File data security management method and system based on artificial intelligence

Through multiple feature extraction and interaction technology based on artificial intelligence and combined with dynamic threshold identification methods, the threat of forged file operation records to data security is solved, and the accurate identification of forged operation records and data security management is achieved.

CN120068111AInactive Publication Date: 2025-05-30HUAIAN JINYUN NETWORK TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510132345.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-06
Publication Date
2025-05-30
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing data security management methods are difficult to effectively identify and prevent forged file operation records, resulting in the reliability and integrity of data security management being threatened.

Method used

Using artificial intelligence-based file data security management methods, multiple feature extraction and interaction are performed by collecting and processing file operation-related data, operating authenticity scores are calculated, and fake operation records are identified using dynamic thresholds.

Benefits of technology

It realizes accurate identification of forged operation records, improves the overall level of data security management, and enhances the reliability and integrity of data protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068111A_ABST
    Figure CN120068111A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of electric digital data processing, in particular to a file data security management method and system based on artificial intelligence. The method comprises the following steps: acquiring and processing file operation related data to obtain an operation record sequence, a file state sequence and a file state change sequence; performing multi-feature extraction on the operation record sequence and the file state change sequence to obtain an operation record feature vector, a state change feature vector and an operation mode feature vector; the multi-feature extraction comprises the steps of performing multi-feature interaction on an operation record feature vector, a state change feature vector and an operation mode feature vector to obtain a first interaction feature, a second interaction feature and a third interaction feature; and calculating an operation authenticity score according to multiple interaction characteristics, and identifying a forged operation record through the operation authenticity score and a dynamic threshold. According to the invention, the overall level of data security management can be improved by identifying the forged file operation record.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of electrical digital data processing, and specifically to a method and system for file data security management based on artificial intelligence. Background Art

[0002] With the rapid development of information technology, data security has become the core issue in the field of information management. File operation records, as an important part of data security management, are important bases for monitoring user behaviors, analyzing potential risks, and tracing the sources of events. However, forged file operation records may pose a serious threat to data security. These forged records may not only cover up actual operation behaviors, but also mislead the security management of data, thereby weakening the reliability and integrity of data protection.

[0003] Current data security management methods still have obvious deficiencies in dealing with the problem of forged file operation records. On the one hand, rule-based detection means are difficult to cover the diversity and complexity of forgery behaviors and are prone to missing hidden abnormal records; on the other hand, with the rapid growth of data volume, traditional means have limited processing capabilities when facing huge and complex file operation records. These deficiencies directly affect the data security management ability, making it difficult to detect forged records in a timely manner, thus providing opportunities for problems such as data tampering and information leakage.

[0004] In view of the impact of forged file operation records on data security, there is an urgent need for a solution that can accurately identify false records to restore the authenticity of file operation records and improve the overall level of data security management.

[0005] Therefore, a method and system for file data security management based on artificial intelligence are proposed. Summary of the Invention

[0006] The purpose of the present invention is to provide a method and system for file data security management based on artificial intelligence. By collecting and processing data related to file operations, an operation record sequence, a file status sequence, and a file status change sequence are obtained; multiple feature extractions are performed on the operation record sequence and the file status change sequence to obtain an operation record feature vector, a status change feature vector, and an operation mode feature vector; the multiple feature extractions include: performing multiple feature interactions on the operation record feature vector, the status change feature vector, and the operation mode feature vector to obtain a first interaction feature, a second interaction feature, and a third interaction feature; calculating an operation authenticity score according to the multiple interaction features, and identifying forged operation records through the operation authenticity score and a dynamic threshold. The present invention can improve the overall level of data security management by identifying forged file operation records.

[0007] To achieve the above object, the present invention provides the following technical solutions:

[0008] An artificial intelligence-based method for file data security management, comprising:

[0009] Collecting and processing the operation record data of each operation on the file and the file status data after each operation to obtain an operation record sequence and a file status sequence of the file, and extracting a file status change sequence according to the file status sequence; the operation record data includes an operation type, an operation time, operation parameters, and an operating user; the file status data includes file attribute values;

[0010] Performing multi-feature extraction on the operation record sequence and the file status change sequence to obtain an operation record feature vector, a status change feature vector, and an operation mode feature vector; the multi-feature extraction includes: respectively processing a first operation record sequence and a first file status change sequence within a first operation record window through a bidirectional long short-term memory network to obtain the operation record feature vector and the status change feature vector; processing a sequence of operation record feature vectors within a second operation record window through a Transformer encoder to obtain the operation mode feature vector;

[0011] Performing multi-feature interaction on the operation record feature vector, the status change feature vector, and the operation mode feature vector to obtain a first interaction feature, a second interaction feature, and a third interaction feature;

[0012] Calculating an operation authenticity score according to the first interaction feature, the second interaction feature, and the third interaction feature, and when the operation authenticity score is less than a dynamic threshold, marking the operation record as a forged operation record.

