Advertisement putting anti-cheating system based on AI intelligent diagnosis and dynamic creative optimization

Through an advertising delivery anti-cheating system based on AI intelligent diagnosis and dynamic creative optimization, the problem of traditional systems lacking closed-loop optimization is solved, and the precise positioning and comprehensive cleaning of traffic cheating is achieved, which improves the accuracy and coverage of the system.

CN120430831AActive Publication Date: 2025-08-05SHANGHAI WANGMAI INFORMATION TECH GRP CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510941671.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-09
Publication Date
2025-08-05
Estimated Expiration
2045-07-09

AI Technical Summary

Technical Problem

The existing anti-cheating system for advertising delivery lacks closed-loop optimization capabilities, resulting in low accuracy and coverage, and is unable to adapt to the rapidly changing cheating environment.

Method used

Advertising anti-cheating system based on AI intelligent diagnosis and dynamic creative optimization is adopted, and precise positioning and comprehensive cleaning of traffic cheating behaviors is achieved through modules such as data acquisition, traffic anti-cheating model, advertising derivatives, strategy generation, traffic processing, data clustering and anti-cheating cleaning.

Benefits of technology

The accuracy and coverage of the anti-cheating system are improved, and it can quickly respond to traffic cheating behavior, reduce losses, and realize the system's self-iteration optimization through the feedback optimization module.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120430831A_ABST
    Figure CN120430831A_ABST
Patent Text Reader

Abstract

The invention provides an advertisement putting anti-cheating system based on AI intelligent diagnosis and dynamic creative optimization, and the system comprises a data obtaining module which is used for obtaining original advertisement data and recent traffic cheating type data, carrying out the data preprocessing, and generating an original advertisement template and a traffic cheating mode; the traffic anti-cheating model is used for generating a traffic anti-cheating strategy, and the traffic anti-cheating model comprises an advertisement derivation module and a strategy generation module; the advertisement derivation module is used for generating multiple groups of derived advertisements according to the original advertisement template; the strategy generation module is used for generating a corresponding traffic anti-cheating strategy for the traffic cheating mode; the traffic processing module is used for acquiring real-time traffic of multiple groups of derivative advertisements and acquiring a traffic entropy value of the real-time traffic; the data clustering module is used for carrying out two times of clustering operation; the anti-cheating cleaning module is used for performing anti-cheating cleaning operation; and the feedback optimization module is used for acquiring the cleaning feedback report, optimizing the traffic anti-cheating model, and improving the accuracy and coverage rate of the anti-cheating system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of advertising delivery technology, and in particular to an advertising delivery anti-cheating system based on AI intelligent diagnosis and dynamic creative optimization. Background Art

[0002] The digital advertising industry is rapidly developing and facing increasingly complex fraud threats. Traditional anti-fraud systems rely primarily on rule matching and statistical analysis based on historical data to identify anomalous traffic. While this approach can remove some fraudulent activity, the lack of an effective feedback mechanism makes it difficult to quickly evaluate the effectiveness of the removal process and continuously optimize the rules. As fraudulent methods continue to evolve, static defense strategies can no longer meet the industry's requirements for real-time and accuracy. Advertisers urgently need a self-sustaining anti-fraud solution.

[0003] Existing anti-cheating technologies often lack closed-loop optimization capabilities. While rule-based cleaning methods can address known cheating patterns, the systems often cannot accurately count specific cases where cleaning fails, nor can they analyze the underlying causes. For example, certain cleaning rules fail to address new cheating techniques, but the lack of an effective effectiveness evaluation mechanism makes these issues difficult to detect and correct in a timely manner. This limitation makes it difficult to continuously improve the accuracy and coverage of anti-cheating systems, making them unable to adapt to the rapidly changing cheating environment. Summary of the Invention

[0004] To address the aforementioned technical issues, the present invention provides an anti-fraud system for advertising based on AI intelligent diagnosis and dynamic creative optimization. This system addresses the existing technical issues in which traditional anti-fraud systems for advertising often lack closed-loop optimization capabilities, resulting in low accuracy and coverage.

[0005] The purpose and effectiveness of the advertising anti-cheating system based on AI intelligent diagnosis and dynamic creative optimization of the present invention are achieved by the following specific technical means: Advertisement anti-fraud system based on AI intelligent diagnosis and dynamic creative optimization, including: A data acquisition module, which is used to obtain the user's original advertisement data and recent traffic fraud type data, and pre-process the original advertisement data and recent traffic fraud type data to generate an original advertisement template and traffic fraud pattern; A traffic anti-fraud model, which is used to generate a traffic anti-fraud strategy based on the original ad template and the traffic fraud pattern, and includes an ad derivation module and a strategy generation module; An advertisement derivation module, configured to generate multiple groups of derivative advertisements based on an original advertisement template; A strategy generation module, which is used to generate a corresponding traffic anti-cheating strategy for the traffic cheating pattern; A traffic processing module, the traffic processing module is used to obtain real-time traffic of multiple groups of derivative advertisements and calculate traffic entropy values of the real-time traffic according to a traffic entropy function; A data clustering module, wherein the data clustering module is used to perform an initial clustering of the real-time traffic according to the traffic entropy value to obtain a first traffic entropy value clustering result, and perform a secondary clustering of the first traffic entropy value clustering result based on a traffic entropy value filtering strategy to obtain a second traffic entropy value clustering result; an anti-cheating cleaning module, the anti-cheating cleaning module being configured to match a corresponding traffic cheating pattern to the second traffic entropy value clustering result and perform anti-cheating cleaning on the second traffic entropy value clustering result according to a corresponding traffic anti-cheating strategy; A feedback optimization module is configured to obtain a cleaning feedback report generated after performing anti-cheating cleaning on the second traffic entropy value clustering result, and optimize the traffic anti-cheating model based on the cleaning feedback report.

