Generative confrontation-driven intelligent security defense method and system
Through a generative adversarial-driven intelligent security defense method, the MoE architecture and GPT-4 architecture are used to simulate the APT attack chain, build a dynamic knowledge graph, and deploy a multi-agent cluster. This solves the problems of dynamic attacks and low efficiency of heterogeneous data fusion in network security defense, and realizes real-time threat analysis and collaborative defense.
Patent Information
- Application Number
- CN202510915186.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2025-03-27
- Filing Date
- 2025-07-03
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2045-07-03
AI Technical Summary
The existing network security defense system faces the problems of static defense mechanisms being unable to cope with dynamic attacks, low efficiency in heterogeneous data fusion, and insufficient timeliness in intelligent decision-making, especially delayed response when dealing with APT attacks and 0day vulnerabilities.
A generative adversarial-driven intelligent security defense method is adopted, computing resources are dynamically allocated through the MoE architecture, the LLM fine-tuned in the security field is introduced to construct a cross-modal semantic similarity matrix, the GPT-4 architecture attack generator is deployed, a dual-agent adversarial training environment is constructed, the dynamic knowledge graph of the cognitive decision-making layer is upgraded, and multi-agent collaborative response is achieved.
It improves the fusion efficiency of heterogeneous data, improves the accuracy of unstructured threat intelligence analysis, enhances the efficiency of adversarial training, realizes real-time threat deduction and encrypted traffic analysis capabilities, and overcomes data layer defects, attack and defense confrontation limitations and decision-making layer bottlenecks.
Smart Images

Figure CN120602194A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a generative adversarial-driven intelligent security defense method and system. Background Art
[0002] The current cybersecurity defense system faces three core challenges: static defense mechanisms are unable to cope with dynamic attacks, heterogeneous data fusion is inefficient, and intelligent decision-making lacks timeliness. Traditional PPDR (Policy-Protection-Detection-Response) security models rely on static rule bases and manual analysis, resulting in a delayed response to emerging threats such as APT attacks and zero-day vulnerabilities. Existing technologies have the following flaws: 1. Data layer flaws: Correlation analysis of multi-source heterogeneous data relies on manual analysis, making it difficult to capture semantic associations in unstructured text. Existing hybrid expert models do not implement dynamic resource allocation in the security field, resulting in wasted computing power. 2. Limitations of attack and defense: Traditional attack simulation technology is based on a library of known vulnerabilities and cannot generate attack chains with evolutionary capabilities. Defense strategy optimization lacks real-time adversarial training, and detection models are easily deceived by adversarial examples. 3. Decision-layer bottlenecks: Threat knowledge graph updates are subject to high latency and a lack of intelligent agent collaboration mechanisms.
[0003] Therefore, there is an urgent need for a targeted generative adversarial-driven intelligent security defense method and system. Summary of the Invention
[0004] The purpose of the present invention is to provide a generative adversarial-driven intelligent security defense method and system to overcome the data layer defects, attack and defense confrontation limitations and decision-making layer bottlenecks of the prior art.
[0005] In a first aspect, the present application provides a generative adversarial driven intelligent security defense method, the method comprising:
[0006] Step 1: Reconstruct the data fusion layer and use the Mixture of Experts (MoE) architecture to drive the extraction of multimodal features, including:
[0007] The data processing engine is built using the MoE architecture. This involves defining a gated network and obtaining multiple expert models for different data sources, such as network traffic, logs, and asset mapping. The gated network is multiplied by the expert models and then summed to form a constructed data processing engine, thereby achieving dynamic allocation of computing power.
[0008] We introduce a security-focused LLM that generates threat description vectors through comparative learning, constructs a semantic similarity matrix, identifies cross-modal relationships, and performs semantic enhancement on unstructured text, including vulnerability descriptions and threat intelligence.
