Information security supervision AI platform

By employing quantum key distribution and multi-factor authentication, quantum random number privacy protection, and adversarial training models, we have solved the problems of data access security and model robustness, achieved efficient information security management, and reduced the risks of data leakage and compliance.

CN120744959BActive Publication Date: 2026-04-10GUANGDONG RONGTIAN CENTURY INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-07
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Existing technologies are insufficient in defending against AI-driven dynamic attacks, have poor data access security, cannot defend against quantum computing threats with anonymized data, and lack sufficient verification of the legitimacy of data sources, resulting in high risks of data leakage and significant legal risks.

Method used

We employ quantum key distribution and multi-factor dynamic verification mechanisms to isolate data access, combine quantum random numbers and adaptive differential privacy for dual privacy protection, use adversarial training and knowledge distillation models to enhance attack detection, construct a threat graph for source tracing, and generate an interpretable ethical assessment report through a quantum entanglement verification mechanism.

Benefits of technology

It improves data access security, enhances the robustness and privacy protection capabilities of the model, ensures the authenticity and integrity of data interaction, meets compliance requirements, and reduces data leakage and legal risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120744959B_ABST
    Figure CN120744959B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of information security, and discloses an information security supervision AI platform, a dynamic access control module configured to generate equivalent requests to isolate direct interaction of original requests and a database through a quantum key distribution and a multi-factor dynamic verification mechanism, an AI countermeasure defense engine configured to enhance detection robustness of an AI model to variant attacks based on a countermeasure training and a knowledge distillation model, and to intelligently trace an attack chain by constructing a threat graph, a data management module configured to perform double privacy protection on anonymous data by combining quantum random numbers and adaptive differential privacy, to perform secondary homomorphic encryption processing on the anonymous data, and to automatically classify and grade sensitive data based on a context-aware large model, and a report generation module configured to generate an explainability ethics evaluation report through a quantum entanglement verification mechanism. The platform improves information security supervision efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of information security, and particularly relates to an information security supervision AI platform. BACKGROUND

[0002] In the field of network information security today, the information security management of data centers and servers faces many severe challenges.

[0003] The traditional static defense system highly depends on rule engines and feature library matching, and is not capable of dealing with AI-driven dynamic attacks such as variant ransomware and automated phishing attacks. These new attack methods are constantly mutating and evolving, and the traditional defense system is difficult to quickly adapt and effectively respond. In terms of data access, the direct access to the database exposes the attack surface, and there is a lack of dynamic relay verification mechanism for access requests, which provides an opportunity for injection attacks, and data is vulnerable to theft or tampering. In terms of privacy protection, anonymized data is only simply processed, and in the face of the rapid development of quantum computing, it has been unable to resist the threat brought by quantum computing, and data privacy may be leaked at any time. Secondly, in the model training process, the problem of insufficient verification of the legitimacy of data sources is widespread. For example, sensitive data without desensitization is used for AI training, which not only violates relevant laws and regulations, but also may cause serious data security accidents, and makes enterprises and users face huge legal risks.

[0004] Therefore, an information security supervision technology based on AI technology is urgently needed to improve the efficiency of information security management. SUMMARY

[0005] The purpose of the present application is to provide an information security supervision AI platform to solve the technical problems raised in the background.

[0006] To achieve the above purpose, the present application discloses the following technical scheme: an information security supervision AI platform, comprising:

[0007] The dynamic access control module is configured to generate equivalent requests to isolate the direct interaction of the original request and the database through quantum key distribution and multi-factor dynamic verification mechanism, and protect the data access security;

[0008] The AI countermeasure defense engine is configured to enhance the detection robustness of the AI model to variant attacks based on the countermeasure training and knowledge distillation model, and intelligently trace the attack chain by constructing a threat graph;

[0009] The data governance module is configured to perform double privacy protection by combining quantum random numbers and adaptive differential privacy, perform secondary homomorphic encryption processing on anonymous data, and automatically classify and grade sensitive data based on a context-aware large model;

[0010] The report generation module is configured to generate an explainability ethics assessment report through a quantum entanglement verification mechanism.

[0011] As a preference, the quantum key distribution specifically includes:

[0012] The sender and the receiver respectively generate random sequences;

[0013] The generated random sequences are transmitted through quantum channels to form quantum states;

[0014] The corresponding base sequences of the sender and the receiver are compared to form an original key;

[0015] The original key is subjected to a privacy amplification algorithm to obtain a final key.

[0016] As a preference, the multi-factor dynamic verification mechanism includes operation timing verification, which specifically includes:

[0017] An operation feature matrix is constructed by extracting a user operation sequence;

[0018] The operation sequence similarity is calculated through a spatio-temporal graph neural network, and a verification result is obtained through a graph attention mechanism.

