A Malicious Entity Detection Method Based on an Intelligent Multi-Task Learning System

Through the intelligent multi-task learning system combined with multiple models and hyperparameter adaptive optimization, the problem of insufficient efficiency and accuracy of existing malicious entity detection methods is solved, and more efficient and accurate malicious entity detection is achieved.

CN119004460BActive Publication Date: 2025-07-01BEIJING TECH & BUSINESS UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410931075.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-11
Publication Date
2025-07-01
Estimated Expiration
2044-07-11

AI Technical Summary

Technical Problem

Existing malicious entity detection methods rely on a single model or manually adjusting hyperparameters, making it difficult to adapt to different data distribution and task requirements, and lack effective utilization of correlations between different tasks, resulting in inefficiency and insufficient accuracy.

Method used

An intelligent multi-task learning system is adopted, combining keyword matching, naive Bayesian classification and BERT classification model, and a hyperparameter adaptive optimizer is introduced to dynamically adjust the learning rate and task weights, and the integration and optimization of the model is achieved through a multi-task learning framework.

Benefits of technology

It improves the accuracy and robustness of malicious entity detection, reduces the cost of manual parameter adjustment, enhances the generalization ability and adaptability of the model, and provides flexible detection result output.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119004460B_ABST
    Figure CN119004460B_ABST
Patent Text Reader

Abstract

The present invention discloses a malicious entity detection method based on an intelligent multi-task learning system, which relates to the field of network and information security technology, and includes Step 1: data collection and preprocessing; Step 2: construction and training of a multi-task learning model; Step 3: design and tuning of a hyperparameter adaptive optimizer; Step 4: dynamic task management mechanism; Step 5: model integration and performance evaluation; Step 6: output of malicious entity detection results. Compared with traditional single-task models or manual parameter tuning methods, the present invention can not only effectively identify diverse malicious entity remarks, but also automatically optimize the model hyperparameters, reduce the manual parameter tuning cost, and improve the robustness and applicability of the model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network and information security, and particularly relates to a malicious entity detection method based on an intelligent multi-task learning system. Background Art

[0002] With the rapid development and popularization of the Internet, social media platforms have become important channels for people to obtain information, communicate, and express their opinions. However, along with the convenience they bring, there is the abuse and malicious manipulation of online speech, including false information, malicious attacks, and cyber warfare. These adverse remarks not only disrupt the network order but also have an impact on individuals, organizations, and society.

[0003] Traditional malicious entity detection methods often rely on manual analysis and judgment, with low efficiency and difficulty in meeting the real-time detection requirements of large-scale information. In recent years, intelligent malicious entity detection methods based on machine learning and deep learning have emerged, such as using technical means like natural language processing, pattern recognition, and deep neural networks to achieve the identification and filtering of false information and malicious attacks in online speech. However, existing malicious entity detection methods still face some challenges, such as the complex process of model training and optimization, difficult selection of hyperparameters, insufficient information sharing between different tasks, etc. And traditional methods often use a single model or manually adjust hyperparameters for malicious entity speech detection, lacking effective utilization of the correlation between different tasks, and hyperparameter adjustment usually relies on expert experience or static settings, making it difficult to adapt to different data distributions and task requirements.

[0004] Therefore, the present invention proposes a method for malicious entity speech detection using an intelligent multi-task learning system. Through the collaborative action of multi-task models, it improves the accuracy, efficiency, and robustness of identification, and protects the security and stability of the cyberspace. Summary of the Invention

[0005] Aiming at the defects and problems of traditional malicious entity detection methods that use a single model or manually adjust hyperparameters for malicious entity speech detection, lack effective utilization of the correlation between different tasks, and hyperparameter adjustment usually relies on expert experience or static settings, making it difficult to adapt to different data distributions and task requirements, the present invention provides a malicious entity detection method based on an intelligent multi-task learning system. The present invention realizes the effective integration and dynamic tuning of multiple task models by introducing a multi-task learning framework and a hyperparameter adaptive optimizer, improving the accuracy, robustness, and generalization ability of the malicious entity detection system.

