Right and interest exchange verification and confirmation system
Through multimodal dynamic behavior trust chain and federated learning, the cross-platform behavior baseline library is built, which solves the problems of insufficient dynamic adaptability and poor cross-platform data interoperability in the existing technology, and realizes efficient rights exchange verification and confirmation, improving the accuracy of fraud identification and user experience.
Patent Information
- Application Number
- CN202510474441.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-07-18
AI Technical Summary
Existing behavioral verification technologies lack dynamic adaptability in the face of complex rights fraud, poor cross-platform data interoperability, and conflicts between privacy protection and data collection, resulting in low accuracy of verification models and inconsistent user experience.
A multimodal dynamic behavior trust chain is adopted, and a cross-platform behavioral acquisition module, a federated behavior modeling module, a situational risk assessment module and a dynamic scheduling execution module are combined with lightweight edge computing and federated learning to build a cross-platform behavior baseline library to realize dynamic trust scoring and hierarchical verification, combining time decay model and scene perception weights to enhance adversarial defense capabilities.
Improves fraud identification accuracy and dynamic defense capabilities, optimizes user experience, reduces verification friction, supports cross-platform behavior baseline comparison and real-time calibration, and enhances security and efficiency.
Smart Images

Figure CN120337188A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the technical field of rights and interests management systems, and relates to a rights and interests exchange verification and confirmation system. Background Art
[0002] Currently, the application of behavior verification technology in rights and interests exchange verification and confirmation systems is gradually deepening, becoming an important means to enhance security and user experience. Some leading platforms have begun to adopt dynamic behavior analysis technologies, such as mouse trajectory recognition, keystroke dynamics analysis, device usage habit modeling, etc., and combine machine learning algorithms to construct user behavior portraits for seamless verification. Compared with traditional verification codes or SMS authentication, behavior verification shows unique advantages in preventing machine attacks (such as bulk registration and automated script wool pulling), while reducing the interaction friction of user-initiated verification. However, the industry penetration rate of this technology is still relatively low. Most systems still rely on basic behavior feature detection, lack the dynamic adaptation ability to complex attack patterns, and cross-platform behavior data is difficult to interoperate, restricting the accuracy of verification models.
[0003] Existing behavior verification technologies still have several key shortcomings. First, the stability and uniqueness of behavior features face challenges. Operation differences of users in different device or network environments may lead to misjudgments, and professional black production can bypass basic detection by simulating real human behavior patterns (such as using Human-like AI scripts). Second, there is a contradiction between privacy protection and data collection. The collection of multi-dimensional behavior data may arouse users' concerns about personal information security. In addition, behavior verification systems generally lack a standardized evaluation framework, and the verification thresholds and risk control strategies of different platforms vary greatly, resulting in inconsistent verification experiences for the same user on multiple platforms. With the development of deepfake technology and adversarial sample attacks, the existing behavior verification system urgently needs to be upgraded in the direction of continuous self-adaptation and multi-modal fusion to cope with the increasingly complex rights and interests fraud risks. Summary of the Invention
[0004] To overcome the deficiencies of the prior art, the present invention provides a rights and interests exchange verification and confirmation system, which solves the problem in the prior art that it is unable to face complex rights and interests fraud behaviors through a multi-modal dynamic behavior trust chain constructed based on behavior federated learning and scenario-based risk dynamic assessment.
[0005] To achieve the above object, the present application provides a rights and interests exchange verification and confirmation system, including:
[0006] A multi-modal behavior acquisition module for real-time acquisition of multi-dimensional data of user interaction behaviors;
[0007] The Federal Behavior Modeling Module, connected to the Multimodal Behavior Acquisition Module, constructs a cross-platform behavior baseline library through the federated learning framework and outputs dynamically updated user behavior trust scores;
[0008] The Scenario Risk Assessment Module, connected to the Federal Behavior Modeling Module, implements a hierarchical verification strategy;
[0009] The Dynamic Scheduling and Execution Module, connected to the verification terminal and the Scenario Risk Assessment Module respectively, realizes intelligent resource allocation. The verification terminal is a hardware or software unit with specific verification capabilities;
[0010] The Audit Module, connected to all modules, generates decision logs compliant with GDPR standards.
[0011] Furthermore, the multi-dimensional data collected by the Multimodal Behavior Acquisition Module includes:
[0012] Input behavior features: keystroke dynamics features, mouse trajectory acceleration curves, touch screen pressure distributions,
[0013] Device behavior features: gyroscope jitter patterns, screen rotation angle changes, GPS movement trajectory entropy values,
[0014] Environmental features: network latency fluctuation features, IP address behavior historical portraits, device sensor noise fingerprints;
[0015] A lightweight edge computing unit is used to desensitize and extract features from the multi-dimensional data, generating standardized behavior vectors.
[0016] Furthermore, the behavior baseline library of the Federal Behavior Modeling Module adopts a hierarchical storage architecture and a dynamic update mechanism, including: Short-term behavior baselines, whose data range is the interaction behavior features of the user in the most recent 7 - 30 days, with an update frequency of incremental updates every 4 hours, and the exponential weighted moving average algorithm is used to smooth the noise; Its typical features include the 90th percentile of the mouse movement angular velocity, the KL divergence value of the touch screen pressure distribution, and the spectral entropy of the device gyroscope jitter;
[0017] Long-term behavior baselines, whose data range is the behavior patterns of the user in the past 3 - 12 months, and the update mechanism is to perform principal component analysis dimensionality reduction once a month, retaining the features with 95% variance, and using Gaussian mixture model clustering to identify the user's habitual operation patterns;
[0018] The population behavior reference library, whose data source is the anonymous statistical features of each platform aggregated by federated learning, aims to provide relative assessment of abnormal behaviors and support the behavior analysis of cold-start users.
