Mobile application runtime behavior detection and control method

By collecting and analyzing the CPU occupancy data of mobile applications, and using timing encoding and message delivery mechanisms to generate predicted values, the problems of high false alarm rates and difficult to identify hidden attacks in traditional detection methods are solved, and precise control of mobile application behavior is achieved.

CN120296726AInactive Publication Date: 2025-07-11STATE GRID HENAN INFORMATION & TELECOMM CO
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510352788.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-07-11
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional mobile application runtime behavior detection methods cannot effectively identify progressive attacks with timing correlation characteristics, and are prone to misjudgment of legal high-load applications as abnormalities, and cannot achieve early warnings for hidden resource abuse.

Method used

By continuously collecting the CPU occupancy data of the target application, the time stack is formed, and local time domain features are extracted using timing encoding. The time series message delivery mechanism combined with the feature space constraints captures long-range dependencies, generates CPU occupancy prediction values, and volatility comparisons with the actual monitored values, intelligently judges resource occupancy abnormalities and triggers early warnings.

Benefits of technology

The false alarm rate of legal high-load applications has been reduced, which has significantly improved the early warning capability for hidden resource abuse, and provided accurate and adaptive mobile application runtime behavior control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296726A_ABST
    Figure CN120296726A_ABST
Patent Text Reader

Abstract

The invention provides a mobile application runtime behavior detection and control method, and relates to the field of intelligent detection.The method comprises the steps that firstly, CPU occupancy rate data during target application runtime are continuously collected to form a time stack, local time domain features are extracted through time sequence coding, a feature space constrained time sequence message passing mechanism is used for capturing a long-range dependency relationship, and a target application runtime behavior is obtained; the method comprises the following steps: simulating a dynamic propagation rule of resource occupation, then generating a CPU occupancy rate prediction value at the next moment through time sequence decoding, carrying out volatility comparison on the CPU occupancy rate prediction value and an actual monitoring value to intelligently judge whether resource occupation abnormity exists or not, and triggering early warning. Thus, the false alarm rate of legal high-load applications can be reduced, early warning of hidden resource abuse behaviors can be realized, and a technical path with both accuracy and adaptability is provided for behavior management and control during mobile application running.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of intelligent detection, and more particularly, in the embodiments of this application, it relates to a method for detecting and controlling the runtime behavior of mobile applications. Background Art

[0002] As mobile devices become the core carriers of modern digital life, the dynamic monitoring and control technology of the runtime behavior of mobile applications has become a key defense line for ensuring system stability, user privacy, and terminal security.

[0003] Traditional security mechanisms mainly rely on static code signature verification or real-time resource monitoring based on fixed thresholds. However, static detection cannot cover runtime dynamic behaviors, and although real-time monitoring can capture instantaneous abnormal indicators, it faces two key defects: First, the preset global fixed threshold (such as an alarm is triggered when the CPU occupancy rate exceeds 70%) ignores the differences in application types and the relevance of scenario contexts, resulting in normal peaks of high-load applications (such as 3D games, video editors) being misjudged as abnormal, while malicious programs can bypass detection by disguising high-load behaviors or consuming resources in a phased low-intensity manner (such as continuously occupying 40% of the CPU for data theft); Second, the resource value analysis at a single time point is difficult to identify progressive attacks with time-series correlation characteristics. For example, a malicious program occupies the CPU resources in a periodic pulse manner, and its single peak value may be lower than the threshold, and the traditional discrete value comparison mechanism cannot capture its cumulative abnormal fluctuations.

[0004] Therefore, an optimized detection and control scheme for the runtime behavior of mobile applications is desired. Summary of the Invention

[0005] To solve the above technical problems, this application is proposed. Embodiments of this application provide a method for detecting and controlling the runtime behavior of mobile applications. First, it continuously collects the CPU occupancy rate data during the operation of the target application to form a time stack, extracts local time-domain features through time-series encoding, and uses a time-series message passing mechanism with feature space constraints to capture long-range dependencies and simulate the dynamic propagation law of resource occupancy. Subsequently, it generates the predicted value of the CPU occupancy rate at the next moment through time-series decoding, and compares the volatility with the actual monitored value to intelligently determine whether there is an abnormal resource occupancy and trigger an early warning. In this way, while reducing the false alarm rate for legitimate high-load applications, it can achieve early warning of hidden resource abuse behaviors, providing a technical path with both accuracy and adaptability for the control of the runtime behavior of mobile applications.

[0006] According to one aspect of this application, there is provided a method for detecting and controlling the runtime behavior of mobile applications, which includes:

[0007] S1: Statistically obtain the CPU occupancy rate of the target mobile application during operation to obtain a time stack of the CPU occupancy rate;

[0008] S2: Perform temporal encoding and decoding on the time stack of the CPU occupancy rate to obtain the predicted value of the CPU occupancy rate at the next time point, including: performing sequence reconstruction and temporal encoding on the time stack of the CPU occupancy rate to obtain the temporal distribution of the local temporal domain mode features of the CPU occupancy rate; performing temporal message passing encoding and decoding on the temporal distribution of the local temporal domain mode features of the CPU occupancy rate to obtain the predicted value of the CPU occupancy rate at the next time point;

[0009] S3: Obtain the true value of the CPU occupancy rate at the next time point;

[0010] S4: Calculate the volatility between the predicted value of the CPU occupancy rate at the next time point and the true value of the CPU occupancy rate at the next time point;

[0011] S5: Based on the comparison between the volatility and a preset threshold, determine whether there is an abnormal resource occupancy in the target mobile application;

[0012] S6: If there is an abnormal resource occupancy in the target mobile application, generate a warning prompt.

[0013] Compared with the prior art, a method for detecting and controlling the running behavior of a mobile application provided by the present application first continuously collects the CPU occupancy rate data during the running of the target application to form a time stack, extracts local temporal domain features through temporal encoding, and uses the temporal message passing mechanism constrained by the feature space to capture long-range dependencies and simulate the dynamic propagation law of resource occupancy. Subsequently, it generates the predicted value of the CPU occupancy rate at the next moment through temporal decoding, and compares the volatility with the actual monitored value to intelligently determine whether there is an abnormal resource occupancy and trigger a warning. In this way, while reducing the false alarm rate for legitimate high-load applications, it can achieve early warning of hidden resource abuse behaviors, providing a technical path with both accuracy and adaptability for the control of the running behavior of mobile applications. Description of the Drawings

[0014] By describing the embodiments of the present application in more detail in conjunction with the drawings, the above and other objects, features, and advantages of the present application will become more obvious. The drawings are used to provide a further understanding of the embodiments of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the present application and do not constitute a limitation to the present application. In the drawings, the same reference numerals generally represent the same components or steps.

[0015] Figure 1 It is a flowchart of a method for detecting and controlling the running behavior of a mobile application according to an embodiment of the present application.

[0016] Figure 2It is a flowchart for performing temporal encoding and decoding on the time stack of the CPU occupancy rate in the mobile application runtime behavior detection and control method according to an embodiment of the present application to obtain a predicted value of the CPU occupancy rate at the next time point.

[0017] Figure 3 It is a schematic diagram of data flow for performing temporal encoding and decoding on the time stack of the CPU occupancy rate in the mobile application runtime behavior detection and control method according to an embodiment of the present application to obtain a predicted value of the CPU occupancy rate at the next time point.

[0018] Figure 4 It is a flowchart for performing temporal message passing encoding and decoding on the temporal distribution of the local time domain pattern features of the CPU occupancy rate in the mobile application runtime behavior detection and control method according to an embodiment of the present application to obtain a predicted value of the CPU occupancy rate at the next time point.

