Method and device for generating adversarial samples, and readable storage medium

By replacing word segmentation and important words on phishing email samples to generate adversarial samples, the problem of poor application of adversarial samples in the prior art is solved, and the efficient application of adversarial samples is achieved.

CN113868365BActive Publication Date: 2025-05-16BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202111143752.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-28
Publication Date
2025-05-16
Estimated Expiration
2041-09-28

AI Technical Summary

Technical Problem

When generating adversarial samples, the prior art simply replaces the words in the phishing email, resulting in the generated adversarial samples that cannot directly reflect the attacker's attack methods and are less applicable.

Method used

By performing word segmentation on phishing email samples, important words are determined, and pictures corresponding to important words are generated to replace them, and the processed phishing email samples are generated, thereby generating an adversarial sample.

Benefits of technology

The generated adversarial samples can directly reflect the attacker's attack methods, improving the applicability and applicability of adversarial samples. For example, it can be used to train phishing email detection models to improve detection accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113868365B_ABST
    Figure CN113868365B_ABST
Patent Text Reader

Abstract

The present application provides a method and device for generating adversarial samples, and a readable storage medium. The method for generating adversarial samples includes: obtaining a phishing email sample; performing word segmentation processing on the phishing email sample to obtain multiple words corresponding to the phishing email sample; determining important words among the multiple words; generating pictures corresponding to the important words; replacing the important words in the phishing email sample according to the pictures corresponding to the important words to obtain a processed phishing email sample; generating an adversarial sample according to the processed phishing email sample. The generation method is used to improve the applicability of adversarial samples.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and more specifically, to a method and device for generating adversarial samples, and a readable storage medium. Background Art

[0002] Phishing emails are a social engineering-based intrusion method. Attackers use carefully constructed emails to induce target users to disclose sensitive information to themselves. In many network security incidents in recent years, phishing emails are often used as the starting point for intrusion into official systems. Currently, deep learning-based methods are widely used in phishing email detection. With the development of technology, the concept of adversarial samples has been proposed in recent years, that is, input samples formed by deliberately adding subtle interference to the data set.

[0003] In the prior art, when generating adversarial samples, some words in phishing emails are simply replaced. The generated adversarial samples cannot directly reflect the attacker's attack methods, making the applicability of the adversarial samples poor. Summary of the invention

[0004] The purpose of the embodiments of the present application is to provide a method and device for generating an adversarial sample, and a readable storage medium, so as to improve the applicability and applicability of the adversarial sample.

[0005] In a first aspect, an embodiment of the present application provides a method for generating an adversarial sample, comprising: obtaining a phishing email sample; performing word segmentation processing on the phishing email sample to obtain multiple words corresponding to the phishing email sample; determining important words among the multiple words; generating pictures corresponding to the important words; replacing the important words in the phishing email sample according to the pictures corresponding to the important words to obtain a processed phishing email sample; and generating an adversarial sample based on the processed phishing email sample.

[0006] In the embodiment of the present application, by analyzing the existing phishing emails, it is found that phishing emails will use pictures to replace some important words to evade the detection of phishing emails. Therefore, by determining the important words in the phishing email sample, replacing them with the pictures corresponding to the important words, and further generating corresponding adversarial samples, the generated adversarial samples can directly reflect the attacker's attack methods, improve the applicability of adversarial samples, for example: using them to train phishing email detection models can improve the detection accuracy of phishing email detection models.

[0007] As a possible implementation method, determining the important words among the multiple words includes: determining multiple candidate important words among the multiple words based on the parts of speech of the multiple words; determining the importance score of each of the candidate important words; determining the important words from the multiple candidate important words based on the importance score; the importance score of the important words meets preset conditions.

[0008] In the embodiment of the present application, a plurality of candidate important words are first determined according to the parts of speech of a plurality of words, and then the importance scores of the plurality of candidate important words are determined, and finally the important words are determined according to the importance scores, thereby achieving effective determination of the important words.

[0009] As a possible implementation method, determining the importance score of each candidate important word includes: generating a candidate important word graph based on the co-occurrence relationship between the multiple candidate important words; wherein the distance between the words with the co-occurrence relationship meets a preset condition; and determining the importance score of each candidate important word based on the candidate important word graph and the preset importance value of each candidate important word according to a preset iterative algorithm.

