An online intelligent monitoring and management system for data security

Through multimodal data fusion and dynamic identification of abnormal propagation nodes, the comprehensiveness and accuracy of malicious content recognition in network public opinion video monitoring is solved, efficient monitoring and precise control of network public opinion videos is achieved, and the timeliness and effectiveness of monitoring management is improved.

CN120186381BActive Publication Date: 2025-07-18XIAN KANGNAI NETWORK TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510655895.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-21
Publication Date
2025-07-18
Estimated Expiration
2045-05-21

AI Technical Summary

Technical Problem

The existing technology ignores the comprehensive analysis of deep-level information of copy, images and audio in videos in online public opinion video monitoring, and lacks comprehensive modeling and weight allocation of multimodal data, resulting in limited comprehensiveness and accuracy of malicious content recognition, and the inability to build an accurate information dissemination topology network, resulting in lag in monitoring and intervention.

Method used

Multimodal data extraction module is used to extract multimodal data of network public opinion video content, combined with emotional tendency recognition module, interactive behavior data acquisition module and abnormal propagation node positioning module, and abnormal propagation node positioning module, and dynamic identification of abnormal propagation nodes through multi-dimensional feature fusion and dynamic identification of abnormal propagation nodes, generate a comprehensive malicious index and trigger a dynamic warning response.

Benefits of technology

It has achieved efficient monitoring and precise control of online public opinion video content, improved the comprehensiveness and accuracy of malicious content recognition, and improved the timeliness and effectiveness of monitoring and management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120186381B_ABST
    Figure CN120186381B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of online public opinion data monitoring, and relates to an online intelligent monitoring and management system for data security. The present invention generates a text sentiment polarity score, an image sensitivity index, and an audio feature outlier value through the structured analysis of text, image, and audio data of online public opinion videos, and generates a comprehensive malicious index through dynamic weighted fusion, fully integrating the multi-dimensional features of video content, effectively improving the accuracy and comprehensiveness of malicious content recognition; constructs an information dissemination topology network based on user interaction behavior data, analyzes the diffusion speed and content similarity of all dissemination nodes, dynamically identifies abnormal dissemination nodes, can clearly grasp the dissemination path and diffusion trend of malicious dissemination content, provides a key basis for subsequent early warning response and precise strike, and triggers a traffic limiting strategy and an account banning operation in real time, effectively improving the timeliness and effectiveness of online public opinion video security monitoring and management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of online public opinion data monitoring, and relates to an online intelligent monitoring and management system for data security. Background Art

[0002] With the rapid development of the Internet, online public opinion information has shown an explosive growth trend. Among them, as a rich and intuitive information dissemination carrier, video is widely used for the dissemination of various types of information, including malicious content. Therefore, effective security monitoring and management of online public opinion video content, timely discovery and handling of malicious content, have become an urgent need to maintain a clean online space.

[0003] In the prior art, for example, an audio-visual content security risk monitoring system with the Chinese patent publication number CN118297396A includes a real-time public opinion collection unit, a media asset video collection unit, a bad information storage unit, a standard information storage unit, a public opinion processing unit, and an analysis server. In the present invention, after public opinion appears and there is content risk in the audio-visual content, the platform can timely discover it and send a risk signal according to a certain strategy, and according to the public opinion, the security loss is minimized. The monitoring system will save the public opinion information and what is monitored in the risk video as an important basis for further traceability and audit confirmation afterwards.

[0004] However, there are still many problems in the actual application of the prior art: 1. The prior art mainly focuses on the structured tagging of video content, such as scene, logo text, person recognition, etc., ignoring the comprehensive analysis of deep-level information such as the emotional tendency and sensitivity contained in the text, images, and audio in the video, lacking the comprehensive modeling and weight allocation of multi-modal data, resulting in one-sided emotional tendency judgment, and limiting the comprehensiveness and accuracy of malicious content recognition.

[0005] 2. The prior art collects and monitors public opinion information, but the collection of user interaction behavior data of malicious content on multiple dissemination platforms is not comprehensive enough, and an accurate information dissemination topology network cannot be constructed to dynamically identify abnormal dissemination nodes, resulting in lagged monitoring and intervention of the spread and diffusion of malicious content. Summary of the Invention

[0006] The present invention provides an online intelligent monitoring and management system for data security, which realizes the efficient monitoring and precise control of online public opinion video content through the deep integration of multi-modal data, real-time tracking of the dissemination path, dynamic positioning of abnormal nodes, and adaptive early warning response.

