Distributed data security early warning method

By constructing a spoofing path generation and structural offset identification mechanism, the problem of the consensus mechanism's inability to identify structural consistency errors is solved, realizing the identification and control of spoofing paths in distributed data systems, and improving the robustness of task execution and the controllability of the strategy.

CN120880876AActive Publication Date: 2025-10-31北京晟达伟华信息科技有限公司
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202511074510.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-01
Publication Date
2025-10-31
Estimated Expiration
2045-08-01

AI Technical Summary

Technical Problem

The consensus mechanism of existing distributed data processing systems cannot identify errors that are structurally consistent but behaviorally disguised, resulting in a lack of early warning in highly consistent error scenarios, which affects the stability of task scheduling and control response.

Method used

By constructing a mechanism for generating spoofed paths, identifying structural deviations, and determining consensus paths, we can proactively identify path results that are structurally consistent but behaviorally spoofed. We can then utilize a set of path feature fragments, spoofed input-induced modeling, and adversarial path generation, combined with a path representation graph, to perform structural deviation analysis and credibility judgment, thereby generating a path control execution structure.

Benefits of technology

It enables the identification of structural consistency errors, improves the accuracy of risk state modeling and the robustness of distributed task execution, enhances the dynamic identification of potential abnormal paths, and ensures the controllability of task scheduling and the reliability of strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880876A_ABST
    Figure CN120880876A_ABST
Patent Text Reader

Abstract

The invention discloses a distributed data security early warning method, and particularly relates to the technical field of distributed data early warning, which comprises the following steps of: obtaining a task instruction sequence in a distributed data node, executing a structure extraction operation, performing structure generation processing, generating a path expression map, performing fragment occurrence frequency statistics and structure position aggregation operation on the path expression spectrum, and outputting a path feature fragment set; performing an adversarial path generation operation after performing a camouflage input induction modeling operation based on the path feature fragment set, outputting a camouflage path set, performing a path input combination construction operation in combination with a path expression map, and outputting a task execution path input combination; by constructing a disguised path generation, structure offset recognition and consensus path judgment mechanism, path results with consistent structures but disguised behaviors are actively recognized, and the problem that a consensus mechanism in the background technology cannot recognize potential consistency disguised errors is solved by bypassing a traditional judgment mode which only depends on result differences.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of distributed data early warning technology, and more specifically, to a distributed data security early warning method. Background Technology

[0002] Error detection mechanisms in current distributed data processing systems generally adopt result consistency judgment methods based on consensus models. Algorithms such as Paxos, Raft, and PBFT reach consensus through voting by a majority of nodes to confirm the validity of the data state and the stability of the system state.

[0003] The majority voting principle is based on the assumption that consistency is the basis of reliability. That is, if the results obtained by multiple nodes independently executing the same task are consistent, the system will determine that there is no abnormality and enter the normal writing, execution or distribution process. The consensus mechanism error detection relies on the difference in node results to trigger response operations. When there are deviations, missing results, disordered order or feedback timeouts, the system will start retransmission, arbitration or fault tolerance modules to repair or block the process.

[0004] Therefore, in the current consensus mechanism design, errors are equivalent to "inconsistent results between nodes" or "some nodes fail and cannot participate in consensus." Risk prediction technology requires the system to perceive error trends and potential risk sources that have not yet become apparent. In multi-source, highly collaborative scenarios such as financial transaction networks, intelligent transportation infrastructure, and meteorological simulation platforms, multiple nodes may be induced to load consistent initial data, accept unified synchronization timing, or respond to similar input disturbances, thereby independently generating completely consistent error outputs without communication negotiation.

[0005] The consensus mechanism only checks the consistency of node results, without analyzing the node execution path, input logic, or timing response structure. Therefore, even in a highly consistent error field, the system will still output a high-confidence judgment that "a consensus has been reached." Risk prediction algorithms often rely on signals such as error evolution, trend shift, and statistical outliers to trigger risk judgments. If independent error results are indistinguishable and do not meet the deviation conditions, no anomaly judgment mechanism will be activated. The system does not exhibit observable anomalies in the output logic, state feedback, and control response links. Dangerous states will remain latent in the consensus path with "zero anomaly characteristics" for a long time, ultimately affecting task scheduling, strategy deployment, and the stability of the control loop.

[0006] It is evident that the consensus mechanism builds error detection logic based on result consistency, but fails to verify the source of the consistent behavior and analyze the execution structure of the consensus path. When nodes independently generate consistent error results, the system identifies the error as a normal state. The danger prediction mechanism cannot detect the consensus spoofing behavior, and the error enters the deep execution link without warning. Summary of the Invention

[0007] To overcome the aforementioned deficiencies of the prior art, embodiments of the present invention provide a distributed data security early warning method. By constructing a mechanism for generating spoofed paths, identifying structural offsets, and determining consensus paths, the method proactively identifies path results that are structurally consistent but behaviorally spoofed, bypassing the traditional judgment method that relies solely on result differences. This addresses the problem in the prior art where consensus mechanisms cannot identify potential consistency spoofing errors.

[0008] To achieve the above objectives, the present invention provides the following technical solution: a distributed data security early warning method, comprising:

[0009] S1: After obtaining the task instruction sequence from the distributed data nodes and performing the structure extraction operation, perform structure generation processing to generate a path representation map. Perform segment frequency statistics and structure position aggregation operations on the path representation map and output a set of path feature segments.

