False user identification method, system and device for mobile application and medium

By generating a multi-dimensional interactive feature matrix through multi-sensor fusion and combining deep learning and hidden Markov model to identify fake users, the fake user identification method solves the identification difficulty problem of traditional methods when facing the upgrade of hacker technology, realizes efficient identification and prevention of fake users, and improves the security of mobile applications and user experience.

CN120687971APending Publication Date: 2025-09-23广州三七极耀网络科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510686901.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-09-23

AI Technical Summary

Technical Problem

Traditional fake user identification methods based on IP addresses and device information are powerless in the face of increasingly advanced hacker techniques, resulting in fake users running rampant in the mobile application ecosystem, affecting game fairness, the healthy development of the mobile shopping market and user safety.

Method used

Through the multi-sensor fusion architecture of mobile terminals, a multi-dimensional interactive feature matrix is ​​generated. The dual-channel adversarial generative network and the residual attention dual-stream network are used to perform comparative analysis of sample streams. A hybrid architecture of spatiotemporal graph convolution and LSTM is combined to form a composite fingerprint encoding. A risk entropy value calculation model of the hidden Markov model is established, and a hierarchical response mechanism is triggered to block abnormal conversations.

Benefits of technology

Effectively identify and prevent fake users generated by simulating IP addresses and device information, improve the accuracy and reliability of identification, protect the mobile application environment and user experience, and prevent fake users from damaging the ecosystem.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120687971A_ABST
    Figure CN120687971A_ABST
Patent Text Reader

Abstract

The invention discloses a false user identification method, system and device for a mobile application, and a medium, and the method specifically comprises the steps: generating an adversarial disturbance mode with boundary constraint through employing a dual-channel adversarial generative network based on a multi-dimensional interaction feature matrix, carrying out the comparison and analysis of a sample flow through employing a residual attention double-flow network, and carrying out the recognition of a false user. Outputting an abnormal mode identification parameter; taking the abnormal mode recognition parameters and the original data as input, and performing multi-modal fusion through a space-time diagram convolution and LSTM hybrid architecture to form a composite fingerprint code; establishing a risk entropy calculation model based on a hidden Markov model according to the dynamic evolution of the composite fingerprint code; and when the risk entropy value output by the risk entropy value calculation model exceeds an adaptive threshold value, triggering a hierarchical response mechanism including chaotic trajectory verification and multi-modal biometric authentication. According to the invention, the false user generated by simulating the IP address and the equipment information can be effectively identified and prevented, so that the environment of the mobile application is protected, and the user experience is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Internet technology, and in particular to a method, system, device and medium for identifying false users of mobile applications. Background Art

[0002] With the rapid development of mobile internet technology and the explosive growth of the mobile application industry, a wide range of mobile applications have sprung up like mushrooms after rain, covering a wide range of fields, including gaming, social networking, shopping, and finance. However, as the mobile application market flourishes, the problem of identifying fake users remains a persistent problem, seriously plaguing game operators, mobile shopping app providers, and other mobile application participants, becoming a key obstacle to the healthy development of the mobile application industry.

[0003] Traditionally, identifying fake users relies primarily on building a system of rules based on the user's IP address and device information. As a crucial identifier in network communications, the IP address was once considered a key basis for determining user authenticity. By analyzing information such as the source, geographic location, and frequency of use of the IP address, attempts are made to identify anomalous IP addresses and, in turn, determine whether there are fake users. Device information, such as the device model, operating system version, and unique device identifier, is also incorporated into the identification rules. Based on this information, a series of rules are developed, such as limiting large-scale operations from the same IP address or device within a short period of time and detecting abnormal simulated device behavior.

[0004] However, with the rapid advancement of network technology, hacker techniques are constantly upgrading and evolving, and traditional identification methods are facing unprecedented challenges. Hackers, with their sophisticated technical skills, are adept at employing various techniques to impersonate IP addresses and device information. For example, they can use proxy servers to hide their true IP addresses. By constantly switching between proxy servers, each IP address appears normal and independent, easily circumventing IP address-based identification rules. The widespread use of virtual machine technology has enabled hackers to simulate multiple virtual devices on a single physical device, each with its own unique device information, rendering device-based identification methods ineffective. The misuse of these techniques has rendered traditional identification methods based on IP addresses and device information increasingly ineffective. Game operators and app providers are groping in the dark, struggling to accurately identify fake users, allowing fake users to run rampant in the mobile app ecosystem.

[0005] The presence of fake users has had a significant negative impact on the mobile app ecosystem in many ways. In the gaming sector, the phenomenon of fake users hogging game resources is extremely common. They use automated scripts or malicious programs to frequently log in and create numerous accounts, consuming significant server bandwidth. When server bandwidth is excessively occupied by fake users, real users experience lag and delays when logging in and playing, significantly compromising their gaming experience. Furthermore, fake users may also obtain large quantities of in-game items through hacks and other means, disrupting the in-game economy and fair competition. Real players are often at a disadvantage when facing fake users with large quantities of illicit items, significantly undermining the fairness of the game. Over time, this situation erodes player trust in the game, leading to players leaving the game in droves, which in turn deteriorates the gaming ecosystem and severely impacts the revenue of game operators, while operating costs continue to rise due to the presence of fake users.

[0006] In mobile shopping apps, fake users engaging in fraudulent order manipulation has become a persistent problem. Driven by profit, these fraudulent users fabricate transaction records to artificially inflate product sales and positive reviews. They use software to simulate user purchasing behavior and generate fake orders in bulk, inflating product sales figures. They also fabricate false reviews, offering unrealistic praise for products and misleading legitimate consumers. When browsing products, consumers are often misled by these fabricated sales figures and positive reviews, leading them to make poor purchasing decisions. If they purchase products of substandard quality or that do not meet their expectations, they not only suffer financial losses but also lose trust in the mobile shopping platform as a whole. For legitimate businesses, fraudulent users' fraudulent order manipulation disrupts the normal competitive environment. Legitimate businesses must invest significant time and effort in authentic marketing and promotion, while fraudulent users use illicit means to rapidly elevate product rankings, making it difficult for legitimate businesses to receive fair exposure and weakening their market competitiveness. This long-term situation severely harms the interests of legitimate businesses and threatens the healthy development of the entire mobile shopping market. Consumer confidence declines, market vitality weakens, and the industry enters a vicious cycle.

[0007] Furthermore, fake users can serve as springboards for cyberattacks. Some fake user accounts can be exploited by hackers to launch cyberattacks, further threatening the security of mobile apps and user privacy. By controlling fake user accounts, hackers can obtain sensitive information from other users, such as account passwords and payment details, causing significant losses to users.

[0008] In summary, traditional methods for identifying fake users based on IP addresses and device information are no longer effective against increasingly sophisticated hacker techniques. The negative impact of fake users on the mobile app ecosystem is widespread and far-reaching, not only harming the interests of participants like game operators and mobile shopping app providers, but also undermining the healthy development of the entire mobile app industry. Summary of the Invention

[0009] The purpose of the present invention is to provide a method, system, device and medium for identifying false users of mobile applications, which can effectively identify and prevent false users generated by simulating IP addresses and device information, thereby protecting the environment of mobile applications and improving user experience, so as to solve at least one of the above-mentioned problems of the prior art.

[0010] In a first aspect, the present invention provides a method for identifying fake users of mobile applications, the method specifically comprising: Through the multi-sensor fusion architecture of the mobile terminal, the spatiotemporal coupling acquisition of the capacitive touch layer and the inertial measurement unit is synchronously implemented to generate a multi-dimensional interaction feature matrix, which includes the pressure gradient tensor, touch differential geometry, multi-finger cooperative phase and device posture compensation; Based on the multi-dimensional interactive feature matrix, a dual-channel adversarial generative network is used to generate adversarial perturbation patterns with boundary constraints. The residual attention two-stream network is used to perform comparative analysis of sample streams and output abnormal pattern recognition parameters in the adversarial feature space. Taking abnormal pattern recognition parameters and raw data as input, multimodal fusion is performed through a hybrid architecture of spatiotemporal graph convolution and LSTM to form a composite fingerprint code that includes time-varying behavioral characteristics and device physical properties. According to the dynamic evolution of composite fingerprint coding, a risk entropy value calculation model based on the hidden Markov model is established; When the risk entropy value output by the risk entropy calculation model exceeds the adaptive threshold, a hierarchical response mechanism including chaotic trajectory verification and multimodal biometric authentication is triggered, and tactile feedback perturbation is applied to block abnormal conversations.

[0011] In a second aspect, the present invention provides a false user identification system for mobile applications, the system specifically comprising: A first identification module is configured to synchronously implement spatiotemporal coupled acquisition of the capacitive touch layer and the inertial measurement unit through a multi-sensor fusion architecture of the mobile terminal to generate a multi-dimensional interaction feature matrix, wherein the multi-dimensional interaction feature matrix includes a pressure gradient tensor, touch differential geometry, multi-finger cooperative phase, and device posture compensation; The second recognition module is used to generate adversarial perturbation patterns with boundary constraints based on a multi-dimensional interactive feature matrix using a dual-channel adversarial generative network, perform sample stream comparative analysis using a residual attention two-stream network, and output abnormal pattern recognition parameters in the adversarial feature space; The third recognition module is used to take the abnormal pattern recognition parameters and raw data as input, and perform multimodal fusion through a hybrid architecture of spatiotemporal graph convolution and LSTM to form a composite fingerprint code that includes time-varying behavioral characteristics and device physical properties; The fourth identification module is used to establish a risk entropy value calculation model based on the hidden Markov model according to the dynamic evolution of the composite fingerprint code; The fifth identification module is used to trigger a hierarchical response mechanism including chaotic trajectory verification and multimodal biometric authentication when the risk entropy value output by the risk entropy value calculation model exceeds an adaptive threshold, and apply tactile feedback perturbation to block abnormal conversations.

[0012] In a third aspect, the present invention provides a computer device comprising: a memory and a processor and a computer program stored in the memory, wherein when the computer program is executed on the processor, the false user identification method for a mobile application as described in any one of the above methods is implemented.

[0013] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the method for identifying false users of mobile applications as described in any one of the above methods is implemented.

[0014] Compared with the prior art, the present invention has at least one of the following technical effects: 1. The present invention can effectively identify and prevent false users generated by simulating IP addresses and device information, thereby protecting the mobile application environment and improving user experience.

[0015] 2. The multi-dimensional feature extraction method of the present invention can comprehensively capture the user's interactive behavior and device status information. Compared with the traditional method that only relies on IP addresses and device information, it greatly increases the information dimension of false user identification and improves the accuracy of identification.

[0016] 3. The present invention can deeply explore abnormal patterns in user behavior and effectively distinguish real users from fake users, especially those fake users who try to evade detection by simulating normal behavior, with stronger recognition capabilities.

[0017] 4. The present invention can more comprehensively characterize the user's behavioral characteristics and device attributes, making it difficult for fake users to disguise themselves through simple simulation means, further improving the reliability of identification.

[0018] 5. By dynamically monitoring the changes in risk entropy values, the present invention can timely discover potential false user behaviors and take corresponding measures to effectively prevent false users from damaging the mobile application ecosystem.

