Defense method and system of active and invisible defense strategy based on artificial intelligence

By adopting an active stealth defense strategy based on artificial intelligence in network defense, the problems of high false alarm rate, lack of initiative and high artificial dependence of passive defense strategies are solved, and more efficient network security protection is achieved.

CN120017403AActive Publication Date: 2025-05-16云尖(北京)软件有限公司
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510305702.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-05-16
Estimated Expiration
2045-03-14

AI Technical Summary

Technical Problem

The existing passive defense strategies have problems such as high false positive rates, lack of initiative, high artificial dependence and inability to deal with unknown threats.

Method used

Adopt an active stealth defense strategy based on artificial intelligence, and by obtaining the data to be sent, sensitive identification, data conversion, semantic obfuscation, encryption and compression processing are performed to form the obfuscated encrypted data and send it.

Benefits of technology

Effectively block attacks, reduce manual analysis and false alarm rates, improve network security, and be able to deal with unknown threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017403A_ABST
    Figure CN120017403A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of data security, and discloses a defense method and system of an active and invisible defense strategy based on artificial intelligence, and the method comprises the steps: obtaining to-be-transmitted data of a transmitting end; performing sensitive identification on the to-be-sent data based on an artificial intelligence algorithm to obtain sensitive data corresponding to the to-be-sent data; converting the sensitive data based on a data conversion algorithm to obtain similar data; based on a confusion algorithm, taking the similar data as confusion data, and performing semantic confusion on the to-be-sent data to obtain confused data; randomly selecting an encryption algorithm from a pre-constructed encryption algorithm library, and encrypting the confused data based on the selected encryption algorithm to obtain encrypted data; compressing the encrypted data based on a compression algorithm to obtain compressed data; and sending the compressed data to a receiving end. According to the method, the to-be-sent data is mixed, encrypted and compressed, so that the network security information security and the digital security can be effectively guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of data security technology, and specifically relates to a defense method and system of an active invisible defense strategy based on artificial intelligence. Background Art

[0002] With the popularization of the Internet and the advent of the big data era, network data security has become a major issue concerning the security and development of individuals, enterprises and even countries. Ensuring network data security means protecting corporate business secrets and personal privacy from infringement.

[0003] At present, the protection of network data security mainly adopts passive defense strategies, which mainly identify potential threats and vulnerabilities through monitoring, recording and analysis, as well as take countermeasures after security incidents occur.

[0004] However, the passive defense strategy still has at least the following problems in practical application: 1. Post-event response: Passive defense strategies rely mainly on monitoring and recording, which only work after security incidents occur, rather than preventing attacks before they occur, which means that the attack may have already caused damage; 2. Lack of initiative: Since they do not actively intervene in network traffic or data transmission, passive defense strategies cannot prevent ongoing attacks and can only provide analysis and reporting after the attack occurs.

[0005] 3. Reliance on manual analysis: Passive defense systems often require security experts to analyze data and logs, which can lead to delayed responses, especially when resources are limited; 4. High false positive rate: Some passive defense systems may generate a large number of false positives, which consumes the security team’s time and resources and may cause real threats to be ignored; 5. Unable to respond to unknown threats: Passive defense strategies are usually based on known security rules and patterns, and therefore may not be able to effectively identify and defend against new or unknown attack methods.

[0006] In summary, existing passive defense strategies have problems such as high false alarm rate, lack of initiative and high dependence on manual work. Summary of the invention

[0007] The purpose of the present invention is to provide a defense method and system for an active stealth defense strategy based on artificial intelligence, so as to solve the problems of high false alarm rate, lack of initiative and high manual dependence in existing passive defense strategies.