[0006] Based on the above aspects, the embodiment of the present application realizes obtaining the original advertisement data to be delivered by the user and the recent traffic cheating type data based on the data acquisition module, and performing data preprocessing on the original advertisement data and the recent traffic cheating type data, generating the original advertisement template and the traffic cheating pattern, obtaining the pre-trained traffic anti-cheating model, inputting the original advertisement template and the traffic cheating pattern into the traffic anti-cheating model, generating multiple groups of derived advertisements based on the advertisement derivation module, and the derived advertisements including two types of advertisement modes, observation state and interference state. The strategy generation module generates corresponding traffic anti-cheating strategies for the traffic cheating patterns, expands the collection surface of traffic cheating features by generating multiple groups of derived advertisements based on the original advertisement data as a template, and quickly responds to traffic cheating behaviors by pre-defining traffic anti-cheating strategies, thereby reducing the losses caused by traffic cheating behaviors.

[0007] Based on the traffic processing module, the real-time traffic of multiple groups of the derived advertisements is obtained, and the traffic entropy value of the real-time traffic is obtained through the traffic entropy function. The data clustering module performs initial clustering on the real-time traffic according to the traffic entropy value to obtain a first traffic entropy value clustering result. The data clustering module performs secondary clustering on the first traffic entropy value clustering result according to the traffic entropy value filtering strategy to obtain a second traffic entropy value clustering result. The anti-cheating cleaning module matches the corresponding traffic cheating pattern for the second traffic entropy value clustering result, and performs anti-cheating cleaning based on the corresponding traffic anti-cheating strategy. The traffic cheating method is quantified by calculating the traffic entropy value, and two clustering operations are performed on the real-time traffic data based on the traffic entropy value to achieve accurate positioning of the traffic cheating pattern, so that the predefined traffic anti-cheating strategy achieves the maximum effect.

[0008] The feedback optimization module obtains a cleaning feedback report generated after performing anti-fraud cleaning on the second traffic entropy value clustering result, and optimizes the traffic anti-fraud model based on the cleaning feedback report. By quantifying the cleaning effect of the traffic anti-fraud strategy, the module locates the specific way in which the advertisement is attacked by traffic fraud. The module adjusts the traffic anti-fraud strategy based on the generated cleaning feedback report to achieve accurate and comprehensive cleaning of traffic fraud behaviors, thereby improving the accuracy and coverage of the anti-fraud system. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] Figure 1 This is a schematic diagram of the execution flow of control steps in the anti-cheating system for advertising based on AI intelligent diagnosis and dynamic creative optimization provided by an embodiment of the present invention; Figure 2 Schematic diagram of an anti-cheating system for advertising based on AI intelligent diagnosis and dynamic creative optimization provided by an embodiment of the present invention; Figure 3 This is a schematic diagram of a traffic anti-fraud model in an advertising anti-fraud system based on AI intelligent diagnosis and dynamic creative optimization provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0010] The following embodiments of the present invention are described in further detail with reference to the accompanying drawings and examples. The following examples are used to illustrate the technical solutions of the present invention, but are not intended to limit the scope of protection of the present invention.

[0011] Example: As attached Figure 1 、 Figure 2 、 Figure 3 As shown: The present invention provides an anti-fraud system for advertising delivery based on AI intelligent diagnosis and dynamic creative optimization, which is applicable to advertising delivery and includes: A data acquisition module, which is used to obtain the user's original advertisement data and recent traffic fraud type data, and pre-process the original advertisement data and recent traffic fraud type data to generate an original advertisement template and traffic fraud pattern; A traffic anti-fraud model, which is used to generate a traffic anti-fraud strategy based on the original ad template and the traffic fraud pattern, and includes an ad derivation module and a strategy generation module; An advertisement derivation module, configured to generate multiple groups of derivative advertisements based on an original advertisement template; A strategy generation module, which is used to generate a corresponding traffic anti-cheating strategy for the traffic cheating pattern; A traffic processing module, the traffic processing module is used to obtain real-time traffic of multiple groups of derivative advertisements and calculate traffic entropy values of the real-time traffic according to a traffic entropy function; A data clustering module, wherein the data clustering module is used to perform an initial clustering of the real-time traffic according to the traffic entropy value to obtain a first traffic entropy value clustering result, and perform a secondary clustering of the first traffic entropy value clustering result based on a traffic entropy value filtering strategy to obtain a second traffic entropy value clustering result; an anti-cheating cleaning module, the anti-cheating cleaning module being configured to match a corresponding traffic cheating pattern to the second traffic entropy value clustering result and perform anti-cheating cleaning on the second traffic entropy value clustering result according to a corresponding traffic anti-cheating strategy; A feedback optimization module is configured to obtain a cleaning feedback report generated after performing anti-cheating cleaning on the second traffic entropy value clustering result, and optimize the traffic anti-cheating model based on the cleaning feedback report.

