An artificial intelligence-based network security encryption authentication method and system

By constructing a full-link, multi-dimensional security encryption authentication system, the system addresses multiple security threats faced by network security encryption authentication systems, achieving precise defense against attacks such as adversarial samples, data poisoning, and model theft, dynamically adapting to new types of attacks, and ensuring the security and availability of the system.

CN122339742APending Publication Date: 2026-07-03HUNAN COLLEGE OF INFORMATION
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HUNAN COLLEGE OF INFORMATION
Filing Date
2026-03-26
Publication Date
2026-07-03

AI Technical Summary

Technical Problem

Existing network security encryption and authentication systems face multiple security threats, including adversarial sample attacks, data poisoning, model theft, and reverse engineering. They lack cross-module linkage and collaboration capabilities, making it difficult to cope with multiple types of complex attacks. Furthermore, traditional protection strategies cannot adapt to new and unknown attacks.

Method used

A comprehensive, multi-dimensional security encryption and authentication system is constructed. This system utilizes dual-dimensional perturbation detection, cryptographic hash comparison, and feature desensitization based on terminal hardware identifiers to build an input layer security barrier. A training data tracing and poisoning sample removal mechanism is established, coupled with backdoor feature detection at the inference end and incremental model updates. Chaotic encrypted sharding storage, dynamic parameter updates, and query behavior fingerprint detection are employed to prevent model theft and reverse engineering attacks. A closed-loop linkage of protection modules is established to achieve unsupervised adaptive optimization.

Benefits of technology

It achieves precise defense against multiple types of attacks, including adversarial samples, data poisoning, and model theft, dynamically iterates and upgrades defense capabilities, adapts to new and unknown attacks, improves alarm response and defense coordination efficiency, ensures a dynamic balance between security, availability, and real-time performance, and provides persistent and stable security protection across all scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122339742A_ABST
    Figure CN122339742A_ABST
Patent Text Reader

Abstract

This invention belongs to the technical field of network security encryption and authentication methods, and particularly relates to a network security encryption and authentication method and system based on artificial intelligence. It constructs an input layer security barrier to block adversarial sample attacks by employing dual-dimensional perturbation detection, cryptographic hash comparison, and feature desensitization based on terminal hardware identifiers. It also establishes a training data tracing and poisoning sample removal mechanism, coupled with backdoor feature detection at the inference end and incremental model updates, to resist data poisoning and backdoor implantation threats. Furthermore, it utilizes chaotic encrypted sharding storage, dynamic parameter updates, and query behavior fingerprint detection to prevent model theft and reverse engineering attacks by returning false results and shielding intermediate layer outputs. Finally, it establishes a closed-loop linkage between adversarial perturbation, data poisoning, and model theft protection modules, simultaneously strengthening defense strategies upon alarms, and achieving unsupervised adaptive optimization through data collection to adapt to new and unknown attacks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the technical field of network security encryption authentication methods, and particularly relates to a network security encryption authentication method and system based on artificial intelligence. Background Technology

[0002] With the deep penetration of artificial intelligence technology into the field of cybersecurity authentication, biometric authentication (such as face, fingerprint, and voiceprint) is widely used in key scenarios such as finance, government affairs, and terminal access due to its convenience and uniqueness. However, AI authentication models face multiple security threats throughout their lifecycle: the input layer is vulnerable to adversarial example attacks, which can mislead the model to output incorrect results through subtle feature perturbations; during training, data poisoning and backdoor implantation may occur, and the injection of malicious samples can lead to model performance degradation or targeted manipulation; after deployment, the model also faces the risk of theft and reverse engineering, with attackers using methods such as batch queries and intermediate layer interface probing to analyze model parameters and decision logic, seriously threatening the reliability and data privacy security of the authentication system.

[0003] Existing protection technologies mostly employ single-dimensional defense strategies, such as independent adversarial sample detection, simple data filtering, or static encrypted storage. They lack cross-module collaborative capabilities and struggle to cope with multi-type complex attacks. Furthermore, traditional protection rules rely on known attack characteristics, resulting in insufficient adaptability to new and unknown attacks. Moreover, performance fluctuations and security vulnerabilities are prone to occur during model updates, hindering dynamic iterative optimization of defense strategies. In addition, security weaknesses exist in data transmission between terminals and servers, as well as in model parameter storage, further reducing the overall protection capability of AI authentication systems. Therefore, there is an urgent need to construct a comprehensive, multi-dimensional, and adaptive security encryption authentication system to fill these technological gaps. Summary of the Invention

[0004] In view of the aforementioned problems, and in conjunction with the first aspect of the present invention, embodiments of the present invention provide an artificial intelligence-based network security encryption authentication method, the method comprising: By employing dual-dimensional perturbation detection, cryptographic hash comparison, and feature desensitization by binding terminal hardware identifiers, an input layer security barrier is constructed to block adversarial sample attacks. Construct a training data source tracing and poisoned sample removal mechanism, combined with backdoor feature detection at the inference end and incremental model updates, to resist the threat of data poisoning and backdoor implantation; It employs chaotic encryption and sharded storage, dynamic parameter updates, and query behavior fingerprint detection to prevent model theft and reverse engineering attacks by returning false results and blocking intermediate layer output; Establish a closed-loop linkage between modules for combating disturbances, data poisoning, and model theft, simultaneously strengthen defense strategies when alarms are triggered, and achieve unsupervised adaptive optimization by combining data collection to adapt to new and unknown attacks.

[0005] Furthermore, embodiments of the present invention also provide an artificial intelligence-based network security encryption authentication system, characterized in that it includes: A processor; a machine-readable storage medium for storing machine-executable instructions of the processor; wherein the processor is configured to execute the aforementioned AI-based network security encryption authentication method by executing the machine-executable instructions.

[0006] In another aspect, embodiments of the present invention also provide a computer program product, the computer program product including machine-executable instructions, the machine-executable instructions being stored in a computer-readable storage medium, a processor of a computer device reading the machine-executable instructions from the computer-readable storage medium, and the processor executing the machine-executable instructions, causing the computer device to execute the aforementioned artificial intelligence-based network security encryption authentication method.

[0007] Based on the above, a comprehensive protection system encompassing the input layer, training layer, deployment layer, and optimization layer is constructed to accurately defend against various types of attacks, including adversarial examples, data poisoning, and model theft. The input layer employs dual-dimensional perturbation detection combined with feature desensitization in a TEE environment, effectively blocking malicious perturbation injection while fully protecting data privacy. The training data tracing and poisoning removal mechanism, through consortium blockchain evidence storage and multi-round clustering detection, significantly improves the purity of training data and accurately blocks backdoor samples from manipulating the model. The model's chaotic encrypted sharding storage and dynamic parameter updates build a robust protection barrier from both physical storage and logical iteration dimensions, effectively identifying abnormal query behavior and curbing attack attempts through a pseudo-result return mechanism.

[0008] Leveraging a closed-loop linkage mechanism across protection modules and an unsupervised adaptive optimization engine, this invention enables dynamic iterative upgrades of defense capabilities. It can quickly adapt to changing trends in novel and unknown attacks, promptly completing attack signature mining and defense strategy optimization. The cross-module linkage mechanism significantly improves alarm response and defense collaboration efficiency, compensating for the shortcomings of single-module protection. Gray-scale deployment and version rollback mechanisms effectively control business interruption risks and ensure the stability of model updates. The overall technical solution strengthens security protection levels while reasonably controlling performance overhead, achieving a dynamic balance between security, availability, and real-time performance, providing persistent and stable full-scenario security assurance for AI authentication systems. Attached Figure Description

[0009] Figure 1 This is a schematic diagram of the execution flow of the AI-based network security encryption authentication method provided in this embodiment of the invention.

[0010] Figure 2 This is a schematic diagram of exemplary hardware and software components of an artificial intelligence-based network security encryption authentication system provided in an embodiment of the present invention. Detailed Implementation

[0011] The present invention will now be described in detail with reference to the accompanying drawings. Figure 1 This is a flowchart illustrating an artificial intelligence-based network security encryption authentication method according to an embodiment of the present invention. The following is a detailed description of the artificial intelligence-based network security encryption authentication method.

[0012] Step S110: By performing dual-dimensional perturbation detection, cryptographic hash comparison, and feature desensitization by binding terminal hardware identifiers, an input layer security barrier is constructed to block adversarial sample attacks; A trusted execution environment (TEE) is built using Qualcomm TrustZone TEE. Dual-dimensional perturbation detection is explicitly defined as pixel-level feature detection and deep feature detection. The cryptographic hash uses the national standard SM3 algorithm, and the terminal hardware identifier uses a combination of IMEI, eSIM card number, and device motherboard serial number. Device legitimacy verification is achieved through hardware identifier binding. Dual-dimensional detection accurately identifies pixel-level tampering and feature perturbation by adversarial examples. Feature desensitization completes data privacy protection within the TEE. These three elements work together to form a triple-layer input layer protection system: device verification, perturbation identification, and data desensitization. This blocks adversarial example injection attacks at the source, ensuring that only compliant data from legitimate devices enters the subsequent authentication process.

[0013] Step S111: Collect sufficient biometric data of legitimate users, extract pixel-level and deep feature-level benchmark features. Pixel-level features include pixel gradient distribution, local variance range, and RGB channel correlation statistics of normal samples. Deep features are extracted into high-dimensional vectors through a pre-trained lightweight network. The two types of features are standardized respectively, and hash values ​​are calculated using SM3 or SHA-256 algorithms. The hash values ​​are encrypted and stored in the benchmark library and associated with the user identity and terminal hardware identifier whitelist. 60-100 biometric images (taking faces as an example) were collected for each legitimate user, covering 8 scenarios including strong light, low light, and side lighting, as well as different poses. Pixel-level features were extracted using the Sobel operator to extract the gradient distribution in the x / y directions, and the local variance range was calculated using an 8×8 window. Pearson coefficients were used to statistically analyze the correlation of the RGB three channels. The pre-trained lightweight network used MobileNetV2, with the input image resized to 224×224, outputting a 256-dimensional deep feature vector. Both types of features were normalized to the [0,1] interval using Min-Max, and a 256-bit hash value was calculated using the SM3 algorithm. The benchmark library was encrypted and stored using the national cryptographic SM4 algorithm, and a 256-bit hash whitelist was created by combining the user's ID number SHA-256 hash value with the hardware identifier to ensure a unique binding between identity, device, and feature.

[0014] Step S112: When the terminal initiates an AI authentication request, the unique hardware identifier of the terminal is read through the TEE or security chip, compared with the hardware identifier whitelist in the benchmark library, and verified to see if it has been tampered with. If they do not match, the authentication is blocked and an illegal device alarm is returned. When a terminal initiates an authentication request, it reads the combined identifier of IMEI, eSIM card number, and motherboard serial number through the Qualcomm TrustZone TEE built-in security API. The identifier signature is verified using the SM2 asymmetric encryption algorithm (the terminal stores the private key, and the server holds the public key) to confirm it has not been tampered with. The verified identifier is then subjected to a SHA-256 hash operation to generate a 256-bit fixed-length hash value, which is compared bit-by-bit with the pre-stored hardware identifier whitelist hash values ​​in the benchmark library. If a mismatch is found, an alarm code 0x002 is immediately returned, and the illegal device identifier and request timestamp are recorded in the encrypted security log, blocking subsequent authentication processes without disclosing the specific reason for the failure to the terminal, thus preventing attackers from reverse engineering the verification logic.

[0015] Step S113: At the pixel level, the pixel gradient outlier and other indicators are calculated through a sliding window and the difference is calculated with the baseline feature to generate a pixel-level perturbation feature vector; at the deep feature level, the data is input into the pre-trained lightweight network, and the deep perturbation feature vector is generated by calculating the cosine similarity and Euclidean distance with the baseline feature vector. Pixel-level detection uses a 6×6 sliding window to traverse the biometric image. The Sobel operator calculates the gradient values ​​in the x / y directions for each window, subtracts them from the mean gradient of the baseline feature, and takes the absolute value to generate gradient outliers. All window outliers constitute a 128-dimensional pixel-level perturbation feature vector. Deep feature detection inputs the image into a MobileNetV3 lightweight network, outputting a 512-dimensional feature vector. The cosine similarity (vector dot product divided by the modulus product) and Euclidean distance (L2 norm) between this vector and the baseline feature vector are calculated. These are then subtracted from preset thresholds of 0.88 and 1.5, respectively. The differences are concatenated dimensionally to generate a 512-dimensional deep perturbation feature vector, comprehensively capturing adversarial perturbation traces at different levels.

[0016] Step S114: Concatenate the two types of perturbation feature vectors, calculate the joint hash value using the corresponding hash algorithm, construct a comprehensive judgment score by combining Hamming distance and pixel-level difference mean, preset a dynamic threshold based on historical samples, block the process and record the attack log if the threshold is exceeded, otherwise determine it as a legitimate input and enter the desensitization stage. A 640-dimensional joint feature vector is obtained by concatenating a 128-dimensional pixel-level feature vector and a 512-dimensional deep perturbation feature vector. A 256-bit joint hash value is calculated using the SM3 algorithm. The Hamming distance is normalized to the [0,1] interval by statistically analyzing the binary bit differences between the joint feature vector and the baseline joint vector; the mean pixel-level difference is the arithmetic mean of all outliers in the sliding window. The comprehensive judgment score = 0.3 × normalized Hamming distance + 0.7 × mean pixel-level difference. The dynamic threshold is based on the 99.95th percentile of the score distribution of legitimate samples over the past 3 months and is automatically updated weekly. If the score exceeds the threshold, the device identifier, timestamp, joint hash value, and perturbation vector are recorded in the encryption attack log, blocking the authentication process; if the score does not exceed the threshold, it is considered legitimate input, triggering the desensitization process within the TEE.

