Abnormality detection method and device

By detecting user behavior deviation values ​​in real time and performing corresponding security operations, the problem of the inability to continuously monitor user identity in existing technologies is solved, and the data security and privacy protection of electronic devices are improved.

CN120597252APending Publication Date: 2025-09-05VIVO MOBILE COMM CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510809724.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-17
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

The security measures of existing electronic devices cannot continuously monitor user identities, resulting in the inability to detect and prevent illegal operations in a timely manner, posing the risk of information leakage and malicious operations.

Method used

By obtaining the user's historical behavior information as a benchmark, calculating the deviation value of the current behavior information, detecting the abnormal level in real time, and performing corresponding security operations such as notification, identity authentication or locking the device, data security is ensured.

Benefits of technology

It enables timely security measures to be taken when user behavior is abnormal, prevents unauthorized access, and improves the data security and privacy protection of electronic devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120597252A_ABST
    Figure CN120597252A_ABST
Patent Text Reader

Abstract

The invention discloses an anomaly detection method and device, and belongs to the technical field of communication. The method comprises the steps that under the condition that first user behavior information is detected, user behavior benchmark information is obtained, and the user behavior benchmark information is used for representing behavior information that a user uses the electronic equipment historically; based on the first user behavior information and the user behavior reference information, determining a first deviation value and a corresponding abnormal level; and based on the exception level, executing a safety operation corresponding to the exception level.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of communication technology, and specifically relates to an anomaly detection method and device. Background Art

[0002] With the development of technology, electronic devices have become increasingly common in people's lives, and their security has also attracted increasing attention. Currently, electronic device security measures mainly include personal identification numbers (PINs), passwords, pattern unlocking, and biometrics to verify user identity and ensure the security of electronic devices and data.

[0003] However, existing methods only perform authentication when a user initially uses an electronic device. Once authentication is successful, the electronic device cannot guarantee that subsequent operations are carried out by the user. If the electronic device is accessed by someone else after the user unlocks it, they can freely operate the device, while the user cannot promptly detect and prevent subsequent operations, potentially leading to security issues such as information leakage and malicious operations. This results in poor data security for electronic devices. Summary of the Invention

[0004] The purpose of the embodiments of the present application is to provide an anomaly detection method and device that can improve the data security of electronic devices.

[0005] In a first aspect, an embodiment of the present application provides an anomaly detection method, which includes: when first user behavior information is detected, obtaining user behavior baseline information, the user behavior baseline information is used to characterize the user's historical behavior information of using an electronic device; based on the first user behavior information and the user behavior baseline information, determining a first deviation value and its corresponding anomaly level; based on the anomaly level, performing a security operation corresponding to the anomaly level.

[0006] In a second aspect, an embodiment of the present application provides an anomaly detection device, comprising: an acquisition module, a determination module, and an execution module. The acquisition module is configured to, upon detecting first user behavior information, acquire user behavior baseline information, where the user behavior baseline information is used to represent the user's historical behavior information regarding the use of an electronic device. The determination module is configured to determine a first deviation value and its corresponding anomaly level based on the first user behavior information and the user behavior baseline information acquired by the acquisition module. The execution module is configured to execute a security operation corresponding to the anomaly level based on the anomaly level determined by the determination module.

[0007] In a third aspect, an embodiment of the present application provides an electronic device comprising a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps of the method described in the first aspect are implemented.

[0008] In a fourth aspect, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented.

[0009] In a fifth aspect, an embodiment of the present application provides a chip, which includes a processor and a communication interface, the communication interface and the processor are coupled, and the processor is used to run programs or instructions to implement the method described in the first aspect.

[0010] In a sixth aspect, an embodiment of the present application provides a computer program product, which is stored in a storage medium and executed by at least one processor to implement the method described in the first aspect.

[0011] In an embodiment of the present application, when first user behavior information is detected, user behavior baseline information for characterizing the user's historical behavior information on the use of electronic devices is obtained, and then based on the first user behavior information and the user behavior baseline information, a first deviation value and its corresponding abnormality level are determined, and then based on the abnormality level, a security operation corresponding to the abnormality level is performed. In this solution, when the user's current behavior information on the electronic device is detected, the user's historical behavior information on the use of the electronic device can be obtained as the user behavior baseline, and then the abnormality level of the user behavior can be detected in real time by calculating the deviation value between the current user behavior information and the historical user behavior information, and a security operation corresponding to the abnormality level can be performed. In this way, when there is an abnormality in the user behavior information, corresponding security measures can be quickly taken according to the degree of the abnormality, thereby timely preventing unauthorized access, protecting the user's privacy and data security, and improving the data security of the electronic device. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Figure 1 This is one of the flow charts of the anomaly detection method provided in the embodiment of the present application;

[0013] Figure 2 This is the second flowchart of the anomaly detection method provided in the embodiment of the present application;

[0014] Figure 3 This is the third flowchart of the anomaly detection method provided in the embodiment of the present application;

[0015] Figure 4 This is the fourth flowchart of the anomaly detection method provided in the embodiment of the present application;

[0016] Figure 5 This is the fifth flowchart of the anomaly detection method provided in the embodiment of the present application;

[0017] Figure 6 is a schematic diagram of the execution process of the anomaly detection method provided in an embodiment of the present application;

[0018] Figure 7 This is one of the schematic diagrams of the anomaly detection device provided in an embodiment of the present application;

[0019] Figure 8 This is the second schematic diagram of the abnormality detection device provided in an embodiment of the present application;

[0020] Figure 9 is a structural diagram of an electronic device provided in an embodiment of the present application;

[0021] Figure 10 This is a schematic diagram of the hardware structure of the electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0022] The following will be combined with the accompanying drawings in the embodiments of the present application to clearly describe the technical solutions in the embodiments of the present application. Obviously, the embodiments described are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field are within the scope of protection of this application.

[0023] The terms "first," "second," and the like in the specification and claims of this application are used to distinguish similar objects, and are not used to describe a specific order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of this application can be implemented in an order other than that illustrated or described herein, and that the objects distinguished by "first," "second," and the like are generally of the same type, and do not limit the number of objects; for example, the first object can be one or more. In addition, the term "and / or" in the specification and claims refers to at least one of the connected objects, and the character " / " generally indicates that the objects connected are in an "or" relationship.

[0024] The terms "at least one" and "at least one of" in this application refer to any one, any two, or a combination of more than two of the objects included. For example, at least one of a, b, and c can be represented by: "a", "b", "c", "a and b", "a and c", "b and c", and "a, b, and c", where a, b, and c can be single or multiple. Similarly, "at least two" means two or more, and its meaning is similar to "at least one".

[0025] The following describes in detail the anomaly detection method and device provided in the embodiments of the present application through specific embodiments and their application scenarios in conjunction with the accompanying drawings.

[0026] The embodiments of the present application can be applied to scenarios where abnormality detection of user behavior is required.

[0027] The following uses some specific scenarios of the embodiments of the present application as examples to exemplify the anomaly detection method provided in the embodiments of the present application.

[0028] Scenario 1: Transaction Payment

[0029] When a user uses an electronic device to perform payment operations, the electronic device needs to monitor the user's payment operations in real time to detect whether there is any abnormal transaction behavior and prevent the user from suffering property losses.

