Systems, methods, computer program products for using machine learning framework in combat attack detection

By combining the autoencoder machine learning model with the production model, divergence measurement detection is used to detect the adversarial attacks, solving the problem of high computing resources and time consumption in the existing technology, and achieving fast and accurate adversarial attack detection.

CN120283241APending Publication Date: 2025-07-08VISA INTERNATIONAL SERVICE ASSOCIATION
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202280101905.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-11-16
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

The prior art requires a large amount of computing resources and storage of adversarial instance samples when detecting adversarial attacks, and the detection time is long, making it difficult to quickly and accurately identify whether the input is an adversarial instance.

Method used

Using the combination of the autoencoder machine learning model and the production machine learning model, the adversarial attack is detected by calculating divergence metrics, including generating the autoencoder output as the production model input, calculating divergence metrics and comparing them with the threshold, and performing corresponding actions to identify the adversarial attack.

Benefits of technology

实现了快速、准确地检测对抗攻击,减少了对计算资源的需求,避免了对抗实例样本的存储,提高了检测效率。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120283241A_ABST
    Figure CN120283241A_ABST
Patent Text Reader

Abstract

A system is provided that includes a processor to provide a first input to an auto-encoder machine learning model; generating a first output of the auto-encoder machine learning model based on the first input; providing the first input to a production machine learning model; providing the first output of the auto-encoder machine learning model as a second input to the production machine learning model; generating a first output of the production machine learning model based on the first input; generating a second output of the production machine learning model based on the second input; determining a divergence metric between the first output and the second output of the production machine learning model, wherein the divergence metric includes an indication of whether the first input is associated with an adversarial attack; and performing an action. Methods and computer program products are also provided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to the detection of adversarial examples, and in some non-limiting embodiments or aspects, to systems, methods, and computer program products for detecting adversarial attacks using a machine learning framework. Background Art

[0002] Deep neural networks (DNNs) can be used for classification / prediction tasks in various applications, such as face recognition, fraud detection, disease diagnosis, navigation of autonomous vehicles, etc. In such applications, the DNN receives an input and generates a prediction based on the input, e.g., the identity of an individual, whether a payment transaction is fraudulent or non-fraudulent, whether a disease is associated with one or more genetic markers, whether an object in the field of view of an autonomous vehicle is in the path of the autonomous vehicle, etc.

[0003] However, an adversary may create malicious inputs to manipulate the predictions of a DNN. For example, the adversary can generate malicious inputs by adding small perturbations that are imperceptible to humans to a sample input. The alteration can produce an input that, when provided to a machine learning model, causes the machine learning model to make a prediction that is different from the prediction that the machine learning model has made based on an input that does not include the malicious perturbation. This type of input is referred to as an adversarial example.

[0004] Thus, a machine learning model can generate an incorrect prediction based on receiving such adversarial examples as inputs. Although certain techniques have been developed to detect adversarial examples, these techniques can use multiple non-adversarial examples (e.g., as references) and / or adversarial examples to determine whether an input is an adversarial example. Therefore, these techniques may require the systems implementing these techniques to reserve additional computational resources and store sufficient samples of adversarial examples and / or non-adversarial examples to determine whether an input is an adversarial example. In addition, these techniques may require a significant amount of time to develop a system that accurately detects adversarial examples as attacks. Summary of the Invention

[0005] Therefore, systems, devices, products, apparatuses, and / or methods for detecting adversarial attacks using a machine learning framework that overcome some or all of the deficiencies of the prior art are disclosed.

[0006] According to some non - limiting embodiments or aspects, a system is provided that includes: at least one processor, the at least one processor being programmed or configured to: provide a first input to an auto - encoder machine - learning model; generate a first output of the auto - encoder machine - learning model based on the first input; provide the first input to a production machine - learning model; provide the first output of the auto - encoder machine - learning model as a second input to the production machine - learning model; generate a first output of the production machine - learning model based on the first input; generate a second output of the production machine - learning model based on the second input; determine a divergence metric between the first output of the production machine - learning model and the second output of the production machine - learning model, where the divergence metric includes an indication of whether the first input is associated with an adversarial attack; and perform an action based on the divergence metric.

[0007] According to some non - limiting embodiments or aspects, a computer - implemented method is provided that includes: providing, by at least one processor, a first input to an auto - encoder machine - learning model; generating, by at least one processor, a first output of the auto - encoder machine - learning model based on the first input; providing, by at least one processor, the first input to a production machine - learning model; providing, by at least one processor, the first output of the auto - encoder machine - learning model as a second input to the production machine - learning model; generating, by at least one processor, a first output of the production machine - learning model based on the first input; generating, by at least one processor, a second output of the production machine - learning model based on the second input; determining, by at least one processor, a divergence metric between the first output of the production machine - learning model and the second output of the production machine - learning model, where the divergence metric includes an indication of whether the first input is associated with an adversarial attack; and performing, by at least one processor, an action based on the divergence metric.

[0008] According to some non - limiting embodiments or aspects, there is provided a computer program product including: at least one non - transient computer - readable medium including one or more instructions which, when executed by at least one processor, cause the at least one processor to: provide a first input to an auto - encoder machine - learning model; generate a first output of the auto - encoder machine - learning model based on the first input; provide the first input to a production machine - learning model; provide the first output of the auto - encoder machine - learning model as a second input to the production machine - learning model; generate a first output of the production machine - learning model based on the first input; generate a second output of the production machine - learning model based on the second input; determine a divergence measure between the first output of the production machine - learning model and the second output of the production machine - learning model, wherein the divergence measure includes an indication of whether the first input is associated with an adversarial attack; and perform an action based on the divergence measure.

[0009] Other embodiments are set forth in the following numbered clauses:

[0010] Clause 1: A system including: at least one processor programmed or configured to: provide a first input to an auto - encoder machine - learning model; generate a first output of the auto - encoder machine - learning model based on the first input; provide the first input to a production machine - learning model; provide the first output of the auto - encoder machine - learning model as a second input to the production machine - learning model; generate a first output of the production machine - learning model based on the first input; generate a second output of the production machine - learning model based on the second input; determine a divergence measure between the first output of the production machine - learning model and the second output of the production machine - learning model, wherein the divergence measure includes an indication of whether the first input is associated with an adversarial attack; and perform an action based on the divergence measure.