[0007] To achieve the above object, the present invention adopts the following technical solutions: A data security online intelligent monitoring and management system, comprising: a multi-modal data extraction module, an emotional tendency recognition module, an interactive behavior data collection module, an abnormal propagation node positioning module, and a dynamic early warning response module.

[0008] The multi-modal data extraction module is used to perform multi-modal data extraction on the network public opinion video content to obtain text data, image data, and audio data.

[0009] The emotional tendency recognition module is used to integrate the text data, image data, and audio data to obtain a text emotional polarity score, an image sensitivity index, and an audio feature outlier value, generate a comprehensive malicious index, and distinguish malicious propagation content from normal user feedback content according to the comprehensive malicious index.

[0010] The interactive behavior data collection module is used to collect user interactive behavior data of malicious propagation content on multiple communication platforms and construct an information dissemination topology network.

[0011] The abnormal propagation node positioning module is used to analyze the diffusion speed and content similarity of all propagation nodes based on the information dissemination topology network and dynamically identify abnormal propagation nodes.

[0012] The dynamic early warning response module is used to generate a risk interception instruction according to the abnormal propagation node and trigger a repair strategy.

[0013] Compared with the prior art, the present invention has the following beneficial effects: (1) The present invention parallelly analyzes the text data, image data, and audio data of the network public opinion video, solves the problem of one-sidedness of single-modal analysis, realizes the multi-dimensional feature fusion extraction of malicious content, and improves the comprehensiveness of recognition.

[0014] (2) The present invention performs emotional polarity scoring on text data, sensitive index analysis on image data, and feature outlier recognition on audio data, and dynamically assigns weights using the entropy weight method to generate a comprehensive malicious index, fully integrating the multi-dimensional features of video content, effectively improving the accuracy and comprehensiveness of malicious content recognition.

[0015] (3) The present invention collects user interactive behavior data of multiple communication platforms, constructs a tree-like dissemination map and a dissemination rate curve, combines the content similarity analysis of text, images, and audio, dynamically identifies abnormal dissemination nodes, can clearly master the dissemination path and diffusion trend of malicious dissemination content, quickly locates dissemination nodes with abnormal diffusion speed and highly similar content, and provides a key basis for subsequent early warning response and precise strike.

[0016] (4) The present invention generates risk interception instructions based on abnormal propagation nodes and triggers repair strategies, realizing dynamic monitoring and real-time response to malicious propagation content, and effectively improving the timeliness and effectiveness of network public opinion video security monitoring and management. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for describing the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0018] Figure 1 It is a schematic diagram of the connection of system modules of the present invention.

[0019] Figure 2 It is a schematic diagram for supplementing the content of the sentiment tendency recognition module in the present invention.

[0020] Figure 3 It is a content step diagram of S3 in the content steps of the sentiment tendency recognition module in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0021] Now, various exemplary embodiments of the present invention will be described in detail with reference to the drawings. It should be noted that: Unless otherwise specifically stated, the relative arrangements, numerical expressions, and numerical values of the components and steps described in these embodiments do not limit the scope of the present invention. At the same time, it should be understood that for the sake of description, the dimensions of the various parts shown in the drawings are not drawn in actual proportional relationships.

[0022] The following description of at least one exemplary embodiment is actually only illustrative and in no way limits the present invention and its application or use. Technologies, methods, and devices known to those of ordinary skill in the relevant fields may not be discussed in detail, but where appropriate, the said technologies, methods, and devices should be regarded as part of the specification.

[0023] In all the examples shown and discussed here, any specific value should be interpreted as merely exemplary and not as a limitation. Therefore, other examples of the exemplary embodiments may have different values.

