Multi-agent cooperative deep forgery attack detection method and system
By building a multi-dimensional nested structural model and a multi-layer heterogeneous CycleGAN network, combined with the timing differential attention mechanism, the problem of difficulty in identifying multi-agent collaborative deep forgery attacks in the existing technology is solved, and more accurate attack recognition and hidden channel detection are achieved.
Patent Information
- Application Number
- CN202510443383.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-04-10
AI Technical Summary
Existing network anti-penetration detection technologies are difficult to effectively identify and deal with multi-agent collaborative attacks, especially deep forgery attacks, and lack the ability to detect hidden channels.
By constructing a multi-dimensional nested structural model including the Agent layer, the channel layer and the DeepFake generation layer, hidden channel communication data and DeepFake generation data are collected, cross-layer differential feature vectors are generated, and a multi-scale significance mapping matrix is generated through the timing differential attention mechanism. Then, a multi-layer heterogeneous CycleGAN network is constructed and a significance mapping matrix is injected. The discriminant results of the network are fed back to the penetration behavior map, and an online adaptive detection mechanism is established.
It realizes finer granular expression and recognition of collaborative deep forgery attacks of multiple Agents, improving the accuracy of attack recognition and the ability to detect hidden channels.
Smart Images

Figure CN119996072A_ABST
Abstract
Description
Technical Field
[0001] Multiple embodiments of this specification relate to the field of information technology, and specifically to a method and system for detecting deep fake attacks by multi-agent collaboration. Background Art
[0002] In terms of network penetration detection, it currently mainly relies on traffic analysis, intrusion detection, intrusion prevention, and methods based on user behavior analysis. Traffic analysis monitors network traffic to find abnormal traffic patterns and detect potential attack behaviors. Intrusion detection and intrusion prevention use preset rules and signatures to identify known attack patterns and respond. Technology based on user behavior analysis monitors the normal behavior of users and captures abnormal behaviors that deviate from normal patterns, thereby discovering potential security threats.
[0003] However, current network anti-penetration detection technology cannot achieve good results when facing more complex attack modes. Existing detection methods usually rely on the analysis of a single dimension, such as traffic, protocol or behavior, and lack cross-level joint analysis. In more complex multi-agent collaborative attacks, analysis methods targeting a single dimension cannot fully capture the attacker's multi-party collaboration and attack. In addition, existing detection technologies lack detection of covert channels. Covert channels often become a way for attackers to bypass detection and achieve penetration. Attackers use covert channels to steal data or remotely control, and covert channels cannot be effectively detected by existing IDS or IPS technologies. Current network defense systems rely on static rules or signature matching, which makes it impossible for network defense systems to respond in a timely manner when faced with new and ever-changing attack strategies.
[0004] With the advancement of AI technology, the emergence of multi-agent collaborative attacks makes it more difficult for existing technologies to effectively deal with network attacks. When attackers use multiple collaborative AI Agents to attack, it will be difficult for existing detection systems to effectively identify and intercept these attacks. Multiple collaborative AI Agent attacks are highly concealed and complex. Each Agent plays a different role in different attack stages, such as generating false identity information (DeepFake), or performing network-side penetration and lateral movement. Existing security protection systems can usually only detect the behavior of a single attacker and lack the ability to analyze the behavior of multiple collaborative agents as a whole. Therefore, it is necessary to study new network attack protection technologies. Summary of the invention
[0005] Multiple embodiments of this specification describe a method and system for detecting deep fake attacks through multi-agent collaboration.
[0006] In a first aspect, the embodiments of this specification provide a method for detecting a multi-agent collaborative deep fake attack, comprising the steps of: S1. Construct a multi-dimensional nested structure model including an agent layer, a channel layer, and a DeepFake generation layer. Each layer is represented by a multi-dimensional feature. The multi-dimensional nested structure is mapped into a hierarchical graph, and the associated mapping relationship, initial state weight, and timestamp are recorded to obtain an infiltration behavior graph. S2. Collect covert channel communication data and DeepFake generation data in multiple time periods, divide them into time slices and mark preset attack behaviors, compare the preset indicators of adjacent time slices, and generate cross-layer differential feature vectors; S3. Decouple the differential features of the Agent layer, the channel layer, and the DeepFake generation layer according to the cross-layer differential feature vector, and generate a multi-scale saliency mapping matrix through a temporal differential attention mechanism; S4, constructing a multi-layer heterogeneous CycleGAN network and injecting the nested saliency mapping matrix; S5. Feedback the discrimination result based on the multi-layer heterogeneous CycleGAN network to the penetration behavior map; S6. Based on the time-series backtracking reinforcement strategy, an online adaptive detection mechanism for the penetration behavior map is established to detect deep fake attacks. Agent refers to intelligent agent, and CycleGAN refers to cycle generative adversarial network.
[0007] In a second aspect, the embodiments of this specification provide a multi-agent collaborative deep fake attack detection system, including: A mapping module constructs a multi-dimensional nested structure model including an agent layer, a channel layer, and a DeepFake generation layer. Each layer is represented by a multi-dimensional feature, and the multi-dimensional nested structure is mapped into a hierarchical graph. The associated mapping relationship, initial state weight, and timestamp are recorded to obtain an infiltration behavior graph. The feature module collects covert channel communication data and DeepFake generation data in multiple time periods, divides and annotates preset attack behaviors by time slices, compares preset indicators of adjacent time slices, and generates cross-layer differential feature vectors; A differential module decouples the differential features of the agent layer, the channel layer, and the DeepFake generation layer according to the cross-layer differential feature vector, and generates a multi-scale saliency mapping matrix through a temporal differential attention mechanism; An injection module constructs a multi-layer heterogeneous CycleGAN network and injects the nested saliency map matrix; A feedback module, based on the discrimination result of the multi-layer heterogeneous CycleGAN network, feeds back to the penetration behavior map; The detection module establishes an online adaptive detection mechanism for the penetration behavior map based on the time-series backtracking reinforcement strategy to realize the detection of deep fake attacks.
