Data defense detection method and system based on artificial intelligence

By generating unique dynamic fingerprints and quantifying threat fusion scores, the existing AI data defense detection methods solve the identification problems of existing AI data defense detection methods in the face of complex adversarial attacks, and efficient and accurate data defense detection is achieved, improving the security and real-time response capabilities of the AI system.

CN120301705AActive Publication Date: 2025-07-11CHENGDU YOUKA DIGITAL INFORMATION TECH CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510764810.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2025-07-11
Estimated Expiration
2045-06-10

AI Technical Summary

Technical Problem

When facing complex adversarial attacks, existing AI data defense detection methods are susceptible to noise data interference, false alarms or missed reports, and are highly computationally consumed, lack real-time response capabilities, making it difficult to effectively identify new threats.

Method used

Using artificial intelligence-based data defense detection methods, by generating a unique dynamic fingerprint, quantifying the possibility of anti-sample tampering, and calculating threat fusion scores, real-time monitoring and analysis of input data, including data collection, dynamic fingerprint generation, possibility quantification and threat fusion score calculation.

Benefits of technology

It improves the security and reliability of AI systems, can timely identify potential malicious attacks and abnormal behaviors, optimize defense strategies, and deal with new attack methods and data tampering technologies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301705A_ABST
    Figure CN120301705A_ABST
Patent Text Reader

Abstract

The invention discloses a data defense detection method and system based on artificial intelligence. The data defense detection method based on artificial intelligence comprises the following steps: S110, collecting data needing defense detection as input data; s120, generating a unique dynamic fingerprint for the input data, and identifying potential attack variants; s130, quantizing the possibility that the data is tampered by the adversarial sample; s140, calculating a threat fusion score according to the possibility that the dynamic fingerprint and the data are tampered by the confrontation sample; s150, performing data defense detection and response according to the threat fusion score; according to the method, continuously updated threat intelligence is provided for data defense detection, and a system can optimize a defense strategy in time so as to cope with a new attack mode and a data tampering technology.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an artificial intelligence data detection method, and particularly to an artificial intelligence-based data defense detection method. Background Art

[0002] With the rapid development of artificial intelligence (AI) and machine learning (ML) technologies, AI has been widely applied in many fields such as data analysis, automated decision-making, and image recognition. However, with the popularization of AI technology, data security issues have become increasingly prominent, especially in terms of adversarial attacks and data tampering. Adversarial attacks can mislead AI models into making wrong decisions through tiny perturbations or carefully designed data forgeries, thus threatening the integrity of data and the security of the system. These attacks are usually difficult to be detected by traditional security protection mechanisms, and with the increasing complexity of attack means, existing defense technologies face huge challenges.

[0003] Although existing AI-based data defense detection methods have shown certain effects in many aspects, they still face many technical challenges. First, existing dynamic fingerprint and behavior analysis technologies usually rely on traditional pattern recognition methods and are easily interfered by noisy data or camouflage attacks, resulting in false positives or false negatives. Attackers can avoid these detection means by simulating normal user behaviors, increasing the difficulty of defense. Second, although defense methods against adversarial examples are constantly evolving, existing technologies such as adversarial training and input data preprocessing often cannot completely eliminate the threat of new adversarial attacks and may lead to a decline in the performance of AI models. In addition, the computational consumption and real-time response capabilities in the defense process are also weak links in current technologies. With the continuous evolution and complexity of attack methods, existing defense detection methods need to be continuously optimized and updated to adapt to the challenges of new threats. Therefore, designing a more efficient, accurate, and robust AI data defense detection method has become the key to ensuring the security and reliability of AI systems. To solve this problem, an artificial intelligence-based data defense detection method has emerged. This method combines machine learning, deep learning, and data mining technologies, and through multi-dimensional security protection strategies such as dynamic fingerprint analysis, behavior monitoring, and adversarial example detection, it monitors and analyzes the input data of the AI system in real time to identify potential malicious attacks and abnormal behaviors. Summary of the Invention

[0004] The present invention provides an artificial intelligence-based data defense detection method, including: S110. Collect data that needs to be defense-detected as input data; S120. Generate a unique dynamic fingerprint for the input data to identify potential attack variants; S130. Quantify the possibility that the data is tampered with by adversarial examples; S140. Calculate the threat fusion score based on the dynamic fingerprint and the likelihood of the data being tampered with by adversarial samples; S150. Conduct data defense detection and response based on the threat fusion score.