[0019] As a preference, the knowledge distillation model is an improved GhostNet architecture, and the feature extraction layer of the improved GhostNet architecture adopts a quantum-inspired attention mechanism.

[0020] As a preference, the quantum-inspired attention mechanism specifically includes:

[0021]

[0022] wherein, is a quantum random number , is an input feature, , is a learnable weight matrix, is a Sigmoid function, is an element-wise multiplication.

[0023] As a preference, the loss function of the improved GhostNet architecture is:

[0024]

[0025] wherein, is a hyperparameter, is a cross-entropy loss, is a student model prediction probability, is a true label, is a student model, for the teacher model, for the temperature parameter, for the adjustment parameter, for variance calculation.

[0026] As a preferred, the threat graph construction step specifically includes:

[0027] Constructing a heterogeneous graph , the node type includes process , file , user and network connection , the edge represents the relationship between entities;

[0028] Semantic analysis is performed on the natural language query , and entity constraints , time range and query intention are extracted;

[0029] Obtain graph neural network computing node representation , the expression is:

[0030]

[0031] wherein, is a normalization constant, is the weight matrix of the layer, is an activation function, and are the time corresponding to nodes v and u respectively, is an adjustment parameter;

[0032] Generate a trace path based on a query-aware attention mechanism, and the query vector is calculated as , wherein, is a quantum random number, is a classification label output by a BERT encoder, and are learnable parameters;

[0033] Calculate the relevance score of the node to the query , is the transpose of the vector , and the top k relevant entities are output in order of score.

[0034] As a preferred, the homomorphic encryption of the data governance module supports risk assessment in the ciphertext state, and the risk assessment specifically includes the following steps:

[0035] Homomorphic feature extraction is performed on the ciphertext data C to generate a ciphertext feature vector ;

[0036] The ciphertext state nonlinear transformation is performed based on Chebyshev polynomial approximation, and the calculation formula is: wherein, is a k-order Chebyshev polynomial, is a polynomial coefficient;

[0037] The ciphertext risk score is calculated wherein, is a ciphertext weight, is a ciphertext bias;

[0038] The determination result When , it indicates that the risk degree of the current processed ciphertext data is high, and there is potential risk; when , it indicates that the risk degree of the current ciphertext data is low.

[0039] As preferred, the sensitive data classification and grading specifically comprises: constructing a multi-modal feature extractor to extract multiple features, calculating a comprehensive feature vector based on a quantum entanglement-inspired feature fusion mechanism, classifying by using a quantum neural network, measuring an output quantum state, calculating a classification probability, and outputting a data type; wherein the output data type includes ordinary data, sensitive data and highly sensitive data.

[0040] As preferred, the report generation module outputs a generative AI ethics evaluation report, forces manual review for high-risk operations, adopts a fairness index based on quantum entanglement fairness measurement, an explainability index based on quantum entropy feature importance distribution, and a robustness index based on model stability measurement of quantum adversarial perturbation, and calculates a comprehensive ethics score.

[0041] Beneficial effects: the information security supervision AI platform of the present application, the dynamic access control module greatly improves the security of data access through dynamic access control and quantum security relay system with quantum key distribution and multi-factor dynamic verification technology; the AI adversarial defense engine significantly enhances the robustness of the model through adversarial training and knowledge distillation technology, the data governance module realizes double privacy protection combined with quantum random number and adaptive differential privacy, and supports risk assessment in the ciphertext state; the report generation module ensures the compliance of model training through the quantum entanglement verification mechanism, effectively avoids the risk of using unauthorized or sensitive data for training, and adaptive differential privacy dynamically adjusts the privacy budget and noise addition according to the data characteristics, better balancing data privacy protection and usability; and, the report generation module guarantees the authenticity and integrity of data interaction through the quantum entanglement verification mechanism, comprehensively improves the security and reliability of the platform, and provides a comprehensive and efficient solution for information security management of data centers and servers. BRIEF DESCRIPTION OF DRAWINGS

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0043] Figure 1 The structural block diagram of the information security supervision AI platform provided by the embodiments of the present application. DETAILED DESCRIPTION

[0044] The technical solutions in the embodiments of the present application will be described clearly and completely below. Obviously, the described embodiments are only some of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0045] In this document, the term "comprising" is intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the elements defined by the statement "comprising" do not exclude the presence of other identical elements in the process, method, article or device including the elements.