[0008] In a third aspect, an embodiment of this specification provides an electronic device, including a processor and a memory; The processor is connected to the memory; The memory is used to store executable program code; The processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to execute the method described in any one of the above aspects.
[0009] In a fourth aspect, an embodiment of the present specification provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the method described in any of the above aspects.
[0010] In a fifth aspect, an embodiment of this specification provides a computer program product, including a computer program, which implements the method described in any of the above aspects when executed by a processor.
[0011] The beneficial effects brought by the technical solutions provided by some embodiments of this specification include at least: In multiple embodiments of this specification, the detection method of deep fake attacks provided by establishing a multi-dimensional nested structure model of the agent layer, channel layer and DeepFake generation layer completes a more fine-grained expression of multi-agent collaborative attack behavior, which can more accurately capture the characteristics of deep fake attacks and help improve the accuracy of deep fake attack identification. The multi-scale saliency mapping matrix generated by the temporal difference attention mechanism can increase the model's attention to abnormal features, which helps to improve the accuracy of attack identification.
[0012] Other features and advantages of the various embodiments of the present specification will be further disclosed in the following detailed description and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] In order to more clearly illustrate the technical solutions in the embodiments of this specification, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0014] Figure 1 A schematic diagram of a scenario of a deep fake attack detection method provided in an embodiment of this specification.
[0015] Figure 2A flowchart of a deep fake attack detection method provided in an embodiment of this specification.
[0016] Figure 3 A schematic diagram of the flow chart of a method for generating a cross-layer differential feature vector provided in an embodiment of this specification.
[0017] Figure 4 A schematic flow chart of a method for generating a multi-scale saliency mapping matrix provided in an embodiment of this specification.
[0018] Figure 5 Schematic diagram of the deep fake attack detection system provided in the embodiments of this specification.
[0019] Figure 6 A schematic diagram of an electronic device provided in an embodiment of this specification. DETAILED DESCRIPTION
[0020] The following is an explanation and description of the technical solutions of the embodiments of this specification in conjunction with the drawings of the embodiments of this specification, but the following embodiments are only preferred embodiments of this specification, not all. Based on the embodiments in the implementation mode, other embodiments obtained by those skilled in the art without creative work are all within the scope of protection of this specification.
[0021] The terms "first", "second", "third", etc. in the description and claims of this specification and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally includes steps or units that are not listed, or optionally includes other steps or units inherent to these processes, methods, products or devices.
[0022] In the following description, terms such as "inside", "outside", "up", "down", "left", "right", etc. that indicate directions or positional relationships are only used to facilitate the description of the embodiments and simplify the description, and do not indicate or imply that the device or element referred to must have a specific direction, be constructed and operated in a specific direction, and therefore should not be understood as a limitation of this specification.
[0023] The data involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection of relevant data complies with the relevant laws, regulations and standards of relevant countries and regions.
[0024] Before describing the technical solution in this specification, an introduction is given to the application scenarios and related technologies of the technical solution.
[0025] Deepfake is a technology that uses artificial intelligence technology, especially deep learning algorithms, to create highly realistic false images, audio or video content. This technology can synthesize one person's facial expressions, voice and other features onto another person's image or video to create fake content that looks real. Deepfake attacks refer to malicious acts using this technology, such as identity theft, using deepfake technology to create false videos or audio of others for illegal activities such as fraud. Information misleading, using deepfake content to spread false information in areas such as politics and commercial competition to manipulate public opinion. Personal privacy infringement, synthesizing someone's facial features into other videos without consent, especially in inappropriate scenes, invading others' privacy. In the face of the risk of deepfake attacks, it is important to raise public awareness of this technology and take measures to enhance the ability to identify such fake content.
[0026] Multi-agent collaborative deep fake attacks are a more complex and advanced form of cyberattack that combines deep fake technology with the capabilities of multi-agent systems (MAS). In this attack mode, multiple autonomous or semi-autonomous software agents (i.e., agents) work together to use deep fake technology to generate highly realistic false content in order to deceive, mislead, or destroy.
[0027] The attack mechanism includes division of labor and cooperation. Different agents can be designed to specialize in specific tasks, such as one agent is responsible for collecting target information, another agent is focused on generating deep fake content, and another agent may be responsible for spreading this content. Adaptive learning. Through machine learning algorithms, agents can continuously learn and adapt to environmental changes, optimize their behavioral strategies, and improve the authenticity and dissemination efficiency of fake content. Distributed execution. This type of attack is usually not carried out in a centralized manner, but is implemented by multiple agents distributed in different locations, which increases the difficulty of detection and defense.
[0028] In complex multi-agent coordinated attacks, a single-dimensional detection method cannot fully capture the attacker's multi-party collaboration and attack methods. Secondly, existing systems usually ignore the existence of covert channels, which often become the main means for attackers to bypass detection and achieve penetration. To this end, this manual proposes a detection method for multi-agent collaborative deep fake attacks. Please refer to the attached Figure 1First, read the historical attack traffic 11, generate cross-layer differential feature vectors and mark the preset attack behaviors, and then establish a multi-scale saliency mapping matrix. After establishing a multi-layer heterogeneous CycleGAN network for discrimination, update the multi-dimensional nested structure model. The updated multi-dimensional nested structure model can extract the multi-dimensional features of the traffic to be detected 12 and obtain the penetration behavior map. The detection results of deep fake attacks are obtained through the results of the multi-layer heterogeneous CycleGAN network identifying the penetration behavior map.