[0019] 6. The present invention can adopt different verification methods according to the degree of risk, thereby improving the efficiency and accuracy of recognition. At the same time, the application of tactile feedback disturbance can timely block abnormal conversations and protect the security and stable operation of mobile applications.

[0020] 7. The continuous model optimization and update mechanism of the present invention can enable the recognition system to continuously adapt to new false user behavior patterns and maintain high recognition accuracy and robustness.

[0021] 8. The present invention generates a multi-dimensional interactive feature matrix through a multi-sensor fusion architecture and spatiotemporal coupling acquisition, which can comprehensively capture user behavior characteristics, provide a rich and accurate data basis for false user identification, and effectively improve identification accuracy and reliability.

[0022] 9. The present invention synchronously collects data from the capacitive touch layer and the inertial measurement unit, and generates a multi-dimensional interaction feature matrix through time synchronization, posture compensation and other processing. This can eliminate interference from factors such as device posture, accurately extract user interaction behavior characteristics, and enhance the ability to identify false user behavior.

[0023] 10. The present invention adopts a dual-channel adversarial generative network to generate adversarial perturbation patterns and uses a residual attention dual-stream network to perform sample stream comparative analysis. It can keenly capture abnormal patterns in the adversarial feature space and effectively identify abnormal behavior patterns generated by fake users.

[0024] 11. The present invention uses a hybrid architecture of spatiotemporal graph convolution and LSTM to perform multimodal fusion of abnormal pattern recognition parameters and original data to form a composite fingerprint code that includes time-varying behavioral characteristics and device physical properties. This can comprehensively characterize the association between user behavior and devices and improve the accuracy of false user identification.

[0025] 12. The present invention establishes a risk entropy value calculation model of the hidden Markov model based on the dynamic evolution of composite fingerprint coding, which can evaluate the risk level of user behavior in real time, promptly discover potential false user behavior, and provide an accurate basis for subsequent response mechanisms.

[0026] 13. When the risk entropy value exceeds the adaptive threshold, the present invention triggers a hierarchical response mechanism. Through chaotic trajectory verification and multimodal biometric authentication, and applying tactile feedback disturbance, it can effectively block abnormal sessions, ensure the safe and stable operation of mobile applications, and prevent further infringement by fake users.

[0027] 14. The present invention obtains a set of basis vectors extracted from abnormal session data streams, generates a lightweight adversarial feature dictionary, constructs a federated learning update protocol to form a global adversarial feature cloud, and uses it to optimize the dual-channel adversarial generative network and the residual attention dual-stream network, which enables the model to continuously adapt to new false user behavior patterns and maintain high recognition accuracy and robustness. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0029] Figure 1 This is a flow chart of a method for identifying false users of a mobile application provided by one embodiment of the present invention; Figure 2 This is a structural diagram of a false user identification system for mobile applications provided by one embodiment of the present invention; Figure 3 It is a structural diagram of a computer device provided by one embodiment of the present invention. DETAILED DESCRIPTION

[0030] In the following description, specific details such as specific system structures and techniques are provided for purposes of illustration rather than limitation to facilitate a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application may be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid obscuring the description of the present application with unnecessary detail.

[0031] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, integers, steps, operations, elements and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or collections thereof.

[0032] It will also be understood that the term "and / or" used in this specification and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.

[0033] As used in this specification and the appended claims, the term "if" can be interpreted as "when" or "upon" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "upon determination" or "in response to determining" or "upon detection of [described condition or event]" or "in response to detecting [described condition or event]," depending on the context.

[0034] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.

[0035] References to "one embodiment" or "some embodiments" in this specification mean that a particular feature, structure, or characteristic described in conjunction with that embodiment is included in one or more embodiments of the present application. Thus, phrases such as "in one embodiment," "in some embodiments," "in other embodiments," and "in other embodiments" appearing in various places in this specification do not necessarily refer to the same embodiment, but rather mean "one or more but not all embodiments," unless otherwise specifically emphasized. The terms "including," "comprising," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.

[0036] In the embodiments of the present application, the execution subject of the process includes a terminal device, which includes but is not limited to: a server, a computer, a smart phone, a tablet computer, and other devices capable of executing the method disclosed in the present application. Figure 1 A flow chart of a method for identifying fake users of a mobile application disclosed in an embodiment of the present invention is shown, and is described in detail as follows: S101, through the multi-sensor fusion architecture of the mobile terminal, synchronously implement the spatiotemporal coupling acquisition of the capacitive touch layer and the inertial measurement unit to generate a multi-dimensional interaction feature matrix, wherein the multi-dimensional interaction feature matrix includes pressure gradient tensor, touch differential geometry, multi-finger collaborative phase and device posture compensation.

[0037] In this embodiment, a multi-sensor fusion architecture is constructed in a mobile terminal (such as a smartphone, tablet computer, etc.). This architecture mainly includes a capacitive touch layer and an inertial measurement unit (IMU). The capacitive touch layer is used to sense the user's touch operations on the screen, and the IMU contains sensors such as accelerometers and gyroscopes to measure the device's motion state and posture. The capacitive touch layer and IMU are integrated at the hardware level to ensure that they can simultaneously receive and process information from user operations and device motion. In terms of hardware connection, the capacitive touch layer and IMU are connected to the central processing unit (CPU) or a dedicated sensor processing chip through the mobile terminal's mainboard circuit to achieve rapid data transmission and interaction.

[0038] When a user touches the screen, the capacitive touch layer senses the touch position, pressure, and other information in real time. For example, when a user slides or taps a finger on the screen, the capacitive touch layer can accurately capture the changes in the touch point's position and the amount of pressure applied.

[0039] The IMU monitors the device's acceleration, angular velocity, and other information in real time, reflecting the device's motion state and posture changes. For example, when a user rotates or tilts the device, the IMU can accurately record this dynamic information.

[0040] Ensure that data collection between the capacitive touch layer and the IMU remains synchronized in time. Through the clock synchronization mechanism at the mobile terminal's operating system level, the data collection timestamps of the capacitive touch layer and the IMU are precisely aligned. For example, when a user performs a swipe operation, the capacitive touch layer records the start and end times of the touch, while the IMU records the changes in the device's acceleration and angular velocity during that time period, achieving coupled collection in time and space.

[0041] The capacitive touch layer collects pressure distribution data during user touches. When a user's finger touches the screen, the capacitive touch layer senses pressure changes at different locations. By analyzing the pressure values ​​at each sensing point on the touch layer and how they change over time, we can obtain the pressure gradient tensor characteristics of the user's touch. For example, when a user slides, we analyze the pressure change trend over time to generate a pressure gradient tensor characteristic.

[0042] Analyze the geometric features of the touch trajectory, such as curvature and tangent slope, to reflect user operation habits and form touch differential geometry.

[0043] Record the temporal synchronization and spatial distribution of multi-finger touch, reflect the coordination of user operations, and form a multi-finger collaborative phase.

[0044] Through IMU data, the device motion posture is calibrated to compensate for the impact of device posture during touch operations, ensure data accuracy, and form device posture compensation.

[0045] In this embodiment, false user behavior patterns can be effectively identified, and multi-dimensional interaction features can be combined to improve the recognition accuracy.

[0046] S102, based on the multi-dimensional interactive feature matrix, uses a dual-channel adversarial generative network to generate an adversarial perturbation pattern with boundary constraints, uses a residual attention dual-stream network to perform sample stream comparative analysis, and outputs abnormal pattern recognition parameters in the adversarial feature space.

[0047] In this embodiment, a dual-channel generative adversarial network (DC-GAN) is constructed. The network contains two main channels: a generator channel and a discriminator channel.

[0048] The generator channel generates adversarial perturbation patterns with bounding constraints. It receives as input a multidimensional interaction feature matrix that contains rich information such as the pressure gradient tensor, touch differential geometry, multi-finger collaborative phase, and device posture compensation. The generator processes the input feature matrix through a series of neural network layers (such as fully connected layers and convolutional layers; the specific formulas and code implementation details are not discussed here). These layers gradually extract and transform features to simulate the feature variation patterns that a fake user might produce. For example, when processing the pressure gradient tensor features, the generator might simulate the abnormal pressure variation patterns produced by a fake user performing touch operations through automated scripts.

[0049] To ensure that the generated adversarial perturbation patterns have bounded boundaries, boundary constraints were introduced during the generator design process. These constraints are based on analysis and statistics of normal user behavior. For example, by collecting a large amount of multi-dimensional interaction feature data from normal users using mobile apps, the reasonable value range for each feature dimension is calculated. When generating adversarial perturbation patterns, the generator is subject to these bounded constraints. This ensures that the generated perturbation patterns can simulate the characteristic changes of fake users while not deviating too far from the reasonable range of normal user behavior, thereby avoiding being easily identified as obvious anomalies.

[0050] The discriminator channel's primary task is to distinguish whether input features originate from real users or adversarial perturbation patterns generated by the generator. It also consists of multiple neural network layers that extract and classify input features. The discriminator conducts in-depth analysis of the input features, learning the differences in multi-dimensional interaction characteristics between real users and fake users (including those simulated by the generator). For example, by analyzing touch differential geometry, the discriminator can determine whether the shape and direction of the touch trajectory conform to normal user behavior.

[0051] During the training process of the dual-channel adversarial generative network, the generator and discriminator undergo adversarial training. The generator continuously generates adversarial perturbation patterns in an attempt to deceive the discriminator into misidentifying the generated perturbation patterns as real user features. The discriminator, on the other hand, continuously learns how to more accurately identify the perturbation patterns generated by the generator, thereby improving its own discrimination ability.

[0052] In each training iteration, the generator receives the multidimensional interaction feature matrix and generates an adversarial perturbation pattern. This perturbation pattern is fused with the original multidimensional interaction feature matrix (for example, through simple weighted fusion, the specific fusion method is not described in detail here) to form new feature data. This new feature data is then input into the discriminator, which classifies it and outputs a probability value indicating the likelihood that the feature data originated from a real user.

[0053] Based on the discriminator's output, the generator and discriminator adjust their parameters. If the discriminator mistakenly identifies the generator's perturbation pattern as a true user signature, it indicates that the generator's generation capability is strong. In this case, the discriminator's parameters are adjusted to better identify this perturbation pattern. Conversely, if the discriminator correctly identifies the generator's perturbation pattern, the generator's parameters are adjusted to generate a more deceptive adversarial perturbation pattern. Through this adversarial training approach, the generator gradually generates adversarial perturbation patterns with bounded constraints that are closer to false user signatures.

[0054] We constructed a Residual Attention Dual-Stream Network (RA-DSN) for comparative analysis of sample streams. The network consists of two parallel streams, each of which includes a residual connection and an attention mechanism.

[0055] The first stream is primarily responsible for processing the raw multi-dimensional interactive feature matrix. It extracts and transforms the raw features through a series of neural network layers. Residual connections address the vanishing gradient problem during deep network training, enabling the network to better learn the complex relationships between features. The attention mechanism is used to automatically focus on important parts of the feature matrix. For example, in the pressure gradient tensor feature, the attention mechanism can automatically focus on areas with large pressure variations, which are more likely to contain characteristic information of fake users.