[0017] Step S115: Using the terminal hardware identifier as the core and combining the one-time session factor, a de-identification key is constructed through the AES-128 simplified algorithm. Pixels in non-critical areas are obfuscated at the pixel level. Deep features are masked and noise perturbed through key control. The entire de-identification process is performed in the TEE environment, with only the de-identification features being passed in, and the original data is destroyed in real time. Using the SHA-256 hash value of IMEI + motherboard serial number as the core identifier, the server generates a 128-bit one-time session factor through a NIST SP800-90A compliant random number generator, which is then sent to the TEE via a TLS 1.3 encrypted channel. The core identifier and session factor are XORed bitwise, and a de-identified master key is generated through a 6-round AES-128 simplified algorithm, which is then split into pixel-level and deep feature sub-keys. Pixel-level sub-keys use a BiSeNetV2 network to identify non-critical areas, performing 10×10 pixel block random permutations and ±3 grayscale value offsets. Deep feature sub-keys use a binary mask generated from the key to mask 5% of non-critical dimensions, and are superimposed with Gaussian noise of 0 mean and 0.008 standard deviation. The entire de-identification process is performed within the TEE isolation domain. The original data is released from memory after three random overwrites; only the de-identified features are transmitted using SM4 encryption, and the key is prohibited from being exported to ordinary memory.

[0018] Step S1151: Extract a unique hardware identifier from the terminal TEE trusted execution environment or security chip, use the SM2 asymmetric encryption algorithm to perform signature verification on the hardware identifier, confirm that the identifier has not been tampered with, perform SHA-256 hash operation on the verified hardware identifier, and generate a 256-bit fixed-length hardware identifier root key. In this embodiment, the terminal TEE uses either Huawei Kunpeng TEE or Qualcomm TrustZone TEE. It extracts a unique hardware identifier through its built-in secure hardware interface. This identifier is a combination string of the IMEI, the unique ID of the security chip, and the motherboard serial number, ensuring the uniqueness and unforgeability of the terminal identifier. The SM2 signature verification of the hardware identifier is performed independently within the TEE. The terminal pre-stores the SM2 private key, while the server's public key is embedded in the TEE's security certificate area. The TEE calls the SM2 signature verification interface to verify the signature value of the hardware identifier, confirming that the identifier has not been tampered with or replaced. After successful verification, the TEE immediately calls the built-in SHA-256 hash algorithm to perform a one-way hash operation on the combined hardware identifier, generating a 256-bit fixed-length hardware identifier root key. This entire process is completed in the TEE's isolated memory; neither the original hardware identifier value nor the root key is exposed to the terminal's execution environment, ensuring the security of the root key from the source.

[0019] Step S1152: When the authentication request is initiated, the server generates a 128-bit one-time session factor through a cryptographically secure random number generator, and sends it to the terminal TEE environment through a TLS1.3 encrypted channel. The hardware identifier root key and the one-time session factor are XORed bitwise, and the first 128 bits of the result are used as the initial key material for the AES-128 simplified algorithm. The server deploys a cryptographically secure random number generator conforming to the NIST SP 800-90A standard. After the terminal initiates an authentication request and completes hardware identifier verification, it generates a 128-bit one-time session factor in real time. This factor is valid only once and cannot be reused. The session factor is distributed through a TLS 1.3 encrypted channel, using the TLS_AES_256_GCM_SHA384 encryption suite. After the terminal TEE verifies the legitimacy of the server's certificate chain, it receives and stores the session factor in secure memory. Subsequently, the TEE performs a bitwise XOR operation between the hardware identifier root key and the session factor in an isolated environment. Since the root key is 256 bits and the session factor is 128 bits, the session factor is first padded with zeros to 256 bits before the XOR operation is performed. The first 128 bits of the result are used as the initial key material for the AES-128 simplified algorithm, ensuring that the material length matches the algorithm requirements and achieving key dynamism.

[0020] Step S1153: Perform a simplified version of AES-128 operation on the initial key material, retain the core round functions of byte substitution, row shift, and column mixing, and simplify the number of operation rounds to 6 rounds to complete the initial key expansion and generate 6 rounds of subkeys. Extract the 128-bit subkey output from the last round as the de-identified master key. Split the de-identified master key into 64 bits to generate pixel-level de-identified subkeys and deep feature de-identified subkeys respectively. All keys are stored only in the secure memory area of ​​the TEE environment and are prohibited from being exported to ordinary memory space. The simplified AES-128 algorithm is implemented in the TEE's built-in cryptography library. It retains the three core round functions—byte substitution, row shifting, and column mixing—while eliminating redundant round expansion logic, reducing the number of rounds to six. After the initial key material is input into the algorithm, key expansion is performed according to the six-round computation requirement, generating six sets of 128-bit subkeys. The 128-bit subkey output from the last round is extracted as the de-identified master key. The de-identified master key is split into high 64 bits and low 64 bits to generate pixel-level de-identified subkeys and deep feature de-identified subkeys, both of which are marked as non-derivative. All keys are stored only in the TEE's secure static random access memory. The TEE kernel disables access, mapping, and DMA operations to this memory region by rich execution environment processes, ensuring that keys are not leaked into ordinary memory space and eliminating the risk of key theft.

[0021] Step S1154: Input biometric data into a lightweight semantic segmentation network, identify and label key feature regions and non-key regions to generate region masks, initialize a linear congruent generator based on the pixel-level desensitization subkey to generate a pseudo-random sequence, divide the non-key regions into 8×8 pixel blocks according to the sequence and perform position permutation, generate grayscale value offsets within ±5 range based on the subkey hash value modulo, and fine-tune the RGB three-channel pixel values ​​to the [0,255] range respectively; The lightweight semantic segmentation network uses the Fast-SCNN network, which is adapted to TEE computing power. After loading pre-trained weights within the TEE, it performs semantic segmentation on the input biometric image, accurately identifying key feature regions (such as facial features and fingerprint ridge regions) and non-key regions (such as background and redundant edge regions), and generating a binary region mask. A linear congruential generator is initialized based on a pixel-level desensitization subkey to generate a pseudo-random permutation sequence. Non-key regions are divided into 8×8 pixel blocks according to this sequence, and position permutations are performed. Simultaneously, a SHA-256 hash operation is performed on the pixel-level desensitization subkey. The hash value is modulo 11 and subtracted by 5 to generate a grayscale value offset within ±5. Offset adjustments are performed on the RGB three-channel pixel values ​​respectively. If the adjusted value exceeds the [0, 255] range, it is automatically truncated to ensure the legitimacy of the pixel-obfuscated image without destroying the integrity of key feature regions.

[0022] Step S1155: Input the pixel-obfuscated biometric data into a pre-trained lightweight feature extraction network, outputting a 512-dimensional or 1024-dimensional deep feature vector. Generate a binary mask sequence that matches the dimension of the feature vector based on the deep feature desensitization subkey. Use the SHAP feature importance algorithm to select 2%-5% of non-critical feature dimensions and set them to 0 according to the mask sequence. Use the subkey as a seed to generate Gaussian noise with a mean of 0 and a standard deviation of 0.01 and superimpose it onto the masked feature vector. After superposition, perform L2 normalization on the vector. The pre-trained lightweight feature extraction network, MobileNetV3-Large, is deployed within a TEE (Technical Environment). The network inputs pixel-obfuscated biometric data and outputs a 512-dimensional deep feature vector. Based on the deep feature desensitization subkey, the TEE random number generator generates a binary mask sequence matching the 512-dimensional vector. A lightweight SHAP feature importance algorithm within the TEE is used to calculate the contribution of each feature dimension to the authentication result, selecting 3% of non-critical feature dimensions and setting them to 0 according to the mask sequence. Subsequently, using the deep feature desensitization subkey as a seed, Gaussian noise with a mean of 0 and a standard deviation of 0.01 is generated and superimposed onto the masked feature vector. Finally, L2 normalization is performed on the superimposed vector to ensure a vector magnitude of 1, guaranteeing that the desensitized deep features still possess authentication discriminative power while protecting privacy.

[0023] Step S1156: All de-identification operations are completed within the isolated execution domain of the TEE environment. The security context is initialized and access permissions of ordinary system processes to TEE memory are disabled. The key, feature vector, and mask sequence intermediate data during the de-identification process are stored only in the TEE encrypted memory and require TEE kernel authorization for access. The de-identification instruction stream is executed by the security application built into the TEE. All de-identification operations are initiated within the isolated execution domain of the TEE. First, the TEE kernel initializes the security context, loads the de-identified security application (which has undergone integrity verification), and simultaneously disables access permissions to TEE memory for all processes in the terminal's rich execution environment, including memory read, write, and inter-process communication. Intermediate data generated during the de-identification process, such as keys, feature vectors, and mask sequences, are all stored in encrypted memory pages within the TEE. These memory pages require sequential authorization from the TEE kernel before they can be read or written, and all read and write operations are logged by the kernel log. The de-identification command stream is executed by the TEE's built-in security application binary file, which is signed using the SM2 algorithm. The TEE automatically verifies the signature upon startup to prevent tampering with the command stream. These isolation measures ensure that the de-identification process is not interfered with by malicious terminal programs, guaranteeing the security of data processing.

[0024] Step S1157: Concatenate the pixel-level desensitized features with the deep desensitized feature vector, encrypt them using the TEE's built-in SM4 algorithm, and then transmit them to the AI ​​authentication model inference node via an encrypted channel. After transmission, write random binary data three times to the original biometric data area in the TEE memory, call the system's underlying function to release the memory and mark it as unrecoverable, and clear all key materials in the TEE memory. Calculate the SHA-256 hash value of the desensitized features in the TEE environment and compare it with the preset verification value. If they do not match, re-execute the desensitization process. At the same time, verify that the effective information retention of the desensitized features is not lower than the preset threshold.

[0025] The pixel-level de-identified features are flattened into a one-dimensional vector and sequentially concatenated with the deep de-identified feature vector to form a combined de-identified feature vector. The TEE calls the built-in SM4 lightweight encryption algorithm, employing CTR encryption mode to encrypt the combined feature vector. The encryption key is a temporarily generated 128-bit session key, which is transmitted to the AI ​​authentication model inference node via a TLS 1.3 encrypted channel. After transmission, the TEE performs three random binary data overwrites on the original biometric data area in memory, then calls the system's underlying memory release function to mark the area as unrecoverable. Simultaneously, all key materials in the TEE memory are cleared, including the hardware identifier root key, session factor, and various de-identified sub-keys. Finally, the SHA-256 hash value of the de-identified features is calculated within the TEE and compared with the pre-issued verification value from the server. If they do not match, the de-identification process is re-executed. Simultaneously, the cosine similarity between the de-identified features and the original features is checked to ensure that the retention of effective information is not lower than a preset threshold.

[0026] Step S116: Regularly collect legitimate biometric data, update the baseline feature library using unsupervised learning, collect perturbation features through attack logs, incrementally learn to optimize the dual-dimensional detection logic and threshold, and update the hardware identification verification algorithm and desensitization key generation rules every quarter.

[0027] This embodiment sets a hierarchical update cycle. Monthly, through the normal authentication process of legitimate users, anonymized biometric data is collected for unsupervised updates of the baseline feature library. Weekly, adversarial perturbation attack alarm logs are collected in real time, and perturbation features are extracted for incremental learning of the dual-dimensional detection model. Quarterly, iterative optimization of the hardware identifier verification algorithm and the anonymized key generation rules is initiated. The baseline feature library update uses an improved unsupervised clustering algorithm to achieve dynamic feature iteration. The dual-dimensional detection model adapts to new perturbation attacks by freezing the backbone network and fine-tuning the decision layer. The hardware identifier verification and key generation rules are deployed in a gray-scale manner after being verified through attack and defense testing. Through a closed-loop mechanism of data collection-model optimization-algorithm iteration, the input layer security barrier continuously adapts to new and unknown adversarial sample attacks, ensuring the effectiveness of protection.

[0028] Step S1161: Collect de-identified biometric data of legitimate users covering multiple scenarios every month, and construct a standardized updated dataset after denoising, geometric alignment, standardization processing and filtering of invalid duplicate data; Each month, a fixed number of legitimate users are selected, covering various scenarios including indoor and outdoor environments, strong light, and low light. Their anonymized biometric data generated during the normal authentication process is collected to ensure the diversity of the dataset. The collected data undergoes standardized preprocessing. First, Gaussian filtering is used to remove image noise, and affine transformation is used to achieve geometric alignment and address pose misalignment. Then, Z-score standardization is performed on pixel-level and deep features separately to eliminate dimensional differences. Subsequently, cosine similarity between feature vectors is calculated, and invalid duplicate data with similarity higher than 0.98 are removed to avoid dataset redundancy. After preprocessing, a standardized updated dataset is generated and encrypted using the SM4 algorithm in a dedicated dataset repository on the server, providing high-quality, non-redundant input data for updating the baseline feature library.

[0029] Step S1162: An improved clustering algorithm with feature distance weights is used to cluster the standardized updated dataset to generate new feature cluster centers. The new feature cluster centers are then fused with the corresponding user features in the original benchmark feature library according to time weights. The updated benchmark feature library is versioned and an update verification code is generated. The verification is then performed offline and online with low traffic. If the verification passes, the original benchmark feature library is overwritten; otherwise, it is rolled back to the previous version. An improved K-means clustering algorithm, incorporating feature distance weights, is employed to cluster the standardized updated dataset. Different weights are assigned based on the feature distance between samples, increasing the influence of core samples on cluster centers and generating new feature cluster centers. These new feature cluster centers are then fused with the historical features of corresponding users in the original benchmark feature library, weighted by time, to achieve dynamic iteration of the benchmark features. A version number, update timestamp, and data batch identifier are added to the updated benchmark feature library, generating an SM3 algorithm checksum for version management. Offline verification is first conducted, testing the library's recognition performance using historical legitimate samples and attack samples. Then, low-volume online verification is initiated, connecting a small amount of real authentication traffic to the new library. Upon successful verification, the original benchmark library is overwritten; if the verification fails, a version rollback is immediately triggered, reverting to a historically stable version to ensure uninterrupted authentication services.