[0029] For details, please refer to the attached Figure 2 This specification first provides a method for detecting a multi-agent collaborative deep fake attack, comprising the steps of: S1. Construct a multi-dimensional nested structure model including an agent layer, a channel layer, and a DeepFake generation layer. Each layer is represented by a multi-dimensional feature. The multi-dimensional nested structure is mapped into a hierarchical graph, and the associated mapping relationship, initial state weight, and timestamp are recorded to obtain an infiltration behavior graph.
[0030] The Agent layer is used to obtain the entity set of the Agent layer and define a multi-dimensional feature vector for each Agent. The Agents involved in the attack are numbered and the Agent entity set is constructed.
[0031] The process of building the Agent layer includes: collecting attribute information such as the behavior type (such as penetration, lateral movement), historical attack strategy, task division, etc. of each Agent. This information is represented as a feature vector A= , Indicates whether to assume the type code of DeepFake generation behavior. Represents the comprehensive value of past attack strategies, Indicates the level of division of labor in a multi-agent collaborative environment.
[0032] The channel layer is used to obtain the entity set of physical or logical channels and define a multi-dimensional feature vector for each channel. The process of constructing the channel layer includes: numbering all channels that may have covert transmission and constructing a channel entity set. Collect the code rate change, time domain characteristics and error packet injection method information of each channel in different time periods. This information is represented as a feature vector C= ,in Indicates the average transmission bit rate. Indicates the number of error packet injections that occur per unit time. Indicates the rate of change in the time domain.
[0033] The DeepFake generation layer is used to obtain the source entity information of the forged content in the DeepFake generation layer and define a multi-dimensional generated feature vector for it. The process of building the DeepFake generation layer includes: numbering the DeepFake forgery sources and building a DeepFake entity set. Collect the specific forgery means (voice, video or text) and dynamically generate quality indicators for each DeepFake entity. This information is represented as a feature vector D= ,in, Indicates the content type encoding (voice, video or text), represents the generated quality score (based on comprehensive quantification such as audio and video resolution, distortion, and naturalness of forged text), Indicates the dynamic generation rate per unit time.
[0034] S2. Collect covert channel communication data and DeepFake generation data in multiple time periods, divide them into time slices and mark the preset attack behaviors, compare the preset indicators of adjacent time slices, and generate cross-layer differential feature vectors.
[0035] Divide the collected data into time slices, and select the appropriate time slice length according to actual needs, such as every 5 minutes, every hour, every day, etc. Mark the data in each time slice to see if there is a preset attack behavior. Define the standards for preset attack behaviors, such as abnormal bit rate changes, sudden increase in the number of error packet injections, sudden changes in DeepFake generation rate, etc. Manually or automatically mark the data in each time slice to mark whether there is a preset attack behavior.
[0036] Please see attached Figure 3 , the method of generating cross-layer differential feature vectors includes: S21. Collect data from actual attack traffic and extract covert channel layer features and DeepFake generation layer features respectively, divide them into multiple time slices according to timestamps, and mark preset key behaviors.
[0037] The covert channel is monitored in each time period, and the following information is recorded: code rate change (i.e., transmission rate), number of error packet injections, and time domain characteristics (such as transmission delay and fluctuation).
[0038] S22. Based on the feature comparison of adjacent time slices, calculate the differential features of the hidden channel layer features and the DeepFake generation layer features. Collect data on DeepFake generation in multiple time periods. Record the DeepFake generation in each time period, including: the type of generated content (voice, video, text), dynamic generation quality indicators (resolution, distortion, naturalness, etc.), and dynamic generation rate per unit time.
[0039] S23. Combine the differential features of the hidden channel layer and the DeepFake generation layer to form a cross-layer differential feature vector.
[0040] For covert channel communication data, calculate the code rate change difference Δcrate between adjacent time slices, calculate the error packet injection number difference Δcerror between adjacent time slices, and calculate the time domain feature change Δcspeed between adjacent time slices. For DeepFake generated data, calculate the generated content quality change Δdquality between adjacent time slices, and then calculate the generation rate change Δdrate between adjacent time slices. Combined with the differences between covert channel and DeepFake generated data, generate a cross-layer differential feature vector. Construct a differential feature vector Δ=[Δcrate,Δcerror,Δcspeed,Δdquality,Δdrate].
[0041] For example, time period 1 (0:00-1:00): Covert channel data: crate=100,cerror=0.05,cspeed=0.9, DeepFake generated data: dquality=0.95,drate=0.8.
[0042] Time period 2 (1:00-2:00): Covert channel data: crate=110,cerror=0.07,cspeed=0.85, DeepFake generated data: dquality=0.94,drate=0.85.
[0043] Follow these steps in order: For time slice division, it is assumed that each time period is 1 hour and no further division is required.
[0044] Mark the preset attack behaviors, assuming that there is no attack behavior in time period 1 and there is potential attack behavior in time period 2.
[0045] Calculate the difference of preset indicators between adjacent time slices: Δcrate=110-100=10, Δcerror=0.07-0.05=0.02, Δcspeed=0.85-0.9=-0.05, Δdquality=0.94-0.95=-0.01, Δdrate=0.85-0.8=0.05.
