Detection Method and System for Deepfake Attacks with Multi-Agent Collaboration

By building a multi-dimensional nested structural model and a multi-layer heterogeneous CycleGAN network, combined with the timing differential attention mechanism, the problem of difficulty in identifying multi-agent collaborative attacks and deep forgery attacks in the existing technology is solved, and more accurate attack recognition and hidden channel detection are achieved.

CN119996072BActive Publication Date: 2025-06-20HANGZHOU ANQUAN DIGITAL INTELLIGENCE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510443383.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-10
Publication Date
2025-06-20
Estimated Expiration
2045-04-10

AI Technical Summary

Technical Problem

Existing network anti-penetration detection technologies are difficult to effectively identify and deal with multi-agent collaborative attacks, especially deep forgery attacks, and lack the ability to detect hidden channels.

Method used

By constructing a multi-dimensional nested structural model including the Agent layer, the channel layer and the DeepFake generation layer, hidden channel communication data and DeepFake generation data are collected, cross-layer differential feature vectors are generated, and a multi-scale significance mapping matrix is ​​generated through the timing differential attention mechanism. Then, a multi-layer heterogeneous CycleGAN network is built and a significance mapping matrix is ​​injected to establish an online adaptive detection mechanism to realize the detection of deep forgery attacks.

Benefits of technology

This method can more accurately capture the characteristics of multiple Agent coordinated attacks, improve the accuracy of deep forgery attack recognition, enhance the detection ability of hidden channels, and improve the accuracy of network attack recognition.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996072B_ABST
    Figure CN119996072B_ABST
Patent Text Reader

Abstract

Multiple embodiments of this specification relate to the field of information technology, and specifically relate to a detection method and system for deepfake attacks with multi-agent collaboration. The method includes the steps of: S1, constructing a multi-dimensional nested structure model including an Agent layer, a channel layer, and a DeepFake generation layer to obtain a penetration behavior map; S2, collecting covert channel communication data and DeepFake generation data within multiple time periods, dividing them by time slices and annotating preset attack behaviors, comparing preset metrics of adjacent time slices to generate cross-layer differential feature vectors; S3, generating a multi-scale saliency mapping matrix through a temporal difference attention mechanism; S4, constructing a multi-layer heterogeneous CycleGAN network and injecting and nesting the saliency mapping matrix; S5, based on the discrimination result of the multi-layer heterogeneous CycleGAN network, feeding back to the penetration behavior map; S6, establishing an online adaptive detection mechanism for the penetration behavior map.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Multiple embodiments of this specification relate to the field of information technology, and specifically to a method and system for detecting deepfake attacks with multi-agent collaboration. Background Art

[0002] In terms of network penetration detection, currently it mainly relies on traffic analysis, intrusion detection, intrusion prevention, and methods based on user behavior analysis. Traffic analysis monitors network traffic to find abnormal traffic patterns and detect potential attack behaviors. Intrusion detection and intrusion prevention identify known attack patterns through preset rules and signatures and make responses. Techniques based on user behavior analysis monitor the normal behavior of users, capture abnormal behaviors that deviate from the normal pattern, and thus discover potential security threats.

[0003] However, current network anti-penetration detection technologies do not achieve good results when facing more complex attack patterns. Existing detection methods usually rely on the analysis of a single dimension, such as traffic, protocol, or behavior, lacking cross-level joint analysis. In more complex multi-Agent collaborative attacks, the analysis methods for a single dimension cannot comprehensively capture the multi-party collaboration and attacks of attackers. And existing detection technologies lack the detection of covert channels. Covert channels often become the means for attackers to bypass detection and achieve penetration. Attackers use covert channels for data theft or remote control, and covert channels cannot be effectively detected by existing IDS or IPS technologies. Current network defense systems rely on static rules or signature matching, which makes it impossible for network defense systems to respond in a timely manner when facing new and constantly changing attack strategies.

[0004] With the progress of AI technology, the emergence of multi-Agent collaborative attacks makes it more difficult for existing technologies to effectively deal with network attacks. When attackers use multiple collaborating AI Agents to conduct attacks, existing detection systems will be very difficult to effectively identify and intercept these attacks. The attacks by multiple collaborating AI Agents are highly concealed and complex. Each Agent plays different roles at different attack stages, such as generating false identity information (DeepFake), or conducting network-side penetration and lateral movement. Existing security protection systems usually can only detect the behavior of a single attacker and lack the overall analysis ability for the behavior of multiple collaborating Agents. Therefore, new network attack protection technologies need to be studied. Summary of the Invention

[0005] Multiple embodiments of this specification describe a method and system for detecting deepfake attacks with multi-agent collaboration.

[0006] First aspect, an embodiment of this specification provides a detection method for deepfake attacks with multi-agent collaboration, including the steps:

[0007] S1. Construct a multi-dimensional nested structure model including an Agent layer, a channel layer, and a DeepFake generation layer. Each layer is represented by multi-dimensional features. Map the multi-dimensional nested structure into a hierarchical graph, and record the association mapping relationship, initial state weights, and timestamps to obtain a penetration behavior graph;

[0008] S2. Collect covert channel communication data and DeepFake generation data within multiple time periods. Divide them by time slices and label preset attack behaviors. Compare the preset metrics of adjacent time slices to generate cross-layer differential feature vectors;

[0009] S3. According to the cross-layer differential feature vectors, decouple the differential features of the Agent layer, the channel layer, and the DeepFake generation layer, and generate a multi-scale saliency mapping matrix through a temporal difference attention mechanism;

[0010] S4. Construct a multi-layer heterogeneous CycleGAN network and inject and nest the saliency mapping matrix;

[0011] S5. Based on the discrimination results of the multi-layer heterogeneous CycleGAN network, feedback to the penetration behavior graph;

[0012] S6. Based on a temporal backtracking reinforcement strategy, establish an online adaptive detection mechanism for the penetration behavior graph to achieve the detection of deepfake attacks. Agent refers to an intelligent agent, and CycleGAN refers to a cyclic generative adversarial network.