[0010] S2: After performing camouflage input-induced modeling based on the path feature fragment set, adversarial path generation is performed, and a camouflage path set is output. Combined with the path representation graph, a path input combination construction operation is performed, and the task execution path input combination is output.

[0011] S3: Combine the task execution path input with the path acceptance status recognition operation and the disguised path extraction operation, output the set of accepted disguised paths, perform structural comparison analysis with the path representation graph, generate the structural offset index matrix, and perform matrix fusion operation with the path judgment response set to output the consistent structural response matrix;

[0012] S4: After performing structural camouflage path identification and credibility analysis on the consistent structural response matrix, perform structural matching operation in combination with the path expression graph, output the path behavior response evolution graph, and perform joint judgment on the path behavior response evolution graph to determine whether the current path result is unusable or the current path result is usable;

[0013] S5: After performing path sorting priority modeling operations on the paths that are deemed usable and the path behavior response evolution graph, construct the path control structure and output the path control execution structure.

[0014] In a preferred embodiment, in S1, a task instruction sequence from a distributed data node is obtained. The task instruction sequence includes a state transition trajectory, an input trigger chain, and a jump sequence. A structure extraction operation is performed on the task instruction sequence to output a path information set. The path information set includes a behavior jump distribution, an input segment response structure, and a state evolution fragment.

[0015] Perform structure generation processing on the path information set to output a path representation graph, which includes a structure representation layer, a jump chain layer, and a response flow layer.

[0016] Perform frequency statistics and structural position aggregation operations on the path representation graph, and output a set of path feature fragments, which includes jump repeating fragments, synchronous triggering sub-paths and input stream segment chains.

[0017] In a preferred embodiment, S1 further includes the segment occurrence frequency statistics and structural position aggregation operation, which, based on the jump chain layer in the path representation map, performs frequency statistics across the entire path range on jump sequences with frequencies higher than a preset threshold, marks the jump structure segments that appear repeatedly in different task paths, and outputs the jump repetition segments.

[0018] Based on the triggering preconditions and location distribution characteristics of jump structure fragments, an aggregation operation is performed to identify path fragment groups with common triggering patterns and extract synchronous triggering sub-paths from the path fragment groups.

[0019] Perform structural classification and functional filtering operations on common structural fragments involving input segment behavior in the input segment response structure, filter out typical input stream structures with reorganization value in task control, and output input stream segment chain;

[0020] The jump repeating segments, synchronous trigger sub-paths, and input stream segment chains are combined to form a set of path feature segments.

[0021] In a preferred embodiment, in S2, a masquerading input inducement modeling operation is performed based on a set of path feature segments, and a perturbation input mapping set is output, which includes input inducement location, structural rearrangement segment and behavioral perturbation trigger point;

[0022] Perform adversarial path generation on the perturbation input mapping group and output a set of spoofed paths;

[0023] Perform a path input combination construction operation on the camouflaged path set and the path representation graph, and output the task execution path input combination.

[0024] In a preferred embodiment, S2 further includes the adversarial path generation operation, which constructs a camouflage path on the perturbation input mapping group, establishes a structural perturbation generator model, embeds the input induction position, structural rearrangement segment and perturbation trigger point as perturbation vectors into the structural perturbation generator model, performs perturbation path construction modeling at the input level, and outputs a preliminary camouflage path set.

[0025] Using the path representation graph as the real path reference set, structural feature parameters of the structural representation layer and the jump chain layer are extracted to train a path structure discriminator.

[0026] By combining the structure perturbation generator model with the path structure discriminator, a path-level adversarial generative network is constructed. The perturbation strategy of the structure perturbation generator model is optimized through multiple rounds of adversarial interaction, and a set of dummy paths with structural deviations but consistent judgments is output.

[0027] In a preferred embodiment, in S3, a distributed data consensus judgment is performed on the task execution path input combination, and a path acceptance status identification operation is performed to output a path judgment response set.

[0028] Perform a fake path extraction operation on the path determination response set and output the set of accepted fake paths;

[0029] Perform a structural comparison analysis between the accepted set of camouflaged paths and the path representation graph, and output the structural offset index matrix;

[0030] The structural offset index matrix and the path decision response set are combined and subjected to a matrix fusion operation to output a consistent structural response matrix.

[0031] In a preferred embodiment, S3 further includes the structural comparison analysis, which aligns the set of fake paths accepted from the distributed data consensus judgment with the path expression graph through multi-layer structural feature processing, extracts structural features such as node nesting order, jump mode and state response sequence based on the structural expression layer and jump chain layer, and outputs a graph embedding representation of the set of fake paths and the path expression graph.

[0032] Training samples are constructed by combining the camouflaged path set with the graph embedding representation of the path representation graph to generate a graph comparison training sample set. The graph structure comparison neural network model is initialized, and a structure alignment encoder and a multidimensional similarity discriminant function are constructed. Based on the structure alignment encoder and the multidimensional similarity discriminant function, the model is trained on the graph comparison training sample set, and the graph structure comparison neural network model is output. This model is used to perform difference judgment operations on the camouflaged path set and the path representation graph to generate a structure offset index matrix.

[0033] In a preferred embodiment, in S4, structural camouflage path identification and credibility analysis operations are performed on the consistent structural response matrix, and a set of path credibility weakening identifiers is output.

