence analysis module, the multimodal semantic distillation method (MTSD) is used to fuse multimodal data such as text, event logs and network traffic, extract threat features and input them into the global model to improve the accuracy of threat detection. The process starts with data collection from external threat intelligence sources, including text reports (such as security announcements), event logs and network traffic data. Feature extraction is performed separately for different modalities: for text, the TF-ITF method is used to extract keywords and threat patterns (such as "ransomware" or "SQL injection"); for event logs, time series features are analyzed (such as the time series pattern of abnormal events); for network traffic, statistical patterns (such as packet size distribution) are analyzed to detect abnormal traffic. Then, these multimodal features are integrated into a unified semantic space through non-negative matrix factorization (NMF) to eliminate inter-modal heterogeneity. Subsequently, feature distillation is performed through iterative optimization (such as gradient descent), retaining the compact feature representation most relevant to the threat (such as a high-risk IP list or attack pattern vector) and eliminating redundant information. These features are input into the global model to further improve its detection accuracy. This step provides high-quality threat input to the global model through multimodal fusion and feature refinement.

[0053] Step Sp5: Adaptive optimization of the global model: Using the adaptive optimization module, the heterogeneous agent co-evolution method (HACE) is used to dynamically optimize the global model, and adapt to the dynamic threat environment through competition and cooperation among multiple agents. The process starts with agent setting and includes three types of agents: feature optimization agents are responsible for selecting the most important features for threat detection (such as high-correlation feature vectors); parameter adjustment agents fine-tune global model parameters (such as adjusting neural network weights); threat prediction agents predict potential threat trends (such as predicting the possibility of DDoS attacks based on historical data). These agents work through a co-evolution mechanism: under the competition mechanism, agents compete for computing resources based on performance (such as the accuracy of feature selection or the F1 score of prediction); under the cooperation mechanism, agents share optimization goals (such as the overall detection rate of the global model) and information (such as threat trend data) to jointly improve performance. Through dynamic adjustment between agents, the parameters and feature selection of the global model are continuously optimized to adapt to the ever-changing threat environment (such as new attack methods). This step ensures that the global model maintains high adaptability and robustness through the synergy of heterogeneous agents.

[0054] Step Sp6: Risk assessment and feedback: Each participating organization downloads the global model, performs local network security risk assessment, and uploads the assessment feedback to optimize the next round of global models. The process starts with model downloading. Each organization obtains the latest global model from the central server or blockchain network. Then, the global model is used to conduct risk assessment on local network security data and generate risk reports (such as identifying high-risk vulnerabilities or potential attack paths). The assessment results and feedback (such as detected threat types and false positives) are uploaded to the system for optimizing the next round of global model training, such as adjusting feature weights or correcting model biases. This step forms a closed loop of continuous improvement of the global model through the local evaluation and feedback mechanism to ensure the system's adaptability to specific threats from each organization.

[0055] like Figure 3 As shown in the figure, the global model accuracy improves with the number of iterations, reflecting the effects of DSA and HACE. Figure 4 As shown in the figure, the distribution of trust scores (TS) of each organization is displayed, reflecting the incentive mechanism of TGIM, such as Figure 5 As shown in the figure, the effect of multimodal feature extraction is demonstrated, reflecting the contribution of MTSD. This method realizes intelligent parameter aggregation through DSA, TGIM ensures collaborative fairness, MTSD improves threat detection accuracy, HACE enhances model adaptability, and combines blockchain technology to ensure security. Specific embodiment two:

[0057] like Figures 1 to 5 As shown, based on the content in the above specific embodiments, the following contents are further disclosed:

[0058] Local data processing module: It consists of a data collector, a feature extractor, and a local model trainer. The data collector collects raw network security data from the network devices (such as firewalls, routers), system logs, and security tools of each participating organization, including traffic data, event logs, and abnormal alarms. The feature extractor uses a custom algorithm (such as the threat-based TF-ITF algorithm) to extract key threat-related features from these data, such as abnormal traffic patterns, malicious IP addresses, or abnormal login attempts. The feature extraction process is based on threat correlation quantification to provide reliable input for subsequent modeling. The local model trainer uses the extracted features to train through a machine learning model (such as a neural network or decision tree) to generate local model parameters (such as weights and biases). While protecting the data privacy of each organization, the local network security data is converted into shareable model parameters, laying the foundation for the construction of the global model while reducing the security risks brought by the transmission of raw data.