[0030] Step S1163: Collect alarm logs of adversarial perturbation attacks in real time, parse them in a structured manner according to the period, identify the perturbation pattern, extract the perturbation features and label the relevant attributes through the rule engine, and store them in the attack feature library to form a standardized perturbation feature dataset. Through the protection linkage control center, the adversarial perturbation attack alarm logs generated in step S114 are collected in real time. The logs contain core information such as terminal identifier, perturbation feature vector, and comprehensive judgment score. The logs are structured and parsed weekly. A rule engine is used to match preset perturbation pattern rules to identify different types of adversarial perturbation attack patterns, such as pixel tampering and feature vector offset. The parsed perturbation feature vectors are labeled with attributes such as attack type, frequency of occurrence, and effective status, and invalid noise data is removed. The processed perturbation feature vectors are stored in the attack feature library, categorized and archived according to attack type, forming a standardized perturbation feature dataset. This dataset serves as the core training data for the incremental learning of the two-dimensional detection model, providing data support for the model to adapt to new attacks and enabling continuous accumulation of attack features.

[0031] Step S1164: Construct an incremental learning framework based on the original dual-dimensional detection model, freeze the backbone feature extraction network and only update the detection decision layer, divide the standardized perturbation feature dataset into training and validation sets according to a reasonable ratio, input the dataset into the model with an appropriate batch size, fine-tune the parameters of the detection decision layer using the cross-entropy loss function, optimize the calculation logic of pixel-level and deep feature-level differences, set a window period to statistically analyze the distribution of comprehensive judgment scores of legal samples, calculate the corresponding quantile as the lower limit of the dynamic threshold, combine the perturbation score distribution in the attack feature library to ensure that the threshold meets the requirements of legal sample coverage and known perturbation attack identification, and after verification by attack sample backtesting and legal sample pass rate, launch the new detection logic and threshold. An incremental learning framework was built based on the original two-dimensional detection model, implemented using the PyTorch framework. The core feature extraction network parameters were frozen, while only the top-level detection decision layer and fully connected layer were unfrozen. The standardized perturbation feature dataset was hierarchically divided by scenario to form training and validation sets. The batch size was adjusted to fit the TEE computing power, and the decision layer parameters were fine-tuned using the cross-entropy loss function to optimize the difference calculation logic between pixel-level and deep feature-level features. A three-month statistical window was set to calculate the quantiles of the comprehensive judgment scores for legitimate samples, serving as the lower limit of the dynamic threshold. This was combined with the perturbation score distribution in the attack feature library to balance the coverage of legitimate samples with the attack identification requirements. The recognition rate was verified through backtesting with attack samples, and the pass rate was verified with legitimate samples. Once both metrics met the standards, the new detection logic and dynamic threshold were officially launched.

[0032] Step S1165: Iterate the hardware identifier verification algorithm every quarter, add timestamp verification and simplify the signature verification steps. After passing the attack and defense test, update the documentation and interface specifications in sync to ensure that the verification logic of the terminal and the server is consistent. The hardware identifier verification algorithm is iterated and optimized quarterly. Based on the original SM2 asymmetric encryption signature verification, a timestamp verification field is added, binding the hardware identifier to the current timestamp before signing, effectively preventing replay attacks. Simultaneously, the verification steps are streamlined, removing redundant double hash operations and directly performing SM2 verification on the combined value of the hardware identifier and timestamp, improving verification efficiency. The optimized algorithm is tested in a test environment using simulated forged and tampered hardware identifier samples to verify its recognition performance. After successful testing, the algorithm technical documentation and terminal-server interface specifications are updated synchronously, clarifying the new verification process, field formats, and interaction sequence. Terminal and server developers are organized to complete joint debugging to ensure complete consistency of the verification logic on both ends, avoiding authentication failures due to version differences.

[0033] Step S1166: Synchronize the verification algorithm update cycle, adjust the details of the simplified AES-128 algorithm, optimize the key fusion method, encrypt the rules for issuing new keys, update the logic after terminal verification, and retain a reasonable transition period; To keep pace with the quarterly update cycle of the hardware identifier verification algorithm, the execution details of the round function of the AES-128 simplified algorithm were adjusted. The fusion method of the hardware identifier root key and the one-time session factor was optimized from bitwise XOR to HMAC-SHA256 fusion, improving the security of key fusion. The server generates a new key rule configuration file, using the SM2 algorithm for signing and the SM4 algorithm for encryption, and distributes it to the terminal TEE environment through a TLS 1.3 encrypted channel. After the terminal TEE verifies the validity of the configuration file signature, it updates its local key generation logic. A reasonable transition period is set, during which terminals can be compatible with both the old and new key generation rules, ensuring that terminals that have not completed the update can still complete authentication normally. After the transition period, the old rules are automatically deactivated, achieving smooth iteration of key rules and avoiding business interruption.

[0034] Step S1167: After the canary deployment update, first switch to a small proportion of traffic, monitor core indicators, and gradually expand to the full volume if the indicators are met; if there are any abnormalities, roll back and optimize. The updated baseline feature library, detection logic, verification algorithm, and key rules are implemented using a canary deployment approach. Initially, 10% of genuine legitimate authentication traffic is routed to a protection system equipped with the updated solution. A real-time monitoring platform is established to focus on three core metrics: legitimate user authentication success rate, attack detection rate, and single authentication response time. A 72-hour canary monitoring cycle is set. If the metrics meet the preset requirements within the cycle, the traffic routing scope is gradually expanded in increments of 20%, 50%, and 100%. If the monitoring reveals that the legitimate user authentication failure rate exceeds the preset threshold, or if the attack detection rate decreases or the response time increases significantly, a traffic rollback mechanism is immediately triggered, switching all traffic back to the original solution. Simultaneously, technical personnel are organized to locate the cause of the anomaly, optimize the solution, and restart the canary deployment process.

[0035] Step S1168: Record the entire process update log, establish a version rollback mechanism, quickly roll back in case of anomalies, analyze the cause and incorporate it into the next round of optimization.

[0036] A log management module is deployed in the protection and linkage control center to record the entire process of updating the benchmark feature library, optimizing detection logic, and upgrading algorithms and key rules. The logs include information such as operation time, operator identity, data batch, algorithm version, verification results, and gray-scale deployment status. The logs are encrypted using the SM4 algorithm and retained for twelve months. A robust version rollback mechanism is established, storing algorithm, rule, and feature library versions for the past twelve quarters on the server, assigning a unique identifier to each version and associating it with the update logs. In the event of a security vulnerability or business anomaly, the version rollback mechanism rolls back to a designated historical stable version within ten minutes. The technical team analyzes the logs to identify the root cause of the anomaly, transforming it into specific requirements for algorithm optimization and rule adjustments, incorporating them into the next round of update and optimization plans, forming a closed loop of continuous improvement.

[0037] Step S120: Construct a training data source tracing and poisoned sample removal mechanism, combined with backdoor feature detection at the inference end and incremental model updates, to resist the threat of data poisoning and backdoor implantation; This embodiment constructs a three-pronged defense system of tracing, detection, and updating to resist data poisoning and backdoor implantation threats. Training data tracing employs SHA-256 hashing + SM2 encryption; poisoning sample removal integrates triple preprocessing detection and real-time monitoring during training; backdoor detection is embedded in the model inference chain; and incremental model updates are implemented using the PyTorch framework. All modules are linked through an encrypted communication protocol. Poisoning sample information located by the tracing module is synchronized to the detection module in real time, and backdoor trigger events automatically trigger the incremental update process, forming a closed-loop defense of poisoning identification, backdoor blocking, and model optimization, ensuring the security of the AI ​​certification model throughout the entire chain from data input to inference output.

[0038] Step S121: Generate a unique traceability identifier for each training sample, calculate the joint hash value of the original sample data and the corresponding metadata using a hash algorithm, digitally sign the hash value using an asymmetric encryption algorithm to form a traceability tag, and embed the traceability tag into the corresponding sample feature data and store it in conjunction with the sample features. A unique traceability identifier is generated for each training sample. The metadata includes the source node ID, collection timestamp, annotation personnel ID, and scene tag. The SHA-256 algorithm is used to calculate the joint hash value of the original sample data and metadata. The hash value is then digitally signed using the SM2 asymmetric encryption algorithm to generate an immutable traceability tag. For image-based biometric samples, the traceability tag is embedded in low-frequency pixel channels. For feature vector samples such as fingerprints / voiceprints, redundant dimensions of the feature vectors are embedded. The embedding depth is controlled within a range that does not affect the model training effect. The traceability tag and sample feature data are bound in the form of key-value pairs and stored using the SM4 algorithm for encryption.

[0039] Step S122: Build a consortium blockchain traceability storage system, put sample traceability tags, metadata and signature information on the chain to form a chain-like immutable structure, store the mapping relationship between samples and traceability identifiers through an encrypted database, and implement multi-factor authentication control for traceability information queries; A consortium blockchain traceability storage system based on Hyperledger Fabric is built. The consortium blockchain nodes include data collection nodes, annotation nodes, training nodes, and audit nodes. Each node must be authenticated via SM2 signature before joining. Sample traceability tags, metadata, and SM2 signature information are uploaded to the blockchain in a block structure. Each block is associated with the hash value of the previous block, forming a chain-like, tamper-proof structure. A MongoDB encrypted version is used to store the mapping relationship between samples and traceability identifiers, with the mapping table managed by data batch partitioning. Traceability information queries require multi-factor authentication: operators must enter an authorization key and verify the terminal device fingerprint (hardware model + MAC address hash value) and a dynamic password (updated every 30 seconds). Only authorized audit nodes can export complete traceability information; other nodes can only query the basic traceability fields of associated samples.

[0040] Step S123: Before the training data is put into the database, perform multi-dimensional preprocessing and detection, including label consistency verification, feature outlier detection and metadata compliance verification, and remove abnormal and suspected poisoning samples from illegal sources based on the detection results; Before training data is entered into the database, a triple preprocessing check is performed: First, label consistency verification, using the majority-voting algorithm to compare the labeling results of the same sample over three rounds; if the results conflict in two or more rounds, the sample is removed. Second, feature outlier detection, using the isolated forest algorithm to cluster the sample feature vectors and calculate the Euclidean distance between the sample and the cluster center; samples exceeding three standard deviations are marked as suspected poisoning samples. Third, metadata compliance verification, verifying whether the source node is within a preset whitelist and whether the collection time is within a legal period; samples from illegal sources are directly blocked from entering the database. Only samples that pass all three checks can enter the training dataset; suspected poisoning samples require manual review before a decision is made on whether to retain them, ensuring that the purity of the entered data is ≥99.9%.

[0041] Step S124: During model training, monitor the gradient contribution value and loss value of each batch of samples in real time. When a poisoning warning is triggered, locate the related samples based on the source information, complete the sample feature re-verification through cluster analysis, remove samples that deviate from the normal feature distribution, and continue training after verifying that the feature distribution of the dataset is compliant. During model training, PyTorch's Hook mechanism is used to statistically analyze the gradient contribution of each batch of samples in real time. The normal fluctuation range of the loss value is set at ±10%. If a batch of samples causes the loss value fluctuation to exceed 20% or a sudden change in gradient direction, a poisoning warning is immediately triggered. The source identifier of the warning batch of samples is extracted, and the source batch and related samples are located through a consortium blockchain tracing system. The DBSCAN clustering algorithm is used to reanalyze the features of this batch of samples, with a cluster radius of 0.5 and a minimum sample size of 5. Samples deviating from the normal feature distribution in the clustering results are removed. The similarity (cosine similarity) of the feature distribution between the removed dataset and the historical clean dataset is calculated. Training can only continue if the similarity is ≥98%; otherwise, the clustering and removal process is repeated.

[0042] Step S125: Embed a backdoor feature detection unit in the AI ​​authentication model inference chain, pre-build a backdoor trigger feature library, extract the feature vector output of the intermediate layer of the model in real time during inference and match it with the backdoor trigger feature library, monitor the probability distribution of the model output at the same time, and determine whether the backdoor is triggered based on the matching result and the probability distribution status. A backdoor feature detection unit is embedded between the intermediate and output layers of the AI-certified model's inference chain. Ten typical backdoor trigger feature libraries (including pixel-triggered, feature vector-triggered, and temporal-triggered modes) are pre-generated through adversarial training, and these feature libraries are updated quarterly. During inference, the output feature vectors of the model's convolutional layers (e.g., the 6th convolutional layer of ResNet18) and fully connected layers are extracted in real time and matched with the backdoor trigger feature library using cosine similarity, with a similarity threshold of 0.85. Simultaneously, the model's output probability distribution is monitored. If a certain category's probability is ≥0.95 and there is no obvious correspondence with the input features (e.g., no key biometric feature matching), it is determined to be an output anomaly. Both a similarity ≥0.85 and an output anomaly are considered backdoor triggering.

[0043] Step S126: When a backdoor is detected, immediately block the model authentication decision and key generation output link and freeze the current inference session. Based on the source identification, trace back the source and transmission path of the input data that triggered the backdoor, isolate the corresponding neuron weights, and start a backup clean model to perform emergency authentication. Upon detection of a backdoor trigger, the blocking interface of the model inference chain is immediately invoked to cut off the output channels for authentication decisions and key generation, freezing the current inference session (while retaining session logs for tracing). The consortium blockchain is then queried in reverse using the sample tracing identifier to obtain the source node, transmission path (e.g., acquisition terminal, edge node, training server), and timestamp of the input data that triggered the backdoor, recording backdoor trigger characteristics, terminal identifiers, and other information. The neuron weights associated with the backdoor features in the model are temporarily isolated, and the corresponding weights are reset to random values ​​with a mean of 0 and a variance of 0.001. Simultaneously, a clean backup model (hot standby deployment, switchover latency ≤ 1 second) is started to perform emergency authentication, ensuring uninterrupted service.