[0056] The second stream processes the feature data resulting from the fusion of the adversarial perturbation pattern generated by the generator and the original features. Similarly, this stream employs residual connections and an attention mechanism to conduct in-depth analysis of the fused features. By comparing the outputs of the two streams, we can identify differences between the original and fused features, thereby identifying anomalous patterns in the adversarial feature space.

[0057] The original multidimensional interaction feature matrix and the feature data fused with the adversarial perturbation pattern are input into the two streams of the two-stream network. Both streams process the input features in parallel and output their own feature representations. The output feature representations of the two streams are then compared and analyzed. For example, the similarity or difference between the two feature representations can be calculated (the specific calculation method is not described in the formula here) to determine whether there are any abnormal patterns.

[0058] If the output feature representations of the two streams differ significantly, it indicates that the fused features may contain abnormal features introduced by the adversarial perturbation pattern, thus determining that the sample may be from a fake user. In this way, the residual attention two-stream network can effectively identify abnormal patterns in the adversarial feature space and output abnormal pattern recognition parameters. These abnormal pattern recognition parameters can include information such as the strength and location of the abnormal features, providing important basis for subsequent fake user identification.

[0059] A large amount of multi-dimensional interaction feature data from both legitimate and fake users is collected and used as training and testing data for a dual-channel GAN ​​and a residual attention two-stream network. The parameters of the two-channel GAN ​​and residual attention two-stream network are initialized, and the two-channel GAN ​​is trained adversarially using the training data. The generator continuously generates adversarial perturbation patterns, and the discriminator continuously improves its discrimination capabilities. After the two-channel GAN ​​is trained, the generated adversarial perturbation patterns are fused with the original features to form new training data. This is then used to train the residual attention two-stream network, enabling it to accurately identify anomalous patterns in the adversarial feature space. In practical applications, the multi-dimensional interaction feature matrix of the mobile app users to be identified is input into the trained system. First, the dual-channel GAN ​​generates the adversarial perturbation patterns and fuses them with the original features. Then, the residual attention two-stream network compares and analyzes the fused features and outputs anomalous pattern recognition parameters.

[0060] In this embodiment, based on the multi-dimensional interactive feature matrix, it is possible to effectively generate anti-disturbance patterns and identify abnormal patterns, providing a new technical means for false user identification in mobile applications, which helps to improve the accuracy and reliability of false user identification.

[0061] S103 takes the abnormal pattern recognition parameters and the original data as input, and performs multimodal fusion through a hybrid architecture of spatiotemporal graph convolution and LSTM to form a composite fingerprint code that includes time-varying behavioral characteristics and device physical properties.

[0062] In this embodiment, each key event in a user operation (e.g., click, slide, input) is defined as a node in the spatiotemporal graph. Each node contains features extracted from the raw data, such as the click coordinates, slide trajectory length, input character content, and corresponding abnormal pattern recognition parameters. For example, for a click operation node, its features may include the horizontal and vertical coordinates of the click location, the click pressure value (from the raw data), and the abnormal pattern recognition parameters corresponding to the click operation, such as the degree of pressure abnormality.

[0063] Edges between nodes are defined based on the temporal order and spatial relationships of user operations. Regarding temporal order, directed edges are established between operation nodes occurring at adjacent times to indicate the order of operations. For example, if a user first clicks and then slides, a directed edge will be established between the click and slide nodes, from the click node to the slide node. Regarding spatial relationships, for operations with spatial associations (such as multi-touch operations), edges can also be established between spatially adjacent touch point nodes. For example, when drawing graphics using multi-touch, there is a spatial association between adjacent touch points, and edges can be established to represent this relationship.

[0064] The graph convolution layer in a spatiotemporal graph convolutional network is used to extract spatial features between nodes in a graph structure. Each node's features are influenced not only by its own features but also by the features of its connected neighboring nodes. Through graph convolution, the feature information of neighboring nodes can be aggregated onto the current node. For example, for a click operation node, the surrounding sliding operation nodes may contain contextual information related to the click operation. Through graph convolution, the features of these sliding operation nodes (such as sliding direction and speed) can be integrated into the features of the click operation node, thereby enriching the spatial feature representation of the click operation node.

[0065] To extract features along the temporal dimension, a temporal convolution module is introduced into the spatiotemporal graph convolutional network. The graph structure is sliced ​​chronologically, and after performing a spatial graph convolution operation on the graph structure in each time slice, a convolution operation is performed on the temporal dimension. For example, the user operation process is divided into multiple time slices according to a certain time interval (such as 1 second). Spatial graph convolution is performed on the graph structure within each time slice to obtain the feature representation of each node in each time slice. The node features on these time slices are then convolved along the temporal dimension using a one-dimensional convolution kernel to capture temporal trends, such as changes in user operation frequency and the periodicity of abnormal patterns.

[0066] The node feature sequence obtained after the spatiotemporal graph convolution operation is input into the LSTM network. The LSTM network is capable of processing sequential data and learning long-term dependencies within the sequence. During user operations, different operations have temporal sequences and logical relationships. The LSTM network, through its internal memory cells and gating mechanism, can remember important information about past operations and combine it with the characteristics of the current operation. For example, when a user performs a series of game operations, earlier operations may affect later ones. The LSTM network can capture this temporal dependency and learn the time-varying behavioral characteristics of user operations.

[0067] At each time step of the LSTM network, the node features obtained through spatiotemporal graph convolution are fused with the hidden state of the LSTM network. The hidden state of the LSTM network contains information about the operation in the previous time step, while the node features obtained through spatiotemporal graph convolution contain the spatial and temporal characteristics of the current operation. By fusing these two features, a more comprehensive characterization of user operations can be achieved. For example, in a mobile shopping app, combining user browsing actions (spatiotemporal graph convolution features) with previous purchase actions (LSTM hidden state information) can better understand users' shopping intentions and behavior patterns.

[0068] After processing by the LSTM network, fused features are obtained at each time step. To generate a composite fingerprint that combines time-varying behavioral features with the device's physical properties, these fused features at each time step need to be aggregated. Average pooling or max pooling can be used to aggregate the fused features across all time steps to produce a fixed-length feature vector. For example, average pooling takes the average of the fused features across all time steps in each dimension to produce a comprehensive feature representation.

[0069] In addition to the time-varying behavioral characteristics of user operations, the device's physical attributes must also be incorporated into the composite fingerprint code. Device physical attributes include the device model, operating system version, and screen resolution. After encoding these attributes (e.g., using one-hot encoding), they are concatenated with the aggregated feature vector to form the final composite fingerprint code. This composite fingerprint code incorporates both the time-varying behavioral characteristics of user operations and the device's physical attributes, providing a more comprehensive and accurate characterization of both the user and the device, providing a strong basis for subsequent fraudulent user identification.

[0070] In this embodiment, the abnormal pattern recognition parameters and the original data can be effectively integrated to generate a composite fingerprint code including time-varying behavior characteristics and device physical properties, providing a more reliable basis for false user identification of mobile applications.

[0071] S104: According to the dynamic evolution of the composite fingerprint code, a risk entropy value calculation model based on the hidden Markov model is established.

[0072] In this embodiment, a single composite fingerprint code can only reflect the user's state at a specific moment or stage of operation, and it is difficult to fully characterize the dynamic changes in user behavior. To more accurately identify fraudulent users, it is necessary to establish a risk entropy calculation model based on the dynamic evolution of the composite fingerprint code to quantify the risk level of user behavior. Hidden Markov models (HMMs) are well-suited for describing dynamic systems with hidden states and are suitable for modeling and analyzing time-series data such as user behavior.

[0073] In dynamic evolution analysis based on composite fingerprint coding, user behavior states are defined as hidden states. These hidden states reflect the underlying patterns of user behavior, such as normal operation state, suspected fraudulent operation state, and clear fraudulent operation state. Normal operation state indicates that the user's behavior conforms to normal operation patterns and shows no abnormalities; suspected fraudulent operation state indicates that the user's behavior has some suspicious characteristics, but it cannot be completely confirmed as fraudulent; and clear fraud state indicates that the user's behavior clearly shows the characteristics of a fraudulent user.

[0074] Hidden states are categorized based on composite fingerprint characteristics, combined with actual mobile app business scenarios and historical data. For example, in gaming apps, states can be categorized based on composite fingerprint characteristics such as user login frequency, operation speed, and item acquisition methods. If a user frequently logs into the game within a short period of time, operates at an abnormally high speed, and acquires a large number of items through unconventional means, the user may be suspected of fraudulent operation or clearly engaged in fraudulent operation.

[0075] Observable variables are directly observable user behavior characteristics that reflect changes in hidden states. In this embodiment, observed variables can be extracted from the composite fingerprint code, such as the range of pressure gradient tensor changes, the degree of abnormality in touch differential geometry, the synchronization of multi-finger coordination phases, and the rationality of device posture compensation. These observed variables can reflect the details of user operations and the physical state of the device, providing a basis for determining hidden states.

[0076] Observation variables at each time point are combined in chronological order to form an observation sequence. For example, during a user's game operation, a composite fingerprint code is collected at regular intervals (e.g., 1 second) and observation variables are extracted from it. These observation variables are then arranged in chronological order to form an observation sequence. The length of the observation sequence can be adjusted based on actual needs and the frequency of data collection.

[0077] Determine the probability of the user being in each hidden state at the initial moment, i.e., the initial state probability distribution. This initial state probability can be estimated based on the initial behavioral characteristics of various types of users (both normal and fake) in historical data. For example, if historical data shows that most normal users have a high probability of being in a normal operating state at the initial moment, while fake users have a low probability of exhibiting certain suspicious characteristics at the initial moment, then the initial probability of the normal operating state can be set higher, while the initial probabilities of other states can be set lower.

[0078] The state transition probability matrix describes the probability of a user transitioning between different hidden states. By analyzing the dynamic changes in user behavior in historical data and counting the frequency of transitions from one hidden state to another, we can estimate state transition probabilities. For example, we can calculate the probability of a normal operation state transitioning to a suspected fraudulent operation state, or the probability of a suspected fraudulent operation state transitioning to a clearly fraudulent operation state. These probabilities reflect the changing trends of user behavior states.

[0079] The observation probability matrix represents the probability of observing each observed variable under each hidden state. For each hidden state, the probability of observing different observed variables is calculated based on the distribution of observed variables under that state in the historical data. For example, under normal operating conditions, the pressure gradient tensor typically varies within a small range, while under suspected spurious operating conditions, the pressure gradient tensor may vary over a larger range. By statistically analyzing this data, we can determine the probability of observing different pressure gradient tensor values ​​under different hidden states.

[0080] Collect a large amount of user behavior data, including both legitimate and fake users, and extract corresponding composite fingerprint codes and observation sequences as training data. Use the training data to train the hidden Markov model. The goal of training is to adjust the model parameters so that the model better fits the training data. During training, optimization methods such as the expectation-maximization (EM) algorithm can be used to estimate the model parameters. Through continuous iteration, the initial state probability distribution, state transition probability matrix, and observation probability matrix are gradually optimized, enabling the model to more accurately describe the dynamic changes in user behavior. Evaluate the trained model using a validation dataset. This validation dataset is independent of the training dataset and is used to test the model's generalization ability. Model performance is evaluated by calculating metrics such as prediction accuracy and recall on the validation dataset. If model performance is unsatisfactory, adjust the model parameters or increase the diversity of the training data before retraining and optimizing.