[0019] Figure 5 It is a flowchart for performing spatially constrained temporal message passing dynamic encoding on the temporal distribution of the local time domain pattern feature vectors of the CPU occupancy rate in the mobile application runtime behavior detection and control method according to an embodiment of the present application to obtain a temporally propagated dynamic encoding feature vector of the CPU occupancy rate.

[0020] Figure 6 It is a flowchart for performing message passing constraint-based dynamic encoding on the temporal distribution of the local time domain pattern feature vectors of the CPU occupancy rate based on the spatially tail-end constrained anchoring encoding vector of the local time domain pattern message passing of the CPU occupancy rate and the spatially axis-constrained anchoring encoding vector of the local time domain pattern message passing of the CPU occupancy rate in the mobile application runtime behavior detection and control method according to an embodiment of the present application to obtain a temporally propagated dynamic encoding feature vector of the CPU occupancy rate. Detailed implementation manners

[0021] Various exemplary embodiments, features, and aspects of the present application will be described in detail below with reference to the accompanying drawings. Identical reference numerals in the drawings denote elements having the same or similar functions. Although various aspects of the embodiments are shown in the drawings, the drawings are not necessarily drawn to scale unless otherwise specified.

[0022] The special word "exemplary" here means "serving as an example, embodiment, or illustration". Any embodiment described as "exemplary" here does not have to be construed as superior to or better than other embodiments.

[0023] In addition, for a better illustration of the present application, numerous specific details are provided in the following detailed implementation. Those skilled in the art should understand that the present application can still be implemented without some specific details. In some instances, methods, means, elements, and circuits well-known to those skilled in the art are not described in detail so as to highlight the gist of the present application.

[0024] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the present application, "a plurality of" means two or more, unless otherwise specifically defined.

[0025] As the core role of mobile devices in digital life becomes increasingly prominent, dynamically monitoring and controlling the runtime behavior of mobile applications has become the key to ensuring system stability, user privacy, and terminal security. However, in the face of attacks by malicious applications through concealed resource consumption (such as high-frequency CPU usage, memory leaks, or abnormal network connections), traditional mechanisms relying on static code signature verification and real-time monitoring based on fixed thresholds are inadequate. These methods either ignore the differences between different types of applications and the relevance of scenario contexts, resulting in misjudgments, or are difficult to identify progressive attacks with temporal characteristics, such as periodic pulsed CPU occupancy, enabling malicious programs to bypass detection and continuously carry out data theft or other illegal activities.

[0026] To address the above technical problems, the technical concept of the present application is to use artificial intelligence-based data analysis and coding algorithms to first continuously collect CPU occupancy rate data during the runtime of the target application to form a time stack, extract local time-domain features through temporal coding, and then use a temporal message passing mechanism with feature space constraints to capture long-range dependencies, simulate the dynamic propagation law of resource occupancy. Subsequently, generate the predicted value of the CPU occupancy rate at the next moment through temporal decoding, and compare the volatility with the actual monitored value to intelligently determine whether there is abnormal resource occupancy and trigger an alarm.

[0027] That is, by introducing a time series encoding and decoding prediction mechanism and dynamic volatility analysis, this technical solution effectively breaks through the technical limitations of the traditional fixed threshold detection mode. In the solution, the time series encoding and decoding extracts features and dynamically models the CPU occupancy time stack, and can learn the resource consumption time series law of a specific application in the normal state, and then generate a prediction value with context awareness. By comparing the volatility of the predicted value and the real value instead of directly judging the absolute value of the resources, it can adaptively distinguish between normal high-load scenarios (such as the expected periodic CPU peaks during game rendering) and abnormal occupancy behaviors (such as malicious programs disguising high loads but showing non-regular fluctuations). At the same time, the time series prediction mechanism can capture the dynamic evolution trend of resource occupancy. For low-intensity continuous occupancy that cannot be recognized by traditional methods (the real value deviates from the prediction curve baseline for a long time) or periodic pulse attacks (the prediction residual sequence shows an abnormal fluctuation pattern), accurate detection can be achieved through the analysis of the statistical characteristics of volatility. In addition, the preset threshold can be dynamically calibrated based on the historical data of different application types. For example, the volatility threshold for video editing applications is relaxed, while that for standby service applications is tightened, so as to improve the sensitivity to hidden attacks while reducing the false alarm rate. This dynamic detection mechanism that combines predictive analysis and context awareness realizes early warning of hidden resource abuse behaviors while reducing the false alarm rate for legitimate high-load applications, providing a technical path with both accuracy and adaptability for the runtime behavior control of mobile applications.

[0028] In particular, this application proposes a method for detecting and controlling the runtime behavior of mobile applications. Figure 1 The flowchart of the method for detecting and controlling the runtime behavior of mobile applications according to the embodiments of this application is as follows. Figure 1 As shown, the method for detecting and controlling the runtime behavior of mobile applications according to the embodiments of this application includes: S1: Statistically calculate the CPU occupancy rate of the target mobile application during runtime to obtain the time stack of the CPU occupancy rate; S2: Perform time series encoding and decoding on the time stack of the CPU occupancy rate to obtain the predicted value of the CPU occupancy rate at the next time point; S3: Obtain the real value of the CPU occupancy rate at the next time point; S4: Calculate the volatility between the predicted value of the CPU occupancy rate at the next time point and the real value of the CPU occupancy rate at the next time point; S5: Based on the comparison between the volatility and the preset threshold, determine whether there is an abnormal resource occupancy in the target mobile application; S6: If there is an abnormal resource occupancy in the target mobile application, generate a warning prompt.

[0029] In the above method for detecting and controlling the runtime behavior of a mobile application, in step S1, the CPU occupancy rate of the target mobile application during runtime is statistically analyzed to obtain a time stack of the CPU occupancy rate. It should be understood that statistically analyzing the CPU occupancy rate of the target mobile application during runtime aims to form a data set with chronological characteristics, that is, a time stack of the CPU occupancy rate, by continuously collecting the CPU occupancy rate data during the runtime of the target application, providing necessary input data for subsequent steps. Specifically, in the initial stage, it is first necessary to determine the target mobile application in order to accurately monitor its resource usage. This step usually involves identifying the applications running on the user device and filtering out the target applications that need to be focused on. Once the target application is determined, the CPU occupancy rate data collection stage follows. During this process, the present application continuously records the CPU occupancy rate values of the target application at fixed or variable time intervals. These values reflect the actual occupancy of the processor resources by the target application at different time periods, thus providing basic data for analyzing its behavior pattern. Among them, considering that too high a collection frequency may lead to unnecessary computational overhead and data redundancy, while too low a collection frequency may miss important transient behavior characteristics. Therefore, a reasonable collection frequency should be set based on the characteristics of the target application and the expected analysis requirements. For example, for high-load applications with large fluctuations in resource consumption and complex behavior patterns, a higher collection frequency may be required to capture their detailed resource usage changes; while for applications with relatively stable resource consumption, a lower collection frequency can be adopted. In addition, due to the influence of factors such as the hardware configuration of the mobile device and the operating system version, there may be differences in the original CPU occupancy rate data obtained between different devices. To ensure the consistency and comparability of the data, the present application also needs to perform appropriate preprocessing on these original data. This includes, but is not limited to, operations such as removing outliers (such as extreme values caused by sudden power outages of the device) and filling in missing values (such as sampling gaps caused by network delays). After such a series of meticulous processes, the finally formed time stack of the CPU occupancy rate will be closer to the real application behavior pattern, providing high-quality input data for subsequent time series encoding / decoding and prediction model training.