[0011] Clause 2: The system according to Clause 1, wherein when performing the action, the at least one processor is programmed or configured to: determine whether the divergence measure meets a divergence threshold; and perform the action based on determining whether the divergence measure meets the divergence threshold.

[0012] Clause 3: The system according to Clause 1 or 2, wherein when determining whether the divergence measure meets the divergence threshold, the at least one processor is programmed or configured to: compare the divergence measure with the divergence threshold; and wherein the divergence threshold is based on the number of times the production machine - learning model correctly predicts a result.

[0013] Clause 4: The system according to any one of Clauses 1 to 3, wherein the at least one processor is further programmed or configured to: retrain the autoencoder machine learning model based on the divergence metric.

[0014] Clause 5: The system according to any one of Clauses 1 to 4, wherein the at least one processor is further programmed or configured to: receive raw data from a request for an inference of the production machine learning model; and perform a feature engineering process on the raw data to generate the first input.

[0015] Clause 6: The system according to any one of Clauses 1 to 5, wherein when performing the action, the at least one processor is programmed or configured to: determine whether the divergence metric meets a divergence threshold; and based on determining that the divergence metric does not meet the divergence threshold, provide the first output of the production machine learning model as a response to the request for an inference of the production machine learning model.

[0016] Clause 7: The system according to any one of Clauses 1 to 6, wherein when performing the action, the at least one processor is programmed or configured to: determine whether the divergence metric meets a divergence threshold; and generate an alert based on determining that the divergence metric does not meet the divergence threshold, or provide the first output of the production machine learning model as an input to an advanced production machine learning model based on determining that the divergence metric meets the divergence threshold.

[0017] Clause 8: A computer-implemented method, comprising: providing a first input to an autoencoder machine learning model with at least one processor; generating a first output of the autoencoder machine learning model based on the first input with at least one processor; providing the first input to a production machine learning model with at least one processor; providing the first output of the autoencoder machine learning model as a second input to the production machine learning model with at least one processor; generating a first output of the production machine learning model based on the first input with at least one processor; generating a second output of the production machine learning model based on the second input with at least one processor; determining a divergence metric between the first output of the production machine learning model and the second output of the production machine learning model, wherein the divergence metric includes an indication of whether the first input is associated with an adversarial attack; and performing an action based on the divergence metric with at least one processor.

[0018] Clause 9: The computer-implemented method according to Clause 8, wherein performing the action includes: determining whether the divergence metric meets a divergence threshold; and performing the action based on determining whether the divergence metric meets the divergence threshold.

[0019] Clause 10: The computer-implemented method according to clause 8 or 9, wherein determining whether the divergence measure satisfies the divergence threshold includes: comparing the divergence measure with the divergence threshold; and wherein the divergence threshold is based on the number of times the production machine learning model correctly predicts the result.

[0020] Clause 11: The computer-implemented method according to any one of clauses 8 to 10, further comprising: retraining the autoencoder machine learning model based on the divergence measure.

[0021] Clause 12: The computer-implemented method according to any one of clauses 8 to 11, further comprising: receiving raw data from a request for an inference of the production machine learning model; and performing a feature engineering process on the raw data to generate the first input.

[0022] Clause 13: The computer-implemented method according to any one of clauses 8 to 12, wherein performing the action includes: determining whether the divergence measure satisfies a divergence threshold; and based on determining that the divergence measure does not satisfy the divergence threshold, providing the first output of the production machine learning model as a response to a request for an inference of the production machine learning model.

[0023] Clause 14: The computer-implemented method according to any one of clauses 8 to 13, wherein performing the action includes: determining whether the divergence measure satisfies a divergence threshold; and generating an alert based on determining that the divergence measure does not satisfy the divergence threshold, or providing the first output of the production machine learning model as an input to an advanced production machine learning model based on determining that the divergence measure satisfies the divergence threshold.

[0024] Clause 15: A computer program product, comprising: at least one non-transitory computer-readable medium, the at least one non-transitory computer-readable medium including one or more instructions that, when executed by at least one processor, cause the at least one processor to: provide a first input to an autoencoder machine learning model; generate a first output of the autoencoder machine learning model based on the first input; provide the first input to a production machine learning model; provide the first output of the autoencoder machine learning model as a second input to the production machine learning model; generate a first output of the production machine learning model based on the first input; generate a second output of the production machine learning model based on the second input; determine a divergence measure between the first output of the production machine learning model and the second output of the production machine learning model, wherein the divergence measure includes an indication of whether the first input is associated with an adversarial attack; and perform an action based on the divergence measure.

[0025] Clause 16: The computer program product according to Clause 15, wherein the one or more instructions that cause the at least one processor to perform the action cause the at least one processor to: determine whether the divergence metric meets a divergence threshold; and perform the action based on determining whether the divergence metric meets the divergence threshold.

[0026] Clause 17: The computer program product according to Clause 15 or 16, wherein the one or more instructions that cause the at least one processor to determine whether the divergence metric meets the divergence threshold cause the at least one processor to: compare the divergence metric with the divergence threshold; and wherein the divergence threshold is based on the number of times the production machine learning model correctly predicts a result.

[0027] Clause 18: The computer program product according to any one of Clauses 15 to 17, wherein the one or more instructions further cause the at least one processor to: receive raw data from a request for an inference of the production machine learning model; and perform a feature engineering process on the raw data to generate the first input.

[0028] Clause 19: The computer program product according to any one of Clauses 15 to 18, wherein the one or more instructions that cause the at least one processor to perform the action cause the at least one processor to: determine whether the divergence metric meets a divergence threshold; and based on determining that the divergence metric does not meet the divergence threshold, provide the first output of the production machine learning model as a response to a request for an inference of the production machine learning model.

[0029] Clause 20: The computer program product according to any one of Clauses 15 to 19, wherein the one or more instructions that cause the at least one processor to perform the action cause the at least one processor to: determine whether the divergence metric meets a divergence threshold; and generate an alert based on determining that the divergence metric does not meet the divergence threshold, or provide the first output of the production machine learning model as an input to an advanced production machine learning model based on determining that the divergence metric meets the divergence threshold.