[0081] Entropy is a measure of the uncertainty or disorder of a system. In the Hidden Markov Model-based risk entropy calculation, the entropy of user behavior in different hidden states is calculated to quantify the risk level of user behavior. A higher entropy value indicates greater uncertainty in user behavior and the potential for fraudulent operations; a lower entropy value indicates more stable user behavior and a lower risk level.

[0082] For each observation sequence, the Hidden Markov Model is used to calculate its probability distribution under different hidden states. Then, the entropy value is calculated based on the probability distribution. For example, for an observation sequence, the probabilities of normal operation, suspected fraudulent operation, and clear fraudulent operation are calculated. Then, the entropy value of the observation sequence is calculated using an entropy calculation formula (such as the Shannon entropy formula). A higher entropy value indicates greater uncertainty in user behavior between different states and a higher risk level.

[0083] The calculated entropy value is used as the risk entropy value to measure the risk level of user behavior. Different entropy value ranges corresponding to different risk levels can be set based on actual needs and business scenarios. For example, user behaviors with low entropy values ​​can be classified as low risk, while user behaviors with high entropy values ​​can be classified as high risk.

[0084] In this embodiment, a risk entropy value calculation model based on a hidden Markov model can be established according to the dynamic evolution of the composite fingerprint code, providing a more accurate risk assessment basis for false user identification of mobile applications.

[0085] S105, when the risk entropy value output by the risk entropy value calculation model exceeds the adaptive threshold, a hierarchical response mechanism including chaotic trajectory verification and multimodal biometric authentication is triggered, and tactile feedback disturbance is applied to block abnormal conversations.

[0086] In this embodiment, the adaptive threshold is not fixed but dynamically adjusted based on the actual operation of the mobile application, user behavior patterns, and security requirements. An initial threshold range is determined by analyzing historical risk entropy data, taking into account the characteristics of different time periods (e.g., peak and off-peak periods), different user groups (e.g., new and returning users), and different business scenarios (e.g., during key gaming events and shopping promotions). Simultaneously, an adaptive threshold adjustment model is trained on historical data using machine learning algorithms (e.g., decision trees and cluster analysis). This model automatically adjusts the threshold based on real-time data changes. During mobile application operation, the risk entropy output of the risk entropy calculation model is monitored in real time. The current risk entropy value is compared with the adaptive threshold. If the risk entropy value exceeds the threshold, a graded response mechanism is immediately triggered.

[0087] When the risk entropy value exceeds the adaptive threshold for the first time, or the excess is small, a first-level response is triggered, generating a chaotic trajectory verification task on the mobile app's interactive interface. A chaotic trajectory is a random and unpredictable trajectory. The user is required to follow the chaotic trajectory displayed on the screen, such as drawing a curve similar to the sample trajectory with their finger. The system records the user's trajectory data, including shape, speed, acceleration, and other information, and compares it with a preset chaotic trajectory template. If the similarity between the user's drawn trajectory and the template falls below the set threshold, the verification is considered failed and the user must re-verify. If the similarity reaches or exceeds the threshold, the next-level response is entered, or the user is temporarily allowed to continue the operation, but subsequent behavior will be monitored more closely. Chaotic trajectory verification provides a preliminary assessment of whether the user is legitimate. Since fraudulent users often operate through automated scripts or programs, which cannot accurately simulate random human behavior, chaotic trajectory verification can effectively identify some fraudulent users.

[0088] When the chaotic trajectory verification of the first-level response fails, or the risk entropy value exceeds the adaptive threshold by a significant margin, the second-level response is triggered, initiating the multimodal biometric authentication process. Multimodal biometric authentication combines multiple biometric recognition technologies, such as fingerprint recognition, facial recognition, and voiceprint recognition. The system prompts the user to collect the appropriate biometrics, such as placing a finger on a fingerprint sensor for fingerprint collection, facing a camera for facial recognition, or speaking specific speech for voiceprint recognition. The system compares the collected biometrics with the user's biometric template stored in a database. If the comparison results are inconsistent, the authentication is considered failed, and the user will be restricted from further operations. If the comparison results are consistent, the user is allowed to continue using the mobile app, but will be marked as a high-risk user and subject to special monitoring. Multimodal biometric authentication offers higher accuracy and security, effectively preventing fraudulent users from operating through account theft and other means. By combining multiple biometrics, it is more difficult for fraudulent users to impersonate legitimate users.

[0089] During the first-level or second-level response process, if an abnormality in user operation is detected (such as verification failure, inconsistent biometric comparison, etc.), or the risk entropy value remains at a persistently high level, a tactile feedback perturbation is triggered. The tactile feedback function of the mobile terminal is used to apply specific tactile perturbations to the user. Tactile feedback can be achieved through a vibration motor, which the system controls to generate vibration signals of different frequencies and intensities. For example, when a user is performing chaotic trajectory verification, if the drawn trajectory deviates, the system will immediately apply a short, moderate vibration to alert the user of the incorrect operation. When biometric authentication fails, the system will apply a longer-lasting, higher-intensity vibration to attract the user's attention and prevent them from continuing the operation. The purpose of the tactile feedback perturbation is to interfere with the automated operations of fake users while alerting legitimate users that there may be problems with their operations.

[0090] After applying tactile feedback perturbations, continuously monitor changes in user behavior. If the user can adjust their actions promptly based on the tactile feedback and ultimately pass verification or authentication, the tactile feedback has served as an effective reminder. If the user still cannot pass verification or authentication, or exhibits abnormal operational behavior, further strengthened response measures may be required, such as directly blocking the user's session. Furthermore, based on user feedback and actual results, the parameters of the tactile feedback perturbations (such as vibration frequency, intensity, and duration) are adjusted and optimized to improve their effectiveness and user experience.

[0091] When multimodal biometric authentication fails in the secondary response, or the risk entropy value exceeds an adaptive threshold and reaches a critical level, and the user is unable to correct the abnormal behavior through tactile feedback perturbations, abnormal session blocking is triggered. The system immediately terminates the user's session with the mobile app, preventing the user from performing any further operations. At the same time, relevant user information, including user ID, operation time, operation behavior, and risk entropy value, is recorded for subsequent analysis and action. Users whose sessions are blocked can be blacklisted or subject to further investigation, such as manual review. After blocking an abnormal session, the mobile app can send an alert to the administrator, notifying them of the potential fraudulent user. Based on the recorded information, the administrator can conduct in-depth analysis of the user's behavior to determine whether the user is fraudulent. If the user is fraudulent, appropriate measures can be taken, such as banning the account. If the user is legitimate and the abnormal operation is caused by special circumstances, the administrator can remove the restrictions on the account and provide appropriate guidance to prevent similar incidents from occurring again.

[0092] In this embodiment, when the risk entropy value output by the risk entropy value calculation model exceeds the adaptive threshold, the hierarchical response mechanism can be effectively triggered to apply tactile feedback disturbance and block abnormal sessions, thereby effectively identifying and responding to false users and ensuring the security and normal operation of mobile applications.

[0093] In some embodiments, in the above step S101, the multi-sensor fusion architecture of the mobile terminal is used to synchronously implement spatiotemporal coupling acquisition of the capacitive touch layer and the inertial measurement unit to generate a multi-dimensional interaction feature matrix, specifically including: Real-time acquisition of touch pressure distribution data through the capacitive touch layer of the mobile terminal, and simultaneous acquisition of six-degree-of-freedom motion parameters through the inertial measurement unit of the mobile terminal; Based on the pressure distribution data and six-degree-of-freedom motion parameters, a least-squares calibration model is used to perform time synchronization and obtain synchronized data streams; Based on the synchronous data stream, the spatial transformation operation of the posture compensation matrix is ​​used to eliminate the offset effect of the device holding posture on the touch coordinates and obtain the compensated touch trajectory; Based on the compensated touch trajectory, the pressure gradient tensor is calculated and the mutation point features of the touch trajectory curvature are extracted; Based on the pressure gradient tensor and mutation point features, combined with the phase difference analysis of multi-finger touch, a multi-dimensional interaction feature matrix for behavior recognition is generated.

[0094] In this embodiment, during the process of identifying fake users in mobile applications, it is necessary to obtain multi-dimensional features that can accurately reflect the real behavior of users. The capacitive touch layer and inertial measurement unit equipped in the mobile terminal can provide rich interactive information, but this information has problems such as time asynchrony and being affected by the device posture. This embodiment aims to synchronously implement the spatiotemporal coupling acquisition of the capacitive touch layer and the inertial measurement unit through the multi-sensor fusion architecture of the mobile terminal, generate a multi-dimensional interactive feature matrix, and provide a reliable feature basis for subsequent fake user identification.

[0095] Because the capacitive touch layer and the inertial measurement unit are independent hardware modules, their data acquisition clocks may differ slightly, resulting in time synchronization between the collected pressure distribution data and the six-degree-of-freedom motion parameters. This time asynchrony can affect subsequent data fusion and analysis, necessitating time synchronization. The least squares calibration model is a data calibration method that calibrates the data by establishing a mathematical relationship between the data acquisition times of the capacitive touch layer and the inertial measurement unit, ensuring temporal alignment.

[0096] When using a mobile terminal, users hold it in various postures, such as portrait, landscape, and tilted. These different holding postures can cause an offset between the touch coordinates detected by the capacitive touch layer and the actual touch location, affecting subsequent feature extraction and behavior recognition. The six-degree-of-freedom motion parameters collected by the inertial measurement unit (IMU) can be used to determine the device's holding posture. By establishing a posture compensation matrix, the touch coordinates detected by the capacitive touch layer are spatially transformed to eliminate the offset caused by the device's holding posture. Specifically, based on the acceleration and angular velocity data collected by the IMU, a posture calculation algorithm (such as the quaternion method or the Euler angle method) is used to calculate the device's current posture, including pitch, roll, and yaw angles. Based on the device's posture information, a corresponding posture compensation matrix is ​​established. This matrix describes the transformation from the touch coordinate system in the device's current posture to the touch coordinate system in the standard posture. The original touch coordinates detected by the capacitive touch layer are multiplied by the posture compensation matrix to obtain the compensated touch coordinates, thereby obtaining the compensated touch trajectory. The compensated touch trajectory can more accurately reflect the user's touch path in actual operation.

[0097] The pressure gradient tensor describes how touch pressure varies across the screen space. It reflects the distribution and changing trends of pressure during a user's touch, providing important features for behavior recognition. Based on the pressure distribution data along the compensated touch trajectory, the pressure difference between adjacent touch points is calculated and combined with the touch point location information to construct a pressure gradient tensor. Specifically, the screen can be divided into multiple small areas, and the average pressure and rate of change within each area are calculated to obtain the various components of the pressure gradient tensor.

[0098] In a touch trajectory, certain points in the pressure gradient tensor may experience sudden changes. These changes are often associated with specific user actions, such as quick taps, long presses, and pauses in sliding. By statistically analyzing the pressure gradient tensor, an appropriate threshold is set. When a component of the pressure gradient tensor exceeds the threshold, the point is identified as a sudden change. The location, pressure value, and time of occurrence of the sudden change point are recorded as part of the subsequent feature matrix.

