A generative adversarial-driven intelligent security defense method and system
By employing a generative adversarial-driven intelligent security defense approach, and combining MoE and GPT-4 architectures with dual-agent reinforcement learning and dynamic knowledge graphs, this approach addresses the data layer, attack-defense adversarial, and decision-making layer issues in network security defense, achieving efficient threat identification and response.
Patent Information
- Application Number
- CN202510915186.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2025-03-27
- Filing Date
- 2025-07-03
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2045-07-03
AI Technical Summary
The existing network security defense system faces challenges such as static defense mechanisms being unable to cope with dynamic attacks, low efficiency in heterogeneous data fusion, insufficient timeliness of intelligent decision-making, and lagging response of traditional PPDR models to new threats. It also suffers from obvious defects in the data layer, limitations in attack and defense confrontation, and bottlenecks in the decision-making layer.
We adopt a generative adversarial-driven intelligent security defense method, dynamically allocate computing power through the MoE architecture, introduce LLM with fine-tuning in the security domain to construct a semantic similarity matrix, deploy a GPT-4 architecture attack generator, build a dual-agent adversarial training environment, upgrade the dynamic knowledge graph of the cognitive decision layer, and deploy a multi-agent cluster for collaborative response.
It improves the distillation efficiency of heterogeneous data, enhances the accuracy of unstructured threat intelligence parsing, strengthens adversarial training efficiency, realizes real-time threat simulation and encrypted traffic parsing capabilities, and overcomes data layer defects, attack and defense adversarial limitations, and decision-making bottlenecks.
Smart Images

Figure CN120602194B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cybersecurity technology, and in particular to a generative adversarial-driven intelligent security defense method and system. Background Technology
[0002] The current cybersecurity defense system faces three core challenges: static defense mechanisms are ill-equipped to handle dynamic attacks, heterogeneous data fusion is inefficient, and intelligent decision-making lacks timeliness. Traditional PPDR (Policy-Protection-Detection-Response) security models rely on static rule bases and manual analysis, resulting in delayed responses to emerging threats such as APT attacks and zero-day vulnerabilities. Existing technologies suffer from the following shortcomings: 1. Data layer deficiencies: Association analysis of multi-source heterogeneous data relies on manual intervention, making it difficult to capture semantic relationships in unstructured text. Existing hybrid expert models lack dynamic resource allocation in the security domain, leading to wasted computing power. 2. Limitations in attack and defense: Traditional attack simulation techniques, based on known vulnerability databases, cannot generate attack chains with evolutionary capabilities. Defense strategy optimization lacks real-time adversarial training, and detection models are easily deceived by adversarial examples. 3. Decision-making layer bottlenecks: Threat knowledge graph updates are delayed, and intelligent agent collaboration mechanisms are lacking.
[0003] Therefore, there is an urgent need for a targeted generative adversarial-driven intelligent security defense method and system. Summary of the Invention
[0004] The purpose of this invention is to provide a generative adversarial driven intelligent security defense method and system, which overcomes the problems of data layer defects, attack and defense adversarial limitations and decision layer bottlenecks in the prior art.
[0005] In a first aspect, this application provides a generative adversarial-driven intelligent security defense method, the method comprising:
[0006] Step 1: Reconstruct the data fusion layer, employing a hybrid expert (MoE) architecture to drive the extraction of multimodal features, including:
[0007] The data processing engine is built using the MoE architecture, which involves defining a gating network and obtaining multiple expert models for different data sources such as network traffic, logs, and asset mapping. The gating network is multiplied by each of the multiple expert models and then summed to obtain the constructed data processing engine, thereby realizing dynamic allocation of computing power.
[0008] By introducing a security-adjusted LLM, threat description vectors are generated through comparative learning, a semantic similarity matrix is constructed, cross-modal relationships are identified, and semantic enhancement is performed on unstructured text, including vulnerability descriptions and threat intelligence.