[0030] Scenario 2: File Viewing

[0031] When viewing private files, electronic devices need to monitor the user's access operations to the private files to detect whether there is any abnormal access behavior and prevent the user's data from being leaked.

[0032] It should be noted that the above-mentioned scenarios 1 and 2 are merely examples of some possible scenarios in which the embodiments of the present application may be applied. In actual implementation, the embodiments of the present application can also be applied to more demand anomaly detection and any possible scenarios, and the embodiments of the present application are not limited here.

[0033] In the related art, the relevant terms are defined as follows:

[0034] Trusted Execution Environment (TEE): A secure area within the system that protects sensitive data and operations from interference from the main system.

[0035] Artificial Intelligence (AI): Machine programs that simulate human intelligence and have the ability to think and act.

[0036] Behavior-Based Authentication: A method of verifying identity based on user behavior patterns.

[0037] In related technologies, security measures for electronic devices include PIN codes, passwords, pattern unlocking, and biometric identification (such as fingerprints and facial recognition). These methods are typically used for initial authentication and may require periodic re-authentication, but they cannot provide continuous user activity monitoring to ensure continued authorization.

[0038] The embodiments of the present application provide an anomaly detection method and apparatus. When an electronic device detects a user's current behavior information regarding the electronic device, it can obtain the user's historical behavior information regarding the electronic device as a benchmark. The electronic device can then calculate the deviation between the current user behavior information and the historical user behavior information to detect the abnormality level of the user behavior in real time and perform security operations corresponding to the abnormality level. In this way, when an abnormality is found in the user behavior information, the electronic device can quickly take corresponding security measures based on the degree of the abnormality, thereby promptly preventing unauthorized access, protecting the user's privacy and data security, and improving the data security of the electronic device.

[0039] The execution subject of the anomaly detection method provided in the embodiment of the present application can be an anomaly detection device, which can be an electronic device, or a functional module or functional entity in the electronic device. The following uses an electronic device as an example to illustrate the technical solution provided in the embodiment of the present application.

[0040] Figure 1 A flowchart of an abnormality detection method provided by an embodiment of the present application is shown in FIG. Figure 1 As shown, the anomaly detection method provided in the embodiment of the present application may include the following steps 201 to 203.

[0041] Step 201: When first user behavior information is detected, the electronic device obtains user behavior benchmark information.

[0042] In the embodiment of the present application, the above-mentioned user behavior benchmark information is used to represent the user's historical behavior information of using the electronic device.

[0043] In the embodiments of the present application, the user behavior benchmark information is a reference standard established based on the user's historical behavior data and is used to describe the user's regular behavior patterns. The user behavior benchmark information is in the form of a feature vector and includes different types of user operation data, such as screen touch events, key trigger events, application data, and location data.

[0044] Among them, each type of operation data may include at least one parameter. For example, screen touch events may include parameters such as touch frequency, touch pressure, touch coordinates, touch time, etc., key trigger events may include parameters such as key frequency and duration, application data may include parameters such as opening frequency and usage time, and location data may include parameters such as geographic location coordinates, place type, switching frequency, etc.

[0045] Optionally, in an embodiment of the present application, the user behavior benchmark information includes the average value and standard deviation of at least one parameter value of each parameter during the user's historical usage. For example, the user behavior benchmark information may include an average click frequency of 10 times / minute and a standard deviation of 2 times / minute, an average touch pressure of 0.5 Newtons (N) and a standard deviation of 0.1N, an average touch time of 5 minutes and a standard deviation of 1 minute, etc.

[0046] In the embodiment of the present application, the above-mentioned first user behavior information is the user behavior data detected by the electronic device at the current moment, which is the result of real-time monitoring.

[0047] Optionally, in an embodiment of the present application, the electronic device can capture the user's current behavior data in real time through its sensors and monitoring module. After detecting the first user behavior information, the electronic device can obtain pre-established user behavior benchmark information.

[0048] Step 202: The electronic device determines a first deviation value and its corresponding abnormality level based on the first user behavior information and the user behavior benchmark information.

[0049] In the embodiment of the present application, the above-mentioned first deviation value refers to the deviation value between the first user behavior information and the user behavior benchmark information, which is used to measure the degree of deviation between the current user behavior and the normal behavior pattern.

[0050] Optionally, in an embodiment of the present application, after obtaining the first user behavior information and pre-established user behavior benchmark information, the electronic device may compare and analyze the first user behavior information with the user behavior benchmark information, calculate the difference between the two, and obtain a first deviation value.

[0051] In the embodiment of the present application, the above-mentioned abnormality levels are pre-set at different levels according to the size of the deviation value, which are used to indicate the degree of abnormal user behavior, for example, they can be divided into mild abnormality, moderate abnormality and severe abnormality.

[0052] In the embodiment of the present application, the security operations corresponding to the above-mentioned abnormality levels are corresponding security measures for different abnormality levels, which are used to respond to detected abnormal user behaviors to protect the security of the device and user data.

[0053] Optionally, in an embodiment of the present application, the electronic device may determine a corresponding abnormality level based on a preset threshold value and a calculated first deviation value, and then perform a safety operation corresponding to the level based on the determined abnormality level.

[0054] Optionally, in an embodiment of the present application, the first user behavior information includes n first parameter values, and the user behavior benchmark information includes a mean value corresponding to each first parameter value and a standard deviation value corresponding to each first parameter value, where n is a positive integer. Figure 1 ,like Figure 2 As shown, the above step 202 can be specifically implemented through the following steps 202a to 202c.

[0055] Step 202a: The electronic device calculates a first difference between each first parameter value and the corresponding mean value.

[0056] In the embodiment of the present application, the above-mentioned first parameter value refers to the real-time value of each parameter contained in the first user behavior information, such as touch pressure, key frequency, etc.

[0057] In the embodiment of the present application, the mean value corresponding to each first parameter value is the historical average value of the parameter corresponding to each first parameter value in the user behavior benchmark information. The standard deviation value corresponding to each first parameter value is the historical standard deviation of the parameter corresponding to each first parameter value in the user behavior benchmark information.

[0058] For example, in the user behavior benchmark information, the historical average value of touch pressure may be 1.5N, and the historical average value of key press frequency may be 8 times per minute.

[0059] Optionally, in an embodiment of the present application, the electronic device can obtain each user behavior parameter value monitored in real time, i.e., the first parameter value, and obtain the mean value corresponding to each first parameter value from the user behavior benchmark, and then the electronic device can calculate the difference between each first parameter value and the corresponding mean value to obtain the first difference value.

[0060] For example, assuming that the electronic device detects a touch pressure of 1.4N and learns from the user behavior benchmark that the historical average touch pressure is 1N, the first difference is the difference between 1.4N and 1N, that is, 1.4N-1N=0.4N.

[0061] Optionally, in an embodiment of the present application, in actual calculations, after calculating the difference between the first parameter value and the corresponding mean, the electronic device can take the absolute value of the difference as the first difference, so that the degree of deviation can still be measured when the difference is negative.

[0062] For example, assuming that the electronic device detects a touch pressure of 1N, and the electronic device learns from the user behavior benchmark that the historical average of the touch pressure is 1.4N, then the difference is 1.0N-1.4N=-0.4N. The electronic device can take the absolute value of the difference, that is, |-0.4N|, and obtain a first difference of 0.4N.