[0046] To solve the problems of high data leakage risk, new attack detection lag, and multi-source heterogeneous data governance difficulty in the prior art, the embodiment provides an information security supervision AI platform fusing dynamic access control, AI countermeasure defense, and privacy enhancement technology, as shown in Figure 1 The information security supervision AI platform fusing dynamic access control, AI countermeasure defense, and privacy enhancement technology comprises a dynamic access control module, an AI countermeasure defense engine, a data governance module, and a report generation module.

[0047] The dynamic access control module is configured to generate equivalent requests to isolate direct interaction of original requests with a database through a quantum key distribution and a multi-factor dynamic verification mechanism, and protect data access security.

[0048] The AI countermeasure defense engine is configured to enhance the detection robustness of AI models to variant attacks based on an adversarial training and a knowledge distillation model, and intelligently trace an attack chain by constructing a threat graph.

[0049] The data governance module is configured to perform double privacy protection by combining quantum random numbers and adaptive differential privacy, perform homomorphic encryption processing on anonymous data twice, and automatically classify and grade sensitive data based on a context-aware large model.

[0050] The report generation module is configured to generate an explainability ethics evaluation report through a quantum entanglement verification mechanism.

[0051] In detail, the dynamic access control module is used to encrypt access requests through a post-quantum cryptography algorithm (such as a NIST standard algorithm), generate equivalent requests to isolate direct interaction of original requests with a database, and perform multi-factor dynamic verification on behavior biometrics (such as operation timing) and an IP reputation library to trigger sandbox isolation review for abnormal access. The AI countermeasure defense engine is used to generate adversarial samples based on a projected gradient descent to enhance the robustness of models to variant attacks, integrate a lightweight knowledge distillation model (such as MobileNet) to reduce computational delay, and construct a threat graph based on an ATT&CK framework, restore an attack path through time sequence reasoning and 3D visualization. The data governance module is used to implement double privacy protection by combining a generative adversarial network and Laplacian noise in a data anonymization stage, perform homomorphic encryption on anonymous data twice, automatically classify and grade sensitive data based on the context awareness of a large model, and realize real-time protection by linking a desensitization strategy library. The report generation module is used to construct an isolated AI training environment to verify data desensitization effects and model compliance, display violation judgment basis through an attention weight heat map, and embed dynamic ethics review rules.

[0052] In an implementation, the steps of encrypting access requests by the post-quantum cryptography algorithm are as follows:

[0053] Step 1: Generate an initial key based on the principle of quantum entanglement is distributed by BB84 protocol;

[0054] Step 2: Adopt CRYSTALS-Kyber algorithm, introduce dynamic noise parameter in key generation stage , the calculation formula is: , wherein H is a hash function, is a timestamp, is a dynamic noise parameter generated based on a quantum random number generator, the value range is 0.1-0.9, and the dynamic noise parameter is calculated by the following formula: , wherein is a quantum random number generator output value, is the maximum value of the generator.

[0055] Further, the quantum key distribution specifically includes:

[0056] Step 1: The sender generates a random bit sequence and base sequence , and the receiver generates a random base sequence ;

[0057] Step 2: The generated random sequence is transmitted through a quantum channel , wherein

[0058]

[0059] Step 3: Both sides disclose and compare the base sequence, retain the bits corresponding to the matching base pair, and form an original key ;

[0060] Step 4: The original key is obtained by a privacy amplification algorithm to obtain a final key , the calculation formula is:

[0061] , wherein is a quantum-resistant hash function (such as Xoodyak), is a hash value generated by a quantum random number generator, and the hash value is calculated by the following formula:

[0062] , wherein is an n-bit quantum random number, is a timestamp, is a system random number.

[0063] In an embodiment, the multi-factor dynamic verification mechanism includes operation timing verification, and the operation timing verification specifically includes:

[0064] Step 1: Extract the user operation sequence , wherein, represents the i-th operation event, including operation type , operation time and operation parameters ;

[0065] Step 2: Construct the operation feature matrix , where the i-th row represents the feature vector of the i-th operation , including time interval , operation type encoding and parameter statistical features ;

[0066] Step 3: Calculate the operation sequence similarity using spatio-temporal graph neural network, the graph structure

[0067] Node represents the operation feature vector;

[0068] The weight of edge E represents the association strength between operations i and j, calculated by the formula: , where , and are learnable parameters, is the operation type similarity function;

[0069] Step 4: Calculate the node importance score through graph attention mechanism , and output the verification result: , where is the attention weight, W is the weight matrix, is the neighbor set of node i.

