Security policy optimization method based on AI watermark tamper-proofing, medium and equipment

By embedding the watermark information generated by AI in the transaction data and optimizing the watermark information in combination with monitoring and evaluation techniques, the shortcomings of data watermarks being tampered with by virus files in the existing technology are solved, and more efficient data security protection is achieved.

CN119918097APending Publication Date: 2025-05-02CHINA TELECOM DIGITAL INTELLIGENCE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411895930.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-20
Publication Date
2025-05-02

AI Technical Summary

Technical Problem

The prior art is not effective in preventing data watermarks from being tampered with by virus files, especially in the face of data poisoning attacks.

Method used

Using AI-based watermark technology, watermark information generated by AI is embedded in transaction data, and watermark information is optimized to improve its security by monitoring transaction logs, evaluating host status and simulating virus attacks.

Benefits of technology

Effectively prevent data watermarks from being tampered with by virus files, and timely stop loss and data recovery through the transmission path of traceable virus files, improving the security of transaction data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119918097A_ABST
    Figure CN119918097A_ABST
Patent Text Reader

Abstract

The invention provides a security policy optimization method based on AI watermark tamper-proofing, a medium and equipment, and the method comprises the steps: initiating an AI watermark function when a transaction voucher two-dimensional code is generated after an e-commerce platform completes payment operation, and embedding the watermark information of a purchase user in each transaction data; acquiring a complete transaction log from a computer host, monitoring whether abnormal transaction data with watermark information tampered by a virus file exists in the transaction log, marking and tracing the abnormal transaction data, and further acquiring the virus file; and performing virus attack hazard assessment on the virus file in combination with the host state, simulating the attack of the virus file on the watermark information based on a data poisoning sample generation algorithm, and optimizing the watermark information according to a simulation result. According to the invention, the security of transaction data is protected in a way of generating watermarks through AI; designed virus attack hazard assessment provides effective early warning for virus defense; and the watermark information is optimized by simulating the virus file, so that the security of the transaction data is further optimized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security, and specifically relates to a security strategy optimization method, medium and device based on AI watermark anti-tampering. Background Art

[0002] The protection of transaction data during the transaction process is an important research topic in the field of data protection. For transaction data, data leakage may cause the business system of the enterprise to be paralyzed, posing a huge threat to the continuity of business; and transaction data usually contains consumers' private information, such as name, ID number, bank card number, etc. If this information is leaked, consumers may suffer from security threats such as identity theft and fraud, resulting in property losses of consumers.

[0003] Data watermarking is a technology that hides watermark information into structured data through certain rules and algorithms. The value of the data remains almost unchanged after hiding. It is mainly used for data protection and tracking and tracing after leakage. This technology is used to embed the user's watermark information in the data to realize the declaration of ownership. After the data is leaked, the watermark in the leaked data file is extracted to hold the person accountable and protect the security of the data. Although there are some means of using data watermarks for transaction data in the prior art, there is no good defense effect against data poisoning attacks due to the lack of effective evaluation of virus aggressiveness and the single generation of watermarks. And considering that many AI products have a wide range of data collection portals, data poisoning attacks still have huge risks. Summary of the invention

[0004] In view of the deficiencies in the prior art, the present invention provides a security strategy optimization method, medium and device based on AI watermark anti-tampering.

[0005] To achieve the above object, the present invention adopts the following technical solutions:

[0006] In a first aspect, the present invention provides a security policy optimization method based on AI watermark anti-tampering, comprising:

[0007] When the e-commerce platform generates a transaction voucher QR code after the payment operation is completed, the AI ​​watermark function is initiated to embed the purchasing user's watermark information generated by AI in each transaction data;

[0008] Obtain complete transaction logs from the computer host, monitor whether there are abnormal transaction data in the transaction logs whose watermark information has been tampered with by virus files, mark and trace the abnormal transaction data, and then obtain the virus files;

[0009] The virus attack hazard assessment is performed on the virus file in combination with the host status, and the attack of the virus file on the watermark information is simulated based on the data poisoning sample generation algorithm, and the watermark information is optimized according to the simulation results.