[0012] The system includes the following control steps: S10: The data acquisition module obtains the original advertisement data to be delivered by the user and the recent traffic fraud type data, and performs data preprocessing on the original advertisement data and the recent traffic fraud type data to generate an original advertisement template and a traffic fraud pattern; S20: Obtain a pre-trained traffic anti-fraud model, input the original ad template and the traffic fraud pattern into the traffic anti-fraud model, and generate multiple sets of derived ads based on the ad derivation module. The derived ads include two ad patterns: observation state and interference state. The strategy generation module generates corresponding traffic anti-fraud strategies for the traffic fraud pattern. S30: Based on the traffic processing module, the real-time traffic of multiple groups of derivative advertisements is obtained, and the traffic entropy value of the real-time traffic is obtained through the traffic entropy function. The data clustering module performs initial clustering on the real-time traffic according to the traffic entropy value to obtain a first traffic entropy value clustering result; S40: The data clustering module performs secondary clustering on the first traffic entropy value clustering result according to the traffic entropy value filtering strategy to obtain a second traffic entropy value clustering result. The anti-cheating cleaning module matches the second traffic entropy value clustering result with a corresponding traffic cheating pattern and performs anti-cheating cleaning based on the corresponding traffic anti-cheating strategy. S50: The feedback optimization module obtains a cleaning feedback report generated after performing anti-cheating cleaning on the second traffic entropy value clustering result, and optimizes the traffic anti-cheating model based on the cleaning feedback report.

[0013] The specific usage and function of this embodiment are as follows: Step S10: obtaining the original advertisement data and recent traffic fraud type data of the user based on the data acquisition module, and performing data preprocessing on the original advertisement data and recent traffic fraud type data to generate an original advertisement template and a traffic fraud pattern.

[0014] In this embodiment, step S10 includes: Step S11: obtaining original advertisement data to be delivered by the user, and performing data preprocessing on the original advertisement data to generate an original advertisement template.

[0015] Specifically, feature extraction is performed on the original advertising data to obtain the promotional content data and key information data of the original advertising data. The promotional content data represents the core content promoted by the original advertising data, and the key information data represents the constituent elements corresponding to the original advertising data. An original advertising template is generated based on the promotional content and key information of the original advertising data.

[0016] For example, the original material for a sports brand's sneaker promotional advertisement includes product images, "Limited-time 50% off" promotional copy, and a buy now button. During the template generation process, the system first deconstructs the promotional content data and key information data contained in the material, uses the sneaker advertising diagram as the template basis, sets the core promotional copy "Limited-time {discount rate} discount", and reserves dynamic slots for subsequent adjustments. It then injects variant parameters, establishes a color scheme library and multiple sets of promotional scripts such as "Only {quantity} left" and "Thousands of people have snapped up", and finally generates the original advertising template. At the same time, a gyroscope detection interface is implanted in the button click area, a millisecond-level TCP clock synchronization node is embedded in the advertising response stream, and a gradient color gamut trap invisible to the human eye is added to the edge of the sneaker image, thereby implanting a triple defense anchor point in the original advertising template.

[0017] Step S12: Acquire recent traffic fraud type data, and perform data preprocessing on the recent traffic fraud type data to generate a traffic fraud pattern.

[0018] Specifically, feature extraction is performed on the recent traffic cheating type data to obtain a traffic cheating feature set, and feature fusion is performed on the traffic cheating feature set to generate a traffic cheating pattern. The traffic cheating pattern includes a device cluster type, a high concealment type, and an abnormal trial type.

[0019] It can be understood that the device cluster type is represented by multiple devices executing exactly the same sequence of operations and the corresponding hardware parameters are highly unified, such as a large number of devices frantically clicking on an advertisement at the same time, or performing exactly the same browsing or clicking operations on a fixed page; the high-anonymity type is represented by the advertisement click location showing a hash distribution and carrying new vulnerability attack characteristics, such as using a different device fingerprint for each request, injecting random offsets into the operation trajectory, and slowly penetrating by simulating the behavior patterns of real users to avoid triggering frequency control rules; the abnormal trial type is represented by continuously triggering unconventional operation chains in the edge area of the advertising interface, such as intensively triggering non-functional area operations, and high-frequency execution of anti-logical behavior sequences such as entering the privacy agreement interface from the homepage and then immediately returning.

[0020] In step S20, a pre-trained traffic anti-cheating model is obtained, and the original advertisement template and traffic cheating pattern are input into the traffic anti-cheating model. Based on the advertisement derivation module, multiple groups of derivative advertisements are generated. The derivative advertisements include two advertisement modes: observation state and interference state. The strategy generation module generates corresponding traffic anti-cheating strategies for the traffic cheating pattern.

[0021] Specifically, based on the advertisement derivation module, feature analysis is performed on the original advertisement template, and feature reorganization is performed on the advertisement features contained in the original advertisement template to generate multiple groups of derivative advertisements.

[0022] Furthermore, based on the strategy generation module, triple defense keys are implanted into multiple groups of the derivative advertisements, and the weights of the triple defense keys are dynamically adjusted according to the traffic cheating pattern, and the multiple groups of the derivative advertisements implanted with the triple defense keys are dual-state packaged.