[0010] In the embodiment of the present application, a candidate important word graph is first generated based on the co-occurrence relationship, and then an iterative algorithm is used based on the candidate important word graph and the preset importance values ​​of each candidate important word to achieve effective and accurate determination of the importance score.

[0011] As a possible implementation, the preset iterative algorithm is expressed as: Among them, d is the preset damping coefficient, for any candidate important word in the candidate important word graph, In(Vi) is the set of candidate important words pointing to the candidate important word in the candidate important word graph, |Out(Vj)| is the number of candidate important words pointed to by the candidate important word in the candidate important word graph, WR(Vj) is the importance value of the j-th candidate important word, and its corresponding iteration initial value is the importance value preset for the j-th candidate important word; WR(Vi) is the importance score of the candidate important word after iterative calculation, and the corresponding iteration initial value is the same as WR(Vj).

[0012] In the embodiment of the present application, the importance score of each candidate important word is effectively and accurately calculated through the above-mentioned iterative algorithm.

[0013] As a possible implementation method, the generation method also includes: inputting the multiple candidate important words into a preset phishing email detection model to obtain a first detection value output by the phishing email detection model; for any one of the multiple candidate important words, inputting the multiple candidate important words after removing the candidate important word into the phishing email detection model to obtain a second detection value output by the phishing email detection model; determining an importance score influence value of the candidate important word based on the first detection value and the second detection value; and determining a final importance score of each candidate important word according to the importance score influence value of each candidate important word and the importance score of each candidate important word.

[0014] In an embodiment of the present application, the importance score influence value of the candidate important words is determined through the output results of the phishing email detection model, and then the final importance score is determined based on the importance score influence value and the importance score, thereby improving the accuracy of the final importance score.

[0015] As a possible implementation, the final importance score of each candidate important word is expressed as: Socre(x i )=DL(x i )+λWR(x i ), where WR(x i ) is the importance score of each candidate important word, DL(x i ) is the importance score influence value of each candidate important word, and λ is a preset parameter.

[0016] In the embodiment of the present application, based on the above relationship, the final importance score is effectively calculated according to the importance score and the importance score influence value.

[0017] As a possible implementation method, determining important words from the multiple candidate important words based on the importance scores includes: obtaining an index score for each of the candidate important words; the index score is used to characterize the index distance between each of the candidate important words and the candidate important word corresponding to the highest importance score; and determining important words from the multiple candidate important words based on the index score and the importance score.

[0018] In the embodiment of the present application, by calculating the index score, it is possible to more effectively determine the important words.

[0019] As a possible implementation method, generating an adversarial sample based on the processed phishing email sample includes: detecting the processed phishing email sample to determine whether the processed phishing email sample can be detected as a phishing email; if the processed phishing email sample cannot be detected as a phishing email, using the processed phishing sample email as an adversarial sample.

[0020] In an embodiment of the present application, if the processed phishing email sample can be detected as a phishing email, it means that its value as an adversarial sample is not great; if it cannot be detected as a phishing email, then its value as an adversarial sample is greater, for example: using it as a training sample for the detection model to improve the detection accuracy of the detection model; improving the applicability and applicability of the ultimately generated adversarial sample.

[0021] As a possible implementation method, the number of the important words is multiple; the important word replaced in the processed phishing email sample is the first important word among the multiple important words; the generation method also includes: if it can be detected that the processed phishing email sample is a phishing email, the second important word among the multiple important words is replaced according to the picture corresponding to the second important word to obtain a re-processed phishing email sample; and an adversarial sample is generated based on the re-processed phishing email sample.

[0022] In an embodiment of the present application, based on multiple important words, the first important word is used for replacement. If the replaced phishing email sample cannot be used as an adversarial sample, other important words are used to continue to be replaced, and adversarial samples are generated to achieve effective generation of adversarial samples.

[0023] In a second aspect, an embodiment of the present application provides an adversarial sample generation device, including: various functional modules for implementing the adversarial sample generation method described in the first aspect and any possible implementation manner of the first aspect.

[0024] In a third aspect, an embodiment of the present application provides a readable storage medium, on which a computer program is stored. When the computer program is executed by a computer, the method for generating adversarial samples as described in the first aspect and any possible implementation of the first aspect is executed. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0026] Figure 1 A flowchart of a method for generating adversarial samples provided in an embodiment of the present application;

[0027] Figure 2 An example diagram of a candidate important word diagram provided in an embodiment of the present application;

[0028] Figure 3 A schematic diagram of the structure of an adversarial sample generation device provided in an embodiment of the present application.