[0030] Figure 2 A flowchart for performing time series encoding / decoding on the time stack of the CPU occupancy rate according to the method for detecting and controlling the runtime behavior of a mobile application in an embodiment of the present application to obtain a predicted value of the CPU occupancy rate at the next time point. Figure 3 A schematic diagram of data flow for performing time series encoding / decoding on the time stack of the CPU occupancy rate according to the method for detecting and controlling the runtime behavior of a mobile application in an embodiment of the present application to obtain a predicted value of the CPU occupancy rate at the next time point. As Figure 2 and Figure 3As shown, in the above method for detecting and controlling the running behavior of a mobile application, in step S2, performing temporal encoding and decoding on the time stack of the CPU occupancy rate to obtain a predicted value of the CPU occupancy rate at the next time point includes: S21, performing sequence reconstruction and temporal encoding on the time stack of the CPU occupancy rate to obtain a temporal distribution of the local temporal pattern features of the CPU occupancy rate; S22, performing temporal message passing encoding and decoding on the temporal distribution of the local temporal pattern features of the CPU occupancy rate to obtain the predicted value of the CPU occupancy rate at the next time point.

[0031] In an embodiment of the present application, step S21, performing sequence reconstruction and temporal encoding on the time stack of the CPU occupancy rate to obtain a temporal distribution of the local temporal pattern features of the CPU occupancy rate, includes: S211, performing sequence reconstruction on the time stack of the CPU occupancy rate according to timestamps to obtain a time queue of the CPU occupancy rate; S212, performing temporal encoding on the time queue of the CPU occupancy rate to obtain the temporal distribution of the local temporal pattern features of the CPU occupancy rate.

[0032] Specifically, in step S211, performing sequence reconstruction on the time stack of the CPU occupancy rate according to timestamps to obtain a time queue of the CPU occupancy rate. It should be understood that malicious programs often evade traditional detection mechanisms through covert attack patterns with temporal correlations (such as staged resource consumption or periodic pulsed calls). Although the resource consumption values at a single time point of such attack behaviors may be lower than a fixed threshold, their abnormal fluctuation patterns in the time dimension are difficult to be captured by traditional discrete value analysis. Therefore, to effectively identify such dynamic threats, it is necessary to perform temporal modeling on the resource occupancy data, and the premise of temporal modeling is to accurately restore the time evolution law of the resource consumption behavior. However, the originally collected time stack of the CPU occupancy rate may have problems such as uneven data collection intervals and temporal misalignment caused by multi-threaded concurrency. If feature extraction is directly performed, it will lead to distortion of the temporal relationship and affect the pattern learning ability of the subsequent model. Based on this, in the technical solution of the present application, sequence reconstruction is performed on the time stack of the CPU occupancy rate according to timestamps to obtain a time queue of the CPU occupancy rate. In this way, the temporal noise in the original data is eliminated, and an ordered sequence with strict time dependence is constructed. Specifically, the discrete CPU occupancy rate data points (time stack) collected in the present application are rearranged and aligned according to their actual timestamps, the out-of-order data caused by multi-threaded collection or system scheduling delay is removed, and the data gaps caused by sampling interval fluctuations are filled, finally forming a continuous, complete and strictly time-increasingly arranged time queue.

[0033] In an embodiment of the present application, step S212, performing temporal encoding on the time queue of the CPU occupancy rate to obtain the temporal distribution of the local temporal domain pattern features of the CPU occupancy rate, includes: using a temporal encoder based on the LSTM model to perform temporal encoding on the time queue of the CPU occupancy rate to obtain the temporal distribution of the local temporal domain pattern feature vectors of the CPU occupancy rate as the temporal distribution of the local temporal domain pattern features of the CPU occupancy rate. It should be understood that considering that malicious programs often evade traditional detection mechanisms through behavior camouflage in the time dimension (such as intermittent resource calls, periodic load fluctuations). Since these abnormal behaviors are often embedded in the temporal patterns of normal resource consumption (for example, a malicious program imitates the periodic CPU occupancy of video rendering but superimposes a covert attack in a specific time window), it is difficult to extract discriminative local dynamic features solely relying on numerical comparison of raw temporal data or simple statistic analysis. Moreover, the early signs of malicious attacks may only manifest as subtle pattern offsets within a local time window (such as an abnormal slope of the rising edge of the CPU occupancy rate, a sudden change in the load fluctuation frequency), and these features are easily submerged by global noise in the raw time queue without structured representation, resulting in the detection model being unable to effectively capture key threat signals. Based on this, the present application performs temporal encoding on the time queue of the CPU occupancy rate to obtain the temporal distribution of the local temporal domain pattern features of the CPU occupancy rate. In particular, in a specific example of the present application, a temporal encoder based on the LSTM model is used to perform temporal encoding on the time queue of the CPU occupancy rate to obtain the temporal distribution of the local temporal domain pattern feature vectors of the CPU occupancy rate as the temporal distribution of the local temporal domain pattern features of the CPU occupancy rate. It is worth mentioning that the temporal encoder based on the LSTM model can dynamically capture the pattern features within the local temporal domain of the CPU occupancy rate time queue through its unique gating mechanism and memory cell structure. Specifically, when processing time series data, the LSTM model can adaptively learn the dependency relationships at different time scales: the forget gate controls the retention degree of historical information, the input gate filters the effective features of the current input, and the output gate synthesizes the memory state to generate context-related feature representations. In this step, the LSTM performs local slicing on the time queue in a sliding window manner, extracts feature vectors containing gradient changes, fluctuation periodicity, and transient anomaly intensity window by window, and maps these local features to a temporal distribution in chronological order. For example, when there is an abnormally steep rising edge of the CPU occupancy rate within a certain window, the memory cell of the LSTM will suppress irrelevant historical fluctuations and strengthen the feature encoding of this abnormal gradient to form a discriminative local pattern vector.

[0034] Figure 4It is a flowchart for performing temporal message passing encoding and decoding on the temporal distribution of the CPU occupancy local temporal domain pattern features in the mobile application runtime behavior detection and control method according to an embodiment of the present application to obtain the predicted value of the CPU occupancy at the next time point. As Figure 4 shown, in the embodiment of the present application, step S22 of performing temporal message passing encoding and decoding on the temporal distribution of the CPU occupancy local temporal domain pattern features to obtain the predicted value of the CPU occupancy at the next time point includes: S221, performing spatially constrained temporal message passing dynamic encoding on the temporal distribution of the CPU occupancy local temporal domain pattern feature vectors to obtain CPU occupancy temporal propagation dynamic encoding feature vectors; S222, based on the CPU occupancy temporal propagation dynamic encoding feature vectors, obtaining the predicted value of the CPU occupancy at the next time point.