[0009] The data processing engine described above is used to extract multimodal features from semantically enhanced unstructured text;
[0010] Step two, construct a dynamic attack and defense layer to obtain a generative adversarial security engine, including:
[0011] Based on the GPT-4 architecture, simulate the APT attack chain, generate attack scripts containing vulnerability exploitation chains, deploy the attack generator, and realize intelligent expansion of the attack surface;
[0012] Construct a dual-agent adversarial training environment, define the maximum penetration success rate to obtain the attacker agent, define the minimum detection latency to obtain the defender agent, and implement a defense reinforcement learning framework.
[0013] The generative adversarial security engine is trained.
[0014] Step 3: Construct a dynamic knowledge graph system to upgrade the cognitive decision-making layer, including:
[0015] A temporal graph neural network is used to model attack evolution and construct a real-time threat graph. The dynamic adjacency matrix involved in the attack evolution modeling process is updated in real time with the attack behavior.
[0016] Deploy multiple functional intelligent agent clusters and establish an intelligent agent collaborative response mechanism. The multiple functional intelligent agent clusters include, but are not limited to, the following: vulnerability hunters, used for zero-day vulnerability pattern recognition; traffic forensics, used for deep analysis of encrypted traffic; and attack chain deduction, used for APT attack path prediction.
[0017] Secondly, this application provides a generative adversarial driven intelligent security defense system, the system comprising: a data fusion layer module, a dynamic attack and defense layer module, and a cognitive decision-making layer module;
[0018] The data fusion layer module is used to reconstruct the data fusion layer and employs a hybrid expert (MoE) architecture to drive the extraction of multimodal features, including:
[0019] The data processing subunit is used to build a data processing engine using the MoE architecture. Specifically, it defines a gating network and obtains multiple expert models for different data sources such as network traffic, logs, and asset mapping. The gating network is multiplied by the multiple expert models and then summed to obtain the constructed data processing engine, thereby realizing dynamic allocation of computing power.
[0020] The semantic enhancement subunit is used to introduce a security-domain fine-tuned LLM, generate threat description vectors through contrastive learning, construct a semantic similarity matrix, identify cross-modal relationships, and perform semantic enhancement on unstructured text, which includes vulnerability descriptions and threat intelligence.
[0021] The feature extraction subunit is used to extract multimodal features from the semantically enhanced unstructured text using the data processing engine.
[0022] The dynamic attack and defense layer module is used to construct a dynamic attack and defense layer to obtain a generative adversarial security engine, including:
[0023] The attack surface expansion subunit is used to simulate APT attack chains based on the GPT-4 architecture, generate attack scripts containing exploit chains, deploy attack generators, and achieve intelligent expansion of the attack surface.
[0024] The defense reinforcement subunit is used to build a dual-agent adversarial training environment. It defines the maximum penetration success rate to obtain the attacker agent and the minimum detection latency to obtain the defender agent. This is a defense reinforcement learning framework.
[0025] The training subunit is used to train a generative adversarial security engine.
[0026] The cognitive decision-making layer module is used to construct a dynamic knowledge graph system and upgrade the cognitive decision-making layer, including:
[0027] The graph construction subunit is used to model attack evolution using a temporal graph neural network and construct a real-time threat graph. The dynamic adjacency matrix involved in modeling attack evolution is updated in real time with the attack behavior.
[0028] The collaborative response subunit is used to deploy multiple functional intelligent agent clusters and establish an intelligent agent collaborative response mechanism. The multiple functional intelligent agent clusters include, but are not limited to, the following: vulnerability hunter, for zero-day vulnerability pattern recognition; traffic forensics, for deep analysis of encrypted traffic; and attack chain deduction, for APT attack path prediction.
[0029] Thirdly, this application provides a generative adversarial-driven intelligent security defense system, the system comprising a processor and a memory:
[0030] The memory is used to store program code and transmit the program code to the processor;
[0031] The processor is configured to execute any one of the four possible methods of the first aspect according to the instructions in the program code.
[0032] Fourthly, this application provides a computer-readable storage medium for storing program code, which is executed by a processor to implement any one of the four possible methods of the first aspect.