[0005] A data defense detection method based on artificial intelligence as described above, wherein the method for generating a unique dynamic fingerprint specifically includes the following sub-steps: Extract local features from the input data and perform weighting and normalization processing; Compress the weighted and normalized features into a stable interval through an activation function; Generate a unique dynamic fingerprint for the processed input data.

[0006] A data defense detection method based on artificial intelligence as described above, wherein the unique dynamic fingerprint represents a unique and robust fingerprint code generated for each input data, and this code is used to detect and distinguish different data samples, identify and track potential attack variants. The dynamic fingerprint of the input data is calculated through a differentiable hashing network. If the attacker slightly tampers with the input data, the dynamic fingerprint will show obvious differences.

[0007] A data defense detection method based on artificial intelligence as described above, wherein the method for calculating the threat fusion score based on the dynamic fingerprint and the likelihood of the data being tampered with by adversarial samples specifically includes the following sub-steps: Calculate the dynamic fingerprint deviation; Calculate the threat fusion score based on the dynamic fingerprint deviation and the likelihood of the data being tampered with by adversarial samples.

[0008] A data defense detection method based on artificial intelligence as described above, wherein the threat fusion score represents a quantitative index of the sample threat level. The larger the value, the more likely the sample is to be attacked or tampered with. The dynamic fingerprint deviation and the adversarial potential respectively provide different abnormality indexes.

[0009] The present invention also provides a data defense detection system based on artificial intelligence, including: a data acquisition module, a dynamic fingerprint generation module, a possibility quantification module, a threat fusion score calculation module, and a detection and response module.

[0010] Data acquisition module: Acquire the data that needs to be subjected to defense detection as input data; Dynamic fingerprint generation module: Generate a unique dynamic fingerprint for the input data to identify potential attack variants; Possibility quantification module: Quantify the likelihood of the data being tampered with by adversarial samples; Threat fusion score calculation module: Calculate the threat fusion score based on the dynamic fingerprint and the likelihood of the data being tampered with by adversarial samples; Detection and Response Module: Based on the threat fusion score, perform data defense detection and response.

[0011] A data defense detection system based on artificial intelligence as described above, wherein the method for generating a unique dynamic fingerprint specifically includes the following sub-steps: Extract local features from the input data and perform weighting and normalization processing; Compress the weighted and normalized features into a stable interval through an activation function; Generate a unique dynamic fingerprint for the processed input data.

[0012] A data defense detection system based on artificial intelligence as described above, wherein the unique dynamic fingerprint represents a unique and robust fingerprint code generated for each input data, and this code is used to detect and distinguish different data samples, identify and track potential attack variants. The dynamic fingerprint of the input data is calculated through a differentiable hashing network. If the attacker slightly tampers with the input data, the dynamic fingerprint will show obvious differences.

[0013] A data defense detection system based on artificial intelligence as described above, wherein the method for calculating the threat fusion score according to the dynamic fingerprint and the possibility of the data being tampered with by adversarial samples specifically includes the following sub-steps: Calculate the dynamic fingerprint deviation; Calculate the threat fusion score according to the dynamic fingerprint deviation and the possibility of the data being tampered with by adversarial samples.

[0014] A data defense detection system based on artificial intelligence as described above, wherein the threat fusion score represents a quantitative index of the sample threat level. The larger the value, the more likely the sample is to be attacked or tampered with. The dynamic fingerprint deviation and the adversarial potential respectively provide different abnormality indexes.