[0035] Figure 5 It is a flowchart for performing spatially constrained temporal message passing dynamic encoding on the temporal distribution of the CPU occupancy local temporal domain pattern feature vectors in the mobile application runtime behavior detection and control method according to an embodiment of the present application to obtain CPU occupancy temporal propagation dynamic encoding feature vectors. As Figure 5As shown, in the embodiment of the present application, step S221, which performs dynamic encoding of temporal message passing based on spatial constraints on the temporal distribution of the CPU occupancy local temporal mode feature vector to obtain a CPU occupancy temporal propagation dynamic encoding feature vector, includes: S2211, respectively performing spatial end constraint anchoring and spatial axis constraint anchoring on the temporal distribution of the CPU occupancy local temporal mode feature vector to obtain a CPU occupancy local temporal mode message passing spatial end constraint anchoring encoding vector and a CPU occupancy local temporal mode message passing spatial axis constraint anchoring encoding vector; S2212, based on the CPU occupancy local temporal mode message passing spatial end constraint anchoring encoding vector and the CPU occupancy local temporal mode message passing spatial axis constraint anchoring encoding vector, performing dynamic encoding of the temporal distribution of the CPU occupancy local temporal mode feature vector based on message passing constraints to obtain the CPU occupancy temporal propagation dynamic encoding feature vector. It should be understood that considering that malicious programs often evade traditional detection mechanisms through long-term associated covert attack patterns (such as cross-time window collaborative resource consumption, phase offset of periodic pulse attacks). Although the CPU occupancy local temporal mode features can capture abnormal fluctuations within a short time window, the dynamic propagation laws of these CPU occupancy local temporal mode features on the time axis (such as how early anomalies affect subsequent resource occupancy, and the co-evolution of attack behaviors among multiple time windows) have not been effectively modeled. For example, a malicious program may cause a slight perturbation in the CPU occupancy rate during a certain period. Although this perturbation does not trigger the local detection threshold, it gradually conducts to subsequent time windows through temporal correlation, forming a cumulative anomaly; traditional methods are difficult to identify such cross-window hidden threats due to the lack of the ability to model the temporal propagation path. In addition, the CPU occupancy local temporal mode feature sequence may contain a large amount of noise fluctuations unrelated to attacks (such as random load changes caused by task scheduling of normal applications). If directly globally aggregated, it is easy to cause key attack signals to be submerged. Therefore, the present application performs dynamic encoding of temporal message passing based on spatial constraints on the temporal distribution of the CPU occupancy local temporal mode feature vector to obtain a CPU occupancy temporal propagation dynamic encoding feature vector.

[0036] Specifically, this method first uses the CPU occupancy local time-domain pattern message passing spatial tail-end constraint to anchor the coding vector (sequence end feature) as the spatio-temporal propagation reference point, so that the message passing process focuses on the evolution trajectory of the current context. For example, when detecting periodic attacks, the CPU occupancy local time-domain pattern message passing spatial tail-end constraint can effectively isolate the noise interference of historical periods, ensuring that the model only focuses on the overall picture and phase characteristics of the current attack waveform. At the same time, the CPU occupancy local time-domain pattern message passing spatial axis constraint anchored coding vector generated by clustering extracts the principal components of the global feature distribution (such as the main frequency of normal load fluctuations and the typical propagation path of attack behaviors), thereby constructing a "normal-abnormal" structural boundary in the feature space. By calculating the dynamic constraint factors of the CPU occupancy local time-domain pattern feature vector with the CPU occupancy local time-domain pattern message passing spatial tail-end constraint anchored coding vector and the CPU occupancy local time-domain pattern message passing spatial axis constraint anchored coding vector, the weights of the features at each time node in the propagation process can be adaptively adjusted: features strongly related to the current attack conduction chain (such as an abnormally steep load rising edge within a certain window) are given high weights, while noise fluctuations deviating from the global main pattern (such as random fluctuations caused by normal task scheduling) are suppressed.

[0037] In an embodiment of the present application, in step S2211, spatial tail-end constraint anchoring and spatial axis constraint anchoring are respectively performed on the temporal distribution of the CPU occupancy local time-domain pattern feature vector to obtain the CPU occupancy local time-domain pattern message passing spatial tail-end constraint anchored coding vector and the CPU occupancy local time-domain pattern message passing spatial axis constraint anchored coding vector, including: S2211-1, extracting the last CPU occupancy local time-domain pattern feature vector from the temporal distribution of the CPU occupancy local time-domain pattern feature vector as the CPU occupancy local time-domain pattern message passing spatial tail-end constraint anchored coding vector; S2211-2, performing clustering analysis on the temporal distribution of the CPU occupancy local time-domain pattern feature vector to obtain the CPU occupancy local time-domain pattern message passing spatial axis constraint anchored coding vector.

[0038] Specifically, in step S2211-1, extracting the last CPU occupancy local time-domain pattern feature vector from the temporal distribution of the CPU occupancy local time-domain pattern feature vector as the CPU occupancy local time-domain pattern message passing spatial tail-end constraint anchored coding vector, which is expressed by the CPU occupancy local time-domain pattern message passing spatial tail-end constraint extraction formula as:

[0039] O = {v1, v2,..., v i ,..., v t}

[0040] v tail = v t

[0041] where O is the temporal distribution of the CPU occupancy local time-domain pattern feature vector, and v1, v2, v i and v t are the 1st, 2nd, i-th, and t-th CPU occupancy local time-domain pattern feature vectors in the temporal distribution of the CPU occupancy local time-domain pattern feature vector respectively, and v tail is the CPU occupancy local time-domain pattern message passing space tail-end constraint anchoring coding vector. It should be understood that in order to cope with the stealthy attack patterns (such as cross-time-window collaborative resource consumption and periodic pulse attack phase shift) of malicious programs through temporal correlation to evade traditional detection mechanisms, in this step, the end point or current state of the sequence in the temporal distribution of the CPU occupancy local time-domain pattern feature vector, that is, the feature of the last CPU occupancy local time-domain pattern feature vector, is used as the CPU occupancy local time-domain pattern message passing space tail-end constraint anchoring coding vector, establishing a boundary condition reference point based on the current state for the dynamic propagation process. This feature not only carries the complete expression of the attack behavior at the current moment but also implies the trend information of the attack pattern evolution over time. For example, when detecting periodic CPU pulse attacks, the CPU occupancy local time-domain pattern message passing space tail-end constraint can automatically limit the message passing range within the current attack cycle, avoiding interference from irrelevant historical cycles, thereby accurately capturing the feature variation brought by the attack phase shift. Specifically, since malicious program attacks often exhibit the feature that early minor perturbations form cumulative anomalies through temporal conduction, if only relying on the instantaneous feature analysis within a local window, the propagation path of the attack signal between multiple time windows may be submerged by noise. By introducing an adaptive constraint mechanism in the temporal dimension, it not only strengthens the model's dynamic tracking ability for the attack conduction path but also ensures the focused investment of computing resources by constraining the message passing direction, ultimately realizing the collaborative modeling of the CPU occupancy local time-domain pattern feature vector and the global attack pattern, and effectively distinguishing the interpretable differences between normal load fluctuations and abnormal attack propagations.

[0042] Specifically, in step S2211-2, clustering analysis is performed on the temporal distribution of the CPU occupancy local time-domain pattern feature vector to obtain the CPU occupancy local time-domain pattern message passing space axis constraint anchoring coding vector, which is represented by the CPU occupancy clustering analysis formula as:

[0043]

[0044] where Cluster is the clustering analysis operation, max(v i ) and min(v i ) are respectively taking v iThe maximum and minimum values, η is a tuning parameter, a i is the i-th CPU occupancy local time-domain pattern constraint anchor value in the time-series distribution of the CPU occupancy local time-domain pattern constraint anchor values, softmax is a normalization function, e i is the i-th CPU occupancy local time-domain pattern constraint anchor weight value in the time-series distribution of the CPU occupancy local time-domain pattern constraint anchor weight values, t is the number of vectors in the O, v axis is the CPU occupancy local time-domain pattern message passing space axis constraint anchor encoding vector. It should be understood that by clustering and analyzing to extract the principal components or representative features (such as the main frequency of normal load fluctuations, the typical propagation path of attack behaviors) in the time-series distribution of the CPU occupancy local time-domain pattern feature vectors, a global structural constraint benchmark is essentially established for the dynamic propagation process. This benchmark can be regarded as the "skeleton" of the internal structure of the data, and is used to guide the message passing process to focus on the key evolution directions of the attack patterns. For example, when detecting periodic CPU pulse attacks, the CPU occupancy local time-domain pattern message passing space axis constraint anchor encoding vector can extract the main frequency feature of the attack period through clustering, enabling the message passing mechanism to automatically align with this frequency dimension, thereby suppressing the noise interference of non-attack periods; when dealing with cross-window collaborative attacks, the clustering results can reveal the correlation patterns of attack signals between different time windows, preventing local features from deviating from the global attack path due to noise interference. This global structural constraint can be analogous to the regularization effect, preventing the model from overfitting noise, and enhancing the model's sensitivity to abnormal propagation paths by extracting the main pattern features.