[0006] The solution adopted by the present invention to solve its technical problems is: a malicious entity detection method based on an intelligent multi-task learning system, including the following steps:

[0007] Step 1: Collect the original text data related to malicious entity remarks from different platforms, and preprocess the original text data to ensure the quality and applicability of the data;

[0008] Step 2: Based on the preprocessed data above, construct a multi-task learning model. The multi-task learning model includes a keyword matching model, a Naive Bayes classification model, and a BERT classification model, and train the multi-task learning model by constructing a training set;

[0009] Step 3: Design a hyperparameter adaptive optimizer to dynamically adjust the learning rate, batch size, and regularization parameter according to the performance of the multi-task learning model on the validation set;

[0010] Step 4: Introduce a dynamic task management mechanism into the multi-task learning model to dynamically adjust the weights of different tasks according to the importance of the tasks, so as to optimize the effect of the model in the multi-task learning process;

[0011] Step 5: Integrate the trained multi-task learning model and the optimized hyperparameter adaptive optimizer to form a complete intelligent multi-task learning system; and use the validation set to verify the model of the intelligent multi-task learning system;

[0012] Step 6: Input the text data to be detected into the intelligent multi-task learning system constructed above to obtain the detection results. The detection results include the classification label and confidence score of the malicious entity remarks.

[0013] Further, in the preprocessing operation of the data collected in Step 1, first is text cleaning, removing HTML tags, special characters, and emojis in the text to retain the basic content of the text; next is tokenization, decomposing the text into a sequence of words or phrases; then is feature extraction, converting the text data into vector form.

[0014] Further, the multi-task learning model in Step 2 is implemented using a neural network structure. The neural network includes multiple specific functional layers, and each layer is optimized for different aspects of the overall task, so as to achieve effective data processing and learning, including:

[0015] 1) Input layer; used to receive the original text data or feature representation as input; for the keyword matching task, the input can be the original text data containing text information; for the Naive Bayes classification and BERT classification tasks, the input can be the text representation after preprocessing and feature extraction;

[0016] 2) Embedding layer; It converts text data into a dense vector representation. For the keyword matching task, the pre-trained word vector model Word2Vec is used to convert the text into word embedding vectors; The output of the embedding layer is expressed as:

[0017] e i = Embedding(w i )

[0018] For the Naive Bayes classification and BERT classification tasks, the pre-trained BERT model is used to encode and perform representation learning on the text;

[0019] 3) Multi-layer neural network; It includes multiple hidden layers, which are used to learn the high-level representation of the input data. Each hidden layer can adopt different activation functions and the number of neurons to adapt to the characteristics of different tasks and data distributions; For the hidden layer l, its output can be expressed as:

[0020] h (l+1) = f(W l h l + b l )

[0021] where h (l) is the output of the l-th layer, W (l) and b l are the weight matrix and bias vector of this layer respectively, and f is the activation function;

[0022] 4) Task-specific layer; For the keyword matching, Naive Bayes classification and BERT classification tasks, corresponding task-specific layers are added at the output end of the neural network; For the keyword matching task, an output layer using the sigmoid activation function is used to predict whether the text contains a specific keyword; For the classification task, an output layer using the softmax activation function is used to predict the probability distribution of the text belonging to different categories; For the output layer of the keyword matching task, the formula is:

[0023]

[0024] where σ is the sigmoid activation function.

[0025] For the output layer of the classification task, it can be expressed as:

[0026] p = softmax(Wh + b)

[0027] where the softmax function converts the output of the neural network into a probability distribution.

[0028] 5) Loss function; for different tasks, different loss functions are selected for optimization. Among them, the binary cross-entropy loss function is used for the keyword matching task, and the multi-class cross-entropy loss function is used for the classification task; for the keyword matching task, the binary cross-entropy loss function is expressed as:

[0029]

[0030] For the classification task, the multi-class cross-entropy loss function is expressed as:

[0031]

[0032] where y c is the one-hot encoding of the true label, and p c is the predicted probability of the corresponding class;

[0033] 6) Optimizer; an optimization algorithm is used to adjust the network parameters to minimize the loss function; within the framework of the hyperparameter adaptive optimizer, the learning rate and other hyperparameters are dynamically adjusted according to the performance of the model on the validation set to improve the training effect and generalization ability of the model;

[0034] 7) Regularization: Regularization techniques are introduced to prevent the model from overfitting. By integrating the keyword matching, Naive Bayes classification, and BERT classification tasks into a multi-task learning model, the system can simultaneously learn the correlations and shared information between different tasks, improving the overall performance and efficiency of the model.