[0063] Step 202b: The electronic device calculates a deviation value corresponding to each first parameter value based on the first difference value and the corresponding standard deviation value corresponding to each first parameter value.

[0064] In the embodiments of the present application, the above-mentioned deviation value is used to measure the degree of dispersion of the corresponding parameter value in the historical data, indicating the fluctuation of the parameter value. The unit of the deviation value is σ. In statistics, σ represents the standard deviation, which is used to measure the degree of dispersion of a set of values, that is, the difference between the data points and the mean. When calculating the deviation value, using σ as the unit can standardize the deviation value, making it dimensionless, which facilitates comparison between different behavioral characteristics.

[0065] Optionally, in an embodiment of the present application, the electronic device may obtain a standard deviation value corresponding to each first parameter value from the user behavior benchmark, and then divide the first difference value corresponding to each first parameter value by the corresponding standard deviation value to calculate a deviation value corresponding to each first parameter value. This standardization process can be performed on the first difference values, eliminating the impact of the dimensions and fluctuations between different parameters, and improving the comparability of the deviation values.

[0066] Optionally, in the embodiment of the present application, the electronic device calculates the deviation value corresponding to each first parameter value in the form of the following formula (1):

[0067] Deviation value = |real-time value-mean|÷standard deviation formula (1)

[0068] Among them, the above-mentioned deviation value is the deviation value corresponding to the first parameter value, the above-mentioned real-time value is the first parameter value, the above-mentioned mean value is the mean value corresponding to the first parameter value, and the above-mentioned standard deviation value corresponds to the standard deviation value of each first parameter value.

[0069] For example, assume that the user behavior benchmark information includes: the mean touch frequency is 10 times / minute, the standard deviation of touch frequency is 2 times / minute, the mean touch pressure is 0.5N, the standard deviation of touch pressure is 0.1N, the mean touch time is 5 minutes, and the standard deviation of touch time is 1 minute. If the electronic device detects that the user's click frequency is 20 times / minute, the pressure is 0.7N, and the touch time is 8 minutes, then the deviation value of each of these parameters can be calculated separately, specifically:

[0070] Deviation of touch frequency = |20-10|÷2 = 5σ;

[0071] Deviation of touch pressure = |0.7-0.5|÷0.1=2σ;

[0072] The deviation value of the touch time = |8-5| ÷ 1 = 3σ.

[0073] Step 202c: The electronic device calculates the first deviation value and determines the corresponding abnormality level based on the deviation value and the corresponding weight value corresponding to each first parameter value.

[0074] In the embodiment of the present application, the above-mentioned weight value is the importance coefficient of each first parameter value in the overall deviation assessment, which is used to measure the relative importance of the parameter in anomaly detection.

[0075] Optionally, in an embodiment of the present application, the electronic device can obtain the weight value corresponding to each first parameter value from a preset weight configuration, and then multiply each deviation value by its corresponding weight value and sum them to obtain a comprehensive deviation value, namely the first deviation value.

[0076] Optionally, in the embodiment of the present application, the electronic device calculates the first deviation value in the form of the formula shown in the following formula (2):

[0077]

[0078] Among them, n is the number of first parameter values, deviation value i is the i-th deviation value among the deviation values ​​corresponding to the n first parameter values, and weight value i is the i-th weight value among the weight values ​​corresponding to the n first parameter values.

[0079] In an embodiment of the present application, the electronic device can comprehensively consider the abnormality and importance of each parameter through weighted summation to obtain an overall first deviation value for evaluating the overall abnormality of the user's current behavior.

[0080] Exemplarily, the user behavior benchmark information includes: touch frequency, touch pressure and touch time, the deviation value of touch frequency is 5σ, the deviation value of touch pressure is 2σ, the deviation value of touch time is 3σ, the weight of touch frequency is 0.5, the weight of touch pressure is 0.3, and the weight of touch time is 0.2. The electronic device can calculate the first deviation value = 0.5×5+0.3×2+0.2×3=2.5+0.6+0.6=3.7σ.

[0081] Optionally, in an embodiment of the present application, the above-mentioned abnormality level can be divided into multiple levels, such as 2, 3, 4, etc. Taking three levels as an example, for example, when the first deviation value is greater than or equal to the first threshold value and less than the second threshold value, the electronic device can determine that the abnormality level corresponding to the first deviation value is a mild abnormality; when the first deviation value is greater than or equal to the second threshold value and less than the third threshold value, the electronic device can determine that the abnormality level corresponding to the first deviation value is a moderate abnormality; when the first deviation value is greater than or equal to the third threshold value, the electronic device can determine that the abnormality level corresponding to the first deviation value is a severe abnormality. The specific level can be determined according to actual use requirements, and the embodiment of the present application does not limit it.

[0082] In this way, the electronic device can more accurately evaluate the degree of abnormality of user behavior in each specific behavior dimension by calculating the first difference and deviation value for each first parameter value respectively, and comprehensively calculating the first deviation value in combination with the weight value, thereby improving the accuracy of abnormality detection.

[0083] Step 203: The electronic device performs a security operation corresponding to the abnormality level based on the abnormality level.

[0084] Optionally, in embodiments of the present application, the electronic device can use an anomaly detection engine to compare user behavior against a benchmark in real time, identifying deviations and determining anomalies. For example, if a user sends a large number of messages at 3 a.m., and the electronic device calculates a deviation greater than a threshold of 3σ, this high deviation can trigger anomaly detection. This detection relies on high-precision analysis using a CNN model, ensuring accuracy through a threshold of 3σ, and promptly identifying security threats.

[0085] Optionally, in embodiments of the present application, the electronic device can respond in a graded manner based on the level of anomaly. Graded responses include: minor anomalies notify the user, moderate anomalies require secondary authentication, such as a PIN or fingerprint, and severe anomalies lock the device and notify the user via email or SMS. Response time is <100ms, and the event is logged.

[0086] Optionally, in the embodiment of the present application, Figure 1 ,like Figure 3 As shown, the above step 203 can be specifically implemented by any one of the following steps 203a to 203c.

[0087] Step 203a: When the first deviation value is greater than or equal to the first threshold value and less than the second threshold value, the electronic device displays an abnormality notification.

[0088] In the embodiment of the present application, the above-mentioned abnormality notification is used to prompt the user that there is an abnormality in the electronic device.

[0089] Optionally, in an embodiment of the present application, the abnormality notification may include a specific description of the abnormal behavior, such as the abnormal behavior type, the time when the abnormality occurred, or the details of the abnormal behavior, for example, "an abnormal touch operation pattern was detected" or "a large number of message sending was detected at 3 a.m."

[0090] Optionally, in an embodiment of the present application, the abnormal notification may include operations recommended for the user, such as suggesting the user to confirm whether the operation is performed by him / herself, or suggesting the user to change the password, etc.

[0091] Optionally, in an embodiment of the present application, the above-mentioned abnormality notification can be a pop-up notification or a status bar notification. Among them, the pop-up notification is to display the abnormality notification in the form of a window, and the status bar notification is to display the abnormality notification in the status bar of the electronic device.