[0010] Optionally, embedding the watermark information of the purchasing user generated by AI in each transaction data is specifically:

[0011] Use AI models to extract feature data from purchasing users;

[0012] Based on the extracted feature data, an AI algorithm is used to generate a watermark code that is random and associated with the purchasing user information;

[0013] Embed the watermark code into the transaction data by field embedding;

[0014] Verify the integrity of the embedded transaction data: If it meets the integrity requirements, upload the transaction data to the transaction log; if it does not meet the integrity requirements, re-embed the watermark code into the transaction data by regenerating the watermark code or changing the embedding position, and then verify it until it meets the integrity requirements.

[0015] Optionally, the field is embedded in an encrypted manner using a symmetric encryption algorithm.

[0016] Optionally, fanotify file monitoring technology is used to monitor whether there is abnormal transaction data in the transaction log whose watermark information has been tampered with by virus files. The abnormal transaction data is marked and traced back to the transmission path of the virus file, and the virus file is isolated after being obtained.

[0017] Optionally, the virus attack hazard assessment of the virus file is performed in combination with the host status, specifically:

[0018] The weighted average method is used to obtain the host status, as follows:

[0019] HostStatus=∑Weight i ×Service i ;

[0020] In the formula, HostStatus represents the host status value, Service i The ith indicator representing the host status, Weight i represents the weighting coefficient of the i-th indicator;

[0021] The harm of virus attack is evaluated based on the host status value. The higher the host status value, the greater the harm of virus attack.

[0022] Optionally, the host status indicators include host connection rate, memory usage, CPU usage and hard disk space increment.

[0023] Optionally, the data poisoning sample generation algorithm simulates the attack of the virus file on the watermark information, specifically:

[0024] The characteristic data of the virus file is extracted as the target sample t, and the expected poisoning sample x is generated using the following poisoning sample generation algorithm:

[0025]

[0026] In the formula, p represents the feasibility evaluation parameter of the expected poisoning sample x, f(x) and f(t) are the vectorized expressions of x and t, respectively. is the two-norm, β is a hyperparameter, and b represents the uninfected benchmark sample;

[0027] Generate a simulated virus file based on the expected poisoned sample x to attack the watermark information.

[0028] Optionally, the optimizing the watermark information according to the simulation result is specifically:

[0029] The security performance of the watermark information is evaluated by verifying the data integrity of the watermark information after being attacked, and the security performance score of each watermark information is stored in the database;

[0030] Retrieve multiple watermark information from the database whose security performance scores are higher than a set threshold, and extract features from them;

[0031] The K-Means clustering algorithm is used to cluster the extracted multiple features. After clustering, the number of features in each category is sorted from large to small, and the category with the highest sorting is selected. The selected category features are used as the input of AI to generate the watermark information of the purchasing user next time.

[0032] In a second aspect, the present invention provides a computer-readable storage medium storing a computer program, wherein the computer program enables a computer to execute the security policy optimization method based on AI watermark anti-tampering as described in the first aspect.

[0033] In a third aspect, the present invention provides an electronic device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the security policy optimization method based on AI watermark anti-tampering as described in the first aspect is implemented.

[0034] The beneficial effects of the present invention are as follows: in view of the fact that data watermarks are tampered with by virus files to trigger the infection mechanism, which may cause data leakage, the present invention protects the security of transaction data by generating watermarks through AI, and traces the source through watermarks after data leakage, so as to fully understand the transmission path of virus files, facilitate timely stop-loss and data recovery, and strengthen data security protection; the present invention designs a scientific virus attack hazard assessment based on the impact of virus files on the host state, and provides effective early warning for subsequent virus defense; the present invention optimizes the data poisoning sample generation algorithm, optimizes the watermark information used in subsequent transaction data by simulating the attack of virus files on watermark information, as well as feature extraction and sorting, forming a dynamic watermark information generation method, and further improving the security of transaction data. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 It is an overall flow chart of a security strategy optimization method based on AI watermark anti-tampering of the present invention.

[0036] Figure 2 This is a functional architecture diagram of a security strategy optimization method based on AI watermark anti-tampering of the present invention. DETAILED DESCRIPTION

[0037] The technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application.

[0038] In one embodiment, the present invention proposes a security strategy optimization method based on AI watermark anti-tampering, the process is as follows: Figure 1 As shown, the architecture is Figure 2 As shown, the specific steps are as follows:

[0039] Step 1: Initiate the AI ​​watermark function when generating a transaction voucher QR code after completing the payment operation on the e-commerce platform, and embed the watermark information of the purchasing user generated by AI in each transaction data.