[0034] Perform a structure matching operation between the set of path credibility weakening identifiers and the path representation map to output a path behavior response evolution map, which includes state change trends, control response differences, and input behavior offset trajectories.

[0035] In a preferred embodiment, S4 further includes, under the background of distributed data task execution, jointly judging the path behavior response evolution graph, judging whether the state change trend exceeds a preset state change trend threshold, whether the control response difference exceeds a preset control response difference threshold, and whether the input behavior offset trajectory exceeds a preset input behavior offset trajectory threshold, as three judgment conditions.

[0036] If all three conditions are met, the current path result is determined to be unusable, path removal is performed, and the path input combination construction operation is re-executed; otherwise, the current path result is determined to be usable.

[0037] In a preferred embodiment, in S5, a path ranking priority modeling operation is performed on the path that is determined to be available and the path behavior response evolution graph, and a path execution priority graph is output. The path execution priority graph includes a reliable path ranking structure, a de-weighted path record, and a policy fallback parameter.

[0038] Perform path control structure construction operations on the path priority graph and output the path control execution structure.

[0039] The technical effects and advantages of this invention are as follows:

[0040] 1. This solution introduces a spoofing path mixing and structural offset analysis mechanism into a distributed data environment, overcoming the technical limitation of equating errors with inconsistent node results in the consensus mechanism, and achieving the ability to identify structural consistency errors.

[0041] 2. A structural offset index matrix is ​​constructed based on multi-layer structure alignment and graph embedding fusion operations to characterize the structural variation of the camouflage path and improve the accuracy of risk state modeling;

[0042] 3. By jointly constructing credibility reduction markers and behavioral evolution characteristics, we can achieve behavioral situational awareness of risk paths and enhance the dynamic identification capability of potential abnormal paths.

[0043] 4. Based on the construction of a path execution priority graph and scheduling control structure, improve the robustness of path scheduling and the controllability of strategies for distributed task execution. Attached Figure Description

[0044] Figure 1 This is a flowchart outlining the method steps of the present invention;

[0045] Figure 2 This is a flowchart of the path graph generation process of the present invention;

[0046] Figure 3 This is a flowchart of the spoofing path construction process of the present invention;

[0047] Figure 4This is a flowchart of the structural offset modeling process of the present invention;

[0048] Figure 5 This is a flowchart illustrating the reliability determination process of the present invention.

[0049] Figure 6 This is a flowchart of the path scheduling control of the present invention. Detailed Implementation

[0050] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0051] Refer to the instruction manual appendix Figure 1-6 An embodiment of the present invention provides a distributed data security early warning method, comprising:

[0052] S1: After obtaining the task instruction sequence from the distributed data nodes and performing the structure extraction operation, perform structure generation processing to generate a path representation map. Perform segment frequency statistics and structure position aggregation operations on the path representation map and output a set of path feature segments.

[0053] S2: After performing camouflage input-induced modeling based on the path feature fragment set, adversarial path generation is performed, and a camouflage path set is output. Combined with the path representation graph, a path input combination construction operation is performed, and the task execution path input combination is output.

[0054] S3: Combine the task execution path input with the path acceptance status recognition operation and the disguised path extraction operation, output the set of accepted disguised paths, perform structural comparison analysis with the path representation graph, generate the structural offset index matrix, and perform matrix fusion operation with the path judgment response set to output the consistent structural response matrix;

[0055] S4: After performing structural camouflage path identification and credibility analysis on the consistent structural response matrix, perform structural matching operation in combination with the path expression graph, output the path behavior response evolution graph, and perform joint judgment on the path behavior response evolution graph to determine whether the current path result is unusable or the current path result is usable;

[0056] S5: After performing path sorting priority modeling operations on the paths that are deemed usable and the path behavior response evolution graph, construct the path control structure and output the path control execution structure.

[0057] In S1, the task instruction sequence from the distributed data nodes is obtained. The task instruction sequence includes state transition trajectories, input trigger chains, and jump sequences. A structure extraction operation is performed on the task instruction sequence to output a path information set. The path information set includes behavior jump distribution, input segment response structure, and state evolution fragments. The structure extraction operation refers to performing item-by-item parsing and structured processing on the state transition trajectories, input trigger chains, and jump sequences recorded in the task instruction sequence to identify the instruction jump patterns, input response logic, and state change nodes during task execution. The path information set, composed of behavior jump distribution, input segment response structure, and state evolution fragments, is extracted. The path information set is used to reflect the structural characteristics of the task execution process and serves as the original basis for constructing the behavior chain structure in hazard prediction.

[0058] The path information set is processed by structure generation to output a path representation map. The path representation map includes a structure representation layer, a jump chain layer, and a response flow layer. The structure generation process takes the behavior jump distribution, input segment response structure, and state evolution fragments in the path information set as inputs. According to the topological features of the jump chain, the boundary patterns of the input response segment, and the temporal rules of the state change segment, structure mapping, hierarchical merging, and fragment segmentation operations are performed to generate three layers: the structure representation layer, the jump chain layer, and the response flow layer. The three layers together constitute a path representation map with a unified format, which is used to express the overall form of the task execution process in terms of structural organization, control flow path, and input response flow. It serves as the path structure basis for establishing a camouflage identification reference standard in hazard prediction.