[0019] Furthermore, the user behavior trust scoring implementation mechanism of the federal behavior modeling module is a multi-dimensional dynamic calculation system, and its technical process is divided into the following five levels:
[0020] Feature quantization layer, which conducts multi-modal behavior vectorization, including: spatio-temporal feature extraction, calculating the deviation from the baseline of time-series data using dynamic time warping, and extracting frequency-domain features from sensor data through wavelet transform; interaction feature encoding, converting the touchscreen pressure distribution into a 128-dimensional SIFT-like descriptor, and using a hidden Markov model to generate a state transition probability matrix for the keyboard input pattern; environmental feature normalization, converting network delay fluctuations into the diffusion coefficient of a Brownian motion model, and encoding GPS trajectories as hierarchical spatial features using H3 geographical grids;
[0021] Federal computing layer, which realizes cross-platform credit fusion, including: local credit calculation, where each edge node calculates the preliminary trust score using the local baseline library:
[0022]
[0023] Among them, is the current behavior feature value, is the baseline value of the corresponding feature, is the feature distance function, usually using: continuous features: standardized Euclidean distance ( is the historical standard deviation) and categorical features: Jaccard distance, is the feature weight, obtained through random forest feature importance analysis;
[0024] Global credit aggregation, which calculates by integrating the scores of each platform through federated weighted average:
[0025]
[0026] Among them, is the number of platforms participating in the federal calculation, is the platform historical interaction data volume (for weighting), is the platform calculated local trust score;
[0027] Dynamic adjustment layer, which is a real-time calibration system for behavior trust scoring. Through multi-dimensional environmental perception and adaptive weight allocation, it ensures that the scoring result is both accurate and in line with the current risk situation. Its mechanism includes:
[0028] Risk scenario perception and weight adjustment. For risk scenario perception, the system monitors the following key scenario indicators in real time:
[0029] Abnormal operation frequency: When the number of requests within a unit time exceeds 2 times the individual baseline value, the high-frequency operation coefficient is triggered, and its weight coefficient is multiplied by 0.8. Device fingerprint change: When a new device logs in and the fingerprint matching degree < 60%, the device risk coefficient is activated, and its weight coefficient is multiplied by 0.6; Geographical displacement contradiction: When the distance between the login IP and the common location > 1000 km and the moving speed is unnatural, the cross-border coefficient is applied, and its weight coefficient is multiplied by 0.7.
[0030] For weight adjustment, through dynamic weight calculation: the final scenario weight Generated by the Bayesian network:
[0031]
[0032] Among them, the prior probability Based on the training of historical attack data, the evidence Evidence includes 10-dimensional features such as real-time network latency and operation time window;
[0033] Time decay model, the decay function adopts a hybrid model of hyperbolic decay and exponential decay:
[0034] Short-term linear decay area (0 < t ≤ 1 hour): No decay, the weight remains 100%;
[0035] Medium-term exponential decay area (1 hour < t ≤ 24 hours): Exponential decay , where is the initial score, from the federal global trust ;
[0036] Long-term hyperbolic decay area (t > 24 hours): Hyperbolic decay ;
[0037] Behavior continuity protection, enabling behavior chain locking for critical operations, pausing time decay during continuous operations to prevent misjudgment;
[0038] Adversarial defense layer, intercepting the abnormal score, using the isolation forest algorithm to detect abnormal points in the feature space for its adversarial sample detection, and observing the response by injecting chaotic noise into the suspected GAN-generated operations; The credit freezing mechanism is to immediately freeze the score when detecting the mutation of the behavior entropy value and the contradiction of multimodal features;
[0039] Visualization decision layer, the visualization decision layer transforms the scoring process into an interpretable and auditable interactive output, including: realizing score decomposition and attribution analysis through a three-dimensional scoring map and a heat map of feature contribution degrees, as well as dynamic threshold management and real-time audit tracking;
[0040] The calculation formula for the final synthesized behavior trust score is:
[0041]
[0042] Among them, is the local trust score of the th platform, which is calculated by the federal computing layer. is the data weight of the th platform, based on the historical data quality and data volume of this platform. is the time decay benchmark, which is the difference between the current time and the time when the behavior occurred. is the correction coefficient of the th risk scenario, used to dynamically adjust the score. When the risk scenario is a new device login, , for cross-border operations , for non-working hours: , is the number of risk scenarios. is the anti-attack identification. It takes 1 when an attack is detected, otherwise it takes 0. is the attack penalty amount. After the attack is confirmed, a fixed score is directly deducted. If , when an attack is detected, the score is reduced by at least 30%.
[0043] Furthermore, the hierarchical verification strategy of the scenario risk assessment module is divided into:
[0044] Low-risk scenario: Trigger non-intrusive verification, only continuously monitor the change of behavior entropy value, based on the trust score ≥ 0.85;
[0045] Medium-risk scenario: Start multi-modal cross-verification, require the user to complete a specific AR gesture within 3 seconds, based on 0.6 ≤ trust score < 0.85;
[0046] High-risk scenario: Activate enhanced verification, and it is necessary to synchronously submit the voiceprint pulse response and the device fingerprint DNA code, based on the trust score < 0.6.
[0047] Furthermore, the intelligent resource allocation of the dynamic scheduling execution module refers to:
[0048] When the processing delay of the verification terminal exceeds 15% of the historical average duration: Automatically switch to the edge computing node for behavior feature extraction, and enable the adaptive compression algorithm for the transmitted data;
[0049] When the characteristics of a distributed denial of service attack (DDoS) are detected: Route the verification request to the standby terminal cluster with the same behavior label, and dynamically increase the anti-disturbance intensity of the image verification code.
[0050] Furthermore, the decision log generated by the audit module includes: Recording the specific reason classification of verification failure, visualizing the heat map of behavior feature deviation, and supporting the regulatory agency for retrospective auditing.