[0046] Finally, the cross-layer differential feature vector is generated: Δ=[10, 0.02, -0.05, -0.01, 0.05].
[0047] S3. According to the cross-layer differential feature vector, the differential features of the Agent layer, the channel layer and the DeepFake generation layer are decoupled, and a multi-scale saliency mapping matrix is generated through a temporal differential attention mechanism.
[0048] Please see attached Figure 4 , the method of generating a multi-scale saliency map matrix includes: S31. Obtain the behavioral features in each time slice. For the Agent layer, obtain the behavioral features of the Agent in each time slice. Specifically, collect the agent's behavior type (such as penetration, lateral movement), historical attack strategy, task division and other attribute information in each time slice. Calculate the differential feature vector ΔA=[Δatype,Δastrategy,Δarole] between adjacent time slices. For the channel layer, obtain the change in the preset feature quantity of the covert channel in different time slices. Specifically, collect the bit rate change, error packet injection number, transmission delay and other features in each time slice. Calculate the differential feature vector ΔC=[Δcrate,Δcerror,Δcspeed] between adjacent time slices. For the DeepFake generation layer, record the change in the preset feature quantity of the DeepFake generation layer in different time slices. Specifically, collect the content quality score in each time slice, the dynamic generation rate per unit time and other features. Calculate the differential feature vector ΔD=[Δdquality,Δdrate] between adjacent time slices.
[0049] S32, construct independent attention weights for the Agent layer, channel layer and DeepFake generation layer respectively, and adjust the attention weights by comparing the differential features of adjacent time slices.
[0050] Construct independent attention weights and initialize the attention weights first, that is, construct initial attention weights for the agent layer, channel layer, and DeepFake generation layer respectively. Set the initial attention weight vectors WA, WC, WD, which can be initialized to uniform distribution or set based on prior knowledge.
[0051] Then the attention weight is adjusted by comparing the differential features of adjacent time slices. Specifically, the attention weight update is calculated using the temporal difference attention mechanism:
[0052] Where f() is a nonlinear function (such as Sigmoid function or ReLU function) used to update the attention weight according to the differential features of the current time slice. t represents the time slice identifier.
[0053] S33. Generate a multi-scale saliency mapping matrix based on the differential features weighted by the attention weights.
[0054] Weighted processing is performed on the differential features of each time slice: , Among them, ⊙ represents element-by-element multiplication. The weighted differential features are integrated into a multi-scale saliency mapping matrix. The weighted differential features of each time slice are arranged in chronological order to form a saliency mapping matrix:
[0055] t1, t2, …, tn represent time slice subscripts.
[0056] For example, the behavior characteristics in each time slice are obtained: Obtain the behavioral characteristics in each time slice, ΔA=[0,-0.1,0], ΔC=[10,0.02,-0.05], ΔD=[-0.01,0.05].
[0057] Constructing independent attention weights: Assuming that the initial attention weights are WA(0)=[0.5,0.5,0.5], WC(0)=[0.5,0.5,0.5], and WD(0)=[0.5,0.5], the attention weights are updated according to the differential features as follows: WA(1)=f([0,-0.1,0],[0.5,0.5,0.5]), WC(1)=f([10,0.02,-0.05],[0.5,0.5,0.5]), WD(1)=f([-0.01,0.05],[0.5,0.5]).
[0058] The weighted differential features generate the saliency mapping matrix: Assume that the updated attention weights are WA(1)=[0.6,0.4,0.5], WC(1)=[0.7,0.5,0.4], WD(1)=[0.5,0.6]. The weighted difference features are calculated as: ΔAweighted(1)=[0,-0.04,0], ΔCweighted(1)=[7,0.01,-0.02], ΔDweighted(1)=[-0.005,0.03].
[0059] The saliency mapping matrix is: .
[0060] This scheme can effectively capture the significant changes in the Agent layer, channel layer, and DeepFake generation layer at different time slices, and generate multi-scale saliency map matrices for further analysis. These matrices can be used as input to train higher-level detection models to identify potential attack behaviors.
[0061] S4. Construct a multi-layer heterogeneous CycleGAN network and inject the nested saliency mapping matrix.
[0062] The method of constructing a multi-layer heterogeneous CycleGAN network and injecting the nested saliency map matrix includes: Split CycleGAN into three heterogeneous branches: A, B, and C, which respectively handle DeepFake content detection, covert channel packet feature mapping, and Agent behavior pattern analysis. The generator and discriminator in the three branches are constrained by a multi-domain interactive consistency loss function. The multi-scale saliency map matrix is injected into the generator and discriminator of branches A, B, and C to enhance the model's attention to abnormal features.
[0063] CycleGAN is split into three heterogeneous branches, A, B, and C, which handle different tasks respectively.
[0064] Branch A is used for DeepFake content detection. Its input is: original image / video frame or generated DeepFake image / video frame. The output is: binary classification result (real or fake).
[0065] Branch B is used for covert channel packet feature mapping. Input: Covert channel packet sequence. Output: Packet feature mapping (such as bit rate change, number of error packet injections, etc.).
[0066] Branch C is used for agent behavior pattern analysis. Input: Agent behavior records (such as attack strategies, role division, etc.). Output: behavior pattern classification (normal or abnormal).
[0067] Design a generator and a discriminator for each branch and constrain them through a multi-domain interaction consistency loss function. The generator is used to generate new samples (such as forged DeepFake content, simulated covert channel packets, simulated agent behavior). Discriminator: used to distinguish between real samples and generated samples. The discriminator of each branch needs to be able to accurately judge the authenticity of the input sample. The multi-domain interaction consistency loss function is used to ensure consistency and collaboration between different branches. For example, the DeepFake content generated in branch A should be consistent with the covert channel packet characteristics in branch B, and match the agent behavior pattern in branch C.