[0092] In the embodiment of the present application, the first threshold is smaller than the second threshold.

[0093] Optionally, in an embodiment of the present application, the electronic device can determine whether the first deviation value is greater than or equal to the first threshold and less than the second threshold, that is, whether it is between the threshold range from the first threshold to the second threshold. If the first deviation value is between the threshold range, the electronic device can determine that the abnormality corresponding to the first deviation value is a mild abnormality, and thus can display an abnormal notification on the screen to prompt the user that there is abnormal behavior.

[0094] Optionally, in the embodiment of the present application, the first threshold and the second threshold may be the default value of the electronic device or pre-set by the user. For example, the first threshold may be 3, 4, 5, etc., and the second threshold may be 5, 6, 7, etc. The specific value may be determined based on actual usage requirements and is not limited in the embodiment of the present application.

[0095] For example, assuming that the first threshold and the second threshold are 3 and 5 respectively, and the first deviation value calculated by the electronic device is 3.7, the electronic device can determine that the first deviation value is greater than or equal to 3 and less than 5, that is, the first deviation value is between the first threshold and the second threshold, so that the electronic device can display an abnormal notification, such as "Abnormal behavior has been detected, please confirm whether it is your operation."

[0096] Step 203b: When the first deviation value is greater than or equal to the second threshold and less than the third threshold, the electronic device performs identity authentication.

[0097] In the embodiment of the present application, the above-mentioned identity authentication is used to authenticate the identity of the user.

[0098] In the embodiments of this application, identity authentication refers to the process of verifying the user's identity through a specific method to ensure that the current operator is the legitimate user of the device or account. Identity authentication can be done in a variety of ways, such as entering a PIN code, fingerprint recognition, facial recognition, or answering preset security questions.

[0099] In the embodiment of the present application, the third threshold is greater than the second threshold and the first threshold.

[0100] Optionally, in an embodiment of the present application, the electronic device can determine whether the first deviation value is greater than or equal to the second threshold and less than the third threshold, that is, whether it is between the threshold range from the second threshold to the third threshold. If the first deviation value is between the threshold range, the electronic device can determine that the abnormality corresponding to the first deviation value is a moderate abnormality, so that identity authentication can be performed to verify the identity of the user.

[0101] Optionally, in an embodiment of the present application, if the user passes identity authentication, the electronic device may allow the user to continue using the electronic device and record the abnormal behavior as a reference for future analysis. If the user fails identity authentication, the electronic device may take further security measures, such as locking the device, restricting functions, or sending an abnormality notification to the user's associated account.

[0102] Optionally, in the embodiment of the present application, the third threshold value may be a default value of the electronic device or a preset value by the user. For example, the third threshold value may be 7, 10, 15, etc. The specific value may be determined based on actual usage requirements and is not limited in the embodiment of the present application.

[0103] For example, assuming that the second threshold and the third threshold are 5 and 7 respectively, and the first deviation value calculated by the electronic device is 6, the electronic device can determine that the first deviation value is greater than or equal to 5 and less than 7, that is, the first deviation value is between the second threshold and the third threshold, so that the electronic device can perform identity authentication and verify the identity of the user.

[0104] Step 203c: When the first deviation value is greater than or equal to the third threshold value, the electronic device locks the electronic device and sends an abnormality notification to the account associated with the electronic device.

[0105] In an embodiment of the present application, the above-mentioned locking of the electronic device refers to restricting the operation or access of the electronic device to prevent unauthorized use or data leakage. For example, the electronic device can enter a lock screen state and restrict unlocking. The user needs to perform identity authentication after a period of time before unlocking and continuing to use the electronic device.

[0106] In an embodiment of the present application, the account associated with the above-mentioned electronic device refers to a security account reserved in the electronic device for receiving abnormal notifications, performing identity authentication or performing security operations, such as an email account, a social application account, a telephone number, etc.

[0107] Optionally, in an embodiment of the present application, the electronic device may determine whether the first deviation value is greater than or equal to a third threshold value. If the first deviation value is greater than or equal to the third threshold value, the electronic device may determine that the anomaly corresponding to the first deviation value is a severe anomaly, thereby determining that an unauthorized operation has occurred. The electronic device may immediately perform a lock operation to prevent potential security threats and send an anomaly notification to the account associated with the electronic device. The notification content may include a detailed description of the abnormal behavior and recommended countermeasures, and may also include a verification code or verification link for unlocking the electronic device.

[0108] For example, assuming that the third threshold is 7 and the first deviation value calculated by the electronic device is 8, the electronic device can determine that the first deviation value is greater than or equal to 7, so that the electronic device can be locked immediately and send an abnormal notification email to the email account reserved by the user in the electronic device, thereby notifying the user of possible abnormal behavior.

[0109] In this way, the electronic device can calculate the first deviation value and compare it with different thresholds to accurately divide abnormal behaviors into different levels, so that the electronic device can take corresponding measures according to the severity of the abnormality. When the abnormality is mild, only a simple notification is made, while for serious abnormalities, strict security measures are taken, thereby avoiding excessive disturbance to the user while effectively preventing potential security threats.

[0110] The present application provides an anomaly detection method. When an electronic device detects a user's current behavior information regarding the electronic device, it can obtain the user's historical behavior information regarding the electronic device as a benchmark. The electronic device can then calculate the deviation between the current user behavior information and the historical user behavior information to detect the abnormality level of the user behavior in real time and perform security operations corresponding to the abnormality level. In this way, when an abnormality is found in the user behavior information, the electronic device can quickly take corresponding security measures based on the degree of the abnormality, thereby promptly preventing unauthorized access, protecting the user's privacy and data security, and improving the data security of the electronic device.

[0111] Optionally, in the embodiment of the present application, Figure 1 ,like Figure 4 As shown, before the above step 201, the anomaly detection method provided in the embodiment of the present application further includes the following steps 301 to 303.

[0112] Step 301: The electronic device pre-processes and encrypts historical usage data.

[0113] In an embodiment of the present application, the above-mentioned historical usage data includes historical usage data of the electronic device, or includes historical usage data of the electronic device and historical usage data of other electronic devices associated with the electronic device.

[0114] In an embodiment of the present application, the above-mentioned historical usage data includes at least one of the following: screen touch events, button trigger events, application data and location data.

[0115] In an embodiment of the present application, the above-mentioned historical usage data is the interaction data of the user operating the electronic device within a preset period of time. For example, the preset period of time can be 7 days, that is, the historical usage data is the data of the user using the electronic device within the past 7 days.

[0116] In the embodiments of the present application, the above-mentioned preprocessing refers to cleaning, transforming, and summarizing historical usage data to improve data quality and applicability, including removing duplicate or invalid data and filtering outliers. For example, an electronic device may treat consecutive identical Global Positioning System (GPS) coordinates as duplicate data, and data with a touch pressure less than 0.1N and a key press duration less than 10 milliseconds as outliers.

[0117] In the embodiment of the present application, the encryption method is to convert the original historical usage data into ciphertext using encryption technology to improve the security of the data. For example, the encryption technology can be AES-256 and RSA-2048.

[0118] Optionally, in an embodiment of the present application, the electronic device can obtain historical usage data of the mobile phone over a period of time, then pre-process the collected historical usage data, and encrypt the pre-processed data using encryption technology to ensure the security and privacy of the data during storage and transmission.