[0059] Perform frequency statistics and structural position aggregation operations on the path representation graph, and output a set of path feature fragments, which includes jump repeating fragments, synchronous triggering sub-paths and input stream segment chains.

[0060] S1 also includes the segment occurrence frequency statistics and structural position aggregation operation. Based on the jump chain layer in the path representation map, frequency statistics are performed on the jump sequence with a frequency higher than a preset threshold across the entire path range to mark the jump structure segments that appear repeatedly in different task paths and output the jump repetition segments.

[0061] Based on the triggering preconditions and location distribution characteristics of jump structure fragments, an aggregation operation is performed to identify path fragment groups with common triggering patterns and extract synchronous triggering sub-paths from the path fragment groups.

[0062] Perform structural classification and functional filtering operations on common structural fragments involving input segment behavior in the input segment response structure, filter out typical input stream structures with reorganization value in task control, and output input stream segment chain;

[0063] The jump repeating segments, synchronous trigger sub-paths, and input stream segment chains are combined to form a set of path feature segments, which serve as the basis for structural reorganization in the construction of camouflaged paths in hazard prediction.

[0064] In S2, a dummy input inducement modeling operation is performed based on the path feature fragment set, outputting a perturbation input mapping group. The perturbation input mapping group includes input inducement positions, structural rearrangement segments, and behavioral perturbation trigger points. The dummy input inducement modeling operation refers to, after obtaining the path feature fragment set, analyzing the triggering preconditions, input timing patterns, and response state changes of the corresponding task for each path's jump repetition fragments, synchronous triggering sub-paths, and input flow segment chains, constructing input construction rules that induce similar structural responses but have perturbation characteristics, generating a mapping relationship set, and establishing mapping relationships between the fragments in the path feature fragment set and the input inducement positions, structural rearrangement segments, and perturbation trigger points to form a perturbation input mapping group, which is used to realize structural interference and result dummy in the dummy path generation.

[0065] Perform adversarial path generation on the perturbation input mapping group and output a set of spoofed paths;

[0066] The path input combination construction operation is performed on the spoofed path set and the path representation graph to output the task execution path input combination. The path input combination construction operation refers to recombining and fusing the input perturbation strategy in the spoofed path set with the real input structure in the path representation graph to generate the task execution path input set used to identify the risk of spoofed path acceptance in distributed data consensus judgment.

[0067] S2 also includes the adversarial path generation operation, which constructs a camouflage path on the perturbation input mapping group, establishes a structural perturbation generator model, embeds the input induction position, structural rearrangement segment and perturbation trigger point as perturbation vectors into the structural perturbation generator model, performs input-level perturbation path construction modeling, and outputs a preliminary camouflage path set;

[0068] Using the path representation graph as the real path reference set, structural feature parameters of the structural representation layer and the jump chain layer are extracted to train a path structure discriminator to determine whether the path is consistent with the real path structure.

[0069] By combining the structure perturbation generator model with the path structure discriminator, a path-level adversarial generative network is constructed. The perturbation strategy of the structure perturbation generator model is optimized through multiple rounds of adversarial interaction, and a set of camouflaged paths with structural deviations but consistent judgments is output. This set is used to simulate the structure camouflage mixing behavior in the execution process of distributed data tasks in hazard prediction.

[0070] It should be noted that in the formula structure involved in this scheme, dimensionless terms can be used as proportional or structural adjustment factors. When combined with quantities with units, they only play a role in numerical scaling and do not introduce new physical dimensions. Therefore, they will not change or confuse the overall unit system. This combination of "dimensionless terms and terms with units" can be understood as a composite structural expression commonly used in mathematical physics modeling. It conforms to the principle of dimensional consistency and has a clear physical interpretation basis.

[0071] Secondly, in the formula structure of this scheme, if multiple variables with different physical units are involved, including but not limited to time, mass or energy variables, their joint appearance is to express the collaborative modeling relationship of multiple physical mechanisms. Each variable can form a unified structure through function mapping, ratio combination or normalization adjustment, with clear units and clear meaning. The overall expression conforms to the principle of dimensional consistency and the conventional formula of engineering modeling.

[0072] In this scheme, constants, weights, adjustment factors, threshold parameters, proportional coefficients, etc., are all adjustable control parameters for different application environments. Their values ​​depend on the target equipment configuration, data input characteristics, and performance optimization goals. During the implementation phase, they are converged within a reasonable range through model verification, performance constraints, or engineering calibration. Although these parameters do not have a unique preset value, they have clear adjustment logic and calculation paths. They belong to the deterministic setting process in engineering implementation. The purpose of this setting is to ensure that the scheme is both universally adaptable and reproducible and operable, without affecting its technical clarity and feasibility.

[0073] In S3, distributed data consensus judgment is performed on the task execution path input combination, and path acceptance status identification operation is performed, outputting a path judgment response set. The distributed data consensus judgment and path acceptance status identification operation refer to the process in a distributed data environment, based on the consensus mechanism of each task node, sending the task execution path input combination to multiple task nodes for synchronous execution, summarizing the structural consistency judgment results fed back by each task node, identifying whether each task input path is accepted by the system globally as an execution path that is structurally consistent with the real task path, and outputting a path judgment response set to characterize the path acceptance status, which serves as the basis for spoofing path identification and structural offset analysis.