[0023] It can be understood that the triple defense key includes a device behavior key, a network environment key, and a visual cognition key. The device behavior key is represented by generating a fluctuating physical fingerprint and embedding the fluctuating physical fingerprint into an advertising interaction event, such as injecting a device gyroscope noise feature into an ad click event. If the standard deviation of the gyroscope noise of 10 devices is detected to be lower than 0.01, a cluster attack alarm is triggered; the network environment key is represented by generating an environment trusted signature and embedding the environment trusted signature into the protocol layer, such as an environment trusted signature containing a correlation between the base station switching delay and the proxy IP blacklist. When 100 connections are detected to show that the base station delay is lower than 5ms and the proxy IP correlation is higher than 92%, it is determined to be a virtualized attack network; the visual cognition key is represented by generating dynamic perception visual elements and performing machine recognition based on the dynamic perception visual elements, such as rendering a dynamic texture QR code in an ad space. The real user scanning success rate reaches 98.3%, while the success rate of the automated tool is lower than 12% due to the loss of rendering frames.

[0024] It can be understood that the strategy generation module sets the baseline weight of the triple defense key according to the characteristics corresponding to each traffic cheating pattern, among which the device key W1 is used for device layer verification, the network environment key W2 is used to analyze the rationality of the operation sequence, and the visual cognition key W3 is used to predict the attack intention. The total weight of the three is always 100%. Based on the baseline weight of the triple defense key, the corresponding traffic anti-cheating strategy is generated for the traffic cheating pattern, and the triple defense key baseline weight is secondary optimized according to the cleaning feedback report of the traffic anti-cheating strategy.

[0025] It can be understood that the dual-state encapsulation is represented by generating two advertising modes, observation state and interference state, for multiple groups of the derived advertisements, and switching the advertising mode according to the real-time traffic state corresponding to the derived advertisements. The observation state is represented by providing a derivative advertisement containing only a lightweight verification key check to the user when the real-time traffic state is judged to be normal, such as embedding a one-dimensional fluctuation physical fingerprint in the "Order Now" button to only collect the fluctuation entropy value of the device's gyroscope Z axis. If the entropy value is in the range of 0.32-0.38Hz, it is released, otherwise it is marked as abnormal; the interference state is represented by judging the real-time traffic state as abnormal. Frequently suspicious traffic provides derivative advertisements that force multiple key verifications, such as a dynamic slider challenge generated by the device behavior key, requiring the user to tilt the phone to the left to 28°±3° while pressing the slider. The network environment key synchronously scans the base station switching delay and the Wi-Fi signal fluctuation spectrum. The visual recognition key superimposes a non-periodic flashing QR code on the interface, and requires real-time scanning through the mobile phone camera. The triple defense key is verified by millisecond-level timing coupling, such as the delay between the gyroscope tilt angle change and the successful QR code scanning, which must be within the physiological response range of 230ms±40ms.

[0026] Step S30, based on the traffic processing module, the real-time traffic of multiple groups of the derivative advertisements is obtained, and the traffic entropy value of the real-time traffic is obtained through the traffic entropy function. The data clustering module performs initial clustering on the real-time traffic according to the traffic entropy value to obtain the first traffic entropy value clustering result.

[0027] In this embodiment, step S30 includes: Step S31: obtaining the real-time traffic of multiple groups of derivative advertisements based on the traffic processing module, and obtaining the traffic entropy value of the real-time traffic through a traffic entropy function.

[0028] Specifically, three-dimensional feature extraction of time features, spatial features and behavioral features is performed on the real-time traffic of multiple groups of derivative advertisements to obtain three-dimensional feature results, such as obtaining time features by analyzing the standard deviation of user click intervals, obtaining spatial features by calculating the standard deviation of user advertisement click coordinates and the rate of change of geographic displacement speed, and obtaining behavioral features by analyzing the complexity of page paths.

[0029] Furthermore, the time entropy value, spatial entropy value and behavioral entropy value of the real-time traffic are obtained based on the three-dimensional feature results, and the flow entropy value of the real-time traffic is obtained according to the flow entropy function. The flow entropy function can be expressed as: ; in, Expressed as the traffic entropy value of real-time traffic, Expressed as the time entropy weight of real-time traffic, Expressed as the time entropy value of real-time traffic, Expressed as the spatial entropy weight of real-time traffic, Expressed as the spatial entropy value of real-time traffic, Expressed as the behavioral entropy weight of real-time traffic, Expressed as the behavioral entropy value of real-time traffic.

[0030] For example, the real-time traffic data of a derivative advertisement includes data that generates 142 clicks within 3 seconds. By calculating the standard deviation of the time interval, the time entropy value corresponding to this segment of data is 0.17. The standard deviation of the user advertisement click coordinates and the rate of change of the geographic displacement speed of this segment of data are calculated to obtain the corresponding spatial entropy value of 0.05. By analyzing the page path complexity of this segment of data, the corresponding behavioral entropy value is 0.08. Substituting the three-dimensional entropy value into the traffic entropy function, the corresponding traffic entropy value is 0.15.

[0031] In step S32, the data clustering module performs initial clustering on the real-time traffic according to the traffic entropy value to obtain a first traffic entropy value clustering result.

[0032] Specifically, based on the preset traffic entropy threshold, the traffic threshold of the real-time traffic is compared with the preset traffic entropy threshold to obtain the traffic entropy comparison result, and the real-time traffic data below the preset traffic entropy threshold is verified by accidental injury. The real-time traffic data that passes the accidental injury verification is defined as accidental injury data, and the data is divided into high entropy traffic. At the same time, the real-time traffic data that fails the accidental injury verification is divided into low entropy traffic.