[0015] The beneficial effects achieved by the present invention are as follows: Provide continuously updated threat intelligence for data defense detection, which is beneficial for the system to optimize the defense strategy in a timely manner to cope with new attack methods and data tampering technologies. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings.

[0017] Figure 1 It is a flowchart of a data defense detection method provided in Embodiment 1 of the present application; Figure 2It is a schematic diagram of a system for detecting the dynamic characteristics of a train under a wind tunnel experiment provided by the second embodiment of the present application. Detailed implementation manners

[0018] Next, with reference to the accompanying drawings in the embodiments of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0019] Embodiment 1 As Figure 1 shown, Embodiment 1 of the present application provides an artificial intelligence-based data defense detection method, including: Step S110: Collect data to be subjected to defense detection as input data; The data sources for defense detection mainly include user behavior data, system log and event data, adversarial sample data, and environmental perception data. User behavior data refers to collecting dynamic fingerprint data of users by tracking user operation behaviors (such as clicks, inputs, operation times, etc.), and these data help to identify whether there are signs of abnormal behaviors or attack behaviors. System log and event data refer to the log information obtained from servers, application programs, and network devices, and these logs contain system access, error information, abnormal operations, etc., which can provide strong support for defense detection. Adversarial sample data refers to obtaining data samples that may affect the AI model by simulating adversarial attacks or collecting malicious samples in the network, and these data are used to evaluate the robustness of the model against adversarial samples. Environmental perception data refers to including device information, IP addresses, geographical locations, etc., and these data help to determine whether the user or device is within the normal activity range, thereby improving the ability to identify abnormal behaviors.

[0020] Collect data to be subjected to defense detection as input data. First, deploy a variety of data collection tools, such as behavior analysis tools, network traffic monitors, and log analysis systems, to automatically collect various data sources. User behavior data is captured through the interaction logs of the front-end page or the activity records of the back-end server to ensure that it can reflect the operation path and time period of each user. System log and event data are transmitted to the security analysis platform at regular intervals by configuring network devices and the server side. The collection of adversarial sample data is achieved by simulating different attack scenarios to automatically generate or collect samples with malicious tampering from the network. All data is stored in an encrypted database, and the integrity and confidentiality of the data are ensured. After being processed, it is used as input and transmitted to the defense detection system for analysis and response.

[0021] Step S120: Generate a unique dynamic fingerprint for the input data to identify potential attack variants; The unique dynamic fingerprint represents a unique and robust fingerprint code generated for each piece of input data. This code can be used to detect and distinguish different data samples, identify and track potential attack variants. Attack variants refer to data after slight tampering or adversarial attacks. Calculate the dynamic fingerprint of the input data through a differentiable hashing network. If an attacker slightly tampers with the input data, the dynamic fingerprint will show obvious differences. The method for generating the unique dynamic fingerprint specifically includes the following sub-steps: Step S121: Extract local features from the input data and perform weighting and normalization processing; Divide the input data into n sub-fragments, assign a learnable weight to each sub-fragment, calculate the weighted value of each sub-fragment, and obtain the local features of each sub-fragment. The weighted local features of the input data are obtained. Specifically, use the formula: Extract the local features of the input data, where represents the local features of the input data, MID(*) is the feature extraction function, x represents the input data, represents the i-th sub-fragment, and i takes values from 1 to n, represents the learnable weight of each fragment, represents the normalization process for the i-th word fragment.

[0022] Step S122: Compress the weighted and normalized features into a stable interval through an activation function; Compress the weighted and normalized features into a stable interval through an activation function to increase the non-linear expression ability. The activation function uses the sigmoid function. Specifically, use the formula: represents the compression process, where represents the result after compressing the features into a stable interval, represents the sigmoid function, represents the local features of the input data.

[0023] Step S123: Generate a unique dynamic fingerprint for the processed input data; Utilize data awareness to make the fingerprint specific to different inputs, and generate a unique dynamic fingerprint for the processed input data. Specifically, use the formula: Generate the unique dynamic fingerprint, where represents the generated unique dynamic fingerprint, represents the processed input data, represents the sensitive adjustment matrix related to the input data, represents element-wise multiplication.