[0013] Further, the multi-feature extraction specifically includes:

[0014] Setting the first operation record window T 1 =[t-k+1,...,t-1,t]; where t represents the operation record serial number of the t-th operation record, and k represents the size of the first operation record window;

[0015] Obtaining all the operation records within the first operation record window according to the operation record sequence to obtain the first operation record sequence, and obtaining all the file status changes within the first operation record window according to the file status change sequence to obtain the first file status change sequence;

[0016] Performing embedding encoding on the first operation record sequence and then inputting it into the bidirectional long short-term memory network for processing to obtain the operation record feature vector;

[0017] Embed and encode the first file status change sequence and input it into the bidirectional long short-term memory network for processing to obtain the status change feature vector;

[0018] Obtain all the operation record feature vectors within the second operation record window T 2 to obtain the operation record feature vector sequence, and use the operation record feature vector sequence to construct a first query matrix, a first key matrix, and a first value matrix; the size of the second operation record window is the length of the operation record sequence;

[0019] Process the first query matrix, the first key matrix, and the first value matrix through the Transformer encoder to obtain the operation mode feature vector.

[0020] Further, the multiple feature interactions specifically include:

[0021] Use the operation record feature vector to construct a second query matrix, use the status change feature vector to construct a second key matrix and a second value matrix, and process the second query matrix, the second key matrix, and the second value matrix through the attention mechanism to obtain the first interaction feature;

[0022] Use the operation mode feature vector to construct a third key matrix and a third value matrix, and process the second query matrix, the third key matrix, and the third value matrix through the attention mechanism to obtain the second interaction feature;

[0023] Concatenate the first interaction feature and the second interaction feature, and use layer normalization and residual connection to obtain the third interaction feature.

[0024] Further, calculating the operation authenticity score specifically includes:

[0025] Process the first interaction feature through a first multi-layer perceptron to obtain a status rationality score;

[0026] Process the second interaction feature through a second multi-layer perceptron to obtain an operation consistency score;

[0027] Process the third interaction feature through a third multi-layer perceptron to obtain a status transition score;

[0028] Perform a weighted sum of the status rationality score, the operation consistency score, and the status transition score to obtain the operation authenticity score.

[0029] Further, calculating the dynamic threshold specifically includes:

[0030] Set a third operation record window T 3=[t - w + 1,..., t - 1, t], where w represents the size of the third operation record window, and the dynamic adjustment coefficient is calculated by the operation authenticity score within the third operation record window:

[0031] β t =1 / (1 + exp(-|μ recent -μ 0 | / σ 0 ));

[0032] Among them, β t represents the dynamic adjustment coefficient of the t-th operation record, μ recent represents the mean value of the operation authenticity scores within the third operation record window, μ 0 and σ 0 respectively represent the mean value and variance of the operation authenticity scores within the second operation record window, and exp() represents the natural exponential function;

[0033] The dynamic threshold is updated by the dynamic adjustment coefficient:

[0034] θ t =β t *θ t-1 +(1 - β t ) * (μ recent -2 * σ recent );

[0035] Among them, θ t represents the dynamic threshold of the t-th operation record, θ t-1 represents the dynamic threshold of the (t - 1)-th operation record, and σ recent represents the variance of the operation authenticity scores within the third operation record window.

[0036] An artificial intelligence-based file data security management system, including:

[0037] A file operation data acquisition unit that collects and processes the operation record data of each file operation and the file status data after each operation, obtains the operation record sequence and file status sequence of the file, and extracts the file status change sequence according to the file status sequence; the operation record data includes operation type, operation time, operation parameters, and operating user; the file status data includes file attribute values;

[0038] The file operation feature extraction unit performs multiple feature extractions on the operation record sequence and the file status change sequence to obtain an operation record feature vector, a status change feature vector, and an operation mode feature vector; the multiple feature extractions include: processing the first operation record sequence and the first file status change sequence within the first operation record window through a bidirectional long short-term memory network to obtain the operation record feature vector and the status change feature vector; processing the operation record feature vector sequence within the second operation record window through a Transformer encoder to obtain the operation mode feature vector;

[0039] The file operation feature interaction unit performs multiple feature interactions on the operation record feature vector, the status change feature vector, and the operation mode feature vector to obtain a first interaction feature, a second interaction feature, and a third interaction feature;

[0040] The operation authenticity scoring unit calculates an operation authenticity score based on the first interaction feature, the second interaction feature, and the third interaction feature, and when the operation authenticity score is less than the dynamic threshold, marks the operation record as a forged operation record.