[0044] Step S127: Regularly collect biometric data of legitimate users in normal authentication scenarios and complete the desensitization process. Perform source tracing verification and poisoning detection on the processed data, construct a clean incremental dataset, divide the training set and validation set proportionally, and ensure the consistency of data distribution. Biometric data from legitimate users in normal authentication scenarios is collected monthly, covering eight scenarios including indoor / outdoor, strong / weak light, and different postures, with 30-50 data points collected per user. After the collected data undergoes the anonymization process described in S115, source verification (verifying the legality of the source tag signature and metadata compliance) and poisoning detection (reusing the triple detection mechanism of S123) are performed to remove abnormal data, ensuring the purity of the incremental dataset is ≥99.9%. The incremental training and validation sets are divided in a 7:3 ratio, and the KS test is used to verify the consistency of feature distribution between the incremental dataset and the original training dataset, requiring a test statistic ≤0.05 to ensure no significant difference in data distribution and avoid model training bias.

[0045] Step S128: Construct an incremental learning framework based on the original model, freeze the parameters of the underlying feature extraction network, and use mini-batch gradient descent combined with regularization constraints to complete incremental training. Monitor the backdoor removal effect in real time during training. Replace the original model after offline verification and small-volume online verification. An incremental learning framework was built based on the original AI authentication model (such as ResNet18+ fully connected layer structure). The parameters of the bottom feature extraction network (the first 3 convolutional layers) were frozen, while only the parameters of the top decision layer (2 fully connected layers) and the intermediate attention interaction layer were unfrozen. Mini-batch (batch size 16) gradient descent was used for training, with AdamW as the optimizer. The initial learning rate was set to 1 / 10 of the original model, and an L2 regularization term (λ=0.001) was introduced into the loss function to prevent overfitting. During training, the backdoor test set (containing 10 typical backdoors and 500+ variant samples) was used in each iteration to monitor the removal effect. A backdoor false positive pass rate ≤0.5% was considered satisfactory. After offline validation (accuracy ≥99% for normal samples) and online validation with 5% traffic (response time ≤1.1 times that of the original model), the original model was replaced.

[0046] Step S1281: Load the trained AI certification original model, split the parameters according to the network structure, mark the bottom feature extraction network as a frozen layer and lock the parameters to not participate in gradient update, mark the top decision layer and the intermediate interaction layer as trainable layers and retain the parameter update permission, build an incremental learning framework based on the deep learning framework, reuse the feature extraction logic of the original model, initialize only the optimizer configuration of the trainable layer, and adapt the optimizer parameters. The trained AI certification model is loaded using PyTorch's `torch.load` function. Parameters are then split layer by layer according to the network structure: the bottom-level feature extraction network (e.g., the first three convolutional layers and feature fusion layer of ResNet18) is marked as a frozen layer, and its parameters are locked by calling `model.parameters().requires_grad_(False)`, preventing them from participating in gradient updates; the top-level decision layer (two fully connected layers) and the intermediate key interaction layer (attention mechanism layer) are marked as trainable layers, retaining their parameter update permissions. An incremental learning framework is built based on PyTorch, reusing the original model's feature extraction logic. Only the optimizer configuration of the trainable layers is initialized. The initial learning rate of the AdamW optimizer is set to 1 / 10 of the original model's training learning rate (e.g., if the original learning rate is 1e-3, the incremental learning rate is 1e-4), and the weight decay coefficient is set to 1e-4 to avoid excessively large initial update amplitudes that could cause model performance fluctuations.

[0047] Step S1282: Align the feature distribution of the preprocessed clean incremental dataset, calculate the difference in feature distribution between the incremental dataset and the original training dataset and reduce the difference through standardization transformation, divide the data into small batches using stratified sampling to ensure that each batch of data contains samples from different scenarios and users, add sample weights to the incremental dataset, and balance the fusion ratio of new data and original model knowledge. The preprocessed clean incremental dataset undergoes feature distribution alignment. The differences in feature mean and variance between the incremental dataset and the original training dataset are calculated, and Z-score normalization (mean reduced to 0, variance normalized to 1) is applied to ensure the difference is ≤5%. Stratified sampling is used to divide the data into small batches, with a batch size of 16 (adaptable to GPU computing power, adjustable to 32 depending on hardware). Sampling dimensions include user identity, collection scenario, and data type, ensuring each batch covers different users and multiple scenarios, avoiding batch data bias. Sample weights are added to the incremental dataset: data collected within the last 3 months has a weight coefficient of 1.2, and data collected within the last 3-6 months has a weight coefficient of 0.9, balancing the integration ratio of new data and original model knowledge, and considering both model updates and stability.

[0048] Step S1283: Introduce a regularization term into the loss function of the trainable layer to constrain the update magnitude of the weight parameters to prevent overfitting, enable the early stopping mechanism, use the authentication accuracy of normal samples on the validation set as the monitoring index, automatically stop the current batch training and backtrack the optimal weights when the preset conditions are triggered, and use gradient clipping during the training process. An L2 regularization term with a regularization coefficient λ = 0.001 is introduced into the cross-entropy loss function of the trainable layers to prevent overfitting by constraining the L2 norm of the weight parameters. An early stopping mechanism is enabled, using the authentication accuracy of normal samples on the validation set as the monitoring metric. Trigger conditions are set: if the accuracy does not improve for five consecutive iterations (improvement < 0.1%) or the accuracy drops by more than 0.5% in a single iteration, training for the current batch is automatically stopped, and the optimal weights are retrieved through model checkpointing. A gradient pruning strategy is employed during training, setting a gradient norm threshold of 1.0. When the gradient norm of the trainable layers exceeds this threshold, the gradient values ​​are scaled proportionally to prevent gradient explosion that could lead to abnormal model parameters.

[0049] Step S1284: Input incremental data in small batches, perform forward propagation to calculate the model prediction results and loss values, calculate the gradient values ​​of trainable layers through backpropagation, perform parameter updates only on the top decision layer and key interaction layer, set the gradient values ​​of the frozen layer to zero and not participate in the update, periodically calculate the weight similarity between the current model and the original model to ensure that the model's feature extraction ability does not degrade, adapt to the total number of training iterations, and balance the risk of knowledge updates and forgetting. Incremental data is input into the model in small batches, and forward propagation is performed to calculate the model's prediction results and cross-entropy loss. Gradient values ​​of trainable layers are calculated via backpropagation; gradient values ​​of frozen layers are set to zero and do not participate in parameter updates. After every 10 batches of training, the cosine similarity between the current model and the weights of the original model's trainable layers is calculated, requiring a similarity ≥95% to ensure that the model's core feature extraction ability does not degrade. The total number of training iterations is set to 1 / 3 to 1 / 2 of the original model's training iterations (e.g., if the original model trained for 100 iterations, incremental training is set to 30-50 iterations) to balance knowledge updates and the risk of forgetting. During training, the loss value and gradient contribution value of each batch are recorded in real time. If abnormal fluctuations occur, training is paused to investigate data or parameter issues.

[0050] Step S1285: After each round of iterative training, the preset backdoor test set is called to input the model, the output features of the intermediate layer of the model are extracted and matched with the backdoor trigger feature library, the false pass rate of the backdoor sample is calculated, the direction of change of the weight of the trainable layer is monitored, the learning rate of the corresponding layer is adjusted when the warning condition is triggered, the backdoor clearing threshold is set, and if the threshold is not met, iterative training continues and re-evaluation is performed. After each round of training iteration, a pre-defined backdoor test set is input into the model. This test set contains 10 typical backdoor trigger samples (such as image watermark triggering, triggering by specific feature vector values) and 500+ random backdoor variant samples. Feature vectors from the intermediate layers (convolutional layer outputs) of the model are extracted and matched with the backdoor trigger feature library using cosine similarity. The false positive pass rate of the backdoor samples (the proportion of the model that fails to identify the backdoor and outputs a valid result) is calculated. Simultaneously, through feature association analysis, the correlation between the trainable layer weights and backdoor features is monitored. If the proportion of parameters associated with backdoor features after a certain layer weight update is ≥3%, a weight adjustment warning is triggered, and the learning rate of that layer is automatically reduced to half of the current value. A backdoor removal threshold is set: false positive pass rate ≤0.5%. If the threshold is not met, iterative training continues, with a maximum of 5 additional rounds for re-evaluation. If the threshold is still not met, the model reverts to the optimal weights from the previous round.

[0051] Step S1286: After training, construct an offline verification dataset and perform verification from the dimensions of normal sample authentication accuracy, backdoor sample blocking rate, and generalization ability to ensure that the model does not lose its original performance after incremental updates and to verify the model inference time. After training, an offline validation dataset was built, containing 100,000+ legitimate normal samples (covering multiple users and scenarios), 20,000+ backdoor samples of various types (known backdoors + unknown variants), and 50,000+ edge scenario samples (such as pose shift and noise interference). Validation was conducted in three aspects: first, the accuracy rate for normal sample authentication was ≥99%, with a difference of ≤0.3% from the original model's accuracy; second, the backdoor sample blocking rate was ≥99.5% for known backdoor samples and ≥98% for unknown variant backdoor samples; third, the generalization ability was validated, with an authentication accuracy rate of ≥97% for edge scenario samples. Simultaneously, inference time testing was performed, verifying that the difference between the model's inference time for a single request and the original model was ≤10%, to avoid excessive performance loss affecting business operations. Meeting all these criteria was considered a successful offline validation.

[0052] Step S1287: After offline verification meets the standards, online verification is launched using a gray-scale deployment method. Some real authentication traffic is routed to the incrementally updated model. A real-time monitoring panel is built to monitor the indicators, and the monitoring period is set. When the indicators are abnormal, the traffic switching mechanism is triggered to reroute the abnormal traffic back to the original model. After offline verification is successful, online verification is launched using a canary deployment approach. A traffic routing system routes 5%-10% of genuine authentication traffic to the incrementally updated model, while the remaining traffic is handled by the original model. A real-time monitoring panel is set up to monitor the following metrics: legitimate user authentication pass rate (≥99%), backdoor trigger alarm rate (deviation from offline verification results ≤1%), single-request inference time (≤1.1 times the original model's time), and abnormal output percentage (≤0.1%). A 24-72 hour monitoring cycle is set. If any abnormal metrics occur during this period (e.g., a sudden increase in the legitimate user failure rate >1%, or a backdoor alarm rate deviation exceeding 1%), a traffic backtracking mechanism is immediately triggered to reroute the abnormal traffic back to the original model, and anomaly logs are recorded for subsequent analysis.

[0053] Step S1288: When there are no abnormal fluctuations in the indicators during the online verification period, gradually expand the traffic routing range to complete the full model replacement, mark the updated model as a version, record the training information and store it in the model version library, retain the original model and intermediate model versions in the incremental update process, and establish a fast rollback mechanism.

[0054] During the online validation period, the metrics showed no abnormal fluctuations. The traffic routing range was gradually expanded in increments of 20%, 50%, and 100%, with each phase spaced 24 hours apart, ensuring the model adapted to real business traffic. After completing the full model replacement, the updated model was version-marked, with the version number including the update date, data batch, iteration round, and key information such as training data batch, regularization parameters, and validation results, and stored in an encrypted model version repository. The original model and three intermediate model versions from the incremental update process were retained, and a 10-minute rapid rollback mechanism was established: the model weight file and configuration parameters could be switched with one click through the version management tool, and if new backdoors or performance degradation issues subsequently appeared, the system could immediately switch to a historically stable version.

[0055] Step S129: Establish a full-process linkage mechanism for tracing, detection, and updating modules. Perform full-process log auditing on sample entry, poisoning detection, sample removal, model updates, and backdoor triggering events. Retain historical logs and model versions to achieve attack path backtracking and optimization of detection rules and update strategies.

[0056] After a poisoned sample is removed, the tracing module automatically marks the tracing information of the corresponding batch of samples as suspected poisoning and synchronizes it to the consortium blockchain. Upon triggering a backdoor, the detection module immediately pushes backdoor features and trigger data to the update module, initiating the incremental model update process. All operations undergo full-process log auditing. Logs include operator ID, timestamp, data batch, model version, detection results, and defense measures, and are encrypted using the SM4 algorithm with a retention period of 24 months. Logs are audited and analyzed regularly (monthly) to extract behavioral characteristics of new poisoning and backdoor attacks, optimize detection rules (such as adjusting outlier thresholds and updating the backdoor feature library) and incremental update strategies (such as adjusting the learning rate and iteration rounds), achieving continuous adaptive optimization of the defense system.

[0057] Step S130: Chaotic encryption sharding storage, dynamic parameter updating and query behavior fingerprint detection are adopted to prevent model theft and reverse engineering attacks by returning false results and blocking intermediate layer output; This embodiment constructs a four-layer defense system—encrypted storage, dynamic protection, behavior detection, and output control—to prevent model theft and reverse engineering attacks. Chaotic encryption uses Logistic chaotic mapping to generate keys; parameter dynamic updates employ a weekly timed update + anomaly triggering mechanism; query behavior fingerprint detection covers four-dimensional features; and output defense is achieved by shielding the intermediate layer interface and dynamic pseudo-results. All modules are linked through encrypted message queues (Kafka + SM4). Abnormal requests identified by the behavior detection module trigger real-time emergency parameter updates and pseudo-result returns. Chaotic encryption sharding blocks complete model theft from the storage layer, forming a closed loop of static protection, dynamic iteration, and real-time interception, comprehensively resisting attacks such as model theft and reverse engineering.

[0058] Step S131: Generate a highly random chaotic sequence based on chaotic mapping as the encryption key, and perform stream encryption on the complete parameter matrix and network structure description file of the AI ​​authentication model. Introduce parameter dimension obfuscation during the encryption process. Split the encrypted model asset into multiple fragments according to functional modules. Add a unique check code to each fragment. Store different fragments on different nodes of the distributed cluster. Each node deploys an independent access control policy. Only authorized nodes can obtain the corresponding fragment through multi-factor authentication. No single node stores the complete model asset. When a fragment is called, the fragment decryption and splicing are completed through multi-party secure computation within the cluster. The splicing process is only temporarily executed in memory. After execution, the complete parameters are immediately cleared. A highly random chaotic sequence is generated based on the Logistic chaotic mapping and used as a stream encryption key to perform stream encryption on the parameter matrix and network structure description file of the AI ​​authentication model. During encryption, the order of convolutional kernel dimensions is shuffled and the weight index of fully connected layers is rearranged to achieve parameter dimension obfuscation. The encrypted model asset is split into 6 fragments according to the feature extraction layer, intermediate interaction layer, and decision output layer, and each fragment is attached with a unique CRC32 checksum. The fragments are stored on 6 different nodes in a Kubernetes distributed cluster. Each node deploys an independent IAM access control policy. Authorized nodes need to obtain fragments through multi-factor authentication using permission keys, timestamp signatures, and biometric verification. When a fragment is accessed, decryption and concatenation are completed in the cluster memory through the SPDZ multi-party secure computation protocol. The complete parameters after concatenation only reside in memory for 100ms and are immediately cleared after inference is completed.