[0008] In order to achieve the above object, the present invention adopts the following technical solutions: In a first aspect, the present invention provides a defense method of an active stealth defense strategy based on artificial intelligence, the method comprising: Get the data to be sent by the sender; Based on artificial intelligence algorithms, sensitive identification is performed on the data to be sent to obtain sensitive data corresponding to the data to be sent; Transform sensitive data based on data transformation algorithm to obtain similar data; Based on the obfuscation algorithm, similar data is used as obfuscated data to perform semantic obfuscation on the data to be sent, and the obfuscated data is obtained; Randomly select an encryption algorithm from a pre-built encryption algorithm library, and encrypt the obfuscated data based on the selected encryption algorithm to obtain encrypted data; Compressing the encrypted data based on a compression algorithm to obtain compressed data; Send the compressed data to the receiving end.

[0009] Preferably, the encryption algorithms in the encryption algorithm library include at least: SM2 algorithm, SM3 algorithm, SM4 algorithm and ZUK algorithm.

[0010] Preferably, the artificial intelligence algorithm is a deep learning algorithm; performing sensitive identification on the data to be sent based on the artificial intelligence algorithm to obtain sensitive data corresponding to the data to be sent includes: Initialize the model parameters of the deep learning algorithm; Train the model parameters of the deep learning algorithm based on the pre-built training set to obtain a trained deep learning model; The data to be sent is input into the trained deep learning model for sensitive prediction to obtain sensitive data.

[0011] Preferably, the data conversion algorithm is an improved generative adversarial network algorithm, and the sensitive data is converted based on the data conversion algorithm to obtain similar data, including: Obtain random noise, and map the random noise to the sample space of sensitive data based on the generator of the improved generative adversarial network algorithm to generate discrete data and continuous data; The discriminator based on the improved generative adversarial network algorithm optimizes the discrete data and the continuous data so that the distribution of the discrete data and the distribution of the continuous data reach the real distribution of the sensitive data, and the optimized discrete data and the continuous data are obtained; Build similar data based on optimized discrete data and continuous data.

[0012] Preferably, the generator of the improved generative adversarial network algorithm comprises: a first generator, wherein the first generator is used to: Extract the category of sensitive data and create initial discrete features based on the category of sensitive data and random noise; Encode the initial discrete features to obtain the encoding vector; Simulating the encoding vector based on a pre-constructed polynomial to obtain a parameterized vector; Calculate the distribution probability of the parameterized vector, and sample the distribution probability of the parameterized vector to obtain a probability vector; Convert the probability vector to a continuous vector; Decode the continuous vector to obtain the final discrete features; Generate discrete data based on the final discrete features.

[0013] Preferably, the generator of the improved generative adversarial network algorithm comprises: a second generator; wherein the second generator is used to: Extract the category of sensitive data, and directly map random noise into the sample space of sensitive data based on the category of sensitive data to generate continuous data.

[0014] Preferably, similar data is used as obfuscated data to perform semantic obfuscation on the data to be sent, and the obfuscated data is obtained, including: Use similar data to replace sensitive data in the data to be sent to obtain obfuscated data.

[0015] In a second aspect, the present invention provides a defense system based on an active stealth defense strategy based on artificial intelligence, which is used to implement the above-mentioned defense method based on an active stealth defense strategy based on artificial intelligence, and the system includes: A data acquisition module, used to acquire the data to be sent by the sender; A sensitive identification module is used to perform sensitive identification on the data to be sent based on an artificial intelligence algorithm to obtain sensitive data corresponding to the data to be sent; A data conversion module is used to convert sensitive data based on a data conversion algorithm to obtain similar data; A data obfuscation module is used to perform semantic obfuscation on the data to be sent based on an obfuscation algorithm and use similar data as obfuscated data to obtain obfuscated data; A data encryption module, used to randomly select an encryption algorithm from a pre-built encryption algorithm library, and encrypt the obfuscated data based on the selected encryption algorithm to obtain encrypted data; A data compression module, used to compress the encrypted data based on a compression algorithm to obtain compressed data; The data sending module is used to send the compressed data to the receiving end.