[0033] It can be understood that the false alarm verification is expressed as a deep entropy verification of real-time traffic data that is lower than the preset traffic entropy threshold, that is, obtaining the time entropy value, space entropy value and behavior entropy value corresponding to the real-time traffic data, and comparing them with the preset time entropy threshold, space entropy threshold and behavior entropy threshold. Only when the time entropy value, space entropy value and behavior entropy value are lower than the corresponding preset threshold at the same time, and there is real-time traffic data associated with the device fingerprint blacklist, the data is directly judged as low entropy traffic; triple defense key verification is performed on data that does not meet the direct judgment conditions for low entropy traffic, such as starting lightweight key verification for real-time traffic data with abnormal single-dimensional entropy value.

[0034] It can be understood that the high entropy traffic is represented by the traffic entropy value corresponding to the real-time traffic being greater than the preset threshold, and the high entropy traffic is directly delivered as a derivative advertisement of the observation-state advertising model; the low entropy traffic is represented by the traffic entropy value corresponding to the real-time traffic being less than the preset threshold, and the low entropy traffic is subjected to secondary clustering.

[0035] In step S40, the data clustering module performs secondary clustering on the first traffic entropy value clustering result according to the traffic entropy value filtering strategy to obtain a second traffic entropy value clustering result. The anti-cheating cleaning module matches the second traffic entropy value clustering result with a corresponding traffic cheating pattern and performs anti-cheating cleaning based on the corresponding traffic anti-cheating strategy.

[0036] In this embodiment, step S40 includes: In step S41, the data clustering module performs secondary clustering on the first traffic entropy value clustering result according to the traffic entropy value filtering strategy to obtain a second traffic entropy value clustering result.

[0037] Specifically, deep behavioral feature extraction is performed on low entropy traffic in the first traffic entropy value clustering result to obtain an enhanced feature set, which at least includes behavior density, device aggregation, spatial dispersion and threat level.

[0038] It can be understood that the behavior density is expressed as the frequency intensity of repeated operations in the user operation sequence per unit time. For example, real users click the "Buy Now" button an average of 1.2 times per second, and the corresponding behavior density is 0.35, while the cheating cluster triggers clicks at a constant rate of 5 times per second, and the corresponding behavior density is 5.0; the device aggregation is expressed as the cluster density intensity of the device fingerprint parameters corresponding to the low entropy traffic. For example, if a large number of devices are detected to carry the same GPU rendering parameters and battery temperature values, the corresponding device aggregation is 0.92, which is much higher than the range corresponding to normal traffic. At this time, it is determined to be under attack from a group control room; the spatial discreteness is expressed as the distribution discrete system of user interaction behavior in the advertising interface coordinate system. For example, the real user click heat map is evenly distributed in the button area of 120×40 pixels, and the corresponding spatial discreteness is greater than 0.85. However, 92% of the click coordinates of the fraudulent traffic are concentrated in the area of [88, 22] ±3 pixels, and the corresponding spatial discreteness is 0.03. The threat level is expressed as the matching similarity between the real-time behavior characteristics of the low-entropy traffic and the preset historical attack pattern library. For example, when the current real-time traffic data is captured with the characteristics of "continuous click interval 100ms±5ms" and "zero page scrolling", the characteristics are matched with the preset historical traffic fraud library. If three historical attack patterns with a similarity greater than 90% are matched, it is determined to be a high-threat isometric and a high-risk alarm is triggered.

[0039] Furthermore, based on the enhanced feature set, the low entropy traffic in the first traffic entropy clustering result is secondary clustered, and the low entropy traffic is divided into device cluster traffic, high hidden traffic and abnormal trial traffic.

[0040] It can be understood that the device cluster traffic is represented by low entropy traffic with high behavior density and high device aggregation, the high hidden traffic is represented by low entropy traffic with high spatial discreteness and high threat level, and the abnormal tentative traffic is represented by low entropy traffic with high spatial discreteness and low device aggregation.

[0041] In step S42, the anti-cheating cleaning module matches the second traffic entropy value clustering result with a corresponding traffic cheating pattern, and performs anti-cheating cleaning based on the corresponding traffic anti-cheating strategy.

[0042] Specifically, the device cluster type traffic in the second traffic entropy value clustering result is matched with the device cluster type traffic cheating pattern, the high concealment type traffic is matched with the high concealment type traffic cheating pattern, and the abnormal tentative type traffic is matched with the abnormal tentative type traffic cheating pattern. The second traffic entropy value clustering result is anti-cheating cleaned according to the traffic anti-cheating strategy corresponding to the matched traffic cheating pattern, such as intercepting the GPU rendering parameters and battery temperature sequence of the device cluster type traffic device, freezing the traffic input of all devices matching the parameters, and injecting a dynamic offset layer in the advertising interface coordinate system with a random offset of ±15 pixels every 0.5 seconds for the button coordinates.

[0043] Furthermore, the cleaning strategy effectiveness, key performance effect, threat evolution log and other indicators generated when executing the traffic anti-cheating strategy are recorded, and optimization suggestions for the traffic anti-cheating strategy are generated based on the cleaning strategy effectiveness, key performance effect and threat evolution log and other indicators, and the corresponding indicators and optimization suggestions are encapsulated into a cleaning feedback report.

[0044] In step S50, the feedback optimization module obtains a cleaning feedback report generated after performing anti-cheating cleaning on the second traffic entropy value clustering result, and optimizes the traffic anti-cheating model based on the cleaning feedback report.