[0059] Step S132: Set up a two-layer update condition of scheduled update and abnormal trigger update. Abnormal trigger update is triggered by query behavior fingerprint detection results or suspicious access logs. An incremental micro-update strategy is adopted. A random perturbation matrix is ​​generated based on the original model parameters. Only the top decision layer parameters of the model are updated, while the bottom feature extraction layer parameters remain stable. During the update process, a dual-model parallel mechanism is enabled. After the performance of the new parameter model is verified to meet the standard by a small traffic test, seamless switching is performed. The old parameters are immediately invalidated and encrypted and archived. At the same time, a chaotic encryption key is regenerated based on the update timestamp and random number. Updates are scheduled every Sunday from 3-5 AM (off-peak business hours). Anomaly-triggered updates are triggered by query behavior fingerprinting detecting ≥20 abnormal requests within 10 minutes on a single terminal or by unauthorized node access to shards in parameter access logs. An incremental micro-update strategy is employed, generating a random perturbation matrix based on the original model parameters (perturbation amplitude controlled within ±3%). Only the top-level decision layer (fully connected layer) parameters are updated, while the bottom-level feature extraction layer parameters are locked. A dual-model parallel mechanism is enabled during updates, with the new parameter model and the original model running simultaneously. The new model's authentication accuracy is verified using 1% real traffic (deviation from the original model ≤0.5%) before seamless switching. Old parameters are encrypted using SM4 and archived to cold storage. A chaotic encryption key is generated using SM3 hashing based on the update timestamp and random numbers from cluster nodes, ensuring synchronous iteration of the encryption system after each update.

[0060] Step S133: Define a multi-dimensional query behavior fingerprint dimension that includes device fingerprint, request features, query pattern, and user behavior. Construct a fingerprint baseline based on normal query behavior data. Use an anomaly detection algorithm to calculate the deviation of each query behavior from the baseline. Collect fingerprint data of query requests in real time. Determine abnormal query behavior based on the deviation of a single request or multiple deviations in a short period of time. Establish an abnormal behavior feature library to achieve accurate identification. Device fingerprints include hardware model, system version, and terminal identifier SHA-256 hash value; request characteristics include request frequency, time interval, and data transmission packet size distribution; query patterns include input feature distribution, interface call order, and parameter input format; user behavior includes historical authentication time period, operation duration, and geographical distribution. A fingerprint baseline is constructed based on 3 months of normal query data (≥1 million records). The Isolation Forest algorithm is used to calculate the deviation of query behavior from the baseline, with a threshold set at 0.8. Request fingerprint data is collected in real time. If a single request deviation is ≥0.8, or if the same terminal makes ≥3 requests with a deviation ≥0.6 within 5 minutes, it is considered abnormal. An abnormal behavior feature library is established, incorporating typical theft behaviors such as batch requests with different inputs (≥50 requests per minute), high-frequency calls to intermediate layer interfaces, and continuous probing of parameter boundaries. Accurate identification is achieved through feature matching.

[0061] Step S134: Remove external access permissions for all intermediate layer output interfaces in the model inference chain, retain only the output channel of the final authentication result of the model, block the execution permissions of requests that attempt to call intermediate layer interfaces, generate pseudo results that follow the distribution characteristics of normal authentication results but have no effective business information for abnormal query requests, embed hidden abnormal markers in the pseudo results, and dynamically update the pseudo result generation logic according to a preset period. For high-frequency abnormal requests, gradually increase the request response delay while returning pseudo results. Remove all intermediate layer output interface routes from the API gateway of the model inference service, retaining only the authentication result return interface. If a request attempting to call the intermediate layer interface is detected, return a 404 error indicating no interface exists, and simultaneously block all query permissions for that terminal for 10 minutes. For abnormal query requests, generate pseudo results: the pass rate and rejection reason types of the pseudo results are consistent with the distribution of normal requests, but they do not contain real identity verification information and embed SM4 encrypted hidden tags (decoded only by the internal audit system). The pseudo result generation logic is updated hourly, adjusting the numerical distribution and the order of returned fields to prevent attackers from reverse engineering. For high-frequency abnormal requests (≥10 times per minute), the response delay when returning pseudo results increases incrementally according to the rule of an initial 100ms, a 1s delay for every additional 10 requests, and a maximum of 5s, reducing the efficiency of theft.

[0062] Step S135: Establish a linkage mechanism for encrypted storage, parameter update, behavior detection, and output defense modules. After an abnormal query behavior is triggered, suspend the access permissions of the corresponding terminal for model parameters, mark high-risk shard access requests and start the emergency parameter update process. Log all defense behaviors throughout the process. The logs are stored in an encrypted manner and retained for a preset period. The logs are audited regularly and new attack behavior characteristics are extracted. Optimize the fingerprint detection baseline, false result generation rules and parameter update strategies. Establish an emergency response process. When a large-scale model theft attack is detected, switch to the backup model instance, take the original model instance offline and complete the full parameter update and encryption system reconstruction.

[0063] Upon triggering an anomaly query, the behavior detection module pushes the terminal identifier to other modules via an encrypted message queue, the encrypted storage module suspends the terminal's shard access permissions, and the parameter update module initiates an emergency update process. All defense behavior logs contain information such as query fingerprints, anomaly judgment criteria, defense measures, and pseudo-result content, and are encrypted and stored in a distributed log system using the SM4 algorithm, with a retention period of 12 months. Monthly log audits and analyses are conducted to extract new attack characteristics (such as unknown query patterns and new interface probing behaviors), optimize fingerprint detection baselines (adjusting deviation thresholds), pseudo-result generation rules (adding rejection reason types), and parameter update strategies (shortening the anomaly trigger update cycle). If ≥50 terminals simultaneously trigger anomalies (large-scale theft attack), the system immediately switches to a hot-standby backup model instance, the original model instance is taken offline, and a full parameter update and chaotic encryption system reconstruction are completed within 2 hours.

[0064] Step S140: Establish a closed-loop linkage between the anti-disturbance, data poisoning, and model theft protection modules, simultaneously strengthen the defense strategy when an alarm is triggered, and combine data collection to achieve unsupervised adaptive optimization to adapt to new and unknown attacks.

[0065] A closed-loop system is constructed, linking three major protection modules: anti-disturbance, data poisoning, and model theft. Adaptive defense is achieved through alarm triggering, policy reinforcement, data collection, and unsupervised optimization. The core of this linkage is the protection control center, which uses a microservice architecture to integrate the interfaces and data channels of the three modules. When an alarm occurs, cross-module defenses are simultaneously strengthened according to the severity level (e.g., a data poisoning alarm triggers the model theft module to block access from suspicious terminals). Attack data and defense logs from the three modules are collected in real time, standardized, and then input into an unsupervised adaptive optimization engine. An improved DBSCAN clustering method is used to discover new attack characteristics, and reinforcement learning is combined to adjust defense parameters (such as detection thresholds and encryption strength). This closed loop undergoes a full optimization iteration weekly. For unknown attacks, an emergency optimization process is triggered, generating temporary defense strategies within one hour and verifying them with small-scale traffic, enabling rapid adaptation to new and unknown attacks.

[0066] Step S141: Construct a unified protection linkage control center, integrate the interfaces and data channels of the three protection modules of anti-disturbance, data poisoning, and model theft, use encrypted communication protocols to realize real-time data interaction between modules, define multi-level alarm levels, establish a mapping rule base of alarm types and cross-module defense actions, form a detection, alarm, and linkage defense trigger link, and the center summarizes the defense status, attack characteristics and processing results of each module in real time to construct a global protection situation view and support cross-module correlation analysis of attack behavior; A unified protection and linkage control center is constructed, adopting a Spring Cloud microservice architecture. It integrates the RESTful API interfaces and data channels of the three major protection modules. Inter-module communication uses TLS 1.3+SM4 encryption protocol to ensure the immutability and non-disclosure of transmitted information. Three alarm levels are defined: Level 1 (large-scale attack) refers to attacks triggered by ≥50 terminals simultaneously; Level 2 (targeted attack) refers to precise attacks against specific users / devices; and Level 3 (suspicious probing) refers to single or a small number of abnormal requests. A mapping rule base between alarm types and cross-module defense actions is established (e.g., model theft triggers Level 1 alarms to urgently update chaotic encryption keys + strengthen device fingerprint verification against disturbance modules). The center aggregates the defense status, attack characteristics, and processing results of each module through the Neo4j graph database, constructing a global protection situation view and supporting cross-module correlation analysis of attack behaviors (e.g., mining the temporal correlation between data poisoning and model theft).

[0067] Step S142: Implement differentiated defense enhancement measures for different alarm levels and attack types. When the anti-disturbance alarm is triggered, strengthen the detection parameters and cross-module feature push. When the data poisoning alarm is triggered, suspend the permissions of suspicious data and start the source tracing query. When the model theft alarm is triggered, optimize the parameter update cycle and access authentication mechanism. Synchronize attack-related information between modules to coordinate and enhance defense. Set dynamic duration for all enhancement measures and automatically fall back to the default policy after the timeout. When a disturbance alarm is triggered, the dual-dimensional detection difference threshold is temporarily increased by 20%, the sliding window density is increased (8×8, 4×4), and disturbance features are pushed to the model theft module. When a data poisoning alarm is triggered, the permission for data from suspicious sources to enter the database is suspended, the source tracing chain query is initiated, and the model theft module is simultaneously required to block access from that terminal. When a model theft alarm is triggered, the parameter update cycle is changed from weekly to daily, and the complexity of sharded access authentication is increased (biometric verification is added). Each module synchronizes attack-related information through an encrypted Kafka message queue. All reinforcement measures are set with dynamic durations: 30 minutes for level 3 alarms, 2 hours for level 2 alarms, and 12 hours for level 1 alarms. After the timeout, the system automatically reverts to the default strategy through the central control to avoid excessive defense affecting business performance.

[0068] Step S143: Collect attack-related data from the three modules in real time to form a full attack event data packet. Perform standardization processing on the collected data, unify the data format, extract attack features, eliminate the differences in feature dimensions between modules through feature alignment algorithm, and generate a standardized attack dataset containing attack type, triggering conditions, feature vectors, and defense effects. Label unknown attack data with specific tags and store them separately in the new attack sample pool. The system includes perturbation feature vectors and detection difference indicators for the adversarial perturbation module; poisoned sample features and source information for the data poisoning module; and abnormal query fingerprints and pseudo-result logs for the model stealing module. The collected data undergoes standardization processing: a unified format is defined according to JSON Schema, and SM4 encryption is used for storage; core attack features are extracted using PCA dimensionality reduction and mutual information entropy algorithms to eliminate differences in feature dimensions between modules; a standardized attack dataset containing attack type, triggering conditions, feature vectors, and defense effectiveness is generated. Unknown attack data that cannot match the existing feature library is labeled with the "unclassified - YYYYMMDD" tag (YYYYMMDD being the collection date) and stored separately in an encrypted new attack sample pool. This sample pool is managed according to attack scenarios and serves as the core input data for unsupervised adaptive optimization.

[0069] Step S144: Based on the standardized attack dataset and the new attack sample pool, build an unsupervised adaptive optimization engine. Use clustering algorithm to cluster unclassified attack samples, identify new attack feature clusters and add them to the attack feature library of each module. Use anomaly pattern mining algorithm to optimize cross-module linkage triggering conditions. Use reinforcement learning framework to adaptively adjust defense strategy parameters. An unsupervised adaptive optimization engine is built based on a standardized attack dataset and a novel attack sample pool. An improved DBSCAN clustering algorithm with adaptive density is used to cluster unclassified attack samples, automatically identifying novel attack feature clusters and extracting cluster center feature vectors to supplement the attack feature database of each module. The Apriori association rule algorithm is used to mine association patterns of different attack types, optimizing cross-module linkage triggering conditions (such as adjusting alarm association confidence thresholds). The PPO reinforcement learning framework is adopted, defining a state space (attack type, alarm level, system load, etc.) and an action space (adjustable parameters for each module). The reward function is set as attack recognition rate × 0.6 - legitimate business impact × 0.3 - system resource consumption × 0.1, adaptively adjusting defense strategy parameters (such as detection threshold, desensitization strength) and setting parameter adjustment constraints (not exceeding default values ​​±30%) to ensure the security and effectiveness of defense iteration.

[0070] Step S1441: Load the standardized attack dataset and the unclassified data in the new attack sample pool, and perform normalization, dimensionality reduction, missing value imputation and outlier filtering operations on all features in sequence to eliminate feature dimension differences, reduce computational complexity and filter invalid data, forming standardized input data for engine training. The system loads standardized attack datasets and unclassified data from a novel attack sample pool, performing Z-score normalization on all features (mean reduced to 0, variance normalized to 1) to eliminate dimensional differences. PCA is used to reduce feature dimensions, retaining principal component features with a cumulative variance contribution rate ≥95% to reduce computational complexity. For a small number of missing feature values, KNN interpolation (neighborhood k=5) is used to impute data integrity. An isolated forest algorithm is used to filter extreme outliers, setting the outlier ratio to ≤1% to avoid noise affecting optimization. The preprocessed data forms standardized input data for engine training, formatted as NumPy arrays, encrypted using the SM4 algorithm, and stored in the engine's local secure memory. This data is only decrypted and accessed during training, and the plaintext data is immediately deleted after training.