[0059] Collaborative learning module: includes parameter uploader, aggregation engine and model distributor. The parameter uploader is responsible for securely uploading the local model parameters generated by each organization to the central server or blockchain network. The aggregation engine implements the dynamic collaborative aggregation concept (DSA) and dynamically generates weighted coefficients through data utility factor (DUF) and threat correlation measurement (TCM). DUF is calculated based on data diversity (feature entropy value), timeliness (time decay function) and contribution (gain to global threat detection). TCM measures the feature similarity between local data and threat intelligence. The aggregation process uses a nonlinear fusion function (such as sigmoid) to perform weighted averaging on the parameters to generate a global model. The model distributor distributes the generated global model back to the participating organizations for use. Through intelligent parameter aggregation, the module balances the contribution differences of each organization, achieves efficient model fusion, and improves the threat detection capability of the global model.

[0060] The blockchain trust module consists of blockchain nodes, smart contracts, and contribution evaluators. The blockchain nodes run the distributed ledger protocol, record all model parameter updates and transaction information, and ensure that the data cannot be tampered with. The smart contract implements the Trust Game Incentive Mechanism (TGIM), automatically managing the organization's trust score (TS) and incentive distribution. The contribution evaluator is based on a game theory model and calculates TS based on the organization's historical behavior and current parameter contribution. If the parameter update improves the global model performance, the TS increases; if a malicious or low-quality update is detected, the TS decreases. The incentive distribution adopts an exponential reward function. (in It rewards high-quality contributions based on contribution rate, ensures the fairness, security and transparency of the collaboration process through a decentralized trust mechanism, encourages high-quality participation and prevents malicious behavior.

[0061] The threat intelligence analysis module includes a data collector, a multimodal fusion unit, and a feature distiller. The data collector obtains multimodal data from external threat intelligence sources, such as text-based threat reports, event logs, and network traffic data. The multimodal fusion unit extracts features for different data types: for text data, the TF-ITF algorithm is used to extract keywords; for log data, time series features are analyzed; for traffic data, statistical patterns are extracted. Subsequently, the multimodal features are integrated into a unified semantic space through non-negative matrix factorization (NMF). The feature distiller uses iterative optimization methods (such as gradient descent) to retain key threat-related information, generate compact feature representations, and input them into the global model. By fusing multi-source threat intelligence, this module improves the threat detection accuracy of the global model and helps the system cope with complex and changing network attacks.

[0062] The adaptive optimization module consists of an agent manager, a competition and cooperation mechanism, and an optimization engine. The agent manager sets up three types of heterogeneous agents: feature optimization agents are responsible for selecting key features, parameter adjustment agents fine-tune model parameters, and threat prediction agents predict threat trends. Under the competition mechanism, each agent competes for resources based on optimization performance; under the cooperation mechanism, optimization goals and information are shared. The optimization engine dynamically adjusts global model parameters based on agent feedback. The model is optimized through the heterogeneous agent co-evolution method (HACE) to adapt it to the dynamic threat environment. Through the co-evolution among multiple agents, the adaptability and robustness of the global model are improved, ensuring that the system remains efficient in the face of emerging threats.

[0063] The user interface and management module consists of a web interface, a monitoring dashboard, and an alert system. The web interface provides user interaction functions, supporting operations such as user login, data upload, and viewing risk assessment reports. The monitoring dashboard displays information such as system health status, risk score, and threat distribution in real time. When a network security incident is detected, the alert system prompts users to take action through real-time notifications (such as emails or pop-ups). This module enhances the user experience and ensures that organizations can easily use the system and respond to security incidents in a timely manner.