[0040] This embodiment targets the characteristics of AI watermark being tampered with by the attack data source file and embedded with virus data, which will cause data leakage when the virus reaches the attack target and triggers the infection mechanism. When the e-commerce platform completes the payment operation and generates a transaction voucher QR code, the AI ​​watermark function is initiated, and the technology is used to embed the watermark information of the purchasing user in the data to realize the purchase behavior voucher declaration. This is conducive to tracing the source by extracting the watermark in the leaked data file after the data is leaked, and protecting the security of the transaction data.

[0041] The embedding process of watermark information is as follows:

[0042] First, the AI ​​model is used to extract the characteristic data of the purchasing user information. Based on the extracted user characteristic data, the AI ​​algorithm is used to preliminarily generate a watermark code that is random and associated with the purchasing user information. Then, the watermark code is embedded in the transaction data by field embedding, and the field embedding method can be encrypted embedding using a symmetric encryption algorithm.

[0043] Next, the integrity of the embedded transaction data must be verified: if it meets the integrity requirements, the transaction data is uploaded to the transaction log; if it does not meet the integrity requirements, the watermark code is re-embedded into the transaction data by regenerating the watermark code or changing the embedding position, and then verified again until it meets the integrity requirements. This step is to ensure that the embedding of the watermark does not affect the transmission and reading of normal transaction data.

[0044] Step 2: Obtain the complete transaction log from the computer host, use fanotify file monitoring technology to monitor whether there is abnormal transaction data in the transaction log whose watermark information has been tampered with by virus files, mark and trace the abnormal transaction data, and then obtain the virus file.

[0045] This embodiment combines fanotify file monitoring technology with complete transaction log data to perform monitoring, marking and tracing, which can simultaneously meet the real-time and batch operations of abnormal transaction data.

[0046] Transaction log data mining and analysis is mainly divided into two layers: the first layer uses the physical node where the user transaction behavior data is located to extract the transaction behavior data of the user account associated with the node from the log, such as clicks, favorites, adding to shopping carts, purchases, etc.; the second layer extracts all data path nodes and time dimensions of the association relationship from the transaction behavior data of the user account, and conducts data mining on the business data exchanges between the server and database, middleware, server CPU, memory, disk, and process.

[0047] For abnormal transaction data in the network where the attacked host is located, fanotify technology is used to reversely trace the abnormality and mark the infected abnormal data in the SIB network topology. fanotify is a new file monitoring technology on the Linux platform, which is often used for malicious access control of antivirus software or virus programs. After the transaction data is encrypted and tampered with by the virus file, when the path and related information of the virus process file are traced back through fanotify technology, the traceability range can be increased in combination with the network node where the attacked host is located. When the digital watermark is tampered with by the virus file within the traceability range, the virus file can be isolated or deleted.

[0048] Step 3: Evaluate the virus attack hazard of the virus file based on the host status.

[0049] Virus attack hazard assessment and defense can be carried out from three dimensions: vulnerability, external attack, and internal anomaly. Vulnerability is centered on log mining and analysis of associated hosts in poisoning attacks, looking for attack surfaces of data and vulnerabilities, and discovering weaknesses in advance. External attacks are based on transaction behavior data such as clicks, favorites, adding to shopping carts, and purchases, combined with vulnerability scanning to adjust defense strategies in a targeted manner. Internal anomalies are to find assets and backend hosts that have been compromised in poisoning attacks, and to mine and analyze the transaction behavior data stored or transmitted by the attacked host through the complete transaction log data in the previous step, and to isolate or delete them.

[0050] This embodiment evaluates the attacked host and optimizes the security policy by taking the host status as the core indicator for determining data anomalies. The log is a true reflection of the operation of the computer host. The host uses indicators such as memory, CPU, hard disk, surface files, and network connections to jointly examine whether the host's operating status is within a reasonable range. If it exceeds the range, it may represent a host anomaly. Host anomalies will cause a significant increase in CPU load and memory occupancy, but generally will not cause system paralysis; however, DoS attacks will cause the host connection to be interrupted, memory and CPU usage to increase dramatically, and hard disk space to increase.