[0016] In a third aspect, the present invention provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned defense method of the active stealth defense strategy based on artificial intelligence when executing the computer program.

[0017] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the above-mentioned defense method of the active stealth defense strategy based on artificial intelligence.

[0018] Beneficial effects: 1. After acquiring the data to be sent from the sender, the present invention adopts active defense strategies such as obfuscation, encryption and compression of the data to be sent, so that attackers cannot detect the device and the protected device and network (sender), and cannot steal the transmitted data, which can effectively ensure network security information security and digital security; 2. The active defense strategy of the present invention can reduce manual analysis and reduce the false alarm rate. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The accompanying drawings are used to provide a further understanding of the embodiments of the present invention and constitute a part of the specification. Together with the following specific implementations, they are used to explain the embodiments of the present invention, but do not constitute a limitation on the embodiments of the present invention. In the accompanying drawings: Figure 1 It is a flow chart of a defense method of an active stealth defense strategy based on artificial intelligence provided by an embodiment of the present invention; Figure 2 It is a block diagram of a defense system of an active stealth defense strategy based on artificial intelligence provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the present invention will be briefly introduced below in combination with the drawings and the description of the embodiments or the prior art. Obviously, the following description of the structure of the drawings is only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. It should be noted that the description of these embodiments is used to help understand the present invention, but does not constitute a limitation of the present invention.

[0021] Embodiment 1 Figure 1It is a flowchart of a defense method based on an active stealth defense strategy of artificial intelligence provided by an embodiment of the present invention. The application scenarios of the defense method based on an active stealth defense strategy of artificial intelligence of this embodiment include: user end and defense terminal, wherein the user end includes but is not limited to mobile phones, PCs, industrial control terminals and application servers, etc., each user end deploys a defense terminal, the user terminal communicates with the corresponding defense terminal, and all defense terminals are connected through the Internet communication; the defense method based on an active stealth defense strategy of artificial intelligence of this embodiment runs on the defense terminal. The execution steps of the method on the defense terminal, such as Figure 1 As shown, the following execution steps are included: Step S10: Obtain the data to be sent from the sender. In this embodiment, when two user terminals are to communicate data, one of the user terminals is used as the sender and the other is used as the receiver; the sender sends the corresponding data to the locally deployed defense terminal, and after receiving the data, the defense terminal uses it as the data to be sent and performs subsequent obfuscation, encryption and compression on the data to be sent.

[0022] Step S20: Perform sensitivity identification on the data to be sent based on an artificial intelligence algorithm to obtain sensitive data corresponding to the data to be sent.

[0023] In this embodiment, the data to be sent contains a large amount of sensitive data, such as personal identity information, corporate financial information, and trade secrets. If these data are illegally attacked and stolen, it will lead to personal privacy infringement, economic losses, and other impacts. Therefore, it is necessary to protect these sensitive data. In this embodiment, the sensitive data in the data to be sent is identified by an artificial intelligence algorithm for subsequent processing. Among them, the artificial intelligence algorithm is a deep learning algorithm; therefore, based on the artificial intelligence algorithm, sensitive identification is performed on the data to be sent, and the sensitive data corresponding to the data to be sent is obtained, including: Step a10: Initialize the model parameters of the deep learning algorithm; the model parameters of the deep learning algorithm mainly include: weight, bias, number of layers, number of neurons in each layer and other parameters; Among them, weights In a neural network, each connection (edge) has a corresponding weight, which determines how information is transmitted in the network; Among them, each neuron usually also has a bias term, which is added to the weight and affects the activation state of the neuron; Among them, the number of neural network layers is also a hyperparameter, which determines the depth of the model.

[0024] Step a20: Train the model parameters of the deep learning algorithm based on the pre-built training set to obtain a trained deep learning model. The training set is composed of a large amount of sensitive sample data and corresponding labels, and the model parameters of the deep learning algorithm are trained using the training set.