[0024] Step S130: Quantify the possibility that the quantified data is tampered with by adversarial samples; To quantify the possibility that the input data is adversarially tampered with, an adversarial gradient field is introduced. This gradient field can quantify the direction and magnitude of data mutation in the input space, thereby effectively identifying potential attack samples. First, calculate the logarithmic likelihood gradient of the model output with respect to the input. The logarithmic likelihood gradient reflects the sensitivity of the model's prediction change near the current input, indicating the direction in which a small perturbation of the data will cause the largest prediction change. To avoid over-amplifying small perturbations when the input data is still close to the clean sample, an adaptive adjustment factor based on the distance between the input and the corresponding clean sample is introduced. This factor tends to zero when the input is close to the clean sample, thereby effectively suppressing the gradient intensity; while when the distance between the input and the clean sample increases, the factor tends to one, fully exposing potential adversarial tampering. Specifically, the formula: is used to calculate the possibility that the data is tampered with by adversarial samples, where represents the possibility, x represents the input data, represents the original clean sample, represents the prediction model, y represents the prediction result, represents the model confidence, represents taking the gradient of the data x.

[0025] Step S140: Calculate the threat fusion score based on the dynamic fingerprint and the possibility that the data is tampered with by adversarial samples; The method for calculating the threat fusion score based on the dynamic fingerprint and the possibility that the data is tampered with by adversarial samples is specifically divided into the following sub-steps: Step S141: Calculate the dynamic fingerprint deviation; To reflect the degree of deviation of the input sample from the clean sample in the feature space, the unique dynamic fingerprint generated from the input data x is compared with the original clean sample fingerprint generated from the original clean sample to calculate the deviation value. Specifically, the formula: is used to calculate the dynamic fingerprint deviation, where represents the dynamic fingerprint deviation value. The higher the deviation value, the more obvious the fingerprint change and the higher the suspicion. x represents the input data, represents the original clean sample, represents the generated unique dynamic fingerprint,

[0026] Step S142: Calculate the threat fusion score based on the dynamic fingerprint deviation and the possibility that the data is tampered with by adversarial samples; The threat fusion score represents a quantitative indicator of the threat level of a sample. The larger the value, the more likely it is that the sample has been attacked or tampered with. The dynamic fingerprint deviation and adversarial potential respectively provide different abnormality indicators. Specifically, the formula: is used to calculate the threat fusion score, where represents the threat fusion score of the input data x, represents the influence factor of the dynamic fingerprint deviation on the threat fusion score, represents the influence factor of the possibility of the data being tampered with by adversarial samples on the threat fusion score, represents the dynamic fingerprint deviation, represents the possibility of the data being tampered with by adversarial samples, represents the normalization function.

[0027] Step S150: According to the threat fusion score, perform data defense detection and response; When the threat fusion score exceeds the set security threshold, the system automatically triggers the defense detection mechanism. First, the system will analyze the nature of the threat based on the specific source of the score: If the score is relatively high due to the dynamic fingerprint deviation, the system will initiate user behavior analysis to identify and isolate potentially abnormal behavior data to prevent further data tampering or abnormal operations. If the score is relatively high due to adversarial sample tampering, the system will evaluate the data integrity through an adversarial sample detection model and initiate data cleaning and repair procedures to remove potential malicious tampering.

[0028] Once a threat is detected, the system automatically executes response measures, enhances the robustness of the model, adjusts the algorithm to cope with new types of attacks, and restricts the access rights of suspicious users. At the same time, the system will also initiate a secondary verification mechanism for manual review and confirmation to minimize false positives. Finally, the defense mechanism will optimize the defense strategy in a timely manner according to the continuously updated threat intelligence to cope with new attack methods and data tampering techniques, forming a dynamic and closed-loop defense system.