[0070] In one embodiment, an equivalent request is generated to isolate the direct interaction of the original request with the database, specifically including the following steps:

[0071] Step 1 - First, parse the original access request and extract key information such as the operation type of the request (e.g. query, insert, update, etc., denoted as O ), the data table or data object involved (denoted as T ), and the request parameters (denoted as P ). For example, if the original request is "query user information with user ID 123 from the user table", then O is the query operation, T is the user table, P is the user ID = 123;

[0072] ​Step 2 - Quantum Encryption Processing: The extracted key information is encrypted using a post-quantum cryptographic algorithm. Assuming the encryption function is , the encrypted information is denoted as , and , that is

[0073]

[0074]

[0075]

[0076] Step 3 - Equivalent Request Generation: Based on the encrypted information, an equivalent request is generated in combination with the virtual execution environment . In the virtual execution environment, according to the pre-set mapping rules and security policies, the encrypted information is converted into a request that is equivalent in form and function but different in content from the original request. For example, the original request is a query to the real user table, which can be mapped to a query to a simulated user table in the virtual environment. The data in the simulated user table is processed and disguised, but can guarantee the logical correctness of the query result. Assuming the mapping function is , the equivalent request is constructed as follows:

[0077]

[0078] Step 4 - Request Forwarding and Interaction Isolation: The generated equivalent request is forwarded to the database for processing, while the original request does not directly interact with the database. After the database processes the equivalent request, the result is returned, which is then decrypted and converted by the system to restore the final result corresponding to the original request and returned to the requester. Assuming the decryption function is and the conversion function is , the final result returned to the requester is:

[0079]

[0080] Through the above steps, the equivalent request is generated to isolate the direct interaction between the original request and the database, ensuring the functionality of the database operation is not affected while ensuring the security of data access.

[0081] In an embodiment, the knowledge distillation model is an improved GhostNet architecture, and the feature extraction layer of the improved GhostNet architecture adopts a quantum-inspired attention mechanism.

[0082] In the improved GhostNet architecture, the quantum-inspired attention mechanism is as follows:

[0083]

[0084] where, is a quantum random number , is the input feature, , is a learnable weight matrix, is a Sigmoid function, is an element-wise multiplication.

[0085] In the improved GhostNet architecture, the loss function used is as follows:

[0086]

[0087] where, is a hyperparameter used to balance the relative importance between the cross-entropy loss and the combined loss part containing the KL divergence and the second moment difference ( , is the cross-entropy loss, is the student model prediction probability, is the true label, is the student model, is the teacher model, is the temperature parameter, is the adjustment parameter, is the variance calculation.

[0088] The value range of is usually between 0 and 1. When is close to 1, it means that the model training pays more attention to the direct fitting of the student model to the true label, i.e., the cross-entropy loss plays a dominant role, and more emphasis is placed on the learning effect of the model on the original task.

[0089] When is close to 0, the model training pays more attention to learning knowledge from the teacher model, and the combined loss part containing the KL divergence and the second moment difference has a greater impact on the training. This part of the loss is used to guide the student model to learn the output distribution characteristics of the teacher model, including the shape of the probability distribution (measured by the KL divergence) and the dispersion degree of the distribution (measured by the second moment difference). By adjusting the value of , a balance can be found between the accuracy of the model and the effect of learning knowledge from the teacher model, so as to achieve better model training effect and performance.

[0090] In an embodiment, the threat graph supports natural language interactive tracing, which can display abnormal process associated files in a specified time period. The construction steps of the threat graph specifically include:

[0091] Constructing a heterogeneous graph , the node types include processes , files , users and network connections , and the edges represent the relationship between entities;

[0092] Semantic analysis of natural language queries , extract entity constraints , time range and query intent ;

[0093] Get graph neural network computing node representation , when aggregating neighbor node information, weight according to the time attribute of the node, and the specific calculation formula is:

[0094]

[0095] wherein, is a normalization constant, is the weight matrix of the layer, is the activation function, and are the times corresponding to nodes v and u respectively, is an adjustment parameter;

[0096] Generate a tracing path based on a query-aware attention mechanism, and the query vector The calculation expression is

[0097]

[0098] wherein, is a quantum random number used to increase the randomness of the query vector, is the classification label output by the BERT encoder, and are learnable parameters;

[0099] Calculate the relevance score of the node to the query , is the vector The transpose of the correlation matrix is output in score order, and the top k relevant entities are output, which will be used for accurate presentation of the detailed information of the abnormal process associated files in the specified time period. The system will integrate and display the relevant clues of the abnormal process according to the entity type, from the dimensions of process, file, user and network connection. If the relevant entity contains a file node, it will be directly displayed as an abnormal process associated file. These files may be target files accessed, modified or created by the abnormal process. For process, user and network connection nodes, it is also possible to further mine the file nodes related to them through the edge relationship in the heterogeneous graph. For example, if there is an "access" edge relationship between the process and the file, or the user interacts with the file through the network connection edge relationship, the corresponding file will be determined as an abnormal process associated file, and their association mode, timestamp and other information will be displayed to help users clearly understand the activity path and impact range of the abnormal process. These relevant entities and their associated information not only visually display the abnormal process associated files, but also provide clues for in-depth investigation for security analysts. By analyzing the attributes, relationships and behavior patterns of these entities within a specified time period, security personnel can quickly determine the nature, source and potential harm of the abnormal process, and then develop more effective security strategies, such as blocking malicious processes, repairing system vulnerabilities, and strengthening access control, to protect the information security of the system.