[0013] Second aspect, an embodiment of this specification provides a detection system for deepfake attacks with multi-agent collaboration, including:

[0014] A mapping module that constructs a multi-dimensional nested structure model including an Agent layer, a channel layer, and a DeepFake generation layer. Each layer is represented by multi-dimensional features. Map the multi-dimensional nested structure into a hierarchical graph, and record the association mapping relationship, initial state weights, and timestamps to obtain a penetration behavior graph;

[0015] A feature module that collects covert channel communication data and DeepFake generation data within multiple time periods. Divide them by time slices and label preset attack behaviors. Compare the preset metrics of adjacent time slices to generate cross-layer differential feature vectors;

[0016] A differential module that decouples the differential features of the Agent layer, the channel layer, and the DeepFake generation layer according to the cross-layer differential feature vectors, and generates a multi-scale saliency mapping matrix through a temporal difference attention mechanism;

[0017] An injection module that constructs a multi-layer heterogeneous CycleGAN network and injects and nests the saliency mapping matrix;

[0018] A feedback module that feeds back to the penetration behavior map based on the discrimination results of the multi-layer heterogeneous CycleGAN network;

[0019] A detection module that establishes an online adaptive detection mechanism for the penetration behavior map based on a time-series backtracking reinforcement strategy to detect deepfake attacks.

[0020] In a third aspect, an embodiment of this specification provides an electronic device, including a processor and a memory;

[0021] The processor is connected to the memory;

[0022] The memory is used to store executable program code;

[0023] The processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory to execute the method described in any of the above aspects.

[0024] In a fourth aspect, an embodiment of this specification provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the method described in any of the above aspects is implemented.

[0025] In a fifth aspect, an embodiment of this specification provides a computer program product, including a computer program, and when the computer program is executed by a processor, the method described in any of the above aspects is implemented.

[0026] The beneficial effects brought by the technical solutions provided in some embodiments of this specification at least include:

[0027] In multiple embodiments of this specification, the detection method for deepfake attacks completes a more fine-grained expression of the collaborative attack behavior of multiple agents by establishing a multi-dimensional nested structure model of the Agent layer, the channel layer, and the DeepFake generation layer, and can capture the characteristics of deepfake attacks more accurately, which helps to improve the accuracy of deepfake attack recognition. The multi-scale saliency mapping matrix generated by the temporal difference attention mechanism can improve the model's attention to abnormal features, which helps to improve the accuracy of attack recognition.

[0028] Other features and advantages of multiple embodiments of this specification will be further revealed in the following detailed description and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] To more clearly illustrate the technical solutions in the embodiments of this specification, the following will briefly introduce the accompanying drawings required in the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of this specification. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.

[0030] Figure 1 It is a schematic diagram of the scenario of the deepfake attack detection method provided by the embodiments of this specification.

[0031] Figure 2 It is a schematic flowchart of the deepfake attack detection method provided by the embodiments of this specification.

[0032] Figure 3 It is a schematic flowchart of the method for generating cross-layer differential feature vectors provided by the embodiments of this specification.

[0033] Figure 4 It is a schematic flowchart of the method for generating a multi-scale saliency mapping matrix provided by the embodiments of this specification.

[0034] Figure 5 It is a schematic diagram of the deepfake attack detection system provided by the embodiments of this specification.

[0035] Figure 6 It is a schematic diagram of the electronic device provided by the embodiments of this specification. Detailed implementation manners

[0036] The following will explain and illustrate the technical solutions in the embodiments of this specification with reference to the accompanying drawings of the embodiments of this specification. However, the following embodiments are only the preferred embodiments of this specification, not all of them. Based on the embodiments in the implementation manners, other embodiments obtained by those of ordinary skill in the art without creative efforts all fall within the protection scope of this specification.

[0037] The terms "first", "second", "third", etc. in the specification, claims and the above accompanying drawings of this specification are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products or devices.

[0038] In the following description, terms such as "inner", "outer", "upper", "lower", "left", "right", etc., which indicate orientation or positional relationship, are only for the convenience of describing embodiments and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of this specification.

[0039] The data involved in this application are all information and data authorized by users or fully authorized by all parties, and the collection of relevant data complies with the relevant laws, regulations and standards of relevant countries and regions.

[0040] Before introducing the technical solutions described in this specification, the application scenarios of the technical solutions and related technologies are introduced.

[0041] Deepfake is a technology that uses artificial intelligence technology, especially deep learning algorithms, to create highly realistic fake images, audio or video content. This technology can synthesize the facial expressions, voices and other features of one person onto the image or video of another person, thus creating seemingly real fake content. Deepfake attacks refer to malicious behaviors using this technology, such as identity theft, where fake videos or audio of others are created through deepfake technology for illegal activities such as fraud. Information misdirection, in the fields of politics, business competition, etc., using deepfake content to spread false information to achieve the purpose of manipulating public opinion. Invasion of personal privacy, synthesizing someone's facial features into other videos without consent, especially in inappropriate scenarios, which violates the privacy of others. In the face of the risks of deepfake attacks, it is important to raise public awareness of this technology and take measures to enhance the ability to identify such fake content.

[0042] The deepfake attack with multi-agent collaboration is a more complex and advanced form of cyber attack, which combines deepfake technology and the capabilities of multi-agent systems (MAS). In this attack mode, multiple autonomous or semi-autonomous software agents (i.e., agents) work together to generate highly realistic fake content using deepfake technology for the purpose of deception, misdirection or destruction.

[0043] The attack mechanisms include division of labor and cooperation. Different agents can be designed to be specifically responsible for specific tasks. For example, one agent is responsible for collecting target information, another agent focuses on generating deepfake content, and another agent may be responsible for spreading this content. Adaptive learning, through machine learning algorithms, agents can continuously learn and adapt to environmental changes, optimize their behavioral strategies, and improve the authenticity and dissemination efficiency of fake content. Distributed execution, this kind of attack is usually not carried out in a centralized manner, but is implemented by multiple agents distributed in different locations, which increases the difficulty of detection and defense.