[0099] When using mobile apps, users often use multiple fingers to perform operations, such as pinch-to-zoom and three-finger swipe. Touch operations performed by different fingers have a certain phase relationship in time and space. The capacitive touch layer detects the touch time and position information of multi-finger touch and calculates the phase difference between the touch trajectories of different fingers. For example, for a pinch-to-zoom operation, the relationship between the distance change and time between the two finger touch points can be calculated to obtain phase difference information. Phase difference can reflect the degree of coordination and operation rhythm of multi-finger touch, providing additional features for behavior recognition.

[0100] The pressure gradient tensor, the sudden change point features of the touch trajectory curvature, and the phase difference analysis results of multi-finger touch are integrated. These features reflect user interaction behavior from different perspectives and are complementary. The integrated features are arranged according to specific rules to construct a multidimensional interaction feature matrix. Each row or column of this matrix represents a specific feature dimension, and the element value in the matrix represents the specific value of the corresponding feature. The multidimensional interaction feature matrix can comprehensively and accurately describe user interaction behavior, providing rich feature input for subsequent fake user identification algorithms.

[0101] In this embodiment, the multi-sensor fusion architecture of the mobile terminal can be effectively used to synchronously implement the spatiotemporal coupling acquisition of the capacitive touch layer and the inertial measurement unit, generate a multi-dimensional interactive feature matrix for behavior recognition, and provide strong feature support for false user identification in mobile applications.

[0102] In some embodiments, in step S102, based on the multi-dimensional interactive feature matrix, a dual-channel adversarial generative network is used to generate an adversarial perturbation pattern with boundary constraints, and a residual attention dual-stream network is used to perform sample stream comparative analysis to output abnormal pattern recognition parameters in the adversarial feature space. Specifically, the following steps are performed: Based on the multi-dimensional interactive feature matrix, a conditional Wasserstein generative adversarial network is constructed. By concatenating the latent space noise vector and the conditional vector, an adversarial perturbation pattern with gradient penalty constraints is generated. The adversarial perturbation pattern and the original feature matrix are combined and input into the residual attention two-stream network, performing multi-scale convolution operations in the original stream and the adversarial stream respectively; Through learnable channel attention weights, the attention heatmaps of the original stream and the adversarial stream at each convolutional layer are calculated; According to the Frobenius norm difference between the attention heat maps of the original stream and the adversarial stream, the adversarial loss value representing the abnormal pattern is output.

[0103] In this embodiment, in mobile application scenarios, user interaction behaviors contain rich information, but they may also be interfered with by fake users or malicious attacks. In order to accurately identify these abnormal behaviors, it is necessary to extract key information from multidimensional interaction features and analyze them using advanced network structures. Based on a multidimensional interaction feature matrix, this embodiment uses a dual-channel adversarial generative network and a residual attention dual-stream network to generate adversarial perturbation patterns with boundary constraints, perform sample stream comparative analysis, and output abnormal pattern recognition parameters in the adversarial feature space, thereby achieving effective detection of abnormal mobile application interaction behaviors.

[0104] Specifically, we chose the Conditional Wasserstein Generative Adversarial Network (CWGAN) as the underlying architecture for generating adversarial perturbation patterns. CWGAN improves upon the traditional Generative Adversarial Network (GAN) by introducing the Wasserstein distance to measure the distribution difference between generated and real data. Furthermore, it incorporates conditional vectors to guide the generation process, making the generated adversarial perturbation patterns more targeted and controllable.

[0105] The latent space noise vector is randomly sampled from the standard normal distribution. This vector is random and diverse, providing an initial source of randomness for generating adversarial perturbation patterns.

[0106] Based on the multidimensional interaction feature matrix, key features related to the current interaction behavior are extracted as conditional vectors. For example, statistical features of touch pressure (such as average pressure and maximum pressure), shape features of touch tracks (such as track length and curvature), and phase difference features of multi-finger touch can be extracted and combined into a conditional vector.

[0107] The latent space noise vector and the conditional vector are concatenated to form a new vector that serves as the input to the generator. This concatenation method allows the generator to not only consider randomness when generating adversarial perturbation patterns, but also incorporates specific interactive behavior characteristics, thereby generating more targeted adversarial perturbation patterns.

[0108] Based on the concatenated input vectors, the generator gradually generates adversarial perturbation patterns through a series of neural network layers (such as fully connected layers and deconvolutional layers). During the training process, the generator's goal is to generate adversarial perturbation patterns that can deceive the discriminator, making it difficult for the discriminator to distinguish between the generated adversarial perturbation patterns and real interactive behavior patterns.

[0109] The discriminator receives the real interaction behavior feature matrix and the adversarial perturbation pattern generated by the generator as input. It classifies and judges the data through neural network layers (such as convolutional layers and fully connected layers), and outputs a probability value indicating the probability that the input data is real data. The discriminator's goal is to distinguish between real data and generated data as accurately as possible.

[0110] To prevent vanishing or exploding gradients during training and improve the quality of generated adversarial perturbation patterns, a gradient penalty constraint is introduced. By limiting the discriminator's gradient, the gradient penalty constraint smoothes its decision boundary, thereby guiding the generator to produce more realistic and diverse adversarial perturbation patterns. During training, the norm of the discriminator's gradient is calculated and penalized according to a set threshold. This penalty term is added to the loss function to jointly optimize the parameters of the generator and discriminator.

[0111] The generated adversarial perturbation pattern is combined with the original multi-dimensional interaction feature matrix. This combination can be a simple concatenation, where the adversarial perturbation pattern is added as an additional feature dimension to the original feature matrix to form a new feature matrix. This combination allows the residual attention two-stream network to simultaneously learn the original interaction behavior characteristics and the adversarial perturbation pattern information.

[0112] The residual attention two-stream network consists of two branches: the original stream and the adversarial stream. Each branch contains multiple convolutional layers and residual connections. Residual connections effectively address the vanishing gradient problem during deep network training, improving network training efficiency and performance. Furthermore, each branch incorporates an attention mechanism, focusing on important feature channels through learnable channel attention weights.

[0113] Multi-scale convolution operations are performed on both the original and adversarial streams. Multi-scale convolution uses kernels of different sizes to extract features, capturing information at different scales. For example, a small kernel can extract fine local features, while a large kernel can extract coarse global features. This multi-scale convolution operation enables a more comprehensive representation of interactive behaviors.

[0114] In the residual attention two-stream network, a channel-wise attention mechanism is introduced to dynamically adjust the importance of different feature channels. The channel-wise attention mechanism performs global average pooling on each feature channel to obtain a channel descriptor. Then, through fully connected layers and nonlinear activation functions (such as the sigmoid function), attention weights for each channel are learned. The attention weights range from 0 to 1 and represent the importance of the channel to the task at hand. These channel-wise attention weights are learnable parameters that are continuously optimized during network training. Through the backpropagation algorithm, the channel-wise attention weights are updated based on the gradient of the loss function, allowing the network to automatically learn the importance of different feature channels in different convolutional layers. Based on the learned channel-wise attention weights, attention heatmaps are calculated for each convolutional layer for both the original and adversarial streams. An attention heatmap is a two-dimensional matrix whose elements represent the strength of attention for the corresponding feature channel at that location. The attention heatmap is obtained by taking the weighted sum of the channel-wise attention weights and the feature map. The attention heatmap intuitively demonstrates the network's attention areas for features at different convolutional layers, helping to understand the network's decision-making process.

[0115] Calculate the Frobenius norm difference between the attention heatmaps of the original and adversarial streams. The Frobenius norm is a commonly used matrix norm that measures the degree of difference between two matrices. By calculating the Frobenius norm of the attention heatmaps of the original and adversarial streams at each convolutional layer, we can determine the difference between them. A larger difference indicates a more significant difference in the feature attention areas between the original and adversarial streams, which may indicate abnormal behavior.

[0116] The calculated Frobenius norm difference is used as the adversarial loss. This value reflects the degree to which the adversarial perturbation pattern affects the original interaction behavior. During training, the adversarial loss is used to optimize the parameters of the generator and discriminator, ensuring that the adversarial perturbation patterns generated by the generator better simulate abnormal behavior and that the discriminator more accurately identifies these abnormal patterns. During testing, the output adversarial loss value is used to determine whether the interaction behavior is abnormal. If the adversarial loss exceeds a set threshold, the interaction behavior is considered to be abnormal and requires further manual review or other remediation measures.

[0117] In this embodiment, the dual-channel network structure can be effectively utilized to identify abnormal patterns from multi-dimensional interaction features, providing a feasible technical solution for the security detection of mobile application interaction behaviors.

[0118] In some embodiments, in step S103, the abnormal pattern recognition parameters and the original data are used as inputs, and multimodal fusion is performed through a hybrid architecture of spatiotemporal graph convolution and LSTM to form a composite fingerprint code containing time-varying behavioral characteristics and device physical properties, specifically including: Based on the abnormal pattern recognition parameters and raw data, a spatiotemporal topological map of the touch trajectory is constructed, and the edge weight matrix of the spatiotemporal topological map is determined by dynamically calculating the similarity of pressure gradients between nodes. By performing spatiotemporal joint convolution on the spatiotemporal topological graph using a deformable 3D convolution kernel, we can extract node feature vectors containing local abnormal patterns. The node feature vector is sliced ​​by time window and input into the bidirectional LSTM network for time series modeling to generate hidden state features that represent the continuity of behavior; The features of the spatiotemporal topological graph and the latent state features are weightedly fused through the gated attention mechanism, and the output is a composite fingerprint code that includes time-varying behavioral features and device physical properties.

[0119] In this embodiment, the raw data generated during the use of the mobile application, such as the touch coordinates, pressure value, touch time and other information of the capacitive touch layer, and the abnormal pattern recognition parameters obtained in the previous step are collected. The abnormal pattern recognition parameters are associated and integrated with the raw data, for example, the abnormal pattern recognition parameters are added as additional attributes to each touch point data. According to the touch time sequence, the continuous touch points are divided into different touch tracks. Each touch track represents an operation behavior of the user, such as clicking, sliding, zooming, etc.

[0120] Each touch point in the touch trajectory is used as a node in the spatiotemporal topology graph. Each node contains information such as the touch point's location coordinates, pressure value, touch time, and abnormal pattern recognition parameters.

[0121] Edges are established based on the temporal and spatial proximity of touch points. For example, for adjacent touch points within the same touch track, edges are directly established. For touch points that are close in time and space within different touch tracks, edge establishment can also be determined based on a certain threshold. In this way, a topological graph structure that reflects the temporal and spatial relationships of touch tracks is constructed.

[0122] For each edge in the spatiotemporal topology graph, the pressure gradient similarity between the two connected nodes is dynamically calculated. The pressure gradient reflects the spatial variation of touch pressure. The similarity between two nodes and their surrounding areas (the range of the neighborhood can be determined based on actual needs) is compared to measure their pressure gradient similarity. For example, if the pressure gradients of two nodes and their surrounding areas have similar directions and small differences in magnitude, their pressure gradients are considered highly similar.