[0045] It is understandable that the cleaning feedback report at least includes cleaning strategy effectiveness, key performance effect, threat evolution log and optimization suggestions.

[0046] The cleaning strategy effectiveness is expressed as a comprehensive indicator consisting of the strategy cleaning success rate and the attack resource consumption growth rate, based on which the implementation effect of the cleaning strategy is quantified; The key performance is expressed as a comprehensive indicator composed of the primary key defense penetration rate and the secondary key restriction rate. This indicator quantifies the effectiveness of triple defense key implementation. The primary key defense penetration rate represents the percentage of attackers who forge defense key parameters and successfully bypass the triple defense key defense line. The secondary key restriction rate represents the percentage of legitimate users who are mistakenly intercepted due to the additional verification process. The primary key represents the key with the highest weight in the current policy and bears the core interception efficiency. The secondary key represents the key with a lower weight and performs auxiliary verification or accidental attack prevention. The threat evolution log is used to record the deviation between new traffic fraud methods and existing traffic anti-fraud models; The optimization suggestion is represented by generating corresponding model optimization suggestions based on the cleaning strategy effectiveness, the key performance effect, and the threat evolution log.

[0047] Specifically, the cleaning feedback report is input into the traffic anti-cheating model, and the traffic anti-cheating model adjusts and optimizes the corresponding parameters of the strategy generation module according to the cleaning feedback report.

[0048] For example, in the cleaning feedback report of the latest monitoring cycle, the comprehensive index of the cleaning strategy effectiveness reached 0.86, exceeding the effective threshold of 0.7, which was specifically manifested in a 92.3% strategy cleaning success rate. However, the attack resource consumption growth rate of 67% exceeded expectations, especially in the cleaning of abnormal tentative attacks. The resource growth rate increased significantly. The core indicator of the triple defense key performance effect, the primary and secondary key health, was 0.73. Among them, the device behavior key as the primary key defense penetration rate rose to 18.7%, and its fluctuating physical fingerprint forgery rate simultaneously climbed to 23%. The network environment key restriction rate dropped to 3.8%, while the visual recognition key defense penetration rate surged to 41.2%, becoming the main vulnerability. It was detected that the attacker used the GAN generative adversarial network to increase the dynamic texture cracking speed by 37%. The threat evolution log recorded a warning value of 0.58 for the deviation index of highly concealed attacks, which was specifically manifested in the dynamic texture cracking success rate soaring from 12% to 39%, and new evasion techniques such as base station delay forgery and CSS mask hijacking rendering were added.

[0049] Based on the above analysis, the optimization proposal takes emergency measures to upgrade the verification difficulty of the visual recognition key and increase its weight from 35% to 48%. At the same time, it is set to activate the base station delay backtracking verification when the fluctuating physical fingerprint forgery rate exceeds 20%, and increase the network environment key weight by 15%. In addition, 12,000 groups of GAN adversarial samples are injected for intensive training, with the goal of compressing the visual key penetration rate to below 28% within 36 hours.

[0050] In addition, an embodiment of the present invention also provides an electronic device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the control steps in the above embodiments.

[0051] The following is a detailed introduction to the various components of electronic equipment: The term "processor" is used to refer to the control center of an electronic device and can be a single processor or a collective term for multiple processing elements. For example, a processor can be one or more central processing units (CPUs), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement embodiments of the present invention, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).

[0052] The processor can execute various functions of the electronic device by running or executing software programs stored in the memory and calling data stored in the memory.

[0053] The memory is used to store the software program for executing the solution of the present invention, and the execution is controlled by the processor. The specific implementation method can refer to the above embodiment and will not be repeated here.

[0054] The memory may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, a random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only (CD-ROM), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto. The memory may be integrated with the processor or exist independently and be coupled to the processor via an interface circuit of the electronic device, and this is not specifically limited in the embodiments of the present invention.

[0055] The above embodiments can be implemented in whole or in part via software, hardware (e.g., circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product comprises one or more computer instructions or computer programs. When loaded or executed on a computer, the processes or functions described in accordance with the embodiments of the present invention are fully or partially performed. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wireless communication (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium accessible by a computer, or a data storage device such as a server or data center that contains a collection of one or more available media. The available medium can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.

[0056] It should be understood that the term "and / or" as used herein simply describes an association between related objects, indicating that three possible relationships exist. For example, "A and / or B" can represent the existence of A alone, the existence of both A and B, or the existence of B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the related objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.

[0057] It should be understood that in the embodiments of the present invention, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0058] The embodiments described above are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention, and should all be included in the scope of protection of the present invention.