[0044] In complex multi-Agent collaborative attacks, single-dimensional detection methods cannot comprehensively capture the multi-party collaboration and attack means of attackers. Secondly, existing systems usually ignore the existence of covert channels, which often become the main means for attackers to bypass detection and achieve penetration. For this reason, this specification proposes a detection method for deepfake attacks with multi-agent collaboration. Please refer to the appendix Figure 1 , first read the historical attack traffic 11, generate cross-layer differential feature vectors and label preset attack behaviors, and then establish a multi-scale saliency mapping matrix. After establishing a multi-layer heterogeneous CycleGAN network for discrimination, update the multi-dimensional nested structure model. The updated multi-dimensional nested structure model can extract multi-dimensional features of the traffic to be detected 12 and obtain a penetration behavior map. Through the recognition results of the penetration behavior map by the multi-layer heterogeneous CycleGAN network, the detection results of deepfake attacks are obtained.

[0045] Specifically, please refer to the appendix Figure 2 , this specification first provides a detection method for deepfake attacks with multi-agent collaboration, including the steps of:

[0046] S1. Construct a multi-dimensional nested structure model including an Agent layer, a channel layer, and a DeepFake generation layer. Each layer is represented by multi-dimensional features, map the multi-dimensional nested structure into a hierarchical map, and record the association mapping relationship, initial state weight, and time stamp to obtain a penetration behavior map.

[0047] The Agent layer is used to obtain the entity set of the Agent layer and define multi-dimensional feature vectors for each Agent. Number the Agents participating in the attack and construct an Agent entity set.

[0048] The process of constructing the Agent layer includes: collecting attribute information such as the behavior type (such as penetration, lateral movement), historical attack strategies, and task division of each Agent. Represent this information as a feature vector A = , The type code indicating whether to undertake the DeepFake generation behavior, The comprehensive value of past attack strategies, The division level in the multi-Agent collaborative environment.

[0049] The channel layer is used to obtain the entity set of physical or logical channels and define multi-dimensional feature vectors for each channel. The process of constructing the channel layer includes: numbering all possible channels for covert transmission and constructing a channel entity set. Collect the bit rate changes, time domain features, and error packet injection method information of each channel at different time periods. Represent this information as a feature vector C = , where represents the average transmission bit rate, represents the number of error packet injections occurring within a unit of time, represents the time-domain change rate.

[0050] The DeepFake generation layer is used to obtain the source entity information of the forged content in the DeepFake generation layer and define a multi-dimensional generation feature vector for it. The process of constructing the DeepFake generation layer includes: numbering the DeepFake forgery sources and constructing a DeepFake entity set. Collecting the specific forgery means (voice, video, or text) and dynamic generation quality indicators of each DeepFake entity. Representing this information as a feature vector D = , where represents the content type encoding (voice, video, or text), represents the generation quality score (comprehensively quantified based on audio-video resolution, distortion, naturalness of forged text, etc.), represents the dynamic generation rate within a unit of time.

[0051] S2. Collect the covert channel communication data and DeepFake generation data over multiple time periods, divide them into time slices and label the preset attack behaviors, and compare the preset metrics of adjacent time slices to generate a cross-layer differential feature vector.

[0052] Divide the collected data into time slices, and select an appropriate time slice length according to actual needs, such as a time slice of every 5 minutes, every hour, every day, etc. Label whether there is a preset attack behavior in the data within each time slice. Define the criteria for preset attack behaviors, such as abnormal bit rate changes, sudden increases in the number of error packet injections, sudden changes in the DeepFake generation rate, etc. Manually or automatically label the data within each time slice to mark whether there is a preset attack behavior.

[0053] Please refer to Appendix Figure 3 , and the method for generating the cross-layer differential feature vector includes:

[0054] S21. Collect data from the actual attack traffic and extract the covert channel layer features and DeepFake generation layer features respectively, divide them into multiple time slices according to the timestamps, and label the preset key behaviors.

[0055] Monitor the covert channel within each time period and record the following information: bit rate change (i.e., transmission rate), number of error packet injections, time-domain features (such as transmission delay, fluctuation situation).

[0056] S22. Calculate the differential features of the steganographic channel layer features and the DeepFake generation layer features based on the feature comparison of adjacent time slices. Collect the data generated by DeepFake over multiple time periods. Record the DeepFake generation situation for each time period, including: the type of generated content (voice, video, text), the dynamic generation quality metrics (resolution, distortion, naturalness, etc.), and the dynamic generation rate per unit time.

[0057] S23. Combine the differential features of the steganographic channel layer and the DeepFake generation layer to form a cross-layer differential feature vector.

[0058] For steganographic channel communication data, calculate the difference in bit rate change Δcrate between adjacent time slices, calculate the difference in the number of error packet injections Δcerror between adjacent time slices, and calculate the change in time domain features Δcspeed between adjacent time slices. For DeepFake generated data, calculate the change in generated content quality Δdquality between adjacent time slices, and then calculate the change in generation rate Δdrate between adjacent time slices. Combine the differences between steganographic channel and DeepFake generated data to generate a cross-layer differential feature vector. Construct the differential feature vector Δ = [Δcrate, Δcerror, Δcspeed, Δdquality, Δdrate].

[0059] Exemplarily, time period 1 (0:00 - 1:00):

[0060] Steganographic channel data:

[0061] crate = 100, cerror = 0.05, cspeed = 0.9,

[0062] DeepFake generated data: dquality = 0.95, drate = 0.8.

[0063] Time period 2 (1:00 - 2:00):

[0064] Steganographic channel data: crate = 110, cerror = 0.07, cspeed = 0.85,

[0065] DeepFake generated data: dquality = 0.94, drate = 0.85.

[0066] Perform the following steps in sequence:

[0067] Time slice division. Assume that each time period is 1 hour and no further division is required.

[0068] Label the preset attack behaviors. Assume that there are no attack behaviors in time period 1 and potential attack behaviors exist in time period 2.