[0123] Based on the pressure gradient similarity calculation results, a weight is assigned to each edge in the spatiotemporal topology graph. A larger weight indicates a higher pressure gradient similarity between two nodes and a closer relationship between them in the spatiotemporal topology graph. This method generates an edge weight matrix for the spatiotemporal topology graph, which reflects the spatiotemporal correlation and pressure change relationship between different touch points in the touch trajectory.

[0124] Traditional 3D convolution kernels have fixed shapes and receptive fields, making them difficult to adapt to feature extraction requirements for touch traces with varying positions and shapes. Deformable 3D convolution kernels, on the other hand, can adaptively adjust their shape and position based on the characteristics of the input data, thereby better capturing local anomaly patterns. The deformable 3D convolution kernel learns an offset field to offset the kernel's sampling position. This offset field is correlated with the input data and is trained and optimized using a backpropagation algorithm, enabling the kernel to focus on areas with important features. The deformable 3D convolution kernel is applied to a spatiotemporal topological graph, performing a convolution operation on the node features of each node and its surrounding neighborhood. This convolution operation considers information from both the spatial dimension (the positional relationship of touch points) and the temporal dimension (the order of touch points), achieving joint spatiotemporal convolution. Through the convolution operation, local features of the area surrounding each node are extracted. These features incorporate information such as touch pressure, position change, and anomaly patterns, forming a node feature vector that captures the local anomaly pattern. This node feature vector provides a more comprehensive representation of each touch point within the spatiotemporal topological graph.

[0125] Determine an appropriate time window size based on actual application requirements and the temporal characteristics of the data. The time window should be large enough to include sufficient touch point information to reflect the continuity of user behavior. For example, the time window can be set to a period covering dozens of touch points. Slice the extracted node feature vectors according to the determined time window. The node feature vectors within each time window constitute a sample sequence for subsequent time series modeling.

[0126] The bidirectional LSTM network consists of two networks: a forward LSTM and a backward LSTM. The forward LSTM processes the sample sequence in chronological order, capturing past information; the backward LSTM processes the sample sequence in reverse chronological order, capturing future information. The node feature vector sequence, sliced ​​into time windows, is input into the bidirectional LSTM network. The bidirectional LSTM network processes the input at each time step and generates the corresponding hidden state. The combined effect of the forward and backward LSTM networks fully utilizes the temporal information of the sample sequence to generate hidden state features that represent behavioral continuity. These hidden state features capture the user's behavioral patterns and changing trends within the time window.

[0127] The attention mechanism automatically learns the importance of different features and performs weighted fusion. The gated attention mechanism, based on the traditional attention mechanism, introduces a gating unit, which allows for more flexible control over the degree of feature fusion. The gating unit dynamically adjusts attention weights based on input feature information, determining which features should be prioritized and which should be appropriately ignored. This gating unit improves the accuracy and robustness of feature fusion.

[0128] The gated attention mechanism uses the spatiotemporal topological map features (i.e., node feature vectors) and the latent state features generated by the bidirectional LSTM network as input. The gated attention mechanism calculates attention weights for the spatiotemporal topological map features and the latent state features, respectively. This calculation considers the correlation and importance between features, and learns the attention weights for each feature. Based on the calculated attention weights, the spatiotemporal topological map features and the latent state features are weighted and summed to achieve feature fusion. The fused features contain information on both time-varying behavioral characteristics (such as temporal changes in touch trajectories and abnormal patterns) and device physical properties (such as touch pressure distribution).

[0129] The weighted fusion features are used as a composite fingerprint code. A composite fingerprint code is a feature vector that uniquely identifies a user's identity and behavioral characteristics. It integrates various information about the user during mobile application usage and has high discrimination and stability. The generated composite fingerprint code can be applied to scenarios such as user identity authentication and behavior monitoring. For example, when a user logs in, the authenticity of the user's identity is determined by comparing the currently generated composite fingerprint code with the pre-stored fingerprint code of a legitimate user. During behavior monitoring, changes in the composite fingerprint code are monitored in real time to detect abnormal behavior and issue early warnings.

[0130] In this embodiment, the abnormal pattern recognition parameters and the original data can be effectively fused to generate a composite fingerprint code including time-varying behavior characteristics and device physical properties, providing a new technical means for the security of mobile applications.

[0131] In some embodiments, in the above step S104, establishing a risk entropy value calculation model based on a hidden Markov model according to the dynamic evolution of the composite fingerprint code specifically includes: Based on the temporal changes of the composite fingerprint code, a three-state hidden Markov model including normal state, transition state and abnormal state is constructed, and the state transition matrix and observation probability distribution of the three-state hidden Markov model are initialized; Based on the three-state hidden Markov model, the forward-backward algorithm is used to calculate the hidden state probability distribution at each moment, and the transition probability pointing to the high-risk state in the state transition matrix is ​​extracted; Based on the hidden state probability distribution and transition probability, the risk entropy value that characterizes the abnormality of the behavior is calculated.

[0132] In this embodiment, the normal state represents the user's normal operating behavior in the mobile application. In this state, the user's operations conform to conventional usage habits, and the characteristics reflected by the composite fingerprint code are within the normal range. For example, the user operates with a normal touch rhythm and pressure, and there are no abnormal interaction patterns.

[0133] The transition state indicates that user behavior is in the middle of transitioning from normal to abnormal, or recovering from abnormal to normal. In this state, the user's operation behavior begins to show some unusual characteristics, but has not yet reached the level of abnormality. For example, the user's touch speed may suddenly increase or decrease, but it is still within the acceptable range.

[0134] The abnormal state corresponds to the state in which the user performs abnormal operations. In this case, the user's composite fingerprint code shows obvious abnormal characteristics, such as abnormal touch pressure, unreasonable operation sequence, etc., which may indicate that the user has been attacked maliciously or has violated the rules.

[0135] Based on the temporal changes of the composite fingerprint code, a three-state hidden Markov model consisting of normal state, transition state, and abnormal state is constructed. In this model, each state corresponds to a potential feature distribution of the composite fingerprint code, and the transition between states reflects the changing process of user behavior.

[0136] The state transition matrix describes the probability of transitions between states in the model. During initialization, initial values ​​for the state transition probabilities are set based on experience or prior knowledge. For example, the probability of transitioning from the normal state to the transition state can be set to a low value, as user behavior does not change frequently under normal circumstances. The probability of transitioning from the transition state to the abnormal state is set based on the risk level of the application scenario, and can be appropriately increased in high-risk scenarios. The probability of returning from the abnormal state to the normal state is relatively low, as abnormal behavior usually requires time or intervention to return to normal.

[0137] The observation probability distribution represents the probability of observing a specific composite fingerprint code in each state. By collecting a large number of composite fingerprint code samples under normal, transitional, and abnormal states, the frequency of occurrence of different fingerprint codes in each state is calculated and used as the initial value of the observation probability distribution. For example, in the normal state, fingerprint codes corresponding to certain common touch patterns appear more frequently; in the abnormal state, fingerprint codes corresponding to uncommon and abnormal touch patterns appear more frequently.

[0138] Starting from the initial moment, the forward probability of each state is calculated step by step. The forward probability represents the probability that the system is in a certain state up to the current moment, given a given observation sequence. The forward probability of the current moment is calculated recursively using the forward probability of the previous moment, the state transition matrix, and the observation probability distribution.

[0139] Starting from the last moment, the backward probability of each state at each moment is calculated in reverse. The backward probability represents the probability of the system being in each state from the current moment to the last moment, given the observation sequence and the current state of the system. Similarly, the backward probability at the next moment is calculated recursively using the backward probability at the next moment, the state transition matrix, and the observation probability distribution.

[0140] Combining the forward and backward probabilities, we can calculate the joint probability of each state at each moment, which is the hidden state probability distribution. The hidden state probability distribution reflects the probability of the system being in each state at each moment given the observation sequence.

[0141] In this embodiment, an abnormal state is defined as a high-risk state because user behavior in an abnormal state may pose a threat to the security of the mobile application, such as malicious operations and data leakage risks.

[0142] In the state transition matrix of the constructed three-state hidden Markov model, we search for transition probabilities that point to abnormal states (high-risk states). These transition probabilities represent the likelihood of transitioning from a normal or transitional state to an abnormal state and are important indicators for assessing risk. For example, the transition probability from a transitional state to an abnormal state in the state transition matrix reflects the probability that user behavior will shift from a potentially problematic state to a clearly abnormal state.

[0143] The risk entropy value is used to measure the uncertainty of user behavior abnormality. A high risk entropy value indicates that the distribution of user behavior abnormality is relatively dispersed, making it difficult to accurately determine whether the behavior is abnormal. A low risk entropy value indicates that the distribution of user behavior abnormality is relatively concentrated, making it easier to determine the behavior status. The calculation of the risk entropy value comprehensively considers the latent state probability distribution and the transition probability to high-risk states in the state transition matrix. The latent state probability distribution reflects the probability of the user's behavior being in each state at the current moment, while the high-risk state transition probability reflects the tendency of the user's behavior to transition to an abnormal state.

[0144] The risk entropy value is derived by weighting the hidden state probability distribution and the high-risk state transition probability, or by other reasonable calculation methods. For example, the hidden state probability distribution can be weighted according to the importance of different states, while also considering the impact of the high-risk state transition probability, to comprehensively calculate a risk entropy value that reflects the degree of abnormal behavior. Specifically, if the probability of being in the transition state at the current moment is high, and the transition probability from the transition state to the abnormal state is also high, then the risk entropy value may be relatively high, indicating a high risk of abnormal behavior.

[0145] In this embodiment, the hidden Markov model can be used to effectively evaluate the risks in the use of mobile applications based on the dynamic evolution of the composite fingerprint code, providing strong support for ensuring the security of mobile applications.

[0146] In some embodiments, in step S105, when the risk entropy value output by the risk entropy value calculation model exceeds the adaptive threshold, a hierarchical response mechanism including chaotic trajectory verification and multimodal biometric authentication is triggered, and tactile feedback perturbation is applied to block the abnormal session, specifically including: When the risk entropy value output by the risk entropy calculation model exceeds the adaptive threshold, the chaotic trajectory verification process is triggered. The user baseline trajectory is generated by solving the Lorenz differential equation group and the spatiotemporal coordinate sequence of the user input trajectory is collected in real time. Based on the Lyapunov exponent difference between the user's baseline trajectory and the spatiotemporal coordinate sequence, it determines whether the operator is an automated script. If the verification fails, multimodal biometric authentication is initiated; During the biometric authentication phase, dynamic time warping matching of pressure waveforms and correlation analysis of device micro-vibrations are performed simultaneously. When the similarity of the two exceeds the respective preset thresholds, the user is identified as a legitimate user. For sessions that fail verification, tactile feedback perturbations with stochastic resonance characteristics are applied until the abnormal session is terminated or passes verification.

[0147] In this embodiment, the risk entropy calculation model continuously assesses the risks during the use of mobile applications and outputs a risk entropy value. The system monitors changes in the risk entropy value in real time. The adaptive threshold is dynamically adjusted based on the historical risk data of the mobile application, user behavior patterns, and the current security environment. For example, during normal user usage, if the application environment is relatively stable, the threshold can be set relatively low; while during high-risk periods (such as late at night, specific holidays, etc.) or when suspicious activities are detected, the threshold can be appropriately increased. When the risk entropy value output by the risk entropy calculation model exceeds the adaptive threshold, the system determines that the current user behavior has a high risk and triggers the chaotic trajectory verification process.