[0068] When injecting the multi-scale saliency map matrix, read the previously calculated multi-scale saliency map matrix for injection into the generator and discriminator of each branch. Specifically, it includes extracting the saliency map matrix Msig(t) of each time slice. Then, these matrices are arranged in chronological order to form a complete sequence of saliency map matrices. The saliency map matrix is embedded in the generator and discriminator of each branch to enhance the model's attention to abnormal features.
[0069] In the generator of branch A (DeepFake content detection), the saliency map matrix is used as an additional input to guide the generator to generate more realistic DeepFake content. In the discriminator of branch A, the saliency map matrix is used as an additional feature input to help the discriminator better identify fake content.
[0070] In the generator of branch B (covert channel packet feature map), the saliency map matrix is used to generate more realistic covert channel packet features. In the discriminator of branch B, the saliency map matrix is used as auxiliary information to improve the detection ability of abnormal covert channel packets.
[0071] In the generator of branch C (agent behavior pattern analysis), the saliency map matrix is used to generate more reasonable agent behavior patterns. In the discriminator of branch C, the saliency map matrix is used as an additional feature to help identify abnormal agent behavior.
[0072] Define a loss function, including consistency loss, adversarial loss, and saliency loss. Consistency loss ensures consistency and collaboration between different branches. Ensure that the outputs between different branches are consistent. For example, the DeepFake content generated by branch A should generate corresponding covert channel packet features in branch B and corresponding Agent behavior patterns in branch C. The adversarial loss uses the CycleGAN adversarial loss that has been disclosed in the art to ensure that the samples generated by the generator are as close to the real samples as possible, and the discriminator can accurately distinguish between real samples and generated samples. The saliency loss is based on the saliency mapping matrix to ensure that the generator and the discriminator pay more attention to saliency features. For example, high-value areas in the saliency mapping matrix should be given higher weights.
[0073] The final loss function is: .
[0074] in, L Cycle is the cycle consistency loss, which ensures that the generated samples can be restored to the original samples after reverse generation. L adv is the adversarial loss, which ensures that the samples generated by the generator are as close to the real samples as possible, while the discriminator can accurately distinguish between the real samples and the generated samples. Lsig is the saliency loss, which ensures that the generator and the discriminator pay more attention to the salient features.
[0075] S5. The discrimination result based on the multi-layer heterogeneous CycleGAN network is fed back to the penetration behavior map.
[0076] The method of feeding back the discrimination result of the multi-layer heterogeneous CycleGAN network to the penetration behavior map includes: Inputting the infiltration behavior map to be detected into the three branches of the multi-layer heterogeneous CycleGAN network, obtaining the detection score of each branch, and obtaining the total score according to the weighted sum of the detection scores of each branch; The discrimination results and comprehensive scores of each branch are fed back to the infiltration behavior map, and the weights in the infiltration behavior map are dynamically adjusted according to the discrimination results to obtain a new infiltration behavior map.
[0077] Input the infiltration behavior map to be detected into the multi-layer heterogeneous CycleGAN network and obtain the detection score of each branch.
[0078] The DeepFake content detection score is obtained through branch A. A binary classification score SA is output, indicating the probability that the sample is real content (a value between 0 and 1). The covert channel packet feature mapping score is obtained through branch B. A score SB is output, indicating the authenticity of the packet feature (a value between 0 and 1). The Agent behavior pattern analysis score is obtained through branch C. A score SC is output, indicating the probability that the Agent behavior pattern is normal (a value between 0 and 1).
[0079] The comprehensive score is calculated by weighted summation. Set the weights of each branch αA, αB, αC. The weights can be adjusted according to actual needs (for example, based on the importance of each branch). Calculate the comprehensive score Stotal=αAxSA+αBxSB+αCxSC.
[0080] Feedback the discrimination results and comprehensive scores to the penetration behavior map, feed back the discrimination results and comprehensive scores of each branch to the penetration behavior map, and dynamically adjust the weights in the map. For each node (Agent, channel, DeepFake generation), update the weight according to its corresponding branch score. If SA is low, it means that the node has a high risk of DeepFake content, and the abnormal weight of the node is increased. If SB is low, it means that the node has a high risk of covert channel data packets, and the abnormal weight of the node is increased. If SC is low, it means that the node has a high risk of abnormal Agent behavior, and the abnormal weight of the node is increased. Dynamically adjust the edge weights between nodes according to the comprehensive score Stotal. If the comprehensive score is low, it means that the entire penetration behavior path has a high risk, and the abnormal weights of all edges on the path are increased.
[0081] Exemplarily, the permeation behavior map data is as follows.
[0082] Node information includes: Agent nodes: a1, a2, Channel nodes: c1, c2, DeepFake generation nodes: d1, d2.
[0083] Initial weights: The initial weights of the agent nodes are: wa1=0.5, wa2=0.6, the initial weights of the channel nodes are: wc1=0.7, wc2=0.8, and the initial weights of the DeepFake generation nodes are: wd1=0.6, wd2=0.7.
[0084] Calculate the branch scores. Branch A score: SA = 0.3, which is low, indicating a risk of forged content.
[0085] Branch B score: SB = 0.8, which is relatively high, indicating that the covert channel data packet is relatively normal.
[0086] Branch C score: SC = 0.4, which is low, indicating the risk of abnormal agent behavior.