[0024] Please refer to Figure 1As shown in the figure, the present invention provides a data security online intelligent monitoring and management system, including a multimodal data extraction module, an emotional tendency recognition module, an interactive behavior data acquisition module, an abnormal propagation node positioning module, and a dynamic early warning response module. The connection relationship between the modules is that the multimodal data extraction module is connected to the emotional tendency recognition module, the interactive behavior data acquisition module is respectively connected to the emotional tendency recognition module and the abnormal propagation node positioning module, and the dynamic early warning response module is connected to the abnormal propagation node positioning module.

[0025] The multimodal data extraction module is used to extract multimodal data from the online public opinion video content to obtain text data, image data, and audio data.

[0026] For example, for an online public opinion video about financial customer complaint feedback, the multimodal data extraction module can accurately extract the text content of the customer complaint description in the video, the image data of the complaint scene, and the audio data of the voices of the people explaining in the video. Among them, the video frame images of the online public opinion video content are extracted at set time intervals, and all the extracted video frame images are arranged in time sequence to obtain image data; at the same time, OCR text extraction technology is used to extract text from the image data and integrate it to obtain text data; and speech recognition technology is used to recognize audio data from the online public opinion video content.

[0027] The present invention performs parallel parsing on the text data, image data, and audio data of the online public opinion video, solves the problem of one-sidedness in single-modal analysis, realizes the extraction of multi-dimensional feature fusion of malicious content, and improves the comprehensiveness of recognition.

[0028] The emotional tendency recognition module is used to generate a comprehensive malicious index based on the text data, image data, and audio data to obtain a text emotional polarity score, an image sensitivity index, and an audio feature outlier value, and distinguish maliciously propagated content from normal user feedback content according to the comprehensive malicious index.

[0029] As Figure 2 shown, the specific content of the emotional tendency recognition module is as follows: S1. Preprocess the text data, image data, and audio data in the online public opinion video content respectively.

[0030] Among them, data cleaning is performed on the text data, including removing garbled characters, special symbols, and redundant and repeated content, and using a word segmentation tool for word segmentation, filtering common stop words, such as "de", "le", etc., and retaining negative words with emotional tendencies, such as "bu", "meiyou", etc., and outputting the processed text data.

[0031] Deduplicate video frame images of the image data and perform resolution normalization, eliminate illumination differences and noise interference, and divide the edge contours of the functional areas in the image. The functional areas include text areas, human areas, object areas, and background element areas, and output the processed image data.

[0032] Perform noise reduction processing on the audio data, remove environmental noises such as wind sounds and current sounds, and standardize the audio amplitude to the range of [-1, 1], and output the processed audio data.

[0033] S2. Introduce the preprocessed text data into the set general sentiment dictionary, mark the sentiment polarity of all words in the text data, count the number of words with each sentiment polarity, and linearly weight the proportion of the number of words with each sentiment polarity to obtain the text sentiment polarity score.

[0034] Among them, words such as "safe", "resolved in a timely manner", "qualified", "satisfied", etc. in the general sentiment dictionary have positive sentiment polarity, and words such as "unstable", "deducted more", "fraudulent swiping", "disappointed", etc. have negative sentiment polarity. Words other than positive sentiment polarity and negative sentiment polarity are regarded as neutral sentiment polarity.

[0035] In sentiment polarity analysis, the weight distribution of positive, negative, and neutral sentiment polarities needs to be set flexibly according to specific scenario goals. For example, in the online public opinion scenario of the financial industry, the weight of negative sentiment polarity is , the weight of positive sentiment polarity is , the weight of neutral sentiment polarity is . The weight of negative sentiment polarity is the dominant one, which needs to be amplified in risk-sensitive scenarios to trigger a high-risk warning. The weight of positive sentiment polarity is used to identify positive signals, and the weight of neutral sentiment polarity is usually set to 0, but a small weight can be reserved in trend analysis to smooth extreme results.

[0036] S3. Call the preset sensitive label knowledge base, use the visual feature similarity analysis method to compare the labels of the preprocessed image data, count the regional coverage rate of each sensitive label, and use the skeleton point tracking technology to analyze the human actions, match the action sensitivity of the human actions, and perform a fusion analysis with the regional coverage rate of each sensitive label to obtain the image sensitivity index.

[0037] Such as Figure 3 shown, the specific content of step S3 is as follows: S31. Extract the visual features in the preprocessed image data, construct an image visual feature set, extract the visual feature sets of various sensitive labels in the preset sensitive label knowledge base, and calculate the similarity between the image visual feature set and the visual feature sets of various sensitive labels through the cosine similarity calculation formula.