[0035] Furthermore, the hyperparameter adaptive optimizer in step three dynamically adjusts the learning rate, batch size, and regularization parameter, including the following:

[0036] 1) Regarding the dynamic adjustment of the learning rate, the following calculation formula is followed:

[0037]

[0038] η t represents the current learning rate, γ is a decay factor less than 1, and 1(condition) is an indicator function that takes the value of 1 when the loss increases and 0 otherwise;

[0039] 2) Regarding the adjustment of the batch size, the following calculation formula is followed:

[0040]

[0041] acc t is the accuracy at time t. This formula indicates that if the accuracy of the model improves, the batch size will increase to accelerate the training process; if the accuracy does not improve, the batch size remains unchanged;

[0042] 3) Regarding the adjustment of the regularization parameter, the following calculation formula is followed:

[0043] λ t+1 = λ t *(1 - δ * 1(acc t+1 < acc t ))

[0044] where λ t is the current regularization parameter, and δ is a small positive value used to increase the regularization strength when the performance drops to prevent overfitting.

[0045] Furthermore, the importance of the tasks in step four is determined according to their performance on the validation set, and the task weight update formula is as follows:

[0046]

[0047] In the above formula, w i is the weight of task i, σ i is the performance metric of task i on the validation set, including accuracy and F1 score, and β is a hyperparameter that controls the speed of weight adjustment;

[0048] Then these weights are used for weighted task loss, and the weighted task loss formula is as follows:

[0049]

[0050] In the above formula, L total is the weighted total loss, N is the number of tasks, and L i is the loss of task i.

[0051] Furthermore, in step six, the detection results are sorted or filtered according to the confidence score; by using the confidence score as a reference standard, the detection results with higher confidence are presented or selected first to improve the credibility and practicality of the results; it is also possible to filter the confidence score by setting a threshold to exclude the detection results with lower confidence, reduce the false alarm rate, and improve the user experience.

[0052] Compared with the prior art, the beneficial effects of the present invention are:

[0053] A malicious entity detection method based on an intelligent multi-task learning system provided by the present invention uses a multi-task learning framework and combines various task models such as keyword matching, Naive Bayes classification, and BERT classification to achieve efficient detection of malicious entity speech. The method of the present invention can more effectively detect malicious entity speech, make up for the limitations of previous single models or tasks, and improve the detection accuracy and robustness. Specifically, it includes the following advantages:

[0054] 1. Comprehensive performance improvement: By introducing a multi-task learning framework, the present invention can simultaneously handle multiple tasks such as keyword matching, Naive Bayes classification, and BERT classification, thereby achieving a significant improvement in comprehensive performance.

[0055] 2. Hyperparameter adaptive optimization: An hyperparameter adaptive optimizer is introduced to dynamically adjust the learning rate, batch size, and regularization parameters according to the actual performance of the model on the validation set, improving the generalization ability and robustness of the model, and reducing the manual cost and difficulty of hyperparameter tuning.

[0056] 3. Dynamic task management mechanism: Through a dynamic task attention mechanism, the weights of different tasks are dynamically adjusted according to the importance of the tasks, effectively improving the adaptability of the model to different tasks and making the model more intelligent and flexible.

[0057] 4. Classification label and confidence score output: Classification labels and confidence scores are output in the detection results, which can provide users with a more intuitive and accurate judgment of malicious entity remarks, improving the interpretability and credibility of the detection results.

[0058] Based on the multi-task learning system described in the present invention, the detection of malicious entities can be realized, which can greatly improve the efficiency and accuracy of malicious entity detection. At the same time, it also provides users with a flexible management and response mechanism, contributing to the construction of a safer and healthier network environment, and having important application value and broad development prospects for malicious entity detection. Brief Description of the Drawings

[0059] Figure 1 It is a schematic diagram of the overall process of the detection method of the present invention;

[0060] Figure 2 It is a schematic diagram of the construction and training of the multi-task learning model of the present invention;

[0061] Figure 3 It is a schematic diagram of the hyperparameter automatic tuning process of the present invention;

[0062] Figure 4 It is a schematic diagram of the adjustment process of the dynamic task management mechanism of the present invention;

[0063] Figure 5 It is a schematic diagram of the loss function and accuracy on the training set and validation set of the present invention;

[0064] Figure 6 It is a schematic diagram of the performance indicators of the test set of the present invention on the model. Detailed Embodiments

[0065] The present invention will be further described below in conjunction with the drawings and embodiments.