[0069] Calculate the differences in preset metrics for adjacent time slices:

[0070] Δcrate = 110 - 100 = 10,

[0071] Δcerror = 0.07 - 0.05 = 0.02,

[0072] Δcspeed = 0.85 - 0.9 = -0.05,

[0073] Δdquality = 0.94 - 0.95 = -0.01,

[0074] Δdrate = 0.85 - 0.8 = 0.05.

[0075] Finally, generate a cross-layer differential feature vector: Δ = [10, 0.02, -0.05, -0.01, 0.05].

[0076] S3. According to the cross-layer differential feature vector, decouple the differential features of the Agent layer, the channel layer, and the DeepFake generation layer, and generate a multi-scale saliency mapping matrix through a temporal difference attention mechanism.

[0077] Please refer to the appendix Figure 4 , the method for generating a multi-scale saliency mapping matrix includes:

[0078] S31. Obtain the behavior features within each time slice. For the Agent layer, obtain the behavior features of the Agent within each time slice. Specifically, it includes collecting attribute information such as the behavior type (e.g., infiltration, lateral movement), historical attack strategies, and task division of the Agent within each time slice. Calculate the differential feature vector ΔA = [Δatype, Δastrategy, Δarole] between adjacent time slices. For the channel layer, obtain the change amount of the preset feature quantity of the covert channel at different time slices. Specifically, it includes collecting features such as the change in code rate, the number of error packet injections, and transmission delay within each time slice. Calculate the differential feature vector ΔC = [Δcrate, Δcerror, Δcspeed] between adjacent time slices. For the DeepFake generation layer, record the change amount of the preset feature quantity of the DeepFake generation layer at different time slices. Specifically, it includes collecting features such as the content quality score and the dynamic generation rate per unit time within each time slice. Calculate the differential feature vector ΔD = [Δdquality, Δdrate] between adjacent time slices.

[0079] S32. Construct independent attention weights for the Agent layer, the channel layer, and the DeepFake generation layer respectively, and adjust the attention weights by comparing the differential features of adjacent time slices.

[0080] Construct independent attention weights. First, initialize the attention weights, that is, construct initial attention weights for the Agent layer, the channel layer, and the DeepFake generation layer respectively. Set the initial attention weight vectors WA, WC, WD, which can be initialized to a uniform distribution or set based on prior knowledge.

[0081] Then adjust the attention weights, and adjust the attention weights by comparing the differential features of adjacent time slices. Specifically, it includes calculating the update of the attention weights using the temporal difference attention mechanism:

[0082]

[0083] where f() is a non-linear function (such as the Sigmoid function or the ReLU function), which is used to update the attention weights according to the differential features of the current time slice. t represents the time slice identifier.

[0084] S33. Generate a multi-scale saliency mapping matrix based on the differential features weighted by the attention weights.

[0085] Perform weighted processing on the differential features of each time slice:

[0086] ,

[0087] where ⊙ represents element-wise multiplication. Integrate the weighted differential features into a multi-scale saliency mapping matrix. Arrange the weighted differential features of each time slice in chronological order to form a saliency mapping matrix:

[0088]

[0089] t1, t2, …, tn represent the time slice subscripts.

[0090] Exemplarily, obtain the behavioral features within each time slice:

[0091] Obtain the behavioral features within each time slice, ΔA = [0, -0.1, 0], ΔC = [10, 0.02, -0.05], ΔD = [-0.01, 0.05].

[0092] Construct independent attention weights:

[0093] Assume the initial attention weights are WA(0)=[0.5,0.5,0.5], WC(0)=[0.5,0.5,0.5], WD(0)=[0.5,0.5]. Update the attention weights according to the differential features as follows:

[0094] WA(1)=f([0,-0.1,0],[0.5,0.5,0.5]),

[0095] WC(1)=f([10,0.02,-0.05],[0.5,0.5,0.5]),

[0096] WD(1)=f([-0.01,0.05],[0.5,0.5]).

[0097] Generate the saliency mapping matrix from the weighted differential features:

[0098] Assume the updated attention weights are WA(1)=[0.6,0.4,0.5], WC(1)=[0.7,0.5,0.4], WD(1)=[0.5,0.6]. Calculate the weighted differential features as: ΔAweighted(1)=[0,-0.04,0], ΔCweighted(1)=[7,0.01,-0.02], ΔDweighted(1)=[-0.005,0.03].

[0099] The saliency mapping matrix is:

[0100] .

[0101] This solution can effectively capture the significant changes in the Agent layer, channel layer, and DeepFake generation layer at different time slices and generate a multi-scale saliency mapping matrix for further analysis. These matrices can be used as inputs to train higher-level detection models to identify potential attack behaviors.

[0102] S4. Construct a multi-layer heterogeneous CycleGAN network and inject and nest the saliency mapping matrix.

[0103] The method of constructing a multi-layer heterogeneous CycleGAN network and injecting and nesting the saliency mapping matrix includes:

[0104] Split CycleGAN into three heterogeneous branches, A, B, and C, to process DeepFake content detection, covert channel packet feature mapping, and Agent behavior pattern analysis respectively. The generators and discriminators in the three branches are constrained by a multi-domain interaction consistency loss function;

[0105] Inject the multi-scale saliency mapping matrix into the generators and discriminators of branches A, B, and C to enhance the model's attention to abnormal features.

[0106] Split CycleGAN into three heterogeneous branches, A, B, and C, to handle different tasks respectively.

[0107] Branch A is used for DeepFake content detection. Its input is: the original image / video frame or the generated DeepFake image / video frame. The output is: a binary classification result (real or fake).

[0108] Branch B is used for the feature mapping of steganographic channel data packets. Input: the data packet sequence of the steganographic channel. Output: the data packet feature mapping (such as bit rate change, number of error packet injections, etc.).

[0109] Branch C is used for Agent behavior pattern analysis. Input: the behavior records of the Agent (such as attack strategies, role divisions, etc.). Output: the behavior pattern classification (normal or abnormal).