[0041] Further, the multiple feature extractions specifically include:

[0042] Set the first operation record window \(T\) 1 \(=[t - k + 1,\cdots,t - 1,t]\); where \(t\) represents the operation record serial number of the \(t\)-th operation record, and \(k\) represents the size of the first operation record window;

[0043] Obtain all the operation records within the first operation record window according to the operation record sequence to obtain the first operation record sequence, and obtain all the file status changes within the first operation record window according to the file status change sequence to obtain the first file status change sequence;

[0044] Embed and encode the first operation record sequence and then input it into the bidirectional long short-term memory network for processing to obtain the operation record feature vector;

[0045] Embed and encode the first file status change sequence and then input it into the bidirectional long short-term memory network for processing to obtain the status change feature vector;

[0046] Obtain all the operation record feature vectors within the second operation record window \(T\) 2 to obtain the operation record feature vector sequence, and use the operation record feature vector sequence to construct a first query matrix, a first key matrix, and a first value matrix; the size of the second operation record window is the length of the operation record sequence;

[0047] Process the first query matrix, the first key matrix, and the first value matrix through the Transformer encoder to obtain the operation mode feature vector.

[0048] Furthermore, the multiple feature interactions specifically include:

[0049] Construct a second query matrix using the operation record feature vector, construct a second key matrix and a second value matrix using the state change feature vector, and process the second query matrix, the second key matrix, and the second value matrix through the attention mechanism to obtain the first interaction feature;

[0050] Construct a third key matrix and a third value matrix using the operation mode feature vector, and process the second query matrix, the third key matrix, and the third value matrix through the attention mechanism to obtain the second interaction feature;

[0051] Concatenate the first interaction feature and the second interaction feature, and use layer normalization and residual connection to obtain the third interaction feature.

[0052] Furthermore, calculating the operation authenticity score specifically includes:

[0053] Process the first interaction feature through a first multi-layer perceptron to obtain a state rationality score;

[0054] Process the second interaction feature through a second multi-layer perceptron to obtain an operation consistency score;

[0055] Process the third interaction feature through a third multi-layer perceptron to obtain a state transition score;

[0056] Perform a weighted sum of the state rationality score, the operation consistency score, and the state transition score to obtain the operation authenticity score.

[0057] Furthermore, calculating the dynamic threshold specifically includes:

[0058] Set the third operation record window \(T\) 3 \(=[t - w + 1,\cdots,t - 1,t]\), where \(t\) represents the operation record sequence number of the \(t\)-th operation record, and \(w\) represents the size of the third operation record window. Calculate the dynamic adjustment coefficient through the operation authenticity scores within the third operation record window:

[0059] \(\beta\) t \(= 1 / (1 + \exp(-|\mu\) recent \(-\mu\) 0 \(| / \sigma\) 0 ));

[0060] Among them, β t represents the dynamic adjustment coefficient of the t-th operation record, and μ recent represents the mean value of the operation authenticity scores within the third operation record window; μ 0 and σ 0 respectively represent the mean value and variance of the operation authenticity scores within the second operation record window, and exp() represents the natural exponential function;

[0061] The dynamic threshold is updated through the dynamic adjustment coefficient:

[0062] θ t = β t * θ t-1 + (1 - β t ) * (μ recent - 2 * σ recent );

[0063] Among them, θ t represents the dynamic threshold of the t-th operation record, θ t-1 represents the dynamic threshold of the (t - 1)-th operation record, and σ recent represents the variance of the operation authenticity scores within the third operation record window.

[0064] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0065] 1. A multiple feature extraction architecture is proposed. First, a bidirectional long short-term memory network is used to process the operation record sequence and the file status change sequence respectively to capture local operation record features and file status change features; then, the complete operation record feature sequence is processed by a Transformer encoder to extract global operation pattern features. This multiple feature extraction architecture can simultaneously focus on short-term and long-term features. The bidirectional long short-term memory network can make full use of context information, and the multi-head self-attention mechanism can discover the relevance of operation records at a long distance, improving the modeling ability for complex operation patterns, providing a reliable feature basis for subsequent authenticity assessment, and helping to improve the ability to identify forged operation records.

[0066] 2. A multiple feature interaction architecture is proposed. Through the attention mechanism, the interaction between the first operation record feature and the state change feature, and the interaction between the second operation record feature and the operation mode feature are realized. Finally, the third interaction feature is obtained through feature splicing, layer normalization, and residual connection. This multiple feature interaction can fully explore the correlation between different features. The interaction between the operation record feature and the operation mode feature can verify the consistency between the current operation and the historical operation mode, while the interaction with the state change feature can verify the rationality of the impact of the operation on the file state. Through the interaction and fusion of multi-dimensional features, a comprehensive evaluation of the operation authenticity is achieved.