[0119] Optionally, in embodiments of the present application, electronic devices can integrate multimodal data, such as voice or gait, and use federated learning to aggregate data across devices weekly, protecting privacy and dynamically adjusting detection sensitivity based on context, such as location or time. For example, when a user uses an electronic device in an unconventional location, the electronic device can increase detection sensitivity. Using federated learning to optimize the model, it can adapt to multi-device scenarios, improving flexibility and accuracy.

[0120] Optionally, in embodiments of the present application, electronic devices can further enhance authentication capabilities by incorporating multimodal data, such as voice patterns or gait data. They can also dynamically adjust the sensitivity of anomaly detection based on user context, such as location or time, to improve detection accuracy and adapt to different usage scenarios. These improvements not only enrich the system's functionality but also enable cross-device data aggregation and learning through federated learning technology, while ensuring user privacy is not violated.

[0121] Step 302: The electronic device transmits the historical usage data to a secure area of ​​the electronic device through a secure transmission channel of the electronic device.

[0122] In this embodiment of the present application, the aforementioned secure area is a TEE in an electronic device. A TEE is a secure area isolated from the standard Rich Execution Environment (REE) in an electronic device. It provides a higher level of security and trust, protecting sensitive data and critical operations from malware and other security threats.

[0123] In an embodiment of the present application, the above-mentioned secure transmission channel is a dedicated channel for inter-process communication (IPC) between TEE and REE, which is used to protect the security and integrity of data during transmission.

[0124] Optionally, in an embodiment of the present application, the electronic device can send the pre-processed and encrypted historical usage data from the REE to the TEE through a secure transmission channel to avoid malicious interception and ensure data integrity and confidentiality.

[0125] For example, electronic devices can encrypt pre-processed data using RSA-2048 (using the Android KeyStore to generate keys) and transmit it to the Trusted Execution Environment (TEE) via a TEE-specific IPC mechanism to prevent man-in-the-middle attacks. Parameters include AES-256 (data encryption), RSA-2048 (key exchange), and a secure IPC channel.

[0126] Step 303: The electronic device analyzes the first historical usage data in the safe area to generate user behavior benchmark information.

[0127] Optionally, in an embodiment of the present application, the electronic device can decrypt and analyze historical usage data within a secure area, using machine learning algorithms, such as a lightweight convolutional neural network (CNN), to analyze the data and generate user behavior benchmark information. The electronic device can store the generated user behavior benchmark information in the TEE for subsequent use as a reference standard during anomaly detection.

[0128] Optionally, in an embodiment of the present application, within the TEE, the electronic device can analyze data through a lightweight CNN (3 convolutional layers + 2 fully connected layers, learning rate 0.001, batch size 32) combined with an incremental learning algorithm. The initial training generates a behavioral benchmark based on 7 days of interaction data, and the model is updated every 24 hours.

[0129] For example, assuming that a user uses a new application for 2 hours a day, the electronic device can incorporate it into the baseline through incremental learning of the AI ​​model (i.e., the above-mentioned lightweight CNN), avoiding misjudgment of anomalies, so that the model architecture and training parameters ensure efficient adaptability.

[0130] In this way, electronic devices can ensure the security and privacy of data during transmission and processing through TEE-specific IPC mechanisms and TEE environments, avoid the risk of data being intercepted or tampered with, and improve data security.

[0131] Optionally, in the embodiment of the present application, Figure 1 ,like Figure 5As shown, after the above step 203, the anomaly detection method provided in the embodiment of the present application further includes the following step 401.

[0132] Step 401: When receiving abnormal feedback information from a user, the electronic device adjusts a second parameter value based on the abnormal feedback information.

[0133] In the embodiment of the present application, the above-mentioned second parameter value includes a reference value for determining whether the user behavior information is abnormal and the abnormality level.

[0134] Optionally, in an embodiment of the present application, the second parameter value may include the weight of each parameter and a threshold value for judging the degree of abnormality (the above-mentioned first threshold value, second threshold value and third threshold value), etc.

[0135] In the embodiment of the present application, abnormal feedback information refers to the user's feedback on the abnormal detection result, for example, the user marks a certain abnormal detection as a false alarm or marks a certain abnormal detection as a real abnormality.

[0136] Optionally, in an embodiment of the present application, the electronic device can receive abnormal feedback information from the user. For example, after receiving the abnormal notification, the user can mark the notification as a false alarm or a real abnormality, or the user can also mark any abnormal record in the historical abnormal records as a false alarm or a real abnormality.

[0137] Optionally, in an embodiment of the present application, the electronic device may adjust the value of the second parameter based on the received abnormality feedback information. If a user reports that a certain abnormality detection is a false alarm, the electronic device may lower the threshold of the relevant abnormality level or adjust the weight of the relevant parameter to reduce false alarms in similar situations in the future.

[0138] For example, assuming that a user uses an electronic device at 3 a.m., the electronic device calculates that the deviation value of the touch frequency is 5σ, the deviation value of the touch pressure is 2σ, and the deviation value of the touch time is 3σ. Assuming that the weight of the touch frequency is 0.5, the weight of the touch pressure is 0.3, and the weight of the touch time is 0.2, the first threshold is 3, the second threshold is 5, and the third threshold is 7, the electronic device can calculate the first deviation value to be 3.7σ, and judge that 3.7 is greater than or equal to the first threshold and less than the second threshold, and judge the operation at 3 a.m. as a mild abnormality and display an abnormality notification. At this time, the user marks the abnormal behavior prompted by the abnormality notification as a false alarm, then the electronic device can judge that the deviation value of the touch frequency is high, resulting in a false alarm, so the electronic device can reduce the weight of the touch frequency, for example, from 0.5 to 0.4, or the electronic device can adjust the threshold, such as adjusting the first threshold from 4 to 4, to reduce false alarms.

[0139] In this way, the electronic device can dynamically adjust and optimize the abnormality detection process by receiving user feedback and adjusting the second parameter value to better adapt to the user's actual usage, thereby improving detection accuracy and user satisfaction.

[0140] Optionally, in an embodiment of the present application, the anomaly detection method provided in the embodiment of the present application further includes the following steps 501 to 502.

[0141] Step 501: The electronic device obtains second user behavior information at preset time intervals.

[0142] In the embodiment of the present application, the above-mentioned preset duration is a pre-set time interval used to regularly obtain the user's latest behavior information in order to update the user behavior benchmark information.

[0143] Optionally, in an embodiment of the present application, the first threshold value may be a default value of the electronic device or a preset value by the user. For example, the preset duration may be 1 day, 2 days, or 3 days. The specific duration may be determined based on actual usage requirements and is not limited in the embodiment of the present application.

[0144] In an embodiment of the present application, the second user behavior information is user behavior information obtained after a preset time period, and is used to reflect the user's behavior pattern after the preset time period, that is, the current behavior pattern.

[0145] Optionally, in an embodiment of the present application, after generating user behavior baseline information, the electronic device may collect the user's latest behavior data within a preset time period through sensors, application interfaces and other channels at preset time intervals, including touch operations, button inputs, application usage, location information, etc., as second user behavior information.

[0146] Step 502: The electronic device updates the user behavior benchmark information based on the second user behavior information.