[0110] Design generators and discriminators for each branch and constrain them through a multi-domain interaction consistency loss function. The generator is used to generate new samples (such as forging DeepFake content, simulating steganographic channel data packets, simulating Agent behavior). Discriminator: used to distinguish real samples from generated samples. The discriminator of each branch needs to be able to accurately judge the authenticity of the input samples. The multi-domain interaction consistency loss function is used to ensure the consistency and collaborative work between different branches. For example, the DeepFake content generated in branch A should be consistent with the steganographic channel data packet features in branch B and match the Agent behavior pattern in branch C.

[0111] When injecting the multi-scale saliency mapping matrix, read the previously calculated multi-scale saliency mapping matrix for injection into the generators and discriminators of each branch. Specifically, it includes extracting the saliency mapping matrix Msig(t) for each time slice. Then arrange these matrices in chronological order to form a complete sequence of saliency mapping matrices. Embed the saliency mapping matrix into the generators and discriminators of each branch to enhance the model's attention to abnormal features.

[0112] In the generator of branch A (DeepFake content detection), use the saliency mapping matrix as an additional input to guide the generator to generate more realistic DeepFake content. In the discriminator of branch A, use the saliency mapping matrix as an additional feature input to help the discriminator better identify forged content.

[0113] In the generator of Branch B (covert channel packet feature mapping), a saliency mapping matrix is used to generate more realistic covert channel packet features. In the discriminator of Branch B, the saliency mapping matrix is used as auxiliary information to improve the detection ability for abnormal covert channel packets.

[0114] In the generator of Branch C (Agent behavior pattern analysis), a saliency mapping matrix is used to generate more reasonable Agent behavior patterns. In the discriminator of Branch C, the saliency mapping matrix is used as an additional feature to help identify abnormal Agent behaviors.

[0115] Define a loss function, including consistency loss, adversarial loss, and saliency loss. The consistency loss ensures the consistency and collaborative work between different branches. Ensure the output between different branches is consistent. For example, the DeepFake content generated by Branch A should generate corresponding covert channel packet features in Branch B and corresponding Agent behavior patterns in Branch C. The adversarial loss adopts the publicly disclosed CycleGAN adversarial loss in the field to ensure that the samples generated by the generator are as close as possible to the real samples, while the discriminator can accurately distinguish between real samples and generated samples. The saliency loss is based on the saliency mapping matrix to ensure that the generator and discriminator pay more attention to the salient features. For example, higher weights should be assigned to the high-value regions in the saliency mapping matrix.

[0116] The final loss function is: .

[0117] where L cycle is the cycle consistency loss, ensuring that the generated samples can be restored to the original samples after reverse generation. L adv is the adversarial loss, ensuring that the samples generated by the generator are as close as possible to the real samples, while the discriminator can accurately distinguish between real samples and generated samples. Lsig is the saliency loss, ensuring that the generator and discriminator pay more attention to the salient features.

[0118] S5. Feedback the discrimination result based on the multi-layer heterogeneous CycleGAN network to the penetration behavior map.

[0119] The method for feeding back the discrimination result based on the multi-layer heterogeneous CycleGAN network to the penetration behavior map includes:

[0120] Input the penetration behavior map to be detected into the three branches of the multi-layer heterogeneous CycleGAN network, obtain the detection scores of each branch, and obtain the total score according to the weighted sum of the detection scores of each branch;

[0121] Feed the discrimination results and comprehensive scores of each branch back to the penetration behavior graph, and dynamically adjust the weights in the penetration behavior graph according to the discrimination results to obtain a new penetration behavior graph.

[0122] Input the penetration behavior graph to be detected into a multi-layer heterogeneous CycleGAN network. Obtain the detection scores of each branch.

[0123] Obtain the DeepFake content detection score through Branch A. Output a binary classification score SA, representing the probability that the sample is real content (a value between 0 and 1). Obtain the hidden channel packet feature mapping score through Branch B. Output a score SB, representing the authenticity of the packet features (a value between 0 and 1). Obtain the Agent behavior pattern analysis score through Branch C. Output a score SC, representing the probability that the Agent behavior pattern is normal (a value between 0 and 1).

[0124] Calculate the comprehensive score through weighted summation. Set the weights αA, αB, αC for each branch. The weights can be adjusted according to actual needs (e.g., based on the importance of each branch). Calculate the comprehensive score Stotal = αA × SA + αB × SB + αC × SC.

[0125] Feed the discrimination results and comprehensive scores back to the penetration behavior graph. Feed the discrimination results and comprehensive scores of each branch back to the penetration behavior graph, and dynamically adjust the weights in the graph. For each node (Agent, channel, DeepFake generation), update the weights according to its corresponding branch score. If SA is low, it means the risk of DeepFake content at this node is high, and increase the abnormal weight of this node. If SB is low, it means the risk of hidden channel packets at this node is high, and increase the abnormal weight of this node. If SC is low, it means the risk of abnormal Agent behavior at this node is high, and increase the abnormal weight of this node. Dynamically adjust the edge weights between nodes according to the comprehensive score Stotal. If the comprehensive score is low, it means the entire penetration behavior path has a high risk, and increase the abnormal weights of all edges on the path.

[0126] Exemplarily, the penetration behavior graph data is as follows.

[0127] The node information includes:

[0128] Agent nodes: a1, a2,

[0129] Channel nodes: c1, c2,

[0130] DeepFake generation nodes: d1, d2.

[0131] Initial weights:

[0132] Initial weights of Agent nodes: wa1 = 0.5, wa2 = 0.6, initial weights of channel nodes: wc1 = 0.7, wc2 = 0.8, initial weights of DeepFake generation nodes: wd1 = 0.6, wd2 = 0.7.

[0133] Calculate the branch scores. Score of branch A: SA = 0.3, which is relatively low, indicating a risk of forged content.

[0134] Score of branch B: SB = 0.8, which is relatively high, indicating that the steganographic channel data packets are normal.

[0135] Score of branch C: SC = 0.4, which is relatively low, indicating a risk of abnormal Agent behavior.