[0030] These and other features and characteristics of the present disclosure, as well as the methods of operation and functions of the related structural elements and combinations of the various parts, and the manufacturing economy, will become more apparent when considering the following description and the appended claims in conjunction with the accompanying drawings, all of which form a part of this specification, where like reference numerals designate corresponding parts in the various figures. However, it should be clearly understood that the drawings are for illustrative and descriptive purposes only and are not intended as a definition of the limits of the present disclosure. Unless the context clearly dictates otherwise, the singular forms "a" and "the" as used in this specification and the claims include plural referents. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] The additional advantages and details of the present disclosure are explained in more detail below with reference to the exemplary embodiments illustrated in the accompanying drawings, in which:

[0032] Figure 1 is a diagram of a non-limiting example or aspect of an environment in which the systems, devices, products, apparatuses, and / or methods described herein can be implemented in accordance with the principles of the present disclosure;

[0033] Figure 2 is Figure 1 a diagram of a non-limiting example or aspect of components of one or more devices of

[0034] Figure 3 is a flowchart of a non-limiting example or aspect of a process for detecting adversarial attacks using a machine learning framework; and

[0035] Figures 4A - 4F is a diagram of a non-limiting example or aspect of an implementation of a process for detecting anomalies in multivariate time series. DETAILED DESCRIPTION

[0036] For purposes of description below, the terms "end", "upper", "lower", "right", "left", "vertical", "horizontal", "top", "bottom", "lateral", "longitudinal", and derivatives thereof shall relate to the present disclosure as oriented in the accompanying drawings. However, it should be understood that the present disclosure may assume various alternative variations and sequences of steps, unless explicitly specified to the contrary. It should also be understood that the specific devices and processes illustrated in the drawings and described in the following description are merely exemplary embodiments or aspects of the present disclosure. Accordingly, unless otherwise indicated, the specific dimensions and other physical characteristics related to the embodiments or aspects of the disclosure herein should not be considered limiting.

[0037] Aspects, components, elements, structures, acts, steps, functions, instructions, etc. used herein should not be construed as critical or essential unless explicitly described as such. Additionally, as used herein, the article "a" is intended to include one or more items and may be used interchangeably with "one or more" and "at least one". Further, as used herein, the term "set" is intended to include one or more items (e.g., related items, unrelated items, combinations of related and unrelated items, etc.) and may be used interchangeably with "one or more" or "at least one". Where only one item is intended, the term "one" or similar language is used. Also, as used herein, the term "has" and / or its like is intended to be an open-ended term. Additionally, unless otherwise explicitly stated, the phrase "based on" is intended to mean "at least partially based on". In appropriate cases, the phrase "based on" may also mean "in response to".

[0038] As used herein, the terms "communicate" and "convey" can refer to the receipt, reception, sending, transmission, provisioning, etc. of information (e.g., data, signals, messages, instructions, commands, etc.). A unit (e.g., a device, a system, a component of a device or system, a combination thereof, etc.) communicates with another unit means that the one unit is capable of receiving information from and / or transmitting (e.g., sending) information to the other unit, either directly or indirectly. This can refer to a direct or indirect connection that is inherently wired and / or wireless. Additionally, although the information sent may be modified, processed, relayed, and / or routed between a first unit and a second unit, the two units can still communicate with each other. For example, even if the first unit receives information passively and does not actively send information to the second unit, the first unit can still communicate with the second unit. As another example, if at least one intermediate unit (e.g., a third unit located between the first unit and the second unit) processes the information received from the first unit and sends the processed information to the second unit, the first unit can communicate with the second unit. In some non-limiting embodiments, a message can refer to a network data packet (e.g., a data packet, etc.) that includes data.

[0039] As used herein, the terms "issuer", "issuer entity", "issuer bank", or "payment device issuer" may refer to one or more entities that provide an account for conducting payment transactions, such as credit card payment transactions and / or debit card payment transactions, to an individual (e.g., a user, customer, etc.). For example, an issuer entity may provide an account identifier, such as a primary account number (PAN), that uniquely identifies one or more accounts associated with the customer. In some non-limiting embodiments, the issuer may be associated with a bank identification number (BIN) that uniquely identifies the issuer entity. As used herein, an "issuer system" may refer to one or more computer systems operated by or on behalf of an issuer, such as a server that executes one or more software applications. For example, an issuer system may include one or more authorization servers for authorizing transactions.

[0040] As used herein, the term "transaction service provider" may refer to an entity that receives a transaction authorization request from a merchant or other entity and, in some cases, provides payment assurance through an agreement between the transaction service provider and the issuer entity. For example, a transaction service provider may include a payment network, such as American or any other entity that processes transactions. As used herein, the term "transaction service provider system" may refer to one or more computer systems operated by or on behalf of a transaction service provider, such as a transaction service provider system that executes one or more software applications. A transaction service provider system may include one or more processors and, in some non-limiting embodiments or aspects, may be operated by or on behalf of a transaction service provider.

[0041] As used herein, the term "merchant" may refer to one or more entities (e.g., an operator of a retail enterprise) that provide goods and / or services and / or access to goods and / or services to a user (e.g., a customer, consumer, etc.) based on a transaction, such as a payment transaction. As used herein, a "merchant system" may refer to one or more computer systems operated by or on behalf of a merchant, such as a server that executes one or more software applications. As used herein, the term "product" may refer to one or more goods and / or services provided by a merchant.

[0042] As used herein, the term "acquirer" may refer to an entity that is licensed by and approved by a transaction service provider to initiate a transaction (e.g., a payment transaction) involving a payment device associated with the transaction service provider. As used herein, the term "acquirer system" may also refer to one or more computer systems, computer devices, etc. operated by or on behalf of the acquirer. Transactions that an acquirer may initiate may include payment transactions (e.g., purchases, original credit transactions (OCTs), account funding transactions (AFTs), etc.). In some non-limiting embodiments, the acquirer may be authorized by the transaction service provider to contract with a merchant or service provider to initiate a transaction involving a payment device associated with the transaction service provider. The acquirer may contract with a payment service provider to enable the payment service provider to provide sponsorship to a merchant. The acquirer may monitor the compliance of the payment service provider according to the regulations of the transaction service provider. The acquirer may conduct due diligence on the payment service provider and ensure that appropriate due diligence is conducted before contracting with a sponsored merchant. The acquirer may be responsible for all transaction service provider programs operated or sponsored by the acquirer. The acquirer may be responsible for the actions of the acquirer's payment service providers, merchants sponsored by the acquirer's payment service providers, etc. In some non-limiting embodiments, the acquirer may be a financial institution, such as a bank.