[0025] Step a30: Input the data to be sent into the trained deep learning model for sensitivity prediction to obtain sensitive data; the trained deep learning model is mainly used to classify the data to be sent into sensitive data and non-sensitive data to achieve sensitive prediction of the data to be sent.

[0026] Step S30: Convert the sensitive data based on a data conversion algorithm to obtain similar data.

[0027] In this embodiment, by converting sensitive data into data having a certain degree of similarity with the sensitive data, also called false data, the false data can be mixed and reorganized with the sensitive data to achieve obfuscation of the sensitive data, which can effectively improve the security of the sensitive data.

[0028] In this embodiment, the method for converting sensitive data into data with a certain similarity can adopt a generative adversarial network algorithm, which includes a generator and a discriminator. The goal of the generator is to generate data that is real enough to deceive the discriminator, that is, to receive a random noise vector as input and output a data sample with a distribution similar to that of real data; the goal of the discriminator is to distinguish between real data and false data generated by the generator, that is, to receive data samples from the generator or a real data set and output a scalar indicating the probability that the sample is real data.

[0029] Since sensitive data contains discrete numerical features and continuous numerical features, and since discrete numerical features have the problem of non-differentiable processing, it is easy to cause the back propagation gradient from the discriminator to the generator to always be zero; therefore, discrete features will cause the data generated by the traditional generative adversarial network algorithm to have noise and low quality problems, and it is also easy to cause the discriminator network training to be unstable, leading to model collapse and other problems. Therefore, the data conversion algorithm of this embodiment is an improved generative adversarial network algorithm, and the improved generative adversarial network algorithm has two generators, namely a first generator and a second generator, wherein the first generator is used to convert the discrete numerical features in the sensitive data to obtain discrete data; the second generator is used to convert the continuous data features in the sensitive data to obtain continuous data.

[0030] Therefore, based on the data conversion algorithm, the sensitive data is converted to obtain similar data, including: Step b10: Obtain random noise, and map the random noise to the sample space of sensitive data based on the generator of the improved generative adversarial network algorithm to generate discrete data and continuous data.

[0031] Among them, the first generator is used to: extract the category of sensitive data, and create initial discrete features based on the category of sensitive data and random noise; wherein the random noise adopts Gaussian white noise; the category of sensitive data is, for example: financial category, trade secret category, identity information category, etc.

[0032] The initial discrete features are encoded to obtain encoding vectors. In this embodiment, a one-hot encoding algorithm is used to convert the initial discrete features into a one-hot encoding form, so that the initial discrete features are converted into a d-dimensional one-hot vector, namely, the encoding vector.

[0033] The encoding vector is simulated based on a pre-built polynomial to obtain a parameterized vector; that is, a parameterized polynomial distribution is used to simulate the one-hot vector. The parameters of the distribution can be obtained through a sigmoid function, and the input of the sigmoid function is a d-dimensional vector.

[0034] The function expression of the parameterized vector is: ; In the formula, represents the encoding vector of the i-th dimension, represents the i-th dimension parameterized vector corresponding to the i-th dimension encoding vector, represents a trainable parameter, when The closer it is to 0, the more similar the discrete data generated subsequently is to the original data; exp() represents an exponential function. Represents the continuous probability distribution probability of the i-th dimension coding vector, that is, it is calculated using the continuous probability distribution function (Gumbel).

[0035] The distribution probability of the parameterized vector is calculated, and the distribution probability of the parameterized vector is sampled to obtain a probability vector; wherein the function expression of the distribution probability of the parameterized vector is: ; In the formula, is the sigmoid function.

[0036] The probability vector is converted into a continuous vector, the continuous vector is decoded to obtain the final discrete features, and discrete data is generated based on the final discrete features.

[0037] In this embodiment, the first generator can solve the problem of non-differentiable processing of discrete numerical features, which easily causes the back propagation gradient from the discriminator to the generator to always be zero, thereby improving the stability of the discriminator network training and the generation quality of similar data.