[0066] Embodiment 1:

[0067] This embodiment provides a malicious entity detection method based on an intelligent multi-task learning system. As Figures 1-6 shown, by introducing a multi-task learning framework and a hyperparameter adaptive optimizer, the effective integration and dynamic tuning of multiple task models are achieved, improving the accuracy, robustness, and generalization ability of the multi-task learning model. The specific steps are as follows:

[0068] 1. Data collection and preprocessing

[0069] First, collect text data related to malicious entity remarks from online social platforms. In this embodiment, malicious entity data information is collected from four platforms: Kuaishou, Douyin, Xiaohongshu, and Weibo, including comments, posts, video titles, and descriptions. Then, perform preprocessing operations on the collected data. First is text cleaning, mainly removing HTML tags, special characters, emojis, etc. from the text to retain the basic content of the text. Next, perform word segmentation operations to decompose the text into a sequence of words or phrases for subsequent processing. Then, perform feature extraction to convert the text data into a feature representation form that can be understood and processed by a computer. The feature extraction methods used in this embodiment include the bag-of-words model, TF-IDF, word embedding, etc. The purpose of feature extraction is to convert the text data into a vector form for subsequent model training and processing.

[0070] The above entire data processing process takes into account the quality and applicability of the data, and can select appropriate data preprocessing methods according to different task requirements to ensure that the subsequent model training and performance can achieve the expected effect.

[0071] 2. Construction and training of the multi-task learning model

[0072] Use the data collected and processed above to construct a multi-task learning model. The multi-task learning model includes a keyword matching model, a Naive Bayes classification model, and a BERT classification model. The specific process is as Figure 2 shown,

[0073] First, define multi - tasks, including keyword matching tasks, Naive Bayes classification tasks, and BERT classification tasks. These tasks will go through a shared layer, then be connected to a fully - connected layer, and finally the output is the [CLS] token. During the construction of the shared model, BERT is used as the shared model to process long texts, learn semantic relationships in the texts, and provide support for downstream tasks. Finally, multi - task training is carried out, including gradient normalization, parameter sharing, and joint optimization. Gradient normalization is used to normalize the gradients of each task to ensure that they are on the same scale, which helps prevent unbalanced learning caused by some task weights being too large; parameter sharing means sharing some network parameters between different tasks, which can utilize the similarities between different tasks and improve the generalization ability of the model; and through joint optimization, the loss functions of all tasks can be combined into a total loss function, and then the shared network parameters are updated through backpropagation while considering the specific objectives of each task. For each task, the system selects an appropriate model structure and algorithm, and conducts model training and optimization to improve the accuracy and efficiency of the model in the malicious entity detection task.

[0074] Furthermore, the multi - task learning model is implemented using a neural network structure, which is used to simultaneously execute multiple task models such as keyword matching, Naive Bayes classification, and BERT classification to detect malicious entity remarks.

[0075] This neural network includes multiple specific functional layers, and each layer is optimized for different aspects of the overall task to achieve effective data processing and learning. Specifically, it includes:

[0076] 1) Input layer; used to receive the original text data or feature representation as input. For the keyword matching task, the input can be the original text data containing text information; for the Naive Bayes classification and BERT classification tasks, the input can be the text representation after pre - processing and feature extraction.

[0077] 2) Embedding layer; converts the text data into a dense vector representation so that the neural network can process it. For the keyword matching task, the pre - trained word vector model Word2Vec is used to convert the text into word embedding vectors; the output of the embedding layer is represented as:

[0078] e i =Embedding(w i )

[0079] For the Naive Bayes classification and BERT classification tasks, the pre - trained BERT model is used to encode and represent the text for learning.

[0080] 3) Multi-layer neural network; including multiple hidden layers for learning high-level representations of input data. Each hidden layer can adopt different activation functions and numbers of neurons to adapt to the characteristics of different tasks and data distributions. For the hidden layer l, its output can be expressed as:

[0081] h (l+1) =f(W l h l +b l )

[0082] where h (l) is the output of the l-th layer, W (l) and b l are the weight matrix and bias vector of this layer respectively, and f is the activation function.