[0009] Applying the data processing engine to extract multimodal features from the semantically enhanced unstructured text;
[0010] Step 2: Build a dynamic attack and defense layer to obtain a generative adversarial security engine, including:
[0011] Based on the GPT-4 architecture, it simulates APT attack chains, generates attack scripts containing vulnerability exploit chains, deploys attack generators, and intelligently expands the attack surface.
[0012] Construct a dual-agent adversarial training environment, define the maximum penetration success rate to obtain the attacker agent, define the minimum detection delay to obtain the defender agent, and defend the reinforcement learning framework;
[0013] Train a generative adversarial security engine;
[0014] Step 3: Build a dynamic knowledge graph system and upgrade the cognitive decision-making layer, including:
[0015] A time-series graph neural network is used to model attack evolution and construct a real-time threat map. The dynamic adjacency matrix involved in the attack evolution process is updated in real time with the attack behavior.
[0016] Deploy multiple functional agent clusters and establish an agent collaborative response mechanism. The multiple functional agent clusters include but are not limited to the following: vulnerability hunters, used for 0day vulnerability pattern identification; traffic forensics, used for deep analysis of encrypted traffic; attack chain deduction, used for APT attack path prediction.
[0017] In a second aspect, the present application provides a generative adversarial driven intelligent security defense system, the system comprising: a data fusion layer module, a dynamic attack and defense layer module, and a cognitive decision layer module;
[0018] The data fusion layer module is used to reconstruct the data fusion layer and adopt the mixture of experts (MoE) architecture to drive the extraction of multimodal features, including:
[0019] The data processing subunit is used to build a data processing engine using the MoE architecture. This involves defining a gated network and obtaining multiple expert models for different data sources, such as network traffic, logs, and asset mapping. The gated network is multiplied by the multiple expert models and then summed to obtain the constructed data processing engine, thereby achieving dynamic allocation of computing power.
[0020] The semantic enhancement subunit is used to introduce the LLM fine-tuned in the security field, generate threat description vectors through contrastive learning, build a semantic similarity matrix, identify cross-modal associations, and perform semantic enhancement on unstructured text, such as vulnerability descriptions and threat intelligence;
[0021] A feature extraction subunit, configured to extract multimodal features from the semantically enhanced unstructured text using the data processing engine;
[0022] The dynamic attack and defense layer module is used to construct a dynamic attack and defense layer to obtain a generative adversarial security engine, including:
[0023] The attack surface expansion subunit is used to simulate APT attack chains based on the GPT-4 architecture, generate attack scripts containing vulnerability exploit chains, deploy attack generators, and achieve intelligent expansion of the attack surface;
[0024] The defense reinforcement subunit is used to build a dual-agent adversarial training environment, define the maximum penetration success rate to obtain the attacker agent, define the minimum detection delay to obtain the defender agent, and form a defense reinforcement learning framework;
[0025] A training subunit, used to train a generative adversarial security engine;
[0026] The cognitive decision layer module is used to build a dynamic knowledge graph system and upgrade the cognitive decision layer, including:
[0027] The graph construction subunit is used to model the attack evolution using a time-series graph neural network and build a real-time threat graph. The dynamic adjacency matrix involved in the attack evolution process is updated in real time with the attack behavior.
[0028] The collaborative response sub-unit is used to deploy multiple functional intelligent agent clusters and establish an intelligent agent collaborative response mechanism. The multiple functional intelligent agent clusters include but are not limited to the following: vulnerability hunters, used for 0day vulnerability pattern identification; traffic forensics, used for deep analysis of encrypted traffic; attack chain deduction, used for APT attack path prediction.
[0029] In a third aspect, the present application provides a generative adversarial driven intelligent security defense system, the system comprising a processor and a memory:
[0030] The memory is used to store program code and transmit the program code to the processor;
[0031] The processor is configured to execute any one of the four possible methods of the first aspect according to instructions in the program code.
[0032] In a fourth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium is used to store program code, and the program code is used to be executed by a processor to implement any one of the four possible methods in the first aspect.