Claims

1. An anti-cheating advertising system based on AI intelligent diagnosis and dynamic creative optimization, characterized by: include: A data acquisition module, which is used to obtain the user's original advertisement data and recent traffic fraud type data, and pre-process the original advertisement data and recent traffic fraud type data to generate an original advertisement template and traffic fraud pattern; A traffic anti-fraud model, which is used to generate a traffic anti-fraud strategy based on the original ad template and the traffic fraud pattern, and includes an ad derivation module and a strategy generation module; An advertisement derivation module, configured to generate multiple groups of derivative advertisements based on an original advertisement template; A strategy generation module, which is used to generate a corresponding traffic anti-cheating strategy for the traffic cheating pattern; A traffic processing module, the traffic processing module is used to obtain real-time traffic of multiple groups of derivative advertisements and calculate traffic entropy values of the real-time traffic according to a traffic entropy function; A data clustering module, wherein the data clustering module is used to perform an initial clustering of the real-time traffic according to the traffic entropy value to obtain a first traffic entropy value clustering result, and perform a secondary clustering of the first traffic entropy value clustering result based on a traffic entropy value filtering strategy to obtain a second traffic entropy value clustering result; an anti-cheating cleaning module, the anti-cheating cleaning module being configured to match a corresponding traffic cheating pattern to the second traffic entropy value clustering result and perform anti-cheating cleaning on the second traffic entropy value clustering result according to a corresponding traffic anti-cheating strategy; A feedback optimization module is configured to obtain a cleaning feedback report generated after performing anti-cheating cleaning on the second traffic entropy value clustering result, and optimize the traffic anti-cheating model based on the cleaning feedback report.

2. The anti-cheating advertising system based on AI intelligent diagnosis and dynamic creative optimization according to claim 1 is characterized in that: The anti-cheating system includes the following control steps: S10: The data acquisition module obtains the original advertisement data to be delivered by the user and the recent traffic fraud type data, and performs data preprocessing on the original advertisement data and the recent traffic fraud type data to generate an original advertisement template and a traffic fraud pattern; S20: Obtain a pre-trained traffic anti-fraud model, input the original ad template and the traffic fraud pattern into the traffic anti-fraud model, and generate multiple sets of derived ads based on the ad derivation module. The derived ads include two ad patterns: observation state and interference state. The strategy generation module generates corresponding traffic anti-fraud strategies for the traffic fraud pattern. S30: Based on the traffic processing module, the real-time traffic of multiple groups of derivative advertisements is obtained, and the traffic entropy value of the real-time traffic is obtained through the traffic entropy function. The data clustering module performs initial clustering on the real-time traffic according to the traffic entropy value to obtain a first traffic entropy value clustering result; S40: The data clustering module performs secondary clustering on the first traffic entropy value clustering result according to the traffic entropy value filtering strategy to obtain a second traffic entropy value clustering result. The anti-cheating cleaning module matches the second traffic entropy value clustering result with a corresponding traffic cheating pattern and performs anti-cheating cleaning based on the corresponding traffic anti-cheating strategy. S50: The feedback optimization module obtains a cleaning feedback report generated after performing anti-cheating cleaning on the second traffic entropy value clustering result, and optimizes the traffic anti-cheating model based on the cleaning feedback report.

3. The anti-cheating advertising system based on AI intelligent diagnosis and dynamic creative optimization according to claim 2 is characterized in that: The ad-based derivation module generates multiple groups of derived advertisements, including two ad modes: observation mode and interference mode. The strategy generation module generates corresponding traffic anti-cheating strategies for the traffic cheating mode, including: Based on the ad derivation module, the original ad template is analyzed for features, and the ad features contained in the original ad template are reorganized to generate multiple groups of derivative ads; Based on the strategy generation module, a triple defense key is implanted into multiple groups of derivative advertisements, and the weight of the triple defense key is dynamically adjusted according to the traffic fraud pattern, and the multiple groups of derivative advertisements implanted with the triple defense key are dual-state packaged; The strategy generation module dynamically adjusts the weight of the triple defense key according to the traffic cheating pattern, and generates a corresponding traffic anti-cheating strategy for the traffic cheating pattern.

4. The anti-cheating advertising system based on AI intelligent diagnosis and dynamic creative optimization according to claim 3 is characterized in that: The controlling step further comprises: The triple defense key includes a device behavior key, a network environment key, and a visual cognition key; The device behavior key is represented by generating a fluctuating physical fingerprint, and embedding the fluctuating physical fingerprint into an advertisement interaction event; The network environment key is represented by generating an environment trusted signature, and the environment trusted signature is embedded in the protocol layer; The visual recognition key is represented by generating a dynamic perception visual element and performing machine recognition based on the dynamic perception visual element; The dual-state encapsulation is represented by generating two advertising modes, observation state and interference state, for multiple groups of derived advertisements, and switching the advertising mode according to the real-time traffic state corresponding to the derived advertisements. The observation state is represented by providing derivative advertisements that only contain lightweight verification key verification for users whose real-time traffic state is judged to be normal. The interference state is represented by providing derivative advertisements that force multiple key verifications for users whose real-time traffic state is judged to be abnormal and suspicious traffic.

5. The anti-cheating advertising system based on AI intelligent diagnosis and dynamic creative optimization according to claim 2 is characterized in that: The method of obtaining the real-time traffic of the plurality of groups of derivative advertisements based on the traffic processing module and obtaining the traffic entropy value of the real-time traffic by using a traffic entropy function includes: Performing three-dimensional feature extraction of time features, spatial features, and behavioral features on the real-time traffic of the plurality of groups of derivative advertisements to obtain three-dimensional feature results; The time entropy value, space entropy value and behavior entropy value of the real-time traffic are obtained based on the three-dimensional feature results, and the traffic entropy value of the real-time traffic is obtained according to the traffic entropy function.