[0136] Assume the weights are set as: αA = 0.4, αB = 0.3, αC = 0.3. Calculate the comprehensive score: Stotal = 0.4×0.3 + 0.3×0.8 + 0.3×0.4 = 0.12 + 0.24 + 0.12 = 0.48.

[0137] Update the node weights. If SA = 0.3 is relatively low, increase the weights of the nodes related to DeepFake generation: d1 = wd1 + Δwd1. Assume Δwd1 = 0.1, then wd1 = 0.6 + 0.1 = 0.7. If SC = 0.4 is relatively low, increase the weights of the nodes related to Agent behavior: wa1 = wa1 + Δwa1. Assume Δwa1 = 0.1, then aw1 = 0.5 + 0.1 = 0.6.

[0138] Update the edge weights. The comprehensive score Stotal = 0.48, which is relatively low, indicating a relatively high risk in the overall penetration behavior path. Increase the abnormal weights of all edges on the path. The initial edge weights are ea1_c1 = 0.6, ec1_d1 = 0.7, increase Δe = 0.1. Then:

[0139] ea1_c1 = ea1_c1 + Δe = 0.6 + 0.1 = 0.7, ec1_d1 = ec1_d1 + Δe = 0.7 + 0.1 = 0.8.

[0140] Feed back the discrimination results of the multi - layer heterogeneous CycleGAN network into the penetration behavior graph, and dynamically adjust the weights in the graph according to these results, so as to obtain a new penetration behavior graph. This helps to more accurately identify and respond to potential attack behaviors.

[0141] S6. Based on the time - series backtracking reinforcement strategy, establish an online adaptive detection mechanism for the penetration behavior graph to realize the detection of deep - fake attacks.

[0142] A method for establishing an online adaptive detection mechanism for the penetration behavior graph based on a time-series backtracking reinforcement strategy to detect deepfake attacks includes:

[0143] Collect real-time data of network traffic, Agent behavior logs, and covert channel data, and obtain a penetration behavior graph according to steps S1 to S5;

[0144] Introduce a time-series backtracking mechanism to generate a sliding window to store historical data within a recent period of time, and update the penetration behavior graph according to the real-time data and the data stored in the sliding window;

[0145] Input the penetration behavior graph into the three branches of the multi-layer heterogeneous CycleGAN network to obtain the detection scores of each branch, and obtain the total score according to the weighted sum of the detection scores of each branch;

[0146] When the total score is greater than a set threshold, it is determined that there is a deepfake attack.

[0147] Real-time collect network traffic as the traffic to be detected 12, Agent behavior logs, and covert channel data. Capture real-time network data packets through a network monitoring tool. Obtain the latest log data from the Agent's behavior recording system, including behavior types, task assignments, historical attack strategies, etc. Capture the packet characteristics of the covert channel through a dedicated covert channel monitoring tool, such as bit rate changes, the number of error packet injections, etc.

[0148] Generate a sliding window to store historical data within a recent period of time. Set the time length of the sliding window (such as 5 minutes, 1 hour, etc.), and the size of the window can be adjusted according to actual needs. Store the real-time collected data in the sliding window in chronological order, and update the window content regularly (that is, remove expired data and add new data).

[0149] Update the penetration behavior graph, and update the penetration behavior graph according to the real-time data and the historical data stored in the sliding window. Update the nodes and edges in the aforementioned manner. Input the updated penetration behavior graph into the three branches of the multi-layer heterogeneous CycleGAN network. Branch A extracts the information of the nodes and edges related to DeepFake generation as input data. Branch B extracts the information of the nodes and edges related to the covert channel as input data. Branch C extracts the information of the nodes and edges related to Agent behavior as input data. Obtain the detection scores of each branch and calculate the total score. When the comprehensive score is greater than a set threshold, it is determined that there is a deepfake attack. Set a threshold T, and this threshold can be set according to historical data and experience (such as 0.8). If Stotal>T, it is determined that there is a deepfake attack and corresponding alarms or defense measures are triggered.

[0150] Exemplarily, network traffic: 100 packets per second, including some suspicious DeepFake video transmissions. Agent behavior logs: Record the behaviors of two Agents, one of which exhibits abnormal behavior. Covert channel data: A packet sequence of the covert channel is discovered, with a high number of error packet injections.

[0151] The time length of the sliding window is 1 hour. That is, the data within the past 1 hour has been stored in the current window. The initial penetration behavior graph is as follows: Nodes: a1, a2, c1, d1, Edges: ea1_c1, ec1_d1. Update the penetration behavior graph according to the new data, adding a new Agent node a3 and a covert channel node c2. Update the weights of the existing nodes, such as wa1 increasing to 0.7 due to abnormal behavior.

[0152] Input the updated penetration behavior graph into three branches of the CycleGAN network:

[0153] Branch A: Detect the authenticity of DeepFake videos, and output a score SA = 0.3.

[0154] Branch B: Detect the authenticity of the characteristics of covert channel packets, and output a score SB = 0.6.

[0155] Branch C: Detect the normality of Agent behavior patterns, and output a score SC = 0.4.

[0156] Calculate the comprehensive score. Assuming the weights are αA = 0.4, αB = 0.3, αC = 0.3, calculate the comprehensive score:

[0157] Stotal = 0.4×0.3 + 0.3×0.6 + 0.3×0.4 = 0.12 + 0.18 + 0.12 = 0.42. Determine whether there is a deepfake attack. In this embodiment, the threshold T = 0.8 is set. Stotal = 0.42 < 0.8, it is determined that there is no deepfake attack. If in the subsequent process, as more abnormal data accumulates and the comprehensive score exceeds the set threshold, it can be determined that there is a deepfake attack and corresponding defense measures are taken.

[0158] On the other hand, this specification provides a detection system for deepfake attacks with multi-agent collaboration. Please refer to the appendix Figure 5 , including:

[0159] Mapping module 100, constructing a multi-dimensional nested structure model including an Agent layer, a channel layer, and a DeepFake generation layer. Each layer is represented by multi-dimensional features, mapping the multi-dimensional nested structure into a hierarchical graph, and recording the association mapping relationship, initial state weight, and timestamp to obtain a penetration behavior graph;

[0160] The feature module 200 collects the covert channel communication data and DeepFake generation data within multiple time periods, divides them into time slices and labels the preset attack behaviors, compares the preset metrics of adjacent time slices, and generates cross-layer differential feature vectors.