[0029] Icon: 300 - device for generating adversarial samples; 310 - acquisition module; 320 - processing module. DETAILED DESCRIPTION

[0030] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0031] The technical solution provided by the embodiment of the present application can be applied to various application scenarios where adversarial samples need to be generated, and the adversarial samples are adversarial samples of phishing emails. Application scenarios include, for example, application scenarios where adversarial samples are needed to train phishing email detection models; and application scenarios where security protection measures for phishing emails need to be formulated based on the analysis of adversarial samples.

[0032] Based on the above application scenarios, the hardware operating environment corresponding to the technical solution provided in the embodiments of the present application may be a server, a client, etc., which is not limited here.

[0033] Please refer to the following Figure 1 , is a flowchart of a method for generating adversarial samples provided in an embodiment of the present application, the method comprising:

[0034] Step 110: Obtain a phishing email sample.

[0035] Step 120: Perform word segmentation processing on the phishing email sample to obtain multiple words corresponding to the phishing email sample.

[0036] Step 130: Determine important words among the plurality of words.

[0037] Step 140: Generate images corresponding to important words.

[0038] Step 150: Replace the important words in the phishing email sample according to the images corresponding to the important words to obtain a processed phishing email sample.

[0039] Step 160: Generate an adversarial sample based on the processed phishing email sample.

[0040] In the embodiment of the present application, by analyzing the existing phishing emails, it is found that phishing emails will use pictures to replace some important words to evade the detection of phishing emails. Therefore, by determining the important words in the phishing email sample, replacing them with the pictures corresponding to the important words, and further generating corresponding adversarial samples, the generated adversarial samples can directly reflect the attacker's attack methods, improve the applicability of adversarial samples, for example: using them to train phishing email detection models can improve the detection accuracy of phishing email detection models.

[0041] Next, the detailed implementation of the method for generating adversarial samples is introduced.

[0042] In step 110, the phishing email sample may be an email that has been identified as a phishing email in the database. Alternatively, it may be a phishing email identified by collecting a large number of emails and then detecting these emails using a phishing email detection model. The number of phishing email samples may be one or more. If there are more than one, each phishing email sample may be processed according to the processing method of steps 120 to 160.

[0043] In an embodiment of the present application, the phishing email detection model can be an LSTM (Long Short-Term Memory) model. The LSTM model has been widely used in the detection of phishing emails. Therefore, a detailed introduction on how the model realizes the detection of phishing emails is not given here.

[0044] After obtaining the phishing email sample, in step 120, the phishing email sample is segmented to obtain a plurality of words corresponding to the phishing email sample. The segmentation process can be implemented by using mature segmentation technology, which will not be described in detail here.

[0045] For example, suppose a phishing email sample includes the text: We are reviewing your account, then the corresponding word segmentation results (that is, multiple words corresponding to the sentence segment) include: "we", "are", "review", "you", "of", and "account".

[0046] After obtaining a plurality of words corresponding to the phishing email sample, in step 130, important words among the plurality of words are determined.

[0047] As a first optional implementation, the important words among the multiple words can be words in a preset important word library. In this implementation, by analyzing a large number of phishing emails, important words used as confusing words or replacement words are determined, and an important word library is formed. When it is necessary to determine the important words, it is only necessary to match the multiple words with the words in the word library. If the corresponding words in the word library are matched, the words can be determined as important words.

[0048] As a second optional implementation, step 130 includes: determining multiple candidate important words from multiple words based on the parts of speech of multiple words; determining the importance score of each candidate important word; determining important words from multiple candidate important words based on the importance score; the importance score of the important word meets preset conditions.

[0049] Among them, the parts of speech of multiple words can be determined by a preset word library table. In the preset word library table, multiple words and parts of speech corresponding to the multiple words are included. The words whose parts of speech are to be determined are matched with the words in the word library table, and the parts of speech corresponding to the words that match the words whose parts of speech are to be determined are determined as the parts of speech of the words whose parts of speech are to be determined. The preset word library table can be an existing word library table in the prior art; it can also be a word library table obtained by customizing the existing word library table in the prior art, which is not limited in the embodiments of the present application.

[0050] Furthermore, the part of speech of the candidate important words can be a preset designated part of speech, such as noun, verb, etc., while stop words and other irrelevant parts of speech do not belong to the part of speech of the candidate important words. Based on this, each word can be screened according to the preset designated part of speech and the part of speech of each word to determine the candidate important words.