[0051] Furthermore, the multimodal behavior collection module and the federated behavior modeling module achieve deep cooperation through layered data stream processing and federated learning closed loop, and the cooperation process is divided into the following three stages:
[0052] S11 real-time behavior data collaborative collection and preprocessing, including:
[0053] Edge-side data reduction: The multimodal behavior collection module cleans the original data locally on the terminal device: sliding window normalization is used for time series data such as mouse trajectory, key features are extracted and a 256-dimensional feature vector is generated. Gaussian noise is added through differential privacy (ε=0.5) to ensure that the data cannot be traced;
[0054] Federated feature alignment: The multimodal behavior acquisition module compares the processed feature vector with the feature space mapping table shared by the federated behavior modeling module, automatically matches the feature fields of each participant, triggers the online negotiation protocol for misaligned features, and dynamically updates the field encoding dictionary of each node;
[0055] S12 distributed model training and attack detection, including: incremental federated learning, model aggregation every 30 minutes: each terminal sends the gradient matrix of the local behavior model Encrypted as Upload, the federated modeling module decrypts and aggregates gradients through secure multi-party computing, and updates the global model , distribute the new model parameters to the multimodal behavior acquisition module for the next round of edge reasoning;
[0056] Collaborative attack identification, including: when the multimodal behavior acquisition module detects abnormal behavior, it immediately sends a compressed event snapshot to the federation module, the federation module compares the attack pattern library of the entire network, returns the risk label within 200ms, and triggers federation adversarial training when a new attack pattern is found, and each node synchronously generates adversarial samples to enhance the robustness of the model;
[0057] S13 dynamic baseline adjustment and verification optimization, including: personalized behavior baseline maintenance, the federated modeling module maintains a dual time scale baseline for each user: a short-term baseline and a long-term baseline, and the multimodal behavior collection module calculates the dynamic time warping (DTW) distance between the user's current behavior and the baseline every hour, triggering secondary verification when the threshold is exceeded;
[0058] Cross-platform credit transfer: When a user passes strict verification on platform A, the federation module generates a verifiable credential (VC). When the user visits platform B, the multimodal behavior collection module automatically submits the VC. After verification, the federation module synchronizes part of the credit score, achieving one-time verification and multi-terminal access.
[0059] Further, when the user initiates a rights and interests redemption request, the system realizes end-to-end intelligent verification and risk control through the cooperation of each module. The specific operation process is as follows:
[0060] S21 Request Triggering and Behavior Collection: Request Interception. When the user clicks "Redeem", the front-end SDK automatically triggers the verification process, generates a session ID and encrypts it for transmission to the gateway. The multi-modal behavior collection module synchronously collects multi-modal data: Input Behavior: Record the mouse trajectory and keyboard input interval of this operation; Device Fingerprint: Obtain the gyroscope noise pattern and screen touch pressure distribution; Environmental Characteristics: Capture the current network latency jitter and GPS positioning hash value. Use a lightweight edge computing unit to desensitize and extract features from the multi-modal data, generating a standardized behavior vector.
[0061] S22 Real-time Trust Score Calculation: Federated Behavior Comparison. The system performs multi-dimensional matching of the preprocessed feature vector with the federated behavior baseline library, including Short-term Behavior Comparison: Calculate the DTW distance between the current session and the baseline in the last 7 days, and Long-term Habit Verification: Check the cosine similarity between the device fingerprint and the historical record, and generate a dynamic trust score. Use a composite formula to calculate the real-time trust score. If the score falls into the medium-risk scenario, start multi-modal cross-verification.
[0062] S23 Hierarchical Verification Execution: The scenario risk assessment module implements hierarchical verification according to its hierarchical verification strategy. Low-risk scenario: Trigger non-intrusive verification, only continuously monitor the change of behavior entropy value. Medium-risk scenario: Start multi-modal cross-verification, requiring the user to complete a specific AR gesture within 3 seconds. High-risk scenario: Activate enhanced verification, and it is necessary to synchronously submit the voiceprint pulse response and the device fingerprint DNA encoding. The multi-modal cross-verification means: The front-end pops up an AR verification interface, requiring the user to complete a 3D gesture signature within 3 seconds, and synchronously verify the consistency of the gesture biomechanical characteristics and the device sensor. Anti-counterfeiting detection is an injection of adversarial noise test, randomly adding a 1ms delay during the verification process to detect whether the operation is program simulation.
[0063] S24 Resource Scheduling and Risk Disposal, Load Balancing: When it is detected that the CPU utilization rate of the target server > 70%, the dynamic scheduling execution module automatically routes the verification request to the edge node and enables the lightweight model. Attack Response: If it is identified that the L2 regularization distance of the mouse trajectory > 3.0 and the Jaccard similarity between the device fingerprint and the known wool party cluster > 0.6, the system immediately freezes the current redemption request and sends a snapshot of the attack characteristics to the risk control center to update the federated adversarial sample library.
[0064] S25 Redemption Completion and Baseline Update, The successful path is: When the final trust score When the verification is successful, a verifiable credential (VC) is issued to the blockchain, the fund freeze is lifted, and the exchange is completed. At this time, the user obtains an invisible verification mark, and similar operations within the next 30 minutes are exempt from verification; whether successful or not, the system will use federated learning to update the user behavior baseline and optimize the scenario coefficient. for baseline iteration.
[0065] For legitimate users with a low trust score, the manual review channel is triggered, and at the same time, behavior replay data is collected for model optimization.
[0066] Due to the above technical solutions adopted by the present invention, it has the following beneficial effects:
[0067] The system described in this application constructs a high-dimensional user portrait through multi-modal behavior features, combines federated learning to achieve cross-platform behavior baseline comparison, solves the problem of data islands on a single platform, and introduces a time decay model and scenario perception weight into the dynamic trust scoring system to calibrate the scoring results in real time, improving the recognition accuracy; the adversarial defense layer uses isolation forest to detect GAN generation attacks and injects chaotic noise interference, which can effectively resist new automated fraud tools; improves fraud recognition accuracy and dynamic defense capabilities.