6. The anti-cheating advertising system based on AI intelligent diagnosis and dynamic creative optimization according to claim 2 is characterized in that: The data clustering module performs initial clustering on the real-time traffic according to the traffic entropy value to obtain a first traffic entropy value clustering result, including: Performing initial clustering on the real-time traffic based on a preset traffic entropy value threshold, and dividing the real-time traffic into high entropy value traffic and low entropy value traffic; The high entropy traffic is represented by the traffic entropy value corresponding to the real-time traffic being greater than the preset threshold, which is the derivative advertisement of the observation state advertising mode directly delivered by the high entropy traffic; The low entropy traffic is represented by a traffic entropy value corresponding to the real-time traffic being less than a preset threshold, and the low entropy traffic is then subjected to secondary clustering.

7. The anti-cheating advertising system based on AI intelligent diagnosis and dynamic creative optimization according to claim 2 is characterized in that: The data clustering module performs secondary clustering on the first traffic entropy value clustering result according to the traffic entropy value filtering strategy to obtain a second traffic entropy value clustering result, including: Performing deep behavioral feature extraction on low-entropy traffic in the first traffic entropy value clustering result to obtain an enhanced feature set, wherein the enhanced feature set includes at least behavior density, device aggregation, spatial dispersion, and threat level; The behavior density is expressed as the frequency intensity of repeated operations in the user operation sequence per unit time. The device aggregation is expressed as the cluster density intensity of the device fingerprint parameters corresponding to the low entropy traffic. The spatial discreteness is expressed as the distribution dispersion coefficient of the user interaction behavior in the advertising interface coordinate system. The threat level is expressed as the matching similarity between the real-time behavior characteristics of the low entropy traffic and the preset historical attack pattern library. Based on the enhanced feature set, secondary clustering is performed on the low entropy traffic in the first traffic entropy value clustering result, and the low entropy traffic is divided into device cluster traffic, high hidden traffic and abnormal trial traffic; The device cluster traffic is represented by low entropy traffic with high behavior density and high device aggregation, the high concealment traffic is represented by low entropy traffic with high spatial discreteness and high threat level, and the abnormal tentative traffic is represented by low entropy traffic with high spatial discreteness and low device aggregation.

8. The anti-cheating advertising system based on AI intelligent diagnosis and dynamic creative optimization according to claim 2 is characterized in that: The anti-cheating cleaning module matches the second traffic entropy value clustering result with a corresponding traffic cheating pattern and performs anti-cheating cleaning based on the corresponding traffic anti-cheating strategy, including: Match the second traffic entropy value clustering result with a corresponding traffic cheating pattern, obtain a traffic anti-cheating strategy corresponding to the matched traffic cheating pattern, and clean the second traffic entropy value clustering result according to the corresponding traffic anti-cheating strategy.

9. The anti-cheating advertising system based on AI intelligent diagnosis and dynamic creative optimization according to claim 2 is characterized in that: The feedback optimization module obtains a cleaning feedback report generated after performing anti-cheating cleaning on the second traffic entropy value clustering result, and optimizes the traffic anti-cheating model based on the cleaning feedback report, including: The cleaning feedback report includes at least cleaning strategy effectiveness, key performance effect, threat evolution log and optimization suggestions; The cleaning strategy effectiveness is expressed as a comprehensive indicator consisting of the strategy cleaning success rate and the attack resource consumption growth rate, based on which the implementation effect of the cleaning strategy is quantified; The key performance effect is expressed as a comprehensive indicator composed of the master key defense penetration rate and the secondary key restriction rate, based on which the implementation effect of the triple defense key is quantified; The threat evolution log is used to record the deviation between new traffic fraud methods and existing traffic anti-fraud models; The optimization suggestion is represented by generating corresponding model optimization suggestions according to the cleaning strategy effectiveness, the key performance effect, and the threat evolution log; The cleaning feedback report is input into the traffic anti-cheating model, and the traffic anti-cheating model adjusts and optimizes the corresponding parameters of the strategy generation module according to the cleaning feedback report.

10. The anti-cheating advertising system based on AI intelligent diagnosis and dynamic creative optimization according to claim 2 is characterized in that: The data acquisition module acquires the original advertisement data to be delivered by the user and the recent traffic fraud type data, and performs data preprocessing on the original advertisement data and the recent traffic fraud type data to generate the original advertisement template and traffic fraud pattern, including: Performing feature extraction on the original advertisement data to obtain promotional content data and key information data of the original advertisement data, wherein the promotional content data represents the core content promoted by the original advertisement data, and the key information data represents the constituent elements corresponding to the original advertisement data, and generating an original advertisement template based on the promotional content and key information of the original advertisement data; Extract features from the recent traffic fraud type data to obtain a traffic fraud feature set, and perform feature fusion on the traffic fraud feature set to generate a traffic fraud pattern. The traffic fraud pattern includes a device cluster type, a highly concealed type, and an abnormal trial type. The device cluster type indicates that multiple devices execute exactly the same operation sequence and the corresponding hardware parameters are highly unified; The high-stealth type indicates that the ad click location presents a hash distribution and carries new vulnerability attack characteristics; The abnormal heuristic type is represented by continuously triggering an unconventional operation chain in the edge area of the advertisement interface.

Citation Information

Patent Citations

  • A method and a device for anti-cheating in advertisement

    CN109003137A

  • A method and a device for detecting cheating

    CN109146546A

  • Advertisement traffic anti-cheating method and system, electronic equipment and storage medium

    CN116562934A

  • Advertisement putting anti-cheating method based on big data analysis

    CN118735595A

  • Advertisement putting method and system based on media data fluctuation analysis of artificial intelligence

    CN118798983A