[0071] Step S1442: An improved clustering algorithm with adaptive density is used to perform clustering operations on unclassified attack samples. The clustering parameters are dynamically adjusted based on the local density of the data. After filtering out noisy isolated clusters, effective feature clusters are retained. The central feature vector of each effective cluster is calculated. The feature dimensions within the cluster are selected to generate new attack feature descriptors. The feature descriptors are mapped to the feature library of the corresponding protection module for adversarial perturbation, data poisoning, and model theft according to the attack type, and the feature library is updated. An improved DBSCAN clustering algorithm with adaptive density is used to cluster unclassified attack samples. First, a value of k is determined based on 5% of the total samples. The average distance of the k-nearest neighbors is calculated, and local densities are generated. eps (high-density regions shrink to 0.8 times the initial value, low-density regions expand to 1.5 times) and min_samples (set to 3% / 2% / 1% according to density quantiles) are dynamically adjusted. Noisy clusters with less than 5 samples are filtered out, and after retaining effective feature clusters, the mean vector of the feature dimension within each cluster is calculated as the central feature vector. The top 25% of highly correlated features are selected using the mutual information entropy algorithm, and key features are refined by combining ≥5% variance contribution. A structured descriptor containing feature UUID, type, numerical distribution (mean ± standard deviation), correlation dimension, and triggering scenario is generated. An "automatic mining" tag and a cluster credibility score (mean cosine similarity within the cluster) are added. Based on the feature type, the corresponding protection module is mapped. Cross-type features are determined to be the main module according to the contribution of ≥60%. The feature library is updated incrementally and deduplicated by cosine similarity (threshold 0.85). The feature is verified by simulated attack test (recognition rate ≥85%). Finally, the feature is versioned and synchronized to the global protection situation view.

[0072] Step S14421: Receive the standardized unclassified attack sample data, perform feature type alignment operation, encode discrete features into continuous features and unify the feature data type to ensure that the feature dimensions of all samples are consistent, and form homogeneous clustering input data; The system receives standardized, unclassified attack sample data and performs feature type alignment: discrete features (such as attack scenario labels) are converted into continuous features using one-hot encoding; textual features (such as API call descriptions) are mapped to low-dimensional vectors using Word2Vec; and all feature data types are unified to float32. The system iterates through the sample feature dimensions, zero-padding for missing dimensions and deleting redundant and invalid dimensions to ensure all samples are uniformly 256-dimensional feature vectors. Through feature dimension consistency verification, outlier samples with mismatched dimensions are removed, ultimately forming homogeneous clustering input data. The data format is unified as a NumPy array (shape=[N,256], where N is the number of samples), ensuring the consistency and effectiveness of the clustering algorithm input.

[0073] Step S14422: Based on Euclidean distance to measure the similarity between samples, construct a global distance matrix for unclassified attack samples, determine the k value according to a preset proportion of the total number of samples, calculate the average k-nearest neighbor distance for each sample point, calculate the local density of the sample through the average k-nearest neighbor distance, generate a global density distribution histogram and determine the density peak and density median. The global distance matrix for unclassified attack samples is calculated using the Euclidean distance formula. A value of k is determined for 5% of the total samples (e.g., k=50 for 1000 samples), and the average distance to the k-nearest neighbors of each sample point is calculated. Local density is calculated using the formula "local density = 1 / k-nearest neighbor average distance". A global density distribution histogram is generated using matplotlib, and the density value corresponding to the peak of the histogram is taken as the density peak, while the density value corresponding to the 50th percentile is taken as the density median. Both the distance matrix and local density data are stored in an in-memory database Redis, managed by sample batches and partitions to ensure rapid retrieval when adjusting subsequent clustering parameters.

[0074] Step S14423: Use a preset multiple of the global average distance of the samples as the initial value of eps. Adjust eps according to the local density distribution. Reduce eps for sample clusters with density higher than the median and increase eps for sample clusters with density lower than the median. Dynamically set minsamples according to the local density quantiles of the samples. Different minsamples values ​​correspond to different density intervals to ensure accurate identification of the core points of each density region. The initial value of eps (exp) is set to 1.2 times the global average distance between samples. This is then dynamically adjusted based on the global density distribution: for sample clusters with local densities higher than the median, eps is reduced to 0.8 times the initial value to improve clustering accuracy in high-density regions; for sample clusters with local densities lower than the median, eps is increased to 1.5 times the initial value to avoid splitting low-density effective clusters. The min_samples value is set according to the local density quantiles of the samples: the top 30% of the density regions are set to 3% of the total samples, the middle 40% to 2%, and the bottom 30% to 1%. This dynamic adaptation strategy ensures that core points in different density regions can be accurately identified, balancing clustering accuracy and recall.

[0075] Step S14424: Start the improved density clustering algorithm based on the dynamically adapted parameters, traverse all unclassified samples, mark core points, boundary points and isolated points, expand the core points to form initial clusters, merge adjacent clusters with a distance less than eps to eliminate inter-cluster redundancy, filter isolated clusters and small clusters with a sample number lower than a preset threshold, and retain effective feature clusters. Based on the dynamically adapted eps and min_samples, an improved density clustering algorithm is initiated, traversing all unclassified samples: those with a neighborhood sample count ≥ min_samples are labeled as core points, those with a neighborhood sample count < min_samples but directly reachable from core points are labeled as boundary points, and the rest are isolated points. Initial clusters are formed through iterative expansion of core points. The Euclidean distance between the centers of adjacent clusters is calculated; if the distance is less than eps, clusters are merged to eliminate redundancy. Isolated clusters and small clusters with less than 5 samples are filtered out as random noise and removed, retaining valid feature clusters with ≥ 5 samples. During the clustering process, a cluster formation log is recorded in real time, including information such as the number of core points, cluster size, and number of merges, for subsequent tracking and optimization.

[0076] Step S14425: Calculate the central feature vector of each effective cluster. The central feature vector is the mean vector of the feature dimensions corresponding to all samples in the cluster. The mutual information entropy algorithm is used to calculate the correlation between each feature dimension in the cluster and the cluster label. The highly correlated feature dimensions are sorted according to the correlation degree and the key feature set is further refined by combining the variance contribution of the feature dimensions. Calculate the central feature vector for each valid cluster, which is the arithmetic mean vector of the corresponding feature dimensions of all samples within the cluster. Use the mutual information entropy algorithm to calculate the correlation between each feature dimension and the cluster label, sorting them in descending order of mutual information entropy value, and selecting the top 25% of highly correlated feature dimensions. Further calculate the variance contribution of each feature dimension, retaining dimensions with a variance contribution ≥ 5%, refining the key feature set (e.g., 60-80 dimensions out of 256). This dual selection mechanism ensures that the key features possess both strong discriminative power (high correlation) and stability (high variance contribution), providing high-quality input for subsequent feature descriptor generation.

[0077] Step S14426: Based on the refined key feature dimensions, generate a new type of structured attack feature descriptor that includes feature identifier, feature type, numerical distribution range, associated feature dimensions, and typical triggering scenarios. Add a preset label, mining timestamp, and cluster credibility score to each feature descriptor. Based on refined key feature dimensions, a new type of structured attack feature descriptor is generated: feature identifiers are uniquely encoded using UUIDs; feature types are categorized as adversarial perturbation / data poisoning / model theft; numerical distribution ranges are expressed as mean ± standard deviation; related feature dimensions list interdependent feature combinations (e.g., "request frequency + time interval"); and typical trigger scenarios clearly define specific scenarios (e.g., "≥20 abnormal requests within 10 minutes on a single terminal"). Each descriptor is added with an "automatic mining" preset label, a mining timestamp accurate to the second, and a cluster credibility score (the mean of pairwise cosine similarity among all samples within the cluster). Descriptors are uniformly stored in JSON format for easy subsequent feature library updates and retrieval.

[0078] Step S14427: Establish a mapping rule base between feature descriptors and attack types. Based on the feature type, map the descriptors to the corresponding protection modules for adversarial perturbation, data poisoning, and model theft. For cross-type features, determine the main mapping module according to the feature contribution weight and associate it with other related modules. A mapping rule base for feature descriptors and attack types is established: perturbation-related features (such as pixel gradient anomalies and feature vector offsets) are mapped to the adversarial perturbation protection module; features such as sample source tracing anomalies and gradient contribution anomalies are mapped to the data poisoning protection module; features such as request behavior fingerprint deviations and intermediate layer access anomalies are mapped to the model theft protection module. For cross-type features (containing multiple attack features simultaneously), the main mapping module (adversarial perturbation module) is determined by calculating feature contribution weights (e.g., 65% contribution of perturbation features and 35% contribution of theft features), while other related modules (model theft modules) are associated, and the association weights are marked to ensure collaborative defense against cross-type attacks.

[0079] Step S14428: The mapped new attack feature descriptors are written into the attack feature library of the corresponding protection module using an incremental update method. The similarity between the new features and the existing features in the library is calculated, duplicate features are removed, and the updated feature library is validated by simulated attack tests. Features that do not reach the preset recognition rate are temporarily stored in the queue to be optimized. An incremental update approach is adopted, appending the mapped new attack feature descriptors to the end of the attack feature library of the corresponding protection module without overwriting existing features. The similarity between the new features and existing features in the library is calculated using a cosine similarity algorithm. If the similarity is ≥0.85, it is considered a duplicate feature and automatically removed to avoid redundancy. The updated feature library undergoes validity verification: a simulated test set containing 1000 new attack samples is constructed and input into the protection module to verify the recognition rate of the new features, requiring a recognition rate ≥85%. Features that do not meet the standard are temporarily stored in an optimization queue, and the feature mining process is re-executed weekly to ensure the validity and purity of the feature library.

[0080] Step S14429: Record the feature database update log, mark the feature database with versions and retain historical versions for a preset period, support version backtracking, push feature database update notifications to the protection linkage control center, and synchronously update the attack feature map in the global protection situation view.

[0081] The system records feature library update logs, including key information such as update time, number of new features, mapping module, verification results, and operators. The logs are encrypted using the SM4 algorithm and retained for 12 months. The feature library is version-marked with version numbers in the format "VYYYYMMDD_XXX" (YYYYMMDD being the update date and XXX being the number of new features), retaining historical versions for the past 12 months and supporting one-click backtracking via version number. Feature library update notifications are pushed to the protection linkage control center via a RESTful API. Upon receiving the notification, the center synchronously updates the global protection posture attack feature map in the Neo4j database, ensuring that cross-module linkage defense can be based on the latest features.

[0082] Step S1443: Use association rule mining algorithm to perform pattern mining on the full attack data to find the association relationship between different attack types; combine anomaly detection algorithm to analyze the misjudgment cases of linkage triggering conditions, extract common features to adjust the linkage condition threshold, establish a linkage condition priority mechanism sorted by attack severity and association strength, and optimize the execution order of linkage actions. The Apriori association rule mining algorithm was used to mine patterns in the full attack data, with a minimum support of 0.05 and a minimum confidence of 0.7, to uncover associations between different attack types (e.g., "the probability of model theft attacks increases by 30% within 72 hours after data poisoning"). The Isolation Forest algorithm was used to analyze misjudgments of linkage triggering conditions, extracting common features of false triggers (e.g., legitimate requests being marked as attacks) and missed triggers. The confidence threshold for cross-module alarm associations was adjusted from 0.8 to 0.75. A linkage condition priority mechanism was established: sorted by attack severity (large-scale attacks > targeted attacks > suspicious probes) and association strength (confidence ≥ 0.7 for strong association), optimizing the execution order of linkage actions, such as first initiating emergency parameter updates (defense priority level 1), then strengthening detection strategies (defense priority level 2), reducing unnecessary resource consumption.

[0083] Step S1444: Define a reinforcement learning state space that includes multi-dimensional indicators such as attack type, alarm level, and system load, covering the action space of adjustable parameters of each protection module, as well as a reward function that integrates attack recognition rate, legitimate business impact, and system resource consumption. Train the reinforcement learning model using a near-end policy optimization algorithm, enable an online learning mechanism to dynamically update policy network parameters, and set parameter adjustment constraint boundaries to limit the adjustment range of defense parameters. Attack types (3 categories), alarm levels (3 levels), system load (CPU utilization / memory utilization), legitimate user authentication pass rate, false alarm rate, and model inference time. The action space includes 20 adjustable parameters, including adversarial disturbance detection threshold, data poisoning source verification depth, and model theft of false results delay gradient. The reward function formula is: Reward = 0.6 × attack recognition rate - 0.3 × (false alarm rate + authentication time increment / 10%) - 0.1 × (CPU utilization / 80%). The PPO algorithm is used to train the model, with an experience replay pool capacity of 10,000 records, a training batch size of 64, and 200 iterations. An online learning mechanism is enabled, triggering incremental training every 100 new attack data records received, with parameter adjustment constraints set (±30%) to avoid excessive adjustments affecting business operations.

[0084] Step S1445: Integrate new attack features, optimized cross-module linkage conditions and defense parameters to generate a standardized configuration file. After encrypting the configuration file, push it to the three protection modules for anti-disturbance, data poisoning and model theft. After each module verifies the legality of the configuration file, loads the corresponding configuration and feeds back the loading result to the optimization engine. The engine records the configuration update log to form a closed loop for the implementation of optimization results.

[0085] The system integrates novel attack signatures, optimized cross-module linkage conditions, and defense parameters to generate a standardized JSON configuration file. This file comprises four main modules: signature description, linkage rules, parameter thresholds, and effective scope. The configuration file is encrypted using the SM4 algorithm and pushed to the three protection modules via a TLS 1.3 encrypted channel. Upon receiving the file, each module verifies its signature using the SM2 algorithm and loads the corresponding configuration according to its function (e.g., the anti-disturbance module loads new disturbance signatures and detection parameters). After loading, each module returns a JSON confirmation message (including module ID, configuration version, and loading time). The optimization engine records the configuration update log and marks it as "update complete," forming a closed loop for the optimization results and ensuring that the configuration takes effect synchronously.