[0038] Among them, the visual features can be the color features, texture features, and shape features of each functional area. The color features describe the color distribution of pixels in the image, such as the color histogram, which reflects the frequency of each color appearance; the texture features describe a certain regular pattern or texture structure in the image, reflecting the surface texture of the image, such as the contrast, energy, and entropy in the gray-level co-occurrence matrix; the shape features describe the geometric characteristics such as the contour, boundary, or spatial layout of the target in the image, such as the boundary curvature and the number of inflection points. The acquisition methods of the above visual features can all be obtained through existing technologies.

[0039] In one embodiment, various sensitive labels in the sensitive label knowledge base corresponding to the financial industry include, but are not limited to, forged material labels, misleading chart labels, illegal operation labels, and malicious tampering labels, etc. Forged materials directly affect the security of funds and belong to high risks, so the weight is the highest; illegal operations involve system security and are also high risks, and their weight is the second highest; misleading charts affect customer decisions, but the severity is slightly lower; malicious tampering involves data authenticity, but the affected range is relatively small. According to risk classification and control, the sensitive weight of the forged material label can be 1, the sensitive weight of the illegal operation label can be 0.8, the sensitive weight of the misleading chart label can be 0.6, and the sensitive weight of the malicious tampering label can be 0.5.

[0040] S32. Screen various sensitive labels with a similarity greater than the set similarity threshold, and count the area coverage rate of each sensitive label in the image. The area coverage rate is the ratio of the area of the sensitive label region to the total area of the image.

[0041] S33. Locate the coordinates of the human body bone points from the preprocessed image data, extract the action behavior trajectory based on the dynamic changes of the bone point coordinates, and match it with the set of human actions at each action sensitive level to identify the human action and the action sensitive level. When the action behavior trajectory coincides with the behavior trajectory of a certain human action in the set of human actions at a certain action sensitive level, output the action sensitive level and the human action.

[0042] In a specific embodiment, each action sensitive level includes a first-level action sensitive level, a second-level action sensitive level, and a third-level action sensitive level. The set of human actions at the first-level action sensitive level can be threatening with weapons, group physical conflicts, and deliberately damaging financial equipment, etc.; the set of human actions at the second-level action sensitive level can be demonstrating forged materials, malicious gathering command, and unauthorized equipment operation, etc.; the set of human actions at the third-level action sensitive level can be exaggerated emotional actions, such as punching the table with a fist and stomping. The sensitivity of the first-level action sensitive level is set to 1.5, the sensitivity of the second-level action sensitive level is set to 1.2, and the sensitivity of the third-level action sensitive level is set to 0.8.

[0043] S34. Dynamically adjust the weight based on the sensitivity corresponding to the action sensitivity level of the human action, and combine it with the human action intensity to output the action sensitivity of the human action.

[0044] In one embodiment, the method for obtaining the human action intensity is as follows: Locate the time-series image set corresponding to the human action from the preprocessed image data, obtain the joint movement speed, joint displacement amplitude, and duration of the human action according to the time-series image set corresponding to the human action, and compare and analyze them with the set reference joint movement speed, reference joint displacement amplitude, and reference duration of the corresponding human action to obtain the human action intensity. The human action intensity analysis formula is , where is the human action intensity, are the weight coefficients of the set joint movement speed, joint displacement amplitude, and duration respectively. The setting of the weight coefficients needs to be closely combined with the scene requirements and can be manually set based on domain knowledge. are the joint movement speed, joint displacement amplitude, and duration of the human action respectively. are the set reference joint movement speed, reference joint displacement amplitude, and reference duration of the human action respectively, and the reference threshold can be determined by the parameter mean in historical data or experimental tests.

[0045] Among them, the joint movement speed is the average movement rate of the coordinates of each bone point in the time-series image set, the joint displacement amplitude is the maximum displacement of the action behavior trajectory, and the duration is the time length from the start to the end of the action.