[0083] 4) Task-specific layer; For tasks such as keyword matching, Naive Bayes classification, and BERT classification, the system adds corresponding task-specific layers at the output end of the neural network. For the keyword matching task, an output layer using the sigmoid activation function is used to predict whether the text contains a specific keyword; for the classification task, an output layer using the softmax activation function is used to predict the probability distribution of the text belonging to different classes. For the output layer of the keyword matching task, the formula is:

[0084]

[0085] where σ is the sigmoid activation function.

[0086] For the output layer of the classification task, it can be expressed as:

[0087] p = softmax(Wh + b)

[0088] where the softmax function converts the output of the neural network into a probability distribution.

[0089] 5) Loss function; For different tasks, different loss functions are adaptively selected for optimization. For example, the binary cross-entropy loss function is used for the keyword matching task, and the multi-class cross-entropy loss function is used for the classification task. For the keyword matching task, the binary cross-entropy loss function is expressed as:

[0090]

[0091] For the classification task, the multi-class cross-entropy loss function is expressed as:

[0092]

[0093] where y c is the one-hot encoding of the true label, p cis the predicted probability of the corresponding category.

[0094] 6) Optimizer; Use optimization algorithms to adjust network parameters to minimize the loss function. Under the framework of the hyperparameter adaptive optimizer, dynamically adjust the learning rate and other hyperparameters according to the performance of the model on the validation set to improve the training effect and generalization ability of the model.

[0095] 7) Regularization: Introduce regularization techniques such as L2 regularization and dropout to prevent the model from overfitting, which helps to improve the generalization ability and stability of the model. By integrating keyword matching, Naive Bayes classification, and BERT classification tasks into a multi-task learning model, the system can simultaneously learn the correlations and shared information between different tasks, improving the overall performance and efficiency of the model.

[0096] The above keyword matching task model, Naive Bayes classification task model, and BERT classification task model share some parameters. That is, at certain layers or certain parameters of the model, these task models can share the same weights or representations, thus reducing the number of model parameters and enabling better utilization of data information to improve the performance of the model. The following is the specific implementation of parameter sharing:

[0097] 1) Embedding layer parameter sharing: Different tasks may have the same word vector embedding layer. Especially for keyword matching tasks and text classification tasks, they usually need to perform similar word vector representations on the text.

[0098] 2) Feature extraction layer parameter sharing: For Naive Bayes classification tasks and BERT classification tasks, they may share some parameters of convolutional layers or attention mechanisms to better extract text features.

[0099] Through parameter sharing, the number of model parameters can be reduced, thereby reducing the complexity of the model and the risk of overfitting. At the same time, parameter sharing can also make the information sharing between different tasks more sufficient, improving the generalization ability and overall performance of the model.

[0100] 3. Design and Tuning of Hyperparameter Adaptive Optimizer

[0101] The multi-task learning system is designed with a hyperparameter adaptive optimizer, which dynamically adjusts the learning rate, batch size, and regularization parameters according to the performance of the multi-task learning model on the validation set. See Figure 3 ,

[0102] First, compile the multi-task learning model constructed above. Then, define some callback functions for the model and instantiate these callback functions for use in actual training. Before starting the formal training, the validation set can be used to evaluate the performance of the model. By calculating the accuracy on the validation set, the quality of the model can be initially understood. According to the results of the validation set accuracy, the hyperparameters of the model need to be adaptively adjusted. After the above preparations, the formal training of the model begins, and the training process is as follows:

[0103] 1) The first round of epoch training: In the first round of epoch training, the model traverses the entire training set once. After each epoch ends, the callback function is executed for monitoring and adjustment during the training process.

[0104] 2) The second round of epoch training: After completing the first round of epoch training, the model conducts the second round of epoch training. The model traverses the entire training set again, and this time it is updated according to the results of the previous round of training.

[0105] 3) Multiple iterations: This process is repeated multiple times until a certain convergence criterion or a preset number of training times is reached. After completing all the training and adjustments, the model is finally evaluated.