[0148] The Lorenz differential equations are a mathematical model that can produce chaotic phenomena, and the trajectories they generate are highly random and unpredictable. In this embodiment, the Lorenz differential equations are used to generate the user's baseline trajectory. During the generation process, appropriate initial parameters are set. These parameters can be personalized according to the user's identity characteristics or device information to improve the uniqueness and security of the baseline trajectory. After triggering the chaotic trajectory verification process, the system collects the spatiotemporal coordinate sequence of the user's input trajectory on the mobile application interface in real time. These coordinate sequences record information such as the starting point, movement path, and end point of the user's touch operation, which can reflect the user's operating habits and real-time behavioral characteristics.

[0149] The Lyapunov exponent is an indicator that measures the sensitivity of a chaotic system to initial conditions. In this embodiment, the difference in the Lyapunov exponent between the user's baseline trajectory and the input trajectory collected in real time is calculated to determine whether the operator is an automated script. The operations of automated scripts are generally regular and predictable, and the Lyapunov exponent of their trajectory differs from the baseline trajectory generated by human users. By analyzing the user's baseline trajectory and the time-space coordinate sequence collected in real time, the Lyapunov exponent of the two is calculated. If the difference exceeds a certain threshold, it indicates that the operator's behavior pattern is significantly different from that of a normal human user, and it is preliminarily determined that it may be an automated script. At this time, the multimodal biometric authentication process is initiated.

[0150] During the biometric authentication phase, real-time pressure waveform data is collected during the user's touch process. Pressure waveforms reflect the force variations during a user's touch and are a form of biometric identification. Dynamic time warping (DWT) is used to match the collected pressure waveforms with pre-stored, legitimate user pressure waveform templates. Dynamic time warping (DWT) is a method used to compare the similarity between two time series. It can process waveform data of varying lengths and speeds, determining the degree of similarity between the user's pressure waveform and the template.

[0151] Utilizing components such as the mobile device's accelerometer, the system collects real-time microvibration data generated during device use. This microvibration data captures subtle characteristics of the user's movements when operating the device. Correlation analysis is performed between this data and a database of microvibration signatures from legitimate users. By comparing microvibration characteristics such as frequency, amplitude, and timing, the system determines whether the current user is legitimate.

[0152] Preset thresholds are set for pressure waveform dynamic time warping and device micro-vibration correlation analysis. These thresholds are derived from data collected and analyzed from a large number of legitimate users and can distinguish legitimate users from unauthorized intruders. When the similarity between pressure waveform dynamic time warping and device micro-vibration correlation analysis exceeds the respective preset thresholds, the user is deemed legitimate and allowed to continue accessing the mobile app. If either similarity exceeds the threshold, the user is deemed unverified.

[0153] Tactile feedback perturbation leverages the principle of stochastic resonance, introducing random vibration signals into the tactile feedback device to disrupt the operations of automated scripts or unauthorized users while minimizing the impact on authorized users. For unverified sessions, the system automatically applies tactile feedback perturbations with stochastic resonance characteristics, such as irregular vibration patterns and varying vibration intensities. The duration and intensity of the perturbation are dynamically adjusted based on the risk entropy value, with higher risk entropy values ​​resulting in greater perturbation intensity. The tactile feedback perturbation continues until the abnormal session terminates (e.g., the user actively logs out, the system forcibly disconnects) or passes verification (e.g., successful chaotic trajectory verification or multimodal biometric authentication).

[0154] In this embodiment, a hierarchical response mechanism can be effectively triggered when the risk entropy value is abnormal, illegal users can be accurately identified through chaotic trajectory verification and multimodal biometric authentication, and abnormal sessions can be blocked by using tactile feedback disturbances, providing multi-level security protection for mobile applications.

[0155] In some embodiments, in steps S101 to S105 above, the method further includes: Obtain the abnormal data stream of the abnormal session and extract the basis vector set that represents the essential characteristics of the adversarial pattern through orthogonal constraint decomposition of the sparse autoencoder; The basis vector set is input into the teacher-student knowledge distillation framework, and a lightweight adversarial feature dictionary is generated through temperature-adjusted probability distribution alignment and cross-entropy joint optimization. Based on a lightweight adversarial feature dictionary, a federated learning update protocol with differential privacy protection is constructed. The model parameters of each edge node are aggregated by weighted average to form a global adversarial feature cloud. Based on the global adversarial feature cloud, the dual-channel adversarial generation network and the residual attention dual-stream network are optimized.

[0156] In this embodiment, a real-time monitoring system is deployed within the mobile application's operating environment to continuously monitor user sessions. By analyzing user behavior patterns, operation frequency, data interaction characteristics, and other indicators, reasonable anomaly detection rules are established. For example, if a user suddenly performs a large number of abnormal operations, or if their behavior deviates significantly from their normal pattern, this is considered an abnormal session. Once an abnormal session is identified, relevant data streams are extracted from the session. These data streams may include user input data, internal application operation logs, network communication data, and so on.

[0157] A sparse autoencoder is a neural network model for unsupervised learning that can automatically learn a sparse representation of input data. In this embodiment, a sparse autoencoder is used to extract features from an abnormal data stream. In order to extract a set of basis vectors that characterize the essential features of the adversarial pattern, an orthogonal constraint is introduced during the training of the sparse autoencoder. The orthogonal constraint requires that the extracted basis vectors are mutually orthogonal, which ensures the independence and discrimination of the basis vectors. By iteratively training the sparse autoencoder, it is able to learn representative basis vectors from the abnormal data stream. These basis vectors constitute a set of basis vectors that characterize the essential features of the adversarial pattern.

[0158] A complex and high-performing model is selected as the teacher model. This model is capable of extracting rich feature information from the basis vector set. A lightweight model is also selected as the student model. The student model aims to learn from the teacher model's knowledge to achieve feature compression and lightweighting. The basis vector set is input into the teacher-student knowledge distillation framework. The teacher model processes the basis vector set and generates a corresponding probability distribution. The student model learns feature representations by mimicking the teacher model's probability distribution.

[0159] During the knowledge distillation process, a temperature parameter is introduced to adjust the probability distributions output by the teacher and student models. The temperature parameter controls the smoothness of the probability distribution. A higher temperature makes the probability distribution smoother, which helps the student model learn the generalization capabilities of the teacher model. A lower temperature makes the probability distribution sharper, highlighting important features.

[0160] Through temperature-adjusted probability distribution alignment, the output probability distributions of the teacher and student models are made as similar as possible. Simultaneously, the student model's training is jointly optimized using a cross-entropy loss function. The cross-entropy loss function measures the difference between the student model's output and the teacher model's output. By continuously adjusting the student model's parameters, it better learns from the teacher model's knowledge, ultimately generating a lightweight adversarial feature dictionary. This dictionary contains lightweight adversarial features extracted from a set of basis vectors. These features effectively represent the essential information of the adversarial pattern while having low computational and storage overhead.

[0161] In the mobile application security protection system, each mobile device or local server serves as an edge node, while the central server serves as the central node. Edge nodes are responsible for collecting and processing local anomaly data and performing preliminary feature extraction and model training using a lightweight adversarial feature dictionary. The central node aggregates the model parameters of each edge node to form a global model. To protect the privacy of user data, differential privacy is introduced into the federated learning process. Differential privacy adds an appropriate amount of noise to the model parameters of edge nodes, preventing attackers from inferring specific information about individual users from the aggregated global model.

[0162] Each edge node is assigned a different weight based on factors such as its data volume and quality. Edge nodes with large amounts of high-quality data are assigned higher weights, and their model parameters have a greater impact on the global model during the aggregation process. The central node aggregates the model parameters of each edge node using a weighted average method. A global adversarial feature cloud is formed by multiplying the model parameters of each edge node by their corresponding weights, then summing and averaging the results. This global adversarial feature cloud contains comprehensive adversarial feature information learned from each edge node, and can more comprehensively reflect adversarial patterns across different users and scenarios.

[0163] The feature information from the global adversarial feature cloud is incorporated into the input of a two-channel GAN. A two-channel GAN ​​typically consists of two components: a generator and a discriminator. By fusing global adversarial features with the original input data, the generator can generate more adversarial samples, and the discriminator can more accurately identify adversarial samples. Based on the characteristics of the global adversarial feature cloud, the structure of the two-channel GAN ​​is appropriately adjusted. For example, certain network layers can be added or removed, and layer parameters can be adjusted to improve the network's efficiency in utilizing adversarial features.

[0164] The residual attention two-stream network uses an attention mechanism to focus on important feature information. Based on the global adversarial feature cloud, the weight distribution of the attention mechanism is adjusted to enable the network to focus more on the key features of the adversarial pattern, improving the detection and recognition of adversarial examples. Residual connections can address the vanishing gradient problem in deep networks. Based on the impact of the global adversarial feature cloud on network performance, the residual connection configuration is optimized, such as adjusting the connection method and number of residual blocks, to improve the stability and performance of the residual attention two-stream network.

[0165] In this embodiment, adversarial features can be effectively extracted from abnormal sessions, a lightweight adversarial feature dictionary can be generated, and model updates under differential privacy protection can be achieved through federated learning. Finally, the dual-channel adversarial generative network and the residual attention dual-stream network can be optimized to provide mobile applications with more powerful security protection capabilities.

[0166] Reference Figure 2 An embodiment of the present invention provides a false user identification system 2 for mobile applications, the system 2 specifically comprising: A first recognition module 201 is configured to synchronously implement spatiotemporal coupled acquisition of the capacitive touch layer and the inertial measurement unit through a multi-sensor fusion architecture of the mobile terminal to generate a multi-dimensional interaction feature matrix, wherein the multi-dimensional interaction feature matrix includes pressure gradient tensor, touch differential geometry, multi-finger cooperative phase, and device posture compensation; The second recognition module 202 is used to generate an adversarial perturbation pattern with boundary constraints based on the multi-dimensional interactive feature matrix using a dual-channel adversarial generative network, perform sample stream comparative analysis using a residual attention dual-stream network, and output abnormal pattern recognition parameters in the adversarial feature space; The third recognition module 203 is used to take the abnormal pattern recognition parameters and the original data as input, and perform multimodal fusion through a hybrid architecture of spatiotemporal graph convolution and LSTM to form a composite fingerprint code that includes time-varying behavioral characteristics and device physical properties; The fourth identification module 204 is used to establish a risk entropy value calculation model based on the hidden Markov model according to the dynamic evolution of the composite fingerprint code; The fifth identification module 205 is configured to trigger a hierarchical response mechanism including chaotic trajectory verification and multimodal biometric authentication when the risk entropy value output by the risk entropy value calculation model exceeds an adaptive threshold, and apply tactile feedback disturbance to block abnormal conversations.

[0167] It is understandable that if Figure 1 The contents of the embodiment of the false user identification method for mobile applications shown in FIG. 1 are applicable to the embodiment of the false user identification system for mobile applications. The functions specifically implemented by the embodiment of the false user identification system for mobile applications are similar to those in FIG. Figure 1 The embodiment of the false user identification method for mobile applications shown in FIG. 1 is the same as that shown in FIG. 1 , and the beneficial effects achieved are the same as those of FIG. Figure 1 The beneficial effects achieved by the embodiment of the false user identification method for mobile applications shown are also the same.