[0043] As used herein, the term "payment gateway" may refer to an entity and / or a payment processing system operated by or on behalf of such entity, where the entity (e.g., a merchant service provider, a payment service provider, a payment facilitator, a payment facilitator under contract with an acquirer, a payment aggregator, etc.) provides payment services (e.g., transaction service provider payment services, payment processing services, etc.) to one or more merchants. The payment services may be associated with the use of a portable financial device managed by the transaction service provider. As used herein, the term "payment gateway system" may refer to one or more computer systems, computer devices, servers, server groups, etc. operated by or on behalf of the payment gateway.

[0044] As used herein, the terms "client" and "client device" may refer to one or more computing devices, such as a processor, a storage device, and / or similar computer components that access services that may be provided by a server. In some non-limiting embodiments, the client device may include a computing device configured to communicate with one or more networks and / or facilitate a payment transaction, such as but not limited to one or more desktop computers, one or more portable computers (e.g., tablet computers), one or more mobile devices (e.g., cellular phones, smartphones, personal digital assistants, wearable devices such as watches, glasses, lenses, and / or clothing, etc.), and / or other similar devices. Additionally, the term "client" may also refer to an entity that owns, uses, and / or operates a client device to facilitate a transaction with another entity.

[0045] As used herein, the term "server" may refer to one or more computing devices, such as a processor, a storage device, and / or similar computer components, that communicate with client devices and / or other computing devices over a network such as the Internet or a private network, and in some examples, facilitate communication between other servers and / or client devices.

[0046] As used herein, the term "system" may refer to one or more computing devices or a combination of computing devices, such as but not limited to a processor, a server, a client device, a software application, and / or other similar components. Additionally, as used herein, a reference to a "server" or "processor" may refer to the previously described server and / or processor stated to perform a previous step or function, a different server and / or processor, and / or a combination of servers and / or processors. For example, as used in the specification and claims, a first server and / or a first processor stated to perform a first step or function may refer to the same or a different server and / or processor stated to perform a second step or function.

[0047] Some non-limiting embodiments or aspects are described herein in connection with a threshold. As used herein, meeting a threshold may refer to a value that is greater than the threshold, more than the threshold, higher than the threshold, greater than or equal to the threshold, less than the threshold, fewer than the threshold, lower than the threshold, less than or equal to the threshold, equal to the threshold, etc.

[0048] Non-limiting embodiments or aspects of the present disclosure relate to systems, methods, and computer program products for detecting adversarial attacks using a machine learning framework. In some non-limiting embodiments or aspects, an adversarial detection system may provide a first input to an autoencoder machine learning model; generate a first output of the autoencoder machine learning model based on the first input; provide the first input to a production machine learning model; provide the first output of the autoencoder machine learning model as a second input to the production machine learning model; generate a first output of the production machine learning model based on the first input; generate a second output of the production machine learning model based on the second input; determine a divergence metric between the first output of the production machine learning model and the second output of the production machine learning model, wherein the divergence metric includes an indication of whether the first input is associated with an adversarial attack; and perform an action based on the divergence metric.

[0049] In some non - limiting embodiments or aspects, when performing an action, an adversarial detection system can determine whether a divergence metric meets a divergence threshold and perform an action based on determining whether the divergence metric meets the divergence threshold. In some non - limiting embodiments or aspects, when determining whether the divergence metric meets the divergence threshold, the adversarial detection system can compare the divergence metric with the divergence threshold. In some non - limiting embodiments or aspects, the divergence threshold can be based on the number of times a production machine - learning model correctly predicts a result. In some non - limiting embodiments or aspects, the adversarial detection system can retrain an auto - encoder machine - learning model based on the divergence metric. In some non - limiting embodiments or aspects, the adversarial detection system can receive raw data from a request for an inference of a production machine - learning model and perform a feature - engineering process on the raw data to generate a first input.

[0050] In some non - limiting embodiments or aspects, when performing an action, the adversarial detection system can determine whether a divergence metric meets a divergence threshold and, based on determining that the divergence metric meets the divergence threshold, provide a first output of the production machine - learning model as a response to a request for an inference of the production machine - learning model.

[0051] In some non - limiting embodiments or aspects, when performing an action, the adversarial detection system can determine whether a divergence metric meets a divergence threshold and generate an alert based on determining that the divergence metric meets the divergence threshold, or provide the first output of the production machine - learning model as an input to an advanced production machine - learning model based on determining that the divergence metric meets the divergence threshold.

[0052] In this way, the adversarial detection system can achieve accurately analyzing raw data to determine whether the raw data includes an adversarial attack in the form of an injected adversarial instance. Non - limiting embodiments or aspects can provide the ability to accurately detect adversarial attacks without the need to reserve additional computing resources and store samples of adversarial and / or non - adversarial instances to determine whether an input is an adversarial instance. Additionally, non - limiting embodiments or aspects can achieve improved detection of adversarial events (e.g., adversarial instances injected by an attacker) by using an auto - encoder - based machine - learning model.

[0053] Now refer to Figure 1 , Figure 1 is a diagram of an example environment 100 in which the apparatuses, systems, and / or methods described herein can be implemented. As Figure 1 shown, the environment 100 can include an adversarial detection system 102, a transaction - service - provider system 104, a user device 106, and a communication network 108. The adversarial detection system 102, the transaction - service - provider system 104, and / or the user device 106 can be interconnected via a wired connection, a wireless connection, or a combination of wired and wireless connections (e.g., establish a connection for communication).

[0054] The anti-fraud detection system 102 may include one or more devices configured to communicate with a transaction service provider system 104 and / or a user device 106 via a communication network 108. For example, the anti-fraud detection system 102 may include servers, server clusters, and / or other similar devices. In some non-limiting embodiments or aspects, the anti-fraud detection system 102 may be associated with the transaction service provider system (e.g., may be operated by the transaction service provider as a component of the transaction service provider system, may be operated by the transaction service provider independently of the transaction service provider system, etc.), as described herein. Additionally or alternatively, the anti-fraud detection system 102 may generate (e.g., train, validate, retrain, etc.), store, and / or implement one or more machine learning models (e.g., operate one or more machine learning models, provide inputs to one or more machine learning models, and / or provide outputs from one or more machine learning models, etc.). For example, the anti-fraud detection system 102 may generate one or more machine learning models by fitting (e.g., validating) one or more machine learning models against data used for training (e.g., training data). In some non-limiting embodiments or aspects, the anti-fraud detection system 102 may generate, store, and / or implement one or more autoencoder machine learning models and / or one or more machine learning models provided for a production environment (e.g., a real-time or runtime environment for providing inferences based on data in a live scenario). In some non-limiting embodiments or aspects, the anti-fraud detection system 102 may communicate with a data storage device, which may be local or remote to the anti-fraud detection system 102. In some non-limiting embodiments or aspects, the anti-fraud detection system 102 may be capable of receiving information from the data storage device, storing information in the data storage device, transmitting information to the data storage device, and / or searching for information stored in the data storage device.