[0067] 3. A dynamic threshold adjustment mechanism based on the operation history is designed. By calculating the statistical features of the operation authenticity score within a local window, the threshold is dynamically adjusted. Considering the differences in operation records in different periods, it can adaptively adjust the judgment criteria according to the changes in the current operation environment. By introducing a dynamic adjustment coefficient, the threshold can be adjusted in a timely manner when the operation mode changes, which not only ensures the accuracy of detection but also avoids false alarm problems caused by fixed thresholds. It is suitable for complex and changeable actual application scenarios, can better adapt to different operation habits and operation characteristics, and greatly improves the adaptability and practicality. BRIEF DESCRIPTION OF THE DRAWINGS

[0068] Figure 1 It is a schematic flow chart of a file data security management method based on artificial intelligence according to the present invention;

[0069] Figure 2 It is a schematic flow chart of multiple feature extraction and multiple feature interaction according to the present invention;

[0070] Figure 3 It is a schematic structural diagram of a file data security management system based on artificial intelligence according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0071] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0072] Please refer to Figures 1 to 3 , the present invention provides a file data security management method and system based on artificial intelligence, and the technical solutions are as follows:

[0073] Embodiment 1:

[0074] In the electronic medical record system of a hospital, the access and modification records of medical record files must be kept absolutely true, which is directly related to medical safety and patient privacy. This embodiment is applied to the electronic medical record system of a certain hospital to ensure the authenticity of all medical record operation records. As Figure 1 shown, an artificial intelligence-based file data security management method includes:

[0075] Collect and process the operation record data of each operation on the file and the file status data after each operation to obtain the operation record sequence and file status sequence of the file, and extract the file status change sequence according to the file status sequence; the operation record data includes operation type, operation time, operation parameters, and operating user; the file status data includes file attribute values;

[0076] Perform multi-feature extraction on the operation record sequence and the file status change sequence to obtain an operation record feature vector, a status change feature vector, and an operation mode feature vector; the multi-feature extraction includes: respectively process the first operation record sequence and the first file status change sequence within the first operation record window through a bidirectional long short-term memory network to obtain the operation record feature vector and the status change feature vector; process the operation record feature vector sequence within the second operation record window through a Transformer encoder to obtain the operation mode feature vector;

[0077] Perform multi-feature interaction on the operation record feature vector, the status change feature vector, and the operation mode feature vector to obtain a first interaction feature, a second interaction feature, and a third interaction feature;

[0078] Calculate the operation authenticity score according to the first interaction feature, the second interaction feature, and the third interaction feature. When the operation authenticity score is less than the dynamic threshold, mark the operation record as a forged operation record.

[0079] The processing of operation record data and file status data includes data cleaning, standardization, and sorting alignment.

[0080] Table 1 shows the detection performance of medical record operations in different departments. Among them, the detection effect in the laboratory department is the best because the operation mode in the laboratory department is relatively fixed and the status changes are more regular.

[0081] Table 1 Detection Performance of Medical Record Operation Records in Different Departments

[0082] Department type Accuracy rate Recall rate F1 score Internal medicine 0.978 0.971 0.974 Surgery 0.965 0.962 0.963 Emergency department 0.959 0.953 0.956 Laboratory department 0.982 0.977 0.979

[0083] Further, as Figure 2 shown, the multi-feature extraction specifically includes:

[0084] Set the first operation record window T 1 = [t - k + 1,..., t - 1, t]; where t represents the operation record serial number of the t-th operation record, and k represents the size of the first operation record window; in this embodiment, the value of k is 20;

[0085] Obtain all the operation records within the first operation record window according to the operation record sequence to obtain the first operation record sequence, and obtain all the file status changes within the first operation record window according to the file status change sequence to obtain the first file status change sequence;

[0086] Embed and encode the first operation record sequence and then input it into the bidirectional long short-term memory network for processing to obtain the operation record feature vector;

[0087] Embed and encode the first file status change sequence and then input it into the bidirectional long short-term memory network for processing to obtain the status change feature vector;

[0088] Obtain all the operation record feature vectors within the second operation record window T 2 to obtain the operation record feature vector sequence, and use the operation record feature vector sequence to construct a first query matrix, a first key matrix, and a first value matrix; the size of the second operation record window is the length of the operation record sequence;

[0089] Process the first query matrix, the first key matrix, and the first value matrix through the Transformer encoder to obtain the operation mode feature vector.

[0090] Multiply the operation record feature vector sequence by three different learnable weight matrices to obtain a first query matrix, a first key matrix, and a first value matrix.

[0091] Multiple feature extraction captures the context information of the sequence by setting the operation record window, fully utilizes the operation record and status change sequences, and effectively models the long-term operation mode, realizing the comprehensive capture of file operation behavior features and being able to accurately extract and represent complex operation record-related features.