[0064] Each module is closely interconnected through data flow and collaboration mechanisms to form a system that supports decentralized collaboration and dynamic threat adaptation. Specifically, after the local data processing module generates model parameters, the collaborative learning module aggregates them, the blockchain trust module records updates and provides incentives, the threat intelligence analysis module integrates external intelligence and extracts features, the adaptive optimization module dynamically adjusts the global model, and the user interface and management module presents the results to the user. The modular design ensures the efficient operation of the system while taking into account privacy protection and performance optimization. Through the collaborative work of local data processing, collaborative learning, blockchain trust, threat intelligence analysis, adaptive optimization, and user interface and management modules, combined with algorithms DSA, TGIM, MTSD, and HACE, efficient and decentralized network security risk assessment is achieved. The modules have clear division of labor and support each other, ensuring that the system has the ability and practicality to dynamically adapt to threats while protecting data privacy. Specific embodiment three:

[0066] like Figures 1 to 5 As shown, based on the content in the above specific embodiments, the following contents are further disclosed:

[0067] According to the contents of the above-mentioned specific embodiment 1 and specific embodiment 2, the algorithm corresponding to the above-mentioned system and method further includes the following contents:

[0068] Dynamic Synergistic Aggregation (DSA) concept:

[0069]

[0070]

[0071]

[0072]

[0073] in:

[0074] : global model parameters (such as neural network weight vector);

[0075] : No. Local model parameters for each organization;

[0076] : No. The aggregation weight of each organization is in the range of [0, 1];

[0077] : Sigmoid function, , used for nonlinear mapping;

[0078] , : Hyperparameters, balancing the contributions of DUF and TCM;

[0079] : No. The data utility factor of an organization;

[0080] : No. Threat relevance metrics for an organization;

[0081] : Weight coefficient, which adjusts the relative importance of diversity, timeliness and contribution;

[0082] : Data characteristics The entropy value, which measures diversity;

[0083] : time decay function, is the attenuation rate, is the current time, The time when the data was generated;

[0084] : The gain of the local model on the global threat detection performance (such as improved accuracy);

[0085] : local eigenvector Threat intelligence features The cosine similarity of

[0086] : number of participating organizations;

[0087] Implementation steps: Calculate DUF: For each organization , calculate data diversity (entropy ), timeliness (time decay) and contribution (performance gain ), and the weighted summation is ; Calculate TCM: extract local features , and threat intelligence features Calculate the cosine similarity and get ; Generate weights: through nonlinear fusion function 𝜎, combined with and Calculating aggregation weights ; Aggregation parameters: according to weight , for each tissue parameter Weighted summation to generate global model parameters , assign weights based on data quality and threat relevance, improve the accuracy of the global model, capture complex relationships through the Sigmoid function, enhance model robustness, eliminate the need to share original data, and achieve parameter fusion while protecting privacy.

[0088] Trust Game Incentive Mechanism (TGIM):

[0089]

[0090]

[0091]

[0092] in:

[0093] : No. The trust score of an organization at time 𝑡+1t+1;

[0094] : No. The trust score of an organization at time 𝑡t;

[0095] : learning rate, which controls the update speed of the trust score;

[0096] : No. The gain of each organizational parameter on the global model performance;

[0097] : Penalty coefficient, which adjusts the penalty intensity for malicious behavior;

[0098] : Malicious behavior score, calculated by anomaly detection algorithms (such as isolation forest);

[0099] : No. Incentive rewards (such as tokens or points) for an organization;

[0100] : No. The contribution of each organization is based on the normalized value of performance gain;

[0101] : number of participating organizations;

[0102] Implementation steps: Calculate the performance gain of each tissue parameter to the global model , normalized to obtain the contribution ; Use anomaly detection algorithms (such as isolation forest) to analyze parameter updates and calculate malicious behavior scores , adjusting trust scores based on performance gains and malicious behavior ; Calculate incentives through exponential reward function , recorded in the blockchain smart contract, the trust score is adjusted in real time based on contribution and behavior, incentivizing high-quality participation, amplifying the rewards of high-quality contributions, enhancing collaboration enthusiasm, and preventing malicious attacks through blockchain records and anomaly detection;