[0051] After determining multiple candidate important words, determine the importance score of each candidate important word. In the embodiment of the present application, the importance score of the candidate important words is calculated based on the TextRank method, which constructs a network through the neighbor relationship between words and then uses the constructed network to calculate the importance score.

[0052] Based on this method, as an optional implementation, the importance score of each candidate important word is determined, including: generating a candidate important word graph based on the co-occurrence relationship between multiple candidate important words; wherein the distance between words with co-occurrence relationship meets preset conditions; based on the candidate important word graph and the preset importance value of each candidate important word, determining the importance score of each candidate important word according to a preset iterative algorithm.

[0053] Among them, the preset condition can be a distance condition between words, for example: adjacent words, one word apart, two words apart, etc.

[0054] In an embodiment of the present application, the co-occurrence relationship between words is determined based on a sliding window. The length of the sliding window can be set according to the number of candidate important words and a preset word distance condition. For example, when the number of candidate important words is large and the preset word distance condition is met, the length of the sliding window can be slightly longer. When the number of candidate important words is small and the distance required by the preset word distance condition is small, the length of the sliding window can be slightly shorter.

[0055] Further, based on the sliding window, if two candidate important words co-occur in the same sliding window, the two candidate important words have a co-occurrence relationship.

[0056] As an optional implementation, the length of the sliding window is 5. In this implementation, the words included in each sliding window should be the currently targeted word and the words whose word distance from the currently targeted word is 2.

[0057] For example, let's say a sample phishing email is: We are reviewing your account. Please submit the requested information via our secure document upload page within 14 days: https: / / sdu.amazon.co.uk. If we do not receive this information within 14 days, your account may be closed. If you have any questions, you can always contact us.

[0058] Based on the above phishing email sample, assume that the word segmentation results are: ["we", "being", "reviewing", "you", "account", "please", "day", "through", "us", "security", "file", "upload", "page", "requirement", "information", "https", "sdu", "amazon", "co", "uk", "if", "we", "day", "no", "received", "information", "close", "you", "account", "question", "contact", "we"].

[0059] Assuming that the length of the sliding window is 5 and the preset condition is within an interval of 2 words, some of the sliding window results are: ["we", "currently", "reviewing", "you", "account"]; ["currently", "reviewing", "you", "account", "please"]; ["reviewing", "you", "account", "please", "day"]; and so on.

[0060] If the length of the sliding window is other lengths, and the condition for the distance between words in the co-occurrence relationship is other conditions, the co-occurrence relationship between the candidate important words can also be determined with reference to the above-mentioned exemplary implementation.

[0061] In addition to the above-mentioned sliding window implementation, in actual application, the candidate important words that have a co-occurrence relationship with each candidate important word can be directly determined according to the preset distance conditions to achieve the determination of the co-occurrence relationship; or other implementations can be used, which are not limited in the embodiments of the present application.

[0062] After determining the co-occurrence relationship of the candidate important words, the candidate important words are used as nodes, and the co-occurrence relationship between the candidate important words is used as the edge between the nodes, so that a candidate important word graph can be generated.

[0063] As an example, based on the results of the above partial sliding window, the generated candidate important word graph is as follows: Figure 2 As shown, it can be seen that corresponding connection relationships are constructed between candidate important words with co-occurrence relationships.

[0064] In the embodiment of the present application, an iterative algorithm is used to determine the importance score of each candidate important word, and the iterative algorithm usually needs to set a corresponding initial value of the iteration, so it is also necessary to preset the importance value of each candidate important word to implement the iterative algorithm. The importance value does not affect the final iteration result, so its preset value can be any initial value, for example, it can be 1.

[0065] As an optional implementation, the preset iterative algorithm is expressed as: Among them, d is the preset damping coefficient, for any candidate important word in the candidate important word graph, In(Vi) is the set of candidate important words pointing to the candidate important word in the candidate important word graph, |Out(Vj)| is the number of candidate important words pointed to by the candidate important word in the candidate important word graph, WR(Vj) is the importance value of the j-th candidate important word, and its corresponding iteration initial value is the preset importance value of the j-th candidate important word; WR(Vi) is the importance score of the candidate important word after iterative calculation, and the corresponding iteration initial value is the same as WR(Vj).

[0066] The preset damping coefficient is usually 0.85, but it may be other values, which are not limited here.