[0092] Further, as Figure 2 shown, the multiple feature interaction specifically includes:

[0093] Use the operation record feature vector to construct a second query matrix, use the status change feature vector to construct a second key matrix and a second value matrix, and process the second query matrix, the second key matrix, and the second value matrix through the attention mechanism to obtain the first interaction feature;

[0094] Construct a third key matrix and a third value matrix using the operation mode feature vector, and process the second query matrix, the third key matrix, and the third value matrix through an attention mechanism to obtain the second interaction feature;

[0095] Concatenate the first interaction feature and the second interaction feature, and use layer normalization and residual connection to obtain the third interaction feature.

[0096] Multiply the operation record feature vector by a learnable weight matrix to obtain the second query matrix; multiply the state change feature vector by two different learnable weight matrices respectively to obtain the second key matrix and the second value matrix; multiply the operation mode feature vector by two different learnable weight matrices respectively to obtain the third key matrix and the third value matrix.

[0097] By constructing multiple query matrices, key matrices, and value matrices, and using the attention mechanism to achieve deep interaction between features, it can automatically focus on important feature associations. At the same time, the combination of layer normalization and residual connection not only preserves the original feature information but also enhances the feature fusion effect, thereby improving the accuracy and reliability of the system's judgment of operation authenticity.

[0098] Further, calculating the operation authenticity score specifically includes:

[0099] Process the first interaction feature through a first multi-layer perceptron to obtain a state rationality score;

[0100] Process the second interaction feature through a second multi-layer perceptron to obtain an operation consistency score;

[0101] Process the third interaction feature through a third multi-layer perceptron to obtain a state transition score;

[0102] Perform a weighted sum of the state rationality score, the operation consistency score, and the state transition score to obtain the operation authenticity score.

[0103] The calculation formula for the operation authenticity score is:

[0104] score final =ω 1 *score 1 +ω 2 *score 2 +ω 3 *score 3 ;

[0105] where score final represents the operation authenticity score, ω 1 、ω2 and ω 3 represent weight coefficients, and score 1 , score 2 and score 3 respectively represent the state rationality score, the operation consistency score, and the state transition score.

[0106] The first multi-layer perceptron, the second multi-layer perceptron, and the third multi-layer perceptron each include an input layer, an output layer, and three hidden layers; the output layer outputs a score between 0 and 1 through an activation function.

[0107] Using three different multi-layer perceptrons to calculate the state rationality score, the operation consistency score, and the state transition score respectively realizes a multi-angle evaluation of the operation authenticity. The multi-dimensional scoring mechanism can respectively verify the degree of conformity of the current operation record with the historical pattern, the rationality of the file state change, and the effectiveness of the state transition before and after the operation. The final score obtained by weighted summation realizes a comprehensive balance of multiple dimensions.

[0108] Further, calculating the dynamic threshold specifically includes:

[0109] Set the third operation record window T 3 = [t - w + 1,..., t - 1, t], where t represents the operation record serial number of the t-th operation record, and w represents the size of the third operation record window. Calculate the dynamic adjustment coefficient through the operation authenticity scores within the third operation record window: In this embodiment, the value of k is 100;

[0110] β t = 1 / (1 + exp(-|μ recent - μ 0 | / σ 0 ));

[0111] Among them, β t represents the dynamic adjustment coefficient of the t-th operation record, μ recent represents the mean value of the operation authenticity scores within the third operation record window, μ 0 and σ 0 respectively represent the mean value and variance of the operation authenticity scores within the second operation record window, and exp() represents the natural exponential function;

[0112] Update the dynamic threshold through the dynamic adjustment coefficient:

[0113] θ t = β t * θ t-1 + (1 - β t ) * (μ recent-2*σ recent );

[0114] where θ t represents the dynamic threshold of the t-th operation record, and θ t-1 represents the dynamic threshold of the (t - 1)-th operation record, and σ recent represents the variance of the operation authenticity score within the third operation record window.

[0115] The initial value θ 0 of the dynamic threshold is calculated according to μ 0 and σ 0 as follows: θ 0 = μ 0 - 2*σ 0 .

[0116] Table 2 shows the comparison of different threshold strategies. The first threshold strategy refers to a fixed threshold, the second threshold strategy refers to a dynamic threshold based on all operation authenticity scores, and the third threshold strategy refers to the dynamic threshold of the present invention, which can obtain better detection effects compared with other strategies.

[0117] Table 2 Comparison of Different Threshold Strategies

[0118] Threshold strategy False positive rate False negative rate 1 0.082 0.075 2 0.063 0.058 3 0.042 0.039

[0119] The dynamic threshold adjustment mechanism ensures the reliability of statistical features by setting an operation record window, calculates a dynamic adjustment coefficient based on the mean and variance of the operation authenticity scores within the window, making the threshold adjustment more accurate and robust. It can adapt to the operation characteristics of different scenarios and periods, effectively avoiding the misjudgment problems that may be caused by a fixed threshold.

