Medical network threat intelligent detection and early warning system based on artificial intelligence

By adopting multimodal data fusion and hybrid architecture detection methods in the medical network threat detection system, the problem of network security and reliability reduction caused by relying on single modal information in the prior art is solved, and comprehensive detection and early warning of multimodal network threats is achieved, and the reliability and detection accuracy of the system are improved.

CN120151027AInactive Publication Date: 2025-06-13JIANGSU PROVINCE HOSPITAL (THE FIRST AFFILIATED HOSPITAL OF NANJING MEDICAL UNIVERSITY)
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510290616.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-06-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing medical network threat detection methods mainly rely on single modal information, resulting in reduced reliability of network security and inability to effectively deal with network threats of multimodal information.

Method used

Using an intelligent medical network threat detection and early warning system based on artificial intelligence, we will establish a data security platform to pre-process, feature extraction and fusion of multimodal data, combine the hybrid architecture of convolutional neural network and Transformer model to carry out data fusion, and achieve comprehensive detection and early warning of multimodal network threats through data comparison and abnormal detection.

Benefits of technology

The system can synchronously process and comprehensively compare multimodal data, improves the detection accuracy of multimodal network threats and the reliability of the system, and ensures the security of medical networks and data integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151027A_ABST
    Figure CN120151027A_ABST
Patent Text Reader

Abstract

The invention discloses a medical network threat intelligent detection and early warning system based on artificial intelligence, and relates to the technical field of medical treatment, and the system comprises the following steps: 1, building a data security platform; step 2, multi-modal data fusion is carried out; 3, performing data comparison detection; according to the method, in the second step, multi-modal data can be fused, synchronous processing can be carried out on the multi-modal data, and therefore targeted processing can be carried out on threats from external multi-modal data; in the third step, synchronous comparison can be carried out on the fused multi-modal data, comprehensive comparison is carried out according to data diversification, and omnibearing network threat detection is carried out; in the fourth step, data backup and storage are carried out while safety early warning is carried out, and the reliability of the system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of medical technology, and particularly to an intelligent detection and early warning system for medical network threats based on artificial intelligence. Background Art

[0002] Medical network security refers to protecting hospital computer network systems and the data therein from unauthorized access, attacks, damage, or tampering through means such as technology, management, and law, ensuring the confidentiality, integrity, and availability of the network system. Medical network security is the key to ensuring the continuity of medical services. With the increasing degree of informatization in the medical industry, the security and privacy protection of medical data have become particularly important. Once medical data is leaked or tampered with, it will have a serious impact on the health of patients and the reputation of medical institutions.

[0003] According to the patent number: CN113919239B - An Intelligent Detection Method and System for Internal Threats Based on Spatiotemporal Feature Fusion, hereinafter collectively referred to as the reference patent. The reference patent records that "the present invention proposes a more concise but superior performance method for extracting time and space characteristics, reducing the computational and storage overhead of the internal threat intelligent detection solution; secondly, the present invention proposes a new spatiotemporal feature fusion scheme for user behavior, which can synchronously establish historical baselines and peer baselines during the detection process, thereby improving the detection accuracy of malicious users and providing an important reference for the intelligent and real-time detection of internal threats". From this, it can be known that the reference patent uses a method of integrating the time and space characteristics of user behavior and combining a deep autoencoder for anomaly detection, providing a key technical reference for the protection of internal threats in the medical industry. However, these data modalities are relatively single, and existing network threats are multi-modal information. If early warning is carried out for single-modal information, the reliability of network security is reduced;

[0004] In summary, an intelligent detection and early warning system for medical network threats based on artificial intelligence is provided. Summary of the Invention

[0005] In order to overcome the above deficiencies, the present invention provides an intelligent detection and early warning system for medical network threats based on artificial intelligence.