[0033] Beneficial effects
[0034] The present invention provides a generative adversarial-driven intelligent security defense method and system, which solves the problem of dynamic network security defense through a three-layer architecture innovation: first, data fusion layer reconstruction, adopting a multimodal feature extraction engine driven by the MoE architecture, dynamically allocating computing power resources to multiple expert models, and improving the efficiency of heterogeneous data distillation; introducing the LLM fine-tuned in the security field, constructing a cross-modal semantic similarity matrix, and improving the accuracy of unstructured threat intelligence analysis; second, dynamic attack and defense layer construction, deploying a GPT-4 architecture attack generator, simulating the generation of multi-stage APT attack chains; designing a dual-agent reinforcement learning architecture to improve the efficiency of adversarial training; third, cognitive decision-making layer upgrade, constructing a dynamic threat map based on a time-series graph neural network, and updating the adjacency matrix in real time; deploying multiple agent clusters to improve the ability of encrypted traffic analysis and attack blocking, and overcoming the data layer defects, attack and defense confrontation limitations and decision-making layer bottlenecks of the existing technology.
[0035] The method and system of the present invention have the following advantages and effects:
[0036] Deploy a generative attack simulator and a dual-agent reinforcement learning framework, using generative adversarial networks to simultaneously generate attack scenarios and defense strategies;
[0037] Build dynamic knowledge graphs for threat deduction;
[0038] Schedule multi-agent clusters to perform coordinated defense actions. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0040] Figure 1 is a flow chart of the method of the present invention;
[0041] Figure 2 This is a system architecture diagram of the present invention. DETAILED DESCRIPTION
[0042] The preferred embodiments of the present invention are described in detail below with reference to the accompanying drawings so that the advantages and features of the present invention can be more easily understood by those skilled in the art, thereby making a clearer and more precise definition of the protection scope of the present invention.
[0043] Figure 1 This is a flowchart of the generative adversarial driven intelligent security defense method provided in this application, which includes:
[0044] Step 1: Reconstruct the data fusion layer and use the Mixture of Experts (MoE) architecture to drive the extraction of multimodal features, including:
[0045] The data processing engine is built using the MoE architecture. This involves defining a gated network and obtaining multiple expert models for different data sources, such as network traffic, logs, and asset mapping. The gated network is multiplied by the expert models and then summed to form a constructed data processing engine, thereby achieving dynamic allocation of computing power.
[0046] We introduce a security-focused LLM that generates threat description vectors through comparative learning, constructs a semantic similarity matrix, identifies cross-modal relationships, and performs semantic enhancement on unstructured text, including vulnerability descriptions and threat intelligence.
[0047] The LLM here refers to the large language model in the field of artificial intelligence. It learns language patterns through pre-training on massive text data, generates natural language text, and has a self-attention mechanism to capture long-range semantic connections.
[0048] Applying the data processing engine to extract multimodal features from the semantically enhanced unstructured text;
[0049] Step 2: Build a dynamic attack and defense layer to obtain a generative adversarial security engine, including:
[0050] Based on the GPT-4 architecture, it simulates APT attack chains, generates attack scripts containing vulnerability exploit chains, deploys attack generators, and intelligently expands the attack surface.
[0051] Construct a dual-agent adversarial training environment, define the maximum penetration success rate to obtain the attacker agent, define the minimum detection delay to obtain the defender agent, and defend the reinforcement learning framework;
[0052] Train a generative adversarial security engine;
[0053] Step 3: Build a dynamic knowledge graph system and upgrade the cognitive decision-making layer, including:
[0054] A time-series graph neural network is used to model attack evolution and construct a real-time threat map. The dynamic adjacency matrix involved in the attack evolution process is updated in real time with the attack behavior.
[0055] The dynamic adjacency matrix here is updated in real time with the attack behavior, and the nodes contain entities such as IP, vulnerability, and attack method. The attack path evolution prediction is achieved through graph convolution operation.