[0103] Multimodal Semantic Distillation (MTSD):

[0104]

[0105]

[0106]

[0107]

[0108]

[0109] in:

[0110] : Feature matrix after multimodal fusion;

[0111] : Non-negative matrix factorization, decomposed into basis matrix and coefficient matrix;

[0112] : Initial feature matrix of text, log and traffic data;

[0113] : Compact threat signature after distillation;

[0114] : L2 norm, measuring feature reconstruction error;

[0115] : KL divergence, which measures the distribution difference between features and threat intelligence;

[0116] : Regularization coefficient, balancing reconstruction and threat relevance;

[0117] : Word frequency-inverse threat frequency algorithm to generate text features;

[0118] : Time series analysis function, extracting log features;

[0119] : Statistical analysis function, extracting traffic characteristics;

[0120] , : Raw text, log and traffic data;

[0121] Implementation steps: Text data Apply TF-ITF to generate features ; For log data Extracting time series features ; For traffic data Extracting statistical features , through NMF Fusion into a unified feature , optimize the objective function and generate compact features , retain threat-related information, The global model is input to integrate multi-source data to enhance the comprehensiveness of features. The distillation process reduces redundant information and improves computational efficiency. KL divergence optimization ensures that features are highly relevant to threats.

[0122] Heterogeneous Agent Co-Evolution (HACE):

[0123]

[0124]

[0125]

[0126] in:

[0127] : optimized global model parameters;

[0128] : current global model parameters;

[0129] : No. Optimization suggestions for each agent (such as feature weights or parameter adjustments);

[0130] : No. The weight of each agent, based on softmax normalization;

[0131] : No. performance scores of each agent;

[0132] : Accuracy of agent after optimization;

[0133] : The execution efficiency of the agent (such as response time);

[0134] : the computational cost of the agent;

[0135] 𝛼,𝛽,𝛾: weight coefficients, balancing accuracy, efficiency, and cost;

[0136] k: number of agents (feature optimization, parameter tuning, threat prediction agents);

[0137] Implementation steps: Agent initialization: Set up feature optimization, parameter adjustment, and threat prediction agents, each performing its own duties, calculate the accuracy, efficiency, and cost of each agent, and generate a score , calculate the proxy weight through the softmax function , according to the recommendations of each agent and weights ,Update the global model, collaborative evolution: multi-agent competition and cooperation, improve optimization effect, adjust the model in real time, respond to emerging threats, balance accuracy and resource consumption, and reduce computational burden. Specific embodiment four:

[0139] like Figures 1 to 5 As shown, based on the content in the above specific embodiments, the following contents are further disclosed:

[0140] In order to further verify the feasibility of this application and the significant features of the technical solution in actual use, the following application case contents are further disclosed:

[0141] Application Case 1: Collaborative Defense against Cross-Bank Cyber Threats in the Financial Industry

[0142] Application scenario: Multiple banks (e.g., Bank A, Bank B, and Bank C) face increasing cyberattacks (e.g., phishing attacks, malware, and distributed denial of service (DDoS) attacks). However, due to data privacy regulations (e.g., the Data Security Law), they are unable to directly share customer data for joint defense. This application system provides privacy-preserving cyber threat assessment and defense capabilities through decentralized collaboration.

[0143] The implementation process is as follows:

[0144] Initialization: The three banks access the system structure of this application, configure local data processing modules, and collect network traffic, transaction logs, and security event data.