[0074] Perform a fake path extraction operation on the path determination response set and output the set of accepted fake paths. The fake path extraction operation refers to filtering out those fake paths that were incorrectly accepted as structurally consistent paths by the system in the consensus judgment from the path determination response set, which are used for structural offset analysis.

[0075] Perform a structural comparison analysis between the accepted set of camouflaged paths and the path representation graph, and output the structural offset index matrix;

[0076] Define the structural offset exponent matrix S Δ :

[0077]

[0078]

[0079] Where ε (w) ε represents the set of graph embedding vectors obtained after performing graph embedding generation operations on the camouflaged path set at the structural representation layer and the jump chain layer; (r) denoted as the set of graph embedding vectors obtained after performing graph embedding generation operations on the path representation graph at the structural representation layer and the jump chain layer; w represents the dummy path set identifier; r represents the path representation graph identifier; Ω(·) represents the graph comparison training sample construction function; Φ(·) represents the structural alignment feature set; A graph structure representation of the camouflage path set at the structural expression layer and the jump chain layer; The graph represents the path representation graph at the structural representation layer and the jump chain layer; Θ(·) is the output tensor of the graph structure contrast neural network, and Θ(·) represents the structural difference vector between the dummy path and the real path; Λ(·) represents the structural difference output fusion function, and Λ(·) is used to output a multi-dimensional structural difference score; Γ(·) represents the graph embedding function, and Γ(·) is used to encode the graph structure into a set of embedding vectors; n represents the number of structural fragment pairs in the dummy path; m represents the number of structural fragment pairs in the real path; Let i represent the graph embedding representation of the i-th structural fragment in the camouflaged path to the set of camouflaged paths; f represents the graph embedding representation of the j-th structural segment in the real path to the path representation graph; enc (·) denotes the structure alignment encoder function; μ(·,·) denotes the multidimensional similarity discriminant function, and μ(·,·) is used to compare the structural correspondence between two embedded structure alignment encoder functions; y label Indicates the structural consistency monitoring label for the current structural fragment pair; f sim (·,·) represents the similarity prediction function of a graph structure comparison neural network; This represents the training loss function, which measures the deviation between the predicted score and the true structural relationship between graph comparisons. This indicates a comparison of graph structure with neural network model parameters. The gradient update process performed; W k Θ represents the weight matrix of the k-th layer in the structure-aligned encoder; k b represents the input structural feature representation of the k-th layer in the structure-aligned encoder. kRepresents the bias vector of the k-th layer in the structure-aligned encoder; ReLU(·) represents the linear rectified activation function; softmax(·) represents the multi-class normalization function; Ψ(·) represents the structure offset index scoring function; δ1…δ m Represents the structural offset strength between all camouflaged paths and the real paths; T represents the vector transpose operation; δ p This represents the structural offset strength between the p-th camouflaged path and the real path; α1 represents the distance value representing the difference in the nesting order of nodes in the p-th path; α1 represents the structural proportion control parameter of the corresponding node nesting structure offset feature. α1 represents the difference metric of the jump topology in the p-th path; α2 represents the structural proportion control parameter of the corresponding jump topology offset feature; α3 represents the temporal and structural matching deviation value of the state response sequence in the p-th path; α3 represents the structural proportion control parameter of the corresponding state response sequence offset feature.

[0080] The structural offset index matrix and the path decision response set are jointly subjected to a matrix fusion operation to output a consistent structural response matrix. The matrix fusion operation refers to combining the structural offset index matrix and the path decision response set according to the path dimension, and generating a consistent structural response matrix for credibility judgment by combining the degree of structural offset and the acceptance state.

[0081] S3 also includes the aforementioned structural comparison analysis, which aligns the set of fake paths accepted from the distributed data consensus judgment with the path expression graph through multi-layer structural feature processing. Based on the structural expression layer and the jump chain layer, structural features such as node nesting order, jump mode and state response sequence are extracted, and the graph embedding representation of the set of fake paths and the path expression graph is output.

[0082] Training samples are constructed by combining the camouflage path set with the graph embedding representation of the path representation graph to generate a graph comparison training sample set. This is used to initialize a graph structure comparison neural network model, construct a structure alignment encoder and a multidimensional similarity discriminant function, and train the model on the graph comparison training sample set based on the structure alignment encoder and the multidimensional similarity discriminant function. The output graph structure comparison neural network model is used to perform difference judgment operations on the camouflage path set and the path representation graph, generating a structure offset index matrix to quantify the structural camouflage depth of the camouflage path and provide input basis for credibility judgment in hazard prediction.

[0083] Among them, the graph structure comparison neural network models include the GSimCNN model or the Graph Matching Network (GMN) model;

[0084] In this scheme, when the GSimCNN model is applied to the graph structure comparison neural network model, the graph embedding representation of the camouflaged path set and the path expression graph can be used as the graph pair input. The structural similarity matching mechanism based on the convolution kernel matrix in GSimCNN is used to perform graph alignment encoding operation and local structure interaction modeling, and output the structural offset index matrix. The structural offset index matrix can quantify the degree of multi-dimensional structural camouflage of the camouflaged path in the structural expression layer and the jump chain layer, and is used to construct the judgment basis for the weakening of path credibility in hazard prediction.