[0046] The action sensitivity of the human action is the sum of the action sensitivities of all human actions. The analysis formula for the action sensitivity of a single human action is , where is the action sensitivity, is the sensitivity corresponding to the action sensitivity level of the human action. The joint movement speed measures the instantaneous threat of the action; the joint displacement amplitude reflects the physical influence range of the action; the duration evaluates the continuous risk of the action. The larger the values of these three parameters, the greater the human action intensity and the higher the action sensitivity of the human action.

[0047] S35. Multiply the area coverage rate of each sensitive label by the sensitive weight of the corresponding sensitive label, and use the sum of the multiplication results and the action sensitivity of the human action as the image sensitive index.

[0048] S4. Extract the voiceprint spectrum features of the audio in the preprocessed audio data, identify the audio emotion polarity, and obtain the audio feature outlier based on the audio emotion polarity and the proportion of the number of words of each emotion polarity.

[0049] It should be noted that the specific content of step S4 is as follows: Frame and window the preprocessed audio data, extract the spectrogram through short-time Fourier transform, identify the voiceprint spectral features based on the spectrogram, input the voiceprint spectral features into the acoustic emotion model, and output the audio emotion polarity.

[0050] Select the emotion polarity with the largest proportion from the proportion of the number of words of each emotion polarity as the text emotion polarity, compare the text emotion polarity with the audio emotion polarity, and judge the consistency of the emotion polarity. In one embodiment, when the text emotion polarity is the same as the audio character polarity, the emotion polarity consistency can be set to 1, otherwise, the emotion polarity consistency can be set to 0.

[0051] Through the fusion analysis of the abnormal characterization value of the audio emotion polarity and the emotion polarity consistency, the audio feature abnormal value is obtained. The audio feature abnormal value is the sum of the abnormal characterization value of the audio emotion polarity and the emotion polarity consistency.

[0052] In a specific embodiment, the acoustic emotion model collects an audio data set containing different emotion polarities. Each audio data sample is labeled with a corresponding emotion polarity label, and the voiceprint spectral features of each audio data sample are extracted, such as harmonics, energy, fundamental frequency, etc. Then, the learning algorithm of the support vector machine is used to train and statistically analyze the spectral features corresponding to different emotion polarities. During the training process, the audio data set is divided into a training set and a validation set. The training set is used to optimize the model parameters, and the model is adjusted through the validation set to avoid overfitting.

[0053] The audio emotion polarity includes positive audio emotion, neutral audio emotion, and negative audio emotion. The abnormal characterization value of positive audio emotion can be set to -1, the abnormal characterization value of medium audio emotion can be set to 0, and the abnormal characterization value of negative audio emotion can be set to 1.

[0054] S5. Perform fitting analysis on the copywriting emotion polarity score, image sensitivity index, and audio feature abnormal value to generate a comprehensive malicious index. When the comprehensive malicious index is greater than the set malicious index threshold, mark the network public opinion video content as maliciously spread content, otherwise mark it as normal user feedback content.

[0055] It should be noted that the comprehensive malicious index generation method is as follows: Based on the entropy weight method, dynamic weights are assigned to the copywriting emotion polarity score, image sensitivity index, and video feature abnormal value. Multiply the copywriting emotion polarity score, image sensitivity index, and video feature abnormal value by the corresponding dynamic weights respectively, and accumulate the multiplication results to obtain the comprehensive malicious index.

[0056] Further, the specific process of dynamically assigning weights to the copywriting sentiment polarity score, image sensitivity index, and video feature outliers based on the entropy weight method is as follows: Collect a certain number of historical online public opinion video sample data, record the copywriting sentiment polarity score, image sensitivity index, and video feature outliers of each video, and use the range normalization method to convert the values of the copywriting sentiment polarity score, image sensitivity index, and video feature outliers into the interval [0, 1]. For the standardized values, use the entropy weight method to calculate the weights of each index. The entropy weight method is a prior art.

[0057] The present invention scores the sentiment polarity of the copywriting data, analyzes the sensitivity index of the image data, identifies the feature outliers of the audio data, and dynamically assigns weights using the entropy weight method to generate a comprehensive malicious index, fully integrating the multi-dimensional features of the video content and effectively improving the accuracy and comprehensiveness of malicious content recognition.