[0006] The present invention achieves the above object through the following technical solutions:

[0007] An intelligent detection and early warning system for medical network threats based on artificial intelligence, comprising the following steps:

[0008] Step 1: Establish a data security platform for unified management of medical information and simultaneous detection of medical network threats;

[0009] Step 2: Multimodal data fusion, which is used to fuse the multimodal data input into the data security platform;

[0010] Step 3: Data comparison and detection, which is used to compare the input multimodal data with the data in the standard library to detect network threats;

[0011] Step 4: Security warning, which is used to give security warning prompts for the data security platform and perform data protection;

[0012] The said Step 2 includes the following steps:

[0013] S21. Data preprocessing, which is used to preprocess each modality data of the multimodal data to ensure the quality and consistency of the data;

[0014] S22. Data feature extraction, which is used to extract key features from each modality data of the multimodal data;

[0015] S23. Hybrid architecture data fusion, which uses a convolutional neural network as the encoder and a Transformer model as the decoder to form a hybrid architecture for data fusion;

[0016] The said Step 3 includes the following steps:

[0017] S31. Data category matching, which performs category matching on the fused data;

[0018] S32. Data comparison, which compares the fused data with the data in the standard library;

[0019] S33. Data anomaly detection, which performs anomaly detection on the compared data and uses a statistical method for anomaly detection.

[0020] Preferably, the data security platform includes a hospital server, a social network and an internal network. The internal network includes a computer terminal, a server terminal and a background terminal. The computer terminal is used to provide medical assistance services for doctors, such as recording patient medical information, querying patient medical cases or medical examples, etc. The server terminal is used to provide services for patients, such as registering and paying fees, etc. The background terminal is used for hospital staff to perform service work within the hospital, such as clocking in and purchasing, etc.

[0021] Preferably, the multimodal data includes image data, physiological signal data, drug management data, and background service data. Image data, which is usually used for medical imaging such as CT, MRI, etc., has high resolution and detailed anatomical structure information. The image data standard promotes the sharing of medical information, improving medical efficiency and quality. Physiological signal data, such as electrocardiogram, provides dynamic information on cardiac electrical activity and is usually used to monitor heart health. It can be fused with other physiological signals such as EEG to improve the accuracy and reliability of data processing. Drug management data, including drug usage records, patient responses, etc., is usually structured text or numerical data for tracking and managing patients' medication situations. Background service data includes information such as hospital staff clock-in, procurement, etc., and also includes patient registration, payment, etc. information, which is usually structured text or numerical data.

[0022] Preferably, in the step S21, the data preprocessing includes image data processing, physiological signal data processing, drug management data processing, and background service data processing. Image data processing includes image segmentation and image reconstruction. Physiological signal data processing includes filtering and feature extraction. Both drug management data processing and background service data processing include data cleaning and format conversion.

[0023] Preferably, in the step S22, the data feature extraction includes image data feature extraction, physiological signal data feature extraction, drug management data feature extraction, and background service data feature extraction.

[0024] Preferably, in the step S32, the data to be compared in the data comparison includes data format, data file size, data image parameters, and data type.

[0025] Preferably, in the step S33, statistical techniques are used to compare the data points of the data to be compared with their mean and standard deviation to identify abnormal situations. First, the mean (μ) and standard deviation (σ) of the data set need to be calculated. The mean is the sum of all data points divided by the number of data points, and the standard deviation is a measure of the degree to which data points deviate from the mean. For each data point in the data set, its z-score is calculated. The formula for the z-score is: z = (X - μ) / σ, where X is the data point to be measured, μ is the mean of the data set, and σ is the standard deviation of the data set. Usually, a threshold for the z-score is set to identify abnormal situations. For example, when |z| > 3, the data point is considered an outlier. This means that the data point deviates from the mean by more than 3 standard deviations. According to the set threshold, check the z-score of each data point. If the absolute value of the z-score of the data point is greater than the threshold, it is marked as an outlier.

[0026] Preferably, the step four includes the following steps:

[0027] S41. Network security warning: Send a network security warning prompt signal to the data security platform for the data security platform to conduct network security inspections.

[0028] S42. Data backup and storage: Back up the databases in the data security platform that are affected.

[0029] The beneficial effects of the present invention are as follows: In this intelligent medical network threat detection and warning system based on artificial intelligence:

[0030] 1. In step two, multi-modal data fusion can be performed, and multi-modal data can be processed synchronously, so as to specifically handle threats from external multi-modal data.

[0031] 2. In step three, the fused multi-modal data can be synchronously compared, and comprehensive comparison can be carried out according to the diversity of the data to conduct all-round network threat detection.