[0055] The transaction service provider system 104 may include one or more devices configured to communicate with the anti-fraud detection system 102 and / or the user device 106 via the communication network 108. For example, the transaction service provider system 104 may include computing devices, such as servers, server clusters, and / or other similar devices. In some non-limiting embodiments or aspects, the transaction service provider system 104 may be associated with the transaction service provider system, as discussed herein. In some non-limiting embodiments or aspects, a time series analysis system may be a component of the transaction service provider system 104.

[0056] The user device 106 may include a computing device configured to communicate with the adversarial detection system 102 and / or the transaction service provider system 104 via the communication network 108. For example, the user device 106 may include a computing device such as a desktop computer, a portable computer (e.g., a tablet computer, a laptop computer, etc.), a mobile device (e.g., a cellular phone, a smartphone, a personal digital assistant, a wearable device, etc.), and / or other similar devices. In some non-limiting embodiments or aspects, the user device 106 may be associated with a user (e.g., an individual operating the user device 106).

[0057] The communication network 108 may include one or more wired and / or wireless networks. For example, the communication network 108 may include a cellular network (e.g., a Long-Term Evolution network, a third-generation (3G) network, a fourth-generation (4G) network, a fifth-generation (5G) network, a Code Division Multiple Access (CDMA) network, etc.), a Public Land Mobile Network (PLMN), a Local Area Network (LAN), a Wide Area Network (WAN), a Metropolitan Area Network (MAN), a telephone network (e.g., a Public Switched Telephone Network (PSTN), etc.), a private network, an ad hoc network, an intranet, the Internet, a fiber-optic-based network, a cloud computing network, etc., and / or a combination of some or all of these or other types of networks.

[0058] Provide Figure 1 The number and arrangement of the devices and networks shown in Figure 1 are provided as an example. There may be additional devices and / or networks, fewer devices and / or networks, different devices and / or networks, or differently arranged devices and / or networks compared to those shown in Figure 1 In addition, Figure 1 two or more of the devices shown in

[0059] Now refer to Figure 2 , Figure 2 which is a diagram of example components of the device 200. The device 200 may correspond to the adversarial detection system 102 (e.g., one or more devices of the adversarial detection system 102), the transaction service provider system 104 (e.g., one or more devices of the transaction service provider system 104), and / or the user device 106. In some non-limiting embodiments or aspects, the adversarial detection system 102, the transaction service provider system 104, and / or the user device 106 may include at least one device 200 and / or at least one component of the device 200. As Figure 2As shown, device 200 may include bus 202, processor 204, memory 206, storage component 208, input component 210, output component 212, and communication interface 214.

[0060] Bus 202 may include components that permit communication among the components of device 200. In some non-limiting embodiments, processor 204 may be implemented in hardware, software, or a combination of hardware and software. For example, processor 204 may include a processor (e.g., a central processing unit (CPU), a graphics processing unit (GPU), an accelerated processing unit (APU), etc.), a microprocessor, a digital signal processor (DSP), and / or any processing component that can be programmed to perform functions (e.g., a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), etc.). Memory 206 may include random access memory (RAM), read only memory (ROM), and / or another type of dynamic or static memory that stores information and / or instructions for use by processor 204 (e.g., flash memory, magnetic memory, optical memory, etc.).

[0061] Storage component 208 may store information and / or software related to the operation and use of device 200. For example, storage component 208 may include a hard disk (e.g., a magnetic disk, an optical disk, a magneto-optical disk, a solid state disk, etc.), a compact disc (CD), a digital versatile disc (DVD), a floppy disk, a cassette tape, a magnetic tape, and / or another type of computer-readable medium, as well as a corresponding drive.

[0062] Input component 210 may include components that permit device 200 to receive information, e.g., via user input (e.g., a touch screen display, a keyboard, a keypad, a mouse, a button, a switch, a microphone, etc.). Additionally or alternatively, input component 210 may include sensors for sensing information (e.g., a global positioning system (GPS) component, an accelerometer, a gyroscope, an actuator, etc.). Output component 212 may include components that provide output information from device 200 (e.g., a display, a speaker, one or more light emitting diodes (LEDs), etc.).

[0063] Communication interface 214 may include transceiver-like components (e.g., a transceiver, separate receiver and transmitter, etc.) that enable device 200 to communicate with other devices, e.g., via a wired connection, a wireless connection, or a combination of a wired connection and a wireless connection. Communication interface 214 may permit device 200 to receive information from another device and / or provide information to another device. For example, communication interface 214 may include an Ethernet interface, an optical interface, a coaxial interface, an infrared interface, a radio frequency (RF) interface, a universal serial bus (USB) interface, an interface, a cellular network interface, etc.

[0064] Device 200 may perform one or more processes described herein. Device 200 may perform these processes based on software instructions stored by a computer-readable medium such as memory 206 and / or storage component 208 and executed by processor 204. A computer-readable medium (e.g., a non-transitory computer-readable medium) is defined herein as a non-transitory memory device. A memory device includes a memory space located within a single physical storage device or a memory space that extends across multiple physical storage devices.

[0065] The software instructions may be read into memory 206 and / or storage component 208 from another computer-readable medium or from another device via communication interface 214. When executed, the software instructions stored in memory 206 and / or storage component 208 may cause processor 204 to perform one or more processes described herein. Additionally or alternatively, hardwired circuitry may be used in place of or in combination with the software instructions to perform one or more processes described herein. Accordingly, the embodiments described herein are not limited to any particular combination of hardware circuitry and software.

[0066] Figure 2 The number and arrangement of components shown are provided as an example. In some non-limiting embodiments or aspects, device 200 may include additional components, fewer components, different components, or differently arranged components compared to the components shown in Figure 2 In addition or alternatively, a set of components (e.g., one or more components) of device 200 may perform one or more functions described as being performed by another set of components of device 200.