[0058] The interactive behavior data acquisition module is used to collect the user interactive behavior data of maliciously spread content on multiple communication platforms and construct an information dissemination topology network. The information dissemination topology network is a tree-like dissemination map with the communication platform as the root node and the user interactive behavior data as the branches.

[0059] The abnormal dissemination node positioning module is used to dynamically identify abnormal dissemination nodes based on the analysis of the diffusion speed and content similarity of all dissemination nodes in the information dissemination topology network.

[0060] It should be noted that the specific content of the abnormal dissemination node positioning module is as follows: Divide the user interactive behavior data of maliciously spread content on multiple communication platforms into dissemination cycles according to a set time window, count the forwarding volume, comment volume, and secondary dissemination volume of each dissemination node in different dissemination cycles, generate a dissemination rate curve, and use the slope of the dissemination rate curve as the diffusion speed.

[0061] Compare the dissemination content in the user interactive behavior data of each dissemination node with the copywriting data, image data, and audio data to obtain the maximum content similarity of each dissemination node with other dissemination nodes.

[0062] Mark the dissemination nodes that meet any one of the conditions that the diffusion speed is greater than the set diffusion speed threshold and the content similarity is greater than the set content similarity threshold as abnormal dissemination nodes.

[0063] In a specific embodiment, the method for generating the propagation rate curve is as follows: The ratio analysis of the forwarding volume, comment volume, and secondary propagation volume to the propagation period is performed to obtain the forwarding rate, comment rate, and secondary propagation rate. The forwarding rate, comment rate, and secondary propagation rate are respectively subjected to Z-Score normalization processing to obtain the normalized forwarding rate, comment rate, and secondary propagation rate. Their mean value is used as the comprehensive propagation rate, and a propagation rate curve is generated with the propagation period as the horizontal axis and the comprehensive propagation rate as the vertical axis.

[0064] In a specific embodiment, the method for obtaining the content similarity is as follows: The corresponding copywriting data of the propagation content of each propagation node is generated into word vectors, and the copywriting similarity between each propagation node and other propagation nodes is analyzed through the cosine similarity calculation formula.

[0065] Extract the image sensitivity index set of the corresponding image data of the propagation content of each propagation node, compare the image sensitivity index sets to obtain the coincidence degree of the image sensitivity distribution between each propagation node and other propagation nodes, and record it as the image similarity. The coincidence degree of the image sensitivity distribution is the ratio of the number of identical image sensitivity indexes between a propagation node and other propagation nodes to the total number of image sensitivity indexes between the propagation node and other propagation nodes.

[0066] Compare the voiceprint spectrum features of the corresponding audio data of the propagation content between each propagation node and other propagation nodes, and use the comparison result as the audio similarity. The audio similarity is the ratio of the number of similar voiceprint spectrum features between a propagation node and other propagation nodes to the total number of voiceprint spectrum features.

[0067] The number of similar voiceprint spectrum features is that the difference between the voiceprint spectrum features of a propagation node and the corresponding voiceprint spectrum features of other propagation nodes is within the allowable error range.

[0068] Perform linear weighted analysis on the copywriting similarity, image similarity, and audio similarity to obtain the content similarity.

[0069] Among them, the weights of the copywriting similarity, image similarity, and audio similarity can be determined according to the prior knowledge of the roles of copywriting, images, and audio in content expression and information transmission. For example, in the similarity analysis of network public opinion videos on financial customer complaint feedback, the image similarity has a higher weight. The weight of the image similarity can be set to 0.5, the weight of the copywriting similarity to 0.3, and the weight of the audio similarity to 0.2. Because the image content in the video usually carries the main viewpoints, facts, and logic, while the copywriting and audio serve as supplementary information.

[0070] The present invention collects user interaction behavior data from multiple dissemination platforms, constructs a tree-like dissemination map and a dissemination rate curve, and combines the content similarity analysis of copywriting, images, and audio to dynamically identify abnormal dissemination nodes, enabling a clear understanding of the dissemination path and diffusion trend of malicious dissemination content, quickly locating dissemination nodes with abnormal diffusion speeds and highly similar content, and providing a key basis for subsequent early warning responses and precise strikes.

[0071] A dynamic early warning response module for generating risk interception instructions based on abnormal dissemination nodes and triggering repair strategies.