[0100] In an implementation, the homomorphic encryption of the data governance module supports risk assessment in the ciphertext state, which includes the following steps:

[0101] Homomorphic feature extraction is performed on the ciphertext data C to generate a ciphertext feature vector ;

[0102] Based on Chebyshev polynomial approximation, a ciphertext state nonlinear transformation is performed, and the improvement is that on the basis of traditional Chebyshev polynomial approximation, a quantum walk optimization polynomial coefficient search process is introduced, and the calculation formula is , where is a k-order Chebyshev polynomial, is a polynomial coefficient, which is optimized by quantum walk. In the context of homomorphic encryption risk assessment in the ciphertext state, this linear combination is used to approximately realize the nonlinear transformation in the ciphertext state . Different values will make the polynomial combination present different shapes, thereby affecting the approximation effect of the objective function and ultimately affecting the accuracy of the risk assessment in the ciphertext state. Quantum walk is a random process in quantum mechanics. Compared with traditional optimization algorithms, quantum walk uses the superposition and entanglement properties of quantum mechanics to more efficiently search for the optimal solution in the solution space. In this context, the quantum walk algorithm is used to optimize the Optimization is to find a set of optimal values, so that the approximation effect is optimal, so as to improve the accuracy of risk assessment under ciphertext state. Calculate the ciphertext risk score

[0103] , where is the ciphertext weight, is the ciphertext bias; Determine the result

[0104] , when , it means that the risk degree of the current processed ciphertext data is high, and there is potential risk; when , it means that the risk degree of the current ciphertext data is low. This simple and intuitive binary determination result is convenient for the subsequent system to take corresponding measures according to different situations, such as triggering more stringent review process or starting data protection mechanism when the determination result is "1"; when the determination result is "0", the data can be processed according to the normal process.

[0105] In an embodiment, the sensitive data classification and grading specifically includes: constructing a multi-modal feature extractor to extract multiple features, calculating a comprehensive feature vector based on a quantum entanglement inspired feature fusion mechanism, using a quantum neural network for classification, measuring the output quantum state, calculating the classification probability, and outputting the data type; wherein the output data type includes ordinary data, sensitive data and highly sensitive data. The specific steps are as follows:

[0106] Step 1: Construct a multi-modal feature extractor to extract text features , structure features and context features ;

[0107] Step 2: Calculate the comprehensive feature vector based on the quantum entanglement inspired feature fusion mechanism , the calculation formula is , where represents the i-th feature, is the feature importance weight, is the phase angle, , is the quantum state interference term (obtained by simulating the entanglement relationship between features through quantum calculation), represents the L2 norm, and the formula considers the quantum entanglement effect between features. The calculation of the phase angle introduces the quantum state interference term;

[0108] Step 3: Use an improved quantum neural network for classification, and the quantum state evolution equation is:

[0109]

[0110] where, is a parameterized quantum gate, is an input quantum state, is an output quantum state; the quantum state evolution equation introduces an extra phase factor is a quantum control parameter) controls the quantum state evolution;

[0111] Step 4: Measure the output quantum state and calculate the classification probability , represents the computational basis state of class c.

[0112] In a simple example, let the computational basis states corresponding to ordinary data, sensitive data, and highly sensitive data be , and , respectively.

[0113] Calculate the probability that it belongs to ordinary data , assuming the calculation result is .

[0114] Calculate the probability that it belongs to sensitive data , assuming the calculation result is .

[0115] Calculate the probability that it belongs to highly sensitive data , assuming the calculation result is . Finally, determine the data type:

[0116] Compare , and , because , it is determined that the data is highly sensitive data.

[0117] In an embodiment, the report generation module outputs a generative AI ethical evaluation report, forces manual review for high-risk operations, uses a fairness index based on quantum entanglement fairness measurement, an explainability index based on quantum entropy feature importance distribution, and a robustness index based on model stability measurement based on quantum adversarial perturbation, and calculates a comprehensive ethical score. Specifically, the evaluation index includes:

[0118] The fairness index F measures the fairness of the platform's prediction results under different sensitive attributes (such as gender, etc.). The closer F is to 1, the smaller the difference between different sensitive attribute groups in platform decision-making, and the more fair the platform treats users of all types. If a credit evaluation platform has a high F value, it means that users of different genders are treated fairly in credit evaluation and there is no bias due to sensitive attributes. The expression of the fairness index is:​ , is a set of sensitive attributes, is a prediction result, is a number of categories.