[0051] First, the weighted average method is used to obtain the host status, as follows:

[0052] HostStatus=∑Weight i ×Service i ;

[0053] In the formula, HostStatus represents the host status value, Service i The ith indicator representing the host status, Weight i Represents the weighted coefficient of the ith indicator; host status indicators include host connection rate, memory usage, CPU usage, and hard disk space increment.

[0054] Then, the harm of the virus attack is evaluated according to the host status value. The higher the host status value, the greater the harm of the virus attack.

[0055] Step 4: Based on the data poisoning sample generation algorithm, simulate the attack of virus files on watermark information.

[0056] The characteristic data of the virus file is extracted as the target sample t, and the expected poisoning sample x is generated using the following poisoning sample generation algorithm:

[0057]

[0058] Where p represents the feasibility evaluation parameter of the expected poisoning sample x, which is generally set according to needs; f(x) and f(t) are the vectorized expressions of x and , respectively, which can be realized through neural networks; is the binary norm, also known as the Euclidean norm, which can calculate the Euclidean distance between vectors (when the input is a matrix, it is called the Frobenius norm, FrobeniusNorm); the first part on the right side of the equation indicates that the expected poisoned sample x and the target sample t are relatively close in the high-dimensional feature space, and the second part indicates that the expected poisoned sample x and the benchmark sample b are relatively close in the original input space of the image; β is a hyperparameter used to balance the control of the above two aspects; the benchmark sample b is the sample data of the original transaction data.

[0059] In actual operation, the expected poisoned sample x is set to be the same as the baseline sample b in advance, and has the same correct label. Then, during the training process, the perturbation added to x is continuously changed so that x and b are not far apart in physical distance (it is not easy to visually detect the perturbation of image x), while f(x) and f(t) are as close as possible. The complete poisoned sample generation process is as follows:

[0060] Input: t, b, learning rate

[0061] Output: Optimized x

[0062] Initialization: x0←b

[0063] definition:

[0064] for i=1 to max_iters do

[0065]

[0066]

[0067] end for

[0068] In the above generation process, the first part of the above formula is defined as the loss L p (·), each iteration first minimizes L p (·) to optimize the expected poisoning sample x. This part of the optimization is the guarantee of the effectiveness of the poisoning data. For the second part, each time through This achieves optimization, which visually ensures that x does not change too much, maintains the consistency of x and its label, and achieves the purpose of hiding.

[0069] Generate a simulated virus file based on the expected poisoned sample x, and conduct an attack simulation experiment on the watermark information, which can effectively avoid the uncontrollable use of the actual virus file. Finally, in the attack simulation experiment, x is easily classified as the same category as b. At the same time, because the target sample has a representation close to the high-dimensional feature vector f(x), it is also likely to be misclassified into the benchmark sample b, that is, the poisoning attack goal is achieved.

[0070] Step 5: Optimize the watermark information according to the simulation results.

[0071] In this embodiment, the security performance of the watermark information is first evaluated by verifying the data integrity of the watermark information after being attacked, and the security performance score of each watermark information is stored in the database; then multiple watermark information with security performance scores higher than the set threshold are retrieved from the database, and features are extracted; finally, the K-Means clustering algorithm is used to cluster the extracted multiple features, and after clustering, the number of features of each category is sorted from large to small, and the category with the highest sorting is selected. The selected category features are combined with user feature data as the input of AI for the next generation of watermark information for purchasing users. In this way, the watermark information used for subsequent transaction data can be optimized, rather than being randomly generated by AI alone. This experience-feedback dynamic watermark information generation method greatly improves transaction security.

[0072] In another embodiment, the present invention proposes a computer-readable storage medium storing a computer program, wherein the computer program enables a computer to execute the security policy optimization method based on AI watermark anti-tampering of the aforementioned embodiment.

[0073] In another embodiment, the present invention proposes an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the security policy optimization method based on AI watermark anti-tampering of the aforementioned embodiment is implemented.

[0074] In the embodiments disclosed in the present application, the computer storage medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. The computer storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or equipment, or any suitable combination of the above. More specific examples of computer storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above.

[0075] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed in this application can be implemented in electronic hardware or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0076] The above are only preferred embodiments of the present invention, and the protection scope of the present invention is not limited to the above embodiments. All technical solutions under the concept of the present invention belong to the protection scope of the present invention. It should be pointed out that for ordinary technicians in this technical field, some improvements and modifications without departing from the principle of the present invention should be regarded as the protection scope of the present invention.