[0033] Beneficial effects
[0034] This invention provides a generative adversarial-driven intelligent security defense method and system, which innovatively solves the challenges of dynamic network security defense through a three-layer architecture: First, a data fusion layer is reconstructed by adopting a multimodal feature extraction engine driven by the MoE architecture, dynamically allocating computing resources to multiple expert models to improve the efficiency of heterogeneous data distillation; it also introduces LLM fine-tuned in the security domain to construct a cross-modal semantic similarity matrix, improving the accuracy of unstructured threat intelligence parsing; second, a dynamic attack and defense layer is constructed by deploying a GPT-4 architecture attack generator to simulate the generation of multi-stage APT attack chains; a dual-agent reinforcement learning architecture is designed to improve the efficiency of adversarial training; third, a cognitive decision layer is upgraded by constructing a dynamic threat graph based on a temporal graph neural network and updating the adjacency matrix in real time; and multiple agent clusters are deployed to improve the ability to parse encrypted traffic and block attacks, overcoming the data layer defects, attack and defense adversarial limitations, and decision layer bottlenecks of existing technologies.
[0035] The method and system of the present invention have the following advantages and effects:
[0036] Deploy a generative attack simulator and a dual-agent reinforcement learning framework to simultaneously generate attack scripts and defense strategies using generative adversarial networks;
[0037] Construct dynamic knowledge graphs for threat simulation;
[0038] Schedule a cluster of multiple intelligent agents to execute coordinated defense actions. Attached Figure Description
[0039] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, those skilled in the art can obtain other drawings based on these drawings without creative effort.
[0040] Figure 1 This is a flowchart of the method of the present invention;
[0041] Figure 2 This is a system architecture diagram of the present invention. Detailed Implementation
[0042] The preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings, so that the advantages and features of the present invention can be more easily understood by those skilled in the art, thereby providing a clearer and more explicit definition of the scope of protection of the present invention.
[0043] Figure 1 A flowchart of the generative adversarial-driven intelligent security defense method provided in this application is provided, the method comprising:
[0044] Step 1: Reconstruct the data fusion layer, employing a hybrid expert (MoE) architecture to drive the extraction of multimodal features, including:
[0045] The data processing engine is built using the MoE architecture, which involves defining a gating network and obtaining multiple expert models for different data sources such as network traffic, logs, and asset mapping. The gating network is multiplied by each of the multiple expert models and then summed to obtain the constructed data processing engine, thereby realizing dynamic allocation of computing power.
[0046] By introducing a security-adjusted LLM, threat description vectors are generated through comparative learning, a semantic similarity matrix is constructed, cross-modal relationships are identified, and semantic enhancement is performed on unstructured text, including vulnerability descriptions and threat intelligence.
[0047] Here, LLM refers to large-scale language models in the field of artificial intelligence. They learn language rules through pre-training on massive amounts of text data, generate natural language text, and have a self-attention mechanism to capture long-distance semantic relationships.
[0048] The data processing engine described above is used to extract multimodal features from semantically enhanced unstructured text;
[0049] Step two, construct a dynamic attack and defense layer to obtain a generative adversarial security engine, including:
[0050] Based on the GPT-4 architecture, simulate the APT attack chain, generate attack scripts containing vulnerability exploitation chains, deploy the attack generator, and realize intelligent expansion of the attack surface;
[0051] Construct a dual-agent adversarial training environment, define the maximum penetration success rate to obtain the attacker agent, define the minimum detection latency to obtain the defender agent, and implement a defense reinforcement learning framework.
[0052] The generative adversarial security engine is trained.
[0053] Step 3: Construct a dynamic knowledge graph system to upgrade the cognitive decision-making layer, including:
[0054] A temporal graph neural network is used to model attack evolution and construct a real-time threat graph. The dynamic adjacency matrix involved in the attack evolution modeling process is updated in real time with the attack behavior.