[0068] Through the hierarchical verification strategy and intelligent resource scheduling of the system described in this application, the system reduces user friction while ensuring security; in low-risk scenarios (score ≥ 0.85), invisible verification is triggered, while in medium-risk scenarios, fast cross-verification is achieved through AR gestures, effectively shortening the verification time; the feature deviation heat map and decision log provided by the audit module not only support regulatory traceability but also help enterprises optimize risk control strategies, achieving a double improvement in security and efficiency and optimizing the user experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0069] The drawings described herein are used to provide a further understanding of the present invention, form a part of this application, and do not constitute an improper limitation of the present invention. In the drawings:
[0070] Figure 1 is a system schematic diagram of a rights and interests exchange verification and confirmation system of the present invention;
[0071] Figure 2 is a schematic diagram of the technical process level of the user behavior trust scoring of the federated behavior modeling module of the present invention;
[0072] Figure 3 is a collaboration flow chart of the multi-modal behavior acquisition module and the federated behavior modeling module of the present invention;
[0073] Figure 4 is a system operation flow chart of the rights and interests exchange of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0074] To make the objectives and advantages of the present invention more clear and understandable, the present invention will be further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only for explaining the present invention and are not used to limit the present invention.
[0075] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are only used to explain the technical principles of the present invention and do not limit the protection scope of the present invention.
[0076] It should be noted that in the description of the present invention, the terms indicating the direction or positional relationship such as "upper", "lower", "left", "right", "inner", "outer", etc. are based on the direction or positional relationship shown in the drawings. This is only for convenience of description and does not indicate or imply that the device or element must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation to the present invention.
[0077] In addition, it should also be noted that in the description of the present invention, unless otherwise clearly specified and limited, the terms "installation", "connection", "connection" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.
[0078] Please refer to Figure 1 , in this embodiment, a rights redemption verification and confirmation system is provided, including:
[0079] A multi-modal behavior acquisition module for real-time acquisition of multi-dimensional data of user interaction behaviors;
[0080] A federated behavior modeling module, connected to the multi-modal behavior acquisition module, constructs a cross-platform behavior baseline library through a federated learning framework, and outputs a dynamically updated user behavior trust score;
[0081] A scenario risk assessment module, connected to the federated behavior modeling module, to implement a hierarchical verification strategy;
[0082] A dynamic scheduling execution module, connected to the verification terminal and the scenario risk assessment module respectively, to achieve intelligent resource allocation, and the verification terminal is a hardware or software unit with specific verification capabilities;
[0083] An audit module, connected to all modules, to generate a decision log compliant with GDPR standards.
[0084] In this embodiment, it should be further noted that the multi-dimensional data collected by the multi-modal behavior acquisition module includes:
[0085] Input behavior features: keystroke dynamics features (press duration, interval time), mouse trajectory acceleration curve, touch screen pressure distribution,
[0086] Device behavior features: gyroscope jitter mode, screen rotation angle change, GPS movement trajectory entropy value,
[0087] Environmental features: network latency fluctuation features, IP address behavior history portrait, device sensor noise fingerprint;
[0088] A lightweight edge computing unit is used to desensitize and extract features from multi-dimensional data to generate standardized behavior vectors.
[0089] In this embodiment, it should be further noted that the behavior baseline library of the federated behavior modeling module adopts a hierarchical storage architecture and a dynamic update mechanism, including: short-term behavior baseline, whose data range is the interaction behavior features of the user in the recent 7 to 30 days, and the update frequency is incremental update every 4 hours. The exponential weighted moving average algorithm is used to smooth the noise; its typical features include the 90th percentile of the mouse movement angular velocity, the KL divergence value of the touch screen pressure distribution, and the spectral entropy of the device gyroscope jitter;
[0090] Long-term behavior baseline, whose data range is the behavior patterns of the user in the past 3 to 12 months. The update mechanism is to perform principal component analysis dimensionality reduction once a month, retain the features with 95% variance, and use Gaussian mixture model clustering to identify the user's habitual operation patterns. Its application scenarios are mostly: detecting long-term behavior deviations such as user device replacement or identifying the slow "account raising" behavior of black production gangs;
[0091] Group behavior reference library, whose data source is the anonymous statistical features aggregated by federated learning from each platform. The purpose is to provide relative evaluation of abnormal behaviors, such as the range of the user's mouse acceleration deviating from the same user group and support the behavior analysis of cold start users, which is enabled during the first 3 operations of new users.
[0092] Please refer to Figure 2 In this embodiment, it should be further noted that the user behavior trust score implementation mechanism of the federated behavior modeling module is a multi-dimensional dynamic calculation system, and its technical process is divided into the following five levels:
[0093] Feature Quantization Layer, which conducts multi-modal behavior vectorization, including: spatio-temporal feature extraction, calculating the deviation from the baseline for time-series data using dynamic time warping, and extracting frequency-domain features from sensor data through wavelet transform, such as the energy value in the 3Hz frequency band of the gyroscope; interaction feature encoding, converting the touchscreen pressure distribution into a 128-dimensional SIFT-like descriptor, and using a hidden Markov model to generate a state transition probability matrix for the keyboard input mode; environmental feature normalization, converting network delay fluctuations into the diffusion coefficient of a Brownian motion model, and encoding GPS trajectories into hierarchical spatial features using H3 geogrids;
[0094] Federated Computing Layer, which realizes cross-platform credit integration, including: local credit calculation, where each edge node calculates a preliminary trust score using the local baseline library:
[0095]
[0096] Among them, is the current th behavior feature value, is the baseline value of the corresponding feature, is the feature distance function, usually adopting: for continuous features: standardized Euclidean distance ( is the historical standard deviation) and for categorical features: Jaccard distance, is the feature weight, obtained through random forest feature importance analysis;
[0097] Global Credit Aggregation, integrating scores of each platform through federated weighted average calculation:
[0098]
[0099] Among them, is the number of platforms participating in the federated calculation, is the historical interaction data volume of platform (for weighting), is the local trust score calculated by platform ;
[0100] Dynamic Adjustment Layer, which is a real-time calibration system for behavioral trust scores. Through multi-dimensional environmental perception and adaptive weight allocation, it ensures that the scoring results are both accurate and in line with the current risk situation. Its mechanisms include:
[0101] Risk Scenario Perception and Weight Adjustment. For risk scenario perception, the system real-time monitors the following key scenario indicators:
[0102] Abnormal operation frequency: When the number of requests within a unit time exceeds 2 times the individual baseline value, the high-frequency operation coefficient is triggered, and its weight coefficient is multiplied by 0.8. Device fingerprint change: When a new device logs in and the fingerprint matching degree < 60%, the device risk coefficient is activated, and its weight coefficient is multiplied by 0.6. Geographical displacement contradiction: When the distance between the login IP and the common location > 1000 km and the moving speed is unnatural, the cross-border coefficient is applied, and its weight coefficient is multiplied by 0.7.