[0067] In(Vi) is a set, vi is any word in it, the initial WR(Vi) = WR(Vj) = 1 (i.e. the initial value of iteration), when i is the word to be calculated, j is a cycle, which includes i. When the right side is calculated as a whole, the WR(Vi) on the left side is an item in WR(Vj).

[0068] For example, assuming that j is 2, i is 1, |Out(V1)|=|Out(V1)|=4, then: The first calculation results: WR(V1)=0.575; Second calculation result: Iterate in this way until the change of WR(V1) is less than the threshold, which means that WR(V1) converges. The WR(V1) value at this time is the final importance score calculation result.

[0069] In the embodiment of the present application, the importance score of each candidate important word is effectively and accurately calculated through the above-mentioned iterative algorithm.

[0070] The importance score calculated in the above manner may be used as the final importance score of the candidate important word; or it may not be the final importance score.

[0071] If it is not the final importance score, as an optional implementation, the method also includes: inputting multiple candidate important words into a preset phishing email detection model to obtain a first detection value output by the phishing email detection model; for any one of the multiple candidate important words, inputting the multiple candidate important words after removing the candidate important word into the phishing email detection model to obtain a second detection value output by the phishing email detection model; determining the importance score influence value of the candidate important word based on the first detection value and the second detection value; and determining the final importance score of each candidate important word according to the importance score influence value of each candidate important word and the importance score of each candidate important word.

[0072] In an embodiment of the present application, the importance score influence value of the candidate important words is determined through the output results of the phishing email detection model, and then the final importance score is determined based on the importance score influence value and the importance score, thereby improving the accuracy of the final importance score.

[0073] The preset phishing email detection model may be the LSTM model introduced in the above embodiment. Based on the word set corresponding to the candidate important words, for each candidate important word, the set containing the candidate important word is input into the phishing email detection model to obtain a detection value; and then the set without the candidate important word is input into the phishing email detection model to obtain a detection value.

[0074] In the embodiment of the present application, the importance score impact value may be the difference between the first detection value and the second detection value.

[0075] As an optional implementation, the final importance score of each candidate important word is expressed as: Socre(xi)=DL(xi)+λWR(xi), wherein WR(xi) is the importance score of each candidate important word, DL(xi) is the influence value of the importance score of each candidate important word, and λ is a preset parameter.

[0076] Among them, λ can be understood as a hyperparameter, and its value can be any value between 0 and 1, which is not limited here.

[0077] In an embodiment of the present application, the importance score of an important word should meet preset conditions, for example: the importance score is greater than a preset value, or the importance score ranks in the top few, etc. Therefore, candidate important words with an importance score greater than a preset value or an importance score ranking in the top can be determined as important words.

[0078] However, different candidate important words may have the same importance scores. In this case, if the important words are determined simply by using the importance scores, the result may not be very accurate.

[0079] In order to avoid the influence of the same importance score on the final result, in the embodiment of the present application, the index score of each candidate important word can also be introduced.

[0080] As an optional implementation, important words are determined from multiple candidate important words based on importance scores, including: obtaining an index score for each candidate important word; the index score is used to characterize the index distance between each candidate important word and the candidate important word corresponding to the highest importance score; and important words are determined from multiple candidate important words based on the index score and the importance score.

[0081] The index score of the candidate important word may be the index distance between the candidate important word and the candidate important word corresponding to the highest importance score, wherein the index distance is the distance between the index positions of the words.

[0082] Specifically, all candidate important words are sorted, and the index position of each word is D = [d1, d2, d3, ... d n ], the index score of the i-th word is recorded as Scored(i). When there are multiple indexes for a word, the minimum score is selected as the index score, so: Scored(i) = (d i -d(Score max )) min .

[0083] Among them, a multi-word index means that the same candidate important word has different index positions. For example, the word "I" has two positions, position 1 (d1) and position 3 (d3), which is a multi-word index.

[0084] For example, assuming that the second candidate important word (i.e., index position is 2) has other candidate important words with the same importance score, and among the multiple candidate important words with the same importance score, the candidate important word with the highest importance score is the fifth candidate important word (i.e., index position is 5), and the second candidate important word does not have multiple indexes, then the index score of the second candidate important word is 3. If the candidate important word has multiple indexes, the distance between each index position and the fifth candidate important word is calculated, and then the minimum distance is used as the index score of the second candidate important word.

[0085] Based on the index scores of the candidate important words, when determining the important words, if the candidate important words need to be sorted, the candidate important words with the same importance score are sorted in order from low to high according to the index scores.