[0119] The interpretability index I reflects the degree of interpretability of the model decision-making process. The larger I is, the clearer the dependence of the model output on the input features, and the easier it is for people to understand why the model makes a particular decision. In a medical diagnosis AI model, a higher I value can help doctors understand the basis on which the model judges the disease, increasing the trust in the model's decision. The expression of the interpretability index is: wherein, , is the gradient of the model output to the input feature .

[0120] The robustness index R reflects the stability of the platform when facing quantum adversarial perturbations and other attacks. The closer R is to 1, the stronger the robustness of the platform, and it can still maintain good performance when attacked. In a financial transaction security platform, a high R value means that the platform can effectively maintain normal transactions and protect user funds when facing hacker attacks and other malicious behaviors. The expression of the robustness index is wherein, is the ith quantum adversarial perturbation, is a tuning parameter.

[0121] The comprehensive ethics score S is: .

[0122] In the formula of the comprehensive ethics score, the numerator is the product of the three indexes, which means that only when F, I, and R are all high, the comprehensive ethics score can be high, emphasizing the synergistic effect of the three indexes. If a platform performs poorly in one of the indexes, even if the other two indexes perform well, the comprehensive score will be affected. A platform may have good fairness and interpretability, but poor robustness and be easily attacked, so its comprehensive ethics score will not be high. The denominator normalizes the comprehensive score, ensuring that S is within a reasonable range. It balances the relative importance of the three indexes to some extent, avoiding the excessive influence of a single index on the comprehensive score. If the value of an index is much higher than the other two, the presence of the denominator will appropriately reduce its influence on the comprehensive score, making the comprehensive score more reflective of the platform's overall performance in the three aspects. The value of the comprehensive ethics score S ranges from 0 to 1. The closer S is to 1, the better the platform's overall performance in fairness, interpretability, and robustness, and the better the ethical performance. The closer S is to 0, the greater the problems in these three aspects, and the platform needs to be improved. , it indicates that the platform performs very well in the ethical level, and has good performance in treating different users fairly, model decision explainability and attack resistance. If , it indicates that the platform may have a large deviation in fairness, or the model has poor explainability and insufficient robustness. In practical applications, the values of F, I and R may change as the platform runs and the environment changes, causing the comprehensive ethical score S to also change. Therefore, it is necessary to regularly evaluate the platform and monitor the trend of S changes, so as to discover potential ethical problems in time and take appropriate measures to improve. When new algorithms or data are introduced into the platform, the comprehensive ethical score needs to be re-evaluated to ensure that the new changes do not have a negative impact on the ethical performance of the platform.

[0123] Feasibly, in an implementation, the adaptive differential privacy combines quantum random number generation to generate a dynamic privacy budget when anonymizing data. Specifically as follows:

[0124] First, according to the information entropy of the data and the data volume , the initial privacy budget is calculated, and the calculation formula is ;

[0125] Then, the quantum random number generated by the quantum random number generator is used to dynamically adjust the initial privacy budget, and the adjustment formula is , wherein is the adjustment coefficient;

[0126] According to the data sensitivity and the noise sensitivity , the noise addition amount is dynamically adjusted, .

[0127] The data sensitivity is used to measure the contribution of different data records in the data set to the overall privacy risk. When calculating , the attribute characteristics and business scenarios of the data usually need to be considered. For example, in a data set containing user personal information, attributes such as identity card number and bank card number, which have strong identification and high privacy risk, will be given a higher sensitivity weight. Taking numerical data as an example, the range (maximum value minus minimum value) of the data can be calculated, and then combined with the privacy sensitivity level coefficient k of the attribute to determine , the formula is: , wherein and are the maximum and minimum values of the attribute in the data set, is the mean of the attribute, and k is determined according to the privacy sensitivity of the attribute, and the value range is between 1-10, the higher the privacy risk, the larger the value of k.