[0161] The differential module 300 decouples the differential features of the Agent layer, the channel layer, and the DeepFake generation layer according to the cross-layer differential feature vectors, and generates a multi-scale saliency mapping matrix through a temporal difference attention mechanism.

[0162] The injection module 400 constructs a multi-layer heterogeneous CycleGAN network and injects and nests the saliency mapping matrix.

[0163] The feedback module 500 feeds back to the penetration behavior map based on the discrimination results of the multi-layer heterogeneous CycleGAN network.

[0164] The detection module 600 establishes an online adaptive detection mechanism for the penetration behavior map based on a temporal backtracking reinforcement strategy to realize the detection of deepfake attacks.

[0165] Please refer to Figure 6 the structural schematic diagram of an electronic device provided by the embodiments of the present specification shown.

[0166] As Figure 6As shown, the electronic device 1100 may include: at least one processor 1101, at least one network interface 1104, a user interface 1103, a memory 1105, and at least one communication bus 1102. Among them, the communication bus 1102 can be used to realize the connection and communication of the above-mentioned components. Among them, the user interface 1103 may include buttons, and the optional user interface may further include a standard wired interface and a wireless interface. Among them, the network interface 1104 may include, but is not limited to, a Bluetooth module, an NFC module, a Wi-Fi module, etc. Among them, the processor 1101 may include one or more processing cores. The processor 1101 connects various parts within the entire electronic device 1100 through various interfaces and lines, and executes various functions of the routing device 1100 and processes data by running or executing instructions, programs, code sets, or instruction sets stored in the memory 1105, and by calling the data stored in the memory 1105. Optionally, the processor 1101 may be implemented in at least one of the hardware forms of DSP, FPGA, and PLA. The processor 1101 may integrate one or several combinations of a CPU, a GPU, and a modem, etc. Among them, the CPU mainly processes the operating system, the user interface, and application programs, etc.; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communication.

[0167] It can be understood that the above-mentioned modem may not be integrated into the processor 1101 and may be implemented separately by a chip.

[0168] Among them, the memory 1105 may include RAM and may also include ROM. Optionally, the memory 1105 includes a non-transitory computer-readable medium. The memory 1105 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 1105 may include a program storage area and a data storage area. Among them, the program storage area may store instructions for implementing the operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned method embodiments, etc.; the data storage area may store the data involved in the above-mentioned method embodiments. Optionally, the memory 1105 may further be at least one storage device located far from the aforementioned processor 1101. The memory 1105, as a computer storage medium, may include an operating system, a network communication module, a user interface module, and application programs. The processor 1101 can be used to call the application programs stored in the memory 1105 and execute the methods in the above-mentioned multiple embodiments.

[0169] The embodiments of this specification also provide a computer-readable storage medium. Instructions are stored in the computer-readable storage medium. When the instructions run on a computer or a processor, the computer or the processor is caused to execute multiple steps in the above embodiments. If each component module of the above electronic device is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in the computer-readable storage medium.

[0170] The embodiments of this specification also provide a computer program product, including a computer program. When the computer program is executed by a processor, multiple steps in the above embodiments are implemented.

[0171] Without conflict, the technical features in this embodiment and the implementation solutions can be combined arbitrarily.

[0172] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes multiple computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of this specification are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted through the computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, Digital Subscriber Line (DSL)) or a wireless manner (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or a data center that includes multiple integrated available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a Digital Versatile Disc (DVD)), or a semiconductor medium (for example, a Solid State Disk (SSD)), etc.

[0173] When implemented through hardware or firmware, the foregoing method flow is programmed into a hardware circuit to obtain a corresponding hardware circuit structure and implement corresponding functions. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit, and its logic function is determined by a user's programming of the device. A designer can program on their own to "integrate" a digital system on a PLD, without having to ask a chip manufacturer to design and fabricate a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compiler used in program development and writing. The original code before compilation also has to be written in a specific programming language, which is called a hardware description language (HDL), and there are not only one but many kinds of HDLs. Those skilled in the art should also be clear that as long as the method flow is slightly logically programmed using the above-mentioned several hardware description languages and programmed into an integrated circuit, it is easy to obtain a hardware circuit that implements the logical method flow.

[0174] The embodiments described above are only described in the preferred embodiment mode of this specification, and do not limit the scope of this specification. Without departing from the design spirit of this specification, various deformations and improvements made by those of ordinary skill in the art to the technical solutions of this specification shall fall within the protection scope determined by the claims of this specification.