[0103] For weight adjustment, through dynamic weight calculation: the final scenario weight Generated by the Bayesian network:
[0104]
[0105] Among them, the prior probability Based on the training of historical attack data, the evidence includes 10-dimensional features such as real-time network latency and operation time window;
[0106] Time decay model, the decay function adopts a hybrid model of hyperbolic decay and exponential decay:
[0107] Short-term linear decay area (0 < t ≤ 1 hour): No decay, the weight remains 100%;
[0108] Medium-term exponential decay area (1 hour < t ≤ 24 hours): Exponential decay , where is the initial score, from the federal global trust ;
[0109] Long-term hyperbolic decay area (t > 24 hours): Hyperbolic decay ;
[0110] Behavior continuity protection, enabling behavior chain locking for critical operations, pausing time decay during continuous operations to prevent misjudgment;
[0111] Adversarial defense layer, intercepting the abnormal score. Its adversarial sample detection uses the isolation forest algorithm to detect abnormal points in the feature space, and injecting chaotic noise into the suspected GAN-generated operations to observe the response; The credit freezing mechanism is to immediately freeze the score when detecting the mutation of the behavior entropy value and the contradiction of multimodal features, such as the spatio-temporal mismatch between mouse movement and touch pressure;
[0112] Visualization decision layer, the visualization decision layer transforms the scoring process into an interpretable and auditable interactive output, including: realizing score decomposition and attribution analysis through a three-dimensional scoring atlas and a feature contribution heat map, and real-time audit tracking;
[0113] The calculation formula for the final synthesized behavior trust score is:
[0114]
[0115] Among them, is the local trust score of the th platform, which is calculated by the federated computing layer. is the data weight of the th platform, based on the historical data quality and data volume of this platform. is the time decay benchmark, which is the difference between the current time and the time when the behavior occurred. is the correction coefficient of the th risk scenario, used to dynamically adjust the score. When the risk scenario is a new device login, , for cross-border operations , for non-working hours: , is the number of risk scenarios. is the anti-attack flag, taking 1 when an attack is detected, otherwise taking 0. is the attack penalty amount, directly deducting a fixed score after the attack is confirmed. If , when an attack is detected, the score is reduced by at least 30%.
[0116] In this embodiment, it should be further noted that the hierarchical verification strategy of the scenario risk assessment module is divided into:
[0117] Low-risk scenario: Trigger non-sensing verification, only continuously monitor the change of behavior entropy value, based on the trust score ≥ 0.85;
[0118] Medium-risk scenario: Start multi-modal cross-verification, requiring the user to complete a specific AR gesture within 3 seconds, based on 0.6 ≤ trust score < 0.85;
[0119] High-risk scenario: Activate enhanced verification, and it is necessary to synchronously submit the voiceprint pulse response and the device fingerprint DNA code, based on the trust score < 0.6.
[0120] In this embodiment, it should be further noted that the intelligent resource allocation of the dynamic scheduling execution module refers to:
[0121] When the processing delay of the verification terminal exceeds 15% of the historical average duration: Automatically switch to the edge computing node for behavior feature extraction, and enable the adaptive compression algorithm for the transmitted data;
[0122] When the characteristics of a distributed denial of service attack (DDoS) are detected: Route the verification request to the standby verification terminal cluster with the same behavior label, and dynamically increase the anti-perturbation intensity of the image verification code.
[0123] In this embodiment, it should be further noted that the decision log generated by the audit module includes: recording the specific cause classification of verification failures, such as "the standard deviation of the mouse trajectory acceleration exceeds the baseline by 32%", visualizing the deviation of behavioral characteristics from the heat map, and supporting the regulatory agency to conduct retrospective audits.
[0124] Please refer to Figure 3 , it should be further noted that the multimodal behavior acquisition module and the federated behavior modeling module are deeply coordinated through hierarchical data stream processing and the federated learning closed-loop. Its cooperation and collaboration process is divided into the following three stages:
[0125] S11 Real-time behavior data collaborative acquisition and preprocessing, including:
[0126] Edge-side data reduction. The multimodal behavior acquisition module completes the cleaning of the original data locally: for time-series data such as mouse trajectories, sliding window normalization is used, key features are extracted and a 256-dimensional feature vector is generated, and Gaussian noise is added through differential privacy (ε = 0.5) to ensure that the data cannot be traced;
[0127] Federated feature alignment: The multimodal behavior acquisition module compares the processed feature vector with the feature space mapping table shared by the federated behavior modeling module, automatically matches the feature fields of each participant, such as mapping the "average touch pressure" to a unified dimension, and triggers an online negotiation protocol for unaligned features to dynamically update the field encoding dictionary of each node;
[0128] S12 Distributed model training and attack detection, including: incremental federated learning, which performs model aggregation every 30 minutes: each terminal encrypts the gradient matrix of the local behavior model as and uploads it. The federated modeling module decrypts and aggregates the gradients through secure multi-party computation to update the global model , and distributes the new model parameters to the multimodal behavior acquisition module for the next round of edge inference;
[0129] Collaborative attack recognition, including: when the multimodal behavior acquisition module detects abnormal behavior (such as a sudden change in the angular velocity of mouse movement ), it immediately sends a compressed event snapshot to the federated module. The federated module compares the network-wide attack pattern library and returns a risk label within 200 ms. When a new attack pattern is found, it triggers federated adversarial training, and each node synchronously generates adversarial samples to enhance the robustness of the model;
[0130] S13 Dynamic baseline adjustment and verification optimization, including: personalized behavior baseline maintenance. The federated modeling module maintains dual-time-scale baselines for each user: a short-term baseline and a long-term baseline. The multimodal behavior acquisition module calculates the dynamic time warping (DTW) distance between the user's current behavior and the baseline every hour. When the threshold is exceeded, a secondary verification is triggered;
[0131] Cross-platform credit transfer. When a user passes strict verification on Platform A, the federated module generates a verifiable credential (VC). When the user accesses Platform B, the multi-modal behavior collection module automatically submits the VC. After verification by the federated module, part of the credit score is synchronized to achieve one-time verification and multi-terminal access.