[0106] The system uses the validation set to evaluate the model performance and adjusts the hyperparameters according to the evaluation results to optimize the training process and results of the model. Specifically, the hyperparameter adaptive optimizer dynamically adjusts the hyperparameters of the model based on the performance metrics of the validation set. The hyperparameter adaptive optimizer is designed to monitor and analyze the performance of the model on the validation set in real time, such as key performance metrics like accuracy and loss value, and accordingly adjust key hyperparameters such as the learning rate, batch size, and regularization parameter, including the following:

[0107] 1) Regarding the dynamic adjustment of the learning rate, the following calculation formula is followed:

[0108]

[0109] η t represents the current learning rate, γ is a decay factor less than 1, and 1(condition) is an indicator function that takes the value of 1 when the condition inside the parentheses (in this embodiment, the loss increases) is true, and 0 otherwise. This formula is used to dynamically reduce the learning rate to prevent performance degradation during training.

[0110] 2) Regarding the adjustment of the batch size, the following calculation formula is followed:

[0111]

[0112] acc tis the accuracy at time t. This formula indicates that if the accuracy of the model improves, the batch size will increase to accelerate the training process; if the accuracy does not improve, the batch size remains unchanged.

[0113] 3) Regarding the adjustment of the regularization parameter, follow the following calculation formula:

[0114] λ t+1 = λ t *(1 - δ * 1(acc t+1 < acc t ))

[0115] where λ t is the current regularization parameter, and δ is a small positive value used to increase the regularization strength when the performance drops to prevent overfitting.

[0116] 4. Dynamic task management mechanism

[0117] The multi - task learning system introduces a dynamic task management mechanism, aiming to dynamically adjust the weights of different tasks according to the relative importance of the tasks to optimize the performance and effect of the model in the multi - task learning process. The importance of the task is determined according to its performance on the validation set. The update process is as Figure 4 shown, and the specific process is as follows:

[0118] 1) Initialize task weights: At the beginning, the system assigns the same initial weight to each task to ensure that all tasks have the same attention at the initial stage of model training.

[0119] 2) The first round of epoch training: The model performs the first iteration (epoch) of training according to the initialized weights. In this process, the model calculates the performance metrics of each task under the current weights.

[0120] 3) Evaluate performance and calculate task weights: After completing one round of epoch training, the system evaluates the performance of each task and calculates the relative importance of each task based on these performance metrics. This is achieved by calculating metrics such as the loss function value and accuracy.

[0121] 4) Adjust task weights: According to the calculated task weights, the system adjusts the weights of each task. Tasks with higher weights will receive more attention in subsequent training, while tasks with lower weights will receive less attention accordingly.

[0122] 5) The second round of epoch training: After completing the weight adjustment, the model enters the second round of iterative training. This time, the model continues to learn and update according to the new weight distribution.

[0123] 6) Continuous loop: This process is repeated multiple times until a certain convergence criterion or a preset number of training iterations is reached. Each loop adjusts the model's attention to tasks, gradually optimizing its multi-task learning ability. When the training process ends, the model gives the final result based on the weight distribution of the last iteration.

[0124] The task weight update formula is as follows:

[0125]

[0126] In the above formula, w i is the weight of task i, σ i is the performance metric (accuracy and F1 score) of task i on the validation set, and β is a hyperparameter that controls the speed of weight adjustment.

[0127] Then these weights are used for weighted task loss to better guide the model's training process. The weighted task loss formula is as follows:

[0128]

[0129] In the above formula, L total is the weighted total loss, N is the number of tasks, and L i is the loss of task i.

[0130] The introduction of the above dynamic task attention mechanism enables the model to allocate different resources and attention according to the importance of tasks, thus learning each task more effectively; this mechanism makes the model more flexible when facing multiple tasks, better able to adapt to the differences between different tasks, and thus improve the overall performance.

[0131] 5. Model Ensemble and Performance Evaluation

[0132] Integrate the trained multi-task learning model and the optimized hyperparameter adaptive optimizer to form a complete intelligent multi-task learning system. In this embodiment, 1200 posts from online water army and 12000 posts from ordinary users from platforms such as Kuaishou, Douyin, Weibo, and Xiaohongshu are used. Among them, the training set includes 1000 posts from online water army and 10000 posts from ordinary users, and the test set includes 200 posts from online water army and 2000 posts from ordinary users. To conduct performance testing on the model, where the loss function and accuracy on the training set and validation set are as Figure 5As shown, it can be obtained from the figure that in this neural network training for 10 epochs, both in the training set and the validation set, the loss function gradually decreases and the accuracy gradually increases, and the performance on the training set is quite good. Then, the test set is used to evaluate the performance of the multi-task learning model, including indicators such as accuracy, recall rate, and F1 value. The results are as Figure 6 shown to verify the effectiveness and generalization ability of the model. From Figure 6 it can be obtained that the accuracy, recall rate, and F1 value are 0.850, 0.820, and 0.835 respectively. Therefore, the intelligent multi-task learning system and the hyperparameter adaptive optimizer in the present invention have a relatively high detection accuracy for malicious entities.