[0045] Figure 6 is a flowchart for dynamically encoding the time-series distribution of the CPU occupancy local time-domain pattern feature vectors based on message passing constraints to obtain the CPU occupancy time-series propagation dynamic encoding feature vectors according to the mobile application runtime behavior detection and control method of an embodiment of the present application based on the CPU occupancy local time-domain pattern message passing space end constraint anchor encoding vector and the CPU occupancy local time-domain pattern message passing space axis constraint anchor encoding vector. As Figure 6As shown, in the embodiments of the present application, in step S2212, based on the CPU occupancy local time-domain mode message-passing space tail-end constraint anchored coding vector and the CPU occupancy local time-domain mode message-passing space axis constraint anchored coding vector, performing dynamic coding based on message-passing constraints on the temporal distribution of the CPU occupancy local time-domain mode feature vector to obtain the CPU occupancy temporal propagation dynamic coding feature vector, including: S2212-1, calculating the CPU occupancy tail-end message-passing constraint factor of each CPU occupancy local time-domain mode feature vector in the temporal distribution of the CPU occupancy local time-domain mode feature vector relative to the CPU occupancy local time-domain mode message-passing space tail-end constraint anchored coding vector; S2212-2, calculating the CPU occupancy axis message-passing constraint factor of each CPU occupancy local time-domain mode feature vector in the temporal distribution of the CPU occupancy local time-domain mode feature vector relative to the CPU occupancy local time-domain mode message-passing space axis constraint anchored coding vector; S2212-3, based on the CPU occupancy tail-end message-passing constraint factor and the CPU occupancy axis message-passing constraint factor of each CPU occupancy local time-domain mode feature vector in the temporal distribution of the CPU occupancy local time-domain mode feature vector, calculating the CPU occupancy message-passing constraint factor of each CPU occupancy local time-domain mode feature vector; S2212-4, based on the CPU occupancy message-passing constraint factor of each CPU occupancy local time-domain mode feature vector, performing message dynamic constraint transfer coding on the temporal distribution of the CPU occupancy local time-domain mode feature vector to obtain the CPU occupancy temporal propagation dynamic coding feature vector.

[0046] Specifically, in step S2212-1, calculating the CPU occupancy tail-end message-passing constraint factor of each CPU occupancy local time-domain mode feature vector in the temporal distribution of the CPU occupancy local time-domain mode feature vector relative to the CPU occupancy local time-domain mode message-passing space tail-end constraint anchored coding vector, which is expressed by the CPU occupancy tail-end message-passing constraint factor calculation formula as:

[0047]

[0048] where f(v i , v tail ) performs tail-end constraint anchoring on v i and v tail , v ij is the eigenvalue at the j-th position of v i , v tailj is the eigenvalue at the j-th position of v tail , log2 is the logarithmic function value with base 2, and n is vi The number of eigenvalues, exp is the exponential function value with the natural constant e as the base, α i is v i The end message passing constraint factor of the corresponding CPU occupancy rate. It should be understood that by using the sequence end feature (i.e., the end constraint anchored coding vector of the CPU occupancy rate local time domain pattern message passing space) as a reference benchmark, calculating the similarity or distance between each CPU occupancy rate local time domain pattern feature vector and the end constraint anchored coding vector of the CPU occupancy rate local time domain pattern message passing space essentially establishes local constraint conditions based on the current state for the dynamic propagation process. This local constraint condition quantifies the temporal evolution continuity of the CPU occupancy rate local time domain pattern feature vector, assigns higher weights to the CPU occupancy rate local time domain pattern feature vectors strongly correlated with the end feature, and thus focuses on the key nodes of the conduction path of attack behaviors during the message passing process. For example, when detecting periodic CPU pulse attacks, the end message passing constraint factor of the CPU occupancy rate can suppress the noise interference of irrelevant historical periods by emphasizing the abnormally steep load rising edge feature at the end of the current period; when dealing with cross-window collaborative attacks, this mechanism can identify the evolution consistency of attack signals between different time windows and prevent missed detections caused by random fluctuations of local features. This dynamic weight assignment not only enhances the sensitivity of the model to the spatio-temporal propagation characteristics of the attack path but also realizes a fine distinction between normal load fluctuations (such as instantaneous high loads during video rendering frames) and abnormal attack behaviors (such as low-intensity continuous occupancy by data stealing programs) through probability distribution modeling under constraint conditions, ultimately reducing the false alarm rate of legitimate applications while significantly improving the early detection ability of covert resource abuse behaviors.

[0049] Specifically, in step S2212-2, calculate the CPU occupancy rate axis message passing constraint factor of each CPU occupancy rate local time domain pattern feature vector in the temporal distribution of the CPU occupancy rate local time domain pattern feature vector relative to the axis constraint anchored coding vector of the CPU occupancy rate local time domain pattern message passing space. It is expressed by the CPU occupancy rate axis message passing constraint factor calculation formula as:

[0050]

[0051] Among them, f(v i , v axis ) performs axis constraint anchoring on v i and v axis , ‖·‖2 is the Euclidean norm for calculating vectors, arccosh is the inverse hyperbolic cosine function, β i is v iThe corresponding CPU occupancy axis message passing constraint factor. It should be understood that the CPU occupancy axis message passing constraint factor extracted through cluster analysis serves as a global structure benchmark. Essentially, it establishes a main mode guidance framework for the dynamic propagation process. This framework quantifies the similarity or distance between the local time-domain mode feature vectors of CPU occupancy and the global principal components (such as the main frequency of normal load fluctuations and the typical propagation path of attack behaviors), and assigns higher weights to the local time-domain mode feature vectors of CPU occupancy that are strongly correlated with the global main mode. Thus, it focuses on the key evolution directions of the attack path during the message passing process. This global constraint not only prevents the model from overfitting noise through the regularization effect but also achieves a fine distinction between normal load fluctuations (such as instantaneous high loads during video rendering frames) and abnormal attack behaviors (such as low-intensity continuous occupancy by data theft programs) through projection weight allocation. Ultimately, while reducing the false alarm rate of legitimate applications, it significantly improves the early detection ability of covert resource abuse behaviors.

[0052] In the embodiment of the present application, in step S2212-3, based on the CPU occupancy end message passing constraint factor and the CPU occupancy axis message passing constraint factor of each CPU occupancy local time-domain mode feature vector in the time sequence distribution of the CPU occupancy local time-domain mode feature vectors, calculating the CPU occupancy message passing constraint factor of each CPU occupancy local time-domain mode feature vector includes: S2212-31, using a canonical spatial domain constraint matrix to perform field strength convergence co-control on the CPU occupancy end message passing constraint factor and the CPU occupancy axis message passing constraint factor corresponding to the CPU occupancy local time-domain mode feature vector to obtain a CPU occupancy end message passing co-control constraint factor and a CPU occupancy axis message passing co-control constraint factor; S2212-32, based on the CPU occupancy end message passing co-control constraint factor and the CPU occupancy axis message passing co-control constraint factor, performing global stability constraint on the CPU occupancy end message passing constraint factor and the CPU occupancy axis message passing constraint factor to obtain an optimized CPU occupancy end message passing constraint factor and an optimized CPU occupancy axis message passing constraint factor; S2212-33, performing weight allocation fusion on the optimized CPU occupancy end message passing constraint factor and the optimized CPU occupancy axis message passing constraint factor to obtain the CPU occupancy message passing constraint factor corresponding to the CPU occupancy local time-domain mode feature vector.