[0087] Assume that the weights are set to: αA=0.4, αB=0.3, αC=0.3, calculate the comprehensive score: Stotal=0.4×0.3+0.3×0.8+0.3×0.4=0.12+0.24+0.12=0.48.
[0088] Update the node weights. If SA=0.3 is low, increase the node weights related to DeepFake generation: d1=wd1+Δwd1. Assuming Δwd1=0.1, then wd1=0.6+0.1=0.7. If SC=0.4 is low, increase the node weights related to Agent behavior: wa1=wa1+Δwa1. Assuming Δwa1=0.1, then aw1=0.5+0.1=0.6.
[0089] Update edge weights, the comprehensive score Stotal = 0.48, which is low, indicating that the overall penetration behavior path has a high risk, and increase the abnormal weights of all edges on the path. The initial edge weights are ea1_c1 = 0.6, ec1_d1 = 0.7, and increase Δe = 0.1. Then: ea1_c1=ea1_c1+Δe=0.6+0.1=0.7, ec1_d1=ec1_d1+Δe=0.7+0.1=0.8.
[0090] The discrimination results of the multi-layer heterogeneous CycleGAN network are fed back into the penetration behavior map, and the weights in the map are dynamically adjusted according to these results to obtain a new penetration behavior map. This helps to more accurately identify and respond to potential attack behaviors.
[0091] S6. Based on the time-series backtracking reinforcement strategy, an online adaptive detection mechanism is established for the penetration behavior map to detect deep fake attacks.
[0092] Based on the time-series backtracking reinforcement strategy, an online adaptive detection mechanism is established for the penetration behavior map to detect deep fake attacks, including: Collect real-time data of network traffic, Agent behavior logs, and covert channel data, and obtain the penetration behavior map according to steps S1 to S5; A time series backtracking mechanism is introduced to generate a sliding window to store historical data in the recent period, and the penetration behavior map is updated according to the real-time data and the data stored in the sliding window; Inputting the infiltration behavior map into the three branches of the multi-layer heterogeneous CycleGAN network to obtain the detection score of each branch, and obtaining the total score according to the weighted sum of the detection scores of each branch; When the total score is greater than a set threshold, it is determined that a deep fake attack exists.
[0093] Collect network traffic in real time as traffic to be detected 12. Agent behavior logs and covert channel data. Capture real-time network data packets through network monitoring tools. Obtain the latest log data from the Agent's behavior recording system, including behavior type, task division, historical attack strategy, etc. Capture covert channel data packet characteristics such as bit rate changes, number of error packet injections, etc. through a dedicated covert channel monitoring tool.
[0094] Generate a sliding window to store the historical data in the recent period. Set the time length of the sliding window (for example, 5 minutes, 1 hour, etc.), and adjust the window size according to actual needs. Store the real-time collected data in the sliding window in chronological order, and update the window content regularly (that is, remove expired data and add new data).
[0095] Update the penetration behavior map according to the real-time data and the historical data stored in the sliding window. Update the nodes and edges in the above manner. Input the updated penetration behavior map into the three branches of the multi-layer heterogeneous CycleGAN network. Branch A extracts the information of nodes and edges related to DeepFake generation as input data. Branch B extracts the information of nodes and edges related to covert channels as input data. Branch C extracts the information of nodes and edges related to Agent behavior as input data. Obtain the detection score of each branch and calculate the total score. When the comprehensive score is greater than the set threshold, it is determined that a deep fake attack exists. Set a threshold T, which can be set based on historical data and experience (for example, 0.8). If Stotal>T, it is determined that a deep fake attack exists and the corresponding alarm or defense measures are triggered.
[0096] For example, network traffic: 100 packets per second, including some suspicious DeepFake video transmissions. Agent behavior log: records the behavior of two agents, one of which exhibits abnormal behavior. Covert channel data: packet sequences where covert channels are found, with a high number of error packet injections.
[0097] The time length of the sliding window is 1 hour. That is, the current window has stored data from the past 1 hour. The initial penetration behavior map is: nodes: a1, a2, c1, d1, edges: ea1_c1, ec1_d1. Update the penetration behavior map based on the new data, add a new agent node a3 and covert channel node c2. Update the weights of existing nodes, such as wa1 increases to 0.7 due to abnormal behavior.
[0098] The updated infiltration behavior map is input into the three branches of the CycleGAN network: Branch A: Detects the authenticity of DeepFake videos, with an output score of SA=0.3.
[0099] Branch B: Detect the authenticity of the covert channel packet characteristics and output score SB=0.6.
[0100] Branch C: Detects the normality of the Agent’s behavior pattern and outputs a score of SC=0.4.
[0101] Calculate the comprehensive score, assuming that the weights are αA=0.4, αB=0.3, αC=0.3, calculate the comprehensive score: Stotal=0.4×0.3+0.3×0.6+0.3×0.4=0.12+0.18+0.12=0.42. To determine whether there is a deep fake attack, the threshold T=0.8 is set in this embodiment. Stotal=0.42<0.8, it is determined that there is no deep fake attack. If in the subsequent process, as more abnormal data accumulates, the comprehensive score exceeds the set threshold, it can be determined that there is a deep fake attack and corresponding defensive measures can be taken.