[0086] Step S145: The new feature library and strategy parameters output by the optimization engine are deployed through a canary deployment mechanism. First, some business traffic is routed to the protection system equipped with the optimization strategy. The indicators are monitored in real time, and a canary verification period is set. During this period, the protection effect before and after optimization is compared. If the indicators meet the standards, the deployment scope is gradually expanded. If an anomaly occurs, the original strategy is immediately rolled back. During the verification process, the running data is collected and fed back to the optimization engine to form a closed-loop iteration. First, 10% of business traffic is routed to the protection system equipped with optimized strategies through the traffic routing system. Four core metrics are monitored in real time: legitimate user authentication pass rate ≥99%, new attack identification rate ≥90%, model inference time increase ≤15%, and false alarm rate ≤0.5%. A 72-hour gray-scale verification cycle is set, during which the control center compares the protection effect before and after optimization every hour. If all metrics are met, the deployment scope is gradually expanded in increments of 30%, 60%, and 100%, with each phase spaced 24 hours apart. If any legitimate business anomalies occur (e.g., the pass rate drops below 98.5%), the system is immediately rolled back to the original strategy using version management tools. During the verification process, operational data is collected hourly and fed back to the unsupervised optimization engine, forming a closed loop of "optimization-verification-feedback-re-optimization".

[0087] Step S146: Establish a regular full-scale optimization iteration cycle. The optimization engine automatically summarizes relevant data within the cycle and re-executes the optimization process. It continuously updates the attack feature library and linkage rule library. For new types of unidentified attack events, it triggers an emergency optimization process, extracts attack features, and quickly generates temporary defense strategies. After verification with small traffic, it is deployed. The linkage efficiency of the three protection modules is regularly evaluated, and the scheduling logic of the control center is optimized to form a dynamic defense closed loop that adapts to unknown attacks.

[0088] A weekly full-scale optimization iteration cycle is established. The optimization engine automatically summarizes attack data, defense logs, and gray-scale verification results within the cycle, re-executes unsupervised clustering, feature mining, and strategy optimization, and updates the attack feature library and linkage rule library. For unidentified new attack events, an emergency optimization process is triggered: isolated features of the attack are extracted within 1 hour, a temporary defense strategy is generated, and after 1 hour of verification with 5% small traffic (requiring an identification rate ≥80%), it is directly deployed to achieve immediate defense upon discovery. The linkage efficiency of the three major protection modules is evaluated monthly, with key indicators including alarm response latency ≤50ms and cross-module action synchronization time ≤10ms. The scheduling logic of the control center is optimized (e.g., by using priority queue scheduling of linkage instructions). A full-scale protection effectiveness evaluation is conducted quarterly, and optimization strategies are dynamically adjusted to form a dynamic defense closed loop that continuously adapts to unknown attacks.

[0089] Based on the same inventive concept, please refer to Figure 2 The diagram shows a schematic block diagram of an AI-based network security encryption authentication system 100 provided in this application embodiment for executing the above-described AI-based network security encryption authentication method. The AI-based network security encryption authentication system 100 may include a communication unit 110, a machine-readable storage medium 120, and a processor 130.

[0090] In this embodiment, both the machine-readable storage medium 120 and the processor 130 are located within the AI-based network security encryption and authentication system 100 and are configured separately. However, it should be understood that the machine-readable storage medium 120 may also be independent of the AI-based network security encryption and authentication system 100 and may be accessed by the processor 130 via a bus interface. Alternatively, the machine-readable storage medium 120 may be integrated into the processor 130 and may communicate and interact with external systems via the communication unit 110.

[0091] The processor 130 is the control center of the AI-based network security encryption authentication system 100. It connects various parts of the system via various interfaces and lines, and performs overall monitoring of the AI-based network security encryption authentication system 100 by running or executing software programs and / or modules stored in the machine-readable storage medium 120 and by calling data stored in the machine-readable storage medium 120. Optionally, the processor 130 may include one or more processing cores; for example, the processor 130 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the modem processor may not be integrated into the processor. The machine-readable storage medium 120 stores machine-executable instructions for executing the scheme of this application, and the processor 130 executes the machine-executable instructions stored in the machine-readable storage medium 120 to implement the AI-based network security encryption authentication method provided in the aforementioned method embodiments.

[0092] It should be noted that, in order to simplify the description of the present invention and thus help to understand one or more embodiments of the invention, multiple features may sometimes be grouped into one embodiment, drawing or description thereof in the foregoing description of the embodiments of the present invention.

Claims

1. An artificial intelligence-based network security encryption authentication method, characterized in that: Includes the following steps: By employing dual-dimensional perturbation detection, cryptographic hash comparison, and feature desensitization by binding terminal hardware identifiers, an input layer security barrier is constructed to block adversarial sample attacks. Construct a training data source tracing and poisoned sample removal mechanism, combined with backdoor feature detection at the inference end and incremental model updates, to resist the threat of data poisoning and backdoor implantation; It employs chaotic encryption and sharded storage, dynamic parameter updates, and query behavior fingerprint detection to prevent model theft and reverse engineering attacks by returning false results and blocking intermediate layer output; Establish a closed-loop linkage between modules for combating disturbances, data poisoning, and model theft, simultaneously strengthen defense strategies when alarms are triggered, and achieve unsupervised adaptive optimization by combining data collection to adapt to new and unknown attacks.

2. The network security encryption authentication method based on artificial intelligence according to claim 1, characterized in that: The method involves constructing an input layer security barrier through dual-dimensional perturbation detection, cryptographic hash comparison, and feature desensitization based on terminal hardware identifiers to block adversarial sample attacks, including: Collect sufficient biometric data of legitimate users, extract pixel-level and deep feature-level benchmark features. Pixel-level features include pixel gradient distribution, local variance range, and RGB channel correlation statistics of normal samples. Deep features are extracted into high-dimensional vectors through a pre-trained lightweight network. The two types of features are standardized respectively, and hash values ​​are calculated using SM3 or SHA-256 algorithms. The hash values ​​are encrypted and stored in the benchmark library and associated with the user identity and terminal hardware identifier whitelist. When a terminal initiates an AI authentication request, the unique hardware identifier of the terminal is read through the TEE or security chip, compared with the hardware identifier whitelist in the benchmark library, and verified to see if it has been tampered with. If they do not match, the authentication is blocked and an illegal device alarm is returned. At the pixel level, outlier indexes of pixel gradients are calculated using a sliding window and the difference is calculated with the baseline feature vector to generate pixel-level perturbation feature vectors; at the deep feature level, data is input into a pre-trained lightweight network, and deep perturbation feature vectors are generated by calculating the cosine similarity and Euclidean distance with the baseline feature vector. Two types of perturbation feature vectors are concatenated, and a joint hash value is calculated using the corresponding hash algorithm. A comprehensive judgment score is constructed by combining Hamming distance and pixel-level difference mean. A dynamic threshold is preset based on historical samples. If the threshold is exceeded, the process is blocked and an attack log is recorded. If the threshold is not exceeded, it is judged as a legitimate input and enters the desensitization stage. Using terminal hardware identifier as the core and combining one-time session factor, a desensitization key is constructed through AES-128 simplified algorithm. Pixel-level pixel obfuscation of non-critical areas is performed, and deep features are masked and noise perturbed through key control. The entire desensitization process is performed in TEE environment, with only the desensitization features being passed in, and the original data is destroyed in real time. Regularly collect legitimate biometric data, update the baseline feature library using unsupervised learning, collect perturbation features through attack logs, incrementally learn to optimize the dual-dimensional detection logic and thresholds, and update the hardware identification verification algorithm and desensitization key generation rules every quarter.

3. The network security encryption authentication method based on artificial intelligence according to claim 2, characterized in that: The process uses terminal hardware identifiers as the core, combined with a one-time session factor, and constructs a de-identification key using the AES-128 simplified algorithm. Pixel-level obfuscation of non-critical areas is performed, and deep features are masked and perturbed by the key. The entire de-identification process is executed in a TEE environment, with only the de-identification features being passed in, and the original data is destroyed in real time. This includes: Extract a unique hardware identifier from the terminal TEE trusted execution environment or security chip, use the SM2 asymmetric encryption algorithm to sign and verify the hardware identifier to confirm that the identifier has not been tampered with, and perform SHA-256 hash operation on the verified hardware identifier to generate a 256-bit fixed-length hardware identifier root key. When an authentication request is initiated, the server generates a 128-bit one-time session factor through a cryptographically secure random number generator, and sends it to the terminal TEE environment through a TLS 1.3 encrypted channel. The hardware identifier root key and the one-time session factor are XORed bitwise, and the first 128 bits of the result are used as the initial key material for the AES-128 simplified algorithm. A simplified version of AES-128 operation is performed on the initial key material, retaining the core round functions of byte substitution, row shift, and column mixing, and the number of operation rounds is reduced to 6 rounds. The initial key is expanded to generate 6 rounds of subkeys. The 128-bit subkey output in the last round is extracted as the de-identified master key. The de-identified master key is split into 64 bits to generate pixel-level de-identified subkeys and deep feature de-identified subkeys. All keys are stored only in the secure memory area of ​​the TEE environment and are prohibited from being exported to ordinary memory space. Biometric data is input into a lightweight semantic segmentation network to identify and label key and non-key regions to generate region masks. A linear congruent generator is initialized based on the pixel-level desensitization subkey to generate a pseudo-random sequence. The non-key regions are divided into 8×8 pixel blocks according to the sequence and position permutation is performed. Gray value offsets within ±5 are generated by taking the modulus of the subkey hash value. The pixel values ​​of the RGB three channels are fine-tuned to the [0,255] interval respectively. The pixel-obfuscated biometric data is input into a pre-trained lightweight feature extraction network, which outputs a 512-dimensional or 1024-dimensional deep feature vector. Based on the deep feature desensitization subkey, a binary mask sequence matching the dimension of the feature vector is generated. The SHAP feature importance algorithm is used to select 2%-5% of non-critical feature dimensions and set them to 0 according to the mask sequence. Gaussian noise with a mean of 0 and a standard deviation of 0.01 is generated using the subkey as a seed and superimposed on the masked feature vector. After superposition, L2 normalization is performed on the vector. All de-identification operations are completed within the isolated execution domain of the TEE environment. The security context is initialized and access permissions of ordinary system processes to TEE memory are disabled. During the de-identification process, the key, feature vector, and mask sequence intermediate data are stored only in the TEE encrypted memory and require TEE kernel authorization to access. The de-identification instruction stream is executed by the TEE's built-in security application. The pixel-level desensitized features are concatenated with the deep desensitized feature vectors, and then lightweight encrypted using the TEE's built-in SM4 algorithm before being transmitted to the AI ​​authentication model inference node via an encrypted channel. After transmission, random binary data is written three times to the original biometric data area in the TEE memory. The system's underlying function is called to release the memory and mark it as unrecoverable. At the same time, all key materials in the TEE memory are cleared. The SHA-256 hash value of the desensitized features is calculated within the TEE environment and compared with a preset verification value. If they do not match, the desensitization process is re-executed. Meanwhile, the effective information retention of the desensitized features is verified to be no less than a preset threshold.

4. The network security encryption authentication method based on artificial intelligence according to claim 2, characterized in that: The process involves periodically collecting legitimate biometric data, updating the baseline feature library using unsupervised learning, collecting perturbation features through attack logs, incrementally optimizing the dual-dimensional detection logic and thresholds, and updating the hardware identifier verification algorithm and de-identification key generation rules quarterly, including: Every month, we collect de-identified biometric data of legitimate users covering multiple scenarios. After denoising, geometric alignment, standardization, and filtering of invalid and duplicate data, we build a standardized and updated dataset. An improved clustering algorithm with feature distance weights is used to cluster the standardized updated dataset to generate new feature cluster centers. The new feature cluster centers are then fused with the corresponding user features in the original benchmark feature library according to time weights. The updated benchmark feature library is versioned and an update verification code is generated. The verification is then performed offline and online with low traffic. If the verification is successful, the original benchmark feature library is overwritten; otherwise, it is rolled back to the historical version. Real-time collection of alarm logs against adversarial perturbation attacks; periodic structured parsing; identification of perturbation patterns, extraction of perturbation features, and labeling of relevant attributes through a rule engine; storage in an attack feature library to form a standardized perturbation feature dataset. An incremental learning framework is built based on the original two-dimensional detection model. The backbone feature extraction network is frozen and only the detection decision layer is updated. The standardized perturbation feature dataset is divided into training and validation sets according to a reasonable ratio and input into the model with an appropriate batch size. The cross-entropy loss function is used to fine-tune the parameters of the detection decision layer, optimize the calculation logic of pixel-level and deep feature-level differences, set a window period to statistically analyze the distribution of comprehensive judgment scores of legal samples, calculate the corresponding quantile as the lower limit of the dynamic threshold, and combine the perturbation score distribution in the attack feature library to ensure that the threshold meets the requirements of legal sample coverage and known perturbation attack identification. After verification by attack sample backtesting and legal sample pass rate, the new detection logic and threshold are launched. The hardware identifier verification algorithm is iterated every quarter, adding timestamp verification and simplifying the signature verification steps. After passing the attack and defense test, the documentation and interface specifications are updated simultaneously to ensure that the verification logic of the terminal and the server is consistent. The synchronization verification algorithm update cycle was adjusted, the AES-128 simplified algorithm details were modified, the key fusion method was optimized, the rules for encrypted distribution of new keys were improved, the update logic was updated after terminal verification, and a reasonable transition period was retained. After the gray-scale deployment update, first switch to a small proportion of traffic, monitor core indicators, and gradually expand to the full scale if the indicators are met; if there are any abnormalities, roll back and optimize. Record the entire process update log, establish a version rollback mechanism, quickly roll back in case of anomalies, analyze the cause and incorporate it into the next round of optimization.