[0128] Noise sensitivity mainly measures the influence degree of adding noise on the accuracy of data analysis results. The noise sensitivity is calculated as follows: The characteristics of the data analysis algorithm and the distribution of the data need to be considered. Assuming that the data analysis algorithm is a linear regression model, for a given data set D, the change of the model prediction result can be observed by adding different intensities of noise in the data multiple times to determine . The specific method is as follows: first, linear regression analysis is performed on the original data to obtain the prediction error of the model , then the noise intensity is gradually increased , and after adding noise each time, linear regression analysis is performed again and the prediction error is calculated. By fitting the curve , the noise intensity corresponding to the maximum change rate of the curve is found , and the prediction error at this time is taken as the estimated value of the noise sensitivity , that is . In the scene where data interaction is frequent and data sensitivity fluctuates greatly, the data sensitivity and noise sensitivity are recalculated every certain time interval (such as 1 minute), and the noise addition amount is updated according to the current privacy budget, so as to ensure that the differential privacy requirement is always met in the whole data processing process, while the data usability is maximized.

[0129] It is feasible that, in an implementation, the quantum entanglement verification mechanism verifies the authenticity and integrity of data interaction through the entanglement characteristics of quantum states in model training compliance checking, preventing data tampering and illegal access. The specific implementation is as follows: the data interaction parties respectively prepare entangled quantum pairs and , the sender encodes the data D on to form the encoded quantum state and sends it to the receiver. After receiving , the receiver performs joint measurement with the local , and the measurement result M satisfies a specific entanglement correlation condition (such as the modified condition of Bell inequality If the probability is higher than a certain pre-set threshold (such as 95%), it is determined that the data interaction is real and complete; if it is lower than the threshold, it is determined that the data may be tampered with or there is a transmission error. In order to improve the accuracy of verification, multiple data interactions and measurement verifications can be performed, and statistical analysis can be performed on the verification results of each time.

[0130] In summary, the information security supervision AI platform of the embodiment has the following technical features:

[0131] 1. Strengthening data access security - dynamic access control and quantum security relay system greatly improves the security of data access by means of quantum key distribution and multi-factor dynamic verification technology. BB84 protocol generates final key combined with quantum random number, enhancing the security and randomness of the key; multi-factor dynamic verification considers multiple factors such as operation timing mode, which can accurately identify abnormal access and effectively prevent data leakage, ensuring the security of data in the access process.

[0132] 2. Improve AI defense capability - AI defense engine significantly enhances the robustness of the model through adversarial training and knowledge distillation technology. The improved GhostNet architecture and quantum-inspired attention mechanism greatly improve the detection and defense capabilities of the model against variant attacks; the constructed threat map combined with timing reasoning and 3D visualization can clearly restore the attack path, providing strong support for rapid response and accurate tracing, effectively dealing with various AI-driven attacks.

[0133] 3. Enhance privacy protection and data governance capability - data governance module combines quantum random number and adaptive differential privacy to achieve double privacy protection and support risk assessment in ciphertext state. Homomorphic encryption and quantum computing-based optimization algorithms enable effective processing and risk assessment of data in encrypted state; automatic classification and real-time protection of sensitive data further ensure data privacy and security, improving the efficiency and security of data governance.

[0134] 4. Ensure model training compliance and explainability - the report generation module uses quantum entanglement verification mechanism to ensure the compliance of model training, effectively avoiding the risk of using unauthorized or sensitive data for training. By outputting the "generated AI ethical assessment report" and implementing manual review of high-risk operations, as well as using multi-dimensional evaluation indicators such as fairness, explainability and robustness, model training is more transparent, compliant and meets regulatory requirements, enhancing user trust in AI models.

[0135] 5. Dynamic privacy protection and comprehensive security protection are realized - adaptive differential privacy dynamically adjusts privacy budget and noise addition amount according to data characteristics, and better balances data privacy protection and availability; quantum entanglement verification mechanism guarantees the authenticity and integrity of data interaction, and comprehensively improves the security and reliability of the platform, and provides a comprehensive and efficient solution for information security management of data centers and servers.

[0136] In the embodiments provided in the present application, it should be understood that the embodiments described herein can be realized in hardware, software, firmware, middleware, code, or any appropriate combination thereof. For hardware implementation, the processor can be realized in one or more of the following units: application specific integrated circuit (ASIC), digital signal processor (DSP), digital signal processing device (DSPD), programmable logic device (PLD), field programmable gate array (FPGA), processor, controller, microcontroller, microprocessor, other electronic units designed to realize the functions described herein, or a combination thereof. For software implementation, part or all of the processes of the embodiments can be instructed by a computer program to relevant hardware. In implementation, the above program can be stored in a computer readable storage medium or transmitted as one or more instructions or codes on a computer readable storage medium. The computer readable storage medium includes computer storage medium and communication medium, wherein the communication medium includes any medium that facilitates the transmission of a computer program from one place to another. The storage medium can be any available medium that can be accessed by a computer. The computer readable storage medium can include, but is not limited to, RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program codes in the form of instructions or data structures and can be accessed by a computer.