[0032] 3. In step four, while conducting security warnings, data backup and storage are also carried out, improving the reliability of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] The present invention will be described by way of examples with reference to the accompanying drawings, where:

[0034] Figure 1 is the step diagram of the present invention;

[0035] Figure 2 is the system schematic diagram of the present invention;

[0036] Figure 3 is the step diagram of the multi-modal data fusion of the present invention;

[0037] Figure 4 is the step diagram of the data comparison and detection of the present invention;

[0038] Figure 5 is the step diagram of the security warning of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0039] Now, the present invention will be further described in detail with reference to the accompanying drawings. These drawings are all simplified schematic diagrams, only showing the basic structure of the present invention in a schematic way, so they only show the components related to the present invention.

[0040] As Figures 1 - 5 shown, an intelligent medical network threat detection and warning system based on artificial intelligence includes the following steps:

[0041] Step one: Establish a data security platform for unified management of medical information and detection of medical network threats at the same time.

[0042] Step 2: Multimodal data fusion, which is used to fuse the multimodal data input into the data security platform;

[0043] Step 3: Data comparison and detection, which is used to compare the input multimodal data with the data in the standard library to detect network threats;

[0044] Step 4: Security warning, which is used to give security warning prompts to the data security platform and perform data protection;

[0045] The said Step 2 includes the following steps:

[0046] S21. Data preprocessing, which is used to preprocess each modality data of the multimodal data to ensure the quality and consistency of the data;

[0047] S22. Data feature extraction, which is used to extract key features from each modality data of the multimodal data;

[0048] S23. Hybrid architecture data fusion, which uses a convolutional neural network as the encoder and a Transformer model as the decoder to form a hybrid architecture for data fusion;

[0049] The said Step 3 includes the following steps:

[0050] S31. Data category matching, which matches the categories of the fused data;

[0051] S32. Data comparison, which compares the fused data with the data in the standard library;

[0052] S33. Data anomaly detection, which performs anomaly detection on the compared data and uses a statistical method for anomaly detection.

[0053] As a specific embodiment, the data security platform includes a hospital server, a social network, and an internal network. The internal network includes a computer terminal, a server, and a background terminal. The computer terminal is used to provide medical assistance services to doctors, such as recording patients' medical information, querying patients' medical cases or medical examples, etc. The server is used to provide services to patients, such as registering and paying. The background terminal is used for hospital staff to perform service work within the hospital, such as clocking in and purchasing.

[0054] As a specific embodiment, the multimodal data includes imaging data, physiological signal data, drug management data, and background service data. Imaging data, which is usually used for medical imaging such as CT, MRI, etc., has high resolution and detailed anatomical structure information. The imaging data standard promotes the sharing of medical information, improving medical efficiency and quality. Physiological signal data, such as electrocardiogram, provides dynamic information on cardiac electrical activity and is usually used to monitor cardiac health. It can be fused with other physiological signals such as EEG to improve the accuracy and reliability of data processing. Drug management data, including drug usage records, patient responses, etc., is usually structured text or numerical data for tracking and managing patients' medication situations. And background service data, including information such as hospital staff clock-in, procurement, etc., also includes information such as patient registration and payment, and is usually structured text or numerical data.

[0055] As a specific embodiment, in the step S21, the data preprocessing includes imaging data processing, physiological signal data processing, drug management data processing, and background service data processing. Imaging data processing includes image segmentation and image reconstruction. Physiological signal data processing includes filtering and feature extraction. Both drug management data processing and background service data processing include data cleaning and format conversion.

[0056] Among them, the operation mode of image segmentation in imaging data processing is to use segmentation algorithms provided by image processing libraries (such as scikit-image library of Python, OpenCV, etc.) to implement image segmentation. For example, in Python, the threshold_otsu function in the scikit-image library can be used for threshold segmentation, or the Canny function in OpenCV can be used for edge detection. The operation mode of image reconstruction is to use professional medical image processing software (such as 3D Slicer, OsiriX, Mimics, etc.) or programming libraries (such as ITK, VTK, etc.) for three-dimensional reconstruction. For example, in 3D Slicer, after importing the DICOM image sequence, select an appropriate reconstruction algorithm (such as the Marching Cubes algorithm) for three-dimensional reconstruction. In a programming environment, the ImageSeriesReader in the ITK library can be used to read the DICOM image sequence, and then the MarchingCubes filter can be used for three-dimensional reconstruction.