[0120] A file data security management method based on artificial intelligence proposed by the present invention collects and processes operation record data and file status data, establishing a complete file operation behavior feature system. It integrates a multiple feature extraction mechanism of a bidirectional long short-term memory network and a Transformer encoder, realizing multi-reconstruction modeling of file operation records. Through the designed multiple feature interaction mechanism, it can deeply analyze the complex associations among operation records, status changes, and operation patterns, thereby comprehensively evaluating the operation authenticity. The introduced dynamic threshold mechanism can adaptively adjust the judgment criteria according to the actual operating environment, effectively improving the adaptability and reliability of data security management. The present invention realizes the accurate identification of forged operation records, thus effectively preventing data tampering and information leakage, providing a reliable technical guarantee for file data security management.

[0121] Example 2:

[0122] The present invention also provides a file data security management system based on artificial intelligence, such asFigure 3 As shown in the figure, it includes:

[0123] A file operation data acquisition unit, which acquires and processes the operation record data of each file operation and the file status data after each operation, obtains the operation record sequence and the file status sequence of the file, and extracts the file status change sequence according to the file status sequence; the operation record data includes the operation type, operation time, operation parameters, and operating user; the file status data includes file attribute values;

[0124] A file operation feature extraction unit, which performs multiple feature extractions on the operation record sequence and the file status change sequence to obtain an operation record feature vector, a status change feature vector, and an operation mode feature vector; the multiple feature extractions include: processing the first operation record sequence and the first file status change sequence within the first operation record window through a bidirectional long short-term memory network respectively to obtain the operation record feature vector and the status change feature vector; processing the operation record feature vector sequence within the second operation record window through a Transformer encoder to obtain the operation mode feature vector;

[0125] A file operation feature interaction unit, which performs multiple feature interactions on the operation record feature vector, the status change feature vector, and the operation mode feature vector to obtain a first interaction feature, a second interaction feature, and a third interaction feature;

[0126] An operation authenticity scoring unit, which calculates an operation authenticity score according to the first interaction feature, the second interaction feature, and the third interaction feature, and marks the operation record as a forged operation record when the operation authenticity score is less than the dynamic threshold.

[0127] Furthermore, the multiple feature extractions specifically include:

[0128] Set the first operation record window T 1 =[t - k + 1,..., t - 1, t]; where t represents the operation record serial number of the t-th operation record, and k represents the size of the first operation record window;

[0129] Obtain all the operation records within the first operation record window according to the operation record sequence to obtain the first operation record sequence, and obtain all the file status changes within the first operation record window according to the file status change sequence to obtain the first file status change sequence;

[0130] Embed and encode the first operation record sequence and then input it into the bidirectional long short-term memory network for processing to obtain the operation record feature vector;

[0131] Embed and encode the first file status change sequence and input it into the bidirectional long short-term memory network for processing to obtain the status change feature vector;

[0132] Obtain all the operation record feature vectors within the second operation record window T 2 to obtain the operation record feature vector sequence, and use the operation record feature vector sequence to construct a first query matrix, a first key matrix, and a first value matrix; the size of the second operation record window is the length of the operation record sequence;

[0133] Process the first query matrix, the first key matrix, and the first value matrix through the Transformer encoder to obtain the operation mode feature vector.

[0134] Further, the multiple feature interactions specifically include:

[0135] Use the operation record feature vector to construct a second query matrix, use the status change feature vector to construct a second key matrix and a second value matrix, and process the second query matrix, the second key matrix, and the second value matrix through the attention mechanism to obtain the first interaction feature;

[0136] Use the operation mode feature vector to construct a third key matrix and a third value matrix, and process the second query matrix, the third key matrix, and the third value matrix through the attention mechanism to obtain the second interaction feature;

[0137] Concatenate the first interaction feature and the second interaction feature, and use layer normalization and residual connection to obtain the third interaction feature.

[0138] Further, calculating the operation authenticity score specifically includes:

[0139] Process the first interaction feature through a first multi-layer perceptron to obtain the status rationality score;

[0140] Process the second interaction feature through a second multi-layer perceptron to obtain the operation consistency score;

[0141] Process the third interaction feature through a third multi-layer perceptron to obtain the status transition score;

[0142] Perform weighted summation on the status rationality score, the operation consistency score, and the status transition score to obtain the operation authenticity score.