[0072] It should be noted that the instruction generation logic of the dynamic early warning response module is as follows: send a dissemination content flow-limiting instruction to the abnormal dissemination node interface, and simultaneously execute account banning and content deletion operations on the publishing accounts corresponding to the malicious dissemination content.

[0073] The present invention generates risk interception instructions based on abnormal dissemination nodes and triggers repair strategies, realizing dynamic monitoring and real-time response to malicious dissemination content, and effectively improving the timeliness and effectiveness of network public opinion video security monitoring and management.

[0074] The above formulas are all dimensionless and take their numerical values for calculation. The formula is obtained by collecting a large amount of data for software simulation to obtain a formula closest to the actual situation. The preset parameters in the formula are set by those skilled in the art according to the actual situation.

[0075] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product.

[0076] Those of ordinary skill in the art can realize that the modules and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0077] In addition, the functional modules in each embodiment of the present application can be integrated into one processing module, or each module can exist physically alone, or two or more modules can be integrated into one module.

[0078] As described above, it is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims described above.

[0079] Finally, the above are only the preferred embodiments of the present invention and are not used to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. An online intelligent monitoring and management system for data security, characterized in that, Including: A multi-modal data extraction module that extracts multi-modal data from the online public opinion video content to obtain text data, image data, and audio data; An emotional tendency recognition module that integrates text data, image data, and audio data to obtain a text emotional polarity score, an image sensitivity index, and an audio feature outlier value, generates a comprehensive malicious index, and distinguishes maliciously spread content from normal user feedback content based on the comprehensive malicious index; An interactive behavior data collection module that collects user interactive behavior data of maliciously spread content on multiple communication platforms and constructs an information dissemination topological network; The specific content of the interactive behavior data collection module is as follows: Real-time collect user interactive behavior data of maliciously spread content on multiple communication platforms and construct a tree-shaped dissemination map with the communication platform as the root node and user interactive behavior data as the branches; An abnormal dissemination node positioning module that analyzes the diffusion speed and content similarity of all dissemination nodes based on the information dissemination topological network and dynamically identifies abnormal dissemination nodes; The specific content of the abnormal dissemination node positioning module is as follows: Divide the user interactive behavior data of maliciously spread content on multiple communication platforms into dissemination cycles according to a set time window, count the number of forwards, comments, and secondary dissemination volumes of each dissemination node in different dissemination cycles, generate a dissemination rate curve, and obtain the diffusion speed based on the dissemination rate curve; Compare the disseminated content in the user interactive behavior data of each dissemination node with text data, image data, and audio data to obtain the maximum content similarity corresponding to each dissemination node and other dissemination nodes; Mark the dissemination nodes that meet any one of the conditions that the diffusion speed is greater than the set diffusion speed threshold and the content similarity is greater than the set content similarity threshold as abnormal dissemination nodes; The method for generating the dissemination rate curve is: Perform ratio analysis on the number of forwards, comments, and secondary dissemination volumes with the dissemination cycle respectively to obtain the forward rate, comment rate, and secondary dissemination rate, perform Z-Score standardization processing on the forward rate, comment rate, and secondary dissemination rate respectively to obtain the standardized forward rate, comment rate, and secondary dissemination rate, take their average value as the comprehensive dissemination rate, and generate a dissemination rate curve with the dissemination cycle as the horizontal axis and the comprehensive dissemination rate as the vertical axis; A dynamic early warning response module that generates a risk interception instruction according to the abnormal dissemination node and triggers a repair strategy.

2. The data security online intelligent monitoring and management system according to claim 1, wherein: The specific content of the emotional tendency recognition module is as follows: S1. Preprocess the text data, image data, and audio data in the online public opinion video content respectively; S2. Introduce the preprocessed text data into a set general emotional dictionary, mark the emotional polarity of all words in the text data, count the number of words with each emotional polarity, and perform linear weighting on the proportion of the number of words with each emotional polarity to obtain a text emotional polarity score; S3. Call a preset sensitive label knowledge base, use the visual feature similarity analysis method to compare the labels of the preprocessed image data, count the regional coverage rate of each sensitive label, and use the skeleton point tracking technology to analyze the human actions, match the action sensitivity of the human actions, and perform fusion analysis with the regional coverage rate of each sensitive label to obtain an image sensitivity index; S4. Extract the voiceprint spectrum features of the audio in the preprocessed audio data, identify the audio emotional polarity, and obtain the audio feature outlier based on the audio emotional polarity and the proportion of the number of words in each emotional polarity. S5. Perform fitting analysis on the copywriting emotional polarity score, the image sensitivity index, and the audio feature outlier to generate a comprehensive malicious index. When the comprehensive malicious index is greater than the set malicious index threshold, mark the network public opinion video content as maliciously spread content; otherwise, mark it as normal user feedback content.