[0056] The process of building a knowledge graph here can also include: defining various entity categories, characterizing the classification system of assets at different levels, and describing the attributes and characteristics of assets; using Cypher query language to store data and constructing corresponding nodes and relationships within the knowledge graph; using a series of standards and methods to test, identify and correct the integrity, consistency and accuracy of the knowledge graph; using the knowledge graph to support decision-making, risk assessment, threat analysis and other scenarios based on business needs, regularly updating the knowledge graph data, and continuously monitoring and optimizing the system;
[0057] Deploy multiple functional agent clusters and establish an agent collaborative response mechanism. The multiple functional agent clusters include but are not limited to the following: vulnerability hunters, used for 0day vulnerability pattern identification; traffic forensics, used for deep analysis of encrypted traffic; attack chain deduction, used for APT attack path prediction.
[0058] The various intelligent agents here collaborate on strategies through a shared memory pool, supporting real-time blocking of phishing attacks such as AI face-changing.
[0059] At the same time, the cognitive decision-making layer can also include decisions on defense strategies and disposal strategies, including:
[0060] Analyze the interaction correlation and attribute similarity, annotate the data processed by the algorithm, classify the target assets to be evaluated based on asset importance, define different weights for interaction correlation and attribute similarity for different types, build a decision tree, and calculate the dependency value of core assets and non-core assets;
[0061] Compare the calculated dependency value with the approved threshold range to obtain a qualitative assessment of the dependency strength, thus completing the construction of the analysis and recognition model.
[0062] Embed the digital asset association knowledge graph and inference rules into the underlying digital asset association database to achieve dynamic and comprehensive digital asset ledger management. Output the results of intelligent asset relationship identification recommendations to linkable security capabilities and security centers, providing important asset data for vulnerability detection, threat analysis, and incident impact assessment, supporting dynamic management of security risks and assisting security decision-making.
[0063] In some preferred embodiments, the MoE architecture satisfies the following requirements: the expert model includes three types of specialized models: traffic behavior analysis, log semantic parsing, and asset vulnerability assessment; the gated network adopts a dynamic resource allocation algorithm to automatically adjust the activation ratio of the expert model according to the data flow throughput.
[0064] In some preferred embodiments, the semantic enhancement adopts a security-fine-tuned LLM model to construct a cross-modal semantic similarity matrix, supporting real-time semantic association of unstructured texts such as CVE vulnerability descriptions and dark web threat intelligence.
[0065] In some preferred embodiments, a dual-agent reward function is designed: the attacker agent optimizes the goal to simulate the phased benefits of APT attacks; the defender agent loss function balances detection timeliness and false alarm rate.
[0066] In addition, secure electronic fence technology can be integrated, forward secrecy protocol can be used for key management, temporary keys can be generated for each session, and dynamic encryption can be implemented for facial authentication data in transmission.
[0067] Figure 2 This is an architecture diagram of the generative adversarial-driven intelligent security defense system provided in this application. The system includes: a data fusion layer module, a dynamic attack and defense layer module, and a cognitive decision layer module;
[0068] The data fusion layer module is used to reconstruct the data fusion layer and adopt the mixture of experts (MoE) architecture to drive the extraction of multimodal features, including:
[0069] The data processing subunit is used to build a data processing engine using the MoE architecture. This involves defining a gated network and obtaining multiple expert models for different data sources, such as network traffic, logs, and asset mapping. The gated network is multiplied by the multiple expert models and then summed to obtain the constructed data processing engine, thereby achieving dynamic allocation of computing power.