[0147] Optionally, in an embodiment of the present application, after the electronic device obtains the second user behavior information, the obtained second user behavior information can be preprocessed and encrypted, and the second user behavior information can be incorporated into the benchmark through incremental learning of lightweight CNN within the TEE to generate new user behavior benchmark information, avoid misjudgment of anomalies, and ensure efficient adaptability of the model architecture and training parameters.

[0148] Optionally, in an embodiment of the present application, the electronic device can receive user flags of abnormal behavior through a feedback interface and optimize the model weights and detection thresholds weekly. For example, when a moderate anomaly is detected, such as abnormal application usage, a PIN code input interface will pop up, the event will be recorded, and user feedback will be received. The model will be optimized based on the feedback to reduce the false alarm rate.

[0149] In this way, the electronic device can regularly obtain the user's latest behavior information and update the user's behavior baseline information to ensure that the baseline information can always reflect the user's current behavior pattern, thereby improving the accuracy of anomaly detection.

[0150] It should be noted that the above step 501 can be performed after the above step 303, that is, after performing the above step 303 to generate the user behavior benchmark information, the electronic device can obtain the second user behavior information every preset time period and update the user behavior benchmark information.

[0151] In an embodiment of the present application, an Android behavior authentication system based on AI and TEE is provided. It detects anomalies by continuously monitoring user behavior. Specific improvements include:

[0152] 1. Continuous Monitoring: Analyze user behavior in real time to detect any anomalies.

[0153] 2. Secure processing: Use TEE to ensure the protection of sensitive user data during processing.

[0154] 3. Adaptive security: AI models can learn and adapt to users’ changing behavior patterns.

[0155] 4. Enhanced privacy: User data is processed within TEE, reducing the risk of data leakage.

[0156] These improvements aim to address core issues with the existing system and provide a more secure and user-friendly authentication experience.

[0157] In the embodiments of the present application, electronic devices can use AI and TEE to implement behavioral authentication of electronic devices, enhance security, adapt to behavioral changes and protect privacy by real-time monitoring of user behavior, while providing a seamless experience and wide applicability, demonstrating significant advantages in improving electronic device protection and user interaction.

[0158] Optionally, in the embodiments of this application, electronic devices can simultaneously integrate other security systems to form a multi-layered defense mechanism and enhance overall security. Its flexibility makes it applicable to a variety of electronic devices and lays the foundation for future expansion to other operating systems, thereby opening up new application prospects in the field of electronic device security and promoting innovation in the way users interact with electronic devices.

[0159] Figure 6 Schematic diagram of the execution process of the anomaly detection method provided in the embodiment of the present application. Figure 6 As shown, the anomaly detection method provided in the embodiment of the present application may include the following steps 10 to 15.

[0160] Step 10: The electronic device obtains and pre-processes the user interaction data through the data collection module.

[0161] Step 11: The electronic device obtains the secure data in the TEE through secure transmission of the pre-processed user interaction data.

[0162] Step 12: The electronic device uses the security data in the TEE and the AI ​​model to analyze and obtain and update the user behavior benchmark.

[0163] Step 13: The electronic device uses the user behavior benchmark and the anomaly detection engine to compare in real time to obtain an anomaly detection result.

[0164] Step 14: The electronic device detects abnormalities, processes them through the security response module, and executes graded security measures.

[0165] Step 15: The electronic device processes user feedback through a feedback mechanism to optimize the AI ​​model and anomaly detection engine.

[0166] In an embodiment of the present application, the electronic device can collect, process and securely transmit user interaction data to a trusted execution environment (TEE), establish a user behavior baseline through a lightweight AI model, and perform anomaly detection in real time. After an anomaly is detected, graded security response measures are taken according to the severity. The system continuously optimizes the AI ​​model and detection engine through user feedback and federated learning to ensure that it efficiently adapts to multi-device scenarios and protects user privacy. Technically, AES-256 and RSA-2048 encryption are used to ensure data security, and efficient behavior analysis is achieved through a lightweight CNN model.

[0167] Each of the above-mentioned method embodiments, or various possible implementation methods in each method embodiment, can be executed separately, or any two or more of them can be executed in combination with each other. The specific implementation can be determined according to actual usage requirements, and the embodiments of this application do not limit this.

[0168] The anomaly detection method provided in the embodiment of the present application can be executed by an anomaly detection device. In the embodiment of the present application, the anomaly detection device performing the anomaly detection method is used as an example to illustrate the anomaly detection device provided in the embodiment of the present application.

[0169] Figure 7 FIG. 1 shows a possible structural diagram of an abnormality detection device involved in some embodiments of the present application. Figure 7 As shown, the abnormality detection device 70 may include: an acquisition module 71 , a determination module 72 and an execution module 73 .

[0170] The acquisition module 71 is configured to acquire user behavior benchmark information when first user behavior information is detected. The user behavior benchmark information is used to represent historical behavior information of the user using the electronic device.

[0171] The determining module 72 is configured to determine a first deviation value and its corresponding abnormality level based on the first user behavior information and the user behavior benchmark information acquired by the acquiring module 71 .

[0172] The execution module 73 is configured to execute a safety operation corresponding to the abnormality level based on the abnormality level determined by the determination module 72 .

[0173] In one possible implementation, combining Figure 7 ,like Figure 8 As shown, the anomaly detection device provided by the embodiment of the present application also includes a transmission module 74. The above-mentioned execution module 73 is also used to pre-process and encrypt the historical usage data before the above-mentioned acquisition module 71 acquires the user behavior benchmark information when the first user behavior information is detected. The historical usage data includes the historical usage data of the electronic device, or includes the historical usage data of the electronic device and the historical usage data of other electronic devices associated with the electronic device; the historical usage data includes at least one of the following: screen touch events, button trigger events, application data and location data. The above-mentioned transmission module 74 is used to transmit the historical usage data processed by the execution module 73 to the secure area of ​​the electronic device through the secure transmission channel of the electronic device. The secure area is a trusted execution environment in the electronic device. The above-mentioned execution module 73 is also used to analyze the historical usage data transmitted by the transmission module in the secure area to generate user behavior benchmark information.

[0174] In one possible implementation, the first user behavior information includes n first parameter values, and the user behavior benchmark information includes a mean value corresponding to each first parameter value and a standard deviation value corresponding to each first parameter value, where n is a positive integer. The determination module 72 is specifically configured to: calculate a first difference value between each first parameter value and the corresponding mean value; calculate a deviation value corresponding to each first parameter value based on the first difference value and the corresponding standard deviation value; and calculate a first deviation value and determine its corresponding abnormality level based on the deviation value and the corresponding weight value corresponding to each first parameter value.

[0175] In one possible implementation, the above-mentioned execution module 73 is specifically used to: when the first deviation value is greater than or equal to the first threshold and less than the second threshold, display an abnormal notification, and the abnormal notification is used to prompt the user that there is an abnormality in the electronic device; or, when the first deviation value is greater than or equal to the second threshold and less than the third threshold, perform identity authentication, and the identity authentication is used to authenticate the identity of the user; or, when the first deviation value is greater than or equal to the third threshold, lock the electronic device and send an abnormal notification to the account associated with the electronic device.