[0085] In this scheme, when the Graph Matching Network (GMN) model is applied to the graph structure comparison neural network model, the fake path set and the path representation graph can be embedded as node representation sequences and structural connection weight graphs, respectively. The attention weighting mechanism and learnable matching function in the GMN model are used to construct the mapping relationship between paths. The node-level alignment scoring operation is performed on the fake path structure and the real path structure, and the structural offset index matrix is ​​output. The structural offset index matrix serves as a key input before the construction of the consistency structure response matrix, and is used to help determine the degree of structural consistency mismatch of the fake path.

[0086] In S4, structural camouflage path identification and credibility analysis are performed on the consistent structural response matrix, outputting a set of path credibility weakening identifiers. The structural camouflage path identification and credibility analysis operation refers to performing structural anomaly feature extraction and credibility score calculation on each camouflage path in the consistent structural response matrix formed in the distributed data environment. By analyzing the structural consistency deviation of the path in the structural expression layer, jump chain layer and response flow layer, paths with structural camouflage characteristics are identified. The set of path credibility weakening identifiers is generated by combining the degree of structural offset and acceptance status, which is used to screen potential abnormal paths in hazard prediction.

[0087] A structural matching operation is performed between the set of path credibility weakening identifiers and the path representation map to output a path behavior response evolution map. The path behavior response evolution map includes state change trends, control response differences, and input behavior offset trajectories. The structural matching operation refers to performing structural hierarchical matching between each masquerading path marked in the path credibility weakening identifier set and the corresponding real path in the path representation map. The structural representation layer performs sequence comparison of the evolution path of state nodes to extract state change trends. The jump chain layer compares the jump relationship of control commands to extract control response differences. The response flow layer performs differential extraction on the response sequence of the input segment to extract the input behavior offset trajectory. This forms a path behavior response evolution map containing three types of dynamic behavioral features: state change trends, control response differences, and input behavior offset trajectories, providing a data foundation for abnormal trajectory determination in hazard prediction.

[0088] S4 also includes a joint judgment on the path behavior response evolution graph under the background of distributed data task execution, judging whether the state change trend exceeds the preset state change trend threshold, whether the control response difference exceeds the preset control response difference threshold, and whether the input behavior offset trajectory exceeds the preset input behavior offset trajectory threshold, as three judgment conditions.

[0089] If all three conditions are met, the current path result is determined to be unusable, path removal is performed, and the path input combination construction operation is re-executed; otherwise, the current path result is determined to be usable.

[0090] In S5, the path ranking priority modeling operation is performed on the paths determined to be usable and their path behavior response evolution graphs, outputting a path execution priority graph. The path execution priority graph includes a reliable path ranking structure, de-weighted path records, and policy fallback parameters. The path ranking priority modeling operation refers to performing a structural feature analysis operation on the paths determined to be usable and their path behavior response evolution graphs, extracting the structural offset strength, behavior evolution stability, and historical execution performance of each path, setting the path priority order based on the degree of structural offset, and forming a reliable path ranking structure. For path records with slight abnormal features but not meeting the elimination criteria, a de-weighting labeling operation is performed to generate de-weighted path records. Combining the fallback execution trajectory of historical abnormal paths with the scheduling relationship of alternative paths, policy fallback parameters are constructed. The reliable path ranking structure, de-weighted path records, and policy fallback parameters together constitute the path execution priority graph, which is used to support the construction of task path scheduling strategies.

[0091] The path execution priority graph is used to construct a path control structure, which outputs the path control execution structure. The path control structure construction operation refers to performing priority mapping, weight adjustment and fallback path derivation operations based on the trusted path sorting structure, de-weighted path records and policy fallback parameters in the path execution priority graph. The path control execution structure is used to construct a path control execution structure for task execution control. The path control execution structure sets the scheduling order of trusted paths, reduces the execution priority of de-weighted paths, and configures fallback paths and alternative strategies for potential spoofed paths, so as to realize the scheduling management and risk isolation of task execution paths in the distributed data environment.

[0092] It should be noted that, including but not limited to, the consensus mechanisms widely used in current distributed data systems, which use the majority voting principle as the basis for judgment, only verify the consistency of node results, but do not verify the behavioral path, execution structure or response chain of the result source;

[0093] This means that even if the execution path is seriously disguised or disturbed, the system may still output a high-confidence consistent judgment when multiple nodes are being guided to be consistent, thus forming a deep-seated error mixing problem with zero-anomaly characteristics.

[0094] Deep-level error mixing problems cannot be identified by traditional consistency detection mechanisms, nor can they be detected by risk prediction methods based on statistical outliers or error mutations. This leads to system failures without warning, seriously threatening scheduling stability and policy accuracy.

[0095] Therefore, this solution proposes to take structural path differences and credibility response as the core clues, and construct a complete security early warning process covering identification, modeling, judgment, sorting and scheduling from five dimensions: path expression structure, camouflage construction, structural offset modeling, credibility judgment and path control reconstruction. This breaks through the limitation of result consistency and forms a structural tracing and risk response system for camouflaged paths.

[0096] This solution includes a path map generation stage:

[0097] The task instruction sequence is obtained from the distributed data nodes. The state transition trajectory, input trigger chain and jump sequence are parsed in sequence. The structure extraction operation is performed to generate a path information set containing behavior jump distribution, input segment response structure and state evolution fragments. The structure merging, hierarchy and segmentation operations are performed to construct a path expression map composed of three layers: structure expression layer, jump chain layer and response flow layer. Based on jump frequency, input position and structure co-occurrence relationship statistics, jump repetition fragments, synchronous trigger sub-paths and input flow segment chains are extracted and the path feature fragment set is output.