3. An online intelligent monitoring and management system for data security according to claim 2, characterized in that: The specific content of step S3 is as follows: S31. Extract the visual features in the preprocessed image data, construct an image visual feature set, extract the visual feature sets of various sensitive tags in the preset sensitive tag knowledge base, and calculate the similarity between the image visual feature set and the visual feature sets of various sensitive tags. S32. Screen out various sensitive tags with similarity greater than the set similarity threshold, and count the regional coverage rate of each sensitive tag in the image. S33. Locate the coordinates of the human body bone points from the preprocessed image data, extract the action behavior trajectory based on the dynamic change of the bone point coordinates, and match it with the set of human actions at each action sensitivity level to identify the human action and the action sensitivity level. S34. Dynamically adjust the weight based on the sensitivity of the human action corresponding to the action sensitivity level, and combine it with the human action intensity to output the action sensitivity of the human action. S35. Multiply the regional coverage rate of each sensitive tag by the sensitive weight of the corresponding sensitive tag, and use the sum of the multiplication result and the action sensitivity of the human action as the image sensitivity index.

4. An online intelligent monitoring and management system for data security according to claim 3, characterized in that: The method for obtaining the human action intensity in step S34 is as follows: Locate the set of sequential images corresponding to the human action from the preprocessed image data, obtain the joint movement speed, joint displacement amplitude, and duration of the human action according to the set of sequential images corresponding to the human action, and compare and analyze them with the set reference joint movement speed, reference joint displacement amplitude, and reference duration of the corresponding human action to obtain the human action intensity.

5. The data security online intelligent monitoring and management system according to claim 2, characterized in that: The specific content of step S4 is as follows: Perform frame windowing on the preprocessed audio data, extract the spectrogram through short-time Fourier transform, identify the voiceprint spectrum features based on the spectrogram, input the voiceprint spectrum features into the acoustic emotion model, and output the audio emotional polarity. Select the emotional polarity with the largest proportion from the proportion of the number of words in each emotional polarity as the text emotional polarity, compare the text emotional polarity with the audio emotional polarity, and judge the emotional polarity consistency. Obtain the audio feature outlier based on the fusion analysis of the abnormal characterization value of the audio emotional polarity and the emotional polarity consistency.

6. An online intelligent monitoring and management system for data security according to claim 1, characterized in that: The method for obtaining the content similarity is as follows: Generate word vectors for the copywriting data corresponding to the dissemination content of each dissemination node, and obtain the copywriting similarity between each dissemination node and other dissemination nodes through cosine similarity analysis. Extract the image sensitivity index set of the image data corresponding to the dissemination content of each dissemination node, compare the image sensitivity index sets to obtain the image sensitivity distribution overlap degree between each dissemination node and other dissemination nodes, and record it as the image similarity. Compare the voiceprint spectrum features of the audio data corresponding to the dissemination content of each dissemination node with those of other dissemination nodes, and use the comparison result as the audio similarity; Perform linear weighted analysis on the copywriting similarity, image similarity, and audio similarity to obtain the content similarity.

7. An online intelligent monitoring and management system for data security according to claim 1, characterized in that: The instruction generation logic of the dynamic early warning response module is as follows: Send a traffic limiting instruction for the dissemination content to the interface of the abnormal dissemination node, and simultaneously execute the account banning and content deletion operations on the publishing account corresponding to the malicious dissemination content.

Citation Information

Patent Citations

  • Audio-visual content security risk monitoring system

    CN118297396A

  • Public opinion data mining method and system, electronic equipment and storage medium

    CN116521962A

  • Network public opinion emotion situation quantification method and system

    CN118885870A