[0176] In one possible implementation, the above-mentioned execution module 73 is also used to adjust the second parameter value based on the abnormal feedback information received from the user after executing the safety operation corresponding to the abnormal level based on the abnormal level corresponding to the first deviation value. The second parameter value includes a reference value for judging whether the user behavior information is abnormal and the abnormal level.

[0177] In a possible implementation, the acquisition module 71 is further configured to acquire the second user behavior information at predetermined intervals. The execution module 73 is further configured to update the user behavior benchmark information based on the second user behavior information.

[0178] In an embodiment of the present application, an anomaly detection device is provided. When detecting a user's current behavior information regarding the anomaly detection device, the anomaly detection device can obtain the user's historical behavior information regarding the anomaly detection device as a benchmark. The anomaly detection device can then calculate the deviation between the current user behavior information and the historical user behavior information to detect the abnormality level of the user's behavior in real time and perform security operations corresponding to the abnormality level. In this way, when an anomaly exists in the user's behavior information, the anomaly detection device can quickly take corresponding security measures based on the degree of the anomaly, thereby promptly preventing unauthorized access, protecting the user's privacy and data security, and improving the data security of the anomaly detection device.

[0179] The anomaly detection device in the embodiment of the present application can be an electronic device, or a component in the electronic device, such as an integrated circuit or a chip. The electronic device can be a terminal, or other devices other than a terminal. For example, the electronic device can be a mobile phone, a tablet computer, a laptop computer, a PDA, an in-vehicle electronic device, a mobile Internet device (MID), an augmented reality (AR) / virtual reality (VR) device, a robot, a wearable device, an ultra-mobile personal computer (UMPC), a netbook or a personal digital assistant (PDA), etc. It can also be a server, a network attached storage (NAS), a personal computer (PC), a television (TV), a teller machine or a self-service machine, etc., and the embodiment of the present application does not specifically limit it.

[0180] The anomaly detection device in the embodiment of the present application may be a device having an operating system. The operating system may be an Android operating system, an iOS operating system, or other possible operating systems, which are not specifically limited in the embodiment of the present application.

[0181] The anomaly detection device provided in the embodiment of the present application can implement each process implemented in the above method embodiment. To avoid repetition, it will not be described here.

[0182] Alternatively, as Figure 9 As shown, an embodiment of the present application further provides an electronic device 1000, including a processor 1001 and a memory 1002, wherein the memory 1002 stores a program or instruction that can be run on the processor 1001, and when the program or instruction is executed by the processor 1001, the various steps of the above-mentioned abnormality detection method embodiment are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0183] It should be noted that the electronic devices in the embodiments of the present application include the mobile electronic devices and non-mobile electronic devices mentioned above.

[0184] Figure 10 A schematic diagram of the hardware structure of an electronic device implementing an embodiment of the present application.

[0185] The electronic device 100 includes but is not limited to components such as a radio frequency unit 101 , a network module 102 , an audio output unit 103 , an input unit 104 , a sensor 105 , a display unit 106 , a user input unit 107 , an interface unit 108 , a memory 109 , and a processor 110 .

[0186] Those skilled in the art will understand that the electronic device 100 may also include a power source (such as a battery) to power each component, and the power source may be logically connected to the processor 110 through a power management system, thereby implementing functions such as charging, discharging, and power consumption management through the power management system. Figure 10 The electronic device structure shown in the figure does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently, which will not be repeated here.

[0187] The processor 110 is configured to obtain user behavior benchmark information when first user behavior information is detected. The user behavior benchmark information is used to represent historical behavior information of the user using the electronic device.

[0188] The processor 110 is configured to determine a first deviation value and its corresponding abnormality level based on the first user behavior information and the user behavior benchmark information.

[0189] The processor 110 is configured to execute a security operation corresponding to the abnormality level based on the abnormality level.

[0190] Optionally, the processor 110 is further configured to, upon detecting the first user behavior information, pre-process and encrypt historical usage data before obtaining the user behavior baseline information. The historical usage data may include historical usage data of the electronic device, or historical usage data of the electronic device and historical usage data of other electronic devices associated with the electronic device. The historical usage data may include at least one of the following: screen touch events, key trigger events, application data, and location data. The processor 110 is configured to transmit the historical usage data to a secure area of ​​the electronic device via a secure transmission channel of the electronic device, where the secure area is a trusted execution environment within the electronic device.

[0191] The processor 110 is further configured to analyze the historical usage data transmitted by the transmission module within the secure area to generate user behavior benchmark information.

[0192] Optionally, the first user behavior information includes n first parameter values, and the user behavior benchmark information includes a mean value corresponding to each first parameter value and a standard deviation value corresponding to each first parameter value, where n is a positive integer. The processor 110 is specifically configured to: calculate a first difference value between each first parameter value and the corresponding mean value; calculate a deviation value corresponding to each first parameter value based on the first difference value and the corresponding standard deviation value corresponding to each first parameter value; and calculate a first deviation value and determine its corresponding abnormality level based on the deviation value and the corresponding weight value corresponding to each first parameter value.

[0193] Optionally, the above-mentioned processor 110 is specifically used to: when the first deviation value is greater than or equal to a first threshold and less than a second threshold, display an abnormal notification, and the abnormal notification is used to prompt the user that there is an abnormality in the electronic device; or, when the first deviation value is greater than or equal to the second threshold and less than a third threshold, perform identity authentication, and the identity authentication is used to authenticate the identity of the user; or, when the first deviation value is greater than or equal to the third threshold, lock the electronic device and send an abnormal notification to the account associated with the electronic device.

[0194] Optionally, the above-mentioned processor 110 is also used to adjust the second parameter value based on the abnormal feedback information received from the user after performing a security operation corresponding to the abnormal level based on the abnormal level corresponding to the first deviation value. The second parameter value includes a reference value for judging whether the user behavior information is abnormal and the abnormal level.

[0195] Optionally, the processor 110 is further configured to obtain the second user behavior information at a preset time interval. The processor 110 is further configured to update the user behavior benchmark information based on the second user behavior information.

[0196] An embodiment of the present application provides an electronic device that, upon detecting a user's current behavior information regarding the electronic device, can obtain the user's historical behavior information regarding the electronic device as a benchmark. The electronic device can then calculate the deviation between the current user behavior information and the historical user behavior information to detect the abnormality level of the user behavior in real time and perform security operations corresponding to the abnormality level. In this way, when abnormalities are found in the user behavior information, the electronic device can quickly take corresponding security measures based on the degree of the abnormality, thereby promptly preventing unauthorized access, protecting the user's privacy and data security, and improving the data security of the electronic device.

[0197] The electronic device provided in the embodiment of the present application can implement each process implemented in the above method embodiment and can achieve the same technical effect. To avoid repetition, it will not be repeated here. The beneficial effects of various implementations in this embodiment can be specifically referred to the beneficial effects of the corresponding implementations in the above method embodiment. To avoid repetition, it will not be repeated here.