[0053] Specifically, in step S2212-31, the field strength convergence co-control is performed on the CPU occupancy tail-end message passing constraint factor and the CPU occupancy axis message passing constraint factor corresponding to the CPU occupancy local time-domain mode feature vector using the canonical airspace constraint matrix to obtain the CPU occupancy tail-end message passing co-control constraint factor and the CPU occupancy axis message passing co-control constraint factor, which is expressed by the CPU occupancy field strength convergence co-control formula as:

[0054]

[0055] where δ i and ε i are respectively the CPU occupancy tail-end message passing co-control constraint factor and the CPU occupancy axis message passing co-control constraint factor after co-control of α i and β i .

[0056] Specifically, in step S2212-32, based on the CPU occupancy tail-end message passing co-control constraint factor and the CPU occupancy axis message passing co-control constraint factor, the global stability constraint is performed on the CPU occupancy tail-end message passing constraint factor and the CPU occupancy axis message passing constraint factor to obtain the optimized CPU occupancy tail-end message passing constraint factor and the optimized CPU occupancy axis message passing constraint factor, which is expressed by the CPU occupancy global stability constraint formula as:

[0057]

[0058] where T represents the transpose operation, |·| is the absolute value operation, α i ′ and β i ′ are respectively the optimized CPU occupancy tail-end message passing constraint factor and the optimized CPU occupancy axis message passing constraint factor corresponding to v i .

[0059] It should be understood that in the steps S2212-31 and S2212-32, when the CPU occupancy local time-domain mode feature vector forms an abnormal field of multi-dimensional coupling during the time-series propagation, the traditional message passing mechanism may cause the field strength distribution to diverge due to the explosion of feature dimensions (such as multi-frequency resonance caused by periodic pulse attacks in different time windows), or the sensitivity of the model to the main attack path may decrease due to insufficient global constraints (such as the imbalance of primary and secondary feature weights in cross-window collaborative attacks). In the technical solution of the present application, through the canonical spatial domain constraint matrix, field strength convergence co-control is implemented on the CPU occupancy tail-end message passing constraint factor and the CPU occupancy axis message passing constraint factor. Essentially, it maps the high-dimensional feature space to a low-dimensional compact manifold through linear transformation, thereby compressing redundant feature dimensions and enhancing the signal strength of key attack patterns. For example, when detecting multi-period superimposed attacks, this operation can suppress the interference of non-attack frequency components and enable the model to focus on the time-series evolution path of the attack main frequency. The global stability constraint establishes a dynamic weight allocation mechanism through the solvable manifold metric rotation transformation to generate a spin space compactification constraint. When it is detected that a certain type of attack pattern (such as the progressive CPU climb caused by memory leak-style resource occupancy) shows non-linear diffusion characteristics in the field, this mechanism can balance the contradiction between local anomaly amplification and global pattern fidelity by adaptively adjusting the constraint factor weights, preventing normal load fluctuations (such as the instantaneous CPU peak during video editor frame rendering) from being misjudged as attack behaviors due to excessive compression of the field. This collaborative optimization not only improves the generalization ability of the model to complex attack scenarios but also accurately captures the spatio-temporal propagation characteristics of abnormal signals through the field energy flow regulation mechanism. Through the synergistic effect of covariant unification and manifold rotation transformation, the optimized CPU occupancy tail-end message passing constraint factor and the optimized CPU occupancy axis message passing constraint factor are finally output. During the information transfer topology process, spatial distribution optimization is achieved through multi-modal field compactification processing, the global stability control mechanism is used to coordinate dimension adaptability, and the dynamic trade-off strategy is used to balance the balance between generalization error control and field energy flow management. In this way, the spatial domain focusing of heterogeneous propagation paths is ensured, and the problem of signal attenuation caused by field energy diffusion in traditional methods is effectively solved through dimension adaptive adjustment under stability constraints. At the same time, a dynamic balance mechanism is constructed between error tolerance and energy regulation, thereby achieving robust detection performance in complex attack scenarios.

[0060] Specifically, in step S2212-33, weight allocation and fusion are performed on the optimized CPU occupancy tail-end message passing constraint factor and the optimized CPU occupancy axis message passing constraint factor to obtain the CPU occupancy message passing constraint factor corresponding to the CPU occupancy local time-domain mode feature vector, which is expressed by the CPU occupancy weight allocation fusion formula as:

[0061] yi = Sigmoid(ω1·α i ′ + ω2·β i ′)

[0062] where ω1 and ω2 are weighting parameters respectively, Sigmoid is a weight mapping function, and y i is the CPU occupancy message passing constraint factor corresponding to v i It should be understood that through the dynamic weight allocation fusion mechanism, essentially, by adaptively adjusting the local and global interaction weights in the optimized CPU occupancy tail message passing constraint factor and the optimized CPU occupancy axis message passing constraint factor, a composite constraint field with spatio-temporal adaptive characteristics is constructed. For example, when detecting multi-period superimposed attacks, this mechanism can suppress the interference of non-attack frequency components and enable the model to focus on the temporal evolution path of the attack main frequency; when dealing with the progressive CPU climb caused by memory leak-style resource occupation, the correlation modeling between early minor perturbations and late cumulative anomalies can be strengthened through dynamic weight adjustment. This fusion strategy not only improves the generalization ability of the model to complex attack scenarios, but also realizes the collaborative optimization of local anomaly capture and global structure fidelity through a multi-task learning framework, thereby reducing the false alarm rate of legitimate high-load applications while significantly enhancing the early recognition ability of covert resource abuse behaviors. Specifically, common fusion methods include weighted summation, product rule, or dynamic weighting based on the attention mechanism.

[0063] Specifically, in step S2212-4, based on the CPU occupancy message passing constraint factors of the local time-domain mode feature vectors of each CPU occupancy, message dynamic constraint passing encoding is performed on the temporal distribution of the local time-domain mode feature vectors of the CPU occupancy to obtain the dynamic encoding feature vector of the CPU occupancy temporal propagation, which is represented by the CPU occupancy message dynamic constraint passing encoding formula as:

[0064]

[0065] Among them, z is the dynamic encoding feature vector of CPU occupancy time series propagation. It should be understood that by introducing the dynamic weighted pooling operation implemented by the CPU occupancy message transmission constraint factor, a feature selection mechanism with spatiotemporal adaptive characteristics is essentially constructed. This mechanism focuses on the key timing nodes in the attack transmission chain (such as abnormally steep load rising edges) through local constraint information, and uses global constraint information to suppress noise interference that deviates from the global main mode (such as normal instantaneous high load between video rendering frames). This dynamic encoding process under dual constraints not only retains the propagation law of attack behavior in the time series dimension (such as the progressive CPU climbing slope caused by memory leaks), but also realizes the decoupling of the main attack path from the noise background through weight allocation. In this way, redundant feature dimensions can be compressed through field compaction coding, the detection computing efficiency can be improved, and the attack features can be given a higher semantic priority based on the dynamic weight allocation of the CPU occupancy message transmission constraint factor.