[0132] Please refer to Figure 4 , when the user initiates a rights and interests redemption request, the system realizes end-to-end intelligent verification and risk control through the cooperation of each module. The specific operation process is as follows:
[0133] S21 Request triggering and behavior collection: Request interception. When the user clicks "Redeem", the front-end SDK automatically triggers the verification process, generates a session ID and encrypts it for transmission to the gateway. The multi-modal behavior collection module synchronously collects multi-modal data: Input behavior: Record the mouse trajectory and keyboard input interval of this operation, Device fingerprint: Obtain the gyroscope noise pattern and screen touch pressure distribution, Environmental characteristics: Capture the current network latency jitter and GPS positioning hash value. Use a lightweight edge computing unit to desensitize and extract features from the multi-modal data to generate a standardized behavior vector
[0134] S22 Real-time trust score calculation: Federated behavior comparison. The system performs multi-dimensional matching of the preprocessed feature vector with the federated behavior baseline library, including short-term behavior comparison: Calculate the DTW distance between the current session and the baseline in the last 7 days, and long-term habit verification: Check the cosine similarity between the device fingerprint and the historical record, and generate a dynamic trust score. Use a synthetic formula to calculate the real-time trust score. If the score falls into the medium-risk scenario, start multi-modal cross-verification;
[0135] S23 Hierarchical verification execution: The scenario risk assessment module implements hierarchical verification according to its hierarchical verification strategy. Low-risk scenario: Trigger non-intrusive verification, only continuously monitor the change of behavior entropy value. Medium-risk scenario: Start multi-modal cross-verification, requiring the user to complete a specific AR gesture within 3 seconds. High-risk scenario: Activate enhanced verification, and synchronously submit the voiceprint pulse response and device fingerprint DNA encoding; The multi-modal cross-verification refers to: The front-end pops up an AR verification interface, requiring the user to complete a 3D gesture signature within 3 seconds, and synchronously verify the consistency of the gesture biomechanical characteristics and device sensors;
[0136] S24 Resource scheduling and risk handling, Load balancing: When it is detected that the CPU utilization rate of the target server > 70%, the dynamic scheduling execution module automatically routes the verification request to the edge node and enables a lightweight model; Attack response: If the L2 regularization distance of the mouse trajectory > 3.0 and the Jaccard similarity between the device fingerprint and the known wool party cluster > 0.6 are identified, the system immediately freezes the current redemption request and sends an attack feature snapshot to the risk control center to update the federated adversarial sample library;
[0137] S25 Exchange completed and baseline updated. The successful path is as follows: When the final trust score is reached, a verifiable credential (VC) is issued to the blockchain, the fund freeze is lifted, and the exchange is completed. At this time, the user obtains a seamless verification mark, and similar operations within the next 30 minutes are exempt from verification; Whether successful or not, the system will use federated learning to update the user behavior baseline and optimize the scenario coefficient , and perform baseline iteration;
[0138] For users with low trust scores but are legitimate, the manual review channel is triggered, and at the same time, behavior replay data is collected for model optimization.
[0139] So far, the technical solution of the present invention has been described in combination with the preferred embodiments shown in the accompanying drawings. However, it should be noted that those skilled in the art can easily understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will all fall within the protection scope of the present invention.
[0140] Finally, it should be noted that: the content of each of the above embodiments is only used to illustrate the technical solution of the present invention, and is not intended to limit it.
Claims
1. A rights exchange verification and confirmation system, characterized in that: It includes a multi-modal behavior acquisition module for real-time acquisition of multi-dimensional data of user interaction behaviors; A federated behavior modeling module, connected to the multi-modal behavior acquisition module, constructs a cross-platform behavior baseline library through a federated learning framework, and outputs a dynamically updated user behavior trust score; A scenario risk assessment module, connected to the federated behavior modeling module, implements a hierarchical verification strategy; A dynamic scheduling execution module, connected to the verification terminal and the scenario risk assessment module respectively, realizes intelligent resource allocation, and the verification terminal is a hardware or software unit with specific verification capabilities; An audit module, connected to all modules, generates decision logs compliant with GDPR standards.
2. The rights and interests exchange verification and confirmation system according to claim 1, wherein: The multi-dimensional data collected by the multi-modal behavior acquisition module includes: Input behavior characteristics: keystroke dynamics characteristics, mouse trajectory acceleration curve, touch screen pressure distribution, Device behavior characteristics: gyroscope jitter pattern, screen rotation angle change, GPS movement trajectory entropy value, Environmental characteristics: network delay fluctuation characteristics, IP address behavior historical portrait, device sensor noise fingerprint; A lightweight edge computing unit is used to desensitize and extract features from multi-dimensional data to generate a standardized behavior vector.
3. The rights exchange verification and confirmation system according to claim 1, characterized in that: The behavior baseline library of the federated behavior modeling module adopts a hierarchical storage architecture and a dynamic update mechanism, including: a short-term behavior baseline, whose data range is the interaction behavior characteristics of the user in the most recent 7 - 30 days, and the update frequency is incremental update every 4 hours, and the exponential weighted moving average algorithm is used to smooth noise; Its typical characteristics include the 90th percentile of the mouse movement angular velocity, the KL divergence value of the touch screen pressure distribution, and the spectral entropy of the device gyroscope jitter; A long-term behavior baseline, whose data range is the behavior patterns of the user in the past 3 - 12 months, and the update mechanism is to perform principal component analysis dimensionality reduction once a month, retain the features with 95% variance, and use Gaussian mixture model clustering to identify the user's habitual operation patterns; A group behavior reference library, whose data source is the anonymous statistical characteristics of each platform aggregated by federated learning, and the purpose is to provide relative evaluation of abnormal behaviors and support the behavior analysis of cold-start users.