[0198] It should be understood that in an embodiment of the present application, the input unit 104 may include a graphics processing unit (GPU) 1041 and a microphone 1042, and the graphics processor 1041 processes the image data of a static picture or video obtained by an image capture device (such as a camera) in a video capture mode or an image capture mode. The display unit 106 may include a display panel 1061, and the display panel 1061 may be configured in the form of a liquid crystal display, an organic light emitting diode, etc. The user input unit 107 includes a touch panel 1071 and at least one of other input devices 1072. The touch panel 1071 is also called a touch screen. The touch panel 1071 may include two parts: a touch detection device and a touch controller. Other input devices 1072 may include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, and an operating stick, which will not be repeated here.

[0199] The memory 109 can be used to store software programs and various data. The memory 109 may mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area may store an operating system, applications or instructions required for at least one function (such as a sound playback function, an image playback function, etc.). In addition, the memory 109 may include a volatile memory or a non-volatile memory, or the memory 109 may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDRSDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchronous link dynamic random access memory (SLDRAM), and a direct memory bus random access memory (DRRAM). The memory 109 in the embodiment of the present application includes but is not limited to these and any other suitable types of memory.

[0200] Processor 110 may include one or more processing units. Optionally, processor 110 integrates an application processor and a modem processor. The application processor primarily handles operations related to the operating system, user interface, and application programs, while the modem processor primarily processes wireless communication signals, such as a baseband processor. It is understood that the modem processor may not be integrated into processor 110.

[0201] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the above-mentioned abnormality detection method embodiment are implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0202] The processor is the processor in the electronic device described in the above embodiment. The readable storage medium includes a computer readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0203] An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned abnormality detection method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0204] It should be understood that the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.

[0205] An embodiment of the present application provides a computer program product, which is stored in a storage medium and is executed by at least one processor to implement the various processes of the above-mentioned anomaly detection method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.

[0206] It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the statement "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, it should be noted that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order shown or discussed, and may also include performing functions in a substantially simultaneous manner or in the opposite order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may also be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0207] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art can be embodied in the form of a computer software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), including a number of instructions for enabling a terminal (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in each embodiment of the present application.

[0208] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.

Claims

1. A method for detecting anomalies, characterized in that: include: When first user behavior information is detected, user behavior benchmark information is acquired, where the user behavior benchmark information is used to represent historical behavior information of the user using the electronic device; determining a first deviation value and a corresponding abnormality level based on the first user behavior information and the user behavior benchmark information; Based on the abnormality level, a security operation corresponding to the abnormality level is performed.

2. The method according to claim 1, characterized in that In the case where the first user behavior information is detected, before obtaining the user behavior benchmark information, the method further includes: Preprocessing and encrypting historical usage data, the historical usage data including historical usage data of the electronic device, or including historical usage data of the electronic device and historical usage data of other electronic devices associated with the electronic device; the historical usage data including at least one of the following: screen touch events, key trigger events, application data, and location data; Transmitting the historical usage data to a secure area of ​​the electronic device through a secure transmission channel of the electronic device, where the secure area is a trusted execution environment in the electronic device; In the secure area, the historical usage data is analyzed to generate the user behavior benchmark information.

3. The method according to claim 1, characterized in that The first user behavior information includes n first parameter values, and the user behavior benchmark information includes a mean value corresponding to each first parameter value and a standard deviation value corresponding to each first parameter value, where n is a positive integer; The determining, based on the first user behavior information and the user behavior benchmark information, a first deviation value and a corresponding abnormality level thereof includes: Calculating a first difference between each first parameter value and the corresponding mean; Calculating a deviation value corresponding to each first parameter value based on the first difference value and the corresponding standard deviation value corresponding to each first parameter value; Based on the deviation value and the corresponding weight value corresponding to each first parameter value, the first deviation value is calculated and the corresponding abnormality level is determined.

4. The method according to claim 1, wherein The performing a safety operation corresponding to the abnormality level based on the abnormality level corresponding to the first deviation value includes: When the first deviation value is greater than or equal to a first threshold value and less than a second threshold value, an abnormality notification is displayed, where the abnormality notification is used to prompt a user that an abnormality exists in the electronic device; or When the first deviation value is greater than or equal to the second threshold value and less than the third threshold value, performing identity authentication, wherein the identity authentication is used to authenticate the identity of the user; or When the first deviation value is greater than or equal to a third threshold, the electronic device is locked and an abnormality notification is sent to an account associated with the electronic device.

5. The method according to claim 1, characterized in that After executing a safety operation corresponding to the abnormality level based on the abnormality level corresponding to the first deviation value, the method further includes: In the case of receiving abnormal feedback information from the user, the second parameter value is adjusted based on the abnormal feedback information, where the second parameter value includes a reference value for determining whether the user behavior information is abnormal and the abnormality level.

6. An abnormality detection device, characterized in that: include: Acquisition module, determination module and execution module; The acquisition module is configured to acquire user behavior benchmark information when first user behavior information is detected, wherein the user behavior benchmark information is used to represent the user's historical behavior information of using the electronic device; The determining module is configured to determine a first deviation value and its corresponding abnormality level based on the first user behavior information and the user behavior benchmark information acquired by the acquiring module; The execution module is configured to execute a security operation corresponding to the abnormality level based on the abnormality level determined by the determination module.

7. The device according to claim 6, characterized in that The anomaly detection device further includes a transmission module; The execution module is further configured to, when the first user behavior information is detected, pre-process and encrypt historical usage data before the acquisition module acquires the user behavior benchmark information, the historical usage data including historical usage data of the electronic device, or including historical usage data of the electronic device and historical usage data of other electronic devices associated with the electronic device; the historical usage data including at least one of the following: screen touch events, key trigger events, application data, and location data; The transmission module is configured to transmit the historical usage data processed by the execution module to a secure area of ​​the electronic device through a secure transmission channel of the electronic device, wherein the secure area is a trusted execution environment in the electronic device; The execution module is further configured to analyze the historical usage data transmitted by the transmission module within the secure area to generate the user behavior benchmark information.

8. The device according to claim 6, characterized in that The first user behavior information includes n first parameter values, and the user behavior benchmark information includes a mean value corresponding to each first parameter value and a standard deviation value corresponding to each first parameter value, where n is a positive integer; The determining module is specifically configured to: Calculating a first difference between each first parameter value and the corresponding mean; Calculating a deviation value corresponding to each first parameter value based on the first difference value and the corresponding standard deviation value corresponding to each first parameter value; Based on the deviation value and the corresponding weight value corresponding to each first parameter value, the first deviation value is calculated and the corresponding abnormality level is determined.

9. The device according to claim 6, characterized in that The execution module is specifically used to: When the first deviation value is greater than or equal to a first threshold value and less than a second threshold value, displaying an abnormality notification, wherein the abnormality notification is used to prompt a user that an abnormality exists in the electronic device; or, When the first deviation value is greater than or equal to the second threshold value and less than the third threshold value, performing identity authentication, wherein the identity authentication is used to authenticate the identity of the user; or When the first deviation value is greater than or equal to a third threshold, the electronic device is locked and an abnormality notification is sent to an account associated with the electronic device.

10. The device according to claim 6, characterized in that The execution module is also used to adjust the second parameter value based on the abnormality level corresponding to the first deviation value after executing the security operation corresponding to the abnormality level, upon receiving abnormal feedback information from the user, the second parameter value includes a reference value for determining whether the user behavior information is abnormal and the abnormality level.

Citation Information

Cited By

  • Remote screen locking control method and system

    CN121125711A