[0133] 6. Output of Malicious Entity Detection Results

[0134] The malicious entity detection method based on the intelligent multi-task learning system provided by the present invention realizes the detection of malicious entities based on the multi-task learning model constructed above. The detection results include classification labels and confidence scores for malicious entity remarks. The classification labels are based on predefined categories, such as "fake news", "inflammatory remarks", "advertising content", etc., while the confidence scores reflect the confidence level of the model in its classification decision. In addition, the system can automatically adjust key hyperparameters such as learning rate, batch size, and regularization coefficient according to the performance feedback of the validation set, so as to optimize the performance in continuous training cycles. Sort or filter the detection results according to the confidence scores. By using the confidence scores as a reference standard, the system can present or select the detection results with higher confidence first to improve the credibility and practicality of the results. In addition, the system can also filter the confidence scores by setting appropriate thresholds according to specific application requirements, so as to exclude the detection results with lower confidence, reduce the false alarm rate, and improve the user experience. Take corresponding handling measures according to the detection results, including but not limited to adding suspicious remarks to the monitoring list and reporting to relevant agencies.

[0135] The malicious entity detection method based on an intelligent multi-task learning system provided by the present invention can, by constructing a multi-task learning framework, enable the system to simultaneously process multiple related tasks, improving the accuracy of the model in malicious entity detection; the application of a hyperparameter adaptive optimizer and regularization techniques helps to improve the robustness of the model, reduce overfitting, and make the model perform more stably when facing new data; the system can customize the model structure and processing flow according to different application requirements and data characteristics; it can monitor malicious remarks on social platforms in real time and respond quickly, effectively curbing the spread of malicious behavior; it can simultaneously process multiple types of malicious entity detection tasks, improving the usage efficiency and application scope of the system. The present invention improves the efficiency and effectiveness of malicious entity detection through an intelligent and automated approach, and also provides users with a more flexible and reliable tool to address network security challenges.

[0136] The above are only the preferred embodiments of the present invention and do not limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A malicious entity detection method based on an intelligent multi-task learning system, characterized in that: The following steps are involved: Step 1: Collect original text data related to malicious entity speeches from different platforms, and pre-process the original text data to ensure the quality and applicability of the data; Step 2: Based on the preprocessed data, a multi-task learning model is constructed, wherein the multi-task learning model includes a keyword matching model, a naive Bayes classification model, and a BERT classification model, and the multi-task learning model is trained by constructing a training set; Step 3: Design a hyperparameter adaptive optimizer to dynamically adjust the learning rate, batch size, and regularization parameters based on the performance of the multi-task learning model on the validation set, including the following: 1) Regarding the dynamic adjustment of the learning rate, follow the following calculation formula: Where: η t represents the current learning rate, γ is a decay factor less than 1, 1 (loss t+1 >loss t ) is an indicator function, which takes the value 1 when the loss increase is true and 0 otherwise; 2) Regarding batch processing size adjustment, follow the following calculation formula: Among them: acc t is the accuracy at time t. This formula shows that if the accuracy of the model improves, the batch size will increase to speed up the training process; if the accuracy does not improve, the batch size remains unchanged; 3) Regarding the adjustment of regularization parameters, follow the following calculation formula: l t+1 =λ t *(1-δ*1(acc t+1 <acc t )) Where: t is the current regularization parameter, δ is a small positive value used to increase the regularization strength when the performance decreases to prevent overfitting; Step 4: Introduce a dynamic task management mechanism into the multi-task learning model to dynamically adjust the weights of different tasks according to the importance of the tasks, so as to optimize the effect of the model in the multi-task learning process; Step 5: Integrate the trained multi-task learning model and the optimized hyperparameter adaptive optimizer to form a complete intelligent multi-task learning system; and use the validation set to perform model validation on the intelligent multi-task learning system; Step 6: Input the text data to be tested into the constructed intelligent multi-task learning system to obtain the detection results, which include the classification labels and confidence scores of the malicious entity speech.