[0070] The semantic enhancement subunit is used to introduce the LLM fine-tuned in the security field, generate threat description vectors through contrastive learning, build a semantic similarity matrix, identify cross-modal associations, and perform semantic enhancement on unstructured text, such as vulnerability descriptions and threat intelligence;
[0071] A feature extraction subunit, configured to extract multimodal features from the semantically enhanced unstructured text using the data processing engine;
[0072] The dynamic attack and defense layer module is used to construct a dynamic attack and defense layer to obtain a generative adversarial security engine, including:
[0073] The attack surface expansion subunit is used to simulate APT attack chains based on the GPT-4 architecture, generate attack scripts containing vulnerability exploit chains, deploy attack generators, and achieve intelligent expansion of the attack surface;
[0074] The defense reinforcement subunit is used to build a dual-agent adversarial training environment, define the maximum penetration success rate to obtain the attacker agent, define the minimum detection delay to obtain the defender agent, and form a defense reinforcement learning framework;
[0075] A training subunit, used to train a generative adversarial security engine;
[0076] The cognitive decision layer module is used to build a dynamic knowledge graph system and upgrade the cognitive decision layer, including:
[0077] The graph construction subunit is used to model the attack evolution using a time-series graph neural network and build a real-time threat graph. The dynamic adjacency matrix involved in the attack evolution process is updated in real time with the attack behavior.
[0078] The collaborative response sub-unit is used to deploy multiple functional intelligent agent clusters and establish an intelligent agent collaborative response mechanism. The multiple functional intelligent agent clusters include but are not limited to the following: vulnerability hunters, used for 0day vulnerability pattern identification; traffic forensics, used for deep analysis of encrypted traffic; attack chain deduction, used for APT attack path prediction.
[0079] The present application provides a generative adversarial driven intelligent security defense system, the system comprising: the system comprising a processor and a memory:
[0080] The memory is used to store program code and transmit the program code to the processor;
[0081] The processor is configured to execute the method described in any one of all embodiments of the first aspect according to instructions in the program code.
[0082] The present application provides a computer-readable storage medium, which is used to store program code, and the program code is used to be executed by a processor to implement any one of the methods in all embodiments of the first aspect.
[0083] In a specific implementation, the present invention further provides a computer storage medium, wherein the computer storage medium may store a program that, when executed, may include some or all of the steps of various embodiments of the present invention. The storage medium may be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).
[0084] Those skilled in the art will clearly understand that the technology in the embodiments of the present invention can be implemented by means of software plus the necessary general-purpose hardware platform. Based on this understanding, the technical solutions in the embodiments of the present invention, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments of the present invention or certain portions of the embodiments.
[0085] In particular, for the embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the description in the method embodiments.
[0086] The above-described embodiments of the present invention do not limit the protection scope of the present invention.
Claims
1. A generative adversarial driven intelligent security defense method, characterized in that: The method comprises: Step 1: Reconstruct the data fusion layer and use the Mixture of Experts (MoE) architecture to drive the extraction of multimodal features, including: The data processing engine is built using the MoE architecture. This involves defining a gated network and obtaining multiple expert models for different data sources, such as network traffic, logs, and asset mapping. The gated network is multiplied by the expert models and then summed to form a constructed data processing engine, thereby achieving dynamic allocation of computing power. We introduce a security-focused LLM that generates threat description vectors through comparative learning, constructs a semantic similarity matrix, identifies cross-modal relationships, and performs semantic enhancement on unstructured text, including vulnerability descriptions and threat intelligence. Applying the data processing engine to extract multimodal features from the semantically enhanced unstructured text; Step 2: Build a dynamic attack and defense layer to obtain a generative adversarial security engine, including: Based on the GPT-4 architecture, it simulates APT attack chains, generates attack scripts containing vulnerability exploit chains, deploys attack generators, and intelligently expands the attack surface. Construct a dual-agent adversarial training environment, define the maximum penetration success rate to obtain the attacker agent, define the minimum detection delay to obtain the defender agent, and defend the reinforcement learning framework; Train a generative adversarial security engine; Step 3: Build a dynamic knowledge graph system and upgrade the cognitive decision-making layer, including: A time-series graph neural network is used to model attack evolution and construct a real-time threat map. The dynamic adjacency matrix involved in the attack evolution process is updated in real time with the attack behavior. Deploy multiple functional agent clusters and establish an agent collaborative response mechanism. The multiple functional agent clusters include but are not limited to the following: vulnerability hunters, used for 0day vulnerability pattern identification; traffic forensics, used for deep analysis of encrypted traffic; attack chain deduction, used for APT attack path prediction.