[0145] Sp1: Local data processing: Each bank uses the TF-ITF algorithm to extract features (such as abnormal transaction patterns and malicious IP addresses) and train local models to generate parameters;

[0146] Sp2: Dynamic Collaborative Aggregation: Generates a global threat detection model based on the DSA algorithm and DUF (Data Diversity, Timeliness, Contribution) and TCM (Threat Correlation) aggregation parameters;

[0147] Sp3: Blockchain Trust: TGIM evaluates the contributions of each bank, allocates incentives (such as tokens), and updates blockchain records to ensure fairness;

[0148] Sp4: Threat Intelligence Analysis: MTSD integrates external intelligence (such as malware reports and network traffic patterns), extracts threat signatures, and inputs them into the global model;

[0149] Sp5: Adaptive Optimization: HACE dynamically adjusts the model to respond to new attacks through feature optimization and threat prediction agents;

[0150] Sp6: Risk Assessment and Feedback: Each bank downloads the global model, assesses local risks (such as DDoS risk score), and uploads feedback to optimize the model.

[0151] In terms of privacy protection, only model parameters are shared to comply with regulatory requirements. DSA and TGIM improve model quality and collaboration fairness, achieving efficient collaboration. MTSD and HACE quickly respond to new threats and achieve dynamic adaptation. The data content is shown in Table 1 below:

[0152] index Bank A Bank B C Bank Global Model Local data volume (GB / day) 50 40 60 - Feature extraction time (seconds) 120 100 150 - Threat detection accuracy (%) 85 82 88 92 Malicious behavior detection rate (%) 90 87 91 95 Model update time (minutes) 10 8 12 15 Data leakage incidents (times) 0 0 0 0

[0153] Table 1

[0154] The global model's accuracy increased from 82%-88% for local models to 92%, with a 95% detection rate for malicious behavior and zero data leaks, demonstrating the system's efficient collaboration while maintaining privacy. Model updates are kept within 15 minutes, making them suitable for real-time defense.

[0155] Application Case 2: Data Security Assessment of Hospital Alliance in the Medical Industry:

[0156] Application scenario: Multiple hospitals (such as municipal hospitals, specialized hospitals, and regional hospitals) need to jointly assess the cybersecurity risks of medical information systems (such as electronic medical record systems). However, patient data is highly sensitive and cannot be shared centrally. This system provides a secure data security assessment solution through federal collaboration and blockchain trust mechanisms.

[0157] The implementation process is as follows:

[0158] Initialization: The hospital alliance joins the system, configures the local data processing module, and collects system logs, access records, and network traffic;

[0159] Sp1: Local data processing: Each hospital uses TF-ITF to extract features (such as abnormal access frequency and SQL injection attempts) and generate local model parameters;

[0160] Sp2: Dynamic collaborative aggregation: DSA dynamically aggregates parameters based on DUF and TCM to generate a global risk assessment model;

[0161] Sp3: Blockchain Trust: TGIM incentivizes high-quality contributions through Trust Score (TS) and exponential reward functions, while blockchain ensures transparency.

[0162] Sp4: Threat Intelligence Analysis: MTSD integrates medical security reports, logs, and traffic data to extract threat signatures (e.g., ransomware patterns);

[0163] Sp5: Adaptive Optimization: HACE optimizes models to detect new threats (such as attacks against medical devices) through multi-agent co-evolution;

[0164] Sp6: Risk Assessment and Feedback: The hospital uses the global model to assess system risks, generate reports (such as vulnerability scores), and provide feedback to optimize the model;

[0165] Through the above steps, patient data is kept locally, meeting privacy regulations. MTSD improves the ability to identify medical-specific threats, and HACE ensures the model is adaptable to new attacks. The data parameters are shown in Table 2 below:

[0166] index Municipal Hospital Specialized Hospital Regional Hospital Global Model Local data volume (GB / day) 30 25 35 - Feature extraction time (seconds) 90 80 100 - Threat detection accuracy (%) 80 78 82 90 New threat response time (minutes) 20 25 18 10 Trust Score (TS, 0-1) 0.85 0.80 0.90 - Data leakage incidents (times) 0 0 0 0

[0167] Table 2

[0168] The global model has an accuracy rate of 90%, which is approximately 10% higher than the local model. The response time to new threats has been shortened to 10 minutes. The trust score reflects the fairness of collaboration, and there have been zero data breaches, proving the system's efficiency and security in the healthcare industry.