[0143] Further, calculating the dynamic threshold specifically includes:

[0144] Set the third operation record window T 3=[t - w + 1,..., t - 1, t], where w represents the size of the third operation record window, and the dynamic adjustment coefficient is calculated through the operation authenticity scores within the third operation record window:

[0145] β t = 1 / (1 + exp(-|μ recent - μ 0 | / σ 0 ));

[0146] Among them, β t represents the dynamic adjustment coefficient of the t-th operation record, μ recent represents the mean of the operation authenticity scores within the third operation record window; μ 0 and σ 0 respectively represent the mean and variance of the operation authenticity scores within the second operation record window, and exp() represents the natural exponential function;

[0147] The dynamic threshold is updated through the dynamic adjustment coefficient:

[0148] θ t = β t * θ t-1 + (1 - β t ) * (μ recent - 2 * σ recent );

[0149] Among them, θ t represents the dynamic threshold of the t-th operation record, θ t-1 represents the dynamic threshold of the (t - 1)-th operation record, and σ recent represents the variance of the operation authenticity scores within the third operation record window.

[0150] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A file data security management method based on artificial intelligence, characterized in that: include: Collect and process the operation record data of each operation on the file and the file status data after each operation to obtain the operation record sequence and the file status sequence of the file, and extract the file status change sequence according to the file status sequence; the operation record data includes the operation type, operation time, operation parameters and operation user; the file status data includes the file attribute value; Performing multiple feature extraction on the operation record sequence and the file state change sequence to obtain an operation record feature vector, a state change feature vector and an operation mode feature vector; The multiple feature extraction includes: processing the first operation record sequence and the first file state change sequence in the first operation record window respectively through a bidirectional long short-term memory network to obtain the operation record feature vector and the state change feature vector; processing the operation record feature vector sequence in the second operation record window through a Transformer encoder to obtain the operation mode feature vector; Performing multiple feature interactions on the operation record feature vector, the state change feature vector, and the operation mode feature vector to obtain a first interaction feature, a second interaction feature, and a third interaction feature; An operation authenticity score is calculated according to the first interaction feature, the second interaction feature, and the third interaction feature, and when the operation authenticity score is less than a dynamic threshold, the operation record is marked as a forged operation record.

2. According to the artificial intelligence-based file data security management method of claim 1, it is characterized in that: The multiple feature extraction specifically includes: Set the first operation record window T1 = [t-k+1, ..., t-1, t]; wherein t represents the operation record sequence number of the t-th operation record, and k represents the size of the first operation record window; Acquire all operation records in the first operation record window according to the operation record sequence to obtain the first operation record sequence, and acquire all file status changes in the first operation record window according to the file status change sequence to obtain the first file status change sequence; Embedding and encoding the first operation record sequence and inputting the sequence into the bidirectional long short-term memory network for processing to obtain the operation record feature vector; Embedding and encoding the first file state change sequence and inputting it into the bidirectional long short-term memory network for processing to obtain the state change feature vector; Acquire all the operation record feature vectors in the second operation record window T2 to obtain the operation record feature vector sequence, and use the operation record feature vector sequence to construct a first query matrix, a first key matrix and a first value matrix; the size of the second operation record window is the length of the operation record sequence; The first query matrix, the first key matrix, and the first value matrix are processed by the Transformer encoder to obtain the operation mode feature vector.

3. According to the artificial intelligence-based file data security management method of claim 1, it is characterized in that: The multiple feature interactions specifically include: constructing a second query matrix using the operation record feature vector, constructing a second key matrix and a second value matrix using the state change feature vector, and processing the second query matrix, the second key matrix and the second value matrix through an attention mechanism to obtain the first interaction feature; constructing a third key matrix and a third value matrix using the operation mode feature vector, processing the second query matrix, the third key matrix and the third value matrix through an attention mechanism, and obtaining the second interaction feature; The first interaction feature and the second interaction feature are concatenated, and layer normalization and residual connection are used to obtain the third interaction feature.

4. The method for file data security management based on artificial intelligence according to claim 1, characterized in that: Calculating the operation authenticity score specifically includes: Processing the first interaction feature by a first multi-layer perceptron to obtain a state rationality score; Processing the second interaction feature by a second multi-layer perceptron to obtain an operation consistency score; Processing the third interaction feature by a third multi-layer perceptron to obtain a state transition score; The operation authenticity score is obtained by performing a weighted summation of the state rationality score, the operation consistency score and the state transition score.

5. The method for file data security management based on artificial intelligence according to claim 1, characterized in that: Calculating the dynamic threshold specifically includes: Set the third operation record window T3 = [t-w+1, ..., t-1, t], t represents the operation record sequence number of the t-th operation record, w represents the size of the third operation record window, and calculate the dynamic adjustment coefficient according to the operation authenticity score in the third operation record window: b t =1 / (1+exp(-|μ recent -μ0| / σ0)); Among them, β t represents the dynamic adjustment coefficient of the t-th operation record, μ recent represents the mean of the operation authenticity score in the third operation record window, μ0 and σ0 represent the mean and variance of the operation authenticity score in the second operation record window respectively, and exp() represents a natural exponential function; The dynamic threshold is updated by the dynamic adjustment coefficient: i t =b t *i t-1 +(1-β t )*(m recent -2*s recent ); Among them, θ t represents the dynamic threshold of the t-th operation record, θ t-1 represents the dynamic threshold of the t-1th operation record, σ recent Represents the variance of the operation authenticity score within the third operation record window.