[0086] In the embodiment of the present application, by calculating the index score, it is possible to more effectively determine the important words.

[0087] It can be understood that the number of important words finally determined in step 130 is usually multiple.

[0088] In step 140 , corresponding images may be generated based only on the important words that currently need to be replaced, or corresponding images may be generated based on all important words, so as to facilitate subsequent applications.

[0089] As an optional implementation, in step 140, the pygame library of python can be used to generate images corresponding to important words, and adjust the size, font, color, etc.

[0090] Furthermore, in step 150, the important words with the highest importance score may be replaced first, and then it is determined whether other important words need to be used for replacement according to the replacement result.

[0091] In an embodiment of the present application, a maximum number of replacements can be preset, and the maximum number of replacements is used to limit the maximum number of replacements that can be performed on the phishing email sample (i.e., the number of important words that can be replaced). For example, assuming the maximum number of replacements is 3, only three important words can be replaced.

[0092] Whether the replacement result meets the requirements can be achieved by testing the processed phishing email samples.

[0093] As an optional implementation, step 160 includes: detecting the processed phishing email sample to determine whether the processed phishing email sample can be detected as a phishing email; if the processed phishing email sample cannot be detected as a phishing email, using the processed phishing sample email as an adversarial sample.

[0094] Among them, detecting whether a phishing email sample is a phishing email can be achieved by using the LSTM model introduced in the aforementioned embodiment.

[0095] In this implementation, if the processed phishing email sample can be detected as a phishing email, it means that its value as an adversarial sample is not great; if it cannot be detected as a phishing email, then its value as an adversarial sample is greater, for example: using it as a training sample for the detection model to improve the detection accuracy of the detection model; improving the applicability and applicability of the ultimately generated adversarial sample.

[0096] If the processed phishing email sample can be detected as a phishing email, it means that the replacement is invalid. You can continue to replace it. Assuming that the first important word is replaced, you can replace the second important word that is different from the first important word. For example, the first important word is the important word with the highest importance score, and the second important word is the important word with the second highest importance score.

[0097] Therefore, as an optional implementation, if it can be detected that the processed phishing email sample is a phishing email, the second important word among multiple important words is replaced according to the picture corresponding to the second important word to obtain a re-processed phishing email sample; and an adversarial sample is generated based on the re-processed phishing email sample.

[0098] The implementation method of generating adversarial samples based on the reprocessed phishing email samples is the same as that introduced in the aforementioned embodiment, except that if the number of important word replacements corresponding to the phishing email sample is greater than the preset number of replacements, and the phishing email sample can still be detected as a phishing email, then the phishing email sample will not be used as an adversarial sample, and other phishing email samples can continue to be processed.

[0099] In an embodiment of the present application, based on multiple important words, the first important word is used for replacement. If the replaced phishing email sample cannot be used as an adversarial sample, other important words are used to continue to be replaced, and adversarial samples are generated to achieve effective generation of adversarial samples.

[0100] The adversarial samples generated in step 160 can have a variety of applications. As an optional application method, the adversarial samples are used together with other existing training samples as a training data set for a phishing email detection model to train the phishing email detection model. The trained phishing email detection model can identify phishing emails that are obtained by replacing important words with pictures, thereby improving the accuracy of the phishing email detection model.

[0101] As another optional application method, the adversarial sample can also be analyzed to develop security protection measures for phishing emails corresponding to the adversarial sample. For example, when a phishing email identical to the adversarial sample is detected, it is immediately blocked, and all emails from the corresponding sender are blocked to improve security.

[0102] Alternatively, adversarial samples may also have other applications, which are only introduced as examples in the embodiments of the present application and do not constitute a limitation on their application methods.

[0103] Based on the same invention concept, please refer to Figure 3 In an embodiment of the present application, a device 300 for generating an adversarial sample is also provided, including: an acquisition module 310 and a processing module 320.

[0104] The acquisition module 310 is used to: acquire a phishing email sample. The processing module 320 is used to: perform word segmentation processing on the phishing email sample to obtain multiple words corresponding to the phishing email sample; determine important words among the multiple words; generate pictures corresponding to the important words; replace the important words in the phishing email sample according to the pictures corresponding to the important words to obtain a processed phishing email sample; and generate an adversarial sample according to the processed phishing email sample.

