A malicious domain name detection method and system based on bimodal fusion
By constructing a dual-modal fusion architecture of graph attention network and large language model, the problems of false positives and false negatives in malicious domain name detection in existing technologies are solved, and accurate detection is achieved in complex attack scenarios.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- UNIV OF JINAN
- Filing Date
- 2026-05-08
- Publication Date
- 2026-07-10
AI Technical Summary
Existing malicious domain name detection methods based on graph structure and semantic features cannot effectively detect malicious domain names that are "abnormal in topological association but normal in character features" or "abnormal in character features but lack historical association" in complex attack scenarios, resulting in false positives or false negatives and inaccurate detection.
A dual-modal fusion architecture combining graph attention networks and large language models is constructed. By building a heterogeneous information network, topological structure modality and semantic feature modality are extracted. Evidence chain backtracking and fusion are performed using multi-head graph attention networks and large language models to achieve accurate detection of malicious domain names.
It enables accurate detection of malicious domains in complex scenarios such as abnormal topological associations but normal character features and abnormal character features but lack of historical associations, avoiding false positives and false negatives and improving the accuracy of security analysis.
Smart Images

Figure CN122372310A_ABST