[0169] Application Case 3: Cybersecurity Monitoring of Critical Government Infrastructure

[0170] Application scenario: Government departments (such as electricity, communications, and transportation) need to jointly monitor the network security of critical infrastructure. However, the data of each unit is scattered and sensitive, and traditional centralized methods are not feasible. This system provides real-time network security monitoring through a decentralized architecture and adaptive optimization.

[0171] The implementation process is as follows:

[0172] Initialization: Each unit joins the system, configures local data processing modules, and collects infrastructure logs and traffic data;

[0173] Sp1: Local data processing: Use TF-ITF to extract features (such as DDoS traffic patterns and abnormal control instructions) and generate parameters;

[0174] Sp2: Dynamic collaborative aggregation: DSA aggregates parameters to generate a global monitoring model;

[0175] Sp3: Blockchain Trust: TGIM evaluates contributions, blockchain records updates, and ensures security;

[0176] Sp4: Threat Intelligence Analysis: MTSD integrates government intelligence, logs, and traffic data to extract features (such as APT attack patterns);

[0177] Sp5: Adaptive Optimization: HACE optimization model to adapt to new threats (such as supply chain attacks);

[0178] Sp6: Risk Assessment and Feedback: The unit assesses risks (such as system vulnerabilities) and provides feedback to optimize the model.

[0179] Through the above steps, MTSD and HACE support rapid threat detection, DSA and TGIM ensure data security and fairness, and the system responds to complex infrastructure threats. The data content is shown in Table 3 below:

[0180] index Municipal Hospital Specialized Hospital Regional Hospital Global Model Local data volume (GB / day) 30 25 35 - Feature extraction time (seconds) 90 80 100 - Threat detection accuracy (%) 80 78 82 90 New threat response time (minutes) 20 25 18 10 Trust Score (TS, 0-1) 0.85 0.80 0.90 - Data leakage incidents (times) 0 0 0 0

[0181] Table 3

[0182] The global model accuracy reached 94%, the APT attack detection rate increased to 90%, and the model update frequency reached 6 times / day, meeting real-time monitoring needs. There were zero data leakage incidents, proving the feasibility and efficiency of the system in critical infrastructure.

[0183] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further restrictions, an element defined by the statement "comprising a reference structure" does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.

[0184] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. An artificial intelligence-based cybersecurity risk assessment method, characterized by: The method comprises the following steps: Sp1: At each participating organization, local network security data is preprocessed, and data features containing threat-related information are generated through feature extraction algorithms. Local model parameters are then generated based on these features. Sp2: Aggregate local model parameters of each organization to generate a global model through the Dynamic Collaborative Aggregation (DSA) concept. The DSA concept dynamically calculates nonlinear weighting coefficients based on the Data Utility Factor (DUF) and Threat Correlation Metric (TCM) to achieve intelligent parameter fusion. Sp3: Leveraging the blockchain trust module, the Trust Game Incentive Mechanism (TGIM) is used to record model updates contributed by participating organizations. Through game theory, trust scores are dynamically adjusted to incentivize high-quality contributions, ensuring fairness and security in collaboration. Sp4: Through the threat intelligence analysis module, the Multimodal Semantic Distillation (MTSD) method is used to fuse multimodal data such as text, event logs, and network traffic to extract threat features and input them into the global model to improve threat detection accuracy. Sp5: Using the adaptive optimization module, the heterogeneous agent co-evolution method (HACE) is used to dynamically optimize the global model and adapt to the dynamic threat environment through competition and cooperation among multiple agents; Sp6: Each participating organization downloads the global model, performs local cybersecurity risk assessments, and uploads the assessment feedback to optimize the next round of global models.

2. The artificial intelligence-based network security risk assessment method according to claim 1, characterized in that: The dynamic collaborative aggregation concept (DSA) in step Sp2 calculates the data utility factor (DUF) based on the diversity, timeliness and threat detection contribution of the data, calculates the threat correlation measure (TCM) based on the feature similarity between local data and threat intelligence, and uses a nonlinear fusion function to generate aggregation weights.