[0055] The dynamic adjacency matrix here is updated in real time according to the attack behavior, and the nodes contain entities such as IP, vulnerability, and attack method; the attack path evolution prediction is realized through graph convolution operation;
[0056] The process of building a knowledge graph here may also include: defining various entity categories, characterizing the classification system of assets at different levels, and describing the attributes and characteristics of assets; using the Cypher query language to store data and building corresponding nodes and relationships within the knowledge graph; verifying the completeness, consistency, and accuracy of the knowledge graph through a series of standards and methods, identifying and correcting it; and, according to business needs, using the knowledge graph to support various scenarios such as decision-making, risk assessment, and threat analysis, regularly updating the knowledge graph data, and continuously monitoring and optimizing the system.
[0057] Deploy multiple functional intelligent agent clusters and establish an intelligent agent collaborative response mechanism. The multiple functional intelligent agent clusters include, but are not limited to, the following: vulnerability hunters, used for zero-day vulnerability pattern recognition; traffic forensics, used for deep analysis of encrypted traffic; and attack chain deduction, used for APT attack path prediction.
[0058] The various intelligent agents here coordinate strategies through a shared memory pool, supporting real-time blocking of phishing attacks such as AI face-swapping.
[0059] Simultaneously, the cognitive decision-making layer can also include decisions on defense and response strategies, specifically including:
[0060] The interaction correlation and attribute similarity are analyzed, the data after algorithm processing is labeled, the target assets to be evaluated are classified based on asset importance, different weight values are defined for interaction correlation and attribute similarity for different types, a decision tree is constructed, and the dependency relationship value between core assets and non-core assets is calculated.
[0061] By comparing the calculated dependency values with the approved threshold range, a qualitative assessment of the strength, level, and intensity of the dependency is obtained, thus completing the construction of the analysis and identification model.
[0062] By embedding digital asset association knowledge graphs and reasoning rules into the underlying digital asset association basic library, dynamic and comprehensive digital asset ledger management is achieved. The results of intelligent recommendation of asset relationship identification are output to the linkable security capabilities and security hub, providing important asset data for vulnerability detection, threat assessment, and event impact assessment, supporting dynamic management of security risks and assisting security decision-making.
[0063] In some preferred embodiments, the MoE architecture satisfies the following: the expert model includes three types of dedicated models: traffic behavior analysis, log semantic parsing, and asset vulnerability assessment; the gated network adopts a dynamic resource allocation algorithm to automatically adjust the activation ratio of the expert model according to the data flow throughput.
[0064] In some preferred embodiments, the semantic enhancement employs a security-tuned LLM model to construct a cross-modal semantic similarity matrix, supporting real-time semantic association of unstructured texts such as CVE vulnerability descriptions and dark web threat intelligence.
[0065] In some preferred embodiments, the dual-agent reward function is designed as follows: the attacker agent optimizes the target to simulate the phased gains of an APT attack; the defender agent has a loss function that balances detection timeliness and false alarm rate.
[0066] In addition, it can integrate secure electronic fence technology, use forward confidentiality protocol for key management, generate temporary keys for each session, and dynamically encrypt face verification data during transmission.
[0067] Figure 2 The architecture diagram of the generative adversarial driven intelligent security defense system provided in this application includes: a data fusion layer module, a dynamic attack and defense layer module, and a cognitive decision layer module;
[0068] The data fusion layer module is used to reconstruct the data fusion layer and employs a hybrid expert (MoE) architecture to drive the extraction of multimodal features, including:
[0069] The data processing subunit is used to build a data processing engine using the MoE architecture. Specifically, it defines a gating network and obtains multiple expert models for different data sources such as network traffic, logs, and asset mapping. The gating network is multiplied by the multiple expert models and then summed to obtain the constructed data processing engine, thereby realizing dynamic allocation of computing power.
[0070] The semantic enhancement subunit is used to introduce a security-domain fine-tuned LLM, generate threat description vectors through contrastive learning, construct a semantic similarity matrix, identify cross-modal relationships, and perform semantic enhancement on unstructured text, which includes vulnerability descriptions and threat intelligence.