[0038] Among them, the data processing steps of the second generator are the same as the data processing steps of the generator of the traditional generative adversarial network algorithm, that is, the second generator is used to: extract the category of sensitive data, directly map random noise to the sample space of sensitive data based on the category of sensitive data, and generate continuous data.

[0039] Step b20: Optimize the discrete data and the continuous data based on the discriminator of the improved generative adversarial network algorithm so that the distribution of the discrete data and the distribution of the continuous data reach the real distribution of the sensitive data, and obtain the optimized discrete data and the continuous data.

[0040] Step b30: construct similar data based on the optimized discrete data and continuous data.

[0041] In this embodiment, similar data can be obtained by splicing the optimized discrete data with the optimized continuous data.

[0042] Step S40: Based on the obfuscation algorithm, similar data is used as obfuscated data to perform semantic obfuscation on the data to be sent to obtain obfuscated data.

[0043] As a further optimization of this embodiment, similar data is used as obfuscated data to perform semantic obfuscation on the data to be sent to obtain obfuscated data, including: using similar data to replace sensitive data in the data to be sent to obtain obfuscated data.

[0044] Step S50: randomly select an encryption algorithm from the pre-built encryption algorithm library, and encrypt the obfuscated data based on the selected encryption algorithm to obtain encrypted data; in this embodiment, the encryption algorithm library has multiple encryption algorithms, for example, including but not limited to: SM2 algorithm, SM3 algorithm, SM4 algorithm and ZUK algorithm; each time the data is encrypted, randomly select an encryption algorithm to encrypt the obfuscated data, this method has the following advantages: 1. Enhanced security: Randomly selecting encryption algorithms can reduce attackers’ ability to predict encryption strategies, thereby improving data security. If attackers do not know which algorithm is used, they need to try multiple cracking methods, which greatly increases the difficulty of the attack.

[0045] 2. Prevent targeted attacks: Some encryption algorithms may have known vulnerabilities, and attackers may target these vulnerabilities to attack. Randomly selecting algorithms can reduce the risk of targeted attacks.

[0046] 3. Improve diversity: Using different encryption algorithms can increase the diversity of the system, so that even if an algorithm is cracked, other data will still remain safe.

[0047] 4. Prevent pattern recognition: If the same encryption algorithm is always used, recognizable patterns may be formed in the encrypted data, which may be exploited by attackers. Randomly selecting the algorithm can reduce this risk.

[0048] 5. Increased cracking costs: In order to crack data, attackers may need to try different cracking methods for each possible encryption algorithm, which will significantly increase their time and resource costs.

[0049] In this embodiment, the SM2 (ShangMi, SM for short, stands for "commercial secret") algorithm is a public key cryptographic algorithm standard issued by the China National Cryptography Administration. It is based on elliptic curve cryptography (ECC). The main components of the SM2 algorithm are as follows: Elliptic curve parameters: The SM2 algorithm defines a set of standard elliptic curve parameters, including the prime number p, the coefficients a and b of the elliptic curve equation, and the coordinates of the base point G; Key generation: The user selects a random number as the private key, and then generates the corresponding public key through point multiplication on the elliptic curve; Digital signature: Use a private key to sign a message, and the signature can be verified by a public key; Key exchange: Two users can exchange keys securely through point multiplication on elliptic curves; Encryption and decryption: Use the public key to encrypt data and the private key to decrypt data.

[0050] In this embodiment, the SM3 algorithm is a cryptographic hash algorithm standard formulated by China, and its full name is "SM3 cryptographic hash algorithm". The SM4 algorithm is a block cipher algorithm standard formulated by China, and its full name is "SM4 block cipher algorithm". Both are one of a series of cryptographic standards issued by the State Cryptography Administration (SCAM) of the People's Republic of China, and together with the SM2 elliptic curve public key cryptographic algorithm and the SM4 block cipher algorithm, they constitute China's commercial cryptographic system.