3. The network security risk assessment method based on artificial intelligence according to claim 1, characterized in that: The Trust Game Incentive Mechanism (TGIM) in step Sp3 calculates the Trust Score (TS) based on the game theory model, dynamically updates it based on historical behavior and current contribution, and uses an exponential reward function to calculate the Trust Score (TS). (in (Contribution) encourages high-quality updates and punishes malicious behavior.

4. The artificial intelligence-based network security risk assessment method according to claim 1, characterized in that: The multimodal semantic distillation method (MTSD) in step Sp4 uses term frequency-inverse threat frequency (TF-ITF) to extract text features, analyzes the temporal characteristics of event logs and the statistical patterns of network traffic, fuses multimodal data through non-negative matrix decomposition, and generates a compact threat feature representation.

5. The network security risk assessment method based on artificial intelligence according to claim 1, characterized in that: The heterogeneous agent co-evolution method (HACE) in step Sp5 sets feature optimization agents, parameter adjustment agents and threat prediction agents, dynamically adjusts the global model through competition and cooperation mechanisms, and improves adaptability to unknown threats.

6. The artificial intelligence-based network security risk assessment method according to claim 2, characterized in that: The data utility factor (DUF) in step Sp2 is calculated by using the feature distribution entropy value to evaluate data diversity, using the time decay function to evaluate data timeliness, and using the gain evaluation contribution of the local model to global threat detection.

7. The artificial intelligence-based network security risk assessment method according to claim 3, characterized in that: The trust score (TS) update rule of the trust game incentive mechanism (TGIM) in step Sp3 is that if the model update improves the global performance, the trust score (TS) is increased; if a malicious update is detected, the trust score (TS) is reduced through the anomaly detection algorithm.

8. The network security risk assessment method based on artificial intelligence according to claim 1, characterized in that: In the step Sp4, the multimodal semantic distillation method (MTSD) uses non-negative matrix decomposition to integrate text, log and traffic data into a unified semantic space when fusing multimodal features, and retains key threat information through iterative optimization.

9. The artificial intelligence-based network security risk assessment method according to claim 5, characterized in that: The agent functions of the heterogeneous agent co-evolution method (HACE) in step Sp5 include feature optimization agents selecting key features, parameter adjustment agents fine-tuning model parameters, and threat prediction agents predicting potential threat trends. The agents work together by sharing optimization goals.

10. The artificial intelligence-based network security risk assessment method according to any one of claims 1 to 9, characterized in that: The system of the method further comprises the following: A local data processing module, which collects cybersecurity data from participating organizations, extracts threat-related features, and generates local model parameters; The collaborative learning module implements the concept of dynamic collaborative aggregation (DSA) and generates a global model by dynamically weighting aggregation parameters based on the data utility factor (DUF) and threat correlation metric (TCM) through the aggregation engine; The blockchain trust module runs the distributed ledger and the Trust Game Incentive Mechanism (TGIM) smart contract to record model updates and incentivize high-quality contributions; The threat intelligence analysis module fuses multimodal data through the Multimodal Semantic Distillation method (MTSD), extracts threat features, and inputs them into the global model; Adaptive optimization module, which uses heterogeneous agent co-evolution (HACE) to manage competition and cooperation among multiple agents and optimize global model performance; The user interface and management module provides an interactive interface and monitoring dashboard for viewing risk assessment results and receiving alerts.

Citation Information

Patent Citations

  • Water conservancy key information infrastructure network security situation awareness platform

    CN118138293A

  • Method and system for carrying out joint verification on digital identity by using combined model

    CN119293772A

  • Multi-private-domain visitor portrait sharing and privacy protection routing method based on federal learning

    CN119383014A

  • Network security threat monitoring method and system based on artificial intelligence

    CN119628963A

  • Pipeline welding seam management system and management method thereof

    CN119831575A

Cited By

  • Game theory-fused medical data security sharing and privacy computing intelligent management method and system

    CN121278756A

  • Intelligent management method and system for medical data security sharing and privacy calculation based on game theory

    CN121278756B