[0102] On the other hand, this specification provides a multi-agent collaborative deep fake attack detection system, please refer to the attached Figure 5 ,include: The mapping module 100 constructs a multi-dimensional nested structure model including an agent layer, a channel layer, and a DeepFake generation layer. Each layer is represented by a multi-dimensional feature, and the multi-dimensional nested structure is mapped into a hierarchical graph, and the associated mapping relationship, initial state weight, and timestamp are recorded to obtain an infiltration behavior graph; The feature module 200 collects covert channel communication data and DeepFake generation data in multiple time periods, divides and annotates preset attack behaviors by time slices, compares preset indicators of adjacent time slices, and generates cross-layer differential feature vectors; The differential module 300 decouples the differential features of the agent layer, the channel layer, and the DeepFake generation layer according to the cross-layer differential feature vector, and generates a multi-scale saliency mapping matrix through a temporal differential attention mechanism; An injection module 400 constructs a multi-layer heterogeneous CycleGAN network and injects and embeds the saliency map matrix; A feedback module 500, based on the discrimination result of the multi-layer heterogeneous CycleGAN network, feeds back to the penetration behavior map; The detection module 600 establishes an online adaptive detection mechanism for the penetration behavior graph based on the time-series backtracking reinforcement strategy to realize the detection of deep fake attacks.
[0103] See also Figure 6 A schematic diagram of the structure of an electronic device provided in an embodiment of this specification is shown.
[0104] like Figure 6 As shown, the electronic device 1100 may include: at least one processor 1101, at least one network interface 1104, a user interface 1103, a memory 1105 and at least one communication bus 1102. Among them, the communication bus 1102 can be used to realize the connection and communication of the above-mentioned components. Among them, the user interface 1103 may include a button, and the optional user interface may also include a standard wired interface and a wireless interface. Among them, the network interface 1104 may include but is not limited to a Bluetooth module, an NFC module, a Wi-Fi module, etc. Among them, the processor 1101 may include one or more processing cores. The processor 1101 uses various interfaces and lines to connect various parts in the entire electronic device 1100, and executes various functions and processes data of the routing device 1100 by running or executing instructions, programs, code sets or instruction sets stored in the memory 1105, and calling data stored in the memory 1105. Optionally, the processor 1101 can be implemented in at least one hardware form of DSP, FPGA, and PLA. The processor 1101 may integrate one or a combination of CPU, GPU and modem, etc. Among them, the CPU mainly processes the operating system, user interface and application programs, etc.; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communication.
[0105] It is understandable that the above-mentioned modem may not be integrated into the processor 1101, but may be implemented by a separate chip.
[0106] Among them, the memory 1105 may include RAM or ROM. Optionally, the memory 1105 includes a non-transitory computer-readable medium. The memory 1105 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 1105 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store data involved in the above-mentioned various method embodiments, etc. The memory 1105 may also be at least one storage device located away from the aforementioned processor 1101. The memory 1105 as a computer storage medium may include an operating system, a network communication module, a user interface module and an application. The processor 1101 may be used to call the application stored in the memory 1105 and execute the methods in the above-mentioned multiple embodiments.
[0107] The embodiments of this specification also provide a computer-readable storage medium, which stores instructions, and when the instructions are executed on a computer or a processor, the computer or the processor executes the multiple steps in the above embodiments. If the components of the above electronic device are implemented in the form of software functional units and sold or used as independent products, they can be stored in the computer-readable storage medium.
[0108] The embodiments of this specification also provide a computer program product, including a computer program, which implements multiple steps in the above embodiments when executed by a processor.
[0109] In the absence of conflict, the technical features in this embodiment and implementation scheme can be combined arbitrarily.
[0110] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented by software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes a plurality of computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of this specification is generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored in a computer-readable storage medium or transmitted through the computer-readable storage medium. The computer instructions may be transmitted from a website site, a computer, a server or a data center to another website site, a computer, a server or a data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or a data center that includes multiple available media integrated. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a digital versatile disc (DVD)), or a semiconductor medium (eg, a solid state drive (SSD)).
[0111] When implemented by hardware or firmware, the aforementioned method flow is programmed into the hardware circuit to obtain the corresponding hardware circuit structure and realize the corresponding function. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit, and its logic function is determined by the user programming the device. The designer programs by himself to "integrate" a digital system on a PLD, without asking a chip manufacturer to design and make a dedicated integrated circuit chip. Moreover, nowadays, instead of manually making integrated circuit chips, this programming is mostly implemented by "logic compiler" software, which is similar to the software compiler used when writing program development, and the original code before compilation must also be written in a specific programming language, which is called hardware description language (HDL), and HDL is not just one, but many. Those skilled in the art should also be aware that it is only necessary to program the method flow slightly in the above-mentioned hardware description languages and program it into the integrated circuit to easily obtain the hardware circuit that implements the logic method flow.
[0112] The embodiments described above are merely preferred embodiments of this specification and are not intended to limit the scope of this specification. Without departing from the design spirit of this specification, various modifications and improvements made to the technical solutions of this specification by ordinary technicians in this field should fall within the scope of protection determined by the claims of this specification.
Claims
1. A method for detecting deep fake attacks by multi-agent collaboration, characterized in that: Includes steps: S1. Construct a multi-dimensional nested structure model including an agent layer, a channel layer, and a DeepFake generation layer. Each layer is represented by a multi-dimensional feature. The multi-dimensional nested structure is mapped into a hierarchical graph, and the associated mapping relationship, initial state weight, and timestamp are recorded to obtain an infiltration behavior graph. S2. Collect covert channel communication data and DeepFake generation data in multiple time periods, divide them into time slices and mark preset attack behaviors, compare the preset indicators of adjacent time slices, and generate cross-layer differential feature vectors; S3. Decouple the differential features of the Agent layer, the channel layer, and the DeepFake generation layer according to the cross-layer differential feature vector, and generate a multi-scale saliency mapping matrix through a temporal differential attention mechanism; S4, constructing a multi-layer heterogeneous CycleGAN network and injecting the nested saliency mapping matrix; S5. Feedback the discrimination result based on the multi-layer heterogeneous CycleGAN network to the penetration behavior map; S6. Based on the time-series backtracking reinforcement strategy, an online adaptive detection mechanism is established for the penetration behavior map to detect deep fake attacks.