Claims

1. A security strategy optimization method based on AI watermark anti-tampering, characterized in that: include: When the e-commerce platform generates a transaction voucher QR code after the payment operation is completed, the AI ​​watermark function is initiated to embed the purchasing user's watermark information generated by AI in each transaction data; Obtain complete transaction logs from the computer host, monitor whether there are abnormal transaction data in the transaction logs whose watermark information has been tampered with by virus files, mark and trace the abnormal transaction data, and then obtain the virus files; The virus attack hazard assessment is performed on the virus file in combination with the host status, and the attack of the virus file on the watermark information is simulated based on the data poisoning sample generation algorithm, and the watermark information is optimized according to the simulation results.

2. A security strategy optimization method based on AI watermark anti-tampering as claimed in claim 1, characterized in that: The watermark information of the purchasing user generated by AI is embedded in each transaction data, specifically: Use AI models to extract feature data from purchasing users; Based on the extracted feature data, an AI algorithm is used to generate a watermark code that is random and associated with the purchasing user information; Embed the watermark code into the transaction data by field embedding; Verify the integrity of the embedded transaction data: If it meets the integrity requirements, upload the transaction data to the transaction log; if it does not meet the integrity requirements, re-embed the watermark code into the transaction data by regenerating the watermark code or changing the embedding position, and then verify it until it meets the integrity requirements.

3. A security strategy optimization method based on AI watermark anti-tampering as claimed in claim 2, characterized in that: The field is embedded in an encrypted manner using a symmetric encryption algorithm.

4. The security strategy optimization method based on AI watermark anti-tampering as claimed in claim 1 is characterized by: The fanotify file monitoring technology is used to monitor whether there is abnormal transaction data in the transaction log whose watermark information has been tampered with by virus files. The abnormal transaction data is marked and traced back to the transmission path of the virus file, and the virus file is isolated after it is obtained.

5. The security strategy optimization method based on AI watermark anti-tampering as claimed in claim 1 is characterized by: The virus attack hazard assessment of the virus file in combination with the host status is specifically as follows: The weighted average method is used to obtain the host status, as follows: HostStatus=∑Weight i ×Service i ; In the formula, HostStatus represents the host status value, Service i The ith indicator representing the host status, Weight i represents the weight coefficient of the i-th indicator; The harm of virus attack is evaluated based on the host status value. The higher the host status value, the greater the harm of virus attack.

6. A security strategy optimization method based on AI watermark anti-tampering as claimed in claim 5, characterized in that: The host status indicators include host connection rate, memory usage, CPU usage and hard disk space increment.

7. The security strategy optimization method based on AI watermark anti-tampering as claimed in claim 1 is characterized by: The data poisoning sample generation algorithm simulates the attack of virus files on watermark information, specifically: The characteristic data of the virus file is extracted as the target sample t, and the expected poisoning sample x is generated using the following poisoning sample generation algorithm: In the formula, p represents the feasibility evaluation parameter of the expected poisoning sample x, f(x) and f(t) are the vectorized expressions of x and t respectively. is the two-norm, β is a hyperparameter, and b represents the uninfected benchmark sample; Generate a simulated virus file based on the expected poisoned sample x to attack the watermark information.

8. A security strategy optimization method based on AI watermark anti-tampering as claimed in claim 7, characterized in that: The optimization of watermark information according to the simulation results is specifically as follows: The security performance of the watermark information is evaluated by verifying the data integrity of the watermark information after being attacked, and the security performance score of each watermark information is stored in the database; Retrieve multiple watermark information from the database whose security performance scores are higher than a set threshold, and extract features from them; The K-Means clustering algorithm is used to cluster the extracted multiple features. After clustering, the number of features in each category is sorted from large to small, and the category with the highest sorting is selected. The selected category features are used as the input of AI to generate the watermark information of the purchasing user next time.

9. A computer-readable storage medium storing a computer program, characterized in that: The computer program enables the computer to execute the security policy optimization method based on AI watermark anti-tampering as described in any one of claims 1-8.

10. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the security policy optimization method based on AI watermark anti-tampering as described in any one of claims 1 to 8 is implemented.