[0098] This path map generation stage provides a standard structural template and a basis for recurring structural segments for the construction of camouflage paths, ensuring that camouflage simulation has a structural reference.

[0099] This solution includes a dummy path construction phase:

[0100] Based on the set of path feature segments, the perturbation location, structural rearrangement segment and behavior trigger point are identified, a perturbation input mapping group is constructed, the structural perturbation generator model is called, the perturbation is reorganized into a strategy, a set of disguised paths is generated, the structural consistency is determined by the path structure discriminator, and a path-level adversarial generative network is formed to realize multi-round optimization and structural deception enhancement of the disguised path. The disguised path is combined with the real path to output the task execution path input combination.

[0101] This camouflage path construction phase simulates the process of camouflage paths that are similar in structure but have potential risks, tests the system's structural discrimination capability, and constructs camouflage attack samples.

[0102] This scheme includes a structural offset modeling stage:

[0103] The task execution path input combination is sent to multiple nodes, and synchronous acceptance judgment is performed according to the consensus mechanism. The path judgment response set is output. The spoofed paths that were incorrectly accepted are filtered out from the path judgment response set. The multi-layer structural features of the path expression graph are aligned and graph embedding is performed to construct a graph comparison training sample set. The graph structure comparison neural network model is initialized. The graph structure comparison neural network model is trained and output through the structure alignment encoder and multi-dimensional similarity discriminant function. The graph structure comparison neural network model performs the difference calculation between the spoofed path and the real path and outputs the structure offset index matrix. The structure offset index matrix is ​​fused with the path judgment response set to generate a consistent structure response matrix.

[0104] This structural offset modeling stage is used to quantify the structural camouflage depth of the camouflage path and the degree of risk of being accepted by the system, and to construct a unified scoring matrix that can be used for credibility determination;

[0105] This solution includes a credibility determination phase:

[0106] Using the consistent structural response matrix as input, structurally abnormal paths are extracted, and the structural offset intensity and acceptance state are analyzed to generate a set of path credibility weakening indicators. The set of path credibility weakening indicators is then matched with the path expression map. Through triple comparison at the structural expression layer, jump chain layer, and response flow layer, the state change trend, control response difference, and input behavior offset trajectory are extracted respectively to construct a path behavior response evolution map. A three-item joint judgment is performed on the path behavior response evolution map to determine whether the current path result is unusable or usable.

[0107] This credibility assessment stage combines structural and behavioral perspectives to screen risky individuals in the disguised path and provides dynamic behavioral characteristics to support path priority ranking.

[0108] This scheme includes a path scheduling control phase:

[0109] Using the usable paths and path behavior response evolution graphs as input, structural offset strength, behavior evolution stability, and historical execution performance are extracted to construct a reliable path ranking structure. Paths with slight anomalies are marked with reduced weight and recorded as reduced-weight paths. Combined with historical execution trajectories and scheduling redundancy, policy backoff parameters are formed. The three together form a path execution priority graph. Based on the path execution priority graph, the path control structure construction operation is performed. Relying on priority mapping, weight adjustment, and backoff derivation, a path control execution structure is formed to achieve scheduling control and risk avoidance.

[0110] This path scheduling control phase is used to ensure that trusted paths are prioritized during task execution, avoiding potentially risky paths, and achieving path scheduling optimization and security control in a distributed environment.

[0111] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A distributed data security early warning method, Includes, characterized in that: S1: After obtaining the task instruction sequence from the distributed data nodes and performing the structure extraction operation, perform structure generation processing to generate a path representation map. Perform segment frequency statistics and structure position aggregation operations on the path representation map and output a set of path feature segments. S2: After performing camouflage input-induced modeling based on the path feature fragment set, adversarial path generation is performed, and a camouflage path set is output. Combined with the path representation graph, a path input combination construction operation is performed, and the task execution path input combination is output. S3: Combine the task execution path input with the path acceptance status recognition operation and the disguised path extraction operation, output the set of accepted disguised paths, perform structural comparison analysis with the path representation graph, generate the structural offset index matrix, and perform matrix fusion operation with the path judgment response set to output the consistent structural response matrix; S4: After performing structural camouflage path identification and credibility analysis on the consistent structural response matrix, perform structural matching operation in combination with the path expression graph, output the path behavior response evolution graph, and perform joint judgment on the path behavior response evolution graph to determine whether the current path result is unusable or the current path result is usable; S5: After performing path sorting priority modeling operations on the paths that are deemed usable and the path behavior response evolution graph, construct the path control structure and output the path control execution structure.

2. The distributed data security early warning method according to claim 1, characterized in that: In S1, the task instruction sequence in the distributed data node is obtained. The task instruction sequence includes the state transition trajectory, input trigger chain and jump sequence. The structure extraction operation is performed on the task instruction sequence to output the path information set, which includes the behavior jump distribution, input segment response structure and state evolution fragment. Perform structure generation processing on the path information set to output a path representation graph, which includes a structure representation layer, a jump chain layer, and a response flow layer. Perform frequency statistics and structural position aggregation operations on the path representation graph, and output a set of path feature fragments, which includes jump repeating fragments, synchronous triggering sub-paths and input stream segment chains.