[0051] Step S60: compress the encrypted data based on a compression algorithm to obtain compressed data.

[0052] In this embodiment, the compression algorithm may adopt the bzip2 algorithm, Huffman coding and Run-Length Encoding (RLE) algorithm, and the data size is reduced by the compression algorithm to improve the efficiency of data transmission.

[0053] Step S70: Send the compressed data to the receiving end.

[0054] In this embodiment, when the compressed data is sent to the receiving end, the defense terminal at the receiving end decompresses, decrypts and deobfuscates the compressed data in sequence after receiving the compressed data to obtain the original data, that is, the data to be sent by the sending end, and then sends the original data to the corresponding user end.

[0055] The present invention adopts active defense strategies such as obfuscating, encrypting and compressing the data to be sent after obtaining the data to be sent from the sender, so that attackers cannot detect the device and the protected device and network (sender), and cannot steal the transmitted data, which can effectively ensure network security information security and digital security; and the active defense strategy of the present invention can reduce manual analysis and reduce the false alarm rate.

[0056] Embodiment 2 Figure 2 FIG. 1 is a block diagram of a defense system based on an active stealth defense strategy based on artificial intelligence provided by an embodiment of the present invention. Figure 2 As shown, this embodiment provides a defense system of an active stealth defense strategy based on artificial intelligence, which is used to implement the defense method of the active stealth defense strategy based on artificial intelligence in Embodiment 1. The system includes: A data acquisition module, used to acquire the data to be sent by the sender; A sensitive identification module is used to perform sensitive identification on the data to be sent based on an artificial intelligence algorithm to obtain sensitive data corresponding to the data to be sent; A data conversion module is used to convert sensitive data based on a data conversion algorithm to obtain similar data; A data obfuscation module is used to perform semantic obfuscation on the data to be sent based on an obfuscation algorithm and use similar data as obfuscated data to obtain obfuscated data; A data encryption module, used to randomly select an encryption algorithm from a pre-built encryption algorithm library, and encrypt the obfuscated data based on the selected encryption algorithm to obtain encrypted data; A data compression module, used to compress the encrypted data based on a compression algorithm to obtain compressed data; The data sending module is used to send the compressed data to the receiving end.

[0057] This embodiment also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the defense method of the active stealth defense strategy based on artificial intelligence in Embodiment 1 is implemented.

[0058] This embodiment also provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the defense method of the active stealth defense strategy based on artificial intelligence in Embodiment 1 is implemented.

[0059] After obtaining the data to be sent from the sender, the present invention obfuscates, encrypts and compresses the data to be sent, making it impossible for attackers to detect the device and the protected device and network (sender), and to steal the transmitted data, thereby effectively ensuring network security information security and digital security.

[0060] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.

[0061] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A system that specifies the functions of a box or multiple boxes.

[0062] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.

Claims

1. A defense method based on an active stealth defense strategy based on artificial intelligence, characterized in that: The method comprises: Get the data to be sent by the sender; Based on artificial intelligence algorithms, sensitive identification is performed on the data to be sent to obtain sensitive data corresponding to the data to be sent; Transform sensitive data based on data transformation algorithm to obtain similar data; Based on the obfuscation algorithm, similar data is used as obfuscated data to perform semantic obfuscation on the data to be sent, and the obfuscated data is obtained; Randomly select an encryption algorithm from a pre-built encryption algorithm library, and encrypt the obfuscated data based on the selected encryption algorithm to obtain encrypted data; Compressing the encrypted data based on a compression algorithm to obtain compressed data; Send the compressed data to the receiving end.

2. The defense method of the active stealth defense strategy based on artificial intelligence according to claim 1 is characterized in that: The encryption algorithms in the encryption algorithm library include at least: SM2 algorithm, SM3 algorithm, SM4 algorithm and ZUK algorithm.