5. The network security encryption authentication method based on artificial intelligence according to claim 1, characterized in that: The aforementioned training data source tracing and poisoned sample removal mechanism, combined with backdoor feature detection at the inference end and incremental model updates, defends against data poisoning and backdoor implantation threats, including: A unique traceability identifier is generated for each training sample. The joint hash value of the original sample data and the corresponding metadata is calculated by a hash algorithm. The hash value is digitally signed by an asymmetric encryption algorithm to form a traceability tag. The traceability tag is hiddenly embedded in the corresponding sample feature data and stored in conjunction with the sample features. A consortium blockchain traceability storage system is built, which puts sample traceability tags, metadata and signature information on the chain to form a chain-like immutable structure. The mapping relationship between samples and traceability identifiers is stored in an encrypted database, and multi-factor authentication control is implemented for traceability information queries. Before the training data is put into the database, multi-dimensional preprocessing and detection are performed, including label consistency verification, feature outlier detection and metadata compliance verification. Based on the detection results, suspected poisoning samples from abnormal or illegal sources are removed. During model training, the gradient contribution value and loss value of each batch of samples are monitored in real time. When a poisoning warning is triggered, the associated samples are located based on the source information. The sample features are re-verified through cluster analysis, and samples that deviate from the normal feature distribution are removed. After verifying that the feature distribution of the dataset is compliant, training continues. A backdoor feature detection unit is embedded in the AI ​​authentication model inference chain. A backdoor trigger feature library is pre-built. During inference, the feature vectors output by the intermediate layer of the model are extracted in real time and matched with the backdoor trigger feature library. At the same time, the probability distribution of the model output is monitored, and the backdoor is determined based on the matching result and the probability distribution status. When a backdoor is detected, the model authentication decision and key generation output link are immediately blocked and the current inference session is frozen. The source and transmission path of the input data that triggered the backdoor are traced back based on the source identifier. The corresponding neuron weights are isolated and a backup clean model is started to perform emergency authentication. Regularly collect biometric data from legitimate users during normal authentication scenarios and perform desensitization processing. Then, perform source tracing verification and poisoning detection on the processed data, construct a clean incremental dataset, and divide the training set and validation set proportionally while ensuring data distribution consistency. An incremental learning framework is built based on the original model. The parameters of the underlying feature extraction network are frozen. Incremental training is completed by using mini-batch gradient descent combined with regularization constraints. The backdoor removal effect is monitored in real time during training. After offline verification and low-volume online verification, the original model is replaced. Establish a full-process linkage mechanism for tracing, detection, and updating modules. Perform full-process log auditing on sample entry, poisoning detection, sample removal, model updates, and backdoor triggering events, retain historical logs and model versions, and realize attack path backtracking and optimization of detection rules and update strategies.

6. The network security encryption authentication method based on artificial intelligence according to claim 5, characterized in that: The incremental learning framework is built based on the original model, the parameters of the underlying feature extraction network are frozen, and incremental training is completed using mini-batch gradient descent combined with regularization constraints. The backdoor removal effect is monitored in real time during training. After offline and low-volume online verification, the original model is replaced. This includes: Load the trained AI certification original model, split the parameters according to the network structure, mark the bottom feature extraction network as a frozen layer and lock the parameters to not participate in gradient update, mark the top decision layer and the intermediate interaction layer as trainable layers and retain the parameter update permission, build an incremental learning framework based on the deep learning framework, reuse the feature extraction logic of the original model, only initialize the optimizer configuration of the trainable layer, and adapt the optimizer parameters. The preprocessed clean incremental dataset is aligned with the feature distribution. The difference between the feature distribution of the incremental dataset and the original training dataset is calculated and reduced by standardization transformation. The data is divided into small batches by stratified sampling to ensure that each batch of data contains samples from different scenarios and users. Sample weights are added to the incremental dataset to balance the fusion ratio of new data and knowledge from the original model. A regularization term is introduced into the loss function of the trainable layer to constrain the update magnitude of the weight parameters to prevent overfitting. An early stopping mechanism is enabled, with the authentication accuracy of normal samples on the validation set as the monitoring index. When a preset condition is triggered, the current batch training is automatically stopped and the optimal weights are backtracked. Gradient clipping is used during the training process. Incremental data is input in small batches, forward propagation is performed to calculate the model prediction results and loss values, backpropagation is used to calculate the gradient values ​​of trainable layers, parameter updates are performed only on the top decision layer and key interaction layer, the gradient values ​​of frozen layers are set to zero and do not participate in the update, the weight similarity between the current model and the original model is calculated periodically to ensure that the model's feature extraction ability does not degrade, adapt to the total number of training iterations, and balance the risk of knowledge updates and forgetting. After each round of iterative training, the model is input with a preset backdoor test set, the output features of the intermediate layers of the model are extracted and matched with the backdoor trigger feature library, the false positive pass rate of the backdoor samples is calculated, the direction of change of the weights of the trainable layers is monitored, the learning rate of the corresponding layer is adjusted when the warning condition is triggered, and the backdoor clearing threshold is set. If the threshold is not met, iterative training continues and the model is re-evaluated. After training, an offline validation dataset is built to validate the model from the dimensions of normal sample authentication accuracy, backdoor sample blocking rate, and generalization ability, to ensure that the model does not lose its original performance after incremental updates and to verify the model's inference time. After offline verification is successful, online verification is launched using a canary deployment method. Some real authentication traffic is routed to the incrementally updated model. A real-time monitoring panel is built to monitor indicators, and a monitoring period is set. When an indicator is abnormal, a traffic switching mechanism is triggered to reroute abnormal traffic back to the original model. When there are no abnormal fluctuations in the metrics during the online validation period, the traffic routing range is gradually expanded to complete the full model replacement. The updated model is version-marked, training information is recorded and stored in the model version library, the original model and intermediate model versions during the incremental update process are retained, and a fast rollback mechanism is established.

7. The network security encryption authentication method based on artificial intelligence according to claim 1, characterized in that: The method employs chaotic encryption and sharded storage, dynamic parameter updates, and query behavior fingerprint detection. By returning false results and shielding intermediate layer outputs, it prevents model theft and reverse engineering attacks, including: Using a highly random chaotic sequence generated by chaotic mapping as the encryption key, stream encryption is performed on the complete parameter matrix and network structure description file of the AI ​​authentication model. Parameter dimension obfuscation is introduced during the encryption process. The encrypted model asset is split into multiple fragments according to functional modules, and each fragment is attached with a unique check code. Different fragments are stored on different nodes of a distributed cluster. Each node deploys an independent access control policy, and only authorized nodes can obtain the corresponding fragment through multi-factor authentication. No single node stores the complete model asset. When a fragment is called, fragment decryption and splicing are completed through multi-party secure computation within the cluster. The splicing process is only temporarily executed in memory, and the complete parameters are immediately cleared after execution. A two-tiered update condition is set: scheduled updates and abnormal trigger updates. Abnormal trigger updates are triggered by query behavior fingerprint detection results or suspicious access logs. An incremental micro-update strategy is adopted, and a random perturbation matrix is ​​generated based on the original model parameters. Updates are performed only on the top-level decision layer parameters of the model, while the bottom-level feature extraction layer parameters remain stable. A dual-model parallel mechanism is enabled during the update process. After the performance of the new parameter model is verified to meet the standards through small-volume testing, seamless switching is performed. The old parameters are immediately invalidated and encrypted and archived. At the same time, a chaotic encryption key is regenerated based on the update timestamp and random number. Define a multi-dimensional query behavior fingerprint dimension that includes device fingerprint, request characteristics, query pattern, and user behavior. Construct a fingerprint baseline based on normal query behavior data. Use an anomaly detection algorithm to calculate the deviation of each query behavior from the baseline. Collect fingerprint data of query requests in real time. Determine abnormal query behavior based on the deviation of a single request or multiple deviations in a short period of time. Establish an abnormal behavior feature library to achieve accurate identification. Remove external access permissions for all intermediate layer output interfaces in the model inference chain, retain only the output channel of the final model authentication result, block the execution permissions of requests that attempt to call intermediate layer interfaces, generate pseudo results that follow the distribution characteristics of normal authentication results but have no effective business information for abnormal query requests, embed hidden abnormal markers in the pseudo results, and dynamically update the pseudo result generation logic according to a preset period. For high-frequency abnormal requests, gradually increase the request response delay while returning pseudo results. Establish a linkage mechanism for encrypted storage, parameter updates, behavior detection, and output defense modules. When an abnormal query behavior is triggered, suspend the access permissions of the corresponding terminal for model parameters, mark high-risk fragment access requests and initiate an emergency parameter update process. Log all defense behaviors throughout the process, store the logs in an encrypted manner and retain them for a preset period, periodically audit the logs and extract the characteristics of new attack behaviors, optimize the fingerprint detection baseline, pseudo result generation rules and parameter update strategies, and establish an emergency response process. When a large-scale model theft attack is detected, switch to a backup model instance, take the original model instance offline and complete a full parameter update and encryption system reconstruction.

8. The network security encryption authentication method based on artificial intelligence according to claim 1, characterized in that: The establishment of a closed-loop linkage mechanism for countering disturbances, data poisoning, and model theft protection modules, simultaneously strengthening defense strategies upon alarm, and achieving unsupervised adaptive optimization through data collection to adapt to new and unknown attacks, includes: A unified protection and linkage control center is constructed, integrating the interfaces and data channels of three protection modules: anti-disturbance, data poisoning, and model theft. An encrypted communication protocol is used to realize real-time data interaction between modules. Multi-level alarm levels are defined, and a mapping rule base for alarm types and cross-module defense actions is established to form a detection, alarm, and linkage defense trigger link. The center summarizes the defense status, attack characteristics, and processing results of each module in real time, constructs a global protection situation view, and supports cross-module correlation analysis of attack behavior. Differentiated defense enhancement measures are implemented for different alarm levels and attack types. When the anti-disturbance alarm is triggered, the detection parameters and cross-module feature push are enhanced. When the data poisoning alarm is triggered, the permissions of suspicious data are suspended and the source tracing query is initiated. When the model theft alarm is triggered, the parameter update cycle and access authentication mechanism are optimized. Attack-related information is synchronized between modules to coordinate and enhance defense. All enhancement measures are set with dynamic duration and automatically fall back to the default policy after the timeout. The system collects attack-related data from three modules in real time, forming a full attack event data packet. It performs standardization processing on the collected data, unifies the data format, extracts attack features, eliminates the differences in feature dimensions between modules through feature alignment algorithms, and generates a standardized attack dataset containing attack type, triggering conditions, feature vectors, and defense effects. It also labels unknown attack data with specific tags and stores them separately in a new attack sample pool. An unsupervised adaptive optimization engine is built based on a standardized attack dataset and a novel attack sample pool. The unclassified attack samples are clustered using a clustering algorithm to identify novel attack feature clusters and supplement them to the attack feature library of each module. The cross-module linkage triggering conditions are optimized using an anomaly pattern mining algorithm, and the defense strategy parameters are adaptively adjusted using a reinforcement learning framework. The new feature library and strategy parameters output by the optimization engine are deployed through a canary deployment mechanism. First, some business traffic is routed to the protection system equipped with the optimization strategy. The indicators are monitored in real time, and a canary verification period is set. During this period, the protection effect before and after optimization is compared. If the indicators meet the standards, the deployment scope is gradually expanded. If an anomaly occurs, the original strategy is immediately rolled back. During the verification process, the running data is collected and fed back to the optimization engine to form a closed-loop iteration. Establish a regular full-scale optimization iteration cycle. The optimization engine automatically summarizes relevant data within the cycle and re-executes the optimization process. Continuously update the attack feature library and linkage rule library. For new types of unidentified attack events, trigger an emergency optimization process, extract attack features, and quickly generate temporary defense strategies. After verification with small traffic, deploy the strategies. Regularly evaluate the linkage efficiency of the three protection modules, optimize the control center scheduling logic, and form a dynamic defense closed loop that adapts to unknown attacks.

9. The network security encryption authentication method based on artificial intelligence according to claim 8, characterized in that: The unsupervised adaptive optimization engine, built upon a standardized attack dataset and a novel attack sample pool, uses a clustering algorithm to cluster unclassified attack samples, identifies novel attack feature clusters and adds them to the attack feature libraries of each module, optimizes cross-module linkage triggering conditions using anomaly pattern mining algorithms, and adaptively adjusts defense strategy parameters using a reinforcement learning framework, including: Load the standardized attack dataset and the unclassified data from the new attack sample pool, and perform normalization, dimensionality reduction, missing value imputation and outlier filtering operations on all features in sequence to eliminate feature dimension differences, reduce computational complexity and filter invalid data, forming standardized input data for engine training. An improved clustering algorithm with adaptive density is used to perform clustering operations on unclassified attack samples. The clustering parameters are dynamically adjusted based on the local density of the data. After filtering out noisy and isolated clusters, effective feature clusters are retained. The central feature vector of each effective cluster is calculated, and new attack feature descriptors are generated by selecting feature dimensions within the cluster. The feature descriptors are mapped to the feature library of the corresponding protection module for adversarial perturbation, data poisoning, and model theft according to the attack type, and the feature library is updated. Association rule mining algorithms are used to perform pattern mining on the full attack data to uncover the correlation between different attack types; combined with anomaly detection algorithms, misjudgment cases of linkage triggering conditions are analyzed, common features are extracted to adjust the threshold of linkage conditions, and a linkage condition priority mechanism is established to sort linkage conditions according to the degree of attack harm and the strength of correlation, thereby optimizing the execution order of linkage actions. Define a reinforcement learning state space that includes attack type, alarm level, and system load multi-dimensional indicators, an action space that covers the adjustable parameters of each protection module, and a reward function that integrates attack recognition rate, legitimate business impact, and system resource consumption. Use a near-end policy optimization algorithm to train the reinforcement learning model, enable an online learning mechanism to dynamically update policy network parameters, and set parameter adjustment constraints to limit the adjustment range of defense parameters. The system integrates new attack characteristics, optimized cross-module linkage conditions, and defense parameters to generate a standardized configuration file. After encrypting the configuration file, it is pushed to three protection modules: anti-disturbance, data poisoning, and model theft. Each module verifies the legality of the configuration file, loads the corresponding configuration, and feeds back the loading result to the optimization engine. The engine records the configuration update log to form a closed loop for the implementation of optimization results.

10. A network security encryption authentication system based on artificial intelligence, characterized in that, include: processor; A machine-readable storage medium for storing machine-executable instructions of the processor; The processor is configured to execute the AI-based network security encryption authentication method according to any one of claims 1 to 9 by executing the machine-executable instructions.