2. The malicious entity detection method based on the intelligent multi-task learning system according to claim 1 is characterized in that: In the step 1, the collected data is preprocessed. First, the text is cleaned to remove HTML tags, special characters, and emoticons in the text to retain the basic content of the text; then a word segmentation operation is performed to decompose the text into a sequence of words or phrases; and then feature extraction is performed to convert the text data into a vector form.

3. The malicious entity detection method based on the intelligent multi-task learning system according to claim 1 is characterized in that: The multi-task learning model in step 2 is implemented using a neural network structure, which includes multiple specific functional layers, each layer is optimized for different aspects of the overall task, thereby achieving effective data processing and learning, including: 1) Input layer: used to receive raw text data or feature representation as input; for keyword matching tasks, the input is raw text data containing text information; for naive Bayes classification and BERT classification tasks, the input is text representation after preprocessing and feature extraction; 2) Embedding layer: Convert text data into dense vector representation. For keyword matching tasks, use the pre-trained word vector model Word2Vec to convert text into word embedding vectors. The output of the embedding layer is i It is expressed as: e i =Embedding(w i ) For Naive Bayes classification and BERT classification tasks, use the pre-trained BERT model to encode and represent text; 3) Multi-layer neural network: It includes multiple hidden layers, which are used to learn the high-level representation of input data. Each hidden layer uses different activation functions and numbers of neurons to adapt to the characteristics of different tasks and data distribution. For hidden layer l, its output is expressed as: h (l+1) =f(W l h l +b l ) Where: h (l) is the output of layer l, W l and b l are the weight matrix and bias vector of the layer respectively, and f is the activation function; 4) Task-specific layer: For keyword matching, naive Bayes classification, and BERT classification tasks, add corresponding task-specific layers at the output of the neural network; For the keyword matching task, the output layer of the sigmoid activation function is used to predict whether the text contains specific keywords; For classification tasks, the output layer of the softmax activation function is used to predict the probability distribution of text belonging to different categories; Output layer for keyword matching tasks The formula is: Where: σ is the sigmoid activation function; For the output layer p of the classification task, it is expressed as: p=softmax(Wh+b) Among them: the softmax function converts the output of the neural network into a probability distribution; 5) Loss function: Different loss functions are selected for optimization for different tasks, where the binary cross entropy loss function is used for keyword matching tasks and the multi-class cross entropy loss function is used for classification tasks; For the keyword matching task, the binary cross entropy loss function is used, which is expressed as: For classification tasks, a multi-class cross entropy loss function is used, expressed as: Where: y c is the one-hot encoding of the true label, p c is the predicted probability of the corresponding category; 6) Optimizer: Use optimization algorithms to adjust network parameters to minimize the loss function; Under the framework of hyperparameter adaptive optimizer, dynamically adjust the learning rate and other hyperparameters according to the performance of the model on the validation set to improve the training effect and generalization ability of the model; 7) Regularization: Regularization technology is introduced to prevent model overfitting. By integrating keyword matching, naive Bayes classification, and BERT classification tasks into a multi-task learning model, the system simultaneously learns the correlation and shared information between different tasks, improving the overall performance and efficiency of the model.

4. The malicious entity detection method based on the intelligent multi-task learning system according to claim 1 is characterized in that: The importance of the task in step 4 is determined based on its performance on the validation set, and the task weight update formula is as follows: Among them, w i is the weight of task i, σ i is the performance indicator of task i on the validation set, including accuracy and F1 score, and β is a hyperparameter that controls the speed of weight adjustment; These weights are then used to calculate the weighted task loss, which is given by: Where: L total is the weighted total loss, N is the number of tasks, and L i is the loss of task i.

5. The malicious entity detection method based on the intelligent multi-task learning system according to claim 1 is characterized in that: In step six, the detection results are sorted or filtered according to the confidence score; by taking the confidence score as a reference standard, the detection results with higher confidence are presented or selected first to improve the credibility and practicality of the results; the confidence score can also be filtered by setting a threshold, thereby excluding detection results with lower confidence, reducing the false alarm rate and improving the user experience.

Citation Information

Patent Citations

  • Deep neural network hyper-parameter optimization method, electronic device and storage medium

    CN110598842A

  • ABSC task syntactic constraint method based on dependency graph convolution and transfer learning

    CN112883714A