[0071] The feature extraction subunit is used to extract multimodal features from the semantically enhanced unstructured text using the data processing engine.
[0072] The dynamic attack and defense layer module is used to construct a dynamic attack and defense layer to obtain a generative adversarial security engine, including:
[0073] The attack surface expansion subunit is used to simulate APT attack chains based on the GPT-4 architecture, generate attack scripts containing exploit chains, deploy attack generators, and achieve intelligent expansion of the attack surface.
[0074] The defense reinforcement subunit is used to build a dual-agent adversarial training environment. It defines the maximum penetration success rate to obtain the attacker agent and the minimum detection latency to obtain the defender agent. This is a defense reinforcement learning framework.
[0075] The training subunit is used to train a generative adversarial security engine.
[0076] The cognitive decision-making layer module is used to construct a dynamic knowledge graph system and upgrade the cognitive decision-making layer, including:
[0077] The graph construction subunit is used to model attack evolution using a temporal graph neural network and construct a real-time threat graph. The dynamic adjacency matrix involved in modeling attack evolution is updated in real time with the attack behavior.
[0078] The collaborative response subunit is used to deploy multiple functional intelligent agent clusters and establish an intelligent agent collaborative response mechanism. The multiple functional intelligent agent clusters include, but are not limited to, the following: vulnerability hunter, for zero-day vulnerability pattern recognition; traffic forensics, for deep analysis of encrypted traffic; and attack chain deduction, for APT attack path prediction.
[0079] This application provides a generative adversarial-driven intelligent security defense system, the system comprising: a processor and a memory.
[0080] The memory is used to store program code and transmit the program code to the processor;
[0081] The processor is configured to execute the method described in any one of the embodiments of the first aspect according to the instructions in the program code.
[0082] This application provides a computer-readable storage medium for storing program code, which is executed by a processor to implement the method described in any one of the embodiments of the first aspect.
[0083] In a specific implementation, the present invention also provides a computer storage medium, wherein the computer storage medium may store a program, and the program, when executed, may include some or all of the steps in the various embodiments of the present invention. The storage medium may be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), etc.
[0084] Those skilled in the art will clearly understand that the techniques in the embodiments of the present invention can be implemented using software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solutions in the embodiments of the present invention, or the parts that contribute to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments or certain parts of the embodiments of the present invention.
[0085] The same or similar parts between the various embodiments in this specification can be referred to mutually. In particular, the embodiments are basically similar to the method embodiments, so the description is relatively simple, and the relevant parts can be referred to the description in the method embodiments.
[0086] The embodiments of the present invention described above do not constitute a limitation on the scope of protection of the present invention.
Claims
1. A method for generating an intelligent security defense driven by generative adversarial, characterized in that, The method comprises: Step 1, reconstructing the data fusion layer, using a mixed expert (MoE) architecture to drive the extraction of multi-modal features, including: Using the MoE architecture to build a data processing engine, i.e., defining a gating network, obtaining multiple expert models for network traffic, logs, and asset mapping of different data sources, multiplying the gating network with the multiple expert models respectively and then summing them up to obtain the constructed data processing engine, thereby realizing dynamic allocation of computing power; Introducing a security field fine-tuned LLM to generate threat description vectors through contrastive learning, construct a semantic similarity matrix, identify cross-modal correlation, and perform semantic enhancement on unstructured text, including vulnerability descriptions and threat intelligence; Applying the data processing engine to extract multi-modal features from the semantically enhanced unstructured text; Step 2, constructing a dynamic attack and defense layer to obtain a generative adversarial security engine, including: Simulating an APT attack chain based on the GPT-4 architecture to generate an attack script containing a vulnerability exploitation chain, deploying an attack generator to achieve intelligent expansion of attack surfaces; Building a double-agent adversarial training environment, defining a maximum penetration success rate to obtain an attacker Agent, and defining a minimum detection delay to obtain a defender Agent, and a defense reinforcement learning framework; Training the generative adversarial security engine; Step 3, constructing a dynamic knowledge graph system to upgrade the cognitive decision-making layer, including: Using a time series graph neural network to model attack evolution and construct a real-time threat graph, wherein the dynamic adjacency matrix involved in the modeling of attack evolution is updated in real time with attack behavior; Deploying multiple functional agent clusters to establish an agent collaborative response mechanism, including but not limited to the following: vulnerability hunters for 0day vulnerability pattern recognition; traffic forensic experts for encrypted traffic deep analysis; attack chain deduction for APT attack path prediction.