[0067] Now referring to Figure 3 , Figure 3 is a flowchart of a non-limiting embodiment or aspect of process 300 for detecting adversarial attacks using a machine learning framework. In some non-limiting embodiments or aspects, one or more steps of process 300 may be performed by adversarial detection system 102 (e.g., one or more devices of adversarial detection system 102) (e.g., fully, partially, etc.). In some non-limiting embodiments or aspects, one or more steps of process 300 may be performed by another device or group of devices (e.g., fully, partially, etc.) separate from or including adversarial detection system 102 (e.g., one or more devices of adversarial detection system 102), transaction service provider system 104 (e.g., one or more devices of transaction service provider system 104), and / or user device 106.

[0068] As Figure 3As shown, at step 302, process 300 includes generating an output of an autoencoder machine learning model. For example, adversarial detection system 102 can generate an output of an autoencoder machine learning model. In some non-limiting embodiments or aspects, adversarial detection system 102 can provide a first input to the autoencoder machine learning model and generate a first output of the autoencoder machine learning model based on the first input.

[0069] In some non-limiting embodiments or aspects, adversarial detection system 102 can receive raw data associated with (e.g., included in) a request for an inference of a production machine learning model and perform a feature engineering process on the raw data to produce a first input. In some non-limiting embodiments or aspects, the raw data can be associated with a task for which the production machine learning model can provide an inference. In some non-limiting embodiments or aspects, the raw data can be associated with a financial services task. For example, the raw data can be associated with a token service task, an authentication task (e.g., 3D secure authentication task), a fraud detection task, etc.

[0070] In some non-limiting embodiments or aspects, the raw data can include runtime input data. In some non-limiting embodiments or aspects, the runtime input data can include data samples received in real time by a trained machine learning model relative to the runtime input data being generated. For example, the runtime input data can be generated by a data source (e.g., a customer performing a transaction) and subsequently received in real time by a trained machine learning model. Runtime (e.g., production) can refer to inputting runtime data (e.g., a runtime dataset, real-world data, real-world observations, etc.) into one or more trained machine learning models (e.g., one or more trained machine learning models of adversarial detection system 102) and / or generating an inference (e.g., using adversarial detection system 102 or another machine learning system to generate an inference).

[0071] In some non-limiting embodiments or aspects, runtime can be performed during a stage that may occur after the training stage, after the testing stage, and / or after deploying the machine learning model to a production environment. During a time period associated with the runtime stage, the machine learning model (e.g., the production machine learning model) can process the runtime input data to generate an inference (e.g., a real-time inference, a real-time prediction, etc.).

[0072] In some non-limiting embodiments or aspects, an autoencoder machine learning model may include a specific type of feedforward neural network, where the input of the feedforward neural network is the same as the output of the feedforward neural network. The feedforward neural network can be used to compress the input into a latent space representation (e.g., a low-dimensional code), which is a compact overview (e.g., compression) of the input, and the output can be reconstructed from the latent space representation. In some non-limiting embodiments or aspects, an autoencoder machine learning model may include three components: an encoder; a code; and a decoder. The encoder can be used to learn a projection method to map the input to a manifold (e.g., a kernel space) with a lower dimension than the input. The code can be used to compress the input and produce a latent space representation, and the decoder can be used to reconstruct the input using the latent space representation.

[0073] As Figure 3 shown, at step 304, process 300 includes generating a first output of the production machine learning model. For example, the adversarial detection system 102 may generate the first output of the production machine learning model. In some non-limiting embodiments or aspects, the adversarial detection system 102 may generate the first output of the production machine learning model based on a first input provided as input to the autoencoder machine learning model. For example, the adversarial detection system 102 may provide the first input to the production machine learning model, and the first input is the same as the first input provided to the autoencoder machine learning model. The adversarial detection system 102 may generate the first output of the production machine learning model based on providing the first input (e.g., as input) to the production machine learning model. In some non-limiting embodiments or aspects, the adversarial detection system 102 may generate the first output of the production machine learning model based on the first input, while the adversarial detection system 102 generates the first output of the autoencoder machine learning model based on the first input.

[0074] In some non-limiting embodiments or aspects, the production machine learning model may include a machine learning model that has been trained and / or validated (e.g., tested) and can be used to generate inferences (e.g., predictions) such as real-time inferences, runtime inferences, etc.

[0075] As Figure 3 shown, at step 306, process 300 includes generating a second output of the production machine learning model. For example, the adversarial detection system 102 may generate the second output of the production machine learning model.

[0076] In some non - limiting embodiments or aspects, the adversarial detection system 102 can generate a second output of the production machine - learning model based on the output of an auto - encoder machine - learning model. For example, the adversarial detection system 102 can provide a first input to the auto - encoder machine - learning model, and the second output of the production machine - learning model is based on the output of the auto - encoder machine - learning model generated from the first input (e.g., the first input used to generate the first output of the production machine - learning model). The adversarial detection system 102 can generate the second output of the production machine - learning model by providing the output of the auto - encoder machine - learning model (e.g., as an input) to the production machine - learning model. In some non - limiting embodiments or aspects, the adversarial detection system 102 can generate the second output of the production machine - learning model based on the output of the auto - encoder machine - learning model, while the adversarial detection system 102 generates the output of the auto - encoder machine - learning model based on the first input.

[0077] As Figure 3 shown, at step 308, process 300 includes determining a divergence metric between the first output and the second output. For example, the adversarial detection system 102 can determine a divergence metric between the first output and the second output of the production machine - learning model. The divergence metric can include an indication of whether the input (e.g., the first input of the production machine - learning model) is associated with an adversarial attack. In some non - limiting embodiments or aspects, the divergence metric can include the value of the Kullback - Leibler (KL) divergence (e.g., relative entropy, I - divergence, etc.). In some non - limiting embodiments or aspects, the KL divergence is a type of statistical distance that provides a measure of how different a first probability distribution is from a second reference probability distribution.

[0078] In some non - limiting embodiments or aspects, the adversarial detection system 102 can train (e.g., retrain) the trained machine - learning models, such as the auto - encoder machine - learning model and / or the production machine - learning model, based on the divergence metric. For example, the adversarial detection system 102 can retrain the trained machine - learning models based on the value of the KL divergence between the first output and the second output of the production machine - learning model.