[0057] The operation mode of filtering in physiological signal data processing is to use a digital filter to filter the ECG signal to remove noise and interference. Common filters include high-pass filters, low-pass filters, band-pass filters, etc. For example, in Matlab, the butter function can be used to design a Butterworth filter, and then the filter function can be used to filter the ECG signal;

[0058] In the operation mode of feature extraction in physiological signal data processing, feature extraction is performed on the filtered ECG signal to obtain feature information such as heart rate, heart rhythm, and ST segment. Feature extraction methods include time-domain analysis, frequency-domain analysis, wavelet transform, etc. For example, in Matlab, the findpeaks function can be used to detect the R-wave peak and then calculate the heart rate; the fft function can be used for frequency-domain analysis to extract spectral features; wavelet transform can be used to perform multi-scale analysis on the ECG signal to extract detailed features.

[0059] In the operation mode of data cleaning in drug management data processing and background service data processing, a combination of automated tools and manual review is used to identify and correct errors, duplicates, and incomplete records in the data. For example, in Excel, the "Remove Duplicates" function under the "Data" tab can be used to remove duplicate data; the "Find and Replace" function can be used to correct incorrect data; the "Data Validation" function can be used to ensure the integrity and accuracy of the data.

[0060] In the operation mode of format conversion in drug management data processing and background service data processing, drug management data is converted from one format to another as needed. Common format conversions include CSV to Excel, Excel to database, etc. For example, in Excel, the "Save As" function can be used to save the data as a CSV format; a database management tool (such as MySQL Workbench) can be used to import Excel data into the database. For converting the pharmacy inventory count sheet to Excel, automated tools such as JandaoCloud can be used to achieve efficient conversion.

[0061] As a specific embodiment, in the step S22, data feature extraction includes image data feature extraction, physiological signal data feature extraction, drug management data feature extraction, and background service data feature extraction.

[0062] Image data feature extraction includes shape feature extraction, texture feature extraction, and edge feature extraction. In shape feature extraction, an image processing library (such as Python's scikit-image library, OpenCV, etc.) is used for image segmentation to extract the region of interest (ROI), and the geometric attributes of the ROI, such as area, perimeter, major axis, minor axis, etc., are calculated as shape features. A convolutional neural network (CNN) model is used to perform feature extraction processing on the normalized DICOM image data to generate DICOM image feature data, and then edge contour extraction and edge detection optimization are performed on the DICOM image feature data to generate optimized DICOM image contour data;

[0063] In texture feature extraction, the gray-level co-occurrence matrix (GLCM) method is used to calculate texture features such as energy, inertia, entropy, correlation, etc. The local binary pattern (LBP) method is used to extract texture features, and the texture is described by statistically analyzing the histogram of local binary patterns. Methods such as wavelet transform can also be used to perform multi-scale analysis on texture images to extract relatively stable eigenvalue as texture features;

[0064] In edge feature extraction, edge detection algorithms (such as Canny edge detection, Sobel operator, etc.) are used to perform edge detection on DICOM images, and the detected edge points or edge segments are extracted as edge features.

[0065] The extraction of physiological signal data features includes heart rate feature extraction, heart rhythm feature extraction, and waveform feature extraction. In heart rate feature extraction, the ECG signal is filtered to remove noise and interference. The R-wave detection algorithm (such as the method based on peak detection) is used to find the position of the R wave, and the time interval between adjacent R waves (RR interval) is calculated, and then the heart rate (HR) is calculated;

[0066] In heart rhythm feature extraction, the ECG signal is analyzed in the time domain, and statistics such as the standard deviation and root mean square difference of the RR interval are calculated as the features of heart rate variability (HRV). Frequency domain analysis is performed, and the spectral features of the ECG signal are extracted through methods such as Fourier transform to further analyze the heart rhythm features;

[0067] In waveform feature extraction, methods such as wavelet transform are used to perform multi-scale analysis on the ECG signal to extract waveform features at different frequencies and scales, and analyze the morphology, amplitude, and duration of waveform segments such as QRS complex, ST segment, and T wave.

[0068] The extraction of drug management data features includes medication frequency feature extraction, dosage feature extraction, and reaction feature extraction. Statistics and data records are made for each drug, dosage, and medication reaction as the corresponding features.

[0069] The extraction of background service data features includes attendance features, procurement features, inpatient registration features, and appointment features. Similarly, statistics are made for these features as the corresponding features.