[0029] Example 2 As Figure 2 shown, Embodiment 1 of the present application provides an artificial intelligence-based data defense detection system, including: Data acquisition module 21: Acquire the data that needs to be subjected to defense detection as input data; The data sources for defense detection mainly include user behavior data, system logs and event data, adversarial sample data, and environmental perception data. User behavior data refers to collecting dynamic fingerprint data of users by tracking their operation behaviors (such as clicks, inputs, operation times, etc.), which helps identify signs of abnormal or attack behaviors. System logs and event data refer to the log information obtained from servers, application programs, and network devices. These logs contain system access, error messages, abnormal operations, etc., and can provide strong support for defense detection. Adversarial sample data refers to obtaining data samples that may affect AI models by simulating adversarial attacks or collecting malicious samples in the network. These data are used to evaluate the robustness of the model against adversarial samples. Environmental perception data includes device information, IP addresses, geographical locations, etc. These data help determine whether users or devices are within the normal activity range, thereby improving the ability to identify abnormal behaviors.

[0030] Collect the data required for defense detection as input data. First, deploy multiple data collection tools, such as behavior analysis tools, network traffic monitors, and log analysis systems, to automatically collect various data sources. User behavior data is captured through the interaction logs of the front-end page or the activity records of the back-end server to ensure that it can reflect the operation path and time period of each user. System logs and event data are transmitted to the security analysis platform regularly by configuring network devices and the server. The collection of adversarial sample data is achieved by simulating different attack scenarios to automatically generate or collect samples with malicious tampering from the network. All data is stored in an encrypted database, and the integrity and confidentiality of the data are ensured. After processing, it is passed as input to the defense detection system for analysis and response.

[0031] Dynamic fingerprint generation module 22: Generate a unique dynamic fingerprint for the input data to identify potential attack variants; The unique dynamic fingerprint represents a unique and robust fingerprint code generated for each input data. This code can be used to detect and distinguish different data samples, identify and track potential attack variants. Attack variants refer to data after slight tampering or adversarial attacks. Calculate the dynamic fingerprint of the input data through a differentiable hashing network. If an attacker slightly tampers with the input data, the dynamic fingerprint will show obvious differences. The method for generating the unique dynamic fingerprint specifically includes the following sub-steps: Local feature extraction module: Extract local features from the input data and perform weighting and normalization processing; Divide the input data into n sub-fragments, assign a learnable weight to each sub-fragment, calculate the weighted value of each sub-fragment to obtain the local feature of each sub-fragment, and weight to obtain the local feature of the input data. Specifically, use the formula: Extract the local features of the input data, where Represents the local features of the input data. MID(*) is the feature extraction function, x represents the input data, Represents the i-th sub-segment, where i ranges from 1 to n, Represents the learnable weight of each segment, Represents the normalization process of the i-th word segment.

[0032] Activation module: Compresses the weighted and normalized features into a stable interval through an activation function; Compresses the weighted and normalized features into a stable interval through an activation function, increasing the non-linear expression ability. The activation function uses the sigmoid function. Specifically, the formula is: Represents the compression process, where Represents the result after compressing the features into a stable interval, Represents the sigmoid function, Represents the local features of the input data.

[0033] Dynamic fingerprint generation module: Generates a unique dynamic fingerprint for the processed input data; Utilizes data awareness to make the fingerprint specific to different inputs and generates a unique dynamic fingerprint for the processed input data. Specifically, the formula is: Generates a unique dynamic fingerprint, where Represents the generated unique dynamic fingerprint, Represents the processed input data, Represents the sensitive adjustment matrix related to the input data, Represents element-wise multiplication.