[0079] As Figure 3As shown, at step 310, process 300 includes performing an action based on a divergence metric. For example, adversarial detection system 102 may perform an action based on a divergence metric. In some non-limiting embodiments or aspects, adversarial detection system 102 may determine whether the divergence metric meets a divergence threshold and perform an action based on the determination of whether the divergence metric meets the divergence threshold. For example, adversarial detection system 102 may determine a divergence metric between a first output and a second output of a production machine learning model and may compare the divergence metric with a divergence threshold. If the divergence metric meets the divergence threshold, adversarial detection system 102 may perform an action based on the determination that the divergence metric meets the divergence threshold. If the divergence metric does not meet the divergence threshold, adversarial detection system 102 may refrain from performing an action based on the determination that the divergence metric does not meet the divergence threshold. In some non-limiting embodiments or aspects, the divergence threshold is a value based on the number of times the production machine learning model correctly predicts an outcome. In some non-limiting embodiments or aspects, the divergence threshold is a value that may be updated. For example, adversarial detection system 102 may update the divergence threshold based on the number of times the production machine learning model correctly predicts an outcome. In some non-limiting embodiments or aspects, if the production machine learning model correctly predicts the outcomes of a plurality of predetermined inferences, adversarial detection system 102 may refrain from updating the divergence threshold. In some non-limiting embodiments or aspects, if the production machine learning model does not correctly predict the outcomes of a plurality of predetermined inferences, adversarial detection system 102 may update the divergence threshold.

[0080] In some non-limiting embodiments or aspects, adversarial detection system 102 may perform an action by providing the first output of the production machine learning model as a response to a request for an inference of the production machine learning model. In some non-limiting embodiments or aspects, adversarial detection system 102 may perform an action by generating and transmitting an alert (e.g., an alert message) based on the determination that the divergence metric does not meet the divergence threshold. For example, adversarial detection system 102 may perform an action by generating an alert and transmitting the alert to user device 106 (e.g., a user associated with user device 106, such as a subject matter expert). Additionally or alternatively, adversarial detection system 102 may perform an action by providing the first output of the production machine learning model as an input to an advanced production machine learning model. The advanced production machine learning model may include a machine learning model configured to perform the same or a similar task as the production machine learning model; however, the advanced production machine learning model may be more accurate, may require more time, and / or may require additional computing resources compared to the production machine learning model in order to perform the task.

[0081] Now refer to Figures 4A - 4F , Figures 4A - 4FFIG. is a schematic diagram of an embodiment 400 or aspect of one (e.g., process 300) for detecting adversarial attacks using a machine learning framework.

[0082] As Figure 4A shown by reference numeral 405 in the accompanying drawings, the adversarial detection system 102 may receive raw data included in a request for an inference of a production machine learning model. For example, the adversarial detection system 102 may receive a request for an inference of a production machine learning model in real time, and the request for the inference may be associated with a financial service provided by a transaction service provider. As Figure 4A further shown by reference numeral 410 in the accompanying drawings, the adversarial detection system 102 may perform a feature engineering process on the raw data to generate a first input. The adversarial detection system 102 may perform a feature engineering process on the raw data so as to provide the first input in a format suitable for the production machine learning model. In some non-limiting embodiments or aspects, the first input may be an input that will be provided to the production machine learning model as an input that can be used to provide inferences in real time.

[0083] As Figure 4B shown by reference numeral 415 in the accompanying drawings, the adversarial detection system 102 may generate a first output of an autoencoder machine learning model shown as "x'". For example, the adversarial detection system 102 may provide a first input shown as "x" to the autoencoder machine learning model, and may generate a first output of the autoencoder machine learning model based on the first input. As Figure 4B further shown by reference numeral 420 in the accompanying drawings, the adversarial detection system 102 may generate an output of the production machine learning model. For example, the adversarial detection system 102 may provide the first input to the production machine learning model, and may provide the first output of the autoencoder machine learning model as a second input to the production machine learning model. The adversarial detection system 102 may generate a first output of the production machine learning model shown as "M(x)" based on the first input, and may generate a second output of the production machine learning model shown as "M(x')" based on the second input.

[0084] As Figure 4C shown by reference numeral 425 in the accompanying drawings, the adversarial detection system 102 may determine a divergence metric between the first output of the production machine learning model and the second output of the production machine learning model. In some non-limiting embodiments or aspects, the divergence metric includes an indication of whether the first input is associated with an adversarial attack. In some non-limiting embodiments or aspects, the divergence metric may include the value of the KL divergence between the first output and the second output of the production machine learning model.

[0085] As Figure 4DAs shown by reference numeral 430 in the figure, the adversarial detection system 102 can determine whether the divergence metric meets the divergence threshold. For example, the adversarial detection system 102 can compare the divergence metric with the divergence threshold based on the determined divergence metric. In some non-limiting embodiments or aspects, the divergence threshold is based on the number of times the production machine learning model correctly predicts the result.

[0086] As Figure 4E shown by reference numeral 435 in the figure, the adversarial detection system 102 can perform a first action based on determining that the divergence metric does not meet the divergence threshold. For example, the adversarial detection system 102 can provide the first output of the production machine learning model as a response to a request for an inference of the production machine learning model based on determining that the divergence metric does not meet the divergence threshold. As Figure 4E further shown by reference numeral 440 in the figure, the adversarial detection system 102 can perform a second action based on determining that the divergence metric meets the divergence threshold. For example, the adversarial detection system 102 can generate an alert based on determining that the divergence metric does not meet the divergence threshold and / or provide the first output of the production machine learning model as an input to an advanced production machine learning model based on determining that the divergence metric meets the divergence threshold.

[0087] As Figure 4F shown by reference numeral 445 in the figure, the adversarial detection system 102 can train an autoencoder machine learning model based on the divergence metric. For example, the adversarial detection system 102 can retrain the autoencoder machine learning model (e.g., the trained autoencoder machine learning model) according to the following formula:

[0088]

[0089] where KL(P||Q) is the KL divergence between the second output P of the production machine learning model and the first output Q of the production machine learning model, which can be used as a reference.