[0070] As a specific embodiment, in the step S32, the data to be compared in data comparison includes data format, data file size, data image parameters, and data type. The data comparison is also multi-modal and comprehensive, and a comprehensive comparison is made from the data file format to the data type to ensure data security.

[0071] As a specific embodiment, in step S33, statistical techniques are used to compare the data points of the data to be compared with their mean and standard deviation to identify abnormal situations. First, the mean (μ) and standard deviation (σ) of the data set need to be calculated. The mean is the sum of all data points divided by the number of data points, and the standard deviation is a measure of the degree to which the data points deviate from the mean. For each data point in the data set, its z-score is calculated. The formula for calculating the z-score is: z = (X - μ) / σ, where X is the data point to be measured, μ is the mean of the data set, and σ is the standard deviation of the data set. Usually, a threshold for the z-score is set to identify abnormal situations. For example, when |z| > 3, the data point is considered an outlier. This means that the data point deviates from the mean by more than 3 standard deviations. According to the set threshold, the z-score of each data point is checked. If the absolute value of the z-score of a data point is greater than the threshold, it is marked as an outlier.

[0072] As a specific embodiment, step four includes the following steps:

[0073] S41. Network security warning, sending a network security warning prompt signal to the data security platform for the data security platform to conduct network security investigation;

[0074] S42. Data backup and storage, backing up the database in the data security platform affected.

[0075] Inspired by the present invention, through the above description, relevant staff can completely make various changes and modifications without departing from the technical idea of this invention. The technical scope of this invention is not limited to the content in the specification, and its technical scope must be determined according to the scope of the claims.

Claims

1. An artificial intelligence-based medical network threat intelligent detection and early warning system, characterized by: The following steps are involved: Step 1: Establish a data security platform to centrally manage medical information and detect medical network threats; Step 2: Multimodal data fusion, used to fuse the multimodal data input into the data security platform; Step 3: Data comparison detection, which is used to compare the input multimodal data with the data in the standard library to detect network threats; Step 4: Security warning, used to provide security warning prompts to the data security platform and perform data protection; The step 2 comprises the following steps: S21, data preprocessing, used to preprocess each modality of multimodal data to ensure data quality and consistency; S22, data feature extraction, for extracting key features from each modality of multimodal data; S23, hybrid architecture data fusion, using convolutional neural network as encoder and Transformer model as decoder to form a hybrid architecture for data fusion; The step three comprises the following steps: S31, data category matching, performing category matching on the fused data; S32, data comparison, comparing the fused data with the data in the standard library; S33, data anomaly detection, anomaly detection is performed by comparing the subsequent data and using statistical methods to perform anomaly detection.

2. According to claim 1, the medical network threat intelligent detection and early warning system based on artificial intelligence is characterized by: The data security platform includes hospital servers, social networks and internal networks, and the internal network includes computer terminals, service terminals and backend terminals.

3. The medical network threat intelligent detection and early warning system based on artificial intelligence according to claim 1 is characterized by: The multimodal data includes image data, physiological signal data, drug management data and background service data.

4. The medical network threat intelligent detection and early warning system based on artificial intelligence according to claim 1 is characterized by: In the step S21, data preprocessing includes image data processing, physiological signal data processing, drug management data processing and background service data processing.

5. The medical network threat intelligent detection and early warning system based on artificial intelligence according to claim 1 is characterized by: In the step S22, data feature extraction includes image data feature extraction, physiological signal data feature extraction, drug management data feature extraction and background service data feature extraction.

6. The medical network threat intelligent detection and early warning system based on artificial intelligence according to claim 1 is characterized by: In the step S32, the data to be compared in the data comparison include data format, data file size, data image parameters and data type.

7. The medical network threat intelligent detection and early warning system based on artificial intelligence according to claim 1 is characterized by: In the step S33, statistical techniques are used to compare the data points of the data to be compared with their average values ​​and standard deviations to identify abnormal situations.

8. The medical network threat intelligent detection and early warning system based on artificial intelligence according to claim 1 is characterized by: The step 4 comprises the following steps: S41, network security warning, sending a network security warning signal to the data security platform, which then conducts network security inspection; S42. Data backup and preservation: back up the database in the affected data security platform.

Citation Information

Patent Citations

  • A method and system for intelligent detection of internal threats based on spatiotemporal feature fusion

    CN113919239B