4. The rights and interests redemption verification and confirmation system according to claim 3, characterized in that: The implementation mechanism of the user behavior trust score of the federated behavior modeling module is a multi-dimensional dynamic calculation system, and its technical process is divided into the following five levels: Feature quantization layer, performs multi-modal behavior vectorization, including: spatio-temporal feature extraction, calculates the deviation degree from the baseline for time series data using dynamic time warping, and extracts frequency domain features from sensor data through wavelet transform; interaction feature encoding, converts the touch screen pressure distribution into a 128-dimensional SIFT-like descriptor, and uses a hidden Markov model to generate a state transition probability matrix for the keyboard input mode; environmental feature normalization, converts network delay fluctuations into the diffusion coefficient of a Brownian motion model, and encodes the GPS trajectory into a hierarchical spatial feature using H3 geographical grid; Federated computing layer, realizes cross-platform credit fusion, including: local credit calculation, each edge node calculates a preliminary trust score using the local baseline library: ; Among them, is the current behavioral eigenvalue, is the baseline value of the corresponding feature, is the feature distance function, usually using: continuous feature: standardized Euclidean distance ( is the historical standard deviation) and categorical feature: Jaccard distance, is the feature weight, obtained through random forest feature importance analysis; Global credit aggregation, integrates the scores of each platform through federated weighted average calculation: ; Among them, is the number of platforms participating in the federated computation, is the historical interaction data volume of the platform (for weighting), is the locally computed trust score of the platform; The dynamic adjustment layer is a real-time calibration system for behavioral trust scores. Through multi-dimensional environmental perception and adaptive weight allocation, it ensures that the scoring results are both accurate and consistent with the current risk situation. Its mechanisms include: Risk scenario perception and weight adjustment. For risk scenario perception, the system monitors the following key scenario indicators in real time: Abnormal operation frequency: When the number of requests per unit time exceeds twice the personal baseline value, the high-frequency operation coefficient is triggered, and its weight coefficient is ×0.
8. Device fingerprint change: When a new device logs in and the fingerprint matching degree is less than 60%, the device risk coefficient is activated, and its weight coefficient is ×0.
6. Geographic displacement contradiction: When the distance between the login IP and the usual place is greater than 1000km and the moving speed is unnatural, the cross-border coefficient is applied, and its weight coefficient is ×0.
7. For weight adjustment, through dynamic weight calculation: the final scene weight Generated by a Bayesian network: ; Among them, the prior probability Trained based on historical attack data, the evidence includes 10-dimensional features such as real-time network latency and operation time window; Time decay model, the decay function adopts a mixed model of hyperbolic decay and exponential decay: Short-term linear decay region (0 <t≤1小时):无衰减,权重保留100%; Medium-term exponential decay region (1 hour < t ≤ 24 hours): exponential decay , where is the initial score, from the federal global trust ; Long-term hyperbolic decay region (t > 24 hours): hyperbolic decay ; Behavior continuity protection, enabling behavior chain locking for key operations, pausing time decay during continuous operations to prevent misjudgment; The adversarial defense layer intercepts abnormal scores. Its adversarial sample detection uses the isolation forest algorithm to detect abnormal points in the feature space and injects chaotic noise to observe the response of operations suspected to be generated by GAN. The credit freezing mechanism immediately freezes the score when a sudden change in the behavior entropy value and a contradiction in the multimodal features are detected. Visualization decision layer: The visualization decision layer transforms the scoring process into an explainable and auditable interactive output, including: scoring deconstruction and attribution analysis through three-dimensional scoring maps and feature contribution heat maps, as well as dynamic threshold management and real-time audit tracking; The calculation formula for the final synthetic behavior trust score is: ; Among them, is the local trust score of the th platform, which is calculated by the federal computing layer. is the data weight of the th platform, based on the historical data quality and data volume of this platform. is the time decay benchmark, which is the difference between the current time and the time when the behavior occurred. is the correction coefficient of the th risk scenario, used to dynamically adjust the score. When the risk scenario is a new device login, , for cross-border operations , for non-working hours: , is the number of risk scenarios, is the anti-attack flag, taking 1 when an attack is detected, otherwise taking 0. is the attack penalty amount, directly deducting a fixed score after the attack is confirmed. If , the score is reduced by at least 30% when an attack is detected.
5. The rights and interests redemption verification and confirmation system according to claim 4, wherein: The multimodal behavior collection module and the federated behavior modeling module achieve deep cooperation through layered data stream processing and federated learning closed loop. The cooperation process is divided into the following three stages: S11 real-time behavior data collaborative collection and preprocessing, including: edge-side data reduction, multimodal behavior collection module completes raw data cleaning locally on the terminal device: sliding window normalization is used for time series data such as mouse trajectory, key features are extracted and 256-dimensional feature vectors are generated, and Gaussian noise is added through differential privacy (ε=0.5) to ensure that the data cannot be traced; Federated feature alignment: The multimodal behavior acquisition module compares the processed feature vector with the feature space mapping table shared by the federated behavior modeling module, automatically matches the feature fields of each participant, triggers the online negotiation protocol for misaligned features, and dynamically updates the field encoding dictionary of each node; S12 Distributed model training and attack detection, including: incremental federated learning, with model aggregation performed every 30 minutes: each terminal encrypts the gradient matrix of the local behavior model and uploads it encrypted. The federated modeling module decrypts and aggregates the gradients through secure multi-party computation to update the global model and distributes the new model parameters to the multi-modal behavior acquisition module for the next round of edge inference; Collaborative attack identification, including: when the multimodal behavior acquisition module detects abnormal behavior, it immediately sends a compressed event snapshot to the federation module, the federation module compares the attack pattern library of the entire network, returns the risk label within 200ms, and triggers federation adversarial training when a new attack pattern is found, and each node synchronously generates adversarial samples to enhance the robustness of the model; S13 Dynamic baseline adjustment and verification optimization, including: personalized behavior baseline maintenance. The federated modeling module maintains dual-time-scale baselines for each user: short-term baseline and long-term baseline. The multimodal behavior acquisition module calculates the dynamic time warping (DTW) distance between the user's current behavior and the baseline every hour. When the threshold is exceeded, secondary verification is triggered; Cross-platform credit transfer. When a user passes strict verification on Platform A, the federated module generates a verifiable credential (VC). When the user accesses Platform B, the multimodal behavior acquisition module automatically submits the VC. After verification by the federated module, part of the credit score is synchronized to achieve one-time verification and multi-terminal access.