[0034] Possibility quantification module 23: Quantifies the possibility that the data is tampered with by adversarial samples; To quantify the possibility that the input data is adversarially tampered with, an adversarial gradient field is introduced. This gradient field can quantify the direction and magnitude of data mutation in the input space, thereby effectively identifying potential attack samples. First, calculate the log-likelihood gradient of the model output with respect to the input. The log-likelihood gradient reflects the sensitivity of the model's prediction change near the current input, indicating the direction in which a small perturbation of the data will cause the largest prediction change. To avoid over-amplifying small perturbations when the input data is still close to the clean sample, an adaptive adjustment factor based on the distance between the input and the corresponding clean sample is introduced. This factor approaches zero when the input is close to the clean sample, thereby effectively suppressing the gradient intensity; while when the distance between the input and the clean sample increases, the factor approaches one, fully exposing potential adversarial tampering. Specifically, the formula is: Calculates the possibility that the data is tampered with by adversarial samples, where Represents the possibility, x represents the input data, represents the original clean sample, represents the prediction model, and y represents the prediction result. represents the model confidence. represents taking the gradient of the data x.

[0035] Threat Fusion Scoring Calculation Module 24: Calculate the threat fusion score based on the dynamic fingerprint and the likelihood of the data being tampered with by adversarial samples; The method for calculating the threat fusion score based on the dynamic fingerprint and the likelihood of the data being tampered with by adversarial samples is specifically divided into the following sub - steps: Dynamic Fingerprint Difference Calculation Module: Calculate the dynamic fingerprint deviation; To reflect the degree of deviation of the input sample from the clean sample in the feature space, the unique dynamic fingerprint generated for the input data x is compared with the original clean sample fingerprint generated from the original clean sample to calculate the deviation value. Specifically, the formula is: Calculate the dynamic fingerprint deviation, where represents the dynamic fingerprint deviation value. The higher the deviation value, the more obvious the fingerprint change and the higher the suspicion level. x represents the input data, represents the original clean sample,

[0036] Threat Fusion Scoring Calculation Module: Calculate the threat fusion score based on the dynamic fingerprint deviation and the likelihood of the data being tampered with by adversarial samples; The threat fusion score is a quantitative indicator representing the threat level of the sample. The larger the value, the more likely the sample is to be attacked or tampered with. The dynamic fingerprint deviation and the adversarial potential respectively provide different abnormality indicators. Specifically, the formula is: Calculate the threat fusion score, where represents the threat fusion score of the input data x, represents the influence factor of the dynamic fingerprint deviation on the threat fusion score, represents the influence factor of the likelihood of the data being tampered with by adversarial samples on the threat fusion score, represents the dynamic fingerprint deviation, represents the likelihood of the data being tampered with by adversarial samples, represents the normalization function.

[0037] Detection and Response Module 25: Perform data defense detection and response based on the threat fusion score; When the threat fusion score When the set security threshold is exceeded, the system automatically triggers the defense detection mechanism. First, the system analyzes the nature of the threat based on the specific source of the score: if the score is high due to dynamic fingerprint deviation, the system will initiate user behavior analysis to identify and isolate possible abnormal behavior data to prevent further data tampering or abnormal operations. If the high score comes from adversarial sample tampering, the system will evaluate data integrity through an adversarial sample detection model and initiate data cleaning and repair procedures to remove potential malicious tampering.

[0038] Once a threat is detected, the system automatically executes response measures, enhances the robustness of the model, adjusts the algorithm to cope with new types of attacks, and restricts the access rights of suspicious users. At the same time, the system will also initiate a secondary verification mechanism for manual review and confirmation to minimize false positives. Finally, the defense mechanism will optimize the defense strategy in a timely manner according to continuously updated threat intelligence to cope with new attack methods and data tampering techniques, forming a dynamic and closed-loop defense system.

[0039] The specific embodiments described above further elaborate on the purpose, technical solutions, and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solutions of the present invention shall be included in the protection scope of the present invention.

Claims

1. A data defense detection method based on artificial intelligence, characterized in that, Including: S110. Collect the data that needs to be defensively detected as input data; S120. Generate a unique dynamic fingerprint for the input data to identify potential attack variants; S130. Quantify the possibility that the data is tampered with by adversarial samples; S140. Calculate the threat fusion score based on the dynamic fingerprint and the possibility that the data is tampered with by adversarial samples; S150. Conduct data defense detection and response based on the threat fusion score.