[0066] In an embodiment of the present application, the step S222, based on the CPU occupancy rate time series propagation dynamic coding feature vector, obtains the predicted value of the CPU occupancy rate at the next time point, including: inputting the CPU occupancy rate time series propagation dynamic coding feature vector into the decoder-based occupancy predictor to obtain the predicted value of the CPU occupancy rate at the next time point. That is, the CPU occupancy rate time series propagation dynamic coding feature vector obtained by time series transmission coding using the time series distribution of the CPU occupancy rate local time domain pattern feature vector is decoded and processed to accurately predict the CPU occupancy rate at the next time point. It should be understood that the decoder-based occupancy predictor is specially designed for processing coding features and making predictions. It has undergone targeted training and optimization, can understand the information contained in the CPU occupancy rate time series propagation dynamic coding feature vector, and has the ability to convert these abstract coding features into specific CPU occupancy rate prediction values. Its internal algorithm and model structure are optimized for the characteristics of time series data, and can capture the laws and trends of CPU occupancy rate changes. That is, the use of the decoder-based occupancy predictor can make use of the patterns and knowledge it has learned. During the training process, the predictor will learn information such as the change pattern of CPU usage and the impact of different factors on it from a large amount of historical data. Inputting the CPU usage time series propagation dynamic encoding feature vector into such a predictor can make full use of its existing learning results and improve the accuracy and reliability of prediction.

[0067] In the above method for detecting and controlling the runtime behavior of a mobile application, the step S3: obtaining the true value of the CPU occupancy rate at the next time point. It should be understood that for a dynamically changing application, its CPU occupancy rate may be affected by various factors, such as user operations, network status changes, or background process scheduling. These factors cause the CPU occupancy rate to exhibit complex temporal characteristics, and simply relying on the predicted value cannot comprehensively capture its true fluctuation. Moreover, although the prediction model can estimate the CPU occupancy rate at a future moment based on historical data, there will inevitably be a certain error in this prediction. Therefore, obtaining the true value through actual measurement can verify and correct the prediction result, thereby improving the reliability and accuracy of the overall model. Specifically, on the Android platform, the CPU usage of a specified process can be obtained by calling the relevant methods of the ActivityManager class. On the iOS platform, a similar function can be achieved through the ProcessInfo class. Using these API interfaces, the CPU occupancy rate data of the target application can be periodically collected without affecting the normal operation of the application. Moreover, considering that there may be concurrent execution of multiple tasks in the actual operating environment, it is necessary to accurately obtain the independent CPU occupancy rate data of each target application based on the API interfaces provided by the operating system or specially designed monitoring tools, rather than the average value of the entire platform. This helps to improve the accuracy of the data. In addition to the above technical considerations, attention also needs to be paid to the issues of data storage and management. On mobile devices, due to limited storage capacity, it is not advisable to store a large amount of raw data for a long time. Therefore, a sliding window mechanism is usually adopted, and only the data in the recent period is retained for real-time analysis. At the same time, in order to facilitate subsequent processing and analysis, the collected data is often sorted according to the timestamp and converted into an easily processable format (such as a CSV file or a database record) for quick retrieval and call. This efficient data management method not only improves the response speed but also provides convenience for data analysis in subsequent steps. Furthermore, obtaining the true value of the CPU occupancy rate at the next time point also needs to consider the data synchronization problem. This application usually adopts a high-precision time synchronization protocol (such as the NTP protocol) to ensure that the time bases of all devices are consistent, thereby avoiding data chaos or misjudgment caused by time deviation.

[0068] In the above method for detecting and controlling the runtime behavior of a mobile application, the step S4: Calculate the volatility between the predicted value of the CPU occupancy rate at the next time point and the true value of the CPU occupancy rate at the next time point. It should be understood that the CPU occupancy rate is an index that dynamically changes over time, and the differences between the predicted values and the true values at different times may vary. The volatility can capture this dynamic change. It not only considers the magnitude of the difference but also the change of this difference in the time series. This helps to more comprehensively understand the fluctuation characteristics of the CPU occupancy rate of the mobile application, rather than just focusing on the difference at a certain time point. Specifically, the predicted value generated based on the time series encoding and decoding model in this application is not a static threshold, but a comprehensive expectation that integrates the application's historical behavior patterns, current context, and resource occupancy propagation rules. The volatility calculation converts the detection of abnormal resource occupancy into a probability assessment of the consistency of time series behavior by comparing the relative change amplitudes (such as the square of the residual, percentage deviation, etc.) of the predicted value and the true value. For example, when a malicious program uses a phased low-intensity attack, although its true CPU occupancy rate is lower than the traditional threshold at multiple time points, the actual value at each time point continuously deviates from the predicted curve, resulting in an accumulated increase in volatility; while for a normal high-load application, although its true value may be relatively high at a single point, it remains within a reasonable fluctuation range compared to the predicted value (such as the periodic load change of game rendering conforms to expectations), and thus is determined to be a legitimate behavior.

[0069] In the above method for detecting and controlling the runtime behavior of a mobile application, the step S5: Based on the comparison between the volatility and a preset threshold, determine whether there is abnormal resource occupancy in the target mobile application. Correspondingly, during the runtime of the mobile application, the CPU occupancy rate will naturally fluctuate, and the simple volatility value itself cannot directly indicate whether there is an abnormality. The preset threshold is a standard value determined based on multiple factors such as experience, application type, and the resource usage situation during the normal operation of the system. Comparing the volatility with the preset threshold can provide a clear and quantifiable standard for judging whether there is abnormal resource occupancy in the target mobile application.

[0070] In the above method for detecting and controlling the runtime behavior of mobile applications, step S6: If there is an abnormal resource occupancy in the target mobile application, a warning prompt is generated. That is, the warning prompt can enable the user to be aware of the abnormal application on the device and remind the user to take measures, such as stopping the abnormal application from running, performing a device scan for virus detection, etc., so as to protect the user's device from malware attacks, prevent data leakage or tampering, and ensure the user's personal privacy and data security. In a specific embodiment of the present application, one way of warning prompt is to directly display a warning message inside the application. The warning message can be displayed through a pop-up window or in a specific area on the application interface to ensure that the user will not miss important notifications during use. The content of the warning message can be more detailed, not only describing the specific parameter values of the abnormal phenomenon (such as the significant deviation between the actual CPU occupancy rate and the predicted value), but also providing further diagnostic results to help the user understand the root cause of the problem. For example, if the abnormality is caused by malware, the warning message can clearly indicate this and guide the user to perform a deep scan to completely remove the threat.

[0071] In summary, the method for detecting and controlling the runtime behavior of mobile applications based on the embodiments of the present application is elucidated. It first continuously collects the CPU occupancy rate data during the operation of the target application to form a time stack, extracts local time-domain features through time series coding, and uses the time series message passing mechanism with feature space constraints to capture long-range dependencies and simulate the dynamic propagation law of resource occupancy. Subsequently, it generates the predicted value of the CPU occupancy rate at the next moment through time series decoding, and compares it with the actual monitored value for volatility comparison to intelligently determine whether there is an abnormal resource occupancy and trigger a warning. In this way, while reducing the false alarm rate for legitimate high-load applications, it can achieve early warning of hidden resource abuse behaviors, providing a technical path with both accuracy and adaptability for the control of mobile application runtime behaviors.

Claims

1. A method for detecting and controlling the runtime behavior of a mobile application, characterized in that Including: S1: Statistically analyze the CPU occupancy rate of the target mobile application during runtime to obtain the time stack of the CPU occupancy rate; S2: Perform temporal encoding and decoding on the time stack of the CPU occupancy rate to obtain the predicted value of the CPU occupancy rate at the next time point, including: performing sequence reconstruction and temporal encoding on the time stack of the CPU occupancy rate to obtain the temporal distribution of the local temporal pattern features of the CPU occupancy rate; performing temporal message passing encoding and decoding on the temporal distribution of the local temporal pattern features of the CPU occupancy rate to obtain the predicted value of the CPU occupancy rate at the next time point; S3: Obtain the true value of the CPU occupancy rate at the next time point; S4: Calculate the volatility between the predicted value of the CPU occupancy rate at the next time point and the true value of the CPU occupancy rate at the next time point; S5: Based on the comparison between the volatility and a preset threshold, determine whether there is an abnormal resource occupancy in the target mobile application; S6: If there is an abnormal resource occupancy in the target mobile application, generate a warning prompt.