3. The defense method of the active stealth defense strategy based on artificial intelligence according to claim 1 is characterized in that: The artificial intelligence algorithm is a deep learning algorithm, which performs sensitive identification on the data to be sent based on the artificial intelligence algorithm to obtain sensitive data corresponding to the data to be sent, including: Initialize the model parameters of the deep learning algorithm; Train the model parameters of the deep learning algorithm based on the pre-built training set to obtain a trained deep learning model; The data to be sent is input into the trained deep learning model for sensitive prediction to obtain sensitive data.

4. The defense method of the active stealth defense strategy based on artificial intelligence according to claim 1 is characterized in that: The data conversion algorithm is an improved generative adversarial network algorithm, which converts sensitive data based on the data conversion algorithm to obtain similar data, including: Obtain random noise, and map the random noise to the sample space of sensitive data based on the generator of the improved generative adversarial network algorithm to generate discrete data and continuous data; The discriminator based on the improved generative adversarial network algorithm optimizes the discrete data and the continuous data so that the distribution of the discrete data and the distribution of the continuous data reach the real distribution of the sensitive data, and the optimized discrete data and the continuous data are obtained; Build similar data based on optimized discrete and continuous data.

5. The defense method of the active stealth defense strategy based on artificial intelligence according to claim 4 is characterized in that: The generator of the improved generative adversarial network algorithm includes: a first generator, wherein the first generator is used to: Extract the category of sensitive data and create initial discrete features based on the category of sensitive data and random noise; Encode the initial discrete features to obtain the encoding vector; Simulating the encoding vector based on a pre-constructed polynomial to obtain a parameterized vector; Calculate the distribution probability of the parameterized vector, and sample the distribution probability of the parameterized vector to obtain a probability vector; Convert the probability vector to a continuous vector; Decode the continuous vector to obtain the final discrete features; Generate discrete data based on the final discrete features.

6. The defense method of the active stealth defense strategy based on artificial intelligence according to claim 4 is characterized in that: The generator of the improved generative adversarial network algorithm further includes: a second generator, wherein the second generator is used to: Extract the category of sensitive data, and directly map random noise into the sample space of sensitive data based on the category of sensitive data to generate continuous data.

7. The defense method of active stealth defense strategy based on artificial intelligence according to claim 1 is characterized in that: Using similar data as obfuscated data, semantic obfuscation is performed on the data to be sent, and the obfuscated data obtained includes: Use similar data to replace sensitive data in the data to be sent to obtain obfuscated data.

8. A defense system based on an active stealth defense strategy of artificial intelligence, used to implement the defense method based on an active stealth defense strategy of artificial intelligence as described in any one of claims 1 to 7, characterized in that: The system comprises: A data acquisition module, used to acquire the data to be sent by the sender; A sensitive identification module is used to perform sensitive identification on the data to be sent based on an artificial intelligence algorithm to obtain sensitive data corresponding to the data to be sent; A data conversion module is used to convert sensitive data based on a data conversion algorithm to obtain similar data; A data obfuscation module is used to perform semantic obfuscation on the data to be sent based on an obfuscation algorithm and use similar data as obfuscated data to obtain obfuscated data; A data encryption module, used to randomly select an encryption algorithm from a pre-built encryption algorithm library, and encrypt the obfuscated data based on the selected encryption algorithm to obtain encrypted data; A data compression module, used to compress the encrypted data based on a compression algorithm to obtain compressed data; The data sending module is used to send the compressed data to the receiving end.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the defense method of the active stealth defense strategy based on artificial intelligence described in any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the defense method of the active stealth defense strategy based on artificial intelligence described in any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Government affair-based sensitive data confusion encryption method and system

    CN113742763A

  • Network security protection system, method and device based on active defense strategy

    CN116471064A

  • Deep neural network decompilation defense method and system based on neural structure confusion and weight encryption

    CN118171247A

  • Data protection via attributes-based aggregation

    US20220222368A1