[0105] In an embodiment of the present application, the processing module 320 is specifically used to: determine multiple candidate important words among the multiple words according to the parts of speech of the multiple words; determine the importance score of each of the candidate important words; determine important words from the multiple candidate important words according to the importance scores; the importance scores of the important words meet preset conditions.

[0106] In an embodiment of the present application, the processing module 320 is specifically used to: generate a candidate important word graph based on the co-occurrence relationship between the multiple candidate important words; wherein the distance between the words with a co-occurrence relationship meets a preset condition; based on the candidate important word graph and the preset importance values ​​of each candidate important word, determine the importance score of each candidate important word according to a preset iterative algorithm.

[0107] In an embodiment of the present application, the processing module 320 is also used to: input the multiple candidate important words into a preset phishing email detection model to obtain a first detection value output by the phishing email detection model; for any one of the multiple candidate important words, input the multiple candidate important words after removing the candidate important word into the phishing email detection model to obtain a second detection value output by the phishing email detection model; determine the importance score influence value of the candidate important word based on the first detection value and the second detection value; and determine the final importance score of each candidate important word according to the importance score influence value of each candidate important word and the importance score of each candidate important word.

[0108] In an embodiment of the present application, the processing module 320 is specifically used to: obtain the index score of each candidate important word; the index score is used to characterize the index distance between each candidate important word and the candidate important word corresponding to the highest importance score; and determine the important words from the multiple candidate important words based on the index score and the importance score.

[0109] In an embodiment of the present application, the processing module 320 is specifically used to: detect the processed phishing email sample to determine whether the processed phishing email sample can be detected as a phishing email; if the processed phishing email sample cannot be detected as a phishing email, use the processed phishing sample email as an adversarial sample.

[0110] In an embodiment of the present application, the processing module 320 is also used for: if it can be detected that the processed phishing email sample is a phishing email, replacing the second important word among the multiple important words according to the picture corresponding to the second important word to obtain a re-processed phishing email sample; and generating an adversarial sample based on the re-processed phishing email sample.

[0111] The adversarial sample generation device 300 corresponds to the adversarial sample generation method, and each functional module corresponds to each step of the adversarial sample generation method. Therefore, the implementation method of each functional module refers to the implementation method of each step and will not be repeated here.

[0112] Based on the same inventive concept, an embodiment of the present application further provides a readable storage medium, on which a computer program is stored. When the computer program is run by a computer, the method for generating adversarial samples introduced in the aforementioned embodiment is executed.

[0113] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, and the indirect coupling or communication connection of the devices or units can be electrical, mechanical or other forms.

[0114] In addition, the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0115] Furthermore, the functional modules in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.

[0116] In this document, relational terms such as first and second, etc. are used merely to distinguish one entity or operation from another entity or operation, but do not necessarily require or imply any such actual relationship or order between these entities or operations.

[0117] The above description is only an embodiment of the present application and is not intended to limit the protection scope of the present application. For those skilled in the art, the present application may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A method for generating adversarial samples, characterized in that: include: Get a sample of the phishing email; Performing word segmentation processing on the phishing email sample to obtain multiple words corresponding to the phishing email sample; determining important words among the plurality of words; Generate pictures corresponding to the important words; Replacing the important words in the phishing email sample according to the pictures corresponding to the important words to obtain a processed phishing email sample; Generate an adversarial sample based on the processed phishing email sample; Generating an adversarial sample according to the processed phishing email sample includes: Detecting the processed phishing email sample to determine whether the processed phishing email sample can be detected as a phishing email; if the processed phishing email sample cannot be detected as a phishing email, using the processed phishing sample email as an adversarial sample; The number of the important words is multiple; the important word replaced in the processed phishing email sample is the first important word among the multiple important words; the generation method further includes: if it can be detected that the processed phishing email sample is a phishing email, the second important word is replaced according to the picture corresponding to the second important word among the multiple important words to obtain a re-processed phishing email sample; and an adversarial sample is generated according to the re-processed phishing email sample; The first important word is an important word with the highest importance score, and the second important word is an important word with the second highest importance score; Determining the important words among the plurality of words includes: Determine a plurality of candidate important words among the plurality of words according to the parts of speech of the plurality of words; Determining the importance score of each of the candidate important words; Determine an important word from the plurality of candidate important words according to the importance score; the importance score of the important word meets a preset condition; Determining an important word from the plurality of candidate important words according to the importance score includes: Obtaining an index score for each candidate important word; the index score is used to represent the index distance between each candidate important word and the candidate important word corresponding to the highest importance score; determining an important word from the plurality of candidate important words according to the index score and the importance score; When the candidate important word has multiple index scores, the minimum index score is used as the index score of the candidate important word; For candidate important words with the same importance score, they are sorted in order from low to high according to their index scores.