[0137] Finally, it should be noted that: the above only describes the preferred embodiments of the present application and does not limit the present application. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art can modify the technical solutions described in the foregoing embodiments or make equivalent replacements to some technical features, as long as they are within the spirit and principles of the present application. Any modification, equivalent replacement, improvement, etc. made shall be included in the protection scope of the present application.

Claims

1. An information security supervision AI platform, characterized in that, The application comprises: A dynamic access control module configured to generate equivalent requests to isolate the original request from direct interaction with the database through quantum key distribution and multi-factor dynamic verification mechanism to protect data access security; An AI adversarial defense engine configured to enhance the detection robustness of AI models to variant attacks based on adversarial training and knowledge distillation models, and intelligently trace attack chains by constructing threat graphs; A data governance module configured to conduct double privacy protection using quantum random numbers and adaptive differential privacy, perform homomorphic encryption processing on anonymous data, and automatically classify and grade sensitive data based on context-aware large models; A report generation module configured to generate an explainability ethics evaluation report through a quantum entanglement verification mechanism; The knowledge distillation model is an improved GhostNet architecture, and the feature extraction layer of the improved GhostNet architecture adopts a quantum-inspired attention mechanism; The quantum-inspired attention mechanism specifically includes: wherein, is a quantum random number , is an input feature, , is a learnable weight matrix, is a Sigmoid function, is an element-wise multiplication; The loss function of the improved GhostNet architecture is: wherein, is a hyperparameter, is a cross-entropy loss, is a student model prediction probability, is a true label, is a student model, is a teacher model, is a temperature parameter, is a tuning parameter, is a variance calculation. 2.The information security supervision AI platform according to claim 1, characterized in that, The quantum key distribution specifically includes: The sender and the receiver generate random sequences respectively; The generated random sequences are transmitted through quantum channels to form quantum states; The corresponding base sequences of the sender and the receiver are compared to form an original key; The original key is obtained through a privacy amplification algorithm to obtain a final key. 3.The information security supervision AI platform according to claim 2, characterized in that, The multi-factor dynamic verification mechanism includes operation timing verification, which specifically includes: Extracting user operation sequences to construct an operation feature matrix; Calculating the similarity of operation sequences through a spatio-temporal graph neural network, and obtaining a verification result through a graph attention mechanism. 4.The information security supervision AI platform according to claim 1, characterized in that, The construction steps of the threat graph specifically include: Constructing heterogeneous graphs The node types include processes , files , users , and network connections The edges represent relationships between entities Performing semantic analysis on natural language queries extracting entity constraints , time ranges and query intent ; Acquiring graph neural network computing node representation , the expression is: wherein, is a normalization constant, is the layer weight matrix, is an activation function, and are the times corresponding to nodes v and u, respectively, is a tuning parameter; Generating a provenance path based on a query-aware attention mechanism, query vector Computing is wherein, is a quantum random number, is a classification label output by a BERT encoder, and are learnable parameters; Computing node and query relevance score , For the transpose of the vector , output the top k relevant entities ordered by score. 5.The information security supervision AI platform according to claim 1, characterized in that, The homomorphic encryption of the data governance module supports risk assessment in a ciphertext state, which specifically includes the following steps: Homomorphic feature extraction is performed on the ciphertext data C to generate a ciphertext feature vector ; The ciphertext nonlinear transformation is performed based on Chebyshev polynomial approximation, and a calculation formula is as follows: wherein, is a k-order Chebyshev polynomial, is a polynomial coefficient; calculating a ciphertext risk score wherein, is a ciphertext weight, is a ciphertext bias; determination result When , it indicates that the risk degree corresponding to the current processed ciphertext data is high, and there is potential risk; when , it indicates that the risk degree of the current ciphertext data is low. 6.The information security supervision AI platform according to claim 1, characterized in that, The sensitive data classification and grading specifically includes: constructing a multi-modal feature extractor to extract multiple features, calculating a comprehensive feature vector based on a quantum entanglement-inspired feature fusion mechanism, classifying using a quantum neural network, measuring an output quantum state, calculating a classification probability, and outputting a data type; wherein the output data types include ordinary data, sensitive data, and highly sensitive data.

7. The information security monitoring Al platform of claim 1, wherein, The report generation module outputs a generative AI ethics evaluation report, and high-risk operations are forced to be manually reviewed. Fairness indicators based on quantum entanglement fairness measurement, explainability indicators based on quantum entropy feature importance distribution, and robustness indicators based on quantum adversarial perturbation model stability measurement are used, and a comprehensive ethics score is calculated.

Citation Information

Patent Citations

  • Privacy computing security system based on domestic cryptographic algorithm

    CN119128944A

  • Network risk assessment model construction method and system based on AI large model

    CN120378177A