2. The method according to claim 1, wherein: The MoE architecture meets the following requirements: the expert model includes three types of specialized models: traffic behavior analysis, log semantic parsing, and asset vulnerability assessment; the gated network adopts a dynamic resource allocation algorithm to automatically adjust the activation ratio of the expert model according to the data flow throughput.
3. The method according to claim 1, wherein: The semantic enhancement adopts a securely fine-tuned LLM model to construct a cross-modal semantic similarity matrix, supporting real-time semantic association of unstructured texts such as CVE vulnerability descriptions and dark web threat intelligence.
4. The method according to any one of claims 2 or 3, characterized in that: Dual-agent reward function design: the attacker agent optimizes the goal to simulate the phased benefits of APT attacks; the defender agent loss function balances detection timeliness and false alarm rate.
5. A generative adversarial driven intelligent security defense system, characterized in that: The system includes: a data fusion layer module, a dynamic attack and defense layer module and a cognitive decision layer module; The data fusion layer module is used to reconstruct the data fusion layer and adopt the mixture of experts (MoE) architecture to drive the extraction of multimodal features, including: The data processing subunit is used to build a data processing engine using the MoE architecture. This involves defining a gated network and obtaining multiple expert models for different data sources, such as network traffic, logs, and asset mapping. The gated network is multiplied by the multiple expert models and then summed to obtain the constructed data processing engine, thereby achieving dynamic allocation of computing power. The semantic enhancement subunit is used to introduce the LLM fine-tuned in the security field, generate threat description vectors through contrastive learning, build a semantic similarity matrix, identify cross-modal associations, and perform semantic enhancement on unstructured text, such as vulnerability descriptions and threat intelligence; A feature extraction subunit, configured to extract multimodal features from the semantically enhanced unstructured text using the data processing engine; The dynamic attack and defense layer module is used to construct a dynamic attack and defense layer to obtain a generative adversarial security engine, including: The attack surface expansion subunit is used to simulate APT attack chains based on the GPT-4 architecture, generate attack scripts containing vulnerability exploit chains, deploy attack generators, and achieve intelligent expansion of the attack surface; The defense reinforcement subunit is used to build a dual-agent adversarial training environment, define the maximum penetration success rate to obtain the attacker agent, define the minimum detection delay to obtain the defender agent, and form a defense reinforcement learning framework; A training subunit, used to train a generative adversarial security engine; The cognitive decision layer module is used to build a dynamic knowledge graph system and upgrade the cognitive decision layer, including: The graph construction subunit is used to model the attack evolution using a time-series graph neural network and build a real-time threat graph. The dynamic adjacency matrix involved in the attack evolution process is updated in real time with the attack behavior. The collaborative response sub-unit is used to deploy multiple functional intelligent agent clusters and establish an intelligent agent collaborative response mechanism. The multiple functional intelligent agent clusters include but are not limited to the following: vulnerability hunters, used for 0day vulnerability pattern identification; traffic forensics, used for deep analysis of encrypted traffic; attack chain deduction, used for APT attack path prediction.
6. A generative adversarial driven intelligent security defense system, characterized in that: The system includes a processor and a memory: The memory is used to store program code and transmit the program code to the processor; The processor is configured to implement the method according to any one of claims 1 to 4 according to the instructions in the program code.
7. A computer-readable storage medium, characterized in that The computer-readable storage medium is used to store program code, and the program code is used to be executed by a processor to implement the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Artificial intelligence network security method and system
CN117201085A
Secure communication platform for a cybersecurity system
US20190260804A1
Cited By
Network security situation awareness method based on artificial intelligence
CN121000511A
An artificial intelligence-based network security situation awareness method
CN121000511B
Attack feature classification clustering method and system based on adaptive vulnerability library
CN121412745A
An attack feature classification clustering method and system based on an adaptive vulnerability library
CN121412745B
Network threat identification and defense method and system based on data enhancement and adversarial evolution
CN121486068A