6. A file data security management system based on artificial intelligence, characterized in that: include: A file operation data collection unit collects and processes the operation record data of each operation on the file and the file status data after each operation to obtain the file operation record sequence and the file status sequence, and extracts the file status change sequence according to the file status sequence; the operation record data includes the operation type, operation time, operation parameters and operation user; the file status data includes the file attribute value; The file operation feature extraction unit performs multiple feature extraction on the operation record sequence and the file state change sequence to obtain an operation record feature vector, a state change feature vector and an operation mode feature vector; The multiple feature extraction includes: processing the first operation record sequence and the first file state change sequence in the first operation record window respectively through a bidirectional long short-term memory network to obtain the operation record feature vector and the state change feature vector; processing the operation record feature vector sequence in the second operation record window through a Transformer encoder to obtain the operation mode feature vector; a file operation feature interaction unit, performing multiple feature interactions on the operation record feature vector, the state change feature vector and the operation mode feature vector to obtain a first interaction feature, a second interaction feature and a third interaction feature; The operation authenticity scoring unit calculates an operation authenticity score according to the first interaction feature, the second interaction feature and the third interaction feature, and marks the operation record as a forged operation record when the operation authenticity score is less than a dynamic threshold.

7. The file data security management system based on artificial intelligence according to claim 6 is characterized in that: The multiple feature extraction specifically includes: Set the first operation record window T1 = [t-k+1, ..., t-1, t]; wherein t represents the operation record sequence number of the t-th operation record, and k represents the size of the first operation record window; Acquire all the operation records in the first operation record window according to the operation record sequence to obtain the first operation record sequence, and acquire all the file status changes in the first operation record window according to the file status change sequence to obtain the first file status change sequence; Embedding and encoding the first operation record sequence and inputting the sequence into the bidirectional long short-term memory network for processing to obtain the operation record feature vector; Embedding and encoding the first file state change sequence and inputting it into the bidirectional long short-term memory network for processing to obtain the state change feature vector; Acquire all the operation record feature vectors in the second operation record window T2 to obtain the operation record feature vector sequence, and use the operation record feature vector sequence to construct a first query matrix, a first key matrix and a first value matrix; the size of the second operation record window is the length of the operation record sequence; The first query matrix, the first key matrix, and the first value matrix are processed by the Transformer encoder to obtain the operation mode feature vector.

8. The file data security management system based on artificial intelligence according to claim 6 is characterized in that: The multiple feature interactions specifically include: constructing a second query matrix using the operation record feature vector, constructing a second key matrix and a second value matrix using the state change feature vector, and processing the second query matrix, the second key matrix and the second value matrix through an attention mechanism to obtain the first interaction feature; constructing a third key matrix and a third value matrix using the operation mode feature vector, processing the second query matrix, the third key matrix and the third value matrix through an attention mechanism, and obtaining the second interaction feature; The first interaction feature and the second interaction feature are concatenated, and layer normalization and residual connection are used to obtain the third interaction feature.

9. The file data security management system based on artificial intelligence according to claim 6 is characterized in that: Calculating the operation authenticity score specifically includes: Processing the first interaction feature by a first multi-layer perceptron to obtain a state rationality score; Processing the second interaction feature by a second multi-layer perceptron to obtain an operation consistency score; Processing the third interaction feature by a third multi-layer perceptron to obtain a state transition score; The operation authenticity score is obtained by performing a weighted summation of the state rationality score, the operation consistency score and the state transition score.

10. The file data security management system based on artificial intelligence according to claim 6 is characterized in that: Calculating the dynamic threshold specifically includes: Set the third operation record window T3 = [t-w+1, ..., t-1, t], w represents the size of the third operation record window, and calculate the dynamic adjustment coefficient according to the operation authenticity score in the third operation record window: βt=1 / (1+exp(-|μ recent -μ0| / σ0)); Among them, β t represents the dynamic adjustment coefficient of the t-th operation record, μ recent represents the mean value of the operation authenticity score in the third operation record window; μ0 and σ0 represent the mean value and variance of the operation authenticity score in the second operation record window respectively, and exp() represents a natural exponential function; The dynamic threshold is updated by the dynamic adjustment coefficient: i t =b t *i t-1 +(1-β t )*(m recent -2*s recent ); Among them, θ t represents the dynamic threshold of the t-th operation record, θ t-1 represents the dynamic threshold of the t-1th operation record, σ recent Represents the variance of the operation authenticity score within the third operation record window.

Citation Information

Cited By

  • Cloud environment-oriented data stealing evidence chain generation method and system

    CN120281576A