2. The generation method according to claim 1, characterized in that: Determining the importance score of each candidate important word includes: Generate a candidate important word graph according to the co-occurrence relationship between the plurality of candidate important words; wherein the distance between the words having the co-occurrence relationship meets a preset condition; Based on the candidate important word map and the preset importance value of each candidate important word, the importance score of each candidate important word is determined according to a preset iterative algorithm.

3. The generation method according to claim 2, characterized in that: The preset iterative algorithm is expressed as: ; Wherein, d is the preset damping coefficient. For any candidate important word in the candidate important word graph, is the set of candidate important words pointing to the candidate important word in the candidate important word graph, |Out(Vj)| is the number of candidate important words pointed to by the candidate important word in the candidate important word graph, is the importance value of the j-th candidate important word, and its corresponding iteration initial value is the importance value preset for the j-th candidate important word; is the importance score of the candidate important word after iterative calculation, and the corresponding initial value of the iteration is same.

4. The generation method according to claim 2, characterized in that: The generating method further comprises: Inputting the plurality of candidate important words into a preset phishing email detection model to obtain a first detection value output by the phishing email detection model; For any one of the plurality of candidate important words, the plurality of candidate important words after the candidate important word is removed are input into the phishing email detection model to obtain a second detection value output by the phishing email detection model; and the importance score influence value of the candidate important word is determined based on the first detection value and the second detection value; The final importance score of each candidate important word is determined according to the importance score influence value of each candidate important word and the importance score of each candidate important word.

5. The generation method according to claim 4, characterized in that: The final importance score of each candidate important word is expressed as: Socre(x i ) = DL(x i ) +λWR(x i ), where WR(x i ) is the importance score of each candidate important word, DL(x i ) is the importance score influence value of each candidate important word, and λ is a preset parameter.

6. A device for generating adversarial samples, characterized in that: include: Acquisition module, used to obtain phishing email samples; Processing modules for: Performing word segmentation processing on the phishing email sample to obtain multiple words corresponding to the phishing email sample; determining important words among the plurality of words; Generate pictures corresponding to the important words; Replacing the important words in the phishing email sample according to the pictures corresponding to the important words to obtain a processed phishing email sample; Generate an adversarial sample based on the processed phishing email sample; Generating an adversarial sample according to the processed phishing email sample includes: Detecting the processed phishing email sample to determine whether the processed phishing email sample can be detected as a phishing email; if the processed phishing email sample cannot be detected as a phishing email, using the processed phishing sample email as an adversarial sample; The number of the important words is multiple; the important word replaced in the processed phishing email sample is the first important word among the multiple important words; if it can be detected that the processed phishing email sample is a phishing email, the second important word among the multiple important words is replaced according to the picture corresponding to the second important word to obtain a re-processed phishing email sample; and an adversarial sample is generated according to the re-processed phishing email sample; The first important word is an important word with the highest importance score, and the second important word is an important word with the second highest importance score; Determining the important words among the plurality of words includes: Determine a plurality of candidate important words among the plurality of words according to the parts of speech of the plurality of words; Determining the importance score of each of the candidate important words; Determine an important word from the plurality of candidate important words according to the importance score; the importance score of the important word meets a preset condition; Determining an important word from the plurality of candidate important words according to the importance score includes: Obtaining an index score for each candidate important word; the index score is used to represent the index distance between each candidate important word and the candidate important word corresponding to the highest importance score; determining an important word from the plurality of candidate important words according to the index score and the importance score; When the candidate important word has multiple index scores, the minimum index score is used as the index score of the candidate important word; For candidate important words with the same importance score, they are sorted in order from low to high according to their index scores.

7. A readable storage medium, characterized in that: The readable storage medium stores a computer program, and when the computer program is executed by a computer, the method for generating an adversarial sample according to any one of claims 1 to 5 is executed.

Citation Information

Patent Citations

  • Recommendation method and device of media content, storage medium, and electronic device

    CN108829822A

  • Novel network media platform variant comment adversarial text generation method

    CN113282746A

  • Method and device for improving reaching rate of short message based on classification simulation model

    CN113434691A