2. The method for detecting a multi-agent collaborative deep fake attack according to claim 1, characterized in that: Methods for generating cross-layer differential feature vectors include: Collect data from actual attack traffic and extract covert channel layer features and DeepFake generation layer features respectively, divide them into multiple time slices according to timestamps, and mark preset key behaviors; Based on the feature comparison of adjacent time slices, the differential features of the hidden channel layer features and the DeepFake generation layer features are calculated; The differential features of the hidden channel layer and the DeepFake generation layer are combined to form a cross-layer differential feature vector.
3. The method for detecting a multi-agent collaborative deep fake attack according to claim 2, characterized in that: Methods for generating a multi-scale saliency map matrix include: Obtain the behavioral characteristics of the Agent layer in each time slice, collect the changes in the preset feature quantities of the covert channel in different time slices, and record the changes in the preset feature quantities of the DeepFake generation layer in different time slices; Construct independent attention weights for the agent layer, channel layer, and DeepFake generation layer respectively, and adjust the attention weights by comparing the differential features of adjacent time slices; A multi-scale saliency map matrix is generated according to the differential features weighted by the attention weights.
4. The method for detecting a multi-agent collaborative deep fake attack according to claim 3, characterized in that: The method of constructing a multi-layer heterogeneous CycleGAN network and injecting the nested saliency map matrix includes: Split CycleGAN into three heterogeneous branches: A, B, and C, which respectively handle DeepFake content detection, covert channel packet feature mapping, and Agent behavior pattern analysis. The generator and discriminator in the three branches are constrained by a multi-domain interactive consistency loss function. The multi-scale saliency map matrix is injected into the generator and discriminator of branches A, B, and C to enhance the model's attention to abnormal features.
5. The method for detecting a multi-agent collaborative deep fake attack according to claim 4, characterized in that: The method of feeding back the discrimination result of the multi-layer heterogeneous CycleGAN network to the penetration behavior map includes: Inputting the infiltration behavior map to be detected into the three branches of the multi-layer heterogeneous CycleGAN network, obtaining the detection score of each branch, and obtaining the total score according to the weighted sum of the detection scores of each branch; The discrimination results and comprehensive scores of each branch are fed back to the infiltration behavior map, and the weights in the infiltration behavior map are dynamically adjusted according to the discrimination results to obtain a new infiltration behavior map.
6. The method for detecting a multi-agent collaborative deep fake attack according to any one of claims 1 to 5, characterized in that: Based on the time-series backtracking reinforcement strategy, an online adaptive detection mechanism is established for the penetration behavior map to detect deep fake attacks, including: Collect real-time data of network traffic, Agent behavior logs, and covert channel data, and obtain the penetration behavior map according to steps S1 to S5; A time series backtracking mechanism is introduced to generate a sliding window to store historical data in the recent period, and the penetration behavior map is updated according to the real-time data and the data stored in the sliding window; Inputting the infiltration behavior map into the three branches of the multi-layer heterogeneous CycleGAN network to obtain the detection score of each branch, and obtaining the total score according to the weighted sum of the detection scores of each branch; When the total score is greater than a set threshold, it is determined that a deep fake attack exists.
7. A multi-agent collaborative deep fake attack detection system, characterized in that: include: A mapping module constructs a multi-dimensional nested structure model including an agent layer, a channel layer, and a DeepFake generation layer. Each layer is represented by a multi-dimensional feature, and the multi-dimensional nested structure is mapped into a hierarchical graph. The associated mapping relationship, initial state weight, and timestamp are recorded to obtain an infiltration behavior graph. The feature module collects covert channel communication data and DeepFake generation data in multiple time periods, divides and annotates preset attack behaviors by time slices, compares preset indicators of adjacent time slices, and generates cross-layer differential feature vectors; A differential module decouples the differential features of the agent layer, the channel layer, and the DeepFake generation layer according to the cross-layer differential feature vector, and generates a multi-scale saliency mapping matrix through a temporal differential attention mechanism; An injection module constructs a multi-layer heterogeneous CycleGAN network and injects the nested saliency map matrix; A feedback module, based on the discrimination result of the multi-layer heterogeneous CycleGAN network, feeds back to the penetration behavior map; The detection module establishes an online adaptive detection mechanism for the penetration behavior map based on the time-series backtracking reinforcement strategy to realize the detection of deep fake attacks.
8. An electronic device, characterized in that: including a processor and a memory; The processor is connected to the memory; The memory is used to store executable program code; The processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to execute the method according to any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Industrial control network APT attack detection system and method based on time sequence prediction
CN117354058A
Network security method, system and equipment based on attack address and medium
CN119182577A
Firewall attacked surface carding and security reinforcement method
CN119276632A
Power grid network attack detection method and system based on deep learning
CN119583182A
Multi-level information security policy generation method based on knowledge graph
CN119728302A
Cited By
Defense method and system for multi-agent attack in steel production environment
CN120710793A
Optical cable identity recognition and illegal access detection method and system for smart power grid
CN121690618A
Optical cable identity recognition and illegal access detection method and system for smart grid
CN121690618B