[0168] It should be noted that the information interaction, execution process and other contents between the above-mentioned systems are based on the same concept as the embodiment of the method of the present invention. Their specific functions and technical effects can be found in the method embodiment part and will not be repeated here.

[0169] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the system can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.

[0170] Reference Figure 3 An embodiment of the present invention further provides a computer device 3, comprising: a memory 302, a processor 301, and a computer program 303 stored in the memory 302. When the computer program 303 is executed on the processor 301, the false user identification method for a mobile application as described in any one of the above methods is implemented.

[0171] The computer device 3 may be a desktop computer, a notebook computer, a PDA, a cloud server or other computing devices. The computer device 3 may include, but is not limited to, a processor 301 and a memory 302. Those skilled in the art will understand that Figure 3 This is merely an example of the computer device 3 and does not constitute a limitation on the computer device 3 . The computer device 3 may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, the computer device 3 may also include input and output devices, network access devices, etc.

[0172] The processor 301 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. A general-purpose processor may be a microprocessor or any conventional processor.

[0173] In some embodiments, the memory 302 may be an internal storage unit of the computer device 3, such as a hard drive or memory of the computer device 3. In other embodiments, the memory 302 may also be an external storage device of the computer device 3, such as a plug-in hard drive, a Smart Media Card (SMC), a Secure Digital (SD) card, a flash memory card, etc. equipped on the computer device 3. Furthermore, the memory 302 may include both an internal storage unit of the computer device 3 and an external storage device. The memory 302 is used to store an operating system, application programs, a boot loader, data, and other programs, such as the program code of the computer program. The memory 302 may also be used to temporarily store data that has been output or is about to be output.

[0174] An embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the method for identifying false users of mobile applications as described in any one of the above methods is implemented.

[0175] In this embodiment, if the integrated unit is implemented as a software functional unit and sold or used as a standalone product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application can implement all or part of the process steps in the above-mentioned method embodiments by using a computer program to instruct the relevant hardware. The computer program can be stored in a computer-readable storage medium. When executed by a processor, the computer program can implement the steps of each of the above-mentioned method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium can include at least: any entity or device capable of carrying computer program code to a camera / terminal device, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signals, telecommunication signals, and software distribution media. Examples include USB flash drives, removable hard drives, magnetic disks, or optical disks. In some jurisdictions, based on legislation and patent practice, computer-readable media cannot be electric carrier signals or telecommunication signals.

[0176] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.

[0177] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0178] In the embodiments disclosed in the present application, it should be understood that the disclosed devices / terminal equipment and methods can be implemented in other ways. For example, the device / terminal equipment embodiments described above are merely schematic. For example, the division of the modules or units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0179] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

Claims

1. A method for identifying fake users of mobile applications, characterized in that: The method specifically includes: Through the multi-sensor fusion architecture of the mobile terminal, the spatiotemporal coupling acquisition of the capacitive touch layer and the inertial measurement unit is synchronously implemented to generate a multi-dimensional interaction feature matrix, which includes the pressure gradient tensor, touch differential geometry, multi-finger cooperative phase and device posture compensation; Based on the multi-dimensional interactive feature matrix, a dual-channel adversarial generative network is used to generate adversarial perturbation patterns with boundary constraints. The residual attention two-stream network is used to perform comparative analysis of sample streams and output abnormal pattern recognition parameters in the adversarial feature space. Taking abnormal pattern recognition parameters and raw data as input, multimodal fusion is performed through a hybrid architecture of spatiotemporal graph convolution and LSTM to form a composite fingerprint code that includes time-varying behavioral characteristics and device physical properties. According to the dynamic evolution of composite fingerprint coding, a risk entropy value calculation model based on the hidden Markov model is established; When the risk entropy value output by the risk entropy calculation model exceeds the adaptive threshold, a hierarchical response mechanism including chaotic trajectory verification and multimodal biometric authentication is triggered, and tactile feedback perturbation is applied to block abnormal conversations.

2. The method according to claim 1, characterized in that The multi-sensor fusion architecture of the mobile terminal is used to synchronously implement spatiotemporal coupling acquisition of the capacitive touch layer and the inertial measurement unit to generate a multi-dimensional interactive feature matrix, specifically including: Real-time acquisition of touch pressure distribution data through the capacitive touch layer of the mobile terminal, and simultaneous acquisition of six-degree-of-freedom motion parameters through the inertial measurement unit of the mobile terminal; Based on the pressure distribution data and six-degree-of-freedom motion parameters, a least-squares calibration model is used to perform time synchronization and obtain synchronized data streams. Based on the synchronous data stream, the spatial transformation operation of the posture compensation matrix is ​​used to eliminate the offset effect of the device holding posture on the touch coordinates and obtain the compensated touch trajectory; Based on the compensated touch trajectory, the pressure gradient tensor is calculated and the mutation point features of the touch trajectory curvature are extracted; Based on the pressure gradient tensor and mutation point features, combined with the phase difference analysis of multi-finger touch, a multi-dimensional interaction feature matrix for behavior recognition is generated.

3. The method according to claim 1, characterized in that Based on the multi-dimensional interactive feature matrix, a dual-channel adversarial generative network is used to generate an adversarial perturbation pattern with boundary constraints, and a residual attention dual-stream network is used to perform sample stream comparative analysis to output abnormal pattern recognition parameters in the adversarial feature space. Specifically, the following steps are involved: Based on the multi-dimensional interactive feature matrix, a conditional Wasserstein generative adversarial network is constructed. By concatenating the latent space noise vector and the conditional vector, an adversarial perturbation pattern with gradient penalty constraints is generated. The adversarial perturbation pattern and the original feature matrix are combined and input into the residual attention two-stream network, performing multi-scale convolution operations in the original stream and the adversarial stream respectively; Through learnable channel attention weights, the attention heatmaps of the original stream and the adversarial stream at each convolutional layer are calculated; According to the Frobenius norm difference between the attention heat maps of the original stream and the adversarial stream, the adversarial loss value representing the abnormal pattern is output.

4. The method according to claim 1, wherein The abnormal pattern recognition parameters and raw data are used as input, and multimodal fusion is performed through a hybrid architecture of spatiotemporal graph convolution and LSTM to form a composite fingerprint code that includes time-varying behavioral characteristics and device physical properties. Specifically, it includes: Based on the abnormal pattern recognition parameters and raw data, a spatiotemporal topological map of the touch trajectory is constructed, and the edge weight matrix of the spatiotemporal topological map is determined by dynamically calculating the similarity of pressure gradients between nodes. By performing spatiotemporal joint convolution on the spatiotemporal topological graph using a deformable 3D convolution kernel, we can extract node feature vectors containing local abnormal patterns. The node feature vector is sliced ​​by time window and input into the bidirectional LSTM network for time series modeling to generate hidden state features that represent the continuity of behavior; The features of the spatiotemporal topological graph and the latent state features are weightedly fused through the gated attention mechanism, and the output is a composite fingerprint code that includes time-varying behavioral features and device physical properties.

5. The method according to claim 1, wherein The risk entropy value calculation model based on the hidden Markov model is established according to the dynamic evolution of the composite fingerprint code, which specifically includes: Based on the temporal changes of the composite fingerprint code, a three-state hidden Markov model including normal state, transition state and abnormal state is constructed, and the state transition matrix and observation probability distribution of the three-state hidden Markov model are initialized; Based on the three-state hidden Markov model, the forward-backward algorithm is used to calculate the hidden state probability distribution at each moment, and the transition probability pointing to the high-risk state in the state transition matrix is ​​extracted; Based on the hidden state probability distribution and transition probability, the risk entropy value that characterizes the abnormality of the behavior is calculated.

6. The method according to claim 1, characterized in that When the risk entropy value output by the risk entropy value calculation model exceeds the adaptive threshold, a hierarchical response mechanism including chaotic trajectory verification and multimodal biometric authentication is triggered, and tactile feedback perturbations are applied to block abnormal conversations, specifically including: When the risk entropy value output by the risk entropy calculation model exceeds the adaptive threshold, the chaotic trajectory verification process is triggered. The user baseline trajectory is generated by solving the Lorenz differential equation group and the spatiotemporal coordinate sequence of the user input trajectory is collected in real time. Based on the Lyapunov exponent difference between the user's baseline trajectory and the spatiotemporal coordinate sequence, it determines whether the operator is an automated script. If the verification fails, multimodal biometric authentication is initiated; During the biometric authentication phase, dynamic time warping matching of pressure waveforms and correlation analysis of device micro-vibrations are performed simultaneously. When the similarity of the two exceeds the respective preset thresholds, the user is identified as a legitimate user. For sessions that fail verification, tactile feedback perturbations with stochastic resonance characteristics are applied until the abnormal session is terminated or passes verification.

7. The method according to any one of claims 1 to 6, characterized in that The method further comprises: Obtain the abnormal data stream of the abnormal session and extract the basis vector set that represents the essential characteristics of the adversarial pattern through orthogonal constraint decomposition of the sparse autoencoder; The basis vector set is input into the teacher-student knowledge distillation framework, and a lightweight adversarial feature dictionary is generated through temperature-adjusted probability distribution alignment and cross-entropy joint optimization; Based on a lightweight adversarial feature dictionary, a federated learning update protocol with differential privacy protection is constructed. The model parameters of each edge node are aggregated by weighted average to form a global adversarial feature cloud. Based on the global adversarial feature cloud, the dual-channel adversarial generation network and the residual attention dual-stream network are optimized.

8. A false user identification system for mobile applications, characterized in that: The system specifically includes: A first identification module is configured to synchronously implement spatiotemporal coupled acquisition of the capacitive touch layer and the inertial measurement unit through a multi-sensor fusion architecture of the mobile terminal to generate a multi-dimensional interaction feature matrix, wherein the multi-dimensional interaction feature matrix includes a pressure gradient tensor, touch differential geometry, multi-finger cooperative phase, and device posture compensation; The second recognition module is used to generate adversarial perturbation patterns with boundary constraints based on a multi-dimensional interactive feature matrix using a dual-channel adversarial generative network, perform sample stream comparative analysis using a residual attention two-stream network, and output abnormal pattern recognition parameters in the adversarial feature space; The third recognition module is used to take the abnormal pattern recognition parameters and raw data as input, and perform multimodal fusion through a hybrid architecture of spatiotemporal graph convolution and LSTM to form a composite fingerprint code that includes time-varying behavioral characteristics and device physical properties; The fourth identification module is used to establish a risk entropy value calculation model based on the hidden Markov model according to the dynamic evolution of the composite fingerprint code; The fifth identification module is used to trigger a hierarchical response mechanism including chaotic trajectory verification and multimodal biometric authentication when the risk entropy value output by the risk entropy value calculation model exceeds an adaptive threshold, and apply tactile feedback perturbation to block abnormal conversations.

9. A computer device, characterized in that: include: A memory, a processor, and a computer program stored in the memory, which, when executed on the processor, implements the false user identification method for a mobile application according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that A computer program is stored thereon, and when the computer program is executed by a processor, the false user identification method for a mobile application according to any one of claims 1 to 7 is implemented.