[0090] Although the present disclosure has been described in detail for purposes of illustration based on the currently considered most practical and preferred embodiments or aspects, it should be understood that such details are for that purpose only and that the present disclosure is not limited to the disclosed embodiments or aspects, but rather is intended to cover modifications and equivalent arrangements within the spirit and scope of the appended claims. For example, it should be understood that the present disclosure contemplates that, to the extent possible, one or more features of any embodiment may be combined with one or more features of any other embodiment.

Claims

1. A system, comprising: at least one processor programmed or configured to: provide a first input to an autoencoder machine learning model; generate a first output of the autoencoder machine learning model based on the first input; provide the first input to a production machine learning model; provide the first output of the autoencoder machine learning model as a second input to the production machine learning model; generate a first output of the production machine learning model based on the first input; generate a second output of the production machine learning model based on the second input; determine a divergence metric between the first output and the second output of the production machine learning model, wherein the divergence metric includes an indication of whether the first input is associated with an adversarial attack; and perform an action based on the divergence metric.

2. The system of claim 1, wherein when performing the action, the at least one processor is programmed or configured to: determine whether the divergence metric meets a divergence threshold; and perform the action based on determining whether the divergence metric meets the divergence threshold.

3. The system of claim 2, wherein when determining whether the divergence metric meets the divergence threshold, the at least one processor is programmed or configured to: compare the divergence metric with the divergence threshold; and wherein the divergence threshold is based on the number of times the production machine learning model correctly predicts a result.

4. The system of claim 1, wherein the at least one processor is further programmed or configured to: retrain the autoencoder machine learning model based on the divergence metric.

5. The system of claim 1, wherein the at least one processor is further programmed or configured to: receive raw data from a request for an inference of the production machine learning model; and perform a feature engineering process on the raw data to produce the first input.

6. The system of claim 1, wherein when performing the action, the at least one processor is programmed or configured to: determine whether the divergence metric meets a divergence threshold; and based on determining that the divergence metric does not meet the divergence threshold, provide the first output of the production machine learning model as a response to the request for an inference of the production machine learning model.

7. The system of claim 1, wherein when performing the action, the at least one processor is programmed or configured to: determine whether the divergence metric meets a divergence threshold; and generate an alert based on determining that the divergence metric does not meet the divergence threshold, or provide the first output of the production machine learning model as an input to an advanced production machine learning model based on determining that the divergence metric meets the divergence threshold.

8. A computer-implemented method, comprising: providing, by at least one processor, a first input to an autoencoder machine learning model; generating, by at least one processor, a first output of the autoencoder machine learning model based on the first input; Provide the first input to a production machine learning model using at least one processor; Provide the first output of the autoencoder machine learning model as a second input to the production machine learning model using at least one processor; Generate a first output of the production machine learning model based on the first input using at least one processor; Generate a second output of the production machine learning model based on the second input using at least one processor; Determine a divergence metric between the first output of the production machine learning model and the second output of the production machine learning model using at least one processor, wherein the divergence metric includes an indication of whether the first input is associated with an adversarial attack; And Perform an action based on the divergence metric using at least one processor.

9. The computer-implemented method according to claim 8, wherein performing the action includes: Determine whether the divergence metric meets a divergence threshold; And Perform the action based on determining whether the divergence metric meets the divergence threshold.

10. The computer-implemented method according to claim 9, wherein determining whether the divergence metric meets the divergence threshold includes: Compare the divergence metric with the divergence threshold; And wherein the divergence threshold is based on the number of times the production machine learning model correctly predicts a result.

11. The computer-implemented method according to claim 8, further comprising: Retrain the autoencoder machine learning model based on the divergence metric.

12. The computer-implemented method according to claim 8, further comprising: Receive raw data from a request for an inference of the production machine learning model; And Perform a feature engineering process on the raw data to produce the first input.

13. The computer-implemented method according to claim 8, wherein performing the action includes: Determine whether the divergence metric meets a divergence threshold; And Based on determining that the divergence metric does not meet the divergence threshold, provide the first output of the production machine learning model as a response to a request for an inference of the production machine learning model.

14. The computer-implemented method according to claim 8, wherein performing the action includes: Determine whether the divergence metric meets a divergence threshold; And Generate an alert based on determining that the divergence metric does not meet the divergence threshold, or Provide the first output of the production machine learning model as an input to an advanced production machine learning model based on determining that the divergence metric meets the divergence threshold.

15. A computer program product, comprising at least one non-transitory computer-readable medium, the at least one non-transitory computer-readable medium including one or more instructions that, when executed by at least one processor, cause the at least one processor to: Provide a first input to an autoencoder machine learning model; Generate a first output of the autoencoder machine learning model based on the first input; Provide the first input to a production machine learning model; Provide the first output of the autoencoder machine learning model as a second input to the production machine learning model; Generate a first output of the production machine learning model based on the first input; Generate a second output of the production machine learning model based on the second input; Determine a divergence metric between the first output and the second output of the production machine learning model, where the divergence metric includes an indication of whether the first input is associated with an adversarial attack; And Perform an action based on the divergence metric.

16. The computer program product according to claim 15, wherein the one or more instructions that cause the at least one processor to perform the action cause the at least one processor to: Determine whether the divergence metric meets a divergence threshold; and Perform the action based on determining whether the divergence metric meets the divergence threshold.

17. The computer program product according to claim 16, wherein the one or more instructions that cause the at least one processor to determine whether the divergence metric meets the divergence threshold cause the at least one processor to: Compare the divergence metric with the divergence threshold; and wherein the divergence threshold is based on the number of times the production machine learning model correctly predicts a result.

18. The computer program product according to claim 15, wherein the one or more instructions further cause the at least one processor to: Receive raw data from a request for an inference of the production machine learning model; and Perform a feature engineering process on the raw data to produce the first input.

19. The computer program product according to claim 15, wherein the one or more instructions that cause the at least one processor to perform the action cause the at least one processor to: Determine whether the divergence metric meets a divergence threshold; and Based on determining that the divergence metric does not meet the divergence threshold, provide the first output of the production machine learning model as a response to a request for an inference of the production machine learning model.

20. The computer program product according to claim 15, wherein the one or more instructions that cause the at least one processor to perform the action cause the at least one processor to: Determine whether the divergence metric meets a divergence threshold; and Generate an alert based on determining that the divergence metric does not meet the divergence threshold, or Based on determining that the divergence metric meets the divergence threshold, provide the first output of the production machine learning model as an input to a high-level production machine learning model.