2. The method of claim 1, wherein: The MoE architecture satisfies: the expert models include traffic behavior analysis, log semantic analysis, and asset vulnerability assessment; the gating network uses a dynamic resource allocation algorithm to automatically adjust the activation ratio of the expert models based on data flow throughput.
3. The method of claim 1, wherein: The semantic enhancement uses a security fine-tuned LLM model to construct a cross-modal semantic similarity matrix, supporting real-time semantic association of unstructured text such as CVE vulnerability descriptions and dark web threat intelligence.
4. The method according to any of claims 2 or 3, characterized in that: Double-agent reward function design: the attacker Agent optimization goal simulates the phased benefits of APT attacks; the defender Agent loss function balances detection timeliness and false positive rate.
5. A generative adversarial driven intelligent security defense system, characterized in that, The system comprises a data fusion layer module, a dynamic attack and defense layer module, and a cognitive decision-making layer module; The data fusion layer module is configured to reconstruct the data fusion layer, extract multi-modal features using a mixed expert (MoE) architecture, including: A data processing subunit is configured to use the MoE architecture to build a data processing engine, i.e., define a gating network, obtain multiple expert models for network traffic, logs, and asset mapping of different data sources, multiply the gating network with the multiple expert models respectively and then sum them up to obtain the constructed data processing engine, thereby realizing dynamic allocation of computing power; A semantic enhancement subunit is configured to introduce a fine-tuned LLM in a security field, generate a threat description vector through contrastive learning, construct a semantic similarity matrix, identify a cross-modal correlation, and perform semantic enhancement on unstructured text, including vulnerability descriptions and threat intelligence. A feature extraction subunit is configured to extract multi-modal features from the unstructured text after semantic enhancement by applying the data processing engine. The dynamic attack-defense layer module is configured to construct a dynamic attack-defense layer to obtain a generative adversarial security engine, including: An attack surface expansion subunit is configured to simulate an APT attack chain based on a GPT-4 architecture, generate an attack script containing a vulnerability exploit chain, deploy an attack generator, and implement intelligent expansion of an attack surface. A defense reinforcement subunit is configured to construct a double-agent adversarial training environment, define a maximum penetration success rate to obtain an attacker agent, and define a minimum detection time delay to obtain a defender agent, and a defense reinforcement learning framework. A training subunit is configured to train the generative adversarial security engine. The cognitive decision-making layer module is configured to construct a dynamic knowledge graph system and upgrade the cognitive decision-making layer, including: A graph construction subunit is configured to model attack evolution using a time-series graph neural network and construct a real-time threat graph, wherein a dynamic adjacency matrix involved in the modeling of attack evolution is updated in real time according to attack behavior. A collaborative response subunit is configured to deploy a plurality of functional agent clusters, including but not limited to the following: a vulnerability hunter for 0day vulnerability pattern recognition, a traffic forensic expert for encrypted traffic deep analysis, and an attack chain deduction for APT attack path prediction, and establish an agent collaborative response mechanism.
6. A generative adversarial driven intelligent security defense system, characterized in that, The system includes a processor and a memory: The memory is configured to store program code and transmit the program code to the processor. The processor is configured to execute instructions in the program code to implement the method of any one of claims 1-4.
7. A computer-readable storage medium, characterized in that, The computer-readable storage medium is configured to store program code for being executed by a processor to implement the method of any one of claims 1-4.
Citation Information
Patent Citations
Artificial intelligence network security method and system
CN117201085A
Secure communication platform for a cybersecurity system
US20190260804A1