2. The data defense detection method based on artificial intelligence according to claim 1, wherein The method for generating a unique dynamic fingerprint specifically includes the following sub-steps: Extract local features from the input data and perform weighting and normalization processing; Compress the weighted and normalized features into a stable interval through an activation function; Generate a unique dynamic fingerprint for the processed input data.

3. The data defense detection method based on artificial intelligence according to claim 2, wherein The unique dynamic fingerprint represents a unique and robust fingerprint code generated for each input data. This code is used to detect and distinguish different data samples, identify and track potential attack variants. By calculating the dynamic fingerprint of the input data through a differentiable hashing network, if the attacker slightly tampers with the input data, the dynamic fingerprint will show obvious differences.

4. The data defense detection method based on artificial intelligence according to claim 1, characterized in that, The method for calculating the threat fusion score based on the dynamic fingerprint and the possibility that the data is tampered with by adversarial samples specifically includes the following sub-steps: Calculate the dynamic fingerprint deviation; Calculate the threat fusion score based on the dynamic fingerprint deviation and the possibility that the data is tampered with by adversarial samples.

5. The data defense detection method based on artificial intelligence according to claim 4, wherein The threat fusion score represents a quantitative indicator of the threat level of the sample. The larger the value, the more likely it is that the sample has been attacked or tampered with. The dynamic fingerprint deviation and adversarial potential respectively provide different abnormality indicators.

6. An artificial intelligence-based data defense detection system, characterized in that, Including: Data acquisition module: Collect the data that needs to be defensively detected as input data; Dynamic fingerprint generation module: Generate a unique dynamic fingerprint for the input data to identify potential attack variants; Possibility quantification module: Quantify the possibility that the data is tampered with by adversarial samples; Threat fusion score calculation module: Calculate the threat fusion score based on the dynamic fingerprint and the possibility that the data is tampered with by adversarial samples; Detection and response module: Conduct data defense detection and response based on the threat fusion score.

7. The data defense detection system based on artificial intelligence according to claim 6, characterized in that, The method for generating a unique dynamic fingerprint specifically includes the following sub-steps: Extract local features from the input data and perform weighting and normalization processing; Compress the weighted and normalized features into a stable interval through an activation function; Generate a unique dynamic fingerprint for the processed input data.

8. An artificial intelligence-based data defense detection system according to claim 7, characterized in that, The unique dynamic fingerprint represents a unique and robust fingerprint code generated for each input data. This code is used to detect and distinguish different data samples, identify and track potential attack variants. By calculating the dynamic fingerprint of the input data through a differentiable hashing network, if the attacker slightly tampers with the input data, the dynamic fingerprint will show obvious differences.

9. The data defense detection system based on artificial intelligence according to claim 6, characterized in that, The method for calculating the threat fusion score based on the dynamic fingerprint and the possibility that the data is tampered with by adversarial samples specifically includes the following sub-steps: Calculate the dynamic fingerprint deviation; Calculate the threat fusion score based on the dynamic fingerprint deviation and the possibility that the data is tampered with by adversarial samples.

10. A data defense detection system based on artificial intelligence according to claim 9, characterized in that, The threat fusion score represents a quantitative indicator of the threat level of the sample. The larger the value, the more likely it is that the sample has been attacked or tampered with. The dynamic fingerprint deviation and adversarial potential respectively provide different abnormality indicators.

Citation Information

Patent Citations

  • Speech recognition attack defense method and device based on gradient estimation and CTC algorithm

    CN110444208A

  • Industrial control system security threat assessment method, device and system

    CN112184091A

  • Adversarial sample detection method based on deep neural network

    CN117034071A

  • Dynamic threat detection and tracing method and device, equipment and storage medium

    CN117896162A

  • Data traffic security defense method based on Internet of Things

    CN118200055A