Claims

1. A method for detecting deep fake attacks by multi-agent collaboration, characterized in that: Includes steps: S1. Construct a multi-dimensional nested structure model including an agent layer, a channel layer, and a DeepFake generation layer. Each layer is represented by a multi-dimensional feature. The multi-dimensional nested structure is mapped into a hierarchical graph, and the associated mapping relationship, initial state weight, and timestamp are recorded to obtain an infiltration behavior graph. S2. Collect covert channel communication data and DeepFake generation data in multiple time periods, divide them into time slices and mark preset attack behaviors, compare the preset indicators of adjacent time slices, and generate cross-layer differential feature vectors; S3. Decouple the differential features of the Agent layer, the channel layer, and the DeepFake generation layer according to the cross-layer differential feature vector, and generate a multi-scale saliency mapping matrix through a temporal differential attention mechanism; S4, constructing a multi-layer heterogeneous CycleGAN network and injecting the nested saliency mapping matrix; S5. Feedback the discrimination result based on the multi-layer heterogeneous CycleGAN network to the penetration behavior map; S6. Based on the time-series backtracking reinforcement strategy, an online adaptive detection mechanism is established for the penetration behavior map to detect deep fake attacks. Methods for generating cross-layer differential feature vectors include: Collect data from actual attack traffic and extract covert channel layer features and DeepFake generation layer features respectively, divide them into multiple time slices according to timestamps, and mark preset key behaviors; Based on the feature comparison of adjacent time slices, the differential features of the hidden channel layer features and the DeepFake generation layer features are calculated; Combine the differential features of the hidden channel layer and the DeepFake generation layer to form a cross-layer differential feature vector; Methods for generating a multi-scale saliency map matrix include: Obtain the behavioral characteristics of the Agent layer in each time slice, collect the changes in the preset feature quantities of the covert channel in different time slices, and record the changes in the preset feature quantities of the DeepFake generation layer in different time slices; Construct independent attention weights for the agent layer, channel layer, and DeepFake generation layer respectively, and adjust the attention weights by comparing the differential features of adjacent time slices; Generating a multi-scale saliency map matrix based on the differential features weighted by the attention weights; Based on the time-series backtracking reinforcement strategy, an online adaptive detection mechanism is established for the penetration behavior map to detect deep fake attacks, including: Collect real-time data of network traffic, Agent behavior logs, and covert channel data, and obtain the penetration behavior map according to steps S1 to S5; A time series backtracking mechanism is introduced to generate a sliding window to store historical data in the recent period, and the penetration behavior map is updated according to the real-time data and the data stored in the sliding window; Inputting the infiltration behavior map into the three branches of the multi-layer heterogeneous CycleGAN network to obtain the detection score of each branch, and obtaining the total score according to the weighted sum of the detection scores of each branch; When the total score is greater than a set threshold, it is determined that a deep fake attack exists.

2. The method for detecting a multi-agent collaborative deep fake attack according to claim 1, characterized in that: The method of constructing a multi-layer heterogeneous CycleGAN network and injecting the nested saliency map matrix includes: Split CycleGAN into three heterogeneous branches: A, B, and C, which respectively handle DeepFake content detection, covert channel packet feature mapping, and Agent behavior pattern analysis. The generator and discriminator in the three branches are constrained by a multi-domain interactive consistency loss function. The multi-scale saliency map matrix is ​​injected into the generator and discriminator of branches A, B, and C to enhance the model's attention to abnormal features.

3. The method for detecting a multi-agent collaborative deep fake attack according to claim 2, characterized in that: The method of feeding back the discrimination result of the multi-layer heterogeneous CycleGAN network to the penetration behavior map includes: Inputting the infiltration behavior map to be detected into the three branches of the multi-layer heterogeneous CycleGAN network, obtaining the detection score of each branch, and obtaining the total score according to the weighted sum of the detection scores of each branch; The discrimination results and comprehensive scores of each branch are fed back to the infiltration behavior map, and the weights in the infiltration behavior map are dynamically adjusted according to the discrimination results to obtain a new infiltration behavior map.

4. A multi-agent collaborative deep fake attack detection system, characterized in that: include: A mapping module constructs a multi-dimensional nested structure model including an agent layer, a channel layer, and a DeepFake generation layer. Each layer is represented by a multi-dimensional feature, and the multi-dimensional nested structure is mapped into a hierarchical graph. The associated mapping relationship, initial state weight, and timestamp are recorded to obtain an infiltration behavior graph. The feature module collects covert channel communication data and DeepFake generation data in multiple time periods, divides and annotates preset attack behaviors by time slices, compares preset indicators of adjacent time slices, and generates cross-layer differential feature vectors; A differential module decouples the differential features of the agent layer, the channel layer, and the DeepFake generation layer according to the cross-layer differential feature vector, and generates a multi-scale saliency mapping matrix through a temporal differential attention mechanism; An injection module constructs a multi-layer heterogeneous CycleGAN network and injects the nested saliency map matrix; A feedback module, based on the discrimination result of the multi-layer heterogeneous CycleGAN network, feeds back to the penetration behavior map; The detection module establishes an online adaptive detection mechanism for the penetration behavior graph based on the time-series backtracking reinforcement strategy to detect deep fake attacks; Methods for generating cross-layer differential feature vectors include: Collect data from actual attack traffic and extract covert channel layer features and DeepFake generation layer features respectively, divide them into multiple time slices according to timestamps, and mark preset key behaviors; Based on the feature comparison of adjacent time slices, the differential features of the hidden channel layer features and the DeepFake generation layer features are calculated; Combine the differential features of the hidden channel layer and the DeepFake generation layer to form a cross-layer differential feature vector; Methods for generating a multi-scale saliency map matrix include: Obtain the behavioral characteristics of the Agent layer in each time slice, collect the changes in the preset feature quantities of the covert channel in different time slices, and record the changes in the preset feature quantities of the DeepFake generation layer in different time slices; Construct independent attention weights for the agent layer, channel layer, and DeepFake generation layer respectively, and adjust the attention weights by comparing the differential features of adjacent time slices; Generating a multi-scale saliency map matrix based on the differential features weighted by the attention weights; Based on the time-series backtracking reinforcement strategy, an online adaptive detection mechanism is established for the penetration behavior map to detect deep fake attacks, including: Collect real-time data of network traffic, Agent behavior logs, and covert channel data, and obtain the penetration behavior map according to steps S1 to S5; A time series backtracking mechanism is introduced to generate a sliding window to store historical data in the recent period, and the penetration behavior map is updated according to the real-time data and the data stored in the sliding window; Inputting the infiltration behavior map into the three branches of the multi-layer heterogeneous CycleGAN network to obtain the detection score of each branch, and obtaining the total score according to the weighted sum of the detection scores of each branch; When the total score is greater than a set threshold, it is determined that a deep fake attack exists.

5. An electronic device, characterized in that including a processor and a memory; The processor is connected to the memory; The memory is used to store executable program code; The processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to execute the method according to any one of claims 1 to 3.

6. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 3 is implemented.

7. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 3 is implemented.

Citation Information

Patent Citations

  • Firewall attacked surface carding and security reinforcement method

    CN119276632A

  • Power grid network attack detection method and system based on deep learning

    CN119583182A