6. The rights exchange verification and confirmation system according to claim 1, characterized in that: The hierarchical verification strategy of the scenario risk assessment module is divided into: Low-risk scenario: Trigger seamless verification, only continuously monitor the change of behavior entropy value, based on the trust score ≥ 0.85; Medium-risk scenario: Initiate multimodal cross-verification, requiring the user to complete a specific AR gesture within 3 seconds, based on 0.6 ≤ trust score < 0.85; High-risk scenario: Activate enhanced verification, and it is necessary to synchronously submit the voiceprint pulse response and the device fingerprint DNA code, based on the trust score < 0.
6.
7. The rights and interests exchange verification and confirmation system according to claim 1, characterized in that: The intelligent resource allocation of the dynamic scheduling execution module refers to: When the processing delay of the verification terminal exceeds 15% of the historical average duration: Automatically switch to the edge computing node for behavior feature extraction, and enable the adaptive compression algorithm for the transmitted data; When the characteristics of distributed denial of service attack (DDoS) are detected: Route the verification request to the standby terminal cluster with the same behavior label, and dynamically increase the anti-disturbance intensity of the image verification code.
8. The rights and interests redemption verification and confirmation system according to claim 1, characterized in that: The decision log generated by the audit module includes: recording the specific reason classification of verification failure, and visualizing the heat map of behavior feature deviation, which supports the regulatory agency to conduct retrospective audit.
9. The rights and interests redemption verification and confirmation system according to any one of claims 1-8, characterized in that: When the user initiates an equity redemption request, the system realizes end-to-end intelligent verification and risk control through the cooperation of each module. The specific operation process is as follows: S21 Request triggering and behavior acquisition: Request interception. When the user clicks "Redeem", the front-end SDK automatically triggers the verification process, generates a session ID and encrypts it for transmission to the gateway. The multimodal behavior acquisition module synchronously acquires multimodal data: Input behavior: Record the mouse trajectory and keyboard input interval of this operation. Device fingerprint: Obtain the gyroscope noise pattern and screen touch pressure distribution. Environmental characteristics: Capture the current network latency jitter and GPS positioning hash value. Use a lightweight edge computing unit to desensitize and extract features from the multimodal data to generate a standardized behavior vector; S22 Real-time trust score calculation: Federated behavior comparison. The system performs multi-dimensional matching of the preprocessed feature vector with the federated behavior baseline library, including short-term behavior comparison: Calculate the DTW distance between the current session and the baseline in the last 7 days, and long-term habit verification: Check the cosine similarity between the device fingerprint and the historical record, and generate a dynamic trust score. Use the synthesis formula to calculate the real-time trust score. If the score falls into the medium-risk scenario, initiate multimodal cross-verification; S23 Hierarchical Verification Execution: The scenario risk assessment module implements hierarchical verification according to its hierarchical verification strategy. Low-risk scenario: Trigger seamless verification and only continuously monitor the change of behavioral entropy value. Medium-risk scenario: Initiate multimodal cross-verification, requiring the user to complete a specific AR gesture within 3 seconds. High-risk scenario: Activate enhanced verification, and it is necessary to synchronously submit the voiceprint pulse response and the device fingerprint DNA code. The multimodal cross-verification refers to: A front-end AR verification interface pops up, requiring the user to complete a 3D gesture signature within 3 seconds, and simultaneously verifying the consistency of the gesture biomechanical characteristics and the device sensors. Anti-counterfeiting detection is an injection of adversarial noise test, randomly adding a 1ms delay during the verification process to detect whether the operation is a program simulation. S24 Resource Scheduling and Risk Disposal, Load Balancing: When it is detected that the CPU utilization rate of the target server > 70%, the dynamic scheduling execution module automatically routes the verification request to the edge node and enables the lightweight model. Attack Response: If the L2 regularization distance of the mouse trajectory is recognized to be > 3.0 and the Jaccard similarity between the device fingerprint and the known fraudster cluster is > 0.6, the system immediately freezes the current redemption request and sends a snapshot of the attack characteristics to the risk control center to update the federated adversarial sample library. S25 Exchange completed and baseline updated. The successful path is as follows: When the final trust score is reached, a verifiable credential (VC) is issued to the blockchain, the fund freeze is lifted, and the exchange is completed. At this time, the user obtains an invisible verification mark, and subsequent operations of the same type within the next 30 minutes are exempt from verification; Whether successful or failed, the system will use federated learning to update the user behavior baseline and optimize the scenario coefficient , and perform baseline iteration; For legitimate users with a low trust score, trigger the manual review channel and simultaneously collect behavior replay data for model optimization.
Citation Information
Cited By
Tough city resource allocation method and system based on block chain and edge computing
CN120579803A
Resilient city resource allocation method and system based on blockchain and edge computing
CN120579803B
Intelligent bidding method and system based on behavior pattern recognition
CN120725770A
Equipment security verification method and system based on multi-level power distribution communication network
CN120811766A
Method and system for device security verification based on multi-level power distribution communication network
CN120811766B