2. The method for detecting and controlling the runtime behavior of a mobile application according to claim 1, wherein Performing sequence reconstruction and temporal encoding on the time stack of the CPU occupancy rate to obtain the temporal distribution of the local temporal pattern features of the CPU occupancy rate, including: Performing sequence reconstruction on the time stack of the CPU occupancy rate according to timestamps to obtain the time queue of the CPU occupancy rate; Performing temporal encoding on the time queue of the CPU occupancy rate to obtain the temporal distribution of the local temporal pattern features of the CPU occupancy rate.

3. The mobile application runtime behavior detection and control method according to claim 2, characterized in that Performing temporal encoding on the time queue of the CPU occupancy rate to obtain the temporal distribution of the local temporal pattern features of the CPU occupancy rate, including: using a temporal encoder based on the LSTM model to perform temporal encoding on the time queue of the CPU occupancy rate to obtain the temporal distribution of the local temporal pattern feature vectors of the CPU occupancy rate as the temporal distribution of the local temporal pattern features of the CPU occupancy rate.

4. The method for detecting and controlling the runtime behavior of a mobile application according to claim 1, characterized in that, Performing temporal message passing encoding and decoding on the temporal distribution of the local temporal pattern features of the CPU occupancy rate to obtain the predicted value of the CPU occupancy rate at the next time point, including: Performing spatially constrained temporal message passing dynamic encoding on the temporal distribution of the local temporal pattern feature vectors of the CPU occupancy rate to obtain the CPU occupancy rate temporal propagation dynamic encoding feature vector; Based on the CPU occupancy rate temporal propagation dynamic encoding feature vector, obtain the predicted value of the CPU occupancy rate at the next time point.

5. The method for detecting and controlling the runtime behavior of a mobile application according to claim 4, characterized in that, Performing spatially constrained temporal message passing dynamic encoding on the temporal distribution of the local temporal pattern feature vectors of the CPU occupancy rate to obtain the CPU occupancy rate temporal propagation dynamic encoding feature vector, including: Performing spatially end-constrained anchoring and spatially axis-constrained anchoring on the temporal distribution of the local temporal pattern feature vectors of the CPU occupancy rate respectively to obtain the CPU occupancy rate local temporal pattern message passing spatially end-constrained anchoring encoding vector and the CPU occupancy rate local temporal pattern message passing spatially axis-constrained anchoring encoding vector; Based on the CPU occupancy local time-domain mode message passing space tail-end constraint anchored coding vector and the CPU occupancy local time-domain mode message passing space axis constraint anchored coding vector, perform dynamic coding based on message passing constraints on the temporal distribution of the CPU occupancy local time-domain mode feature vector to obtain the CPU occupancy temporal propagation dynamic coding feature vector.

6. The method for detecting and controlling the runtime behavior of a mobile application according to claim 5, wherein Respectively perform space tail-end constraint anchoring and space axis constraint anchoring on the temporal distribution of the CPU occupancy local time-domain mode feature vector to obtain the CPU occupancy local time-domain mode message passing space tail-end constraint anchored coding vector and the CPU occupancy local time-domain mode message passing space axis constraint anchored coding vector, including: Extract the last CPU occupancy local time-domain mode feature vector from the temporal distribution of the CPU occupancy local time-domain mode feature vector as the CPU occupancy local time-domain mode message passing space tail-end constraint anchored coding vector; Perform clustering analysis on the temporal distribution of the CPU occupancy local time-domain mode feature vector to obtain the CPU occupancy local time-domain mode message passing space axis constraint anchored coding vector.

7. The method for detecting and controlling the runtime behavior of a mobile application according to claim 6, wherein Based on the CPU occupancy local time-domain mode message passing space tail-end constraint anchored coding vector and the CPU occupancy local time-domain mode message passing space axis constraint anchored coding vector, perform dynamic coding based on message passing constraints on the temporal distribution of the CPU occupancy local time-domain mode feature vector to obtain the CPU occupancy temporal propagation dynamic coding feature vector, including: Calculate the CPU occupancy tail-end message passing constraint factor of each CPU occupancy local time-domain mode feature vector in the temporal distribution of the CPU occupancy local time-domain mode feature vector relative to the CPU occupancy local time-domain mode message passing space tail-end constraint anchored coding vector; Calculate the CPU occupancy axis message passing constraint factor of each CPU occupancy local time-domain mode feature vector in the temporal distribution of the CPU occupancy local time-domain mode feature vector relative to the CPU occupancy local time-domain mode message passing space axis constraint anchored coding vector; Based on the CPU occupancy tail-end message passing constraint factor and the CPU occupancy axis message passing constraint factor of each CPU occupancy local time-domain mode feature vector in the temporal distribution of the CPU occupancy local time-domain mode feature vector, calculate the CPU occupancy message passing constraint factor of each CPU occupancy local time-domain mode feature vector; Based on the CPU occupancy message passing constraint factor of each CPU occupancy local time-domain mode feature vector, perform message dynamic constraint passing coding on the temporal distribution of the CPU occupancy local time-domain mode feature vector to obtain the CPU occupancy temporal propagation dynamic coding feature vector.

8. The mobile application runtime behavior detection and control method according to claim 7, characterized in that Calculating the CPU occupancy message passing constraint factor for each CPU occupancy local time domain pattern feature vector based on the CPU occupancy tail-end message passing constraint factor and the CPU occupancy axis message passing constraint factor of each CPU occupancy local time domain pattern feature vector in the temporal distribution of the CPU occupancy local time domain pattern feature vectors, including: Using a canonical airspace constraint matrix to perform field strength convergence co-control on the CPU occupancy tail-end message passing constraint factor and the CPU occupancy axis message passing constraint factor corresponding to the CPU occupancy local time domain pattern feature vector to obtain a CPU occupancy tail-end message passing co-control constraint factor and a CPU occupancy axis message passing co-control constraint factor; Based on the CPU occupancy tail-end message passing co-control constraint factor and the CPU occupancy axis message passing co-control constraint factor, performing global stability constraint on the CPU occupancy tail-end message passing constraint factor and the CPU occupancy axis message passing constraint factor to obtain an optimized CPU occupancy tail-end message passing constraint factor and an optimized CPU occupancy axis message passing constraint factor; Performing weight assignment fusion on the optimized CPU occupancy tail-end message passing constraint factor and the optimized CPU occupancy axis message passing constraint factor to obtain the CPU occupancy message passing constraint factor corresponding to the CPU occupancy local time domain pattern feature vector.

9. The method for detecting and controlling the runtime behavior of a mobile application according to claim 8, wherein Based on the CPU occupancy temporal propagation dynamic coding feature vector, obtaining the predicted value of the CPU occupancy at the next time point, including: inputting the CPU occupancy temporal propagation dynamic coding feature vector into an occupancy predictor based on a decoder to obtain the predicted value of the CPU occupancy at the next time point.

Citation Information

Cited By

  • High-temperature-resistant and high-pressure-resistant lubricating oil and preparation method thereof

    CN120340644A

  • Attack event prediction method and system based on low-intensity abnormal mode data

    CN120455180A

  • Intelligent water meter anomaly detection system and method

    CN120524394A