3. The distributed data security early warning method according to claim 2, characterized in that: S1 also includes the segment occurrence frequency statistics and structural position aggregation operation. Based on the jump chain layer in the path representation map, frequency statistics are performed on the jump sequence with a frequency higher than a preset threshold across the entire path range to mark the jump structure segments that appear repeatedly in different task paths and output the jump repetition segments. Based on the triggering preconditions and location distribution characteristics of jump structure fragments, an aggregation operation is performed to identify path fragment groups with common triggering patterns and extract synchronous triggering sub-paths from the path fragment groups. Perform structural classification and functional filtering operations on common structural fragments involving input segment behavior in the input segment response structure, filter out typical input stream structures with reorganization value in task control, and output input stream segment chain; The jump repeating segments, synchronous trigger sub-paths, and input stream segment chains are combined to form a set of path feature segments.

4. The distributed data security early warning method according to claim 3, characterized in that: In S2, a dummy input inducement modeling operation is performed based on the set of path feature segments, and a perturbation input mapping group is output. The perturbation input mapping group includes the input inducement position, the structural rearrangement segment, and the behavioral perturbation trigger point. Perform adversarial path generation on the perturbation input mapping group and output a set of spoofed paths; Perform a path input combination construction operation on the camouflaged path set and the path representation graph, and output the task execution path input combination.

5. A distributed data security early warning method according to claim 4, characterized in that: S2 also includes the adversarial path generation operation, which constructs a camouflage path on the perturbation input mapping group, establishes a structural perturbation generator model, embeds the input induction position, structural rearrangement segment and perturbation trigger point as perturbation vectors into the structural perturbation generator model, performs input-level perturbation path construction modeling, and outputs a preliminary camouflage path set; Using the path representation graph as the real path reference set, structural feature parameters of the structural representation layer and the jump chain layer are extracted to train a path structure discriminator. By combining the structure perturbation generator model with the path structure discriminator, a path-level adversarial generative network is constructed. The perturbation strategy of the structure perturbation generator model is optimized through multiple rounds of adversarial interaction, and a set of dummy paths with structural deviations but consistent judgments is output.

6. A distributed data security early warning method according to claim 5, characterized in that: In S3, a distributed data consensus judgment is performed on the combination of task execution path inputs, and a path acceptance status identification operation is performed to output a path judgment response set. Perform a fake path extraction operation on the path determination response set and output the set of accepted fake paths; Perform a structural comparison analysis between the accepted set of camouflaged paths and the path representation graph, and output the structural offset index matrix; The structural offset index matrix and the path decision response set are combined and subjected to a matrix fusion operation to output a consistent structural response matrix.

7. A distributed data security early warning method according to claim 6, characterized in that: S3 also includes the structural comparison analysis, which aligns the set of fake paths accepted from the distributed data consensus judgment with the path expression graph through multi-layer structural feature processing. Based on the structural expression layer and the jump chain layer, it extracts the structural features of node nesting order, jump mode and state response sequence, and outputs the graph embedding representation of the set of fake paths and the path expression graph. Training samples are constructed by combining the camouflaged path set with the graph embedding representation of the path representation graph to generate a graph comparison training sample set. The graph structure comparison neural network model is initialized, and a structure alignment encoder and a multidimensional similarity discriminant function are constructed. Based on the structure alignment encoder and the multidimensional similarity discriminant function, the model is trained on the graph comparison training sample set, and the graph structure comparison neural network model is output. This model is used to perform difference judgment operations on the camouflaged path set and the path representation graph to generate a structure offset index matrix.

8. A distributed data security early warning method according to claim 7, characterized in that: In S4, structural camouflage path identification and credibility analysis are performed on the consistent structural response matrix, and a set of path credibility weakening identifiers is output. Perform a structure matching operation between the set of path credibility weakening identifiers and the path representation map to output a path behavior response evolution map, which includes state change trends, control response differences, and input behavior offset trajectories.

9. A distributed data security early warning method according to claim 8, characterized in that: S4 also includes a joint judgment on the path behavior response evolution graph under the background of distributed data task execution, judging whether the state change trend exceeds the preset state change trend threshold, whether the control response difference exceeds the preset control response difference threshold, and whether the input behavior offset trajectory exceeds the preset input behavior offset trajectory threshold, as three judgment conditions. If all three conditions are met, the current path result is determined to be unusable, path removal is performed, and the path input combination construction operation is re-executed; otherwise, the current path result is determined to be usable.

10. A distributed data security early warning method according to claim 9, characterized in that: In S5, the path ranking priority modeling operation is performed on the path that is determined to be usable and the path behavior response evolution graph, and the path execution priority graph is output. The path execution priority graph includes the trusted path ranking structure, the de-weighted path record and the policy backoff parameter. Perform path control structure construction operations on the path priority graph and output the path control execution structure.

Citation Information

Patent Citations

  • Artificial intelligence early warning system

    CN109447048A

  • Periodic mean constant false alarm-based voltage disturbance detection threshold design method

    CN113742951A

  • Distributed monitoring method and device for data security

    CN115086086A

  • Anti-Traceroute network topology confusion system based on P4

    CN119109638A

  • Distributed energy storage equipment predictive maintenance system and method based on AI

    CN119919125A